wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Day 13 Quiz - Final Review Part 1 (Domains 1 & 2)

Total questions: 161

Worksheet time: 2hrs 24mins

Name
Class
Date
1.

Objective 1.1/Day 3 -

During a security audit, a cybersecurity analyst discovers that the organization's logging mechanism does not utilize time synchronization across its systems. What is the most significant risk associated with this oversight?

a)

Increased storage costs for logs

b)

Difficulty in correlating log data

c)

Limited access to system processes

d)

Enhanced performance degradation

2.

Objective 1.1/Day 3 -

Which operating system concept involves minimizing potential vulnerabilities by configuring system settings and removing unnecessary services or software?

a)

Windows Registry

b)

System hardening

c)

File structure

d)

Log ingestion

3.

Objective 1.1/Day 3 -

In a network architecture, logging levels are configured to capture varying amounts of detail about system events. Which logging level is typically used to log the most severe issues that require immediate attention?

a)

Debug

b)

Info

c)

Error

d)

Critical

4.

Objective 1.1/Day 3 -

Which infrastructure concept allows applications to run without the need for managing the underlying server infrastructure, enabling scalability and reducing operational overhead?

a)

Virtualization

b)

Serverless

c)

Containerization

d)

Network segmentation

5.

Objective 1.1/Day 3 -

In a hybrid cloud environment, which network architecture combines both on-premises resources and cloud-based services to provide flexibility and scalability?

a)

On-premises

b)

Hybrid

c)

Zero trust

d)

Software-defined networking (SDN)

6.

Objective 1.1/Day 3 -

Which network architecture concept focuses on minimizing trust assumptions within a network and ensures that every access request is verified, regardless of the source?

a)

Network segmentation

b)

Secure access secure edge (SASE)

c)

Zero trust

d)

Cloud

7.

Objective 1.1/Day 3 -

Which identity and access management concept enhances security by requiring users to provide two or more verification factors to gain access to a resource?

a)

Single sign-on (SSO)

b)

Federation

c)

Multifactor authentication (MFA)

d)

Privileged access management (PAM)

8.

Objective 1.1/Day 3 -

Which identity and access management method allows users to log in once and gain access to multiple applications without needing to re-enter credentials for each?

a)

Federation

b)

Passwordless

c)

Single sign-on (SSO)

d)

Cloud access security broker (CASB)

9.

Objective 1.1/Day 3 -

Which access management approach focuses on managing and securing the credentials and access rights of users with elevated privileges, ensuring that sensitive operations are tightly controlled?

a)

Multifactor authentication (MFA)

b)

Privileged access management (PAM)

c)

Cloud access security broker (CASB)

d)

Federation

10.

Objective 1.1/Day 3 -

Which encryption framework uses a pair of keys, one public and one private, to secure communications and verify the identity of the communicating parties?

a)

Secure sockets layer (SSL)

b)

Data loss prevention (DLP)

c)

Public key infrastructure (PKI)

d)

Transport Layer Security (TLS)

11.

Objective 1.1/Day 3 -

What technology is primarily used to encrypt data transmitted over the internet, ensuring secure connections between web browsers and servers?

a)

Public key infrastructure (PKI)

b)

Data loss prevention (DLP)

c)

Secure sockets layer (SSL)

d)

Personally identifiable information (PII)

12.

Objective 1.1/Day 3 -

Which data protection strategy focuses on identifying and preventing the unauthorized transfer of sensitive information, such as credit card numbers and personal identification details?

a)

Public key infrastructure (PKI)

b)

Personally identifiable information (PII)

c)

Data loss prevention (DLP)

d)

Cardholder data (CHD)

13.

Objective 1.1/Day 3 -

A security analyst needs to ensure that log entries from various network devices and systems are accurate and can be correlated effectively. This is crucial for incident response and forensic analysis. Which practice is essential to ensure the accuracy and correlation of log entries from multiple devices and systems?

a)

Configuring logging levels

b)

Using serverless architecture

c)

Time synchronization

d)

Implementing virtualization

14.

Objective 1.1/Day 3 -

A company is migrating some of its applications to a containerized environment to improve scalability and resource utilization. Which infrastructure concept is being utilized by the company to achieve better scalability and resource utilization?

a)

Virtualization

b)

Serverless

c)

Containerization

d)

On-premises

15.

Objective 1.1/Day 3 -

A network administrator is implementing a security strategy that does not inherently trust any device inside or outside the network and requires continuous verification for access. Which network architecture strategy is the network administrator implementing?

a)

Zero trust

b)

Network segmentation

c)

Software-defined networking (SDN)

d)

Secure access secure edge (SASE)

16.

Objective 1.1/Day 3 -

A company is implementing a security solution that inspects SSL/TLS encrypted traffic to detect malicious activity without compromising encryption. Which security solution is the company implementing to inspect SSL/TLS traffic?

a)

Public key infrastructure (PKI)

b)

Secure sockets layer (SSL) inspection

c)

Data loss prevention (DLP)

d)

Cloud access security broker (CASB)

17.

Objective 1.1/Day 3 -

A company is using a network architecture that combines both on-premises infrastructure and cloud services to optimize resource utilization and provide flexibility. Which network architecture is the company using to combine on-premises infrastructure and cloud services?

a)

On-premises

b)

Cloud

c)

Hybrid

d)

Software-defined networking (SDN)

18.

Objective 1.1/Day 3 -

A security team is implementing measures to protect sensitive data such as personally identifiable information (PII) and cardholder data (CHD) from unauthorized access and breaches. Which security measure is specifically designed to protect sensitive data such as PII and CHD?

a)

Multifactor authentication (MFA)

b)

Data loss prevention (DLP)

c)

Secure access secure edge (SASE)

d)

Single sign-on (SSO)

19.

Objective 1.2/Day 10 -

A security analyst notices an unusually high bandwidth consumption originating from a specific internal IP address. The usage spikes during non-business hours and appears to be sending large amounts of data to an external IP address that is not recognized. What does this behavior most likely indicate?

a)

Normal scheduled backups

b)

Data exfiltration activity

c)

Routine software updates

d)

Internal system monitoring

20.

Objective 1.2/Day 10 -

During a routine network audit, an analyst discovers multiple devices connected to the network that are not recognized or documented in the asset inventory. Some of these devices are attempting to communicate with sensitive systems. What does this situation most likely indicate?

a)

Authorized guest devices

b)

Rogue devices on the network

c)

A normal network configuration change

d)

Scheduled maintenance activities

21.

Objective 1.2/Day 10 -

A security analyst detects irregular peer-to-peer communication patterns within the network traffic logs. Several internal devices are communicating with each other over unusual ports not typically used for such communication. What is the most likely implication of this observation?

a)

Routine file sharing activities

b)

Possible command and control (C2) communication

c)

Normal software application functionality

d)

Misconfigured network services

22.

Objective 1.2/Day 10 -

A security analyst is monitoring a server and notices that the CPU usage has consistently been at 95% for several hours. Additionally, the analyst identifies a process called "suspicious.exe" running on the server that is not part of the standard operating system. What should the analyst's primary concern be?

a)

Routine server load management

b)

Possible malicious process activity

c)

Normal software update behavior

d)

Server performance degradation

23.

Objective 1.2/Day 10 -

An analyst notices an unauthorized application installed on several endpoints in the organization. The application appears to have access to sensitive files and is configured to run at startup. What does this situation suggest?

a)

A legitimate software installation

b)

A potential security risk from unauthorized software

c)

A standard operating system behavior

d)

A company-sanctioned application

24.

Objective 1.2/Day 10 -

During a security review, an analyst finds that the hard drive on a critical workstation is nearly full, with many files created in the last few days that appear suspicious. The file names are nonsensical, and the analyst has not seen these files before. What should this indicate?

a)

Normal user activity

b)

Data exfiltration activity

c)

Routine disk cleanup

d)

Malware infection

25.

Objective 1.2/Day 10 -

An analyst is reviewing the system logs and discovers unauthorized changes made to the Windows registry, particularly in areas associated with startup applications. The changes were made by a process that the analyst does not recognize. What is the most likely implication of this finding?

a)

Legitimate system configuration changes

b)

Possible persistence mechanism for malware

c)

Routine maintenance activity

d)

User-initiated software installation

26.

Objective 1.2/Day 10 -

A security analyst reviews the application logs of a web application and notices multiple failed login attempts followed by a successful login from an unfamiliar IP address. The analyst also observes that the account used was modified to have elevated privileges shortly after the login. What does this pattern indicate?

a)

A user is experiencing login issues

b)

A potential account compromise

c)

Routine access by a new user

d)

Normal user behavior

27.

Objective 1.2/Day 10 -

An organization experiences an unexpected service interruption in its internal messaging application. The IT team discovers that the application was sending out unusually high volumes of messages to external addresses. What could this behavior signify?

a)

Normal operational activity

b)

A user error during application usage

c)

A potential malware infection or data exfiltration

d)

Routine maintenance tasks

28.

Objective 1.2/Day 10 -

During an audit of a company's financial software, an analyst finds unexpected output in the form of unusual transaction entries. Additionally, there are new user accounts created with administrative access that were not authorized by IT management. What is the most likely implication of these findings?

a)

Standard software updates have been performed

b)

A potential insider threat or external breach

c)

Normal changes to user accounts

d)

Routine application performance issues

29.

Objective 1.2/Day 10 -

An employee receives an urgent email from what appears to be their company's IT department, requesting immediate verification of their login credentials through a provided link. Upon hovering over the link, the URL displayed does not match the company's domain. What does this indicate?

a)

A routine security check by the IT department

b)

A potential phishing attempt

c)

An internal system update notification

d)

Normal communication protocol

30.

Objective 1.2/Day 10 -

A user receives a text message from an unknown number claiming to be from their bank, asking them to click on a link to verify recent transactions. The user notices the link is shortened and leads to a suspicious website. What should the user conclude about this message?

a)

It is a legitimate security measure from the bank

b)

It may be a social engineering attack

c)

It is part of a routine customer service initiative

d)

It is an internal company procedure

31.

Objective 1.2/Day 10 -

An employee receives a message on social media from a contact claiming to have found an important document related to the employee's recent project. The message contains a link labeled "Click here for more details!" The employee is unsure of the sender's identity. What action should the employee take?

a)

Click the link to access the document

b)

Ignore the message, as it is likely harmless

c)

Verify the sender's identity before taking any action

d)

Report the message to IT as a phishing attempt

32.

Objective 1.2/Day 10 -

A network administrator reviews the network traffic logs and notices the following pattern of outbound traffic (See Image):

What does this pattern most likely indicate?

a)

Regular backup operations

b)

Network scans

c)

Beaconing from a malware infection

d)

Legitimate remote work activity

33.

Objective 1.2/Day 10 -

A security analyst examines the system performance logs and sees the following information (See Image):

What does this information indicate about the system's current state?

a)

Normal operation with high workload

b)

Malicious processes consuming resources

c)

Routine software updates

d)

System performance testing

34.

Objective 1.2/Day 10 -

An IT team is alerted to unusual file system changes. The following log entries are observed (See Image):

What does the sequence of these file system changes most likely indicate?

a)

System updates being applied

b)

User error in file handling

c)

Unauthorized changes potentially from malware

d)

Scheduled maintenance tasks

35.

Objective 1.2/Day 10 -

During a review of application logs, the following entries are found (See Image):

What does this activity suggest?

a)

Routine administrative maintenance

b)

Malicious activity involving privilege escalation

c)

User training exercise

d)

Normal user account creation

36.

Objective 1.2/Day 10 -

A network monitor alerts the security team to unusual outbound traffic patterns (See Image):

What does this network traffic most likely indicate?

a)

Regular user browsing activity

b)

Data exfiltration attempt

c)

Video streaming service

d)

Scheduled data transfer

37.

Objective 1.2/Day 10 -

An employee's computer has been experiencing unusual behavior. The following task scheduler entries are found (See Image):

What is the most likely cause of this behavior?

a)

Legitimate software updates

b)

Unauthorized scheduled tasks potentially from malware

c)

Employee troubleshooting attempts

d)

System maintenance scripts

38.

Objective 1.2/Day 10 -

A network administrator identifies a rogue device on the network with the following traffic pattern (See Image):

What does this traffic pattern likely indicate?

a)

Regular file transfer operations

b)

Data exfiltration via FTP

c)

Routine server backup

d)

Software update distribution

39.

Objective 1.3/Day 9 -

A network administrator detects unusual outbound traffic from a server that is not typical for its operations. To investigate this anomaly, the administrator decides to capture and analyze the network packets to identify the nature of the traffic. Which tool should the administrator use?

a)

Security Information and Event Management (SIEM)

b)

Wireshark

c)

Endpoint Detection and Response (EDR)

d)

VirusTotal

40.

Objective 1.3/Day 9 -

An organization experiences a series of failed login attempts on multiple accounts, indicating a possible brute-force attack. The incident response team decides to analyze the logs from their authentication system to determine the source of the attack. Which tool would be most effective for this log analysis?

a)

Security Information and Event Management (SIEM)

b)

Cuckoo Sandbox

c)

AbuseIPDB

d)

Strings

41.

Objective 1.3/Day 9 -

After a phishing attack, a cybersecurity analyst discovers a suspicious IP address linked to the emails. They want to check whether this IP address has been reported for malicious activities. Which tool should the analyst use to perform this check?

a)

WHOIS

b)

tcpdump

c)

AbuseIPDB

d)

Endpoint Detection and Response (EDR)

42.

Objective 1.3/Day 9 -

An analyst is investigating a suspicious executable file that was flagged by the endpoint security system. To determine if the file contains any malicious code, the analyst decides to analyze its contents. Which tool should the analyst use to extract and examine strings from the executable file?

a)

VirusTotal

b)

Strings

c)

Cuckoo Sandbox

d)

Security Orchestration, Automation, and Response (SOAR)

43.

Objective 1.3/Day 9 -

A cybersecurity analyst receives an alert regarding abnormal account activity for a user who is logged in from two different geographic locations within a short time frame. This behavior raises suspicion of a potential account compromise. Which technique should the analyst employ to validate the legitimacy of the login attempts?

a)

Command and Control (C2) pattern recognition

b)

Impossible travel analysis

c)

Email header analysis

d)

Hashing of user files

44.

Objective 1.3/Day 9 -

An organization receives a suspicious email that appears to come from a known supplier but contains a request for sensitive information. The cybersecurity team wants to determine if the email is genuine or a phishing attempt. Which method should they use to analyze the email?

a)

User behavior analysis

b)

DKIM and DMARC verification

c)

Command and Control pattern recognition

d)

Hashing of the email content

45.

Objective 1.3/Day 9 -

During a routine security audit, an analyst discovers a series of commands executed on a server that appear to be unusual and potentially malicious. To assess whether these commands are part of a command and control operation, which technique should the analyst apply?

a)

Email analysis for spoofing

b)

Pattern recognition of command sequences

c)

User behavior analysis for account access

d)

File hashing for executable integrity

46.

Objective 1.3/Day 9 -

A security analyst is using Wireshark to monitor network traffic. They notice the following packet capture data (See Image):

What does this traffic pattern most likely indicate?

a)

Regular web browsing activity

b)

HTTP DDoS attack

c)

Normal system update check

d)

Network scan

47.

Objective 1.3/Day 9 -

Using a SIEM tool, a security analyst correlates multiple logs and discovers the following pattern (See Image):

What does this pattern most likely indicate?

a)

Normal file access by different users

b)

Unusual download activity possibly indicating insider threat

c)

Routine file transfer operations

d)

Automated backup process

48.

Objective 1.3/Day 9 -

An analyst uses VirusTotal to analyze a suspicious file and receives the following report (See Image):

What is the appropriate action to take based on this report?

a)

Ignore the file, it’s likely a false positive

b)

Quarantine the file and initiate an incident response

c)

Submit the file for further sandbox analysis

d)

Continue monitoring without any action

49.

Objective 1.3/Day 9 -

A security team uses WHOIS to investigate a suspicious domain and finds the following information (See Image):

What does this information suggest about the domain?

a)

It is a legitimate business domain

b)

It may be associated with malicious activity

c)

It is used for secure communications

d)

It is a government-owned domain

50.

Objective 1.3/Day 9 -

An IT security analyst receives an alert about abnormal outbound traffic from an internal server. The analyst uses tcpdump and captures the following (See Image):

What does this tcpdump output likely indicate?

a)

Normal server communications

b)

Data exfiltration activity

c)

Routine software update

d)

Network performance testing

51.

Objective 1.3/Day 9 -

A security analyst is using an EDR tool to monitor endpoint activity and finds the following process information (See Image):

What should be the analyst's next step?

a)

Ignore the process, it’s likely a system process

b)

Terminate the process and isolate the endpoint

c)

Whitelist the process for future operations

d)

Monitor the process without taking action

52.

Objective 1.3/Day 9 -

An email security analysis reveals the following email header information (See Image):

What does this email analysis suggest?

a)

The email is legitimate and can be trusted

b)

The email is likely a phishing attempt

c)

The email requires a DMARC configuration update

d)

The email is part of regular business communication

53.

Objective 1.3/Day 12 -

A security analyst is investigating a series of suspicious network requests that appear to be encoded and embedded within an XML file. To analyze the structure and content of these requests, which of the following tools or techniques should the analyst use?

a)

PowerShell

b)

Regular expressions

c)

Python

d)

XML parsing

54.

Objective 1.3/Day 12 -

During an incident response, an analyst discovers a PowerShell script that contains obfuscated commands used to execute malicious payloads. To effectively analyze and understand the script, which tool or technique would be most appropriate?

a)

JSON decoding

b)

Shell script analysis

c)

Python scripting

d)

PowerShell analysis

55.

Objective 1.3/Day 12 -

A security team is reviewing logs that contain entries formatted in JSON. To identify patterns or extract specific information from these logs, which of the following techniques would be most effective?

a)

Python scripting

b)

Regular expressions

c)

XML parsing

d)

PowerShell

56.

Objective 1.3/Day 12 -

An analyst needs to detect and analyze potentially harmful regular expressions embedded within shell scripts. Which of the following approaches would be most effective in this scenario?

a)

Regular expression analysis

b)

Shell script execution

c)

PowerShell scripting

d)

XML parsing

57.

Objective 1.3/Day 12 -

A security analyst is investigating a suspicious script found on a compromised server. The script is written in PowerShell and contains the following code (See Image):

What is the primary purpose of this PowerShell script?

a)

To update system files

b)

To download and execute a malicious payload

c)

To create a backup of important files

d)

To monitor network traffic

58.

Objective 1.3/Day 12 -

An analyst discovers a Python script running on an internal server. The script's purpose is unclear, so they review the following snippet (See Image):

What does this Python script do?

a)

It updates the system configuration files

b)

It scans a directory and computes the SHA-256 hash of each file

c)

It monitors network traffic

d)

It deletes temporary files in the directory

59.

Objective 1.4/Day 2 -

A security analyst is evaluating the motivations and resources behind a prolonged and sophisticated attack on the organization’s network. The attack seems to be well-funded, persistent, and targeted specifically at stealing sensitive data. Which type of threat actor is most likely behind this attack?

a)

Script kiddie

b)

Insider threat

c)

Organized crime

d)

Advanced persistent threat (APT)

60.

Objective 1.4/Day 2 -

An organization is concerned about employees unintentionally exposing sensitive information through phishing attacks. Which type of insider threat does this scenario best describe?

a)

Unintentional insider threat

b)

Intentional insider threat

c)

Script kiddie

d)

Hacktivist

61.

Objective 1.4/Day 2 -

Which threat actor is most likely to engage in politically motivated attacks, often seeking to disrupt services or deface websites to spread a particular message?

a)

Advanced persistent threat (APT)

b)

Nation-state

c)

Hacktivist

d)

Supply chain attacker

62.

Objective 1.4/Day 2 -

A security analyst receives a threat intelligence report that contains data about a new malware variant. The report was published six months ago, and the malware's characteristics have likely evolved since then. Which confidence level aspect is most impacted by the age of the report?

a)

Relevancy

b)

Timeliness

c)

Accuracy

d)

Collection method

63.

Objective 1.4/Day 2 -

Which of the following is an example of a closed-source threat intelligence collection method?

a)

Government bulletins

b)

Paid feeds

c)

Social media

d)

Deep/dark web

64.

Objective 1.4/Day 2 -

During threat hunting, an analyst is reviewing information from forums and blogs to identify potential indicators of compromise (IOCs) related to a recent vulnerability. Which collection method is the analyst primarily using?

a)

Closed source

b)

Government bulletins

c)

Open source

d)

Internal sources

65.

Objective 1.4/Day 2 -

An organization is implementing a threat intelligence sharing program to improve its security posture. How can sharing threat intelligence specifically enhance the organization's incident response capabilities?

a)

By reducing the need for vulnerability assessments

b)

By providing timely information on emerging threats

c)

By eliminating the need for security engineering efforts

d)

By ensuring compliance with legal and regulatory requirements

66.

Objective 1.4/Day 2 -

A security team is using shared threat intelligence to prioritize patching efforts based on the most critical vulnerabilities affecting the organization. Which aspect of threat intelligence sharing does this activity best align with?

a)

Risk management

b)

Detection and monitoring

c)

Security engineering

d)

Vulnerability management

67.

Objective 1.4/Day 2 -

During a threat-hunting exercise, a security analyst discovers unusual outbound traffic patterns from an isolated network. What is the primary focus area the analyst is addressing in this scenario?

a)

Business-critical assets and processes

b)

Configurations/misconfigurations

c)

Honeypot

d)

Isolated networks

68.

Objective 1.4/Day 2 -

A threat hunter is analyzing collected Indicators of Compromise (IoCs) to determine the presence of specific threats within the organization's environment. Which of the following best describes the process the threat hunter is engaged in?

a)

IoC Application

b)

IoC Collection

c)

IoC Analysis

d)

Active defense

69.

Objective 1.4/Day 2 -

An organization deploys a honeypot to lure potential attackers and analyze their methods. What is the primary purpose of using a honeypot in the context of threat hunting?

a)

To secure business-critical assets

b)

To identify misconfigurations in the network

c)

To engage in active defense and gather threat intelligence

d)

To isolate networks from potential threats

70.

Objective 1.4/Day 2 -

A security team is investigating an advanced persistent threat (APT) that has been targeting their organization for months. The attackers have shown a high level of sophistication, using custom malware and avoiding detection. Which type of threat actor is most likely responsible for this type of attack?

a)

Script kiddie

b)

Insider threat

c)

Nation-state

d)

Hacktivist

71.

Objective 1.4/Day 2 -

During a threat-hunting exercise, an analyst discovers unusual network traffic patterns that suggest a potential insider threat. The traffic includes large data transfers to external IP addresses. What is the most likely explanation for this activity?

a)

Script kiddie

b)

Intentional insider threat

c)

Nation-state

d)

Supply chain attack

72.

Objective 1.4/Day 2 -

An organization relies on various sources for threat intelligence, including social media, blogs, and government bulletins. They also subscribe to several paid threat intelligence feeds. What types of threat intelligence sources is this organization using?

a)

Open source and internal sources

b)

Closed source and internal sources

c)

Open source and closed source

d)

Closed source and open source

73.

Objective 1.4/Day 2 -

A security operations center (SOC) is analyzing indicators of compromise (IoCs) to detect potential threats. They use these IoCs to identify suspicious activities within their network. What is one primary focus area for threat hunting using IoCs?

a)

Security engineering

b)

Vulnerability management

c)

Business-critical assets and processes

d)

Incident response

74.

Objective 1.4/Day 2 -

A cybersecurity analyst needs to determine the relevance and accuracy of threat intelligence data collected from various sources. Which aspect of threat intelligence is being evaluated?

a)

Tactics, techniques, and procedures (TTP)

b)

Confidence levels

c)

Collection methods and sources

d)

Threat intelligence sharing

75.

Objective 1.4/Day 2 -

An organization has deployed a honeypot to gather information on attackers' methods and to divert them away from actual assets. Which threat-hunting concept does this best illustrate?

a)

Indicators of compromise (IoC)

b)

Active defense

c)

Threat intelligence sharing

d)

Collection methods and sources

76.

Objective 1.5/Day 4 -

Which process improvement technique focuses on identifying repetitive tasks that can be automated to enhance efficiency in security operations?

a)

Standardization

b)

Task automation

c)

Team coordination

d)

Process documentation

77.

Objective 1.5/Day 4 -

What is a key benefit of standardizing processes in security operations?

a)

Increased complexity

b)

Enhanced incident response times

c)

Greater reliance on manual processes

d)

Reduced team communication

78.

Objective 1.5/Day 4 -

Which approach involves integrating various security tools and processes to enhance incident response capabilities and improve overall efficiency in security operations?

a)

Security Information and Event Management (SIEM)

b)

Security orchestration, automation, and response (SOAR)

c)

Vulnerability management

d)

Incident response planning

79.

Objective 1.5/Day 4 -

What is one of the primary benefits of data enrichment during the orchestration of threat intelligence data?

a)

Increased manual workload

b)

Improved decision-making

c)

Simplified threat feeds

d)

Reduced visibility into threats

80.

Objective 1.5/Day 4 -

What is a key goal of minimizing human engagement in security operations?

a)

Increasing response times

b)

Reducing the risk of human error

c)

Encouraging manual analysis

d)

Maximizing resource utilization

81.

Objective 1.5/Day 4 -

Which method allows different security tools to communicate and share data seamlessly, enhancing the overall efficiency of security operations?

a)

Webhooks

b)

Application programming interface (API)

c)

Manual reporting

d)

Security operations center (SOC)

82.

Objective 1.5/Day 4 -

What is the purpose of using webhooks in security operations?

a)

To create static reports

b)

To enable real-time notifications and data sharing

c)

To automate vulnerability scans

d)

To manage user access controls

83.

Objective 1.5/Day 4 -

What is the advantage of having a single pane of glass in security operations?

a)

Increased complexity in monitoring

b)

Fragmented visibility of security events

c)

Simplified management and improved visibility

d)

Redundant data sources

84.

Objective 1.5/Day 4 -

A security operations center (SOC) is overwhelmed with repetitive tasks such as log monitoring and alerting. The team decides to implement a solution that can automate these processes, reducing the need for constant human intervention. Which concept is most relevant to addressing the SOC's issue?

a)

Threat feed combination

b)

Security orchestration, automation, and response (SOAR)

c)

Application programming interface (API)

d)

Single pane of glass

85.

Objective 1.5/Day 4 -

A cybersecurity team is looking to integrate various security tools to improve incident response times. They want to ensure that the tools can communicate and work together seamlessly. Which technology would best support this integration?

a)

Webhooks

b)

Single pane of glass

c)

Data enrichment

d)

Threat feed combination

86.

Objective 1.5/Day 4 -

A company wants to reduce the manual effort required to analyze and enrich threat intelligence data from multiple sources. Which strategy would best achieve this goal?

a)

Implementing APIs for tool integration

b)

Orchestrating threat intelligence data

c)

Developing plugins for each tool

d)

Standardizing processes

87.

Objective 1.5/Day 4 -

The security team at an organization needs to ensure that their security tools provide a unified view of all security events and incidents, allowing for quicker decision-making. Which solution should they implement?

a)

Automation and orchestration

b)

Single pane of glass

c)

Threat feed combination

d)

Data enrichment

88.

Objective 1.5/Day 4 -

An organization is identifying tasks within their security operations that can be automated to improve efficiency. They need to choose tasks that are repetitive and do not require human interaction. Which tasks should they consider automating?

a)

Incident response requiring complex decision-making

b)

Analyzing unique security incidents

c)

Repeatable log monitoring and alerting

d)

Handling customer support tickets

89.

Objective 2.1/Day 5 -

A security analyst is tasked with identifying all devices connected to the corporate network. They decide to utilize a method that assesses each device's operating system and services running. Which method should the analyst implement?

a)

Map scans

b)

Passive scanning

c)

Device fingerprinting

d)

Non-credentialed scanning

90.

Objective 2.1/Day 5 -

An organization wants to conduct a vulnerability assessment but is concerned about potential disruptions to business operations. They plan to run the scans during off-peak hours to minimize impact. Which special consideration is the organization prioritizing?

a)

Sensitivity levels

b)

Scheduling

c)

Regulatory requirements

d)

Segmentation

91.

Objective 2.1/Day 5 -

A company is implementing a new vulnerability scanning solution that will not require any additional software to be installed on its systems. Which scanning method are they using?

a)

Agent-based scanning

b)

Active scanning

c)

Agentless scanning

d)

Credentialed scanning

92.

Objective 2.1/Day 5 -

An organization responsible for managing a power grid is implementing a vulnerability scanning solution specifically designed for its industrial control systems (ICS). The security team needs to ensure that the scanning does not disrupt critical operations or affect system performance. Which scanning method should the team prioritize?

a)

Active scanning

b)

Passive scanning

c)

Security baseline scanning

d)

Credentialed scanning

93.

Objective 2.1/Day 5 -

A manufacturing company is implementing a new vulnerability scanning program to assess its operational technology (OT) environment, which includes various supervisory control and data acquisition (SCADA) systems. The security team wants to establish a baseline to ensure that these systems remain secure over time. Which approach should they take to achieve this?

a)

Periodic active vulnerability scanning

b)

Continuous monitoring of network traffic

c)

Regular security baseline scanning

d)

External vulnerability assessments

94.

Objective 2.1/Day 5 -

A retail organization is preparing for an upcoming audit and needs to ensure compliance with the Payment Card Industry Data Security Standard (PCI DSS). The security team wants to implement vulnerability scanning methods that align with these requirements. Which action should the team prioritize?

a)

Conducting annual vulnerability assessments

b)

Implementing real-time monitoring of network traffic

c)

Performing regular internal and external vulnerability scans

d)

Developing a comprehensive incident response plan

95.

Objective 2.1/Day 5 -

A financial institution is looking to adopt industry best practices for securing its applications and infrastructure. They plan to utilize the Center for Internet Security (CIS) benchmarks for vulnerability scanning. Which approach should the security team take to implement these benchmarks effectively?

a)

Conduct vulnerability scans without reviewing the benchmarks

b)

Tailor the benchmarks to fit specific organizational needs

c)

Focus solely on external scans to meet benchmark criteria

d)

Use the benchmarks only for external compliance checks

96.

Objective 2.1/Day 5 -

An organization developing a web application is concerned about potential vulnerabilities and wants to follow the Open Web Application Security Project (OWASP) guidelines. They are planning to conduct vulnerability scans to identify risks early in the development process. What should be the primary focus of their scanning efforts?

a)

Scanning for compliance with ISO 27000 series

b)

Identifying and remediating the top ten web application vulnerabilities

c)

Performing external network vulnerability assessments

d)

Implementing firewalls to block threats

97.

Objective 2.1/Day 5 -

Your organization wants to conduct a vulnerability scan on its internal network without causing any disruption to the production systems. The network administrator recommends using an approach that monitors network traffic without actively probing the systems. Which type of scanning method is most appropriate in this scenario?

a)

Passive scanning

b)

Active scanning

c)

Dynamic scanning

d)

Non-credentialed scanning

98.

Objective 2.1/Day 5 -

You are tasked with performing a vulnerability scan on a critical industrial control system (ICS) network to identify potential security weaknesses. The system operates 24/7 and any interruption could have serious operational consequences. Which type of scanning method should you use to minimize the risk of disrupting the ICS network?

a)

Active scanning

b)

Non-credentialed scanning

c)

Passive scanning

d)

Dynamic scanning

99.

Objective 2.1/Day 5 -

An organization needs to ensure compliance with the Payment Card Industry Data Security Standard (PCI DSS) and plans to perform regular vulnerability scans. They want the scans to be thorough and have a higher chance of detecting vulnerabilities that require authentication. Which scanning approach should they adopt?

a)

Agentless scanning

b)

Credentialed scanning

c)

Non-credentialed scanning

d)

Passive scanning

100.

Objective 2.1/Day 5 -

Your company wants to schedule regular vulnerability scans during off-peak hours to avoid impacting system performance during business operations. The goal is to ensure comprehensive coverage without disrupting users. What special consideration is this scenario addressing?

a)

Sensitivity levels

b)

Scheduling

c)

Performance

d)

Segmentation

101.

Objective 2.1/Day 5 -

A security team is deploying a vulnerability scanner across a segmented network to ensure that all segments are thoroughly scanned without missing any systems. Each segment contains different types of devices and systems. Which method will help to ensure that every device is accurately identified and scanned?

a)

Map scans

b)

Device fingerprinting

c)

Dynamic scanning

d)

Non-credentialed scanning

102.

Objective 2.1/Day 5 -

An organization wants to implement vulnerability scanning that aligns with industry best practices and security benchmarks to ensure a robust security posture. They are particularly focused on maintaining high standards and following widely accepted frameworks. Which industry frameworks should the organization consider using for their security baseline scanning?

a)

PCI DSS and CIS benchmarks

b)

OWASP and ISO 27000 series

c)

PCI DSS, CIS benchmarks, OWASP, and ISO 27000 series

d)

None of the above

103.

Objective 2.2/Day 11 -

A security analyst runs a network scan using Angry IP Scanner and receives the following output (See Image):

What does this output indicate about the target system?

a)

The system is not vulnerable since it is offline.

b)

The system is potentially exposed to external attacks via open ports.

c)

The system is completely secure with no open ports.

d)

The system is only accessible via secure protocols.

104.

Objective 2.2/Day 11 -

During a web application assessment, a security analyst uses Burp Suite and observes the following results in the scanner report (See Image):

What should be the analyst's next step regarding these findings?

a)

Ignore the vulnerabilities as they are common.

b)

Immediately exploit the vulnerabilities to confirm them.

c)

Document the vulnerabilities and recommend remediation actions.

d)

Conduct a full network scan to check for additional vulnerabilities.

105.

Objective 2.2/Day 11 -

After running a vulnerability scan with Nessus, an analyst receives the following output for a critical vulnerability (See Image):

What action should the analyst prioritize based on this report?

a)

Upgrade the Apache HTTP Server immediately to mitigate the vulnerability.

b)

Monitor the system for any unusual activity.

c)

Configure firewall rules to block access to the Apache server.

d)

Perform a deeper analysis of the network traffic to this server.

106.

Objective 2.2/Day 11 -

An organization conducts a vulnerability assessment using OpenVAS and identifies several high-severity issues. The report states (See Image):

What should the organization do in response to these findings?

a)

Update Microsoft Office and enforce a stronger password policy.

b)

Wait for the next scheduled assessment to address these issues.

c)

Ignore the findings as they are not immediate threats.

d)

Increase network monitoring for unusual user account activity.

107.

Objective 2.2/Day 11 -

A security analyst uses the GNU Debugger (GDB) to examine a suspicious executable. The following output is observed (See Image):

What does this output suggest about the application being analyzed?

a)

The application is secure and free from vulnerabilities.

b)

The application contains a potential buffer overflow vulnerability.

c)

The application is functioning correctly with no issues.

d)

The application has been successfully patched.

108.

Objective 2.2/Day 11 -

During a penetration test, an analyst utilizes Nmap and receives the following scan results (See Image):

What does this output indicate about the target system?

a)

The system has a firewall blocking all incoming traffic.

b)

The system is a web server with secure SSH access.

c)

The system is not accessible over any protocols.

d)

The system is vulnerable to all detected services.

109.

Objective 2.2/Day 11 -

An organization conducts a cloud infrastructure assessment using Scout Suite. The assessment report indicates (See Image):

What should the organization prioritize based on this report?

a)

Enable logging for all services to monitor usage.

b)

Restrict public access to S3 buckets and review IAM policies.

c)

Increase the number of IAM users for better resource allocation.

d)

Deploy more Lambda functions to enhance cloud performance.

110.

Objective 2.2/Day 11 -

A security analyst runs a vulnerability scan using Metasploit Framework (MSF) and receives the following output (See Image):

What is the appropriate next step for the organization based on this finding?

a)

Apply the patch or disable SMBv1 to mitigate the risk.

b)

Document the finding for future reference.

c)

Continue using SMBv1 as it is commonly used.

d)

Increase network monitoring for SMB traffic.

111.

Objective 2.3/Day 11 -

A security analyst receives a vulnerability report with the following CVSS metrics (See Image):

What is the overall risk level associated with this vulnerability?

a)

Low risk due to the requirement for user interaction.

b)

Medium risk due to the high confidentiality impact.

c)

High risk due to the network attack vector and low privileges required.

d)

Critical risk due to the low attack complexity and unchanged scope.

112.

Objective 2.3/Day 11 -

An organization discovers a vulnerability with the following characteristics (See Image):

Based on this information, how should the organization prioritize this vulnerability?

a)

High priority due to the potential for significant impact on integrity and availability.

b)

Medium priority due to the high attack complexity and local attack vector.

c)

Low priority as it requires high privileges and user interaction.

d)

Critical priority due to the low confidentiality impact.

113.

Objective 2.3/Day 11 -

A vulnerability scan identifies two vulnerabilities in a web application (See Image):

How should the analyst prioritize these vulnerabilities?

a)

Prioritize Vulnerability A as it has a higher CVSS score and does not require user interaction.

b)

Prioritize Vulnerability B due to its lower CVSS score and local attack vector.

c)

Treat both vulnerabilities equally as they are both important.

d)

Focus only on Vulnerability B since user interaction is required for exploitation.

114.

Objective 2.3/Day 11 -

After reviewing incident reports, an analyst notices discrepancies between the reported vulnerabilities and the actual security posture. Some vulnerabilities were flagged but had no exploitation attempts, while others were not flagged but were exploited. This leads to a concern about:

a)

True positives and false negatives in the vulnerability assessment process.

b)

True negatives and false positives in the security monitoring tools.

c)

The need for additional training for the security team.

d)

The effectiveness of the organization's incident response plan.

115.

Objective 2.3/Day 11 -

A security analyst is assessing vulnerabilities in a company's network and finds the following (See Image):

Given this information, which vulnerability should the analyst prioritize first?

a)

Vulnerability A due to its high CVSS score and external exposure.

b)

Vulnerability B because it has a lower CVSS score but is internal.

c)

Vulnerability C because zero-day vulnerabilities can be exploited immediately.

d)

All vulnerabilities should be prioritized equally as they all pose risks.

116.

Objective 2.3/Day 11 -

An organization has discovered a critical vulnerability in a widely used internal application that stores sensitive customer data. The application is isolated from the internet, and no external access is allowed. The CVSS score for the vulnerability is 8.0. What should be the organization's approach to prioritize this vulnerability?

a)

Treat it as a lower priority due to its isolation from external threats.

b)

Prioritize it highly because of the sensitive data involved and high CVSS score.

c)

Address it only if there are signs of exploitation attempts.

d)

Defer remediation until after addressing external vulnerabilities.

117.

Objective 2.3/Day 11 -

A vulnerability assessment identifies an external-facing service with a medium CVSS score of 5.5. However, this service is critical for business operations and serves many users. In contrast, an internal vulnerability with a high CVSS score of 9.0 exists on a system used by a limited number of employees. How should the organization prioritize these vulnerabilities?

a)

Prioritize the external-facing service due to its lower CVSS score and critical business need.

b)

Focus on the internal vulnerability first due to its higher CVSS score and potential impact.

c)

Treat both vulnerabilities equally since they serve different purposes.

d)

Prioritize the internal vulnerability last as it affects fewer users.

118.

Objective 2.3/Day 11 -

A security team is reviewing vulnerabilities in their systems and discovers several zero-day vulnerabilities that have not been publicly disclosed yet. The team must decide how to address these vulnerabilities effectively. What should be the team’s primary consideration when prioritizing these vulnerabilities?

a)

The potential impact on assets if the vulnerabilities were exploited.

b)

The number of users affected by the vulnerabilities.

c)

The length of time the vulnerabilities have been known.

d)

The existence of any public exploits for these vulnerabilities.

119.

Objective 2.2/Day 11 -

A security analyst is reviewing the output from a vulnerability assessment tool used to scan the organization's network. The tool has identified several open ports and services on a particular server. Which tool is most likely used to identify open ports and services during the network scanning process?

a)

Maltego

b)

Nikto

c)

Nessus

d)

Nmap

120.

Objective 2.2/Day 11 -

A web application security tester is analyzing the output generated by a scanning tool used to assess the security posture of a web application. The tool has identified multiple instances of cross-site scripting (XSS) vulnerabilities in the application. Which tool is specifically designed to detect common web application vulnerabilities such as cross-site scripting (XSS)?

a)

Burp Suite

b)

Maltego

c)

Nessus

d)

Metasploit framework

121.

Objective 2.2/Day 11 -

A system administrator is reviewing the results from a vulnerability scan performed on the organization's servers. The scan report includes detailed information about missing patches, configuration issues, and potential security vulnerabilities. Which tool is commonly used to perform comprehensive vulnerability scans and provide detailed reports on system vulnerabilities?

a)

Angry IP Scanner

b)

Metasploit framework

c)

OpenVAS

d)

Immunity debugger

122.

Objective 2.2/Day 11 -

A security analyst is analyzing the output from a debugging tool used during the investigation of a suspicious program behavior. The tool provides real-time information about the program's memory, registers, and execution flow. Which type of tool is likely to provide real-time information about a program's memory, registers, and execution flow during debugging?

a)

GNU debugger (GDB)

b)

Pacu

c)

Zed Attack Proxy (ZAP)

d)

Recon-ng

123.

Objective 2.2/Day 11 -

A penetration tester is conducting a security assessment of a client's network infrastructure. As part of the assessment, the tester is using a tool that combines network discovery, vulnerability scanning, and exploitation capabilities. Which multipurpose tool is commonly used by penetration testers to perform network discovery, vulnerability scanning, and exploitation?

a)

Maltego

b)

Nessus

c)

Nmap

d)

Metasploit framework

124.

Objective 2.2/Day 11 -

A cloud security engineer is tasked with assessing the security posture of the organization's cloud infrastructure deployed on AWS. The engineer plans to use a tool that provides automated assessment capabilities specifically tailored for cloud environments. Which tool is most suitable for assessing the security of cloud infrastructure and automating security assessments in AWS?

a)

Burp Suite

b)

Pacu

c)

Maltego

d)

Recon-ng

125.

Objective 2.3/Day 11 -

A healthcare company prioritizes maintaining the confidentiality of patient data within its systems. A security analyst must prioritize vulnerabilities for remediation based on the CVSS impact metrics for the system. Which of the following vulnerabilities should be given priority for remediation? (See Image)

a)

Vulnerability 1

b)

Vulnerability 2

c)

Vulnerability 3

d)

Vulnerability 4

126.

Objective 2.3/Day 11 -

A vulnerability is currently being exploited and requires no user interaction or elevated privileges. It significantly impacts integrity and availability but has no effect on confidentiality. Which of the following CVE metrics would best capture the characteristics of this vulnerability?

a)

CVSS:/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

b)

CVSS:/AV:P/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H

c)

CVSS:/AV:A/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:L

d)

CVSS:/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N

127.

Objective 2.3/Day 11 -

A vulnerability is currently being exploited, requiring no user interaction but demanding elevated privileges. It highly impacts integrity but has no impact availability. It also has a low impact on confidentiality. Which of the following CVE metrics would best capture the characteristics of this vulnerability?

a)

CVSS:/AV:P/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:L

b)

CVSS:/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

c)

CVSS:/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:N/A:H

d)

CVSS:/AV:A/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N

128.

Objective 2.3/Day 11 -

A vulnerability assessment has flagged a critical vulnerability in a web server. The security analyst needs to determine if the vulnerability is a false positive. The initial investigation reveals that the conditions required for the vulnerability to be exploited are not present on the server. What should the security analyst classify this vulnerability as?

a)

True positive

b)

False positive

c)

True negative

d)

False negative

129.

Objective 2.3/Day 11 -

A company uses a proprietary application critical to its operations. A recent vulnerability scan shows a medium-severity vulnerability in the application. However, the application's role in business operations significantly increases its value to the company. How should the security analyst prioritize this vulnerability?

a)

Low priority

b)

Medium priority

c)

High priority

d)

Ignore the vulnerability

130.

Objective 2.3/Day 11 -

During a routine security scan, a zero-day vulnerability is discovered in a widely-used operating system. This vulnerability can be easily weaponized, and an exploit has already been observed in the wild. What should be the immediate action taken by the security analyst?

a)

Ignore the vulnerability until a patch is released

b)

Validate if the zero-day is a false positive

c)

Apply available mitigations and monitor for any signs of exploitation

d)

Wait for further instructions from the operating system vendor

131.

Objective 2.4/Day 12 -

A web application is susceptible to reflected cross-site scripting (XSS) attacks, allowing attackers to inject malicious scripts into URLs that are subsequently executed in users' browsers. What control should the development team implement to mitigate this type of vulnerability?

a)

Input validation and sanitization

b)

Implementing a Content Security Policy (CSP)

c)

Using secure cookies

d)

Session management practices

132.

Objective 2.4/Day 12 -

An organization has identified that its application is vulnerable to stack overflow vulnerabilities, which could allow attackers to execute arbitrary code. Which control should be recommended to mitigate the risk associated with this type of vulnerability?

a)

Input validation

b)

Implementing address space layout randomization (ASLR)

c)

Data encryption

d)

Regular security training for developers

133.

Objective 2.4/Day 12 -

A security analyst discovers that an application is vulnerable to data poisoning attacks, where attackers can manipulate input data to compromise the integrity of the application. Which control should be recommended to mitigate this risk?

a)

Implementing rate limiting

b)

Data validation and sanitization

c)

Role-based access control (RBAC)

d)

Logging and monitoring

134.

Objective 2.4/Day 12 -

A recent security audit revealed broken access control vulnerabilities in a web application, allowing users to access resources and functionalities they should not be able to. What control should be recommended to address this issue?

a)

Input validation

b)

Session management practices

c)

Implementing proper authorization checks

d)

Using HTTPS for data transmission

135.

Objective 2.4/Day 12 -

A security analyst has discovered that an application is susceptible to cryptographic failures, specifically due to the use of weak encryption algorithms. Which control should be recommended to mitigate the risk associated with this vulnerability?

a)

Implementing strong encryption standards such as AES

b)

Using hash functions for all sensitive data

c)

Limiting user input to prevent injection attacks

d)

Regularly updating software dependencies

136.

Objective 2.4/Day 12 -

A web application is vulnerable to SQL injection attacks, allowing attackers to manipulate database queries through user inputs. What control should be implemented to mitigate the risk of injection flaws in this application?

a)

Input validation and parameterized queries

b)

Session management practices

c)

Implementing a Content Security Policy (CSP)

d)

Data encryption in transit

137.

Objective 2.4/Day 12 -

During a security review, a vulnerability related to cross-site request forgery (CSRF) is identified in a web application that allows unauthorized actions to be performed on behalf of authenticated users. Which control should be recommended to mitigate this type of vulnerability?

a)

Using SameSite cookies

b)

Implementing input validation

c)

Utilizing encryption for data storage

d)

Restricting access based on IP address

138.

Objective 2.4/Day 12 -

A company has recently discovered that its web application is vulnerable due to insecure design practices, allowing attackers to bypass security controls easily. What control should be implemented to mitigate the risk associated with insecure design?

a)

Conduct regular security reviews and threat modeling

b)

Apply patches to outdated software components

c)

Implement multi-factor authentication (MFA)

d)

Configure firewalls to block unauthorized access

139.

Objective 2.4/Day 12 -

During a routine security audit, it was found that several servers were not configured securely, leaving them exposed to potential attacks. Which control should be recommended to mitigate risks associated with security misconfiguration?

a)

Perform regular configuration audits and hardening

b)

Update the operating system to the latest version

c)

Increase network bandwidth for better performance

d)

Use weak passwords to allow easier access

140.

Objective 2.4/Day 12 -

An organization is still using a legacy application that has reached its end-of-life and is no longer supported by the vendor. What control should be recommended to mitigate risks associated with using outdated components?

a)

Upgrade to a newer, supported version of the application

b)

Implement additional firewalls around the legacy application

c)

Increase user access rights to improve productivity

d)

Disable logging to prevent unnecessary data storage

141.

Objective 2.4/Day 12 -

A web application allows users to submit URLs that the server fetches and processes. An attacker has discovered that they can manipulate the URL to make the server perform requests to internal resources. What control should be implemented to mitigate the risk of Server-Side Request Forgery (SSRF)?

a)

Validate and sanitize user input for URLs

b)

Implement strong access controls on internal resources

c)

Use a web application firewall (WAF)

d)

Regularly update server software and libraries

142.

Objective 2.4/Day 12 -

A security analyst discovers that a web application is vulnerable to Remote Code Execution (RCE) due to inadequate input validation. An attacker can send crafted inputs that allow them to execute arbitrary code on the server. What control should be recommended to mitigate this vulnerability?

a)

Use application-level firewalls

b)

Implement strict input validation and output encoding

c)

Increase logging verbosity for application activities

d)

Limit user access to the application

143.

Objective 2.4/Day 12 -

A user account has been compromised, allowing the attacker to gain higher privileges within the application. The organization needs to mitigate the risk of privilege escalation attacks. Which control should be recommended?

a)

Conduct regular audits of user privileges

b)

Allow users to have admin access for flexibility

c)

Disable two-factor authentication (2FA) for ease of access

d)

Implement a password expiration policy for all users

144.

Objective 2.4/Day 12 -

A web application is vulnerable to cross-site scripting (XSS) attacks where malicious scripts are reflected back to the user. This has led to several incidents of data theft from user sessions. Which control would be most effective in mitigating this type of attack?

a)

Implementing input validation and output encoding

b)

Using secure cryptographic algorithms

c)

Disabling unused services and ports

d)

Applying principle of least privilege to user accounts

145.

Objective 2.4/Day 12 -

A server was compromised through a buffer overflow vulnerability, allowing attackers to execute arbitrary code. Which control is most appropriate to prevent buffer overflow attacks?

a)

Using parameterized queries

b)

Implementing data execution prevention (DEP)

c)

Enforcing multi-factor authentication (MFA)

d)

Conducting regular vulnerability scans

146.

Objective 2.4/Day 12 -

An application allows for unrestricted file uploads, leading to a remote file inclusion (RFI) vulnerability being exploited. Which control should be implemented to mitigate this vulnerability?

a)

Enforcing strict file type validation and scanning uploaded files for malware

b)

Implementing HTTPS across the application

c)

Enforcing password complexity requirements

d)

Disabling directory browsing on the web server

147.

Objective 2.4/Day 12 -

A web application is susceptible to SQL injection attacks, which has allowed attackers to manipulate the database and extract sensitive information. Which control would best mitigate this type of attack?

a)

Implementing input validation and parameterized queries

b)

Encrypting sensitive data at rest

c)

Disabling directory indexing

d)

Using a web application firewall (WAF)

148.

Objective 2.4/Day 12 -

A company's web application has a vulnerability that allows unauthorized users to access restricted directories and files through directory traversal attacks. Which control would most effectively mitigate this vulnerability?

a)

Implementing access control lists (ACLs) and input validation

b)

Using strong encryption for data in transit

c)

Enforcing password expiration policies

d)

Implementing secure session management

149.

Objective 2.4/Day 12 -

An organization has identified several outdated components in its web application stack, which are vulnerable to remote code execution (RCE) attacks. Which control is most appropriate to address this issue?

a)

Regularly updating and patching software components

b)

Implementing network segmentation

c)

Enforcing multi-factor authentication (MFA)

d)

Conducting regular security awareness training

150.

Objective 2.5/Day 1 -

Which of the following is an example of a compensating control used to address a vulnerability until a permanent fix is implemented?

a)

Implementing a firewall to block unauthorized access

b)

Applying a software patch to address the vulnerability

c)

Restricting access to sensitive systems based on user roles

d)

Using multi-factor authentication (MFA) to enhance security

151.

Objective 2.5/Day 1 -

What type of control is designed to detect and respond to security incidents by identifying anomalies or unauthorized activities?

a)

Managerial

b)

Operational

c)

Technical

d)

Detective

152.

Objective 2.5/Day 1 -

During a scheduled maintenance window, a recent software update causes critical issues and needs to be undone. What is the appropriate step in the patch management process to address this situation?

a)

Testing

b)

Implementation

c)

Validation

d)

Rollback

153.

Objective 2.5/Day 1 -

Which of the following is an essential component of governance that helps ensure that security policies align with organizational objectives?

a)

Service Level Objectives (SLOs)

b)

Threat Modeling

c)

Penetration Testing

d)

Bug Bounty Programs

154.

Objective 2.5/Day 1 -

What is the primary focus of attack surface management in a security context?

a)

Identifying vulnerabilities in existing systems

b)

Reducing the number of potential entry points for attackers

c)

Evaluating the effectiveness of security controls

d)

Implementing secure coding practices

155.

Objective 2.5/Day 1 -

Which secure coding practice is specifically designed to prevent injection attacks by ensuring that user input is treated as data rather than executable code?

a)

Output Encoding

b)

Session Management

c)

Input Validation

d)

Parameterized Queries

156.

Objective 2.5/Day 1 -

Your organization needs to address a vulnerability that cannot be patched immediately due to operational constraints. A temporary solution is required to mitigate the risk until a permanent fix can be applied. Which type of control would best describe this temporary solution?

a)

Preventative control

b)

Compensating control

c)

Detective control

d)

Corrective control

157.

Objective 2.5/Day 1 -

During a vulnerability assessment, a critical security flaw is discovered in your organization's main web application. The vulnerability needs to be addressed, but the fix could impact business operations. Which step in the patching and configuration management process involves ensuring that the patch does not negatively affect the application's functionality?

a)

Implementation

b)

Testing

c)

Rollback

d)

Validation

158.

Objective 2.5/Day 1 -

Your security team is tasked with reducing the attack surface of the organization's network. This includes identifying and addressing any unnecessary services and open ports. Which activity is most closely associated with attack surface reduction?

a)

Passive discovery

b)

Penetration testing

c)

Security controls testing

d)

Edge discovery

159.

Objective 2.5/Day 1 -

A security analyst is reviewing the organization's policies and governance structures to ensure they align with service-level objectives (SLOs) for incident response times. Which control type is being evaluated in this scenario?

a)

Technical

b)

Operational

c)

Managerial

d)

Corrective

160.

Objective 2.5/Day 1 -

Your company has identified a security vulnerability in a third-party library used in multiple applications. The vendor has not yet released a patch. As a result, your team must determine how to manage the associated risk. Which risk management principle involves deciding to use a compensating control until a patch is available?

a)

Accept

b)

Transfer

c)

Avoid

d)

Mitigate

161.

Objective 2.5/Day 1 -

A new web application is being developed, and the development team needs to ensure that the application is secure from common vulnerabilities such as SQL injection and cross-site scripting (XSS). Which secure coding best practices should the development team implement to prevent these vulnerabilities?

a)

Session management and data protection

b)

Input validation and output encoding

c)

Authentication and parameterized queries

d)

Secure SDLC and threat modeling