WorksheetsMultiple Choice Questions 1-10
Total questions: 143
Worksheet time: 72hrs 1mins
Which of the following threat actors is the most likely to be hired by a foreign government to attack critical systems located in other countries?
Hacktivist
Whistleblower
Organized crime
Unskilled attacker
Which of the following is used to add extra complexity before using a one-way data transformation algorithm?
Key stretching
Data masking
Steganography
Salting
An employee clicked a link in an email from a payment website that asked the employee to update contact information. The employee entered the log-in information but received a “page not found” error message. Which of the following types of social engineering attacks occurred?
Brand impersonation
Pretexting
Typosquatting
Phishing
An enterprise is trying to limit outbound DNS traffic originating from its internal network. Outbound DNS requests will only be allowed from one device with the IP address 10.50.10.25. Which of the following firewall ACLs will accomplish this goal?
Access list outbound permit 0.0.0.0/0 0.0.0.0/0 port 53 Access list outbound deny 10.50.10.25/32 0.0.0.0/0 port 53
Access list outbound permit 0.0.0.0/0 10.50.10.25/32 port 53 Access list outbound deny 0.0.0.0/0 0.0.0.0/0 port 53
Access list outbound permit 0.0.0.0/0 0.0.0.0/0 port 53 Access list outbound deny 0.0.0.0/0 10.50.10.25/32 port 53
Access list outbound permit 10.50.10.25/32 0.0.0.0/0 port 53 Access list outbound deny 0.0.0.0/0 0.0.0.0/0 port 53
A data administrator is configuring authentication for a SaaS application and would like to reduce the number of credentials employees need to maintain. The company prefers to use domain credentials to access new SaaS applications. Which of the following methods would allow this functionality?
SSO
LEAP
MFA
PEAP
Which of the following scenarios describes a possible business email compromise attack?
An employee receives a gift card request in an email that has an executive’s name in the display field of the email.
Employees who open an email attachment receive messages demanding payment in order to access files.
A service desk employee receives an email from the HR director asking for log-in credentials to a cloud administrator account.
An employee receives an email with a link to a phishing site that is designed to look like the company’s email portal.
A company prevented direct access from the database administrators’ workstations to the network segment that contains database servers. Which of the following should a database administrator use to access the database servers?
Jump server
RADIUS
HSM
Load balancer
An organization’s internet-facing website was compromised when an attacker exploited a buffer overflow. Which of the following should the organization deploy to best protect against similar attacks in the future?
NGFW
WAF
TLS
SD-WAN
Which of the following is NOT among the top-tier leadership in information security?
CEO
CIO
CISO
CSCO
Which of the following is NOT a best practice when handling encryption keys?
Using cryptographically secure random number generation to create keys.
Storing encryption keys in an HSM.
Rotating encryption keys frequently.
Hard-coding encryption keys into application source code.
Several employees received a fraudulent text message from someone claiming to be the Chief Executive Officer (CEO). The message stated: “I’m in an airport right now with no access to email. I need you to buy gift cards for employee recognition awards. Please send the gift cards to following email address.” Which of the following are the best responses to this situation? (Choose two.)
Cancel current employee recognition gift cards.
Add a smishing exercise to the annual company training.
A company is required to use certified hardware when building networks. Which of the following best addresses the risks associated with procuring counterfeit hardware?
A thorough analysis of the supply chain
A legally enforceable corporate acquisition policy
A right to audit clause in vendor contracts and SOWs
Which of the following provides the details about the terms of a test with a third-party penetration tester?
Rules of engagement
Supply chain analysis
A penetration tester begins an engagement by performing port and service scans against the client environment according to the rules of engagement. Which of the following reconnaissance types is the tester performing?
Active
Passive
Which of the following is required for an organization to properly manage its restore process in the event of system failure?
IRP
DRP
An administrator notices that several users are logging in from suspicious IP addresses. After speaking with the users, the administrator determines that the employees were not logging in from those IP addresses and resets the affected users’ passwords. Which of the following should the administrator implement to prevent this type of attack from succeeding in the future?
An employee receives a text message that appears to have been sent by the payroll department and is asking for credential verification. Which of the following social engineering techniques are being attempted? (Choose two.)
Phishing
Impersonation
Which of the following statements best describes the primary purpose of a Web Application Firewall (WAF)?
In response to repeated smishing attempts targeting executives, which training update would most directly reduce employee susceptibility to similar attacks in the future?
During planning for a third-party penetration test, which document formally defines what systems may be tested, when testing will occur, and which actions are authorized?
During a security incident, the security operations team identified sustained network traffic from a malicious IP address: 10.1.4.9. A security analyst is creating an inbound firewall rule to block the IP address from accessing the organization’s network. Which of the following fulfills this request?
access-list inbound deny ip source 0.0.0.0/0 destination 10.1.4.9/32
access-list inbound deny ip source 10.1.4.9/32 destination 0.0.0.0/0
access-list inbound permit ip source 10.1.4.9/32 destination 0.0.0.0/0
access-list inbound permit ip source 0.0.0.0/0 destination 10.1.4.9/32
A company needs to provide administrative access to internal resources while minimizing the traffic allowed through the security boundary. Which of the following methods is most secure?
Implementing a bastion host
Deploying a perimeter network
Installing a WAF
Utilizing single sign-on
A security analyst is reviewing alerts in the SIEM related to potential malicious network traffic coming from an employee’s corporate laptop. The security analyst has determined that additional data about the executable running on the machine is necessary to continue the investigation. Which of the following logs should the analyst use as a data source?
Application
IPS/IDS
Network
Endpoint
A threat hunter is performing network-based hunting using a SIEM tool. Which of the following would be needed for earlier detection?
Critical asset logs
Exfiltration data
User metadata
Packet metadata
A company is assessing regulatory compliance within the organization’s environments. Based on the assessment, the company decides to require MFA, update policies, add security devices, and document the review. Which of the following is the company best completing?
Risk avoidance
Risk transfer
Risk mitigation
Risk acceptance
A company’s bug bounty program has relied on the same researchers for the last three years. Recently, a competing product had a huge vulnerability disclosed. The CSO is concerned that the company’s bug bounty program may be falling short and has suggested that other approaches and tools should be included to increase coverage. Which of the following would be the BEST action for the CSO to take?
Engage with new vendors for bug bounty and consider the purchase of a new EASM tool
Implement a new bug bounty program using a different platform and only allow the top researchers
Increase the current bug bounty financial incentives to attract more researchers
Hire a dedicated internal red team and eliminate the current bug bounty program
Which of the following is the MOST likely reason a security analyst should review the logs from a DNS server in an investigation?
To determine whether threat policy rules were triggered
To determine the websites in which a computer communicated
To determine whether command-and-control channels are being tunneled
To determine whether exfiltration has occurred over HTTPS
A vulnerability management team is performing discovery scans in a flat network. The team notices a lot of network rings and some scanning tools crash. Which of the following will MOST likely hyperinflate the number of findings?
NAC
EDR
NIDS
WIDS
Which of the following is the PRIMARY reason for implementing Zero Trust?
Regulatory compliance
Network segmentation only
Continuous verification of users and devices
Perimeter-based security enhancement
A company’s productivity suite has moved to a SaaS solution. The company would like to build a process by which a security analyst could review patterns of data usage and generate reportable metrics. Which of the following should the company implement?
CASB
DLP
UEBA
SWG
Which of the following statements best describes threat intelligence in an organization?
Point-in-time data used for real-time blocking only
Information about threats and vulnerabilities that can be applied to mitigate risk
A list of current antivirus signatures
A static dataset maintained quarterly
A cyber operations team informs a security analyst about a new tactic malicious actors are using to compromise networks. SIEM alerts have not yet been configured. Which of the following best describes what the security analyst should do to identify this behavior?
Digital forensics
E-discovery
Incident response
Threat hunting
A company purchased cyber insurance to address items listed on the risk register. Which of the following strategies does this represent?
Accept
Transfer
Mitigate
Avoid
A security administrator would like to protect data on employees’ laptops. Which of the following encryption techniques should the security administrator use?
Partition
Asymmetric
Full disk
Database
Which of the following security control types does an acceptable use policy best represent?
Detective
Compensating
Corrective
Preventive
An IT manager informs the entire help desk staff that only the IT manager and the help desk lead will have access to the administrator console of the help desk software. Which of the following security techniques is the IT manager setting up?
Hardening
Employee monitoring
Configuration enforcement
Least privilege
Which of the following is the most likely to be used to document risks, responsible parties, and thresholds?
Risk tolerance
Risk transfer
Risk register
Risk analysis
Which of the following should a security administrator adhere to when setting up a new set of firewall rules?
Disaster recovery plan
Incident response procedure
Business continuity plan
Change management procedure
A company is expanding its threat surface program and allowing individuals to security test the company’s internet-facing application. The company will compensate researchers based on the vulnerabilities discovered. Which of the following best describes the program the company is setting up?
Bug bounty program
Vulnerability scan program
Red teaming program
Threat hunting program
Endpoint logs are the most suitable data source for gathering additional information about the executable running on the employee’s corporate laptop. These logs contain detailed information about processes, executables, and activities occurring on the endpoint, enabling the security analyst to understand the behavior of the executable and its potential impact on the system and network. Based on this explanation, which data source should the analyst consult?
Network flow logs
Endpoint logs
Firewall logs
DNS query logs
Which of the following threat actors is the most likely to use large financial resources to attack critical systems located in other countries?
Insider
Unskilled attacker
Nation-state
Hacktivist
Which of the following enables the use of an input field to run commands that can view or manipulate data?
Cross-site scripting
Side loading
Buffer overflow
SQL injection
Employees in the research and development business unit receive extensive training to ensure they understand how to best protect company data. Which of the following is the type of data these employees are most likely to use in day-to-day work activities?
Encrypted
Intellectual property
Critical
Data in transit
A company has begun labeling all laptops with asset inventory stickers and associating them with employee IDs. Which of the following security benefits do these actions provide? (Choose two.)
If a security incident occurs on the device, the correct employee can be notified.
The security team will be able to send user awareness training to the appropriate device.
Users can be mapped to their devices when configuring software MFA tokens.
User-based firewall policies can be correctly targeted to the appropriate laptops.
A technician wants to improve the situational and environmental awareness of existing users as they transition from remote to in-office work. Which of the following is the best option?
Send out periodic security reminders.
Update the content of new hire documentation.
Modify the content of recurring training.
Implement a phishing campaign.
A newly appointed board member with cybersecurity knowledge wants the board of directors to receive a quarterly report detailing the number of incidents that impacted the organization. The systems administrator is creating a way to present the data to the board of directors. Which of the following should the systems administrator use?
Packet captures
Vulnerability scans
Metadata
Dashboard
A systems administrator receives the following alert from a file integrity monitoring tool: The hash of the cmd.exe file has changed. The systems administrator checks the OS logs and notices that no patches were applied in the last two months. Which of the following most likely occurred?
The end user changed the file permissions.
A cryptographic collision was detected.
A snapshot of the file system was taken.
A rootkit was deployed.
Which of the following roles, according to the shared responsibility model, is responsible for securing the company’s database in an IaaS model for a cloud environment?
Client
Third-party vendor
Cloud provider
A client asked a security company to provide a document outlining the project, the cost, and the completion time frame. Which of the following documents should the company provide to the client?
MSA
SLA
BPA
SOW
A security team is reviewing the findings in a report that was delivered after a third party performed a penetration test. One of the findings indicated that a web application form field is vulnerable to cross-site scripting. Which of the following application security techniques should the security analyst recommend the developer implement to prevent this vulnerability?
Secure cookies
Version control
Input validation
Which of the following must be considered when designing a high-availability network? (Choose two).
Ease of recovery
Ability to patch
Physical isolation
A technician needs to apply a high-priority patch to a production system. Which of the following steps should be taken first?
Air gap the system.
Move the system to a different network segment.
Create a change control request.
Which of the following describes the reason root cause analysis should be conducted as part of incident response?
To gather IoCs for the investigation
To discover which systems have been affected
To prevent future incidents of the same nature
Which of the following is the most likely outcome if a large bank fails an internal PCI DSS compliance assessment?
Fines
Audit findings
Sanctions
Which of the following best describes the primary responsibility of the client in the shared responsibility model for cloud services?
Identify the document type that defines the scope, deliverables, timeline, and cost of a project to ensure both client and provider have a clear understanding of requirements and expectations.
Name the secure development practice that directly mitigates cross-site scripting by validating and sanitizing user-supplied input before processing or rendering.
State the initial governance step that should precede making changes such as applying patches to production systems to minimize disruption and unauthorized alterations.
A company is developing a business continuity strategy and needs to determine how many staff members would be required to sustain the business in the case of a disruption. Which of the following best describes this step?
Capacity planning
Redundancy
Geographic dispersion
Tabletop exercise
A company’s legal department drafted sensitive documents in a SaaS application and wants to ensure the documents cannot be accessed by individuals in high-risk countries. Which of the following is the most effective way to limit this access?
Data masking
Encryption
Geolocation policy
Data sovereignty regulation
Which of the following is a hardware-specific vulnerability?
Firmware version
Buffer overflow
SQL injection
Cross-site scripting
While troubleshooting a firewall configuration, a technician determines that a “deny any” policy should be added to the bottom of the ACL. The technician updates the policy, but the new policy causes several company servers to become unreachable. Which of the following actions would prevent this issue?
Documenting the new policy in a change request and submitting the request to change management
Testing the policy in a non-production environment before enabling the policy in the production network
Disabling any intrusion prevention signatures on the “deny any” policy prior to enabling the new policy
Including an “allow any” policy above the “deny any” policy
An organization is building a new backup data center with cost-benefit as the primary requirement and RTO and RPO values around two days. Which of the following types of sites is the best for this scenario?
Real-time recovery
Hot
Cold
Warm
A company requires hard drives to be securely wiped before sending decommissioned systems to recycling. Which of the following best describes this policy?
Enumeration
Sanitization
Destruction
Inventory
A systems administrator works for a local hospital and needs to ensure patient data is protected and secure. Which of the following data classifications should be used to secure patient data?
Private
Critical
Sensitive
Public
A U.S.-based cloud-hosting provider wants to expand its data centers to new international locations. Which of the following should the hosting provider consider first?
Local data protection regulations
Risks from hackers residing in other countries
Impacts to existing contractual obligations
Time zone differences in log correlation
Which of the following would be the best way to block unknown programs from executing?
Question: 55
Question: 56
Question: 57
Question: 58
A company hired a consultant to perform an offensive security assessment covering penetration testing and social engineering. Which of the following teams will conduct this assessment activity?
White
Purple
Blue
Red
Which of the following allows for the attribution of messages to individuals?
Adaptive identity
Non-repudiation
Authentication
Access logs
A systems administrator is looking for a low-cost application-hosting solution that is cloud-based. Which of the following meets these requirements?
Serverless framework
Type 1 hypervisor
SD-WAN
SDN
A security operations center determines that the malicious activity detected on a server is normal. Which of the following activities describes the act of ignoring detected activity in the future?
Tuning
Aggregating
Quarantining
Archiving
A security analyst reviews domain activity logs and notices the following: UserID jsmith, password authentication: succeeded, MFA: failed (invalid code) UserID jsmith, password authentication: succeeded, MFA: failed (invalid code) UserID jsmith, password authentication: succeeded, MFA: failed (invalid code) UserID jsmith, password authentication: succeeded, MFA: failed (invalid code) Which of the following is the best explanation for what the security analyst has discovered?
The user jsmith’s account has been locked out.
A keylogger is installed on jsmith’s workstation.
An attacker is attempting to brute force jsmith’s account.
Ransomware has been deployed in the domain.
A company is concerned about weather events causing damage to the server room and downtime. Which of the following should the company consider?
Clustering servers
Geographic dispersion
Load balancers
Off-site backups
Which of the following is a primary security concern for a company setting up a BYOD program?
End of life
Buffer overflow
VM escape
Jailbreaking
A company decided to reduce the cost of its annual cyber insurance policy by removing the coverage for ransomware attacks. Which of the following analysis elements did the company most likely use in making this decision?
MTTR
RTO
ARO
MTBF
Which of the following is the most likely to be included as an element of communication in a security awareness program?
Reporting phishing attempts or other suspicious activities
Detecting insider threats using anomalous behavior recognition
Verifying information when modifying wire transfer data
Performing social engineering as part of third-party penetration testing
Question: 76 HOTSPOT - Select the appropriate attack and remediation from each drop-down list to label the corresponding attack with its remediation. INSTRUCTIONS - Not all attacks and remediation actions will be used. If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.
Attack Description: An attacker sends multiple SYN packets from multiple sources. Target: Web server. Identify the attack and choose the BEST preventative or remediation action.
Attack Identified: Botnet; Remediation: Enable DDoS protection
Attack Identified: RAT; Remediation: Disable remote access services
Attack Identified: Virus; Remediation: Patch vulnerable systems
Attack Identified: Keylogger; Remediation: Implement 2FA using push notification
Attack Description: The attack establishes a connection, which allows remote commands to be executed. Target: User. Identify the attack and choose the BEST preventative or remediation action.
Attack Identified: Backdoor; Remediation: Conduct a code review
Attack Identified: RAT; Remediation: Disable remote access services
Attack Identified: Virus; Remediation: Update cryptographic algorithms
Attack Identified: Phishing; Remediation: Implement application fuzzing
Attack Description: The attack is self propagating and compromises a SQL database using well-known credentials as it moves through the network. Target: Database server. Identify the attack and choose the BEST preventative or remediation action.
Attack Identified: Worm; Remediation: Implement a host-based IPS
Attack Identified: Virus; Remediation: Patch vulnerable systems
Attack Identified: Spyware; Remediation: Change the default application password
Attack Identified: Ransomware; Remediation: Enable DDoS protection
Attack Description: The attacker uses hardware to remotely monitor a user's input activity to harvest credentials. Target: Executive. Identify the attack and choose the BEST preventative or remediation action.
Attack Identified: RAT; Remediation: Disable remote access services
Attack Identified: Keylogger; Remediation: Implement 2FA using push notification
Attack Identified: Worm; Remediation: Implement application fuzzing
Attack Identified: Adware; Remediation: Update the default system password
Attack Description: The attacker embeds hidden access in an internally developed application that bypasses account login. Target: Application. Identify the attack and choose the BEST preventative or remediation action.
Attack Identified: Backdoor; Remediation: Conduct a code review
Attack Identified: Botnet; Remediation: Enable DDoS protection
Attack Identified: Virus; Remediation: Update the cryptographic algorithms
Attack Identified: Spyware; Remediation: Disable vulnerable services
Question: 77 HOTSPOT - You are a security administrator investigating a potential infection on a network. INSTRUCTIONS - Click on each host and firewall. Review all logs to determine which host originated the infection and then identify if each remaining host is clean or infected. If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.
Log excerpt for 192.168.10.22 shows scans initiated, completed with 0 files removed/quarantined, boot sector clean, and scheduled update disabled by process scvh0st.exe. Based on this log, determine the status of this host.
Clean
Infected
Unable to determine
Quarantined
From the hotspot scenario instructions, what user action resets the simulation to its initial state?
Click the Reset All button
Restart the host system
Close and reopen the browser
Disable scheduled updates
In the attack-mapping hotspot, which target is affected by an attacker sending multiple SYN packets from multiple sources?
User
Database server
Web server
Application
In the attack-mapping hotspot, which target is associated with a hidden access that bypasses account login?
Executive
Application
Web server
User
Which workstation first quarantined the suspicious file svch0st.exe according to the endpoint logs?
192.168.10.37
192.168.10.41
10.10.9.18
57.203.54.183
On 4/18/2019 at 14:33, what event occurred on host 192.168.10.37?
Definition update complete
Update available v10.2.3.4440
Scan complete
Files quarantined: 1
What prevented host 192.168.10.41 from updating signatures on 4/18/2019 14:34?
Network disconnected
Unable to reach update server
License expired
Proxy authentication required
According to the log for 192.168.10.41, what happened to svch0st.exe at 14:37 on 4/18/2019?
File removed
File quarantined successfully
Unable to quarantine file svch0st.exe
Whitelisted by policy
At the conclusion of the 4/18/2019 scans, what was the boot sector status on both hosts?
Infected
Unknown
Clean
Not scanned
Which application is most frequently observed in the firewall log entries shown?
http
rpc
smb
ssl
Based on the firewall log, which internal source communicated to destination 57.203.55.89 over port 8080 using http?
10.10.9.18
192.168.10.41
10.10.9.12
192.168.10.37
Which destination IP appears multiple times as an external address in the firewall table?
192.168.10.41
57.203.56.143
10.10.9.18
192.168.10.22
Compare the outcomes of the 14:41 scan completion events on 4/18/2019 for both hosts. Which statement is correct?
Both hosts removed 1 file
192.168.10.37 quarantined 1 file while 192.168.10.41 quarantined 0
Both hosts quarantined svch0st.exe
192.168.10.41 removed 1 file while 192.168.10.37 removed 0
Which log entry indicates a heuristic detection rather than a signature definition match?
File found svch0st.exe match definition v10.2.3.4440
File quarantine file
Unable to reach update server
Scan type = full
Based on the antivirus scan logs for host 10.10.9.12, what was the result of the 4/18/2019 scan regarding quarantined files?
Files quarantined: 0
Files quarantined: 1
Files quarantined: 2
Files quarantined: 3
According to the 10.10.9.12 log, which event occurred immediately before 'Definition update complete' on 4/18/2019?
Scan type = full
Downloading update
Scan start
Scanning system files
From the 10.10.9.12 log, which file name was quarantined during the 4/18/2019 scan?
svch0st.exe
svchost.exe
services.exe
explorer.exe
On host 10.10.9.12, what was the status of the boot sector after the scans shown?
Infected
Clean
Unknown
Not scanned
According to the 10.10.9.18 log, why did the host not receive updated definitions on 4/18/2019?
No update available
Unable to reach update server
Download corrupted
Update disabled by policy
On 10.10.9.18, what message appears when attempting to quarantine the suspicious file on 4/18/2019?
File quarantined svch0st.exe
Unable to quarantine file svch0st.exe
File removed successfully
Heuristic scan disabled
In the 10.10.9.18 log, which detection method is indicated for svch0st.exe?
Signature match v10.2.3.4440
Match heuristic pattern 0xc09488c08d0f3k
Behavioral sandbox alert
YARA rule match
Using the network diagram and logs, identify the status of host 10.10.9.12 in the Engineering Network.
Origin
Infected
Clean
Unknown
Using the network diagram and logs, identify the status of host 10.10.9.18 in the Engineering Network.
Origin
Infected
Clean
Unknown
Based on the diagram, which host is the likely origin of the malware?
192.168.10.22
192.168.10.37
192.168.10.41
10.10.9.12
According to the provided answer overlay in the diagram, what is the status of host 192.168.10.41?
Origin
Infected
Clean
Unknown
Referencing the completed diagram answer, what is the status of host 192.168.10.37?
Origin
Infected
Clean
Unknown
Which of the following is the phase in the incident response process when a security analyst reviews roles and responsibilities?
Preparation
Recovery
Lessons learned
Analysis
After a recent vulnerability scan, a security engineer needs to harden the routers within the corporate network. Which of the following is the most appropriate to disable?
Console access
Routing protocols
VLANs
Web-based administration
A security administrator needs a method to secure data in an environment that includes some form of checks so track any changes. Which of the following should the administrator set up to achieve this goal?
SPF
GPO
NAC
An administrator is reviewing a single server's security logs and discovers the following: Keywords Date and Time Source Event ID Task Category Audit 09/16/2022 Microsoft 4625 Logon Failure 11:13:05 AM Windows security 4625 Logon Audit 09/16/2022 Microsoft 4625 Logon Failure 11:13:07 AM Windows security 4625 Logon Audit 09/16/2022 Microsoft 4625 Logon Failure 11:13:09 AM Windows security 4625 Logon Audit 09/16/2022 Microsoft 4625 Logon Failure 11:13:11 AM Windows security 4625 Logon Audit 09/16/2022 Microsoft 4625 Logon Failure 11:13:13 AM Windows security 4625 Logon Audit 09/16/2022 Microsoft 4625 Logon Failure 11:13:15 AM Windows security 4625 Logon Audit 09/16/2022 Microsoft 4625 Logon Failure 11:13:17 AM Windows security 4625 Logon Audit 09/16/2022 Microsoft 4625 Logon Failure 11:13:19 AM Windows security 4625 Logon Audit 09/16/2022 Microsoft 4625 Logon Failure 11:13:21 AM Windows security 4625 Logon Audit 09/16/2022 Microsoft 4625 Logon Failure 11:13:23 AM Windows security 4625 Logon Audit 09/16/2022 Microsoft 4625 Logon Failure 11:13:25 AM Windows security 4625 Logon Audit 09/16/2022 Microsoft 4625 Logon Failure 11:13:27 AM Windows security 4625 Logon Which of the following best describes the action captured in this log file?
Brute-force attack
Privilege escalation
Failed password audit
A security engineer is implementing FDE for all laptops in an organization. Which of the following are the most important for the engineer to consider as part of the planning process? (Choose two.)
Key escrow
TPM presence
Digital signatures
Security controls in a data center are being reviewed to ensure data is properly protected and that human life considerations are included. Which of the following best describes how the controls should be set up?
Remote access points should fail closed.
Logging controls should fail open.
Safety controls should fail open.
Logical security controls should fail closed.
Which of the following would be best suited for constantly changing environments?
RTOS
Containers
Embedded systems
SCADA
Which of the following incident response activities ensures evidence is properly handled?
E-discovery
Chain of custody
Legal hold
Preservation
An accounting clerk sent money to an attacker's bank account after receiving fraudulent instructions to use a new account. Which of the following would most likely prevent this activity in the future?
Standardizing security incident reporting
Executing regular phishing campaigns
Implementing insider threat detection measures
Updating processes for sending wire transfers
A systems administrator is creating a script that would save time and prevent human error when performing account creation for a large number of end users. Which of the following would be a good use case for this task?
Off-the-shelf software
Orchestration
Baseline
Policy enforcement
A company's marketing department collects, modifies, and stores sensitive customer data. The infrastructure team is responsible for securing the data while in transit and at rest. Which of the following data roles describes the customer?
Processor
Custodian
Subject
Owner
Which of the following describes the maximum allowance of accepted risk?
Risk indicator
Risk level
Risk score
Risk threshold
A security analyst receives alerts about an internal system sending a large amount of unusual DNS queries to systems on the internet over short periods of time during non-business hours. Which of the following is most likely occurring?
A worm is propagating across the network.
Data is being exfiltrated.
A logic bomb is deleting data.
Ransomware is encrypting files.
Which of the following would be the best control configuration to ensure human safety during system failures in a data center?
Fail-closed safety systems
Fail-open safety systems
Fail-open logging systems
Fail-closed remote access
To reduce the chance of fraudulent wire transfers, which procedural change is most effective?
Add antivirus scanning to email servers
Require multi-level approval and callbacks for new payment instructions
Rotate bank account numbers weekly
Encrypt all internal emails
The role responsible for protecting stored and transmitted data for a department is best described as which of the following?
Owner
Custodian
Subject
Processor
A technician is opening ports on a firewall for a new system being deployed and supported by a SaaS provider. Which of the following is a risk in the new system?
Default credentials
Non-segmented network
Supply chain vendor
Vulnerable software
A systems administrator is working on a solution with the following requirements: • Provide a secure zone. • Enforce a company-wide access control policy. • Reduce the scope of threats. Which of the following is the systems administrator setting up?
Zero Trust
AAA
Non-repudiation
CIA
Which of the following involves an attempt to take advantage of database misconfigurations?
Buffer overflow
SQL injection
VM escape
Memory injection
Which of the following is used to validate a certificate when it is presented to a user?
OCSP
CSR
CA
CRC
One of a company’s vendors sent an analyst a security bulletin that recommends a BIOS update. Which of the following vulnerability types is being addressed by the patch?
Virtualization
Firmware
Application
Operating system
Which of the following is used to quantitatively measure the criticality of a vulnerability?
CVE
CVSS
CIA
CERT
Which of the following actions could a security engineer take to ensure workstations and servers are properly monitored for unauthorized changes and software?
Configure all systems to log scheduled tasks.
Collect and monitor all traffic exiting the network.
Block traffic based on known malicious signatures.
Install endpoint management software on all systems
An organization is leveraging a VPN between its headquarters and a branch location. Which of the following is the VPN protecting?
Data in use
Data in transit
Geographic restrictions
Data sovereignty
After reviewing the following vulnerability scanning report: Server: 192.168.14.6 Service: Telnet Port: 23 Protocol: TCP Status: Open Severity: High Vulnerability: Use of an insecure network protocol A security analyst performs the following test:
• The security analyst connects to 192.168.14.6 using a Telnet client. • The analyst enters username: admin and password: Admin123! • The login is successful and a prompt is displayed. Which of the following best describes the issue confirmed by the test?
Exploitation of a buffer overflow vulnerability
Presence of default or weak credentials over an insecure protocol
Successful privilege escalation to root user
Detection of a man-in-the-middle attack on SSH
Based on the vulnerability report and the test, what is the most appropriate immediate remediation?
Disable Telnet and enable SSH with key-based authentication
Increase the firewall’s logging level for port 23
Install a web application firewall (WAF)
Segment the network using VLANs only
Which of the following would the security analyst conclude for this reported vulnerability?
It is a false positive.
A rescan is required.
It is considered noise.
Compensating controls exist.
An organization disabled unneeded services and placed a firewall in front of a business-critical legacy system. Which of the following best describes the actions taken by the organization?
Exception
Segmentation
Risk transfer
Compensating controls
A security consultant needs secure, remote access to a client environment. Which of the following should the security consultant most likely use to gain access?
EAP
DHCP
IPSec
NAT
Which of the following should a systems administrator use to ensure an easy deployment of resources within the cloud provider?
Software as a service
Infrastructure as code
Internet of Things
Software-defined networking
After a security awareness training session, a user called the IT help desk and reported a suspicious call. The suspicious caller stated that the Chief Financial Officer wanted credit card information in order to close an invoice. Which of the following topics did the user recognize from the training?
Insider threat
Email phishing
Social engineering
Executive whaling
