wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Comptia Security+ Practice 2

Total questions: 87

Worksheet time: 47mins

Name
Class
Date
1.

A recently breached company tasks the cyber team to further restrict end-user permissions. What describes the use of an application allow list?

a)

It is used in computer systems and networks to enforce policies.

b)

It is a list of rules or entries that specify users' access.

c)

It allows or denies an application from running.

d)

It controls access to files, directories, or systems resources in OSs.

2.

An organization performs a business impact analysis to identify potential effects of business interruptions. It is trying to identify the maximum acceptable time its key business process can be down before it severely impacts operations. What is the organization attempting to determine?

a)

Annualized Rate of Occurrence (ARO)

b)

Mean Time To Repair (MTTR)

c)

Recovery Time Objective (RTO)

d)

Mean Time Between Failures (MTBF)

3.

A company using Wi-Fi Protected Access (WPA) wireless security on their wireless access points (WAPs) uses Lightweight Extensible Authentication Protocol (LEAP) to authenticate users to the network. LEAP is vulnerable to password cracking. What other options does the company have to mitigate this vulnerability? (Select the two best options.)

a)

Protected Extensible Authentication Protocol (PEAP)

b)

Flexible Authentication via Secure Tunneling (EAP-FAST)

c)

RADIUS federation

d)

EAP-MD5

4.

A system admin is discussing the importance of prompt attention to vulnerabilities with a new IT hire. One of the MOST important things to capture about a new vulnerability is its classification. What characteristics are directly related to this? (Select the three best options.)

a)

Nature of vulnerability

b)

Potential impact

c)

Scope

d)

Type of system affected

5.

A cybersecurity specialist in a company notes a general decrease in system performance due to resource consumption, but there is no evidence of harmful intent, and the network seems to be functional. What is MOST likely causing the decreased performance?

a)

Virus

b)

Bloatware

c)

Directory traversal

d)

Concurrent session usage

6.

A healthcare organization is preparing to decommission several servers containing sensitive patient information. The organization wants to ensure that it securely disposes of the data on these servers and properly documents this process. What should the organization primarily focus on to ensure secure data disposal and regulation compliance?

a)

Pass the servers to the IT team for random allocation among employees.

b)

Sell the servers as soon as possible to reclaim some of the initial investment.

c)

Keep the servers in storage indefinitely as a backup in case of data loss.

d)

Obtain a certificate of destruction or sanitization from a third-party provider.

7.

A cybersecurity specialist deals with potential system compromises that can manifest as suspicious network activity or abnormal system behavior in the organization's network. What manifestation should the cybersecurity specialist be analyzing?

a)

Intrusion detection system (IDS) alerts

b)

Indicators

c)

System logs

d)

Firewall alerts

8.

A lab technician explores the variances regarding automation and orchestration opportunities between security operations and infrastructure management. What is a benefit of automation and orchestration in infrastructure management? (Select the three best options.)

a)

It enforces standardized configurations to ensure consistency.

b)

It enhances scalability and flexibility by simplifying deployment.

c)

It enforces standardized baselines through configuration management tools.

d)

It saves time and resources by allowing configurations to deploy quickly.

9.

A recent attack on the company involving a threat actor from another country prompted the security team to host regular penetration testing exercises. The attack involved the IT team and human resources because the breach occurred on an employee desktop. In the upcoming training, what role would the human resource team portray along with the IT team to simulate the recent attack and its experiences?

a)

Blue team

b)

Red team

c)

White team

d)

Purple team

10.

After encountering a cyber attack, an organization uses a monitoring solution that automatically restarts services after it has detected the system has crashed. What type of functional security control is the company implementing?

a)

Technical

b)

Managerial

c)

Corrective

d)

Compensating

11.

A cloud storage company wants to ensure that it stores user data in the same country as the user's physical location. Which factor is the cloud storage company primarily considering here?

a)

Data sovereignty

b)

Geolocation

c)

Data integrity

d)

Data classification

12.

A financial organization has hired a cybersecurity expert to strengthen the security of its system. The expert recommends implementing a specific technique into unreadable ciphertext by converting plaintext credit card information, regardless if it is active, in transit, or at rest. What technique should the cybersecurity expert implement?

a)

Tokenization

b)

Hashing

c)

Encryption

d)

Obfuscation

13.

The network security manager of a large corporation is planning to improve the efficiency of the company's Security Information and Event Management (SIEM) system. The SIEM system receives data from various sources, including Windows and Linux hosts, switches, routers, and firewalls. To make the data from different sources more consistent and searchable, which functionality should the manager focus on enhancing in the SIEM system?

a)

Enhance the agent-based collection method on the security information and event management (SIEM) system

b)

Implement additional packet sniffers in the network

c)

Improve the security information and event management (SIEM) system's vulnerability scanning capabilities

d)

Refine the log aggregation process in the security information and event management (SIEM) system

14.

The IT department at a large corporation noticed an unfamiliar software application running on its network. Upon investigation, they discovered that a team in the marketing department started using a new cloud-based project management tool to improve their workflow efficiency. The team did not consult with the IT department before implementing this tool. In the context of cybersecurity threats, what does this situation BEST exemplify?

a)

Nation-state

b)

Shadow IT

c)

Careless password management

d)

Insider threat

15.

A financial institution is preparing to decommission a number of its old servers. The servers contain sensitive customer data that needs proper handling to prevent unauthorized access or data breaches. Which strategy should the institution primarily employ to ensure the data on these servers stays irretrievable.

a)

Carry out a sanitization process that includes multiple passes of overwriting and degaussing.

b)

Leave the data on the servers, as the system will eventually overwrite it.

c)

Physically destroying the servers is necessary.

d)

Use a basic method of overwriting, such as zero filling, once.

16.

A healthcare organization is retiring an old database server that housed sensitive patient information. It aims to ensure that this information is completely irretrievable. What key process should the organization prioritize before disposing of this server?

a)

Certification of the server's functionality

b)

Preservation of all data for future reference

c)

Repurposing of the server without any modifications

d)

Secure destruction of all data stored on the server

17.

Upon receiving additional funding for the new quarter, a software team leader looks to acquire new automation and orchestration tools to enhance the IT department. What is NOT considered a benefit of automation and orchestration implementation for infrastructure management?

a)

Enhancing scalability and flexibility by simplifying deployment

b)

Enforcing standardized configurations to ensure consistency

c)

Saving time and resources by allowing configurations to deploy quickly

d)

Enforcing standardized baselines through configuration management tools

18.

An organization is experiencing an attack where the attackers break into the premises or cabinets by forcing a gateway or locks. What BEST describes the observed attack?

a)

Collision

b)

Brute force

c)

Downgrade

d)

Birthday

19.

A systems administrator receives an alert for potential unauthorized access to sensitive data while in active memory on a server within the organization. The organization has tasked the systems administrator with enforcing stricter controls to prevent such breaches. What would be the MOST appropriate measure to implement?

a)

Data obfuscation

b)

Data masking

c)

Data encryption

d)

Permission restrictions

20.

A mid-sized software development company recently expanded its operations and acquired many new IT assets. Which method should the company primarily consider for asset enumeration to manage these assets and maintain an accurate inventory effectively?

a)

Implementing asset management software to automatically discover, track, and catalog various types of assets

b)

Using network scanning tools to automatically discover and enumerate networked devices

c)

Relying on staff members to report their assigned assets and maintain the inventory

d)

Manually inspecting and recording information about each asset

21.

The IT department in an accounting firm is gearing up for an external penetration testing engagement to evaluate the organization's security readiness. To guarantee a seamless testing process and prevent misunderstandings, the IT team has worked closely with the company's management and relevant stakeholders to set up the rules of engagement (ROE) for the assessment. What is the purpose of establishing rules of engagement during a penetration testing engagement?

a)

To ensure the penetration test results are shared with external parties to strengthen collaboration

b)

To define the scope of the assessment, testing methods, and timeframe for conducting the test

c)

To allow penetration testers unrestricted access to all systems and data within the organization

d)

To eliminate all security vulnerabilities identified during the testing process

22.

A board of directors convenes a monthly meeting to discuss reports that the tech department was not meeting legal regulations. What are the impacts associated with sanctions? (Select the two best options.)

a)

It can include financial penalties, legal liabilities, and loss of customer trust.

b)

It can grant certain individuals with the ability to challenge credit data on their personal reports.

c)

It can be overseen by numerous governing bodies, such as regulatory authorities.

d)

It can result in a breach or termination of an agreement, or indemnification.

23.

A cybersecurity team is investigating a complex cyber threat landscape for a large financial institution. The team is aware of some potential threats due to previous encounters and security measures in place, but the evolving nature of the landscape presents new threats and challenges. What type of cyber environment is the team dealing with?

a)

Reconnaissance

b)

Fully known environment

c)

Unknown environment

d)

Partially known environment

24.

An organization's IT department wants to implement a security model responsible for verifying user identities, determining access rights, and monitoring activities within a system. Which concept is MOST appropriate for the department to implement?

a)

AAA

b)

Zero trust

c)

Policy engine

d)

RBAC

25.

A large financial corporation is refining its information security policies to enhance its overall cybersecurity posture. The security team recognizes the need for continuous monitoring and revision of policies to adapt to the changing threat landscape. Given the scenario, which statements accurately outline the considerations for monitoring and revising information security policies in this context? (Select the two best options.)

a)

The team should use employee feedback to identify gaps in current policies.

b)

The team should only revise policies when a security incident occurs.

c)

The team should regularly review policies to address emerging security threats.

d)

The team does not need to monitor policies if there are no apparent security incidents.

26.

When setting up a new server room for sensitive data storage, a tech company seeks to enhance preventive measures against unauthorized access. Which measure would be MOST effective for this purpose?

a)

Intrusion detection system (IDS)

b)

Server encryption

c)

Physical security

d)

Video surveillance

27.

A company wants to improve the physical security at its headquarters. They need a solution that can help regulate access to the building and deter potential intruders during nighttime. Which physical security measure should they prioritize?

a)

Closed-circuit television (CCTV)

b)

Access control vestibule

c)

Enhanced lighting

d)

Perimeter fencing

28.

A small business wants to enhance the security of its IT infrastructure which includes various network devices, operating systems, and applications. The business is considering a standardized approach by changing default configurations, disabling unnecessary services, applying regular patches and updates, and enforcing strong password policies. To which resource should the company refer for secure configuration BEST practices?

a)

Latest Cyber Threat Intelligence Reports

b)

Vendor-specific user manuals

c)

Network Performance Analysis Reports

d)

Center for Internet Security (CIS) Benchmarks

29.

Which organizational policy does a cybersecurity analyst need to outline the procedures in case of a security breach or cyberattack? This policy includes steps for identifying, investigating, controlling, and mitigating the impact of incidents.

a)

Software Development Life Cycle (SDLC)

b)

Information security policy

c)

Disaster recovery policy

d)

Acceptable use policy (AUP)

30.

A representative at a company reports receiving numerous unsolicited phone calls seeking banking information for a credit report. Which social engineering variant is the finance director experiencing?

a)

Spear phishing

b)

Smishing

c)

Vishing

d)

Vishing

31.

A tech department receives funding to enhance the automation and scripting for IT operations to streamline processes and improve efficiency. Upon reviewing the various capabilities associated with automation and scripting, what capability provides frameworks for managing security within an organization and can monitor and enforce compliance with security policies?

a)

Resource provisioning

b)

Guardrail

c)

User provisioning

d)

Workforce multiplier

32.

An organization is considering a hybrid cloud deployment to leverage the benefits of both private and public cloud resources. While reviewing third-party vendors, what critical aspect should the employees consider for a secure and effective transition?

a)

Delegate all security management to the provider

b)

Focus on data redundancy

c)

Prioritize lowest-cost vendors

d)

Establish clear service level agreements (SLAs)

33.

A healthcare organization is setting up a system to store patient passwords securely. To ensure that only authorized personnel can verify the passwords and the system cannot be compromised during a breach, which technique should the organization implement?

a)

Symmetric encryption

b)

Asymmetric encryption

c)

Tokenization

d)

Hashing

34.

A healthcare provider is digitalizing its patient data and needs a system that guarantees the preservation of its sensitive data in the event of a disaster while avoiding lock-in to a single technology vendor's platform. What is the MOST crucial practice the provider needs to implement?

a)

Incorporating additional power generators

b)

Maintaining regular data backups

c)

Implementing an Uninterruptible Power Supply (UPS)

d)

Adopting platform diversity for their digital infrastructure

35.

A technology firm's network security specialist notices a sudden increase in unidentified activities on the firm's Security Event and Incident Management (SIEM) incident tracking system. An unknown entity or process also increases the number of reported incidents. The specialist decides to investigate these incidents. Which combination of data sources would provide a balanced perspective to support the investigation?

a)

Logs from vulnerability assessment tools, which identify potential weaknesses; transaction logs from databases, tracking changes; and logs from mobile devices, recording device activities.

b)

System-specific security logs, which track system-level operations; logs generated by applications running on hosts; and real-time reports from the SIEM solution, summarizing incidents.

c)

Gateway logs, which track incoming and outgoing network traffic; network interactions monitored by intrusion detection systems (IDS), which detect unauthorized activities; and logs from server OS components.

d)

User activity logs, which record user behaviors; daily summary reports from the SIEM solution; and high-level network overviews, providing a broad view of network activities.

36.

An IT security analyst is conducting a risk assessment for a global corporation that recently started outsourcing its hardware production to several manufacturers overseas. The corporation is aware of the threats associated with an expanded supply chain and seeks to mitigate potential security risks linked to its hardware devices. Which of the following risk mitigation strategies should the corporation adopt to ensure the security of its hardware devices without unnecessarily hindering its operations? (Select the best two options.)

a)

Implement strict supplier vetting processes.

b)

Adopt a zero-trust network architecture.

c)

Outsource all hardware production to a single trusted manufacturer.

d)

Perform regular audits of its supplier's manufacturing processes.

37.

A system administrator assesses a software company's security measures, paying special attention to the varied cryptographic methods used for data security. Given the potential misconfigurations that could endanger data integrity and confidentiality, the administrator seeks to lower the risk of misconfigurations within the cryptographic settings that might result in security vulnerabilities. Which actions should the system administrator prioritize to ensure properly configured cryptographic systems and prevent potential security breaches? (Select the two best options.)

a)

Conduct periodic penetration testing.

b)

Adopt biometric authentication.

c)

Regularly update and patch cryptographic software.

d)

Implement network segmentation.

38.

The cybersecurity department of a major bank has just finished deploying a new email security tool to detect and filter potential phishing emails. To validate its effectiveness, which phase of the phishing prevention strategy should the department focus on next?

a)

User guidance and training

b)

Recognizing a phishing attempt

c)

Execution phase of the prevention strategy

d)

Establishing an anomaly-based intrusion detection system

39.

A company is developing a system that requires instantaneous response to certain inputs. The system will incorporate into a larger device and will not have many resources. What type of system is likely to be MOST suitable for this scenario?

a)

Linux operating system

b)

Embedded systems

c)

Real-time operating system

d)

Windows operating system

40.

The security team at a multinational cloud services company is working on their port security. They implemented basic Media Access Control (MAC) address filtering on all switch ports, but they have concerns about the risk of MAC spoofing and the management overhead of maintaining a list of valid MAC addresses. To address these concerns, they now require strong authentication before a user can obtain full network access. Which of the following measures should the team implement next?

a)

Disable all unused switch ports.

b)

Implement physical isolation for critical servers.

c)

Implement EAP and RADIUS.

d)

Segregate into multiple security zones.

41.

Companies often update their website links to redirect users to new web pages that may feature a unique promotion or to transition to a new web experience. How would an attacker take advantage of these common operations to lead users to fake versions of the website?

a)

Hijack the website's domain

b)

Include a malicious attachment in the email

c)

Ruin the companys reputation with reviews

d)

Craft phishing links in email

42.

A US-based financial institution is increasing security on customer-stored driver's license number data by using a method of converting the information from "123456789" to "ef7FTrR87". What type of obfuscation is the institution using to protect the driver's license information?

a)

Data masking

b)

Tokenization

c)

Steganography

d)

Salting

43.

How do data inventories assist organizations in maintaining records of collected data?

a)

It requires individuals or entities to announce their understanding of compliance obligations formally.

b)

It is the comprehensive assessment and evaluation of an organization's data protection practices.

c)

It is an established timeline that requires organizations to keep documentation.

d)

It provides a comprehensive overview of the types of handled data.

44.

In a medium-sized tech company, employees have different roles and responsibilities requiring access to specific resources and data. The IT team is implementing security measures to control access effectively and reduce the risk of unauthorized activities. What security measure could the IT team implement in the tech company to control access effectively and minimize the risk of unauthorized activities?

a)

Implement a firewall to protect the company's network from external threats

b)

The principle of least privilege, granting each employee the minimum necessary access based on job roles

c)

Enforce mandatory password changes every month to enhance password security

d)

Implement intrusion detection systems to monitor and identify potential security breaches

45.

A financial organization is currently handling a document that contains sensitive customer information, including financial details and social security numbers. According to data classifications, how should the financial organization categorize this data?

a)

Proprietary data

b)

Restricted data

c)

Confidential data

d)

Trade secret data

46.

During a cybersecurity attack, how would a threat actor use image files as a lure to target a vulnerability in a browser or document editing software?

a)

The threat actor embeds malicious code in word processing and PDF format files to exploit vulnerabilities in document viewer or editor software.

b)

They may use a program file with concealed exploit code, like Trojan Horse malware, to create backdoor access.

c)

The threat actor conceals exploit code within an image file that targets a vulnerability in the browser or document editing software.

d)

The threat actor conceals malware on a USB thumb drive or memory card and tricks employees into connecting the media to a PC, laptop, or smartphone.

47.

A global e-commerce company faces challenges with its legacy monolithic application. The application is becoming increasingly difficult to maintain due to its intertwined components and struggles to scale quickly enough to handle sudden traffic surges during big sales events. The company has already invested in cloud technology and on-premises infrastructure but still faces scalability and manageability issues. What would MOST effectively address these challenges?

a)

Embedded systems

b)

Serverless infrastructure

c)

Virtualization

d)

Microservices

48.

At a technology company, the IT department is finalizing an agreement with a cloud service provider to host its sensitive customer data. The IT team has actively ensured the inclusion of a Service Level Agreement (SLA) in the contract. What is the primary purpose of actively including an SLA in the contract with the cloud service provider?

a)

To outline the intentions and expectations of parties involved in a potential partnership

b)

To protect the confidentiality of sensitive information shared between parties

c)

To establish clear guidelines on what information is considered confidential

d)

To define the level of service the cloud service provider must deliver

49.

An organization requires employees to take an annual training course to identify malicious emails. What aspects of cybersecurity BEST practices is the organization emphasizing? (Select the three best options.)

a)

Reporting and monitoring cyber threats

b)

Anomalous behavior recognition

c)

Recurring training and awareness programs

d)

Insider threat management

50.

A cyber technician reduces a computer's attack surface by installing a cryptoprocessor that a plug-in PCIe adaptor card can remove. What type of cryptoprocessor can support this requirement?

a)

Certificate Revocation Lists (CRL)

b)

Hardware Security Module (HSM)

c)

Trusted Platform Module (TPM)

d)

Public Key Infrastructure (PKI)

51.

A network engineer has the task of creating a remote access solution for a global enterprise. The solution should secure encrypted communication for the company’s employees worldwide and detect potential security threats in real time. Which configuration should the network engineer deploy to meet these requirements?

a)

A VPN utilizing IKE and IPSec protocols, combined with an inline intrusion detection system (IDS)

b)

A Software-Defined Wide Area Network (SD-WAN) with secure access service edge (SASE) implementation, supplemented by an intrusion prevention system (IPS)

c)

A network equipped with a Next Generation Firewall (NGFW), a Web Application Firewall (WAF), and an intrusion prevention system (IPS) in tap/monitor mode

d)

A network fortified by 802.1X port security, an Extensible Authentication Protocol (EAP), and a load balancer

52.

As a network security administrator tasked with ensuring that only authorized devices can connect to the company's network, what would be the three MOST effective strategies to accomplish this goal? (Select the three best options.)

a)

Place the network switches in secure server rooms and/or lockable hardware cabinets.

b)

Physically disable the ports that unauthorized devices could potentially connect to.

c)

Implement media access control (MAC) filtering on network ports to only permit certain MAC addresses to connect.

d)

Use the IEEE 802.1X Port-based Network Access Control (PNAC) standard to require authentication when a host connects to a port.

53.

Customers receive a seemingly genuine email from their trusted bank informing them that their passwords need updating. However, when authenticating, an attacker captures the customer's credentials. What kind of attack did the bank customers experience?

a)

Whaling

b)

SMiShing

c)

Phishing

d)

Vishing

54.

A security architect at a multinational corporation designs a comprehensive security strategy to defend against advanced persistent threats (APTs). The strategy includes real-time analysis of network traffic, detection of unknown threats, correlation of events across different layers, and automatic response to mitigate risks. The architect also ensures compliance with international regulations on data privacy. Which data sources and security components combination would BEST align with this multifaceted approach?

a)

Intrusion prevention system/intrusion detection system (IPS/IDS) logs, anomaly detection, and automated response mechanisms

b)

Network logs, firewall logs, and operating system (OS)-specific security logs

c)

Vulnerability scans, packet captures, and dashboards

d)

Application logs and endpoint security

55.

A company acquires a smaller company and has its in-house technical team review the new systems before allowing them on the existing network. During this review, the technical team discovers users with unnecessary permissions, user accounts for former employees, and no longer needed groups. These discoveries indicate the violation of what BEST practice?

a)

Principle of least privilege

b)

File system permissions

c)

Configuration enforcement

d)

Access control

56.

In a medium-sized company, the IT department manages access to various systems and resources for employees. The team wants to enhance the security posture by implementing better access controls. They use rule-based access controls and time-of-day restrictions to achieve this goal. What are the IT department's objectives in implementing rule-based access controls and time-of-day restrictions?

a)

To ensure all employees have access to all resources at any time for increased productivity

b)

To restrict access to critical systems during non-working hours to enhance security

c)

To define specific access rules based on employees' roles and responsibilities

d)

To eliminate the need for user authentication and simplify access management

57.

The IT department at a governmental agency is actively responsible for ensuring the security of the agency's sensitive information and physical assets. Recently, concerns have arisen about unauthorized access to certain restricted areas within the building. To address this issue, the IT team is implementing access control measures to enhance physical security. The main objective is to restrict entry to authorized personnel only and prevent unauthorized individuals from gaining access to sensitive areas. What access control measures could the IT department implement in the office building to enhance physical security and prevent unauthorized access to restricted areas?

a)

Mandatory password changes for employee accounts

b)

Installation of surveillance cameras throughout the building

c)

Installation of alarms within restricted zones

d)

Biometric authentication system using fingerprint scanning

58.

A healthcare organization is strengthening its data protection framework to ensure compliance with local and international regulations. One focus area is clearly defining the roles and responsibilities between the data controllers and processors, as this impacts the overall management and protection of sensitive data. In this scenario, which two statements accurately outline the responsibilities of the data controller and the data processor regarding data protection? (Select the two best options.)

a)

Data controller—determines the purposes for which data is processed

b)

Data controller—performs day-to-day operations on data

c)

Data processor—decides the purpose of data processing

d)

Data processor—processes data on behalf of the controller

59.

A multinational corporation is reviewing its data governance policies to enhance its cybersecurity posture. A data governance expert has to outline the distinct roles and responsibilities between the systems owners and the data custodians. The company is specifically interested in the functions that pertain to data confidentiality, integrity, and availability. Based on the scenario, which roles are correctly assigned to the system owner and the data custodian in order to maintain the confidentiality, integrity, and availability of data? (Select the two best options.)

a)

System owner—performing system backups

b)

Data custodian—enforcing access controls

c)

System owner—implementing data classification

d)

Data custodian—making business decisions

60.

A company tasks a cybersecurity manager with improving the efficiency of its Security Information and Event Management (SIEM) system. The manager observes that the high number of false positive alerts causes alert fatigue among the analysts, potentially leading them to miss high-impact alerts. Which combination of strategies should the manager consider implementing to tackle this issue effectively?

a)

Assign all infrastructure-related alerts to the incident response team and increase the frequency of system reporting

b)

Mute all alerts to log-only status and deploy additional threat intelligence feeds in the SIEM system

c)

Refine detection rules, redirect sudden alert "floods" to a dedicated group, and continuously monitor alert volume and analyst feedback

d)

Increase the number of correlation rules and assign all alerts to a dedicated agent or team to remediate

61.

An enterprise has recently suffered from a series of cyber attacks. The IT security team is considering enhancing its security by improving the intrusion detection and prevention system (IDS/IPS). Which of the following options is the MOST effective way to improve the IDS/IPS?

a)

Disable signature updates to focus on anomaly detection only

b)

Update the signature database frequently

c)

Manually code all new attack signatures

d)

Ignore alerts generated by the system

62.

A multinational company is preparing to submit its annual statements and needs to share confidential reports with its global offices. The data includes the company's revenues, profits, and other sensitive information. What data category do these annual statements fall under?

a)

Trade secret data

b)

Regulated data

c)

Human-readable data

d)

Financial data

63.

A company is revamping its current IT infrastructure with a focus on enhancing its ability to operate under changing or harmful conditions without suffering a significant loss of functionality. What primary aspect of the system design should the team focus on to achieve this goal?

a)

Load balancing

b)

Resilience

c)

Network segmentation

d)

Availability

64.

A cyber security analyst notices an unusual amount of data transmitted from an employee's company computer to an unknown external IP address. The employee has all necessary permissions to access externally transferred sensitive data. What type of threat actor is MOST likely responsible for this situation?

a)

Unskilled attacker

b)

Nation-state

c)

Internal threat actor

d)

Hacktivist

65.

Which policy outlines the processes to follow after a security breach or cyberattack occurs and includes procedures for identifying, investigating, controlling, and mitigating the impact of incidents?

a)

Disaster recovery policy

b)

Acceptable use policy (AUP)

c)

Incident response policy

d)

Change management policy

66.

A test engineer analyzes a team's set of laptops after an outbreak of viruses and malware infections. What malware conceals itself within an installer package for software that appears to be legitimate?

a)

Trojan

b)

Ransomware

c)

Worm

d)

Spyware

67.

A company is reviewing its policies to ensure compliance with data privacy regulations. It wants to establish a policy that outlines the appropriate use of customer data. What type of policy should the company focus on?

a)

Disaster recovery policy

b)

Acceptable use policy (AUP)

c)

Data privacy policy

d)

Information security policy

68.

A company experiences a significant system failure that leads to service interruption. The IT department works to restore the system and documents the duration it takes to fix the problem. This recorded duration is primarily indicative of which of the following options?

a)

Risk tolerance

b)

Risk assessment

c)

Mean time between failures (MTBF)

d)

Mean time to repair (MTTR)

69.

A CEO receives the results of a regulatory audit demonstrating that the company is not complying with state and federal laws. What monetary penalty could directly impact the organization if sanctioned?

a)

Fines

b)

Reputational damage

c)

Loss of license

d)

Indemnification

70.

Which malicious actors are likely to show great interest in another country's energy infrastructure and have unlimited resources to carry out espionage attacks?

a)

Semi-authorized hackers

b)

Unauthorized hackers

c)

Shadow IT

d)

State actors

71.

A rapidly growing startup is trying to categorize and manage its expanding collection of assets, from laptops and servers to cloud services. This step is crucial in its attempt to strengthen the security of the business. What should be the startup's primary guiding factor in establishing its asset classification process?

a)

Organizing assets based on the department that purchased them

b)

Organizing assets based on their size and physical attributes

c)

Classifying assets based on their value, sensitivity, or criticality to the organization

d)

Classifying assets based on the purchase date

72.

A cyber team is setting up new incident response processes for the organization. As part of the incident response process, what correlates events from network and system data sources and determines where there are indicators of an incident?

a)

Eradication

b)

Detection

c)

Analysis

d)

Containment

73.

The IT department of a corporation evaluates its security mechanisms to identify areas lacking sufficient protection. Which of the following techniques should the IT department employ?

a)

Authorization models

b)

Gap analysis

c)

Zero trust

d)

Non-repudiation

74.

An international business is experiencing an increase in remote work scenarios, resulting in a significant rise in employees using personal devices and smart appliances for work. This development raises potential issues related to unauthorized network access and adherence to security standards. Which of the following solutions MOST effectively addresses these security issues?

a)

Implement agentless Network Access Control without firewall integration.

b)

Depend solely on the existing firewall for device authentication.

c)

Use Network Access Control (NAC) without employing dynamic Virtual Local Area Networks (VLANs).

d)

Deploy agent-based Network Access Control (NAC) with dynamic Virtual Local Area Networks (VLANs) and firewall integration.

75.

A company's IT team is investigating a security incident where a hacker gained unauthorized access to its server. The team suspects the attack was a buffer overflow exploit in one of the OS-based applications. The team analyzes the server logs and discovers unusual patterns in the application's behavior before the breach. Now, the team needs to implement measures to prevent such attacks in the future and enhance the application's security. What security measures can the IT team implement to mitigate buffer overflow exploits in its OS-based applications?

a)

Use firewall rules to restrict network traffic to and from the server.

b)

Enable address space layout randomization (ASLR) or data execution prevention (DEP).

c)

Regularly update the operating system and applications with the latest security patches.

d)

Implement strong password policies for user accounts accessing the applications.

76.

A large multinational company uses a cloud-based document storage system. The system provides access to documents by considering a combination of factors: the user's department, geographic location, the document's sensitivity level, and the current date and time. For example, only the finance department of a specific region can access its financial reports, and they can do so only during business hours. Which access control model does the company MOST likely use to manage this complex access control?

a)

Rule-based access controls

b)

Discretionary access control (DAC)

c)

Attribute-based access control (ABAC)

d)

Role-based access control (RBAC)

77.

Which social engineering technique involves pretending to be someone else and may use persuasive or coercive approaches to manipulate the target?

a)

Pharming

b)

Watering hole attack

c)

Impersonation

d)

Phishing

78.

An organization wants to implement a hybrid cloud strategy and understand the security implications of its responsibility matrix. What should the employees consider in this analysis?

a)

Completely relying on third-party security audits

b)

Implementing a full IaaS model, handing all infrastructure security responsibilities to the cloud provider

c)

Balancing security responsibilities between on-premises and cloud, ensuring clear definition in the responsibility matrix

d)

Choosing the cloud provider based only on pricing

79.

The cybersecurity team at a large company has recently uncovered evidence of a successful malicious cryptographic attack on their data servers facilitated by a misconfiguration in the cryptographic systems. What is the MOST appropriate initial response that the team should employ to address this critical security issue?

a)

Initiate a complete redesign of the organization's website.

b)

Switch to a new data server provider.

c)

Correct the misconfiguration and implement secure cryptographic controls.

d)

Install an advanced firewall across the entire network.

80.

Upon receiving the quarterly budget, the board decides to enhance its automation capabilities within security operations. What are the benefits tied to automation in this instance? (Select the two best options.)

a)

Continuous integration and testing

b)

Generate tickets

c)

Escalation

d)

Enabling/disabling services and accesses

81.

A user in a company wants a new USB flash drive. Rather than requesting one through the proper channel, the user obtains one from one of the company's storage closets. Upon approaching the closet door, the user notices a warning sign indicating cameras are in use. What is the control objective of the observed sign?

a)

Detective

b)

Corrective

c)

Preventive

d)

Deterrent

82.

An IT auditor is responsible for ensuring compliance with best practice frameworks. The auditor conducts a compliance scan, using the security content automation protocol (SCAP), to measure system and configuration settings against a best practice framework. Which XML Schema should the IT auditor use to develop and audit best practice configuration checklists and rules?

a)

Security content automation protocol (SCAP)

b)

Simple Network Management Protocol (SNMP)

c)

Extensible configuration checklist description format (XCCDF)

d)

Open Vulnerability and Assessment Language (OVAL)

83.

A network engineer is optimizing an existing cloud-based system. The primary goal is to ensure the system remains operational, minimizing downtime, even under adverse conditions or potential failure points. What key characteristic of system design should the engineer prioritize?

a)

Centralized

b)

Containerization

c)

Availability

d)

Scalability

84.

CloudSecure is facing a cybersecurity challenge where some of its critical software applications are no longer supported by vendors, making them vulnerable to potential exploits. The IT team is exploring various strategies to mitigate the risk posed by these unsupported apps. What’s the MOST effective approach to enhance the security posture?

a)

Implementing regular patch management to fix the faulty code.

b)

Ignoring the vulnerability as it can only be exploited in specific circumstances.

c)

Isolating the unsupported apps from other systems to reduce the attack surface.

d)

Consolidating all operating systems and applications into one product.

85.

A new department head wants all risks that affect the company systems treated the same to ensure the data is always secure. The IT department manager discusses the financial responsibility of the department to accomplish this and suggests the company follows the guidelines within approved management practices. What two practices is the IT department head referring to? (Select the two best options.)

a)

Risk tolerance

b)

Vulnerability feed

c)

Vulnerability Management

d)

Risk management

86.

In a large corporate office, employees use various devices such as laptops, smartphones, and tablets that support both Bluetooth and Wi-Fi connectivity. The office implements strict security measures to protect sensitive data and ensure compliance with industry regulations. However, the IT team noticed some security concerns. What security risks is the IT team primarily concerned about regarding the use of Bluetooth and Wi-Fi in the corporate office?

a)

Lack of connectivity

b)

Physical damage to devices

c)

Incompatibility with devices

d)

Unauthorized access and data interception

87.

A company had data for an upcoming project stolen and leaked online. The investigation implies that social engineering is the cause. Which policy can prevent such an incident from occurring?

a)

Standard operating procedure (SOP)

b)

Clean desk

c)

Fair use

d)

Non-disclosure agreement (NDA)