wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

CompTIA Security+ MOCK EXAM

Total questions: 120

Worksheet time: 3600secs

Name
Class
Date
1.

Why might an organization be particularly concerned about introducing automation tools that become single points of failure during secure operations?

a)

Compromised availability leading to operational disruptions.

b)

Challenges in upholding data confidentiality.

c)

Issues related to system scalability and slow authentication.

d)

Potential gaps in maintaining data integrity.

2.

A power plant utilizes a specialized system to manage and monitor its daily operations, including machinery and sensor feedback. While these systems offer centralized control, what security concern is most associated with them?

a)

Runtime efficiency constraints.

b)

Optimization for containerized deployments.

c)

Constrained memory use.

d)

Limited security update capabilities.

3.

If a company's server has an estimated Single Loss Expectancy (SLE) of $15,000 due to an operational failure, and the Annual Rate of Occurrence (ARO) of these failures is expected to be 0.1 times per year, what is the Annual Loss Expectancy (ALE)?

a)

$1,500

b)

$150,000

c)

$150

d)

$15,000

4.

Which asymmetric encryption technique provides a comparable level of security with shorter key lengths, making it efficient for cryptographic operations?

a)

ECC

b)

DSA

c)

RSA

d)

Diffie-Hellman

5.

Kelly Innovations Corp, an IT company, is implementing a process of encryption where two parties establish a shared secret for communication purposes. Which of the following MOST accurately describes this process?

a)

Asymmetric encryption

b)

Key exchange

c)

Hashing

d)

Symmetric encryption

6.

When evaluating the introduction of automated systems in a security operations center (SOC), which of the following is a prominent time-related benefit that security professionals might expect?

a)

Reduced response time to security incidents.

b)

Longer periods for system patching.

c)

Increased time for team meetings.

d)

Extended working hours for security staff.

7.

Which of the following BEST describes an approach where the foundational systems are set up and overseen using scripts and automated instruments instead of hands-on methods?

a)

IaC

b)

Microservices architecture

c)

Air-gapped network

d)

Serverless architecture

8.

Which of the following vulnerabilities BEST describes a situation where a threat actor can manipulate data after it has been verified by an application, but before the application uses it for a specific operation?

a)

Memory leaks

b)

Race conditions

c)

Time-of-check (TOC)

d)

Resource exhaustion

9.

Which of the following BEST describes an organizational structure that allows for autonomous decision-making in separate departments or sectors within the company?

a)

Hierarchical management

b)

Matrix structure

c)

Flat organization

d)

Decentralized governance

10.

Which of the following statements BEST explains the importance of 'patching' in the context of vulnerability management?

a)

Patching involves installing special, custom made features on software interfaces to enhance user experience and aesthetics.

b)

Patching is the process of identifying and fixing security vulnerabilities in software, firmware, and operating systems to prevent potential exploits.

c)

Patching refers to regularly updating hardware components to ensure optimal performance and prevent system downtime.

d)

Patching refers to the process of securing physical entry points to an organization's premises.

11.

As part of a new building initiative, Dion Training Solutions plans to connect two office buildings via a direct physical link. Which measure will BEST protect the physical infrastructure connectivity?

a)

Running the connection on overhead poles.

b)

Placing the cable on the ground between buildings.

c)

Installing the cable in a conduit buried underground.

d)

Using wireless bridges without encryption.

12.

Given the need for resilience and the ability to recover in a security architecture, which of the following devices ensures uninterrupted operation during a power outage?

a)

Voltage Regulator

b)

Power Strip

c)

Uninterruptible power supply (UPS)

d)

Onsite/offsite backups

13.

Which of the following statements BEST explains the importance of environmental variables in regard to vulnerability management?

a)

Environmental variables refer to the unique characteristics of an organization's infrastructure that can affect vulnerability assessments and risk analysis

b)

Environmental variables are parameters used in vulnerability scanning tools to assess the security posture of an organization's network and infrastructure

c)

Environmental variables are specific conditions that trigger an automated response when a vulnerability is detected in an organization's systems

d)

Environmental variables are factors that impact the physical security of an organization's premises

14.

Dion Training Solutions needs a network appliance capable of filtering traffic based on URL, HTTP headers, and specific web application functionalities. At which layer of the OSI model would this appliance primarily operate?

a)

Layer 6

b)

Layer 7

c)

Layer 3

d)

Layer 5

15.

Which of the following BEST describes the Software Development Life Cycle (SDLC) in application security?

a)

It primarily focuses on the speed of software delivery over security.

b)

It replaces the need for regular software updates and patches.

c)

It emphasizes the integration of security in software creation and maintenance.

d)

It only considers security during the testing and creation phases of software development.

16.

To improve security at their law firm, Norah, a security analyst wants to implement a system that will selectively block or allow traffic based on the nature of the communication. Which firewall type would be MOST effective for this purpose?

a)

VPN

b)

802.1x

c)

Layer 4 Firewall

d)

Layer 7 Firewall

17.

Reed & Jamario Security Services has recommended your company use a port based system to prevent unauthorized users and devices. Which of the following are they recommending?

a)

Fail-open

b)

IDS

c)

Fail-closed

d)

802.1X

18.

Which of the following motivations refers to any act of stealing information from a system or network?

a)

Data exfiltration

b)

Ethical motivations

c)

Disruption/chaos

d)

Service disruption

19.

What term refers to an organization's predetermined level of acceptable risk exposure?

a)

Risk appetite

b)

Risk tolerance

c)

Exposure factor

d)

Conservative

20.

When a legal organization routinely communicates with clients via email containing sensitive case details, which strategy would be the MOST effective to secure the communications?

a)

Deployment of regular data backups to secure cloud storage

b)

Implementation of end-to-end encrypted email

c)

Conducting regular user cybersecurity training

d)

Utilization of VPNs for email transmission

21.

Which of the following characteristics of a cloud architecture model describes a model that can quickly recover from failures due to adverse conditions?

a)

Resilience

b)

Availability

c)

Ease of Deployment

d)

Scalability

22.

Kelly Innovations LLC is redesigning its network infrastructure to support its expanding R&D team. Which of the following strategies will MOST effectively lessen the attack surface?

a)

Allowing most inbound and outbound traffic.

b)

Implementing a single-layered security approach.

c)

Disabling unnecessary services and protocols.

d)

Using the same password for all devices.

23.

Which of the following threats is MOST likely to accidentally cause harm to the system?

a)

Unskilled attackers

b)

Nation-state actors

c)

Shadow IT

d)

Hacktivist

24.

In a meeting with the CEO, Burton has asked for guidance on developing the rules of engagement for an upcoming penetration test. The CEO doesn't think they need to create rules of engagement since they are hiring an experienced, well respected company to do the penetration testing.  Why is it important for the company to still establish rules of engagement?

a)

They need the names of all personnel who will be involved in the penetration test.

b)

They need to know the total costs of the penetration test.

c)

They need to set the timeline for later penetration tests.

d)

They need to set boundaries and limitations during the penetration test.

25.

Within the IT department, Sarah has been designated to oversee the security measures for the new data management platform. She is accountable for the regular review of security protocols and responding to any breaches or vulnerabilities that may arise. Sarah's role would be BEST described by which of the following terms?

a)

Risk owner

b)

Risk register

c)

Risk assessor

d)

Risk indicator

26.

You are a cybersecurity analyst working for a software development company that develops mobile applications. The company wants to implement a secure and standardized method for users to grant third-party applications access to their account data without sharing their credentials. As a cybersecurity analyst, you recommend implementing OAuth for this purpose. Which of the following approaches would be the MOST effective way to implement OAuth in the given scenario?

a)

Generating random access tokens for users and sharing them directly with third-party applications for data access.

b)

Requesting users to share their account credentials directly with third-party applications for data access.

c)

Implementing a central OAuth authorization server to handle user authentication and issue access tokens to third-party applications.

d)

Providing third-party applications with unrestricted access to user account data without authentication or authorization.

27.

Which of the following BEST describes the initial step to ensure a secure procurement process at Dion Training?

a)

Collaborate with the IT department for installation.

b)

Check for discounts or bulk pricing.

c)

Determine the software's compatibility with existing systems.

d)

Verify the legitimacy of the software vendor.

28.

Before disposing of old computers at Kelly Innovations LLC, Sasha receives a document that confirms all data has been securely removed. What is this document known as?

a)

Purchase Order

b)

Service Agreement

c)

Data Retention Policy

d)

Certificate of Sanitization

29.

Which of the following BEST describes a threat actor who primarily depends on commonly found tools, often easily accessible from the web or dark web?

a)

Ethical hacker

b)

Bug bounty hunter

c)

Script kiddie

d)

APT

30.

Jamario, a security analyst at Dion Training, has just completed a vulnerability assessment on a company's internal web application. One of the vulnerabilities detected has a high likelihood of being exploited and, if successful, could expose sensitive customer data. Based on severity and potential impact, how should this vulnerability be classified?

a)

Medium

b)

Critical

c)

Low

d)

Informational

31.

Which mitigation technique involves the use of tools like Nagios or Splunk to continuously observe and check the operation of a system or network?

a)

Hardening techniques

b)

Segmentation

c)

Monitoring

d)

Patching

32.

Which of the following mitigation techniques can help protect a device from unauthorized network traffic solely by using software that can control network traffic based on predefined rules and policies?

a)

Host-based Firewall

b)

Encryption

c)

Patching

d)

Host-based Intrusion Prevention

33.

Which of the following BEST describes how automation and orchestration in cybersecurity operations influence employee satisfaction and retention?

a)

Decreases the demand for cybersecurity professionals.

b)

Reduces repetitive and mundane tasks.

c)

Directly increases salary packages.

d)

Facilitates frequent role rotation among teams.

34.

Kelly Innovations decides to manage its IT infrastructure within its physical location, retaining full control over its hardware, software, and data. Which of the following security implications is MOST directly associated with this approach?

a)

Risk transference to third-party vendors.

b)

Dependence on external patch availability.

c)

Multi-tenancy risks.

d)

Increased responsibility for physical security.

35.

Which of the following statements BEST explains the importance of enforcing baselines when automating and orchestrating secure operations?

a)

Enforcing baselines allows for the almost complete automation of incident response, reducing the need for large security teams and incident response teams.

b)

Baselines set the initial targets for automating threat hunting and penetration testing, thereby reducing dependence on human input.

c)

Enforcing baselines helps to standardize configurations across systems, enabling efficient automation and reducing the risk of security incidents.

d)

Baselines eliminate the need for continuous monitoring of systems because these things are all either automated or orchestrated, thereby freeing up resources.

36.

Alex, a network administrator, reviews logs from the company's main database server. He finds that every night at 3 AM, a backup process runs which generates a series of logs. However, on scanning through last week's data, he finds that logs from two nights are missing entirely. On further investigation, Alex discovers a new, unauthorized user account was created on one of those nights. What might Alex reasonably infer from these observations?

a)

The IT team might have created a new account for a new employee and forgot to inform him.

b)

An attacker gained access, created the unauthorized account, and removed logs.

c)

The database server accidentally skipped the backup on those nights due to low storage.

d)

The backup process was paused by the IT department for maintenance purposes.

37.

Which of the following hardening techniques can help protect systems or devices from attacks by installing software like a firewall or antivirus directly on user devices to report and block potential attacks?

a)

Changing Default Passwords

b)

Patching

c)

Least Privilege

d)

Installation of endpoint protection

38.

Which of the following ports, if left open and unmonitored, might allow database queries from unauthorized external sources?

a)

Port 1433

b)

Port 21

c)

Port 443

d)

Port 53

39.

Which of the following terms emphasizes the mathematical structure used to scramble data so that only a specific key can unscramble it?

a)

Encryption algorithm

b)

Hash function

c)

Cipher block

d)

Digital signature

40.

Which of the following statements is NOT true about the importance of log aggregation?

a)

Log aggregation increases the complexity of managing and interpreting security logs.

b)

Log aggregation aids in maintaining regulatory compliance by keeping a record of events that happened in the system.

c)

Log aggregation can enhance security by consolidating logs from different sources for easier analysis.

d)

Log aggregation helps to detect unusual activity or behavior that may indicate a security breach.

41.

Which of the following is an aspect of asset management that ensures that each IT asset is clearly associated with a specific individual or department, providing clarity on responsibilities and access rights?

a)

Monitoring

b)

Decommissioning

c)

Acquisition

d)

Ownership

42.

Dion Training is conducting a security awareness training program for its employees to enhance their cybersecurity knowledge. As part of this program, they have planned and executed phishing campaigns. Which of the following BEST describes the primary objective of phishing campaigns conducted during security awareness training?

a)

To promote a competitive environment among employees.

b)

To test employees' ability to recognize and report phishing attempts.

c)

To trick employees into revealing sensitive information.

d)

To prevent any form of malware from spreading within the organization's network.

43.

Dion Training is considering a collaboration with a new IT service vendor. To ensure compliance and adherence to industry standards, Dion Training wishes to see verifiable evaluations of the vendor's security controls and practices. Which of the following would provide Dion Training with insights into the vendor's own internal evaluations of their security measures?

a)

Customer testimonials

b)

Evidence of internal audits

c)

External penetration test reports

d)

Regulatory compliance certificates

44.

Which of the following mitigation techniques can help enforce compliance with security standards and policies on a system or network by designating programs that are allowed to run and blocking all other programs from being run?

a)

Application allow list

b)

Patching

c)

Configuration Enforcement

d)

Least Privilege

45.

When considering the RSA algorithm, which description BEST captures its underlying mathematical property used for public key cryptography?

a)

Digital signature

b)

Hash function

c)

Trapdoor function

d)

Symmetric encryption

46.

Which of the following terms refers to how any country's government regulates how its citizens' data should be collected, stored, and processed?

a)

National legal implications

b)

Consent management

c)

Data encryption

d)

General Data Protection Regulation (GDPR)

47.

Enrique, the head of IT at Dion Training, is tasked with ensuring all deployed company systems adhere to a set of standardized configurations. He wants to reduce the attack surface as much as possible. Which of the following techniques would BEST reduce the organization's attack surface?

a)

Requiring frequent password resets for all employees.

b)

Turning off all unused services and closing unnecessary ports.

c)

Implementing a VPN for any remote access to company devices.

d)

Deploying antivirus software on all company workstations and other devices.

48.

Dion Training has recently implemented a new web portal for their customers. During a routine security review, the IT team notices that some suspicious activities have been logged. An unknown user attempted to access the system with a strange pattern: when requesting a particular user file, instead of the usual URL structure ( /users/[username]/profile ) the system registered requests like ( /users/../admin/config ). Within a short span of time, several such patterns were identified, each trying to reach different sensitive files and directories. Given this information, which of the following types of attack is the user MOST likely attempting?

a)

Attempting to access files outside of intended directories.

b)

Attempting to inject malicious scripts into the system.

c)

Attempting to exploit a buffer overflow vulnerability.

d)

Attempting to escalate their privileges on the system.

49.

What is the primary difference between sanitization and destruction in the disposal process?

a)

Sanitization refers to physically damaging the asset to render it unusable, while destruction involves completely eliminating all residual data.

b)

Sanitization concerns the reuse of assets in an organization, and destruction involves transferring those assets to a different department.

c)

Sanitization and destruction are synonyms and refer to the same process.

d)

Sanitization involves erasing data so it cannot be recovered; destruction is total physical demolition of the asset.

50.

At Kelly Innovations LLC, Susan has been entrusted with determining the purposes and means of processing personal data for the organization's new marketing campaign. She decides what data to collect, how long it will be retained, and with whom it will be shared. Which of the following BEST describes the role Susan is playing?

a)

Data Processor

b)

Data Custodian

c)

Data Subject

d)

Data Controller

51.

An investment firm allows a fluctuation of up to 10% in the value of its high-risk investment portfolio compared to the expected return on investment, but immediate action is required if this threshold is exceeded. This 10% fluctuation represents an example of:

a)

Risk matrix

b)

Risk appetite

c)

Risk tolerance

d)

Risk management

52.

Georgina, a lawyer, needs to send a contract to their client for signature. She want to ensure that their client cannot later deny signing the contract. Which of the following methods can they use to prevent them from denying that they have signed contracts?

a)

Digital signatures

b)

Firewalls

c)

Encryption

d)

A cryptographic primitive

53.

Dion Training Solutions is aiming to optimize their wide-area network (WAN) while ensuring advanced network management and performance optimization. They are considering a solution that can be deployed both on-premises and in the cloud. Which of the following technologies would BEST match their requirements?

a)

AH

b)

SASE

c)

SD-WAN

d)

TLS

54.

Florence is the CEO of a company. She has the final say over all decisions made regarding the business, IT, accounting, and other departments. What type of governance does Florence's company have?

a)

Committee governance

b)

Board governance

c)

Centralized governance

d)

Decentralized governance

55.

Susan, a security analyst at Kelly Innovations LLC, is reviewing alerts from the IPS. She recognizes a pattern of false positives from signature-based detections. Which of the following is the MOST likely cause for false positives in signature-based detection systems?

a)

The IPS is scanning encrypted traffic only.

b)

The signatures require tuning.

c)

Signature databases are stored in volatile memory.

d)

The system is only updated with old signatures.

56.

You are a security analyst at Dion Training and you discover that an unauthorized device has been connected to the company’s network. As you investigate, you discover that the device was added so the employee could play video games during her breaks. What type of threat actor are you dealing with?

a)

Unskilled Actor

b)

Shadow IT

c)

Nation-state Actor

d)

Insider Threat

57.

Clumsy Contraptions Engineering is seeking to change its security footing. In the past, they have found that too many pieces of malicious software have gotten past the system. Their Chief Security Officer believes they need a device which will actively evaluate traffic and reject or modify packets according to policies the company sets. What type of device is the CSO suggesting?

a)

SASE

b)

Fail-close

c)

Remote Access

d)

Inline

58.

In regards to automation and orchestration, which of the following terms accurately captures the challenges faced when dealing with a system characterized by its intricate web of interconnected components and varied functionalities, potentially hindering seamless integration, effortless management, and straightforward comprehension?

a)

Ongoing supportability

b)

Complexity

c)

Technical debt

d)

Cost

59.

At Kelly Innovations Corp., Sarah noticed that their core business application, which tracks customer orders, was not updating inventory levels accurately. A recent update seemed to have introduced a bug. Which of the following would offer the BEST solution?

a)

Dependency check

b)

Application rollback

c)

Application restart

d)

Patch management

60.

When considering user interactions with a web service, which of the following are the security measures that involve the secure creation and transfer of identifiers as well as enforcing inactivity limits to prevent unauthorized access?

a)

Timeout policies

b)

Token handling

c)

Session cookies

d)

Session management

61.

The executive team at a software development firm decides that any project with a potential financial impact greater than $500,000 due to a security incident will require an immediate review and intervention. This financial impact figure represents which of the following in risk management?

a)

Risk limit

b)

Risk tolerance

c)

Risk level

d)

Risk threshold

62.

Which of the following terms refers to a critical predictive metric that organizations monitor to foresee potential risks and their impact on operations?

a)

Risk threshold

b)

Risk parameters

c)

Risk metrics

d)

Key risk indicators

63.

What type of encryption only affects a section of a storage device?

a)

Partition encryption

b)

File-level encryption

c)

Full-disk encryption

d)

Database encryption

64.

A software development company regularly releases software updates to its global customer base. Recently, some customers reported receiving unauthorized and potentially malicious software updates. The company wants to implement a security technique to ensure the authenticity and integrity of its software updates when delivered to customers. Which of the following would BEST assist in achieving this goal?

a)

Intrusion Detection System

b)

Antivirus Scanning

c)

Code Signing

d)

Multi-factor Authentication

65.

A tech company discovers that the firmware in some of their devices contains a hidden backdoor. Upon investigation, it's determined that the compromised firmware came from an overseas supplier they contracted with. The backdoor gave attackers remote access to devices without user knowledge. What type of attack vector has the company fallen victim to?

a)

Bluesnarfing

b)

Supply chain

c)

On-path attack

d)

Drive-by download

66.

While performing a digital investigation, which of the following statements BEST describes the role of preservation of evidence?

a)

It allocates budgetary resources for the forensic investigation.

b)

It maintains the integrity of digital evidence over time.

c)

It allows investigators to prioritize evidence collection.

d)

It provides legal teams with a roadmap for case strategy.

67.

When sending an encrypted message to Dion Training, a client would use which of the following to ensure only Dion Training can decrypt and read the message?

a)

Key escrow

b)

Wildcard certificate

c)

Private key

d)

Public key

68.

After remedying a previously identified vulnerability in their systems, Kelly Innovations LLC wants to ensure that the remediation steps were successful. Which of the following is the BEST method that involves examining related system and network logs to enhance the vulnerability report validation process?

a)

Threat modeling

b)

Rescanning

c)

Patch management

d)

Reviewing event logs

69.

For ensuring the security of an HTTP application like WordPress or Magento against threats like SQL injection or cross-site scripting, which monitoring tool or method would be MOST appropriate?

a)

Web application firewall (WAF)

b)

Host-based intrusion detection system (HIDS)

c)

NetFlow

d)

Antivirus software

70.

Reginald, an IT Manager, is the owner of a file on a server and wants to grant his colleagues access to the file. He is the only one who can decide who is allowed access to the file and what actions they can perform on it. Which authorization model is being used in this scenario?

a)

MAC

b)

DAC

c)

ABAC

d)

RBAC

71.

Which mitigation technique involves shutting off specific entry and exit points in a system to prevent potential vulnerabilities or unauthorized access?

a)

Monitoring

b)

Segmentation

c)

Disabling ports

d)

Encryption

72.

During a network investigation, Aiden, a cybersecurity analyst, identifies two key irregularities: The CEO, who tends to work late, logged in from both Paris and Tokyo within five minutes, and there's an unexpected surge in emails from the HR department outside of recruitment season. Which of the following should the analyst be MOST concerned about based on these observations?

a)

The absence of the CEO's usual late-night login.

b)

A recent software update on the CEO's computer.

c)

Simultaneous CEO logins from distant locations.

d)

The sudden increase in emails from the HR department.

73.

The HR department for a large corporation is looking to streamline the onboarding process for new employees. What can the use of scripting do to help attain this goal, in terms of system access?

a)

Facilitating personal interviews between IT and new hires.

b)

Automating the provisioning of account credentials.

c)

Directly improving onboarding training content.

d)

Generating hard-copy user manuals for each new hire.

74.

What element of backup strategy involves making data copies regularly at set intervals?

a)

Journaling

b)

Load balancing

c)

Frequency

d)

Replication

75.

What is the name of a cryptographic key that can be freely distributed and used by others to encrypt messages?

a)

Digital signature

b)

Public key

c)

Symmetric key

d)

Hash key

76.

Which of the following terms BEST describe the affirmation of the validation of the accuracy and thoroughness of compliance-related reports?

a)

Attestation

b)

Regulatory examination

c)

Internal assessment

d)

Independent third-party audit

77.

Which of the following vulnerabilities is unique to cloud computing environments, posing risks related to unauthorized access and data manipulation?

a)

Buffer overflow

b)

Side loading

c)

Insecure Interfaces and APIs

d)

Cross-site scripting (XSS)

78.

Reed, a cybersecurity specialist at Dion Training Solutions, is optimizing the company's IPS. He notes that while signature-based detection is highly effective against known threats, it has some limitations. Which of the following BEST describes a limitation of signature-based detection in an IPS?

a)

It might not detect zero-day exploits.

b)

It automatically updates with behavioral patterns of users.

c)

It requires substantial network bandwidth to operate.

d)

It encrypts network traffic to hide malicious signatures.

79.

Travid is evaluating an attack that has occurred on his organization's system. He sees that the attacker entered a lot of data into the the area of memory in the API that temporarily stores user input. What type of attack did Travid discover?

a)

Memory leak

b)

Memory fragmentation

c)

Buffer underflow

d)

Buffer overflow

80.

What is the purpose of a security analyst doing due diligence in the vendor selection process?

a)

To assess the vendor's ability to provide the goods or services when they have promised

b)

To compare multiple vendors' suppliers to ensure they are all diligent in analyzing their own supply chains.

c)

To ensure that the chosen vendor is the best choice among the list of possible vendors

d)

To ensure that the vendor's practices align with the organization's requirements

81.

Which of the following are hardware issues that result from products that are no longer being made or supported, but are still usable?

a)

Hardware cloning

b)

Legacy vulnerability

c)

Hardware tampering

d)

End-of-life vulnerability

82.

A drone manufacturer employs a real-time operating system (RTOS) to ensure timely task executions. While optimizing for real-time performance, which of the following security concerns might arise?

a)

Overhead from virtualization.

b)

Inadequate buffer overflow protections.

c)

Lack of legacy protocol support.

d)

Uncontrolled cloud access.

83.

Lexicon, an AI company, wants to implement a security measure to identify and evaluate potential threats to their systems and networks. Which of the following is an example of a managerial security control that the company could implement?

a)

Intrusion detection system

b)

Firewall

c)

Security guards

d)

Risk assessments

84.

As a security analyst, you are reviewing application logs while investigating a suspected breach. Which of the following pieces of information is NOT typically documented in the application log data?

a)

Timestamps of application activity.

b)

The physical location of the user accessing the application.

c)

User IDs related to specific application transactions.

d)

Server IP address where the application is hosted.

85.

Kelly Innovations LLC wants to implement a network appliance that focuses on filtering traffic based on source and destination IP addresses, and port numbers. Which layer of the OSI model is this appliance primarily operating at?

a)

Layer 3

b)

Layer 2

c)

Layer 5

d)

Layer 4

86.

Which method is used for the authentication process used in WPA2 with PSK?

a)

Using a passphrase to generate a pairwise master key (PMK).

b)

QR codes for client device configuration.

c)

Password Authenticated Key Exchange (PAKE).

d)

Dragonfly handshake with a MAC address hash.

87.

Which of the following BEST describes the primary purpose of archiving as a method to bolster security monitoring?

a)

To provide historical insights into security incidents for future investigations.

b)

To analyze real-time threats and mitigate them instantly.

c)

To maintain compliance with regulations without needing long-term data storage.

d)

To provide an external backup in case of system crashes

88.

Your organization is implementing deception controls within its cloud infrastructure to detect unauthorized access and malicious behavior. Identify the correct deception technology for each implementation.

A database server running PostgreSQL with intentionally weak authentication that logs all connection attempts and queries.

a)

Honeypot

b)

Honeynet

c)

Honeyfile

d)

Honeytoken

89.

Your organization is implementing deception controls within its cloud infrastructure to detect unauthorized access and malicious behavior. Identify the correct deception technology for each implementation.

A fabricated customer database record with a unique email address that triggers alerts when contacted or exported.

a)

Honeynet

b)

Honeypot

c)

Honeyfile

d)

Honeytoken

90.

Your organization is implementing deception controls within its cloud infrastructure to detect unauthorized access and malicious behavior. Identify the correct deception technology for each implementation.

Multiple AWS EC2 instances configured as a e-commerce platform with web servers, APIs, and databases on an isolated VPC.

a)

Honeynet

b)

Honeypot

c)

Honeyfile

d)

Honeytoken

91.

Your organization is implementing deception controls within its cloud infrastructure to detect unauthorized access and malicious behavior. Identify the correct deception technology for each implementation.

A Word document named merger_acquisition_plans.docx stored in the legal department's cloud storage.

a)

Honeynet

b)

Honeypot

c)

Honeyfile

d)

Honeytoken

92.

Consider the following terms associated with various social engineering attacks. Match each attack with the technique being used.

A user accidentally enters 'amaz0n.com' instead of 'amazon.com' and lands on a fake shopping site that looks identical to the legitimate retailer to capture their login credentials.

a)

Pretexting

b)

Impersonation

c)

Misinformation

d)

Typosquatting

93.

Consider the following terms associated with various social engineering attacks. Match each attack with the technique being used.

An attacker carefully creates a story about being a new employee who lost their badge on the first day to gain access to the building.

a)

Pretexting

b)

Impersonation

c)

Misinformation

d)

Typosquatting

94.

Consider the following terms associated with various social engineering attacks. Match each attack with the technique being used.

An attacker wearing a delivery uniform and carrying packages tailgates an employee into a secure building by claiming to have a delivery for the third floor.

a)

Pretexting

b)

Impersonation

c)

Misinformation

d)

Typosquatting

95.

Consider the following terms associated with various social engineering attacks. Match each attack with the technique being used.

Attackers spread false rumors on social media claiming a company's banking system was breached to cause its customers to panic and call support lines where attackers pose as help desk agents.

a)

Pretexting

b)

Impersonation

c)

Misinformation

d)

Typosquatting

96.

Which NIST Cybersecurity Framework implementation tier reflects an organization that adapts practices based on lessons learned and predictive indicators?

a)

a) Tier 1: Partial

b)

b) Tier 2: Risk‑Informed

c)

c) Tier 3: Repeatable

d)

d) Tier 4: Adaptive

97.

In a Zero Trust architecture, what component makes the decision to allow or deny access after evaluating policy and context?

a)

a) Policy Enforcement Point (PEP)

b)

b) Policy Decision Point/Engine (PDP/PE)

c)

c) Subject

d)

d) Cloud broker

98.

Which CVSS base metric describes whether exploitation requires user action?

a)

a) Attack Vector

b)

b) Attack Complexity

c)

c) Privileges Required

d)

d) User Interaction

99.

Who is primarily responsible for determining the purposes and means of processing personal data in an enterprise?

a)

a) Data Processor

b)

b) Data Custodian

c)

c) Data Controller

d)

d) Privacy Officer

100.

Which control BEST prevents unapproved software from running on endpoints?

a)

a) Blacklisting

b)

b) Application allow‑listing

c)

c) EDR

d)

d) Anti‑virus signatures

101.

What is the correct order of volatility during evidence collection?

a)

a) Backups → RAM → CPU cache → swap

b)

b) CPU cache → RAM → swap/temp → disk → remote logs → backups

c)

c) RAM → CPU cache → disk → backups

d)

d) Disk → RAM → CPU cache → backups

102.

Which statement BEST reflects the cloud shared‑responsibility model for SaaS?

a)

a) Customer manages OS hardening; provider manages data.

b)

b) Customer manages data and identities; provider manages app/OS/hardware/DC.

c)

c) Customer manages hypervisor; provider manages data.

d)

d) Customer manages physical DC; provider manages application.

103.

Which defensive control is specifically designed to stop SQL injection and XSS in HTTP/S traffic?

a)

a) IDS

b)

b) WAF

c)

c) NetFlow

d)

d) EDR

104.

During 802.1X authentication, which role is the network switch or AP performing?

a)

a) Supplicant

b)

b) Authenticator

c)

c) Authentication Server

d)

d) RADIUS client on the server

105.

Which RAID level provides striping with parity that tolerates a single drive failure?

a)

a) RAID 0

b)

b) RAID 1

c)

c) RAID 5

d)

d) RAID 10

106.

Which activity immediately follows containment in the incident response lifecycle?

a)

a) Analysis

b)

b) Eradication

c)

c) Detection

d)

d) Recovery

107.

Which encryption approach is typically used to exchange a session key that then protects bulk data transfer?

a)

a) Pure symmetric encryption only

b)

b) Pure asymmetric encryption only

c)

c) Hybrid: asymmetric to wrap a symmetric key

d)

d) Hashing with HMAC only

108.

Which data‑protection technique replaces sensitive values with reversible placeholders stored in a separate vault?

a)

a) Masking

b)

b) Hashing

c)

c) Tokenization

d)

d) Obfuscation

109.

What SCADA/ICS component directly interfaces with sensors and actuators to control physical processes?

a)

a) HSM

b)

b) PLC

c)

c) SIEM

d)

d) TPM

110.

UEFI Secure Boot prevents execution of untrusted code at boot by validating which item first?

a)

a) Kernel modules only

b)

b) Bootloader and UEFI apps against trusted signature databases

c)

c) Userland services

d)

d) Hypervisor only

111.

Which logging concept MOST improves threat hunting by centralizing events from endpoints, network devices, and apps?

a)

a) Local logs only

b)

b) Log aggregation and SIEM correlation

c)

c) Ad‑hoc CSV exports

d)

d) Packet captures only

112.

Which SDLC practice reduces defects introduced by late security reviews?

a)

a) Big‑bang deployment

b)

b) Shift‑left security integrated into CI/CD

c)

c) Annual pen test only

d)

d) Waterfall with security at the end

113.

Which DLP deployment monitors and controls data copied to USB media on laptops?

a)

a) Network DLP

b)

b) Storage DLP

c)

c) Endpoint DLP

d)

d) Cloud DLP

114.

Kerberos primarily prevents which attack by using time‑stamped authenticators?

a)

a) On‑path SSL stripping

b)

b) Replay attacks

c)

c) DNS cache poisoning

d)

d) SQL injection

115.

Which wireless standard first introduced operation in the 6 GHz band (Wi‑Fi 6E)?

a)

a) 802.11ac

b)

b) 802.11ax

c)

c) 802.11n

d)

d) 802.11a

116.

What is the PRIMARY difference between OAuth 2.0 and OpenID Connect (OIDC)?

a)

a) OAuth provides authentication; OIDC provides authorization.

b)

b) OAuth provides authorization; OIDC adds authentication on top of OAuth.

c)

c) Both are the same protocol with different names.

d)

d) OIDC replaces TLS in transit.

117.

Which backup property specifies how often backups are taken (e.g., hourly vs. daily)?

a)

a) Retention

b)

b) Frequency

c)

c) Recovery Point Objective

d)

d) Recovery Time Objective

118.

Which deception control is a single decoy system designed to attract attackers?

a)

a) Honeytoken

b)

b) Honeyfile

c)

c) Honeypot

d)

d) Honeynet

119.

Which port is used by LDAPS?

a)

a) TCP 389

b)

b) TCP 636

c)

c) UDP 161

d)

d) TCP 995

120.

Which term refers to the acceptable deviation from expected results before management action is required?

a)

a) Risk appetite

b)

b) Risk tolerance

c)

c) Risk threshold

d)

d) Exposure factor