Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

SEC+ 026-050

Total questions: 25

Worksheet time: 25mins

Name
Class
Date
1.

Question #:26
Which of the following is the best reason to complete an audit in a banking environment?

a)

Regulatory requirement

b)

Organizational change

c)

Self-assessment requirement

d)

Service-level requirement

2.

Question #:27
A security analyst reviews domain activity logs and notices the following:

Which of the following is the best explanation for what the security analyst has discovered?

a)

The user jsmith's account has been locked out.

b)

A keylogger is installed on [smith's workstation

c)

An attacker is attempting to brute force ismith's account.

d)

Ransomware has been deployed in the domain.

3.

Question #:28
A security administrator is deploying a DLP solution to prevent the exfiltration of sensitive customer data. Which of the following should the administrator do first?

a)

Block access to cloud storage websites.

b)

Create a rule to block outgoing email attachments

c)

Apply classifications to the data.

d)

Remove all user permissions from shares on the file server.

4.

Question #:29
Which of the following describes the process of concealing code or text inside a graphical image?

a)

Symmetric encryption

b)

Hashing

c)

Data masking

d)

Steganography

5.

Question #:30
Which of the following must be considered when designing a high-availability network? (Select two).

a)

Ease of recovery

b)

Ability to patch

c)

Physical isolation

d)

Responsiveness

e)

Attack surface

6.

Question #:31
A data administrator is configuring authentication for a SaaS application and would like to reduce the number of credentials employees need to maintain. The company prefers to use domain credentials to access new SaaS applications. Which of the following methods would allow this functionality?

a)

SSO

b)

LEAP

c)

MFA

d)

PEAP

7.

Question #:32
Which of the following roles, according to the shared responsibility model, is responsible for securing the company’s database in an IaaS model for a cloud environment?

a)

Client


b)

Third-party vendor

c)

Cloud provider

d)

DBA

8.

Question #:33
A systems administrator receives the following alert from a file integrity monitoring tool:

The hash of the cmd.exe file has changed.

The systems administrator checks the OS logs and notices that no patches were applied in the last two months. Which of the following most likely occurred?

a)

The end user changed the file permissions.

b)

A cryptographic collision was detected.

c)

A snapshot of the file system was taken.

d)

A rootkit was deployed.

9.

Question #:34
A security manager created new documentation to use in response to various types of security incidents. Which of the following is the next step the manager should take?

a)

Set the maximum data retention policy.

b)

Securely store the documents on an air-gapped network.

c)

Review the documents' data classification policy.

d)

Conduct a tabletop exercise with the team.

10.

Question #:35
A small business uses kiosks on the sales floor to display product information for customers. A security team discovers the kiosks use end-of-life operating systems. Which of the following is the security team most likely to document as a security implication of the current architecture?

a)

Patch availability


b)

Product software compatibility

c)

Ease of recovery

d)

Cost of replacement

11.

Question #:36
A systems administrator is changing the password policy within an enterprise environment and wants this update implemented on all systems as quickly as possible. Which of the following operating system security measures will the administrator most likely use?

a)

Deploying PowerShell scripts


b)

Pushing GPO update

c)

Enabling PAP

d)

Updating EDR profiles

12.

Question #:37
A company’s legal department drafted sensitive documents in a SaaS application and wants to ensure the documents cannot be accessed by individuals in high-risk countries. Which of the following is the most
effective way to limit this access?

a)

Data masking


b)

Encryption

c)

Geolocation policy

d)

Data sovereignty regulation

13.

Question #:38
A company is adding a clause to its AUP that states employees are not allowed to modify the operating system on mobile devices. Which of the following vulnerabilities is the organization addressing?

a)

Cross-site scripting

b)

Buffer overflow

c)

Jailbreaking

d)

Side loading

14.

Question #:39
A security analyst is investigating an application server and discovers that software on the server is behaving abnormally. The software normally runs batch jobs locally and does not generate traffic, but the process is now generating outbound traffic over random high ports. Which of the following vulnerabilities has likely been exploited in this software?

a)

Memory injection

b)

Race condition

c)

Side loading

d)

SQL injection

15.

Question #:40
A healthcare organization wants to provide a web application that allows individuals to digitally report health emergencies.

Which of the following is the most important consideration during development?

a)

Scalability

b)

Availability

c)

Cost

d)

Ease of deployment

16.

Question #:41
Which of the following is the most common data loss path for an air-gapped network?

a)

Bastion host

b)

Unsecured Bluetooth

c)

Unpatched OS

d)

Removable devices

17.

Question #:42
An engineer needs to find a solution that creates an added layer of security by preventing unauthorized access to internal company resources. Which of the following would be the best solution?

a)

RDP server

b)

Jump server

c)

Proxy server

d)

Hypervisor

18.

Question #:43
Which of the following would help ensure a security analyst is able to accurately measure the overall risk to an organization when a new vulnerability is disclosed?

a)

A full inventory of all hardware and software

b)

Documentation of system classifications

c)

A list of system owners and their departments

d)

Third-party risk assessment documentation

19.

Question #:44
After a recent vulnerability scan, a security engineer needs to harden the routers within the corporate network. Which of the following is the most appropriate to disable?

a)

Console access


b)

Routing protocols

c)

VLANs

d)

Web-based administration

20.

Question #:45
An organization recently updated its security policy to include the following statement:

Regular expressions are included in source code to remove special characters such as $, |, ;. &, `, and ? from variables set by forms in a web application.

Which of the following best explains the security technique the organization adopted by making this addition to the policy?

a)

Identify embedded keys

b)

Code debugging

c)

Input validation

d)

Static code analysis

21.

Question #:46
Which of the following describes a security alerting and monitoring tool that collects system, application, and network logs from multiple sources in a centralized system?

a)

SIEM

b)

DLP

c)

IDS

d)

SNMP

22.

Question #:47
An administrator is reviewing a single server's security logs and discovers the following;

Which of the following best describes the action captured in this log file?

a)

Brute-force attack


b)

Privilege escalation

c)

Failed password audit

d)

Forgotten password by the user

23.

Question #:48
An analyst is evaluating the implementation of Zero Trust principles within the data plane. Which of the following would be most relevant for the analyst to evaluate?

a)

Secured zones

b)

Subject role

c)

Adaptive identity

d)

Threat scope reduction

24.

Question #:49
Several employees received a fraudulent text message from someone claiming to be the Chief Executive Officer (CEO). The message stated:

“I’m in an airport right now with no access to email. I need you to buy gift cards for employee recognition awards. Please send the gift cards to following email address.”

Which of the following are the best responses to this situation? (Choose two).

a)

Cancel current employee recognition gift cards.

b)

Add a smishing exercise to the annual company training.

c)

Issue a general email warning to the company.

d)

Have the CEO change phone numbers.

e)

Conduct a forensic investigation on the CEO's phone

25.

Question #:50
A software development manager wants to ensure the authenticity of the code created by the company. Which of the following options is the most appropriate?

a)

Testing input validation on the user input fields

b)

Performing code signing on company-developed software

c)

Performing static code analysis on the software

d)

Ensuring secure cookies are use