WorksheetsSiberAbluka 601-630
Total questions: 26
Worksheet time: 52mins
NO.601 Which of tre following would BEST identity and remediate a catatoss
event in an enterprise using third-pany, web-based services and file-sharing platanmns?
(A). SIEM
(B). CASE
(C). UTM
(D). EDR
NO.602 An engineer is setting up a VDI environment for a factory tocation, and the business wants to deploy a low-cost solution to enadle users on the shop floor to log in to the VDI environment directly. Which of the following should the engineer select to meet these requirements?
(A). Laptops
(B). Containers
(C). Thin clients
(D). Workstations
NO.603 A security analyst is reviewing the following command-line output:
Which of the following Is the analyst observing?
(A). IGMP spoofing
(B). URL redirection
(C). MAG address cloning
(D). DNS poisoning
NO.604 Which of the following should a data owner require all personnel to sign to legally protect intellectual property?
(A). An NDA
(B). An AUP
(C). An ISA
(D). An MOU
NO.605 A security administrator needs to inspect in-transit files on the enterprise network to search for Pll, credit card data, and classification words. Which of the following would be the BEST to use?
(A). IDS solution
(B). EDR solution
(C). HIPS software solution
(D). Network DLP solution
NO.606 A security analyst must determine if either SSH or Telnet is being used to log in to servers. Which of the following should the analyst use?
(A). logger
(B). Metasploit
(C). tcpdump
(D). netstat
NO.607 A routine audit of medical billing claims revealed that several claims were submitted
without the subscriber's knowledge. A review of the audit logs for the medical billing company's
system indicated a company employee downloaded customer records and adjusted the direct
deposit information to a personal bank account. Which of the following does this action describe?
(A). Insider threat
(B). Social engineering
(C). Third-party risk
(D). Data breach
NO.608 A security administrator is trying to determine whether a server is vulnerable to a range of attacks. After using a tool, the administrator obtains the following output: Which of the following attacks was successfully implemented based on the output?
(A). Memory leak
(B). Race conditions
(C). SQL injection
(D). Directory traversal
NO.611 A Chief Security Officer (CSO) is concerned about the volume and integrity of sensitive
information that is exchanged between the organization and a third party through email. The CSO is particularly concerned about an unauthorized party who is intercepting information that is in transit between the two organizations. Which of the following would address the CSO's concerns?
(A). SPF
(B). DMARC
(C). SSL
(D). DKIM
(E). TLS
NO.612 Which of the following BEST describes the MFA attribute that requires a callback on a predefined landline?
(A). Something you exhibit
(B). Something you can do
(C). Someone you know
(D). Somewhere you are
NO.613 A multinational organization that offers web-based services has datacenters that are located
only in the United States; however, a large number of its customers are in Australia, Europe, and Chin
a. Payments for services are managed bya third party in the United Kingdom that specializes in
payment gateways. The management team is concerned the organization is not compliant with
privacy laws that cover some of its customers. Which of the following frameworks should the
management team follow?
(A). Payment Card Industry Data Security Standard
(B). Cloud Security Alliance Best Practices
(C). ISO/IEC 27032 Cybersecurity Guidelines
(D). General Data Protection Regulation
NO.614 The concept of connecting a user account across the systems of multiple enterprises is BEST known as:
(A). federation.
(B). a remote access policy.
(C). multifactor authentication.
(D). single sign-on.
NO.615 A Chief Executive Officer (CEO) is dissatisfied with the level of service from the company's new service provider. The service provider is preventing the CEO from sending email from a work account to a personal account. Which of the following types of service providers is being used?
(A).
Telecommunications service provider
(B).
Cloud service provider
(C).
Master managed service provider
(D).
Managed security service provider
NO.616 nteping a secure area requires passing though two doors, both of which require someone who is already inside to initiate access. Which of the following types of physical security controls does this describe?
(A). Cameras
B: Faraday cage
(C). Access control vestibule
(D). Sensors
NO.618 An attacker was eavesdropping on a user who was shopping online. The attacker was able to spoof the IP address associated with the shopping site. Later, the user received an email regarding the credit card statement with unusual purchases. Which of the following attacks took place?
(A). On-path attack
(B). Protocol poisoning
(C). Domain hijacking
(D). Bluejacking
NO.620 A security administrator has noticed unusual activity occurring between different global instances and workloads and needs to identify the source of the unusual traffic. Which of the following log sources would be BEST to show the source of the unusual traffic?
(A). HIDS
(B).UEBA
(C). CASB
(D). VPC
NO.621 A manufacturing company has several one-off legacy information systems that cannot be migrated to a newer OS due to software compatibility issues. The OSs are still supported by the vendor, but the industrial software is no longer supported. The Chief Information Security Officer (CISO) has created a resiliency plan for these systems that will allow OS patches to be installed in a non-production environment, while also creating backups of the systems for recovery. Which of the following resiliency techniques will provide these capabilities?
(A). Redundancy
(B). RAID 1+5
(C). Virtual machines
(D). Full backups
NO.622 Whictpof the following will MOST likely cause machine-learning and Al enabled systems to operate with unintended consequences?
(A). Stored procedures
(B). Buffer overflows
(C). Data bias
(D). Code reuse
NO.623 A security operations analyst is using the company's SIEM solution to correlate alerts. Which of the following stages of the incident response process is this an example of?
(A). Eradication
(B). Recovery
(C). Identification
(D). Preparation
NO.624 Which of the following terms should be included in a contract to help a company monitor the ongoing security maturity of a new vendor?
(A). A right-to-audit clause allowing for annual security audits
(B). Requirements for event logs to be kept for a minimum of 30 days
(C). Integration of threat intelligence in the company's AV
(D). A data-breach clause requiring disclosure of significant data loss
NO.625 An incident, which is affecting dozens of systems, involves malware that reaches out to an Internet service for rules and updates. The IP addresses for the Internet host appear to be different in each case. The organization would like to determine a common IoC to support response and recovery actions. Which of the following sources of information would BEST support this solution?
(A). Web log files
(B). Browser cache
(C). DNS query logs
(D). Antivirus
NO.626 Which of the following represents a biometric FRR?
(A). Authorized users being denied access
(B). Users failing to enter the correct PIN
(C). The denied and authorized numbers being equal
(D). The number of unauthorized users being granted access
NO.627 Aweb server administrator has redundant servers and needs to ensure failover to the secondary server when the primary server goes down. Which of the following should the administrator implement to avoid disruption?
(A). NIC teaming
(B). High availability
(C). Dual power supply
(D). laaS
NO.628 An organization regularly scans its infrastructure for missing security patches but is concerned about hackers gaining access to the scanner's account. Which of the following would be BEST to minimize this risk?
(A). Require a complex, eight-character password that is updated every 90 days.
(B). Perform only non-intrusive scans of workstations.
(C). Use non-credentialed scans against high-risk servers.
(D). Log and alert on unusual scanner account logon times.
NO.629 Which of the following is assured when a user signs an email using a private key?
(A). Non-repudiation
(B). Confidentiality
(C). Availably
(D). Authentication
NO.630 The process of passively gathering information prior to launching a cyberattack is called:
(A). Tailgating
(B). Reconnaissance
(C). Pharming
(D). Prepending
