Log in
Sign up for FREE
arrow_back
Library

SY0-701 Practice B

star
star
star
star
star
Last updated about 2 years ago
114 questions
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
Question 1
1.

Question 2
2.

Question 3
3.

Question 4
4.

Question 5
5.

Question 6
6.

Question 7
7.

Question 8
8.

Question 9
9.

Question 10
10.

Question 11
11.

Question 12
12.

Question 13
13.

Question 14
14.

Question 15
15.

Question 16
16.

Question 17
17.

Question 18
18.

Question 19
19.

Question 20
20.

Question 21
21.

Question 22
22.

Question 23
23.

Question 24
24.

Question 25
25.

Question 26
26.

Question 27
27.

Question 28
28.

Question 29
29.

Question 30
30.

Question 31
31.

Question 32
32.

Question 33
33.

Question 34
34.

Question 35
35.

Question 36
36.

Question 37
37.

Question 38
38.

Question 39
39.

Question 40
40.

Question 41
41.

Question 42
42.

Question 43
43.

Question 44
44.

Question 45
45.

Question 46
46.

Question 47
47.

Question 48
48.

Question 49
49.

Question 50
50.

Question 51
51.

Question 52
52.

Question 53
53.

Question 54
54.

Question 55
55.

Question 56
56.

Question 57
57.

Question 58
58.

Question 59
59.

Question 60
60.

Question 61
61.

Question 62
62.

Question 63
63.

Question 64
64.

Question 65
65.

Question 66
66.

Question 67
67.

Question 68
68.

Question 69
69.

Question 70
70.

Question 71
71.

Question 72
72.

Question 73
73.

Question 74
74.

Question 75
75.

Question 76
76.

Question 77
77.

Question 78
78.

Question 79
79.

Question 80
80.

Question 81
81.

Question 82
82.

Question 83
83.

Question 84
84.

Question 85
85.

Question 86
86.

Question 87
87.

Question 88
88.

Question 89
89.

Question 90
90.

Question 91
91.

Question 92
92.

Question 93
93.

Question 94
94.

Question 95
95.

Question 96
96.

Question 97
97.

Question 98
98.

Question 99
99.

Question 100
100.

Question 101
101.

Question 102
102.

Question 103
103.

Question 104
104.

Question 105
105.

Question 106
106.

Question 107
107.

Question 108
108.

Question 109
109.

Question 110
110.

Question 111
111.

Question 112
112.

Question 113
113.

Question 114
114.

Match the certificate characteristic to the description: This is a file containing a list of the revoked certificates. Maintained by the associated certificate authority.
CRL (Certificate Revocation List)
OCSP (Online Certificate Status Protocol)
CA (Certificate Authority)
CSR (Certificate Signing Request)
Match the certificate characteristic to the description: This is sent with the public key to the certificate authority. Once verified, the CA will digitally sign the public key certificate.
CRL (Certificate Revocation List)
OCSP (Online Certificate Status Protocol)
CA (Certificate Authority)
CSR (Certificate Signing Request)
Match the certificate characteristic to the description: This is the administrative control for any public key infrastructure deployment.
CRL (Certificate Revocation List)
OCSP (Online Certificate Status Protocol)
CA (Certificate Authority)
CSR (Certificate Signing Request)
Match the certificate characteristic to the description: This is a protocol used by the browser to check the revocation status of a certificate.
CRL (Certificate Revocation List)
OCSP (Online Certificate Status Protocol)
CA (Certificate Authority)
CSR (Certificate Signing Request)
An organization is deploying a mobile app to its sales team in the field. The application will be accessed from tablets for remote team members and a browser-based front-end on desktops for corporate office users. The application contains sensitive customer information, and two forms of authentication are required to launch the application. Select the best security features for the following platform: Tablet for Field Sales
MDM integration
Host-based Firewall
Full Device Encryption
Infrared Sensors
Anti-Malware
OSINT
Biometric authentication
An organization is deploying a mobile app to its sales team in the field. The application will be accessed from tablets for remote team members and a browser-based front-end on desktops for corporate office users. The application contains sensitive customer information, and two forms of authentication are required to launch the application. Select the best security features for the following platform: Desktop with Browser-based Front-end
MDM integration
Host-based Firewall
Full Device Encryption
Infrared Sensors
Anti-Malware
OSINT
Biometric authentication
What is the first phase in incident response?
Eradication
Recovery
Analysis
Preparation
Containment
Lessons Learned
Detection
What is the second phase in incident response?
Eradication
Recovery
Analysis
Preparation
Containment
Lessons Learned
Detection
What is the third phase in incident response?
Eradication
Recovery
Analysis
Preparation
Containment
Lessons Learned
Detection
What is the fourth phase in incident response?
Eradication
Recovery
Analysis
Preparation
Containment
Lessons Learned
Detection
What is the fifth phase in incident response?
Eradication
Recovery
Analysis
Preparation
Containment
Lessons Learned
Detection
What is the sixth phase in incident response?
Eradication
Recovery
Analysis
Preparation
Containment
Lessons Learned
Detection
What is the final phase in incident response?
Eradication
Recovery
Analysis
Preparation
Containment
Lessons Learned
Detection
Match the security technology to the implementation: Store a password on an authentication server.
Key escrow
Journaling
Hashing
SPF (Sender Policy Framework)
Obfuscation
Digital signature
Match the security technology to the implementation: Verify a sender's identity.
Key escrow
Journaling
Hashing
SPF (Sender Policy Framework)
Obfuscation
Digital signature
Match the security technology to the implementation: Authenticate the server sending an email.
Key escrow
Journaling
Hashing
SPF (Sender Policy Framework)
Obfuscation
Digital signature
Match the security technology to the implementation: Prevent data corruption when a system fails.
Key escrow
Journaling
Hashing
SPF (Sender Policy Framework)
Obfuscation
Digital signature
Match the security technology to the implementation: Modify a script to make it difficult to understand.
Key escrow
Journaling
Hashing
SPF (Sender Policy Framework)
Obfuscation
Digital signature
Match the security technology to the implementation: Store keys with a third-party.
Key escrow
Journaling
Hashing
SPF (Sender Policy Framework)
Obfuscation
Digital signature
Select the data state that best fits the description: All switches in a data center are connected with an 802.1Q trunk.
Data in-transit
Data at-rest
Data in-use
Select the data state that best fits the description: Sales information is uploaded daily from a remote site using a satellite network.
Data in-transit
Data at-rest
Data in-use
Select the data state that best fits the description: A company stores customer purchase information in a MySQL database.
Data in-transit
Data at-rest
Data in-use
Select the data state that best fits the description: An application decrypts credit card numbers and expiration dates to validate for approval.
Data in-transit
Data at-rest
Data in-use
Select the data state that best fits the description: An authentication program performs a hash of all passwords.
Data in-transit
Data at-rest
Data in-use
Select the data state that best fits the description: An IPS identifies a SQL injection attack and removes the attack frames from the network.
Data in-transit
Data at-rest
Data in-use
Select the data state that best fits the description: An automatic teller machine validates a user's PIN before allowing a deposit.
Data in-transit
Data at-rest
Data in-use
Select the data state that best fits the description: Each time a spreadsheet is updated, all of the cells containing formulas are automatically updated.
Data in-transit
Data at-rest
Data in-use
Select the data state that best fits the description: All weekly backup tapes are transported to an offsite storage facility.
Data in-transit
Data at-rest
Data in-use
Select the data state that best fits the description: All user spreadsheets are stored on a cloud-based file sharing service.
Data in-transit
Data at-rest
Data in-use
A security administrator has performed an audit of the organization’s production web servers, and the results have identified default configurations, web services running from a privileged account, and inconsistencies with SSL certificates. Which of the following would be the BEST way to resolve these issues?
Server hardening
Multi-factor authentication
Enable HTTPS
Run operating system updates
A shipping company stores information in small regional warehouses around the country. The company maintains an IPS at each warehouse to watch for suspicious traffic patterns. Which of the following would BEST describe the security control used at the warehouse?
Deterrent
Compensating
Directive
Detective
The Vice President of Sales has asked the IT team to create daily backups of the sales data. The Vice President is an example of a:
Data owner
Data controller
Data steward
Data processor
A security engineer is preparing to conduct a penetration test of a third-party website. Part of the preparation involves reading through social media posts for information about this site. Which of the following describes this practice?
Partially known environment
OSINT
Exfiltration
Active reconnaissance
A company would like to orchestrate the response when a virus is detected on company devices. Which of the following would be the BEST way to implement this function?
Active reconnaissance
Log aggregation
Vulnerability scan
Escalation scripting
A user in the accounting department has received a text message from the CEO. The message requests payment by cryptocurrency for a recently purchased tablet. Which of the following would BEST describe this attack?
Brand impersonation
Watering hole attack
Smishing
Typosquatting
A company has been informed of a hypervisor vulnerability that could allow users on one virtual machine to access resources on another virtual machine. Which of the following would BEST describe this vulnerability?
Containerization
Jailbreaking
SDN (Software-Defined Networking)
Escape
While working from home, users are attending a project meeting over a web conference. When typing in the meeting link, the browser is unexpectedly directed to a different website than the web conference. Users in the office do not have any issues accessing the conference site. Which of the following would be the MOST likely reason for this issue?
Buffer overflow
Wireless disassociation
Amplified DDoS
DNS poisoning
A company is launching a new internal application that will not start until a username and password is entered and a smart card is plugged into the computer. Which of the following BEST describes this process?
Federation
Accounting
Authentication
Authorization
An online retailer is planning a penetration test as part of their PCI DSS validation. A third-party organization will be performing the test, and the online retailer has provided the Internet-facing IP addresses for their public web servers. No other details were provided. What penetration testing methodology is the online retailer using?
Known environment
Passive reconnaissance
Partially known environment
Benchmarks
A manufacturing company produces radar used by commercial and military organizations. A recently proposed policy change would allow the use of mobile devices inside the facility. Which of the following would be the MOST significant threat vector issue associated with this change in policy?
Unauthorized software on rooted devices
Remote access clients on the mobile devices
Out of date mobile operating systems
Loss of intellectual property
Which of the following would be the BEST way for an organization to verify the digital signature provided by an external email server?
Perform a vulnerability scan
View the server's device certificate
Authenticate to a RADIUS server
Check the DKIM record
A company is using older operating systems for their web servers and are concerned of their stability during periods of high use. Which of the following should the company use to maximize the uptime and availability of this service?
Cold site
UPS (Uninterruptible Power Supply)
Redundant routers
Load balancer
A user in the accounting department would like to email a spreadsheet with sensitive information to a list of third-party vendors. Which of the following would be the BEST way to protect the data in this email?
Full disk encryption
Key exchange algorithm
Salted hash
Asymmetric encryption
A system administrator would like to segment the network to give the marketing, accounting, and manufacturing departments their own private network. The network communication between departments would be restricted for additional security. Which of the following should be configured on this network?
VPN (Virtual Private Network)
RBAC (Role-Based Access Control)
VLAN (Virtual Local Area Network)
SDN (Software Defined Networking)
A technician at an MSP has been asked to manage devices on third-party private network. The technician needs command line access to internal routers, switches, and firewalls. Which of the following would provide the necessary access?
HSM (Hardware Security Module)
Jump server
NAC (Network Access Control)
Air Gap
A transportation company is installing new wireless access points in their corporate office. The manufacturer estimates the access points will operate an average of 100,000 hours before a hardware-related outage. Which of the following describes this estimate?
MTTR (Mean Time to Repair)
RPO (Recovery Point Objectives)
RTO (Recovery Time Objectives)
MTBF (Mean Time Between Failures)
A security administrator is creating a policy to prevent the disclosure of credit card numbers in a customer support application. Users of the application would only be able to view the last four digits of a credit card number. Which of the following would provide this functionality?
Hashing
Tokenization
Masking
Salting
A user is authenticating through the use of a PIN and a fingerprint. Which of the following would describe these authentication factors?
Something you know, something you are
Something you are, somewhere you are
Something you have, something you know
Somewhere you are, something you are
A security administrator is configuring the authentication process used by technicians when logging into wireless access points and switches. Instead of using local accounts, the administrator would like to pass all login requests to a centralized database. Which of the following would be the BEST way to implement this requirement?
COPE (Corporate-owned, personally enabled)
AAA (Authentication, Authorization, and Accounting)
IPsec
SIEM (Security Information and Event Management)
A recent audit has determined that many IT department accounts have been granted Administrator access. The audit recommends replacing these permissions with limited access rights. Which of the following would describe this policy?
Password vaulting
Offboarding
Least privilege
Discretionary access control
A recent security audit has discovered usernames and passwords which can be easily viewed in a packet capture. Which of the following did the audit identify?
Weak encryption
Improper patch management
Insecure protocols
Open ports
Before deploying a new application, a company is performing an internal audit to ensure all of their servers are configured with the appropriate security features. Which of the following would BEST describe this process?
Due care
Active reconnaissance
Data retention
Statement of work
An organization has previously purchased insurance to cover a ransomware attack, but the costs of maintaining the policy have increased above the acceptable budget. The company has now decided to cancel the insurance policies and address potential ransomware issues internally. Which of the following would best describe this action?
Mitigation
Acceptance
Transference
Risk-avoidance
Which of these threat actors would be MOST likely to install a company's internal application on a public cloud provider?
Organized crime
Nation state
Shadow IT
Hacktivist
An IPS report shows a series of exploit attempts were made against externally facing web servers. The system administrator of the web servers has identified a number of unusual log entries on each system. Which of the following would be the NEXT step in the incident response process?
Check the IPS logs for any other potential attacks
Create a plan for removing malware from the web servers
Disable any breached user accounts
Disconnect the web servers from the network
A security administrator is viewing the logs on a laptop in the shipping and receiving department and identifies these events: 8:55:30 AM | D:\Downloads\ChangeLog-5.0.4.scr | Quarantine Success 9:22:54 AM | C:\Program Files\Photo Viewer\ViewerBase.dll | Quarantine Failure 9:44:05 AM | C:\Sales\Sample32.dat | Quarantine Success Which of the following would BEST describe the circumstances surrounding these events?
The antivirus application identified three viruses and quarantined two viruses
The host-based firewall blocked two traffic flows
A host-based allow list has blocked two applications from executing
A network-based IPS has identified two known vulnerabilities
In the past, an organization has relied on the curated Apple App Store to avoid issues associated with malware and insecure applications. However, the IT department has discovered an iPhone in the shipping department with applications not available on the Apple App Store. How did the shipping department user install these apps on their mobile device?
Side loading
Malicious update
VM escape
Cross-site scripting
A company has noticed an increase in support calls from attackers. These attackers are using social engineering to gain unauthorized access to customer data. Which of the following would be the BEST way to prevent these attacks?
User training
Next-generation firewall
Internal audit
Penetration testing
As part of an internal audit, each department of a company has been asked to compile a list of all devices, operating systems, and applications in use. Which of the following would BEST describe this audit?
Attestation
Self-assessment
Regulatory compliance
Vendor monitoring
A company is concerned about security issues at their remote sites. Which of the following would provide the IT team with more information of potential shortcomings?
Gap analysis
Policy administrator
Change management
Dependency list
An attacker has identified a number of devices on a corporate network with the username of “admin” and the password of “admin.” Which of the following describes this situation?
Open service ports
Default credentials
Unsupported systems
Phishing
A security administrator attends an annual industry convention with other security professionals from around the world. Which of the following attacks would be MOST likely in this situation?
Smishing
Supply chain
SQL injection
Watering hole
A transportation company headquarters is located in an area with frequent power surges and outages. The security administrator is concerned about the potential for downtime and hardware failures. Which of the following would provide the most protection against these issues? Select TWO.
UPS (Uninterruptable Power Supply)
Parallel processing
Snapshots
Multi-cloud system
Load balancing
Generator
An organization has developed an in-house mobile device app for order processing. The developers would like the app to identify revoked server certificates without sending any traffic over the corporate Internet connection. Which of the following must be configured to allow this functionality?
CSR (Certificate Signing Request) generation
OCSP (Online Certificate Status Protocol) stapling
Key escrow
Wildcard
A security administrator has been asked to build a network link to secure all communication between two remote locations. Which of the following would be the best choice for this task?
SCAP (Security Content Automation Protocol)
Screened subnet
IPsec
Network access control
A Linux administrator has received a ticket complaining of response issues with a database server. After connecting to the server, the administrator views this information: Filesystem Size Used Avail Use% Mounted on /dev/xvda1 158G 158G 0 100% / Which of the following would BEST describe this information?
Buffer overflow
Resource consumption
SQL injection
Race condition
Which of the following can be used for credit card transactions from a mobile device without sending the actual credit card number across the network?
Tokenization
Hashing
Steganography
Masking
A security administrator receives a report each week showing a Linux vulnerability associated with a Windows server. Which of the following would prevent this information from appearing in the report?
Alert tuning
Application benchmarking
SIEM (Security Information and Event Manager) aggregation
Data archiving
Which of the following would a company use to calculate the loss of a business activity if a vulnerability is exploited?
Risk tolerance
Vulnerability classification
Environmental variables
Exposure factor
An administrator is designing a network to be compliant with a security standard for storing credit card numbers. Which of the following would be the BEST choice to provide this compliance?
Implement RAID (Redundant Array of Independent Disks) for all storage systems
Connect a UPS (Uninterruptible Power Supply) to all servers
DNS should be available on redundant servers
Perform regular audits and vulnerability scans
A company is accepting proposals for an upcoming project, and one of the responses is from a business owned by a board member. Which of the following would describe this situation?
Due diligence
Vendor monitoring
Conflict of interest
Right-to-audit
A company has rolled out a new application that requires the use of a hardware-based token generator. Which of the following would be the BEST description of this access feature?
Something you know
Somewhere you are
Something you are
Something you have
A company has signed an SLA with an Internet service provider. Which of the following would BEST describe the requirements of this SLA?
The customer will connect to remote sites over an IPsec tunnel
The service provider will provide 99.99% uptime
The customer applications use HTTPS over TCP/443
Customer application use will be busiest on the 15th of each month
An attacker has created multiple social media accounts and is posting information in an attempt to get the attention of the media. Which of the following would BEST describe this attack?
On-path
Watering hole
Misinformation campaign
Phishing
Which of the following would be the BEST way to protect credit card account information when performing real-time purchase authorizations?
Masking
DLP (Data Loss Prevention)
Tokenization
NGFW (Next-Generation Firewall)
A company must comply with legal requirements for storing customer data in the same country as the customer's mailing address. Which of the following would describe this requirement?
Geographic dispersion
Least privilege
Data sovereignty
Exfiltration
A company is installing access points in all of their remote sites. Which of the following would provide confidentiality for all wireless data?
802.1X
WPA3
RADIUS (Remote Authentication Dial-In User Service)
MDM (Mobile Device Manager)
A security administrator has found a keylogger installed in an update of the company's accounting software. Which of the following would prevent the transmission of the collected logs?
Prevent the installation of all software
Block all unknown outbound network traffic at the Internet firewall
Install host-based anti-virus software
Scan all incoming email attachments at the email gateway
A user in the marketing department is unable to connect to the wireless network. After authenticating with a username and password, the user receives this message: -- -- -- The connection attempt could not be completed. The Credentials provided by the server could not be validated. Radius Server: radius.example.com Root CA: Example.com Internal CA Root Certificate -- -- -- The access point is configured with WPA3 encryption and 802.1X authentication. Which of the following is the MOST likely reason for this login issue?
The user's computer is in the incorrect VLAN
The RADIUS (Remote Authentication Dial-In User Service) server is not responding
The user's computer does not support WPA3 encryption
The user is in a location with an insufficient wireless signal
The client computer does not have the proper certificate installed
A security administrator has created a new policy prohibiting the use of MD5 hashes due to collision problems. Which of the following describes the reason for this new policy?
Two different messages have different hashes
The original message can be derived from the hash
Two identical messages have the same hash
Two different messages share the same hash
A security administrator has been tasked with hardening all internal web servers to control access from certain IP address ranges and ensure all transferred data remains confidential. Which of the following should the administrator include in his project plan? (Select TWO)
Change the administrator password
Use HTTPS for all server communication
Uninstall all unused software
Enable a host-based firewall
Install the latest operating system update
A security administrator has identified the installation of ransomware on a database server and has quarantined the system. Which of the following should be followed to ensure that the integrity of the evidence is maintained?
E-discovery
Non-repudiation
Chain of custody
Legal hold
Which of the following would be the BEST option for application testing in an environment completely separated from the production network?
Virtualization
VLANs
Cloud computing
Air gap
A security engineer is planning the installation of a new IPS. The network must remain operational if the IPS is turned off or disabled. Which of the following would describe this configuration?
Containerization
Load balancing
Fail open
Tunneling
Which of the following describes the process of hiding data from others by embedding the data inside of a different media type?
Hashing
Obfuscation
Encryption
Masking
Which of the following vulnerabilities would be the MOST significant security concern when protecting against a hacktivist?
Data center access with only one authentication factor
Spoofing of internal IP addresses when accessing an intranet server
Employee VPN access uses a weak encryption cipher
Lack of patch updates on an Internet-facing database server
A company is installing a security appliance to protect the organization's web-based applications from attacks such as SQL injections and unexpected input. Which of the following would BEST describe this appliance?
WAF (Web Application Firewall)
VPN concentrator
UTM (Unified Threat Management)
SASE (Secure Access Service Edge)
Which of the following would be the BEST way to determine if files have been modified after the forensics data acquisition process has occurred?
Use a tamper seal on all storage devices
Create a hash of the data
Image each storage device for future comparison
Take screenshots of file directories
A system administrator is implementing a password policy that would require letters, numbers, and special characters to be included in every password. Which of the following controls MUST be in place to enforce this password policy?
Length
Expiration
Reuse
Complexity
Which of the following would a company follow to deploy a weekly operating system patch?
Tabletop exercise
Penetration testing
Change management
Internal audit
Which of the following would be the MOST likely result of plaintext application communication?
Buffer overflow
Replay attack
Resource consumption
Directory traversal
A system administrator believes that certain configuration files on a Linux server have been modified from their original state. The administrator has reverted the configurations to their original state, but he would like to be notified if they are changed again. Which of the following would be the BEST way to provide this functionality?
HIPS (Host-based Intrusion Prevention System)
File integrity monitoring
Application allow list
WAF (Web Application Firewall)
A security administrator is updating the network infrastructure to support 802.1X. Which of the following would be the BEST choice for this configuration?
LDAP (Lightweight Directory Access Protocol)
SIEM (Security Information and Event Management)
SNMP (Simple Network Management Protocol) traps
SPF (Sender Policy Framework)
A company owns a time clock appliance, but the time clock doesn’t provide any access to the operating system and it doesn't provide a method to upgrade the firmware. Which of the following describes this appliance?
End-of-life
ICS (Industrial Control Systems)
SDN (Software Defined Network)
Embedded system
A company has deployed laptops to all employees, and each laptop is enumerated during each login. Which of the following is supported with this configuration?
If the laptop hardware is modified, the security team is alerted
Any malware identified on the system is automatically deleted
Users are required to use at least two factors of authentication
The laptop is added to a private VLAN after the login process
A security manager believes that an employee is using their laptop to circumvent the corporate Internet security controls through the use of a cellular hotspot. Which of the following could be used to validate this belief? (Select TWO)
HIPS (Host-based Intrusion Prevention System)
UTM (Unified Threat Management) logs
Web application firewall events
Host-based firewall logs
Next-generation firewall logs
An application developer is creating a mobile device app that will require a true random number generator real-time memory encryption. Which of the following technologies would be the BEST choice for this app?
HSM (Hardware Security Module)
Secure enclave
NGFW (Next Generation Firewall)
Self-signed certificates
Which of the following would be a common result of a successful vulnerability scan?
Usernames and password hashes from a server
A list of missing software patches
A copy of image files from a private file share
The BIOS configuration of a server
When connected to the wireless network, users at a remote site receive an IP address which is not part of the corporate address scheme. Communication over this network is also slower than the wireless connections elsewhere in the building. Which of the following would be the MOST likely reason for these issues?
Rogue access point
Domain hijack
DDoS
Encryption is enabled
A company has identified a compromised server, and the security team would like to know if an attacker has used this device to move between systems. Which of the following would be the BEST way to provide this information?
DNS server logs
Penetration test
NetFlow logs
Email metadata
A system administrator has protected a set of system backups with an encryption key. The system administrator used the same key when restoring files from this backup. Which of the following would BEST describe this encryption type?
Asymmetric
Key escrow
Symmetric
Out-of-band key exchange
A new malware variant takes advantage of a vulnerability in a popular email client. Once installed, the malware forwards all email attachments with credit card information to an external email address. Which of the following would limit the scope of this attack?
Enable MFA (Multi-Factor Authentication) on the email client
Scan outgoing traffic with DLP (Data Loss Prevention)
Require users to enable the VPN when using email
Update the list of malicious URLs in the firewall
An organization has identified a security breach and has removed the affected servers from the network. Which of the following is the NEXT step in the incident response process?
Eradication
Preparation
Recovery
Detection
Containment
A security administrator has been tasked with storing and protecting customer payment and shipping information for a three-year period. Which of the following would describe the source of this data?
Controller
Owner
Data subject
Processor
Which of the following would be the main reasons why a system administrator would use a TPM when configuring full disk encryption? (Select TWO)
Allows the encryption of multiple volumes
Uses burned-in cryptographic keys
Stores certificates in a hardware security module
Maintains a copy of the CRL (Certificate Revocation List)
Includes built-in protections against against brute-force attacks
A security administrator is using an access control where each file or folder is assigned a security clearance level, such as “confidential” or “secret.” The security administrator then assigns a maximum security level to each user. What type of access control is used in this network?
Mandatory
Rule-based
Discretionary
Role-based
A security administrator is reviewing a report showing a number of devices on internal networks are connecting with servers in the data center network. Which of the following security systems should be added to prevent internal systems from accessing data center devices?
VPN
IPS (Intrusion Prevention System)
SIEM (Security Information and Event Management)
ACL (Access Control List)
A financial services company is headquartered in an area with a high occurrence of tropical storms and hurricanes. Which of the following would be MOST important when restoring services disabled by a storm?
Disaster recovery plan
Stakeholder management
Change management
Retention policies
A user in the mail room has reported an overall slowdown of his shipping management software. An anti-virus scan did not identify any issues, but a more thorough malware scan identified a kernel driver which is not part of the original operating system installation. Which of the following malware was installed on this system?
Rootkit
Logic bomb
Bloatware
Ransomware
Keylogger
A virus scanner has identified a macro virus in a word processing file attached to an email. Which of the following information could be obtained from the metadata of this file?
IPS signature name and number
Operating system version
Date and time when the file was created
Alert disposition
When a person enters a data center facility, they must check-in before they are allowed to move further into the building. People who are leaving must be formally checked-out before they are able to exit the building. Which of the following would BEST facilitate this process?
Access control vestibule
Air gap
Pressure sensors
Bollards
A security administrator has discovered an employee exfiltrating confidential company information by embedding data within image files and emailing the images to a third-party. Which of the following would best describe this activity?
Digital signatures
Steganography
Salting
Data masking
A third-party has been contracted to perform a penetration test on a company's public web servers. The testing company has been provided with the external IP addresses of the servers. Which of the following would describe this scenario?
Defensive
Active reconnaissance
Partially known environment
Regulatory
Which of the following would be the best way to describe the estimated number of laptops that might be stolen in a fiscal year?
ALE (Annual Loss Expectancy)
SLE (Single Loss Expectancy)
ARO (Annualized Rate of Occurrence)
MTTR (Mean Time to Repair)