Font size
Worksheets601 Uc 12192022
Total questions: 70
Worksheet time: 37mins
Which of the following is a proprietary wireless standard maintained by Silicon Labs and supports throughput up to 40 kbps over distances of 10-100m between nodes?
Z-Wave
CAN bus
NB-IoT
What kind of policy governs the removal of sensitive data and credentials when a user device is no longer used for company business?
Offboarding
Storage segmentation
Onboarding
Asset tracking
You’ve been asked to provide security advice for a custom-robotics project using an off-the-shelf single-board computer and a specialized Linux operating system. What technology should you research first?
RTOS
Raspberry Pi
Arduino
FPGA
What connection type is very similar to Bluetooth but used by more specialized devices, such as sensors and fitness trackers?
SATCOM
NFC
GSM
ANT
Which of the following are essential security steps on all mobile devices?
Each correct answer represents a complete solution. Choose two.
Using biometric authentication
Installing a firewall app
Configuring antivirus software
Regularly applying operating system updates
Configuring remote backup features
Which of the following key management solutions would be best for a multinational organization with a strong multi-cloud presence?
HSM
HSMaaS
Key escrow
KMS
Which of the following is an integrated circuit with a logical structure that can be reprogrammed after manufacture, in contrast to the pre-printed logic functions found in a microprocessor or ASIC?
IoT
RTOS
FPGA
SoC
Which Windows encryption tool can protect the entire system volume?
Encrypting File System (EFS)
BitLocker
The attrib . +r command
Both BitLocker and EFS
What connection type is very similar to Bluetooth but is used by more specialized devices?
RFID
ANT+
GPS
NFC
What kind of policy governs a set process for how an employee needs to prepare a device to join the program?
Offboarding
Onboarding
Storage segmentation
Asset tracking
Question 11 :Mark wants to securely erase the contents of a tape used for backups in his organization's tape library. What is the fastest secure erase method will he use that will allow the tape to be reused?
Burn the tape.
Incinerate the tape.
Wipe the tape by writing a random pattern of 1s and 0s to it.
Use a degausser.
In which of the following can the employee choose between a list of devices the company has approved for security features and support?
Asset tracking
CYOD
GPS
BYOD
Which standard do you need to use when handling credit card data?
NIST
HIPAA
PKI
PCI DSS
What potential security risk does an SD card pose that a USB flash drive does not?
Data exfiltration
Wireless attacks
Photographs of sensitive areas
Malware
Question 15 :Privacy-enhancing technologies are part of a larger principle by which the amount of PII, PHI, or other sensitive private data that is collected and stored is carefully limited. What is the "umbrella" term under which many other terms regarding privacy enhancement fall?
Data minimization
Anonymization
Tokenization
Data masking
Which of the following technologies helps to control what information can be exfiltrated from internal users and systems and what form such data can take?
HSM
FDE
DLP
TPM
What was the first version of Windows to include real-time antivirus scanning?
Windows Vista
Windows XP Service Pack 2
Windows 8
Windows 7
You are developing an application for sale to the public. You want to assure your users that the application they receive actually came from you. What technique will you use to provide this assurance?
HIDS
Trusted hardware
Code signing
Firewall
What kind of malware can spread through a network without any human interaction?
Trojan horse
PUP
Worm
Virus
Among the options listed, which mitigation technique is known most for increasing security at the expense of flexibility?
SOAR
Application whitelisting
Application blacklisting
MDM
Which of the following environments is a prime vector for fileless malware in a Windows environment?
Macros
PowerShell
Python
Bash
Crypto-malware is a type of what sort of malware?
Keylogger
Trojan
Rootkit
Ransomware
In terms of data governance policies, what is the relationship between the terms data custodian and data steward?
The data owner performs the role of data custodian, but the data steward is a different employee.
There is no functional difference in the roles based on these terms, but different organizations prefer one over the other.
The custodian is interested in the technical nature of data security, while the steward is focused on its value, usefulness, and compliance to standards
The custodian has sole "custody" of, or access to, the data, while the steward ensures that the data is placed where only the custodian can access it.
A company decides to invest in embedded systems to improve security by limiting the number of components used in various critical and sensitive systems. Which of the following would make it more difficult to justify embedded systems in certain cases?
Rejecting the use of FPGAs
The decision to interface with external cryptographic modules
The wireless networking range
The fact that an entire system is placed on a single chip
It has come to your attention that a newly created sensitive document is making the rounds among authorized users in the company. Which enterprise utility can you adjust the configuration of to reduce the likelihood that the document will fall into the wrong hands in a readable format?
SSL decryptor
Firewall
MDM
DLP
What kind of malware replicates itself by exploiting system vulnerabilities?
Trojan horse
Logic bomb
Worm
Virus
What data management model assists professionals in decision making with regard to the creation of policy based on the convergence of data security and privacy, focusing on such aspects as to how it's attained and classified, how it's used and stored, and how it's archived and destroyed?
An impact assessment
The information life cycle
Public notifications and disclosures
Privacy-enhancing technologies
Which of the following is a form of ransomware?
Crypto-malware
Rootkit
Command and control
Bot
The VP of human resources has put you in charge of securing a critical server for the department. You’ll be hardening its operating system according to company policies and regularly checking configuration and system logs. In asset management terms, what role have you taken on?
Custodian
User
Owner
Administrator
Which privacy-enhancing technology cannot be reversed and, yet, has the distinguishing capability of either replacing private data in the database or retaining it and replacing it only when each record is read from the database, usually while keeping the format and structure of the fields it impacts?
Data masking
Tokenization
Pseudo-anonymization
Anonymization
What technology uses the TPM to store hashes of signed boot files for comparison the next time the system boots and for export in a quote for remote attestation?
Secure boot
UEFI
Boot attestation
Measured boot
A user complains that every time they open their Internet browser, it no longer goes to their preferred home page, and advertisements pop up in dialog boxes that they have to close. What is the likely cause?
Virus
Trojan
Spyware
Worm
What cryptographic tool is commonly built into a motherboard?
FDE
TPM
HSM
DLP
Your organization has a degausser in the basement. What media can it securely destroy? Each correct answer represents a complete solution. Choose two.
Backup tapes
Hard drives
Optical discs
Paper documents
SSDs
Among the options listed, which mitigation technique is known most for increasing security at the expense of flexibility?
Application blacklisting
Application whitelisting
SOAR
MDM
A host on the network is potentially infected with a novel virus, and you don't want it to spread while you study it. You've decided that network segmentation won't be effective enough and you'd prefer to isolate the host. Which of the following will best achieve that goal?
Changing firewall rules to exclude traffic to and from the affected host
Changing the VLAN of the switch port to which the affected host connects
Changing the IP address of the affected host
Creating an air gap
Which technology or category of products was developed to allow agents installed on hosts to report a variety of measurable statistics for central processing and analysis?
NIDS
UTM
EDR
HIDS
Which of the following are essential security steps on all mobile devices?
Each correct answer represents a complete solution. Choose two.
Using biometric authentication
Configuring remote backup features
Regularly applying operating system updates
Configuring antivirus software
Installing a firewall app
It has come to your attention that a newly created sensitive document is making the rounds among authorized users in the company. Which enterprise utility can you adjust the configuration of to reduce the likelihood that the document will fall into the wrong hands in a readable format?
MDM
DLP
SSL decryptor
Firewall
What is an example of IP theft?
A competitor's use of the public IPv4 address space that was assigned by an ISP to your organization
A competitor's unauthorized use of your organization's original engineering documents
Publishing a textbook written by an independent author
Downloading an operating system from the Ubuntu website and installing it without paying for it
What kind of application centrally manages security policy and settings on all company mobile devices?
GPS
MAM
MDM
BYOD
While analyzing the shortcomings in the operation of the enterprise's NIDS, you discover that in its current mode of operation, only known attacks are being reported. What is recommended to enable detection of previously unknown attack methods through the use of artificial intelligence (AI)?
Heuristic
Stateful protocol analysis
Signature-based rule
Passive detection
Steffie wants to select a mobile device deployment method that provides employees with devices that are company-issued and supported, but employees can use them for personal reasons too. Which of the following is the most likely culprit?
COBO
COPE
CYOD
BYOD
Which standard do you need to use when handling credit card data?
NIST
HIPAA
PKI
PCI DSS
Which of the following is a proprietary wireless standard maintained by Silicon Labs and supports throughput up to 40 kbps over distances of 10-100m between nodes?
Z-Wave
Zigbee
NB-IoT
CAN bus
Which privacy-enhancing technology performs a reversible substitution of PII, storing the private data elsewhere, reducing the likelihood that a breach of the records containing the non-private substituted information will lead to legal jeopardy for the organization entrusted with the PII?
Pseudo-anonymization
Data minimization
Full Anonymization
Data masking
Which privacy-enhancing technology neither alters original PII in a database nor creates a separate version in a new database and instead provides a representation of the sensitive data to the viewer in its original format, often replacing all parts of the sensitive information with the same character?
Encryption
Hashing
Masking
Tokenization
Which of the following security risks is least important to address in enterprise patch management systems?
Operating systems
Applications
CPU microcode
Firmware
Which of these statements about bash scripts is accurate?
Bash scripts must be executed in a special command-line shell on top of the standard Linux shell.
Bash scripts are more dangerous than PowerShell scripts because the attacker does not need elevated privileges to cause the same damage.
Bash scripts are not dangerous until they are compiled into executables.
Bash scripts can be used to attack Windows 10 machines.
Which of the following tools is used to sandbox suspected malware and report on what occurred during its execution?
Nessus
netstat
cURL
Cuckoo
Which of the following statements is correct regarding BitLocker?
Each user account has a separate BitLocker key stored in its settings.
BitLocker-encrypted files are unreadable to other users on the same computer.
Any user can independently encrypt files using BitLocker.
It protects entire drives with personal and system files.
You're classifying data for a private company which uses four classification levels. Under what classification does PHI most likely fall?
Private
Sensitive
Confidential
Critical
Which authentication method allows a trusted system to vouch for the secure hardware and software configuration of another?
Federation
Remote attestation
HOTP
Directory services
What data management model assists professionals in decision making with regard to the creation of policy based on the convergence of data security and privacy, focusing on such aspects as to how it's attained and classified, how it's used and stored, and how it's archived and destroyed?
Privacy-enhancing technologies
An impact assessment
The information life cycle
Public notifications and disclosures
What kind of malware replicates itself by exploiting system vulnerabilities?
Logic bomb
Trojan horse
Virus
Worm
You’ve taken up a contract helping to upgrade the existing industrial control network for an oil refinery. What network type should you expect to work with?
SCADA
IoT
DCS
VoIP
Which mobile deployment model allows users to carry a single mobile device for business and personal use while allowing the enterprise to retain ownership of, and control over, the selection of devices on which support staff must be trained and skilled?
COPE
COBO
BYOD
CYOD
Which of the following enterprise mobile deployment models introduces the greatest amount of risk for the implementing organization?
COPE
CYOD
COBO
BYOD
Who among the following is a system administrator responsible for creating and enforcing the technical controls regarding access to data, under the direction of its owner?
Privacy officer
Data steward
Data owner
Data custodian
What MDM features allow the administrator to silently update a corporate app and its content on mobile devices in the background?
Each correct answer represents a part of the solution. Choose two
MAM
Push notifications
SMS/MMS
VDI/VMI
MCM
Which of the following delivers advertisements to the infected system, usually within a browser or other application windows?
Virus
Worm
Adware
Trojan
You want to use your Android phone to store and manage cryptographic certificates. Which type of solution will you choose to do this using secure hardware?
SEAndroid
A microSD HSM
MDM
A wireless TPM
You’ve traced some anomalous network activity infecting the whole department’s computers by stealing information. They're installed as add-ons with legitimate free software applications by popular download sites. What kind of malware is it?
Botnet
Trojan
Spyware
PUP
A company configures workstations only to run software on an approved list. What is this an example of?
Hardening
Sandboxing
Allow listing
Block listing
Question 79 :You’ve traced some anomalous network activity to malware that’s infected a whole department’s computers. The computers are processing a distributed task using spare CPU cycles, communicating with a remote server, and sending emails to random targets. What kind of malware is it?
Botnet
PUP
Trojan
Spyware
Why might an administrator decide to employ an enterprise MDM solution to deny support for USB OTG on mobile devices?
USB OTG can drain the mobile devices by allowing them to charge other devices.
USB OTG supports the attachment of devices that block remote-wipe signals.
Geolocation is unable to track devices running USB OTG.
The connector on the mobile devices is used simultaneously for charging and for data transfer.
What is the most common concern with regard to residential IoT devices and technologies?
Weak default configurations
Lack of standards
No ability to encrypt transmissions
Manufacturer lock-in
Which of the following are differences between SED and non-SED FDE?
Each correct answer represents a complete solution. Choose two.
SED drivers are supported by fewer operating systems.
Opal is a standard that applies only to SED.
SED-based encryption does not suffer from OS-related performance degradation.
SED does not encrypt all data on the drive.
SED does not require a key for encryption and decryption.
Your organization has a degausser in the basement. What media can it securely destroy? Each correct answer represents a complete solution. Choose two.
Backup tapes
SSDs
Paper documents
Optical discs
Hard drives
What potential security risk does an SD card pose that a USB flash drive does not?
Photographs of sensitive areas
Wireless attacks
Data exfiltration
Malware
