wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Comptia Security+ Practice

Total questions: 87

Worksheet time: 1hrs 27mins

Name
Class
Date
1.

A financial institution's risk assessment department evaluates a potential threat that could disrupt its financial transactions. They have quantified the likelihood of this risk event happening and aim to project this probability over an annual period. What metric are they attempting to establish?

a)

Annualized Rate of Occurrence (ARO)

b)

Risk threshold

c)

Annualized Loss Expectancy (ALE)

d)

Single Loss Expectancy (SLE)

2.

A large enterprise recently introduced a Bring Your Own Device (BYOD) policy and is seeing an uptick in the use of Internet of Things (IoT) devices in the office. Concerns about unauthorized network access and compliance with security standards accompany these changes. Assess the following options and determine the MOST suitable strategy to alleviate these security concerns.

a)

Depend solely on the existing firewall for device authentication.

b)

Use Network Access Control (NAC) without employing dynamic Virtual Local Area Networks (VLANs).

c)

Deploy agent-based Network Access Control (NAC) with dynamic Virtual Local Area Networks (VLANs) and firewall integration.

d)

Implement agentless Network Access Control (NAC) without firewall integration.

3.

A software development company has implemented an IPsec tunnel with Internet Key Exchange (IKE) for mutual authentication as part of its Virtual Private Network (VPN) setup for employees. The company chooses this solution for its ability to encrypt network connections at the packet level and support mutual authentication with low packet overhead. What benefits do the IT department likely aim to achieve with this setup?

a)

Mutual authentication using SSL

b)

Protection at the packet level with mutual authentication

c)

Secure application-level connections

d)

Reliability of an established legacy protocol

4.

After finding some of the company's confidential data on the internet, a software team is drafting a policy on vulnerability response and remediation. What remediation practice refers to measures put in place to mitigate the risk of a vulnerability when the team cannot directly eliminate it?

a)


Insurance

b)

Segementation

c)

Patching

d)

Compensating Controls

5.

A network engineer is optimizing an existing cloud-based system. The primary goal is to ensure the system remains operational, minimizing downtime, even under adverse conditions or potential failure points. What key characteristic of system design should the engineer prioritize?

a)

Availability

b)

Centralized

c)

Containerization

d)

Scalability

6.

Given the need to prioritize cost-effective solutions for enhancing the company's cybersecurity posture, a global corporation's chief security officer (CSO) considers implementing technical controls over physical controls. Which of the following options is a technical control?

a)

Installing a building access control system

b)

Setting up a network intrusion detection system

c)

Conducting employee cybersecurity training

d)

Implementing a risk identification tool

7.

Cloud service providers offer global services across multiple regions. With respect to high availability, what does the concept of zone-redundant storage imply?

a)

Duplication of data across multiple zones within a region

b)

Storage of data in a single zone to reduce latency

c)

Storage of data in a single zone with a backup in another region

d)

Duplication of data in the same zone for failover purposes

8.

The IT department of a medium-sized company is in the process of finalizing agreements with various vendors. The legal team drafted the contracts to ensure proper arrangements. The team considers three types of agreements: an NDA, a BPA, and an MOU. The IT team wants to select the MOST appropriate agreement for each vendor to ensure smooth collaboration. Which of the following agreements protects sensitive information shared between the company and its vendors?

a)

Memorandum of agreement (MOA)

b)

Memorandum of understanding (MOU)

c)

Non-disclosure agreement (NDA)

d)

Business partnership agreement (BPA)

9.

The IT security team of a medium-sized company has identified various attack vectors and threat scenarios that could impact the organization. To enhance their incident response capabilities, the team is developing incident response playbooks. Additionally, the team is researching external considerations such as legal and regulatory requirements, the potential involvement of law enforcement, and the need to notify affected customers in the event of a data breach. What is the primary purpose of developing incident response playbooks in the company's cybersecurity strategy?

a)

To prevent cybersecurity incidents from occurring in the company's IT infrastructure

b)

To provide predefined steps and procedures to respond effectively to cybersecurity incidents

c)

To ensure compliance with legal and regulatory requirements in case of a security breach

d)

To identify potential attack vectors and threat scenarios in the organization

10.

A software application contains sensitive transmittal information, and an end user takes it out on a laptop in the field. The end user must understand how to protect and dispose of the data. Which one of the following should help the end user prepare for this?

a)

User training

b)

General purpose guide

c)

Vendor-specific guide

d)

Change management

11.

An organization observes several computer systems in a secured area showing signs of damage, having various cables disconnected, or hardware component tampering. Which type of attack is likely responsible for these issues?

a)

Malware attacks

b)

Insider threats

c)

Physical attacks

d)

Denial-of-service attacks

12.

A network administrator notices that a self-replicating program spreads across the network, infecting multiple systems and consuming significant bandwidth. Which of the following BEST describes this type of security threat?

a)

Worm

b)

Trojan Horse

c)

Malicious Code

d)

Spyware

13.

A proprietary software remains mission-critical ten years after its in-house creation. The software requires an exception to the rules as it cannot use the latest in-use operating system (OS) version. How can the IT department protect this mission-critical software and reduce its exposure factor? (Select the two best options.)

a)

Vulnerability feeds

b)

Network segmentation

c)

Compensating controls

d)

Patching

14.

A company wants to determine the single loss expectancy (SLE) for a critical server. What formula will the company use to calculate the SLE?

a)

Annualized loss expectancy (ALE) x Annualized rate of occurrence (ARO)

b)

Annualized loss expectancy (ALE) x Exposure factor (EF)

c)

Asset x Annualized rate of occurrence (ARO)

d)

Asset x Exposure factor (EF)

15.

A global software development company seeks to minimize its exposure to security vulnerabilities across its network infrastructure. In this context, what strategic approach should the company prioritize?

a)

Analyze data plane

b)

Threat scope reduction

c)

Analyze the control plane

d)

Policy-driven access control

16.

A software technician develops a new procedure to safeguard privacy data and ensure all groups adhere to compliance mandates. What BEST describes due diligence?

a)

It is the comprehensive assessment and evaluation of an organization's data protection practices.

b)

It is an established timeline that requires organizations to keep documentation.

c)

It requires individuals or entities to formally announce their understanding of compliance obligations.

d)

It provides a comprehensive overview of the types of handled data.

17.

What component of the incident response process applies mitigation techniques and controls to remove unauthorized configuration changes from systems?

a)

Containment

b)

Analysis

c)

Detection

d)

Eradication

18.

Which data and privacy law ensures executives within a financial institution take individual responsibility for the accuracy of financial reporting?

a)

Sarbanes-Oxley (SOX) Act

b)

Health Insurance Portability and Accountability Act of 1996 (HIPAA)

c)

Federal Deposit Insurance Corporation (FDIC)

d)

General Data Protection Regulation (GDPR)

19.

An organization is considering a hybrid cloud deployment to leverage the benefits of both private and public cloud resources. While reviewing third-party vendors, what critical aspect should the employees consider for a secure and effective transition?

a)

Focus on data redundancy

b)

Delegate all security management to the provider

c)

Establish clear service level agreements (SLAs)

d)

Prioritize lowest-cost vendors

20.

A university with an expansive network infrastructure uses a robust firewall to ensure network security. As the number of users and network complexity grows, the administration identifies the need for improved threat detection and prevention. The admin is contemplating whether integrating intrusion detection and prevention systems (IDS/IPS) with existing firewall would bolster the university's network security. How should they proceed?

a)

Keep the firewall and ignore IDS/IPS adoption

b)

Add network-based IDS/IPS and maintain the firewall rules

c)

Discard firewall rules, rely solely on network-based IDS/IPS

d)

Abandon the firewall and adopt host-based IDS/IPS

21.

A cybersecurity analyst implements security measures for a financial institution's infrastructure. The analyst explores different technologies to enhance security and must select the appropriate technology to strengthen security within the organization's infrastructure. Which technology should the cybersecurity analyst choose to enhance security for executing sensitive operations and protecting critical data in the financial institution's infrastructure?

a)

Firewall

b)

Key management system

c)

Intrusion detection system

d)

Secure enclave

22.

A Security Operations Center (SOC) manager notices a significant increase in unclassified events on the incident handler’s Security Event and Incident Management (SIEM) dashboard. At the same time, someone or something raises the number of incidents. The manager investigates these incidents further to ensure efficient and timely incident response. Which combination of data sources would provide the MOST comprehensive view to support the manager’s investigation?

a)

Log files from network-based vulnerability scanners, application logs, and endpoint logs

b)

Endpoint logs, automated reports from the SIEM tool, and metadata

c)

OS-specific security logs, log files generated by applications and services running on hosts, and automated reports from the SIEM tool

d)

Firewall logs, network traffic captured by sensors, and log files generated by OS components of server host computers

23.

Which malicious actors are likely to show great interest in another country's energy infrastructure and have unlimited resources to carry out espionage attacks?

a)

State Actors

b)

Shadow IT

c)

Unauthorized hackers

d)

Semi-authorized hackers

24.

A threat actor targets a company by exploiting a vulnerability in a third-party vendor's software that the company uses for its financial transactions. The threat actor gains unauthorized access to the vendor's system and manipulates the software to steal funds from the company's accounts. What type of threat actor is the vendor in this scenario?

a)

Insider threat

b)

Phishing attacker

c)

External threat

d)

Vishing attacker

25.

Employees at CloudCom receive a suspicious email claiming to be from "CloudCom Support," informing employees that their passwords need to be reset urgently due to a security breach. The email includes a link to a login page that looks identical to CloudCom's official site. What type of social engineering attack does this scenario exemplify?

a)

Typosquatting

b)

Phishing

c)

Watering hole attack

d)

SMiShing

26.

An organization in the education sector plans to implement an Intrusion Detection System (IDS) with strategically placed sensors as part of its network infrastructure redesign to improve enterprise security. The IT manager also considers implementing an Intrusion Prevention System (IPS) and deliberates over active versus passive modes. Which statement BEST describes the implications of choosing an active IPS over a passive IDS?

a)

Both an active IPS and a passive IDS can block malicious traffic, but the IPS causes more latency.

b)

Both an active IPS and a passive IDS can only detect and alert on malicious traffic and cause latency.

c)

An active IPS can only detect and alert on malicious traffic, while a passive IDS can block such traffic.

d)

An active IPS can block malicious traffic but may introduce latency, while a passive IDS avoids latency.

27.

The IT department at a financial institution notices a peculiar trend in its system logs. The system, which generally logs events during regular business hours, has recorded an unusual volume of logs outside these hours. They observe this anomaly despite the company following a detailed security protocol. What is likely the cause of this unusual logging pattern?

a)

Spraying

b)

Incorrect documentation

c)

Out-of-cycle logging

d)

Malware attacks

28.

Which of the following involves threat actors attaching unauthorized devices to a physical network port, allowing them to eavesdrop on network traffic, intercept and modify data, run spoofed services and applications, or execute exploit code against other hosts?

a)

Lack of confidentiality

b)

Lack of authentication

c)

Lack of availability

d)

Lack of integrity

29.

A company tasks a cybersecurity manager with improving the efficiency of its Security Information and Event Management (SIEM) system. The manager observes that the high number of false positive alerts causes alert fatigue among the analysts, potentially leading them to miss high-impact alerts. Which combination of strategies should the manager consider implementing to tackle this issue effectively?

a)

Assign all infrastructure-related alerts to the incident response team and increase the frequency of system reporting

b)

Mute all alerts to log-only status and deploy additional threat intelligence feeds in the SIEM system

c)

Refine detection rules, redirect sudden alert "floods" to a dedicated group, and continuously monitor alert volume and analyst feedback

d)

Increase the number of correlation rules and assign all alerts to a dedicated agent or team to remediate

30.

The IT team of a large multinational corporation is working to improve the security of their remote access services. They plan to implement Remote Authentication Dial-In User Service (RADIUS) to enhance the authentication process for remote users. RADIUS provides a centralized authentication and authorization mechanism for users connecting from various locations. The IT team evaluated different authentication protocols alongside RADIUS to ensure a strong and secure remote access solution. Which choice of authentication protocols would be MOST appropriate to complement RADIUS for the company's remote access solution?

a)

Protected Extensible Authentication Protocol (PEAP)

b)

Address Resolution Protocol (ARP)

c)

Password Authentication Protocol (PAP)

d)

Wired Equivalent Privacy (WEP)

31.

An organization's system alerting tool detects a series of unsuccessful attempts of someone trying to gain unauthorized access to its servers. These attempts lack sophistication and appear to be using publicly available hacking tools. Which type of threat actor is MOST likely responsible for these attempts?

a)

Nation-state

b)

Unskilled attacker

c)

Hacktivist

d)

Insider threat

32.

A nonprofit organization is working to create an integrated strategy that responds to potential disasters and ensures the continuation of essential functions across various scenarios, including budget constraints and prolonged disruptions. Which approach would BEST address these multifaceted requirements?

a)

Deploy a cold site

b)

Set up a warm site

c)

Establish a COOP

d)

Implement a hot site

33.

A recent attack on a major retail chain resulted in stolen customer private information, including credit card information. The report explained that a heating, ventilation, and air conditioning (HVAC) contractor copied the information to an external hard drive while servicing an air conditioner unit and later uploaded the data to a cloud storage resource. A security engineer would classify this type of attack as which of the following?

a)

Supply chain attack

b)

Birthday attack

c)

Cloud-based attack

d)

USB cable attack

34.

A CEO asks the tech department to create a console that shows day-to-day incident response and summaries of information drawn from underlying data sources. What can the tech department present to the CEO as a viable option?

a)

Log data

b)

Dashboards

c)

Network logs

d)

Metadata

35.

The IT manager of a large corporation is considering implementing a Unified Threat Management (UTM) system to enhance the security of the network infrastructure. What would be the primary benefit of implementing a UTM in this scenario?

a)

UTM can perform application-layer filtering, enhancing the security of network traffic.

b)

UTM can replace all network appliances, reducing the complexity of the network.

c)

UTM can act as a proxy server, improving client performance.

d)

UTM provides multiple security functions in a single system, simplifying security management.

36.

A cybersecurity team is preparing to conduct a comprehensive security assessment. The team has access to system documentation, network diagrams, and source code, and has permission to interview IT staff. What type of testing environment is the team operating within?

a)

Partially known environment

b)

Unknown environment

c)

Known environment

d)

Uncontrolled environment

37.

A company requires improvement in identifying patterns, anomalies, and potential threats in its network traffic. Which firewall and intrusion detection system/intrusion prevention system (IDS/IPS) methods should the company adopt to provide more efficient detection and trend analysis?

a)

Adopt signature-based detection; avoid screened subnets.

b)

Implement a screened subnet and behavioral-based detection.

c)

Establish a screened subnet; use signature-based detection.

d)

Use anomaly-based detection without a screened subnet.

38.

The IT Manager at a multinational corporation wants to enhance the corporation's overall cybersecurity posture by implementing compensating technical controls. The organization has challenges implementing multi-factor authentication due to the nature of its operations. Which of the following should they consider?

a)

Installing a network intrusion detection system (NIDS)

b)

Implementing firewalls at key network junctures

c)

Conducting regular security risk assessments

d)

Implementing a rigorous password complexity and change schedule.

39.

During a cybersecurity attack, how would a threat actor use image files as a lure to target a vulnerability in a browser or document editing software?

a)

The threat actor embeds malicious code in word processing and PDF format files to exploit vulnerabilities in document viewer or editor software.

b)

They may use a program file with concealed exploit code, like Trojan Horse malware, to create backdoor access.

c)

The threat actor conceals exploit code within an image file that targets a vulnerability in the browser or document editing software.

d)

The threat actor conceals malware on a USB thumb drive or memory card and tricks employees into connecting the media to a PC, laptop, or smartphone.

40.

The organization's engineering team observes a system failure during the implementation of new software patching. From a conceptual standpoint, what can the team use to restore the system to its original state?

a)

Impact analysis

b)

Test results

c)

Backout plan

d)

Maintenance windows

41.

An organization needs to implement web filtering to bolster its security. The goal is to ensure consistent policy enforcement for both in-office and remote workers. Which of the following web filtering methods BEST meets this requirement?

a)

Implementing manual URL blocking

b)

Deploying agent-based web filtering

c)

Utilizing a centralized proxy server

d)

Relying solely on reputation-based filtering

42.

How does signature-based detection differ from anomaly-based detection in an intrusion detection system (IDS)?

a)

Signature-based detection identifies deviations from normal behavior, while anomaly-based detection relies on known attack patterns.

b)

Both signature-based and anomaly-based detection rely on known attack patterns.

c)

Signature-based detection relies on known attack patterns, while anomaly-based detection identifies deviations from normal behavior.

d)

Both signature-based and anomaly-based detection identify deviations from normal behavior.

43.

An organization's security team notices an unexpected program running in the background of several employee machines. The program is generating suspicious output files, filling up with recognizable, plaintext strings of characters. Which type of malicious software MOST likely involves generating this type of output?

a)

Keylogger

b)

Ransomware

c)

Rootkit

d)

Spyware

44.

The security manager at a financial technology company seeks to enforce a control that enhances user behavior to mitigate cybersecurity risks. What type of control should an analyst recommend the security manager put in place?

a)

The analyst should recommend installing biometric security devices.

b)

The analyst should recommend the enforcement of a strict password policy.

c)

The analyst should recommend a tool that assesses potential security risks.

d)

The analyst should recommend the placement of security cameras around the premises.

45.

A company is looking to expand its business into new markets despite associated risks. It prepares to accept higher risks for potentially higher returns. Which of the following approaches BEST meets the company's risk management approach parameters?

a)

Risk mitigation

b)

Risk intolerance

c)

Risk threshold

d)

Risk appetite

46.

A small department at a company manages a server, separate from IT, for data access and backup purposes. What role does the department fulfill?

a)

Data owner

b)

Data processor

c)

Data controller

d)

Data custodian

47.

The IT team for a small company is getting ready to implement a new wireless network to improve workplace mobility and productivity. Conducting a thorough analysis of the office layout and user needs, they face the challenge of strategically positioning the wireless access points (WAPs) throughout the office. What factors should the IT team consider when strategically placing the WAPs in the company's new wireless network? (Select the two best options.)

a)

Ensuring the wireless access points (WAPs) are accessible only to employees with specific job roles and responsibilities

b)

Optimal coverage of the office area to ensure reliable connectivity for all users

c)

Positioning wireless access points (WAPs) based on the design preferences of the company's management

d)

Minimizing interference from nearby electronic devices to enhance network performance

48.

The state library is in the process of digitizing its collection of antique manuscripts to publish online. Some of these manuscripts contain information that has barriers preventing the general public from accessing them. What type of data are these manuscripts?

a)

Sensitive

b)

Public

c)

Restricted

d)

Private

49.

A company's network has experienced increased infiltration due to employees accessing dangerous websites from different content categories. The company has decided to enhance its security by implementing reputation-based filtering and content categorization in its web filtering system. Which of the following BEST compares these features?

a)

Reputation-based filtering allows .exe downloads, while content categorization prevents the use of social media platforms.

b)

Reputation-based filtering classifies websites into different categories, and content categorization scores websites based on behavior and history.

c)

Reputation-based filtering assesses transport methods to score sites, while content categorization classifies sites based on content type.

d)

Reputation-based filtering scores websites based on their behavior and history, while content categorization classifies websites into various groups like social networking or adult content.

50.

During an annual review, a health services company's leadership aims to scrutinize its disaster response and data recovery protocols. They focus on effectiveness, hidden weaknesses, and clarity of employee roles during a disaster. Which course of action would BEST serve these objectives?

a)

Expanding the IT department

b)

Organizing tabletop exercises

c)

Increasing the frequency of data backups

d)

Installing larger uninterruptible power supply (UPS) systems

51.

A company finds that employees are accessing streaming websites that are not being monitored for malware or viruses. Which type of control can the network administrator implement to protect the system and keep the employees from viewing unapproved sites?

a)

Corrective

b)

Detective

c)

Technical

d)

Operational

52.

Which feature of web filtering is the MOST effective for organizations aiming to reduce the risk of malware infections by blocking access to websites known for hosting malicious content?

a)

Block rules

b)

Uniform Resource Locator (URL) scanning

c)

Content categorization

d)

Reputation-based filtering

53.

A globally recognized fast-food chain recently experienced a cyber attack. The attackers have not shown interest in stealing sensitive data or disrupting operations but have defaced the company's website with messages promoting animal rights and the ethical treatment of livestock. Based on this information, which type of threat actor is MOST likely responsible for this attack?

a)

Nation-state

b)

Insider threat

c)

Individual hacker

d)

Hacktivist

54.

A cybersecurity specialist deals with potential system compromises that can manifest as suspicious network activity or abnormal system behavior in the organization's network. What manifestation should the cybersecurity specialist be analyzing?

a)

Intrusion detection system (IDS) alerts

b)

Indicators

c)

System logs

d)

Firewall alerts

55.

A large organization is redesigning its network and is considering the placement of servers and networking equipment, and is enabling switch port security. The primary concern is maintaining the high availability of services and securing the network infrastructure from unauthorized access. What approach should the organization adopt to address these concerns?

a)

Distribute servers across different secure locations for redundancy, leave all ports enabled for flexibility, and implement 802.1X authentication.

b)

Place all networking devices in easily accessible locations for maintenance, leave all ports enabled for flexibility.

c)

Distribute servers across different secure locations for redundancy, disable unused ports, and implement 802.1X authentication.

d)

Place all servers in one location for ease of management, disable unused ports, and implement MAC filtering.

56.

What action of the incident response process removes affected components from the larger environment?

a)

Eradication

b)

Detection

c)

Analysis

d)

Containment

57.

An IT company purchases a commercial-off-the-shelf (COTS) product that allows four developers to access and run the product against developed code for vulnerability and threat assessments. An IT audit indicates that five developers have accessed the product. Which of the following BEST describes what the company has violated?

a)

Vendor diversity

b)

Terms of agreement

c)

Compliance/Licensing

d)

Regulatory framework

58.

An organization notices an external actor trying to gain access to the company network. The attacker is not targeting a specific account but rather using the same password across a vast range of usernames in hopes that one might be correct. What type of attack BEST describes this scenario?

a)

Dictionary

b)

Brute force

c)

Spraying

d)

Rainbow table

59.

A tech department must develop asset protection standards for the organization after several laptop computers went missing from a storage bank. How does classification assist in ensuring the organization is effectively managing and protecting its resources while maintaining accountability? (Select the best three options.)

a)

It enables consistent and repeatable activity.

b)

It involves organizing assets based on their value and sensitivity.

c)

It establishes a clear chain of accountability.

d)

It enables effective prioritization for maintenance.

60.

Analyze and select the statements that accurately distinguish the differences between Mean Time to Repair (MTTR) and Mean Time Between Failures (MTBF).

a)

MTBF is the amount of data loss that a system can sustain, measured in time. While MTTR is the longest period of time that a business function outage may occur for without causing irrecoverable business failure.

b)

MTTR refers to how long equipment will last until it is no longer operational. While the MTBF describes how long it would take to bring equipment back into operation.

c)

MTTR describes how long it would take to bring equipment back into operation. While the MTBF refers to how long equipment will last until it is no longer operational.

d)

MTTR is the amount of data loss that a system can sustain, measured in time. While MTBF is the longest period of time that a business function outage may occur without causing irrecoverable business failure.

61.

A field technician adds automation to assist in streamlining the new human resource interviewing process. How does using Application Programming Interfaces (APIs) assist in this scenario?

a)

Different software systems are enabled to communicate and interact, creating seamless workflows.

b)

Developers regularly merge their changes back to the main code branch.

c)

The system automatically evaluates merges to help detect and fix integration issues.

d)

The technician makes improvements to code quality and accelerates development cycles.

62.

The data processing department of a company is struggling to handle increasing computational demands due to business growth. What approach could they consider to address this issue effectively?

a)

Implementing scalable architecture

b)

Introducing microservices

c)

Establishing a third-party vendor partnership

d)

Adopting an air-gapped system

63.

In a company, different departments actively access various cloud-based applications and services to perform their tasks efficiently. The company's security team has concerns about the growing complexity and risks of managing user credentials across multiple platforms. To address this concern proactively, the team implements a modern authentication solution that actively provides Single Sign-On (SSO) capabilities, ensuring enhanced user convenience and security. In this scenario, which technology should the organization proactively employ for federation and enabling SSO capabilities effectively across the diverse range of cloud-based applications?

a)

Lightweight Directory Access Protocol (LDAP)

b)

Public Key Infrastructure (PKI)

c)

Open Authorization (OAuth)

d)

Role-Based Access Control (RBAC)

64.

A technology firm is adopting a structured approach to managing risk. It catalogs potential risks and assigns them to responsible parties within the team. This catalog also includes the strategies to mitigate these risks and their potential impacts. What document must the firm develop as it adopts this approach?

a)

Risk register

b)

Risk analysis

c)

Business impact analysis

d)

Risk assessment

65.

A small IT company is experiencing an increased number of cyberattacks. Its server uses default settings from the developer, which the company believes is a potential source of vulnerability. Which of the following changes should the IT company consider to improve the server's security?

a)

Limit the privileges of each user on the server

b)

Continue to use the default settings but increase monitoring efforts

c)

Switch off the server whenever it is not in use

d)

Ignore software and security patches and updates

66.

In a fast-paced technology company, employees often need access to various proprietary software applications and sensitive databases to perform their roles efficiently. The IT team is considering implementing a new authentication solution to ensure secure access and data protection. They want a system that allows employees to log in using their company credentials and provides seamless access to all authorized resources. Additionally, the solution should integrate with their existing Lightweight Directory Access Protocol (LDAP) infrastructure, enabling easy user management and reducing administrative overhead. Which technology would BEST meet the company's requirements for a new authentication solution that allows seamless access to authorized resources, integrates with LDAP for user management, and ensures data protection?

a)

Network Address Translation (NAT)

b)

Virtual Private Network (VPN)

c)

Remote Authentication Dial-in User Service (RADIUS)

d)

Security assertion markup language (SAML)

67.

A security specialist is drafting a memorandum on secure data destruction for the organization after a recent breach. What benefit does the certification concept offer when evaluating appropriate disposal/decommissioning?

a)

It refers to the documentation and verification of the data sanitization or destruction process.

b)

It refers to policies and practices governing the storage and preservation of information within the organization for a set period of time.

c)

It ensures that organizations maintain compliance with relevant regulations and minimize breach risks.

d)

It is often based on legal, regulatory, or operational requirements.

68.

An IT security manager at a technical college wants to increase the use of controls that generate alerts where ongoing attacks are suspected in the organization's network infrastructure. Which of the following is a suitable illustration of this type of control?

a)

Implementing an intrusion detection system

b)

Establishing a secure firewall

c)

Using strong password policies

d)

Regularly updating antivirus software

69.

A healthcare organization is setting up a system to store patient passwords securely. To ensure that only authorized personnel can verify the passwords and the system cannot be compromised during a breach, which technique should the organization implement?

a)

Symmetric encryption

b)

Asymmetric encryption

c)

Tokenization

d)

Hashing

70.

A cyber group is reviewing its web filtering capabilities after a recent breach. Which centralized web-filtering technique groups websites into categories such as social networking, gambling, and webmail?

a)

Uniform resource locators (URL) scanning

b)

Reputation-based filtering

c)

Block rules

d)

Content categorization

71.

The security team at a tech company receives a notification regarding a sudden increase in the number of system logs generated. The system is generating logs at unusual times outside regular business hours. The company follows a well-documented security protocol. What does the sudden increase in the logging activity indicate?

a)

Spraying

b)

Incorrect documentation

c)

Malware attacks

d)

Out-of-cycle logging

72.

The IT department in a mid-sized organization recently moved to a virtualized environment to host its applications and data. The network administrator observes an increase in resource utilization efficiency. However, to mitigate potential data leakage and ensure the integrity of data, the administrator plans to implement a strategy for resource reuse. Given the current scenario, which of the following approaches should the network administrator consider for reassigning resources in the virtualized environment to protect remnants of any previous data from exposure to the subsequent processes?

a)

Enable Secure Sockets Layer (SSL) encryption.

b)

Develop an incident response plan.

c)

Enforce password complexity rules.

d)

Apply secure deallocation.

73.

In a corporate setting, the IT department is working to enhance the organization's cybersecurity measures. They are implementing a new encryption system to protect sensitive data stored on their servers. As part of the security enhancement, the IT team is also educating employees about the importance of strong passwords. What is the primary purpose of implementing an encryption system and promoting strong passwords in the organization's cybersecurity strategy?

a)

To protect sensitive data and ensure its confidentiality and security

b)

To prevent employees from accessing certain encrypted data

c)

To avoid the need for regular password changes by employees

d)

To increase the complexity of the organization's IT infrastructure

74.

The IT department at a governmental agency is actively responsible for ensuring the security of the agency's sensitive information and physical assets. Recently, concerns have arisen about unauthorized access to certain restricted areas within the building. To address this issue, the IT team is implementing access control measures to enhance physical security. The main objective is to restrict entry to authorized personnel only and prevent unauthorized individuals from gaining access to sensitive areas. What access control measures could the IT department implement in the office building to enhance physical security and prevent unauthorized access to restricted areas?

a)

Mandatory password changes for employee accounts

b)

Installation of surveillance cameras throughout the building

c)

Installation of alarms within restricted zones

d)

Biometric authentication system using fingerprint scanning

75.

The management of a tech startup is seeking to confirm that their newly developed app is adhering to all pertinent data protection laws and regulations, especially regarding user data handling. To gain assurance and demonstrate this adherence to its stakeholders, which approach should the startup primarily employ?

a)

Peer review

b)

External compliance audit

c)

Self-regulation

d)

Internal regulatory review

76.

A user in a company wants a new USB flash drive. Rather than requesting one through the proper channel, the user obtains one from one of the company's storage closets. Upon approaching the closet door, the user notices a warning sign indicating cameras are in use. What is the control objective of the observed sign?

a)

Detective

b)

Corrective

c)

Preventive

d)

Deterrent

77.

A nonprofit organization with limited funds needs a cost-effective disaster recovery plan that doesn't necessitate immediate resumption of services after a disaster. Which strategy is the MOST suitable?

a)

Implement a hot site

b)

Deploy a cold site

c)

Set up a warm site

d)

Establish a COOP

78.

CryptoCloud is expanding its business and is considering outsourcing its IT resources to a managed services provider (MSP) to improve efficiency and reliability. Which of the following statements about MSPs and their role in the supply chain are correct? (Select the two best options.)

a)

Managed services provider (MSP) are only suitable for large enterprises with extensive IT infrastructure and are not recommended for smaller businesses.

b)

Managed services provider (MSP) may introduce a complex security challenge as monitoring their employees can be difficult.

c)

Managed services provider (MSP) handle the end-to-end process of designing, manufacturing, and distributing goods and services to customers.

d)

Managed services provider (MSP) primarily focus on providing support for IT resources such as networks, security, or web infrastructure.

79.

A cyber technician reduces a computer's attack surface by installing a cryptoprocessor that a plug-in PCIe adaptor card can remove. What type of cryptoprocessor can support this requirement?

a)

Certificate Revocation Lists (CRL)

b)

Hardware Security Module (HSM)

c)

Trusted Platform Module (TPM)

d)

Public Key Infrastructure (PKI)

80.

An organization is experiencing recurring unauthorized data transfer incidents linked to the misuse of peripheral storage devices. To contain this specific threat, what would be the MOST effective measure?

a)

Implement removable media controls

b)

Deploy an intrusion detection system (IDS)

c)

Increase password complexity

d)

Focus on employee training

81.

An organization has an established change management program that includes standard operating procedures (SOPs). It wants to implement changes consistently and effectively. What role do SOPs play in the change management process?

a)

Standard operating procedures (SOPs) help track and communicate the status and outcome of approved changes.

b)

Standard operating procedures (SOPs) outline the steps for employees to follow when conducting an impact analysis.

c)

Standard operating procedures (SOPs) define routine operations or changes and provide detailed instructions for their implementation.

d)

Standard operating procedures (SOPs) provide guidelines for developing backout plans for changes.

82.

A network administrator suspects that an attacker is intercepting and potentially modifying communications between their organization's server and the client systems. The attacker is not detected by either party during this process. Which type of attack is the network administrator likely observing in this instance?

a)

Replay attack

b)

On-path attack

c)

Domain Name System (DNS) attack

d)

Distributed denial-of-service (DDoS) attack

83.

A threat actor poses as a remote sales representative and contacts the help desk of CloudSecure. The threat actor claims to need assistance setting up remote access. Through a series of convincing phone calls, the threat actor obtains the name and address of the remote access server and a login credential. What type of attack does this scenario illustrate?

a)

Man-in-the-middle

b)

Phishing

c)

Social engineering

d)

Denial-of-service

84.

An organization wants to implement a hybrid cloud strategy and understand the security implications of its responsibility matrix. What should the employees consider in this analysis?

a)

Completely relying on third-party security audits

b)

Implementing a full IaaS model, handing all infrastructure security responsibilities to the cloud provider

c)

Balancing security responsibilities between on-premises and cloud, ensuring clear definition in the responsibility matrix

d)

Choosing the cloud provider based only on pricing

85.

A multinational corporation handles regulated data. What are the key considerations for handling and protecting the data to ensure compliance?

a)

Financial and trade secret data: reporting, risk management, non-disclosure agreements

b)

Data requiring encryption: secure storage, transmission, adherence to standards

c)

Data subject to legal and regulatory requirements: privacy, security, compliance

d)

Data requiring user awareness training: content filtering, web security, authentication

86.

A system admin is discussing the importance of prompt attention to vulnerabilities with a new IT hire. One of the MOST important things to capture about a new vulnerability is its classification. What characteristics are directly related to this? (Select the three best options.)

a)

Nature of vulnerability

b)

Potential impact

c)

Scope

d)

Type of system affected

87.

A multinational corporation wants to enhance its security infrastructure by deploying an Intrusion Detection System (IDS) across its global network. The IT manager is considering the placement of IDS sensors to ensure comprehensive network visibility. Which IDS sensor placement is the MOST effective in this scenario?

a)

Place the IDS sensors on the external network.

b)

Place the IDS sensors at network choke points.

c)

Place the IDS sensors on the internal network.

d)

Place the IDS sensors near the network perimeter.