Font size
WorksheetsSEC+ 001-025
Total questions: 25
Worksheet time: 13mins
Question #:1
A security administrator needs a method to secure data in an environment that includes some form of checks so that the administrator can track any changes. Which of the following should the administrator set up to achieve this goal?
A
SPF
B
GPO
C
NAC
D
FIM
Question #:2
The local administrator account for a company's VPN appliance was unexpectedly used to log in to the remote management interface. Which of the following would have most likely prevented this from happening'?
A
Using least privilege
B
Changing the default password
C
Assigning individual user IDs
D
Reviewing logs more frequently
Question #:3
A Chief Information Security Officer (CISO) wants to explicitly raise awareness about the increase of ransomware-as-a-service in a report to the management team. Which of the following best describes the threat actor in the CISO's report?
A
Insider threat
B
Hacktivist
C
Nation-state
D
Organized crime
Question #:4
A security consultant needs secure, remote access to a client environment. Which of the following should the
security consultant most likely use to gain access?
A
EAP
B
DHCP
C
IPSec
D
NAT
Question #:5
A systems administrator set up a perimeter firewall but continues to notice suspicious connections between internal endpoints. Which of the following should be set up in order to mitigate the threat posed by the suspicious activity?
A
Host-based firewall
B
Web application firewall
C
Access control list
D
Application allow list
Question #:6
An administrator assists the legal and compliance team with ensuring information about customer transactions is archived for the proper time period. Which of the following data policies is the administrator carrying out?
A
Compromise
B
Retention
C
Analysis
D
Transfer
E
Inventory
Question #:7
Which of the following is a hardware-specific vulnerability?
A
Firmware version
B
Buffer overflow
C
SQL injection
D
Cross-site scripting
Question #:8
After an audit, an administrator discovers all users have access to confidential data on a file server. Which of the following should the administrator use to restrict access to the data quickly?
A
Group Policy
B
Content filtering
C
Data loss prevention
D
Access control lists
Question #:9
Which of the following scenarios describes a possible business email compromise attack?
An employee receives a gift card request in an email that has an executive's name in the display field of the email.
Employees who open an email attachment receive messages demanding payment in order to access files.
A service desk employee receives an email from the HR director asking for log-in credentials to a cloud administrator account.
An employee receives an email with a link to a phishing site that is designed to look like the company's email portal.
Question #:10
An enterprise has been experiencing attacks focused on exploiting vulnerabilities in older browser versions with well-known exploits. Which of the following security solutions should be configured to best provide the ability to monitor and block these known signature-based attacks?
A
ACL
B
DLP
C
IDS
D
IPS
Question #:11
A user is attempting to patch a critical system, but the patch fails to transfer. Which of the following access
controls is most likely inhibiting the transfer?
A
Attribute-based
B
Time of day
C
Role-based
D
Least privilege
Question #:12
A company is planning to set up a SIEM system and assign an analyst to review the logs on a weekly basis. Which of the following types of controls is the company setting up?
A
Corrective
B
Preventive
C
Detective
D
Deterrent
Question #:13
A company is expanding its threat surface program and allowing individuals to security test the company’s internet-facing application. The company will compensate researchers based on the vulnerabilities discovered. Which of the following best describes the program the company is setting up?
A
Open-source intelligence
B
Bug bounty
C
Red team
D
Penetration testing
Question #:14
An organization’s internet-facing website was compromised when an attacker exploited a buffer overflow. Which of the following should the organization deploy to best protect against similar attacks in the future?
A
NGFW
B
WAF
C
TLS
D
SD-WAN
Question #:15
Which of the following describes the maximum allowance of accepted risk?
A
Risk indicator
B
Risk level
C
Risk score
D
Risk threshold
Question #:16
A systems administrator is working on a solution with the following requirements:
• Provide a secure zone.
• Enforce a company-wide access control policy.
• Reduce the scope of threats.
Which of the following is the systems administrator setting up?
A
Zero Trust
B
AAA
C
Non-repudiation
D
CIA
Question #:17
A security engineer is implementing FDE for all laptops in an organization. Which of the following are the most important for the engineer to consider as part of the planning process? (Select two).
A
Key escrow
B
TPM presence
C
Digital signatures
D
Data tokenization
E
Public key management
F
Certificate authority linking
Question #:18
Which of the following is used to add extra complexity before using a one-way data transformation algorithm?
A
Key stretching
B
Data masking
C
Steganography
D
Salting
Question #:19
The management team notices that new accounts that are set up manually do not always have correct access or permissions.
Which of the following automation techniques should a systems administrator use to streamline account creation?
A
Guard rail script
B
Ticketing workflow
C
Escalation script
D
User provisioning script
Question #:20
Which of the following would be most useful in determining whether the long-term cost to transfer a risk is less than the impact of the risk?
A
ARO
B
RTO
C
RPO
D
ALE
E
SLE
Question #:21
A company wants to verify that the software the company is deploying came from the vendor the company purchased the software from. Which of the following is the best way for the company to confirm this information?
A
Validate the code signature
B
Execute the code in a sandbox
C
Search the executable for ASCII strings
D
Generate a hash of the files
Question #:22
Simulation Questions check SQ+edited.pdf
A
Simulation Questions check SQ+edited.pdf
B
C
D
Question #:23
Which of the following must be considered when designing a high-availability network? (Choose two).
A
Ease of recovery
B
Ability to patch
C
Physical isolation
D
Responsiveness
E
Attack surface
F
Extensible authentication
Question #:24
Which of the following involves an attempt to take advantage of database misconfigurations?
A
Buffer overflow
B
SQL injection
C
VM escape
D
Memory injection
Question #:25
A bank insists all of its vendors must prevent data loss on stolen laptops. Which of the following strategies is the bank requiring?
A
Encryption at rest
B
Masking
C
Data classification
D
Permission restrictions
