Font size
WorksheetsChapter 5 (PART I) Securing Hosts and Data
Total questions: 47
Worksheet time: 47mins
Question #3: A technician needs to prevent data loss in a laboratory. The laboratory is not connected to any external networks.
Which of the following methods would BEST prevent the exfiltration of data? (Select TWO)
A. VPN
B. Drive encryption
C. Network firewall
D. File level encryption
E. USB blocker
F. MFA
Question #4: The Chief Executive Officer (CEO) of an organization would like staff members to have the flexibility to work from home anytime during business hours, incident during a pandemic or crisis. However, the CEO is concerned that some staff members may take advantage of the flexibility and work from high-risk countries while on holidays work to a third-party organization in another country. The Chief information Officer (CIO) believes the company can implement some basic to mitigate the majority of the risk.
Which of the following would be BEST to mitigate the CEO's concern? (Select TWO)
A. Geolocation
B. Time-of-day restrictions
D. Certificates
E. Tokens
F. Geotagging
G. Role-based access controls
Question #6: A security engineer needs to implement an MDM solution that complies with the corporate mobile device policy. The policy states that in order for mobile users to access corporate resources on their devices the following requirements must be met:
Mobile device OSs must be patched up to the latest release A screen lock must be enabled (passcode or biometric) Corporate data must be removed if the device is reported lost or stolen
Which of the following controls should the security engineer configure? (Select TWO)
A. Containerization
B. Storage segmentation
C. Posturing
D. Remote wipe
E. Full-device encryption
G. Geofencing
Question #7: A startup company is using multiple SaaS and IaaS platforms to stand up a corporate infrastructure and build out a customer - facing web application. Which of the following solutions would be BEST to provide security, manageability, and visibility into the platforms?
SIEM
DLP
CASB
SWG
Question #8: An enterprise needs to keep cryptographic keys in a safe manner.
Which of the following network appliances can achieve this goal?
HSM
CASB
TPM
DLP
Question #9: A company recently transitioned to a strictly BYOD culture due to the cost of replacing lost or damaged corporate-owned mobile devices. Which of the following technologies would be BEST to balance the BYOD culture while also protecting the company’s data?
Containerization
Geofencing
Full-disk encryption
Remote wipe
Question #10: Which of the following distributes data among nodes, making it more difficult to manipulate the data while also minimizing downtime?
MSSP
Public cloud
Hybrid cloud
Fog computing
Question #11: A security audit has revealed that a process control terminal is vulnerable to malicious users installing and executing software on the system. The terminal is beyond end-of-life support and cannot be upgraded, so it is placed on a projected network segment. Which of the following would be MOST effective to implement to further mitigate the reported vulnerability?
DNS sinkholding
DLP rules on the terminal
An IP blacklist
Application whitelisting
Question #12: A nationwide company is experiencing unauthorized logins at all hours of the day. The logins appear to originate from countries in which the company has no employees. Which of the following controls should the company consider using as part of its IAM strategy? (Select TWO)
A. A complex password policy
B. Geolocation
C. An impossible travel policy
D. Self-service password reset
E. Geofencing
F. Time-based logins
Question #13: A company is adopting a BYOD policy and is looking for a comprehensive solution to protect company information on user devices. Which of the following solutions would BEST support the policy?
Mobile device management
Full-device encryption
Remote wipe
Biometrics
Question #14: A company provides mobile devices to its users to permit access to email and enterprise applications. The company recently started allowing users to select from several different vendors and device models. When configuring the MDM, which of the following is a key security implication of this heterogeneous device approach?
The most common set of MDM configurations will become the effective set of enterprise mobile security controls.
All devices will need to support SCEP-based enrollment; therefore, the heterogeneity of the chosen architecture may unnecessarily expose private keys to adversaries.
Certain devices are inherently less secure than others, so compensatory controls will be needed to address the delta between device vendors.
MDMs typically will not support heterogeneous deployment environments, so multiple MDMs will need to be installed and configured.
Question #15: A major clothing company recently lost a large amount of proprietary information. The security officer must find a solution to ensure this never happens again. Which of the following is the BEST technical implementation to prevent this from happening again?
Configure DLP solutions
Disable peer-to-peer sharing.
Enable role-based access controls
Mandate job rotation.
Implement content filters
Question #16: A company is implementing MFA for all applications that store sensitive data. The IT manager wants MFA to be non-disruptive and user friendly. Which of the following technologies should the IT manager use when implementing MFA?
One-time passwords
Email tokens
Push notifications
Hardware authentication
Question #17: Which of the following would BEST identify and remediate a data-loss event in an enterprise using third-party, web-based services and filesharing platforms?
SIEM
CASB
UTM
DLP
Question #18: To secure an application after a large data breach, an e-commerce site will be resetting all users’ credentials. Which of the following will BEST ensure the site’s users are not compromised after the reset?
A password reuse policy
Account lockout after three failed attempts
Encrypted credentials in transit
A geofencing policy based on login history
Question #19: An organization recently recovered from a data breach. During the root cause analysis, the organization determined the source of the breach to be a personal cell phone that had been reported lost. Which of the following solutions should the organization implement to reduce the likelihood of future data breaches?
MDM
MAM
VDI
DLP
Question #20: The lessons-learned analysis from a recent incident reveals that an administrative office worker received a call from someone claiming to be from technical support. The caller convinced the office worker to visit a website, and then download and install a program masquerading as an antivirus package. The program was actually a backdoor that an attacker could later use to remote control the worker's PC. Which of the following would be BEST to help prevent this type of attack in the future?
Data loss prevention
Segmentation
Application whitelisting
Quarantine
Question #21: An organization has decided to host its web application and database in the cloud. Which of the following BEST describes the security concerns for this decision?
Access to the organization's servers could be exposed to other cloudprovider clients
The cloud vendor is a new attack vector within the supply chain
Outsourcing the code development adds risk to the cloud provider
Vendor support will cease when the hosting platforms reach EOL.
Question #22: A company has drafted an insider- threat policy that prohibits the use of external storage devices. Which of the following would BEST protect the company from data exfiltration via removable media?
Monitoring large data transfer transactions in the firewall logs
Developing mandatory training to educate employees about the removable media policy
Implementing a group policy to block user access to system files
Blocking removable-media devices and write capabilities using a hostbased security tool
Question #23: Which of the following is a risk that is specifically associated with hosting applications in the public cloud?
Unsecured root accounts
Zero day
Shared tenancy
Insider threat
Question #24: Which of the following cloud models provides clients with servers, storage, and networks but nothing else?
SaaS
PaaS
IaaS
DaaS
Question #26: A company has decided to move its operations to the cloud. It wants to utilize technology that will prevent users from downloading company applications for personal use, restrict data that is uploaded, and have visibility into which applications are being used across the company. Which of the following solutions will BEST meet these requirements?
An NGFW
A CASB
Application whitelisting
An NG-SWG
Question #27: A Chief Executive Officer (CEO) is dissatisfied with the level of service from the company's new service provider. The service provider is preventing the CEO from sending email from a work account to a personal account. Which of the following types of service providers is being used?
Telecommunications service provider
Cloud service provider
Master managed service provider
Managed security service provider
Question #28: After installing a Windows server, a cybersecurity administrator needs to harden it, following security best practices. Which of the following will achieve the administrator's goal?
(Select TWO)
Disabling guest accounts
Disabling service accounts
Enabling network sharing
Disabling NetBIOS over TCP/IP
Storing LAN manager hash values
Enabling NTLM
Question #29: A security analyst needs to implement security features across smartphones, laptops, and tablets. Which of the following would be the MOST effective across heterogeneous platforms?
Enforcing encryption
Deploying GPOs
Removing administrative permissions
Applying MDM software
Question #30: A company just implemented a new telework policy that allows employees to use personal devices for official email and file sharing while working from home. Some of the requirements are:
Employees must provide an alternate work location (i.e., a home address)
Employees must install software on the device that will prevent the loss of proprietary data but will not restrict any other software from being installed.
Which of the following BEST describes the MDM options the company is using?
Geofencing, content management, remote wipe, containerization, and storage segmentation
Content management, remote wipe, geolocation, context-aware authentication, and containerization
Application management, remote wipe, geofencing, context-aware authentication, and containerization
Remote wipe, geolocation, screen locks, storage segmentation, and full-device encryption
Question #31: Which of the following describes the ability of code to target a hypervisor from inside?
Fog computing
VM escape
Software-defined networking
Image forgery
Container breakout
Question #32: A Chief Security Officer (CSO) was notified that a customer was able to access confidential internal company files on a commonly used file-sharing service. The file-sharing service is the same one used by company staff as one of its approved third-party applications. After further investigation, the security team determines the sharing of confidential files was accidental and not malicious. However, the CSO wants to implement changes to minimize this type of incident from reoccurring but does not want to impact existing business processes. Which of the following would BEST meet the CSO's objectives?
DLP
SWG
CASB
Virtual network segmentation
Container security
Question #33: A user wanted to catch up on some work over the weekend but had issues logging in to the corporate network using a VPN. On Monday, the user opened a ticket for this issue but was able to log in successfully. Which of the following BEST describes the policy that is being implemented?
Time-based logins
Geofencing
Network location
Password history
Question #34: An engineer is setting up a VDI environment for a factory location, and the business wants to deploy a low- cost solution to enable users on the shop floor to log in to the VDI environment directly. Which of the following should the engineer select to meet these requirements?
Laptops
Containers
Thin clients
Workstations
Question #35: An organization has a growing workforce that is mostly driven by additions to the sales department. Each newly hired salesperson relies on a mobile device to conduct business. The Chief Information Officer (CIO) is wondering if the organization may need to scale down just as quickly as it scaled up. The ClO is also concerned about the organization's security and customer privacy. Which of the following would be BEST to address the ClO’s concerns?
Disallow new hires from using mobile devices for six months
Select four devices for the sales department to use in a CYOD model
Implement BYOD for the sales department while leveraging the MDM
Deploy mobile devices using the COPE methodology
Question #36: A cybersecurity administrator has a reduced team and needs to operate an on-premises network and security infrastructure efficiently. To help with the situation, the administrator decides to hire a service provider. Which of the following should the administrator use?
SDP
AAA
IaaS
MSSP
Microservices
Question #37: A Chief Security Officer (CSO) is concerned about the amount of PII that is stored locally on each salesperson’s laptop. The sales department has a higher-than-average rate of lost equipment. Which of the following recommendations would BEST address the CSO’s concern?
Deploy an MDM solution
Implement managed FDE
Replace all hard drives with SEDs
Install DLP agents on each laptop
Question #38: An organization has implemented a policy requiring the use of conductive metal lockboxes for personal electronic devices outside of a secure research lab. Which of the following did the organization determine to be the GREATEST risk to intellectual property when creating this policy?
The theft of portable electronic devices
Geotagging in the metadata of images
Bluesnarfing of mobile devices
Data exfiltration over a mobile hotspot
Question #43: A company recently experienced a data breach and the source was determined to be an executive who was charging a phone in a public area. Which of the following would MOST likely have prevented this breach?
A firewall
A device pin
A USB data blocker
Biometrics
Question #44: A startup company is using multiple SaaS and IaaS platforms to stand up a corporate infrastructure and build out a customer - facing web application. Which of the following solutions would be BEST to provide security, manageability, and visibility into the platforms?
SIEM
DLP
CASB
SWG
Question #45: Which of the following technical controls is BEST suited for the detection and prevention of buffer overflows on hosts?
DLP
HIDS
EDR
NIPS
Question #46: During a security assessment, a security finds a file with overly permissive permissions. Which of the following tools will allow the analyst to reduce the permission for the existing users and groups and remove the set-user-ID from the file?
1a
chflags
chmod
leof
setuid
Question #47: A network administrator is concerned about users being exposed to malicious content when accessing company cloud applications. The administrator wants to be able to block access to sites based on the AUP. The users must also be protected because many of them work from home or at remote locations, providing on-site customer support. Which of the following should the administrator employ to meet these criteria?
Implement NAC
Implement an SWG
Implement a URL filter
Implement an MDM
Question #48: A RAT that was used to compromise an organization’s banking credentials was found on a user’s computer. The RAT evaded antivirus detection. It was installed by a user who has local administrator rights to the system as part of a remote management tool set. Which of the following recommendations would BEST prevent this from reoccurring?
Create a new acceptable use policy.
Segment the network into trusted and untrusted zones.
Enforce application whitelisting.
Implement DLP at the network boundary.
Question #49: A security administrator needs to inspect in-transit files on the enterprise network to search for PII, credit card data, and classification words. Which of the following would be the BEST to use?
IDS solution
EDR solution
HIPS software solution
Network DLP solution
Question #50: To reduce costs and overhead, an organization wants to move from an on -premises email solution to a cloud-based email solution. At this time, no other services will be moving. Which of the following cloud models would BEST meet the needs of the organization?
MaaS
laaS
SaaS
PaaS
Question #51: A pharmaceutical sales representative logs on to a laptop and connects to the public WiFi to check emails and update reports. Which of the following would be BEST to prevent other devices on the network from directly accessing the laptop? (Choose two)
A. Trusted Platform Module
B. A host-based firewall
C. A DLP solution
D. Full disk encryption
E. A VPN
F. Antivirus software
Question #52: An organization with a low tolerance for user inconvenience wants to protect laptop hard drives against loss or data theft. Which of the following would be the MOST acceptable?
SED
HSM
DLP
TPM
Question #53: A desktop support technician recently installed a new document-scanning software program on a computer. However, when the end user tried to launch the program, it did not respond. Which of the following is MOST likely the cause?
A new firewall rule is needed to access the application.
The system was quarantined for missing software updates
The software was not added to the application whitelist.
The system was isolated from the network due to infected software.
Question #54: A security analyst has received an alert about PII being sent via email. The analyst’s Chief information Security Officer (CISO) has made it clear that PII must be handled with extreme care from which of the following did the alert MOST likely originate?
S/MIME
DLP
IMAP
HIDS
Question #55: Users have been issued smart cards that provide physical access to a building. The cards also contain tokens that can be used to access information systems. Users can login to any thin client located throughout the building and see the same desktop each time. Which of the following technologies are being utilized to provide these capabilities? (Select TWO)
A. COPE
B. VDI
C. GPS
D. TOTP
E. RFID
F. BYOD
