Font size
WorksheetsSEC+ set 1
Total questions: 26
Worksheet time: 27mins
A security engineer is installing a WAF to protect the company's website from malicious web requests over SSL. Which of the following is needed to meet the objective?
A reverse proxy
A decryption certificate
A spill-tunnel VPN
Load-balanced servers
A security analyst is running a vulnerability scan to check for missing patches during a suspected security rodent During
which of the following phases of the response process is this activity MOST likely occurring?
Containment
Preparation
Recovery
Identification
A security engineer needs to create a network segment that can be used for servers that require connections from
untrusted networks. Which of the following should the engineer implement?
An air gap
A screened subnet
A VLAN
A hot site
A systems engineer is building a new system for production. Which of the following is the FINAL step to be performed prior to promotion to production?
Disable unneeded services.
Install the latest security patches.
Run a vulnerability scan.
Encrypt all disks.
A major clothing company recently lost a large amount of proprietary information. The security officer must find a solution to ensure this never happens again. Which of the following is the BEST technical implementation to prevent this from happening again?
Configure DLP solutions
Disable peer-to-peer sharing
Enable role-based
Mandate job rotation
Implement content filters
Which of the following would be BEST for a technician to review to determine the total risk an organization can bear
when assessing a "cloud-first" adoption strategy?
Risk matrix
Risk tolerance
Risk register
Risk appetite
Ann, a customer, received a notification from her mortgage company stating her PII may be shared with partners,
affiliates, and associates to maintain day-to-day business operations.
Which of the following documents did Ann receive?
An annual privacy notice
A non-disclosure agreement
A privileged-user agreement
A memorandum of understanding
The help desk has received calls from users in multiple locations who are unable to access core network services. The
network team has identified and turned off the network switches using remote commands. Which of the following
actions should the network team take NEXT?
Disconnect all external network connections from the firewall
Send response teams to the network switch locations to perform updates
Turn on all the network switches by using the centralized management software
Initiate the organization's incident response plan.
A company would like to set up a secure way to transfer data between users via their mobile phones. The company's top
priority is utilizing technology that requires users to be in as close proximity as possible to each other. Which of the
following connection methods would BEST fulfill this need?
Cellular
NFC
Wi-Fi
Bluetooth
A security analyst has been tasked with creating a new WiFi network for the company. The requirements received by
the analyst are as follows:
•Must be able to differentiate between users connected to WiFi
•The encryption keys need to change routinely without interrupting the users or forcing reauthentication
•Must be able to integrate with RADIUS
•Must not have any open SSIDs
Which of the following options BEST accommodates these requirements?
WPA2-Enterprise
WPS
802.11n
WPA3-PSK
Which of the following describes a maintenance metric that measures the average time required to troubleshoot and
restore failed equipment?
RTO
MTTR
MTBF
RPO
A company recently experienced an attack during which its main website was directed to the attacker's web server,
allowing the attacker to harvest credentials from unsuspecting customers. Which of the following should the company
implement to prevent this type of attack from occurring in the future?
IPsec
SSL/TLS
DNSSEC
S/MIME
Which of the following are the MOST likely vectors for the unauthorized inclusion of vulnerable code in a software
company’s final software releases? (Select TWO.)
Unsecure protocols
Included third-party libraries
Outdated anti-malware software
Weak passwords
E. Vendors/supply chain
A backdoor was detected in the containerized application environment. The investigation detected that a zero-day
vulnerability was introduced when the latest container image version was downloaded from a public registry. Which of
the following is the BEST solution to prevent this type of incident from occurring again?
Enforce the use of a controlled trusted source of container images
Deploy an IPS solution capable of detecting signatures of attacks targeting containers
Define a vulnerability scan to assess container images before being introduced on the environment
Create a dedicated VPC for the containerized environment
A company wants to modify its current backup strategy to minimize the number of backups that would need to be
restored in case of data loss. Which of the following would be the BEST backup strategy
Incremental backups followed by differential backups
Full backup followed by incremental backups
Delta backups followed by differential backups
Incremental backups followed by delta backups
Full backup followed by differential backups
Which of the following roles would MOST likely have direct access to the senior management team?
Data custodian
Data owner
Data protection officer
Data controller
Which of the following incident response steps occurs before containment?
Eradication
Recovery
Lessons learned
Identification
A dynamic application vulnerability scan identified code injection could be performed using a web form.
Which of the following will be BEST remediation to prevent this vulnerability?
Implement input validations
Deploy MFA
Utilize a WAF
Configure HIPS
A network engineer and a security engineer are discussing ways to monitor network operations. Which of the following
is the BEST method?
Disable Telnet and force SSH.
Establish a continuous ping.
Utilize an agentless monitor
Enable SNMPv3 With passwords.
Which of the following involves the inclusion of code in the main codebase as soon as it is written?
Continuous monitoring
Continuous deployment
Continuous validation
Continuous integration
During a forensic investigation, a security analyst discovered that the following command was run on a compromised
host:
crackmapexec smb 192.168.10.232 -u localadmin -H 0A3CE8D07A46E5C51070F03593E0A5E6
Which of the following attacks occurred?
Buffer overflow
Pass the hash
SQL injection
Replay attack
An attacker replaces a digitally signed document with another version that goes unnoticed. Upon reviewing the
document’s contents, the author notices some additional verbiage that was not originally in the document but can’t
validate an integrity issue. Which of the following attacks was used?
Cryptomalware
Hash substitution
Collision
Phishing
A security analyst notices several attacks are being blocked by the NIPS but does not see anything on the boundary
firewall logs. The attack seems to have been thwarted. Which of the following resiliency techniques was applied to the
network to prevent this attack?
NIC Teaming
Port mirroring
Defense in depth
High availability
Geographic dispersal
During an incident, a company’s CSIRT determines it is necessary to observe the continued network-based transactions
between a callback domain and the malware running on an enterprise PC. Which of the following techniques would be
BEST to enable this activity while reducing the risk of lateral spread and the risk that the adversary would notice any
changes?
Physically move the PC to a separate internet point of presence
Create and apply micro segmentation rules.
Emulate the malware in a heavily monitored DMZ segment.
Apply network blacklisting rules for the adversary domain
If a current private key is compromised, which of the following would ensure it cannot be used to decrypt any
historical data?
Perfect forward secrecy
Elliptic-curve cryptography
Key stretching
Homomorphic encryption
A security analyst is responding to an alert from the SIEM. The alert states that malware was discovered on a host and
was not automatically deleted. Which of the following would be BEST for the analyst to perform?
Add a deny-all rule to that host in the network ACL
Implement a network-wide scan for other instances of the malware.
Quarantine the host from other parts of the network
Revoke the client's network access certificates
