An employee’s laptop containing sensitive company files is stolen. The attacker is able to immediately open and read the files on the device. What is the most likely reason this was possible?
A company allows all employees to have administrator access on their computers. An attacker gains access to one employee’s account through a phishing email. What is the biggest risk to the organization?
A shared folder in a company is configured so that all employees can view and edit its contents. What vulnerability does this represent?
A company encrypts all sensitive files stored on employee laptops. What is the primary benefit of this practice?
An attacker gains physical access to a USB drive containing company data. Under which condition would the attacker be able to read the files most easily?
A company limits administrative privileges to only a few IT staff members. Why is this considered a good security practice?
An attacker modifies important application files stored in a shared folder, causing the application to stop working. Which vulnerability is most likely being exploited?
A user with administrative privileges accidentally installs malicious software. What makes this situation particularly dangerous?
A company stores sensitive files on a server. Only specific employees are given permission to view or edit those files. What security concept is being applied?
An attacker gains access to a standard (non-admin) user account on a system. What can the attacker typically do?
A company gives all employees access to edit files in a shared financial folder to improve collaboration. What is the main risk of this decision?
An attacker steals a company laptop but cannot read any of the files stored on it. What is the most likely explanation?
A company wants to reduce the risk of attackers gaining full control of systems. Which action would be most effective?
An employee’s account is compromised, and the attacker is able to install software and disable antivirus protections. What does this indicate about the account?
A company notices that many employees can access files unrelated to their job roles. What type of vulnerability does this indicate?