wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

500+

Total questions: 189

Worksheet time: 2hrs 37mins

Name
Class
Date
1.
Where is unencrypted network traffic most commonly encountered?
a)
SDN
b)
IoT
c)
VPN
d)
SCADA
2.
What is the primary purpose of conducting a tabletop exercise?
a)
To address audit findings
b)
To collect remediation response times
c)
To update the IRP
d)
To calculate the ROI
3.
What is the purpose of using CVSS?
a)
To determine the cost associated with patching systems
b)
To identify unused ports and services that should be closed
c)
To analyze code for defects that could be exploited
d)
To prioritize the remediation of vulnerabilities
4.
A company is preparing for a new product release and selects a marketing firm owned by the CEO’s close relative. What policy has most likely been violated?
a)
Independent assessments
b)
Supply chain analysis
c)
Right-to-audit clause
d)
Conflict of interest policy
5.

(!)An organization implements a fail-open inbound firewall for a new website. Which goal are they most likely prioritizing?

a)
Confidentiality
b)
Non-repudiation
c)
Availability
d)
Integrity
6.
What is the best way for an engineer to verify that a script remains unchanged before execution?
a)
Masking
b)
Obfuscation
c)
Hashing
d)
Encryption
7.
What is the most crucial element to consider when designing a security governance structure?
a)
Discovering and documenting external considerations
b)
Developing procedures for employee onboarding and offboarding
c)
Assigning roles and responsibilities for owners, controllers, and custodians
d)
Designing and monitoring change management procedures
8.
Why would a contractor check the motherboards of newly purchased servers for physical changes?
a)
Embedded rootkit
b)
Supply chain
c)
Firmware failure
d)
RFID keylogger
9.
What kind of risk or threat might be introduced during the sideloading process?
a)
User impersonation
b)
Rootkit
c)
On-path attack
d)
Buffer overflow
10.
While a school district conducts state exams, all internet services suddenly become unavailable. A security analyst detects ARP poisoning on the network and blocks the offending device. Which entity is most likely behind this attack?
a)
Unskilled attacker
b)
Shadow IT
c)
Insider threat
d)
Nation-state
11.
A user types https://comptiatraining.com manually but notices the website looks different from the usual company site. What is the most probable reason for this discrepancy?
a)
Cross-site scripting
b)
Pretexting
c)
Typosquatting
d)
Vishing
12.
A company works with a service provider annually using consistent terms and wants to review those terms every three years. Which document best establishes these general terms?
a)
MSA
b)
NDA
c)
MOU
d)
SLA
13.
When updating security awareness training, what advice should be included to handle risks from compromised vendor email accounts?
a)
Refrain from clicking on images included in emails from new vendors
b)
Delete emails from unknown service provider partners.
c)
Require that invoices be sent as attachments
d)
Be alert to unexpected requests from familiar email addresses
14.
To comply with a policy requiring MFA for resource access, what technology or system should the company deploy? (Choose two.)
a)
Authentication tokens
b)
Least privilege
c)
Biometrics
d)
LDAP
e)
Password vaulting
15.
A help desk worker gets a call from someone pretending to be the CEO asking for a password reset. What type of incident is this?
a)
Vishing
b)
Hacktivism
c)
Blackmail
d)
Misinformation
16.

(!) To decrease the number of false-positive phishing reports flooding the help desk, which solution should be implemented?

a)
Performing more phishing simulation campaigns
b)
Improving security awareness training
c)
Hiring more help desk staff
d)
Implementing an incident reporting web page
17.
To secure sensitive information with a technology that allows data recovery, which option is most appropriate?
a)
Hardware security module
b)
Hashing algorithm
c)
Tokenization
d)
Steganography
18.
A systems administrator wants to encrypt all data stored on employee laptops. What type of encryption should be applied?
a)
Volume
b)
Partition
c)
Full disk
d)
File
19.
What is the most effective step to take when a vulnerability is discovered on a company’s web server?
a)
Patching
b)
Segmentation
c)
Decommissioning
d)
Monitoring
20.
Following an incident where 50 employees clicked a link from an email sent by IT, which action best enhances the company’s security against accidental malware introduction?
a)
Social engineering training
b)
SPF con]guration
c)
Simulated phishing campaign
d)
Insider threat awareness
21.
A penetration test reveals SMBv1 is active on several servers. What is the most efficient way for the organization to fix this vulnerability?
a)
GPO
b)
ACL
c)
SFTP
d)
DLP
22.
Which solution most effectively safeguards sensitive information during transmission over a dispersed infrastructure?
a)
Encryption
b)
Masking
c)
Tokenization
d)
Obfuscation
23.
To meet compliance audits, servers must be segmented into separate networks and only accessible from approved internal systems. What solution achieves this?
a)
Configure firewall rules to block external access to Internal resources.
b)
Set up a WAP to allow internal access from public networks.
c)
Implement a new IPSec tunnel from internal resources.
d)
Deploy an internal jump server to access resources.
24.
What is the first step in compiling a list of vulnerabilities within an IT environment?
a)
Automated scanning
b)
Penetration testing
c)
Threat hunting
d)
Log aggregation
e)
Adversarial emulation
25.
What measures can be implemented to reduce attacks originating from high-risk geographic areas?
a)
Obfuscation
b)
Data sovereignty
c)
IP geolocation
d)
Encryption
26.
Which components are most important to assess when implementing Zero Trust within the data plane?
a)
Secured zones
b)
Subject role
c)
Adaptive identity
d)
Threat scope reduction
27.
What security advantages come from labeling laptops with asset tags and linking them to employee IDs? (Choose two.)
a)
If a security incident occurs on the device, the correct employee can be notified.
b)
The security team will be able to send user awareness training to the appropriate device.
c)
Users can be mapped to their devices when configuring software MFA tokens.
d)
User-based firewall policies can be correctly targeted to the appropriate laptops.
e)

Company data can be accounted for when the employee leaves the organization.

28.
What factors are essential to consider when planning a high-availability network design? (Select two).
a)
Ease of recovery
b)
Ability to patch
c)
Physical isolation
d)
Responsiveness
e)
Attack surface
29.
What mechanism enables linking messages directly to specific individuals?
a)
Adaptive identity
b)
Non-repudiation
c)
Authentication
d)
Access logs
30.
What automation method can help ensure new user accounts have consistent access and permissions?
a)
Guard rail script
b)
Ticketing workflow
c)
Escalation script
d)
User provisioning script
31.

The administrator is implementing new design to:
● Provide a secure zone.
● Enforce a company-wide access control policy.
● Reduce the scope of threats.

What type of environment is the systems administrator setting up?

a)
Zero Trust
b)
AAA
c)
Non-repudiation
d)
CIA
32.
What method is used to verify the authenticity of a certificate shown to a user?
a)
OCSP
b)
CSR
c)
CA
d)
CRC
33.
An organization turned off unnecessary services and installed a firewall to protect a vital legacy system. Which of the following best describes these measures?
a)
Exception
b)
Segmentation
c)
Risk transfer
d)
Compensating controls
34.
Which of the following situations would justify an engineer recommending the decommissioning of a network device? (Select two).
a)
The device has been moved from a production environment to a test environment.
b)
The device is configured to use cleartext passwords.
c)
The device is moved to an isolated segment on the enterprise network.
d)

The device is unable to receive authorized updates.

e)
The device's encryption level cannot meet organizational standards.
35.
A company must conduct a risk assessment every year. What type of risk assessment does this requirement represent?
a)
Continuous
b)
Ad hoc
c)
Recurring
d)
One time
36.
Which solution most effectively minimizes downtime and data loss for businesses operating essential IT equipment in areas at high risk of earthquakes?
a)
Generators and UPS
b)
Off-site replication
c)
Redundant cold sites
d)
High availability networking
37.
After users reported a failed VPN connection, investigators discovered traffic was redirected to a rogue IP to harvest login details. What security control would have been most effective in stopping this attack initially?
a)
Enabling MFA for DNS admin accounts
b)
Deploying updates to VPN agents sooner
c)
Using honeypots to detect network attacks
d)
Patching the VPN servers to the latest version
38.
When updating a password policy enterprise-wide for rapid deployment, which operating system security mechanism would an administrator typically employ?
a)
Deploying PowerShell scripts
b)
Pushing GPO update
c)
Enabling PAP
d)
Updating EDR profiles
39.
Despite web services being up, they're inaccessible because of a sudden traffic spike. Which attack is most likely occurring?
a)
Logic bomb
b)
Brute-force
c)
Buffer overflow
d)
DDoS
40.
When reassigning a former employee's laptop, what is the optimal sequence of data-handling steps a security administrator should follow? (Select two).
a)
Data retention
b)
Certification
c)
Destruction
d)
Classification
e)
Sanitization
41.
What methods are effective for detecting adversaries that have gained unauthorized access to a network? (Select two).
a)
Tokenization
b)
CI/CD
c)
Honeypots
d)
Threat modeling
e)
DNS sinkhole
42.
A traveler logs into an airline website via airport Wi-Fi, dismisses a security alert, and buys a seat upgrade. Later, fraudulent credit card transactions appear. Which attack most likely caused this?
a)
Replay attack
b)
Memory leak
c)
Buffer overflow attack
d)
On-path attack
43.
A network engineer implemented a redundant switch stack for high availability but could only afford a single ISP connection. Which risk does this scenario most likely introduce?
a)
The equipment of MTBF is unknown.
b)
The ISP has no SLA.
c)
An RPO has not been determined.
d)
There is a single point of failure.
44.
Which policy best aligns with a company’s goals to minimize retained records, comply with regulations, and securely destroy unnecessary data?
a)
Security policy
b)
Classification policy
c)
Retention policy
d)
Access control policy
45.
After implementing controls and mitigation measures, which term best describes the remaining risk?
a)
Residual
b)
Avoided
c)
Inherent
d)
Operational
46.
Which scenario best illustrates the use of a DNS sinkhole?
a)
Attackers can see a DNS sinkhole as a highly valuable resource to identify a company's domain structure.
b)
A DNS sinkhole can be used to draw employees away from known-good websites to malicious ones owned by the attacker.
c)
A DNS sinkhole can be used to capture traffic to known-malicious domains used by attackers.
d)
A DNS sinkhole can be set up to attract potential attackers away from a company's network resources
47.
An incident analyst discovers image files on a hard drive that might embed geolocation data. What type of information is the analyst attempting to retrieve?
a)
Log data
b)
Metadata
c)
Encrypted data
d)
Sensitive data
48.
In a digital forensics investigation, which component is the most volatile and should be prioritized for data collection?
a)
Hard drive
b)
RAM
c)
SSD
d)
Temporary files
49.
Which of the following is categorized as a preventive security control?
a)
Configuration auditing
b)
Log correlation
c)
Incident alerts
d)
Segregation of duties
50.
A security team detects a surge of emails with random subject lines sent to multiple employees, each containing a URL shortener link redirecting to a defunct domain. What is the team’s best immediate action?
a)
Send the dead domain to a DNS sinkhole.
b)
Quarantine all emails received and notify all employees.
c)
Block the URL shortener domain in the web proxy
d)
Create a blocklist for all subject lines.
51.
Which of the following best defines a legal hold?
a)
It occurs during litigation and requires retention of both electronic and physical documents.
b)
It occurs during a risk assessment and requires retention of risk-related documents.
c)
It occurs during incident recovery and requires retention of electronic documents
d)
It occurs during a business impact analysis and requires retention of documents categorized as personally identifiable information
52.
An auditor identified several insecure ports on certain servers and noticed that outdated protocols were enabled on the other servers. Which tool was most likely used to uncover these findings?
a)
Nessus
b)
curl
c)
Wireshark
d)
netcat
53.
Which of the following most accurately describes a social engineering attack involving a directed electronic message campaign focused on a Chief Executive Officer?
a)
Identity fraud
b)
Whaling
c)
Spear phishing
d)
Impersonation
54.
An organization seeks to establish MFA. Which option below supplies the extra factor of authentication while employing a smart card?
a)
PIN
b)
Hardware token
c)
User ID
d)
SMS
55.
An organization engaged an outside consultant to help with mandatory system enhancements to a vital business application. A systems administrator must secure the consultant's access while avoiding the sharing of passwords for critical systems. Which of the following approaches should probably be implemented?
a)
TACACS+
b)
SAML
c)
An SSO platform
d)
Role-based access control
e)
PAM software
56.
A recently deployed wireless network is configured to allow visitors to access the wireless connection for business purposes. The legal team is worried that visitors could join the network and conduct illegal activities. Which of the following should the security team deploy to mitigate this risk?
a)
Configure a RADIUS server to manage device authentication.
b)
Use 802.1 X on all devices connecting to wireless.
c)
Add a guest captive portal requiring visitors to accept terms and conditions.
d)
Allow for new devices to be connected via WPS.
57.
A third-party supplier is placing a certain application into end-of-life phase at year's end. Which of the following poses the greatest risk if the company chooses to maintain the application's operation?
a)
Lack of security updates
b)
Lack of new features
c)
Lack of support
d)
Lack of source code access
58.
A development group shares a backup account for accessing the source code repository. Which of the following is the most effective approach to safeguard the backup account when SSO fails?
a)
RAS
b)
EAP
c)
SAML
d)
PAM
59.
Which of the following is the most suitable source to check for information regarding the most prevalent application vulnerability exploitation approaches?
a)
OWASP
b)
STIX
c)
OVAL
d)
Threat intelligence feed
e)
Common Vulnerabilities and Exposures
60.

A system administrator is notified that the internal file server is experiencing significant slowdowns and only functions sporadically. The system administrator checks the server management tool and uncovers the following details regarding the server:

Which of the following indicators most likely triggered this alert?

a)
Concurrent session usage
b)
Network saturation
c)
Account lockout
d)
Resource consumption
61.
Which data state refers to information currently being handled or processed by a database server?
a)
In use
b)
At rest
c)
In transit
d)
Being hashed
62.
Which architecture is best suited to ensure redundancy for critical business operations?
a)
Network-enabled
b)
Server-side
c)
Cloud-native
d)
Multitenant
63.

While examining log files, a security administrator comes across the following code snippet:

Which option most accurately explains the vulnerability that is being exploited?

a)
XSS
b)
SQLi
c)
DDoS
d)
CSRF
64.
A company has distributed new laptops to staff and wants to enforce web filtering regardless of location, without requiring extra network access setup. What type of web filtering should the system administrator implement?
a)
Agent-based
b)
Centralized proxy
c)
URL scanning
d)
Content categorization
65.
Which option offers the strongest defense against unauthorized or unsafe communications to and from a device?
a)
System hardening
b)
Host-based firewall
c)
Intrusion detection system
d)
Anti-malware software
66.
A remote employee lost a mobile device that held company information. What is the most effective solution to avoid similar data loss incidents in the future?
a)
MDM
b)
DLP
c)
FDE
d)
EDR
67.
An IT administrator is responsible for enforcing data retention policies on a corporate application. Which term best describes this role?
a)
Processor
b)
Custodian
c)
Privacy officer
d)
Owner
68.

A company intends to enhance the security of its systems by:
• Preventing users from sending sensitive data over corporate email
• Restricting access to potentially harmful websites

Which features should the company implement? (Choose two.)

a)
DLP software
b)
DNS filtering
c)
File integrity monitoring
d)
Stateful firewall
e)
Guardrails
69.
A company handles sensitive data on its internal systems. What is the initial step it should take to comply with privacy laws?
a)
Implement access controls and encryption.
b)
Develop and provide training on data protection policies.
c)
Create incident response and disaster recovery plans.
d)
Purchase and install security software.
70.
Which cryptographic technique is best suited for securing communications on devices with limited processing power?
a)
Hashing algorithm
b)
Public key infrastructure
c)
Symmetric encryption
d)
Elliptic curve cryptography
71.
A network administrator aims to secure network traffic during transmission. Which of the following steps best accomplishes this?
a)
Ensure that NAC is enforced on all network segments, and con]rm that firewalls have updated policies to block unauthorized traffic.
b)
Ensure only TLS and other encrypted protocols are selected for use on the network, and only permit authorized traffic via secure protocols.
c)
Configure the perimeter IPS to block inbound HTTPS directory traversal traffic, and verify that signatures are updated on a daily basis.
d)
Ensure the EDR software monitors for unauthorized applications that could be used by threat actors, and con]gure alerts for the security team.
72.
Which definition most accurately explains the concept of log correlation?
a)
Combining relevant logs from multiple sources into one location
b)
Searching and processing data to identify patterns of malicious activity
c)
Making a record of the events that occur in the system
d)
Analyzing the log ]les of the system components
73.
A security team is exploring a new architecture to enhance protection for networks and applications against modern cyber threats. With a fully remote workforce, the solution must be highly redundant and allow users to connect via VPN that includes a software-based firewall. Which solution fits these criteria?
a)
IPS
b)
SIEM
c)
SASE
d)
CASB
74.
Which method enables an exploit to remain hidden from the operating system?
a)
Firmware vulnerabilities
b)
Side loading
c)
Memory injection
d)
Encrypted payloads
75.
An insider in marketing modifies records and redirects company funds to their own account. What method would best protect company records against such actions in the future?
a)
Permission restrictions
b)
Hashing
c)
Input validation
d)
Access control list
76.
Which report best demonstrates that an organization’s controls are correctly designed and functioning effectively?
a)
Red teaming
b)
Penetration testing
c)
Independent audit
d)
Vulnerability assessment
77.
After setting up VPN access to a cloud environment, which feature should the systems administrator use to enable efficient remote management?
a)
A jump host in the shared services security zone
b)
An SSH server within the corporate LAN
c)
A reverse proxy on the firewall
d)
An MDM solution with conditional access
78.
An audit finds that logs from the cardholder database are improperly exposing account numbers. Which mechanism would best help reduce the risk from this issue?
a)
Segmentation
b)
Hashing
c)
Journaling
d)
Masking
79.
A security analyst tries to start a database server but gets an authentication failure. After investigation, it’s confirmed that attackers compromised the server and redirected its outgoing database traffic to a malicious server. Which MITRE ATT&CK technique most likely explains this traffic redirection?
a)
Browser extension
b)
Process injection
c)
Valid accounts
d)
Escape to host
80.
A penetration tester gains entry to an office by following employees inside without having an access badge. What type of attack is this?
a)
Tailgating
b)
Shoulder surfing
c)
RFID cloning
d)
Forgery
81.
Which solution allows gathering and receiving a unified report from multiple network devices?
a)
IPS
b)
DLP
c)
SIEM
d)
Firewall
82.
A customer gets a call from someone pretending to be from the company, asking for credit card info. The caller ID shows the company’s real phone number. What kind of attack is this?
a)
Phishing
b)
Whaling
c)
Smishing
d)
Vishing
83.
A security analyst is examining logs to trace the destination of command-and-control traffic coming from a compromised device inside the local network. Which of the following is the best log to review?
a)
IDS
b)
Antivirus
c)
Firewall
d)
Application
84.
An employee encounters a security warning when accessing an internal website. Which type of certificate is the site probably using?
a)
Wildcard
b)
Root of trust
c)
Third-party
d)
Self-signed
85.
Which goal is best accomplished through a tabletop exercise?
a)
Familiarizing participants with the incident response process
b)
Deciding red and blue team rules of engagement
c)
Quickly determining the impact of an actual security breach
d)
Conducting multiple security investigations in parallel
86.
After a website’s private key was compromised and a new certificate issued, what should be updated next?
a)
SCEP
b)
CRL
c)
OCSP
d)
CSR
87.
Which organizational document is commonly used to define and share expectations about integrity and ethical conduct within a company?
a)
AUP
b)
SLA
c)
EULA
d)
MOA
88.
How can an organization identify the global regulations that apply to its data, no matter where the data is physically stored?
a)
Geographic dispersion
b)
Data sovereignty
c)
Geographic restrictions
d)
Data segmentation
89.
An organization’s web servers running an online ordering system are vulnerable to malicious JavaScript injection that could expose customer payment data. What mitigation strategy would best prevent such attacks? (Choose two.)
a)
Regularly updating server software and patches
b)
Implementing strong password policies
c)
Encrypting sensitive data at rest and in transit
d)
Utilizing a web-application firewall
e)
Performing regular vulnerability scans
90.
Which tool is most suitable for logging and monitoring in a cloud environment?
a)
IPS
b)
FIM
c)
NAC
d)
SIEM
91.
During a SQL update, an attacker replaced a temporary field to gain system access. What type of vulnerability does this represent?
a)
Race condition
b)
Memory injection
c)
Malicious update
d)
Side loading
92.
Which element of digital forensics should an organization use to guarantee the integrity of collected evidence?
a)
Preservation
b)
E-discovery
c)
Acquisition
d)
Containment
93.
After a major incident involving 30GB of data exfiltration from the corporate network, what is the most efficient method to determine the source system and the destination where the attacker sent the data?
a)
Analyze firewall and network logs for large amounts of outbound traffic to external IP addresses or domains.
b)
Analyze IPS and IDS logs to find the IP addresses used by the attacker for reconnaissance scans.
c)
Analyze endpoint and application logs to see whether file-sharing programs were running on the company systems.
d)
Analyze external vulnerability scans and automated reports to identify the systems the attacker could have exploited a remote code vulnerability.
94.
A security analyst wants to monitor user and device behavior to spot potential malicious activities by detecting deviations from normal patterns. Which control should be used?
a)
Intrusion prevention system
b)
Sandbox
c)
Endpoint detection and response
d)
Antivirus
95.
The legal department needs to keep backups from all devices that have been physically destroyed and recycled by an external party. What does this requirement best represent?
a)
Data retention
b)
Certi]cation
c)
Sanitization
d)
Destruction
96.
What type of attack can be used to compromise a system running a RTOS?
a)
Cross-site scripting
b)
Memory injection
c)
Replay attack
d)
Ransomware
97.
To stop employees from getting malicious email attachments, what function should the security solution perform?
a)
Apply IP address reputation data.
b)
Tap and monitor the email feed.
c)
Scan email traffic inline.
d)
Check SPF records.
98.
What is the first stage in the incident response process?
a)
Detection
b)
Declaration
c)
Containment
d)
Verification
99.
What is the primary concern when a critical legacy system cannot be replaced?
a)
Resource provisioning
b)
Cost
c)
Single point of failure
d)
Complexity
100.
What compensating control can be used to safely provide user access to a high-risk website?
a)
Enabling threat prevention features on the firewall
b)
Con]guring a SIEM tool to capture all web traffic
c)
Setting firewall rules to allow traffic from any port to that destination
d)
Blocking that website on the endpoint protection software
101.
What elements should an organization include when implementing a COPE mobile device management policy? (Choose two.)
a)
Remote wiping of the device
b)
Data encryption
c)
Requiring passwords with eight characters
d)
Data usage caps
e)
Employee data ownership
102.

While investigating an incident, a security administrator reviewed a web server log and noticed the following entries:
"GET ../../../../etc/passwd"

What type of attack did the security administrator most likely detect?

a)
Privilege escalation
b)
Credential replay
c)
Brute force
d)
Directory traversal
103.
What is the first step a security team should take before launching a new web server?
a)
Harden the virtual host.
b)
Create WAF rules.
c)
Enable network intrusion detection.
d)
Apply patch management.
104.
What techniques can be used to securely erase data on a hard drive while still allowing the drive to be reused?
a)
Degaussing
b)
Drive shredder
c)
Retention platform
d)
Wipe tool
105.
An attacker sends a request with unexpected characters trying to access unauthorized information in the system. What type of attack is this?
a)
Side loading
b)
Target of evaluation
c)
Resource reuse
d)
SQL injection
106.
A security analyst estimates a breach will cost $15,000 each time and is expected to happen twice in three years. What is the ALE?
a)
$7,500
b)
$10,000
c)
$15,000
d)
$30,000
107.
A systems administrator finds a critical system that’s no longer supported by the vendor, can’t be modified, and must remain operational. What is the most suitable risk treatment?
a)
Reject
b)
Accept
c)
Transfer
d)
Avoid
108.
After discovering proprietary data being sold on the dark web, what should the company do next?
a)
Identify the attacker’s entry methods.
b)
Report the breach to the local authorities.
c)
Notify the applicable parties of the breach.
d)
Implement vulnerability scanning of the company's systems.
109.
What is the best low-cost option to set up a standby site that includes hardware and internet connectivity?
a)
Recovery site
b)
Cold site
c)
Hot site
d)
Warm site
110.
To track how many employees enter the building daily for configuring access controls, which type of control is most appropriate?
a)
Detective
b)
Preventive
c)
Corrective
d)
Directive
111.
What is the best secure solution for remote users who regularly handle sensitive PHI and need to access an internal corporate application? (Choose two.)
a)
Local administrative password
b)
Perimeter network
c)
Jump server
d)

MFA

e)

VPN

112.
What is the term for an architecture where secure systems are physically isolated from other networks or systems?
a)
SDN
b)
Air gapped
c)
Containerized
d)
Highly available
113.
A company with limited IT resources is migrating to the cloud. Which cloud service model best suits their needs for both migration and ongoing support?
a)
IPS
b)
WAF
c)
SASE
d)
IAM
114.
After an employee clicked a malicious email link impersonating the CEO, resulting in ransomware infection, what is the most effective way to prevent such incidents going forward?
a)
Security awareness training
b)
Database encryption
c)
Segmentation
d)
Reporting suspicious emails
115.
What are the key advantages of microservices architecture compared to a monolithic architecture? (Choose two.)
a)
Easier debugging of the system
b)
Reduced cost of ownership of the system
c)
Improved scalability of the system
d)
Increased compartmentalization of the system
e)
Stronger authentication of the system
116.
A workstation becomes unresponsive and shows a ransom note after the user opened a resume received via message. Prior to the attack, the user accessed a resume sent through a message, visited the company’s website, and performed operating system updates. Which of the following is the most likely vector of this attack?
a)
Spear-phishing attachment
b)
Watering hole
c)
Infected website
d)
Typosquatting
117.
During an on-site penetration test, the tester discovers an Ethernet port that is not currently in use. After connecting a device to the unused port, the tester observes that it receives an IP address, enabling access to and exploration of the local network. What measures should an administrator take to prevent this issue from recurring?
a)
Port security
b)
Transport Layer Security
c)
Proxy server
d)
Security zones
118.
What method should be used to prevent an attacker from accessing the data on a lost mobile device’s storage?
a)
TPM
b)
ECC
c)
FDE
d)
HSM
119.

During a network services assessment, a security administrator recorded the following information:

After two weeks, the administrator reviewed the logs again and observed that the records had been modified as follows:

After confirming with the service owner that the new address doesn’t belong to the company network, what is the most probable issue the company is facing?

a)
DDoS attack
b)
DNS poisoning
c)
Ransomware compromise
d)
Spyware infection
120.
Why is it important to be concerned about false negatives in vulnerability scans?
a)
The system has vulnerabilities that are not being detected.
b)
The time to remediate vulnerabilities that do not exist is excessive.
c)
Vulnerabilities with a lower severity will be prioritized over critical vulnerabilities.
d)
The system has vulnerabilities, and a patch has not yet been released.
121.
Which architecture best helps a large IT organization improve control, standardization, and reduce server deployment time?
a)
IoT
b)
IaC
c)
IaaS
d)
ICS
122.
A government official gets an anonymous envelope with photos and a note demanding a large payment by midnight to avoid leaking the photos online. What is the threat actor’s primary intent?
a)
Organized crime
b)
Philosophical beliefs
c)
Espionage
d)
Blackmail
123.
What is the main security benefit of shutting down unnecessary service ports?
a)
To mitigate risks associated with unencrypted traffic
b)
To eliminate false positives from a vulnerability scan
c)
To reduce a system's attack surface
d)
To improve a system's resource utilization
124.
After a brute-force attack compromised customer data on a company’s web servers, what is the most effective prevention method for future attacks?
a)
Regular patching of servers
b)
Web application firewalls
c)
Multifactor authentication
d)
Enabling encryption of customer data
125.
Which option offers the shortest RTO and RPO for a database?
a)
Snapshots
b)
On-site backups
c)
Journaling
d)
Hot site
126.
After a cyberattack caused prolonged system downtime, the company wants to determine how fast systems need to be restored to reduce business impact. What metric would they use?
a)
Recovery point objective
b)
Risk appetite
c)
Risk tolerance
d)
Recovery time objective
e)
Mean time between failure
127.
Which type of attacker targeting an organization is most commonly driven by personal or ideological beliefs?
a)
Nation-state
b)
Organized crime
c)
Hacktivist
d)
Insider threat
128.
What tool or method should a security team use to record ongoing vulnerabilities along with suggested fixes?
a)
Audit report
b)
Risk register
c)
Compliance report
d)
Penetration test
129.
A company purchased an essential business application that holds sensitive information. The company wants to make sure the application is protected against typical data theft attempts. Which method would most effectively meet this need?
a)
URL scanning
b)
WAF
c)
Reverse proxy
d)
NAC
130.
During a risk assessment of new software, what aspects should the company evaluate?
a)
Software vulnerabilities
b)
Cost-benefit analysis
c)
Ongoing monitoring strategies
d)
Network infrastructure compatibility
131.
A threat actor attempts to obtain sensitive financial data by capturing and replaying login credentials. What type of attack is this?
a)
SQL injection
b)
On-path
c)
Brute-force
d)
Password spraying
132.
A new employee visited a website they were not permitted to access. The investigation revealed this was against company policy. What did the employee violate?
a)
MOU
b)
AUP
c)
NDA
d)
MOA
133.
While checking VPN logs, a systems administrator sees a user accessing the company file server outside working hours and transferring data to a suspicious IP address. What threat is most likely happening?
a)
Typosquatting
b)
Root or trust
c)
Data exfiltration
d)
Blackmail
134.
A company finds suspicious database transactions linked to a user account purposely created to detect malicious activity. What type of account is this?
a)
Honeytoken
b)
Honeynet
c)
Honeypot
d)
Honeyfile
135.
A network engineer wants to enhance the security of network devices by hardening them. What is the best approach to achieve this?
a)
Configuring centralized logging
b)
Generating local administrator accounts
c)
Replacing Telnet with SSH
d)
Enabling HTTP administration
136.
The accounting team receives an urgent wire transfer request, supposedly from the company's bank domain. The sender urges that the wire transfer be processed immediately. What type of attack is this?
a)
Business email compromise
b)
Vishing
c)
Spear phishing
d)
Impersonation
137.
The company lodged a complaint against its IT service provider upon discovering that the provider’s external auditors accessed some of the company’s confidential data. What is the most probable cause for the company to have submitted the complaint?
a)
The MOU had basic clauses from a template.
b)
A SOW had not been agreed to by the client.
c)
A WO had not been mutually approved.
d)
A required NDA had not been signed.
138.
An analyst is examining job advertisements to verify that confidential company details are not exposed to the public. What is the analyst most likely searching for?
a)
Office addresses
b)
Software versions
c)
List of board members
d)
Government identification numbers
139.
An engineer has updated the switches with the newest operating system, applied the latest patches to servers, and ensured endpoint security definitions are current. Which type of threat do these measures most effectively protect against?
a)
Zero-day attacks
b)
Insider threats
c)
End-of-life support
d)
Known exploits
140.
What is the primary security risk associated with deploying and operating inexpensive IoT devices in infrastructure settings?
a)
Country of origin
b)
Device responsiveness
c)
Ease of deployment
d)
Storage of data
141.
A company collects login data and analyzes it weekly to spot issues like repeated login attempts and frequent account lockouts. What should a security analyst suggest to enhance the effectiveness of security compliance monitoring?
a)
Including the date and person who reviewed the information in a report
b)
Adding automated alerting when anomalies occur
c)
Requiring a statement each week that no exceptions were noted
d)
Masking the username in a report to protect privacy
142.
A security team is working to strengthen the network's defenses against malicious traffic originating from external sources. Which option offers the highest level of protection for the internal network?
a)
Anti-malware solutions
b)
Host-based firewalls
c)
Intrusion prevention systems
d)
Network access control
e)
Network allow list
143.
What is the best option a systems administrator can implement to reduce the organization's exposure to hardware-based threats?
a)
Replication
b)
Isolation
c)
Centralization
d)
Virtualization
144.
A company plans to implement multi-factor authentication for employees who connect to the corporate network from remote locations. Authentication criteria involve factors based on something you know, are, and have. The company seeks an MFA solution that avoids the need for buying third-party software or extra hardware. Which MFA option best fits these criteria?
a)
Smart card with PIN and password
b)
Security questions and a one-time passcode sent via email
c)
Voice and fingerprint verification with an SMS one-time passcode
d)
Mobile application-generated, one-time passcode with facial recognition
145.
A company utilizes an old FTP server to send financial information to an external partner. Because the legacy system lacks SFTP support, an alternative control must be implemented to secure the sensitive financial data during transmission. Which option would be the best choice for the company to secure the data in this situation?
a)
Telnet connection
b)
SSH tunneling
c)
Patch installation
d)
Full disk encryption
146.
A security manager aims to minimize the steps needed to detect and respond to simple threats. Which option would best assist in accomplishing this objective?
a)
SOAR
b)
SIEM
c)
DMARC
d)
NIDS
147.
The Chief Information Officer (CIO) requested that a vendor supply documentation outlining the exact compliance framework objectives that their services fulfill. The vendor gave the CIO a report along with a signed letter confirming that their services satisfy 17 out of 21 objectives. Which type of document did the vendor provide?
a)
Penetration test results
b)
Self-assessment ]ndings
c)
Attestation of compliance
d)
Third-party audit report
148.
What is the best method to handle operating system vulnerabilities once they have been discovered?
a)
Endpoint protection
b)
Removal of unnecessary software
c)
Con]guration enforcement
d)
Patching
149.
The management team states that employees are lacking certain features on their company-issued tablets, leading to reduced productivity. The management team instructs the IT department to fix the problem within 48 hours. Which solution should the IT team use to best address this situation?
a)
EDR
b)
COPE
c)
MDM
d)
FDE
150.
A company plans to let employees use their own devices for work but wants to restrict installation to only approved applications. Which solution best enforces this requirement?
a)
MDM
b)
Containerization
c)
DLP
d)
FIM
151.
An alert highlights attacks using a zero-day exploit. To lower the risk, an analyst adds a bastion host to the network. What type of control is the analyst applying?
a)
Compensating
b)
Detective
c)
Operational
d)
Physical
152.
Which of the following illustrates an instance of memory injection?
a)
Two processes access the same variable, allowing one to cause a privilege escalation.
b)
A process receives an unexpected amount of data, which causes malicious code to be executed.
c)
Malicious code is copied to the allocated space of an already running process.
d)
An executable is overwritten on the disk, and malicious code runs the next time it is executed.
153.
A security administrator is encrypting all the organization's hard drives. Which security principle is being implemented?
a)
Integrity
b)
Authentication
c)
Zero Trust
d)
Confidentiality
154.
An administrator set up a quarantine subnet for guest devices connecting to the network. What should the security team do before granting these devices access to corporate resources?
a)
Device fingerprinting
b)
Compliance attestation
c)
Penetration test
d)
Application vulnerability test
155.
A Chief Information Security Officer is creating procedures for detecting and responding to common threats like phishing, social engineering, and business email compromise. Which document should be updated to support these activities?
a)
SDLC
b)
IRP
c)
BCP
d)
AUP
156.
Which testing approach combines both offensive and defensive strategies and involves developers to ensure the secure development of critical applications and software?
a)
Blue
b)
Yellow
c)
Red
d)
Green
157.
What is the most effective way for an administrator to automate updating permissions for many user accounts?
a)
Security groups
b)
Federation
c)
User provisioning
d)
Vertical scaling
158.
What is the quickest and most affordable method to verify that a third-party supplier meets their security requirements?
a)
Attestation report
b)
Third-party audit
c)
Vulnerability assessment
d)
Penetration testing
159.
Which cryptographic technique is designed to conceal the very existence of communication?
a)
Steganography
b)
Data masking
c)
Tokenization
d)
Private key
160.
A program manager needs to restrict contract workers so they can access company systems only during business hours, specifically from 9:00 a.m. to 5:00 p.m., Monday to Friday. Which method would be most effective in enforcing this access limitation?
a)
Creating a GPO for all contract employees and setting time-of-day log-in restrictions
b)
Creating a discretionary access policy and setting rule-based access for contract employees
c)
Implementing an OAuth server and then setting least privilege for contract employees
d)
Implementing SAML with federation to the contract employees’ authentication server
161.
A power outage recently disrupted operations at the company’s sole data center. Which solution would most effectively prevent this type of disruption from happening again?
a)
Platform diversity
b)
Generator
c)
Snapshots
d)
Load balancing
162.
Which analysis method enables an organization to quantify the potential level of loss to its assets in the event of a specific threat?
a)
Heuristic
b)
Quantitative
c)
User-driven
d)
Trend-based
163.
A security analyst detects a rise in port scanning activity at the corporate network’s perimeter. Which log should the analyst review to find the attacker’s source IP address?
a)
OS security
b)
Firewall
c)
Application
d)
Endpoint
164.
The security team is alerted to significant network delays and widespread outages across the office. Network flow logs from campus switches reveal heavy traffic on TCP port 445. What is the most probable cause of this issue?
a)
Buffer overflow
b)
NTP amplification attack
c)
Worm
d)
DoS attack
165.
While reviewing a penetration test report, a security analyst finds that the tester was able to access critical internal systems by reusing the same local user ID and password. What measure would best help prevent this from happening again?
a)
Implement centralized authentication with proper password policies
b)
Add password complexity rules and increase password history limits
c)
Connect the systems to an external authentication server
d)
Limit the ability of user accounts to change passwords
166.
When combined with an access control vestibule, which solution most effectively prevents tailgating?
a)
PIN
b)
Access card
c)
Security guard
d)
CCTV
167.
A security professional finds a folder with an employee’s personal data on the company’s shared drive. Which data classification should be used to guide policies and standards for storing such personal information?
a)
Legal
b)
Financial
c)
Privacy
d)
Intellectual property
168.
A site reliability engineer is planning a recovery approach that allows fast failover to a duplicate site in case the main site fails. What type of site should the engineer choose?
a)
Recovery site
b)
Hot site
c)
Cold site
d)
Warm site
169.
What method would an organization typically implement to reduce data loss on a file server when restoring data after an incident?
a)
Snapshots
b)
Journaling
c)
Obfuscation
d)
Tokenization
170.
Which method is commonly used in the financial sector to mask sensitive information?
a)
Tokenization
b)
Hashing
c)
Salting
d)
Steganography
171.
What type of vulnerability can arise due to the use of outdated cryptographic algorithms or keys?
a)
Hash collision
b)
Cryptographic
c)
Buffer overflow
d)
Input validation
172.
A company aims to stop proprietary and confidential information from being disclosed to external parties. Which security concept best describes this goal?
a)
MOA
b)
SLA
c)
MSA
d)
NDA
173.
To minimize potential vulnerabilities in the company’s data centers, what action should a security administrator take to effectively reduce the attack surface?
a)
Implement a honeynet.
b)
Define Group Policy on the servers.
c)
Configure the servers for high availability.
d)
Upgrade end-of-support operating systems.
174.
What is a necessary requirement that must be in place before implementing a DLP solution?
a)
Data destruction
b)
Data sanitization
c)
Data classification
d)
Data masking
175.

A company offers long-term cold storage services to banks that must comply with regulatory data retention requirements. These banks require that data be destroyed in a specific way once the retention period ends. Which aspect of data management is most critical to the bank when ensuring proper data destruction?

a)
Encryption
b)
Classification
c)
Certification
d)
Procurement
176.

The physical security team has received complaints that employees are not showing their badges and have witnessed tailgating at secured entrances. What topic is the security team most likely to focus on during upcoming training sessions?

a)
Social engineering
b)
Situational awareness
c)
Phishing
d)
Acceptable use policy
177.
What is the most common motivation driving a hacktivist’s actions?
a)
Financial gain
b)
Espionage
c)
Philosophical beliefs
d)
Revenge
178.

While reviewing logs, an analyst finds proof of successful injection attacks. What action would be most effective in preventing these attacks in the future?

a)
Authentication
b)
Secure cookies
c)
Static code analysis
d)
Input validation
179.
What is the initial action that should be taken to secure a newly installed server?
a)
Close unnecessary service ports.
b)
Update the current version of the software.
c)
Add the device to the ACL.
d)
Upgrade the OS version.
180.

After receiving an alert about an attempted download of known malware, which action would provide the best opportunity to analyze the malware?

a)

Review the IPS logs and determine which command-and-control IPs were blocked.

b)

Analyze application logs to see how the malware attempted to maintain persistence.

c)

Run vulnerability scans to check for systems and applications that are vulnerable to the malware

d)

Obtain and execute the malware in a sandbox environment and perform packet captures.

181.

What should be implemented to make sure a user has the appropriate permissions required to perform their assigned job functions effectively?

a)
Changing default passwords
b)
Implementing least privilege
c)
Enforcing baseline configurations
d)
Applying network segmentation
182.

An employee gets a text from an unknown number pretending to be the CEO, requesting the purchase of gift cards. What type of attack does this represent?

a)
Watering-hole
b)
Disinformation
c)
Phishing
d)
Impersonation
183.

An employee receives an unusual email from the CEO’s corporate account requesting financial details and a change to the contact number. Which attack vector is most likely involved in this scenario?

a)
Business email compromise
b)
Phishing
c)
Brand impersonation
d)
Pretexting
184.

What should an organization implement to be able to assess the controls and performance of its service providers or vendors?

a)
Service-level agreement
b)
Memorandum of agreement
c)
Right-to-audit clause
d)
Supply chain analysis
185.

Which metric is used to determine the impact or loss to an organization from a single cybersecurity incident?

a)
SLE
b)
ALE
c)
ARO
d)
SLA
186.

When a retail company receives a request to delete a customer's data, what role does the company hold under GDPR regulations?

a)
Data processor
b)
Data controller
c)
Data subject
d)
Data custodian
187.

Despite deploying web-filtering tools, users are still accessing malicious websites. Which configuration setting should the security administrator check to address this issue?

a)
Intrusion prevention system
b)
Content categorization
c)
Encryption
d)
DNS service
188.

A security analyst is examining following logs related to suspicious VPN login activity for a user;

Which of the following malicious activity indicators triggered the alert?

a)
Impossible travel
b)
Account lockout
c)
Blocked content
d)
Concurrent session usage
189.

In the incident response process, which phase focuses on reducing the impact and disruption caused by the incident?

a)
Recovery
b)
Containment
c)
Preparation
d)
Analysis