Font size
WorksheetsSec+ 701 061209302025
Total questions: 59
Worksheet time: 30mins
An organization with a public-facing application is experiencing growth and has implemented multiple virtual servers to boost performance and reduce the load on individual servers. What solution is most likely to be deployed to further enhance the application's performance and availability?
Load balancer
Jump server
Proxy server
SD-WAN
Which of the following security concepts mandates that a system must first verify an entity before permitting it to send data to other systems?
Policy enforcement
Authentication
Zero Trust architecture
Confidentiality
Identify which of the following is considered a technical security measure.
Security guard
Policy
Fence
Firewall
A security analyst needs to automate a routine function that involves exchanging data between different systems. The most suitable technology for the analyst to utilize.
SOAR
API
SFTP
RDP
What is the primary reason for implementing a two-person integrity security control for a critical process?
To speed up the task so it takes only half the time compared to one individual doing it alone
To let two employees from another department monitor the work being done by an authorized individual
To minimize the chance of mistakes or prevent unauthorized individuals from carrying out the process
To enable one individual to carry out the task while being monitored by a CCTV camera
A company wants to keep a record of all changes made to the source code used for creating new virtual servers. What tool will the company most likely implement?
Change management ticketing system
Behavioral analyzer
Collaboration platform
Version control tool
Which type of attack best describes this activity?
Spraying
Brute-force
Dictionary
Rainbow table
Which of the following phases represents the final step in the modern incident response lifecycle?
Lessons learned
Eradication
Containment
Recovery
Within the risk management process, which step involves defining the project's boundaries and identifying potential hazards?
Risk mitigation
Risk identification
Risk treatment
Risk monitoring and review
A security analyst is investigating an application server and observes that a program that normally performs local batch jobs and generates no network traffic is now unexpectedly sending outbound data over random high ports. Which type of vulnerability has most likely been exploited in this software?
Remote code execution
SQL injection
Cross-site scripting (XSS)
Denial of service (DoS)
Which of the following is an example of a vulnerability that allows code to be injected into memory at runtime?
Memory injection
Race condition
Side loading
SQL injection
A company wants to allow employees to copy files from their virtual desktop during standard business hours but prevent this activity outside of those hours. Which security measure should the company configure?
Digital rights management
Role-based access control
Time-based access control
Network access control
An attacker attempts to gain unauthorized access to underlying systems by submitting a request that includes unexpected characters. Which attack best describes this action?
Side loading
Target of evaluation
Resource reuse
SQL injection
As part of the Business Impact Analysis (BIA), which metric directly influences how often backups must be performed?
RTO
RPO
An accounts payable clerk at a company receives a request from a vendor to update their bank account details before a payment is sent. The clerk makes the change and processes the payment to the new account. Days later, the clerk receives another message from the vendor, inquiring about a missing payment to the original bank account. What is the most likely cause of this incident?
Phishing campaign
Data exfiltration
Pretext calling
Business email compromise
A security team is receiving reports of widespread high latency and complete network outages across the office building. Flow logs from the campus switches indicate an unusually high volume of traffic on TCP port 445. What is the most probable root cause of this incident?
Buffer overflow
NTP amplification attack
Worm
Kerberoasting attack
What is the most effective way to test a system's ability to maintain operation and recover after a primary power source failure?
Parallel processing
Tabletop exercise
Simulation testing
Production failover
What is the most effective method to safeguard an application server running end-of-life, unsupported software from network-based threats?
Air gap
Barricade
Port security
Screen subnet
By deploying a Host-based Intrusion Prevention System (HIPS), which two security control types is a company implementing?
Preventive
Detective
Directive
Physical
Corrective
At the beginning of a penetration test, the tester consults Open Source Intelligence (OSINT) resources to gather information about the client's environment. What kind of reconnaissance is the tester performing?
Active
Passive
Offensive
Which threat actor is most likely driven by personal beliefs or ideology when attacking an organization?
Nation-state
Organized crime
Hacktivist
Insider threat
A security engineer is deploying an Intrusion Prevention System (IPS) to automatically block known signature-based attacks within the network environment. Which mode of operation is best suited to achieve this goal?
Monitor
Sensor
Audit
Active
Which vulnerability type involves compromising a virtual machine (VM) to gain unauthorized access to adjacent hosts on the same physical server?
VM escape
Side loading
Remote code execution
Resource exhaustion
Which application identification method can be executed on a software application while it is running in its deployed environment?
Dynamic analysis
Code review
Package monitoring
Bug bounty
A network administrator aims to ensure that network traffic is highly secured during transmission. Which set of actions best describes the steps the network administrator should take?
Verify that NAC is applied across all network segments and that firewalls use updated rules to block unauthorized access.
Require TLS and other encrypted protocols for network communication, allowing only approved traffic through secure channels.
Set up the perimeter IPS to block HTTPS directory traversal attempts and confirm signatures are refreshed daily.
Make sure the EDR system detects unauthorized applications that attackers could exploit and is configured to alert the security team.
A company is rolling out a Bring Your Own Device (BYOD) policy but wants to restrict application installation on employee personal equipment to only company-approved software. What solution addresses this specific concern?
MDM
Containerization
DLP
FIM
What process should be used to assign a descriptive label to a file based on its business value, data sensitivity, or applicable regulatory requirements?
Verification
Certification
Classification
Inventory
An organization must demonstrate that its security controls are correctly designed and are operating effectively as intended. Which report type will best fulfill this objective?
Red teaming
Penetration testing
Independent audit
Vulnerability assessment
Which tactic is most frequently employed by attackers to perform credential harvesting?
Social engineering
Supply chain compromise
Third-party software
Rainbow table
In the event a retail chain fails to comply with the Payment Card Industry Data Security Standard (PCI DSS), which consequence would they most likely face from their customers?
Contractual impacts
Sanctions
Fines
Reputational damage
A security analyst must develop a remediation plan for every item in the risk register. The highest-priority item states that employees have separate logins and differing password complexity requirements for various Software as a Service (SaaS) solutions. What implementation plan is most likely to resolve this security issue effectively?
Establish a consistent password complexity policy
Connect all SaaS applications to the identity provider
Protect access to all SaaS apps with one wildcard certificate
Apply geofencing controls to each SaaS application
A security analyst receives an alert from a corporate endpoint used by employees to issue visitor badges, with the alert containing details about numerous failed login attempts. Which type of indicator most accurately describes what triggered this alert?
Blocked content
Brute-force attack
Concurrent session usage
Account lockout
Which scenario accurately describes a possible Business Email Compromise (BEC) attack?
Email requests gift cards using an executive’s name
Opening an attachment triggers a ransom demand
HR director email requests cloud admin credentials
Email contains a link to a fake company portal
Which threat vector is the most commonly exploited by insider threat actors when attempting to steal data (data exfiltration)?
Unidentified removable devices
Default network device credentials
Spear phishing emails
Impersonation of business units through typosquatting
An organization has been notified that its data is being sold or exchanged on the dark web. The CIO has requested an investigation to identify weak security practices and implement the most secure solution to protect all employee accounts. What is the most appropriate security solution to meet the CIO's requirements?
Implement multi-factor authentication (MFA) for all employee accounts
Increase password length requirements only
Rely solely on employee security awareness training
Disable all external access to company systems
When a host-based firewall on a legacy Linux system is configured to permit connections only from a specific list of internal IP addresses, what security principle is being implemented?
Compensating control
Network segmentation
Transfer of risk
SNMP traps
A security analyst discovers a potentially malicious video file on a server and needs to determine both the date the file was created and the identity of the user who created it. Which action is most likely to provide the required information?
Obtain the file's SHA-256 hash
Use hexdump on the file's contents.
Check endpoint logs.
Query the file's metadata
A healthcare organization is developing a web application that allows users to digitally report medical emergencies. Which factor is the most crucial consideration during the application's development?
Scalability
Availability
Cost
Ease of deployment
A security analyst reviewing domain activity logs observes numerous failed login attempts for a specific user account. Which conclusion best explains the analyst's discovery?
jdoe’s account is locked out
Keylogger detected on jdoe’s workstation
Brute-force attempt on jdoe’s account
Ransomware deployed in the domain
A user receives an email from someone pretending to be a company executive, requesting sensitive details to close an outstanding invoice. Which topic from the training did the user successfully identify?
Insider threat
Email phishing
Social engineering
Executive whaling
A security audit found that a majority of the IT staff possess domain administrator credentials and have not been regularly changing their passwords. What solution should the security team recommend to resolve these findings in the most comprehensive manner?
Enforce password rotation via group policies
Audit admin group and rotate all passwords
Require SSO with MFA for admin access
Store credentials in PAM with role-based access
A Chief Information Security Officer (CISO) wishes to specifically highlight the increased threat posed by ransomware-as-a-service in a report to the management team. Which threat actor best describes the entity discussed in the CISO's report?
Insider threat
Hacktivist
Nation-state
Organized crime
A security analyst successfully identifies an active incident within the network. Which phase of the incident response process should the security analyst perform immediately after identification?
Containment
Detection
Eradication
Recovery
What protocol is employed to verify the current validity status of a digital certificate when it is presented to a user's browser or application?
A. OCSP
B. CSR
C. CA
D. CRC
Which social engineering attack involves a malicious actor impersonating a legitimate website URL by using a closely-spelled alternative?
Pretexting
Misinformation
Typosquatting
Watering-hole
A security analyst is tasked with creating the initial network diagram for a company's new customer-facing payment application, which will be hosted by an external cloud service provider. What is the primary purpose of this network diagram?
To visualize the architecture and data flow of the payment application
To configure firewall rules for the application
To select the cloud service provider
To monitor real-time application performance
What is the name of the security tool used for centralized collection, analysis, alerting, and monitoring of system, application, and network logs from various sources?
SIEM
DLP
IDS
SNMP
What is the best immediate course of action to mitigate a zero-day vulnerability discovered in mission-critical production servers that must maintain high availability?
Move to a virtualized container environment
Quarantine in an isolated network
Implement monitoring and compensating controls
Apply patches and return to production quickly
An administrator needs to replace an expired SSL certificate. What file or request must the administrator generate to begin the process of obtaining the new SSL certificate?
CSR
OCSP
Key
Which data type best describes an Artificial Intelligence (AI) tool that a company developed internally to automate its ticketing system under a specific contract?
Classified
Regulated information
Open source
Intellectual property
An employee used the company's billing system to process fraudulent checks. The administrator is now searching for evidence of any similar previous occurrences of this activity. Which log source should the administrator focus on?
Application logs
Vulnerability scanner logs
IDS/IPS logs
Firewall logs
A company wants to receive alerts when external parties are conducting research and reconnaissance on the company's infrastructure. One strategy involves placing a portion of the company's infrastructure online, configured with known vulnerabilities, to appear as legitimate company assets. What is this security approach called?
Watering hole
Bug bounty
DNS sinkhole
A visitor connects their laptop to an unoccupied network port in the lobby and gains access to the company's network. Which configuration on the existing network infrastructure is the most effective way to prevent this activity?
Port security
Web application firewall
Transport layer security
Virtual private network
A company is required to ensure that sensitive data stored on its systems (data at rest) is rendered unreadable to unauthorized users. What method will the company most likely use?
Hashing
Tokenization
Encryption
Segmentation
Which architectural model is most appropriate for establishing redundancy and ensuring high availability for essential business processes?
Network-enabled
Server-side
Cloud-native
Multitenant
A systems administrator is concerned about security weaknesses within cloud computing instances. What is the most critical vulnerability the administrator must consider when designing a cloud computing environment?
SQL injection
TOC/TOU
VM escape
Tokenization
Password spraying
A US-based cloud hosting provider plans to launch new data centers in international locations. What is the most important factor the hosting provider should analyze before expanding?
Local data protection regulations
Risks from hackers residing in other countries
Impacts to existing contractual obligations
Time zone differences in log correlation
According to the shared responsibility model in an Infrastructure as a Service (IaaS) cloud environment, which role is accountable for the security of the company's database?
Client
Third-party vendor
Cloud provider
DBA
A company uncovers suspicious transactions that were entered into the company's database and traced back to a user account that was intentionally created to act as a trap for malicious activity. What is this specific user account an example of?
Honeytoken
Honeynet
Honeypot
Honeyfile
