WorksheetsSEC+ 026-050
Total questions: 25
Worksheet time: 25mins
Question #:26
Which of the following is the best reason to complete an audit in a banking environment?
Regulatory requirement
Organizational change
Self-assessment requirement
Service-level requirement
Question #:27
A security analyst reviews domain activity logs and notices the following:
Which of the following is the best explanation for what the security analyst has discovered?
The user jsmith's account has been locked out.
A keylogger is installed on [smith's workstation
An attacker is attempting to brute force ismith's account.
Ransomware has been deployed in the domain.
Question #:28
A security administrator is deploying a DLP solution to prevent the exfiltration of sensitive customer data. Which of the following should the administrator do first?
Block access to cloud storage websites.
Create a rule to block outgoing email attachments
Apply classifications to the data.
Remove all user permissions from shares on the file server.
Question #:29
Which of the following describes the process of concealing code or text inside a graphical image?
Symmetric encryption
Hashing
Data masking
Steganography
Question #:30
Which of the following must be considered when designing a high-availability network? (Select two).
Ease of recovery
Ability to patch
Physical isolation
Responsiveness
Attack surface
Question #:31
A data administrator is configuring authentication for a SaaS application and would like to reduce the number of credentials employees need to maintain. The company prefers to use domain credentials to access new SaaS applications. Which of the following methods would allow this functionality?
SSO
LEAP
MFA
PEAP
Question #:32
Which of the following roles, according to the shared responsibility model, is responsible for securing the company’s database in an IaaS model for a cloud environment?
Client
Third-party vendor
Cloud provider
DBA
Question #:33
A systems administrator receives the following alert from a file integrity monitoring tool:
The hash of the cmd.exe file has changed.
The systems administrator checks the OS logs and notices that no patches were applied in the last two months. Which of the following most likely occurred?
The end user changed the file permissions.
A cryptographic collision was detected.
A snapshot of the file system was taken.
A rootkit was deployed.
Question #:34
A security manager created new documentation to use in response to various types of security incidents. Which of the following is the next step the manager should take?
Set the maximum data retention policy.
Securely store the documents on an air-gapped network.
Review the documents' data classification policy.
Conduct a tabletop exercise with the team.
Question #:35
A small business uses kiosks on the sales floor to display product information for customers. A security team discovers the kiosks use end-of-life operating systems. Which of the following is the security team most likely to document as a security implication of the current architecture?
Patch availability
Product software compatibility
Ease of recovery
Cost of replacement
Question #:36
A systems administrator is changing the password policy within an enterprise environment and wants this update implemented on all systems as quickly as possible. Which of the following operating system security measures will the administrator most likely use?
Deploying PowerShell scripts
Pushing GPO update
Enabling PAP
Updating EDR profiles
Question #:37
A company’s legal department drafted sensitive documents in a SaaS application and wants to ensure the documents cannot be accessed by individuals in high-risk countries. Which of the following is the most
effective way to limit this access?
Data masking
Encryption
Geolocation policy
Data sovereignty regulation
Question #:38
A company is adding a clause to its AUP that states employees are not allowed to modify the operating system on mobile devices. Which of the following vulnerabilities is the organization addressing?
Cross-site scripting
Buffer overflow
Jailbreaking
Side loading
Question #:39
A security analyst is investigating an application server and discovers that software on the server is behaving abnormally. The software normally runs batch jobs locally and does not generate traffic, but the process is now generating outbound traffic over random high ports. Which of the following vulnerabilities has likely been exploited in this software?
Memory injection
Race condition
Side loading
SQL injection
Question #:40
A healthcare organization wants to provide a web application that allows individuals to digitally report health emergencies.
Which of the following is the most important consideration during development?
Scalability
Availability
Cost
Ease of deployment
Question #:41
Which of the following is the most common data loss path for an air-gapped network?
Bastion host
Unsecured Bluetooth
Unpatched OS
Removable devices
Question #:42
An engineer needs to find a solution that creates an added layer of security by preventing unauthorized access to internal company resources. Which of the following would be the best solution?
RDP server
Jump server
Proxy server
Hypervisor
Question #:43
Which of the following would help ensure a security analyst is able to accurately measure the overall risk to an organization when a new vulnerability is disclosed?
A full inventory of all hardware and software
Documentation of system classifications
A list of system owners and their departments
Third-party risk assessment documentation
Question #:44
After a recent vulnerability scan, a security engineer needs to harden the routers within the corporate network. Which of the following is the most appropriate to disable?
Console access
Routing protocols
VLANs
Web-based administration
Question #:45
An organization recently updated its security policy to include the following statement:
Regular expressions are included in source code to remove special characters such as $, |, ;. &, `, and ? from variables set by forms in a web application.
Which of the following best explains the security technique the organization adopted by making this addition to the policy?
Identify embedded keys
Code debugging
Input validation
Static code analysis
Question #:46
Which of the following describes a security alerting and monitoring tool that collects system, application, and network logs from multiple sources in a centralized system?
SIEM
DLP
IDS
SNMP
Question #:47
An administrator is reviewing a single server's security logs and discovers the following;
Which of the following best describes the action captured in this log file?
Brute-force attack
Privilege escalation
Failed password audit
Forgotten password by the user
Question #:48
An analyst is evaluating the implementation of Zero Trust principles within the data plane. Which of the following would be most relevant for the analyst to evaluate?
Secured zones
Subject role
Adaptive identity
Threat scope reduction
Question #:49
Several employees received a fraudulent text message from someone claiming to be the Chief Executive Officer (CEO). The message stated:
“I’m in an airport right now with no access to email. I need you to buy gift cards for employee recognition awards. Please send the gift cards to following email address.”
Which of the following are the best responses to this situation? (Choose two).
Cancel current employee recognition gift cards.
Add a smishing exercise to the annual company training.
Issue a general email warning to the company.
Have the CEO change phone numbers.
Conduct a forensic investigation on the CEO's phone
Question #:50
A software development manager wants to ensure the authenticity of the code created by the company. Which of the following options is the most appropriate?
Testing input validation on the user input fields
Performing code signing on company-developed software
Performing static code analysis on the software
Ensuring secure cookies are use
