Font size
Worksheets500+
Total questions: 189
Worksheet time: 2hrs 37mins
(!)An organization implements a fail-open inbound firewall for a new website. Which goal are they most likely prioritizing?
(!) To decrease the number of false-positive phishing reports flooding the help desk, which solution should be implemented?
Company data can be accounted for when the employee leaves the organization.
The administrator is implementing new design to:
● Provide a secure zone.
● Enforce a company-wide access control policy.
● Reduce the scope of threats.
What type of environment is the systems administrator setting up?
The device is unable to receive authorized updates.
A system administrator is notified that the internal file server is experiencing significant slowdowns and only functions sporadically. The system administrator checks the server management tool and uncovers the following details regarding the server:
Which of the following indicators most likely triggered this alert?
While examining log files, a security administrator comes across the following code snippet:
Which option most accurately explains the vulnerability that is being exploited?
A company intends to enhance the security of its systems by:
• Preventing users from sending sensitive data over corporate email
• Restricting access to potentially harmful websites
Which features should the company implement? (Choose two.)
While investigating an incident, a security administrator reviewed a web server log and noticed the following entries:
"GET ../../../../etc/passwd"
What type of attack did the security administrator most likely detect?
MFA
VPN
During a network services assessment, a security administrator recorded the following information:
After two weeks, the administrator reviewed the logs again and observed that the records had been modified as follows:
After confirming with the service owner that the new address doesn’t belong to the company network, what is the most probable issue the company is facing?
A company offers long-term cold storage services to banks that must comply with regulatory data retention requirements. These banks require that data be destroyed in a specific way once the retention period ends. Which aspect of data management is most critical to the bank when ensuring proper data destruction?
The physical security team has received complaints that employees are not showing their badges and have witnessed tailgating at secured entrances. What topic is the security team most likely to focus on during upcoming training sessions?
While reviewing logs, an analyst finds proof of successful injection attacks. What action would be most effective in preventing these attacks in the future?
After receiving an alert about an attempted download of known malware, which action would provide the best opportunity to analyze the malware?
Review the IPS logs and determine which command-and-control IPs were blocked.
Analyze application logs to see how the malware attempted to maintain persistence.
Run vulnerability scans to check for systems and applications that are vulnerable to the malware
Obtain and execute the malware in a sandbox environment and perform packet captures.
What should be implemented to make sure a user has the appropriate permissions required to perform their assigned job functions effectively?
An employee gets a text from an unknown number pretending to be the CEO, requesting the purchase of gift cards. What type of attack does this represent?
An employee receives an unusual email from the CEO’s corporate account requesting financial details and a change to the contact number. Which attack vector is most likely involved in this scenario?
What should an organization implement to be able to assess the controls and performance of its service providers or vendors?
Which metric is used to determine the impact or loss to an organization from a single cybersecurity incident?
When a retail company receives a request to delete a customer's data, what role does the company hold under GDPR regulations?
Despite deploying web-filtering tools, users are still accessing malicious websites. Which configuration setting should the security administrator check to address this issue?
A security analyst is examining following logs related to suspicious VPN login activity for a user;
Which of the following malicious activity indicators triggered the alert?
In the incident response process, which phase focuses on reducing the impact and disruption caused by the incident?
