Worksheetszubeyirr
Total questions: 30
Worksheet time: 15mins
A security administrator needs to create a RAID configuration that is focused on high read/write speeds and fault tolerance. It is unlikely that multiple drives will fail simultaneously. Which of the following RAID configurations should the administrator use?
RAID 0
RAID 1
RAID 5
RAID 10
A certificate vendor notified a company that recently invalidated certificates may need to be updated. Which of the following mechanisms should a security administrator use to determine whether the certificates installed on the company's machines need to be updated?
CRL
CSR
OCSP
SCEP
A company wants to build a new website to sell products online. The website will host a storefront application that will allow visitors to add products to a shopping cart and pay for the products using a credit card. Which of the following protocols would be the MOST secure to implement?
SSL
SFTP
SNMP
TLS
In a rush to meet an end-of-year business goal, the IT department was told to implement a new business application. The security engineer reviews the attributes of the application and decides the time needed to perform due diligence is insufficient from a cybersecurity perspective. Which of the following BEST describes the security engineer's response?
Risk appetite
Risk importance
Risk acceptance
Risk tolerance
While assessing the security of a web application, a security analyst was able to introduce unsecure strings through the application input fields by bypassing client-side controls. Which of the following solutions should the analyst recommend?
Server-side validation
Secure cookies
Host-based intrusion detection system
Code signing
The local administrator account for a company’s VPN appliance was unexpectedly used to log in to the remote management interface. Which of the following would have prevented this from happening?
Implementing multifactor authentication
Assigning individual user IDs
Changing the default password
Using least privilege
Which of the following should a security administrator adhere to when setting up a new set of firewall rules?
Business continuity plan
Change management procedure
cident response procedure
Disaster recovery plan
A root cause analysis reveals that a web application outage was caused by one of the company's developers uploading a newer version of the third-party libraries that were shared among several applications. Which of the following implementations would be BEST to prevent this issue from reoccurring?
CASB
SWG
Containerization
Automated failover
Which of the following techniques eliminates the use of rainbow tables for password cracking?
Hashing
Tokenization
Asymmetric encryption
Salting
Which of the following is MOST likely to outline the roles and responsibilities of data controllers and data processors?
ISO 31000
GDPR
PCI DSS
SSAE SOC 2
An upcoming project focuses on secure communications and trust between external parties. Which of the following security components will need to be considered to ensure a chosen trust provider IS used and the selected option is highly scalable?
Domain validation
Public key Infrastructure
Self-signed certificate
Certificate attributes
A security administrator performs weekly vulnerability scans on all cloud assets and provides a detailed report. Which of the following describes the administrator’s activities?
Data processor
Data owners
Continuous integration
Continuous deployment
A security administrator performs weekly vulnerability scans on all cloud assets and provides a detailed report. Which of the following describes the administrator's activities?
Continuous integration
Continuous validation
Continuous monitoring
Continuous deployment
Which of the following best describes the situation where a successfully onboarded employee who is using a fingerprint reader is denied access at the company's mam gate?
Crossover error rate
False positive
False rejection
False match raw
During an incident a company CIRT determine it is necessary to observe the continued network-based transaction between a callback domain and the malware running on an enterprise PC. Which of the following techniques would be BEST to enable this activity while reducing the risk of lateral spread and the risk that the adversary would notice any changes?
Apply network blacklisting rules for the adversary domain
Emulate the malware in a heavily monitored DMZ segment.
Create and apply micro segmentation rules.
Physical move the PC to a separate internet pint of presence
A company has discovered unauthorized devices are using its WiFi network, and it wants to harden the access point to improve security. Which of the following configurations should an analyst enable to improve security? (Choose two.)
SSL
WPA-TKIP
WPA2-PSK
RADIUS
EAP-PEAP
A corporate security team needs to secure the wireless perimeter of its physical facilities to ensure only authorized users can access corporate resources. Which of the following should the security team do?
Create heat maps.
Check for channel overlaps.
Identify rogue access points.
Implement domain hijacking.
A new security engineer has started hardening systems. One o( the hardening techniques the engineer is using involves disabling remote logins to the NAS. Users are now reporting the inability lo use SCP to transfer files to the NAS, even though the data is still viewable from the users' PCs. Which of the following is the MOST likely cause of this issue?
Network services are no longer running on the NAS
Remote login was disabled in the networkd.conf instead of using the sshd. conf.
D.
TFTP was disabled on the local hosts.
SSH was turned off instead of modifying the configuration file.
An organization’s Chief Information Security Officer is creating a position that will be responsible for implementing technical controls to protect data, including ensuring backups are properly maintained. Which of the following roles would MOST likely include these responsibilities?
Internal auditor
Data custodian
Backup administrator
Data protection officer
Data owner
Which of the following allow access to remote computing resources, a operating system. and centrdized configuration and data
Edge computing
Infrastructure as a service
Containers
Thin client
Stakeholders at an organization must be kept aware of any incidents and receive updates on status changes as they occur. Which of the following plans would fulfill this requirement?
Communication plan
Disaster recovery plan
Business continuity plan
Risk plan
Which of the following should an organization consider implementing in the event executives need to speak to the media after a publicized data breach?
Communication plan
Business continuity plan
Incident response plan
Disaster recovery pl
A company wants the ability to restrict web access and monitor the websites that employees visit. Which of the following would best meet these requirements?
Firewall
VPN
WAF
Internet proxy
A security operations center wants to implement a solution that can execute files to test for malicious activity. The solution should provide a report of the files' activity against known threats.
Which of the following should the security operations center implement?
Sn1per
Cuckoo
theHarvester
Nessus
A recent vulnerability scan revealed multiple servers have non-standard ports open for applications that are no longer in use. The security team is working to ensure all devices are patched and hardened. Which of the following would the security team perform to ensure the task is completed with minimal impact to production?
Enable HIDS on all servers and endpoints.
Ensure the antivirus is up to date.
Configure the deny list appropriately on the NGFW
Disable unnecessary services.
A company is launching a website in a different country in order to capture user information that a marketing business can use. The company itself will not be using the information. Which of the following roles is the company assuming?
Data collector
Data steward
Data processor
Data owner
Stakeholders at an organization must be kept aware of any incidents and receive updates on status changes as they occur. Which of the following plans would fulfill this requirement?
Risk plan
Disaster recovery plan
Communication plan
Business continuity plan
A network architect wants a server to have the ability to retain network availability even if one of the network switches it is connected to goes down. Which of the following should the architect implement on the server to achieve this goal?
Load balancing
NIC teaming
RAID
UPS
A company is under investigation for possible fraud. As part of the investigation, the authorities need to review all emails and ensure data is not deleted. Which of the following should the company implement to assist in the investigation?
Content filter
Data loss prevention
Legal hold
A user wanted to catch up on some work over the weekend but had issues logging in to the corporate network using a VPN. On Monday, the user opened a ticket for this issue but was able to log in successfully. Which of the following BEST describes the policy that is being implemented?
Network location
Password history
Geofencing
Time-based logins
