WorksheetsCompTIA Security + (Part 1)
Total questions: 20
Worksheet time: 23mins
A company's IT department considers different approaches to obtaining digital certificates for its internal network infrastructure. The IT department evaluated the use of a Certificate Signing Request (CSR) and third-party Certificate Authorities (CAs) to meet their security requirements. What is the primary advantage of using a CSR and a third-party CA for obtaining digital certificates compared to other methods?
Using a Certificate Signing Request and a third-party Certificate Authority allows for faster deployment of digital certificates within the network.
Using a Certificate Signing Request and a third-party Certificate Authority eliminates the need for regular certificate renewals and maintenance.
Digital certificates obtained through a Certificate Signing Request and a third-party Certificate Authority provide stronger encryption algorithms and key lengths.
Digital certificates obtained through a Certificate Signing Request and a third-party Certificate Authority have a higher level of trust and recognition within the industry.
An educational institution plans to transition from a traditional to a digital learning system. The school's administration has assembled a Change Management Board (CMB) to ensure smooth and secure execution. Within the scope of this educational institution's digital transformation project, what would be the primary role of the CMB?
Overseeing the daily operations of the school's IT department
Conducting cybersecurity awareness training for all school staff
Assessing, approving, and managing changes in the IT infrastructure
Developing and implementing the school's digital learning curriculum
An educational institution plans to transition from a traditional to a digital learning system. The school's administration has assembled a Change Management Board (CMB) to ensure smooth and secure execution. Within the scope of this educational institution's digital transformation project, what would be the primary role of the CMB?
Overseeing the daily operations of the school's IT department
Conducting cybersecurity awareness training for all school staff
Assessing, approving, and managing changes in the IT infrastructure
Developing and implementing the school's digital learning curriculum
A global e-commerce company faces challenges with its legacy monolithic application. The application is becoming increasingly difficult to maintain due to its intertwined components and struggles to scale quickly enough to handle sudden traffic surges during big sales events. The company has already invested in cloud technology and on-premises infrastructure but still faces scalability and manageability issues. What would MOST effectively address these challenges?
Virtualization
Serverless infrastructure
Microservices
Embedded systems
Experts at a scientific facility suspect that operatives from another government entity planted malware and are spying on one of their top secret systems. Which attacker type is likely responsible based on the attacker's location and likely goals?
Criminal syndicates
State actors
Hacktivists
Unskilled attackers
A cyber group is reviewing its web filtering capabilities after a recent breach. Which centralized web-filtering technique groups websites into categories such as social networking, gambling, and webmail?
Content categorization
Block rules
Uniform resource locators (URL) scanning
Reputation-based filtering
An organization wants to enhance its cybersecurity by implementing web filtering. The company needs a solution that provides granular control over web traffic, ensures policy enforcement even when employees are off the corporate network, and can log and analyze Internet usage patterns. Which of the following strategies BEST meets these requirements?
Manual uniform resource locators (URLs) blocking
Centralized web filtering
Agent-based filtering
Reputation-based filtering
A company is looking to expand its business into new markets despite associated risks. It prepares to accept higher risks for potentially higher returns. Which of the following approaches BEST meets the company's risk management approach parameters?
Risk appetite
Risk mitigation
Risk intolerance
Risk threshold
A tech company is in the process of decommissioning a fleet of old servers. It wants to ensure that sensitive data stored on these servers is fully eliminated and are not accesible in the event of unauthorized attempts. What primary process should the company implement before disposing or repurposing these servers?
Moving the servers to a secure storage location
Selling the servers immediately
Sanitizing the servers
Deleting all the files on the servers
A network security administrator for a mid-sized enterprise must enhance the company’s security posture. The existing infrastructure includes a network with several connected devices, a firewall, and a virtual private network (VPN) for remote access. People have raised concerns about the potential attack surface, especially from inside threats. The enterprise recently shifted toward a hybrid working model, amplifying the need for secure remote access. The task requires implementing a solution that secures the enterprise infrastructure and ensures secure communication and access. Which approach should the network security administrator take to meet the company's needs?
Implement 802.1X for port security.
Establish a jump server for secure communication.
Replace the current firewall with a Next Generation Firewall (NGFW).
Configure an intrusion prevention system (IPS).
A network administrator configures the security for data transmitted by employees working remotely. The data includes personal employee information such as addresses and phone numbers. Which category does this scenario BEST fit?
Confidential
Private
Regulated
Public
A nationwide company is preparing to overhaul its encryption protocols due to newly released options that can quickly protect all data. It is leaning towards an encryption standard that will allow faster processing as it does not require Operating System intervention to encrypt the data. What standard will the company be employing?
Self-encrypting drives
Opal Storage Specification
Key-encryption key
Full Disk Encryption
A network administrator at a large tech company has the task of enhancing the visibility into network traffic patterns in a distributed enterprise network. The administrator wants to implement a solution that captures metadata and statistics about network traffic without recording each frame, with the goal of improving the company’s security measures. Which tool should the administrator consider implementing?
A vulnerability scanner
A NetFlow collector
A data loss prevention (DLP)
A simple network management protocol (SNMP) trap
A global financial institution with a vast network of offices and data centers has faced increasing cybersecurity threats. The organization's IT team realizes that privileged accounts are a prime target for hackers, and manually managing them poses a significant risk. The company implemented a Privileged Access Management (PAM) solution to strengthen its security posture. As part of the implementation, the IT team focuses on password vaulting, a critical component of PAM. As part of the advanced PAM implementation, which of the following options depicts the primary purpose of password vaulting?
Enforcing strong password policies
Automatically generate and assign passwords for all users
Complying with regulatory requirements
Securely store and manage privileged account credentials
CloudSecure is facing a cybersecurity challenge where some of its critical software applications are no longer supported by vendors, making them vulnerable to potential exploits. The IT team is exploring various strategies to mitigate the risk posed by these unsupported apps. What’s the MOST effective approach to enhance the security posture?
Ignoring the vulnerability as it can only be exploited in specific circumstances.
Consolidating all operating systems and applications into one product.
Implementing regular patch management to fix the faulty code.
Isolating the unsupported apps from other systems to reduce the attack surface.
When performing forensic investigation in public clouds, what document would contain the right-to-audit clause and give the investigator the authority to audit files on the network?
Service Level Agreement (SLA)
Supply chain analysis
Forensic reports
Checksums
An organization's IT security team has discovered that a recent software update, unknowingly deployed, contained a zero-day exploit. This vulnerability has now made the company's systems susceptible to potential unauthorized access. Which of the following immediate actions should the security team execute to manage this zero-day exploit situation?
Isolate the impacted systems and apply a patch or remediation strategy.
Contact all clients and inform them about the security breach.
Reformat all affected systems and restore data from backup.
Disconnect the company's entire network from the internet.
A group of threat actors disrupts the online services of an oil company due to their disagreement with the company's environmental policies. They believe their actions can force the company to change its practices. This type of threat actor is primarily driven by what kind of motivation?
Political/philosophical beliefs
Espionage
Financial gain
Service disruption
A medium-sized organization is designing a new network infrastructure. The IT manager wants to minimize the attack surface without sacrificing connectivity. Which of the following measures would be MOST effective in achieving this goal?
Implementing a Web Application Firewall (WAF)
Deploying network appliances in different security zones
Applying port security measures to control network access
Setting up a Software-Defined Wide Area Network (SD-WAN)
A multinational corporation operates in several countries with diverse regulations regarding data privacy and security. What is the primary responsibility of the security team concerning the multitude of governmental and regulatory entities influencing the corporation's operations?
Shaping internal policies independently from external regulations
Ensuring compliance with all applicable regulations and laws
Avoiding any interaction with regulatory entities to maintain operational secrets
Lobbying governmental entities for favorable policies
