NEW
Font size
WorksheetsSecurity+ Study Guide-05 Securing Hosts and Data
Total questions: 15
Worksheet time: 11mins
Attackers recently exploited vulnerabilities in a web server hosted by your organization. Management has tasked administrator with checking the server and eliminating any weak configurations on it.
Which of the following will meet this goal?
Installing a NIDS
Disabling unnecessary services
Enabling root acounts
Implementing SSL encryption
The BizzFad organization develops and sells software. Occasionally they update the software to fix security vulnerabilities and/or add additional features. However, before resealing these updates to customers, they test them in different environments.
Which of the following solutions provides the BEST method to test the updates?
Baseline configuration
BYOD
Sandbox
Change management
Network administrators have identified what appears to be malicious traffic coming from an internal computer, but only when no one is logged on the computer. You suspect the system is infected with malware. It periodically runs an application that attempts to run hping3 via remote websites. After comparing the computer with a list of applications from the master image, they verify this application is likely the problem.
What allowed them to make this determination?
Version control
Sandbox
Blacklist
Integrity measurements
While investigating a recent data breach, investigators discovered a RAT on Bart's computer. Antivirus software didn't detect it. Logs show a user with local administrator privileges installed it.
Which of the following answer has the BEST change of preventing this from happening again in the future?
Enforce an application allow list
Enforce an application block list
Implement a BYOD policy
Implement a DLP policy
Salespeople within a company regularly take company-owned laptops with them on the road. The company wants to implement a solution to protect laptop drives against data theft.
DLP
HSM
MDM
SEDs
Managers within your organization want to implement a secure boot for some key computers. During the boot process, each computer should send data to a remote system to check the computer's configuration.
Which of the following will meet this goal?
Trusted Platform Module
Hardware root of trust
Remote attestation
Tokenization
Your organization recently updated its security policy to prohibit the use of external storage devices. The goal is to reduce threats from insiders.
Which of the following methods would have the BEST chance of reducing the risk of data exfiltration using external storage devices?
Train employees about the policy
Monitor firewall logs to detect data exfiltration
Block write capabilities to removable media
Implement a network-based DLP solution
Maggie, the new CTO at your organization, wants to reduce costs by utilizing more cloud services. She has directed the use of a cloud service instead of purchasing all the hardware and software needed for an upcoming project. She also wants to ensure that the cloud provider maintains all the required hardware and software.
Which of the following BEST describes the cloud computing service model that will meet these requirements?
IaaS
PaaS
SaaS
XaaS
You are asked to research prices for cloud-based services. The cloud service provider needs to supply servers, storage, and networks, but nothing else.
Which of the following will BEST meet your needs?
IaaS
PaaS
SaaS
XaaS
Your organization has been using more cloud resources and Lisa, the new CIO, is concerned about security. She want to add a service that is logically placed between the organization's network and the cloud provider. This service will monitor all network traffic and ensure that data sent to the cloud for storage is encrypted.
Which of the following will BEST meet these requirements?
CASB
Storage permissions
A storage encryption policy
Firewall
Management at your organization wants to add a cloud-based service to filter all traffic going to or from the Internet from internal clients. At a minimum, the solution should include URL filtering, DLP protection, and malware detection and filtering.
Which of the following will BEST meet these requirements?
Next-generation SWG
Container security
Cloud-based segmentation
API inspection and integration
Your organization is planning to implement a BYOD policy. However, management wants to implement a comprehensive solution to protect the organization's data when the BYOD policy is put into place.
Which of the following is the BEST choice to meet these needs?
FDE
SED
MDM
MAM
Your organization recently implemented a security policy requiring that all endpoint computing devices have a unique identifier to simplify asset inventories. Administrators implement this on servers, desktop PCs, and laptops with an RFID system. However, they haven't found a reliable method to tag corporate-owned smartphones and tablet devices.
Which of the following choices would be the BEST alternative?
VDI
MDM application
RFID tag
GPS tagging
Your organization is switching from a COPE model to BYOD model due to the cost of replacing lost or damaged mobile devices.
Which of the following is the BEST choice to protect the organization's data when using a BYOD model?
Full-disk encryption
Containerization
Remote wipe
Geolocation
Bart is showing Wendell a new app that he downloaded from a third party onto his iPhone. Wendell has the same model of smartphone, but when he searches for the app, he is unable to find it.
Of the following choices, what is the MOST likely explanation for this?
Jailbreaking
Tethering
Sidebreaking
Rooting
