NEW
Font size
Worksheetssecurityplus 26-50
Total questions: 25
Worksheet time: 25mins
NO.26 An organization maintains several environments in which patches are developed and tested before deployed to an operation status. Which of the following is the environment in which patches will be deployed just prior to being put into an operational status?
(A). Development
(B). Test
(C). Production
(D). Staging
NO.27 A security analyst is investigating suspicious traffic on the web server located at IP address 10.10.1.1. A search of the WAF logs reveals the following output:
Which of the following is MOST likely occurring?
(A). XSS attack
(B). SQLi attack
(C). Replay attack
(D). XSRF attack
NO.28 Company engineers regularly participate in a public Internet forum with other engineers throughout the industry. Which of the following tactics would an attacker MOST likely use in this scenario?
(A). Watering-hole attack
(B). Credential harvesting
(C). Hybrid warfare
(D). Pharming
NO.29 Which of the following is a targeted attack aimed at compromising users within a specific industry or group?
(A). Watering hole
(B). Typosquatting
(C). Hoax
(D). Impersonation
NO.30 A user reports falling for a phishing email to an analyst. Which of the following system logs would the analyst check FIRST?
(A). DNS
(B). Message gateway
(C). Network
(D). Authentication
NO.31 A company labeled some documents with the public sensitivity classification. This means the documents can be accessed by:
(A). employees of other companies and the press
(B). all members of the department that created the documents
(C). only the company's employees and those listed in the document
(D). only the individuate listed in the documents
NO.32 Given the following logs:
Which of the following BEST describes the type of attack that is occurring?
(A). Rainbow table
(B). Dictionary
(C). Password spraying
(D). Pass-the-hash
NO.33 Which of the following is a benefit of including a risk management framework into an organization's security approach?
(A). It defines expected service levels from participating supply chain partners to ensure system
outages are remediated in a timely manner
(B). It identifies specific vendor products that have been tested and approved for use in a secure
environment.
(C). It provides legal assurances and remedies in the event a data breach occurs
(D). It incorporates control, development, policy, and management activities into IT operations.
NO.34 Business partners are working on a security mechanism to validate transactions securely. The requirement is for one company to be responsible for deploying a trusted solution that will register and issue artifacts used to sign encrypt, and decrypt transaction files. Which of the following is the BEST solution to adopt?
(A). PKI
(B). Blockchain
(C). SAML
(D). OAuth
NO.35 A website developer is working on a new e-commerce website and has asked an information security expert for the most appropriate way to store credit card numbers to create an easy reordering process. Which of the following methods would BEST accomplish this goal?
(A). Salting the magnetic strip information
(B). Encrypting the credit card information in transit.
(C). Hashing the credit card numbers upon entry.
(D). Tokenizing the credit cards in the database
NO.36 A security administrator needs to create a RAID configuration that is focused on high read speeds and fault tolerance. It is unlikely that multiple drivers will fail simultaneously. Which of the following RAID configurations should the administration use?
(A). RAID 0
(B). RAID1
(C). RAID 5
(D). RAID 10
NO.37 Which of the following provides a calculated value for known vulnerabilities so organizations can prioritize mitigation steps?
(A). CVSS
(B). SIEM
(C). SOAR
(D). CVE
NO.38 A social media company based in North America is looking to expand into new global markets and needs to maintain compliance with international standards. With which of the following is the company's data protection officer MOST likely concerned?
(A). NIST Framework
(B). ISO 27001
(C). GDPR
(D). PCI-DSS
NO.39 A security analyst is looking for a solution to help communicate to the leadership team the severity levels of the organization's vulnerabilities. Which of the following would BEST meet this need?
(A). CVE
(B). SIEM
(C). SOAR
(D). CVSS
NO.40 Which of the following describes a social engineering technique that seeks to exploit a person's sense of urgency?
(A). A phishing email stating a cash settlement has been awarded but will expire soon
(B). A smishing message stating a package is scheduled for pickup
(C). A vishing call that requests a donation be made to a local charity
(D). A SPIM notification claiming to be undercover law enforcement investigating a cybercrime
NO.41 Which of the following is an example of transference of risk?
(A). Purchasing insurance
(B). Patching vulnerable servers
(C). Retiring outdated applications
(D). Application owner risk sign-off
NO.42 Which of the following describes the continuous delivery software development methodology?
(A). Waterfall
(B). Spiral
(C). V-shaped
(D). Agile
NO.43 During a security incident investigation, an analyst consults the company's SIEM and sees an event concerning high traffic to a known, malicious command-and-control server. The analyst would like to determine the number of company workstations that may be impacted by this issue. Which of the following can provide the information?
(A). WAF logs
(B). DNS logs
(C). System logs
(D). Application logs
NO.44 A company is setting up a web server on the Internet that will utilize both encrypted and unencrypted web-browsing protocols. A security engineer runs a port scan against the server from the Internet and sees the following output:
Which of the following steps would be best for the security engineer to take NEXT?
(A). Allow DNS access from the internet.
(B). Block SMTP access from the Internet
(C). Block HTTPS access from the Internet
(D). Block SSH access from the Internet.
NO.45 Which of the following documents provides guidance regarding the recommended deployment of network security systems from the manufacturer?
(A). Cloud control matrix
(B). Reference architecture
(C). NIST RMF
(D). CIS Top 20
NO.46 Which of the following would be the BEST way to analyze diskless malware that has infected a VDI?
(A). Shut down the VDI and copy off the event logs.
(B). Take a memory snapshot of the running system.
(C). Use NetFlow to identify command-and-control IPs.
(D). Run a full on-demand scan of the root volume.
NO.47 Digital signatures use asymmetric encryption. This means the message is encrypted with:
(A). the sender's private key and decrypted with the sender's public key
(B). the sender's public key and decrypted with the sender's private key
(C). the sender's private key and decrypted with the recipient's public key
(D). the sender's public key and decrypted with the recipient's private key
NO.48 Which of the following is a risk that is specifically associated with hosting applications in the public cloud?
(A). Unsecured root accounts
(B). Zero-day
(C). Shared tenancy
(D). Insider threat
NO.49 A company discovered that terabytes of data have been exfiltrated over the past year after an employee clicked on an email link. The threat continued to evolve and remain undetected until a security analyst noticed an abnormal amount of external connections when the employee was not working. Which of the following is the MOST likely threat actor?
(A). Shadow IT
(B). Script kiddies
(C). APT
(D). Insider threat
NO.50 During a recent security incident at a multinational corporation a security analyst found the following logs for an account called user:
Which Of the following account policies would BEST prevent attackers from logging in as user?
(A). Impossible travel time
(B). Geofencing
(C). Time-based logins
(D). Geolocation
