Font size
WorksheetsComp_Sec_241-270
Total questions: 30
Worksheet time: 3hrs 30mins
NO.241 Several employees have noticed other bystanders can clearly observe a terminal where
passcodes are being entered. Which of the following can be eliminated with the use of a privacy
screen?
Shoulder surfing
Spear phishing
Impersonation attack
Card cloning
NO.242 A security analyst needs to complete an assessment.
The analyst is logged into a server and
must use native tools to map services running on it to the server's listening ports.
Which of the
following tools can BEST accomplish this talk?
Netcat
Netstat
Nmap
Nessus
NO.243 A workwide manufacturing company has been experiencing email account compromised.
In one incident, a user logged in from the corporate office in France, but then seconds later, the same user account attempted a login from Brazil.
Which of the following account policies would BEST prevent this type of attack?
Network location
Impossible travel time
Geolocation
Geofencing
NO.244 A user recently attended an exposition and received some digital promotional materials.
The user later noticed blue boxes popping up and disappearing on the computer,
and reported receiving several spam emails, which the user did not open.
Which of the following is MOST likely the cause of the reported issue?
There was a drive-by download of malware
The user installed a cryptominer
The OS was corrupted
There was malicious code on the USB drive
NO.245 An organization is concerned about intellectual property theft by
employee who leave the organization.
Which of the following will be organization MOST likely implement?
CBT
NDA
MOU
AUP
NO.246 An end user reports a computer has been acting slower than normal for a few weeks. During an investigation, an analyst determines the system is sending the user's email address and a ten-digit number to an IP address once a day.
The only recent log entry regarding the user's computer is the following:
Which of the following is the MOST likely cause of the issue?
The end user purchased and installed a PUP from a web browser
A bot on the computer is brute forcing passwords against a website
A hacker is attempting to exfiltrate sensitive data
Ransomware is communicating with a command-and-control server
NO.247 An organization would like to remediate the risk associated with its cloud service provider not meeting its advertised 99.999% availability metrics.
Which of the following should the
organization consult for the exact requirements for the cloud provider?
SLA
BPA
NDA
MOU
No. 248 Which of the following will provide the BEST physical security countermeasures to stop intruders? (Choose two)
Alarms
&
Signage
Lighting
Sensors
Mantraps
Fencing
NO.249 An incident response technician collected a mobile device during an investigation.
Which of the following should the technician do to maintain chain of custody?
Document the collection and require a sign-off when possession changes.
Lock the device in a safe or other secure location to prevent theft or alteration.
Place the device in a Faraday cage to prevent corruption of the data.
Record the collection in a blockchain-protected public ledger.
NO.250 Administrators have allowed employee to access their company email from personal
computers.
However, the administrators are concerned that these computes are another attach
surface and can result in user accounts being breached by foreign actors.
Which of the following actions would provide the MOST secure solution?
Enable an option in the administration center so accounts can be locked if they are accessed from
different geographical areas
Implement a 16-character minimum length and 30-day expiration password policy
Set up a global mail rule to disallow the forwarding of any company email to email addresses
outside the organization
Enforce a policy that allows employees to be able to access their email only while they are
connected to the internet via VPN
NO.251 A security analyst is performing a forensic investigation compromised account credentials.
Using the Event Viewer, the analyst able to detect the following message, ''Special privileges assigned to new login.''
Several of these messages did not have a valid logon associated with the user before these privileges were assigned.
Which of the following attacks is MOST likely being detected?
Pass-the-hash
Buffer overflow
Cross-site scripting
Session replay
No.252 Which of the following environments would MOST likely be used to assess the execution of component parts of a system at both the hardware and software levels and to measure performance of characteristics?
Test
Staging
Development
Production
NO.253 A security administrator suspects there may be unnecessary services running on a server.
Which of the following tools will the administrator MOST likely use to confirm the suspicions?
Nmap
Wireshark
Autopsy
DNSEnum
NO.254 A technician needs to prevent data loss in a laboratory. The laboratory is not connected to any external networks.
Which of the following methods would BEST prevent data? (Select TWO)
VPN
Drive encryption
Network firewall
MFA
&
File-level encryption
USB blocker
NO.255 The security team received a report of copyright infringement from the IP space of lire
corporate network. The report provided a precise time stamp for the incident as well as the name of
the copyrighted le. The analyst has been tasked with determining the infringing source machine and
instructed to implement measures to prevent such incidents from occurring again.
Which of the following is MOST capable of accomplishing both tasks?
HIDS
Allow list
TPM
NGFW
NO.256 An organization's corporate offices were destroyed due to a natural disaster, so the organization is now setting up offices in a temporary work space.
Which of the following will the organization MOST likely consult?
The business continuity plan
The disaster recovery plan
The communications plan
The incident response plan
No. 257 Which of the following describes the ability of code to target a hypervisor from inside a guest OS?
Fog computing
VM escape
Software-defined networking
Image forgery
Container breakout
NO.258 An information security policy states that separation of duties is required for all highly sensitive database changes that involve customers' financial data. Which of the following will this be BEST to prevent?
Least privilege
An insider threat
A data breach
A change control violation
NO.259 A user recent an SMS on a mobile phone that asked for bank delays.
Which of the following social-engineering techniques was used in this case?
SPIM
Vishing
Spear phishing
Smishing
NO. 260 A company wants to deploy PKI on its Internet-facing website.
The applications that are currently deployed are:
✑ www.company.com (main website)
✑ contactus.company.com (for locating a nearby location)
✑ quotes.company.com (for requesting a price quote)
The company wants to purchase one SSL certificate that will work for all the existing applications and any future applications that follow the same naming conventions, such as store.company.com.
Which of the following certificate types would BEST meet the requirements?
SAN
Wildcard
Extended validation
Self-signed
NO.261 An attack relies on an end user visiting a website the end user would typically visit, however, the site is compromised and uses vulnerabilities in the end users browser to deploy malicious software.
Which of the blowing types of attack does this describe?
Smishing
Whaling
Watering hole
Phishing
NO.262 Which of the following will MOST likely adversely impact the operations of unpatched traditional programmable-logic controllers, running a back-end LAMP server and OT systems with human-management interfaces that are accessible over the Internet via a web interface?
SQL injection &
Cross-site scripting
Data exfiltration
Poor system logging
Weak encryption
Server-side request forgery
NO.263 A systems analyst is responsible for generating a new digital forensics chain-of-custody form.
Which of the following should the analyst include in this documentation? (Select TWO).
The order of volatility
A checksum
&
A warning banner
The location of the artifacts
The vendor's name
The date and time
NO.264 The Chief Financial Officer (CFO) of an insurance company received an email from Ann, the company's Chief Executive Officer (CEO), requesting a transfer of $10,000 to an account. The email states Ann is on vacation and has lost her purse, containing cash and credit cards.
Which of the
following social-engineering techniques is the attacker using?
Phishing
Whaling
Typo squatting
Pharming
NO.265 A software developer needs to perform code-execution testing, black-box testing, and non-functional testing on a new product before its general release.
Which of the following BEST describes the tasks the developer is conducting?
Verification
Validation
Normalization
Staging
A security analyst sees the following log output while reviewing web logs:
Which of the following mitigation strategies would be BEST to prevent this attack from being successful?
Secure cookies
Input validation
Code signing
Stored procedures
NO.267 On which of the following is the live acquisition of data
for forensic analysis MOST dependent?
Data accessibility
&
Value and volatility of data
Legal hold
Cryptographic or hash algorithm
Data retention legislation
Right-to-audit clauses
NO.268 The human resources department of a large online retailer has received multiple customer
complaints about the rudeness of the automated chatbots. It uses to interface and assist online
shoppers.
The system, which continuously learns and adapts, was working fine when it was installed
a few months ago.
Which of the following BEST describes the method being used to exploit the
system?
Baseline modification
A fileless virus
Tainted training data
Cryptographic manipulation
NO.269 A company is upgrading its wireless infrastructure to WPA2-Enterprise using EAP-TLS. Which
of the following must be part of the security architecture to achieve AAA?
DNSSEC
Reverse proxy
VPN concentrator
PKI
Active Directory
& RADIUS
NO.270 An organization has various applications that contain sensitive data hosted in the cloud.
The company's leaders are concerned about lateral movement across applications of different trust
levels.
Which of the following solutions should the organization implement to address the concern?
ISFW
UTM
SWG
CASB
( cloud
access security broker)
