Font size
WorksheetsThreats & Preventative Measures (I01-I04)
Total questions: 138
Worksheet time: 1hrs 27mins
A small firm uses admin/admin on a router and has no password policy. What is the most effective first step to reduce risk, while planning for layered controls?
Time limit: 1 minute
Install an enterprise password manager
Enable MFA for all accounts immediately
Deploy SIEM to monitor failed logins
Implement a 15+ character password policy
You are designing access for staff and visitors who share one subnet with guest Wi‑Fi. Which strategic change best isolates traffic while keeping manageability?
Time limit: 1 minute
Segment using VLANs with ACLs between segments
Create separate physical networks for each group
Install antivirus on all endpoints
Increase password complexity requirements
A school has OneDrive-only backups and no offsite copy. Which plan most directly meets the 3-2-1 backup principle?
Time Limit: 1 minute
Two cloud copies and weekly local copy
Three copies, two different media, one offsite
One cloud copy and daily local snapshots
One local copy and one offsite tape
Login attempts show unlimited retries without rate limiting. What policy choice creates both deterrence and monitoring value? Time limit: 1 minute
Disable guest Wi‑Fi during work hours
Require BitLocker on laptops
Increase password expiration frequency
Lockout after five failures with SIEM alerts
A nonprofit with limited technical skill wants to strengthen authentication quickly. Which layered approach balances cost and impact?
Time Limit: 1 minute
Password manager without policy changes
Password policy plus MFA for all users
MFA only for IT administrators
Firewall ACLs between existing VLANs
BYOD devices must not access internal finance systems on the same switch. Which plan uses realistic controls to enforce this?
Time limit: 1 minute
Use SIEM to watch BYOD connections
Apply VLAN separation and firewall rules
Enable antivirus on finance PCs
Raise password length to 20 characters
Ransomware risk analysis shows manual backups on a single external drive. Which step most improves business continuity?
You have 1 minute to answer this question.
Adopt account lockout on all services
Increase password complexity to 18 characters
Upgrade to premium antivirus software
Switch to immutable or air‑gapped backups
A helpdesk receives tickets about default credentials found on IoT cameras. Which trigger word signals a needed solution area for these devices?
Time limit: 1 minute
Password strength
Network separation
Disaster recovery
Endpoint protection
You must reduce lateral movement between staff PCs and visitor devices. What planning choice sets the foundation before adding firewall policies?
Time limit for this question: 1 minute
Create SIEM correlation rules
Implement VLAN tagging (802.1Q)
Deploy application whitelisting
Enable Windows Defender
A team disables antivirus due to budget constraints and old equipment. What low‑cost measure restores baseline protection?
Time limit for this question: 1 minute.
Apply BitLocker on portable laptops
Implement EDR across all endpoints
Install Microsoft Defender (built‑in)
Use account lockout after failed logins
A laptop with sensitive data is often used offsite. You have 1 minute to answer: Which measure directly protects data at rest if the device is lost?
Place the laptop on a separate VLAN
Install SIEM agent on the laptop
Increase password length to 20 characters
Enable BitLocker full‑disk encryption
While drafting policy, you need a tertiary measure for weak passwords beyond policy and MFA. Which option fits as an additional safeguard?
Time Limit: 1 minute
Firewall ACLs between VLANs
Password manager adoption
BitLocker full‑disk encryption
SIEM alerts for failed logins
A startup wants to implement segmentation but lacks deep networking skills. Which statement best represents realistic difficulty and cost?
Time limit: 1 minute
Easy and free with built‑in policies
Medium difficulty, no hardware cost
Hard and requires networking knowledge
Very hard and requires custom software
During an audit, you see repeated failed logins. Which combined action improves both security and incident visibility?
Time limit for this question is now 1 minute.
Increase password length only
Move finance systems to a new VLAN only
Enable account lockout with SIEM alerts
Install antivirus on all servers
Leadership asks for a concise MFA benefit when paired with strong passwords. Which impact should you emphasize?
Time Limit: 1 minute
Eliminates the need for backups entirely
Stops all phishing attempts completely
Prevents network segmentation requirements
Reduces risk from stolen credentials
You must write requirements for backups after a ransomware incident. Which wording most clearly indicates the needed strategy?
Time limit: 1 minute
Single cloud backup copy only
Automated 3‑2‑1 with offsite media
Manual nightly local copy
Weekly snapshot on the same disk
An organization with guest Wi‑Fi wants to prevent guests from reaching admin interfaces. Which design sequence is most robust?
Time limit for this question: 1 minute.
BitLocker first, then EDR rollout
VLAN separation, then firewall ACLs
Password policy, then SIEM alerts
Account lockout, then antivirus
A security plan mandates lockout after five failed attempts. You now have 1 minute to answer. What complementary control adds detection for brute force campaigns?
Deploy VLANs across all departments
Increase password expiration frequency
Enable SIEM alerts on repeated failures
Implement BitLocker on endpoints
You are prioritizing internal controls for a small business with limited budget. Which layered set best addresses common internal threats quickly?
Time limit: 1 minute
Backups only using 3‑2‑1
Antivirus alone on all devices
Password policy and MFA together
VLANs only across all networks
A company stores sensitive files on laptops used by sales staff who travel frequently. Which mitigation best protects those files if a laptop is stolen?
Time limit: 1 minute
Full‑disk encryption with BitLocker enabled
Per‑file passwords set by users
Local firewall with strict outbound rules
Hidden folders and renamed file extensions
You must recommend an open‑source alternative to BitLocker for encrypting data at rest on Windows. Which choice aligns with that requirement?
Time limit: 1 minute
Windows EFS for selected directories
WinZip with strong archive passwords
VeraCrypt implementing file‑level encryption
TLS certificates installed on devices
An organization issues USB drives to staff for offline backups. What is the most appropriate control to reduce data‑at‑rest theft from lost USBs?
Time limit: 1 minute
Disabling USB ports on all desktops
Weekly antivirus scans on the drives
Labeling drives with owner names
Hardware‑encrypted USB drives with PIN
A small IT team suspects intrusions go unnoticed because logs are scattered and never reviewed. Which solution creates centralized detection with alerting?
You have 1 minute to answer this question.
Remove guest Wi‑Fi to reduce noise
Increase password complexity policy
Deploy a SIEM platform for log analysis
Add more admin accounts for faster response
Finance must keep an audit trail of access to payment systems. Which principle most directly limits insider abuse while preserving accountability?
Time Limit: 1 minute
Least privilege with role‑based access
Daily password rotation for all users
Shared admin credentials for efficiency
Unlimited access with post‑incident audits
A startup runs all services on one server without redundancy. Which term best describes the risk and its primary mitigation?
Time Limit: 1 minute
Vendor lock‑in; use open standards
Cold site recovery; schedule backups
Network congestion; increase bandwidth
Single point of failure; add failover
A branch office relies on a single ISP link for critical operations. Which practical step improves availability during outages?
Time limit for this question: 1 minute
Block all social media to save bandwidth
Switch all devices to static IP addresses
Raise firewall default logging level
Install a 4G router for backup connectivity
During a power cut, the file server shut down abruptly and corrupted a database. Which control best prevents this impact?
Time limit for this question: 1 minute
Deploy an uninterruptible power supply
Replace spinning disks with SSDs
Disable automatic OS updates
Increase antivirus scan frequency
Security needs detection coverage without large license fees. Which stack fits an open‑source SIEM approach?
Time limit: 1 minute
Splunk Enterprise with premium apps
Graylog with Wazuh for alerts
Commercial IDS appliance only
Microsoft Sentinel with Azure AD
To strengthen network‑level intrusion discovery, which tools align with free network IDS capability?
Time limit: 1 minute
Remote desktop gateway service
FTP server for log archiving
NTP servers for time sync
Snort or Suricata as sensors
An employee threatens to leak data during a dispute. Which combination best reduces risk of malicious insider exfiltration?
Time limit: 1 minute
DLP monitoring with least privilege
Allow personal email for large files
Open file shares with faster access
Disable SIEM to improve performance
A team frequently makes mistakes in complex manual deployments. What strategic change reduces error rates while preserving oversight?
Time Limit: 1 minute
Process automation with change approval
Longer passwords for all staff
More shared admin accounts
Quarterly social events for morale
Visitors connect phones and laptops to office Wi‑Fi, occasionally spreading malware. Which control enforces device checks before access?
Time limit for this question: 1 minute
Open SSID bridged to internal VLAN
RDP access for all guests
Default allow rules on core switch
Network Access Control with captive portal
Guest devices should be isolated from internal systems yet still browse the web. What network design supports this?
Time Limit: 1 minute
Separate guest VLAN with limited access
Single flat network with DHCP
Air‑gapped internal Wi‑Fi only
Proxy all traffic through admin LAN
Before allowing BYOD laptops onto Wi‑Fi, the company wants assurance they have basic protections. Which control fits this need?
Time Limit: 1 minute
Force WPA2‑PSK for all internal users
Mandatory local admin rights enabled
Disable Windows Defender updates
Device posture check for antivirus status
Email staff often click suspicious links. What program most effectively builds resilience against phishing?
Time limit for this question: 1 minute
Using only plaintext email formatting
Blocking all external emails entirely
Weekly password changes enforced globally
Security awareness training with simulations
Endpoint security needs continuous monitoring and response to modern threats. Which capability directly provides this?
Time limit: 1 minute
Standalone antivirus with no telemetry
Static firewall rules without updates
Periodic manual log reviews monthly
Endpoint Detection and Response agents
For data at rest on Windows Pro devices, which built‑in feature enables disk encryption integrated with TPM?
Time limit: 1 minute
BitLocker full‑disk encryption
Windows Hello biometrics only
Group Policy password policies
SMB signing on file shares
Security wants better detection fidelity by correlating events across devices and networks in near‑real time. Which platform type fulfills this?
Time limit: 1 minute
Load balancer distributing traffic
Backup software running nightly
DNS server with caching enabled
SIEM collecting and analyzing logs
A company aims to survive a core router failure without major downtime. Which design principle guides a robust solution?
Time limit: 1 minute
Default deny for outbound traffic
Strict VLAN segmentation only
Redundancy with automatic failover
Manual reboot procedures documented
A contractor plugs an unknown USB drive into a workstation. Which control best prevents data exfiltration while still allowing file receipt in a highly regulated lab?
Time Limit: 1 minute
Antivirus scans on USB insertion for malware
Manual user checks of files after copy
USB data diodes enabling one-way data transfer
Group Policy allowing any USB mass storage
An office has valuable equipment in a remote, unsupervised area with no locks or cameras. Which layered plan most effectively reduces unauthorized physical access?
Time Limit: 1 minute
Deploy CCTV with NVR, then burglar alarm, then locks
Hide equipment and use visitor sign-in sheets only
Install biometric locks only on the main door
Add keypad locks and remove all windows
A school uses guest Wi‑Fi with WPA or WEP and a default SSID/password. Which strategic upgrade best strengthens authentication and isolation for staff devices?
Change SSID name and rotate password weekly
Adopt WPA3‑Enterprise with 802.1X RADIUS
Create a single VLAN for all wireless clients
Enable hidden SSID with MAC filtering
Students frequently install personal apps on BYOD laptops connected to campus resources. Which approach best enforces least privilege and approved software use?
Time limit: 1 minute
Grant local admin rights for easier installs
Block all internet access from BYOD devices
Use AppLocker or equivalent whitelist with PAM
Rely on an honor code for responsible installs
Staff rely on personal Dropbox and Gmail for work file sharing. Which plan balances usability and data governance?
Time limit: 1 minute
Permit any cloud app if users encrypt files
Ban all cloud services and allow USB transfers
Use DLP only without any user guidance
Publish an approved SaaS list and enforce via CASB
Phishing emails bypass basic filters. Which sequenced measures reduce successful credential theft and fraud?
Time Limit: 1 minute
Install CCTV to monitor email usage visually
Enable guest VLAN isolation only
Run simulations, deploy an email gateway, enable DMARC/SPF/DKIM
Rely on hidden SSID and MAC filtering
A company wants to allow guests on Wi‑Fi without risking internal systems. What is the most effective network segmentation strategy?
Time Limit: 1 minute
Isolate guest network on a separate VLAN
Use one SSID for guests and staff together
Allow guests with strong password rotation
Hide the guest SSID from scans
Which statement best captures the Principle of Least Privilege in managing admin rights on endpoints?
Time Limit: 1 minute
Disable all privileges including basic functions
Grant rights temporarily and keep them afterward
Assign minimal rights needed for tasks via PAM
Users should have full control for productivity
A lab needs to whitelist only approved software while maintaining an inventory. What paired controls achieve this?
Time Limit: 1 minute
AppLocker policies plus application approval process
Group Policy to allow any app installation
Hidden SSID combined with MAC address filtering
CCTV monitoring combined with biometric locks
An organization must detect and block unapproved cloud uploads from campus networks. Which monitoring choice is most appropriate?
Visitor management logs at reception
RADIUS authentication on Wi‑Fi only
Network monitoring integrated with CASB enforcement
Antivirus scheduled scans on endpoints
Which prioritized sequence best reflects a defense-in-depth approach to USB malware risk?
Time limit: 1 minute
Encrypt all USB drives without whitelisting
Run AV scans only and disable whitelisting
Whitelist allowed USB storage, then AV scans, then consider data diodes
Permit any USB devices to improve flexibility
A school plans CCTV with an NVR retaining 30 days of footage. You have 1 minute to answer: Which reasoning best justifies this over alarms alone?
Alarms stop all insider threats without recordings
CCTV eliminates the need for locks entirely
Alarms are always cheaper than cameras and better
CCTV provides visual evidence and deterrence for investigations
For WPA3‑Enterprise authentication, what backend service is typically required to validate user credentials?
Time Limit: 1 minute
NVR video retention server
802.1X RADIUS authentication server
DMARC DNS text records
CASB proxy for SaaS apps
A team wants to prevent shadow IT while enabling needed tools. Which plan demonstrates strategic governance?
Time limit: 1 minute
Ban all SaaS and require local file shares
Use MAC filtering to block unknown devices
Allow any app but monitor with antivirus only
Acceptable Use Policy with an approved tools list, CASB enforcement, and DLP
Which control best mitigates unauthorized application installations on Windows endpoints?
Time limit: 1 minute
Visitor sign‑in with badges
AppLocker rule set with software inventory
Biometric door locks at the lab
Hidden SSID and guest VLAN
Why is relying on MAC filtering and hidden SSIDs insufficient for Wi‑Fi security in a school?
Time limit: 1 minute
They require expensive licenses only
They replace the need for RADIUS servers
They do not provide strong authentication or encryption
They prevent all guest access completely
A policy states: remove local admin rights, then whitelist apps, then approve new tools via catalog. What threat is this strategy primarily addressing?
Time Limit: 1 minute
Phishing through email attachments
Physical access by visitors after hours
Unauthorized software installation and misuse
Weak Wi‑Fi encryption and SSIDs
Which measure complements burglar alarms to strengthen physical security for sensitive areas?
Time limit: 1 minute
Group Policy allowing all USB devices
DMARC records for email authentication
Guest VLAN isolation on Wi‑Fi
CCTV with NVR plus biometric or keypad locks
A district wants to reduce phishing success while quantifying training outcomes. Which method provides actionable feedback?
Time limit: 1 minute
Random password changes every month
Security awareness training with phishing simulations
Blocking all external emails permanently
Moving staff to guest Wi‑Fi networks
A school uses legacy servers with updates disabled. Plan a layered mitigation that balances cost and effort while reducing exploit risk over six months.
Time limit: 1 minute
Run full Nessus weekly, ignore Windows Update
Enable auto updates, then quarterly WSUS rollout
Migrate to new hardware without patching plan
Disable services and postpone updates indefinitely
An SME has no SIEM and incidents are discovered late. Which plan best improves forensic readiness while controlling cost?
You have 1 minute to answer this question.
Disable application logs, rely on antivirus alerts only
Keep local logs, increase disk space, review annually
Enable Windows logs, centralize to Graylog, 90‑day retention
Deploy premium SIEM, skip log forwarding, short retention
Users all have local admin rights. Which staged approach reduces risk while maintaining productivity for developers?
Time limit: 1 minute
Create standard accounts, separate admin, add JIT elevation
Remove all admin rights, deny elevation permanently
Move developers to PAWs, no process changes
Keep admin rights, add password complexity only
Your patch budget is nearly zero. Which practical sequence strengthens security fastest?
Time limit: 1 minute
Turn on automatic Windows Update, schedule WSUS later
Buy EDR first, delay operating system updates
Implement vulnerability scans, ignore patch results
Replace legacy apps, keep current patch state
A hospital worries about ransomware. Design a defense that remains effective if endpoints are encrypted.
Time limit: 1 minute
Offline backups using 3‑2‑1 plus tested restores
Full‑disk encryption of all endpoints only
Email filtering alone for suspicious attachments
Real‑time AV signatures without backup strategy
You must justify purchasing Nessus Professional. Which outcome makes it a secondary control after enabling auto update?
Time Limit: 1 minute
Replace Graylog as centralized log collector
Block brute force attempts at the firewall
Provide offline backup storage automation
Identify missing patches and misconfigs regularly
A company has external RDP exposed and weak passwords. Propose an order of controls to reduce account takeover risk.
You have 1 minute to answer this question.
Permit guest accounts, monitor failed logins
Deploy EDR, ignore authentication hardening
Increase password length, leave RDP open to internet
Enable MFA, set lockout policy, restrict to VPN/IP whitelist
Executives ask for a minimal‑cost logging plan that still supports incident triage within 90 days. You have 1 minute to answer this question. What do you recommend?
Forward Windows Event logs to Graylog with 90‑day retention
Use a cloud SIEM without retention or parsing
Store logs locally and delete weekly to save space
Collect only security logs, ignore system/application
Your org has shadow IT: unsanctioned cloud apps. Which control aligns visibility and policy enforcement across SaaS use?
Time Limit: 1 minute
Mandate weekly password changes
Rely on endpoint AV signatures only
Block all internet traffic by default
Deploy a CASB for discovery and control
A university must choose between WSUS and Intune for centralized patching. Which reasoning supports either option?
Time limit: 1 minute
Both provide centralized Windows patch orchestration
Only WSUS can patch endpoints off campus
Intune replaces backups for ransomware
Neither supports scheduling update windows
Security wants least privilege but admins resist. What argument best supports JIT elevation?
You have 1 minute to answer this question.
Eliminates need for service accounts everywhere
Grants permanent admin access for convenience
Provides time‑bound admin rights reducing standing risk
Replaces MFA across all privileged operations
You analyze a brute force pattern: five failed logins per user in bursts. Which policy change most directly limits success if the account is locked out for 1 minute after 5 failed attempts?
Account lockout after 5 attempts for 1 minute
Disable password complexity requirements
Allow unlimited attempts to improve usability
Rotate usernames monthly without lockout
During ransomware containment, email gateways begin flagging suspicious attachments. How should this be positioned in the defense?
Time limit for this question: 1 minute.
Tertiary filter behind backups and EDR behavior
Primary control replacing offline backups
Sole measure making endpoints immune
Quaternary control removing need for MFA
Budgeting for ransomware defenses, which cost‑effective combo delivers resilience and detection?
Time limit: 1 minute
Password rotation every 30 days without backups
Offline backups plus EDR with behavioral detection
Premium SIEM only with monthly reviews
IP whitelisting alone for all services
A team proposes PAWs for admins. What strategic benefit justifies them beyond standard accounts and JIT?
Time limit for this question: 1 minute
Reduce exposure by isolating privileged operations
Replace CASB for SaaS access control
Offer faster internet browsing for admins
Eliminate need for patching privileged hosts
Logs exist but are never reviewed. You have 1 minute to answer this question: Which change increases detection speed without major spend?
Forward to centralized SIEM and create basic alerts
Disable system logs to reduce noise
Only review after incidents are public
Keep logs local and archive quarterly
A small business wonders if EDR can replace backups for ransomware. What is the sound plan?
Disable backups, enable Windows Defender CFA
Rely on AV signatures, avoid behavior rules
Adopt EDR only, skip backups entirely
Use EDR as secondary, keep offline 3‑2‑1 backups
After enabling MFA, lockouts rise. Which tuning maintains protection while reducing disruptions?
Time limit for this question: 1 minute.
Disable lockout policy to reduce helpdesk
Whitelist all internet IPs to allow access
Remove MFA, trust passwords again
Keep MFA, adjust lockout thresholds and IP whitelist
To address unpatched systems where updates were disabled, which governance step sustains progress long term?
Time limit: 1 minute
Ignore legacy systems until replacement
Rely on ad‑hoc manual updates by users
Disable auto updates to avoid reboots
Define update schedules and compliance reporting
Which set maps internal threats to matching mitigations for a quick‑win roadmap?
Time limit: 1 minute
Unpatched→hardware refresh; No logging→annual review; Excess privilege→passwords
Unpatched→email filters; No logging→local storage; Excess privilege→guest admin
Unpatched→EDR only; No logging→disable logs; Excess privilege→keep admin
Unpatched→auto updates; No logging→central SIEM; Excess privilege→JIT
An organization sees a rise in phishing emails despite running simulations. You have 1 minute to answer: Which strategic change most directly reduces successful spoofing of your domain when mail is forwarded by partners?
Enable basic spam filters on user inboxes
Publish SPF records without DMARC policy alignment
Implement DMARC with DKIM signing and monitoring
Rely on employee reporting via a shared mailbox
You’re planning controls for credential stuffing against a public login portal. Given limited developer time, which layered plan balances quick impact and longer-term resilience?
You have 1 minute to answer this question.
Implement input validation on usernames, then add WAF rules
Add MFA for all external accounts, then enable breached password checks
Deploy rate limiting only for failed logins
Roll out CAPTCHA everywhere, then remove password complexity
A charity uses an email gateway but still suffers phishing. What sequencing best raises protection while controlling cost and complexity?
Time limit: 1 minute
Replace gateway with user training courses
Buy advanced sandboxing before training users
Disable gateway, rely on fail2ban for SMTP
Keep gateway, add DMARC with DKIM, continue simulations
During a DDoS attack on an e‑commerce site, what immediate, evidence‑based action most likely restores availability with minimal internal changes?
You have 1 minute to answer this question.
Rewrite backend database queries for efficiency
Enable strict CSP headers on all pages
Route traffic through a CDN with DDoS protection like Cloudflare
Switch hosting provider mid‑attack
Your team must mitigate SQL injection in custom forms. With limited budget but strong developer skills, what plan addresses root cause and auditability?
Time limit: 1 minute
Encode output and trust client‑side validation
Block risky IPs via WAF only, no code changes
Use parameterized queries throughout, then schedule a pen‑test
Sanitize input using ad‑hoc string replacement
A forum suffers Cross‑Site Scripting via comment fields. Which two‑step approach most directly prevents execution and reduces future exposure?
Time limit for this question: 1 minute.
Validate user names only, then rate limit posts
Strip all text containing angle brackets, then add WAF
Escape output on render, then enforce a restrictive CSP
Whitelist allowed HTML and disable JavaScript globally
You’re tasked to justify spending on Cloudflare Pro for a critical booking site. What evidence‑based rationale best supports the purchase?
Time limit: 1 minute
It eliminates SQL injection risks without code changes
It replaces the need for MFA on staff accounts
It provides traffic scrubbing and stronger DDoS mitigation features
It blocks all malware from user devices
A business has no MFA and reuses passwords across services. Which control sequence most effectively reduces account takeover from credential stuffing?
Time limit: 1 minute
Deploy CSP headers, then enforce output encoding
Implement MFA on all external accounts, then add breached password detection
Enable CAPTCHA first, then consider MFA next year
Increase password length policy, then remove lockouts
Email spoofing bypasses basic filters. You have 1 minute to answer: What configuration change provides domain‑level enforcement against unauthenticated senders?
Disable DKIM to reduce complexity
Set DMARC policy to reject with aligned DKIM
Publish a permissive SPF include for all clouds
Move mail to on‑prem servers with fail2ban only
A login endpoint suffers bot traffic causing lockouts. Which plan balances usability and defense with measurable thresholds?
Time limit for this question is 1 minute.
Block all traffic from foreign countries
Require password changes weekly for all users
Apply rate limiting to a small max attempts per IP, plus CAPTCHA on spikes
Allow unlimited attempts to avoid support tickets
Security wants to rely only on WAF to stop SQL injection. What is the strongest counter‑argument grounded in risk and maintainability?
Time limit: 1 minute
Pen‑testing removes the need for development fixes
Parameterized queries address the vulnerability at code level
WAF is free and perfect at blocking attacks
Client‑side validation is sufficient for trusted users
A social app needs to support user‑generated content safely. You have 1 minute to answer: Which combined measures reduce XSS without breaking features?
Encode database inputs, skip output encoding
Escape dynamic content on output and enforce CSP headers
Disable all forms and comments globally
Use client‑side filters only for script tags
Your incident plan must include post‑phishing resilience. Which metric‑driven approach improves outcomes over time?
Time limit for this question: 1 minute
Stop simulations to avoid user fatigue
Run regular phishing simulations tied to training and measure click rates
Block all external emails by default
Forward suspicious emails to IT without user training
For a legacy site under DDoS, DNS change is acceptable but code changes are not. What step aligns with constraints and offers defense in depth?
Time limit: 1 minute
Deploy parameterized queries everywhere
Add DMARC to outbound email
Rewrite application to use web sockets
Implement Cloudflare free tier, then consider Pro for advanced mitigation
Developers propose input validation lists to stop SQL injection. What refinement makes the plan robust against bypass techniques?
You have 1 minute to answer this question.
Trust blacklists of dangerous characters
Use server‑side parameterized statements with bound variables
Encode output instead of validating inputs
Allow client‑side JavaScript validation only
Which coordinated actions most reduce XSS risk while maintaining developer velocity on a comments feature?
Time limit: 1 minute
Enable CSP report‑only without other changes
Escape HTML/JavaScript on render and sanitize inputs server‑side
Strip all user content including emojis and links
Rely solely on WAF signatures for script detection
A company wants to minimize email attack surface quickly with low complexity. Which prioritized set is most appropriate?
Time limit: 1 minute
Rely on employee vigilance only, remove simulations
Replace gateway with on‑prem SMTP, disable DKIM
Enable DMARC and DKIM, keep existing gateway, continue awareness training
Use CSP headers on newsletters to block phishing
Which plan best integrates WAF into broader application security for injection and XSS risks?
Time limit: 1 minute
Use WAF alone for all protection layers
Treat WAF as tertiary defense after code fixes and validation
Disable parameterized queries to avoid duplication
Run WAF only during business hours to save cost
You’re evaluating costs for mitigating SQL injection across a portfolio. Which option reflects realistic investment and capability needs?
Time limit for this question: 1 minute
Parameterized queries plus scheduled pen‑tests, requiring developer skill
Only output encoding, no developer involvement
CAPTCHA and rate limiting on login pages
Zero‑cost fixes by interns over a weekend
A critical service must resist automated login abuse and maintain user experience. Which strategy balances defense and friction using evidence?
You have 1 minute to answer this question.
Force MFA on every page view
Use CSP to restrict scripts at login
Combine MFA for external accounts, breached password detection, and IP‑based rate limits
Block sign‑ins from unfamiliar browsers entirely
A company forces browsers to use HTTPS and refuses HTTP fallback. Which measure best ensures this behavior on the web?
Time limit: 1 minute
DNSSEC zone signing policy
HSTS header enforcing HTTPS
VPN split-tunneling config
TLS session resumption headers only
Remote employees often use public Wi‑Fi at cafes. Which strategic pairing mitigates man‑in‑the‑middle risk when full certificate pinning is not feasible?
Time Limit: 1 minute
Local firewall and IDS only
Password rotation weekly
VPN for all remote access
Endpoint AV plus ad‑blocker
A mobile app needs to prevent rogue certificates during TLS connections. What approach most directly addresses this?
Time limit: 1 minute
DNSSEC validating resolvers
Certificate pinning in the app
HSTS with preload lists
Registry lock at registrar
Which ordered plan best reduces MITM risk for a small firm, considering effort and impact?
Time limit: 1 minute
Buy WAF first, block ads, rotate passwords
Turn on IDS, enforce MFA, change domains
Enable HSTS, deploy VPN, educate staff
Enable DNSSEC, add SBOM, patch monthly
To lower supply chain risk from third‑party software, which policy is most effective at the point of acquisition?
Time limit for this question: 1 minute.
Disable HTTPS to speed downloads
Avoid code signing verification
Use public Wi‑Fi for quick access
Download only from official vendors
Security wants visibility into dependencies inside delivered software packages. Which artifact supports this?
Time limit: 1 minute
Browser ad‑block rules
VPN connection profile
DNSSEC DS record set
Software Bill of Materials list
Which strategic sequence strengthens vendor assurance for outsourced IT services?
Time limit: 1 minute
Run EDR first, then patch monthly
Use vendor risk questionnaires
Enable ad‑blockers enterprise‑wide
Change registrar at quarter end
Your organization suspects a zero‑day in a web app but cannot patch immediately. Which control buys time by filtering exploit traffic?
Time limit: 1 minute
Registry lock with MFA
Certificate pinning feature
DNSSEC on all zones
Virtual patching via WAF/IPS
To prepare for urgent zero‑day fixes, what proactive subscription is most useful for rapid response?
Browser ad network feeds
Public Wi‑Fi hotspot alerts
General tech newsletters
Vendor security bulletins
Endpoint protection should stop common exploit techniques before patching occurs. Which capability aligns with this?
Time limit for this question: 1 minute
Basic antivirus only
EDR with exploit protection
DNSSEC resolvers
Ad‑blocker on browsers
You need to validate DNS answers cryptographically to prevent spoofing. What mechanism provides this?
Time limit: 1 minute
Certificate pinning policy
HSTS preload lists
DNSSEC with validation
VPN client configuration
A domain keeps getting unauthorized nameserver changes. What registrar‑level control reduces this?
You have 1 minute to answer this question.
Use virtual patching WAF
Enable browser ad‑blocker
Registry lock on the domain
Turn off HTTPS headers
Which detection step helps discover unexpected DNS zone edits promptly?
Time limit for this question: 1 minute
SBOM periodic review
Monthly password changes
DNS monitoring alerts
Ad‑blocking on endpoints
To protect registrar accounts from takeover, what access control is most appropriate?
Time limit for this question: 1 minute
VPN split tunnel only
HSTS with strict mode
MFA on registrar account
EDR network containment
Employees see malicious ads delivering drive‑by scripts. What immediate workstation control reduces risk?
Time limit: 1 minute
Enable SBOM publishing
Registry lock at registrar
Disable HTTPS on sites
Browser ad‑block extension
A school wants network‑level ad blocking without managing every browser. Which solution fits?
Time Limit: 1 minute
Vendor questionnaires
DNS‑based ad blocking
Local HSTS policies
Certificate pinning per app
During a critical zero‑day, what planned environment helps safely test updates before deployment?
Time Limit: 1 minute
Air‑gapped testing setup
Open registrar account
Public Wi‑Fi staging
Live production trial
Which pair correctly matches threat and primary countermeasure?
Time limit: 1 minute
DNS hijacking—enable DNSSEC
MITM—enable registry lock
Supply chain—use ad‑blocker
Zero‑day—disable TLS
A startup must balance cost and effort securing remote access. Which statement reflects realistic planning?
Time limit: 1 minute
Set up VPN server costs £0–500
DNSSEC costs £500 monthly
Ad‑blocking requires new ISP
SBOM requires new hardware
Which strategic combination exemplifies defense‑in‑depth against zero‑day web exploits?
Time limit: 1 minute
Pin certificates everywhere, ignore patches
Enable DNSSEC, registry lock, ad‑block only
Disable HTTPS, use public Wi‑Fi, trust ads
Patch fast, deploy EDR, add WAF rules
A mid-size firm wants to cut drive-by malware from industry news sites without blocking all browsing. Which preventative stack best reduces risk while keeping usability?
Time Limit: 1 minute
Primary web filtering plus browser isolation layered
Adding banner warnings to all external emails
Only disabling JavaScript on all external sites
Relying on auto-update of browsers alone
Finance receives an urgent wire request appearing from the CEO. You now have 1 minute to respond. Which immediate action most effectively prevents Business Email Compromise loss?
Execute transfer within policy time window
Verify via dual-approval with out-of-band call
Forward email to IT for later DMARC check
Reply asking the sender to confirm by email
Your security plan must address predictable user behavior at industry-specific portals. Which evidence-backed control combination strengthens resilience?
Time limit for this question: 1 minute
Deploy IDS and threat intel feeds together
Train users to avoid all external websites
Disable all browser extensions organization-wide
Mandate VPN for all browsing sessions
Budget allows £0–2,000 per year for commercial threat intelligence. Which planning choice best uses this budget to reduce watering-hole risk?
Time limit: 1 minute
Hire marketing to rewrite external banners
Purchase new laptops with faster CPUs
Subscribe to threat feeds updating blocklists
Buy DLP software and restrict sales data
To protect large payments, which policy redesign offers both low cost and high impact?
Time Limit: 1 minute
Enable DMARC quarantine without training
Implement mandatory browser isolation for finance
Deploy endpoint DLP across all departments
Dual-approval with voice verification on transfers
An email spoofs a trusted partner domain. Which control directly rejects spoofed messages at the gateway?
Time limit: 1 minute
Access controls limiting finance inboxes
User training on suspicious senders
Threat intelligence domain blocklists
DMARC enforcement policy on inbound mail
Compliance wants a measurable way to harden browsers against watering-hole sites. Which plan is most defensible?
Time limit: 1 minute
Disable JavaScript only for untrusted domains
Block all downloads organization-wide
Force TOR for external web access
Remove Chrome and use legacy IE
Executives demand quick browsing with minimal phishing exposure. Which layered approach balances speed and safety?
Time limit: 1 minute
Remote browser isolation plus web filtering
Company-wide email banners only
Quarterly awareness training alone
Upgrade Wi-Fi with stronger encryption
Sales data must be protected from competitor espionage. Which access design most limits exposure while preserving operations?
Time limit: 1 minute
Only sales team sees customer lists
Everyone in company views CRM exports
Marketing shares full lists with partners
Finance team owns all prospect records
A startup lacks formal agreements with contractors handling proprietary designs. Which step offers the strongest immediate legal protection?
Block social media on office Wi‑Fi
Purchase IDS for internal network
Enable DMARC reject for outbound mail
Implement Non-Disclosure Agreements with contractors
Which control specifically aims to prevent data exfiltration to competitors from endpoints?
Time limit for this question: 1 minute
Email banners on external messages
Threat intelligence blocklist updates
Dual-approval for large wire payments
DLP software deployment organization-wide
A firm wants to reduce the implementation difficulty of BEC protections while maintaining effectiveness. Which plan fits?
Time limit: 1 minute
Deploy enterprise DLP across departments
Replace email with internal chat only
Mandate browser isolation for all users
Adopt dual-approval and DMARC gradually
Security proposes remote browser rendering for risky sites. Which outcome does this most directly achieve?
Eliminates need for web filtering policies
Guarantees zero phishing emails are received
Isolates web content away from endpoints
Encrypts all network traffic end-to-end
During incident planning, which evidence supports choosing IDS for watering-hole mitigation?
Time limit: 1 minute
Automatically rewrites all third-party JavaScript
Blocks every external site by default
Replaces the need for patch management
Detects suspicious traffic patterns to known threats
To verify a high-risk payment instruction, which method provides independent confirmation and auditability?
Time limit: 1 minute
Out-of-band call to a known contact number
Reply to the requesting email for confirmation
Send a text message to the sender’s number
Approve based on email signature graphics
Which combination most effectively counters competitor data theft with balanced cost and difficulty?
Time limit: 1 minute
NDAs plus access controls on customer data
Only deploy DLP to block all uploads
Train staff quarterly without agreements
Encrypt Wi‑Fi and rotate passwords weekly
A company updates browsers automatically but still gets infected via compromised industry portals. Which added control best addresses the gap?
Time limit for this question: 1 minute
Introduce web filtering to block known malicious sites
Remove auto-update to test patches manually
Force all traffic through email gateways only
Disable internal DNS resolution entirely
Leadership asks for a practical first step against BEC with minimal spend. Which action should be prioritized?
Time limit: 1 minute
Deploy full browser isolation to finance
Implement process change for dual-approval
Launch a custom phishing simulation program
Purchase advanced DLP software suite
The security team must flag external emails for caution. Which measure complements authentication checks to aid users?
Banner warnings on messages from outside
Mandatory VPN for sending all emails
Blocking emails with attachments only
Auto-forwarding external mail to quarantine
When designing a layered defense for watering-hole attacks, which sequence reflects sensible prioritization?
Intel feeds then disable all browsing then IDS
User training then block all JavaScript globally
Web filtering then browser isolation then intel feeds
Auto-updates alone then rely on email banners
