wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

CompTIA Security+ (SYO-701) Obj 4

Total questions: 153

Worksheet time: 1hrs 17mins

Name
Class
Date
1.
As a network administrator, you have been assigned the critical task of upgrading a company's encryption protocol for wireless devices. The current encryption method is outdated and poses a significant security risk. Your objective is to select the most secure option for the upgrade. Which of the following encryption mechanisms BEST represents the ideal choice for this upgrade?
a)
WEP
b)
AES
c)
WPA
d)
TKIP
2.
At Dion Training, David is advising on cloud security best practices regarding a company's recent issue with logins. Which measure is the most crucial to inform them when safeguarding against unauthorized logon attempts?
a)
Implementing MFA and using conditional authentication for risky logons
b)
Rely solely on the CSP's IAM for user management
c)
Leave Default settings on Google's firewall
d)
Allow programmatic access without unique secret keys
3.
Jason is working with David to enhance the security of the switches at Dion Training. Which technique would be the BEST for them to prioritize?
a)
Enabling SNMP monitoring
b)
Disabling unused ports
c)
Using default VLAN for all operations
d)
Implementing regular system backups on the switches
4.
A software development company regularly releases software updates to its global customer base. Recently, some customers reported receiving unauthorized and potentially malicious software updates. The company is now seeking to implement a security technique to ensure the authenticity and integrity of its software updates when delivered to customers. Which of the following would BEST assist in achieving this goal?
a)
Antivirus scanning
b)
MFA
c)
IDS solution
d)
Code signing
5.
After a security assessment, Jono has been tasked with replacing his home office AP with one that has the capability of providing WPA3, which his previous one was unable to handle. Which of the following is true when considering WPA3 standards? (Select 4.)
a)
It is the latest and most secure wireless security protocol
b)
It utilizes a Diffie-Hellman key agreement
c)
It prevents eavesdropping, forging, and tampering with management frames
d)
It provides individualized data encryption even in open networks
e)
It encrypts the authentication process using TCP for enhanced security
6.
Mary, a network administrator at Dion Training, is discussing with Enrique ways to harden the company's mobile devices. Which technique would be the MOST effective for them to implement first?
a)
Enable Bluetooth discoverable mode
b)
Enforce screen lock after inactivity
c)
Recommend users to use strong Wi-Fi passwords
d)
Enforce full device encryption
7.
A company wants to test a new software application that was downloaded from an unknown source. The company does not want to risk infecting its network or compromising its data with malware or other threats. Which of the following techniques would be the MOST suitable for this scenario?
a)
Encryption
b)
Firewall
c)
Sandboxing
d)
Antivirus
8.
As a network administrator responsible for evaluating a company's encryption protocol method for wireless devices, you have discovered that the company is currently utilizing a deprecated encryption protocol that poses a significant security threat. Which of the following is the MOST appropriate encryption protocol to recommend upgrading to?
a)
AES
b)
TKIP
c)
WEP
d)
WPA
9.
Mary, a security analyst for Kelly Innovations LLC, is recommending a security control to protect the component of an Industrial Control System (ICS) responsible for direct operator interaction. Which of the following ICS components is she MOST likely addressing, and what primary security concern is she likely considering?
a)
PLC – Firmware Tampering
b)
DCS – System Availability
c)
HMI – Unauthorized Access
d)
Data historian – Data Integrity
10.
A company allows its employees to use their personal mobile devices for work-related tasks, such as accessing company email and sensitive documents. The IT department is concerned about the security risks to company data when these devices are lost. Which of the following aspects of an MDM will address this concern effectively?
a)
Installing antivirus software on the company's network servers
b)
Enabling remote wiping of devices
c)
Requiring employees to use strong passwords for their personal email accounts
d)
Enforcing full device encryption on all employee mobile devices
11.
Your company has recently acquired a batch of new servers for the software development department. As a security specialist, you are tasked with setting up the initial environment before handing it over to the developers. You have just installed the operating system, and the next step involves a baseline deployment process. Which of the following statements would be the BEST next course of action?
a)
Immediately hand over the servers to the development team for software installation and configuration
b)
Begin networking with other servers without applying any configurations
c)
Install development software without any further system-level modifications
d)
Apply a preset configuration template that includes security updates, and standard configurations
12.
Sweet Advances Inc. is a leading technology company that specializes in designing and manufacturing embedded systems for critical infrastructure. Their devices are used in various sectors such as healthcare, transportation, and energy. The company is concerned about the security of their embedded systems and wants to implement the most appropriate security technique to protect their computing resources from potential threats. Which of the following would be the most suitable for the company to secure their embedded systems used in critical infrastructure?
a)
Biometric authentication
b)
Network firewalls
c)
Antivirus software
d)
RTOS
13.
Wonka Industries, a multinational company, is planning to open a new office in a different city. The company's IT team wants to determine if any new security requirements are needed for the new office. They want to ensure that the computing resources will be adequately protected against potential threats. Which of the following should Wonka Industries do to determine if new requirements are needed?
a)
Installing CCTV cameras in all office areas
b)
Conducting a thorough site survey
c)
Implementing biometric authentication for all employees
d)
Conducting a vulnerability assessment and penetration testing
14.
Dion Training recently set up a new web server for their e-learning platform. The IT team has been tasked with implementing security measures to mitigate potential attacks. Which of the following practices would be MOST effective for server hardening?
a)
Increasing server storage capacity and the number of servers
b)
Setting up a guest account for all users and guests
c)
Identify all software and hardware that is approaching end of life
d)
Implementing a least-privilege principle and patch management
15.
Cyberdud is a global non-profit organization dedicated to making internet access a reality throughout the world. Company officials are concerned about whether the network infrastructure can ensure data confidentiality and protect sensitive information when it is being sent to Cyberdud's many international locations. Which of the following network devices would be the MOST suitable for the organization to enhance security?
a)
Hubs
b)
Routers
c)
Switches
d)
Bridges
16.
A company's web application allows users to search for products using a search bar. The search query is then used in a SQL query to fetch relevant products from the database. Additionally, the web application allows users to leave comments on product pages. The comments are displayed on the website without any restrictions. The company's security team is concerned about the risk of SQL injection and XSS attacks. Which of the following security techniques should be applied to address these concerns effectively?
a)
Implementing a WAF to monitor and filter network traffic
b)
Limiting user access to product pages using strong authentication
c)
Enabling HTTPS on the web server to secure data transmission
d)
Validating and sanitizing user input for both search and comments
17.
Holi, a small batch yarn producer, is growing. They recently made their first international sale. Holly realizes that as their web presence grows, they need to be more aware of security concerns. She has hired Hani to set up a system that will collect and analyze data about the security of Holi's network. It will detect and respond to any incidents or anomalies that may occur. Which of the following security techniques will Hani be in charge of?
a)
Patching
b)
Logging
c)
Monitoring
d)
Auditing
18.
Gekko, a clothing retailer, is expanding its headquarters and plans to implement a new wireless network across the facility. Carthy has been assigned to ensure strong and secure wireless coverage throughout the building, especially in customer-facing and high-traffic areas. What should Carthy do before installing the access points to optimize placement and reduce interference?
a)
Create a wireless heat map of the building layout
b)
Install wireless network repeaters at the corners of the facility
c)
Disable SSID broadcasting on all wireless devices
d)
Configure WPA3 security on all access points during setup
19.
Enrique, a network administrator at Kelly Innovations LLC, is discussing with Reed strategies to further secure the organization's routers. Which of the following would be the BEST approach to ensure their routers' security?
a)
Enable SNMPv1 for backward compatibility
b)
Frequently change router IP addresses to avoid detection
c)
Enable Telnet for remote management
d)
Implement ACLs to filter traffic
20.
Reed is getting a new computer from his employer, Kelly Innovations LLC. He wants to remove all his personal data from his old computer, ensuring it's irretrievable. Which of the following methods should he use?
a)
Secure erase
b)
System restore
c)
Emptying the recycle bin
d)
Disk defragmentation
21.
During the decommissioning process of a database server, the IT department of Dion Training ensures that all stored customer data is rendered unrecoverable to protect against unauthorized access in the future. Which of the following practices is the IT department employing in this scenario?
a)
Inventory
b)
Assignment
c)
Sanitization
d)
Enumeration
22.
Sanford and Sons, a recycling center, has recently decommissioned a number of servers containing confidential client data. Before selling the servers, the organization wants to ensure that all data has been securely removed and seeks a documented affirmation that the process was complete. Which of the following would provide the organization with the assurance it needs?
a)
Data destruction certification
b)
HCL
c)
SLA
d)
Asset inventory report
23.
Which of the following BEST describes the role of classification in effective hardware, software, and data asset management?
a)
Classification allows organizations can track their physical location across multiple locations
b)
Classification helps in tracking the financial value of assets
c)
Classification ensures that assets are labeled with appropriate access levels
d)
Classification establishes accountability for asset usage
24.
What is the primary difference between sanitization and destruction in the disposal process?
a)
Sanitization and destruction are synonyms and refer to the same process
b)
Sanitization concerns the reuse of assets in an organization, and destruction involves transferring those assets to a different department
c)
Sanitization refers to physically damaging the asset to render it unusable, while destruction involves completely eliminating all residual data
d)
Sanitization involves erasing data so it cannot be recovered; destruction is total physical demolition of the asset
25.
Cheryl's job at Kelly Innovations LLC involves maintaining a record of all company-owned smartphones. Which of the following is MOST likely to be Cheryl's role at Kelly Innovations?
a)
Network administrator
b)
IT support specialist
c)
Asset inventory manager
d)
Mobile application developer
26.
Which of the following statements is NOT true regarding the security implications in the procurement process?
a)
Once a vendor is selected for procurement, there is no ongoing need to periodically re-evaluate their suitability
b)
Vendor reputation and capabilities should be thoroughly evaluated to ensure they meet the necessary security standards
c)
Procurement contracts should include clauses delineating liability if assets provided by vendors lead to a security breach
d)
The procurement process must consider compatibility with existing infrastructure to maintain a similar level of security across all assets
27.
Which of the following is an aspect of asset management that ensures that each IT asset is clearly associated with a specific individual or department, providing clarity on responsibilities and access rights?
a)
Decommissioning
b)
Acquisition
c)
Monitoring
d)
Ownership
28.
Which of the following statements about inventories in the asset tracking process is NOT correct?
a)
Well-maintained inventory can help identify unauthorized devices on the network, enhancing the security posture
b)
Inventory practices include tracking but are not limited to: physical location, configuration, and authorized users of the assets
c)
An up-to-date inventory supports efficient asset management by monitoring the life cycles of all assets
d)
Inventory management is a one-time process, needing few updates after initialization
29.
Which of the following statements regarding data retention in the disposal process is NOT true?
a)
Data retention periods should account for business needs as well as any legal, regulatory, or contractual requirements
b)
Formal data retention policies help organizations decide when data assets should be backed up, archived, or purged
c)
Data retention implies storing all data indefinitely as it might be needed at some point
d)
Data retention is a critical governance factor that organizations need to adhere to while managing their information systems and data assets
30.
Which of the following is a process that involves assigning categories to assets based on factors such as sensitivity, criticality, or function?
a)
Classification
b)
Enumeration
c)
Sanitization
d)
Inventory
31.
Which of the following BEST underscores the value of enumeration in the effective management of hardware, software, and data assets?
a)
Enumeration aids inventory by tracking equipment and access controls to hardware, software, and data assets
b)
Enumeration identifies potential vulnerabilities in hardware, software, and data assets
c)
Enumeration ranks and prioritizes all hardware, software, and data assets based on their value to the organization
d)
Enumeration identifies and counts all hardware, software, and data assets in an organization
32.
Which of the following BEST highlights the significance of inventory in managing hardware, software, and data assets effectively?
a)
Inventory identifies individuals responsible for asset handling
b)
Inventory enables organizations to maintain up-to-date records
c)
Inventory documentation helps in tracking the financial value of assets
d)
Inventory facilitates the physical organization of assets
33.
Which of the following statements BEST explains the importance and security implications of ownership concerning hardware, software, and data asset management?
a)
Ownership facilitates physical security by determining asset location, preventing theft
b)
Ownership documentation aids in budget allocation for security measures
c)
Ownership ensures easy asset identification during audits and reduces unauthorized access risk
d)
Ownership establishes accountability, reducing insider threat risks
34.
Enrique is making a detailed list of every application installed on Dion Training's server. Which of the following tasks BEST describes Enrique's task?
a)
Risk assessment
b)
Patch management
c)
Software enumeration
d)
Network mapping
35.
Which of the following statements regarding certification in the disposal process is NOT true?
a)
Certification is not necessary if the destruction process was overseen by a staff member
b)
Certificates of disposal should include details of the disposal method, date and time, and responsible personnel
c)
Certification of disposal mitigates the risk of unauthorized access or recovery of sensitive data from discarded assets
d)
Certification of disposal verifies that the appropriate sanitization and destruction methods have been applied to the assets
36.
After a security audit, Kelly Innovations LLC decided to dispose of several old hard drives containing sensitive data. They wish to employ a method that ensures the data on these drives is completely unrecoverable. Sasha suggests hitting the drives with a hammer. Given that this is not the most effective solution, which of the following would be the BEST method to use?
a)
Shredding to Level 1
b)
Degaussing
c)
Burning in municipal incinerators
d)
Pulverizing with industrial machinery
37.
Kelly Innovations LLC has integrated a new payment gateway into their application. To ensure no potential security gaps exist, especially related to data breaches or financial data leaks, which of the following actions would be the MOST effective?
a)
Deploying a new intrusion detection system for the payment module
b)
Engaging penetration testers to mimic real-world hacking techniques
c)
Updating the application to its latest version post-integration
d)
Ensuring two-factor authentication is enabled for application users
38.
Which of the following BEST explains the importance of exceptions and exemptions in vulnerability management?
a)
Exceptions and exemptions are official authorizations that allow specific deviations from established security policies or baseline controls
b)
Exceptions and exemptions are designed to eliminate the need for regular audits by providing an all-access pass to privileged users
c)
Exceptions and exemptions allow systems to completely bypass all security policies for maximum efficiency
d)
Exceptions and exemptions permit organizations to ignore all known vulnerabilities without any consequences from internal procedures but don't affect government compliance
39.
Which of the following is the BEST action a security professional would undertake to determine the order in which identified vulnerabilities should be addressed, based on potential impact and exploitation likelihood?
a)
Vulnerability prioritization
b)
Dynamic analysis
c)
False positive assessment
d)
Threat intelligence gathering
40.
Which of the following is NOT true about environmental variables?
a)
Environmental variables such as temperature and humidity can have significant impacts on hardware performance
b)
Knowing the environmental variables helps in managing the needs of different hardware and software in a data center
c)
Environmental variables, like power supply and cooling, are crucial to ensure the longevity of hardware assets
d)
Maintaining standard levels of environmental variables isn't necessary in most data center environments
41.
Dion Training Solutions recently remediated a critical vulnerability on their servers. Which of the following actions is the BEST step to verify the remediation efforts were successful?
a)
Rescanning
b)
Segmentation
c)
Reviewing event logs
d)
Intrusive scanning
42.
Which of the following statements BEST explains the importance of package monitoring in the context of vulnerability management?
a)
It involves tracking the dependencies of software packages to ensure that all required components are up to date and compatible
b)
It insures that all software packages are up to date with the latest features and enhancements
c)
It helps identify and address vulnerabilities in software packages
d)
It allows organizations to track the physical location and status of hardware packages
43.
Which system offers a consistent and standardized method for naming and referring to specific publicly known security vulnerabilities and exposures in software and systems?
a)
CVSS
b)
Responsible disclosure program
c)
CVE
d)
Vulnerability prioritization
44.
Which of the following statements BEST explains the importance of penetration testing in the context of vulnerability management?
a)
Penetration testing involves monitoring network traffic to detect and prevent potential intrusions by unauthorized users
b)
Penetration testing refers to the process of installing security patches and updates to protect against known vulnerabilities
c)
Penetration testing focuses on creating backups of critical data and testing data restoration procedures to ensure business continuity
d)
Penetration testing includes conducting simulated cyberattacks on systems and applications to identify and address security vulnerabilities
45.
Kelly Innovations LLC has identified a vulnerability in one of its systems. However, due to a critical ongoing project, the IT team decides it's not the right time to apply the recommended fix. Which of the following strategies is the MOST appropriate for Kelly Innovations LLC to implement?
a)
Increase cybersecurity training for employees
b)
Conduct a penetration test
c)
Implement an vulnerability exception
d)
Migrate all data to another system
46.
Which of the following best explains the importance of Insurance in vulnerability management?
a)
Insurance can provide financial support in mitigating the aftermath of a security breach
b)
Insurance has no impact on vulnerability response and remediation processes
c)
Insurance determines the lifespan of hardware or software assets
d)
Insurance affects the actual security measures implemented to prevent vulnerabilities
47.
Which of the following statements BEST explains the importance of 'risk tolerance' in the context of vulnerability management?
a)
Risk tolerance involves an organization's willingness to implement expensive comprehensive security controls to eliminate all vulnerabilities and potential risks
b)
Risk tolerance refers to an organization's willingness to accept the potential impact of a vulnerability and its associated risks without mitigating them
c)
Risk tolerance is the level of uncertainty associated with a specific vulnerability, measured through the likelihood of occurrence and potential impact
d)
Risk tolerance is the practice of conducting regular vulnerability scans and penetration tests to identify and remediate security weaknesses
48.
Dion Training has implemented fixes for buffer overflow vulnerabilities in their application. To validate the effectiveness of their remediation efforts, which approach should be considered?
a)
Training the in-house IT team about buffer overflow prevention
b)
Checking the system's current performance metrics post-fix
c)
Contracting a cybersecurity firm for targeted vulnerability assessments
d)
Subscribing to a threat intelligence feed for real-time updates
49.
Kelly Innovations LLC has discovered a vulnerability in one of its software applications. The vulnerability is difficult to exploit, and exploiting it would require a significant level of expertise. However, if successfully exploited, it could have severe consequences. Which of the following is the MOST appropriate CVSS vulnerability classification?
a)
Low
b)
Critical
c)
High
d)
Informational
50.
Which of the following statements BEST describes the importance of compensating controls in vulnerability management?
a)
Compensating controls are used to increase the complexity of the system, making intrusion attempts more difficult
b)
Compensating controls are deployed to slow down the performance of the system and therefore deter potential hackers
c)
Compensating controls are designed to provide companies methods for not mitigating vulnerabilities
d)
Compensating controls provide alternative security measures when primary controls are not feasible or effective
51.
Which of the following statements BEST explains the importance of OSINT in the context of vulnerability management?
a)
OSINT helps organizations assess and analyze vulnerabilities in operating systems
b)
OSINT uses public information to discover vulnerabilities in an organization's network infrastructure
c)
OSINT uses proprietary software to eliminate vulnerabilities in an organization's network infrastructure
d)
OSINT allows organizations to track and monitor the physical location and status of hardware assets
52.
Why are CVE identifiers important for cybersecurity professionals?
a)
They provide mitigation techniques for vulnerabilities
b)
They offer a standardized way to share vulnerability data
c)
They assign severity scores to vulnerabilities
d)
They track software versions and updates
53.
Which of the following terms is used to describe a situation where a security system or tool incorrectly flags an action or event as malicious or harmful, even though it's actually benign?
a)
False positive
b)
Package monitoring
c)
False negative
d)
Penetration testing
54.
Which of the following statements BEST explains the function of an 'exposure factor' in the context of vulnerability management?
a)
An exposure factor measures the likelihood of a vulnerability being exploited
b)
An exposure factor evaluates the level of vulnerability in an organization's network infrastructure
c)
An exposure factor refers to the time required to detect and respond to a security incident
d)
An exposure factor helps organizations assess the monetary impact of a security breach
55.
Which of the following statements is NOT true about the Dark Web?
a)
Specialized software, such as Tor, is typically required to access the Dark Web
b)
The Dark Web is part of the Deep Web that is intentionally hidden and is inaccessible through standard web browsers
c)
All content available on the Dark Web is illegal and harmful
d)
The Dark Web often serves as a marketplace for illicit activities due to its anonymity
56.
Which of the following BEST describes compensating controls in information security?
a)
Standard regulations that all businesses must adhere to
b)
Software patches and updates applied to fix known vulnerabilities
c)
Alternative measures to mitigate risk when standard controls are not feasible
d)
Primary tools for risk management and vulnerability assessment
57.
Which of the following represents a valid format for a CVE identifier?
a)
22-0123
b)
10.0-AV:N/AC:L/PR:N/UI:N
c)
2022-12345
d)
2022-Vulnerability Name
58.
Which term refers to the collection of publicly available information used to inform about an individual, organization, or application, often aiding in vulnerability assessments or security research?
a)
OSINT
b)
Dark web
c)
Proprietary/third-party
d)
Information-sharing organization
59.
Which of the following statements BEST explains the purpose of Netflow?
a)
Netflow is a network tool that provides visibility into network traffic and helps identify potential security threats
b)
Netflow is a hardware-based security appliance that monitors and filters network traffic to prevent unauthorized access
c)
Netflow is a type of firewall that inspects network traffic and blocks malicious packets to prevent cyber-attacks
d)
Netflow is a protocol used for secure data transmission and encryption between devices on a network
60.
Which option BEST explains the importance of having vulnerability scanners?
a)
Vulnerability scanners detect and mitigate many potential problems on a wide variety of devices
b)
Vulnerability scanners continuously monitoring network traffic and identifying potential security breaches
c)
Vulnerability scanners are critical in detecting and assessing security weaknesses in applications and systems
d)
Vulnerability scanners are responsible for monitoring user activities and detecting suspicious behavior on the network
61.
Which of the following statements BEST explains the concept of Log aggregation?
a)
Log aggregation is the monitoring network traffic and identifying potential security breaches
b)
Log aggregation collects and normalizes log data from various sources to make it easier to analyze
c)
Log aggregation is the collecting of data from a scan and making it available to security analysts
d)
Log aggregation is the analysis of wide varieties of log data to identify security breaches
62.
Which of the following statements BEST explains the importance of 'benchmarks'?
a)
Benchmarks compare a security performance to industry-standard metrics, identifying potential security weaknesses
b)
Benchmarks are cryptographic algorithms used to secure data transmission over the internet
c)
Benchmarks are firewall technologies that inspect network traffic and block malicious packets to prevent cyber-attacks
d)
Benchmarks are intrusion detection systems that monitor and analyze network traffic for potential security breaches
63.
Which of the following is a disadvantage of agentless posture assessment in Network Access Control (NAC) solutions?
a)
Less detailed information about the client is available
b)
Increased risk of malware infection on client devices
c)
Inability to support smartphones, tablets, and IoT devices
d)
Requires more storage space on the client device
64.
Which of the following statements is NOT true concerning the significance of SNMP?
a)
SNMP allows network administrators to monitor network performance, find and solve network problems, and plan for network growth
b)
SNMP makes it possible to manage network performance, control network configuration, and store data about network components
c)
SNMP ensures secure communication among software applications and allows security analysts to monitor these communications
d)
SNMP assists in collecting information from various network devices to ensure proper functioning and security
65.
Which of the following statements is NOT true regarding the importance of Archiving?
a)
Archiving speeds up searches for older data, making the retrieval of data faster and more effective
b)
Archiving can improve system performance by moving less frequently accessed data off primary systems
c)
Archiving helps organizations store data safely for long-term retention and regulatory compliance
d)
Archiving is crucial for providing historical context to help in future data analysis and investigations
66.
Which of the following BEST explains the difference between an Agent-based and Agentless NAC?
a)
Agent based NACs use additional software to authenticate users, while Agentless NACs use network level protocols to authenticate users
b)
Agent based NACs use network level protocols to authenticate users, while Agentless NACs use additional software to authenticate users
c)
Both require additional software installed on network devices to monitor network traffic, but Agentless NACs collect more data
d)
Both involve monitoring network traffic without the need for additional software, but Agent-based NACs collect more data
67.
Which of the following statements is NOT true concerning the significance of NetFlow?
a)
NetFlow can identify the source and destination of traffic, making it easier to spot potential threats
b)
NetFlow can interpret traffic flow patterns and identify the type of network attack that is occurring
c)
NetFlow can help with capacity planning and understanding network performance issues
d)
NetFlow helps provide an understanding of network traffic flow, enhancing security by identifying unusual patterns
68.
Which of the following BEST explains the concept of Alerting in the context of security activities?
a)
Alerting is the assessing network traffic and identifying potential security breaches
b)
Alerting provides real-time notifications of security incidents and potential threats
c)
Alerting is the constant monitoring of networks to prevent unauthorized access
d)
Alerting monitors user activities and detecting suspicious behavior on the network
69.
Which of the following BEST describes the action taken when a file is quarantined during an alert response?
a)
Access to all files in the directory is restricted
b)
Access to the original file is denied to the user
c)
File is immediately forwarded to a threat intelligence platform
d)
File is permanently deleted
70.
Which of the following BEST explains the purpose of SNMP?
a)
SNMP is an intrusion detection system that monitors and analyzes network traffic for potential security breaches
b)
SNMP is a security protocol used to encrypt network traffic and protect sensitive data from unauthorized access
c)
SNMP is a firewall technology that inspects network traffic and blocks malicious packets to prevent cyber-attacks
d)
SNMP is a network protocol that enables the sending and receiving alerts about performance and status
71.
Which of the following statements BEST explains the importance of DLP in the context of vulnerability management?
a)
DLP is a set of techniques and tools for preventing unauthorized transmission of data
b)
DLP is a data encryption technique used to secure sensitive information stored in databases and cloud environments
c)
DLP is a network security technology that monitors and analyzes network traffic to detect and prevent DDoS attacks
d)
DLP is a cybersecurity tool that focuses on identifying and blocking malicious software and viruses to prevent data breaches
72.
Which of the following statements BEST explains the importance of SCAP?
a)
SCAP is a firewall technology that analyzes network traffic and blocks suspicious connections to protect against cyber threats
b)
SCAP is a network protocol used for secure data transmission between remote devices, ensuring data confidentiality
c)
SCAP is a cybersecurity framework that enables automated vulnerability assessment and compliance checking
d)
SCAP is an intrusion detection system that monitors and analyzes network traffic for potential security breaches
73.
Last month at Kelly Innovations LLC, Jamario reported receiving inappropriate images while researching industry competitors. To prevent employees from accidentally accessing such media in the future, which of the following solutions would be MOST effective?
a)
Installing a state-of-the-art firewall
b)
Upgrading to a faster internet connection
c)
Implementing content categorization
d)
Requiring two-factor authentication for internet access
74.
You are a cybersecurity analyst for a large enterprise that has experienced several security incidents resulting from insider threats and compromised user accounts. The organization wants to enhance its security posture by implementing User Behavior Analytics (UBA). Which of the following approaches would be the MOST effective way to implement UBA for the given scenario?
a)
Deploying UBA on all endpoint devices to monitor user interactions and application usage
b)
Configuring UBA to perform scheduled scans of all user accounts prevent any anomalies
c)
Implementing UBA on the organization's perimeter firewalls to analyze incoming and outgoing network traffic
d)
Using UBA to monitor and analyze the activities of privileged users with elevated access rights only
75.
Which email security standard helps prevent email spoofing by allowing domain owners to specify which mail servers are authorized to send email on their behalf?
a)
SPF
b)
DKIM
c)
DMARC
d)
SMTP
76.
You are a security analyst for an enterprise that has recently experienced several security incidents related to web browsing. Management has decided to implement a centralized proxy solution to enhance security and mitigate the risk of future incidents. Which of the following actions would be the MOST effective way to enhance security with the centralized proxy in the given scenario?
a)
Allowing unrestricted access to internal resources for users who are connected to the corporate network
b)
Implementing SSL inspection to monitor and control encrypted web traffic
c)
Permitting employees to install browser extensions from trusted sources to enhance their browsing experience
d)
Enforcing the use of HTTP for all web traffic to ensure compatibility with older browsers
77.
Which email security protocol uses cryptographic signatures to verify the authenticity of an email's sender?
a)
SPF
b)
DMARC
c)
MTA
d)
DKIM
78.
Jamario, an IT administrator for Dion Training Solutions, is considering deploying an agent-based web filter solution to manage and monitor web traffic for remote employees. Which of the following is the MOST important advantage of implementing agent-based web filters over traditional gateway-based filters for this purpose?
a)
It doesn’t require any updates or maintenance
b)
It allows for consistent policy enforcement regardless of the user's location
c)
It reduces the total cost of ownership (TCO) due to the absence of hardware
d)
It can filter traffic at a faster rate than gateway solutions
79.
You are an IT security manager for an enterprise that deals with sensitive customer information and intellectual property. The organization is concerned about data loss through email and removable storage devices. As a security manager, you recommend implementing a Data Loss Prevention (DLP) solution to enhance security. Which of the following configurations would be the MOST effective way to implement Data Loss Prevention (DLP) for the given scenario?
a)
Implementing DLP on endpoints with a focus on monitoring and preventing data transfers between internal users
b)
Using the DLP solution solely for monitoring purposes without implementing any preventive measures
c)
Configuring the DLP solution to scan all outbound emails and files leaving the organization for sensitive information
d)
Enabling the DLP solution to block all email attachments and USB storage devices to prevent data leakage
80.
Jason, an IT administrator for Kelly Innovations LLC, is tasked with enforcing specific access rights only for the marketing department. Given the tools available on a Windows Active Directory network, which would be the MOST effective way for Jason to accomplish this?
a)
Applying a local group policy on individual marketing department computers
b)
Linking a GPO to the organizational unit containing marketing department users
c)
Creating a new domain for the marketing department
d)
Linking a GPO to a site
81.
The New York Inquirer's main headquarters has a diverse IT infrastructure, including servers, workstations, and IoT devices. They have implemented a firewall to protect their internal network from external threats. The organization wants to modify the firewall rules to enhance security and minimize potential attack vectors. Which modification to firewall ports and protocols is NOT recommended for the organization to enhance security?
a)
Allowing any outgoing traffic to any destination
b)
Enabling stateful Inspection for packet filtering
c)
Closing unused and unnecessary ports and protocols
d)
Implementing port forwarding for remote access to internal servers
82.
Which of the following BEST describes the term 'web reputation score'?
a)
Popularity and frequency of website visitation
b)
The website's SSL/TLS certification status
c)
Assessment of a website's trustworthiness
d)
The loading speed and mobile optimization of a website
83.
Jason, the CTO of Dion Training Solutions, wants to standardize and simplify the web filtering solutions currently in use across the organization's various branches. He also hopes to have a consolidated view of web traffic reports. Which of the following would BEST meet Jason's needs?
a)
Increasing the frequency of software updates
b)
Adopting a cloud-based storage solution
c)
Implementing a centralized proxy
d)
Deploying local firewalls at each branch
84.
Sasha, a system administrator at Dion Training Solutions, is looking to enhance the security of her Linux servers by restricting processes to minimum necessary privileges and defining their behavior. Which Linux feature should Sasha MOST likely implement?
a)
SELinux
b)
SSH key authentication
c)
Filesystem quotas
d)
Chroot environment
85.
Sasha, a security consultant at Kelly Innovations LLC, has been tasked with finding a solution that can monitor and filter the web traffic of employees who frequently travel or work remotely. Which of the following would be the MOST effective solution for ensuring consistent policy enforcement regardless of the user's location?
a)
Requiring remote users to use a specific browser
b)
Setting up strict firewall rules for outbound traffic
c)
Deploying a VPN for remote users
d)
Implementing an agent-based web filter
86.
Soylent International employees use many types of devices to connect to the corporate network. Due to increased security incidents, Claude, Soylent's Chief Security Officer, has decided to implement NAC on the company network. Which of the following choices BEST explains the reason for implementing NAC in the given scenario?
a)
NAC ensures all network traffic is encrypted, protecting sensitive data from unauthorized access
b)
NAC automatically applies all security patches to devices on network related software, ensuring up-to-date security
c)
NAC enables the organization to enforce security policies and controls for all devices connecting to the network
d)
NAC allows employees to access the network remotely, improving productivity and collaboration
87.
Jamario, a network technician at Kelly Innovations LLC, is setting up a new server. He wants to ensure that users can access unencrypted web pages on the server and transfer files to and from it. Jamario should ensure which of the following ports are open? (Select TWO)
a)
21
b)
80
c)
22
d)
25
e)
445
88.
Sasha, a network engineer at Kelly Innovations LLC, is presenting to the board about the advantages of screened subnets in their new office setup. Which of the following is a primary advantage of placing servers accessed from the external internet (like web servers) on a screened subnet?
a)
It enables servers to bypass firewall rules
b)
If compromised, it prevents access to the internal network
c)
It increases the processing speed of the servers
d)
It provides automatic backup for the servers
89.
You are a security administrator for a large non-profit organization with multiple departments and diverse security requirements. The organization has faced challenges in managing security settings and configurations on individual computers. To improve security and streamline management, you decide to implement Group Policy in the Windows Active Directory environment. Which of the following approaches would be the MOST effective way to implement Group Policy for the given scenario?
a)
Designing multiple GPOs, each tailored to the specific security requirements of individual departments, and applying them accordingly
b)
Creating a single, comprehensive GPOs with all security settings applied uniformly across all departments and computers
c)
Designing GPOs so that each has no more than 5 users so that monitoring the members of each group is easier and more customizable
d)
Implementing Group Policy Preferences to enforce security settings, allowing end-users to modify configurations as needed
90.
Reed, a CTO at Dion Training Solutions, is concerned about potential threats like malware command and control as well as data exfiltration from user traffic. Which solution would be MOST effective in filtering URLs that appear on content deny lists and applying time-based restrictions while also performing threat analysis for user traffic?
a)
Implementing a SWG
b)
Using only a NGFW
c)
Using a content filter
d)
Implementing a standalone DLP system
91.
Dion Training Solutions has partnered with several smaller companies. They set up a system allowing employees from any company to access resources from another partner company without requiring a separate username and password. Which of the following is this an example of?
a)
Federation
b)
RBAC
c)
Centralized access management
d)
Access dekegations
92.
A company's access control mechanism determines access to resources based on users' job functions. The system enforces access control based on these predefined responsibilities, and users do not have the discretion to modify or override access permissions. Which type of access control mechanism is being used in this scenario?
a)
Discretionary
b)
Rule-based
c)
Role-based
d)
Attribute-based
93.
Jenny, a newly hired sales representative, has been granted access to view customer records but is unable to modify, delete, or add new ones. Only managers and the IT department have the ability to make changes to these records to maintain data integrity. Which principle is the organization applying?
a)
Attribute-based access control (ABAC)
b)
Principle of least privilege
c)
Data classification
d)
Mandatory access control (MAC)
94.
Oliver travels frequently for work. His organization wants to implement an additional authentication method that considers his geographic location before granting access to sensitive systems. Which factor of multifactor authentication is the organization planning to use?
a)
Something you are
b)
Something you have
c)
Something you know
d)
Somewhere you are
95.
At Jamario Tech, employees often complain about having to remember multiple strong passwords for different platforms, leading some to resort to insecure practices like writing them on sticky notes. The cybersecurity team wants to offer a solution to help employees securely manage and store their numerous credentials. What would be the MOST effective solution for this problem?
a)
Introduce a company-wide password manager
b)
Advise employees to regularly change passwords
c)
Encourage employees to use similar passwords for different platforms
d)
Allow their employees to write down their passwords as long as they keep them safe
96.
John is an IT administrator at Dion Training Solutions. Due to the dynamic nature of his job, he often requires access to various servers and systems on an as-needed basis. The organization wants to ensure that John is granted access only when required and for a short duration. Which security approach would be MOST suitable for John's role?
a)
Just-in-time permissions
b)
Data classification
c)
RBAC
d)
Mandatory access control
97.
Your organization is implementing a new Identity and Access Management (IAM) system to enhance security and streamline user management processes. During the planning phase, you discover that there are multiple existing systems in use that require integration with the new IAM system. Ensuring interoperability between these systems is crucial. What is the BEST approach to achieve interoperability in this scenario?
a)
Replacing all existing systems with new ones that are guaranteed to be compatible with the new IAM system
b)
Implementing SSO to allow users to access multiple systems using a single set of credentials
c)
Creating separate user accounts in each system and maintaining them independently to avoid potential compatibility issues
d)
Assigning different user roles in each system, ensuring no overlap in permissions or access rights
98.
Dion Training is deploying a new application for remote employees. They want to ensure that users can securely log in without needing a physical device other than their smartphones. The system would generate a temporary numeric code on the user's device, which would then be used as a second form of authentication. Which of the following solutions BEST fulfills this requirement?
a)
Software authentication tokens
b)
Network location-based authentication
c)
Static password
d)
Biometric authentication
99.
Sarah, a cloud engineer, often needs to perform maintenance on cloud resources. To ensure high security, her organization wants to grant her access credentials that last only for the duration of her maintenance task and then automatically expire. Which of the following methods is BEST suited for this scenario?
a)
Static access tokens
b)
Principle of least privilege
c)
Time-of-day restrictions
d)
Ephemeral credentials
100.
The access control mechanism at ABC Bank allows access only during working hours. When access is requested, the time of day is evaluated. If the request comes in during working hours, access is granted. If not, access is denied. Which type of access control mechanism is being used in this scenario?
a)
Discretionary
b)
Role-based
c)
Rule-based
d)
Attribute-based
101.
Before providing access to a new cloud-based application, a company verifies the authenticity of its employees by asking them a series of knowledge-based questions, checking their government-issued IDs, and validating their current employment status. This process is an example of:
a)
Account recovery
b)
Identity proofing
c)
2FA
d)
Access delegation
102.
Dion Solutions, an e-commerce platform, has decided to overhaul its user authentication system. Instead of relying on traditional passwords, they want to provide users with an option where their online account credentials are proven only when they unlock their biometric-enabled laptops, all underpinned by public key cryptography. By doing this, users won't need to remember or enter passwords for their accounts. Which of the following BEST describes this authentication solution?
a)
Passkey
b)
CAPTCHA
c)
Hardware token
d)
Password vault
103.
Sasha often travels for work. Her company's secure system detects her login attempts based on her geographical location, allowing access only if she's logging in from an approved country. This system considers which factor of multi-factor authentication?
a)
Something you know
b)
Something you do
c)
Something you have
d)
Somewhere you are
104.
Jamario, the CISO of Dion Training Solutions, noticed that many employees were using simple passwords that were easy to guess. He wants to improve the security of employee accounts. What would be the MOST effective method to enhance password security against brute force attacks?
a)
Using encrypted communication channels
b)
Regularly updating firewall rules
c)
Switching to biometric authentication
d)
Implementing a policy for longer passwords
105.
To enhance security, an organization requires employees to insert a small device into their computer's USB port when logging in. This device proves their identity in combination with something they know, like a password. What are these devices called?
a)
Physical security keys
b)
Biometric scanners
c)
Smart cards
d)
Software tokens
106.
In a large organization dealing with sensitive data, the security team wants a way to provide temporary access credentials to privileged users, such as system administrators. This access should be granted for a short duration and should automatically expire after its intended use. Which method should the organization use for this requirement?
a)
Ephemeral credentials
b)
Static access tokens
c)
Password vaulting
d)
PKI
107.
At NovoTech, employees often use the same password for their email, CRM, and intranet platforms. The typical password format they use is "PlatformName123!" (e.g., "Email123!", "CRM123!"). Recognizing the security risk, what should NovoTech's cybersecurity lead recommend to address the issue of password reuse effectively?
a)
Implement a two-factor authentication for all platforms
b)
Educate employees about the risks of password reuse
c)
Advise employees to use a passphrase instead of a password
d)
Introduce unique password requirements for each platform
108.
Sasha, a cybersecurity analyst at Dion Training Solutions, noticed a trend of employees using the same passwords across multiple work-related platforms. She is concerned about the potential security risks this behavior presents. What should Sasha recommend to BEST mitigate the threat of one compromised password leading to multiple breaches?
a)
Training users on the dangers of phishing emails
b)
Increasing the frequency of password expiration
c)
Implement a policy discouraging password reuse
d)
Conducting more frequent security audits
109.
You are the security administrator for a financial institution that deals with highly sensitive customer data. As part of your IAM strategy, you are implementing an attestation process to ensure the accuracy and validity of user access rights. Which of the following statements best describes the purpose of attestation in this scenario?
a)
Attestation is a process where users are required to provide biometric authentication, such as fingerprints or retina scans, to access sensitive data
b)
Attestation is a process where data owners periodically review, validate and confirm the access rights of all users
c)
Attestation is a procedure where employees must sign a document to acknowledge their acceptance of the company's security policies
d)
Attestation is an audit performed by external regulatory agencies to assess the overall security posture of the financial institution
110.
Dion Training Solutions has noticed that when employees leave the company, their accounts often remain active for an extended period. The IT team is concerned that former employees might access these accounts. What solution would help ensure accounts are only active for a certain period after their last password change?
a)
Use a password complexity checker
b)
Introduce account lockouts after a few incorrect attempts
c)
Implement a maximum password age
d)
Implement a password history policy
111.
Vertex Industries utilizes numerous software tools, each requiring separate authentication. The cybersecurity team is concerned about the frequent support tickets related to forgotten passwords. They believe this could lead to employees adopting unsafe password habits. Which solution would BEST alleviate the stress of remembering multiple credentials and promote better password security?
a)
Increase the password expiration time frame
b)
Encourage employees to document their passwords
c)
Adopt a company-approved password manager
d)
Deploying a stateful firewall
112.
Kelly Innovations LLC recently discovered that a significant number of employees have been using the same password for their work accounts for over a year. The IT department believes this might be contributing to a higher risk of unauthorized account access, especially if any employee’s password was previously compromised. What would be the BEST strategy to regularly prompt employees to update their credentials?
a)
Set a password expiration policy
b)
Increase password complexity requirements
c)
Implement biometric authentication
d)
Mandate periodic security training
113.
You were recently hired by a large software company that specializes in developing mobile applications. After receiving your username and password, you are required to provide a fingerprint scan using a biometric reader to gain access to the company's development environment. Which type of multi-factor authentication (MFA) factor does the biometric reader represent?
a)
Something you have
b)
Somewhere you are
c)
Something you know
d)
Something you are
114.
Reed, an IT manager at Kelly Innovations LLC, found out that a popular password-cracking tool was easily deciphering many user passwords. He suspects this is due to users relying on easily guessable patterns and words. What is the BEST approach for Reed to ensure that passwords are not easily decipherable?
a)
Mandating increased complexity in passwords
b)
Increasing the frequency of mandatory password changes
c)
Switching to a different encryption algorithm for stored passwords
d)
Implementing multi-factor authentication
115.
Kelly Innovations LLC is looking for an authentication method that generates a unique and temporary code to be used for verifying the identity of its remote employees. This code can be generated by a software application installed on the employees' smartphones. Which of the following BEST describes the authentication method the company is considering?
a)
Static passwords
b)
Physical security keys
c)
Biometric authentication
d)
Software authentication tokens
116.
Mary is concerned about the security of her online accounts. She reads about a device she can carry with her, which, when inserted or tapped on her computer or phone, provides a higher level of authentication assurance. Which of the following BEST describes what she is considering?
a)
Physical security keys
b)
QR code scanners
c)
Software-based certificates
d)
Biometric cards
117.
StellarTech Corp. has always been at the forefront of adopting cutting-edge security measures. Recently, the company started a pilot program where employees use a physical device that they plug into their computers. When they tap a button on this device, they are instantly granted access to company systems. Which passwordless authentication method is StellarTech Corp. trialing?
a)
PIN-based authentication
b)
Biometric authentication
c)
Hardware token-based authentication
d)
Cognitive authentication
118.
Which of the following statements BEST explains the importance of considering technical debt?
a)
Addressing technical debt helps organizations to automate security operations more effectively, reducing the need for human intervention
b)
Technical debt can increase the complexity of long term security issues, making automation and orchestration more difficult
c)
Technical debt only applies to non-security-related IT systems such as outdated software and hardware and does not impact the security posture of an organization
d)
Considering technical debt allows organizations to prioritize cybersecurity investments based on the cost of eliminating debt
119.
Which of the following terms BEST describes a situation in which a company avoids addressing known system inefficiencies or shortcuts due to time constraints, potentially leading to future rework and vulnerabilities?
a)
Single point of failure
b)
Technical debt
c)
Cost
d)
Complexity
120.
Which of the following statements is NOT true regarding the role of Ticket Creation in the context of automation for secure operations?
a)
Ticket creation allows proper tracking and management of user issues, requests, or tasks
b)
Ticket creation facilitates communication and coordination among IT teams
c)
Ticket creation fosters more security team cohesion and makes collaboration within the team more effective
d)
Ticket creation enables accountability and better measurement of IT team performance
121.
Which of the following statements BEST explains the importance of 'continuous' integration for the security of an organization?
a)
Continuous integration allows for real-time monitoring of network activities
b)
Continuous integration makes collaboration of security teams and developers easier
c)
Continuous integration automatically generates regular backups of critical data and encrypts them
d)
Continuous integration automates the process of updating and patching software
122.
Which of the following statements BEST explains the importance of employee retention in securing an organization?
a)
Employee retention helps to maintain institutional knowledge and expertise in managing security automation
b)
Employee retention reduces the likelihood of social engineering attacks because long term employees get more training to spot and avoid such attacks
c)
Employee retention reduces the need for automation and orchestration, leading to a more stable workforce
d)
High employee retention promotes a deeper understanding of automated security processes, improving response times
123.
Which of the following statements is NOT true about the importance of continuous integration in relation to secure operations?
a)
Continuous integration may slow down the development process but it provides far more secure systems overall
b)
Continuous integration enables early detection of issues, making it easier to address them before they escalate
c)
Continuous integration automates the building and testing of code, which enhances developer productivity
d)
Continuous integration can increase software quality by catching and fixing bugs quickly
124.
An organization aims to elevate its security posture through improved system configurations. Which of the following BEST describes how automation supports this initiative?
a)
Enhancing user authentication protocols
b)
Facilitating remote team collaborations
c)
Accelerating hardware upgrades
d)
Enforcing consistent baselines across devices
125.
Which of the following statements is NOT true regarding the importance of guard rails in the context of automation for secure operations?
a)
Guard rails function as boundaries in automation workflows to ensure they remain within designed parameters
b)
Guard rails enforce policies that help to avoid errors in automated processes
c)
Guard rails contribute to the safety of automation and orchestration by preventing unintended actions
d)
Guard rails are primarily focus on providing baseline security for servers rooms and sever systems
126.
Why might an organization be particularly concerned about introducing automation tools that become single points of failure during secure operations?
a)
Challenges in upholding data confidentiality
b)
Potential gaps in maintaining data integrity
c)
Issues related to system scalability and slow authentication
d)
Compromised availability leading to operational disruptions
127.
The HR department for a large corporation is looking to streamline the onboarding process for new employees. What can the use of scripting do to help attain this goal in terms of system access?
a)
Facilitating personal interviews between IT and new hires
b)
Automating the provisioning of account credentials
c)
Generation of hard-copy user manuals for each new hire
d)
Directly improving the onboarding training content
128.
Which of the following statements BEST explains the importance of considering single points of failure?
a)
Identifying single points of failure helps in centralizing control of security systems for better orchestration
b)
Mitigating single points of failure is crucial to maintain the availability and reliability of automated security operations
c)
Single points of failure represent an entry point into a system so being aware of them will prevent more failures throughout the system
d)
Addressing single points of failure ensures that automated security processes do not replace human decision-making
129.
Which of the following statements is NOT true about the importance of resource provisioning in relation to secure operations?
a)
Resource provisioning reduces the risk of resource-related security vulnerabilities by assigning appropriate permissions
b)
Resource provisioning allows for punctual adjustment of resources depending on the changing needs of an organization
c)
Resource provisioning contributes to operational efficiency by avoiding over-provisioning or under-provisioning of resources
d)
Resource provisioning ensures employees have accounts when they are hired and those accounts are deprovisioned when they leave
130.
Which of the following statements BEST explains the importance of automating resource provisioning?
a)
It decreases the flexibility and adaptability of cloud systems
b)
It restricts resources to only pre-defined configurations
c)
It helps in rapid scaling of resources based on demand
d)
It ensures only one user can access a resource at a time
131.
Which of the following statements BEST explains the importance of enforcing baselines when automating and orchestrating secure operations?
a)
Baselines eliminate the need for continuous monitoring of systems because these things are all either automated or orchestrated, thereby freeing up resources
b)
Enforcing baselines allows for the almost complete automation of incident response, reducing the need for large security teams and incident response teams
c)
Baselines set the initial targets for automating threat hunting and penetration testing, thereby reducing dependence on human input
d)
Enforcing baselines helps to standardize configurations across systems, enabling efficient automation and reducing the risk of security incidents
132.
Which of the following is MOST crucial when determining the ongoing supportability of a newly introduced security automation tool in the organization's environment?
a)
Tool popularity in the market
b)
Availability of skilled personnel
c)
Vendor's market presence
d)
Integration capabilities
133.
Which of the following statements BEST explains the importance of the workforce multiplier?
a)
The workforce multiplier reduces the need for highly skilled and credentialed cybersecurity professionals, resulting in cost savings for the organization
b)
The workforce multiplier limits the scope of security incidents by rapidly deploying virtual firewalls, preventing them from affecting a large number of users
c)
Workforce multiplier enables organizations to rapidly scale their security capabilities using a combination of human and automated resources
d)
Leveraging the workforce multiplier allows organizations to replace manual security tasks with automated processes, improving efficiency
134.
In the realm of digital forensics, which activity is MOST essential to maintaining the chain of custody for digital evidence?
a)
Drafting a comprehensive summary of findings after analyzing the evidence
b)
Isolating the digital evidence storage system from network access
c)
Documenting who has handled the evidence
d)
Utilizing cryptographic hashes to confirm the integrity of stored evidence
135.
In digital forensics, which of the following MOST describes why the acquisition process is of utmost importance?
a)
It provides a platform for communication between IT and legal teams
b)
It grants forensic investigators immediate access to a crime scene
c)
It ensures a precise and unaltered copy of digital evidence is obtained
d)
It determines the relevance of the evidence to the case
136.
Which of the following BEST describes the primary purpose of e-discovery in digital investigations?
a)
It sets guidelines for selecting appropriate forensic software tools throughout the investigation
b)
It offers insights into the potential financial consequences of an incident being investigated
c)
It provides methodologies to ensure consistent data protection during the investigation process
d)
It aids in identifying, collecting, and producing electronically stored information for legal cases
137.
Which of the following statements BEST explains the importance of the Chain of Custody in incident response?
a)
The chain of custody is the process of systematically analyzing how the incident referred, linking the events from inception to the point of attack
b)
The chain of custody determines the individuals or groups responsible for the incident and helps in legal proceedings
c)
The chain of custody involves following the processes as they are laid out in the incident response plan from Preparation to Lessons Learned
d)
The chain of custody is the process of securing and preserving evidence related to a security incident for potential use in legal proceedings
138.
In the realm of digital forensics, which activity is a primary focus during the preservation phase?
a)
Generating and documenting cryptographic hashes of digital evidence to verify its integrity
b)
Drafting a comprehensive summary of findings and presenting it to stakeholders
c)
Performing keyword searches on electronic documents to identify pertinent information
d)
Recording the specific tools and methodologies used during the evidence collection phase
139.
Which of the following statements BEST explains the importance of 'E-discovery' in incident response?
a)
E-discovery requires the finding and recognizing potential threats or breaches in the security infrastructure to prevent incidents
b)
E-discovery involves examining drives to find data that is electronically stored to use them for evidence
c)
E-discovery dictates the steps in preserving evidence in its original state to maintain its integrity for future forensic or legal needs
d)
E-discovery is a step in the process of documenting the details of a security incident, its impact, and potential remedies
140.
Which of the following statements best explains the importance of Threat Hunting in incident response?
a)
Threat Hunting determines the individuals or groups responsible for the incident and helps in legal proceedings
b)
Threat Hunting allows the identifying and mitigating of security threats before they cause damage
c)
Threat hunting involves removing the root cause of the incident from affected systems and networks to prevent its recurrence
d)
Threat hunting is the process of identifying and classifying incidents based on their severity and impact to the organization
141.
Which of the following statements represents the correct order of steps in the incident response process?
a)
Detection, Eradication, Containment, Preparation, Recovery
b)
Preparation, Detection, Eradication, Containment, Recovery
c)
Preparation, Detection, Containment, Eradication, Recovery
d)
Containment, Preparation, Detection, Eradication, Recovery
142.
In digital forensics, which of the following is MOST crucial to consider when determining the requirements for an investigative report?
a)
The intended audience of the report
b)
The personal preferences of the forensic analyst
c)
The software tools used in the investigation
d)
The geographical location of the incident
143.
While performing a digital investigation, which of the following statements BEST describes the role of preservation of evidence?
a)
It maintains the integrity of digital evidence over time
b)
It allows investigators to prioritize evidence collection
c)
It allocates budgetary resources for the forensic investigation
d)
It provides legal teams with a roadmap for case strategy
144.
Which of the following statements BEST explains the importance of 'Preservation' in incident response?
a)
Preservation is the process of carefully handling evidence to maintain its integrity for future forensic analysis
b)
Preservation is the process of recognizing potential threats protect an organization's infrastructure
c)
Preservation is the process of keeping security controls up to date to prevent future incidents
d)
Preservation is the process of documenting the details of a security incident, its impact, and potential remedies
145.
Which of the following activities take place during the detection phase in the incident response process?
a)
Analyzing the evidence and determining the root cause of the incident
b)
Determining how long it will take to get affected systems and services to their normal operation after an incident
c)
Identifying and classifying incidents based on their severity and impact to the organization
d)
Limiting contact of the affected device with other devices and looking for the problem on the affected device
146.
Which of the following statements BEST explains the importance of Root Cause Analysis in incident response?
a)
Root Cause Analysis helps to understand how the incident occurred and how to prevent similar incidents in the future
b)
Root Cause Analysis helps determining how severe and incident would be and how it would impact the organization
c)
Root Cause Analysis determines the individuals or groups responsible for the incident and helps in legal proceedings
d)
Root Cause Analysis involves removing the root cause of the incident from affected systems and networks to prevent its recurrence
147.
As a security analyst, you are examining packet captures for an ongoing investigation into a network breach. Which of the following information is NOT typically recorded in packet captures?
a)
Protocols used in the captured data
b)
Source and destination IP addresses
c)
The content of secure encrypted communications
d)
The timestamp of the captured data
148.
As a security analyst, you are investigating a suspicious file activity incident. While examining metadata associated with different files, which of the following pieces of information is NOT typically presented in metadata?
a)
Users who have accessed the file
b)
File size
c)
Date and time of last modification
d)
The file's creator
149.
You are a security analyst tasked with investigating a suspected security breach incident. You decide to examine the Firewall logs. Which of the following pieces of information would be MOST valuable in this firewall log to investigate the incident?
a)
The number of software updates performed last month, when they were completed and what was installed
b)
A summary of the amount of data bandwidth and throughput by each department over the previous week
c)
The details of the website purchases made by employees during lunchtime
d)
Connection details including source and destination IPs, timestamps, and ports used in the last week
150.
You are a security analyst tasked with investigating a suspected security breach on a company's Linux server. You decide to examine the operating system (OS)-specific security logs. Which of the following pieces of information would be MOST valuable in these logs to investigate the incident?
a)
Information about the latest patches and software updates installed on the server
b)
The amount of free storage space left on the server and whether the amount has changed recently
c)
Information about the number of users added to the server in the past year
d)
Records of failed and successful system and user level authentications
151.
You are a security analyst tasked with investigating a suspected security breach that occurred two days ago and involved a frequently used spreadsheet application. You decide to examine the application logs. Which of the following pieces of information would be MOST valuable in these logs to investigate the incident?
a)
Details of failed logins, including timestamps, usernames, and originating IP addresses for the past week
b)
The number of updates performed on the application in the last two months
c)
Details of the users currently online using the spreadsheet application and its macros
d)
The total number of transactions processed by the application in the previous 2 days
152.
As a security analyst, you are reviewing application logs while investigating a suspected breach. Which of the following pieces of information is NOT typically documented in the application log data?
a)
Timestamps of application activity
b)
The physical location of the user accessing the application
c)
Server IP address where the application is hosted
d)
User IDs related to specific application transactions
153.
As a security analyst, you are reviewing firewall logs as part of an ongoing investigation into suspicious network activity. Which of the following pieces of information is NOT typically available in the firewall log data?
a)
Open ports on the destination device
b)
Destination port the traffic was trying to reach
c)
Timestamps of firewall log entries
d)
Source IP address of the traffic