Browse all practice questions for the Western Governors University (WGU) ITAS6291 D488 Cybersecurity Architecture and Engineering Practice Exam. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

Western Governors University (WGU) ITAS6291  D488 Cybersecurity Architecture and Engineering Practice Exam course image
More practice questions

These questions are part of the practice quiz. Start practicing

  • What MAC solution is used by Ubuntu, SUSE Linux, and other distributions, and is also known as a Linux Security Module (LSM)?
  • Which of the following is not part of the foundational elements of blockchain but supports cloud-based applications that need access to documents, videos, and image files?
  • Which technology integrates hardware and software into a single, low-power, high-performance unit for compact spaces?
  • Which virtualization technology allows an x86 computer to run the Android OS or software designed for systems like Nintendo or Xbox?
  • Which system categorizes resources by purpose, owner, or environment using key-value pairs?
  • Which service lists the configuration and access levels of an instance and may expose it to vulnerabilities?
  • Which of the following tools is a good source of data that can be fed into security data analytics tools for further analysis?
  • Which mode of operation is simple but vulnerable to padding-oracle attacks?
  • Which of the following involves blocking or limiting access to resources like files, folders, or write access from specific accounts?
  • Which testing method would likely be chosen for identifying security flaws in source code during the development phase, especially on a budget?
  • Which security technology ensures that only authorized software loads on a device during boot?
  • A forensics analyst needs to extract and analyze metadata from various image and document files as part of an ongoing investigation. Which tool should the analyst use to read and write file metadata?
  • What provides privilege management and authorization by storing information about users, computers, security groups/roles, and services on an enterprise network?
  • Which of the following is not a feature or ability of a Cloud Access Security Broker (CASB) solution?
  • What is the term for a mobile device policy that allows employees to choose from approved devices while maintaining company control?
  • Which model enables access decisions based on both system-wide and context-sensitive attributes?
  • In what type of scenario is risk response identification commonly executed?
  • Which publication provides comprehensive guidelines on security controls for information systems?
  • Which process detects flaws, bugs, errors, and defects in applications running in production environments?
  • What explains the degradation in system performance and alerts regarding high central processing unit (CPU) usage?
  • A network administrator is trying to set up network security so that only trusted devices have network access. What solution should the administrator set up?
  • What type of solution is deployed by Systems Administrators when utilizing a virtual desktop infrastructure?
  • What framework should a risk auditor contracted by a U.S. government agency use for risk assessments?
  • Which objective specifies how much time is acceptable for system recovery, highlighting tolerable downtime?
  • Which identity proofing method combines something a user knows, like a password, with an ownership-based smart card or biometric identifier?
  • Which NIST publication delineates essential security and privacy controls for auditing information systems during certification?
  • At what point in the SDLC should security policies, standards, and regulatory requirements be identified to ensure compliance?
  • Which issue can arise during a failover if the health status of disaster recovery (DR) devices is not properly monitored?
  • What is primarily used to enable remote connectivity for people working from home or to connect branch locations to the enterprise network?
  • What is one method to enhance the effectiveness of security cameras?
  • Which step in business continuity planning involves identifying the systems and assets that exist before any preventative measures can be established?
  • Which type of scan compares a computer or software configuration and patch level against pre-determined settings within a content baseline?
  • In terms of regulatory compliance, what strategy should organizations adopt to secure personal data?
  • Which aspect of vendor management involves determining if a vendor will remain in business over time?
  • Which of the following features is NOT a characteristic of Encapsulating Security Payload (ESP)?
  • An attacker gains access to a sensitive shared folder. What might a security engineer configure to directly mitigate the problem?
  • Which laws govern the export of commodities, software, and technology, requiring coordination between countries to enforce?
  • What type of mobile device policy allows the company to provide devices that can be used for both work and personal activities?
  • What feature of WPA3 provides enhanced security by using simultaneous authentication?
  • What key management practice associates cryptographic keys with an identity?
  • Which program is designed by the Cloud Security Alliance to validate a cloud service provider's commitment to security practices?
  • What term describes a suite of policies and technology tools for centralized management of mobile devices?
  • Which of the following operates as a guardian between two connected sites, enforcing mandatory access controls and interpreting data sensitivity levels?
  • Which Linux-based security solutions enforce MAC policies to restrict access and control system behavior?
  • Which solution should be deployed to block SQL injection attacks on a web application?
  • Which risk management framework is tailored for U.S. federal agencies ensuring cybersecurity risk management?
  • Which of the following describes integrity in the context of information security risks?
  • Which interface provides code that allows the host to boot to an operating system and enforces boot integrity checks?
  • In which stage of forensics does a forensic expert interpret data and examine file structures for tampering signs?
  • In a cloud environment, what controls inbound and outbound traffic between networks, particularly between virtual private clouds (VPCs)?
  • Which cloud model allows multiple organizations to reduce costs by sharing infrastructure while maintaining a private-like cloud experience?
  • Which kind of technology is primarily used to deceive attackers and collect information about their methods?
  • A red teamer is following the steps of the cyber kill chain process during an exercise. What is the first step the red team member should perform?
  • What is the most efficient way for a systems administrator to identify unnecessary services on a server?
  • What programming framework is ideal for handling asynchronous network programming in Python applications?
  • When implementing a CASB, what aspect might an organization expect improved visibility into?
  • What is a major concern addressed by Host-based Intrusion Detection Systems (HIDS)?
  • What encryption method is used on Microsoft Windows computers to protect data at rest, and uses Advanced Encryption Standard (AES)?
  • A Linux administrator is configuring ModSecurity for Apache servers. Which types of attacks should the administrator set rule configurations to protect against?
  • An application is experiencing a security flaw where the system checks the state of a resource, but the resource changes state before action is taken. What is this issue called?
  • What formal mechanism is used to measure the performance of a program against its desired goals?
  • What approach do developers use to identify open source code in their software?
  • RC4 is an example of which type of encryption?
  • What access control model assigns security clearance levels and uses labels to regulate access?
  • Which type of analysis involves inspecting source code to identify open source components and any libraries used as part of an application's design?
  • Which U.S. Department of Defense (DoD) resource provides Security Technical Implementation Guides (STIGs) for system hardening?
  • Which of the following defines how objects can interact with each other within a network?
  • Which authentication mechanism uses public key authentication by specifying a remote user's public key in a locally stored list of authorized keys on the server?
  • Which type of testing focuses on the functions of individual software components?
  • What does the deployment of EAP Transport Layer Security (EAP-TLS) require on both the clients and servers?
  • A cloud architect is analyzing the benefits of a Content Delivery Network (CDN). Which of the following are benefits of a CDN?
  • Which plan has a broad scope that covers the development of a business continuity policy and the creation of response plans?
  • Which of the following is a characteristic of an FPGA?
  • Which type of analysis involves deconstructing software and hardware to determine how it works and to see how much information can be extracted?
  • Which agreement focuses specifically on the exchange of data between organizations and includes security controls?
  • What method involves a Cloud Access Security Broker (CASB) positioned at the cloud network edge that directs traffic to cloud services based on policy compliance?
  • Which disaster recovery test method involves performing an exercise on live systems and data, potentially causing a true disaster recovery event?
  • What should a cloud engineer reference when establishing a zero trust architecture in a cloud environment?
  • What are the primary categories in which security flaws may exist?
  • Which technology is extensively used for User and Entity Behavior Analytics (UEBA)?
  • What advantage does a BYOD policy provide to employees?
  • Which country is least likely to be chosen for a company focused on privacy and anonymity due to its government's control over information and lack of strong privacy protections?
  • What type of authentication requires multiple credentials or factors for access?
  • What technology combines multiple components like CPU, RAM, and storage into a single chip?
  • A security administrator monitoring network traffic for suspicious activity should implement which solution?
  • What is one of the crucial roles of CASB in cloud security?
  • Which process uses platform configuration registers (PCRs) in the Trusted Platform Module (TPM) to check system state data during boot?
  • What is assessed during a compliance audit to ensure data handling practices meet legal standards?
  • What is the correct sequence of steps in the risk management process for a new telemedicine platform?
  • What type of test is designed to check whether changes in code have caused previously existing functionality to fail?
  • Which technique involves analyzing the state of an application in real-time even if data is encrypted?
  • Which technology uses algorithms to parse input data and develop strategies for using that data, such as object identification or determining the next move in a game?
  • When hardening a server's security, what should be the priority regarding active services?
  • What describes a relationship where if resource A trusts resource B, and resource B trusts resource C, then resource A automatically trusts resource C?
  • Which type of analysis involves inspecting a system and software while it operates, including techniques like packet capture and traffic analysis?
  • What technology focuses on monitoring the integrity of specific files to ensure they haven't been altered or compromised?
  • What minimum requirement should a CASB address when mediating user access across various devices?
  • Which of the following best describes the role of a trusted certificate authority?
  • Which technology is primarily used to connect devices like keyboards, mice, headsets, and IoT devices, but is also vulnerable to attacks such as BlueBorne?
  • A mid-sized company wants to integrate code scanning into their process while keeping costs low. Which security testing method involves add-ons to an IDE to evaluate source code developed in a specific language?
  • Which solution would maintain the full management responsibility with the company's IT team without reducing their workload?
  • Which type of threat actor is primarily focused on seeking criminal profit through financial fraud or blackmail?
  • Which technology is used for managing cryptographic keys and centralizing public key infrastructure (PKI) management, but is not specifically designed for encrypting data at rest?
  • Which scenario occurs when a vendor's product design leads to integration challenges with other vendor products?
  • What type of scalability does a CDN represent, where additional servers are added to help handle the same workload?
  • An IT consultant is starting to travel abroad but has concerns about being able to VPN back home to access a private home network. What should the consultant research?
  • Which agreement commonly establishes a relationship with a cloud service provider (CSP) and includes metrics related to information privacy and data protection beyond what is detailed in a Service Level Agreement (SLA)?
  • Which global standard is designed for secure processing of credit card information?
  • What is the main objective of a Master Service Agreement (MSA)?
  • What are the two major components of risk that are essential in understanding its evaluation?
  • Which technique provides a secure operating system with access controls for user applications in a financial institution?
  • What is the key difference between Elliptic-Curve Diffie-Hellman (ECDH) and standard Diffie-Hellman (DH)?
  • How can an administrator harden a server by removing unnecessary FTP services without causing disruption?
  • Which security control will secure a web-based credit monitoring service and protect credit information of consumers in compliance with FCRA requirements?
  • A motivated technology analyst is starting a company focused on privacy and anonymity. What country would the technology analyst most likely want to operate from?
  • When a forensic analyst uses hashing to ensure data integrity during a hard drive copy, which process stage is involved?
  • What does RADIUS primarily serve in a network environment?
  • Which regulation enforces rules for organizations serving the European Union concerning data collection?
  • A developer tasked with building a Java web application is seeking a well-known framework. Which one should they choose?
  • Which tool should a network administrator use to read and write data over TCP and UDP?
  • What happens to a file when it is quarantined in a data loss prevention system?
  • Which NIST standard is focused on the overall security and privacy controls required for federal information systems?
  • What is the benefit of managing network devices according to risk management principles?
  • Which non-active test identifies a specific objective to determine whether parties involved know what to do?
  • Which NIST publication provides guidance for implementing Zero Trust Architecture?
  • What happens after the correct PIN authorizes the smartcard's cryptoprocessor?
  • When securing against broken authentication, which control is NOT relevant for protection?
  • What is the total estimated financial impact of a single incident of server downtime called?
  • Which type of analysis involves manually inspecting source code to identify vulnerabilities in programming techniques?
  • What type of network behavior might signal a security issue in an organization's systems?
  • Which threat actor would most likely launch a ransomware attack against a large retail chain to demand payment?
  • In vendor management, which term corresponds to the evaluation of a vendor's ability to consistently deliver?
  • Which feature of a Cloud Access Security Broker (CASB) solution helps scan for malware and restrict rogue or non-compliant device access?
  • When modernizing an application that used Flash, which technology is recommended for avoiding browser plugins?
  • Which protocol does NOT involve checking a certificate status in PKI?
  • Which type of scanning involves assessing endpoints with vulnerability assessment software and may involve providing credentials to see inside the device or application?
  • What is the ultimate goal of the 'Control' phase within the Risk Management Lifecycle?
  • In which environment would you expect to see continuous integration taking place?
  • Which type of threat actor arises from an individual whom the organization has identified and granted access?
  • Which technology allows the client to either access an application hosted on a server or stream the application for local processing?
  • Which type of security tool would be least effective at preventing social engineering attacks but is crucial for defending against web-based attacks?
  • What is the purpose of a general purpose certificate?
  • Which feature of a CASB allows for centralized management of access controls from the enterprise network to cloud services?
  • In the hierarchical model, what does a single certificate authority (CA), called the root, issue certificates to?
  • For contactless payments on point-of-sale machines, which technology is commonly used?
  • In cryptography, what key feature is necessary for a block cipher?
  • In a Kerberos authentication system, what process occurs first when logging in with a smart card?
  • A security analyst is tasked with improving defenses against malware that could evade detection. Which of the following should the analyst focus on?
  • An owner of a small company produces digital manga in the United States, but it has also become very popular in Japan. Which privacy law should the owner comply with to set up an operation in Japan?
  • What type of information is used to identify an individual and includes details about their health and healthcare operations?
  • Which part of the cipher "ECDHE-RSA-AES128-GCM-SHA256" is used for signatures?
  • Which tool is suitable for monitoring real-time server memory usage and I/O operations?
  • How does 3D printing help companies protect their intellectual property?
  • Which network device would you use to ensure that traffic continues to flow to a functional web server when another server in a cluster goes down?
  • What risk management strategy ensures data security in a software application?
  • When evidence preservation is crucial in an investigation, which forensics process is prioritized first?
  • Which of the following encryption methods requires careful management of initialization vectors to maintain security?
  • Which major category of security flaws is most directly impacted by human actions, such as phishing attacks?
  • What is a significant drawback of the MD5 hashing algorithm?
  • What type of testing can be performed by developers to assess software functionality in unexpected scenarios?
  • What enabled an attack through a backdoor in a connected application?
  • Which type of exercise is used to identify a specific objective and determine whether all parties involved in the response know what to do and how to work together to complete the exercise?
  • Which strategy involves using diverse, non-similar components to create a barrier that complicates an adversary's attempts to infiltrate before detection?
  • How can a developer validate passwords against weak password lists to prevent weak password creation?
  • A security engineer is performing a business impact assessment (BIA) for an organization. Where should the security engineer begin?
  • Which NIST publication includes a guide to test, training, and exercise programs for IT plans, along with an after-action report template?
  • What is one key outcome of the accreditation process under a Certifying Authority?
  • What does the alert mode do in a data loss prevention solution?
  • A website administrator is setting up a cluster of web servers and wants to ensure that if one server goes down, the system in place will route the traffic through the others. Which network appliance should the administrator use?
  • Which boot process enhances security but does not require a Trusted Platform Module for operation?
  • How does a CDN help improve security in a cloud environment?
  • In which phase of development is SAST most effective?
  • Which solution is specifically designed to automate security incident responses, helping reduce the workload on security personnel?
  • What risk strategy involves ceasing the activity that is considered to be risk-bearing to avoid the associated risks entirely?
  • Which of the following standards would be least relevant for a company focusing on credit card transaction security?
  • What is the impact of a finding that the recovery point objective is not satisfactory due to server backup schedules?
  • Which cloud service model requires the least amount of management and maintenance from the customer, with the service provider handling all aspects including applications?
  • What is the recommended solution to prevent unapproved devices from accessing the corporate network?
  • Which NIST Special Publication provides guidelines on establishing and operating an incident response capability within an organization, identifying the necessary groups involved in incident response?
  • A security architect for a university wants to set up a federation method commonplace in their industry. Which of the following is routinely known for being used by universities?
  • Which major category combines people and processes to enhance defenses against security threats?
  • What is the purpose of using a hardware security module (HSM) in an enterprise?
  • A security engineer looks to change the Extensible Authentication Protocol (EAP) authentication method. If the current solution uses the Protected Access credential, which EAP implementation does the engineer look to replace?
  • Which type of system is commonly used in industrial settings for automation tasks such as assembly line operations, field tasks, and robotics?
  • Which functionality allows a mobile device to maintain a constant VPN connection?
  • A network administrator is tasked with scanning a range of IP addresses to identify active hosts and services in the network. Which of the following tools should be used to perform this task?
  • Which certificate type can be used to secure multiple subdomains under the same domain?
  • A penetration tester is attempting to target core mechanisms that enable integration and orchestration of the entire information systems and technology landscape. Which of the following should the pen tester pursue?
  • Which boot method enhances security at startup and can utilize TPM for storing encryption keys?
  • Which feature of a central log management system aids in the efficient and effective response to security incidents?
  • How does privilege escalation affect virtual machine security?
  • A software developer needs to be able to run various versions of Android on an x86 system. Which virtualization technology will allow the software developer to perform this?
  • Which key exchange algorithm allows two parties to establish a shared secret key without pre-shared secrets?
  • Which word best describes the concept of due diligence, emphasizing the ongoing effort to evaluate and improve asset protection mechanisms?
  • Which security tool provides a foundational level of protection for a network by blocking or allowing traffic based on pre-configured rules?
  • What is the limitation of Diffie-Hellman (DH) when used for key agreement?
  • Which security practice helps detect potential fraud or inappropriate activities by temporarily shifting an employee's duties to another individual during their absence?
  • What should be used to prevent data breaches caused by insider threats based on the indicators of compromise?
  • Which environment is specifically intended for final testing before software is released to production?
  • What term refers to data collections that are so large and complex that they are difficult for traditional database tools to manage?
  • During which phases of data lifecycle are regulatory restrictions focused on data retention and disposal methods?
  • Which tool evaluates operating system files, such as the Windows registry, to identify any unauthorized changes?
  • What type of risk management is involved in understanding how threats can impact a business?
  • What is the focus of NIST SP 800-61?
  • Why was SHA-1 phased out by NIST as a secure hashing standard?
  • Which type of testing is focused on validating that changes in code do not negatively impact existing functionalities?
  • What type of encryption is used to protect data in transit, such as website traffic and remote access traffic?
  • What cloud service model provides a selection of operating systems that the customer can load and configure, while the underlying infrastructure and physical security are managed by the provider?
  • In a privacy impact assessment (PIA), why is it important to analyze the sensitivity level of privacy data?
  • What process establishes the necessary controls, such as encryption and access controls, required to protect data adequately?
  • What type of alternate site can be described as a "data center in a box" and is commonly used by the military?
  • Which type of service agreement typically includes performance metrics and emphasizes a partnership with the vendor?
  • In what scenario is live VM migration particularly risky for virtualized environments?
  • Which physical security control should be implemented to eliminate dark spaces and support the capture of clear video?
  • Which of the following is NOT a Type 1 hypervisor but instead an operating system that includes the option to install Microsoft's Type 1 hypervisor?
  • Which type of threat actor might use cyber espionage despite it being commonly associated with state actors?
  • What approach should an administrator take to improve server security after identifying running services?
  • When defining vendor expectations and requirements, what is the significance of establishing a vendor policy?
  • What standard should a cloud engineer reference for designing a zero trust architecture?
  • A system administrator wants to harden the organization's servers. Which of the following would best help to harden the servers?
  • What technique can be used to randomly arrange the memory addresses used by a program to enhance security?
  • What hardening technique is essential for protecting a manufacturing company's industrial control systems from firmware attacks?
  • What does the acronym CSP stand for in cloud computing?
  • Which security solution employs mandatory access control policies to run applications in sandboxes on Android devices?
  • Which tool performs automated tasks, including system maintenance and status checks, often triggering scripts to run?
  • Which EAP (Extensible Authentication Protocol) type is similar to PEAP (Protected Extensible Authentication Protocol) but uses a Protected Access Credential (PAC) instead of a certificate to set up the tunnel?
  • What platform helps a company manage relationships with customers by providing data about those customers?
  • What solution should an organization implement to centralize its security event logs and automate analysis?
  • What is a key characteristic of middleware in software architecture?
  • In which phase of the Risk Management Lifecycle do practitioners identify risks and create a foundational inventory?
  • Which solution is focused on speed and efficiency and operates well on devices without AES hardware acceleration?
  • Which of the following is NOT a characteristic of Diameter protocol compared to RADIUS?
  • Which solution streamlines the incident response process during a cyberattack?
  • Which system involves sensors, logic solvers, and control elements designed to return an industrial process to a safe state after detecting certain conditions?
  • What layer of the OSI model do web application firewalls like ModSecurity focus on when defending against attacks?
  • Which encryption mechanism is specifically designed to protect data as it exists in memory, preventing untrusted processes from decoding it?
  • What tool can help determine dependencies for a process during a security examination?
  • What should have been performed during the initial stage of business continuity planning, rather than during a privacy impact assessment (PIA)?
  • Which simple mode of encryption is susceptible to the padding-oracle attack and should not be used?
  • Which category is specifically protected by the Children's Online Privacy Protection Act (COPPA) but is not the only group that privacy data aims to protect?
  • What part of a resilience strategy involves preparing specific responses to potential events, ensuring the organization is ready to act when necessary?
  • Which document would be critical for an organization conducting independent audits on its cybersecurity practices?
  • Which of the following is designed to trigger an alert when accessed by an adversary, commonly referred to as a honeytoken or canary trap?
  • Which of the following benefits is NOT typically associated with a CASB solution?
  • What should the company consider when developing metrics to measure a cybersecurity risk management program's effectiveness?
  • Which tool should a security researcher use to deconstruct malware for analysis?
  • What mechanism should be implemented to prevent printing documents from a corporate file share?
  • What is the first step of the software development life cycle (SDLC) that identifies policy, standard, and regulatory requirements governing how software operates?
  • Which authenticated encryption mode is designed to provide strong message authentication and is fast?
  • Which certificate contains an asterisk in its domain name field, allowing usage for any number of subdomains?
  • What authentication method is used to protect access to corporate resources during device enrollment?
  • To collect network metadata without capturing every packet, which method is recommended?
  • In threat modeling, which approach is often used to identify potential vulnerabilities by simulating an attack?
  • Which of the following is a necessary component to generate a public key?
  • Which Type 1 hypervisor would you choose if you're looking for a bare metal solution from VMware that supports multiple virtual machines running on a single physical machine?
  • What does the term 'collision' refer to in hashing algorithms?
  • What method clearly identifies the classification, use, and licensing terms of digital content but does not control how consumers use the data?
  • Which elements are considered essential in key management for a Public Key Infrastructure?
  • What type of web application firewall is commonly used with Apache servers to help defend against application layer attacks?
  • A young technician is in charge of the security awareness program for an organization and begins looking at common attack vectors. Which tools are best suited to help defend against social engineering attacks?
  • What method requires representatives from all groups in the BCDR plan to participate in a meeting to review the plan?
  • Which type of agreement typically serves as an "umbrella" contract, establishing the terms for business between two entities over a defined period?
  • Which tool allows for applying policies that define minimum and maximum capacity for scaling resources?
  • Which of the following consists of multiple honeypots connected to a tightly controlled and heavily monitored network?
  • During the Risk Management Lifecycle, which phase should a security architect allocate the most hours?
  • Which act related to fraudulent accounting includes descriptions of Business Continuity and Disaster Recovery (BCDR) capabilities?
  • Which type of response header is effective in securing resources against certain cross-origin scripting attacks?
  • Which type of IoT device is designed to measure environmental variables such as humidity and temperature?
  • What type of agreement defines the conditions under which entities can use data and information shared between them?
  • Which security control will mitigate the risk of a successful phishing attack on a financial institution's employees?
  • Which system is most suitable for automation tasks directly controlling operations in assembly lines?
  • What solution can improve website speed and performance in case of high traffic due to a disaster?
  • Which of the following best describes the term 'exploitability' in risk assessment?
  • Which of the following is a technique to disrupt access to a system during an attack?
  • In the context of testing, what enables the developer to identify broken functionality after a code change?
  • Which type of attack involves accessing directories outside of the web root and can be mitigated by a web application firewall like ModSecurity?
  • Why should a privacy impact assessment (PIA) document the parties involved in data-sharing arrangements?
  • What technology is most applicable for integrating sensors in a conveyor belt system?
  • A software developer is setting up a symmetric encryption block cipher with an initial chaining vector. Which will they use?
  • Which technology is widely utilized for contactless payments at point-of-sale terminals?
  • Which entity accepts requests for digital certificates and performs additional steps to validate that the requestor has the authorization to do so?
  • What type of encryption is used to protect data in transit while it is being moved across systems?
  • What is the primary role of a Cloud Access Security Broker (CASB) in cloud security?
  • A defense contractor is tasked with using Mandatory Access Control policies for a classified project. Which of the following could they use?
  • Which audit area describes the legally compliant means by which data is removed and made inaccessible?
  • In the context of risk assessment, which term describes the frequency at which a threat may occur?
  • Which of the following is a popular source for system hardening, with a compliance checker tool provided by the U.S. Department of Defense?
  • Which of the following technologies is more resource intensive than virtualization but allows for running software designed for different hardware architectures?
  • Which method involves removing information that can uniquely identify an individual from data so that it can be shared without violating privacy laws and regulations?
  • In key management, what practice prevents the indefinite vulnerability of a compromised key?
  • In which log would an event related to a failed application startup due to a malicious process be recorded on a Windows server?
  • Why should a systems administrator not immediately release HIPAA information in response to a litigation hold?
  • What is often used to automate the process of checking system security, configurations, and compliance levels?
  • Privacy data typically refers to information that can uniquely identify which of the following?
  • Which security measure is defined by its ability to highlight what is allowed to run while blocking everything else?
  • An application specialist suggests using a particular application in a virtualized environment. What does the specialist recommend?
  • Which privacy law should an owner research before expanding operations in Japan?
  • Which trusted execution environment (TEE) mechanism can encrypt data as it exists in memory to prevent decoding by untrusted processes?
  • Which analysis method is typically used to explore vulnerabilities through manual code inspection?
  • Which of the following technologies focuses on creating realistic, synthetic images and videos that can mimic real people?
  • In the context of cybersecurity, what does the term ‘tokenization’ specifically help to achieve?
  • Which method is least likely to allow an organization to manage risks effectively?
  • What principle involves granting users the minimum account privileges necessary to perform their duties, helping to mitigate both insider threats and compromised accounts?
  • Which type of information is commonly associated with data provided to a financial institution?
  • What does the FFIEC (Federal Financial Institutions Examination Council) provide guidance on?
  • A system administrator is setting up a central log management solution. What are some of the benefits to doing so?
  • Which NIST Special Publication identifies the necessary groups when responding to an incident?
  • What is it called when a qubit can have multiple states simultaneously, including any value between 0 and 1?
  • What metric indicates how many times a single loss event is expected to happen annually?
  • Which of the following tasks is typically performed during digital forensics regarding file recovery?
  • Which organization is known for creating international standards utilized across various industries?
  • Which type of network architecture uses two firewalls placed on either side of a demilitarized zone (DMZ)?
  • Which detection technique should be used for an intrusion detection system to validate known signatures?
  • What allows connectivity between private subnets, or Virtual Private Clouds (VPC), and the Internet?
  • What should be the primary focus during a post-engagement review in penetration testing?
  • Which of the following is not a mandatory access control solution, but rather a Data Loss Policy that quarantines a file and replaces it with a policy violation notice?
  • Which of the following is NOT considered a strong hashing algorithm?
  • Which type of threat actor could use cyber espionage to steal a tech company's product designs?
  • What type of product automates the discovery and classification of data types and enforces rules to ensure that data is not viewed or transferred without proper authorization?
  • Which security control meets the needs of a financial institution required to comply with PCI DSS?
  • Which solution is commonly used on Microsoft Windows computers to protect data at rest?
  • Which EAP (Extensible Authentication Protocol) type is known for being one of the strongest and most widely supported authentication methods?
  • What is the outcome of implementing rate limiting for protecting against DDoS attacks?
  • Which encryption method is commonly used to protect data in transit, including website traffic, remote access, and cloud synchronization?
  • What hashing algorithm is utilized within the bitcoin network for proof-of-work?
  • Which solution provides security and management for mobile devices across an organization?
  • Which type of data sanitization provides effective protection from all recovery techniques?
  • While the system is operational, an industrial control systems engineer assesses analyses on packet capture and traffic analysis. What type of analysis is this?
  • Which component of risk management aims to reduce exposure to risk factors and decrease residual risk?
  • A security manager is reviewing security best practices. Which of the following would NOT be a physical security best practice?
  • Which protocol enhances network security by providing data encryption and authentication between two devices?
  • Which document serves as a formal means to define roles and expectations but is widely considered a non-binding agreement or difficult to enforce in court?
  • Which document describes the set of policies, contracts, and standards identified as essential in the agreement between two parties?
  • Which firmware interface can enforce boot integrity checks and allows the host to boot to an operating system?
  • Which service model is the best choice for a small business looking to minimize administration responsibility when migrating to the cloud?
  • Which type of system involves creating an unchangeable core that remains usable but not re-configurable?
  • Which metric represents the total amount of loss anticipated over a year due to single loss events?
  • Which method can be used to protect data at rest on Microsoft Windows computers?
  • What describes the deployment of an API-based Cloud Access Security Broker (CASB)?
  • What describes the set of automated tasks performed as part of deploying an instance, typically related to system administration?
  • Which type of system analyzes patterns and behaviors of users and entities to detect anomalies in User and Entity Behavior Analytics (UEBA)?
  • Which type of firewall architecture places a firewall both before and after a DMZ?
  • Which of the following provides critical information for defensive operations, including details about IP addresses and URLs associated with phishing campaigns and malware?
  • Which model describes five levels of maturity within an organization's operational or software capabilities?
  • A software developer is selecting a key agreement for an organization's authentication. Which agreement type should the developer use?
  • What is the primary data asset type being protected by enhanced security controls on a business network?
  • Which algorithm is primarily used for signing and operates similarly to RSA (Rivest, Shamir, and Adleman) but is based on logarithmic and modulus mathematics?
  • Which framework is created and maintained by ISACA to frame IT risk from a business leadership perspective?
  • Which type of intelligence involves collecting and analyzing data from publicly available sources to address the needs of a specific project or operation?
  • After completing an investigation, which stage involves sharing findings with authorities?
  • A security manager is standing up a risk management program at a company. What should the security manager set up that might be considered the most recognized output?
  • Which network appliance is used to provide fault tolerance by re-directing traffic when one server in a group becomes inoperable?
  • Which state of data is at risk in volatile memory that concerns the IT department?
  • In a cloud environment, which control mechanism is used to regulate both inbound and outbound traffic between virtual private clouds (VPCs)?
  • Which hashing algorithm was the NIST standard but was replaced in 2005 due to vulnerabilities?
  • What element of a risk management program is essential for ensuring consistency and reliability, but is not necessarily the most recognized output?
  • What certificate can a developer use to show that a browser plugin is trusted and has undergone an identity check by a certificate authority (CA)?
  • What describes the process of bundling certain libraries with an application at compile time?
  • Which tool should an incident handler use for hashing during an incident?
  • A security engineer is looking at various methods to use identity proofing. Which of the following are identity proofing methods?
  • What arrangement includes forty-two participating states and is designed to prevent the destabilizing accumulation of weaponry and military capabilities?
  • Which method allows a process to efficiently check if a certificate is revoked?
  • Which key exchange protocol is based on elliptic curve cryptography and is similar in operation to standard Diffie-Hellman?
  • What aspect of a privacy impact assessment (PIA) involves evaluating how the company uses and maintains data to ensure processes continue during a disaster?
  • Which service uses public cloud resources for Disaster Recovery, providing an offsite DR site for businesses?
  • Which protocol is a serial communications bus used primarily in the automotive industry for connecting electronic control units (ECUs)?
  • What protocol enables network interoperability for connected machines and supports scalability, performance, and Quality of Service (QoS) features in modern industrial applications?
  • Which risk management strategy can minimize SQL database breach risks?
  • What type of system is highly hardened, closely monitored, and typically used to perform administrative tasks or access servers in a secured environment?
  • Which value can a qubit represent in a quantum computing system?
  • What is the primary goal of a firewall in a network security architecture?
  • A security researcher wants to look for new and emerging malware on unindexed and hidden locations on the Internet. What should the security researcher use to look?
  • Which of the following is NOT an example of a benefit provided by a CDN?
  • Which of the following practices enhances privacy in a blockchain environment?
  • Which encryption algorithm is commonly combined with the Poly1305 MAC algorithm for secure encryption?
  • What is a key benefit of enforcing email protection as a cybersecurity measure?
  • Which web traffic protection method periodically obtains a time-stamped OCSP response from the certificate authority?
  • Which algorithm produces a 128-bit output but is deemed insecure for password representation?
  • Which remediation action prevents the user from copying a file but still allows them access to it, logging the violation?
  • What type of threat actor engages in actions like defacing websites and launching denial-of-service attacks?
  • Which protocol improves upon RADIUS (Remote Authentication Dial-in User Service) by addressing some of its weaknesses but is not commonly used as an identity proofing method?
  • Which tool is most suitable for performing live collection of system information from a powered-on server?
  • Which term refers to intangible products of human thought and creativity protected by intellectual property laws?
  • What tool is most appropriate for a software analyst debugging a Microsoft Windows application with a graphical user interface?
  • What consequence arises if the same hash is generated for two different files?
  • Which solution is typically associated with military establishments and enforces mandatory access controls between connected sites?
  • Which continuous process is often associated with detecting security vulnerabilities, but can also be used by developers to find issues while generating new code?
  • In which phase of forensic investigation do legal concerns primarily arise?
  • What term describes when a certificate establishes a trust relationship between two different certification authorities?
  • Which type of threat intelligence provides leadership-focused information and is associated with big-picture reports?
  • Which message authentication code (MAC) is designed for speed and efficiency, particularly on devices without AES hardware acceleration, such as older iPhone and Android devices?
  • A developer wants to create a web application using Python that promotes code re-use and facilitates rapid development. Which framework is the best fit?
  • During risk management activities, which phase utilizes quantitative and qualitative methods?
  • Which policy would most likely reduce security risks associated with personal device use in a corporate environment?
  • Which encryption method is known for both speed and providing integrity checks through its associated data?
  • What does the NIST Special Publication (SP) 800-84 provide guidance on?
  • How is a critical system protected when placed on a subnet between two firewalls?
  • Which solution provides day-to-day monitoring and reporting on various operational resources and activities within an enterprise?
  • Which sanitization method protects against all recovery techniques, even those in clean-room environments?
  • Which protocol is primarily used for network access control and has several server and client products available?
  • What vulnerability assessment method involves entering malformed data at data entry points?
  • Which protocol ensures that critical systems are available and responsive with minimal downtime?
  • A security engineer is setting up a security solution that can enforce mandatory access controls between two connected sites. Which of the following should the engineer implement?
  • Which cloud storage type is required for high-speed data access and performance, especially for transactional applications?
  • What is a key advantage of implementing a Cloud Access Security Broker (CASB) solution in terms of controlling access to cloud services?
  • Which of the following is just a component of both due care and due diligence, rather than the complete concept?
  • What component of risk is most closely associated with the concept of damage assessment?
  • Which risk management measure helps in reducing the risk levels by involving investments like insurance?
  • To improve a company's security posture with minimal infrastructure, which solution should be implemented?
  • What type of threat actor might attempt to obtain and release confidential information, perform DoS attacks, or deface websites?
  • Which type of actor might act against an organization to gain a financial advantage through illegal means?
  • Why might the use of a virtual private network (VPN) commonly employed in the United States be problematic in other countries?
  • Which NIST standard offers the latest guidance on password compliance and changes traditional password policy elements?
  • Which tool is responsible for automatically generating and injecting malformed data into a system using various number formats, character types, text values, and binary values?
  • What issue occurs when the system checks the state of a resource, but the resource's state changes after the initial check?
  • What mechanism allows the system to verify both the source and content of a message without using any other means?
  • During which SDLC phase are Static Code Analysis tools, linters, and automated unit tests used to identify vulnerabilities while writing code?
  • Which of the following is designed to collect and analyze data from multiple deceptive systems?
  • Which method is commonly used to analyze and determine the vulnerabilities within a network system?
  • What primarily distinguishes a Microcontroller from a System on Chip (SoC)?
  • Which step is not part of the first three steps of the data life cycle but occurs later when data is no longer used regularly and is stored to reduce costs and complexity?
  • Which incident type involves the theft of sensitive information through unauthorized access?
  • A system engineer is trying to explain due diligence to a group of system administrators. What word would best describe the idea behind due diligence?
  • Which protocol is specifically designed to combat replay attacks in WPA3?
  • Why is senior leadership support essential for successful Business Continuity and Disaster Recovery (BCDR) preparedness?
  • Which cloud model allows several organizations to share the costs of either a hosted private cloud or a fully private cloud?
  • In the hierarchical CA model, what is the role of intermediate CAs?
  • In evaluating a software company's supply chain, which components are most likely to be included?
  • What component is integrated into a System on Chip (SoC)?
  • What is the main focus during the 'Identify' phase of the Risk Management Lifecycle?
  • What is one of the primary ways a CDN improves the customer experience?
  • Which system effectively detects modifications in managed file images, such as application executables?
  • In a data loss prevention system, what action involves preventing all access to original files while notifying the user?
  • A security architect is setting up their demilitarized zone to place one firewall on each side. What is this type of configuration called?
  • Which type of scanner assesses endpoint devices, including computers, network equipment, and mobile devices, as well as the applications installed on them?
  • Which of the following is commonly referred to as an identity management protocol?
  • A data science engineer is analyzing qubits in a quantum computing artificial intelligence built to predict the end of the world. Which of the following values does the qubit represent?
  • A digital forensics expert needs to extract metadata from image files as part of an investigation. Which of the following tools is designed to read and write metadata for a wide variety of file formats?
  • Which cloud service model represents the lowest amount of responsibility for the customer, with the provider managing the facilities, utilities, physical security, platform, and applications?
  • Which core foundation of blockchain describes how all systems come to an agreement regarding a particular computation to maintain the overall integrity of the system?
  • What should a cloud administrator examine to see all configuration and access levels for an instance?
  • Which security solution aims to prevent data loss and protect data from unauthorized disclosure, while also trying to identify if and when data loss occurs?
  • Which mobile device policy allows employees to use their personal devices if they meet specific company requirements?
  • What does unauthorized alteration of system settings indicate?
  • What approach is used in key management to ensure proper identification and ownership of keys?
  • What does Level 2: Managed signify within a process framework?
  • Which cloud model falls between SaaS and IaaS in terms of the amount of resources provided and client administration responsibility?
  • Which of the following is not a data sanitization type but a process to reduce seek times on a hard drive?
  • Which standard focuses on cybersecurity audits and compliance, particularly relevant to the ISO 27k series?
  • What is the global data protection standard maintained by a consortium of payment card companies?
  • Which of the following is a security mechanism that prevents execution of code in certain memory regions?
  • Which practice involves monitoring user account activity to prevent unauthorized access and manipulation?
  • In the context of security frameworks, which phase focuses on implementing remediation strategies?
  • A systems manager is in charge of endpoint devices and wants to specify using a trusted CA. What should the systems manager specify?
  • Which of the following best describes the purpose of SAST?
  • Which security strategy is implemented by developers focusing on dynamic application testing?
  • During which phase of the Lockheed Martin cyber kill chain is persistent access typically established?
  • Which metric indicates the percentage of an asset's value lost during a risk event, used for calculating SLE?
  • What is the main action in inventorying certificates during their lifecycle?
  • What method is typically used to filter and manage traffic flow between different VPCs in a cloud environment?
  • Which open-source NAC (Network Access Control) solution can integrate with Microsoft's public key infrastructure (PKI)?
  • Which type of analysis involves manually inspecting source code to identify vulnerabilities in programming techniques?
  • What uses desktop virtualization to separate the personal computing environment from the user's physical machine?
  • Why is it important to adopt the principle of least privilege when securing logs in a central log management system?
  • Which security measure defines what is not allowed to run on a system?
  • Which NIST Special Publication outlines necessary controls for audits of information systems used for certification?
  • Which analysis type is most suitable for assessing software behavior under real conditions?
  • Which solution is ideal for file system integrity monitoring in data center environments?
  • Which method is used to measure the state of a qubit?
  • How did network administrators identify the vulnerability related to wireless signal extension into public areas?
  • Which metric is essential for risk management and provides insight into how often losses are likely to occur?
  • Which database is best for a development team looking for a document-oriented, open-source solution?
  • In which category can ambiguous processes lead to security breaches, such as fraudulent email requests?
  • What is a common method used to protect data at rest using encryption, often seen in Microsoft environments?
  • A military unit is going into a foreign country and setting up a small data center for their operations but wants to have an alternate option that is flexible and versatile. Which of the following options would best suit their needs?
  • What process involves deciding to continue operating despite identified risks as part of assessing residual risk?
  • What is the consequence of a COBO policy in a corporate environment?
  • What mechanism provides a trusted third party with vendor-developed source code for access if the vendor ceases operations?
  • What strategy involves evaluating risks and opting to continue with potential consequences?
  • Which phase of the software development life cycle incorporates secure coding patterns and best practice guidance from organizations like OWASP?
  • Which trusted execution environment (TEE) mechanism can encrypt data as it exists in memory, preventing untrusted processes from decoding the information?
  • When a company provides a list of devices for employees to select, which mobile device policy does that represent?
  • Which type of risk management approach focuses directly on reducing risks associated with operations rather than appetite levels?
  • What term defines how a system protects communication channels from risks such as infiltration, exploitation, and interception?
  • A disgruntled employee with access to sensitive systems intentionally deletes key files, causing disruption to business operations. Which type of threat actor does this scenario describe?
  • What NIST standard can a security architect reference for guidance on password compliance?
  • What type of cloud storage supports applications needing access to resources such as documents and videos?
  • Which step in the cyber kill chain refers to the successful delivery of a tool that results in a breach and provides access to the target system?
  • A security architect is setting up various security mechanisms for a retail company that handles a considerable amount of credit card processing. What industry-standard data masking technique should the security architect recommend?
  • A forensic expert needs to recover deleted or corrupted files from a disk partition. Which of the following tools should the expert use?
  • What is the term used for assessing the measure of a vendor’s product and its financial stability?
  • Which risk strategy involves assigning risk to a third party, often through purchasing an insurance policy?
  • A systems engineer is working in conjunction with security and has set up a data loss prevention solution. What remediation action should they choose to quarantine and replace files with a policy violation notice?
  • Which logical segmentation method creates separate virtual local area networks on a network device?
  • What concept do experts refer to when managing risk that includes the phases of Identify, Assess, Control, and Review?
  • Which response header can a developer use to protect against Cross-Site Script (XSS) Inclusion attacks?
  • Which type of analysis involves deconstructing software or hardware to determine how it works and how much information can be extracted from it?
  • What process identifies and evaluates the impact of updating a disaster recovery plan?
  • Which access control model empowers the resource owner to manage access permissions, typically the creator of the resource?
  • In quantum computing, what physical properties might represent quantum particle information in a qubit?
  • Which tool captures traffic in a networked environment and can store the captured traffic for further analysis using other software tools?
  • Which system identifies solutions to abstract problems by determining which simpler concepts are applicable?
  • A tech company suspects that a rival has used cyber means to steal its latest product designs just before a big launch. Which type of threat actor could be responsible for this industrial espionage?
  • Which of the following is a characteristic of mandatory access control (MAC)?
  • What solution should be recommended to provide a failback option for future application deployments?
  • What term describes the financial amount lost in one occurrence of a risk event, such as server downtime?
  • What legal concerns must an organization consider when implementing site-to-site VPNs?
  • During which phase are risks analyzed to assess their level of threat?
  • Which security tool monitors network traffic from a SPAN port but does not block traffic, instead analyzing it for suspicious activity?
  • What term best describes a protocol for verifying the successful connection between devices for secure communication?
  • Which MAC (message authentication code) mechanism would be best suited for older devices like iPhones and Androids that lack AES (advanced encryption standard) hardware acceleration?
  • What risk strategy focuses on reducing exposure to or the effects of risk factors?
  • Which backup solution is best for a mid-sized company with limited personnel looking for cloud solutions?
  • If a company provides a selection of approved devices for employees, what is the type of policy they are implementing?
  • In a cybersecurity incident response, which action is considered a priority during active investigation?
  • In data classification, what classification is used for documents intended strictly for internal use within the organization?
  • Which control measure is most effective at ensuring that sensitive areas are monitored continuously?
  • Why is it unlikely for conflicting laws to be an issue during the first verification of a data center failover?
  • What device is best suited for a solution engineer needing a controller that can change programming logic post-manufacture?
  • A forensic analyst needs to examine the contents of a memory dump to investigate running processes, open sockets, and other volatile data. Which of the following tools is best suited for this analysis?
  • Which component serves as a critical storage solution for developers managing their code in a software supply chain?
  • What are the first three steps of the data life cycle?
  • Which of the following best describes the term 'Confidential' in an organizational context?
  • Which of the following is not the primary focus of privacy data protection, as privacy data typically refers to information that can identify individuals?
  • A security architect is considering the design for an organization's transactional records and is currently researching blockchain. What are some of the foundational elements of blockchain technology? (Select all that apply.)
  • Which of the following primarily focuses on device identity and access policies?
  • Which strategy reduces the threat surface on a new web application?
  • What type of test is used to validate the system's compliance with non-functional requirements?
  • Which of the following components of WPA3 enhances the encryption techniques implemented in wireless communications?
  • Which hashing algorithm is stronger than MD5 (Message Digest Algorithm) and produces a much larger output but is not considered an authentication code?
  • Which type of security measure allows the definition of what is permitted to run on a system?
  • What does the AS grant to the user after processing the TGT request?
  • What security technology can detect and respond to suspicious activity on a company's computer systems?
  • What type of vendor assessment is concerned with the ongoing financial stability of a vendor?
  • An administrator creates a SPAN port that feeds traffic to a security tool. What type of tool is used to monitor suspicious network traffic without blocking it?
  • A security engineer is preparing tools for an engagement with operational technology. Which of the following protocols are most likely part of OT?
  • Which process uses platform configuration registers (PCRs) in the TPM during the boot process to ensure system integrity but is not related to encrypting data at rest?
  • For a service that communicates over HTTP using XML, which protocol ensures proper data exchange?
  • Which aspect is NOT supported by Public Key Infrastructure (PKI)?
  • What document identifies existing risks, ongoing monitoring, corrective actions, and the current disposition of an information system?
  • What is achieved by implementing blackhole routing for systems against DDoS attacks?
  • What does DLP stand for in the context of cybersecurity?
  • Which device is a processing unit that can perform sequential operations from a dedicated instruction set and requires software to be converted into assembly language?
  • APIs play a major role in interacting with which technology that allows applications to run independently in virtual instances?
  • What phase of the data lifecycle generally describes the collection of data with respect to regulatory compliance?
  • A new security analyst starts reading about varying privacy laws across different countries. Privacy data typically refers to which of the following?
  • Which type of threat intelligence focuses on the objectives and motivations of potential threat actors?
  • Which organization offers a vast library of guidance on secure coding practices, including topics like input validation, output encoding, and authentication management?
  • Which component of risk involves assessing potential consequences including scope, asset value, and financial impacts?
  • Which solution contains software that monitors daily operations of an enterprise and reports on the status of various resources and activities?
  • Which entity acts as a trusted third party in the public key ecosystem?
  • Which item is least likely to be a concern for a software company's supply chain but commonly pertains to hardware companies?
  • Which process involves setting up a new file system but does not ensure original data is non-recoverable?
  • A small business is looking at migrating to the cloud but wants as little administration responsibility as possible. Which of the following solutions would best suit them?
  • What objective is a security architect defining in a business continuity plan when assessing how much data can be lost without harming operations?
  • What issue arises when two files on a company website respond with the same hash?
  • Which Risk Management Lifecycle phase primarily deals with threat assessment and prioritization?
  • What is a common use of a Virtual Private Network (VPN)?
  • What type of database contains information on assets and components within an enterprise's IT environment?
  • What type of attack involves a malicious script being inserted directly into a vulnerable web application?
  • What allows a certificate to secure multiple subdomains by containing an asterisk character in its domain name field?
  • What is the risk of denying a data request for HIPAA information without consulting attorneys first?
  • Which option is not a method of network segmentation but protects communication channels from infiltration?
  • What type of segmentation is commonly used in ICS and SCADA networks, involving separate physical hardware?
  • Which component of PKI is responsible for issuing certificates to users or devices?
  • Which mode of encryption uses an initial chaining vector for the first round and combines previous outputs as input for subsequent rounds?
  • Which approach uses threat intelligence in a practical and actionable way?
  • An auditor for a federal agency is reviewing encryption. Which standard is the auditor most likely using?
  • Which protocol enables a server to communicate the status of a requested certificate efficiently?
  • A major retail company needs to set up alternate sites so that despite any unforeseen circumstances, the business has as little impact on its operation as possible. Which of the following would be the best setup?
  • Which of the following rewrites file data to occupy contiguous clusters, reducing seek times on an HDD?
  • Which measure does NOT protect against broken authentication for a web application?
  • A solutions architect is analyzing technology for user and entity behavior analytics (UEBA). The solutions architect should analyze which of the following technology solutions?
  • What method did a user use to install a custom ROM on a company-owned Android tablet?
  • In which access control model are organizational roles defined, with subjects assigned to those roles for access management?
  • In cybersecurity, which tool is crucial for monitoring user behavior and identifying anomalies?
  • What is important to establish when defining the maturity of vendor security operations and setting requirements for vendors?
  • Which system would an engineer implement to manage and automate workflows across multiple sites?
  • Which access control model allows users to manage permissions for various resources in a flexible manner?
  • A vulnerability manager is onboarding developers to the vulnerability management program and wants to focus on integrating security from the very beginning. What is the first step of the software development lifecycle the manager should integrate?
  • What attack involves manipulating the URL to access sensitive system files on a web server?
  • Which protocol is commonly used to protect data in motion across networks, such as cloud-synchronized data?
  • In which scenario would you use Network Access Control (NAC)?
  • What is the entity responsible for issuing and guaranteeing certificates that an organization can set up privately for internal communications?
  • What is the primary focus of a first responder securing a crime scene with digital evidence?
  • Which mechanism is specifically designed to control traffic between virtual private clouds (VPCs) in a cloud environment?
  • Which option can effectively manage permissions and access to sensitive files?
  • Which privacy act is specific to Singapore and governs the protection of personal data in that country?
  • Which of the following foundational elements ensures the integrity of a blockchain by cryptographically linking blocks?
  • Which assessment type ensures that a vendor is financially sound and will likely continue its services?
  • Which of the following places security at the forefront of development efforts but is not considered a software development method itself?
  • Which type of intelligence is focused on collecting information through direct human interaction to understand and influence people?
  • Which of the following best describes a zero-day vulnerability?
  • Which type of indicator informs management of the risk levels associated with various processes?
  • Which technology solution takes complex concepts and breaks them into simpler elements?
  • A systems administrator has a litigation hold for HIPAA data that is older than four years old. How should the administrator respond?
  • Which key management practice involves considering secure locations to store cryptographic keys, to avoid accidental exposure or compromise?
  • A web developer requires a method for client-server data exchange that supports standard HTTP methods. What should they implement?
  • Which method allows an employer to manage the portion of a mobile device that connects to the corporate network?
  • In which type of cloud model do users share resources but have their own allocated environments?
  • Which block cipher mode of operation prevents manipulation of ciphertext by prior ciphertext blocks?
  • What main benefit does implementing Security as Code provide during development?
  • What ISO 27k standard focuses on personal data and privacy guidance?
  • What type of deceptive tool is best for tight control and monitoring of network attacks?
  • In quantum mechanics, what term describes a system being in a specific state due to observation?
  • In deploying a Cloud Access Security Broker (CASB) solution using a reverse proxy, how is the CASB configured?
  • A data center manager is planning for disaster recovery. What key element should the manager first gain that is critical to success?
  • Which model describes five levels of maturity in operational or software capabilities?
  • Which of the following involves the use of a digital certificate issued by a Certificate Authority (CA) to encrypt emails and attachments?
  • What architectural approach seeks to minimize trust levels for resources and users?
  • Which of the following is closely associated with the extraction of executable logic and data?
  • What resource is most useful for an incident responder creating an incident response plan?
  • Which risk strategy involves evaluating an identified risk and deciding to continue the activity despite the risk?
  • What is another term for public clouds, where businesses can offer subscriptions or pay-as-you-go services and sometimes provide lower-tier services free of charge?
  • Which of the following ISO 27k standards is specifically for information security controls in cloud environments?
  • What is the primary responsibility of a Cloud Service Provider (CSP) after a security breach?
  • Which of the following is an application layer attack that ModSecurity can help protect against?
  • What is a core function of a good business continuity plan?
  • Which client authentication mechanism can help a server verify that a connection request is originating from a pre-authorized endpoint?
  • Which central log management strategy supports real-time monitoring and alerting of security events?
  • If a cloud engineer is setting up a Zero Trust Architecture, which NIST document should they avoid as it is focused on incident response?
  • What must key strategic objectives and metrics development include to measure operational success effectively?
  • Which solution can inspect higher-level protocols to provide more granular protection against malicious traffic?
  • Which type of contract typically serves as an "umbrella" agreement between two entities to conduct business during a defined term?
  • What should a systems administrator do first when handling a litigation hold request involving sensitive HIPAA data?
  • What process is utilized to ensure that a digital certificate represents the correct owner?
  • Which Cloud Access Security Broker (CASB) method directs traffic from users at the client network to cloud services but only forwards traffic that complies with organizational policy?
  • What solution implements user identity assertions and transmits attestations between the principal, the relying party, and the identity provider?
  • Which framework, maintained by ISACA, addresses IT risk from a business perspective?
  • Which type of cipher does RC4 belong to?
  • Which step in business continuity planning involves developing fallback options if planned strategies fail, and requires an accurate inventory to be effective?
  • Which framework, created and maintained by ISACA, frames IT risk from a business leadership viewpoint and is used to manage and govern enterprise IT?
  • What process involves making changes to the production environment using configuration management platforms to support newly updated applications?
  • Which audit area defines the timespan for which a company must keep its data, including both the minimum and maximum duration?
  • Which response header limits documents from loading from origins other than the source but would not mitigate XSS Inclusion attacks?
  • Which of the following is not a simulation but would be an option for actually performing an active failover to test disaster recovery capabilities?
  • Which type of analysis requires the evaluation of a system or software while it is actively running?
  • A Ruby developer is searching for a lightweight web application framework that supports third-party library extensions. What should they choose?
  • What enables quantum computers to perform computations significantly faster than traditional computers in certain scenarios?
  • What technology, used in WPA3, replaces WPA's 4-way handshake authentication and association mechanism with a protocol based on the Diffie-Hellman key agreement?
  • Which protocol facilitates sharing of information within a user profile between sites, allowing users to log in without sharing their password with the consumer site?
  • Which response header defines whether content can be displayed using frames, primarily to defend against clickjacking attacks?
  • What term describes how long systems or applications can be down before significant harm occurs?
  • What is the function of modes of operation in encryption?
  • Which attack allows an attacker to take control of all virtual machines on a host?
  • Which of the following does not occur during the smartcard authentication process?
  • In what type of network do nodes self-organize to provide services typically associated with client-server networks?
  • Which environment is typically used in the early stages of testing, allowing developers to perform broad testing and proof of concept evaluations?
  • What system allows users to authenticate and gain access to various service providers by issuing a token?
  • Which solution is designed to ensure that digital content is only accessed or used in specific, authorized ways by consumers?
  • What type of information can be used to identify an individual, including names and social security numbers?
  • In cloud computing, what does the acronym IaaS stand for?
  • What is a key consideration when granting a pen-tester access during a penetration test assessment?
  • Which security testing method evaluates source code for security flaws often through add-ons to an IDE?
  • What type of IoT device can be specifically used to gather environmental data?
  • Which mode of operation provides authenticated encryption with associated data (AEAD)?
  • Who is the entity held accountable for the protection of data under their control?
  • Which development method focuses on releasing small, well-tested code blocks as quickly as possible to bring functionality to the business?
  • Which phase involves the periodic re-evaluation of risks to confirm their current threat levels and effectiveness of controls?
  • In the Lockheed Martin cyber kill chain, what step is discussed when a tool is delivered successfully?
  • In which mobile device policy are all devices strictly for business use without personal activities allowed?
  • Why might an organization consider a federation approach for credential management?
  • Which technology helps to strengthen the resilience of a cloud presence?
  • Which of the following is a technical control that helps protect against attacks targeting personnel but does not directly manage personnel risk?
  • What type of attack aims to overwhelm a target with traffic, disrupting normal traffic flow to a server or service?
  • What is the function of the Certificate Revocation List (CRL)?
  • What is a key benefit of using a System on Chip (SoC) in electronic devices?
  • Which method allows sysadmins to configure devices and services for administrative logins, using cryptographic keys or passwords?
  • Which type of policy allows a company to own devices that can be used for personal purposes?
  • Which standard focuses on IT security techniques, including the introduction and general model, as well as functional and assurance components that define various operations?
  • A forensic investigator prepares a report outlining tools and methods from an investigation. What process stage is this?
  • Which service model provides hardware hosted at a provider facility, with the provider responsible for infrastructure, physical security, and utilities like power?
  • What process ensures that an application can run independently on different systems by bundling necessary libraries?
  • A network administrator is searching for an open source network access control (NAC) solution to integrate with the company's public key infrastructure (PKI) environment. Which of the following could the administrator use?
  • What is the secure version of the Lightweight Directory Access Protocol (LDAP), using SSL/TLS encryption to prevent eavesdropping and man-in-the-middle attacks?
  • Which term describes the phase in which an adversary or penetration tester may continue to work on an exploited system to maintain access for future use?
  • Which type of assessment is practical and useful for consistently identifying and remediating vulnerabilities within an organization's environment?
  • Which type of threat intelligence identifies current attacks and indicators of compromise (IOCs) and is used by security and forensic analysts, as well as incident responders?
  • How does 3D printing increase on-demand availability for custom parts?
  • A security researcher for a political campaign is researching threat actors. Who should the researcher investigate that would most likely target them specifically?
  • Microsoft Windows BitLocker can use whole disk encryption to protect which type of data?
  • What is the primary impact of a security breach resulting from people-related flaws?
  • Which of the following is a benefit of 3D printing, allowing companies to craft accurate components at a fraction of the cost of traditional manufacturing?
  • Which security control will secure web applications and protect personal data of EU residents in compliance with GDPR?
  • Which department is key in a qualitative risk assessment regarding a company's brand image?
  • Traffic originating from a country without business operations may suggest what?
  • What is one of the key benefits of using a Cloud Access Security Broker (CASB)?
  • What solution has a systems security engineer provided by using a hardware security module (HSM)?
  • Which technology is specifically designed for encrypting data at rest and incorporates FIPS 140-2 standards?
  • Which development model uses iterative processes to release well-tested code in smaller blocks, with development and provisioning tasks conceived as continuous?
  • In a data life cycle plan, regulatory restrictions are typically less stringent during which phases?
  • In industrial environments, what are control computers used for direct automation in assembly lines called?
  • What approach do systems administrators use to isolate a critical system from outside networks?
  • Which method involves a series of phases where each phase starts only when all tasks from the previous phase are completed, creating a cascading effect?
  • Which solution controls how consumers use digital content after it is published?
  • Which type of intelligence gathers and analyzes publicly available data to address the needs of a specific project or operation?
  • What issue occurs when the system checks the state of a resource to verify its state, and then performs an action based on that check, which may become invalid?
  • If a security analyst has limited storage, which type of data is the best for traffic analysis?
  • What risk is associated with live VM migration lacking proper authentication?
  • A security administrator is concerned about unauthorized changes to system files in a server environment and wants to monitor files for any changes. The administrator plans to use a method that compares file hashes with known legitimate values. Which solution should the administrator implement?
  • Which systems are most important for operational continuity and should be prioritized in disaster recovery planning?
  • What principle encourages developers to commit and test updates frequently, sometimes multiple times a day?
  • What term describes the process of identifying, collecting, and providing electronically stored information (ESI) as part of a legal hold?
  • Wireless engineers at a large communications provider rollout Wi-Fi Protected Access 3 (WPA3) at a client site. Which features influence the decision to utilize WPA3 over WPA2?
  • Which devices in an IoT system are responsible for measuring factors such as temperature, humidity, proximity, motion, and more?
  • In which cloud model does the customer take responsibility for selecting and configuring operating systems, while the provider manages the underlying infrastructure?
  • A system administrator wants to send an email with an attachment through encrypted means. Which of the following should the sysadmin use?
  • Which of the following is best done before an incident or during an after-action review, rather than during the actual response to an incident?
  • Which department can provide significant insights during a qualitative analysis of intangible assets?
  • Which measure involves assigning risk to a third party, such as through insurance, to reduce residual risk?
  • A solutions engineer is looking for a cloud model owned primarily by the organization they work for, but the engineer also wants to reduce costs where possible. What solution would most likely fit the engineer's organizational needs?
  • A developer is looking for a solution that will help to detect flaws, bugs, errors, and defects in applications running in production environments. What is this method called?
  • Which option, while often seen as a modern solution, does not by itself ensure security without a proper defense-in-depth strategy?
  • What is typically the first step in the software development life cycle?
  • Which step in the cyber kill chain involves developing the tool and technique used against an organization based on information gathered during reconnaissance?
  • Which CA model involves a root CA issuing certificates to several intermediate CAs, which in turn issue certificates to end users?
  • Which emerging technology could significantly impact the security of current encryption methods?
  • Which solution will notify the security team automatically in the event of future malware variants invading the network?
  • What type of remediation policy is implemented if users cannot copy files but can read them?
  • What tool can a security analyst use to capture network packets for further analysis?
  • A security manager is planning for the needs of an immediate frantic and pressing emergency. Which plan should the security manager focus on developing?
  • What is the primary goal of using Data Loss Prevention (DLP) systems?
  • What security measure protects web servers by ensuring the validity of digital certificates?
  • Which system is suited for large-scale industrial control, replacing the control server?
  • What type of agreement occurs between two entities that need to share data via an interface, focusing on security considerations?
  • What type of segmentation allows for separate operational and information technology networks?
  • Which service allows users to access various service providers (SPs) by authenticating the user and granting a token for access?
  • Which function does a load balancer primarily serve in a distributed server environment?
  • Which type of data is considered intangible and would require strict security measures?
  • What is the main purpose of a cryptoprocessor in a smartcard?
  • A penetration tester is trying to stress test a web application by injecting malformed data into it. What is this method called?
  • Which type of attack involves overwhelming a system with traffic to render it unavailable to users?
  • Which stage of the forensic process involves creating a copy of evidence?
  • A developer is looking for a solution that will provide confidentiality and check its integrity and authenticity for encrypted plaintext. Which solution should the developer use?
  • What type of test is performed to ensure that individual components of a system interact correctly when tested together?
  • Which network architecture is often used with blockchain ledgers to mitigate risks associated with a centralized authority but is not commonly used in UEBA?
  • To focus on network-related information without including system logs, which should a security analyst collect?
  • What device is typically used for facilitating Z-Wave or Zigbee communication in IoT systems?
  • What type of agreement typically serves as an "umbrella" contract between two entities to conduct business during a defined term?
  • What data integrity control mechanism is used to locate invalid, obsolete, redundant, or outdated data from a database or data warehouse?
  • Which technology is designed to encrypt data at rest specifically in compliance with FIPS 140-2 standards?
  • A developer needs an authentication coding mechanism that supports older iPhone/iPad and Android devices. Which of the following would work best for the developer?
  • Which protocol is primarily used for securing voice over IP (VoIP) communications?
  • Which NIST publication is the standard for Zero Trust Architecture, focusing on security based on resources like users, services, and workflows instead of network boundaries?
  • To prioritize analysis of user interactions with software, which data type should an analyst focus on?
  • Which solution automates routine security tasks and responses to security incidents?
  • Which of the following technologies encrypts data as it exists in memory to prevent untrusted processes from decoding the information?
  • Which technique is used to secure sensitive information, such as credit card numbers, by replacing the data with a non-sensitive token?
  • Which type of certificate is considered the same as a general purpose certificate?
  • What tool is best for comparing functionally identical files that may have been obfuscated?
  • What is Microsoft's solution for a Type 1 hypervisor that allows a systems administrator to perform a physical to virtual migration?
  • What label should be applied to information that is too valuable to allow any risk of its capture, with viewing severely restricted?
  • Which security design provides an empty area surrounding a high-value asset, disconnecting it from any network and making it easier to detect unauthorized attempts?
  • Why can the AS decrypt a TGT request during the smartcard authentication process?
  • Which of the following should not be a characteristic of a central log management system, as it can lead to security misconfigurations?
  • After a Certifying Authority accredits a system, what formal letter is granted to the system owner, allowing the system to operate for a period of three years?
  • What is the role of subordinate or intermediate CAs (Certificate Authorities) in a hierarchical certificate model?
  • What type of attack involves intercepting and altering communications between two parties without their knowledge?
  • What authentication feature does Security Assertion Markup Language (SAML) provide?
  • Which virtual machine attack has the highest potential to compromise the entire architecture?
  • Why is RC4 considered vulnerable despite being a stream cipher?
  • Which network application protocol supports communications within an Operational Technology (OT) network?
  • Which metric indicates the potential alteration of information if a vulnerability is successfully exploited?
  • Which department's involvement is less critical in qualitative risk assessments for intangible metrics?
  • A helpdesk administrator is implementing encryption for data at rest for their Enterprise Windows clients. Which of the following is a common solution?
  • What is a common method used to secure wireless networks from unauthorized access?
  • Which tool can be used to monitor and analyze network traffic for potential security issues?
  • Which type of site is management looking to implement to save costs in a business continuity plan?
  • A security researcher is tasked with assessing the security of a WiFi network to ensure that it is protected against potential attacks. Which of the following tools would be the most appropriate for this purpose?
  • Which of the following best describes the purpose of a vulnerability scan?
  • What term describes a customer's high dependency on a vendor's products or services, complicating vendor changes?
  • Which agreement goes beyond the provisions of an SLA to include metrics and measures related to information privacy and data protection?
  • What tool should a web developer use to interact with code in the browser without restrictions?
  • What technology uses a virtual machine to provision corporate desktops, often replacing typical desktop computers with low-spec thin clients?
  • What does 128-bit AES-GCM (Galois Counter Mode) represent in a cipher suite?
  • Which phase of the Risk Management Lifecycle demands significant time and effort for security control implementation?
  • Which labels should be used for information too valuable to allow any risk of its capture?
  • Which technology emulates a real-life environment through computer-generated sights, sounds, and sometimes smells and touch but is not commonly used in UEBA?
  • Which service model provides resources like servers and storage but requires the most amount of administration responsibility from the client?
  • Developers that are working on a web application use coding practices to prevent insecure references. What vulnerability have testers uncovered?
  • A security practitioner is conducting a privacy impact assessment (PIA) as part of a business continuity plan. What should the practitioner assess?
  • An organization has contracted a penetration tester to perform a test for them. Which of the following is NOT a consideration for the test?
  • During which phase of a digital forensics investigation do experts perform repeatable methods using the same tools on data?
  • Which NIST document addresses security and privacy controls for federal information systems but is not specifically focused on Zero Trust Architecture?
  • What component of WPA3 is designed to protect against key recovery attacks?
  • Which security design would be most appropriate for protecting a high-value asset in a sensitive facility, such as a nuclear power plant, by isolating it from any network?
  • What is an example of a method used to protect data in motion, which describes the state when a system moves data?
  • Which testing method is aimed at deep integration of various subsystems in a larger system?
  • To ensure builds of a new mobile application are trusted, which solution should the security team use?
  • What technology enables secure and contactless payment transactions using a PoS machine?
  • What cloud service model allows the provider to handle physical security and utilities while the customer manages their own operating systems?
  • A data center lead is preparing an organization for disaster recovery and wants to minimize impact to production systems. Which method should be used?
  • What is the main control mechanism emphasized by role-based access control (RBAC)?
  • What type of analysis emphasizes the examination of system operations in a live environment?
  • Which device forwards traffic between subnets by inspecting IP addresses and operates at layer 3 of the OSI model?
  • What access control mechanism involves defining access levels for users and subjects in a network environment?
  • Which cloud service model requires the least amount of administration responsibility from the client's perspective?
  • What cloud model is offered over the Internet by cloud service providers (CSPs) to cloud consumers, often on a pay-as-you-go basis?
  • Which strategic assessment determines the acceptable level of residual risk an organization can tolerate?
  • What component of WPA3 enhances security by implementing stronger authentication mechanisms?
  • What role does a cloud access security broker (CASB) serve in cloud environments?
  • What is a primary function of a CASB regarding cloud data management?
  • Which scenario best describes a lock-out issue with a technology services vendor?
  • Which type of environment is designed to be used by visitors, such as the public or vendors?
  • What evaluation measures security capabilities of a cloud service provider against Cloud Controls Matrix?
  • During a risk management exercise regarding server security, what phase is used to document findings about file replication without encryption?
  • Which hashing algorithm does bitcoin use for program development?
  • Which entity accepts requests for digital certificates and validates that the requestor has authorization?
  • In the context of software development, what is a common issue that occurs due to multiple processes attempting to modify a shared resource at the same time?
  • During which process are data remnants most concerning in a virtualized environment?
  • Which method is used to protect data in transit, including website traffic, remote access traffic, and data synchronized between cloud repositories?
  • Which two forms of segmentation would typically be included in a risk assessment consultation?
  • Which solution should a storage administrator choose for high-performance, transactional applications?
  • Which of the following is NOT typically a function of a Cloud Access Security Broker (CASB)?
  • What principle ensures that an employee has access only to the information necessary for their job role?
  • Which cloud model is completely private to an organization and typically managed by one business unit while others make use of it?
  • Which standard segmentation options could a risk assessment consultant offer?
  • Which mode is used to ensure confidentiality by combining plaintext with a keystream generated from an incrementing counter value?
  • Which test ensures that a particular block of code performs the exact action intended and provides the exact output expected?
  • What specific action do security consultants recommend during a tabletop exercise?
  • What term is used to describe the network of suppliers, vendors, and partners involved in delivering a final product, and is often a significant source of risk?
  • A security analyst is attempting to create efficiencies by automating certain tasks defined in the security playbook. Which automation tool would help the analyst accomplish this?
  • Which of the following is not an industry standard but is important for defining how modern organizations work with vendors, suppliers, and contractors?
  • Which framework aligns IT risks with business objectives for executive leadership?
  • A web development team wants to modernize an application that relied on Flash plugins. What should they consider using?
  • What must a Certifying Authority review to grant accreditation to a corporation's information system?
  • A security analyst is performing a security assessment and is recommending ways to manage risk relating to personnel. Which of the following should the analyst recommend?
  • Which detection system is best for continuous monitoring of intrusions on host-based systems?
  • What can be a consequence of improper deprovisioning in a virtualized environment?
  • Which of the following is true about a port scanner in cybersecurity?
  • Which network security solution would control access to a network and is open-source?
  • Which algorithm is widely used for digital signatures and is based on factoring large prime numbers?
  • Which of the following involves blocking traffic based on static rules or dynamically updating settings based on alerts from SIEM and IDS tools?
  • What does standardized log formatting facilitate in a central log management system?
  • Which concept creates a blend of complexity through diversity, slowing down an attacker's progress and granting more time for detection?
  • What solution does heterogeneity refer to when strengthening a cloud architecture?
  • Which configuration is typically used to secure a demilitarized zone (DMZ) by placing firewalls on both the external and internal sides?
  • Which of the following is used to create cloud resources within private networks, similar to traditional data centers?
  • Which actions can ensure the integrity and authenticity of a company's cloud infrastructure?
  • Which configuration guides can be downloaded for free and include detailed descriptions of configuration points for system hardening?
  • Which standard addresses IT security techniques, including the introduction and general model, as well as functional and assurance components?
  • Which tool is most effective in defending against social engineering attacks, especially since attackers use it to directly access staff and employees?
  • What role does communication play in the context of security processes?
  • In a central log management system, which approach is best for ensuring data integrity and security?
  • Which method of deploying a CASB involves a security appliance positioned at the client network edge that forwards user traffic to the cloud if it complies with policy?
  • What does the principle of least privilege in cybersecurity refer to?
  • Which service model is specifically designed to charge clients based on execution time instead of fixed hourly rates?
  • Which type of threat intelligence focuses on the tactics, techniques, and procedures (TTPs) of a threat actor and is used to fortify vulnerability remediation and alerting?
  • When dealing with sensitive data, which encryption method is often employed for data storage?
  • What identity proofing method is a refinement of the Hashed Message Authentication Code One-Time Password (HOTP)?
  • Which feature of Public Key Infrastructure (PKI) supports integrity checks?
  • A security administrator wants to enable a feature that distinguishes between executable and non-executable areas of memory for protection. What feature should be enabled?
  • What type of inspection method evaluates running code to observe its behavior and detect anomalies?
  • Which element is not typically part of a penetration test assessment unless specifically requested by the customer?
  • If a security engineer uses public key certificates between clients and servers, which EAP implementation is deployed?
  • Which system facilitates direct automation of operations within assembly lines and robotics?
  • What type of information is the consultant auditing in a compliance audit for a hospital?
  • A security auditor is conducting a compliance audit for his company. Which audit area would describe how long the company is required to keep copies of data?
  • Which EAP (Extensible Authentication Protocol) type uses a server-side certificate to establish a protected tunnel, similar to PEAP (Protected Extensible Authentication Protocol)?
  • A site developer has experienced issues with Cross-Site Script Inclusion attacks. Which response header could be used to mitigate this attack?
  • Which algorithm used in modern data encryption is designed for high performance in software implementations?
  • Which cryptographic protocol, used in WPA3, replaces AES CCMP to provide updated encryption?
  • A software process that authenticates through certificates can check for validity using which of the following methods?
  • What cryptographic function combines two functions to authenticate a sender and prove the integrity of a message?
  • What is a potential risk of not implementing a central log management system?
  • Which consideration is important when performing an onsite penetration test to comply with corporate policy regarding access and staff limits?
  • Which tool is used for network discovery tasks and security auditing, providing a way to assess systems and software running in a networked environment?
  • Which policy can be implemented on mobile devices to grant different levels of access based on geographic location?
  • Which assessment framework is best suited for supporting a security architect's policies for safeguarding technology and financial operations?
  • What technology is used in video games and simulations but is not typically associated with User and Entity Behavior Analytics (UEBA)?
  • What aspect of cybersecurity focuses on preventing malicious activity from exploiting software vulnerabilities?
  • Which software solution is designed to detect and prevent sensitive information from being used, transmitted, or stored inappropriately?
  • By analyzing which of the following can trends appear that may indicate additional risk items requiring proactive attention?
  • Which tool should a forensic analyst use for analyzing a memory dump related to running processes during an investigation?
  • What is the primary purpose of Mobile Device Management (MDM)?
  • What is the advantage of having different subordinate CAs set up in the hierarchical CA model?
  • A Security Operations Center (SOC) analyst wants to develop internal indicators of compromise (IOCs). What type of threat intelligence should the analyst use?
  • An application uses encrypted transactional data to record incoming and changing data sets. Which technology does the application use?
  • Which algorithm is a variant of Salsa20, used for encryption in the Chrome browser on Android devices?
  • Which element is significant for the Common Vulnerability Scoring System (CVSS) score but is not a primary risk component?
  • Which label is commonly used in military settings for sensitive information while companies might use a different term for the same level of sensitivity?
  • A software developer wants to ensure that an application includes all required libraries during compile time, allowing it to run independently without external dependencies. Which of the following describes this process?
  • A security analyst is determining a process for some important infrastructure elements to leverage when responding to a valid indicator of compromise. Which of the following would NOT be a normal step?
  • Which component of WPA3 replaces the traditional 4-way handshake mechanism?
  • What set of cybersecurity standards was created by the United States Department of Defense to enhance supply chain security?
  • Which controller is most appropriate for engineers requiring post-manufacturing programming adjustments?
  • What is the entity responsible for issuing and guaranteeing certificates, often set up privately for internal communications?
  • What component is related to both people and processes but is not a primary category for identifying security flaws?
  • Who among the following is considered a threat actor that acts from within the organization?
  • Which method should a Flash developer use to communicate a markup text type similar to XML?
  • What does data integrity management focus on ensuring?
  • Which methods would likely guarantee that hard drive data is irrecoverable from advanced recovery methods?
  • In the context of securing a corporate network, which approach is emphasized by zero trust security?
  • Which of the following is not a benefit of 3D printing, but rather a potential drawback related to liability?
  • A data scientist is trying to gather sources for data analytics. Which of the following is NOT an example?
  • A website administrator wants a digital certificate that requires more rigorous checks. What could the administrator try to use?
  • Which system is responsible for managing process automation at a localized site?
  • Which of the following are part of the OWASP Top Ten vulnerabilities?
  • Which security solution is responsible for filtering unwanted email based on predetermined criteria?
  • A software developer is looking to implement a cloud test environment that charges based on execution time. What is this model known as?
  • What is the purpose of a vulnerability assessment in cybersecurity?
  • In which attack is a user tricked into submitting a malicious form request on a banking website?
  • Which US federal law protects the privacy of children under the age of thirteen?
  • Which identity proofing method generates a software token on a server and sends it to a resource assumed to be safely controlled by the user?
  • Which type of environment is ideal for testing unknown third-party code and is also referred to as a malware analysis server?
  • Which type of alternate site provides close to real-time activation with little to no service disruption but is the most expensive and complicated to implement?
  • Which type of analysis requires the evaluation of a system or software while it is actively running?
  • What could cause software not to work when brought up from recovery during a data center failover?
  • What type of cloud storage is most suitable for high-performance, transactional applications such as databases?
  • What is a common way to manage user permissions and segment access within an application layer?
  • What are the primary benefits of WPA3 in wireless security?
  • What problem does public key cryptography address within Public Key Infrastructure (PKI)?
  • A software developer is looking for a common framework for Java development. Which framework could they use?
  • A vulnerability manager must comply with certain regulations for the organization's industry. What should the manager most likely do to comply?
  • Which U.S. law applies to medical information and is not applicable outside the United States?
  • When implementing zero trust security, how should vulnerability scans for a cloud-based infrastructure be conducted?
  • Which of the following is NOT an indicator of compromise according to CompTIA?
  • Which approach is essential for tracking and managing vulnerabilities within a system?
  • Which component specifically handles the conversion of private IP addresses to public IP addresses for internet access?
  • Which of the following is not directly related to key management but refers to the intentional spreading of data across different storage locations?
  • Which security testing method reviews code while it is executing as the final product?
  • What is the live environment used by staff, employees, customers, and other stakeholders on a day-to-day basis?
  • An internal cloud application at an organization requires additional storage space. What cloud deployment and service models did the engineers use?
  • Which tool provides functionality for analyzing live memory data?
  • What is the primary objective of using a digital signature in federated identity management?
  • In the context of cybersecurity, what does NIST SP 800-53 primarily provide guidance on?
  • What mechanism does WPA3 utilize to help ensure protection against man-in-the-middle attacks?
  • What term describes the framework for passing messages between applications using formats like SOAP and REST?
  • A data center technician is part of an organization that requires FIPS 140-2 encryption standards for encrypting data at rest. Which of the following technologies incorporates this standard specifically for data at rest?
  • A solutions architect is designing a security architecture for a nuclear power plant facility. Which of the following would be the best design?
  • Which NIST standard focuses on Zero Trust Architecture, addressing security based on resources like users and services rather than network boundaries?
  • A systems administrator is looking into hardening their systems. What are some popular guides the sysadmin could follow?
  • A security analyst notices a spike in inbound traffic that deviates from normal patterns. This could indicate which of the following?
  • Which of the following is generally less complicated to deploy than other deceptive technologies but serves a similar purpose?
  • A security researcher wants to deconstruct software to determine how it works. What is this type of analysis called?
  • For establishing incident handling procedures, which publication should an incident responder reference?
  • Why might Demilitarized Zone (DMZ) systems, despite their extra risk factor, not be prioritized over mission critical systems in disaster recovery planning?
  • Which model assesses the maturity of software engineering practices in an organization?
  • Which of the following refers to honeytokens or canary traps, designed to lure adversaries by containing appealing data like user credentials or account numbers?
  • Which method allows users to authenticate with certain websites using a single account, enabling them to retain a single login for all participating sites?
  • In the context of PKI, which of the following is a requirement for achieving non-repudiation?
  • A security analyst is setting up documents for the outputs of the test or incident, along with recommendations based on the outputs and findings. Which standard should the analyst reference?
  • When a developer writes a simple "pass/no pass" test for code, what type of test is being performed?
  • What is the most effective risk mitigation process to address a vulnerability in a Kubernetes deployment?
  • Which NIST publication outlines the necessary controls for audits of information systems used for certification?
  • Which approach involves multiple redundant processing nodes that share data and accept connections to provide redundancy in case of failure?
  • Which key management practice is crucial in order to ensure compromised keys do not remain vulnerable?
  • Which component, often used in projects to speed up development, may also introduce potential security vulnerabilities?
  • Which term describes an adversary's or penetration tester's ability to establish access to the target environment at-will and undetected?
  • Which protocol should a system administrator use to send an email with an encrypted attachment?
  • Which cryptographic protocol in WPA3 offers authenticated encryption with 128-bit and 192-bit AES options?
  • A security architect is looking for examples of standards and regulations with descriptions of Business Continuity and Disaster Recovery (BCDR) capabilities. Which of the following are examples?
  • Which protocol is commonly used for secure user authentication in PKI?
  • A software development manager wants to integrate a development model for a company that will allow them to release small blocks of well-tested code to bring functionality to the business as soon as possible. What is this method called?
  • Which storage type employs a hierarchical file system for organizing files by path with attributes like owner and permissions?
  • Which departments should be consulted for qualitative analysis of intangible assets?
  • Which strategy helps to identify weaknesses in systems before they can be exploited by attackers?
  • A system administrator has decided to start a small data center venture for small businesses. What type of agreement should the sysadmin set up to meet the performance metrics defined in Service Level Agreements?
  • What type of security tool actively blocks malicious traffic and must be placed inline with network traffic to be effective?
  • Which council provides guidelines and standards for financial institutions, including Business Continuity and Disaster Recovery (BCDR) capabilities?
  • What does a certificate signing request (CSR) contain?
  • During a forensic analysis, a security professional needs to extract data from a binary file and display the content in hexadecimal format. Which tool would be the best choice?
  • Which physical security control should be used to track visitors to a facility, with the level of detail depending on the facility's sensitivity?
  • Which type of control offers preventive capabilities by removing elements often exploited by an adversary and is considered a technical, not physical, control?
  • What is the main purpose of implementing continuous integration in software development?
  • What type of certificate requires an identity check and validation by a certificate authority before being issued to a software publisher?
  • Which service model is optimal for billing based on actual usage, particularly execution time?
  • A developer working on a Python-based project needs to implement network communications. Which framework should they choose?
  • Why is it important to collaborate with business units when identifying mission critical systems?
  • What is a common risk when multiple unnecessary services are running on a server?
  • What does 'Critical' indicate when labeling data?
  • What benefit of a central log management system helps ensure compliance with legal and regulatory requirements for log collection and alerting?
  • Which type of scanning uses indirect methods, such as inspecting traffic flows and protocols, and is often suited for industrial or sensitive networks?
  • What technology enables applications to run virtual instances independently from the traditional hypervisor virtual machine approach?
  • Unauthorized access to devices would most likely indicate which of the following?
  • Which type of certificate allows the use of the certificate for multiple subdomains by containing an asterisk in its domain name?
  • What value can a qubit have that is different from a traditional computer bit?
  • A software developer is troubleshooting cipher issues and sees the output "ECDHE-RSA-AES128-GCM-SHA256." Which portion is the part regarding HMAC?
  • What process describes the creation or removal of virtual machines or instances, beyond just the basic provisioning of resources?
  • In security audits, what does the term “least privilege” refer to?
  • A security administrator has a server environment where most files don't change much, and the administrator wants to implement a solution that monitors for changes. What should the security administrator implement?
  • During an attack on integrated systems, which software solution was targeted?
  • A political organization's website is defaced with messages protesting its policies, and confidential emails are released to the public. Which type of threat actor is most likely responsible for this attack?
  • What system ensures an optimal indoor environment through effective heating, ventilation, and air conditioning?
  • What is the key difference between a NIDS (network intrusion detection system) and a NIPS (network intrusion prevention system)?
  • Which act related to personal financial information includes requirements for Business Continuity and Disaster Recovery (BCDR) capabilities?
  • What does crypto erase involve in terms of data sanitization, making the recovery of data effectively impossible?
  • Which organization provides secure coding standards for programming languages such as C, C++, Android, Java, and Perl?
  • What approach allows for the configurable physical and virtual network appliances via scripting to manage security and traffic flow?
  • Which category of security flaws includes technical failures like outdated software?
  • A developer creates a mock SSH application to capture interactions for analysis. Which strategy is this an example of?
  • In ABAC, which factors are considered when making access decisions?
  • In the context of cybersecurity agreements, what does OLA stand for?
  • What field in a domain certificate allows for the use of a single certificate across multiple domains?
  • If a help desk manager observes a high volume of incoming calls, what is the most likely conclusion?
  • Which security solution uses execution control to determine what additional software or scripts an administrator may install or run on a Linux host?
  • What control should a company implement to allow only preapproved software to run on its endpoints?
  • Which hardware-based solution stores encryption keys, hashed passwords, and identification information, but is not directly used for encrypting data at rest under FIPS 140-2?
  • Which concept describes spreading data across different storage locations or cloud storage providers to ensure data preservation in case of unavailability?
  • What measures should a disaster recovery manager assess to determine residual risk compared to inherent risk?
  • A security professional has some spare time to do research on the corporate network and wants to set up a system configured to carefully monitor and log interactions. Which of the following should the security professional set up?
  • Which standard is primarily used to assess cloud service providers for security practices?
  • Which response header specifically protects against speculative execution attacks, such as Spectre, in addition to mitigating XSS inclusion attacks?
  • What is the primary focus of the Capability Maturity Model Integration (CMMI) for organizations?
  • A security analyst is actively responding to a detected indicator of compromise on a critical system. Which of the following actions should the analyst avoid during this time?
  • Which technology identifies anomalies and threats by scanning multiple intrusion detection sources?
  • Which word describes due care, which is intentionally open-ended and focuses on what is "reasonable and expected" under different circumstances?
  • What does a score of Level 2: Managed indicate about the state of software applications?
  • What security feature ensures a computer is not hijacked by a malicious OS while requiring UEFI?
  • What is the process called when a user gains root access to an Android device?
  • A security team needs to analyze network data while managing storage. What is the best data collection method?
  • Which protocol is widely used for remote access to manage devices and services?
  • What is the common term for the symmetric key algorithm that utilizes a larger key size for enhanced security when compared to its predecessors?
  • Which term describes the unindexed and hidden locations on the Internet often associated with malicious activity and criminal operations?
  • Which label is used for highly sensitive information in military organizations and is in the same category as critical information?
  • How does Public Key Infrastructure (PKI) support non-repudiation of users and devices?
  • What method can be used to verify that new code changes do not adversely affect existing system functionalities?
  • Which environment should mirror the production environment to ensure the highest levels of compatibility for testing purposes?
  • Which regulation enforces rules for organizations collecting data on subjects in the European Union?
  • What set of standards is widely utilized to evaluate methods for protecting technology and financial operations?
  • In which scenario is the "data in use" state most critical to protect?
  • Which term is not an industry standard but is important for establishing the necessary controls to protect data, such as security configurations and access controls?
  • In the context of penetration testing, which aspect falls under pre-engagement?
  • Which of the following refers to a decentralized network where participating nodes self-organize to provide services typically found in client-server networks?
  • A company plans a technology rollout. As a precaution, security engineers prepare mitigation plans in the event of an eavesdropping attack. Which connectivity solution is being rolled out?
  • Which NIST publication should a security architect refer to for the most recent guidance on password compliance?
  • Which type of controller allows for configuration of its programming logic by the end user?
  • What manages the virtual machine environment and facilitates interaction between virtual machines, the computer hardware, and the network?
  • What is a common issue that may occur during a data recovery failover due to syncing issues or corrupt disks at the recovery site?
  • Which regulation should a company researching operations in Europe focus on for data analysis compliance?
  • Which of the following is a benefit of a Content Delivery Network (CDN) that involves adding servers to help process the same workload?
  • A forensics expert is performing file carving during an investigation. Which of the following tools could the forensics expert use?
  • An engineer is searching for something that incorporates both hardware and software capabilities, uses low power while maintaining great performance, and also takes up less space. What is the engineer looking for?
  • A web developer wants a browser tool that is independent of browser restrictions. Which should they avoid using?
  • What deceptive technique involves creating realistic but false data to mislead attackers?
  • Which action replaces the original file with a notice that describes the policy violation and how it can be released?
  • Which organization’s guidance includes secure coding standards specifically for programming practices?
  • Which identity proofing method involves a combination of two factors, such as something a user knows and something a user has, for authentication?
  • Which protocol uses SSL/TLS to secure directory access services?
  • What involves pre-configured lists of certificate authorities typically stored within browsers or operating system configurations?
  • For a cloud service to be recognized under the CSA Security Trust and Assurance Registry, what must it meet?
  • Which preventive measure can protect sensitive data while it is actively processed on a system?
  • Which access control model is characterized by making access decisions based on subject, object, and context-sensitive attributes?
  • A large retail chain falls victim to ransomware, with attackers demanding payment to restore access to encrypted data. Which type of threat actor is most likely responsible for this attack?
  • What is the first step of the data life cycle, involving the creation of files, manual data entry, data interfaces, and more?
  • What does EMM stand for in the context of mobile device management?
  • Which certificate type provides ownership of a particular domain by proving ownership through email authorization or publishing a text record?
  • Which type of analysis involves inspecting a system and software as it operates, with examples including packet capture and traffic analysis?
  • What type of agreement occurs between two entities that need to share data via an interface, focusing on security considerations?
  • Which NIST Special Publication provides a guide to test, training, and exercise programs for IT plans and includes an after-action report template?
  • Which tool automates routine tasks typically performed by security personnel in response to a security incident?
  • Which NIST document is specifically designed to help identify the groups necessary for responding to a security incident?
  • A forensics analyst is attempting to read file metadata during the course of an investigation. Which tool could they use?
  • Which model is characterized by resources being shared among multiple organizations with similar concerns?
  • Which NIST Special Publication outlines the necessary controls for audits of information systems used for certification, focusing on security and privacy controls?
  • What does Elliptic-Curve Diffie-Hellman (ECDH) represent in a cipher suite?
  • Which initiative focuses on collaboration among private sector organizations to create risk management frameworks?
  • What aspect of a business continuity plan involves defining the speed and state of system recovery?
  • A developer creating a web application in Python desires a framework that is designed for quick iterations and code re-use. Which framework would be most suitable?
  • A web developer needs to exchange data using standard HTTP methods. Which should they use for data formats like JSON or XML?
  • Which of the following is a common practice for ensuring data redundancy?
  • What is the technology called that generates computer-generated images and videos of a person that appear real but are actually synthetic?
  • Which protocol is used to facilitate secure authorization and access to resources across sites without requiring users to share their passwords?
  • A security consultant reviewing live virtual machine vulnerabilities should prioritize which of the following aspects?
  • Which mode of encryption generates a keystream using an initialization vector and does not require padding?
  • A Windows client administrator is implementing a solution for data in use. Which of the following represents security protection for data in use?
  • What does Secure Authentication (SA) describe in the context of network security?
  • What tool could a forensics analyst use for conducting memory analysis?
  • Which type of agreement is an internal document that defines the essential operational needs of an organization and meets performance metrics defined in a Service Level Agreement (SLA)?
  • Which technology enables users to run multiple operating systems on a single physical machine?
  • What is the advantage of having subordinate CAs (Certificate Authorities) set up under the root CA (Certificate Authority)?
  • Which key agreement protocol should a developer use for authentication, relying on elliptic curve mathematics?
  • In digital forensics, the examination of tampered data is part of which stage of the process?
  • Which EAP (Extensible Authentication Protocol) type requires only a server-side public key certificate to establish an encrypted tunnel?
  • What is a downside of using a single CA model?
  • Which subset of Enterprise Mobility Management focuses on compliance and security for mobile devices?
  • Which device in IoT systems facilitates networking, often required to enable communications for technologies like Z-Wave or Zigbee?
  • A disaster recovery planner needs to focus prioritization efforts around operational impact. The disaster recovery planner should focus on which system?
  • Which attack allows a malicious script to execute whenever a user views a webpage, due to an injection in the comment section?
  • What allows for the creation of cloud resources within private networks that parallel the functionality of creating resources in a traditional, privately operated data center?
  • Which label is typically applied to highly sensitive information meant for viewing only by approved persons?
  • While patching may help prevent catastrophic events, why is it not considered part of the Business Impact Analysis (BIA)?
  • What process allows users to install untrusted apps from a website using the .apk file format on a mobile device?
  • Which device provides foundational protection for a network by blocking or allowing traffic based on pre-configured rules?
  • Regarding cloud security, what does the acronym CCM stand for?
  • During the smartcard authentication, the Ticket Granting Ticket (TGT) is issued by which entity?
  • What type of attack occurs when a user unknowingly clicks a link that reflects a malicious script back to their browser?
  • What term defines the threshold where recovery efforts may exist, focusing on critical operational systems?
  • During the extended validation process for domain names, which certificate feature is not feasible?
  • What process ensures that all account creation, modification, deletion, and account activity are logged and reviewed, serving as a method to manage personnel risk?
  • Why should cryptographic keys not be stored in public source code repositories?
  • What type of encryption algorithm is RC4?
  • Which technology provides Quality of Service (QoS) features required by modern industrial applications?
  • Which federated identity method, based on SAML, is commonly used by universities and public service organizations?
  • Which of the following is a popular bare metal Type 1 hypervisor that allows multiple operating systems to run simultaneously on a single computer?
  • Which security technology will automatically secure sensitive data as it is stored on a company's devices?
  • A systems administrator is working with a developer to upgrade to the latest version of Java, but first, the sysadmin wants to see whether changes in code have caused previously existing functionality to fail. What is this called?
  • A digital manga artist is meeting with a security professional to control how consumers use digital content after it is published. Which solution should the security professional recommend?
  • What could cause Business Continuity and Disaster Recovery (BCDR) development work to come to a halt, even if plans are in place?
  • A security code reviewer is setting up an environment for an organization that can analyze third-party libraries. Which type of environment should the reviewer set up?
  • Before allocating staff resources to work on Business Continuity and Disaster Recovery (BCDR) planning, what critical element must first be secured?
  • A security engineer is trying to identify appropriate groups to help determine which groups should be part of incident response. Which guide could they use?
  • How is a cloud access security broker (CASB) configured when using a forward proxy?
  • What is the main purpose of the OAuth protocol in security architecture?
  • Which encryption standard has been identified by NIST to be replaced by AES due to security issues?
  • Which of the following is not a possible state of a qubit in a quantum computing system?
  • What type of system is designed to manage process automation at a single industrial site?
  • Which system provides mechanisms for controlling machinery and automating workflows in critical infrastructure?
  • Which type of security measure specifically updates settings based on alerts from security monitoring tools?
  • What has a company established by determining the probability of a threat being realized?
  • Which risk mitigation strategy is demonstrated when vulnerabilities are accepted due to a lack of resources to address them?
  • What metric defines the maximum data loss a company can withstand without irreparable harm?
  • What is the purpose of using the X-Frame-Options header in a web application?
  • What Wi-Fi encryption standard should a retail company use to comply with PCI DSS?
  • Which system enables non-technical users to create, manage, and modify content on a website?
  • Which of the following is NOT typically defended against by ModSecurity as it is a network layer defense?
  • Which of the following is not a standard or regulation but a mechanism to achieve Business Continuity and Disaster Recovery (BCDR) capabilities using public cloud services?
  • A security manager is looking for a solution that contains software to monitor and report the day-to-day operations of an enterprise and the status of various resources and activities. Which of the following should the security manager consider?
  • Which technique will best address the known vulnerability in a web content management system?
  • Which foundational element of blockchain distributes computation across multiple systems so that no individual system can read the other parties' data?
  • Which physical security control should be placed to provide full coverage of an area and prevent attackers from disabling it by gaining access to its back?
  • What data sanitization method involves destroying the decryption key to make data recovery impossible?
  • Which system is intended to supervise large-scale industrial control systems across multiple sites by replacing the control server?
  • Which risk involves an attacker exploiting a weakness in VM migration due to lack of proper protocols?
  • Which cloud solution offers a managed turnkey disaster recovery process for small data centers with few personnel?
  • A developer wants to create a certificate to show the browser plugin is trusted. What could the developer use?
  • A network technician is setting up Extensible Authentication Protocol (EAP) but wants to ensure using the strongest authentication and widely supported type. Which type should the technician choose?
  • Which type of assessment may be a regulatory or contractual requirement and helps identify both obvious and non-obvious issues to enhance internal vulnerability assessments?
  • What mobile device security issue involves allowing unknown sources to install apps from third-party websites?
  • Which method is likely to consume the most storage when analyzing network traffic?
  • What process involves an independent audit to review the information system and associated documentation to ensure necessary controls are implemented, as outlined in NIST SP 800-53?
  • Which protocol is known for providing a more efficient way to check a certificate's status without a complete list?
  • A security team has detected unusual traffic patterns and needs to prevent further suspicious activity from entering the network. Which of the following should they modify to block the suspicious traffic?
  • What does a checklist test require, involving the distribution of the BCDR plan to all the departments, teams, and other participants included in the plan?
  • Which type of threat actor could intentionally delete key files after being given access to sensitive systems?
  • Which part of the cipher "ECDHE-RSA-AES128-GCM-SHA256" represents the HMAC function?
  • Which Type 1 hypervisor is provided by Citrix and requires the hardware to support both the hypervisor and the guest operating systems?
  • A systems administrator wants to enable a setting to make it difficult for buffer overflow attacks to locate the area of memory needed to successfully perform an exploit. What is this called?
  • Which risk mitigation process should a company use to address vulnerabilities identified in a cybersecurity assessment?
  • What best describes a lock-in scenario with a technology vendor?
  • A security architect is designing a strategy to help continue operating in the face of a cyber-attack. Which of the following will help to accomplish this objective?
  • Which approach is used by a development team integrating incremental and waterfall methods?
  • What standard should a security consultant reference for compliance with international IT security standards?
  • What is a significant benefit of using virtualization in IT environments?
  • What intelligence collection method do investigators use to monitor a suspect's social network feeds?
  • Which of the following involves updating signature and behavior rules to block or quarantine suspicious activity?
  • Which method allows for alternative ways of authentication and is based on the principles of federated identity systems?
  • What is a characteristic of a honeypot system?
  • What type of system is an oil engineer likely to use for managing process automation on a single site?
  • Which step of the cyber kill chain involves seeking information about weaknesses with people and technology at the target organization?
  • What benefit of a central log management system helps distinguish between critical events that need immediate action and less severe items?
  • What policy should be implemented to reduce the risk of unauthorized access to sensitive information?
  • What is the name of the configuration that uses two firewalls placed on either side of the demilitarized zone (DMZ), with the edge firewall restricting traffic on the external/public interface?
  • Which disaster recovery test method involves activating a DR site as though it is the primary site, minimizing impact on production systems?
  • Which risk component focuses on the scope and potential implications of an identified risk?
  • In a scenario where a network is designed to prevent unauthorized access, which approach is typically implemented?
  • How can a company prevent the unauthorized distribution of copyrighted videos?
  • What is the first step in the development of a Business Impact Assessment (BIA), similar to critical security controls?
  • Which system is specifically designed for time-sensitive embedded controllers?
  • What type of data is considered the safest when it is encrypted and stored properly?
  • What is the purpose of the 'Review' phase in the Risk Management Lifecycle?
  • Which encryption mode replaced AES CCMP for Wi-Fi encryption and is used in the cipher "ECDHE-RSA-AES128-GCM-SHA256"?
  • Which country, known for its comprehensive legal framework, is more likely to be chosen by a company focused on privacy and anonymity over the United States?
  • How does risk tolerance affect the development of a financial services mobile application?
  • Which department assists in evaluating the effect of risks on intangible assets?
  • What does the likelihood component of risk evaluate?
  • A small business owner is reviewing third-party vendors to manage the server environment. What document should the business owner draft to define data protection and privacy protection requirements?
  • Which Cloud Access Security Broker (CASB) deployment method uses broker connections between the cloud service and cloud consumer, without being inline with the cloud consumer and services?
  • Which blockchain technology assigns a hash value to each block and includes the hash value of the previous block in the next block's calculation, linking them cryptographically?
  • Which strategy will best mitigate risks associated with a new vendor's access to sensitive customer data?
  • What standard focuses on guidelines for protecting personally identifiable information (PII) in cloud environments?
  • Which NIST publication offers guidance on security and privacy controls for compliance audits?
  • Which of the following is NOT a typical function of a hub in an IoT environment?
  • Which of the following tools serves as a data source by providing logs and other information for security data analytics?
  • What type of agreement is best for setting expectations and preventing additional service requests from companies?
  • What is the term for the willingness of an organization to accept certain levels of risk related to its operations?
  • A defense contractor is setting up acceptable programs to run on a new jet. What should they establish?
  • What does a CYOD policy specifically provide to employees?
  • Which encryption mode applies an initialization vector and an incrementing counter value to generate a keystream, making it more efficient than modes that require padding?
  • Which hashing algorithm produces a 128-bit output and is sometimes used to represent passwords, though it is not an authentication code?
  • What method is used to define permissions on a network or file but does not segment like VLANs or physical segmentation?
  • How does data execution protection (DEP) help prevent a buffer overflow?
  • What type of alternate site is simply a facility under the organization's control but lacks pre-established information system capability?
  • Which service model requires the least responsibility from clients, with the provider taking care of most operational aspects?
  • Which major Type 1 hypervisors can a systems administrator evaluate for future migration?
  • Which device is primarily responsible for managing outbound and inbound traffic based on defined rules in a network?
  • What is a key benefit of using a virtual private network (VPN)?
  • What is the primary purpose of a Cloud Access Security Broker?
  • Which benefit of a log management system helps organize log data, making it easier to review and analyze through consistent collection and formatting?
  • A company is handling sensitive customer data and wants to ensure that no unauthorized data transfers occur. They need a solution that automates the discovery and classification of data and enforces rules to prevent data leaks. Which of the following should they implement?
  • What is a primary goal of physical security controls?
  • What is a security measure that can give insights into attacker methods by engaging them into controlled environments?
  • Which protocol is most commonly associated with facilitating communication between different devices in an OT network?
  • Which environment is a mirror of the production environment used to test changes to infrastructure, software, and data?
  • What is the third step of the data life cycle that describes how data supports operational needs and objectives?
  • Which method combines approaches like incremental and waterfall into a hybrid model for software development?
  • Which encryption method is used to protect data at rest on Microsoft Windows computers, typically using AES (Advanced Encryption Standard)?
  • Which industry-standard data masking technique is recommended for credit card processing, where a token represents sensitive data records such as a credit card number?
  • What method is used to protect data in use, such as when it exists in memory, preventing untrusted processes from accessing it?
  • What does the NIST 800-63 standard primarily focus on?
  • Which protocol encrypts packets and provides both data integrity and confidentiality?
  • Which environment would a security code reviewer set up to safely analyze third-party libraries and code without risking the main systems?
  • How long are companies required by regulation to keep HIPAA data?
  • What type of incident is a security engineer responding to if they attempt to hack back after a compromise?
  • Which of the following are examples of block ciphers?
  • What vulnerability is associated with default administrative credentials being misconfigured in software?
  • What is one of the primary goals of vulnerability management in cybersecurity?
  • Which ISO standard is part of the cloud standards focused on cloud privacy?
  • How can 3D printing help prevent intellectual property (IP) theft?
  • Which cryptographic protocol is best for securing data transmission in a new software application processing sensitive information?
  • A mobile device manager neglected to disable a selection of different stores. What process is associated with downloading a file with an apk extension onto the corporate phone?
  • Which of the following is a hardened and closely monitored system used for performing administrative tasks or accessing servers in a protected environment?
  • For setting up communication between web services using XML over HTTP, which protocol is appropriate?
  • Which step in the SDLC incorporates secure coding patterns and best practices, such as those from the Open Web Application Security Project (OWASP)?
  • What public-key cryptosystem is described by the equation y^2 = x^3 + ax + b?
  • How does a Cloud Access Security Broker (CASB) mitigate the risk of data exfiltration?
  • Which public-key cryptosystem uses prime factorization as the basis for its security?
  • In a cyber context, which type of actor often aims to raise awareness of political issues through their actions?
  • Which NIST publication is the standard for Zero Trust Architecture, focusing on security based on resources such as users, services, and workflows instead of network boundaries?
  • Which of the following tools analyzes network activity to detect suspicious traffic, unauthorized account use, and support threat hunting, but is not a data source?
  • Which suite of policies and tools is specifically designed for centralized management of mobile devices?
  • Which type of threat actor might attempt to obtain and release confidential information or deface websites?
  • What is the focus of NIST 800-53?
  • Which network architecture places two firewalls on either side of a demilitarized zone (DMZ) to control traffic between public networks and protected internal networks?
  • A solutions architect plans to implement a Cloud Access Security Broker (CASB) positioned at the edge of the client's network. What is this method of deploying a CASB known as?
  • Which certificate type requires more rigorous checks on the subject's legal identity and control over the domain or software the certificate authority (CA) signs?
  • Financial fraud is most likely to be attempted by which type of threat actor?
  • Which step in the data life cycle involves defining the locations used to house data, such as databases and file systems, and implementing mechanisms for data protection?
  • Which standard should a coffee company comply with for processing credit card transactions securely?
  • A developer is troubleshooting a situation where several processes are trying to access the same resource simultaneously, causing unpredictable system behavior. What is this type of issue called?
  • In risk analysis, what is an example of a primary factor in assessing risk severity?
  • Which method involves all groups included in the BCDR plan identifying a representative to participate in a meeting to review the plans?
  • Which encryption standard is the current U.S. federal government standard for symmetric encryption?
  • What solution provides visibility into compromises but does not stop initial execution?
  • What is the primary function of a registration authority (RA) in the certificate process?
  • What is the primary focus of continuous monitoring in application development?
  • Which step in the cyber kill chain refers to the methods used to communicate with an exploited system to further the attack?
  • Which of the following consists of files containing attractive data, such as user credentials and account numbers, that can lure adversaries?
  • Which response header changes the way documents load to prevent cross-origin attacks but would not be effective against XSS Inclusion attacks?
  • Which term is more closely related to due care, serving as the basis for due diligence and emphasizing careful actions that are expected in various circumstances?
  • What type of simulation should a security analyst perform to determine if all parties know how to respond effectively?
  • What is a key advantage of EAP-TLS (Extensible Authentication Protocol-Transport Layer Security) over other EAP types?
  • What term describes attractive data used to mislead and trap adversaries in cybersecurity?
  • Which of the following is an example of an availability function rather than a PKI-supported feature?
  • Which security solution is capable of detecting previously identified malware and can be fine-tuned to identify malicious activity?
  • Which of the following is required to comply with privacy laws but is not the type of entity that privacy data directly refers to?
  • In the hierarchical model, what is the same as an intermediate CA and can be set up with different certificate policies?
  • What benefit does cross-certification provide in a private network?
  • An enterprise administrator is reviewing the process for how smartcard authentication works. Which of the following is NOT one of the steps?
  • Which process is basic and involves setting up a new file system on a storage device?
  • What type of cybersecurity best practice does OWASP focus on?
  • Which security testing method is typically used in addition to other methods and is associated with continuous development and CI/CD environments?
  • What type of scaling is achieved by adding more memory and processor cores to a virtual server?
  • What is the best solution to prevent medical researchers from sharing protected health information (PHI) data?
  • Which Risk Management Lifecycle phase focuses on the application and management of security measures?
  • What term describes the capability for a task to run with exclusive access to resources, preventing multiple tasks from accessing or modifying critical resources at the same time?
  • Which tool provides visibility into cloud applications and enforces data security policies?
  • In which type of networking application are policy decisions made at the control plane level?
  • What are some common issues a consultant might expect to encounter during a data recovery failover scenario?
  • Which hardware-based solution is specifically used for storing encryption keys and hashed passwords?
  • Which plan focuses on addressing the tasks required to bring critical systems back online during the most frantic and pressing events?
  • Which service provides a list of configuration and access levels available to a cloud instance, allowing for potential vulnerabilities if not secured?
  • For which purpose is NGFW primarily used?
  • Which type of attack poses a severe risk to the entire virtualized environment?
  • Which NIST standard provides guidance for developing test, training, and exercise programs for IT capabilities?
  • A vulnerability management lead recommends purchasing an insurance policy for legacy systems. What type of risk strategy is this?
  • Which regulation enforces rules for organizations that offer services to entities in the European Union (EU) or that collect and analyze data on subjects located there?
  • What is a key risk if an attacker gains elevated privileges in a virtualized environment?
  • What does the label 'Top Secret' indicate in terms of data sensitivity?
  • Which document is often considered the most recognized output of a risk management program, containing metadata such as threat, impact, likelihood, plan, and risk level?
  • What factor in a software supply chain can greatly impact the selection of frameworks used in development?
  • A systems designer needs to set up a protocol to facilitate secure authorization and access to resources within a user profile between sites without sharing passwords. Which protocol should the systems designer use?
  • What may cause a hash mismatch and mark a downloaded file as untrusted?
  • What function transforms an input into a fixed-length hexadecimal output, also known as a digest?
  • What solution does IT configure to provide a warning system against unauthorized file copying?
  • What should a web application developer implement to limit failed login attempts and mitigate brute force attacks?
  • Which hashing algorithm was selected by NIST in 2012 as the successor to previous standards?
  • Which of the following is an example of a source that can feed into data analytics tools by providing information for collection and analysis?
  • Which protocol was superseded by GCMP for authentication in WPA3?
  • Which country is considered the gold standard for privacy and anonymity due to its uniquely protective privacy laws?
  • Which of the following allows for the creation of policies to evaluate connected devices and determine access to a network?
  • What is the role of the TGT in the smartcard authentication process?
  • A large corporation has just completed an audit by a Certifying Authority who determined that they are compliant. What will the Certifying Authority award the corporation?
  • Which framework should a developer working in Java consider to manage web application development?
  • Which of the following mimics a genuine system and is configured to carefully monitor and log interactions, warranting closer inspection since it does not serve regular staff?
  • Which type of alternate site includes a scaled-down data center that can run critical systems and software but is not as immediately operational as a hot site?
  • Which type of certificate requires more rigorous checks on the subject's legal identity and control over the domain?
  • Which type of cloud storage is ideal for storing large amounts of unstructured data, like archives and backups?
  • When planning a penetration test, what aspect should be a priority to ensure the safety of systems being tested?
  • A system administrator wants to prevent unauthorized users from accessing sensitive company files. Which of the following should be modified to achieve this?
  • Which method focuses on testing all the infrastructure that supports the application, including networking, database functionality, and security?
  • What term describes adding more servers to a cluster to improve application performance?
  • Which of the following best describes the focus of a security team's risk management activities?
  • What term would a security architect use to describe all of the suppliers, vendors, and partners needed to deliver a final product?
  • At which stage of business continuity planning should a security engineer identify preventative measures, ensuring that these measures are applied to known systems?
  • What should be the top priority in disaster recovery planning over systems with critical vulnerabilities?
  • In the hierarchical model, what is the role of the root Certificate Authority (CA)?
  • Which type of firewall can identify and filter out malicious traffic using sophisticated rules, specifically for web-based attacks?
  • What term identifies the laws governing the country where the company stores data and controls over its collection and use in a global economy?
  • Which standard defines security controls and provides guidelines for organizational security standards?
  • What must be understood in order to effectively assess and protect infrastructure components during a penetration test?
  • A cloud engineer is setting up controls between VPCs. Which of the following should the engineer use?
  • What is the primary focus of NIST Special Publication 800-207?
  • What does a CASB primarily help organizations manage in relation to cloud applications?
  • Which of the following steps directly supports operational needs by utilizing data?
  • What document is necessary to outline corrective actions and ongoing monitoring of an information system?
  • Which security measure can be implemented to specifically limit access based on geographical locations?
  • What action does a server engineer take to document certificates during the certification life cycle?
  • What action should a developer implement to strengthen authentication security against broken authentication?
  • What is a Domain Validation (DV) certificate, and how does it compare to a general purpose certificate?
  • Which protocol improves upon RADIUS (Remote Authentication Dial-in User Service), strengthening some of its weaknesses, but is less widespread due to fewer products using it?
  • Which technology helps mitigate DNS spoofing and poisoning attacks?
  • A forensics investigator is experiencing a problem where the state of the item checked changes after the initial check. What is it called after it changes?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy