wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Comp_Sec_421-450

Total questions: 30

Worksheet time: 3hrs 30mins

Name
Class
Date
1.

NO.421 Which of the following function as preventive, detective, and deterrent controls to reduce

the risk of physical theft? (Select TWO).

a)

(A). Mantraps

b)

(B). Security guards

c)

(C). Video surveillance

d)

(D). Fences

e)

(E). Bollards

2.

NO.422 A security analyst needs to perform periodic vulnerably scans on production systems. Which

of the following scan types would produce the BEST vulnerability scan report?

a)

(A). Port

b)

(B). Intrusive

c)

(C). Host discovery

d)

(D). Credentialed

3.

NO.423 Which of the following will MOST likely cause machine learning and Al-enabled systems to

operate with unintended consequences?

a)

(A). Stored procedures

b)

(B). Buffer overflows

c)

(C). Data bias

d)

(D). Code reuse

4.

NO.424 Which of the following are requirements that must be configured for PCI DSS compliance?

(Select TWO).

a)

(A). Testing security systems and processes regularly

b)

(B). Installing and maintaining a web proxy to protect cardholder data

c)

(C). Assigning a unique ID to each person with computer access

d)

(D). Encrypting transmission of cardholder data across private networks

e)

(E). Benchmarking security awareness training for contractors

5.

NO.425 A security analyst is reviewing the following output from a system:

Which of the following is MOST likely being observed?

a)

(A). ARP poisoning

b)

(B). Man in the middle

c)

(C). Denial of service

d)

(D). DNS poisoning

6.

NO.426 Customers reported their antivirus software flagged one of the company's primary software

products as suspicious. The company's Chief Information Security Officer has tasked the developer

with determining a method to create a trust model between the software and the customer's

antivirus software. Which of the following would be the BEST solution?

a)

(A). Code signing

b)

(B). Domain validation

c)

(C). Extended validation

d)

(D). Self-signing

7.

NO.427 As part of a company's ongoing SOC maturation process, the company wants to implement

a method to share cyberthreat intelligence data with outside security partners. Which of the

following will the company MOST likely implement?

a)

(A). TAXII

b)

(B). TLP

c)

(C). TTP

d)

(D). STIX

8.

NO.428 A company recently experienced an attack in which a malicious actor was able to exfiltrate

data by cracking stolen passwords, using a rainbow table the sensitive data. Which of the following

should a security engineer do to prevent such an attack in the future?

a)

(A). Use password hashing.

b)

(B). Enforce password complexity.

c)

(C). Implement password salting.

d)

(D). Disable password reuse.

9.

NO.429 After consulting with the Chief Risk Officer (CRO). a manager decides to acquire

cybersecurity insurance for the company Which of the following risk management strategies is the

manager adopting?

a)

(A). Risk acceptance

b)

(B). Risk avoidance

c)

(C). Risk transference

d)

(D). Risk mitigation

10.

NO.430 A manufacturing company has several one-off legacy information systems that cannot be

migrated to a newer OS due to software compatibility issues. The Oss are still supported by the

vendor, but the industrial software is no longer supported. The Chief Information Security Officer

(CISO) has created a resiliency plan for these systems that will allow OS patches to be installed in a

non-production environment, while also creating backups of the systems for recovery. Which of the

following resiliency techniques will provide these capabilities?

a)

(A). Redundancy

b)

(B). RAID 1+5

c)

(C). Virtual machines

d)

(D). Full backups

11.

NO.431 Which of the following types of controls is a CCTV camera that is not being monitored?

a)

(A). Detective

b)

(B). Deterrent

c)

(C). Physical

d)

(D). Preventive

12.

NO.432 The

website http://companywebsite.com requires users to provide personal Information, Including

security question responses, for registration. Which of the following would MOST likely cause a data

breach? (237.Soru ile ayni)

a)

(A). Lack of input validation

b)

(B). Open permissions

c)

(C). Unsecure protocol

d)

(D). Missing patches

13.

NO.433 An attacker was easily able to log in to a company's security camera by performing a basic

online search for a setup guide for that particular camera brand and model Which of the following

BEST describes the configurations the attacker exploited?

a)

(A). Weak encryption

b)

(B). Unsecure protocols

c)

(C). Default settings

d)

(D). Open permissions

14.

NO.434 A network manager is concerned that business may be negatively impacted if the firewall in

its datacenter goes offline. The manager would like to Implement a high availability pair to:

a)

(A). decrease the mean ne between failures

b)

(B). remove the single point of failure

c)

(C). cut down the mean tine to repair

d)

(D). reduce the recovery time objective

15.

NO.435 An organization has expanded its operations by opening a remote office. The new office is

fully furnished with office resources to support up to 50 employees working on any given day. Which

of the following VPN solutions would BEST support the new office?

a)

(A). Always On

b)

(B). Remote access

c)

(C). Site-to-site

d)

(D). Full tunnel

16.

NO.436 A network administrator is concerned about users being exposed to malicious content when

accessing company cloud applications. The administrator wants to be able to block access to sites

based on the AUP.

The users must also be protected because many of them work from home or at remote locations,

providing on-site customer support. Which of the following should the administrator employ to meet

these criteria?

a)

(A). Implement NAC.

b)

(B). Implement an SWG.

c)

(C). Implement a URL filter.

d)

(D). Implement an MDM.

17.

NO.437 Which of the following would produce the closet experience of responding to an actual

incident response scenario?

a)

(A). Lessons learned

b)

(B). Simulation

c)

(C). Walk-through

d)

(D). Tabletop

18.

NO.438 A client sent several inquiries to a project manager about the delinquent delivery status of

some critical reports. The project manager claimed the reports were previously sent via email, but

then quickly generated and backdated the reports before submitting them as plain text within the

body of a new email message thread.

Which of the following actions MOST likely supports an investigation for fraudulent submission?

a)

(A). Establish chain of custody.

b)

(B). Inspect the file metadata.

c)

(C). Reference the data retention policy.

d)

(D). Review the email event logs

19.

NO.439 Local guidelines require that all information systems meet a minimum-security baseline to

be compliant.

Which of the following can security administrators use to assess their system configurations against

the baseline?

a)

(A). SOAR playbook

b)

(B). Security control matrix

c)

(C). Risk management framework

d)

(D). Benchmarks

20.

NO.440 While investigating a data leakage incident, a security analyst reviews access control to

cloud-hosted data. The following information was presented in a security posture report.

Based on the report, which of the following was the MOST likely attack vector used against the

company?

a)

(A). Spyware

b)

(B). Logic bomb

c)

(C). Potentially unwanted programs

d)

(D). Supply chain

21.

NO.441 Which of the following environments typically hosts the current version configurations and

code, compares user-story responses and workflow, and uses a modified version of actual data for

testing?

a)

(A). Development

b)

(B). Staging

c)

(C). Production

d)

(D). Test

22.

NO.442 A host was infected with malware. During the incident response, Joe, a user, reported that

he did not receive any emails with links, but he had been browsing the Internet all day. Which of the

following would MOST likely show where the malware originated?

a)

(A). The DNS logs

b)

(B). The web server logs

c)

(C). The SIP traffic logs

d)

(D). The SNMP logs

23.

NO.443 While reviewing pcap data, a network security analyst is able to locate plaintext usernames

and passwords being sent from workstations to network witches. Which of the following is the

security analyst MOST likely observing?

a)

(A). SNMP traps

b)

(B). A Telnet session

c)

(C). An SSH connection

d)

(D). SFTP traffic

24.

NO.444 A Chief Security Officer (CSO) has asked a technician to devise a solution that can detect

unauthorized execution privileges from the OS in both executable and data files,

and can work in conjunction with proxies or UTM. Which of the following would BEST meet the CSO's

requirements?

a)

(A). Fuzzing

b)

(B). Sandboxing

c)

(C). Static code analysis

d)

(D). Code review

25.

NO.445 The facilities supervisor for a government agency is concerned about unauthorized access to

environmental systems in the event the staff WiFi network is breached. Which of the blowing would

BEST address this security concern

a)

(A). install a smart meter on the staff WiFi

b)

(B). Place the environmental systems in the same DHCP scope as the staff WiFi

c)

(C). Implement Zigbee on the staff WiFi access point

d)

(D). Segment the staff WiFi network from the environmental systems networ

26.

NO.446 A customer called a company's security team to report that all invoices the customer has

received over the last five days from the company appear to have fraudulent banking details. An

investigation into the matter reveals the following

* The manager of the accounts payable department is using the same password across multiple

external websites and the corporate account.

* One of the websites the manager used recently experienced a data breach.

* The manager's corporate email account was successfully accessed in the last five days by an IP

address located in a foreign country Which of the following attacks has MOST likely been used to

compromise the manager's corporate account?

a)

(A). Remote access Trojan

b)

(B). Brute-force

c)

(C). Dictionary

d)

(D). Credential stuffing

e)

(E). Password spraying

27.

NO.447 After reading a security bulletin, a network security manager is concerned that a malicious

actor may have breached the network using the same software flaw. The exploit code is publicly

available and has been reported as being used against other industries in the same vertical. Which of

the following should the network security manager consult FIRST to determine a priority list for

forensic review?

a)

(A). The vulnerability scan output

b)

(B). The IDS logs

c)

(C). The full packet capture data

d)

(D). The SIEM alerts

28.

NO.448 A network administrator has been asked to design a solution to improve a company's

security posture The administrator is given the following, requirements?

* The solution must be inline in the network

* The solution must be able to block known malicious traffic

* The solution must be able to stop network-based attacks

Which of the following should the network administrator implement to BEST meet these requirements?

a)

(A). HIDS

b)

(B). NIDS

c)

(C). HIPS

d)

(D). NIPS

29.

NO.449 A company is adopting a BYOD policy and is looking for a comprehensive solution to protect

company information on user devices. Which of the following solutions would BEST support the

policy?

a)

(A). Mobile device management

b)

(B). Full-device encryption

c)

(C). Remote wipe

d)

(D). Biometrics

30.

NO.450 A security administrator is setting up a SIEM to help monitor for notable events across the

enterprise. Which of the following control types does this BEST represent?

a)

A) Preventive

b)

B) Compensating

c)

C) Corrective

d)

D) Detective