Font size
WorksheetsComptia Security+ Practice 2
Total questions: 87
Worksheet time: 47mins
A recently breached company tasks the cyber team to further restrict end-user permissions. What describes the use of an application allow list?
It is used in computer systems and networks to enforce policies.
It is a list of rules or entries that specify users' access.
It allows or denies an application from running.
It controls access to files, directories, or systems resources in OSs.
An organization performs a business impact analysis to identify potential effects of business interruptions. It is trying to identify the maximum acceptable time its key business process can be down before it severely impacts operations. What is the organization attempting to determine?
Annualized Rate of Occurrence (ARO)
Mean Time To Repair (MTTR)
Recovery Time Objective (RTO)
Mean Time Between Failures (MTBF)
A company using Wi-Fi Protected Access (WPA) wireless security on their wireless access points (WAPs) uses Lightweight Extensible Authentication Protocol (LEAP) to authenticate users to the network. LEAP is vulnerable to password cracking. What other options does the company have to mitigate this vulnerability? (Select the two best options.)
Protected Extensible Authentication Protocol (PEAP)
Flexible Authentication via Secure Tunneling (EAP-FAST)
RADIUS federation
EAP-MD5
A system admin is discussing the importance of prompt attention to vulnerabilities with a new IT hire. One of the MOST important things to capture about a new vulnerability is its classification. What characteristics are directly related to this? (Select the three best options.)
Nature of vulnerability
Potential impact
Scope
Type of system affected
A cybersecurity specialist in a company notes a general decrease in system performance due to resource consumption, but there is no evidence of harmful intent, and the network seems to be functional. What is MOST likely causing the decreased performance?
Virus
Bloatware
Directory traversal
Concurrent session usage
A healthcare organization is preparing to decommission several servers containing sensitive patient information. The organization wants to ensure that it securely disposes of the data on these servers and properly documents this process. What should the organization primarily focus on to ensure secure data disposal and regulation compliance?
Pass the servers to the IT team for random allocation among employees.
Sell the servers as soon as possible to reclaim some of the initial investment.
Keep the servers in storage indefinitely as a backup in case of data loss.
Obtain a certificate of destruction or sanitization from a third-party provider.
A cybersecurity specialist deals with potential system compromises that can manifest as suspicious network activity or abnormal system behavior in the organization's network. What manifestation should the cybersecurity specialist be analyzing?
Intrusion detection system (IDS) alerts
Indicators
System logs
Firewall alerts
A lab technician explores the variances regarding automation and orchestration opportunities between security operations and infrastructure management. What is a benefit of automation and orchestration in infrastructure management? (Select the three best options.)
It enforces standardized configurations to ensure consistency.
It enhances scalability and flexibility by simplifying deployment.
It enforces standardized baselines through configuration management tools.
It saves time and resources by allowing configurations to deploy quickly.
A recent attack on the company involving a threat actor from another country prompted the security team to host regular penetration testing exercises. The attack involved the IT team and human resources because the breach occurred on an employee desktop. In the upcoming training, what role would the human resource team portray along with the IT team to simulate the recent attack and its experiences?
Blue team
Red team
White team
Purple team
After encountering a cyber attack, an organization uses a monitoring solution that automatically restarts services after it has detected the system has crashed. What type of functional security control is the company implementing?
Technical
Managerial
Corrective
Compensating
A cloud storage company wants to ensure that it stores user data in the same country as the user's physical location. Which factor is the cloud storage company primarily considering here?
Data sovereignty
Geolocation
Data integrity
Data classification
A financial organization has hired a cybersecurity expert to strengthen the security of its system. The expert recommends implementing a specific technique into unreadable ciphertext by converting plaintext credit card information, regardless if it is active, in transit, or at rest. What technique should the cybersecurity expert implement?
Tokenization
Hashing
Encryption
Obfuscation
The network security manager of a large corporation is planning to improve the efficiency of the company's Security Information and Event Management (SIEM) system. The SIEM system receives data from various sources, including Windows and Linux hosts, switches, routers, and firewalls. To make the data from different sources more consistent and searchable, which functionality should the manager focus on enhancing in the SIEM system?
Enhance the agent-based collection method on the security information and event management (SIEM) system
Implement additional packet sniffers in the network
Improve the security information and event management (SIEM) system's vulnerability scanning capabilities
Refine the log aggregation process in the security information and event management (SIEM) system
The IT department at a large corporation noticed an unfamiliar software application running on its network. Upon investigation, they discovered that a team in the marketing department started using a new cloud-based project management tool to improve their workflow efficiency. The team did not consult with the IT department before implementing this tool. In the context of cybersecurity threats, what does this situation BEST exemplify?
Nation-state
Shadow IT
Careless password management
Insider threat
A financial institution is preparing to decommission a number of its old servers. The servers contain sensitive customer data that needs proper handling to prevent unauthorized access or data breaches. Which strategy should the institution primarily employ to ensure the data on these servers stays irretrievable.
Carry out a sanitization process that includes multiple passes of overwriting and degaussing.
Leave the data on the servers, as the system will eventually overwrite it.
Physically destroying the servers is necessary.
Use a basic method of overwriting, such as zero filling, once.
A healthcare organization is retiring an old database server that housed sensitive patient information. It aims to ensure that this information is completely irretrievable. What key process should the organization prioritize before disposing of this server?
Certification of the server's functionality
Preservation of all data for future reference
Repurposing of the server without any modifications
Secure destruction of all data stored on the server
Upon receiving additional funding for the new quarter, a software team leader looks to acquire new automation and orchestration tools to enhance the IT department. What is NOT considered a benefit of automation and orchestration implementation for infrastructure management?
Enhancing scalability and flexibility by simplifying deployment
Enforcing standardized configurations to ensure consistency
Saving time and resources by allowing configurations to deploy quickly
Enforcing standardized baselines through configuration management tools
An organization is experiencing an attack where the attackers break into the premises or cabinets by forcing a gateway or locks. What BEST describes the observed attack?
Collision
Brute force
Downgrade
Birthday
A systems administrator receives an alert for potential unauthorized access to sensitive data while in active memory on a server within the organization. The organization has tasked the systems administrator with enforcing stricter controls to prevent such breaches. What would be the MOST appropriate measure to implement?
Data obfuscation
Data masking
Data encryption
Permission restrictions
A mid-sized software development company recently expanded its operations and acquired many new IT assets. Which method should the company primarily consider for asset enumeration to manage these assets and maintain an accurate inventory effectively?
Implementing asset management software to automatically discover, track, and catalog various types of assets
Using network scanning tools to automatically discover and enumerate networked devices
Relying on staff members to report their assigned assets and maintain the inventory
Manually inspecting and recording information about each asset
The IT department in an accounting firm is gearing up for an external penetration testing engagement to evaluate the organization's security readiness. To guarantee a seamless testing process and prevent misunderstandings, the IT team has worked closely with the company's management and relevant stakeholders to set up the rules of engagement (ROE) for the assessment. What is the purpose of establishing rules of engagement during a penetration testing engagement?
To ensure the penetration test results are shared with external parties to strengthen collaboration
To define the scope of the assessment, testing methods, and timeframe for conducting the test
To allow penetration testers unrestricted access to all systems and data within the organization
To eliminate all security vulnerabilities identified during the testing process
A board of directors convenes a monthly meeting to discuss reports that the tech department was not meeting legal regulations. What are the impacts associated with sanctions? (Select the two best options.)
It can include financial penalties, legal liabilities, and loss of customer trust.
It can grant certain individuals with the ability to challenge credit data on their personal reports.
It can be overseen by numerous governing bodies, such as regulatory authorities.
It can result in a breach or termination of an agreement, or indemnification.
A cybersecurity team is investigating a complex cyber threat landscape for a large financial institution. The team is aware of some potential threats due to previous encounters and security measures in place, but the evolving nature of the landscape presents new threats and challenges. What type of cyber environment is the team dealing with?
Reconnaissance
Fully known environment
Unknown environment
Partially known environment
An organization's IT department wants to implement a security model responsible for verifying user identities, determining access rights, and monitoring activities within a system. Which concept is MOST appropriate for the department to implement?
AAA
Zero trust
Policy engine
RBAC
A large financial corporation is refining its information security policies to enhance its overall cybersecurity posture. The security team recognizes the need for continuous monitoring and revision of policies to adapt to the changing threat landscape. Given the scenario, which statements accurately outline the considerations for monitoring and revising information security policies in this context? (Select the two best options.)
The team should use employee feedback to identify gaps in current policies.
The team should only revise policies when a security incident occurs.
The team should regularly review policies to address emerging security threats.
The team does not need to monitor policies if there are no apparent security incidents.
When setting up a new server room for sensitive data storage, a tech company seeks to enhance preventive measures against unauthorized access. Which measure would be MOST effective for this purpose?
Intrusion detection system (IDS)
Server encryption
Physical security
Video surveillance
A company wants to improve the physical security at its headquarters. They need a solution that can help regulate access to the building and deter potential intruders during nighttime. Which physical security measure should they prioritize?
Closed-circuit television (CCTV)
Access control vestibule
Enhanced lighting
Perimeter fencing
A small business wants to enhance the security of its IT infrastructure which includes various network devices, operating systems, and applications. The business is considering a standardized approach by changing default configurations, disabling unnecessary services, applying regular patches and updates, and enforcing strong password policies. To which resource should the company refer for secure configuration BEST practices?
Latest Cyber Threat Intelligence Reports
Vendor-specific user manuals
Network Performance Analysis Reports
Center for Internet Security (CIS) Benchmarks
Which organizational policy does a cybersecurity analyst need to outline the procedures in case of a security breach or cyberattack? This policy includes steps for identifying, investigating, controlling, and mitigating the impact of incidents.
Software Development Life Cycle (SDLC)
Information security policy
Disaster recovery policy
Acceptable use policy (AUP)
A representative at a company reports receiving numerous unsolicited phone calls seeking banking information for a credit report. Which social engineering variant is the finance director experiencing?
Spear phishing
Smishing
Vishing
Vishing
A tech department receives funding to enhance the automation and scripting for IT operations to streamline processes and improve efficiency. Upon reviewing the various capabilities associated with automation and scripting, what capability provides frameworks for managing security within an organization and can monitor and enforce compliance with security policies?
Resource provisioning
Guardrail
User provisioning
Workforce multiplier
An organization is considering a hybrid cloud deployment to leverage the benefits of both private and public cloud resources. While reviewing third-party vendors, what critical aspect should the employees consider for a secure and effective transition?
Delegate all security management to the provider
Focus on data redundancy
Prioritize lowest-cost vendors
Establish clear service level agreements (SLAs)
A healthcare organization is setting up a system to store patient passwords securely. To ensure that only authorized personnel can verify the passwords and the system cannot be compromised during a breach, which technique should the organization implement?
Symmetric encryption
Asymmetric encryption
Tokenization
Hashing
A healthcare provider is digitalizing its patient data and needs a system that guarantees the preservation of its sensitive data in the event of a disaster while avoiding lock-in to a single technology vendor's platform. What is the MOST crucial practice the provider needs to implement?
Incorporating additional power generators
Maintaining regular data backups
Implementing an Uninterruptible Power Supply (UPS)
Adopting platform diversity for their digital infrastructure
A technology firm's network security specialist notices a sudden increase in unidentified activities on the firm's Security Event and Incident Management (SIEM) incident tracking system. An unknown entity or process also increases the number of reported incidents. The specialist decides to investigate these incidents. Which combination of data sources would provide a balanced perspective to support the investigation?
Logs from vulnerability assessment tools, which identify potential weaknesses; transaction logs from databases, tracking changes; and logs from mobile devices, recording device activities.
System-specific security logs, which track system-level operations; logs generated by applications running on hosts; and real-time reports from the SIEM solution, summarizing incidents.
Gateway logs, which track incoming and outgoing network traffic; network interactions monitored by intrusion detection systems (IDS), which detect unauthorized activities; and logs from server OS components.
User activity logs, which record user behaviors; daily summary reports from the SIEM solution; and high-level network overviews, providing a broad view of network activities.
An IT security analyst is conducting a risk assessment for a global corporation that recently started outsourcing its hardware production to several manufacturers overseas. The corporation is aware of the threats associated with an expanded supply chain and seeks to mitigate potential security risks linked to its hardware devices. Which of the following risk mitigation strategies should the corporation adopt to ensure the security of its hardware devices without unnecessarily hindering its operations? (Select the best two options.)
Implement strict supplier vetting processes.
Adopt a zero-trust network architecture.
Outsource all hardware production to a single trusted manufacturer.
Perform regular audits of its supplier's manufacturing processes.
A system administrator assesses a software company's security measures, paying special attention to the varied cryptographic methods used for data security. Given the potential misconfigurations that could endanger data integrity and confidentiality, the administrator seeks to lower the risk of misconfigurations within the cryptographic settings that might result in security vulnerabilities. Which actions should the system administrator prioritize to ensure properly configured cryptographic systems and prevent potential security breaches? (Select the two best options.)
Conduct periodic penetration testing.
Adopt biometric authentication.
Regularly update and patch cryptographic software.
Implement network segmentation.
The cybersecurity department of a major bank has just finished deploying a new email security tool to detect and filter potential phishing emails. To validate its effectiveness, which phase of the phishing prevention strategy should the department focus on next?
User guidance and training
Recognizing a phishing attempt
Execution phase of the prevention strategy
Establishing an anomaly-based intrusion detection system
A company is developing a system that requires instantaneous response to certain inputs. The system will incorporate into a larger device and will not have many resources. What type of system is likely to be MOST suitable for this scenario?
Linux operating system
Embedded systems
Real-time operating system
Windows operating system
The security team at a multinational cloud services company is working on their port security. They implemented basic Media Access Control (MAC) address filtering on all switch ports, but they have concerns about the risk of MAC spoofing and the management overhead of maintaining a list of valid MAC addresses. To address these concerns, they now require strong authentication before a user can obtain full network access. Which of the following measures should the team implement next?
Disable all unused switch ports.
Implement physical isolation for critical servers.
Implement EAP and RADIUS.
Segregate into multiple security zones.
Companies often update their website links to redirect users to new web pages that may feature a unique promotion or to transition to a new web experience. How would an attacker take advantage of these common operations to lead users to fake versions of the website?
Hijack the website's domain
Include a malicious attachment in the email
Ruin the companys reputation with reviews
Craft phishing links in email
A US-based financial institution is increasing security on customer-stored driver's license number data by using a method of converting the information from "123456789" to "ef7FTrR87". What type of obfuscation is the institution using to protect the driver's license information?
Data masking
Tokenization
Steganography
Salting
How do data inventories assist organizations in maintaining records of collected data?
It requires individuals or entities to announce their understanding of compliance obligations formally.
It is the comprehensive assessment and evaluation of an organization's data protection practices.
It is an established timeline that requires organizations to keep documentation.
It provides a comprehensive overview of the types of handled data.
In a medium-sized tech company, employees have different roles and responsibilities requiring access to specific resources and data. The IT team is implementing security measures to control access effectively and reduce the risk of unauthorized activities. What security measure could the IT team implement in the tech company to control access effectively and minimize the risk of unauthorized activities?
Implement a firewall to protect the company's network from external threats
The principle of least privilege, granting each employee the minimum necessary access based on job roles
Enforce mandatory password changes every month to enhance password security
Implement intrusion detection systems to monitor and identify potential security breaches
A financial organization is currently handling a document that contains sensitive customer information, including financial details and social security numbers. According to data classifications, how should the financial organization categorize this data?
Proprietary data
Restricted data
Confidential data
Trade secret data
During a cybersecurity attack, how would a threat actor use image files as a lure to target a vulnerability in a browser or document editing software?
The threat actor embeds malicious code in word processing and PDF format files to exploit vulnerabilities in document viewer or editor software.
They may use a program file with concealed exploit code, like Trojan Horse malware, to create backdoor access.
The threat actor conceals exploit code within an image file that targets a vulnerability in the browser or document editing software.
The threat actor conceals malware on a USB thumb drive or memory card and tricks employees into connecting the media to a PC, laptop, or smartphone.
A global e-commerce company faces challenges with its legacy monolithic application. The application is becoming increasingly difficult to maintain due to its intertwined components and struggles to scale quickly enough to handle sudden traffic surges during big sales events. The company has already invested in cloud technology and on-premises infrastructure but still faces scalability and manageability issues. What would MOST effectively address these challenges?
Embedded systems
Serverless infrastructure
Virtualization
Microservices
At a technology company, the IT department is finalizing an agreement with a cloud service provider to host its sensitive customer data. The IT team has actively ensured the inclusion of a Service Level Agreement (SLA) in the contract. What is the primary purpose of actively including an SLA in the contract with the cloud service provider?
To outline the intentions and expectations of parties involved in a potential partnership
To protect the confidentiality of sensitive information shared between parties
To establish clear guidelines on what information is considered confidential
To define the level of service the cloud service provider must deliver
An organization requires employees to take an annual training course to identify malicious emails. What aspects of cybersecurity BEST practices is the organization emphasizing? (Select the three best options.)
Reporting and monitoring cyber threats
Anomalous behavior recognition
Recurring training and awareness programs
Insider threat management
A cyber technician reduces a computer's attack surface by installing a cryptoprocessor that a plug-in PCIe adaptor card can remove. What type of cryptoprocessor can support this requirement?
Certificate Revocation Lists (CRL)
Hardware Security Module (HSM)
Trusted Platform Module (TPM)
Public Key Infrastructure (PKI)
A network engineer has the task of creating a remote access solution for a global enterprise. The solution should secure encrypted communication for the company’s employees worldwide and detect potential security threats in real time. Which configuration should the network engineer deploy to meet these requirements?
A VPN utilizing IKE and IPSec protocols, combined with an inline intrusion detection system (IDS)
A Software-Defined Wide Area Network (SD-WAN) with secure access service edge (SASE) implementation, supplemented by an intrusion prevention system (IPS)
A network equipped with a Next Generation Firewall (NGFW), a Web Application Firewall (WAF), and an intrusion prevention system (IPS) in tap/monitor mode
A network fortified by 802.1X port security, an Extensible Authentication Protocol (EAP), and a load balancer
As a network security administrator tasked with ensuring that only authorized devices can connect to the company's network, what would be the three MOST effective strategies to accomplish this goal? (Select the three best options.)
Place the network switches in secure server rooms and/or lockable hardware cabinets.
Physically disable the ports that unauthorized devices could potentially connect to.
Implement media access control (MAC) filtering on network ports to only permit certain MAC addresses to connect.
Use the IEEE 802.1X Port-based Network Access Control (PNAC) standard to require authentication when a host connects to a port.
Customers receive a seemingly genuine email from their trusted bank informing them that their passwords need updating. However, when authenticating, an attacker captures the customer's credentials. What kind of attack did the bank customers experience?
Whaling
SMiShing
Phishing
Vishing
A security architect at a multinational corporation designs a comprehensive security strategy to defend against advanced persistent threats (APTs). The strategy includes real-time analysis of network traffic, detection of unknown threats, correlation of events across different layers, and automatic response to mitigate risks. The architect also ensures compliance with international regulations on data privacy. Which data sources and security components combination would BEST align with this multifaceted approach?
Intrusion prevention system/intrusion detection system (IPS/IDS) logs, anomaly detection, and automated response mechanisms
Network logs, firewall logs, and operating system (OS)-specific security logs
Vulnerability scans, packet captures, and dashboards
Application logs and endpoint security
A company acquires a smaller company and has its in-house technical team review the new systems before allowing them on the existing network. During this review, the technical team discovers users with unnecessary permissions, user accounts for former employees, and no longer needed groups. These discoveries indicate the violation of what BEST practice?
Principle of least privilege
File system permissions
Configuration enforcement
Access control
In a medium-sized company, the IT department manages access to various systems and resources for employees. The team wants to enhance the security posture by implementing better access controls. They use rule-based access controls and time-of-day restrictions to achieve this goal. What are the IT department's objectives in implementing rule-based access controls and time-of-day restrictions?
To ensure all employees have access to all resources at any time for increased productivity
To restrict access to critical systems during non-working hours to enhance security
To define specific access rules based on employees' roles and responsibilities
To eliminate the need for user authentication and simplify access management
The IT department at a governmental agency is actively responsible for ensuring the security of the agency's sensitive information and physical assets. Recently, concerns have arisen about unauthorized access to certain restricted areas within the building. To address this issue, the IT team is implementing access control measures to enhance physical security. The main objective is to restrict entry to authorized personnel only and prevent unauthorized individuals from gaining access to sensitive areas. What access control measures could the IT department implement in the office building to enhance physical security and prevent unauthorized access to restricted areas?
Mandatory password changes for employee accounts
Installation of surveillance cameras throughout the building
Installation of alarms within restricted zones
Biometric authentication system using fingerprint scanning
A healthcare organization is strengthening its data protection framework to ensure compliance with local and international regulations. One focus area is clearly defining the roles and responsibilities between the data controllers and processors, as this impacts the overall management and protection of sensitive data. In this scenario, which two statements accurately outline the responsibilities of the data controller and the data processor regarding data protection? (Select the two best options.)
Data controller—determines the purposes for which data is processed
Data controller—performs day-to-day operations on data
Data processor—decides the purpose of data processing
Data processor—processes data on behalf of the controller
A multinational corporation is reviewing its data governance policies to enhance its cybersecurity posture. A data governance expert has to outline the distinct roles and responsibilities between the systems owners and the data custodians. The company is specifically interested in the functions that pertain to data confidentiality, integrity, and availability. Based on the scenario, which roles are correctly assigned to the system owner and the data custodian in order to maintain the confidentiality, integrity, and availability of data? (Select the two best options.)
System owner—performing system backups
Data custodian—enforcing access controls
System owner—implementing data classification
Data custodian—making business decisions
A company tasks a cybersecurity manager with improving the efficiency of its Security Information and Event Management (SIEM) system. The manager observes that the high number of false positive alerts causes alert fatigue among the analysts, potentially leading them to miss high-impact alerts. Which combination of strategies should the manager consider implementing to tackle this issue effectively?
Assign all infrastructure-related alerts to the incident response team and increase the frequency of system reporting
Mute all alerts to log-only status and deploy additional threat intelligence feeds in the SIEM system
Refine detection rules, redirect sudden alert "floods" to a dedicated group, and continuously monitor alert volume and analyst feedback
Increase the number of correlation rules and assign all alerts to a dedicated agent or team to remediate
An enterprise has recently suffered from a series of cyber attacks. The IT security team is considering enhancing its security by improving the intrusion detection and prevention system (IDS/IPS). Which of the following options is the MOST effective way to improve the IDS/IPS?
Disable signature updates to focus on anomaly detection only
Update the signature database frequently
Manually code all new attack signatures
Ignore alerts generated by the system
A multinational company is preparing to submit its annual statements and needs to share confidential reports with its global offices. The data includes the company's revenues, profits, and other sensitive information. What data category do these annual statements fall under?
Trade secret data
Regulated data
Human-readable data
Financial data
A company is revamping its current IT infrastructure with a focus on enhancing its ability to operate under changing or harmful conditions without suffering a significant loss of functionality. What primary aspect of the system design should the team focus on to achieve this goal?
Load balancing
Resilience
Network segmentation
Availability
A cyber security analyst notices an unusual amount of data transmitted from an employee's company computer to an unknown external IP address. The employee has all necessary permissions to access externally transferred sensitive data. What type of threat actor is MOST likely responsible for this situation?
Unskilled attacker
Nation-state
Internal threat actor
Hacktivist
Which policy outlines the processes to follow after a security breach or cyberattack occurs and includes procedures for identifying, investigating, controlling, and mitigating the impact of incidents?
Disaster recovery policy
Acceptable use policy (AUP)
Incident response policy
Change management policy
A test engineer analyzes a team's set of laptops after an outbreak of viruses and malware infections. What malware conceals itself within an installer package for software that appears to be legitimate?
Trojan
Ransomware
Worm
Spyware
A company is reviewing its policies to ensure compliance with data privacy regulations. It wants to establish a policy that outlines the appropriate use of customer data. What type of policy should the company focus on?
Disaster recovery policy
Acceptable use policy (AUP)
Data privacy policy
Information security policy
A company experiences a significant system failure that leads to service interruption. The IT department works to restore the system and documents the duration it takes to fix the problem. This recorded duration is primarily indicative of which of the following options?
Risk tolerance
Risk assessment
Mean time between failures (MTBF)
Mean time to repair (MTTR)
A CEO receives the results of a regulatory audit demonstrating that the company is not complying with state and federal laws. What monetary penalty could directly impact the organization if sanctioned?
Fines
Reputational damage
Loss of license
Indemnification
Which malicious actors are likely to show great interest in another country's energy infrastructure and have unlimited resources to carry out espionage attacks?
Semi-authorized hackers
Unauthorized hackers
Shadow IT
State actors
A rapidly growing startup is trying to categorize and manage its expanding collection of assets, from laptops and servers to cloud services. This step is crucial in its attempt to strengthen the security of the business. What should be the startup's primary guiding factor in establishing its asset classification process?
Organizing assets based on the department that purchased them
Organizing assets based on their size and physical attributes
Classifying assets based on their value, sensitivity, or criticality to the organization
Classifying assets based on the purchase date
A cyber team is setting up new incident response processes for the organization. As part of the incident response process, what correlates events from network and system data sources and determines where there are indicators of an incident?
Eradication
Detection
Analysis
Containment
The IT department of a corporation evaluates its security mechanisms to identify areas lacking sufficient protection. Which of the following techniques should the IT department employ?
Authorization models
Gap analysis
Zero trust
Non-repudiation
An international business is experiencing an increase in remote work scenarios, resulting in a significant rise in employees using personal devices and smart appliances for work. This development raises potential issues related to unauthorized network access and adherence to security standards. Which of the following solutions MOST effectively addresses these security issues?
Implement agentless Network Access Control without firewall integration.
Depend solely on the existing firewall for device authentication.
Use Network Access Control (NAC) without employing dynamic Virtual Local Area Networks (VLANs).
Deploy agent-based Network Access Control (NAC) with dynamic Virtual Local Area Networks (VLANs) and firewall integration.
A company's IT team is investigating a security incident where a hacker gained unauthorized access to its server. The team suspects the attack was a buffer overflow exploit in one of the OS-based applications. The team analyzes the server logs and discovers unusual patterns in the application's behavior before the breach. Now, the team needs to implement measures to prevent such attacks in the future and enhance the application's security. What security measures can the IT team implement to mitigate buffer overflow exploits in its OS-based applications?
Use firewall rules to restrict network traffic to and from the server.
Enable address space layout randomization (ASLR) or data execution prevention (DEP).
Regularly update the operating system and applications with the latest security patches.
Implement strong password policies for user accounts accessing the applications.
A large multinational company uses a cloud-based document storage system. The system provides access to documents by considering a combination of factors: the user's department, geographic location, the document's sensitivity level, and the current date and time. For example, only the finance department of a specific region can access its financial reports, and they can do so only during business hours. Which access control model does the company MOST likely use to manage this complex access control?
Rule-based access controls
Discretionary access control (DAC)
Attribute-based access control (ABAC)
Role-based access control (RBAC)
Which social engineering technique involves pretending to be someone else and may use persuasive or coercive approaches to manipulate the target?
Pharming
Watering hole attack
Impersonation
Phishing
An organization wants to implement a hybrid cloud strategy and understand the security implications of its responsibility matrix. What should the employees consider in this analysis?
Completely relying on third-party security audits
Implementing a full IaaS model, handing all infrastructure security responsibilities to the cloud provider
Balancing security responsibilities between on-premises and cloud, ensuring clear definition in the responsibility matrix
Choosing the cloud provider based only on pricing
The cybersecurity team at a large company has recently uncovered evidence of a successful malicious cryptographic attack on their data servers facilitated by a misconfiguration in the cryptographic systems. What is the MOST appropriate initial response that the team should employ to address this critical security issue?
Initiate a complete redesign of the organization's website.
Switch to a new data server provider.
Correct the misconfiguration and implement secure cryptographic controls.
Install an advanced firewall across the entire network.
Upon receiving the quarterly budget, the board decides to enhance its automation capabilities within security operations. What are the benefits tied to automation in this instance? (Select the two best options.)
Continuous integration and testing
Generate tickets
Escalation
Enabling/disabling services and accesses
A user in a company wants a new USB flash drive. Rather than requesting one through the proper channel, the user obtains one from one of the company's storage closets. Upon approaching the closet door, the user notices a warning sign indicating cameras are in use. What is the control objective of the observed sign?
Detective
Corrective
Preventive
Deterrent
An IT auditor is responsible for ensuring compliance with best practice frameworks. The auditor conducts a compliance scan, using the security content automation protocol (SCAP), to measure system and configuration settings against a best practice framework. Which XML Schema should the IT auditor use to develop and audit best practice configuration checklists and rules?
Security content automation protocol (SCAP)
Simple Network Management Protocol (SNMP)
Extensible configuration checklist description format (XCCDF)
Open Vulnerability and Assessment Language (OVAL)
A network engineer is optimizing an existing cloud-based system. The primary goal is to ensure the system remains operational, minimizing downtime, even under adverse conditions or potential failure points. What key characteristic of system design should the engineer prioritize?
Centralized
Containerization
Availability
Scalability
CloudSecure is facing a cybersecurity challenge where some of its critical software applications are no longer supported by vendors, making them vulnerable to potential exploits. The IT team is exploring various strategies to mitigate the risk posed by these unsupported apps. What’s the MOST effective approach to enhance the security posture?
Implementing regular patch management to fix the faulty code.
Ignoring the vulnerability as it can only be exploited in specific circumstances.
Isolating the unsupported apps from other systems to reduce the attack surface.
Consolidating all operating systems and applications into one product.
A new department head wants all risks that affect the company systems treated the same to ensure the data is always secure. The IT department manager discusses the financial responsibility of the department to accomplish this and suggests the company follows the guidelines within approved management practices. What two practices is the IT department head referring to? (Select the two best options.)
Risk tolerance
Vulnerability feed
Vulnerability Management
Risk management
In a large corporate office, employees use various devices such as laptops, smartphones, and tablets that support both Bluetooth and Wi-Fi connectivity. The office implements strict security measures to protect sensitive data and ensure compliance with industry regulations. However, the IT team noticed some security concerns. What security risks is the IT team primarily concerned about regarding the use of Bluetooth and Wi-Fi in the corporate office?
Lack of connectivity
Physical damage to devices
Incompatibility with devices
Unauthorized access and data interception
A company had data for an upcoming project stolen and leaked online. The investigation implies that social engineering is the cause. Which policy can prevent such an incident from occurring?
Standard operating procedure (SOP)
Clean desk
Fair use
Non-disclosure agreement (NDA)
