Font size
WorksheetsCompTIA Security+ MOCK EXAM
Total questions: 120
Worksheet time: 3600secs
Why might an organization be particularly concerned about introducing automation tools that become single points of failure during secure operations?
Compromised availability leading to operational disruptions.
Challenges in upholding data confidentiality.
Issues related to system scalability and slow authentication.
Potential gaps in maintaining data integrity.
A power plant utilizes a specialized system to manage and monitor its daily operations, including machinery and sensor feedback. While these systems offer centralized control, what security concern is most associated with them?
Runtime efficiency constraints.
Optimization for containerized deployments.
Constrained memory use.
Limited security update capabilities.
If a company's server has an estimated Single Loss Expectancy (SLE) of $15,000 due to an operational failure, and the Annual Rate of Occurrence (ARO) of these failures is expected to be 0.1 times per year, what is the Annual Loss Expectancy (ALE)?
$1,500
$150,000
$150
$15,000
Which asymmetric encryption technique provides a comparable level of security with shorter key lengths, making it efficient for cryptographic operations?
ECC
DSA
RSA
Diffie-Hellman
Kelly Innovations Corp, an IT company, is implementing a process of encryption where two parties establish a shared secret for communication purposes. Which of the following MOST accurately describes this process?
Asymmetric encryption
Key exchange
Hashing
Symmetric encryption
When evaluating the introduction of automated systems in a security operations center (SOC), which of the following is a prominent time-related benefit that security professionals might expect?
Reduced response time to security incidents.
Longer periods for system patching.
Increased time for team meetings.
Extended working hours for security staff.
Which of the following BEST describes an approach where the foundational systems are set up and overseen using scripts and automated instruments instead of hands-on methods?
IaC
Microservices architecture
Air-gapped network
Serverless architecture
Which of the following vulnerabilities BEST describes a situation where a threat actor can manipulate data after it has been verified by an application, but before the application uses it for a specific operation?
Memory leaks
Race conditions
Time-of-check (TOC)
Resource exhaustion
Which of the following BEST describes an organizational structure that allows for autonomous decision-making in separate departments or sectors within the company?
Hierarchical management
Matrix structure
Flat organization
Decentralized governance
Which of the following statements BEST explains the importance of 'patching' in the context of vulnerability management?
Patching involves installing special, custom made features on software interfaces to enhance user experience and aesthetics.
Patching is the process of identifying and fixing security vulnerabilities in software, firmware, and operating systems to prevent potential exploits.
Patching refers to regularly updating hardware components to ensure optimal performance and prevent system downtime.
Patching refers to the process of securing physical entry points to an organization's premises.
As part of a new building initiative, Dion Training Solutions plans to connect two office buildings via a direct physical link. Which measure will BEST protect the physical infrastructure connectivity?
Running the connection on overhead poles.
Placing the cable on the ground between buildings.
Installing the cable in a conduit buried underground.
Using wireless bridges without encryption.
Given the need for resilience and the ability to recover in a security architecture, which of the following devices ensures uninterrupted operation during a power outage?
Voltage Regulator
Power Strip
Uninterruptible power supply (UPS)
Onsite/offsite backups
Which of the following statements BEST explains the importance of environmental variables in regard to vulnerability management?
Environmental variables refer to the unique characteristics of an organization's infrastructure that can affect vulnerability assessments and risk analysis
Environmental variables are parameters used in vulnerability scanning tools to assess the security posture of an organization's network and infrastructure
Environmental variables are specific conditions that trigger an automated response when a vulnerability is detected in an organization's systems
Environmental variables are factors that impact the physical security of an organization's premises
Dion Training Solutions needs a network appliance capable of filtering traffic based on URL, HTTP headers, and specific web application functionalities. At which layer of the OSI model would this appliance primarily operate?
Layer 6
Layer 7
Layer 3
Layer 5
Which of the following BEST describes the Software Development Life Cycle (SDLC) in application security?
It primarily focuses on the speed of software delivery over security.
It replaces the need for regular software updates and patches.
It emphasizes the integration of security in software creation and maintenance.
It only considers security during the testing and creation phases of software development.
To improve security at their law firm, Norah, a security analyst wants to implement a system that will selectively block or allow traffic based on the nature of the communication. Which firewall type would be MOST effective for this purpose?
VPN
802.1x
Layer 4 Firewall
Layer 7 Firewall
Reed & Jamario Security Services has recommended your company use a port based system to prevent unauthorized users and devices. Which of the following are they recommending?
Fail-open
IDS
Fail-closed
802.1X
Which of the following motivations refers to any act of stealing information from a system or network?
Data exfiltration
Ethical motivations
Disruption/chaos
Service disruption
What term refers to an organization's predetermined level of acceptable risk exposure?
Risk appetite
Risk tolerance
Exposure factor
Conservative
When a legal organization routinely communicates with clients via email containing sensitive case details, which strategy would be the MOST effective to secure the communications?
Deployment of regular data backups to secure cloud storage
Implementation of end-to-end encrypted email
Conducting regular user cybersecurity training
Utilization of VPNs for email transmission
Which of the following characteristics of a cloud architecture model describes a model that can quickly recover from failures due to adverse conditions?
Resilience
Availability
Ease of Deployment
Scalability
Kelly Innovations LLC is redesigning its network infrastructure to support its expanding R&D team. Which of the following strategies will MOST effectively lessen the attack surface?
Allowing most inbound and outbound traffic.
Implementing a single-layered security approach.
Disabling unnecessary services and protocols.
Using the same password for all devices.
Which of the following threats is MOST likely to accidentally cause harm to the system?
Unskilled attackers
Nation-state actors
Shadow IT
Hacktivist
In a meeting with the CEO, Burton has asked for guidance on developing the rules of engagement for an upcoming penetration test. The CEO doesn't think they need to create rules of engagement since they are hiring an experienced, well respected company to do the penetration testing. Why is it important for the company to still establish rules of engagement?
They need the names of all personnel who will be involved in the penetration test.
They need to know the total costs of the penetration test.
They need to set the timeline for later penetration tests.
They need to set boundaries and limitations during the penetration test.
Within the IT department, Sarah has been designated to oversee the security measures for the new data management platform. She is accountable for the regular review of security protocols and responding to any breaches or vulnerabilities that may arise. Sarah's role would be BEST described by which of the following terms?
Risk owner
Risk register
Risk assessor
Risk indicator
You are a cybersecurity analyst working for a software development company that develops mobile applications. The company wants to implement a secure and standardized method for users to grant third-party applications access to their account data without sharing their credentials. As a cybersecurity analyst, you recommend implementing OAuth for this purpose. Which of the following approaches would be the MOST effective way to implement OAuth in the given scenario?
Generating random access tokens for users and sharing them directly with third-party applications for data access.
Requesting users to share their account credentials directly with third-party applications for data access.
Implementing a central OAuth authorization server to handle user authentication and issue access tokens to third-party applications.
Providing third-party applications with unrestricted access to user account data without authentication or authorization.
Which of the following BEST describes the initial step to ensure a secure procurement process at Dion Training?
Collaborate with the IT department for installation.
Check for discounts or bulk pricing.
Determine the software's compatibility with existing systems.
Verify the legitimacy of the software vendor.
Before disposing of old computers at Kelly Innovations LLC, Sasha receives a document that confirms all data has been securely removed. What is this document known as?
Purchase Order
Service Agreement
Data Retention Policy
Certificate of Sanitization
Which of the following BEST describes a threat actor who primarily depends on commonly found tools, often easily accessible from the web or dark web?
Ethical hacker
Bug bounty hunter
Script kiddie
APT
Jamario, a security analyst at Dion Training, has just completed a vulnerability assessment on a company's internal web application. One of the vulnerabilities detected has a high likelihood of being exploited and, if successful, could expose sensitive customer data. Based on severity and potential impact, how should this vulnerability be classified?
Medium
Critical
Low
Informational
Which mitigation technique involves the use of tools like Nagios or Splunk to continuously observe and check the operation of a system or network?
Hardening techniques
Segmentation
Monitoring
Patching
Which of the following mitigation techniques can help protect a device from unauthorized network traffic solely by using software that can control network traffic based on predefined rules and policies?
Host-based Firewall
Encryption
Patching
Host-based Intrusion Prevention
Which of the following BEST describes how automation and orchestration in cybersecurity operations influence employee satisfaction and retention?
Decreases the demand for cybersecurity professionals.
Reduces repetitive and mundane tasks.
Directly increases salary packages.
Facilitates frequent role rotation among teams.
Kelly Innovations decides to manage its IT infrastructure within its physical location, retaining full control over its hardware, software, and data. Which of the following security implications is MOST directly associated with this approach?
Risk transference to third-party vendors.
Dependence on external patch availability.
Multi-tenancy risks.
Increased responsibility for physical security.
Which of the following statements BEST explains the importance of enforcing baselines when automating and orchestrating secure operations?
Enforcing baselines allows for the almost complete automation of incident response, reducing the need for large security teams and incident response teams.
Baselines set the initial targets for automating threat hunting and penetration testing, thereby reducing dependence on human input.
Enforcing baselines helps to standardize configurations across systems, enabling efficient automation and reducing the risk of security incidents.
Baselines eliminate the need for continuous monitoring of systems because these things are all either automated or orchestrated, thereby freeing up resources.
Alex, a network administrator, reviews logs from the company's main database server. He finds that every night at 3 AM, a backup process runs which generates a series of logs. However, on scanning through last week's data, he finds that logs from two nights are missing entirely. On further investigation, Alex discovers a new, unauthorized user account was created on one of those nights. What might Alex reasonably infer from these observations?
The IT team might have created a new account for a new employee and forgot to inform him.
An attacker gained access, created the unauthorized account, and removed logs.
The database server accidentally skipped the backup on those nights due to low storage.
The backup process was paused by the IT department for maintenance purposes.
Which of the following hardening techniques can help protect systems or devices from attacks by installing software like a firewall or antivirus directly on user devices to report and block potential attacks?
Changing Default Passwords
Patching
Least Privilege
Installation of endpoint protection
Which of the following ports, if left open and unmonitored, might allow database queries from unauthorized external sources?
Port 1433
Port 21
Port 443
Port 53
Which of the following terms emphasizes the mathematical structure used to scramble data so that only a specific key can unscramble it?
Encryption algorithm
Hash function
Cipher block
Digital signature
Which of the following statements is NOT true about the importance of log aggregation?
Log aggregation increases the complexity of managing and interpreting security logs.
Log aggregation aids in maintaining regulatory compliance by keeping a record of events that happened in the system.
Log aggregation can enhance security by consolidating logs from different sources for easier analysis.
Log aggregation helps to detect unusual activity or behavior that may indicate a security breach.
Which of the following is an aspect of asset management that ensures that each IT asset is clearly associated with a specific individual or department, providing clarity on responsibilities and access rights?
Monitoring
Decommissioning
Acquisition
Ownership
Dion Training is conducting a security awareness training program for its employees to enhance their cybersecurity knowledge. As part of this program, they have planned and executed phishing campaigns. Which of the following BEST describes the primary objective of phishing campaigns conducted during security awareness training?
To promote a competitive environment among employees.
To test employees' ability to recognize and report phishing attempts.
To trick employees into revealing sensitive information.
To prevent any form of malware from spreading within the organization's network.
Dion Training is considering a collaboration with a new IT service vendor. To ensure compliance and adherence to industry standards, Dion Training wishes to see verifiable evaluations of the vendor's security controls and practices. Which of the following would provide Dion Training with insights into the vendor's own internal evaluations of their security measures?
Customer testimonials
Evidence of internal audits
External penetration test reports
Regulatory compliance certificates
Which of the following mitigation techniques can help enforce compliance with security standards and policies on a system or network by designating programs that are allowed to run and blocking all other programs from being run?
Application allow list
Patching
Configuration Enforcement
Least Privilege
When considering the RSA algorithm, which description BEST captures its underlying mathematical property used for public key cryptography?
Digital signature
Hash function
Trapdoor function
Symmetric encryption
Which of the following terms refers to how any country's government regulates how its citizens' data should be collected, stored, and processed?
National legal implications
Consent management
Data encryption
General Data Protection Regulation (GDPR)
Enrique, the head of IT at Dion Training, is tasked with ensuring all deployed company systems adhere to a set of standardized configurations. He wants to reduce the attack surface as much as possible. Which of the following techniques would BEST reduce the organization's attack surface?
Requiring frequent password resets for all employees.
Turning off all unused services and closing unnecessary ports.
Implementing a VPN for any remote access to company devices.
Deploying antivirus software on all company workstations and other devices.
Dion Training has recently implemented a new web portal for their customers. During a routine security review, the IT team notices that some suspicious activities have been logged. An unknown user attempted to access the system with a strange pattern: when requesting a particular user file, instead of the usual URL structure ( /users/[username]/profile ) the system registered requests like ( /users/../admin/config ). Within a short span of time, several such patterns were identified, each trying to reach different sensitive files and directories. Given this information, which of the following types of attack is the user MOST likely attempting?
Attempting to access files outside of intended directories.
Attempting to inject malicious scripts into the system.
Attempting to exploit a buffer overflow vulnerability.
Attempting to escalate their privileges on the system.
What is the primary difference between sanitization and destruction in the disposal process?
Sanitization refers to physically damaging the asset to render it unusable, while destruction involves completely eliminating all residual data.
Sanitization concerns the reuse of assets in an organization, and destruction involves transferring those assets to a different department.
Sanitization and destruction are synonyms and refer to the same process.
Sanitization involves erasing data so it cannot be recovered; destruction is total physical demolition of the asset.
At Kelly Innovations LLC, Susan has been entrusted with determining the purposes and means of processing personal data for the organization's new marketing campaign. She decides what data to collect, how long it will be retained, and with whom it will be shared. Which of the following BEST describes the role Susan is playing?
Data Processor
Data Custodian
Data Subject
Data Controller
An investment firm allows a fluctuation of up to 10% in the value of its high-risk investment portfolio compared to the expected return on investment, but immediate action is required if this threshold is exceeded. This 10% fluctuation represents an example of:
Risk matrix
Risk appetite
Risk tolerance
Risk management
Georgina, a lawyer, needs to send a contract to their client for signature. She want to ensure that their client cannot later deny signing the contract. Which of the following methods can they use to prevent them from denying that they have signed contracts?
Digital signatures
Firewalls
Encryption
A cryptographic primitive
Dion Training Solutions is aiming to optimize their wide-area network (WAN) while ensuring advanced network management and performance optimization. They are considering a solution that can be deployed both on-premises and in the cloud. Which of the following technologies would BEST match their requirements?
AH
SASE
SD-WAN
TLS
Florence is the CEO of a company. She has the final say over all decisions made regarding the business, IT, accounting, and other departments. What type of governance does Florence's company have?
Committee governance
Board governance
Centralized governance
Decentralized governance
Susan, a security analyst at Kelly Innovations LLC, is reviewing alerts from the IPS. She recognizes a pattern of false positives from signature-based detections. Which of the following is the MOST likely cause for false positives in signature-based detection systems?
The IPS is scanning encrypted traffic only.
The signatures require tuning.
Signature databases are stored in volatile memory.
The system is only updated with old signatures.
You are a security analyst at Dion Training and you discover that an unauthorized device has been connected to the company’s network. As you investigate, you discover that the device was added so the employee could play video games during her breaks. What type of threat actor are you dealing with?
Unskilled Actor
Shadow IT
Nation-state Actor
Insider Threat
Clumsy Contraptions Engineering is seeking to change its security footing. In the past, they have found that too many pieces of malicious software have gotten past the system. Their Chief Security Officer believes they need a device which will actively evaluate traffic and reject or modify packets according to policies the company sets. What type of device is the CSO suggesting?
SASE
Fail-close
Remote Access
Inline
In regards to automation and orchestration, which of the following terms accurately captures the challenges faced when dealing with a system characterized by its intricate web of interconnected components and varied functionalities, potentially hindering seamless integration, effortless management, and straightforward comprehension?
Ongoing supportability
Complexity
Technical debt
Cost
At Kelly Innovations Corp., Sarah noticed that their core business application, which tracks customer orders, was not updating inventory levels accurately. A recent update seemed to have introduced a bug. Which of the following would offer the BEST solution?
Dependency check
Application rollback
Application restart
Patch management
When considering user interactions with a web service, which of the following are the security measures that involve the secure creation and transfer of identifiers as well as enforcing inactivity limits to prevent unauthorized access?
Timeout policies
Token handling
Session cookies
Session management
The executive team at a software development firm decides that any project with a potential financial impact greater than $500,000 due to a security incident will require an immediate review and intervention. This financial impact figure represents which of the following in risk management?
Risk limit
Risk tolerance
Risk level
Risk threshold
Which of the following terms refers to a critical predictive metric that organizations monitor to foresee potential risks and their impact on operations?
Risk threshold
Risk parameters
Risk metrics
Key risk indicators
What type of encryption only affects a section of a storage device?
Partition encryption
File-level encryption
Full-disk encryption
Database encryption
A software development company regularly releases software updates to its global customer base. Recently, some customers reported receiving unauthorized and potentially malicious software updates. The company wants to implement a security technique to ensure the authenticity and integrity of its software updates when delivered to customers. Which of the following would BEST assist in achieving this goal?
Intrusion Detection System
Antivirus Scanning
Code Signing
Multi-factor Authentication
A tech company discovers that the firmware in some of their devices contains a hidden backdoor. Upon investigation, it's determined that the compromised firmware came from an overseas supplier they contracted with. The backdoor gave attackers remote access to devices without user knowledge. What type of attack vector has the company fallen victim to?
Bluesnarfing
Supply chain
On-path attack
Drive-by download
While performing a digital investigation, which of the following statements BEST describes the role of preservation of evidence?
It allocates budgetary resources for the forensic investigation.
It maintains the integrity of digital evidence over time.
It allows investigators to prioritize evidence collection.
It provides legal teams with a roadmap for case strategy.
When sending an encrypted message to Dion Training, a client would use which of the following to ensure only Dion Training can decrypt and read the message?
Key escrow
Wildcard certificate
Private key
Public key
After remedying a previously identified vulnerability in their systems, Kelly Innovations LLC wants to ensure that the remediation steps were successful. Which of the following is the BEST method that involves examining related system and network logs to enhance the vulnerability report validation process?
Threat modeling
Rescanning
Patch management
Reviewing event logs
For ensuring the security of an HTTP application like WordPress or Magento against threats like SQL injection or cross-site scripting, which monitoring tool or method would be MOST appropriate?
Web application firewall (WAF)
Host-based intrusion detection system (HIDS)
NetFlow
Antivirus software
Reginald, an IT Manager, is the owner of a file on a server and wants to grant his colleagues access to the file. He is the only one who can decide who is allowed access to the file and what actions they can perform on it. Which authorization model is being used in this scenario?
MAC
DAC
ABAC
RBAC
Which mitigation technique involves shutting off specific entry and exit points in a system to prevent potential vulnerabilities or unauthorized access?
Monitoring
Segmentation
Disabling ports
Encryption
During a network investigation, Aiden, a cybersecurity analyst, identifies two key irregularities: The CEO, who tends to work late, logged in from both Paris and Tokyo within five minutes, and there's an unexpected surge in emails from the HR department outside of recruitment season. Which of the following should the analyst be MOST concerned about based on these observations?
The absence of the CEO's usual late-night login.
A recent software update on the CEO's computer.
Simultaneous CEO logins from distant locations.
The sudden increase in emails from the HR department.
The HR department for a large corporation is looking to streamline the onboarding process for new employees. What can the use of scripting do to help attain this goal, in terms of system access?
Facilitating personal interviews between IT and new hires.
Automating the provisioning of account credentials.
Directly improving onboarding training content.
Generating hard-copy user manuals for each new hire.
What element of backup strategy involves making data copies regularly at set intervals?
Journaling
Load balancing
Frequency
Replication
What is the name of a cryptographic key that can be freely distributed and used by others to encrypt messages?
Digital signature
Public key
Symmetric key
Hash key
Which of the following terms BEST describe the affirmation of the validation of the accuracy and thoroughness of compliance-related reports?
Attestation
Regulatory examination
Internal assessment
Independent third-party audit
Which of the following vulnerabilities is unique to cloud computing environments, posing risks related to unauthorized access and data manipulation?
Buffer overflow
Side loading
Insecure Interfaces and APIs
Cross-site scripting (XSS)
Reed, a cybersecurity specialist at Dion Training Solutions, is optimizing the company's IPS. He notes that while signature-based detection is highly effective against known threats, it has some limitations. Which of the following BEST describes a limitation of signature-based detection in an IPS?
It might not detect zero-day exploits.
It automatically updates with behavioral patterns of users.
It requires substantial network bandwidth to operate.
It encrypts network traffic to hide malicious signatures.
Travid is evaluating an attack that has occurred on his organization's system. He sees that the attacker entered a lot of data into the the area of memory in the API that temporarily stores user input. What type of attack did Travid discover?
Memory leak
Memory fragmentation
Buffer underflow
Buffer overflow
What is the purpose of a security analyst doing due diligence in the vendor selection process?
To assess the vendor's ability to provide the goods or services when they have promised
To compare multiple vendors' suppliers to ensure they are all diligent in analyzing their own supply chains.
To ensure that the chosen vendor is the best choice among the list of possible vendors
To ensure that the vendor's practices align with the organization's requirements
Which of the following are hardware issues that result from products that are no longer being made or supported, but are still usable?
Hardware cloning
Legacy vulnerability
Hardware tampering
End-of-life vulnerability
A drone manufacturer employs a real-time operating system (RTOS) to ensure timely task executions. While optimizing for real-time performance, which of the following security concerns might arise?
Overhead from virtualization.
Inadequate buffer overflow protections.
Lack of legacy protocol support.
Uncontrolled cloud access.
Lexicon, an AI company, wants to implement a security measure to identify and evaluate potential threats to their systems and networks. Which of the following is an example of a managerial security control that the company could implement?
Intrusion detection system
Firewall
Security guards
Risk assessments
As a security analyst, you are reviewing application logs while investigating a suspected breach. Which of the following pieces of information is NOT typically documented in the application log data?
Timestamps of application activity.
The physical location of the user accessing the application.
User IDs related to specific application transactions.
Server IP address where the application is hosted.
Kelly Innovations LLC wants to implement a network appliance that focuses on filtering traffic based on source and destination IP addresses, and port numbers. Which layer of the OSI model is this appliance primarily operating at?
Layer 3
Layer 2
Layer 5
Layer 4
Which method is used for the authentication process used in WPA2 with PSK?
Using a passphrase to generate a pairwise master key (PMK).
QR codes for client device configuration.
Password Authenticated Key Exchange (PAKE).
Dragonfly handshake with a MAC address hash.
Which of the following BEST describes the primary purpose of archiving as a method to bolster security monitoring?
To provide historical insights into security incidents for future investigations.
To analyze real-time threats and mitigate them instantly.
To maintain compliance with regulations without needing long-term data storage.
To provide an external backup in case of system crashes
Your organization is implementing deception controls within its cloud infrastructure to detect unauthorized access and malicious behavior. Identify the correct deception technology for each implementation.
A database server running PostgreSQL with intentionally weak authentication that logs all connection attempts and queries.
Honeypot
Honeynet
Honeyfile
Honeytoken
Your organization is implementing deception controls within its cloud infrastructure to detect unauthorized access and malicious behavior. Identify the correct deception technology for each implementation.
A fabricated customer database record with a unique email address that triggers alerts when contacted or exported.
Honeynet
Honeypot
Honeyfile
Honeytoken
Your organization is implementing deception controls within its cloud infrastructure to detect unauthorized access and malicious behavior. Identify the correct deception technology for each implementation.
Multiple AWS EC2 instances configured as a e-commerce platform with web servers, APIs, and databases on an isolated VPC.
Honeynet
Honeypot
Honeyfile
Honeytoken
Your organization is implementing deception controls within its cloud infrastructure to detect unauthorized access and malicious behavior. Identify the correct deception technology for each implementation.
A Word document named merger_acquisition_plans.docx stored in the legal department's cloud storage.
Honeynet
Honeypot
Honeyfile
Honeytoken
Consider the following terms associated with various social engineering attacks. Match each attack with the technique being used.
A user accidentally enters 'amaz0n.com' instead of 'amazon.com' and lands on a fake shopping site that looks identical to the legitimate retailer to capture their login credentials.
Pretexting
Impersonation
Misinformation
Typosquatting
Consider the following terms associated with various social engineering attacks. Match each attack with the technique being used.
An attacker carefully creates a story about being a new employee who lost their badge on the first day to gain access to the building.
Pretexting
Impersonation
Misinformation
Typosquatting
Consider the following terms associated with various social engineering attacks. Match each attack with the technique being used.
An attacker wearing a delivery uniform and carrying packages tailgates an employee into a secure building by claiming to have a delivery for the third floor.
Pretexting
Impersonation
Misinformation
Typosquatting
Consider the following terms associated with various social engineering attacks. Match each attack with the technique being used.
Attackers spread false rumors on social media claiming a company's banking system was breached to cause its customers to panic and call support lines where attackers pose as help desk agents.
Pretexting
Impersonation
Misinformation
Typosquatting
Which NIST Cybersecurity Framework implementation tier reflects an organization that adapts practices based on lessons learned and predictive indicators?
a) Tier 1: Partial
b) Tier 2: Risk‑Informed
c) Tier 3: Repeatable
d) Tier 4: Adaptive
In a Zero Trust architecture, what component makes the decision to allow or deny access after evaluating policy and context?
a) Policy Enforcement Point (PEP)
b) Policy Decision Point/Engine (PDP/PE)
c) Subject
d) Cloud broker
Which CVSS base metric describes whether exploitation requires user action?
a) Attack Vector
b) Attack Complexity
c) Privileges Required
d) User Interaction
Who is primarily responsible for determining the purposes and means of processing personal data in an enterprise?
a) Data Processor
b) Data Custodian
c) Data Controller
d) Privacy Officer
Which control BEST prevents unapproved software from running on endpoints?
a) Blacklisting
b) Application allow‑listing
c) EDR
d) Anti‑virus signatures
What is the correct order of volatility during evidence collection?
a) Backups → RAM → CPU cache → swap
b) CPU cache → RAM → swap/temp → disk → remote logs → backups
c) RAM → CPU cache → disk → backups
d) Disk → RAM → CPU cache → backups
Which statement BEST reflects the cloud shared‑responsibility model for SaaS?
a) Customer manages OS hardening; provider manages data.
b) Customer manages data and identities; provider manages app/OS/hardware/DC.
c) Customer manages hypervisor; provider manages data.
d) Customer manages physical DC; provider manages application.
Which defensive control is specifically designed to stop SQL injection and XSS in HTTP/S traffic?
a) IDS
b) WAF
c) NetFlow
d) EDR
During 802.1X authentication, which role is the network switch or AP performing?
a) Supplicant
b) Authenticator
c) Authentication Server
d) RADIUS client on the server
Which RAID level provides striping with parity that tolerates a single drive failure?
a) RAID 0
b) RAID 1
c) RAID 5
d) RAID 10
Which activity immediately follows containment in the incident response lifecycle?
a) Analysis
b) Eradication
c) Detection
d) Recovery
Which encryption approach is typically used to exchange a session key that then protects bulk data transfer?
a) Pure symmetric encryption only
b) Pure asymmetric encryption only
c) Hybrid: asymmetric to wrap a symmetric key
d) Hashing with HMAC only
Which data‑protection technique replaces sensitive values with reversible placeholders stored in a separate vault?
a) Masking
b) Hashing
c) Tokenization
d) Obfuscation
What SCADA/ICS component directly interfaces with sensors and actuators to control physical processes?
a) HSM
b) PLC
c) SIEM
d) TPM
UEFI Secure Boot prevents execution of untrusted code at boot by validating which item first?
a) Kernel modules only
b) Bootloader and UEFI apps against trusted signature databases
c) Userland services
d) Hypervisor only
Which logging concept MOST improves threat hunting by centralizing events from endpoints, network devices, and apps?
a) Local logs only
b) Log aggregation and SIEM correlation
c) Ad‑hoc CSV exports
d) Packet captures only
Which SDLC practice reduces defects introduced by late security reviews?
a) Big‑bang deployment
b) Shift‑left security integrated into CI/CD
c) Annual pen test only
d) Waterfall with security at the end
Which DLP deployment monitors and controls data copied to USB media on laptops?
a) Network DLP
b) Storage DLP
c) Endpoint DLP
d) Cloud DLP
Kerberos primarily prevents which attack by using time‑stamped authenticators?
a) On‑path SSL stripping
b) Replay attacks
c) DNS cache poisoning
d) SQL injection
Which wireless standard first introduced operation in the 6 GHz band (Wi‑Fi 6E)?
a) 802.11ac
b) 802.11ax
c) 802.11n
d) 802.11a
What is the PRIMARY difference between OAuth 2.0 and OpenID Connect (OIDC)?
a) OAuth provides authentication; OIDC provides authorization.
b) OAuth provides authorization; OIDC adds authentication on top of OAuth.
c) Both are the same protocol with different names.
d) OIDC replaces TLS in transit.
Which backup property specifies how often backups are taken (e.g., hourly vs. daily)?
a) Retention
b) Frequency
c) Recovery Point Objective
d) Recovery Time Objective
Which deception control is a single decoy system designed to attract attackers?
a) Honeytoken
b) Honeyfile
c) Honeypot
d) Honeynet
Which port is used by LDAPS?
a) TCP 389
b) TCP 636
c) UDP 161
d) TCP 995
Which term refers to the acceptable deviation from expected results before management action is required?
a) Risk appetite
b) Risk tolerance
c) Risk threshold
d) Exposure factor
