Browse all practice questions for the Western Governors University (WGU) ITAS6291 D488 Cybersecurity Architecture and Engineering Practice Exam. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

Western Governors University (WGU) ITAS6291  D488 Cybersecurity Architecture and Engineering Practice Exam course image
More practice questions

These questions are part of the practice quiz. Start practicing

  • A software developer is looking to implement a cloud test environment that charges based on execution time. What is this model known as?
  • Which of the following should not be a characteristic of a central log management system, as it can lead to security misconfigurations?
  • What cloud model is offered over the Internet by cloud service providers (CSPs) to cloud consumers, often on a pay-as-you-go basis?
  • Which of the following refers to a decentralized network where participating nodes self-organize to provide services typically found in client-server networks?
  • Who among the following is considered a threat actor that acts from within the organization?
  • In the hierarchical model, what is the role of the root Certificate Authority (CA)?
  • What policy should be implemented to reduce the risk of unauthorized access to sensitive information?
  • What factor in a software supply chain can greatly impact the selection of frameworks used in development?
  • Which feature of a CASB allows for centralized management of access controls from the enterprise network to cloud services?
  • How does 3D printing increase on-demand availability for custom parts?
  • What feature of WPA3 provides enhanced security by using simultaneous authentication?
  • Which security design provides an empty area surrounding a high-value asset, disconnecting it from any network and making it easier to detect unauthorized attempts?
  • What identity proofing method is a refinement of the Hashed Message Authentication Code One-Time Password (HOTP)?
  • What manages the virtual machine environment and facilitates interaction between virtual machines, the computer hardware, and the network?
  • What solution should an organization implement to centralize its security event logs and automate analysis?
  • Which of the following is NOT typically a function of a Cloud Access Security Broker (CASB)?
  • What approach allows for the configurable physical and virtual network appliances via scripting to manage security and traffic flow?
  • Which physical security control should be used to track visitors to a facility, with the level of detail depending on the facility's sensitivity?
  • Which encryption standard has been identified by NIST to be replaced by AES due to security issues?
  • Which of the following is closely associated with the extraction of executable logic and data?
  • What is the purpose of using the X-Frame-Options header in a web application?
  • Which Cloud Access Security Broker (CASB) deployment method uses broker connections between the cloud service and cloud consumer, without being inline with the cloud consumer and services?
  • What risk management strategy ensures data security in a software application?
  • Which technique will best address the known vulnerability in a web content management system?
  • How can a company prevent the unauthorized distribution of copyrighted videos?
  • A data scientist is trying to gather sources for data analytics. Which of the following is NOT an example?
  • Which hashing algorithm produces a 128-bit output and is sometimes used to represent passwords, though it is not an authentication code?
  • Which word best describes the concept of due diligence, emphasizing the ongoing effort to evaluate and improve asset protection mechanisms?
  • What hardening technique is essential for protecting a manufacturing company's industrial control systems from firmware attacks?
  • Which of the following is not a mandatory access control solution, but rather a Data Loss Policy that quarantines a file and replaces it with a policy violation notice?
  • A data center lead is preparing an organization for disaster recovery and wants to minimize impact to production systems. Which method should be used?
  • What is a key risk if an attacker gains elevated privileges in a virtualized environment?
  • Which protocol is primarily used for securing voice over IP (VoIP) communications?
  • Which security tool monitors network traffic from a SPAN port but does not block traffic, instead analyzing it for suspicious activity?
  • What type of segmentation is commonly used in ICS and SCADA networks, involving separate physical hardware?
  • Which objective specifies how much time is acceptable for system recovery, highlighting tolerable downtime?
  • What public-key cryptosystem is described by the equation y^2 = x^3 + ax + b?
  • Which control measure is most effective at ensuring that sensitive areas are monitored continuously?
  • Which incident type involves the theft of sensitive information through unauthorized access?
  • What set of cybersecurity standards was created by the United States Department of Defense to enhance supply chain security?
  • In which type of cloud model do users share resources but have their own allocated environments?
  • What type of risk management is involved in understanding how threats can impact a business?
  • Which device provides foundational protection for a network by blocking or allowing traffic based on pre-configured rules?
  • What solution does IT configure to provide a warning system against unauthorized file copying?
  • Which of the following technologies encrypts data as it exists in memory to prevent untrusted processes from decoding the information?
  • What term describes the process of identifying, collecting, and providing electronically stored information (ESI) as part of a legal hold?
  • Which threat actor would most likely launch a ransomware attack against a large retail chain to demand payment?
  • What is the function of modes of operation in encryption?
  • Which system facilitates direct automation of operations within assembly lines and robotics?
  • A security researcher is tasked with assessing the security of a WiFi network to ensure that it is protected against potential attacks. Which of the following tools would be the most appropriate for this purpose?
  • Which type of network architecture uses two firewalls placed on either side of a demilitarized zone (DMZ)?
  • Which protocol should a system administrator use to send an email with an encrypted attachment?
  • Which method should a Flash developer use to communicate a markup text type similar to XML?
  • Which category of security flaws includes technical failures like outdated software?
  • Which EAP (Extensible Authentication Protocol) type requires only a server-side public key certificate to establish an encrypted tunnel?
  • Which component of risk involves assessing potential consequences including scope, asset value, and financial impacts?
  • What is the key difference between a NIDS (network intrusion detection system) and a NIPS (network intrusion prevention system)?
  • A security manager is reviewing security best practices. Which of the following would NOT be a physical security best practice?
  • Which system is most suitable for automation tasks directly controlling operations in assembly lines?
  • What ISO 27k standard focuses on personal data and privacy guidance?
  • What is the term for the willingness of an organization to accept certain levels of risk related to its operations?
  • What value can a qubit have that is different from a traditional computer bit?
  • Which tool provides functionality for analyzing live memory data?
  • Which privacy act is specific to Singapore and governs the protection of personal data in that country?
  • What benefit of a central log management system helps ensure compliance with legal and regulatory requirements for log collection and alerting?
  • Why should a privacy impact assessment (PIA) document the parties involved in data-sharing arrangements?
  • Which algorithm produces a 128-bit output but is deemed insecure for password representation?
  • Which certificate type provides ownership of a particular domain by proving ownership through email authorization or publishing a text record?
  • A solutions architect plans to implement a Cloud Access Security Broker (CASB) positioned at the edge of the client's network. What is this method of deploying a CASB known as?
  • What term describes adding more servers to a cluster to improve application performance?
  • Which technique involves analyzing the state of an application in real-time even if data is encrypted?
  • Which type of analysis involves inspecting source code to identify open source components and any libraries used as part of an application's design?
  • In a cybersecurity incident response, which action is considered a priority during active investigation?
  • What is the role of the TGT in the smartcard authentication process?
  • Which of the following is just a component of both due care and due diligence, rather than the complete concept?
  • Which NIST publication is the standard for Zero Trust Architecture, focusing on security based on resources like users, services, and workflows instead of network boundaries?
  • What does the FFIEC (Federal Financial Institutions Examination Council) provide guidance on?
  • In which stage of forensics does a forensic expert interpret data and examine file structures for tampering signs?
  • Which metric is essential for risk management and provides insight into how often losses are likely to occur?
  • A security researcher for a political campaign is researching threat actors. Who should the researcher investigate that would most likely target them specifically?
  • A security manager is standing up a risk management program at a company. What should the security manager set up that might be considered the most recognized output?
  • Which security solution aims to prevent data loss and protect data from unauthorized disclosure, while also trying to identify if and when data loss occurs?
  • An application specialist suggests using a particular application in a virtualized environment. What does the specialist recommend?
  • What is a common way to manage user permissions and segment access within an application layer?
  • Which type of security measure allows the definition of what is permitted to run on a system?
  • Which process uses platform configuration registers (PCRs) in the Trusted Platform Module (TPM) to check system state data during boot?
  • Which tool should a security researcher use to deconstruct malware for analysis?
  • Which department assists in evaluating the effect of risks on intangible assets?
  • What is a downside of using a single CA model?
  • What solution does heterogeneity refer to when strengthening a cloud architecture?
  • Which document would be critical for an organization conducting independent audits on its cybersecurity practices?
  • In cloud computing, what does the acronym IaaS stand for?
  • In key management, what practice prevents the indefinite vulnerability of a compromised key?
  • Which system is intended to supervise large-scale industrial control systems across multiple sites by replacing the control server?
  • What is the secure version of the Lightweight Directory Access Protocol (LDAP), using SSL/TLS encryption to prevent eavesdropping and man-in-the-middle attacks?
  • How does 3D printing help companies protect their intellectual property?
  • A penetration tester is attempting to target core mechanisms that enable integration and orchestration of the entire information systems and technology landscape. Which of the following should the pen tester pursue?
  • What is one of the key benefits of using a Cloud Access Security Broker (CASB)?
  • Which program is designed by the Cloud Security Alliance to validate a cloud service provider's commitment to security practices?
  • What type of agreement defines the conditions under which entities can use data and information shared between them?
  • What term describes a suite of policies and technology tools for centralized management of mobile devices?
  • Which term describes the phase in which an adversary or penetration tester may continue to work on an exploited system to maintain access for future use?
  • A web developer requires a method for client-server data exchange that supports standard HTTP methods. What should they implement?
  • When securing against broken authentication, which control is NOT relevant for protection?
  • Which entity accepts requests for digital certificates and performs additional steps to validate that the requestor has the authorization to do so?
  • Which US federal law protects the privacy of children under the age of thirteen?
  • What is the primary focus of continuous monitoring in application development?
  • In the context of cybersecurity agreements, what does OLA stand for?
  • A systems engineer is working in conjunction with security and has set up a data loss prevention solution. What remediation action should they choose to quarantine and replace files with a policy violation notice?
  • Which type of information is commonly associated with data provided to a financial institution?
  • A security engineer is preparing tools for an engagement with operational technology. Which of the following protocols are most likely part of OT?
  • Which mode of operation provides authenticated encryption with associated data (AEAD)?
  • Which method allows sysadmins to configure devices and services for administrative logins, using cryptographic keys or passwords?
  • What advantage does a BYOD policy provide to employees?
  • Which type of intelligence gathers and analyzes publicly available data to address the needs of a specific project or operation?
  • Which approach uses threat intelligence in a practical and actionable way?
  • Which security technology ensures that only authorized software loads on a device during boot?
  • How does Public Key Infrastructure (PKI) support non-repudiation of users and devices?
  • Which interface provides code that allows the host to boot to an operating system and enforces boot integrity checks?
  • What component of WPA3 is designed to protect against key recovery attacks?
  • Which solution is commonly used on Microsoft Windows computers to protect data at rest?
  • How does data execution protection (DEP) help prevent a buffer overflow?
  • Which hashing algorithm was the NIST standard but was replaced in 2005 due to vulnerabilities?
  • What method is used to define permissions on a network or file but does not segment like VLANs or physical segmentation?
  • Which system is specifically designed for time-sensitive embedded controllers?
  • Which risk involves an attacker exploiting a weakness in VM migration due to lack of proper protocols?
  • Which non-active test identifies a specific objective to determine whether parties involved know what to do?
  • How can a developer validate passwords against weak password lists to prevent weak password creation?
  • Which of the following is a benefit of 3D printing, allowing companies to craft accurate components at a fraction of the cost of traditional manufacturing?
  • Which certificate type requires more rigorous checks on the subject's legal identity and control over the domain or software the certificate authority (CA) signs?
  • Which term describes the unindexed and hidden locations on the Internet often associated with malicious activity and criminal operations?
  • What does the NIST Special Publication (SP) 800-84 provide guidance on?
  • Which of the following is not a possible state of a qubit in a quantum computing system?
  • What is a significant drawback of the MD5 hashing algorithm?
  • Unauthorized access to devices would most likely indicate which of the following?
  • What method requires representatives from all groups in the BCDR plan to participate in a meeting to review the plan?
  • A security manager is planning for the needs of an immediate frantic and pressing emergency. Which plan should the security manager focus on developing?
  • In the hierarchical CA model, what is the role of intermediate CAs?
  • Which of the following is a common practice for ensuring data redundancy?
  • An application uses encrypted transactional data to record incoming and changing data sets. Which technology does the application use?
  • What allows for the creation of cloud resources within private networks that parallel the functionality of creating resources in a traditional, privately operated data center?
  • Which technology is extensively used for User and Entity Behavior Analytics (UEBA)?
  • Which method of deploying a CASB involves a security appliance positioned at the client network edge that forwards user traffic to the cloud if it complies with policy?
  • Which NIST standard offers the latest guidance on password compliance and changes traditional password policy elements?
  • Which EAP (Extensible Authentication Protocol) type is similar to PEAP (Protected Extensible Authentication Protocol) but uses a Protected Access Credential (PAC) instead of a certificate to set up the tunnel?
  • What uses desktop virtualization to separate the personal computing environment from the user's physical machine?
  • Which protocol enables a server to communicate the status of a requested certificate efficiently?
  • What type of test is performed to ensure that individual components of a system interact correctly when tested together?
  • Which type of security measure specifically updates settings based on alerts from security monitoring tools?
  • What principle encourages developers to commit and test updates frequently, sometimes multiple times a day?
  • A security researcher wants to look for new and emerging malware on unindexed and hidden locations on the Internet. What should the security researcher use to look?
  • Which stage of the forensic process involves creating a copy of evidence?
  • Which type of threat intelligence focuses on the tactics, techniques, and procedures (TTPs) of a threat actor and is used to fortify vulnerability remediation and alerting?
  • What cryptographic function combines two functions to authenticate a sender and prove the integrity of a message?
  • What method is typically used to filter and manage traffic flow between different VPCs in a cloud environment?
  • What is the live environment used by staff, employees, customers, and other stakeholders on a day-to-day basis?
  • Which environment should mirror the production environment to ensure the highest levels of compatibility for testing purposes?
  • Which of the following involves blocking or limiting access to resources like files, folders, or write access from specific accounts?
  • What type of agreement occurs between two entities that need to share data via an interface, focusing on security considerations?
  • Which method allows an employer to manage the portion of a mobile device that connects to the corporate network?
  • Which step in the SDLC incorporates secure coding patterns and best practices, such as those from the Open Web Application Security Project (OWASP)?
  • A disaster recovery planner needs to focus prioritization efforts around operational impact. The disaster recovery planner should focus on which system?
  • How long are companies required by regulation to keep HIPAA data?
  • Which system effectively detects modifications in managed file images, such as application executables?
  • In digital forensics, the examination of tampered data is part of which stage of the process?
  • A solutions engineer is looking for a cloud model owned primarily by the organization they work for, but the engineer also wants to reduce costs where possible. What solution would most likely fit the engineer's organizational needs?
  • What should be used to prevent data breaches caused by insider threats based on the indicators of compromise?
  • In which scenario would you use Network Access Control (NAC)?
  • Which framework, created and maintained by ISACA, frames IT risk from a business leadership viewpoint and is used to manage and govern enterprise IT?
  • Which model assesses the maturity of software engineering practices in an organization?
  • Which type of cloud storage is ideal for storing large amounts of unstructured data, like archives and backups?
  • Which risk management framework is tailored for U.S. federal agencies ensuring cybersecurity risk management?
  • Which cloud service model requires the least amount of administration responsibility from the client's perspective?
  • Which benefit of a log management system helps organize log data, making it easier to review and analyze through consistent collection and formatting?
  • A forensic expert needs to recover deleted or corrupted files from a disk partition. Which of the following tools should the expert use?
  • What key management practice associates cryptographic keys with an identity?
  • Which service provides a list of configuration and access levels available to a cloud instance, allowing for potential vulnerabilities if not secured?
  • Which of the following is not a simulation but would be an option for actually performing an active failover to test disaster recovery capabilities?
  • Which type of testing is focused on validating that changes in code do not negatively impact existing functionalities?
  • Which country is least likely to be chosen for a company focused on privacy and anonymity due to its government's control over information and lack of strong privacy protections?
  • A web developer wants a browser tool that is independent of browser restrictions. Which should they avoid using?
  • What solution should be recommended to provide a failback option for future application deployments?
  • Which of the following best describes the term 'exploitability' in risk assessment?
  • Which NIST publication offers guidance on security and privacy controls for compliance audits?
  • What process allows users to install untrusted apps from a website using the .apk file format on a mobile device?
  • What describes a relationship where if resource A trusts resource B, and resource B trusts resource C, then resource A automatically trusts resource C?
  • Which system provides mechanisms for controlling machinery and automating workflows in critical infrastructure?
  • Which phase of the Risk Management Lifecycle demands significant time and effort for security control implementation?
  • Which of the following does not occur during the smartcard authentication process?
  • Which value can a qubit represent in a quantum computing system?
  • A system administrator wants to harden the organization's servers. Which of the following would best help to harden the servers?
  • Which analysis type is most suitable for assessing software behavior under real conditions?
  • Which technology uses algorithms to parse input data and develop strategies for using that data, such as object identification or determining the next move in a game?
  • Which of the following tasks is typically performed during digital forensics regarding file recovery?
  • In vendor management, which term corresponds to the evaluation of a vendor's ability to consistently deliver?
  • Which protocol is primarily used for network access control and has several server and client products available?
  • Which type of indicator informs management of the risk levels associated with various processes?
  • Which service allows users to access various service providers (SPs) by authenticating the user and granting a token for access?
  • What is the entity responsible for issuing and guaranteeing certificates, often set up privately for internal communications?
  • Which NIST document addresses security and privacy controls for federal information systems but is not specifically focused on Zero Trust Architecture?
  • What describes the set of automated tasks performed as part of deploying an instance, typically related to system administration?
  • Which act related to personal financial information includes requirements for Business Continuity and Disaster Recovery (BCDR) capabilities?
  • Which of the following is a popular bare metal Type 1 hypervisor that allows multiple operating systems to run simultaneously on a single computer?
  • What is the recommended solution to prevent unapproved devices from accessing the corporate network?
  • Which privacy law should an owner research before expanding operations in Japan?
  • Which security control meets the needs of a financial institution required to comply with PCI DSS?
  • Which of the following is NOT an indicator of compromise according to CompTIA?
  • Which term is more closely related to due care, serving as the basis for due diligence and emphasizing careful actions that are expected in various circumstances?
  • Which web traffic protection method periodically obtains a time-stamped OCSP response from the certificate authority?
  • What security measure protects web servers by ensuring the validity of digital certificates?
  • Which testing method would likely be chosen for identifying security flaws in source code during the development phase, especially on a budget?
  • Which Type 1 hypervisor would you choose if you're looking for a bare metal solution from VMware that supports multiple virtual machines running on a single physical machine?
  • Which authentication mechanism uses public key authentication by specifying a remote user's public key in a locally stored list of authorized keys on the server?
  • What technology enables applications to run virtual instances independently from the traditional hypervisor virtual machine approach?
  • A mobile device manager neglected to disable a selection of different stores. What process is associated with downloading a file with an apk extension onto the corporate phone?
  • What does the term 'collision' refer to in hashing algorithms?
  • What concept do experts refer to when managing risk that includes the phases of Identify, Assess, Control, and Review?
  • What vulnerability assessment method involves entering malformed data at data entry points?
  • Which response header defines whether content can be displayed using frames, primarily to defend against clickjacking attacks?
  • Which practice involves monitoring user account activity to prevent unauthorized access and manipulation?
  • What type of incident is a security engineer responding to if they attempt to hack back after a compromise?
  • Which security measure defines what is not allowed to run on a system?
  • A company plans a technology rollout. As a precaution, security engineers prepare mitigation plans in the event of an eavesdropping attack. Which connectivity solution is being rolled out?
  • Which laws govern the export of commodities, software, and technology, requiring coordination between countries to enforce?
  • Which system categorizes resources by purpose, owner, or environment using key-value pairs?
  • Which detection technique should be used for an intrusion detection system to validate known signatures?
  • Which of the following is an example of a source that can feed into data analytics tools by providing information for collection and analysis?
  • Which of the following practices enhances privacy in a blockchain environment?
  • Which security practice helps detect potential fraud or inappropriate activities by temporarily shifting an employee's duties to another individual during their absence?
  • What is a key benefit of using a virtual private network (VPN)?
  • In which mobile device policy are all devices strictly for business use without personal activities allowed?
  • An attacker gains access to a sensitive shared folder. What might a security engineer configure to directly mitigate the problem?
  • Which standard should a coffee company comply with for processing credit card transactions securely?
  • Which type of attack involves accessing directories outside of the web root and can be mitigated by a web application firewall like ModSecurity?
  • Which solution should a storage administrator choose for high-performance, transactional applications?
  • When defining vendor expectations and requirements, what is the significance of establishing a vendor policy?
  • Which security measure can be implemented to specifically limit access based on geographical locations?
  • What term describes the financial amount lost in one occurrence of a risk event, such as server downtime?
  • A developer working on a Python-based project needs to implement network communications. Which framework should they choose?
  • Why is RC4 considered vulnerable despite being a stream cipher?
  • What must a Certifying Authority review to grant accreditation to a corporation's information system?
  • Which of the following is a benefit of a Content Delivery Network (CDN) that involves adding servers to help process the same workload?
  • Which council provides guidelines and standards for financial institutions, including Business Continuity and Disaster Recovery (BCDR) capabilities?
  • Which of the following is NOT a typical function of a hub in an IoT environment?
  • If a cloud engineer is setting up a Zero Trust Architecture, which NIST document should they avoid as it is focused on incident response?
  • What set of standards is widely utilized to evaluate methods for protecting technology and financial operations?
  • What aspect of a privacy impact assessment (PIA) involves evaluating how the company uses and maintains data to ensure processes continue during a disaster?
  • What method involves a Cloud Access Security Broker (CASB) positioned at the cloud network edge that directs traffic to cloud services based on policy compliance?
  • Which access control model is characterized by making access decisions based on subject, object, and context-sensitive attributes?
  • What is achieved by implementing blackhole routing for systems against DDoS attacks?
  • Which of the following refers to honeytokens or canary traps, designed to lure adversaries by containing appealing data like user credentials or account numbers?
  • What is one of the primary ways a CDN improves the customer experience?
  • What is the primary function of a registration authority (RA) in the certificate process?
  • At which stage of business continuity planning should a security engineer identify preventative measures, ensuring that these measures are applied to known systems?
  • What hashing algorithm is utilized within the bitcoin network for proof-of-work?
  • Which of the following are part of the OWASP Top Ten vulnerabilities?
  • What principle ensures that an employee has access only to the information necessary for their job role?
  • Which department's involvement is less critical in qualitative risk assessments for intangible metrics?
  • What method did a user use to install a custom ROM on a company-owned Android tablet?
  • Which technology is widely utilized for contactless payments at point-of-sale terminals?
  • A developer is looking for a solution that will provide confidentiality and check its integrity and authenticity for encrypted plaintext. Which solution should the developer use?
  • Which organization’s guidance includes secure coding standards specifically for programming practices?
  • Which scenario occurs when a vendor's product design leads to integration challenges with other vendor products?
  • Which access control model allows users to manage permissions for various resources in a flexible manner?
  • A systems administrator is looking into hardening their systems. What are some popular guides the sysadmin could follow?
  • In the context of penetration testing, which aspect falls under pre-engagement?
  • Which attack allows an attacker to take control of all virtual machines on a host?
  • Which method is used to protect data in transit, including website traffic, remote access traffic, and data synchronized between cloud repositories?
  • Which major category of security flaws is most directly impacted by human actions, such as phishing attacks?
  • Financial fraud is most likely to be attempted by which type of threat actor?
  • Which regulation should a company researching operations in Europe focus on for data analysis compliance?
  • Which type of agreement is an internal document that defines the essential operational needs of an organization and meets performance metrics defined in a Service Level Agreement (SLA)?
  • What does the deployment of EAP Transport Layer Security (EAP-TLS) require on both the clients and servers?
  • What is a Domain Validation (DV) certificate, and how does it compare to a general purpose certificate?
  • Which type of data is considered intangible and would require strict security measures?
  • Which NIST standard is focused on the overall security and privacy controls required for federal information systems?
  • Which Cloud Access Security Broker (CASB) method directs traffic from users at the client network to cloud services but only forwards traffic that complies with organizational policy?
  • Which NIST publication outlines the necessary controls for audits of information systems used for certification?
  • In the context of cybersecurity, what does NIST SP 800-53 primarily provide guidance on?
  • A security engineer is looking at various methods to use identity proofing. Which of the following are identity proofing methods?
  • What mechanism should be implemented to prevent printing documents from a corporate file share?
  • Which type of threat intelligence identifies current attacks and indicators of compromise (IOCs) and is used by security and forensic analysts, as well as incident responders?
  • A disgruntled employee with access to sensitive systems intentionally deletes key files, causing disruption to business operations. Which type of threat actor does this scenario describe?
  • Which type of threat actor might attempt to obtain and release confidential information or deface websites?
  • A red teamer is following the steps of the cyber kill chain process during an exercise. What is the first step the red team member should perform?
  • When implementing a CASB, what aspect might an organization expect improved visibility into?
  • Why can the AS decrypt a TGT request during the smartcard authentication process?
  • Which certificate contains an asterisk in its domain name field, allowing usage for any number of subdomains?
  • Which NIST standard focuses on Zero Trust Architecture, addressing security based on resources like users and services rather than network boundaries?
  • What type of data is considered the safest when it is encrypted and stored properly?
  • Which of the following foundational elements ensures the integrity of a blockchain by cryptographically linking blocks?
  • Which network device would you use to ensure that traffic continues to flow to a functional web server when another server in a cluster goes down?
  • What mechanism provides a trusted third party with vendor-developed source code for access if the vendor ceases operations?
  • Which test ensures that a particular block of code performs the exact action intended and provides the exact output expected?
  • What should the company consider when developing metrics to measure a cybersecurity risk management program's effectiveness?
  • Which plan has a broad scope that covers the development of a business continuity policy and the creation of response plans?
  • Which service model requires the least responsibility from clients, with the provider taking care of most operational aspects?
  • Which document serves as a formal means to define roles and expectations but is widely considered a non-binding agreement or difficult to enforce in court?
  • In a cloud environment, which control mechanism is used to regulate both inbound and outbound traffic between virtual private clouds (VPCs)?
  • If a security engineer uses public key certificates between clients and servers, which EAP implementation is deployed?
  • What is the global data protection standard maintained by a consortium of payment card companies?
  • What authentication feature does Security Assertion Markup Language (SAML) provide?
  • What type of web application firewall is commonly used with Apache servers to help defend against application layer attacks?
  • What is it called when a qubit can have multiple states simultaneously, including any value between 0 and 1?
  • In a data life cycle plan, regulatory restrictions are typically less stringent during which phases?
  • What method clearly identifies the classification, use, and licensing terms of digital content but does not control how consumers use the data?
  • Which type of analysis involves inspecting a system and software while it operates, including techniques like packet capture and traffic analysis?
  • Which type of analysis involves deconstructing software or hardware to determine how it works and how much information can be extracted from it?
  • What does a score of Level 2: Managed indicate about the state of software applications?
  • Which act related to fraudulent accounting includes descriptions of Business Continuity and Disaster Recovery (BCDR) capabilities?
  • A developer wants to create a certificate to show the browser plugin is trusted. What could the developer use?
  • Which technology identifies anomalies and threats by scanning multiple intrusion detection sources?
  • In cryptography, what key feature is necessary for a block cipher?
  • Which of the following involves blocking traffic based on static rules or dynamically updating settings based on alerts from SIEM and IDS tools?
  • In a Kerberos authentication system, what process occurs first when logging in with a smart card?
  • Which tool allows for applying policies that define minimum and maximum capacity for scaling resources?
  • What is a characteristic of a honeypot system?
  • To ensure builds of a new mobile application are trusted, which solution should the security team use?
  • Which initiative focuses on collaboration among private sector organizations to create risk management frameworks?
  • What does crypto erase involve in terms of data sanitization, making the recovery of data effectively impossible?
  • What control should a company implement to allow only preapproved software to run on its endpoints?
  • How does risk tolerance affect the development of a financial services mobile application?
  • Which solution provides day-to-day monitoring and reporting on various operational resources and activities within an enterprise?
  • For which purpose is NGFW primarily used?
  • What standard should a cloud engineer reference for designing a zero trust architecture?
  • What type of security tool actively blocks malicious traffic and must be placed inline with network traffic to be effective?
  • Which security solution is capable of detecting previously identified malware and can be fine-tuned to identify malicious activity?
  • What is a primary goal of physical security controls?
  • Which type of system is commonly used in industrial settings for automation tasks such as assembly line operations, field tasks, and robotics?
  • What type of encryption is used to protect data in transit while it is being moved across systems?
  • Which strategic assessment determines the acceptable level of residual risk an organization can tolerate?
  • What framework should a risk auditor contracted by a U.S. government agency use for risk assessments?
  • Why is it unlikely for conflicting laws to be an issue during the first verification of a data center failover?
  • What primarily distinguishes a Microcontroller from a System on Chip (SoC)?
  • What should be the primary focus during a post-engagement review in penetration testing?
  • What Wi-Fi encryption standard should a retail company use to comply with PCI DSS?
  • Which suite of policies and tools is specifically designed for centralized management of mobile devices?
  • Which of the following places security at the forefront of development efforts but is not considered a software development method itself?
  • How is a cloud access security broker (CASB) configured when using a forward proxy?
  • What is the consequence of a COBO policy in a corporate environment?
  • What programming framework is ideal for handling asynchronous network programming in Python applications?
  • Which technique is used to secure sensitive information, such as credit card numbers, by replacing the data with a non-sensitive token?
  • What is primarily used to enable remote connectivity for people working from home or to connect branch locations to the enterprise network?
  • Which type of analysis requires the evaluation of a system or software while it is actively running?
  • A system administrator wants to prevent unauthorized users from accessing sensitive company files. Which of the following should be modified to achieve this?
  • What are the primary benefits of WPA3 in wireless security?
  • What does a CYOD policy specifically provide to employees?
  • Which method is least likely to allow an organization to manage risks effectively?
  • What field in a domain certificate allows for the use of a single certificate across multiple domains?
  • What main benefit does implementing Security as Code provide during development?
  • Which regulation enforces rules for organizations that offer services to entities in the European Union (EU) or that collect and analyze data on subjects located there?
  • Which public-key cryptosystem uses prime factorization as the basis for its security?
  • What type of certificate requires an identity check and validation by a certificate authority before being issued to a software publisher?
  • Which audit area describes the legally compliant means by which data is removed and made inaccessible?
  • Which type of system analyzes patterns and behaviors of users and entities to detect anomalies in User and Entity Behavior Analytics (UEBA)?
  • If a company provides a selection of approved devices for employees, what is the type of policy they are implementing?
  • What approach should an administrator take to improve server security after identifying running services?
  • What must key strategic objectives and metrics development include to measure operational success effectively?
  • An enterprise administrator is reviewing the process for how smartcard authentication works. Which of the following is NOT one of the steps?
  • Which EAP (Extensible Authentication Protocol) type is known for being one of the strongest and most widely supported authentication methods?
  • Which service model provides hardware hosted at a provider facility, with the provider responsible for infrastructure, physical security, and utilities like power?
  • Which standard is primarily used to assess cloud service providers for security practices?
  • Which hashing algorithm is stronger than MD5 (Message Digest Algorithm) and produces a much larger output but is not considered an authentication code?
  • How did network administrators identify the vulnerability related to wireless signal extension into public areas?
  • Which phase of the software development life cycle incorporates secure coding patterns and best practice guidance from organizations like OWASP?
  • What type of attack aims to overwhelm a target with traffic, disrupting normal traffic flow to a server or service?
  • Why might an organization consider a federation approach for credential management?
  • Which document is often considered the most recognized output of a risk management program, containing metadata such as threat, impact, likelihood, plan, and risk level?
  • Which protocol is used to facilitate secure authorization and access to resources across sites without requiring users to share their passwords?
  • A data center technician is part of an organization that requires FIPS 140-2 encryption standards for encrypting data at rest. Which of the following technologies incorporates this standard specifically for data at rest?
  • Which item is least likely to be a concern for a software company's supply chain but commonly pertains to hardware companies?
  • A security team needs to analyze network data while managing storage. What is the best data collection method?
  • Which of the following is not an industry standard but is important for defining how modern organizations work with vendors, suppliers, and contractors?
  • A site developer has experienced issues with Cross-Site Script Inclusion attacks. Which response header could be used to mitigate this attack?
  • What type of disaster recovery site ensures a hospital can quickly resume operations in case of a disaster?
  • Which type of site is management looking to implement to save costs in a business continuity plan?
  • Which MAC (message authentication code) mechanism would be best suited for older devices like iPhones and Androids that lack AES (advanced encryption standard) hardware acceleration?
  • Which NIST Special Publication outlines necessary controls for audits of information systems used for certification?
  • What is an example of a method used to protect data in motion, which describes the state when a system moves data?
  • Which cloud model falls between SaaS and IaaS in terms of the amount of resources provided and client administration responsibility?
  • In the context of securing a corporate network, which approach is emphasized by zero trust security?
  • During the smartcard authentication, the Ticket Granting Ticket (TGT) is issued by which entity?
  • A security manager is looking for a solution that contains software to monitor and report the day-to-day operations of an enterprise and the status of various resources and activities. Which of the following should the security manager consider?
  • Which entity acts as a trusted third party in the public key ecosystem?
  • Which feature of Public Key Infrastructure (PKI) supports integrity checks?
  • What happens after the correct PIN authorizes the smartcard's cryptoprocessor?
  • Which type of data sanitization provides effective protection from all recovery techniques?
  • Which issue can arise during a failover if the health status of disaster recovery (DR) devices is not properly monitored?
  • What layer of the OSI model do web application firewalls like ModSecurity focus on when defending against attacks?
  • Why is senior leadership support essential for successful Business Continuity and Disaster Recovery (BCDR) preparedness?
  • Which of the following is a technique to disrupt access to a system during an attack?
  • Which of the following operates as a guardian between two connected sites, enforcing mandatory access controls and interpreting data sensitivity levels?
  • Which of the following involves the use of a digital certificate issued by a Certificate Authority (CA) to encrypt emails and attachments?
  • Which risk strategy involves evaluating an identified risk and deciding to continue the activity despite the risk?
  • What is the first step of the data life cycle, involving the creation of files, manual data entry, data interfaces, and more?
  • Which systems are most important for operational continuity and should be prioritized in disaster recovery planning?
  • A security analyst is setting up documents for the outputs of the test or incident, along with recommendations based on the outputs and findings. Which standard should the analyst reference?
  • What issue arises when two files on a company website respond with the same hash?
  • Which type of risk management approach focuses directly on reducing risks associated with operations rather than appetite levels?
  • What can be a consequence of improper deprovisioning in a virtualized environment?
  • In terms of regulatory compliance, what strategy should organizations adopt to secure personal data?
  • What device is best suited for a solution engineer needing a controller that can change programming logic post-manufacture?
  • Which service model is specifically designed to charge clients based on execution time instead of fixed hourly rates?
  • What is a security measure that can give insights into attacker methods by engaging them into controlled environments?
  • What is Microsoft's solution for a Type 1 hypervisor that allows a systems administrator to perform a physical to virtual migration?
  • Which solution controls how consumers use digital content after it is published?
  • An internal cloud application at an organization requires additional storage space. What cloud deployment and service models did the engineers use?
  • Which algorithm is a variant of Salsa20, used for encryption in the Chrome browser on Android devices?
  • Which type of IoT device is designed to measure environmental variables such as humidity and temperature?
  • What explains the degradation in system performance and alerts regarding high central processing unit (CPU) usage?
  • What type of inspection method evaluates running code to observe its behavior and detect anomalies?
  • What are the two major components of risk that are essential in understanding its evaluation?
  • A data science engineer is analyzing qubits in a quantum computing artificial intelligence built to predict the end of the world. Which of the following values does the qubit represent?
  • What is the main objective of a Master Service Agreement (MSA)?
  • Which configuration guides can be downloaded for free and include detailed descriptions of configuration points for system hardening?
  • Which technology is designed to encrypt data at rest specifically in compliance with FIPS 140-2 standards?
  • What best describes a lock-in scenario with a technology vendor?
  • What term describes the framework for passing messages between applications using formats like SOAP and REST?
  • What is the most efficient way for a systems administrator to identify unnecessary services on a server?
  • A security team has detected unusual traffic patterns and needs to prevent further suspicious activity from entering the network. Which of the following should they modify to block the suspicious traffic?
  • A forensics expert is performing file carving during an investigation. Which of the following tools could the forensics expert use?
  • What does the label 'Top Secret' indicate in terms of data sensitivity?
  • During a risk management exercise regarding server security, what phase is used to document findings about file replication without encryption?
  • Which logical segmentation method creates separate virtual local area networks on a network device?
  • Which risk mitigation strategy is demonstrated when vulnerabilities are accepted due to a lack of resources to address them?
  • Which security strategy is implemented by developers focusing on dynamic application testing?
  • What provides privilege management and authorization by storing information about users, computers, security groups/roles, and services on an enterprise network?
  • A developer is troubleshooting a situation where several processes are trying to access the same resource simultaneously, causing unpredictable system behavior. What is this type of issue called?
  • What access control model assigns security clearance levels and uses labels to regulate access?
  • Which mode of encryption uses an initial chaining vector for the first round and combines previous outputs as input for subsequent rounds?
  • Which environment is typically used in the early stages of testing, allowing developers to perform broad testing and proof of concept evaluations?
  • Which of the following technologies focuses on creating realistic, synthetic images and videos that can mimic real people?
  • What type of simulation should a security analyst perform to determine if all parties know how to respond effectively?
  • A systems administrator is working with a developer to upgrade to the latest version of Java, but first, the sysadmin wants to see whether changes in code have caused previously existing functionality to fail. What is this called?
  • Which protocol does NOT involve checking a certificate status in PKI?
  • What may cause a hash mismatch and mark a downloaded file as untrusted?
  • Which network application protocol supports communications within an Operational Technology (OT) network?
  • Which labels should be used for information too valuable to allow any risk of its capture?
  • Which device is a processing unit that can perform sequential operations from a dedicated instruction set and requires software to be converted into assembly language?
  • What enabled an attack through a backdoor in a connected application?
  • What enables quantum computers to perform computations significantly faster than traditional computers in certain scenarios?
  • Which cloud service model represents the lowest amount of responsibility for the customer, with the provider managing the facilities, utilities, physical security, platform, and applications?
  • What does DLP stand for in the context of cybersecurity?
  • What does data integrity management focus on ensuring?
  • Which Risk Management Lifecycle phase focuses on the application and management of security measures?
  • A Windows client administrator is implementing a solution for data in use. Which of the following represents security protection for data in use?
  • An organization has contracted a penetration tester to perform a test for them. Which of the following is NOT a consideration for the test?
  • In which attack is a user tricked into submitting a malicious form request on a banking website?
  • A system administrator has decided to start a small data center venture for small businesses. What type of agreement should the sysadmin set up to meet the performance metrics defined in Service Level Agreements?
  • Which of the following best describes the focus of a security team's risk management activities?
  • Which of the following technologies is more resource intensive than virtualization but allows for running software designed for different hardware architectures?
  • What is the outcome of implementing rate limiting for protecting against DDoS attacks?
  • A defense contractor is tasked with using Mandatory Access Control policies for a classified project. Which of the following could they use?
  • Which of the following allows for the creation of policies to evaluate connected devices and determine access to a network?
  • Which response header changes the way documents load to prevent cross-origin attacks but would not be effective against XSS Inclusion attacks?
  • Which boot method enhances security at startup and can utilize TPM for storing encryption keys?
  • Which cryptographic protocol in WPA3 offers authenticated encryption with 128-bit and 192-bit AES options?
  • What is the benefit of managing network devices according to risk management principles?
  • Which model is characterized by resources being shared among multiple organizations with similar concerns?
  • What should a cloud engineer reference when establishing a zero trust architecture in a cloud environment?
  • Which concept describes spreading data across different storage locations or cloud storage providers to ensure data preservation in case of unavailability?
  • What is the primary focus of a first responder securing a crime scene with digital evidence?
  • Microsoft Windows BitLocker can use whole disk encryption to protect which type of data?
  • What describes the process of bundling certain libraries with an application at compile time?
  • What type of test is designed to check whether changes in code have caused previously existing functionality to fail?
  • Which approach involves multiple redundant processing nodes that share data and accept connections to provide redundancy in case of failure?
  • What is one method to enhance the effectiveness of security cameras?
  • Which encryption mode replaced AES CCMP for Wi-Fi encryption and is used in the cipher "ECDHE-RSA-AES128-GCM-SHA256"?
  • Which encryption standard is the current U.S. federal government standard for symmetric encryption?
  • What encryption method is used on Microsoft Windows computers to protect data at rest, and uses Advanced Encryption Standard (AES)?
  • Which type of threat intelligence provides leadership-focused information and is associated with big-picture reports?
  • What technology is used in video games and simulations but is not typically associated with User and Entity Behavior Analytics (UEBA)?
  • What term is used to describe the network of suppliers, vendors, and partners involved in delivering a final product, and is often a significant source of risk?
  • What is another term for public clouds, where businesses can offer subscriptions or pay-as-you-go services and sometimes provide lower-tier services free of charge?
  • Which of the following standards would be least relevant for a company focusing on credit card transaction security?
  • How can 3D printing help prevent intellectual property (IP) theft?
  • Which tool is used for network discovery tasks and security auditing, providing a way to assess systems and software running in a networked environment?
  • Which device in IoT systems facilitates networking, often required to enable communications for technologies like Z-Wave or Zigbee?
  • Which mechanism is specifically designed to control traffic between virtual private clouds (VPCs) in a cloud environment?
  • What is the primary purpose of Mobile Device Management (MDM)?
  • What technology focuses on monitoring the integrity of specific files to ensure they haven't been altered or compromised?
  • A software developer is selecting a key agreement for an organization's authentication. Which agreement type should the developer use?
  • A network administrator is trying to set up network security so that only trusted devices have network access. What solution should the administrator set up?
  • During a forensic analysis, a security professional needs to extract data from a binary file and display the content in hexadecimal format. Which tool would be the best choice?
  • Which strategy helps to identify weaknesses in systems before they can be exploited by attackers?
  • In what scenario is live VM migration particularly risky for virtualized environments?
  • Which departments should be consulted for qualitative analysis of intangible assets?
  • Which mode is used to ensure confidentiality by combining plaintext with a keystream generated from an incrementing counter value?
  • What should a web application developer implement to limit failed login attempts and mitigate brute force attacks?
  • A security analyst is tasked with improving defenses against malware that could evade detection. Which of the following should the analyst focus on?
  • What risk strategy involves ceasing the activity that is considered to be risk-bearing to avoid the associated risks entirely?
  • Which environment is specifically intended for final testing before software is released to production?
  • What is the total estimated financial impact of a single incident of server downtime called?
  • What does standardized log formatting facilitate in a central log management system?
  • What cloud service model provides a selection of operating systems that the customer can load and configure, while the underlying infrastructure and physical security are managed by the provider?
  • What is the focus of NIST SP 800-61?
  • For a service that communicates over HTTP using XML, which protocol ensures proper data exchange?
  • What tool is most appropriate for a software analyst debugging a Microsoft Windows application with a graphical user interface?
  • Which type of controller allows for configuration of its programming logic by the end user?
  • How does privilege escalation affect virtual machine security?
  • Which encryption algorithm is commonly combined with the Poly1305 MAC algorithm for secure encryption?
  • What cloud service model allows the provider to handle physical security and utilities while the customer manages their own operating systems?
  • Which system would an engineer implement to manage and automate workflows across multiple sites?
  • What MAC solution is used by Ubuntu, SUSE Linux, and other distributions, and is also known as a Linux Security Module (LSM)?
  • Which type of attack involves overwhelming a system with traffic to render it unavailable to users?
  • What is a potential risk of not implementing a central log management system?
  • Which foundational element of blockchain distributes computation across multiple systems so that no individual system can read the other parties' data?
  • Which step of the cyber kill chain involves seeking information about weaknesses with people and technology at the target organization?
  • To collect network metadata without capturing every packet, which method is recommended?
  • Which technology enables users to run multiple operating systems on a single physical machine?
  • Which of the following consists of files containing attractive data, such as user credentials and account numbers, that can lure adversaries?
  • Which audit area defines the timespan for which a company must keep its data, including both the minimum and maximum duration?
  • Which of the following is not directly related to key management but refers to the intentional spreading of data across different storage locations?
  • What type of product automates the discovery and classification of data types and enforces rules to ensure that data is not viewed or transferred without proper authorization?
  • What aspect of cybersecurity focuses on preventing malicious activity from exploiting software vulnerabilities?
  • Which standard focuses on IT security techniques, including the introduction and general model, as well as functional and assurance components that define various operations?
  • What architectural approach seeks to minimize trust levels for resources and users?
  • Which NIST standard provides guidance for developing test, training, and exercise programs for IT capabilities?
  • Which step in business continuity planning involves developing fallback options if planned strategies fail, and requires an accurate inventory to be effective?
  • What term describes attractive data used to mislead and trap adversaries in cybersecurity?
  • Which label is used for highly sensitive information in military organizations and is in the same category as critical information?
  • An administrator creates a SPAN port that feeds traffic to a security tool. What type of tool is used to monitor suspicious network traffic without blocking it?
  • Which type of analysis involves manually inspecting source code to identify vulnerabilities in programming techniques?
  • Which NIST publication includes a guide to test, training, and exercise programs for IT plans, along with an after-action report template?
  • Which type of threat actor could use cyber espionage to steal a tech company's product designs?
  • Which type of policy allows a company to own devices that can be used for personal purposes?
  • What standard should a security consultant reference for compliance with international IT security standards?
  • What is the main focus during the 'Identify' phase of the Risk Management Lifecycle?
  • Which type of environment is ideal for testing unknown third-party code and is also referred to as a malware analysis server?
  • Which NIST publication delineates essential security and privacy controls for auditing information systems during certification?
  • What is the main control mechanism emphasized by role-based access control (RBAC)?
  • What is a key advantage of implementing a Cloud Access Security Broker (CASB) solution in terms of controlling access to cloud services?
  • What standard focuses on guidelines for protecting personally identifiable information (PII) in cloud environments?
  • Which document describes the set of policies, contracts, and standards identified as essential in the agreement between two parties?
  • Which step is not part of the first three steps of the data life cycle but occurs later when data is no longer used regularly and is stored to reduce costs and complexity?
  • Which protocol facilitates sharing of information within a user profile between sites, allowing users to log in without sharing their password with the consumer site?
  • Which hashing algorithm was selected by NIST in 2012 as the successor to previous standards?
  • Which client authentication mechanism can help a server verify that a connection request is originating from a pre-authorized endpoint?
  • A website administrator is setting up a cluster of web servers and wants to ensure that if one server goes down, the system in place will route the traffic through the others. Which network appliance should the administrator use?
  • Which system is suited for large-scale industrial control, replacing the control server?
  • Which open-source NAC (Network Access Control) solution can integrate with Microsoft's public key infrastructure (PKI)?
  • Which system involves sensors, logic solvers, and control elements designed to return an industrial process to a safe state after detecting certain conditions?
  • Which of the following is NOT a characteristic of Diameter protocol compared to RADIUS?
  • During which phase are risks analyzed to assess their level of threat?
  • Which security control will secure a web-based credit monitoring service and protect credit information of consumers in compliance with FCRA requirements?
  • Which of the following best describes the role of a trusted certificate authority?
  • What type of test is used to validate the system's compliance with non-functional requirements?
  • A web developer needs to exchange data using standard HTTP methods. Which should they use for data formats like JSON or XML?
  • Which assessment framework is best suited for supporting a security architect's policies for safeguarding technology and financial operations?
  • Which type of actor might act against an organization to gain a financial advantage through illegal means?
  • Which of the following is a technical control that helps protect against attacks targeting personnel but does not directly manage personnel risk?
  • What process ensures that all account creation, modification, deletion, and account activity are logged and reviewed, serving as a method to manage personnel risk?
  • Which of the following defines how objects can interact with each other within a network?
  • What is the primary purpose of a Cloud Access Security Broker?
  • Which methods would likely guarantee that hard drive data is irrecoverable from advanced recovery methods?
  • Which type of attack poses a severe risk to the entire virtualized environment?
  • Which solution is ideal for file system integrity monitoring in data center environments?
  • What metric defines the maximum data loss a company can withstand without irreparable harm?
  • Which tool should a network administrator use to read and write data over TCP and UDP?
  • Which country, known for its comprehensive legal framework, is more likely to be chosen by a company focused on privacy and anonymity over the United States?
  • Which service lists the configuration and access levels of an instance and may expose it to vulnerabilities?
  • What is the impact of a finding that the recovery point objective is not satisfactory due to server backup schedules?
  • In what type of network do nodes self-organize to provide services typically associated with client-server networks?
  • Which technology helps to strengthen the resilience of a cloud presence?
  • Which key exchange algorithm allows two parties to establish a shared secret key without pre-shared secrets?
  • For establishing incident handling procedures, which publication should an incident responder reference?
  • What should a systems administrator do first when handling a litigation hold request involving sensitive HIPAA data?
  • Which key management practice involves considering secure locations to store cryptographic keys, to avoid accidental exposure or compromise?
  • What technology uses a virtual machine to provision corporate desktops, often replacing typical desktop computers with low-spec thin clients?
  • Which step in the data life cycle involves defining the locations used to house data, such as databases and file systems, and implementing mechanisms for data protection?
  • A systems manager is in charge of endpoint devices and wants to specify using a trusted CA. What should the systems manager specify?
  • Which type of scanning involves assessing endpoints with vulnerability assessment software and may involve providing credentials to see inside the device or application?
  • A network technician is setting up Extensible Authentication Protocol (EAP) but wants to ensure using the strongest authentication and widely supported type. Which type should the technician choose?
  • Which cloud model is completely private to an organization and typically managed by one business unit while others make use of it?
  • What risk is associated with live VM migration lacking proper authentication?
  • To focus on network-related information without including system logs, which should a security analyst collect?
  • What tool can help determine dependencies for a process during a security examination?
  • Which security tool provides a foundational level of protection for a network by blocking or allowing traffic based on pre-configured rules?
  • What is the advantage of having different subordinate CAs set up in the hierarchical CA model?
  • What is the technology called that generates computer-generated images and videos of a person that appear real but are actually synthetic?
  • What legal concerns must an organization consider when implementing site-to-site VPNs?
  • During an attack on integrated systems, which software solution was targeted?
  • RC4 is an example of which type of encryption?
  • What risk strategy focuses on reducing exposure to or the effects of risk factors?
  • What is the risk of denying a data request for HIPAA information without consulting attorneys first?
  • For contactless payments on point-of-sale machines, which technology is commonly used?
  • Which label is typically applied to highly sensitive information meant for viewing only by approved persons?
  • Which regulation enforces rules for organizations serving the European Union concerning data collection?
  • What type of threat actor engages in actions like defacing websites and launching denial-of-service attacks?
  • Which action replaces the original file with a notice that describes the policy violation and how it can be released?
  • What mobile device security issue involves allowing unknown sources to install apps from third-party websites?
  • Which standard focuses on cybersecurity audits and compliance, particularly relevant to the ISO 27k series?
  • Which NIST Special Publication identifies the necessary groups when responding to an incident?
  • Which of the following ISO 27k standards is specifically for information security controls in cloud environments?
  • What process ensures that an application can run independently on different systems by bundling necessary libraries?
  • What type of IoT device can be specifically used to gather environmental data?
  • During which process are data remnants most concerning in a virtualized environment?
  • Which network security solution would control access to a network and is open-source?
  • Which key agreement protocol should a developer use for authentication, relying on elliptic curve mathematics?
  • In quantum computing, what physical properties might represent quantum particle information in a qubit?
  • Which label is commonly used in military settings for sensitive information while companies might use a different term for the same level of sensitivity?
  • What does the acronym CSP stand for in cloud computing?
  • What is a common issue that may occur during a data recovery failover due to syncing issues or corrupt disks at the recovery site?
  • Which solution should be deployed to block SQL injection attacks on a web application?
  • Which trusted execution environment (TEE) mechanism can encrypt data as it exists in memory, preventing untrusted processes from decoding the information?
  • Which cloud model allows multiple organizations to reduce costs by sharing infrastructure while maintaining a private-like cloud experience?
  • In which scenario is the "data in use" state most critical to protect?
  • What is the primary impact of a security breach resulting from people-related flaws?
  • What benefit of a central log management system helps distinguish between critical events that need immediate action and less severe items?
  • Which tool should a forensic analyst use for analyzing a memory dump related to running processes during an investigation?
  • A defense contractor is setting up acceptable programs to run on a new jet. What should they establish?
  • Which type of scanner assesses endpoint devices, including computers, network equipment, and mobile devices, as well as the applications installed on them?
  • Regarding cloud security, what does the acronym CCM stand for?
  • Which of the following is commonly referred to as an identity management protocol?
  • Which NIST publication is the standard for Zero Trust Architecture, focusing on security based on resources such as users, services, and workflows instead of network boundaries?
  • Which solution would maintain the full management responsibility with the company's IT team without reducing their workload?
  • What mechanism allows the system to verify both the source and content of a message without using any other means?
  • Which country is considered the gold standard for privacy and anonymity due to its uniquely protective privacy laws?
  • A software developer is setting up a symmetric encryption block cipher with an initial chaining vector. Which will they use?
  • Which assessment type ensures that a vendor is financially sound and will likely continue its services?
  • Which regulation enforces rules for organizations collecting data on subjects in the European Union?
  • In risk analysis, what is an example of a primary factor in assessing risk severity?
  • What component is integrated into a System on Chip (SoC)?
  • What is the term for a mobile device policy that allows employees to choose from approved devices while maintaining company control?
  • Which hashing algorithm does bitcoin use for program development?
  • Which controller is most appropriate for engineers requiring post-manufacturing programming adjustments?
  • A Ruby developer is searching for a lightweight web application framework that supports third-party library extensions. What should they choose?
  • Which method involves all groups included in the BCDR plan identifying a representative to participate in a meeting to review the plans?
  • Which service model is optimal for billing based on actual usage, particularly execution time?
  • What type of cloud storage supports applications needing access to resources such as documents and videos?
  • Which type of response header is effective in securing resources against certain cross-origin scripting attacks?
  • APIs play a major role in interacting with which technology that allows applications to run independently in virtual instances?
  • What is a core function of a good business continuity plan?
  • A military unit is going into a foreign country and setting up a small data center for their operations but wants to have an alternate option that is flexible and versatile. Which of the following options would best suit their needs?
  • Which component specifically handles the conversion of private IP addresses to public IP addresses for internet access?
  • What is a significant benefit of using virtualization in IT environments?
  • Which message authentication code (MAC) is designed for speed and efficiency, particularly on devices without AES hardware acceleration, such as older iPhone and Android devices?
  • Which of the following is not part of the foundational elements of blockchain but supports cloud-based applications that need access to documents, videos, and image files?
  • What is the first step in the development of a Business Impact Assessment (BIA), similar to critical security controls?
  • Which technology integrates hardware and software into a single, low-power, high-performance unit for compact spaces?
  • A small business is looking at migrating to the cloud but wants as little administration responsibility as possible. Which of the following solutions would best suit them?
  • Which physical security control should be placed to provide full coverage of an area and prevent attackers from disabling it by gaining access to its back?
  • What type of testing can be performed by developers to assess software functionality in unexpected scenarios?
  • Which cryptographic protocol, used in WPA3, replaces AES CCMP to provide updated encryption?
  • During risk management activities, which phase utilizes quantitative and qualitative methods?
  • Which protocol uses SSL/TLS to secure directory access services?
  • How does a Cloud Access Security Broker (CASB) mitigate the risk of data exfiltration?
  • Which model describes five levels of maturity in operational or software capabilities?
  • What method can be used to verify that new code changes do not adversely affect existing system functionalities?
  • What is the main purpose of a cryptoprocessor in a smartcard?
  • To prioritize analysis of user interactions with software, which data type should an analyst focus on?
  • Which element is significant for the Common Vulnerability Scoring System (CVSS) score but is not a primary risk component?
  • A forensic analyst needs to examine the contents of a memory dump to investigate running processes, open sockets, and other volatile data. Which of the following tools is best suited for this analysis?
  • What access control mechanism involves defining access levels for users and subjects in a network environment?
  • Which type of analysis involves manually inspecting source code to identify vulnerabilities in programming techniques?
  • What does a checklist test require, involving the distribution of the BCDR plan to all the departments, teams, and other participants included in the plan?
  • A software developer is looking for a common framework for Java development. Which framework could they use?
  • What component of WPA3 enhances security by implementing stronger authentication mechanisms?
  • A website administrator wants a digital certificate that requires more rigorous checks. What could the administrator try to use?
  • What approach do systems administrators use to isolate a critical system from outside networks?
  • Which tool captures traffic in a networked environment and can store the captured traffic for further analysis using other software tools?
  • Which framework should a developer working in Java consider to manage web application development?
  • A solutions architect is analyzing technology for user and entity behavior analytics (UEBA). The solutions architect should analyze which of the following technology solutions?
  • What platform helps a company manage relationships with customers by providing data about those customers?
  • Which of the following components of WPA3 enhances the encryption techniques implemented in wireless communications?
  • What is the purpose of the 'Review' phase in the Risk Management Lifecycle?
  • What does the alert mode do in a data loss prevention solution?
  • What is the third step of the data life cycle that describes how data supports operational needs and objectives?
  • To improve a company's security posture with minimal infrastructure, which solution should be implemented?
  • What does Level 2: Managed signify within a process framework?
  • Which of the following is not a data sanitization type but a process to reduce seek times on a hard drive?
  • A systems designer needs to set up a protocol to facilitate secure authorization and access to resources within a user profile between sites without sharing passwords. Which protocol should the systems designer use?
  • What metric indicates how many times a single loss event is expected to happen annually?
  • A developer needs an authentication coding mechanism that supports older iPhone/iPad and Android devices. Which of the following would work best for the developer?
  • Which of the following is an example of an availability function rather than a PKI-supported feature?
  • Which disaster recovery test method involves activating a DR site as though it is the primary site, minimizing impact on production systems?
  • Which U.S. Department of Defense (DoD) resource provides Security Technical Implementation Guides (STIGs) for system hardening?
  • What approach is used in key management to ensure proper identification and ownership of keys?
  • What tool should a web developer use to interact with code in the browser without restrictions?
  • Which of the following is a characteristic of an FPGA?
  • A security analyst is actively responding to a detected indicator of compromise on a critical system. Which of the following actions should the analyst avoid during this time?
  • Which strategy involves using diverse, non-similar components to create a barrier that complicates an adversary's attempts to infiltrate before detection?
  • Which of the following is NOT an example of a benefit provided by a CDN?
  • Which method combines approaches like incremental and waterfall into a hybrid model for software development?
  • What type of information is used to identify an individual and includes details about their health and healthcare operations?
  • A systems administrator has a litigation hold for HIPAA data that is older than four years old. How should the administrator respond?
  • Why should cryptographic keys not be stored in public source code repositories?
  • What data sanitization method involves destroying the decryption key to make data recovery impossible?
  • How does a CDN help improve security in a cloud environment?
  • What does 'Critical' indicate when labeling data?
  • An application is experiencing a security flaw where the system checks the state of a resource, but the resource changes state before action is taken. What is this issue called?
  • Who is the entity held accountable for the protection of data under their control?
  • Which of the following is used to create cloud resources within private networks, similar to traditional data centers?
  • Which algorithm used in modern data encryption is designed for high performance in software implementations?
  • In which access control model are organizational roles defined, with subjects assigned to those roles for access management?
  • A developer is looking for a solution that will help to detect flaws, bugs, errors, and defects in applications running in production environments. What is this method called?
  • A security architect is setting up various security mechanisms for a retail company that handles a considerable amount of credit card processing. What industry-standard data masking technique should the security architect recommend?
  • Which of the following is NOT typically defended against by ModSecurity as it is a network layer defense?
  • Which solution contains software that monitors daily operations of an enterprise and reports on the status of various resources and activities?
  • How can an administrator harden a server by removing unnecessary FTP services without causing disruption?
  • Why should a systems administrator not immediately release HIPAA information in response to a litigation hold?
  • Which development method focuses on releasing small, well-tested code blocks as quickly as possible to bring functionality to the business?
  • A developer creating a web application in Python desires a framework that is designed for quick iterations and code re-use. Which framework would be most suitable?
  • In security audits, what does the term “least privilege” refer to?
  • Which of the following is NOT considered a strong hashing algorithm?
  • Which Risk Management Lifecycle phase primarily deals with threat assessment and prioritization?
  • Which of the following are examples of block ciphers?
  • What term defines how a system protects communication channels from risks such as infiltration, exploitation, and interception?
  • In the Lockheed Martin cyber kill chain, what step is discussed when a tool is delivered successfully?
  • Which risk component focuses on the scope and potential implications of an identified risk?
  • What are some common issues a consultant might expect to encounter during a data recovery failover scenario?
  • Which method focuses on testing all the infrastructure that supports the application, including networking, database functionality, and security?
  • What describes the deployment of an API-based Cloud Access Security Broker (CASB)?
  • Which part of the cipher "ECDHE-RSA-AES128-GCM-SHA256" represents the HMAC function?
  • Which algorithm is primarily used for signing and operates similarly to RSA (Rivest, Shamir, and Adleman) but is based on logarithmic and modulus mathematics?
  • Which of the following is a characteristic of mandatory access control (MAC)?
  • A software developer is troubleshooting cipher issues and sees the output "ECDHE-RSA-AES128-GCM-SHA256." Which portion is the part regarding HMAC?
  • Which protocol is specifically designed to combat replay attacks in WPA3?
  • What type of authentication requires multiple credentials or factors for access?
  • Which authenticated encryption mode is designed to provide strong message authentication and is fast?
  • What type of encryption is used to protect data in transit, such as website traffic and remote access traffic?
  • Which strategy reduces the threat surface on a new web application?
  • A Linux administrator is configuring ModSecurity for Apache servers. Which types of attacks should the administrator set rule configurations to protect against?
  • What allows connectivity between private subnets, or Virtual Private Clouds (VPC), and the Internet?
  • Which solution is focused on speed and efficiency and operates well on devices without AES hardware acceleration?
  • In the context of software development, what is a common issue that occurs due to multiple processes attempting to modify a shared resource at the same time?
  • Which publication provides comprehensive guidelines on security controls for information systems?
  • Which tool performs automated tasks, including system maintenance and status checks, often triggering scripts to run?
  • In the context of PKI, which of the following is a requirement for achieving non-repudiation?
  • What is the function of the Certificate Revocation List (CRL)?
  • Which tool is responsible for automatically generating and injecting malformed data into a system using various number formats, character types, text values, and binary values?
  • Which subset of Enterprise Mobility Management focuses on compliance and security for mobile devices?
  • Which encryption method is known for both speed and providing integrity checks through its associated data?
  • Which type of threat actor is primarily focused on seeking criminal profit through financial fraud or blackmail?
  • Which solution automates routine security tasks and responses to security incidents?
  • While patching may help prevent catastrophic events, why is it not considered part of the Business Impact Analysis (BIA)?
  • Which protocol ensures that critical systems are available and responsive with minimal downtime?
  • Which department can provide significant insights during a qualitative analysis of intangible assets?
  • What arrangement includes forty-two participating states and is designed to prevent the destabilizing accumulation of weaponry and military capabilities?
  • What resource is most useful for an incident responder creating an incident response plan?
  • Which cloud solution offers a managed turnkey disaster recovery process for small data centers with few personnel?
  • Which type of firewall can identify and filter out malicious traffic using sophisticated rules, specifically for web-based attacks?
  • In industrial environments, what are control computers used for direct automation in assembly lines called?
  • Which EAP (Extensible Authentication Protocol) type uses a server-side certificate to establish a protected tunnel, similar to PEAP (Protected Extensible Authentication Protocol)?
  • Which mobile device policy allows employees to use their personal devices if they meet specific company requirements?
  • What is important to establish when defining the maturity of vendor security operations and setting requirements for vendors?
  • What should be the top priority in disaster recovery planning over systems with critical vulnerabilities?
  • What is the process called when a user gains root access to an Android device?
  • Which component, often used in projects to speed up development, may also introduce potential security vulnerabilities?
  • Which security solution employs mandatory access control policies to run applications in sandboxes on Android devices?
  • While the system is operational, an industrial control systems engineer assesses analyses on packet capture and traffic analysis. What type of analysis is this?
  • Which of the following tools analyzes network activity to detect suspicious traffic, unauthorized account use, and support threat hunting, but is not a data source?
  • In which phase of the Risk Management Lifecycle do practitioners identify risks and create a foundational inventory?
  • A security architect is designing a strategy to help continue operating in the face of a cyber-attack. Which of the following will help to accomplish this objective?
  • Which process detects flaws, bugs, errors, and defects in applications running in production environments?
  • During the extended validation process for domain names, which certificate feature is not feasible?
  • Which actions can ensure the integrity and authenticity of a company's cloud infrastructure?
  • Which identity proofing method involves a combination of two factors, such as something a user knows and something a user has, for authentication?
  • What is the primary goal of a firewall in a network security architecture?
  • Which solution is typically associated with military establishments and enforces mandatory access controls between connected sites?
  • What principle involves granting users the minimum account privileges necessary to perform their duties, helping to mitigate both insider threats and compromised accounts?
  • What vulnerability is associated with default administrative credentials being misconfigured in software?
  • What action does a server engineer take to document certificates during the certification life cycle?
  • Which framework, maintained by ISACA, addresses IT risk from a business perspective?
  • What does RADIUS primarily serve in a network environment?
  • What is the primary focus of the Capability Maturity Model Integration (CMMI) for organizations?
  • A security engineer looks to change the Extensible Authentication Protocol (EAP) authentication method. If the current solution uses the Protected Access credential, which EAP implementation does the engineer look to replace?
  • Which technology allows the client to either access an application hosted on a server or stream the application for local processing?
  • What type of information can be used to identify an individual, including names and social security numbers?
  • A vulnerability management lead recommends purchasing an insurance policy for legacy systems. What type of risk strategy is this?
  • A systems administrator wants to enable a setting to make it difficult for buffer overflow attacks to locate the area of memory needed to successfully perform an exploit. What is this called?
  • Which cloud service model requires the least amount of management and maintenance from the customer, with the service provider handling all aspects including applications?
  • Which of the following is true about a port scanner in cybersecurity?
  • Which risk strategy involves assigning risk to a third party, often through purchasing an insurance policy?
  • A security consultant reviewing live virtual machine vulnerabilities should prioritize which of the following aspects?
  • A software developer wants to ensure that an application includes all required libraries during compile time, allowing it to run independently without external dependencies. Which of the following describes this process?
  • What is often used to automate the process of checking system security, configurations, and compliance levels?
  • Which option, while often seen as a modern solution, does not by itself ensure security without a proper defense-in-depth strategy?
  • Which of the following best describes the purpose of a vulnerability scan?
  • What is the purpose of using a hardware security module (HSM) in an enterprise?
  • Which type of alternate site includes a scaled-down data center that can run critical systems and software but is not as immediately operational as a hot site?
  • A developer creates a mock SSH application to capture interactions for analysis. Which strategy is this an example of?
  • Which global standard is designed for secure processing of credit card information?
  • What does the NIST 800-63 standard primarily focus on?
  • What type of system is an oil engineer likely to use for managing process automation on a single site?
  • Which of the following is a popular source for system hardening, with a compliance checker tool provided by the U.S. Department of Defense?
  • What is the main purpose of the OAuth protocol in security architecture?
  • Which tool automates routine tasks typically performed by security personnel in response to a security incident?
  • A digital manga artist is meeting with a security professional to control how consumers use digital content after it is published. Which solution should the security professional recommend?
  • In the context of testing, what enables the developer to identify broken functionality after a code change?
  • Which process is basic and involves setting up a new file system on a storage device?
  • Which security technology will automatically secure sensitive data as it is stored on a company's devices?
  • Which two forms of segmentation would typically be included in a risk assessment consultation?
  • Which of the following describes integrity in the context of information security risks?
  • Which type of analysis involves inspecting a system and software as it operates, with examples including packet capture and traffic analysis?
  • A vulnerability manager is onboarding developers to the vulnerability management program and wants to focus on integrating security from the very beginning. What is the first step of the software development lifecycle the manager should integrate?
  • During the Risk Management Lifecycle, which phase should a security architect allocate the most hours?
  • Which tool is most suitable for performing live collection of system information from a powered-on server?
  • Which model describes five levels of maturity within an organization's operational or software capabilities?
  • Which of the following is a security mechanism that prevents execution of code in certain memory regions?
  • Which method involves removing information that can uniquely identify an individual from data so that it can be shared without violating privacy laws and regulations?
  • A young technician is in charge of the security awareness program for an organization and begins looking at common attack vectors. Which tools are best suited to help defend against social engineering attacks?
  • In the context of cybersecurity, what does the term ‘tokenization’ specifically help to achieve?
  • Which storage type employs a hierarchical file system for organizing files by path with attributes like owner and permissions?
  • What term identifies the laws governing the country where the company stores data and controls over its collection and use in a global economy?
  • What tool is best for comparing functionally identical files that may have been obfuscated?
  • Which type of certificate requires more rigorous checks on the subject's legal identity and control over the domain?
  • What issue occurs when the system checks the state of a resource, but the resource's state changes after the initial check?
  • A security architect is considering the design for an organization's transactional records and is currently researching blockchain. What are some of the foundational elements of blockchain technology? (Select all that apply.)
  • What specific action do security consultants recommend during a tabletop exercise?
  • A system administrator is setting up a central log management solution. What are some of the benefits to doing so?
  • When a company provides a list of devices for employees to select, which mobile device policy does that represent?
  • Which type of service agreement typically includes performance metrics and emphasizes a partnership with the vendor?
  • Which method allows for alternative ways of authentication and is based on the principles of federated identity systems?
  • Traffic originating from a country without business operations may suggest what?
  • What type of alternate site can be described as a "data center in a box" and is commonly used by the military?
  • What type of deceptive tool is best for tight control and monitoring of network attacks?
  • In the context of risk assessment, which term describes the frequency at which a threat may occur?
  • What type of scaling is achieved by adding more memory and processor cores to a virtual server?
  • In a scenario where a network is designed to prevent unauthorized access, which approach is typically implemented?
  • What strategy involves evaluating risks and opting to continue with potential consequences?
  • Which component of WPA3 replaces the traditional 4-way handshake mechanism?
  • Which continuous process is often associated with detecting security vulnerabilities, but can also be used by developers to find issues while generating new code?
  • Which method is likely to consume the most storage when analyzing network traffic?
  • A security architect for a university wants to set up a federation method commonplace in their industry. Which of the following is routinely known for being used by universities?
  • Why is it important to adopt the principle of least privilege when securing logs in a central log management system?
  • What type of mobile device policy allows the company to provide devices that can be used for both work and personal activities?
  • What could cause software not to work when brought up from recovery during a data center failover?
  • Which type of certificate allows the use of the certificate for multiple subdomains by containing an asterisk in its domain name?
  • What is assessed during a compliance audit to ensure data handling practices meet legal standards?
  • Which category is specifically protected by the Children's Online Privacy Protection Act (COPPA) but is not the only group that privacy data aims to protect?
  • Which devices in an IoT system are responsible for measuring factors such as temperature, humidity, proximity, motion, and more?
  • Which solution can inspect higher-level protocols to provide more granular protection against malicious traffic?
  • What action should a developer implement to strengthen authentication security against broken authentication?
  • What formal mechanism is used to measure the performance of a program against its desired goals?
  • Which of the following is NOT a Type 1 hypervisor but instead an operating system that includes the option to install Microsoft's Type 1 hypervisor?
  • Which technology solution takes complex concepts and breaks them into simpler elements?
  • Which Type 1 hypervisor is provided by Citrix and requires the hardware to support both the hypervisor and the guest operating systems?
  • Which physical security control should be implemented to eliminate dark spaces and support the capture of clear video?
  • A network administrator is tasked with scanning a range of IP addresses to identify active hosts and services in the network. Which of the following tools should be used to perform this task?
  • What element of a risk management program is essential for ensuring consistency and reliability, but is not necessarily the most recognized output?
  • Which standard addresses IT security techniques, including the introduction and general model, as well as functional and assurance components?
  • Which technology provides Quality of Service (QoS) features required by modern industrial applications?
  • Which protocol encrypts packets and provides both data integrity and confidentiality?
  • What solution has a systems security engineer provided by using a hardware security module (HSM)?
  • What is the ultimate goal of the 'Control' phase within the Risk Management Lifecycle?
  • In quantum mechanics, what term describes a system being in a specific state due to observation?
  • What term refers to data collections that are so large and complex that they are difficult for traditional database tools to manage?
  • What type of network behavior might signal a security issue in an organization's systems?
  • Which type of intelligence is focused on collecting information through direct human interaction to understand and influence people?
  • What should have been performed during the initial stage of business continuity planning, rather than during a privacy impact assessment (PIA)?
  • Which agreement goes beyond the provisions of an SLA to include metrics and measures related to information privacy and data protection?
  • What is the limitation of Diffie-Hellman (DH) when used for key agreement?
  • Which protocol enhances network security by providing data encryption and authentication between two devices?
  • What is a primary function of a CASB regarding cloud data management?
  • At what point in the SDLC should security policies, standards, and regulatory requirements be identified to ensure compliance?
  • Which method allows a process to efficiently check if a certificate is revoked?
  • Which type of assessment is practical and useful for consistently identifying and remediating vulnerabilities within an organization's environment?
  • Which organization offers a vast library of guidance on secure coding practices, including topics like input validation, output encoding, and authentication management?
  • Which service model provides resources like servers and storage but requires the most amount of administration responsibility from the client?
  • What is a common risk when multiple unnecessary services are running on a server?
  • Which identity proofing method generates a software token on a server and sends it to a resource assumed to be safely controlled by the user?
  • Which strategy will best mitigate risks associated with a new vendor's access to sensitive customer data?
  • What is a key characteristic of middleware in software architecture?
  • A data center manager is planning for disaster recovery. What key element should the manager first gain that is critical to success?
  • Which network appliance is used to provide fault tolerance by re-directing traffic when one server in a group becomes inoperable?
  • In a privacy impact assessment (PIA), why is it important to analyze the sensitivity level of privacy data?
  • What type of vendor assessment is concerned with the ongoing financial stability of a vendor?
  • What security feature ensures a computer is not hijacked by a malicious OS while requiring UEFI?
  • What mechanism does WPA3 utilize to help ensure protection against man-in-the-middle attacks?
  • What function transforms an input into a fixed-length hexadecimal output, also known as a digest?
  • A helpdesk administrator is implementing encryption for data at rest for their Enterprise Windows clients. Which of the following is a common solution?
  • What type of system is highly hardened, closely monitored, and typically used to perform administrative tasks or access servers in a secured environment?
  • Which aspect is NOT supported by Public Key Infrastructure (PKI)?
  • What term describes a customer's high dependency on a vendor's products or services, complicating vendor changes?
  • What approach do developers use to identify open source code in their software?
  • What NIST standard can a security architect reference for guidance on password compliance?
  • What is a key benefit of using a System on Chip (SoC) in electronic devices?
  • Which tool evaluates operating system files, such as the Windows registry, to identify any unauthorized changes?
  • Which firmware interface can enforce boot integrity checks and allows the host to boot to an operating system?
  • Which of the following tools serves as a data source by providing logs and other information for security data analytics?
  • What component is related to both people and processes but is not a primary category for identifying security flaws?
  • Which solution provides security and management for mobile devices across an organization?
  • What type of information is the consultant auditing in a compliance audit for a hospital?
  • A major retail company needs to set up alternate sites so that despite any unforeseen circumstances, the business has as little impact on its operation as possible. Which of the following would be the best setup?
  • What is the advantage of having subordinate CAs (Certificate Authorities) set up under the root CA (Certificate Authority)?
  • Which blockchain technology assigns a hash value to each block and includes the hash value of the previous block in the next block's calculation, linking them cryptographically?
  • In ABAC, which factors are considered when making access decisions?
  • Which encryption mode applies an initialization vector and an incrementing counter value to generate a keystream, making it more efficient than modes that require padding?
  • A vulnerability manager must comply with certain regulations for the organization's industry. What should the manager most likely do to comply?
  • Which analysis method is typically used to explore vulnerabilities through manual code inspection?
  • A security code reviewer is setting up an environment for an organization that can analyze third-party libraries. Which type of environment should the reviewer set up?
  • Which model enables access decisions based on both system-wide and context-sensitive attributes?
  • Which protocol was superseded by GCMP for authentication in WPA3?
  • Which type of scan compares a computer or software configuration and patch level against pre-determined settings within a content baseline?
  • A security architect is setting up their demilitarized zone to place one firewall on each side. What is this type of configuration called?
  • What could cause Business Continuity and Disaster Recovery (BCDR) development work to come to a halt, even if plans are in place?
  • If a security analyst has limited storage, which type of data is the best for traffic analysis?
  • Which solution streamlines the incident response process during a cyberattack?
  • Which encryption method is commonly used to protect data in transit, including website traffic, remote access, and cloud synchronization?
  • Which NIST Special Publication provides a guide to test, training, and exercise programs for IT plans and includes an after-action report template?
  • When evidence preservation is crucial in an investigation, which forensics process is prioritized first?
  • Which security solution is responsible for filtering unwanted email based on predetermined criteria?
  • Which detection system is best for continuous monitoring of intrusions on host-based systems?
  • What is the primary focus of NIST Special Publication 800-207?
  • What term describes how long systems or applications can be down before significant harm occurs?
  • What certificate can a developer use to show that a browser plugin is trusted and has undergone an identity check by a certificate authority (CA)?
  • Which certificate type can be used to secure multiple subdomains under the same domain?
  • What issue occurs when the system checks the state of a resource to verify its state, and then performs an action based on that check, which may become invalid?
  • What term would a security architect use to describe all of the suppliers, vendors, and partners needed to deliver a final product?
  • A system administrator wants to send an email with an attachment through encrypted means. Which of the following should the sysadmin use?
  • A developer wants to create a web application using Python that promotes code re-use and facilitates rapid development. Which framework is the best fit?
  • Which of the following best describes the term 'Confidential' in an organizational context?
  • Which part of the cipher "ECDHE-RSA-AES128-GCM-SHA256" is used for signatures?
  • Which response header limits documents from loading from origins other than the source but would not mitigate XSS Inclusion attacks?
  • Which technology emulates a real-life environment through computer-generated sights, sounds, and sometimes smells and touch but is not commonly used in UEBA?
  • What term describes when a certificate establishes a trust relationship between two different certification authorities?
  • What solution can improve website speed and performance in case of high traffic due to a disaster?
  • Which security design would be most appropriate for protecting a high-value asset in a sensitive facility, such as a nuclear power plant, by isolating it from any network?
  • A security practitioner is conducting a privacy impact assessment (PIA) as part of a business continuity plan. What should the practitioner assess?
  • What type of agreement is best for setting expectations and preventing additional service requests from companies?
  • In data classification, what classification is used for documents intended strictly for internal use within the organization?
  • What is a common method used to secure wireless networks from unauthorized access?
  • Which of the following best describes a zero-day vulnerability?
  • In a central log management system, which approach is best for ensuring data integrity and security?
  • Which metric indicates the percentage of an asset's value lost during a risk event, used for calculating SLE?
  • Which NIST publication should a security architect refer to for the most recent guidance on password compliance?
  • Which of the following is not the primary focus of privacy data protection, as privacy data typically refers to information that can identify individuals?
  • If a help desk manager observes a high volume of incoming calls, what is the most likely conclusion?
  • What is a key advantage of EAP-TLS (Extensible Authentication Protocol-Transport Layer Security) over other EAP types?
  • Which risk management measure helps in reducing the risk levels by involving investments like insurance?
  • Which standard defines security controls and provides guidelines for organizational security standards?
  • What device is typically used for facilitating Z-Wave or Zigbee communication in IoT systems?
  • Which tool is most effective in defending against social engineering attacks, especially since attackers use it to directly access staff and employees?
  • A network administrator is searching for an open source network access control (NAC) solution to integrate with the company's public key infrastructure (PKI) environment. Which of the following could the administrator use?
  • A cloud engineer is setting up controls between VPCs. Which of the following should the engineer use?
  • What process involves an independent audit to review the information system and associated documentation to ensure necessary controls are implemented, as outlined in NIST SP 800-53?
  • What term best describes a protocol for verifying the successful connection between devices for secure communication?
  • In threat modeling, which approach is often used to identify potential vulnerabilities by simulating an attack?
  • What method is used to protect data in use, such as when it exists in memory, preventing untrusted processes from accessing it?
  • Which service uses public cloud resources for Disaster Recovery, providing an offsite DR site for businesses?
  • Which boot process enhances security but does not require a Trusted Platform Module for operation?
  • What process identifies and evaluates the impact of updating a disaster recovery plan?
  • Which security measure is defined by its ability to highlight what is allowed to run while blocking everything else?
  • What objective is a security architect defining in a business continuity plan when assessing how much data can be lost without harming operations?
  • Which framework is created and maintained by ISACA to frame IT risk from a business leadership perspective?
  • Which of the following is a hardened and closely monitored system used for performing administrative tasks or accessing servers in a protected environment?
  • Which protocol is most commonly associated with facilitating communication between different devices in an OT network?
  • Which of the following is best done before an incident or during an after-action review, rather than during the actual response to an incident?
  • Which remediation action prevents the user from copying a file but still allows them access to it, logging the violation?
  • Which attack allows a malicious script to execute whenever a user views a webpage, due to an injection in the comment section?
  • A software developer needs to be able to run various versions of Android on an x86 system. Which virtualization technology will allow the software developer to perform this?
  • What is the best solution to prevent medical researchers from sharing protected health information (PHI) data?
  • Which network architecture places two firewalls on either side of a demilitarized zone (DMZ) to control traffic between public networks and protected internal networks?
  • What has a company established by determining the probability of a threat being realized?
  • What type of analysis emphasizes the examination of system operations in a live environment?
  • What is one key outcome of the accreditation process under a Certifying Authority?
  • Which consideration is important when performing an onsite penetration test to comply with corporate policy regarding access and staff limits?
  • What authentication method is used to protect access to corporate resources during device enrollment?
  • What minimum requirement should a CASB address when mediating user access across various devices?
  • Which security testing method is typically used in addition to other methods and is associated with continuous development and CI/CD environments?
  • Which step in business continuity planning involves identifying the systems and assets that exist before any preventative measures can be established?
  • When implementing zero trust security, how should vulnerability scans for a cloud-based infrastructure be conducted?
  • Which protocol is commonly used for secure user authentication in PKI?
  • Which type of cipher does RC4 belong to?
  • What is the key difference between Elliptic-Curve Diffie-Hellman (ECDH) and standard Diffie-Hellman (DH)?
  • A forensics investigator is experiencing a problem where the state of the item checked changes after the initial check. What is it called after it changes?
  • A mid-sized company wants to integrate code scanning into their process while keeping costs low. Which security testing method involves add-ons to an IDE to evaluate source code developed in a specific language?
  • A small business owner is reviewing third-party vendors to manage the server environment. What document should the business owner draft to define data protection and privacy protection requirements?
  • Which protocol is known for providing a more efficient way to check a certificate's status without a complete list?
  • Developers that are working on a web application use coding practices to prevent insecure references. What vulnerability have testers uncovered?
  • What is the primary data asset type being protected by enhanced security controls on a business network?
  • What consequence arises if the same hash is generated for two different files?
  • What protocol enables network interoperability for connected machines and supports scalability, performance, and Quality of Service (QoS) features in modern industrial applications?
  • What is the term used for assessing the measure of a vendor’s product and its financial stability?
  • During which phases of data lifecycle are regulatory restrictions focused on data retention and disposal methods?
  • Which database is best for a development team looking for a document-oriented, open-source solution?
  • In cybersecurity, which tool is crucial for monitoring user behavior and identifying anomalies?
  • What is the primary objective of using a digital signature in federated identity management?
  • What is the primary goal of using Data Loss Prevention (DLP) systems?
  • A security analyst notices a spike in inbound traffic that deviates from normal patterns. This could indicate which of the following?
  • Which backup solution is best for a mid-sized company with limited personnel looking for cloud solutions?
  • Which security control will mitigate the risk of a successful phishing attack on a financial institution's employees?
  • What is a common use of a Virtual Private Network (VPN)?
  • What deceptive technique involves creating realistic but false data to mislead attackers?
  • Which U.S. law applies to medical information and is not applicable outside the United States?
  • In which phase of development is SAST most effective?
  • What does 128-bit AES-GCM (Galois Counter Mode) represent in a cipher suite?
  • What is the correct sequence of steps in the risk management process for a new telemedicine platform?
  • Which type of analysis involves deconstructing software and hardware to determine how it works and to see how much information can be extracted?
  • What tool can a security analyst use to capture network packets for further analysis?
  • Which department is key in a qualitative risk assessment regarding a company's brand image?
  • What is the most effective risk mitigation process to address a vulnerability in a Kubernetes deployment?
  • During which SDLC phase are Static Code Analysis tools, linters, and automated unit tests used to identify vulnerabilities while writing code?
  • Which of the following is a necessary component to generate a public key?
  • Before allocating staff resources to work on Business Continuity and Disaster Recovery (BCDR) planning, what critical element must first be secured?
  • What does a CASB primarily help organizations manage in relation to cloud applications?
  • Which technology is specifically designed for encrypting data at rest and incorporates FIPS 140-2 standards?
  • A security researcher wants to deconstruct software to determine how it works. What is this type of analysis called?
  • In a data loss prevention system, what action involves preventing all access to original files while notifying the user?
  • What does the likelihood component of risk evaluate?
  • Which of the following is not a feature or ability of a Cloud Access Security Broker (CASB) solution?
  • Which protocol is a serial communications bus used primarily in the automotive industry for connecting electronic control units (ECUs)?
  • What document is necessary to outline corrective actions and ongoing monitoring of an information system?
  • Which technique provides a secure operating system with access controls for user applications in a financial institution?
  • A political organization's website is defaced with messages protesting its policies, and confidential emails are released to the public. Which type of threat actor is most likely responsible for this attack?
  • What type of encryption algorithm is RC4?
  • What is a common method used to protect data at rest using encryption, often seen in Microsoft environments?
  • Which approach is essential for tracking and managing vulnerabilities within a system?
  • Which component of PKI is responsible for issuing certificates to users or devices?
  • What type of segmentation allows for separate operational and information technology networks?
  • Which concept creates a blend of complexity through diversity, slowing down an attacker's progress and granting more time for detection?
  • In which type of networking application are policy decisions made at the control plane level?
  • What type of attack involves a malicious script being inserted directly into a vulnerable web application?
  • Which federated identity method, based on SAML, is commonly used by universities and public service organizations?
  • An engineer is searching for something that incorporates both hardware and software capabilities, uses low power while maintaining great performance, and also takes up less space. What is the engineer looking for?
  • In evaluating a software company's supply chain, which components are most likely to be included?
  • A security auditor is conducting a compliance audit for his company. Which audit area would describe how long the company is required to keep copies of data?
  • Which phase involves the periodic re-evaluation of risks to confirm their current threat levels and effectiveness of controls?
  • Which type of system involves creating an unchangeable core that remains usable but not re-configurable?
  • Which virtualization technology allows an x86 computer to run the Android OS or software designed for systems like Nintendo or Xbox?
  • Which type of alternate site provides close to real-time activation with little to no service disruption but is the most expensive and complicated to implement?
  • What type of database contains information on assets and components within an enterprise's IT environment?
  • Which response header can a developer use to protect against Cross-Site Script (XSS) Inclusion attacks?
  • Which ISO standard is part of the cloud standards focused on cloud privacy?
  • In the hierarchical model, what is the same as an intermediate CA and can be set up with different certificate policies?
  • Which term is not an industry standard but is important for establishing the necessary controls to protect data, such as security configurations and access controls?
  • How is a critical system protected when placed on a subnet between two firewalls?
  • Which technology is primarily used to connect devices like keyboards, mice, headsets, and IoT devices, but is also vulnerable to attacks such as BlueBorne?
  • What security technology can detect and respond to suspicious activity on a company's computer systems?
  • Which type of firewall architecture places a firewall both before and after a DMZ?
  • Which kind of technology is primarily used to deceive attackers and collect information about their methods?
  • Which encryption mechanism is specifically designed to protect data as it exists in memory, preventing untrusted processes from decoding it?
  • What role does communication play in the context of security processes?
  • What happens to a file when it is quarantined in a data loss prevention system?
  • What is the purpose of a vulnerability assessment in cybersecurity?
  • What involves pre-configured lists of certificate authorities typically stored within browsers or operating system configurations?
  • Which cloud storage type is required for high-speed data access and performance, especially for transactional applications?
  • What are the first three steps of the data life cycle?
  • Which plan focuses on addressing the tasks required to bring critical systems back online during the most frantic and pressing events?
  • What type of remediation policy is implemented if users cannot copy files but can read them?
  • Wireless engineers at a large communications provider rollout Wi-Fi Protected Access 3 (WPA3) at a client site. Which features influence the decision to utilize WPA3 over WPA2?
  • What does EMM stand for in the context of mobile device management?
  • Which technology helps mitigate DNS spoofing and poisoning attacks?
  • What term defines the threshold where recovery efforts may exist, focusing on critical operational systems?
  • Which of the following is not a benefit of 3D printing, but rather a potential drawback related to liability?
  • What type of system is designed to manage process automation at a single industrial site?
  • Which key management practice is crucial in order to ensure compromised keys do not remain vulnerable?
  • What is the role of subordinate or intermediate CAs (Certificate Authorities) in a hierarchical certificate model?
  • What type of solution is deployed by Systems Administrators when utilizing a virtual desktop infrastructure?
  • A software process that authenticates through certificates can check for validity using which of the following methods?
  • In which log would an event related to a failed application startup due to a malicious process be recorded on a Windows server?
  • Which method is commonly used to analyze and determine the vulnerabilities within a network system?
  • Which protocol improves upon RADIUS (Remote Authentication Dial-in User Service) by addressing some of its weaknesses but is not commonly used as an identity proofing method?
  • What is one of the primary goals of vulnerability management in cybersecurity?
  • What is a key benefit of enforcing email protection as a cybersecurity measure?
  • In what type of scenario is risk response identification commonly executed?
  • What evaluation measures security capabilities of a cloud service provider against Cloud Controls Matrix?
  • Which solution is specifically designed to automate security incident responses, helping reduce the workload on security personnel?
  • Which option can effectively manage permissions and access to sensitive files?
  • Which access control model empowers the resource owner to manage access permissions, typically the creator of the resource?
  • A motivated technology analyst is starting a company focused on privacy and anonymity. What country would the technology analyst most likely want to operate from?
  • Which function does a load balancer primarily serve in a distributed server environment?
  • What system allows users to authenticate and gain access to various service providers by issuing a token?
  • Which of the following primarily focuses on device identity and access policies?
  • Which metric indicates the potential alteration of information if a vulnerability is successfully exploited?
  • Which tool should an incident handler use for hashing during an incident?
  • Which environment is a mirror of the production environment used to test changes to infrastructure, software, and data?
  • When planning a penetration test, what aspect should be a priority to ensure the safety of systems being tested?
  • Which software solution is designed to detect and prevent sensitive information from being used, transmitted, or stored inappropriately?
  • What process describes the creation or removal of virtual machines or instances, beyond just the basic provisioning of resources?
  • A large retail chain falls victim to ransomware, with attackers demanding payment to restore access to encrypted data. Which type of threat actor is most likely responsible for this attack?
  • What should a cloud administrator examine to see all configuration and access levels for an instance?
  • Why is it important to collaborate with business units when identifying mission critical systems?
  • Which entity accepts requests for digital certificates and validates that the requestor has authorization?
  • Which NIST document is specifically designed to help identify the groups necessary for responding to a security incident?
  • A forensics analyst needs to extract and analyze metadata from various image and document files as part of an ongoing investigation. Which tool should the analyst use to read and write file metadata?
  • What does the AS grant to the user after processing the TGT request?
  • Which encryption method is used to protect data at rest on Microsoft Windows computers, typically using AES (Advanced Encryption Standard)?
  • What type of agreement occurs between two entities that need to share data via an interface, focusing on security considerations?
  • Which standard segmentation options could a risk assessment consultant offer?
  • Which development model uses iterative processes to release well-tested code in smaller blocks, with development and provisioning tasks conceived as continuous?
  • Which tool provides visibility into cloud applications and enforces data security policies?
  • Which emerging technology could significantly impact the security of current encryption methods?
  • Which key exchange protocol is based on elliptic curve cryptography and is similar in operation to standard Diffie-Hellman?
  • Which NIST Special Publication provides guidelines on establishing and operating an incident response capability within an organization, identifying the necessary groups involved in incident response?
  • A security administrator has a server environment where most files don't change much, and the administrator wants to implement a solution that monitors for changes. What should the security administrator implement?
  • Which element is not typically part of a penetration test assessment unless specifically requested by the customer?
  • A security engineer is trying to identify appropriate groups to help determine which groups should be part of incident response. Which guide could they use?
  • Which functionality allows a mobile device to maintain a constant VPN connection?
  • Which cryptographic protocol is best for securing data transmission in a new software application processing sensitive information?
  • Which security control will secure web applications and protect personal data of EU residents in compliance with GDPR?
  • Which Linux-based security solutions enforce MAC policies to restrict access and control system behavior?
  • Which agreement focuses specifically on the exchange of data between organizations and includes security controls?
  • Which trusted execution environment (TEE) mechanism can encrypt data as it exists in memory to prevent decoding by untrusted processes?
  • Which approach is used by a development team integrating incremental and waterfall methods?
  • In deploying a Cloud Access Security Broker (CASB) solution using a reverse proxy, how is the CASB configured?
  • What is the common term for the symmetric key algorithm that utilizes a larger key size for enhanced security when compared to its predecessors?
  • Which aspect of vendor management involves determining if a vendor will remain in business over time?
  • When dealing with sensitive data, which encryption method is often employed for data storage?
  • Which NIST Special Publication outlines the necessary controls for audits of information systems used for certification, focusing on security and privacy controls?
  • A security analyst is determining a process for some important infrastructure elements to leverage when responding to a valid indicator of compromise. Which of the following would NOT be a normal step?
  • Which type of agreement typically serves as an "umbrella" contract, establishing the terms for business between two entities over a defined period?
  • What component of risk is most closely associated with the concept of damage assessment?
  • Which measure does NOT protect against broken authentication for a web application?
  • Which type of security tool would be least effective at preventing social engineering attacks but is crucial for defending against web-based attacks?
  • In the hierarchical model, what does a single certificate authority (CA), called the root, issue certificates to?
  • In a cloud environment, what controls inbound and outbound traffic between networks, particularly between virtual private clouds (VPCs)?
  • Which measure involves assigning risk to a third party, such as through insurance, to reduce residual risk?
  • When modernizing an application that used Flash, which technology is recommended for avoiding browser plugins?
  • Which word describes due care, which is intentionally open-ended and focuses on what is "reasonable and expected" under different circumstances?
  • What is one of the crucial roles of CASB in cloud security?
  • When a developer writes a simple "pass/no pass" test for code, what type of test is being performed?
  • What type of attack occurs when a user unknowingly clicks a link that reflects a malicious script back to their browser?
  • Which type of testing focuses on the functions of individual software components?
  • During which phase of the Lockheed Martin cyber kill chain is persistent access typically established?
  • Which organization is known for creating international standards utilized across various industries?
  • Which block cipher mode of operation prevents manipulation of ciphertext by prior ciphertext blocks?
  • What type of agreement typically serves as an "umbrella" contract between two entities to conduct business during a defined term?
  • Which option is not a method of network segmentation but protects communication channels from infiltration?
  • Which type of contract typically serves as an "umbrella" agreement between two entities to conduct business during a defined term?
  • Which CA model involves a root CA issuing certificates to several intermediate CAs, which in turn issue certificates to end users?
  • Why might Demilitarized Zone (DMZ) systems, despite their extra risk factor, not be prioritized over mission critical systems in disaster recovery planning?
  • A digital forensics expert needs to extract metadata from image files as part of an investigation. Which of the following tools is designed to read and write metadata for a wide variety of file formats?
  • An owner of a small company produces digital manga in the United States, but it has also become very popular in Japan. Which privacy law should the owner comply with to set up an operation in Japan?
  • A system engineer is trying to explain due diligence to a group of system administrators. What word would best describe the idea behind due diligence?
  • What is the purpose of a general purpose certificate?
  • Which component serves as a critical storage solution for developers managing their code in a software supply chain?
  • What data integrity control mechanism is used to locate invalid, obsolete, redundant, or outdated data from a database or data warehouse?
  • Which process uses platform configuration registers (PCRs) in the TPM during the boot process to ensure system integrity but is not related to encrypting data at rest?
  • In which category can ambiguous processes lead to security breaches, such as fraudulent email requests?
  • What does a certificate signing request (CSR) contain?
  • Which risk management strategy can minimize SQL database breach risks?
  • Which risk mitigation process should a company use to address vulnerabilities identified in a cybersecurity assessment?
  • Which preventive measure can protect sensitive data while it is actively processed on a system?
  • Which of the following features is NOT a characteristic of Encapsulating Security Payload (ESP)?
  • What part of a resilience strategy involves preparing specific responses to potential events, ensuring the organization is ready to act when necessary?
  • Which industry-standard data masking technique is recommended for credit card processing, where a token represents sensitive data records such as a credit card number?
  • What measures should a disaster recovery manager assess to determine residual risk compared to inherent risk?
  • Which of the following best describes the purpose of SAST?
  • What phase of the data lifecycle generally describes the collection of data with respect to regulatory compliance?
  • A security professional has some spare time to do research on the corporate network and wants to set up a system configured to carefully monitor and log interactions. Which of the following should the security professional set up?
  • What process involves making changes to the production environment using configuration management platforms to support newly updated applications?
  • Which of the following benefits is NOT typically associated with a CASB solution?
  • By analyzing which of the following can trends appear that may indicate additional risk items requiring proactive attention?
  • Which testing method is aimed at deep integration of various subsystems in a larger system?
  • When hardening a server's security, what should be the priority regarding active services?
  • What type of scalability does a CDN represent, where additional servers are added to help handle the same workload?
  • What type of cloud storage is most suitable for high-performance, transactional applications such as databases?
  • Which of the following is generally less complicated to deploy than other deceptive technologies but serves a similar purpose?
  • Which organization provides secure coding standards for programming languages such as C, C++, Android, Java, and Perl?
  • Which agreement commonly establishes a relationship with a cloud service provider (CSP) and includes metrics related to information privacy and data protection beyond what is detailed in a Service Level Agreement (SLA)?
  • Which feature of a central log management system aids in the efficient and effective response to security incidents?
  • In which phase of forensic investigation do legal concerns primarily arise?
  • Which hardware-based solution is specifically used for storing encryption keys and hashed passwords?
  • What does the principle of least privilege in cybersecurity refer to?
  • Why might the use of a virtual private network (VPN) commonly employed in the United States be problematic in other countries?
  • A security analyst is performing a security assessment and is recommending ways to manage risk relating to personnel. Which of the following should the analyst recommend?
  • Which component of risk management aims to reduce exposure to risk factors and decrease residual risk?
  • In a cyber context, which type of actor often aims to raise awareness of political issues through their actions?
  • What is the main action in inventorying certificates during their lifecycle?
  • What is the entity responsible for issuing and guaranteeing certificates that an organization can set up privately for internal communications?
  • During which phase of a digital forensics investigation do experts perform repeatable methods using the same tools on data?
  • A software development manager wants to integrate a development model for a company that will allow them to release small blocks of well-tested code to bring functionality to the business as soon as possible. What is this method called?
  • What solution implements user identity assertions and transmits attestations between the principal, the relying party, and the identity provider?
  • Which protocol is commonly used to protect data in motion across networks, such as cloud-synchronized data?
  • Which network architecture is often used with blockchain ledgers to mitigate risks associated with a centralized authority but is not commonly used in UEBA?
  • What label should be applied to information that is too valuable to allow any risk of its capture, with viewing severely restricted?
  • Which of the following is designed to trigger an alert when accessed by an adversary, commonly referred to as a honeytoken or canary trap?
  • Which state of data is at risk in volatile memory that concerns the IT department?
  • Which technology is used for managing cryptographic keys and centralizing public key infrastructure (PKI) management, but is not specifically designed for encrypting data at rest?
  • Why was SHA-1 phased out by NIST as a secure hashing standard?
  • What is the first step of the software development life cycle (SDLC) that identifies policy, standard, and regulatory requirements governing how software operates?
  • What is the focus of NIST 800-53?
  • What benefit does cross-certification provide in a private network?
  • Which mode of operation is simple but vulnerable to padding-oracle attacks?
  • Which method involves a series of phases where each phase starts only when all tasks from the previous phase are completed, creating a cascading effect?
  • Which process involves setting up a new file system but does not ensure original data is non-recoverable?
  • A cloud architect is analyzing the benefits of a Content Delivery Network (CDN). Which of the following are benefits of a CDN?
  • What is a major concern addressed by Host-based Intrusion Detection Systems (HIDS)?
  • Which security solution uses execution control to determine what additional software or scripts an administrator may install or run on a Linux host?
  • Which central log management strategy supports real-time monitoring and alerting of security events?
  • Which step in the cyber kill chain refers to the methods used to communicate with an exploited system to further the attack?
  • Which type of threat actor arises from an individual whom the organization has identified and granted access?
  • Which major Type 1 hypervisors can a systems administrator evaluate for future migration?
  • What term describes the capability for a task to run with exclusive access to resources, preventing multiple tasks from accessing or modifying critical resources at the same time?
  • What problem does public key cryptography address within Public Key Infrastructure (PKI)?
  • A web development team wants to modernize an application that relied on Flash plugins. What should they consider using?
  • What process is utilized to ensure that a digital certificate represents the correct owner?
  • Which system enables non-technical users to create, manage, and modify content on a website?
  • Which identity proofing method combines something a user knows, like a password, with an ownership-based smart card or biometric identifier?
  • What solution provides visibility into compromises but does not stop initial execution?
  • Which method is used to measure the state of a qubit?
  • Which term describes an adversary's or penetration tester's ability to establish access to the target environment at-will and undetected?
  • Which framework aligns IT risks with business objectives for executive leadership?
  • Which device forwards traffic between subnets by inspecting IP addresses and operates at layer 3 of the OSI model?
  • A solutions architect is designing a security architecture for a nuclear power plant facility. Which of the following would be the best design?
  • Which algorithm is widely used for digital signatures and is based on factoring large prime numbers?
  • What is the name of the configuration that uses two firewalls placed on either side of the demilitarized zone (DMZ), with the edge firewall restricting traffic on the external/public interface?
  • Which type of analysis requires the evaluation of a system or software while it is actively running?
  • Which type of exercise is used to identify a specific objective and determine whether all parties involved in the response know what to do and how to work together to complete the exercise?
  • What does Secure Authentication (SA) describe in the context of network security?
  • What does unauthorized alteration of system settings indicate?
  • Which policy can be implemented on mobile devices to grant different levels of access based on geographic location?
  • In the context of security frameworks, which phase focuses on implementing remediation strategies?
  • Which of the following is not a standard or regulation but a mechanism to achieve Business Continuity and Disaster Recovery (BCDR) capabilities using public cloud services?
  • Which system identifies solutions to abstract problems by determining which simpler concepts are applicable?
  • Which tool can be used to monitor and analyze network traffic for potential security issues?
  • A security administrator is concerned about unauthorized changes to system files in a server environment and wants to monitor files for any changes. The administrator plans to use a method that compares file hashes with known legitimate values. Which solution should the administrator implement?
  • After a Certifying Authority accredits a system, what formal letter is granted to the system owner, allowing the system to operate for a period of three years?
  • What type of threat actor might attempt to obtain and release confidential information, perform DoS attacks, or deface websites?
  • Which of the following involves updating signature and behavior rules to block or quarantine suspicious activity?
  • Which of the following mimics a genuine system and is configured to carefully monitor and log interactions, warranting closer inspection since it does not serve regular staff?
  • Which security testing method reviews code while it is executing as the final product?
  • Which of the following encryption methods requires careful management of initialization vectors to maintain security?
  • What does Elliptic-Curve Diffie-Hellman (ECDH) represent in a cipher suite?
  • Which type of scanning uses indirect methods, such as inspecting traffic flows and protocols, and is often suited for industrial or sensitive networks?
  • A forensic investigator prepares a report outlining tools and methods from an investigation. What process stage is this?
  • What type of cybersecurity best practice does OWASP focus on?
  • What process involves deciding to continue operating despite identified risks as part of assessing residual risk?
  • Which type of intelligence involves collecting and analyzing data from publicly available sources to address the needs of a specific project or operation?
  • Which mode of encryption generates a keystream using an initialization vector and does not require padding?
  • Which step in the cyber kill chain involves developing the tool and technique used against an organization based on information gathered during reconnaissance?
  • A security engineer is performing a business impact assessment (BIA) for an organization. Where should the security engineer begin?
  • Which disaster recovery test method involves performing an exercise on live systems and data, potentially causing a true disaster recovery event?
  • What is the primary responsibility of a Cloud Service Provider (CSP) after a security breach?
  • A security architect is looking for examples of standards and regulations with descriptions of Business Continuity and Disaster Recovery (BCDR) capabilities. Which of the following are examples?
  • What technology combines multiple components like CPU, RAM, and storage into a single chip?
  • What process establishes the necessary controls, such as encryption and access controls, required to protect data adequately?
  • What document identifies existing risks, ongoing monitoring, corrective actions, and the current disposition of an information system?
  • What aspect of a business continuity plan involves defining the speed and state of system recovery?
  • Which solution is designed to ensure that digital content is only accessed or used in specific, authorized ways by consumers?
  • Which protocol is widely used for remote access to manage devices and services?
  • A large corporation has just completed an audit by a Certifying Authority who determined that they are compliant. What will the Certifying Authority award the corporation?
  • What intelligence collection method do investigators use to monitor a suspect's social network feeds?
  • What type of alternate site is simply a facility under the organization's control but lacks pre-established information system capability?
  • Which elements are considered essential in key management for a Public Key Infrastructure?
  • Which configuration is typically used to secure a demilitarized zone (DMZ) by placing firewalls on both the external and internal sides?
  • Which step in the cyber kill chain refers to the successful delivery of a tool that results in a breach and provides access to the target system?
  • What technology enables secure and contactless payment transactions using a PoS machine?
  • Which type of certificate is considered the same as a general purpose certificate?
  • Which NIST publication provides guidance for implementing Zero Trust Architecture?
  • Which simple mode of encryption is susceptible to the padding-oracle attack and should not be used?
  • What must be understood in order to effectively assess and protect infrastructure components during a penetration test?
  • Which term refers to intangible products of human thought and creativity protected by intellectual property laws?
  • What is typically the first step in the software development life cycle?
  • An IT consultant is starting to travel abroad but has concerns about being able to VPN back home to access a private home network. What should the consultant research?
  • Which system is responsible for managing process automation at a localized site?
  • Which scenario best describes a lock-out issue with a technology services vendor?
  • Which tool is suitable for monitoring real-time server memory usage and I/O operations?
  • Which of the following provides critical information for defensive operations, including details about IP addresses and URLs associated with phishing campaigns and malware?
  • What role does a cloud access security broker (CASB) serve in cloud environments?
  • For a cloud service to be recognized under the CSA Security Trust and Assurance Registry, what must it meet?
  • A forensics analyst is attempting to read file metadata during the course of an investigation. Which tool could they use?
  • What tool could a forensics analyst use for conducting memory analysis?
  • Which hardware-based solution stores encryption keys, hashed passwords, and identification information, but is not directly used for encrypting data at rest under FIPS 140-2?
  • A company is handling sensitive customer data and wants to ensure that no unauthorized data transfers occur. They need a solution that automates the discovery and classification of data and enforces rules to prevent data leaks. Which of the following should they implement?
  • A security administrator monitoring network traffic for suspicious activity should implement which solution?
  • Which type of threat intelligence focuses on the objectives and motivations of potential threat actors?
  • A developer tasked with building a Java web application is seeking a well-known framework. Which one should they choose?
  • In which environment would you expect to see continuous integration taking place?
  • Which cloud model allows several organizations to share the costs of either a hosted private cloud or a fully private cloud?
  • After completing an investigation, which stage involves sharing findings with authorities?
  • Which response header specifically protects against speculative execution attacks, such as Spectre, in addition to mitigating XSS inclusion attacks?
  • Which of the following steps directly supports operational needs by utilizing data?
  • Which protocol improves upon RADIUS (Remote Authentication Dial-in User Service), strengthening some of its weaknesses, but is less widespread due to fewer products using it?
  • Which method can be used to protect data at rest on Microsoft Windows computers?
  • A Security Operations Center (SOC) analyst wants to develop internal indicators of compromise (IOCs). What type of threat intelligence should the analyst use?
  • What attack involves manipulating the URL to access sensitive system files on a web server?
  • What technique can be used to randomly arrange the memory addresses used by a program to enhance security?
  • What type of attack involves intercepting and altering communications between two parties without their knowledge?
  • Which major category combines people and processes to enhance defenses against security threats?
  • What allows a certificate to secure multiple subdomains by containing an asterisk character in its domain name field?
  • A tech company suspects that a rival has used cyber means to steal its latest product designs just before a big launch. Which type of threat actor could be responsible for this industrial espionage?
  • Which type of assessment may be a regulatory or contractual requirement and helps identify both obvious and non-obvious issues to enhance internal vulnerability assessments?
  • When a forensic analyst uses hashing to ensure data integrity during a hard drive copy, which process stage is involved?
  • Which method allows users to authenticate with certain websites using a single account, enabling them to retain a single login for all participating sites?
  • Which environment would a security code reviewer set up to safely analyze third-party libraries and code without risking the main systems?
  • What is a key consideration when granting a pen-tester access during a penetration test assessment?
  • A security engineer is setting up a security solution that can enforce mandatory access controls between two connected sites. Which of the following should the engineer implement?
  • Which of the following consists of multiple honeypots connected to a tightly controlled and heavily monitored network?
  • Which virtual machine attack has the highest potential to compromise the entire architecture?
  • A security administrator wants to enable a feature that distinguishes between executable and non-executable areas of memory for protection. What feature should be enabled?
  • What technology, used in WPA3, replaces WPA's 4-way handshake authentication and association mechanism with a protocol based on the Diffie-Hellman key agreement?
  • Which core foundation of blockchain describes how all systems come to an agreement regarding a particular computation to maintain the overall integrity of the system?
  • Which of the following is an application layer attack that ModSecurity can help protect against?
  • Which of the following is required to comply with privacy laws but is not the type of entity that privacy data directly refers to?
  • Which of the following is designed to collect and analyze data from multiple deceptive systems?
  • Which feature of a Cloud Access Security Broker (CASB) solution helps scan for malware and restrict rogue or non-compliant device access?
  • Which type of environment is designed to be used by visitors, such as the public or vendors?
  • What technology is most applicable for integrating sensors in a conveyor belt system?
  • Which of the following rewrites file data to occupy contiguous clusters, reducing seek times on an HDD?
  • In which cloud model does the customer take responsibility for selecting and configuring operating systems, while the provider manages the underlying infrastructure?
  • What is the main purpose of implementing continuous integration in software development?
  • Which device is primarily responsible for managing outbound and inbound traffic based on defined rules in a network?
  • A new security analyst starts reading about varying privacy laws across different countries. Privacy data typically refers to which of the following?
  • Which policy would most likely reduce security risks associated with personal device use in a corporate environment?
  • Which type of threat actor could intentionally delete key files after being given access to sensitive systems?
  • Which metric represents the total amount of loss anticipated over a year due to single loss events?
  • For setting up communication between web services using XML over HTTP, which protocol is appropriate?
  • Which service model is the best choice for a small business looking to minimize administration responsibility when migrating to the cloud?
  • Privacy data typically refers to information that can uniquely identify which of the following?
  • Which of the following tools is a good source of data that can be fed into security data analytics tools for further analysis?
  • Which solution will notify the security team automatically in the event of future malware variants invading the network?
  • What is the primary role of a Cloud Access Security Broker (CASB) in cloud security?
  • An auditor for a federal agency is reviewing encryption. Which standard is the auditor most likely using?
  • Which type of threat actor might use cyber espionage despite it being commonly associated with state actors?
  • Which sanitization method protects against all recovery techniques, even those in clean-room environments?
  • What are the primary categories in which security flaws may exist?
  • What system ensures an optimal indoor environment through effective heating, ventilation, and air conditioning?
  • A penetration tester is trying to stress test a web application by injecting malformed data into it. What is this method called?
  • A security analyst is attempting to create efficiencies by automating certain tasks defined in the security playbook. Which automation tool would help the analyst accomplish this?
  • Which security testing method evaluates source code for security flaws often through add-ons to an IDE?
  • Which type of control offers preventive capabilities by removing elements often exploited by an adversary and is considered a technical, not physical, control?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy