wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Certified in Cybersecurity (CC): Full Coverage Mastery Exam 1

Total questions: 101

Worksheet time: 51mins

Name
Class
Date
1.

In a system, Alice, a programmer, attempts to access a code repository. In terms of access control, how would Alice and the code repository be classified?

a)

Alice is the object, the code repository is the subject

b)

Alice is the subject, the code repository is the object

c)

Both Alice and the code repository are subjects

d)

Both Alice and the code repository are objects

2.

As an IT manager at a financial institution, you are designing a system to ensure that any transaction made cannot be denied by the party making it. This security measure is known as:

a)

Confidentiality

b)

Non-repudiation

c)

Authorization

d)

Encryption

3.

In a financial company, a system requires both the manager and the accountant to simultaneously use their access codes to transfer funds exceeding $10,000. What security concept does this scenario illustrate?

a)

Defense in depth

b)

Principle of least privilege

c)

Two-person integrity

d)

Mandatory Access Control (MAC)

4.

You've just discovered that an unknown attacker has obtained unauthorized access to your company's client database. This situation is best defined as:

a)

Exploit

b)

Breach

c)

Intrusion

d)

Zero Day

5.

The IT team at XYZ Corp is working on identifying potential threats to their network. They are also assessing the impact of these threats and planning how to respond if any of these threats occur. What is the IT team engaged in?

a)

Risk Management

b)

Incident Response

c)

Asset Management

d)

Compliance Management

6.

In the context of user authentication, which factors typically fall under the categories of "something you are" and "something you have"?

a)

Username and password

b)

Fingerprint and mobile phone

c)

Security questions and PIN

d)

Smart card and email address

7.

A company implements multiple layers of security controls, including firewalls, intrusion detection systems, encryption, and regular security awareness training for employees. This approach is an example of:

a)

Defense in Depth

b)

Least Privilege

c)

Separation of Duties

d)

Single Sign-On

8.

An organization wants to ensure that a message sent over the internet cannot be read if intercepted. What technique should they use?

a)

Encryption

b)

Tokenization

c)

Authentication

d)

Authorization

9.

As a cybersecurity analyst, your supervisor instructs you to create a document outlining the step-by-step process for configuring firewall rules in the organization's network infrastructure. What type of document are you creating?

a)

Policy

b)

Procedure

c)

Standard

d)

Guideline

10.

In risk management, the term "impact" refers to:

a)

Confidentiality

b)

The severity or consequences of a risk event

c)

The potential vulnerabilities in a system or process

d)

The actions taken to transfer or mitigate risks

11.

Which of the following options is an example of a logical access control?

a)

Physical locks on doors

b)

Security cameras monitoring a facility

c)

Passwords

d)

Security guards patrolling an area

12.

A company employs mantraps/turnstiles at the entrance to their high-security data center. This physical access control measure is primarily aimed at:

a)

Preventing tailgating

b)

Detecting motion within the data center

c)

Restricting access based on time of day

d)

Alerting security personnel in case of an intrusion

13.

Your company is based in the US and wants to extend its services to the European market. Which regulation should your company comply with to protect the personal data of its European users?

a)

Health Insurance Portability and Accountability Act (HIPAA)

b)

General Data Protection Regulation (GDPR)

c)

National Institutes of Standards and Technology (NIST)

d)

Institute of Electrical and Electronics Engineers (IEEE)

14.

For a large healthcare organization seeking to streamline user access management based on specific job titles like doctor, nurse, and administrator, which access control model offers the most efficiency and minimal administrative overhead?

a)

Discretionary Access Control (DAC)

b)

Mandatory Access Control (MAC)

c)

Role-Based Access Control (RBAC)

d)

Attribute-Based Access Control (ABAC)

15.

If Alice and Bob are using symmetric cryptography for secure communication, and Alice wants to send an encrypted message to Bob, which key should she use?

a)

Bob's private key

b)

Alice's public key

c)

Bob's public key

d)

The shared symmetric key

16.

In which cloud service model does the IT department have the least responsibility for managing and maintaining the underlying infrastructure and software?

a)

Infrastructure as a Service (IaaS)

b)

Platform as a Service (PaaS)

c)

Software as a Service (SaaS)

d)

On-Premises Deployment

17.

As part of a risk mitigation strategy, an organization decides to share the financial impact of potential data breaches with a third-party. This strategy is an example of:

a)

Risk Acceptance

b)

Risk Avoidance

c)

Risk Transference

d)

Risk Mitigation

18.

In the context of cybersecurity, what is the primary purpose of data backups?

a)

To prevent unauthorized access to sensitive information

b)

To recover lost or corrupted data in the event of a disaster

c)

To ensure the availability of network resources

d)

To monitor and detect potential security breaches

19.

In the event of a major earthquake, what should be the immediate priority?

a)

Ensuring the safety of individuals

b)

Activating the disaster recovery plan for systems

c)

Assessing the physical damage to infrastructure

d)

Implementing additional security measures

20.

Which device is typically responsible for directing or guiding traffic between different networks in a typical home or small business network?

a)

Firewall

b)

Modem

c)

Switch

d)

Router

21.

John, an IT manager, receives an alert that the company's website has been defaced. Which principle of cybersecurity has been primarily violated?

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Non-repudiation

22.

Alice is tasked with configuring a network design that separates an organization's public-facing servers (like the web server and email server) from its internal network to enhance security. What should she implement?

a)

VLAN

b)

VPN

c)

IDS

d)

DMZ

23.

At ABC Company, the cybersecurity team identifies a group of hackers who are known for exploiting a specific weakness in network security. What does this group represent for ABC Company? •

a)

Threat Actors

b)

Threat Vector

c)

Risk

d)

Vulnerability

24.

What type of cyberattack involves an attacker encrypting a victim's data and then demanding payment in exchange for the decryption key?

a)

Phishing Attack

b)

SQL Injection Attack

c)

Ransomware Attack

d)

Denial-of-Service (DoS) Attack

25.

In securing Protected Health Information (PHI), which of the following is a key principle of information security?

a)

Confidentiality

b)

Compliance

c)

Availability

d)

Authentication

26.

As a cybersecurity analyst, you discover a known vulnerability in a web application that could allow an attacker to execute arbitrary code on the server. What term is used to describe the act of taking advantage of this vulnerability?

a)

Vulnerability

b)

Threat

c)

Exploitation

d)

Risk

27.

To improve the security of your organization's information system, you have been tasked to perform a vulnerability assessment. Which of the following will you primarily focus on? • • (Correct) •

a)

Identifying potential threat actors

b)

Identifying potential weaknesses in the system

c)

Assessing the potential impacts of threat

d)

Ensuring availability of data

28.

Which port is commonly used for secure web communication over HTTPS?

a)

Port 80

b)

Port 443

c)

Port 22

d)

Port 53

29.

What does the term "Governance" refer to in an organizational context?

a)

The process of how an organization is managed, including decision-making policies and roles

b)

The implementation of security controls to protect organizational assets

c)

The monitoring and assessment of security controls to ensure compliance

d)

The identification and management of risks within an organization

30.

Firewalls, intrusion detection systems, and antivirus software are examples of which type of cybersecurity control?

a)

Logical control

b)

Physical control

c)

Administrative control

d)

Operational control

31.

ABC Company has hired a cybersecurity consultant to assess the value of their proprietary software, customer databases, and brand reputation. What is the consultant evaluating?

a)

Threats

b)

Vulnerabilities

c)

Assets

d)

Risks

32.

A company installs a perimeter fence equipped with motion detectors and alarms to protect its manufacturing facility from unauthorized access. This access control method primarily falls under:

a)

Logical access control

b)

Physical access control

c)

Technical access control

d)

Administrative access control

33.

What does the term "Risk Tolerance" refer to in cybersecurity?

a)

The level of risk an entity is willing to assume in order to achieve a potential desired result

b)

The level of risk associated with a specific vulnerability or threat

c)

The process of assessing and mitigating risks in an organization

d)

The likelihood of a risk event occurring and its potential impact

34.

Your company's IT department has noticed an unusual amount of outgoing network traffic during non-business hours from several company computers. No significant harm has been done yet, but the traffic pattern is consistent with a potential malware infection. How would you classify this situation?

a)

Cybersecurity Alert

b)

Cybersecurity Vulnerability

c)

Cybersecurity Incident

d)

Cybersecurity Threat

35.

Which cloud service model is specifically designed to enable businesses and developers to host, build, and deploy consumer-facing apps?

a)

Infrastructure as a Service (IaaS)

b)

Platform as a Service (PaaS)

c)

Software as a Service (SaaS)

d)

Hybrid Cloud

36.

What is the purpose of subnet masks in IP addressing?

a)

Subnet masks define the maximum number of devices allowed on a network.

b)

Subnet masks determine the network portion and host portion of an IP address.

c)

Subnet masks provide encryption for secure communication over the internet.

d)

Subnet masks assign IP addresses to devices within a local network.

37.

In the Incident Response Plan, which phase involves learning from the incident to improve the existing plan?

a)

Preparation

b)

Detection and Analysis

c)

Containment

d)

Post-Incident Activity

38.

What is the primary purpose of a digital signature in cryptography?

a)

To ensure data confidentiality by encrypting messages

b)

To verify the integrity and authenticity of digital data

c)

To facilitate secure key exchange between two parties

d)

To compress and optimize the size of digital files

39.

Which of the following organizations is a private non-profit organization that develops and promotes voluntary Internet standards, in particular the standards that comprise the Internet protocol suite (TCP/IP)?

a)

National Institute of Standards and Technology (NIST)

b)

Internet Engineering Task Force (IETF)

c)

Institute of Electrical and Electronics Engineers (IEEE)

d)

International Organization for Standardization (ISO)

40.

You work for an online travel agency that collects customer information for bookings. Which of the following examples would be considered Personally Identifiable Information (PII)?

a)

Customer's travel destination

b)

Customer's passport number

c)

Customer's preferred airline

d)

Employee's department name

41.

During an incident response, what is the highest priority of first responders?

a)

To identify the attacker

b)

To preserve evidence

c)

To restore services as quickly as possible

d)

To update the security policies

42.

Your organization's primary data center is located in an area prone to earthquakes. In the context of disaster recovery and business continuity planning, which of the following best describes the nature of an earthquake?

a)

Vulnerability

b)

Threat

c)

Impact

d)

Zero Day

43.

As the new head of cybersecurity at your organization, you are tasked with preparing a Business Impact Analysis (BIA). What is the primary purpose of a BIA?

a)

To assess the potential effects of an interruption to critical business operations

b)

To ensure that all employees are trained in cybersecurity best practices

c)

To identify all potential cybersecurity threats to the organization

d)

To create a plan for responding to a cybersecurity incident

44.

What is the purpose of classifying data in terms of its sensitivity within an organization?

a)

To determine the level of encryption needed for each data type

b)

To identify what information can be made public

c)

To understand the potential impact if the data were to be compromised

d)

To ensure all employees have access to all data

45.

Sam, a system administrator, has been tasked with ensuring that all new hires have the minimum necessary access to perform their job duties. Which principle is Sam applying in this scenario?

a)

Defense in Depth

b)

Principle of Least Privilege

c)

Segregation of Duties

d)

Mandatory Access Control

46.

Which type of cyberattack primarily targets the availability aspect of the CIA triad in cybersecurity, often by overwhelming network resources and causing a disruption in services?

a)

Phishing Attack

b)

Man-in-the-Middle Attack

c)

AttackDenial-of-Service (DoS) Attack

d)

SQL Injection Attack

47.

When a cyber attacker successfully performs a phishing attack and gains unauthorized access to sensitive information, which principle of the CIA triad is primarily violated?

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Non-repudiation

48.

What is the primary purpose of a firewall in network security?

a)

To encrypt data transmitted between network devices.

b)

To filter incoming traffic based on rules and control access to the network.

c)

To identify and remove malicious software from network devices.

d)

To monitor and log network traffic for analysis and troubleshooting.

49.

John, an IT analyst at XYZ Corp, successfully logs into a company system using his unique credentials. Which cybersecurity process is described in this scenario?

a)

Authentication

b)

Authorization

c)

Encryption

d)

Firewall

50.

Which of the following best describes Discretionary Access Control (DAC)?

a)

An access control policy determined by the system administrator

b)

An access control policy where permissions are granted or denied based on user's discretion

c)

An access control policy where permissions are granted based on role of the user

d)

An access control policy that restricts access based on the sensitivity level of the information

51.

ABC Corp has identified a potential risk of unauthorized access to their network. They decide to implement two-factor authentication for all employees to address this risk. What risk strategy are they employing?

a)

Risk Acceptance

b)

Risk Avoidance

c)

Risk Transfer

d)

Risk Mitigation

52.

A company implements a review and approval process for financial transactions, where one employee enters the transaction, another approves it, and a third person verifies the accuracy. This practice primarily aligns with: • • • (Correct) •

a)

Defense in Depth

b)

Least Privilege

c)

Segregation of Duties

d)

Single Sign-On

53.

In the context of a Disaster Recovery (DR) plan, which component primarily focuses on defining the maximum tolerable data loss in the event of a system failure or disaster?

a)

Business Impact Analysis (BIA)

b)

Recovery Time Objective (RTO)

c)

Recovery Point Objective (RPO)

d)

Incident Response Plan (IRP)

54.

Which of the following is a common metric used in quantitative risk analysis?

a)

Color-coded risk level

b)

Descriptive risk ranking (high, medium, low)

c)

Expected Monetary Value (EMV)

d)

Subjective risk labels (critical, substantial, moderate)

55.

As a cybersecurity professional, you are educating your team about Disaster Recovery (DR). Which of the following best describes the primary goal of DR?

a)

To prepare for and prevent any potential cyber incidents

b)

To restore normal business operations as quickly as possible after a disaster

c)

To detect and analyze potential cybersecurity threats

d)

To provide a framework for overall organizational security

56.

You are a cybersecurity professional working for a financial institution. As part of your responsibilities, you are in charge of implementing controls to protect customer data and prevent unauthorized access. Your focus is on establishing guidelines and practices to ensure employees follow proper procedures and adhere to security policies. What type of control are you primarily implementing? • • • (Correct) •

a)

Technical control

b)

Physical control

c)

Administrative control

d)

Operational control

57.

Which type of access control measure is primarily designed to discourage potential attackers from attempting to breach a system, rather than preventing their actions outright?

a)

Compensating Access Control

b)

Corrective Access Control

c)

Detective Access Control

d)

Deterrent Access Control

58.

You are a cybersecurity analyst tasked with prioritizing risks. You decided to rank the risks based on their likelihood and potential impact but without assigning exact numerical values. Which type of risk analysis are you conducting?

a)

Qualitative risk analysis

b)

Quantitative risk analysis

c)

Financial risk analysis

d)

Strategic risk analysis

59.

An IT administrator is setting permissions for folders on the company server. In this scenario, which of the following is considered an 'Object'?

a)

The IT administrator

b)

The permissions being set

c)

The folders on the server

d)

The server management software

60.

A company uses an access control method where employees can set permissions for files they own, choosing who can read, write, or execute them. What type of access control is the company using?

a)

Mandatory Access Control (MAC)

b)

Role-Based Access Control (RBAC)

c)

Discretionary Access Control (DAC)

d)

Rule-Based Access Control (RBAC)

61.

In the context of privileged access management, what is the purpose of just-in-time privileged access management and just-in-time identity?

a)

Granting users permanent and unrestricted access to all resources and services

b)

Assigning specific roles to users based on their job responsibilities

c)

Providing users with temporary elevated privileges when needed

d)

Verifying users' identities through real-time authentication processes Explanation

62.

A company implements a new software system to manage customer data. The company performs a thorough risk assessment, identifies potential vulnerabilities, and implements various security controls. Despite these efforts, the risk assessment reveals that there is still a residual risk associated with the system. This residual risk represents:

a)

The risk level before any security controls are implemented

b)

The total risk exposure faced by the company

c)

The remaining risk after security controls have been implemented

d)

The unidentified or unknown risks within the system

63.

Which of the following statements accurately describes the role of hash functions in data integrity?

a)

Hash functions encrypt data to protect its confidentiality

b)

Hash functions compress data to reduce its size

c)

Hash functions generate unique fingerprints to verify data integrity

d)

Hash functions verify the availability and accessibility of data

64.

Which of the following is a suitable scenario for using degaussing as a data destruction method?

a)

Securely erasing data from a solid-state drive (SSD)

b)

Permanently deleting files from a cloud storage service

c)

Disposing of old magnetic tape backups

d)

Cleaning up unused data partitions on a hard drive

65.

A large software company is concerned about potential security risks within its own systems. The security team identified that several employees have more system permissions than their roles require, due to temporary assignments or promotions that have since ended. What is the term for this situation?

a)

Privilege escalation

b)

Access aggregation

c)

Privilege creep

d)

Permission inflation

66.

Your job is to make sure any changes to a system, like updates or patches, are checked and approved before they're made. What is this process called?

a)

Disaster Recovery

b)

System Hardening

c)

Change Control

d)

Patch Management

67.

Which of the following is an example of behavioral biometrics?

a)

Facial recognition

b)

Fingerprint scanning

c)

Keyboard dynamics

d)

Iris scanning

68.

Which of the following best describes the purpose of Data Loss Prevention (DLP) technology?

a)

To monitor and control inbound network traffic

b)

To prevent unauthorized access to the organization's network

c)

To detect and prevent data breaches or unauthorized data leakage

d)

To encrypt data in transit for secure communication

69.

An audit in a financial institution revealed that two employees were able to bypass the Two-Person Integrity control in a critical system to siphon funds. They were able to do this because each of them held one piece of the required access information. Which of the following terms best describes this scenario?

a)

Privilege Escalation

b)

Collusion

c)

Impersonation

d)

Access Control Bypass

70.

Tom, a cybersecurity analyst, is working for a company that has recently switched to remote work. Employees need a secure way to access the company's internal resources from their homes. What should Tom recommend?

a)

RDP (Remote Desktop Protocol)

b)

VLAN (Virtual Local Area Network)

c)

IDS (Intrusion Detection System)

d)

VPN (Virtual Private Network)

71.

Why is proper provisioning and deprovisioning important in user account management?

a)

To maintain administrative control over user accounts

b)

To ensure the availability of system resources

c)

To reduce the risk of unauthorized access

d)

To enforce compliance with security policies

72.

In an asymmetric encryption system, if Bob wants to send a confidential message to Alice, which key should he use to encrypt the message?

a)

Alice's private key

b)

Bob's private key

c)

Bob's public key

d)

Alice's public key

73.

What is the primary purpose of a password manager?

a)

To generate and store passwords in clear text

b)

To provide a convenient way to remember all passwords without encryption

c)

To securely store and manage complex and unique passwords

d)

To replace the need for passwords altogether Explanation

74.

Who is primarily responsible for publishing and signing cybersecurity policies within an organization?

a)

Human resources

b)

IT administrators

c)

Senior management

d)

Security professionals

75.

Which of the following ports is typically used for the Simple Mail Transfer Protocol (SMTP) that Lisa, a network administrator, needs to set up on a mail server?

a)

Port 22

b)

Port 25

c)

Port 23

d)

Port 21

76.

In your role as a system administrator, you have implemented a change to the network configuration of XYZ Corp. Unfortunately, this has led to unintended system instability. What process would you utilize to restore the system to its previous stable state?

a)

Baseline Identification

b)

Hardening

c)

Change Control

d)

Rollback

77.

What is a valid compressed version of the following IPv6 address: 2001:0db8:0000:0000:0000:ff00:0042:8329?

a)

2001:db8:0:0:0:ff00:42:8329

b)

2001:db8::ff00:42:8329

c)

2001::db8:ff00:42:8329

d)

2001:db8::ff00:42::8329

78.

When a cyber attacker pretends to be someone else to trick people into giving away private information, what is this kind of attack called?

a)

Spoofing

b)

Pretexting

c)

Pharming

d)

Vishing

79.

How many layers are there in the OSI model, which is a conceptual framework used to understand and describe network protocols and functions?

a)

5

b)

6

c)

7

d)

8

80.

Which type of fire suppression system is commonly used in data centers to minimize water damage to sensitive electronic equipment?

a)

Gas-based fire suppression system

b)

Water-based fire suppression system

c)

Foam-based fire suppression system

d)

Powder-based fire suppression system

81.

What measure can be taken to mitigate the risks associated with data remanence?

a)

Using strong encryption for all data

b)

Implementing a robust data backup policy

c)

Performing secure data deletion techniques

d)

Frequently updating software applications

82.

Robert, a system administrator, is concerned about software that could infect the company's systems and potentially destroy or steal data. He wants a solution that can scan, identify, and eliminate such harmful software. What type of solution should Robert consider?

a)

Firewall

b)

Intrusion Detection System (IDS)

c)

Virtual Private Network (VPN)

d)

Anti-malware

83.

Which layer of the OSI model is responsible for managing the formatting and encryption of data to ensure its proper interpretation by the receiving device?

a)

Network Layer

b)

Data Link Layer

c)

Presentation Layer

d)

Transport Layer

84.

Emily, a cybersecurity consultant, is asked to recommend a network design strategy that can effectively control internal traffic flows, both within a data center and between the data center and the internet. Which strategy should Emily suggest?

a)

Implementing an intrusion detection system

b)

Deploying an antivirus solution across all systems

c)

Utilizing microsegmentation

d)

Setting up a Virtual Private Network (VPN)

85.

Why is it important for an organization to maintain an accurate inventory of its data assets, including location, retention period requirement, and destruction requirements?

a)

To ensure efficient use of storage space

b)

To maintain data accuracy and reliability

c)

To ensure compliance with data privacy laws and regulations

d)

To reduce the costs associated with data management

86.

Which of the following best describes the purpose of out-of-band distribution in authentication processes?

a)

To increase the efficiency of authentication

b)

To provide a separate and secure channel for authentication

c)

To eliminate the need for multi-factor authentication

d)

To reduce the complexity of the authentication process

87.

Alice, a security analyst, is working on a system where an attacker might try to gather information indirectly by exploiting implementation characteristics of the system, such as timing information, power consumption, electromagnetic leaks, or even sound to extract data. What type of attack should Alice be concerned about?

a)

Buffer Overflow Attack

b)

Side Channel Attack

c)

Cross-Site Scripting Attack

d)

SQL Injection Attack

88.

What type of malware is Emily likely dealing with if she observes abnormal behavior on her network, including increased network traffic and automatic propagation without user interaction?

a)

Worm

b)

Trojan

c)

Ransomware

d)

Spyware

89.

Which category of encryption does the substitution cipher belong to?

a)

Symmetric encryption

b)

Asymmetric encryption

c)

Hashing

d)

Digital signature

90.

In a secure government facility, access to information is based on the classification level of the data and the clearance level of the user. This is an example of which type of access control?

a)

Discretionary Access Control (DAC)

b)

Mandatory Access Control (MAC)

c)

Role-Based Access Control (RBAC)

d)

Attribute-Based Access Control (ABAC)

91.

Sarah, a security analyst, is responsible for monitoring and analyzing security events and logs from various sources within her organization's network. She needs a centralized system that can collect, correlate, and analyze this data to identify security incidents and provide real-time alerts. Which type of solution should Sarah consider?

a)

Firewall

b)

Intrusion Detection System (IDS)

c)

SIEM (Security Information and Event Management)

d)

VPN (Virtual Private Network)

92.

Which command-line tool is used to display the path that a packet takes to get from the source host to the destination host, while also recording the time taken for each hop?

a)

netstat

b)

nslookup

c)

ping

d)

traceroute

93.

In the context of Business Continuity (BC) and Disaster Recovery (DR), what is the purpose of a Memorandum of Understanding (MOU) or Memorandum of Agreement (MOA)?

a)

To establish an agreement for data sharing between organizations

b)

To create a legally binding contract for financial transactions

c)

To ensure mutual assistance and resource sharing during an emergency situation

d)

To define software licensing terms between two organizations

94.

A company wants to logically segment its network without altering the physical topology. Which network design concept will best serve this purpose? • • • (Correct) •

a)

Network Access Control (NAC)

b)

Virtual Private Network (VPN)

c)

Virtual Local Area Network (VLAN)

d)

Demilitarized Zone (DMZ)

95.

Which of the following statements regarding MAC and IP addresses is true?

a)

Both MAC and IP addresses are easily changed

b)

MAC addresses are fixed, IP addresses can change

c)

IP stays same across networks, MAC changes

d)

Both MAC and IP addresses are hard-coded and fixed

96.

Which process occurs as data moves up the layers of the OSI model?

a)

Encapsulation

b)

De-encapsulation

c)

Segmentation

d)

Concatenation

97.

Which step of the three-way handshake in TCP involves the server acknowledging the client's connection request?

a)

SYN packet

b)

SYN-ACK packet

c)

ACK packet

d)

Data packet

98.

As the new cybersecurity officer at XYZ Corp, you've been tasked with enhancing the organization's security posture. You propose establishing a security baseline. Which of the following BEST describes the primary benefit of this approach?

a)

It ensures that all system patches and updates are applied in real time

b)

It serves as a minimum level of security against which all system changes are evaluated

c)

It guarantees that all network traffic is encrypted to maintain data confidentiality

d)

It optimizes system performance by automatically allocating network resources

99.

What is the primary purpose of a records retention policy in an organization?

a)

To ensure data is stored forever

b)

To determine how long data needs to be maintained before it can be securely disposed of

c)

To minimize the size of data backups

d)

To limit the number of records an organization collects

100.

How many layers are there in the OSI model, which is a conceptual framework used to understand and describe network protocols and functions?

a)

5

b)

6

c)

7

d)

8

101.

Which of the following controls is specifically designed to identify and alert on known patterns or signatures of malicious activities in a network?

a)

Firewalls

b)

Intrusion Detection System (IDS)

c)

Virtual Private Network (VPN)

d)

Access Control Lists (ACLs)