Question 1
Multiple choice
A security engineer needs to implement an MDM solution that complies with the corporate mobile device policy. The policy states that in order for mobile users to access corporate resources on their devices, the following requirements must be met: 1. Mobile device OSs must be patched up to the latest release. 2. A screen lock must be enabled (passcode or biometric). 3. Corporate data must be removed if the device is reported lost or stolen. Which of the following controls should the security engineer configure? (Choose two.)
-
A
-
B
-
C
-
D
-
E
-
F
Reveal answer details
Close answer details
Correct answersC, D
ExplanationIf a mobile device does not meet the policy requirements, such as having an outdated OS or not being able to enable a screen lock, it should not be allowed access to corporate resources until it meets these requirements. to the point "posturing" becomes particularly relevant and first priority. Posturing, as part of a Mobile Device Management (MDM) solution, can assess the compliance of mobile devices with the corporate security policy. If a device is found to be non-compliant (e.g., due to an outdated OS or lack of a screen lock), the MDM solution can restrict or deny access to corporate resources until the device is brought into compliance. Posturing: Use posturing checks to verify that mobile devices comply with the policy's requirements, such as having an up-to-date OS and enabling a screen lock.
A security analyst is evaluating the risks of authorizing multiple security solutions to collect data from the company's cloud environment. Which of the following is an immediate consequence of these integrations?
-
A
Non-compliance with data sovereignty rules
-
B
Loss of the vendor's interoperability support
-
C
Mandatory deployment of a SIEM solution
-
D
Increase in the attack surface
Reveal answer details
Close answer details
Correct answerD
ExplanationWhile Non-compliance with data sovereignty rules is an implication of having multiple cloud providers at DIFFERENT countries, this is not specified in the question, besides, they are security solutions, which typically means they will not collect any kind of PII, PHI, SPI
A commercial cyber-threat intelligence organization observes IoCs across a variety of unrelated customers. Prior to releasing specific threat intelligence to other paid subscribers, the organization is MOST likely obligated by contracts to:
-
A
perform attribution to specific APTs and nation-state actors.
-
B
anonymize any PII that is observed within the IoC data.
-
C
add metadata to track the utilization of threat intelligence reports.
-
D
assist companies with impact assessments based on the observed data
Reveal answer details
Close answer details
Which of the following policies establishes rules to measure third-party work tasks and ensure deliverables are provided within a specific time line?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
The Chief Information Security Officer is concerned about employees using personal email rather than company email to communicate with clients and sending sensitive business information and PII. Which of the following would be the BEST solution to install on the employees' workstations to prevent information from leaving the company's network?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Which of the following would be the BEST way to analyze diskless malware that has infected a VDI?
-
A
Shut down the VDI and copy off the event logs.
-
B
Take a memory snapshot of the running system.
-
C
Use NetFlow to identify command-and-control IPs.
-
D
Run a full on-demand scan of the root volume.
Reveal answer details
Close answer details
Correct answerB
ExplanationThe best way to analyze diskless malware that has infected a VDI would be to take a memory snapshot of the running system. This would capture the state of the system's memory at the time the snapshot was taken, including any malware that may be present in memory. This would allow analysts to examine the malware without running the risk of infecting other systems or allowing the malware to continue operating. Additionally, taking a memory snapshot would allow analysts to examine the malware without shutting down the VDI, which could disrupt other users and potentially cause data loss. Using NetFlow to identify command-and-control IPs and running a full on-demand scan of the root volume would not be as effective in analyzing diskless malware, as they would not provide direct access to the malware itself. Copying off the event logs would also not be as effective, as they may not contain detailed information about the malware.
A company was compromised, and a security analyst discovered the attacker was able to get access to a service account. The following logs were discovered during the investigation:  Which of the following MOST likely would have prevented the attacker from learning the service account name?
-
A
-
B
-
C
Forward web server logs to a SIEM
-
D
Reveal answer details
Close answer details
A user enters a username and a password at the login screen for a web portal. A few seconds later the following message appears on the screen: Please use a combination of numbers, special characters, and letters in the password field. Which of the following concepts does this message describe?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerA
ExplanationPassword complexity - is the method that obligate users to use passwords this some characteristics.
Which of the following best describes the process of adding a secret value to extend the length of stored passwords?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 10
Single choice
Which of the following would BEST provide a systems administrator with the ability to more efficiently identify systems and manage permissions and policies based on location, role, and service level?
-
A
Standard naming conventions
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerA
ExplanationQuoting from the official guide below. A standard naming convention for hardware assets, and for digital assets such as accounts and virtual machines, makes the environment more consistent. This means that errors are easier to spot and that it is easier to automate through scripting. The naming strategy should allow administrators to identify the type and function of any particular resource or location at any point in the CMDB or network directory. Each label should conform to rules for host and DNS names.
Question 11
Single choice
A public relations team will be taking a group of guest on a tour through the facility of a large e-commerce company. The day before the tour, the company sends out an email to employees to ensure all whiteboars are cleaned and all desks are cleared. The company is MOST likely trying to protect against.
-
A
Loss of proprietary information
-
B
Damage to the company's reputation
-
C
-
D
Reveal answer details
Close answer details
Correct answerA
ExplanationIn the context of information security, social engineering is the psychological manipulation of people into performing actions or divulging confidential information think phishing, spoofing. That is not being demonstrated in this question. The company is protecting themselves from loss of proprietary information by clearing it all out. so that if anyone in the tour is looking to take it they will be out of luck
Question 12
Single choice
An organization recently recovered from a data breach. During the root cause analysis, the organization determined the source of the breach to be a personal cell phone that had been reported lost. Which of the following solutions should the organization implement to reduce the likelihood of future data breaches?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerA
ExplanationD)DLP won't prevent data being recovered from a stolen/lost phone. A) MDM would have the data encrypted or the ability to have it wiped remotely.
Question 13
Single choice
A technician was dispatched to complete repairs on a server in a data center. While locating the server, the technician entered a restricted area without authorization. Which of the following security controls would BEST prevent this in the future?
-
A
Use appropriate signage to mark all areas.
-
B
Utilize cameras monitored by guards.
-
C
Implement access control vestibules.
-
D
Enforce escorts to monitor all visitors.
Reveal answer details
Close answer details
Correct answerC
ExplanationAn access control vestibule, or mantrap, is a physical access control system designed to prevent unauthorized individuals from following authorized individuals into facilities with controlled access. This question is asking for a way to prevent physical access to restricted area and this method would address this.
Question 14
Single choice
An engineer wants to access sensitive data from a corporate-owned mobile device. Personal data is not allowed on the device. Which of the following MDM configurations must be considered when the engineer travels for business?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerA
Explanation" access sensitive data from a corporate-owned mobile device" screen locks is MORE important that geofencing in this case..
Question 15
Single choice
A security engineer is installing a WAF to protect the company's website from malicious web requests over SSL. Which of the following is needed to meet the objective?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerB
ExplanationWAF can only block abnormal traffic by filtering the plaintext data.
Question 16
Single choice
A security researcher has aferted an organization that is sensitive user data was found for sale on a website. Which of the following should the organization use to inform the affected partes?
-
A
An incident response plan
-
B
-
C
A business continuity plan
-
D
Reveal answer details
Close answer details
Question 17
Single choice
A security analyst is reviewing application logs to determine the source of a breach and locates the following log:  Which Of the following has been observed?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerC
ExplanationSQLi (SQL injection) has been observed. SQL injection is a type of cyber attack that involves injecting malicious code into a database through a vulnerable web application. The malicious code is typically designed to manipulate or extract data from the database, allowing the attacker to gain unauthorized access to sensitive information. The log provided in the question appears to be a URL for a login page, with a string of text appended to the end. This string includes the text "or '1'1='1", which is a common syntax used in SQL injection attacks. This indicates that an SQL injection attack may have been attempted or successfully carried out against the website.
Question 18
Single choice
Server administrators want to configure a cloud solution so that computing memory and processor usage is maximized most efficiently across a number or virtual servers. They also need to avoid potential dental-of-service situations caused by availability. Which of the following should administrators configure to maximize system availability while efficiently utilizing available computing power?
-
A
Dynamic resource allocation
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerA
ExplanationTo maximize system availability and efficiently utilize available computing power, administrators should configure dynamic resource allocation. Dynamic resource allocation is a technique that allows a system to automatically adjust the allocation of resources, such as memory and processing power, to different applications or processes in response to changing workloads or conditions. This can help to ensure that computing resources are used efficiently and that the system is able to respond to changes in demand without encountering performance issues or becoming unavailable.
Question 19
Single choice
A security analyst has been tasked with ensuring all programs that are deployed into the enterprise have been assessed in a runtime environment. Any critical issues found in the program must be sent back to the developer for verification and remediation. Which of the following BEST describes the type of assessment taking place?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 20
Single choice
Which of the following BEST describes the team that acts as a referee during a penetration-testing exercise?
-
A
-
B
-
C
-
D
-
E
Reveal answer details
Close answer details
Question 21
Single choice
A company is launching a new internet platform for its clients. The company does not want to implement its own authorization solution but instead wants to rely on the authorization provided by another platform. Which of the following is the BEST approach to implement the desired solution?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerC
ExplanationOAuth is an AUTHORIZATION protocol, not an authentication protocol. "Determines what resources a user will be able to access. Twitter/Google/Facebook login on 3rd party sites" - Prof Messer SAML is a secure authentication and authorization system that uses third parties SAML is authentication OAuth is authorization, not authentication SSO is the process PAP is a password-based authentication protocol
DRAG DROP An attack has occurred against a company. INSTRUCTIONS You have been tasked to do the following: Identify the type of attack that is occurring on the network by clicking on the attacker's tablet and reviewing the output. (Answer Area 1) Identify which compensating controls should be implemented on the assets, in order to reduce the effectiveness of future attacks by dragging them to the correct server. (Answer area 2) All objects will be used, but not all placeholders may be filled. Objects may only be used once. If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.   
Reveal answer details
Close answer details
Question 23
Single choice
A security analyst is reviewing computer logs because a host was compromised by malware After the computer was infected it displayed an error screen and shut down. Which of the following should the analyst review first to determine more information?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 24
Single choice
A major political party experienced a server breach. The hacker then publicly posted stolen internal communications concerning campaign strategies to give the opposition party an advantage. Which of the following BEST describes these threat actors?
-
A
-
B
-
C
-
D
Advanced persistent threats
Reveal answer details
Close answer details
Correct answerB
ExplanationComptia's handbook: APT=An attacker's ability to obtain, maintain, and diversify access to network systems using exploits and malware.
Question 25
Single choice
Which of the following conditions impacts data sovereignty?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 26
Single choice
An organization relies on third-party video conferencing to conduct daily business. Recent security changes now require all remote workers to utilize a VPN to corporate resources. Which of the following would BEST maintain high-quality video conferencing while minimizing latency when connected to the VPN?
-
A
Using geographic diversity to have VPN terminators closer to end users
-
B
Utilizing split tunneling so only traffic for corporate resources is encrypted
-
C
Purchasing higher-bandwidth connections to meet the increased demand
-
D
Configuring QoS properly on the VPN accelerators
Reveal answer details
Close answer details
Correct answerB
Explanationhttps://support.zoom.us/hc/en-us/articles/360053610731-VPN-Split-Tunneling-Recommendations
Question 27
Single choice
A user downloaded software from an online forum. After the user installed the software, the security team observed external network traffic connecting to the user's computer on an uncommon port. Which of the following is the most likely explanation of this unauthorized connection?
-
A
The software had a hidden keylogger.
-
B
The software was ransomware.
-
C
The user's computer had a fileless virus.
-
D
The software contained a backdoor.
Reveal answer details
Close answer details
Question 28
Single choice
A network administrator is concerned about users being exposed to malicious content when accessing company cloud applications. The administrator wants to be able to block access to sites based on the AUP. The users must also be protected because many of them work from home or at remote locations, providing on-site customer support. Which of the following should the administrator employ to meet these criteria?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerB
ExplanationWhat is SWG in cyber security? " A secure web gateway (SWG) protects users from web-based threats in addition to applying and enforcing corporate acceptable use policies. Instead of connecting directly to a website, a user accesses the SWG, which is then responsible for connecting the user to the desired website and performing functions such as URL filtering, web visibility, malicious content inspection, web access controls and other security measures." This hits all the points.
Question 29
Single choice
A tax organization is working on a solution to validate the online submission of documents. The solution should be earned on a portable USB device that should be inserted on any computer that is transmitting a transaction securely. Which of the following is the BEST certificate for these requirements?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerA
ExplanationThe best certificate for these requirements would be a user certificate. A user certificate is a digital certificate that is issued to an individual and is used to authenticate the user's identity when accessing a network or system. In this case, the organization could issue a user certificate to each individual who is authorized to submit documents online, and the certificate could be stored on a portable USB device. When the individual inserts the USB device into a computer and initiates a transaction, the user certificate would be used to securely authenticate the user's identity and allow the transaction to be processed. Other types of certificates such as a self-signed certificate, a computer certificate, or a root certificate could potentially be used for these purposes, but a user certificate would be the most appropriate solution in this scenario.
Question 30
Multiple choice
A company has discovered unauthorized devices are using its WiFi network, and it wants to harden the access point to improve security. Which of the following configurations should an analyst enable to improve security? (Choose two.)
-
A
-
B
-
C
-
D
-
E
-
F
Reveal answer details
Close answer details
Correct answersA, F
ExplanationWPA2-PSK: WPA works using discrete modes for enterprise and personal use. The most recent enterprise mode, WPA-EAP, uses a stringent 802.1x authentication. The latest personal mode, WPA-PSK, uses Simultaneous Authentication of Equals (SAE) to create a secure handshake.
Question 31
Single choice
A company wants to enable BYOD for checking email and reviewing documents. Many of the documents contain sensitive organizational information. Which of the following should be deployed first before allowing the use of personal devices to access company data?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerA
ExplanationMDM stands for Mobile Device Management, which is a solution that can be used to manage and secure personal devices that access company data. MDM can enforce policies and rules, such as password protection, encryption, remote wipe, device lock, application control, and more. MDM can help a company enable BYOD (Bring Your Own Device) while protecting sensitive organizational information.
Question 32
Single choice
A security analyst receives an alert from trie company's SIEM that anomalous activity is coming from a local source IP address of 192.168.34.26. The Chief Information Security Officer asks the analyst to block the originating source Several days later, another employee opens an internal ticket stating that vulnerability scans are no longer being performed properly. The IP address the employee provides is 192 168.3426. Which of the following describes this type of alert?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerC
ExplanationTrue Positive: A legitimate attack which triggers to produce an alarm. You have a brute force alert, and it triggers. You investigate the alert and find out that somebody was indeed trying to break into one of your systems via brute force methods. False Positive: An event signalling to produce an alarm when no attack has taken place. You investigate another of these brute force alerts and find out that it was just some user who mistyped their password a bunch of times, not a real attack. False Negative: When no alarm is raised when an attack has taken place. Someone was trying to break into your system, but they did so below the threshold of your brute force attack logic. For example, you set your rule to look for ten failed login in a minute, and the attacker did only 9. The attack occurred, but your control was unable to detect it. True Negative: An event when no attack has taken place and no detection is made. No attack occurred, and your rule didn't make fire.
Question 33
Single choice
A company must ensure sensitive data at rest is rendered unreadable. Which of the following will the company most likely use?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerC
ExplanationEncryption is the process of converting plaintext data into ciphertext using an algorithm and encryption key. It ensures that sensitive data stored at rest (e.g., on hard drives, databases, or storage devices) is rendered unreadable to unauthorized users or attackers. Only those with the appropriate decryption key can transform the ciphertext back into readable plaintext.
Question 34
Single choice
An audit report showed that a former employee saved the following files to an external USB drive before the employee's termination date: ? annual_tax_form.pdf ? encrypted_passwords.db ? team_picture.jpg ? contact_list.db ? human_resources.txt Which of the following could the former employee do to potentially compromise corporate credentials?
-
A
Perform an offline brute-force attack
-
B
Use the files to create a rainbow table.
-
C
-
D
Release a network dictionary attack.
Reveal answer details
Close answer details
Question 35
Single choice
A security analyst has been tasked with finding the maximum amount of data loss that can occur before ongoing business operations would be impacted. Which of the following terms BEST defines this metric?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 36
Single choice
A network engineer and a security engineer are discussing ways to monitor network operations. Which of the following is the BEST method?
-
A
Disable Telnet and force SSH.
-
B
Establish a continuous ping.
-
C
Utilize an agentless monitor
-
D
Enable SNMPv3 With passwords.
Reveal answer details
Close answer details
Question 37
Single choice
The SOC for a large MSSP is meeting to discuss the lessons learned from a recent incident that took much too long to resolve This type of incident has become more common in recent weeks and is consuming large amounts of the analysts' time due to manual tasks being performed. Which of the following solutions should the SOC consider to BEST improve its response time?
-
A
Configure a NIDS appliance using a Switched Port Analyzer
-
B
Collect OSINT and catalog the artifacts in a central repository
-
C
Implement a SOAR with customizable playbooks
-
D
Install a SIEM with community-driven threat intelligence
Reveal answer details
Close answer details
Correct answerC
ExplanationSOAR (Security Orchestration, Automation, and Response) Can use either playbook or runbook. It assists in collecting threat related data from a range of sources and automate responses to low level threats. (frees up some of the CSIRT time)
Question 38
Single choice
An enterprise has hired an outside security firm to conduct penetration testing on its network and applications. The firm has been given all the developer's documentation about the internal architecture. Which of the following best represents the type of testing that will occur?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 39
Single choice
An end user reports a computer has been acting slower than normal for a few weeks, During an investigation, an analyst determines the system 3 sending the users email address and a ten-digit number ta an IP address once a day. The only resent log entry regarding the user's computer is the following:  Which of the following is the MOST likely cause of the issue?
-
A
The end user purchased and installed a PUP from a web browser
-
B
A bot on the computer is brute forcing passwords against a website
-
C
A hacker is attempting to exfiltrate sensitive data
-
D
Ransomware is communicating with a command-and-control server.
Reveal answer details
Close answer details
Question 40
Single choice
A security engineer is working to address the growing risks that shadow IT services are introducing to the organization. The organization has taken a cloud-first approach and does not have an on-premises IT infrastructure. Which of the following would best secure the organization?
-
A
Upgrading to a next-generation firewall
-
B
Deploying an appropriate in-line CASB solution
-
C
Conducting user training on software policies
-
D
Configuring double key encryption in SaaS platforms
Reveal answer details
Close answer details
Question 41
Single choice
An organization has expanded its operations by opening a remote office. The new office is fully furnished with office resources to support up to 50 employees working on any given day. Which of the following VPN solutions would BEST support the new office?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerC
Explanationkey word "expanded its operations" - a new office has been opened that needs to connect to already existing offices.
Question 42
Multiple choice
An organization has been experiencing outages during holiday sales and needs to ensure availability of its point-of-sale systems The IT administrator has been asked to improve both server-data fault tolerance and site availability under high consumer load Which of the following are the BEST options to accomplish this objective? (Select TWO)
-
A
-
B
-
C
-
D
-
E
-
F
Reveal answer details
Close answer details
Question 43
Single choice
A security researcher is using an adversary's infrastructure and TTPs and creating a named group to track those targeted. Which of the following is the researcher MOST likely using?
-
A
-
B
The incident response process
-
C
The Diamond Model of Intrusion Analysis
-
D
Reveal answer details
Close answer details
Question 44
Single choice
An organization recently released a zero-trust policy that will enforce who is able to remotely access certain data. Authenticated users who access the data must have a need to know, depending on their level of permissions. Which of the following is the first step the organization should take when implementing the policy?
-
A
Determine a quality CASB solution.
-
B
Configure the DLP policies by user groups.
-
C
Implement agentless NAC on boundary devices.
-
D
Classify all data on the file servers.
Reveal answer details
Close answer details
Correct answerD
Explanationzero trust is a security strategy that assumes breach and verifies each request as though it originates from an untrusted network 12. A zero trust policy is a set of "allow rules" that specify conditions for accessing certain resources 3. According to one source4, the first step in implementing a zero trust policy is to identify and classify all data and assets in the organization. This helps to determine the level of sensitivity and risk associated with each resource and apply appropriate access controls. Classifying all data on the file servers is the first step in implementing a zero trust policy because it helps to determine the level of sensitivity and risk associated with each resource and apply appropriate access controls. References: Zero Trust implementation guidance | Microsoft Learn
Question 45
Single choice
A network manager is concerned that business may be negatively impacted if the firewall in its datacenter goes offline. The manager would like to implement a high availability pair to:
-
A
ned that business may be negatecrease the mean time between failures.
-
B
remove the single point of failure.
-
C
cut down the mean time to repair,
-
D
reduce the recovery time objective.
Reveal answer details
Close answer details
Question 46
Single choice
A security architect at a large, multinational organization is concerned about the complexities and overhead of managing multiple encryption keys securely in a multicloud provider environment. The security architect is looking for a solution with reduced latency to allow the incorporation of the organization's existing keys and to maintain consistent, centralized control and management regardless of the data location. Which of the following would best meet the architect's objectives?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerC
ExplanationHSMaaS (Hardware Security Module as a Service): HSMaaS is a cloud service that offers dedicated cryptographic processing and key management. It's designed to protect sensitive data and allows for centralized management and storage of encryption keys. By using HSMaaS, organizations can achieve the required key management across multicloud environments while maintaining centralized control.
Question 47
Single choice
A security analyst needs to propose a remediation plan for each item in a risk register. The item with the highest priority requires employees to have separate logins for SaaS solutions and different password complexity requirements for each solution. Which of the following implementation plans will most likely resolve this security issue?
-
A
Creating a unified password complexity standard
-
B
Integrating each SaaS solution with the identity provider
-
C
Securing access to each SaaS by using a single wildcard certificate
-
D
Configuring geofencing on each SaaS solution
Reveal answer details
Close answer details
Question 48
Single choice
A Chief Information Officer is concerned about employees using company-issued laptops lo steal data when accessing network shares. Which of the following should the company Implement?
-
A
-
B
-
C
-
D
-
E
Reveal answer details
Close answer details
Correct answerA
ExplanationChmod removes the setuido permission, that is, it removes the S bit. Setuido is the specific permission, but it is removed with Chmod. https://www.cbtnuggets.com/blog/technology/system-admin/linux-file-permissions-understanding-setuid-setgid-and-the-sticky-bit
Question 49
Single choice
Which of the following prevents an employee from seeing a colleague who is visting an inappropriate website?
-
A
-
B
-
C
-
D
Separation of duties policy
Reveal answer details
Close answer details
Correct answerC
Explanation"Which of the following prevents an employee from visiting an inappropriate website".....which would somewhat make more sense. An acceptable use policy (AUP) is a document that outlines the rules and restrictions employees must follow in regard to the company's network, software, internet connection and devices. The employee shouldn't access the inappropriate website as it would go against proper use of the company network. ================ Helpful Info I Guess NDA (Non-disclosure agreement) - a binding contract between two or more parties that prevents sensitive information from being shared with others. Separation of Duty - refers to the principle that no user should be given enough privileges to misuse the system on their own. Job rotation - A concept that has employees rotate through different jobs to learn the procedures and processes in each. From a security perspective, job rotation helps to prevent or expose dangerous shortcuts or even fraudulent activity.
Question 50
Single choice
A customer service representative reported an unusual text message that was sent to the help desk. The message contained an unrecognized invoice number with a large balance due and a link to click for more details. Which of the following BEST describes this technique?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerD
ExplanationPretty straightforward. Smishing, a portmanteau of SMS and phishing, is a specific type of phishing done via text messaging, and it's commonly used to orchestrate invoice scams or otherwise harvest credentials.
Question 51
Single choice
Which of the following is an example of transference of risk?
-
A
-
B
Patching vulnerable servers
-
C
Retiring outdated applications
-
D
Application owner risk sign-off
Reveal answer details
Close answer details
Question 52
Single choice
The Chief information Security Officer has directed the security and networking team to retire the use of shared passwords on routers and switches. Which of the following choices BEST meets the requirements?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 53
Single choice
A company has a flat network in the cloud. The company needs to implement a solution to segment its production and non-production servers without migrating servers to a new network. Which of the following solutions should the company implement?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 54
Single choice
A multinational organization that offers web-based services has datacenters that are located only in the United States; however, a large number of its customers are in Australia, Europe, and China. Payments for services are managed by a third party in the United Kingdom that specializes in payment gateways. The management team is concerned the organization is not compliant with privacy laws that cover some of its customers. Which of the following frameworks should the management team follow?
-
A
Payment Card Industry Data Security Standard
-
B
Cloud Security Alliance Best Practices
-
C
ISO/IEC 27032 Cybersecurity Guidelines
-
D
General Data Protection Regulation
Reveal answer details
Close answer details
Correct answerD
ExplanationFor example, the GDPR does not apply to US ( in this case Datacenters) data subjects, but it does apply to US companies that collect or process personal data from people in countries of the EU.And in this case, there are a lof of clients in Europe, China and Australia.
Question 55
Single choice
Which of the following terms should be included in a contract to help a company monitor the ongoing security maturity of a new vendor?
-
A
A right-to-audit clause allowing for annual security audits
-
B
Requirements for event logs to be kept for a minimum of 30 days
-
C
Integration of threat intelligence in the company's AV
-
D
A data-breach clause requiring disclosure of significant data loss
Reveal answer details
Close answer details
Correct answerA
ExplanationThe right-to-audit clause in a contract would enable the company to perform annual security audits on the vendor. This clause gives the company the ability to monitor the ongoing security practices and maturity of the vendor. By conducting security audits, the company can assess the vendor's compliance with security requirements, identify potential security risks, and ensure that the vendor is implementing appropriate security measures. This is a common practice to maintain oversight and ensure security alignment between the company and its vendors.
Question 56
Single choice
Which of the following environment utilizes dummy data and is MOST to be installed locally on a system that allows to be assessed directly and modified easily wit each build?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerD
ExplanationA development environment is essentially what is on the development team's computers. It's where the developers are writing their code, making code updates, and where all their commits and branches exist. The development environment does not affect what the end user sees. Instead, it allows development to try out new features and updates before pushing them forward to deployment. A lot of preliminary testing is done at this point before moving to the next environment - the stage environment. https://www.pagerduty.com/resources/learn/what-is-production-environment/
Question 57
Single choice
A security engineer obtained the following output from a threat intelligence source that recently performed an attack on the company's server:  Which of the following BEST describes this kind of attack?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerA
ExplanationThis cannot be Directory Traversal. The key to a traversal attack is the presence of ".../etc/...." on the path.
Question 58
Single choice
A financial organization has adopted a new secure, encrypted document-sharing application to help with its customer loan process. Some important PII needs to be shared across this new platform, but it is getting blocked by the DLP systems. Which of the following actions will BEST allow the PII to be shared with the secure application without compromising the organization's security posture?
-
A
Configure the DLP policies to allow all PII
-
B
Configure the firewall to allow all ports that are used by this application
-
C
Configure the antivirus software to allow the application
-
D
Configure the DLP policies to whitelist this application with the specific PII
-
E
Configure the application to encrypt the PII
Reveal answer details
Close answer details
Question 59
Single choice
A Chief Security Officer (CSO) was notified that a customer was able to access confidential internal company files on a commonly used file-sharing service. The file-sharing service is the same one used by company staff as one of its approved third-party applications. After further investigation, the security team determines the sharing of confidential files was accidental and not malicious. However, the CSO wants to implement changes to minimize this type of incident from reoccurring but does not want to impact existing business processes. Which of the following would BEST meet the CSO's objectives?
-
A
-
B
-
C
-
D
Virtual network segmentation
-
E
Reveal answer details
Close answer details
Question 60
Single choice
A small company that does not have security staff wants to improve its security posture. Which of the following would BEST assist the company?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerA
ExplanationRead this article : https://doubleoctopus.com/blog/general/small-business-security-to-mssp-or-not-to-mssp/ Small businesses must afford MSSP model (or risk shutting the business off). To me , SOAR deos not make sense with (NO security staff). SOAR is a product to be procured. This leaves me with this question , Who would take the ownership of the product evalutaion, configuration, operations etc.. ? you cannot just plug&play a SOAR
Question 61
Single choice
A user forwarded a suspicious email to the security team, Upon investigation, a malicious URL was discovered. Which of the following should be done FIRST to prevent other users from accessing the malicious URL?
-
A
Configure the web content filter for the web address.
-
B
Report the website to threat intelligence partners
-
C
Set me SIEM to alert for any activity to the web address.
-
D
Send out a corporate communication to warn all users Of the malicious email.
Reveal answer details
Close answer details
Correct answerA
ExplanationWeb content filtering is the practice of blocking access to web content that may be deemed offensive, inappropriate, or even dangerous. Better to just block out the URL since we already know its malicious now and notify later since you don't know how many other people received the email.
Question 62
Single choice
The Chief Information Secunty Officer came across a news arbcle outining a mechan'sm thal allows certan OS passwords to be bypassed The security team was then tasked with determining which method could be used to prevent data loss in the corporate environment in case an attacker bypasses authentication Which of the following will accomplish this objective?
-
A
-
B
Proper patch management protocols
-
C
-
D
Reveal answer details
Close answer details
Question 63
Single choice
Which of the following control types is focused primarily on reducing risk before an incident occurs?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerA
Explanation"Preventive controls act before an event, preventing it from advancing". Deterrent - "acts to discourage the attacker by reducing the likelhood of success from the perspective of the attacker".
Question 64
Single choice
Audit logs indicate an administrative account that belongs to a security engineer has been locked out multiple times during the day. The security engineer has been on vacation (or a few days). Which of the following attacks can the account lockout be attributed to?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerB
ExplanationThe account lockout can be attributed to a brute-force attack. A brute-force attack is a type of attack where an attacker attempts to guess a user's password by continually trying different combinations of characters. In this case, it is likely that the security engineer's account was locked out due to an attacker attempting to guess their password. Backdoor, rootkit, and Trojan attacks are not relevant in this scenario.
Question 65
Multiple choice
A security analyst is performing a packet capture on a series of SOAP HTTP requests for a security assessment. The analyst redirects the output to a file After the capture is complete, the analyst needs to review the first transactions quickly and then search the entire series of requests for a particular string Which of the following would be BEST to use to accomplish the task? (Select TWO).
-
A
-
B
-
C
-
D
-
E
-
F
-
G
Reveal answer details
Close answer details
Correct answersA, C
ExplanationA - "analyst needs to review the first transactions quickly" C - "search the entire series of requests for a particular string" To simplify The head command by default will display the first 10 lines of a file... which is correct! The grep command will search anything you want... which of course is correct! Now... Tcpdump is used to capture traffic (sniffing) or read PCAP files. The tail command by default will display the last 10 files. The curl tool is used to download/read resources from the web (HTML, text, files... etc.)/ OpenSSL is ... SSL related. dd is for binary business and copy files/drives (generally speaking).
Question 66
Single choice
A security operations technician is searching the log named /vax/messages for any events that were associated with a workstation with the IP address 10.1.1.1. Which of the following would provide this information?
-
A
cat /var/messages | grep 10.1.1.1
-
B
grep 10.1.1.1 | cat /var/messages
-
C
grep /var/messages | cat 10.1.1.1
-
D
cat 10.1.1.1 | grep /var/messages
Reveal answer details
Close answer details
Correct answerA
Explanationthe cat command reads the file and streams its content to standard output. The | symbol connects the output of the left command with the input of the right command. The grep command returns all lines that match the regex. The cut command splits each line into fields based on a delimiter and extracts a specific field.
Question 67
Single choice
Which of the following is most likely associated with introducing vulnerabilities on a corporate network by the deployment of unapproved software?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerD
ExplanationShadow IT refers to information technology systems used within organizations without explicit organizational approval.
Question 68
Single choice
A security analyst is reviewing information regarding recent vulnerabilities. Which of the following will the analyst MOST likely consult to validate which platforms have been affected?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerD
ExplanationCVE as answer doesn't make sense to me, unless I'm reading/interpreting it in a wrong way, here's why: If tha analyst is reviwring info regarding recent vulnerabilities, that means he's aware of the vuln, so why bother to look into the CVE at the first place? The questions goes "...to validate **which platforms have been affected**", how can you possibly know which platforms have been affected in your environment just looking at an external informational database like CVE/ CVSS? You need some sort of internal tool that will log which platform/devices are likely vulnerable to a given CVE, and a SIEM solution has definitely all the requirements to give you that information.
Question 69
Single choice
A systems administrator needs to install the same X.509 certificate on multiple servers. Which of the following should the administrator use?
-
A
-
B
A self-signed certificate
-
C
-
D
An extended validation certificate
Reveal answer details
Close answer details
Question 70
Single choice
A large enterprise has moved all its data to the cloud behind strong authentication and encryption. A sales director recently had a laptop stolen, and later, enterprise data was found to have been compromised from a local database. Which of the following was the MOST likely cause?
-
A
-
B
-
C
-
D
-
E
Reveal answer details
Close answer details
Correct answerA
ExplanationAnother example of unintentional insider threat is the concept of shadow IT, where users purchase or introduce computer hardware or software to the workplace without the sanction of the IT department and without going through a procurement and security analysis process. The problem of shadow IT is exacerbated by the proliferation of cloud services and mobile devices, which are easy for users to obtain. Shadow IT creates a new unmonitored attack surface for malicious adversaries to exploit. While SQL Injection might be one way that enterprise data from the local database was compromised, an attacker could simple have hacked into the person machine and opened up the local database to steal the data. SQL Injection is possible, but is not MOST Likely. You need to ask the question: If the enterprise has moved everything into the cloud, then the only reason there is a local database on the person's machine is because they installed the database. They installed an application on their local machine when they should have been using an application on the company's cloud. That, in its definition, is shadow IT.
Question 71
Single choice
A company labeled some documents with the public sensitivity classification. This means the documents can be accessed by:
-
A
employees of other companies and the press
-
B
all members of the department that created the documents
-
C
only the company's employees and those listed in the document
-
D
only the individuate listed in the documents
Reveal answer details
Close answer details
Correct answerA
ExplanationA company labeled some documents with the public sensitivity classification means that the documents can be accessed by employees of other companies and the press. The public sensitivity classification indicates that the documents are intended for public access and can be shared with a wide audience, including employees of other companies and members of the media. This classification is often used for documents that contain information that is not sensitive or confidential and that can be shared freely with the public. In contrast, documents with other sensitivity classifications, such as "confidential" or "private," may have more restricted access and may only be shared with a limited group of individuals, such as employees of the company or those listed in the document.
Question 72
Single choice
An organization has developed an application that needs a patch to fix a critical vulnerability In which of the following environments should the patch be deployed LAST?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerD
ExplanationProduction should be the last place where to apply patches as you have already tested properly
Question 73
Single choice
A company's bank has reported that multiple corporate credit cards have been stolen over the past several weeks. The bank has provided the names of the affected cardholders to the company's forensics team to assist in the cyber-incident investigation. An incident responder learns the following information: The timeline of stolen card numbers corresponds closely with affected users making Internet-based purchases from diverse websites via enterprise desktop PCs. All purchase connections were encrypted, and the company uses an SSL inspection proxy for the inspection of encrypted traffic of the hardwired network. Purchases made with corporate cards over the corporate guest WiFi network, where no SSL inspection occurs, were unaffected. Which of the following is the MOST likely root cause?
-
A
HTTPS sessions are being downgraded to insecure cipher suites
-
B
The SSL inspection proxy is feeding events to a compromised SIEM
-
C
The payment providers are insecurely processing credit card charges
-
D
The adversary has not yet established a presence on the guest WiFi network
Reveal answer details
Close answer details
Correct answerB
ExplanationThe purchases are only getting affected from systems where SSL inspection is occurring. Its fine on all others. IT cant be a HTTPS downgrade as that wouldn't be specific to the SSL inspection.
Question 74
Single choice
An enterprise needs to keep cryptographic keys in a safe manner. Which of the following network appliances can achieve this goal?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerA
Explanation"A hardware security module (HSM) is a physical computing device that safeguards and manages digital keys" References: https://www.techtarget.com/searchsecurity/definition/hardware-security-module-HSM
Question 75
Single choice
An analyst needs to identify the applications a user was running and the files that were open before the user's computer was shut off by holding down the power button. Which of the following would MOST likely contain that information?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 76
Single choice
The Chief Technology Officer of a local college would like visitors to utilize the school's Wi-Fi but must be able to associate potential malicious activity to a specific person. Which of the following would best allow this objective to be met?
-
A
Requiring all new. on-site visitors to configure their devices to use WPS
-
B
Implementing a new SSID for every event hosted by the college that has visitors
-
C
Creating a unique PSK for every visitor when they arrive at the reception area
-
D
Deploying a captive portal to capture visitors' MAC addresses and names
Reveal answer details
Close answer details
Correct answerD
ExplanationDeploying a captive portal to capture visitors' MAC addresses and names: A captive portal forces all users trying to access the Internet over Wi-Fi to view a special web page and take action, usually authentication or acceptance of terms and conditions, before they can get connected. In this scenario, by capturing visitors' names along with their device's MAC address, the college can associate network activity with specific individuals.
Question 77
Single choice
A security administrator would like to ensure all cloud servers will have software preinstalled for facilitating vulnerability scanning and continuous monitoring. Which of the following concepts should the administrator utilize?
-
A
-
B
-
C
Reveal answer details
Close answer details
Question 78
Single choice
Which of the following is the FIRST environment in which proper, secure coding should be practiced?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerB
ExplanationThe developer has to start writing secure code from beginning itself. Which will then be tested, staged and finally production
Question 79
Multiple choice
Which of the following are the MOST likely vectors for the unauthorized or unintentional inclusion of vulnerable code in a software company's final software releases? (Choose two.)
-
A
-
B
Use of penetration-testing utilities
-
C
-
D
Included third-party libraries
-
E
-
F
Outdated anti-malware software
Reveal answer details
Close answer details
Correct answersD, E
ExplanationE. Vendors/supply chain: Supply chain attacks, where attackers compromise vendors or suppliers to introduce vulnerabilities into the software supply chain, are a significant concern. This can result in vulnerable code making its way into the final software releases. D. Included third-party libraries: Third-party libraries are often used in software development to expedite the process. However, if these libraries contain vulnerabilities or are not kept up-to-date, they can introduce security flaws into the software.
Question 80
Single choice
Which of the following stores data directly on devices with limited processing and storage capacity?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 81
Single choice
DDoS attacks are causing an overload on the cluster of cloud servers. A security architect is researching alternatives to make the cloud environment respond to load fluctuation in a cost-effective way. Which of the following options BEST fulfils the architect's requirements?
-
A
An orchestration solution that can adjust scalability of cloud assets
-
B
Use of multipath by adding more connections to cloud storage
-
C
Cloud assets replicated on geographically distributed regions
-
D
An on-site backup that is deployed and only used when the load increases
Reveal answer details
Close answer details
Correct answerA
ExplanationScaling cloud infrastructures can experience lag during the periods of high activity, where other assets have to either be added, or become active. This is the compromise for a cost-effective solution that scales. The company could go for a system that is absolutely overkill on assets at all times, in preparation for those brief peak moments. But this is expensive, and unlikely to be taken by most companies. Only case you would want to use one of these is if you have a sensitive or critical service that MUST remain online. Stock exchange servers, military servers, bank servers, etc. come to mind for this criteria.
Question 82
Single choice
A recent security breach exploited software vulnerabilities in the firewall and within the network management solution. Which of the following will MOST likely be used to identify when the breach occurred through each device?
-
A
SIEM correlation dashboards
-
B
Firewall syslog event logs
-
C
Network management solution login audit logs
-
D
Bandwidth monitors and interface sensors
Reveal answer details
Close answer details
Correct answerA
ExplanationSIEM could tell when the breach occurred in firewall AND in network management solution
Question 83
Single choice
An attacker replaces a digitally signed document with another version that foes unnoticed. Upon reviewing the document's contents, the author notices some additional verbaige that was not originally in the document but can't validate an integrity issue. Which of the following attacks was used?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 84
Single choice
A security analyst finds a rogue device during a monthly audit of current endpoint assets that are connected to the network. The corporate network utilizes 802.1 X for access control. To be allowed on the network, a device must have a known hardware address, and a valid username and password must be entered in a captive portal. The following is the audit report:  Which of the following is the most likely way a rogue device was allowed to connect?
-
A
A user performed a MAC cloning attack with a personal device.
-
B
A DHCP failure caused an incorrect IP address to be distributed.
-
C
An administrator bypassed the security controls for testing.
-
D
DNS hijacking let an attacker intercept the captive portal traffic.
Reveal answer details
Close answer details
Question 85
Single choice
An end user reports a computer has been acting slower than normal for a few weeks. During an investigation, an analyst determines the system is sending the user's email address and a ten-digit number to an IP address once a day. The only recent log entry regarding the user's computer is the following:  Which of the following is the MOST likely cause of the issue?
-
A
The end user purchased and installed a PUP from a web browser
-
B
A bot on the computer is brute forcing passwords against a website
-
C
A hacker is attempting to exfiltrate sensitive data
-
D
Ransomware is communicating with a command-and-control server
Reveal answer details
Close answer details
Question 86
Single choice
A hospital's administration is concerned about a potential loss of patient data that is stored on tablets. A security administrator needs to implement controls to alert the SOC any time the devices are near exits. Which of the following would BEST achieve this objective?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 87
Single choice
A company wants to restrict emailing of PHI documents. The company is implementing a DLP solution. In order to restrict PHI documents, which of the following should be performed FIRST?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerC
ExplanationClassification is the first step to determine what data contains PHI
Question 88
Single choice
Which of the following is a reason why a forensic specialist would create a plan to preserve data after an incident and prioritize the sequence for performing forensic analysis?
-
A
-
B
Preservation of event logs
-
C
-
D
Compliance with legal hold
Reveal answer details
Close answer details
Correct answerA
ExplanationThe order of volatility is a concept in digital forensics and incident response that refers to the sequence in which different types of data should be preserved or collected during an investigation, based on their likelihood to change or be lost. The general principle is to start with the most volatile data first, as it is more prone to alteration or loss, and then proceed to less volatile data. The order of volatility typically follows a hierarchy from more volatile to less volatile data.
Question 89
Single choice
As part of the lessons-learned phase, the SOC is tasked with building methods to detect if a previous incident is happening again. Which of the following would allow the security analyst to alert the SOC if an event is reoccurring?
-
A
Creating a playbook within the SOAR
-
B
Implementing rules in the NGFW
-
C
Updating the DLP hash database
-
D
Publishing a new CRL with revoked certificates
Reveal answer details
Close answer details
Question 90
Single choice
The Chief Security Officer (CSO) at a major hospital wants to implement SSO to help improve security in the environment and protect patient data, particularly at shared terminals. The Chief Risk Officer (CRO) is concerned that training and guidance have not been provided to frontline staff, and a risk analysis has not been performed. Which of the following is the MOST likely cause of the CRO's concerns?
-
A
SSO would simplify username and password management, making it easier for hackers to guess accounts.
-
B
SSO would reduce password fatigue, but staff would still need to remember more complex passwords.
-
C
SSO would reduce the password complexity for frontline staff.
-
D
SSO would reduce the resilience and availability of systems if the identity provider goes offline.
Reveal answer details
Close answer details
Question 91
Single choice
Which of the following describes business units that purchase and implement scripting software without approval from an organization's technology Support staff?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerA
Explanationshadow IT is the use of IT-related hardware or software by a department or individual without the knowledge or approval of the IT or security group within the organization 12. Shadow IT can encompass cloud services, software, and hardware. The main area of concern today is the rapid adoption of cloud-based services 1. According to one source3, shadow IT helps you know and identify which apps are being used and what your risk level is. 80% of employees use non-sanctioned apps that no one has reviewed, and may not be compliant with your security and compliance policies.
Question 92
Single choice
A security analyst is working on a project to implement a solution that monitors network communications and provides alerts when abnormal behavior is detected Which of the following is the security analyst MOST likely implementing?
-
A
-
B
-
C
Security orchestration, automation, and response
-
D
Reveal answer details
Close answer details
Correct answerB
Explanation"UEBA is an extension of SIEM where, in addition to observing suspicious network behavior, they also trigger alerts when unusual entity or user behavior is observed"
Question 93
Single choice
A company policy requires third-party suppliers to self-report data breaches within a specific time frame. Which of the following third-party risk management policies is the company complying with?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 94
Single choice
A company is enhancing the security of the wireless network and needs to ensure only employees with a valid certificate can authenticate to the network. Which of the following should the company implement?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerA
ExplanationPEAP stands for Protected Extensible Authentication Protocol, which is a protocol that can provide secure authentication for wireless networks. PEAP can use certificates to authenticate the server and the client, or only the server. PEAP can also use other methods, such as passwords or tokens, to authenticate the client. PEAP can ensure only employees with a valid certificate can authenticate to the network.
Question 95
Single choice
A security administrator needs to provide secure access to internal networks for external partners. The administrator has given the PSK and other parameters to the third-party security administrator. Which of the following is being used to establish this connection?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerC
ExplanationIPSec is a protocol suite that provides secure communication over IP networks. It uses encryption, authentication, and integrity mechanisms to protect data from unauthorized access or modification. IPSec can operate in two modes: transport mode and tunnel mode. In tunnel mode, IPSec can create a virtual private network (VPN) between two endpoints, such as external partners and internal networks. To establish a VPN connection, IPSec requires a pre-shared key (PSK) or other parameters to negotiate the security association. References: https://www.comptia.org/content/guides/what-is-vpn
Question 96
Single choice
A company is providing security awareness training regarding the importance of not forwarding social media messages from unverified sources. Which of the following risks would this training help to prevent?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerA
ExplanationHoax A hoax is a falsehood deliberately fabricated to masquerade as the truth. It is distinguishable from errors in observation or judgment, rumors, urban legends, pseudo sciences, and April Fools' Day events that are passed along in good faith by believers or as jokes. Identity theft Identity theft occurs when someone uses another person's personal identifying information, like their name, identifying number, or credit card number, without their permission, to commit fraud or other crimes. The term identity theft was coined in 1964. Identity fraud (also known as identity theft or crime) involves someone using another individual's personal information without consent, often to obtain a benefit. Credential Harvesting Credential Harvesting (or Account Harvesting) is the use of MITM attacks, DNS poisoning, phishing, and other vectors to amass large numbers of credentials (username / password combinations) for reuse.
Question 97
Single choice
An organization wants to implement a biometric system with the highest likelihood that an unauthorized user will be denied access. Which of the following should the organization use to compare biometric solutions?
-
A
-
B
-
C
-
D
-
E
Reveal answer details
Close answer details
Correct answerD
ExplanationThe Crossover Error Rate (CER) describes the point where the False Reject Rate (FRR) and False Accept Rate (FAR) are equal. CER is also known as the Equal Error Rate (EER). The Crossover Error Rate describes the overall accuracy of a biometric system.
Question 98
Single choice
During a penetration test, a flaw in the internal PKI was exploited to gain domain administrator rights using specially crafted certificates. Which of the following remediation tasks should be completed as part of the cleanup phase?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 99
Single choice
Which of the following corporate policies is used to help prevent employee fraud and to detect system log modifications or other malicious activity based on tenure?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 100
Single choice
A company's help desk has received calls about the wireless network being down and users being unable to connect to it. The network administrator says all access points are up and running. One of the help desk technicians notices the affected users are working in a building near the parking lot. Which of the following is the most likely reason for the outage?
-
A
Someone near the building is jamming the signal.
-
B
A user has set up a rogue access point near the building.
-
C
Someone set up an evil twin access point in the affected area.
-
D
The APs in the affected area have been unplugged from the network.
Reveal answer details
Close answer details
Correct answerA
ExplanationThe most likely reason for the wireless network outage in the affected building near the parking lot is that someone is jamming the wireless signal. Jamming is a deliberate attempt to disrupt wireless communication by transmitting interference on the same frequency as the wireless network, causing the access points and clients to experience connectivity issues. Jamming can be carried out using various devices that emit radio frequency signals, interfering with the normal operation of wireless devices. This interference prevents legitimate users from connecting to the wireless network and disrupts the communication between access points and clients.
|