Font size
WorksheetsSec+ Quiz - 3
Total questions: 15
Worksheet time: 16mins
An administrator is experiencing issues when trying to upload a support file to a vendor. A pop-up message reveals that a payment card number was found in the file, and the file upload was Mocked. Which of the following controls is most likely causing this issue and should be checked FIRST?
DLP
Firewall rule
Content filter
MDM
Application allow list
A security analyst needs to be able to search and correlate logs from multiple sources in a single tool. Which of the following would BEST allow a security analyst to have this ability?
SOAR
SIEM
Log collectors
Network-attached storage
Which of the following would BEST provide detective and corrective controls for thermal regulation?
A smoke detector
A fire alarm
An HVAC system
A fire suppression system
Guards
During a trial, a judge determined evidence gathered from a hard drive was not admissible. Which of the following BEST explains this reasoning?
The forensic investigator forgot to run a checksum on the disk image after creation.
The chain of custody form did not note time zone offsets between transportation regions.
The computer was turned off. and a RAM image could not be taken at the same time.
The hard drive was not properly kept in an antistatic bag when rt was moved.
A tax organization is working on a solution to validate the online submission of documents. The solution should be carried out on a portable USB device that should be inserted on any computer that is transmitting a transaction securely. Which of the following is the BEST certificate for these requirements?
User certificate
Self-signed certificate
Computer certificate
Root certificate
Which of the following will increase cryptographic security?
High data entropy
Algorithms that require less computing power
Longer key longevity
Hashing
An engineer recently deployed a group of 100 web servers in a cloud environment. Per the security policy, all web-server ports except 443 should be disabled. Which of the following can be used to accomplish this task?
Application allow list
SWG
Host-based firewall
VPN
A security engineer was assigned to implement a solution to prevent attackers from gaining access by pretending to be authorized users. Which of the following technologies meets the requirement?
SSO
IDS
MFA
TPM
A company needs to validate its updated incident response plan using a real-world scenario that will test decision points and relevant incident response actions without interrupting daily operations. Which of the following would BEST meet the company's requirements?
Red-team exercise
Capture-the-flag exercise
Tabletop exercise
Phishing exercise
Which of the following are common VoIP-associated vulnerabilities? (Select TWO).
SPIM
Vishing
Phishing
Credential harvesting
Tailgating
A company wants to improve end users experiences when they log in to a trusted partner website. The company does not want the users to be issued separate credentials for the partner website. Which of the following should be implemented to allow users to authenticate using their own credentials to log in to the trusted partner's website?
Directory service
AAA server
Federation
Multifactor authentication
A company is implementing BYOD and wants to ensure all users have access to the same cloud-based services. Which of the following would BEST allow the company to meet this requirement?
laaS
PaaS
MaaS
SaaS
Which of the following risk management strategies would an organization use to maintain a legacy system with known risks for operational purposes?
Acceptance
Transference
Avoidance
Mitigation
A report delivered to the Chief Information Security Officer (CISO) shows that some user credentials could be exfiltrated. The report also indicates that users tend to choose the same credentials on different systems and applications. Which of the following policies should the CISO use to prevent someone from using the exfiltrated credentials?
MFA
Lockout
Time-based logins
Password history
A help desk technician receives a phone call from someone claiming to be a part of the organization's cybersecurity modem response team. The caller asks the technician to verify the network's internal firewall IP address. Which of the following is the technician's BEST course of action?
Direct the caller to stop by the help desk in person and hang up declining any further requests from the caller
Ask for the callers name, verify the person's identity in the email directory and provide the requested information over the phone.
Write down the phone number of the caller if possible, the name of the person requesting the information, hang up. and notify the organization's cybersecurity officer
Request the caller send an email for identity verification and provide the requested information via email to the caller
