Category 81-85
Category 86-90
Category 91-95
Category 96-100
Category 101-105
100

A Chief Information Security Officer (CISO) needs to create a policy set that meets international standards for data privacy and sharing. Which of the following should the CISO read and understand before writing the policies?

 

A. PCI DSS 

B. GDPR 

C. NIST 

D. ISO 31000  

The correct answer is B: GDPR

100

A public relations team will be taking a group of guest on a tour through the facility of a large e-commerce company. The day before the tour, the company sends out an email to employees to ensure all whiteboars are cleaned and all desks are cleared. The company is MOST likely trying to protect against. 

A. Loss of proprietary information 

B. Damage to the company’s reputation 

C. Social engineering 

D. Credential exposure.

Correct answer: C

Social engineering

100

A company has drafted an insider-threat policy that prohibits the use of external storage devices. Which of the following would BEST protect the company from data exfiltration via removable media? 

A. Monitoring large data transfer transactions in the firewall logs 

B. Developing mandatory training to educate employees about the removable media policy 

C. Implementing a group policy to block user access to system files 

D. Blocking removable-media devices and write capabilities using a host-based security tool

Correct answer: D

Blocking removable-media devices and write capabilities using a host-based security tool

100

Which of the following relates to applications and systems that are used within an organization without consent or approval? 

A. Shadow IT 

B. OSINT 

C. Dark web 

D. Insider threats

Correct answer: A

Shadow IT

100

A security administrator needs to create a RAIS configuration that is focused on high read speeds and fault tolerance. It is unlikely that multiple drivers will fail simultaneously. Which of the following RAID configurations should the administration use? 

A. RA1D 0 

B. RAID1 

C. RAID 5 

D. RAID 10  

Correct answer: C

RAID 5

200

A financial organization has adopted a new secure, encrypted document-sharing application to help with its customer loan process. Some important PII needs to be shared across this new platform, but it is getting blocked by the DLP systems. Which of the following actions will BEST allow the PII to be shared with the secure application without compromising the organization’s security posture?

 

A. Configure the DLP policies to allow all PII 

B. Configure the firewall to allow all ports that are used by this application 

C. Configure the antivirus software to allow the application 

D. Configure the DLP policies to whitelist this application with the specific PII 

E. Configure the application to encrypt the PII  

The correct answer is D: Configure the DLP policies to whitelist this application with the specific PII

200

A document that appears to be malicious has been discovered in an email that was sent to a company's Chief Financial Officer (CFO). Which of the following would be BEST to allow a security analyst to gather information and confirm it is a malicious document without executing any code it may contain? 

A. Open the document on an air-gapped network 

B. View the document's metadata for origin clues 

C. Search for matching file hashes on malware websites 

D. Detonate the document in an analysis sandbox

Correct answer: D

Detonate the document in an analysis sandbox

200

A company recently experienced an attack in which a malicious actor was able to exfiltrate data by cracking stolen passwords, using a rainbow table the sensitive data. Which of the following should a security engineer do to prevent such an attack in the future? 

A. Use password hashing. 

B. Enforce password complexity. 

C. Implement password salting. 

D. Disable password reuse.

Correct answer: D

Disable password reuse

200

A security modern may have occurred on the desktop PC of an organization's Chief Executive Officer (CEO). A duplicate copy of the CEO's hard drive must be stored securely to ensure appropriate forensic processes and the chain of custody are followed. Which of the following should be performed to accomplish this task? 

A. Install a new hard drive in the CEO's PC, and then remove the old hard drive and place it in a tamper-evident bag 

B. Connect a write blocker to the hard drive Then leveraging a forensic workstation, utilize the dd command and live Linux environment to create a duplicate copy 

C. Remove the CEO's hard drive from the PC, connect to the forensic workstation, and copy all the contents onto a remote fileshare while the CEO watches 

D. Refrain from completing a forensic analysts of the CEO's hard drive until after the incident is confirmed, duplicating the hard drive at this stage could destroy evidence  

Correct answer: D

Refrain from completing a forensic analysts of the CEO's hard drive until after the incident is confirmed, duplicating the hard drive at this stage could destroy evidence

200

A privileged user at a company stole several proprietary documents from a server. The user also went into the log files and deleted all records of the incident. The systems administrator has Just informed investigators that other log files are available for review. Which of the following did the administrator MOST likely configure that will assist the investigators? 

A. Memory dumps 

B. The syslog server 

C. The application logs 

D. The log retention policy

Correct answer: B

The syslog server

300

A security engineer needs to Implement the following requirements: 

• All Layer 2 switches should leverage Active Directory tor authentication. 

• All Layer 2 switches should use local fallback authentication If Active Directory Is offline. 

• All Layer 2 switches are not the same and are manufactured by several vendors. Which of the following actions should the engineer take to meet these requirements? (Select TWO). 

A. Implement RADIUS. 

B. Configure AAA on the switch with local login as secondary. 

C. Configure port security on the switch with the secondary login method. 

D. Implement TACACS+ 

E. Enable the local firewall on the Active Directory server. 

F. Implement a DHCP server.

Correct answers: A & B

A. Implement RADIUS. 

B. Configure AAA on the switch with local login as secondary.

300

A company processes highly sensitive data and senior management wants to protect the sensitive data by utilizing classification labels. Which of the following access control schemes would be BEST for the company to implement? 

A. Discretionary 

B. Rule-based 

C. Role-based 

D. Mandatory  

Correct answer: D

Mandatory

300

A well-known organization has been experiencing attacks from APIs. The organization is concerned that custom malware is being created and emailed into the company or installed on USB sticks that are dropped in parking lots. Which of the following is the BEST defense against this scenario? 

A. Configuring signature-based antivirus io update every 30 minutes 

B. Enforcing S/MIME for email and automatically encrypting USB drives upon insertion. 

C. Implementing application execution in a sandbox for unknown software. 

D. Fuzzing new files for vulnerabilities if they are not digitally signed  

Correct answer: C

Implementing application execution in a sandbox for unknown software.

300

A security analyst receives the configuration of a current VPN profile and notices the authentication is only applied to the IP datagram portion of the packet. Which of the following should the analyst implement to authenticate the entire packet? 

A. AH 

B. ESP 

C. SRTP 

D. LDAP Answer:

Correct answer: B

ESP

300

After a ransomware attack a forensics company needs to review a cryptocurrency transaction between the victim and the attacker. Which of the following will the company MOST likely review to trace this transaction? 

A. The public ledger 

B. The NetFlow data 

C. A checksum 

D. The event log

Correct answer: A

The public ledger

400

A cybersecurity department purchased a new PAM solution. The team is planning to randomize the service account credentials of the Windows server first. Which of the following would be the BEST method to increase the security on the Linux server? 

A. Randomize the shared credentials 

B. Use only guest accounts to connect. 

C. Use SSH keys and remove generic passwords

D. Remove all user accounts. 

Correct answer: C

Use SSH keys and remove generic passwords

400

An organization has decided to host its web application and database in the cloud Which of the following BEST describes the security concerns for this decision? 

A. Access to the organization's servers could be exposed to other cloud-provider clients 

B. The cloud vendor is a new attack vector within the supply chain

C. Outsourcing the code development adds risk to the cloud provider 

D. Vendor support will cease when the hosting platforms reach EOL.

Correct answer: B

The cloud vendor is a new attack vector within the supply chain

400

The website http://companywebsite.com requires users to provide personal Information, Including security question responses, for registration. Which of the following would MOST likely cause a data breach? 

A. Lack of input validation 

B. Open permissions 

C. Unsecure protocol 

D. Missing patches  

Correct answer: C

Unsecure protocol

400

When used at the design stage, which of the following improves the efficiency, accuracy, and speed of a database? 

A. Tokenization 

B. Data masking 

C. Normalization 

D. Obfuscation  

Correct answer: C

Normalization

400

An organization is concerned that its hosted web servers are not running the most updated version of the software. Which of the following would work BEST to help identify potential vulnerabilities? 

A. hping3 -S corsptia.org -p 80 

B. nc —1 —v comptia.org -p 80 

C. nmap comptia.org -p 80 —sV 

D. nslookup -port=80 comptia.org

Correct answer: C

nmap comptia.org -p 80 —sV

500

A company wants to deploy PKI on its Internet-facing website. The applications that are currently deployed are: www.company.com (main website) contactus.company.com (for locating a nearby location) quotes.company.com (for requesting a price quote). The company wants to purchase one SSL certificate that will work for all the existing applications and any future applications that follow the same naming conventions, such as store.company.com. Which of the following certificate types would BEST meet the requirements?

A. SAN 

B. Wildcard 

C. Extended validation 

D. Self-signed 

Correct answer: B

Wildcard

500

An engineer wants to access sensitive data from a corporate-owned mobile device. Personal data is not allowed on the device. Which of the following MDM configurations must be considered when the engineer travels for business? 

A. Screen locks 

B. Application management 

C. Geofencing 

D. Containerization

Correct answer: D

Containerization

500

An organization just experienced a major cyberattack modem. The attack was well coordinated sophisticated and highly skilled. Which of the following targeted the organization? 

A. Shadow IT 

B. An insider threat 

C. A hacktivist 

D. An advanced persistent threat  

Correct answer: D

An advanced persistent threat 

500

A company is launching a new internet platform for its clients. The company does not want to implement its own authorization solution but instead wants to rely on the authorization provided by another platform. Which of the following is the BEST approach to implement the desired solution? 

A. OAuth 

B. TACACS+ 

C. SAML 

D. RADIUS

Correct answer: D

RADIUS

500

A cloud administrator is configuring five compute instances under the same subnet in a VPC. Three instances are required to communicate with one another, and the other two must be logically isolated from all other instances in the VPC. Which of the following must the administrator configure to meet this requirement? 

A. One security group 

B. Two security groups 

C. Three security groups 

D. Five security groups

Correct answer: B

Two security groups