wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Sec+ 701 061209302025

Total questions: 59

Worksheet time: 30mins

Name
Class
Date
1.

An organization with a public-facing application is experiencing growth and has implemented multiple virtual servers to boost performance and reduce the load on individual servers. What solution is most likely to be deployed to further enhance the application's performance and availability?

a)

Load balancer

b)

Jump server

c)

Proxy server

d)

SD-WAN

2.

Which of the following security concepts mandates that a system must first verify an entity before permitting it to send data to other systems?

a)

Policy enforcement

b)

Authentication

c)

Zero Trust architecture

d)

Confidentiality

3.

Identify which of the following is considered a technical security measure.

a)

Security guard

b)

Policy

c)

Fence

d)

Firewall

4.

A security analyst needs to automate a routine function that involves exchanging data between different systems. The most suitable technology for the analyst to utilize.

a)

SOAR

b)

API

c)

SFTP

d)

RDP

5.

What is the primary reason for implementing a two-person integrity security control for a critical process?

a)

To speed up the task so it takes only half the time compared to one individual doing it alone

b)

To let two employees from another department monitor the work being done by an authorized individual

c)

To minimize the chance of mistakes or prevent unauthorized individuals from carrying out the process

d)

To enable one individual to carry out the task while being monitored by a CCTV camera

6.

A company wants to keep a record of all changes made to the source code used for creating new virtual servers. What tool will the company most likely implement?

a)

Change management ticketing system

b)

Behavioral analyzer

c)

Collaboration platform

d)

Version control tool

7.

Which type of attack best describes this activity?

a)

Spraying

b)

Brute-force

c)

Dictionary

d)

Rainbow table

8.

Which of the following phases represents the final step in the modern incident response lifecycle?

a)

Lessons learned

b)

Eradication

c)

Containment

d)

Recovery

9.

Within the risk management process, which step involves defining the project's boundaries and identifying potential hazards?

a)

Risk mitigation

b)

Risk identification

c)

Risk treatment

d)

Risk monitoring and review

10.

A security analyst is investigating an application server and observes that a program that normally performs local batch jobs and generates no network traffic is now unexpectedly sending outbound data over random high ports. Which type of vulnerability has most likely been exploited in this software?

a)

Remote code execution

b)

SQL injection

c)

Cross-site scripting (XSS)

d)

Denial of service (DoS)

11.

Which of the following is an example of a vulnerability that allows code to be injected into memory at runtime?

a)

Memory injection

b)

Race condition

c)

Side loading

d)

SQL injection

12.

A company wants to allow employees to copy files from their virtual desktop during standard business hours but prevent this activity outside of those hours. Which security measure should the company configure?

a)

Digital rights management

b)

Role-based access control

c)

Time-based access control

d)

Network access control

13.

An attacker attempts to gain unauthorized access to underlying systems by submitting a request that includes unexpected characters. Which attack best describes this action?

a)

Side loading

b)

Target of evaluation

c)

Resource reuse

d)

SQL injection

14.

As part of the Business Impact Analysis (BIA), which metric directly influences how often backups must be performed?

a)

RTO

b)

RPO

15.

An accounts payable clerk at a company receives a request from a vendor to update their bank account details before a payment is sent. The clerk makes the change and processes the payment to the new account. Days later, the clerk receives another message from the vendor, inquiring about a missing payment to the original bank account. What is the most likely cause of this incident?

a)

Phishing campaign

b)

Data exfiltration

c)

Pretext calling

d)

Business email compromise

16.

A security team is receiving reports of widespread high latency and complete network outages across the office building. Flow logs from the campus switches indicate an unusually high volume of traffic on TCP port 445. What is the most probable root cause of this incident?

a)

Buffer overflow

b)

NTP amplification attack

c)

Worm

d)

Kerberoasting attack

17.

What is the most effective way to test a system's ability to maintain operation and recover after a primary power source failure?

a)

Parallel processing

b)

Tabletop exercise

c)

Simulation testing

d)

Production failover

18.

What is the most effective method to safeguard an application server running end-of-life, unsupported software from network-based threats?

a)

Air gap

b)

Barricade

c)

Port security

d)

Screen subnet

19.

By deploying a Host-based Intrusion Prevention System (HIPS), which two security control types is a company implementing?

a)

Preventive

b)

Detective

c)

Directive

d)

Physical

e)

Corrective

20.

At the beginning of a penetration test, the tester consults Open Source Intelligence (OSINT) resources to gather information about the client's environment. What kind of reconnaissance is the tester performing?

a)

Active

b)

Passive

c)

Offensive

21.

Which threat actor is most likely driven by personal beliefs or ideology when attacking an organization?

a)

Nation-state

b)

Organized crime

c)

Hacktivist

d)

Insider threat

22.

A security engineer is deploying an Intrusion Prevention System (IPS) to automatically block known signature-based attacks within the network environment. Which mode of operation is best suited to achieve this goal?

a)

Monitor

b)

Sensor

c)

Audit

d)

Active

23.

Which vulnerability type involves compromising a virtual machine (VM) to gain unauthorized access to adjacent hosts on the same physical server?

a)

VM escape

b)

Side loading

c)

Remote code execution

d)

Resource exhaustion

24.

Which application identification method can be executed on a software application while it is running in its deployed environment?

a)

Dynamic analysis

b)

Code review

c)

Package monitoring

d)

Bug bounty

25.

A network administrator aims to ensure that network traffic is highly secured during transmission. Which set of actions best describes the steps the network administrator should take?

a)

Verify that NAC is applied across all network segments and that firewalls use updated rules to block unauthorized access.

b)

Require TLS and other encrypted protocols for network communication, allowing only approved traffic through secure channels.

c)

Set up the perimeter IPS to block HTTPS directory traversal attempts and confirm signatures are refreshed daily.

d)

Make sure the EDR system detects unauthorized applications that attackers could exploit and is configured to alert the security team.

26.

A company is rolling out a Bring Your Own Device (BYOD) policy but wants to restrict application installation on employee personal equipment to only company-approved software. What solution addresses this specific concern?

a)

MDM

b)

Containerization

c)

DLP

d)

FIM

27.

What process should be used to assign a descriptive label to a file based on its business value, data sensitivity, or applicable regulatory requirements?

a)

Verification

b)

Certification

c)

Classification

d)

Inventory

28.

An organization must demonstrate that its security controls are correctly designed and are operating effectively as intended. Which report type will best fulfill this objective?

a)

Red teaming

b)

Penetration testing

c)

Independent audit

d)

Vulnerability assessment

29.

Which tactic is most frequently employed by attackers to perform credential harvesting?

a)

Social engineering

b)

Supply chain compromise

c)

Third-party software

d)

Rainbow table

30.

In the event a retail chain fails to comply with the Payment Card Industry Data Security Standard (PCI DSS), which consequence would they most likely face from their customers?

a)

Contractual impacts

b)

Sanctions

c)

Fines

d)

Reputational damage

31.

A security analyst must develop a remediation plan for every item in the risk register. The highest-priority item states that employees have separate logins and differing password complexity requirements for various Software as a Service (SaaS) solutions. What implementation plan is most likely to resolve this security issue effectively?

a)

Establish a consistent password complexity policy

b)

Connect all SaaS applications to the identity provider

c)

Protect access to all SaaS apps with one wildcard certificate

d)

Apply geofencing controls to each SaaS application

32.

A security analyst receives an alert from a corporate endpoint used by employees to issue visitor badges, with the alert containing details about numerous failed login attempts. Which type of indicator most accurately describes what triggered this alert?

a)

Blocked content

b)

Brute-force attack

c)

Concurrent session usage

d)

Account lockout

33.

Which scenario accurately describes a possible Business Email Compromise (BEC) attack?

a)

Email requests gift cards using an executive’s name

b)

Opening an attachment triggers a ransom demand

c)

HR director email requests cloud admin credentials

d)

Email contains a link to a fake company portal

34.

Which threat vector is the most commonly exploited by insider threat actors when attempting to steal data (data exfiltration)?

a)

Unidentified removable devices

b)

Default network device credentials

c)

Spear phishing emails

d)

Impersonation of business units through typosquatting

35.

An organization has been notified that its data is being sold or exchanged on the dark web. The CIO has requested an investigation to identify weak security practices and implement the most secure solution to protect all employee accounts. What is the most appropriate security solution to meet the CIO's requirements?

a)

Implement multi-factor authentication (MFA) for all employee accounts

b)

Increase password length requirements only

c)

Rely solely on employee security awareness training

d)

Disable all external access to company systems

36.

When a host-based firewall on a legacy Linux system is configured to permit connections only from a specific list of internal IP addresses, what security principle is being implemented?

a)

Compensating control

b)

Network segmentation

c)

Transfer of risk

d)

SNMP traps

37.

A security analyst discovers a potentially malicious video file on a server and needs to determine both the date the file was created and the identity of the user who created it. Which action is most likely to provide the required information?

a)

Obtain the file's SHA-256 hash

b)

Use hexdump on the file's contents.

c)

Check endpoint logs.

d)

Query the file's metadata

38.

A healthcare organization is developing a web application that allows users to digitally report medical emergencies. Which factor is the most crucial consideration during the application's development?

a)

Scalability

b)

Availability

c)

Cost

d)

Ease of deployment

39.

A security analyst reviewing domain activity logs observes numerous failed login attempts for a specific user account. Which conclusion best explains the analyst's discovery?

a)

jdoe’s account is locked out

b)

Keylogger detected on jdoe’s workstation

c)

Brute-force attempt on jdoe’s account

d)

Ransomware deployed in the domain

40.

A user receives an email from someone pretending to be a company executive, requesting sensitive details to close an outstanding invoice. Which topic from the training did the user successfully identify?

a)

Insider threat

b)

Email phishing

c)

Social engineering

d)

Executive whaling

41.

A security audit found that a majority of the IT staff possess domain administrator credentials and have not been regularly changing their passwords. What solution should the security team recommend to resolve these findings in the most comprehensive manner?

a)

Enforce password rotation via group policies

b)

Audit admin group and rotate all passwords

c)

Require SSO with MFA for admin access

d)

Store credentials in PAM with role-based access

42.

A Chief Information Security Officer (CISO) wishes to specifically highlight the increased threat posed by ransomware-as-a-service in a report to the management team. Which threat actor best describes the entity discussed in the CISO's report?

a)

Insider threat

b)

Hacktivist

c)

Nation-state

d)

Organized crime

43.

A security analyst successfully identifies an active incident within the network. Which phase of the incident response process should the security analyst perform immediately after identification?

a)

Containment

b)

Detection

c)

Eradication

d)

Recovery

44.

What protocol is employed to verify the current validity status of a digital certificate when it is presented to a user's browser or application?

a)

A. OCSP

b)

B. CSR

c)

C. CA

d)

D. CRC

45.

Which social engineering attack involves a malicious actor impersonating a legitimate website URL by using a closely-spelled alternative?

a)

Pretexting

b)

Misinformation

c)

Typosquatting

d)

Watering-hole

46.

A security analyst is tasked with creating the initial network diagram for a company's new customer-facing payment application, which will be hosted by an external cloud service provider. What is the primary purpose of this network diagram?

a)

To visualize the architecture and data flow of the payment application

b)

To configure firewall rules for the application

c)

To select the cloud service provider

d)

To monitor real-time application performance

47.

What is the name of the security tool used for centralized collection, analysis, alerting, and monitoring of system, application, and network logs from various sources?

a)

SIEM

b)

DLP

c)

IDS

d)

SNMP

48.

What is the best immediate course of action to mitigate a zero-day vulnerability discovered in mission-critical production servers that must maintain high availability?

a)

Move to a virtualized container environment

b)

Quarantine in an isolated network

c)

Implement monitoring and compensating controls

d)

Apply patches and return to production quickly

49.

An administrator needs to replace an expired SSL certificate. What file or request must the administrator generate to begin the process of obtaining the new SSL certificate?

a)

CSR

b)

OCSP

c)

Key

50.

Which data type best describes an Artificial Intelligence (AI) tool that a company developed internally to automate its ticketing system under a specific contract?

a)

Classified

b)

Regulated information

c)

Open source

d)

Intellectual property

51.

An employee used the company's billing system to process fraudulent checks. The administrator is now searching for evidence of any similar previous occurrences of this activity. Which log source should the administrator focus on?

a)

Application logs

b)

Vulnerability scanner logs

c)

IDS/IPS logs

d)

Firewall logs

52.

A company wants to receive alerts when external parties are conducting research and reconnaissance on the company's infrastructure. One strategy involves placing a portion of the company's infrastructure online, configured with known vulnerabilities, to appear as legitimate company assets. What is this security approach called?

a)

Watering hole

b)

Bug bounty

c)

DNS sinkhole

53.

A visitor connects their laptop to an unoccupied network port in the lobby and gains access to the company's network. Which configuration on the existing network infrastructure is the most effective way to prevent this activity?

a)

Port security

b)

Web application firewall

c)

Transport layer security

d)

Virtual private network

54.

A company is required to ensure that sensitive data stored on its systems (data at rest) is rendered unreadable to unauthorized users. What method will the company most likely use?

a)

Hashing

b)

Tokenization

c)

Encryption

d)

Segmentation

55.

Which architectural model is most appropriate for establishing redundancy and ensuring high availability for essential business processes?

a)

Network-enabled

b)

Server-side

c)

Cloud-native

d)

Multitenant

56.

A systems administrator is concerned about security weaknesses within cloud computing instances. What is the most critical vulnerability the administrator must consider when designing a cloud computing environment?

a)

SQL injection

b)

TOC/TOU

c)

VM escape

d)

Tokenization

e)

Password spraying

57.

A US-based cloud hosting provider plans to launch new data centers in international locations. What is the most important factor the hosting provider should analyze before expanding?

a)

Local data protection regulations

b)

Risks from hackers residing in other countries

c)

Impacts to existing contractual obligations

d)

Time zone differences in log correlation

58.

According to the shared responsibility model in an Infrastructure as a Service (IaaS) cloud environment, which role is accountable for the security of the company's database?

a)

Client

b)

Third-party vendor

c)

Cloud provider

d)

DBA

59.

A company uncovers suspicious transactions that were entered into the company's database and traced back to a user account that was intentionally created to act as a trap for malicious activity. What is this specific user account an example of?

a)

Honeytoken

b)

Honeynet

c)

Honeypot

d)

Honeyfile