Font size
WorksheetsComp_Sec_421-450
Total questions: 30
Worksheet time: 3hrs 30mins
NO.421 Which of the following function as preventive, detective, and deterrent controls to reduce
the risk of physical theft? (Select TWO).
(A). Mantraps
(B). Security guards
(C). Video surveillance
(D). Fences
(E). Bollards
NO.422 A security analyst needs to perform periodic vulnerably scans on production systems. Which
of the following scan types would produce the BEST vulnerability scan report?
(A). Port
(B). Intrusive
(C). Host discovery
(D). Credentialed
NO.423 Which of the following will MOST likely cause machine learning and Al-enabled systems to
operate with unintended consequences?
(A). Stored procedures
(B). Buffer overflows
(C). Data bias
(D). Code reuse
NO.424 Which of the following are requirements that must be configured for PCI DSS compliance?
(Select TWO).
(A). Testing security systems and processes regularly
(B). Installing and maintaining a web proxy to protect cardholder data
(C). Assigning a unique ID to each person with computer access
(D). Encrypting transmission of cardholder data across private networks
(E). Benchmarking security awareness training for contractors
NO.425 A security analyst is reviewing the following output from a system:
Which of the following is MOST likely being observed?
(A). ARP poisoning
(B). Man in the middle
(C). Denial of service
(D). DNS poisoning
NO.426 Customers reported their antivirus software flagged one of the company's primary software
products as suspicious. The company's Chief Information Security Officer has tasked the developer
with determining a method to create a trust model between the software and the customer's
antivirus software. Which of the following would be the BEST solution?
(A). Code signing
(B). Domain validation
(C). Extended validation
(D). Self-signing
NO.427 As part of a company's ongoing SOC maturation process, the company wants to implement
a method to share cyberthreat intelligence data with outside security partners. Which of the
following will the company MOST likely implement?
(A). TAXII
(B). TLP
(C). TTP
(D). STIX
NO.428 A company recently experienced an attack in which a malicious actor was able to exfiltrate
data by cracking stolen passwords, using a rainbow table the sensitive data. Which of the following
should a security engineer do to prevent such an attack in the future?
(A). Use password hashing.
(B). Enforce password complexity.
(C). Implement password salting.
(D). Disable password reuse.
NO.429 After consulting with the Chief Risk Officer (CRO). a manager decides to acquire
cybersecurity insurance for the company Which of the following risk management strategies is the
manager adopting?
(A). Risk acceptance
(B). Risk avoidance
(C). Risk transference
(D). Risk mitigation
NO.430 A manufacturing company has several one-off legacy information systems that cannot be
migrated to a newer OS due to software compatibility issues. The Oss are still supported by the
vendor, but the industrial software is no longer supported. The Chief Information Security Officer
(CISO) has created a resiliency plan for these systems that will allow OS patches to be installed in a
non-production environment, while also creating backups of the systems for recovery. Which of the
following resiliency techniques will provide these capabilities?
(A). Redundancy
(B). RAID 1+5
(C). Virtual machines
(D). Full backups
NO.431 Which of the following types of controls is a CCTV camera that is not being monitored?
(A). Detective
(B). Deterrent
(C). Physical
(D). Preventive
NO.432 The
website http://companywebsite.com requires users to provide personal Information, Including
security question responses, for registration. Which of the following would MOST likely cause a data
breach? (237.Soru ile ayni)
(A). Lack of input validation
(B). Open permissions
(C). Unsecure protocol
(D). Missing patches
NO.433 An attacker was easily able to log in to a company's security camera by performing a basic
online search for a setup guide for that particular camera brand and model Which of the following
BEST describes the configurations the attacker exploited?
(A). Weak encryption
(B). Unsecure protocols
(C). Default settings
(D). Open permissions
NO.434 A network manager is concerned that business may be negatively impacted if the firewall in
its datacenter goes offline. The manager would like to Implement a high availability pair to:
(A). decrease the mean ne between failures
(B). remove the single point of failure
(C). cut down the mean tine to repair
(D). reduce the recovery time objective
NO.435 An organization has expanded its operations by opening a remote office. The new office is
fully furnished with office resources to support up to 50 employees working on any given day. Which
of the following VPN solutions would BEST support the new office?
(A). Always On
(B). Remote access
(C). Site-to-site
(D). Full tunnel
NO.436 A network administrator is concerned about users being exposed to malicious content when
accessing company cloud applications. The administrator wants to be able to block access to sites
based on the AUP.
The users must also be protected because many of them work from home or at remote locations,
providing on-site customer support. Which of the following should the administrator employ to meet
these criteria?
(A). Implement NAC.
(B). Implement an SWG.
(C). Implement a URL filter.
(D). Implement an MDM.
NO.437 Which of the following would produce the closet experience of responding to an actual
incident response scenario?
(A). Lessons learned
(B). Simulation
(C). Walk-through
(D). Tabletop
NO.438 A client sent several inquiries to a project manager about the delinquent delivery status of
some critical reports. The project manager claimed the reports were previously sent via email, but
then quickly generated and backdated the reports before submitting them as plain text within the
body of a new email message thread.
Which of the following actions MOST likely supports an investigation for fraudulent submission?
(A). Establish chain of custody.
(B). Inspect the file metadata.
(C). Reference the data retention policy.
(D). Review the email event logs
NO.439 Local guidelines require that all information systems meet a minimum-security baseline to
be compliant.
Which of the following can security administrators use to assess their system configurations against
the baseline?
(A). SOAR playbook
(B). Security control matrix
(C). Risk management framework
(D). Benchmarks
NO.440 While investigating a data leakage incident, a security analyst reviews access control to
cloud-hosted data. The following information was presented in a security posture report.
Based on the report, which of the following was the MOST likely attack vector used against the
company?
(A). Spyware
(B). Logic bomb
(C). Potentially unwanted programs
(D). Supply chain
NO.441 Which of the following environments typically hosts the current version configurations and
code, compares user-story responses and workflow, and uses a modified version of actual data for
testing?
(A). Development
(B). Staging
(C). Production
(D). Test
NO.442 A host was infected with malware. During the incident response, Joe, a user, reported that
he did not receive any emails with links, but he had been browsing the Internet all day. Which of the
following would MOST likely show where the malware originated?
(A). The DNS logs
(B). The web server logs
(C). The SIP traffic logs
(D). The SNMP logs
NO.443 While reviewing pcap data, a network security analyst is able to locate plaintext usernames
and passwords being sent from workstations to network witches. Which of the following is the
security analyst MOST likely observing?
(A). SNMP traps
(B). A Telnet session
(C). An SSH connection
(D). SFTP traffic
NO.444 A Chief Security Officer (CSO) has asked a technician to devise a solution that can detect
unauthorized execution privileges from the OS in both executable and data files,
and can work in conjunction with proxies or UTM. Which of the following would BEST meet the CSO's
requirements?
(A). Fuzzing
(B). Sandboxing
(C). Static code analysis
(D). Code review
NO.445 The facilities supervisor for a government agency is concerned about unauthorized access to
environmental systems in the event the staff WiFi network is breached. Which of the blowing would
BEST address this security concern
(A). install a smart meter on the staff WiFi
(B). Place the environmental systems in the same DHCP scope as the staff WiFi
(C). Implement Zigbee on the staff WiFi access point
(D). Segment the staff WiFi network from the environmental systems networ
NO.446 A customer called a company's security team to report that all invoices the customer has
received over the last five days from the company appear to have fraudulent banking details. An
investigation into the matter reveals the following
* The manager of the accounts payable department is using the same password across multiple
external websites and the corporate account.
* One of the websites the manager used recently experienced a data breach.
* The manager's corporate email account was successfully accessed in the last five days by an IP
address located in a foreign country Which of the following attacks has MOST likely been used to
compromise the manager's corporate account?
(A). Remote access Trojan
(B). Brute-force
(C). Dictionary
(D). Credential stuffing
(E). Password spraying
NO.447 After reading a security bulletin, a network security manager is concerned that a malicious
actor may have breached the network using the same software flaw. The exploit code is publicly
available and has been reported as being used against other industries in the same vertical. Which of
the following should the network security manager consult FIRST to determine a priority list for
forensic review?
(A). The vulnerability scan output
(B). The IDS logs
(C). The full packet capture data
(D). The SIEM alerts
NO.448 A network administrator has been asked to design a solution to improve a company's
security posture The administrator is given the following, requirements?
* The solution must be inline in the network
* The solution must be able to block known malicious traffic
* The solution must be able to stop network-based attacks
Which of the following should the network administrator implement to BEST meet these requirements?
(A). HIDS
(B). NIDS
(C). HIPS
(D). NIPS
NO.449 A company is adopting a BYOD policy and is looking for a comprehensive solution to protect
company information on user devices. Which of the following solutions would BEST support the
policy?
(A). Mobile device management
(B). Full-device encryption
(C). Remote wipe
(D). Biometrics
NO.450 A security administrator is setting up a SIEM to help monitor for notable events across the
enterprise. Which of the following control types does this BEST represent?
A) Preventive
B) Compensating
C) Corrective
D) Detective
