WorksheetsSecurity+ SY0 601 Questions 42-82
Total questions: 42
Worksheet time: 22mins
An organization is tuning SIEM rules based off of threat intelligence
reports. Which of the following phases of the incident response process
does this scenario represent?
Eradication
Lessons Learned
Preparation
Recovery
A network manager is concerned that business may be negatively
impacted if the firewall in its datacenter goes offline. The manager would
like to implement a high availability pair to:
decrease the mean time between failures
remove the single point of failure.
cut dawn the mean time to repair.
reduce the recovery time objective.
A host was infected with malware. During the incident response, Joe, a
user, reported that he did not receive any emails with links, but he had
been browsing the Internet all day.
Which of the following would MOST likely show where the malware
originated?
The DNS logs
The web server logs
The SIP traffic logs
The SNMPlogs
Which of the following would MOST likely be identified by a
Points
credentialed scan but would be missed by an uncredentialed scan?
Vulnerabilities with a CVSS score greater than 6.9.
Critical infrastructure vulnerabilities on non-lP protocols.
CVEs related to nan-Microsoft systems such as printers and switches.
Missing patches far third-party software an Windows workstations and
servers.
A recent phishing campaign resulted in several compromised user
accounts. The security incident response team has been tasked with
reducing the manual labor ot filtering through all the phishing emails as
they arrive and blocking the sender's email address, along with other
time-consuming mitigation actions.
Which of the following can be configured to streamline those tasks?
SOAR playbook
MOM policy
Firewall rules
URLfilter
SIEM data collection
Which of the following is a reason to publish files' hashes?
To validate the integrity af the files
To verify if the software was digitally signed
To use the hash as a software activation key
To use the hash as a decryption passphrase
A security analyst is tasked with classifying data to be stored on company
servers.
Which of the following should be classified as proprietary?
CustomerS dates af birth
CustomerS email addresses
Marketing strategies
Employee salaries
Which of the following are requirements that must be configured for PCI
OSS compliance? (Choose two.)
Testing security systems and processes regularly
Installing and maintaining a web proxy to protect cardholder data
Assigning a unique 10 to each person with computer access
Encrypting transmission of cardholder data across private networks
Benchmarking security awareness training far contractors
Which of the following can be used by a monitoring tool to compare
values and detect password leaks without providing the actual
credentials?
Hashing
Tokenization
Masking
Encryption
An organization would like to give remote workers the ability to use
applications hosted inside the corporate network. Users will be allowed to
use their personal computers, or they will be provided organization
assets. Either way, no data or applications will be installed locally on any
user systems.
Which of the following mobile solutions would accomplish these
goals?
VDI
MDM
COPE
UTM
Which of the following explains why RTO is included in a BlA?
It identifies the amount of allowable downtime for an application or system.
It prioritizes risks so the organization can allocate resources appropriately.
It monetizes the loss of an asset and determines a break-even point for risk
mitigation.
It informs the backup approach so that the organization can recover data ta
a known time.
Against the recommendation ot the IT security analyst, a company set all
user passwords on a server as F@55w0rD. upon review of the
/etc/passwd file, an attacker found the following:
Perfect forward secrecy
Key stretching
Salting
Hashing
Which of the following would be the BEST way to analyze diskless
malware that has infected a VDI?
Run a full on-demand scan of the root volume.
Shut down the VOI and copy off the event logs.
Take a memory snapshot of the running system.
Use NetFlow to identify command-and-control IPs.
An attacker browses a company's online job board attempting to find any
relevant information regarding the technologies the company uses.
Which of the following BEST describes this social engineering
technique?
Hoax
Reconnaissance
Impersonation
Pretexting
An organization is building backup server rooms in geographically diverse
locations. The Chief Information Security Officer implemented a
requirement on the project that states the new hardware cannot be
susceptible to the same vulnerabilities in the existing server room.
Which of the following should the systems engineer consider?
Purchasing hardware from different vendors
Migrating workloads to public cloud infrastructure
Implementing a robust patch management solution
Designing new detective security controls
While investigating a recent security incident, a security analyst decided
to view all network connections on a paäicular server.
Which of the following would provide the desired information?
nslookup
netstat
nmap
arp
A Chief Information Security Officer (CISO) has defined resiliency
requirements for a new data center architecture The requirements are as
follows:
• Critical fileshares will remain accessible during and after a natural
disaster
• Five percent of hard disks can fail at any given time without impacting
the data.
• Systems will be forced to shut down gracefully when battery levels are
below 20%.
Which of the following are required to BEST meet these objectives? (Select THREE)
RAID
High Availability
NAS
UPS
Redundant power supplies
While investigating a recent security incident, a security analyst decided
to view all network connections on a particular server.
Which of the following would provide the desired information?
nslookup
arp
netstat
nmap
A security analyst is reviewing the following command-line output:
ICMP spoofing
URL redirection
MAC address cloning
DNS poisoning
A company is required to continue using legacy software to support a
critical service.
Which of the following BEST explains a risk of this practice?
Default system configuration
Unsecure protocols
Lack of vendor support
Weak encryption
A major political pay experienced a server breach. The hacker then
publicly posted stolen internal communications concerning campaign
strategies to give the opposition party an advantage.
Which of the following BEST describes these threat actors?
Semi-authorized hackers
State actors
Script kiddies
Advanced persistent threats
While reviewing the wireless router, a systems administrator of a small
business determines someone is spoofing the MAC address of an
authorized device. Given the table ABOVE
Which of the following should be the administrators NEXT step to detect if
there is a rogue system without impacting availability?
Conduct a ping sweep
Physically check each system.
Deny Internet access to the "UNKNOWN" hostname.
Apply MAC filtering
A forensics investigator is examining a number ot unauthorized payments
that were reported on the company's website. Some unusual log entries
show users received an email for an unwanted mailing attempt to
unsubscribe. One of the users reported the email to the phishing team,
and the forwarded email revealed the link to be:
<a href="https://www.company.com/payto.do?routing=00001111&acct=22223334&amount=250">Click here to unsubscribe</a>
Which of the following will the forensics investigator MOST likely determine has occurred?
SQL Injection
Broken authentication
XSS
XSRF
Which of the following is a risk that is specifically associated with hosting
applications in the public cloud?
Unsecured root accounts
Zero-day
Shared tenancy
Insider threat
While checking logs, a security engineer notices a number of end users
suddenly downloading files with the .tar.gz extension. Closer examination
of the files reveals they are PE32 files. The end users state they did not
initiate any of the downloads. Fuäher investigation reveals the end users
all clicked on an external email containing an infected MHT file with an
href link a week prion
Which of the following is MOST likely occurring?
A RATwas installed and is transferring additional exploit tools.
The workstations are beaconing to a command-and-control server.
A logic bomb was executed and is responsible for the data transfers.
Afireless virus is spreading in the local network environment.
A worldwide manufacturing company has been experiencing email
account compromises. In one incident, a user logged in from the
corporate office in France, but then seconds later, the same user account
attempted a login from Brazil.
Which of the following account policies would BEST prevent this type of
attack?
Network location
Impossible travel time
Geolocation
Geofencing
After segmenting the network, the network manager wants to control the
traffic between the segments.
Which of the following should the manager use to control the
network traffic?
A DMZ
A VPN
A VLAN
An ACL
Which of the following uses SAML for authentication?
HOTP
Federation
TOTP
Kerberos
While reviewing pcap data, a netv,ork security analyst is able to locate
plaintext usernames and passwords being sent from workstations to
network switches.
Which of the following is the security analyst MOST likely observing?
SNMP traps
A Telnet session
An SSH connection
SFTP traffic
The manager who is responsible for a data set has asked a security
engineer to apply encryption to the data on a hard disk. The security
engineer is an example of a:
data controller.
data owner
data custodian
data processor
A cybersecurity analyst reviews the log files trom a web server and sees a
series of files that indicate a directory-traversal attack has occurred.
Which of the following is the analyst MOST likely seeing?
Under GOPR, which of the following is MOST responsible for the
protection of privacy and website user rights?
The data protection officer
The data processor
The data owner
The data controller
A security administrator is analyzing the corporate wireless network. The
network only has two access points running on channels 1 and 11. While
using airodump-ng. the administrator notices other access points are
running with the same corporate ESSID on all available channels and with
the same 3SSlO of one of the legitirnate access points.
Which of the following attacks is happening on the corporate network?
Man in the middle
Evil twill
Jamming
Rogue access point
Disassociation
The IT depaäment's on-site developer has been WI•th the team for many
years. Each time an application is released, the security team is able to
identify multiple vulnerabilities.
Which of the following would BEST help the team ensure the application
is ready to be released to production?
Limit the use of third-pady libraries
Prevent data exposure queries.
Obfuscate the source code
Submit the application to
before releasing it
A user received an SMS on a mobile phone that asked for bank details.
Which of the following social-engineering techniques was used in this
case?
SPIM
Vishing
Spear phishing
Smishing
A company recently experienced a data breach and the source was
determined to be an executive who was charging a phone in a public
area.
Which of the following would MOST likely have prevented this breach?
A firewall
A device pin
A
data blocker
Biometrics
A company is adopting a BYOD policy and is looking for a comprehensive
solution to protect company information on user devices.
Which of the following solutions would BEST support the policy?
Mobile device management
Full-device encryption
Remote wipe
Biometrics
A security analyst is investigating multiple hosts that are communicating
to external IP addresses during the hours of 2.00 mm - 4:00 am. The
malware has evaded detection by traditional antivirus software.
Which of the following types of malware is MOST likely infecting the
hosts?
Ransomware
A worm
Plymorphic
A RAT
A security analyst is investigating multiple hosts that are communicating
to external IP addresses between the hours of 2.00 a.m. and 4:00 a.m.
The malware has evaded detection by traditional antivirus somware.
Which of the following types of malware is MOST likely infecting the
hosts?
RAT
Ransomeware
Logic Bomb
Worm
A security administrator suspects there may be unnecessary services
running on a server. Which of the following tools will the administrator
MOST likely use to confirm the suspicions?
Nmap
Wireshark
Autopsy
DNSEnum
An organization is concerned about hackers potentially entering a facility
and plugging in a remotely accessible Kali Linux box.
Which of the following should be the first lines of defense against
such an attack? (Choose two.)
MAC filtering
Network access control
Zero Trust segmentation
Access control vestibules
Guards
Ann, a customer, received a notification from her mortgage company
stating her PII may be shared with partners, affiliates, and associates to
maintain day-to-day business operations.
Which of the following documents did Ann receive?
An annual privacy n06ce
Anon-disclosure agreement
A privNeged•user agreement
memorandum of understandng
