Career Employer

Your FREE CompTIA Security+ (SY0-701) Practice Test 2026 – 450+ Q&A

Prepare with realistic, SY0-701-style questions — take a full practice test or drill one objective domain at a time, from General Security Concepts to Security Program Management.

How ready are you?

To find us again, just search “Career Employer CompTIA Security+”

By

Click Start Test above to launch a full-length CompTIA Security+ practice test weighted exactly like the real SY0-701 exam, or drill a single objective domain — General Security Concepts; Threats, Vulnerabilities, and Mitigations; Security Architecture; Security Operations; or Security Program Management and Oversight. Every question includes a clear rationale so you learn the reasoning, not just the answer.

CompTIA Security+ (exam code SY0-701) is a vendor-neutral, entry-level cybersecurity certification administered by CompTIA.

[1]It validates the baseline skills needed to assess an enterprise’s security posture, secure hybrid environments, respond to security events, and operate with an awareness of governance, risk, and compliance.

These free Security+ practice questions follow the published SY0-701 exam objectives so you practice the way the real exam is built.[2]

Pair these with our free study guide, flashcards, and cheat sheet. Want extra insurance for exam day? Capital Prep’s CompTIA Security+ premium study materials come with a CompTIA Security+ exam pass guarantee: your money back if you don’t pass, plus up to $439 toward your retake fee — and Career Employer students get a special discount.

CompTIA Security+ is one of the 14 CompTIA certifications — explore all our CompTIA practice tests to compare and prep across the whole family.

Career Employer CompTIA Security+ Student Data

Updated daily

Career Employer CompTIA Security+ practice-test data · through Oct 7, 2026 · 585 students

CompTIA Security+ students on Career Employer get 68% of practice questions right on the first try; Security Architecture is the most-missed section.[6]

68%
first-try accuracy
1,544 answers
79%
median first full practice exam
253 students · 44% scored 80%+
11 days
median time from setting an exam date to the exam
86% were within 30 days · n = 151

What 585 CompTIA Security+ students on Career Employer got wrong

First-try accuracy by exam section, hardest first[6]

  1. Security Architecture18% of exam · data from the previous question set
    70%n=1,723
  2. Security Operations28% of exam · data from the previous question set
    72%n=2,679
  3. General Security Concepts12% of exam · data from the previous question set
    73%n=1,386
  4. Security Program Management and Oversight20% of exam · data from the previous question set
    76%n=1,849
  5. Threats, Vulnerabilities, and Mitigations22% of exam · data from the previous question set
    81%n=2,020

Security Architecture is the most-missed CompTIA Security+ section (70% correct), but it’s only 18% of the exam. The section costing students the most points is Security Operations (72% correct × 28% of the exam). Drill both, in that order.[6]

Get Capital Prep’s CompTIA Security+ Premium with an exam pass guarantee: your money back if you don’t pass, up to $439 of your retake fee reimbursed, plus a CE student discount →

See Career Employer’s full CompTIA Security+ student data ↓Our data & methodology

Source: Career Employer CompTIA Security+ practice-test data, first attempt at each question only, Aug 29, 2026 – Oct 7, 2026. Sections marked “previous question set” were rewritten recently; they show the earlier version until the new one qualifies. Our practice questions written to the official outline, not the official exam; self-selected sample; a student is one browser.

SY0-701 at a Glance

CompTIA Security+ (SY0-701) at a glance
DetailCompTIA Security+ (SY0-701)
Exam codeSY0-701
QuestionsMaximum of 90
Question typesMultiple-choice and performance-based questions (PBQs)
Time limit90 minutes
Passing score750 on a scale of 100–900
CostApproximately $425 USD per attempt (verify at comptia.org)
Recommended experienceCompTIA Network+ and 2 years in a security/systems administration role
ValidityCertification valid for 3 years; renewable via continuing education

What’s Changed on the CompTIA Security+ Exam (2026–2027)

Checked against official sources: Sep 30, 2026

Coming up

  • Nov 17, 2026

    Security+ V8 (exam code SY0-801) launches on or around November 17, 2026. It keeps 90 questions max, 90 minutes and a 750 passing score, but reweights the domains and adds AI-related security risks.

    Source: CompTIA (opens in a new tab)

  • Jun 11, 2027

    The current SY0-701 (V7) exam retires in English on June 11, 2027 (Japanese, Portuguese, Spanish and Thai on August 13, 2027).

    Source: CompTIA (opens in a new tab)

What Is on the Security+ Exam?

The CompTIA Security+ (SY0-701) exam covers five objective domains: General Security Concepts (12%); Threats, Vulnerabilities, and Mitigations (22%); Security Architecture (18%); Security Operations (28%); and Security Program Management and Oversight (20%).[2]

Security Operations carries the most weight at 28%, followed by Threats, Vulnerabilities, and Mitigations at 22%. Our full practice test is weighted to match:

SY0-701 Domain Weighting
Security Operations28% · ≈25 Qs
Threats, Vulnerabilities, and Mitigations22% · ≈20 Qs
Security Program Management and Oversight20% · ≈18 Qs
Security Architecture18% · ≈16 Qs
General Security Concepts12% · ≈11 Qs
CompTIA Security+ practice test — practice questions by domain with answer explanations

Practice Questions by Domain

Use Start Test for a full weighted SY0-701 simulation, or open the hub and pick a single domain to drill your weak area. After each full exam, your results show a per-domain breakdown so you know exactly where to focus — most candidates need the most reps on Security Operations and performance-based questions.

Are There Prerequisites for Security+?

There are no mandatory prerequisites to sit for CompTIA Security+ (SY0-701).[1] However, CompTIA recommends candidates hold the CompTIA Network+ certification and have at least two years of hands-on experience in IT security or systems administration with a security focus before attempting the exam.

How Do You Register for the Security+ Exam?

You register for CompTIA Security+ through Pearson VUE, the authorized testing partner for CompTIA.[3] Purchase an exam voucher from the CompTIA Store (or an authorized reseller), create or sign in to your Pearson VUE account, and schedule either an in-person test-center session or an online proctored exam. Always confirm current pricing, scheduling, and ID requirements at comptia.org.

What Is the Passing Score for Security+?

The passing score for CompTIA Security+ (SY0-701) is 750 on a scale of 100 to 900.[2] The exam uses a maximum of 90 items combining multiple-choice and performance-based questions; PBQs are typically presented first and may carry more weight. Results are provided immediately at the end of the exam.

How Hard Is Security+?

CompTIA Security+ is widely regarded as moderately challenging — harder than entry-level certs like A+ or Network+, but more approachable than advanced credentials such as CISSP. CompTIA does not publish an official pass rate for Security+.[1] The performance-based questions and the broad scope of Security Operations (28% of the exam) are the most commonly cited challenges.

750
Passing scaled score
of 100–900
90
Maximum questions
MCQs + PBQs
28%
Security Operations
largest domain

The takeaway: drill until you’re consistently scoring above target on full-length practice — especially Security Operations and the PBQ-heavy domains — before you book your exam date.

On Career Employer, CompTIA Security+ students get 68% right on the first try and miss Security Architecture most[6] — see the CompTIA Security+ student data above.

What to Expect on Exam Day

Arrive at your Pearson VUE test center at least 15 minutes early to check in — bring a valid, unexpired government-issued photo ID whose name matches your registration.[3]You’ll store phones and personal items in a locker; no notes are allowed.

Performance-based questions usually appear first and ask you to solve a hands-on scenario, then you move through the multiple-choice items. You have 90 minutes to answer a maximum of 90 questions, and your scaled result is shown immediately when you finish.

If you test via online proctoring, expect a similar room scan and ID check. Having simulated the full timing with practice tests makes that clock feel routine.

How to Use This Security+ Practice Test

  • Recreate exam conditions. Take the full test timed, with no notes.
  • Diagnose, then drill. Use a full SY0-701 simulation to find weak domains, then drill them.
  • Prioritize Security Operations. It’s the biggest score-mover at 28%.
  • Learn the why. Read every rationale — understanding beats memorizing.
  • Answer everything. There’s no guessing penalty, so never leave a question blank.

Plan for the full sitting. Only 48% of CompTIA Security+ students on Career Employer who start a full-length practice exam finish one (240 of 501)[6] — set aside the full sitting before you press Start Test.

Mind the calendar. CompTIA Security+ students who set an exam date on Career Employer had a median of 11 days until their exam, and 86% were within 30 days (n = 151)[6] — if you have more runway than that, use it to work through every section.

Why Get Security+ Certified?

Security+ is one of the most widely recognized entry-level cybersecurity credentials, often required (or strongly preferred) by employers and approved for U.S. Department of Defense roles.[1] These free Security+ practice tests are the most efficient way to get there.

Conclusion

Passing SY0-701 comes down to knowing security operations, threats and mitigations, and core concepts cold — and being comfortable with performance-based questions. Use this free CompTIA Security+ practice test to find your weak domains and drill them to mastery — and round out your prep with our free study guide, flashcards, and cheat sheet. On Career Employer, CompTIA Security+ students lose the most points on Security Operations (72% correct on the first try), so start your drilling there.[6]

Security+ Practice Test FAQ

The current version of the CompTIA Security+ exam is SY0-701, which launched on November 7, 2023 and replaced the earlier SY0-601. SY0-701 is organized into five objective domains and is the version you will sit today.

Career Employer CompTIA Security+ practice-test data, through Oct 7, 2026 · 585 students
Every published Career Employer CompTIA Security+ practice-test number, with its sample size, source and date
MetricValuenStudentsSourceData through
Students who answered practice questions585—585all question versionsOct 7, 2026
First-try answers (all question versions)36,79736,797585all question versionsOct 7, 2026
First-try accuracy, whole exam68.2%1,544 answers57current question set (since Oct 5, 2026)Oct 7, 2026
First-try accuracy: Security Architecture (17.8% of the exam; costs 5.4 of every 100 exam points)69.7%1,723 answers115previous question setOct 5, 2026
First-try accuracy: Security Operations (27.8% of the exam; costs 7.8 of every 100 exam points)71.7%2,679 answers119previous question setOct 5, 2026
First-try accuracy: General Security Concepts (12.2% of the exam; costs 3.3 of every 100 exam points)72.8%1,386 answers114previous question setOct 5, 2026
First-try accuracy: Security Program Management and Oversight (20% of the exam; costs 4.9 of every 100 exam points)75.7%1,849 answers104previous question setOct 5, 2026
First-try accuracy: Threats, Vulnerabilities, and Mitigations (22.2% of the exam; costs 4.3 of every 100 exam points)80.7%2,020 answers117previous question setOct 5, 2026
Median score on first full-length practice exam79%253 students253all question versionsOct 7, 2026
Scored 80%+ on first full-length practice exam44.3%253 students253all question versionsOct 7, 2026
Median days from setting an exam date to the exam11 days151 exam dates151first date each student setOct 7, 2026
Exam dates within 30 days of being set86.1%151 exam dates151first date each student setOct 7, 2026
Started a full-length practice exam501—501all question versionsOct 7, 2026
Finished a full-length practice exam240of 501 starters240all question versionsOct 7, 2026
Full-length practice exam finish rate47.9%501 starters501all question versionsOct 7, 2026

First attempt at each question only; repeats, answers after revealing the explanation, bots and staff excluded. Aug 29, 2026 – Oct 7, 2026. Our practice questions written to the official outline, not the official exam; self-selected sample; a student is one browser. Free to reuse under CC BY 4.0 — cite “Career Employer practice-test data, careeremployer.com/data”.

CompTIA Security+ question bank

All 454 questions, by domain

A reference copy of every question in this practice test. Each answer stays hidden until you choose to show it. To practice with scoring, timing and your readiness score, use Start Test at the top of the page.

General Security Concepts (54)

  1. In cybersecurity, what is a 'honeypot' primarily used for?

    • A.To lure an attacker onto a decoy server we monitor
    • B.To lure an intruder across a decoy subnet we log
    • C.To lure an intruder into opening bait files we log
    • D.To stall an intruder's scans with replies we delay
    Show answerHide answer

    Correct answer: To lure an attacker onto a decoy server we monitor

    A honeypot exists to lure an attacker onto a decoy server we monitor, so defenders can detect the intrusion and study the attacker's tools and techniques. Luring an intruder across a decoy subnet describes a honeynet, a network of many decoy systems rather than a single one. Luring an intruder into opening bait files describes a honeyfile, which is a single document, not a system. Stalling an intruder's scans with delayed replies describes a tarpit, which slows the attacker rather than drawing them in to be studied.

  2. In network security, what is the primary purpose of using a honeypot?

    • A.To draw an intruder to open a planted bait file
    • B.To draw an intruder to use a planted credential
    • C.To draw an attacker onto a watched false target
    • D.To stall an attacker with a host's slow replies
    Show answerHide answer

    Correct answer: To draw an attacker onto a watched false target

    A honeypot exists to draw an attacker onto a watched false target: a decoy system with no production role, so any connection to it is suspicious and can be studied safely. Drawing an intruder into opening a planted bait file describes a honeyfile, and drawing one into using a planted credential describes a honeytoken; both are decoy data, not decoy systems. Stalling an attacker with a host's slow replies is a tarpit, which wastes attacker time rather than observing them.

  3. Which of the following is a security concept that ensures that data is only modified by authorized users and in authorized ways?

    • A.Confidentiality policy
    • B.Integrity requirements
    • C.Availability assurance
    • D.Nonrepudiation reviews
    Show answerHide answer

    Correct answer: Integrity requirements

    Integrity is the property that data has not been altered except by an authorized party acting in an authorized way, and hashing, digital signatures, input validation and change control are the mechanisms that enforce it. Confidentiality governs who may see data rather than who may change it, so it is fully satisfied by a record an attacker has silently rewritten but nobody has read. Availability governs whether the data is reachable when it is needed and says nothing about whether its contents are still true. Nonrepudiation binds an action to a specific actor so it cannot later be denied, a proof-of-origin property layered on top of integrity rather than the modification control itself.

  4. In a security context, what is the main purpose of employing a honeypot in a network?

    • A.Drawing attackers toward a decoy server to study their techniques
    • B.Redirecting malware callbacks to a sinkhole so their traffic dies
    • C.Slowing hostile scanners using a tarpit that stalls their traffic
    • D.Seeding fake records into a database so their theft raises alerts
    Show answerHide answer

    Correct answer: Drawing attackers toward a decoy server to study their techniques

    A honeypot's main purpose is drawing attackers toward a decoy server to study their techniques: it has no production role, so every connection it receives is hostile and can be observed and recorded. Redirecting malware callbacks to a sinkhole is DNS sinkholing, which cuts off command traffic rather than inviting study. Slowing scanners with a tarpit deliberately stalls connections to waste an attacker's time. Seeding fake records into a database describes a honeytoken, a tripwire planted inside real data rather than a decoy system.

  5. Which security principle is primarily concerned with minimizing the amount of damage that can be done in the event of a security breach?

    • A.Change management
    • B.Security training
    • C.Minimum privilege
    • D.Vendor assessment
    Show answerHide answer

    Correct answer: Minimum privilege

    Least privilege, the principle of issuing an account the minimum privilege its task actually needs, is what caps the damage of a breach: a compromised account inherits only that narrow set of rights, so the harm stops where the entitlements stop. Change management governs how modifications reach production and prevents self-inflicted outages, an availability and integrity concern rather than a containment one. Security training reduces how often a person is tricked into opening the door at all, lowering the chance of a breach without limiting what one costs. Vendor assessment rates the risk a third party carries before it is onboarded, a supply-chain judgment made in advance rather than a limit on an intruder already inside.

  6. Which of the following best describes the concept of 'Zero Trust' in network security?

    • A.Verifying user identity and device posture wherever requests originate
    • B.Verifying user identity through MFA, then trusting each device it uses
    • C.Verifying device health at enrollment, then trusting every later login
    • D.Verifying nobody and denying every request until an admin approves it
    Show answerHide answer

    Correct answer: Verifying user identity and device posture wherever requests originate

    Zero Trust means verifying user identity and device posture wherever requests originate, so network location earns no standing trust and every request is evaluated on its own. Verifying identity through MFA and then trusting each device it uses checks only half the picture and grants implicit trust to the endpoint. Verifying device health once at enrollment and then trusting every later login is one-time admission, the opposite of continuous verification. Denying every request until an admin approves it misreads 'never trust' as 'never allow'; Zero Trust grants access automatically once policy checks pass.

  7. Which of the following best describes the concept of defense in depth in network security?

    • A.Stacking several independent layers so a single failure stays contained
    • B.Ranking discovered weaknesses so the worst findings get corrected first
    • C.Splitting a transaction between two approvers so neither acts unwatched
    • D.Rotating admins through roles so hidden fraud becomes detectable sooner
    Show answerHide answer

    Correct answer: Stacking several independent layers so a single failure stays contained

    Defense in depth assumes that any one control will eventually fail, so it layers independent administrative, technical and physical controls along the path an attacker must take; a firewall, segmentation, endpoint protection, least privilege and monitoring each buy time and none of them is load-bearing on its own. Ranking discovered weaknesses so the worst are corrected first is risk-based vulnerability management, which sequences remediation instead of layering protection. Splitting a transaction so no single person completes it is separation of duties, an insider control. Rotating people through roles surfaces concealed misuse over time, another personnel control; each of those is one individual layer, not the layering principle itself.

  8. What is the primary security concern addressed by the implementation of a Zero Trust model?

    • A.Zero-day threats
    • B.Insider threats
    • C.Zero-click threats
    • D.Social engineering threats
    Show answerHide answer

    Correct answer: Insider threats

    Zero Trust's primary concern is insider threats: the traditional perimeter model granted implicit trust to anyone already inside the network, and Zero Trust removes that by verifying identity, device and authorization on every request, limiting what a malicious insider or compromised internal account can reach. Zero-day threats are unknown vulnerabilities, addressed by patching, exploit mitigation and behavioural detection; the shared word "zero" is a coincidence. Zero-click threats exploit flaws in software such as messaging apps with no user interaction and are countered by patching and attack-surface reduction, not by removing implicit trust. Social engineering threats manipulate people into acting, which awareness training counters; Zero Trust limits the damage afterwards but does not target the manipulation itself.

  9. In an Identity and Access Management system, what does the term "Least Privilege" primarily refer to?

    • A.Forcing an account to regenerate its password on a timetable
    • B.Locking an account after a sequence of failed logons appears
    • C.Assigning an account a rights bundle scoped for one function
    • D.Placing an account inside a group whose members share duties
    Show answerHide answer

    Correct answer: Assigning an account a rights bundle scoped for one function

    Least privilege gives every user, service and process a bundle of rights scoped to the single function it performs and nothing wider, and it applies for as long as that function lasts, so a compromised or misused account carries the smallest possible reach. Forcing a periodic password change is a credential hygiene rule that limits how long a stolen secret stays valid without changing what the account can do. Locking an account after repeated failed logons frustrates guessing attacks, an authentication throttle rather than an entitlement decision. Putting an account in a group is the mechanism by which rights are often delivered, but a group can over-grant just as easily as it can grant correctly; the principle concerns the size of the grant, not the container it arrives in.

  10. In the context of Public Key Infrastructure (PKI), what role does the Certificate Revocation List (CRL) play?

    • A.Holding private keys inside tamper evident hardware under tight control
    • B.Naming certificates the issuing authority has withdrawn ahead of expiry
    • C.Binding each published key to a single independently verified applicant
    • D.Publishing the hierarchy of trust traversed by a validating application
    Show answerHide answer

    Correct answer: Naming certificates the issuing authority has withdrawn ahead of expiry

    A CRL is a signed, periodically republished list of the serial numbers of certificates that the issuing certificate authority has revoked before their natural expiry, because a key was compromised, an employee left or a certificate was issued in error; a relying party consults it, or the equivalent OCSP response, before trusting a certificate that is otherwise still inside its validity dates. Holding private keys in tamper-evident hardware describes a hardware security module or a smart card, which protects keys rather than listing dead ones. Binding a verified applicant to a published key is what the certificate itself does at issuance. Publishing the hierarchy a client walks to a trusted root is the work of the CA and its intermediates, which establishes trust rather than withdrawing it.

  11. In a PKI, what is the function of a Key Escrow?

    • A.It shortens the time an appliance needs to verify certificates
    • B.It keeps copies of private keys in trusted third-party custody
    • C.It publishes the public key that enrolled users currently hold
    • D.It signs certificate requests submitted by each of the clients
    Show answerHide answer

    Correct answer: It keeps copies of private keys in trusted third-party custody

    Key escrow means a trusted third party keeps a protected copy of private keys so an authorized party can obtain them later. It has nothing to do with validation speed, which depends on revocation list or status protocol checking. Publishing public keys is what a public repository or directory does, and public keys need no escrow because they are already public. Signing certificate requests is the certificate authority's own function, performed with the authority's key rather than with escrowed material.

  12. Which cryptographic principle prevents the sender of a message from denying the message's content and transmission?

    • A.Non-repudiation proofs
    • B.Confidentiality shield
    • C.Integrity verification
    • D.Authentication factors
    Show answerHide answer

    Correct answer: Non-repudiation proofs

    Non-repudiation is the property that stops a sender from later denying that they produced and sent a message; a private-key digital signature supplies it because only the signer holds the key. Confidentiality keeps the content unreadable by outsiders but says nothing about who sent it. Integrity shows that content was not altered in transit, yet an altered-free message can still be disowned. Authentication proves who a party is at the time of a session, without binding them to a specific message afterwards.

  13. What is the main difference between symmetric and asymmetric encryption?

    • A.The size of the block each cipher shifts at once
    • B.The kind of data each cipher is allowed to guard
    • C.The number of the keys each cipher needs to work
    • D.The type of hash each cipher must apply up front
    Show answerHide answer

    Correct answer: The number of the keys each cipher needs to work

    The defining difference is key count and key relationship: symmetric encryption uses one shared secret for both directions, while asymmetric encryption uses a mathematically linked public and private pair. Block size varies among algorithms within both families and separates nothing. Neither family restricts the kind of data it may protect. Neither family requires a hash before encrypting, and hashing is a separate primitive used alongside either one.

  14. Which of the following algorithms is not a symmetric key algorithm?

    • A.AES
    • B.RSA
    • C.RC4
    • D.DES
    Show answerHide answer

    Correct answer: RSA

    RSA is the odd one out because it is asymmetric: it works with a linked public and private key pair, and its security rests on the difficulty of factoring large numbers. AES is the symmetric block cipher that replaced DES as the standard. RC4 is a symmetric stream cipher, now deprecated. DES is the original symmetric block cipher whose short key made it obsolete. All three of those use the same secret to encrypt and to decrypt.

  15. What cryptographic concept involves the use of two keys, a public key for encryption, and a private key for decryption?

    • A.Symmetric enciphering
    • B.Cryptographic digests
    • C.Block-cipher chaining
    • D.Asymmetric encryption
    Show answerHide answer

    Correct answer: Asymmetric encryption

    Asymmetric encryption is built on a linked key pair: anyone may encrypt with the freely published public key, and only the matching private key held by the recipient can decrypt the result. Symmetric enciphering uses one secret for both operations. Cryptographic digests are one-way and cannot be reversed with any key at all. Block-cipher chaining is a mode of operation that links blocks together and introduces no second key.

  16. In cryptography, what is a 'collision'?

    • A.Two unlike messages that share one hash value
    • B.Two unlike keys that give the same ciphertext
    • C.Two unlike sessions that reuse a single nonce
    • D.Two unlike packets that arrive in wrong order
    Show answerHide answer

    Correct answer: Two unlike messages that share one hash value

    A collision occurs when two different inputs share an identical digest from the same hash function; because a hash maps unlimited input to a fixed-length output, collisions must exist, and a strong function makes finding one infeasible. Two keys producing matching ciphertext is not what the term names. Reusing a nonce across sessions is a separate weakness in a mode of operation. Packets arriving in the wrong order is a transport condition with no hashing involved.

  17. Which cryptographic method is primarily used to ensure the integrity of data?

    • A.Asymmetric encryption
    • B.Steganographic hiding
    • C.Cryptographic hashing
    • D.Deterministic padding
    Show answerHide answer

    Correct answer: Cryptographic hashing

    Cryptographic hashing is the primary integrity mechanism: recompute the digest and compare it, and any change of even one bit produces a completely different value. Asymmetric encryption protects confidentiality and enables key exchange, but ciphertext can still be corrupted without detection. Steganographic hiding conceals that a message exists and does nothing to prove it is unchanged. Deterministic padding only fills a block to the required size and carries no verification value.

  18. In PKI, what is the main purpose of a key escrow?

    • A.To recover data after a private key is destroyed
    • B.To shorten the delay a handshake takes to finish
    • C.To raise the strength of the chosen cipher suite
    • D.To publish a record of the certificates now void
    Show answerHide answer

    Correct answer: To recover data after a private key is destroyed

    The business reason for escrowing keys is recoverability: if an employee leaves, a device fails or a key is destroyed, encrypted data would be permanently unreadable unless a protected copy of the key exists. Escrow adds a step to key management and shortens no handshake. It changes nothing about the algorithm or key length, so cipher strength is unaffected. Publishing a record of void certificates is the job of a revocation list or an online status responder.

  19. What is the primary purpose of using a salt in cryptographic hashing?

    • A.It hides the hash output from the casual user
    • B.It makes each stored hash value end up unique
    • C.It shrinks the data before the hash is formed
    • D.It speeds up the hash routine on shared files
    Show answerHide answer

    Correct answer: It makes each stored hash value end up unique

    A salt is a random value added to the input before hashing, so two users who choose the same password still store different digests, and precomputed tables built for unsalted hashes become useless. A salt does not conceal the stored output, which is usually readable to anyone with database access. It adds input rather than compressing it. It adds work rather than saving it, and slowing the routine down is often deliberate.

  20. What is the primary difference between stream ciphers and block ciphers in cryptography?

    • A.The length of the keys that each one accepts
    • B.The number of the rounds that each one makes
    • C.The type of medium that each one can protect
    • D.The way that each one takes in its plaintext
    Show answerHide answer

    Correct answer: The way that each one takes in its plaintext

    The categories are defined by how plaintext is taken in: a stream cipher runs a keystream against the data bit by bit or byte by byte, while a block cipher gathers plaintext into fixed-size blocks and transforms one block at a time. Accepted key lengths vary between individual algorithms inside both families. Round count is an internal design detail of a particular algorithm. Neither family is restricted to a particular kind of medium.

  21. What is the primary function of the Diffie-Hellman algorithm in cryptography?

    • A.Shared secret creation
    • B.Bulk data encipherment
    • C.Digital file signature
    • D.Fast message digesting
    Show answerHide answer

    Correct answer: Shared secret creation

    Diffie-Hellman lets two parties create a shared secret over a channel an eavesdropper can watch, because each side combines its own private value with the other's public value and reaches the same result. It does not encipher bulk data; the shared secret is handed to a symmetric cipher for that. It produces no signature and proves nothing about identity on its own. It produces no digest, so it performs no hashing.

  22. Which cryptographic protocol provides security for electronic data interchange (EDI) transactions?

    • A.The IKE exchange
    • B.The RADIUS proxy
    • C.The SRTP streams
    • D.The SET protocol
    Show answerHide answer

    Correct answer: The SET protocol

    Secure Electronic Transaction was designed specifically to protect commercial transaction data as it moves between the parties to a trade, wrapping the order and payment details in certificates so each side proves who it is. The IKE exchange negotiates keys for a network-layer tunnel. A RADIUS proxy forwards authentication and accounting for network access. SRTP encrypts real-time voice and video streams. None of those three was built to secure trading documents.

  23. In cryptography, what is the main purpose of a Certificate Revocation List (CRL)?

    • A.It records the certificates that hit their expiry date
    • B.It names the certificates that an issuer has withdrawn
    • C.It records the certificates that the CAs logged openly
    • D.It answers the status queries that check a certificate
    Show answerHide answer

    Correct answer: It names the certificates that an issuer has withdrawn

    It names the certificates that an issuer has withdrawn: a CRL is the CA's signed list of revoked serial numbers that relying parties check before trusting a certificate. Certificates that hit their expiry date fail on their own dates and are normally dropped from the CRL rather than listed on it. An open log of the certificates CAs issued is Certificate Transparency, not revocation. Answering status queries that check one certificate at a time is what an OCSP responder does.

  24. What cryptographic concept involves splitting data into parts where individual parts do not reveal the whole?

    • A.Escrowed private keys
    • B.Reversible data masks
    • C.Rotating nonce values
    • D.Shamir secret sharing
    Show answerHide answer

    Correct answer: Shamir secret sharing

    Shamir secret sharing splits a secret into shares and sets a threshold, so any group smaller than the threshold learns absolutely nothing while a large enough group can rebuild the original. Escrowed private keys are whole keys held in custody, not fragments. Reversible data masks substitute readable values and can be undone by whoever holds the mapping. Rotating nonce values replace one complete value with another and never divide a secret into parts.

  25. Which property of cryptographic hash functions ensures that, if two different messages produce the same hash, it's computationally infeasible to find them?

    • A.Collision resistance
    • B.Fixed-size digesting
    • C.Deterministic output
    • D.Uniform distribution
    Show answerHide answer

    Correct answer: Collision resistance

    Collision resistance is the property named: it must be computationally infeasible to discover any two inputs that map to one digest, which is what keeps signatures and file checksums trustworthy. Fixed-size digesting only means every input yields an output of the same length, and it is the very reason collisions must exist. Deterministic output means one input always yields the same digest. Uniform distribution describes how outputs spread across the range, not how hard it is to find a matching pair.

  26. In the context of PKI, what does the term 'chain of trust' refer to?

    • A.The order in which a cipher repeats its own rounds
    • B.The chain of trusted issuers that ends at the root
    • C.The lineup of ciphers a client offers in the hello
    • D.The bundle of keys shared by two peers per session
    Show answerHide answer

    Correct answer: The chain of trusted issuers that ends at the root

    The chain of trust is the certificate path: the end-entity certificate is signed by an intermediate authority, which is signed by another, up to a root the relying party already trusts, and each link is verified in turn. The order of cipher rounds is an internal algorithm detail. The lineup a client offers is the handshake proposal. The keys two peers share for a session are established after the chain has already been validated.

  27. A security analyst needs to encrypt several terabytes of database backups quickly using a single shared secret, and separately needs a way for two parties who have never met to agree on that secret over an untrusted network. Which combination correctly matches each task to the right cryptography type?

    • A.Use one shared secret for both tasks, sent by hand
    • B.Use a public key pair for both tasks, however slow
    • C.Use a shared secret for copies, a key-pair to swap
    • D.Use a one-way hash for backups, a courier for keys
    Show answerHide answer

    Correct answer: Use a shared secret for copies, a key-pair to swap

    Each type is used where it is strong: a shared secret cipher encrypts terabytes quickly, and a public and private key pair lets two strangers settle that secret across an untrusted link without ever transmitting it. Using one shared secret for both tasks leaves the original problem of getting that secret to the far end, and hand delivery does not scale. A key pair is far too slow for terabytes. A one-way hash cannot restore a backup, and a courier is not a cryptographic mechanism.

  28. An organization cannot patch a legacy payroll server because the vendor no longer supports it, but a policy requires that all systems handling sensitive data be on a supported, patched platform. To satisfy the requirement's intent, the team isolates the server on its own segmented VLAN behind strict firewall rules. According to CompTIA's control taxonomy, what BEST describes this firewall-and-segmentation measure?

    • A.A compensating safeguard
    • B.A preventative screening
    • C.A managerial instruction
    • D.A corrective improvement
    Show answerHide answer

    Correct answer: A compensating safeguard

    A compensating safeguard is an alternative put in place when the required primary measure cannot be implemented, and it must deliver comparable protection; segmenting an unpatchable server behind strict filtering is the textbook example. A preventative screening stops an event before it starts, which is not possible here because the flaw remains present. A managerial instruction is written direction such as a policy. A corrective improvement restores a system after an incident has already occurred.

  29. A company installs warning signs, motion-activated lighting, and visible security cameras around its data center perimeter. According to the CompTIA control type taxonomy, into which category do these measures PRIMARILY fall?

    • A.Detective or investigative
    • B.Preventive or obstructive
    • C.Compensating or alternate
    • D.Deterrent or discouraging
    Show answerHide answer

    Correct answer: Deterrent or discouraging

    Warning signs, lighting and visible cameras are deterrent or discouraging controls, because their primary purpose is to make an attacker decide not to try. Detective controls identify an incident as it happens; cameras can record, but being visible is what makes them discourage. Preventive controls physically obstruct entry, as a locked gate or bollard does, and a sign obstructs nothing. Compensating controls substitute for a required control that cannot be implemented.

  30. An organization wants to map every control it deploys to one of the functional control types used by CompTIA. Which set lists ONLY valid functional control types?

    • A.Technical, managerial, operational, physical
    • B.Preventive, deterrent, detective, corrective
    • C.Mandatory, discretionary, regulatory, hybrid
    • D.Confidentiality, integrity, advisory, manual
    Show answerHide answer

    Correct answer: Preventive, deterrent, detective, corrective

    Preventive, deterrent, detective and corrective are all functional control types, the labels that state what a control is meant to DO, and compensating and directive complete that same list of six. Technical, managerial, operational and physical describe how a control is implemented and by whom, which is the category axis rather than the functional one. Mandatory and discretionary name access control models, regulatory names a compliance driver, and hybrid names a deployment mix. Confidentiality and integrity are security properties, while advisory and manual describe a document and a method rather than a control type.

  31. A security policy document instructs all employees that they must lock their workstations whenever they step away from their desks. What functional type of control is this written instruction itself?

    • A.Detective control
    • B.Deterrent control
    • C.Technical control
    • D.Directive control
    Show answerHide answer

    Correct answer: Directive control

    A directive control works by instructing people, and a written policy requiring staff to lock a workstation states exactly the behavior the organization expects. A detective control establishes that something has already occurred, such as a log entry showing an unattended session. A deterrent control discourages an outsider from attempting an attack, which an internal policy read only by employees does not do. A technical control names the category of implementation, a mechanism enforced by the system itself rather than an instruction given to a person.

  32. After a malware infection, an organization runs antivirus to remove the malicious files and restores affected files from clean backups. Which functional control type BEST describes these post-incident remediation actions?

    • A.Operational
    • B.Managerial
    • C.Corrective
    • D.Physical
    Show answerHide answer

    Correct answer: Corrective

    Corrective controls act after an incident to remove the cause and restore systems to a known-good state, which is what removing the malicious files and restoring clean backups does. Operational is a control category describing controls carried out by people, such as backup procedures, not a functional type describing what the control does. Managerial is a category covering policies and risk assessments, not post-incident remediation. Physical is a category for tangible barriers such as locks and fences, not a functional type.

  33. Which CompTIA control category encompasses measures such as security guards, fences, locks, bollards, and access badges that protect tangible assets?

    • A.Operational or staff-based
    • B.Technical or device-based
    • C.Physical or environmental
    • D.Deterrent or preventive
    Show answerHide answer

    Correct answer: Physical or environmental

    Guards, fences, locks, bollards and access badges all act on the tangible world, so CompTIA places them in the physical or environmental control category. Operational or staff-based controls are the procedures people carry out, such as awareness training and log review; a guard is a person, but the category counts what the control protects against, physical access. Technical or device-based controls live in software and system configuration, not in a badge or a gate. Deterrent or preventive describes control TYPES, which cut across every category, so it does not answer a question about category.

  34. A risk committee creates a formal acceptable use policy and conducts an annual risk assessment. Within the CompTIA control category model, what type of controls are these governance and policy activities?

    • A.Technical or electronic
    • B.Operational or everyday
    • C.Managerial or strategic
    • D.Preventive or proactive
    Show answerHide answer

    Correct answer: Managerial or strategic

    Managerial controls are the governance instruments through which an organization directs risk, and both an acceptable use policy and a scheduled risk assessment are decisions and direction rather than mechanisms. Technical controls are enforced by systems, such as access control lists and encryption. Operational controls are the routine tasks staff perform, such as reviewing logs or provisioning accounts. Preventive names what a control is meant to do, which is a functional type and not one of the implementation categories.

  35. An administrator configures security awareness training, account provisioning procedures, and routine log review carried out by analysts. Which control CATEGORY do these human-performed, day-to-day activities belong to?

    • A.Operational or manual
    • B.Physical or perimeter
    • C.Directive or advisory
    • D.Detective or reactive
    Show answerHide answer

    Correct answer: Operational or manual

    Operational controls are the ones people execute while running the business, so awareness training, account provisioning and log review performed by analysts all sit in this category. Physical controls protect the building and the equipment inside it. Directive controls state what staff are required to do, which is the written instruction rather than the work itself. Detective names what a control is for, identifying that an event has occurred, instead of naming how the control is implemented.

  36. Which element of the CIA triad is directly compromised when a denial-of-service attack prevents legitimate users from reaching a web application?

    • A.Confidentiality of data
    • B.Availability of service
    • C.Integrity of processing
    • D.Accountability of users
    Show answerHide answer

    Correct answer: Availability of service

    Availability is the property a denial-of-service attack strikes directly: nothing is read and nothing is altered, the application simply cannot be reached by the people entitled to use it. Confidentiality concerns unauthorized disclosure, and flooding a site discloses nothing. Integrity concerns unauthorized modification, and the stored data is left exactly as it was. Accountability concerns being able to attribute an action to a particular identity, which the outage does not undermine.

  37. A bank wants to be able to prove that a customer who submitted a wire transfer request cannot later credibly deny having sent it. Which security concept addresses this requirement?

    • A.Tamper-evidence
    • B.Fault-tolerance
    • C.Self-encryption
    • D.Non-repudiation
    Show answerHide answer

    Correct answer: Non-repudiation

    Non-repudiation is the assurance that whoever originated an action cannot later deny it, and it is produced by binding the request to a private key that only the customer holds, usually through a digital signature. Tamper-evidence shows that a seal or a record has been disturbed, which reveals interference after the fact but never ties a message to the person who sent it. Fault-tolerance keeps a service running through component failure, which is an availability property. Self-encryption protects data written to a drive and offers no evidence about the origin of a transaction.

  38. In the AAA framework used for access control, which component records what an authenticated user did, such as the commands run and resources accessed?

    • A.Authentication or identity
    • B.Authorization or privilege
    • C.Accounting or traceability
    • D.Provisioning or onboarding
    Show answerHide answer

    Correct answer: Accounting or traceability

    Accounting is the third A of AAA: once a subject has been authenticated and authorized, accounting records what was actually done, including the commands issued, the resources touched and how long the session lasted, and that record is what makes an audit possible. Authentication establishes that the subject really is who it claims to be. Authorization decides which resources that proven identity may use. Provisioning is the account lifecycle work of creating and removing access, which happens before a session ever starts rather than recording what goes on inside one.

  39. A network architect designing under a Zero Trust model is implementing the control plane. Which function is a responsibility of the Zero Trust control plane rather than the data plane?

    • A.Forwarding packets and blocking the denied sessions
    • B.Encrypting payloads and rotating the symmetric keys
    • C.Evaluating requests and issuing the access decision
    • D.Assigning addresses and renewing the expired leases
    Show answerHide answer

    Correct answer: Evaluating requests and issuing the access decision

    The Zero Trust control plane is where the access decision is made: the policy engine evaluates each request against policy and the policy administrator issues the resulting grant or denial. Forwarding packets and blocking denied sessions is the work of the policy enforcement point in the data plane, which carries out a decision it did not make. Encrypting payloads and rotating symmetric keys protects traffic in flight but decides nothing about who may reach what. Assigning addresses and renewing leases is ordinary network plumbing that exists whether or not Zero Trust is deployed.

  40. In a Zero Trust architecture, which component is responsible for ENFORCING the access decision by allowing or blocking a session between a subject and a resource?

    • A.Enforcement point or gateway
    • B.Decision engine or evaluator
    • C.Trust algorithm or heuristic
    • D.Resource portal or connector
    Show answerHide answer

    Correct answer: Enforcement point or gateway

    The policy enforcement point sits in the data plane and is the component that actually opens, refuses or tears down the session once a verdict has been handed to it. The decision engine is the policy engine, which produces the verdict but never touches the traffic. The trust algorithm is the scoring logic the policy engine runs to reach that verdict. The resource portal is a deployment model that fronts an application, not the component charged with allowing or blocking a session.

  41. In a Zero Trust architecture, what is the role of the threat scope reduction (microsegmentation) approach?

    • A.It rechecks device trust per session so one login cannot linger
    • B.It rechecks device posture per request so one token cannot last
    • C.It hides internal hosts from scans so one probe cannot map them
    • D.It shrinks implicit trust zones so one breach cannot spread far
    Show answerHide answer

    Correct answer: It shrinks implicit trust zones so one breach cannot spread far

    Threat scope reduction through microsegmentation means it shrinks implicit trust zones so one breach cannot spread far: small segments with policy between them cap how far a compromised workload can move laterally. Rechecking device trust per session is continuous authentication, which judges who is connecting rather than limiting where they can reach. Rechecking device posture per request is dynamic access evaluation, a policy decision point job, not segmentation. Hiding internal hosts from scans is the cloaking a software-defined perimeter provides, which limits discovery, not the blast radius after a breach.

  42. A security team deploys decoy systems and fake credentials across the network specifically to mislead attackers and study their behavior. Which category of techniques does this represent?

    • A.Deception technology
    • B.Network segmentation
    • C.Privilege management
    • D.Behavioral analytics
    Show answerHide answer

    Correct answer: Deception technology

    Deception technology is the family of tools built to mislead an intruder: honeypots, honeynets, honeyfiles and honeytokens all present something attractive and false, so any interaction with them is both a high-confidence alert and a chance to watch how the attacker works. Network segmentation limits where traffic may flow but presents nothing fake. Privilege management decides what an account is allowed to do rather than baiting it. Behavioral analytics hunts for anomalies in genuine activity instead of planting decoys.

  43. An administrator plants a single fake API key in a configuration repository that no legitimate process should ever use, so that any attempt to use it raises an immediate alert. What deception technique is this?

    • A.Honeynet or subnet
    • B.Honeypot or server
    • C.Honeytoken or item
    • D.Sinkhole or router
    Show answerHide answer

    Correct answer: Honeytoken or item

    A honeytoken is a single piece of bait data, such as a fake credential, API key or database record, placed where no legitimate process will ever touch it, so any use of it is unambiguous evidence of intrusion. A honeynet is a whole decoy network of systems. A honeypot is a decoy host built to be attacked and studied. A sinkhole redirects malicious traffic to a controlled destination rather than planting false data and waiting for someone to pick it up.

  44. Before a planned modification to a production firewall, an organization requires that the change be documented, analyzed for impact, and approved by a review board. Which security governance process mandates these steps?

    • A.Change management
    • B.Incident response
    • C.Firewall auditing
    • D.Capacity planning
    Show answerHide answer

    Correct answer: Change management

    Change management is the governance process that requires a proposed change to be documented, assessed for impact and approved before it reaches production, precisely so an unplanned outage or a new security gap is caught on paper first. Incident response governs what happens once something has already gone wrong. Firewall auditing reviews an existing rule base for drift and unused entries but authorizes no change. Capacity planning forecasts future resource demand and plays no part in approving modifications.

  45. During a change management review, the team documents a backout plan. What is the PRIMARY purpose of a backout plan?

    • A.To define tests that prove the change worked
    • B.To record the root cause if the change fails
    • C.To state the downtime users should expect
    • D.To capture the precise steps of the rollback
    Show answerHide answer

    Correct answer: To capture the precise steps of the rollback

    The primary purpose of a backout plan is to capture the precise steps of the rollback, so that a failed change can be reversed quickly to the last known good state. Defining tests that prove the change worked is the validation or test plan, which decides success rather than how to undo failure. Recording the root cause if the change fails belongs to the post-incident review after the event. Stating the downtime users should expect is part of the impact analysis and communication plan, not the reversal procedure.

  46. A configuration management practice records the version, settings, and dependencies of every approved system build so that unauthorized drift can be detected. Which change management concept does this describe?

    • A.Baseline configuration
    • B.Maintenance scheduling
    • C.Records classification
    • D.Compliance attestation
    Show answerHide answer

    Correct answer: Baseline configuration

    A baseline configuration is the documented, approved state of a system, covering its version, its settings and its dependencies, and it exists so that any later deviation can be recognized as drift. Maintenance scheduling reserves a time in which changes may be made rather than describing what the approved state is. Records classification labels information by sensitivity and says nothing about build settings. Compliance attestation asserts that a control set meets an external standard, which is a statement made to an auditor rather than a technical reference point.

  47. An organization implements full-disk encryption on all laptops. At which level of encryption is this protection being applied?

    • A.Volume level
    • B.Disk level
    • C.File container level
    • D.File system level
    Show answerHide answer

    Correct answer: Disk level

    Full-disk encryption works at the disk level: the entire physical drive, including the operating system, swap and free space, is encrypted as one unit, so a lost laptop reveals nothing. Volume level encryption protects one logical volume and can leave other volumes on the same drive readable. File container level encryption protects only what is stored inside one encrypted container file. File system level encryption protects the files and directories within one mounted file system, not the raw drive beneath it.

  48. A developer needs to protect sensitive fields in a payment system but must keep the data format and length identical so legacy applications still function. Which technique BEST meets this requirement?

    • A.Segmentation
    • B.Tokenization
    • C.Sanitization
    • D.Minimization
    Show answerHide answer

    Correct answer: Tokenization

    Tokenization swaps each sensitive value for a surrogate of the same type and length, so a legacy application that expects a fixed-length field keeps working while the real value sits in a separate vault. Segmentation isolates parts of a network and does nothing to the field itself. Sanitization destroys data so that it cannot be recovered, which is the opposite of keeping it usable. Minimization reduces how much data is collected in the first place and cannot preserve a format that has to stay exactly as it is.

  49. A security analyst hides a confidential message inside the least significant bits of an image file so its very existence is concealed. Which technique is being used?

    • A.Steganography
    • B.Watermarking
    • C.Covert channel
    • D.Obfuscation
    Show answerHide answer

    Correct answer: Steganography

    Steganography hides a message inside a carrier file, such as the least significant bits of an image, so an observer never knows the message exists. Watermarking also embeds data in an image, but its purpose is to mark ownership, not to conceal a secret message. A covert channel hides communication by abusing a channel never meant for data transfer, such as timing or protocol fields, rather than a file. Obfuscation makes data or code hard to understand, without hiding that it is there.

  50. An organization wants hardware-based protection that securely stores cryptographic keys on a motherboard and supports measured boot for individual endpoints. Which technology is designed for this purpose?

    • A.HSM
    • B.KMS
    • C.TPM
    • D.TEE
    Show answerHide answer

    Correct answer: TPM

    A TPM, or trusted platform module, is a chip bound to a system board that holds keys in hardware and stores the measurements a machine takes as it boots, which is precisely the per-endpoint function described. An HSM, or hardware security module, is a separate tamper-resistant appliance sized for enterprise key operations rather than a component of one laptop. A KMS, or key management system, is software that tracks key lifecycles across an estate and stores nothing on a motherboard. A TEE, or trusted execution environment, is an isolated region inside a processor for running sensitive code and does not supply boot measurements.

  51. A company must perform thousands of high-volume cryptographic operations and securely manage keys at enterprise scale using a dedicated, tamper-resistant appliance. Which solution is MOST appropriate?

    • A.Hardware security module
    • B.Secure enclave processor
    • C.Software defined network
    • D.Virtual desktop platform
    Show answerHide answer

    Correct answer: Hardware security module

    A hardware security module is the dedicated, tamper-resistant appliance built for this workload: bulk cryptographic operations and centralized key custody for a whole organization, with private keys that never leave the device in the clear. A secure enclave processor isolates a small region inside one chip to protect one device's sensitive code. A software defined network abstracts routing and switching and performs no key custody. A virtual desktop platform delivers user sessions from a server and has nothing to do with cryptographic throughput.

  52. A team is concerned that future quantum computers could break their current public-key algorithms. Which approach directly addresses this concern?

    • A.Migrating to lengthened RSA modulus sizes
    • B.Migrating to elliptic curve key exchanges
    • C.Migrating to quantum random key material
    • D.Migrating to quantum resistant primitives
    Show answerHide answer

    Correct answer: Migrating to quantum resistant primitives

    Migrating to quantum resistant primitives, such as the lattice-based algorithms NIST has standardized, replaces the factoring and discrete-log mathematics that Shor's algorithm breaks. Lengthened RSA modulus sizes only raise the cost slightly, because Shor's algorithm still factors them efficiently. Elliptic curve key exchanges rely on the discrete-log problem and fall to the same quantum attack. Quantum random key material improves randomness, but keys used with a breakable public-key algorithm remain breakable.

  53. An application stores user passwords by adding a unique random value to each password before hashing it. What is the PRIMARY security benefit of adding this unique random value per user?

    • A.It repeats costly derivation rounds so guessing cannot finish early
    • B.It breaks prebuilt hashing tables so attackers cannot reuse digests
    • C.It demands longer mixed passphrases so cracking cannot succeed soon
    • D.It blocks repeated failed logins so scripts cannot continue probing
    Show answerHide answer

    Correct answer: It breaks prebuilt hashing tables so attackers cannot reuse digests

    A unique per-user salt makes every stored digest different even when two people pick the same password, so an attacker's prebuilt table of password-to-digest pairs, a rainbow table, matches nothing and would have to be rebuilt for every account separately. Repeating costly derivation rounds is key stretching, which slows an attacker but leaves one precomputed table covering every unsalted account. Demanding longer mixed passphrases raises the cost of guessing without changing how the stored value is formed. Blocking repeated failed logins limits online guessing and has no effect on an offline attack against a stolen hash file.

  54. In a zero trust architecture, which control plane component continuously adjusts a user's access requirements based on signals such as device posture, location, and behavior during an active session?

    • A.Policy administrator, a common security label
    • B.Adaptive identity, a routine security concept
    • C.Implicit trust, a familiar security construct
    • D.Threat intelligence, a known security element
    Show answerHide answer

    Correct answer: Adaptive identity, a routine security concept

    Adaptive identity is the zero trust control-plane function that keeps re-evaluating context, including device health, geolocation, time and behavioral patterns, and raises or lowers what the user must satisfy as that context shifts inside a live session. The policy administrator establishes and tears down the session once a decision has already been reached, so it executes rather than weighs signals. Implicit trust is the assumption zero trust is built to remove, not a component that performs work. Threat intelligence supplies external indicators about adversaries and sits outside the access decision path.

Threats, Vulnerabilities, and Mitigations (100)

  1. Which of the following is a type of malware that requires user interaction to activate and replicate, often disguised as legitimate software?

    • A.Rootkit, whose code hides below the host kernel
    • B.Worm, whose code scans each nearby subnet alone
    • C.Ransomware, whose code locks up the local files
    • D.Trojan, whose code sits within a wanted upgrade
    Show answerHide answer

    Correct answer: Trojan, whose code sits within a wanted upgrade

    A Trojan is malware wrapped inside something the victim wants to install, so the victim runs it themselves and grants it their own privileges. Rootkit is wrong because a rootkit's defining trait is concealment beneath the operating system once access already exists, not disguise at the point of delivery. Worm is wrong because a worm propagates on its own across the network and needs no user to launch it. Ransomware is wrong because it is named for what its payload does, encrypting files for extortion, not for how it reaches the host.

  2. Which type of attack involves flooding a target system with traffic to exhaust resources and bandwidth, rendering the system unresponsive?

    • A.MAC flooding, which overflows a switch's CAM tables
    • B.Broadcast storm, which loops frames across a switch
    • C.Fork bomb, which exhausts the host's process table
    • D.Volumetric DDoS, which saturates a slow core uplink
    Show answerHide answer

    Correct answer: Volumetric DDoS, which saturates a slow core uplink

    Volumetric DDoS, which saturates a slow core uplink, floods the target from many sources until bandwidth and resources run out and the system stops responding. MAC flooding also sends a flood of frames, but its goal is to make a switch fail open so traffic can be sniffed. A broadcast storm is a switching loop caused by misconfiguration, not a targeted attack. A fork bomb exhausts a host's process table locally and needs no network traffic at all.

  3. What is the primary purpose of a 'zero-day' exploit in cybersecurity?

    • A.To strike a software flaw the vendor has not spotted
    • B.To restore the lost files from an offline backup set
    • C.To rank an asset by its likely full replacement cost
    • D.To rotate a shared key on a strict calendar schedule
    Show answerHide answer

    Correct answer: To strike a software flaw the vendor has not spotted

    A zero-day exploit targets a weakness the software vendor does not yet know about, so no patch or signature exists and defenders have had zero days to prepare. Restoring lost files from an offline backup is a recovery control used after an incident, not an attack technique. Ranking an asset by replacement cost belongs to business impact analysis and risk assessment. Rotating a shared key on a schedule is routine key management, which limits the damage of a compromised key rather than exploiting anything.

  4. In the context of cybersecurity, what is 'social engineering'?

    • A.Mining staff profiles on social media for recon
    • B.Monitoring staff to catch leaks of company data
    • C.Reviewing staff access to catch misuse of data
    • D.Tricking staff into giving up their own secrets
    Show answerHide answer

    Correct answer: Tricking staff into giving up their own secrets

    Social engineering means tricking staff into giving up their own secrets or taking actions they should not, using persuasion, authority, urgency or familiarity to exploit people rather than technology. Mining staff profiles on social media for recon is open-source intelligence gathering, which may prepare an attack but does not itself manipulate anyone. Monitoring staff to catch leaks of company data is a data loss prevention and insider-threat control run by defenders. Reviewing staff access to catch misuse of data is an access review or audit, also a defensive control rather than an attack on people.

  5. What type of cyber attack involves intercepting and altering communications between two parties without their knowledge?

    • A.Replay attack, which resends those captured frames
    • B.Downgrade attack, which selects a weaker handshake
    • C.Dictionary attack, which guesses at common secrets
    • D.MitM attack, which secretly relays entire messages
    Show answerHide answer

    Correct answer: MitM attack, which secretly relays entire messages

    In a man-in-the-middle, or on-path, attack the attacker positions themselves between two communicating parties and passes messages along, so both sides believe they are talking directly while the attacker can read or modify everything in transit. A replay attack re-sends previously captured traffic later and does not sit in the live conversation. A downgrade attack pushes the parties onto weaker cryptography, which is a step toward interception rather than the interception itself. A dictionary attack guesses secrets from a word list and touches no live session.

  6. Which type of attack is characterized by the insertion or "injection" of a SQL query via the input data from the client to the application?

    • A.LDAP injection, which rewrites the input filters
    • B.SQL injection, which reaches the backend records
    • C.Command injection, which runs input in the shell
    • D.Stored XSS, which saves input script to SQL rows
    Show answerHide answer

    Correct answer: SQL injection, which reaches the backend records

    SQL injection, which reaches the backend records, is the attack in which client input is concatenated into a database statement so the attacker's text is parsed as part of the SQL query itself. LDAP injection also abuses unsanitised input, but it alters a directory search filter, not a SQL statement. Command injection passes input to an operating system shell rather than a database engine. Stored XSS may be saved in a database table, but the payload is script that runs in a victim's browser, and it never changes the meaning of a query.

  7. What is a 'buffer overflow' attack in the context of cybersecurity?

    • A.Reading past a heap buffer to leak key bytes
    • B.Reusing heap memory after a process freed it
    • C.Injecting code into another process's memory
    • D.Writing beyond a buffer into adjacent memory
    Show answerHide answer

    Correct answer: Writing beyond a buffer into adjacent memory

    A buffer overflow is writing beyond a buffer into adjacent memory: the program copies more data than the allocation holds, overwriting neighbouring values such as a return address. Reading past a heap buffer to leak key bytes is a buffer over-read, the Heartbleed class, which discloses memory without overwriting it. Reusing heap memory after a process freed it is a use-after-free flaw. Injecting code into another process's memory is process or DLL injection, which uses legitimate APIs rather than overrunning an allocation.

  8. In cybersecurity, what does 'phishing' primarily refer to?

    • A.Phoning a user as fake IT support to wheedle a login
    • B.Baiting a user with faked mail for their credentials
    • C.Poisoning DNS so a user lands on a cloned login page
    • D.Infecting a site a user group visits to seize logins
    Show answerHide answer

    Correct answer: Baiting a user with faked mail for their credentials

    Phishing means baiting a user with faked mail for their credentials: a fraudulent message impersonates a trusted sender and pushes the recipient to hand over a login or personal data. Phoning a user while posing as IT support is vishing, the voice channel rather than mail. Poisoning DNS so a user lands on a cloned login page is pharming, which redirects traffic without any lure message. Infecting a site that a user group visits is a watering hole attack, which waits for victims instead of mailing them.

  9. Which type of cybersecurity attack involves exploiting vulnerabilities in web applications by sending malicious scripts to end users?

    • A.Cross-site request forgery, which abuses logins
    • B.Server-side request forgery, which abuses hosts
    • C.Cross-site scripting, which runs in the browser
    • D.SQL injection, which rewrites a web app's query
    Show answerHide answer

    Correct answer: Cross-site scripting, which runs in the browser

    Cross-site scripting, which runs in the browser, is correct: a vulnerable web application delivers attacker-supplied script to other users, and it executes in their browsers under the site's origin. Cross-site request forgery abuses a user's logged-in session to send forged requests, but no attacker script runs in the page. Server-side request forgery makes the server itself fetch internal hosts. SQL injection rewrites the back-end database query and targets the server, not end users.

  10. What kind of attack involves the unauthorized interception and retransmission of a valid data transmission, often to bypass authentication processes?

    • A.Replay, which re-sends a recorded user logon exchange
    • B.Smurf, which reflects broadcast pings across a subnet
    • C.Typosquat, which registers a store name spelled wrong
    • D.Evil twin, which impersonates a trusted wireless link
    Show answerHide answer

    Correct answer: Replay, which re-sends a recorded user logon exchange

    In a replay attack the attacker captures a legitimate authentication exchange and transmits it again later, so a system that accepts the repeated message treats the attacker as the original user; timestamps, sequence numbers and nonces exist to defeat exactly this. Smurf is wrong because it amplifies broadcast ICMP echo traffic to deny service, not to reuse a credential. Typosquatting is wrong because it registers look-alike domain names to catch mistyped visits. An evil twin is wrong because it impersonates a wireless network to attract new associations rather than repeating a captured transmission.

  11. In cybersecurity, what is 'vishing'?

    • A.Texting a fake bank alert to harvest card PINs
    • B.Porting a victim's phone number onto a new SIM
    • C.Phoning a target to extract secret PIN details
    • D.Sending a fake bank email to harvest card PINs
    Show answerHide answer

    Correct answer: Phoning a target to extract secret PIN details

    Vishing is voice phishing, so phoning a target to extract secret PIN details is the correct description: the attacker uses a voice call and a pretext to talk the victim out of sensitive data. Texting a fake bank alert is smishing, the SMS form of the attack. Porting a victim's phone number onto a new SIM is SIM swapping, which hijacks the number rather than deceiving anyone in a call. Sending a fake bank email is ordinary email phishing.

  12. Which type of cybersecurity threat involves exploiting a flaw in software before a patch or solution is implemented?

    • A.N-day exploit, which hits after a fix is released
    • B.Zero-day attack, which lands before any fix exists
    • C.Legacy exploit, which hits systems no vendor fixes
    • D.Supply chain attack, which rides a vendor's update
    Show answerHide answer

    Correct answer: Zero-day attack, which lands before any fix exists

    A zero-day attack, which lands before any fix exists, is the threat defined by exploiting a flaw before a patch or solution is available. An N-day exploit targets a flaw that is already publicly known and patched, hitting systems that have not yet applied the fix. A legacy exploit targets end-of-life systems that the vendor no longer supports, which is a support problem rather than a race against a pending patch. A supply chain attack hides malicious code inside a trusted vendor update.

  13. What is the main difference between a virus and a worm in the context of cybersecurity threats?

    • A.A virus needs a human click; a worm moves alone
    • B.A virus copies itself; a worm needs a host file
    • C.A virus spreads by email; a worm spreads by USB
    • D.A virus spreads by USB; a worm spreads by email
    Show answerHide answer

    Correct answer: A virus needs a human click; a worm moves alone

    A virus needs a human click; a worm moves alone: a virus runs only when someone opens the infected file or program, while a worm copies itself across the network with no user action. Saying a worm needs a host file reverses the classic distinction, since it is the virus that attaches to a host file and the worm that is standalone. Tying viruses to email and worms to USB drives, or the reverse, confuses delivery channels with the defining propagation difference, since both can travel either way.

  14. What is the primary purpose of 'watering hole' attacks in cybersecurity?

    • A.To poison a site the target group really trusts
    • B.To flood a link with garbage until it collapses
    • C.To duplicate a badge for entry past a turnstile
    • D.To crack a passphrase hash from a rainbow table
    Show answerHide answer

    Correct answer: To poison a site the target group really trusts

    In a watering hole attack the adversary cannot reach the intended victims directly, so it compromises a legitimate third-party site those victims are known to visit and waits for them to infect themselves. Flooding a link until it collapses is denial of service, aimed at availability rather than at a chosen group. Duplicating a badge is a physical access attack against an entry point. Cracking a passphrase hash from a rainbow table is an offline credential attack. Only the poisoned trusted site selects its victims by who visits it.

  15. In the context of cybersecurity, what is 'spear phishing'?

    • A.A cloned copy of a real mail the staff once got
    • B.A crafted mail aimed at one named senior person
    • C.A cloned login page linked in a fake text alert
    • D.A poisoned site that the target group frequents
    Show answerHide answer

    Correct answer: A crafted mail aimed at one named senior person

    Spear phishing is targeted: the attacker researches a specific person, then sends a crafted mail aimed at one named senior person that only makes sense for that recipient. A cloned copy of a real mail the staff once got is clone phishing, defined by copying a legitimate message. A cloned login page linked in a fake text alert is smishing. A poisoned site that the target group frequents is a watering hole attack, which waits for victims instead of messaging them.

  16. What type of cyber attack uses multiple compromised systems to target a single system, causing a Denial of Service (DoS)?

    • A.Reflected DoS, which bounces replies off servers
    • B.Botnet DDoS, which aims many hosts at one target
    • C.SYN flood, which swamps a target with half-opens
    • D.Amplified DoS, which prompts large DNS responses
    Show answerHide answer

    Correct answer: Botnet DDoS, which aims many hosts at one target

    A botnet DDoS, which aims many hosts at one target, is the attack that uses multiple compromised systems to overwhelm a single victim. A reflected DoS bounces replies off third-party servers that are spoofed into responding, not compromised. A SYN flood swamps a target with half-open connections and can be launched from a single host. An amplified DoS abuses services that return large DNS responses to small queries, relying on innocent resolvers rather than a botnet.

  17. Which type of attack involves an attacker relaying messages between two parties, making them believe they are talking directly to each other?

    • A.Man-in-the-middle, which sits between two live peers
    • B.Replay attack, which re-sends captured traffic later
    • C.Session hijack, which takes over a logged-in session
    • D.Eavesdropping, which captures the traffic off a wire
    Show answerHide answer

    Correct answer: Man-in-the-middle, which sits between two live peers

    Man-in-the-middle, which sits between two live peers, is the attack that relays each message so both parties believe they are talking directly while the attacker reads or alters the traffic. A replay attack re-sends captured traffic later instead of relaying a live exchange. A session hijack takes over one side of a logged-in session, so the victim is cut out rather than fooled into talking through the attacker. Eavesdropping passively captures traffic and never relays or forwards any messages.

  18. In cybersecurity, what does 'ransomware' do?

    • A.Mines crypto using your CPU for a payout
    • B.Fakes an infection to sell you a cleanup
    • C.Encrypts your files for a ransom payment
    • D.Steals your saved passwords for a payout
    Show answerHide answer

    Correct answer: Encrypts your files for a ransom payment

    Ransomware encrypts your files for a ransom payment, withholding the decryption key and often threatening to publish stolen copies until the victim pays. Mining cryptocurrency on a victim's CPU is cryptojacking, which uses the word crypto but locks nothing. Faking an infection to sell a cleanup is scareware. Stealing saved passwords for resale is an infostealer, which takes credentials without holding files hostage.

  19. What is the main goal of a 'rootkit' in terms of cybersecurity threats?

    • A.To hide inside a wanted app until a user runs it
    • B.To open a remote way in that bypasses the logins
    • C.To keep hidden admin control of a target machine
    • D.To quietly record every key the user types on it
    Show answerHide answer

    Correct answer: To keep hidden admin control of a target machine

    A rootkit exists to keep hidden admin control of a target machine, hooking or replacing operating system components so its files, processes and connections stay invisible to administrators and security tools. Hiding inside a wanted app until a user runs it describes a Trojan. Opening a remote way in that bypasses the logins is a backdoor, which grants access but is not defined by kernel-level concealment. Quietly recording every key the user types is a keylogger.

  20. Which technology is essential for securing a network against Zero Day exploits?

    • A.A pattern scanner tuned to spot known malware
    • B.A packet filter set to block unapproved ports
    • C.A behaviour engine alert to odd host activity
    • D.A backup vault isolated from the main network
    Show answerHide answer

    Correct answer: A behaviour engine alert to odd host activity

    Behaviour-based detection is what catches a zero-day, because a zero-day has no published signature by definition: detection has to come from what the code does rather than what it looks like, such as anomalous process creation, unexpected outbound connections, memory injection or privilege changes. A pattern scanner can only match malware it already knows and is blind to a new exploit. A packet filter enforces port rules and cannot judge behaviour. An isolated backup vault helps recovery after an incident but prevents nothing.

  21. Which cryptographic attack involves attempting to decrypt a cipher by trying every possible key?

    • A.Rainbow table lookup
    • B.Brute force recovery
    • C.Padding oracle abuse
    • D.Session token replay
    Show answerHide answer

    Correct answer: Brute force recovery

    Brute force recovery is the attack that simply walks the entire key space, testing candidate keys one after another until the ciphertext decrypts to something meaningful; only key length makes it impractical. A rainbow table lookup reverses stored password hashes using precomputed chains, not cipher keys. Padding oracle abuse reads a server's padding error responses to peel off plaintext without ever guessing a key. Session token replay reuses a captured token and defeats no cipher at all.

  22. Which of the following best describes a man-in-the-middle attack in the context of cryptography?

    • A.An attacker records a link's traffic for replay
    • B.An attacker taps a link's traffic to decrypt it
    • C.An attacker sits between two peers to pass data
    • D.An attacker hijacks a session to pose as a peer
    Show answerHide answer

    Correct answer: An attacker sits between two peers to pass data

    An attacker sits between two peers to pass data is the man-in-the-middle position: each party believes it is talking to the other while the attacker relays, reads and can alter the traffic. Recording traffic to resend later is a replay attack and needs no position in the live exchange. Tapping a link to decrypt captured traffic is passive eavesdropping followed by cryptanalysis, with nothing relayed. Hijacking a session takes over one side of it after login rather than sitting between both peers.

  23. A help-desk analyst is asked to define malware for a new-hire onboarding deck. Which description most accurately captures what malware is?

    • A.Software that copies itself to spread over a network
    • B.Software bundled into an installer to show pop-up ads
    • C.Software used to scan or probe a network for flaws
    • D.Software built to damage a computer or steal its data
    Show answerHide answer

    Correct answer: Software built to damage a computer or steal its data

    Software built to damage a computer or steal its data is the accurate definition, because malware is defined by its malicious intent, whatever form it takes. Software that copies itself to spread over a network describes a worm, which is one type of malware, not the definition of the whole category. Software bundled into an installer to show pop-up ads is adware, a potentially unwanted program. Software used to scan or probe a network for flaws is a vulnerability scanner, a legitimate assessment tool.

  24. An employee receives a text message claiming to be from the company's IT department, urging them to click a link to 'reverify' their VPN credentials. What type of attack is this?

    • A.Pharming attacks
    • B.Smishing tactics
    • C.Whaling campaign
    • D.Vishing attempts
    Show answerHide answer

    Correct answer: Smishing tactics

    Smishing is phishing delivered by text message: the lure arrives as an SMS and pushes the target to a link or a phone number to surrender credentials. Pharming does not send a message at all; it corrupts name resolution so a correctly typed address lands on the attacker's server. A whaling campaign targets a senior executive, usually by email, and this employee is not one. Vishing is carried out over a live voice call rather than in writing.

  25. A finance manager gets a phone call from someone claiming to be the company's bank, using urgency and an official-sounding script to extract account verification details. This social-engineering technique is best described as which of the following?

    • A.Pretexting calls
    • B.Whaling phone calls
    • C.Vishing callbacks
    • D.Spear phishing
    Show answerHide answer

    Correct answer: Vishing callbacks

    A live phone call from someone impersonating the bank to extract account details is voice phishing, so vishing callbacks is the best description. Pretexting calls use an invented story, but pretexting names the fabricated scenario, not the voice channel the question emphasizes. Whaling phone calls target senior executives such as the CEO, not a finance manager. Spear phishing is a targeted message, normally email, rather than a live voice call.

  26. A security team detects an intruder who maintained covert access to the network for eight months, moving laterally and exfiltrating intellectual property in small amounts to avoid detection. This pattern is most characteristic of which threat?

    • A.Random ransomware outbreak
    • B.Advanced persistent threat
    • C.Automated worm propagation
    • D.Delayed logic-bomb payload
    Show answerHide answer

    Correct answer: Advanced persistent threat

    An advanced persistent threat is defined by exactly this profile: a well-resourced adversary that gains a foothold, stays hidden for months, moves laterally, and steals data slowly enough to stay under detection thresholds. A ransomware outbreak announces itself immediately because encrypting files is the goal. Worm propagation is automatic and noisy, spreading as fast as the network allows. A logic bomb waits for a trigger and then fires once; it does not roam a network for months.

  27. An attacker crafts an email that appears to come from a specific manager and is addressed to one named employee in accounting, referencing a real recent project. What type of attack is this?

    • A.Whaling attack email
    • B.Clone phishing email
    • C.Pretexting attack email
    • D.Spear phishing email
    Show answerHide answer

    Correct answer: Spear phishing email

    A spear phishing email is written for one named recipient, impersonates a real internal sender and cites genuine context such as a recent project so it survives scrutiny. A whaling attack email is spear phishing aimed specifically at a senior executive; here the target is an accounting employee, and it is the manager who is impersonated. A clone phishing email copies a legitimate message the victim already received and swaps in a malicious link or attachment, which the scenario does not describe. A pretexting attack email relies on an invented scenario to justify a request; the real project reference supports the lure, but the attack type defined by targeting one named person is spear phishing.

  28. A CEO receives a highly personalized fraudulent email impersonating a board member and requesting an urgent confidential wire transfer. Because the target is a senior executive, this attack is specifically classified as which of the following?

    • A.Whaling email lures
    • B.Spear phishing email lures
    • C.Clone phishing email lures
    • D.Impersonation email lures
    Show answerHide answer

    Correct answer: Whaling email lures

    Whaling email lures are phishing aimed specifically at senior executives such as a CEO, often requesting confidential wire transfers. Spear phishing is personalized phishing against any chosen individual; whaling is the executive-targeted subset, and the stem classifies it by the target's seniority. Clone phishing resends a copy of a legitimate message with a malicious link swapped in. Impersonation describes the pretext used, not the classification that comes from targeting an executive.

  29. A fraudulent message impersonating a vendor instructs an accounts-payable clerk to change the bank account on file so future invoice payments are redirected to the attacker. This scheme is best described as which of the following?

    • A.Malicious cache poisoning
    • B.Stored cross-site scripts
    • C.Business email compromise
    • D.Targeted rainbow cracking
    Show answerHide answer

    Correct answer: Business email compromise

    Business email compromise is the fraud in which an attacker impersonates a trusted counterparty over email to reroute legitimate payments, and vendor bank-detail changes are its most common form. Cache poisoning corrupts resolver records to misdirect traffic and sends no invoice instruction. Stored cross-site scripts run in a visitor's browser from a vulnerable page. Rainbow cracking reverses stolen password hashes and plays no part in redirecting a payment.

  30. Before launching an attack, an adversary calls an employee while posing as a new auditor and invents a detailed backstory to justify requesting system access. The fabricated scenario the attacker uses is known as what?

    • A.Quiet tailgating entry
    • B.Pretexting cover story
    • C.Watering hole planting
    • D.Sudden privilege climb
    Show answerHide answer

    Correct answer: Pretexting cover story

    Pretexting is the invention of a believable scenario and false identity that gives the attacker a reason to ask for what they want, and posing as an auditor with a detailed backstory is a standard version of it. Tailgating is following someone through a controlled door. Watering hole planting seeds malware on a site the targets already trust. Privilege escalation happens after access is obtained and describes gaining higher rights, not the story used to gain entry.

  31. A user reports that their banking passwords were stolen even though they never visited a malicious site. Investigation reveals software that silently records every keystroke and emails the log to an external server. What is this software?

    • A.Keylogger implant
    • B.Form-grabber module
    • C.Screen-capture module
    • D.Clipboard-logger module
    Show answerHide answer

    Correct answer: Keylogger implant

    A keylogger implant records every keystroke the victim types and sends the log to the attacker, which explains how banking passwords were stolen without any malicious site being visited. A form-grabber module captures the contents of web forms as they are submitted in the browser, not every keystroke typed across the system. A screen-capture module takes images of the display, so it records what is shown rather than the keys pressed. A clipboard-logger module saves only text that is copied and pasted, so typed passwords never pass through it.

  32. A user installs a free utility that secretly monitors browsing habits and transmits personal data to an advertiser without consent. Which type of malware best describes this?

    • A.An adware installer
    • B.A keystroke logger
    • C.A spyware collector
    • D.A browser hijacker
    Show answerHide answer

    Correct answer: A spyware collector

    A spyware collector is the best description because the utility covertly monitors browsing habits and transmits personal data to a third party without consent. An adware installer delivers unwanted advertisements; it may accompany spyware, but its defining trait is displaying ads, not harvesting data. A keystroke logger captures typed input such as passwords. A browser hijacker changes the home page or search settings to redirect the user rather than quietly reporting their habits.

  33. A current employee with legitimate database access copies the customer list before resigning to join a competitor. What category of threat does this represent?

    • A.Negligent insider leak
    • B.Shadow IT data leak
    • C.Hacktivist data theft
    • D.Trusted insider misuse
    Show answerHide answer

    Correct answer: Trusted insider misuse

    This is trusted insider misuse: the employee already holds legitimate access and deliberately uses it for an unapproved purpose before leaving. A negligent insider leak is accidental exposure with no intent, whereas copying the list on the way to a competitor is deliberate. A shadow IT data leak comes from staff using unapproved services, not from abusing sanctioned access. Hacktivist data theft is driven by an outside actor's cause, not by a departing employee's personal gain.

  34. A piece of malware is engineered to hide at the operating-system kernel level, intercepting system calls so that its files and processes are invisible to standard antivirus tools. What is this malware?

    • A.Rootkit driver
    • B.Adware toolbar
    • C.Trojan bundles
    • D.Botnet beacons
    Show answerHide answer

    Correct answer: Rootkit driver

    A rootkit installs at the deepest privilege level available and hooks system calls so that its own files, processes and registry entries are filtered out of any answer the operating system gives; that is why ordinary scanners see nothing. An adware toolbar is visible by design and shows unwanted advertising. Trojan bundles hide inside software the user chose to install but do not subvert the kernel. Botnet beacons call home for orders and hide traffic, not the kernel.

  35. A vulnerability has been discovered and exploited in the wild, but the software vendor is not yet aware of it and no patch exists. What is this vulnerability called?

    • A.N-day exploited defect
    • B.Zero-day software flaw
    • C.Known exploited defect
    • D.Embargoed software bug
    Show answerHide answer

    Correct answer: Zero-day software flaw

    A zero-day software flaw is being exploited while the vendor is still unaware of it, so no patch exists and signature-based defenses have nothing to match. An N-day exploited defect is attacked after public disclosure, when the vendor already knows and a fix usually exists. A known exploited defect, such as an entry in CISA's KEV catalog, is likewise already disclosed to the vendor. An embargoed software bug has been reported privately to the vendor under coordinated disclosure, so the vendor is aware.

  36. A web application checks whether a user has permission to access a file and then opens it as two separate steps. An attacker exploits the brief gap between the check and the use to swap the file. This class of vulnerability is known as what?

    • A.A downgrade rollback
    • B.A precomputed lookup
    • C.A memory-leak defect
    • D.A race-condition bug
    Show answerHide answer

    Correct answer: A race-condition bug

    A race condition of the time-of-check to time-of-use kind arises because the security decision and the action on the resource are separate operations, and anything that changes between them is not re-validated. A downgrade rollback forces a weaker protocol version during negotiation. A precomputed lookup reverses hashes from a prepared table. A memory-leak defect exhausts resources over time and involves no window between a check and its use.

  37. An attacker uses an automated tool to try every possible password combination against a login until one succeeds. What is this attack called?

    • A.Credential stuffing
    • B.Mask-based attack
    • C.Brute-force crack
    • D.Hybrid attack
    Show answerHide answer

    Correct answer: Brute-force crack

    Trying every possible combination until one works is a brute-force crack, which searches the entire keyspace and only length and lockout limits slow it. Credential stuffing replays username and password pairs leaked from another breach. A mask-based attack tries only combinations that fit a known pattern, such as a capital letter followed by six digits. A hybrid attack takes dictionary words and appends or substitutes characters, so neither covers every possible combination.

  38. An attacker attempts to gain access to an account by trying a precompiled list of common words and known passwords rather than every possible combination. Which attack is this?

    • A.Password spraying
    • B.Dictionary attack
    • C.Pass-the-hash run
    • D.Rainbow-table hit
    Show answerHide answer

    Correct answer: Dictionary attack

    A dictionary attack draws from a prepared list of real words and previously leaked passwords, which succeeds quickly against human-chosen credentials while testing a tiny fraction of the possible combinations. Password spraying tries a few very common passwords against many accounts instead of many passwords against one. Pass-the-hash reuses a stolen hash without ever recovering the password. A rainbow-table hit reverses captured hashes offline rather than guessing at a login.

  39. An attacker obtains a database of password hashes and uses a large set of precomputed hash-to-plaintext tables to reverse them quickly. What technique is being used, and what control best defeats it?

    • A.Dictionary attack, blocked by fast account lockout
    • B.Credential stuffing, blocked by new device binding
    • C.Rainbow table lookups, blocked by randomized salts
    • D.Password spraying, blocked by login rate throttles
    Show answerHide answer

    Correct answer: Rainbow table lookups, blocked by randomized salts

    Precomputed hash-to-plaintext tables are the signature of rainbow table lookups, and a unique random salt per password defeats them because the attacker's tables were built for unsalted input and would have to be rebuilt for every salt. A dictionary attack guesses words live rather than reversing a stolen hash file. Credential stuffing replays credentials leaked from another site. Password spraying tries a few common passwords widely; none of those three uses precomputed tables.

  40. An attacker inserts a malicious database command into a web form's input field to read and modify records the application should not expose. This attack and its primary mitigation are best described as which of the following?

    • A.XSS scripting, stopped by strict output encoding
    • B.ARP poisoning, stopped by dynamic ARP inspection
    • C.CSRF attacks, stopped by per-session form tokens
    • D.SQL injection, stopped by bound query parameters
    Show answerHide answer

    Correct answer: SQL injection, stopped by bound query parameters

    Placing database syntax into an input field so the server executes it is SQL injection, and bound query parameters fix it at the root by sending the statement and the data separately so user input can never become code. Cross-site scripting puts browser script into a page rather than commands into a database. ARP poisoning misdirects traffic on the local link. Cross-site request forgery rides a victim's existing session; none of those three is a database command.

  41. An attacker injects a malicious script into a vulnerable web page so that the script executes in the browsers of other visitors, stealing their session cookies. What is this attack?

    • A.Stored cross-site scripting
    • B.Reflected cross-site scripting
    • C.DOM-based cross-site scripting
    • D.Cross-site request forgery
    Show answerHide answer

    Correct answer: Stored cross-site scripting

    Stored cross-site scripting saves the attacker's script in the vulnerable page itself, so it executes in the browser of every later visitor and can steal their session cookies. Reflected cross-site scripting echoes the script back from a crafted request, so it only runs for a victim who clicks that specific link rather than for other visitors of the page. DOM-based cross-site scripting is triggered by client-side code processing attacker-controlled input such as a URL fragment, again requiring the victim to load a crafted link. Cross-site request forgery makes a logged-in victim's browser send an unwanted request to a site; it rides the session rather than injecting script to steal cookies.

  42. An attacker registers the domain 'gooogle-login.com' hoping users who mistype the real address will land on a fake credential-harvesting page. This technique is known as what?

    • A.A typosquatting lure
    • B.A homograph spoofing
    • C.A DNS pharming trick
    • D.A DNS hijacking ploy
    Show answerHide answer

    Correct answer: A typosquatting lure

    The attacker is relying on a typosquatting lure: registering a near-miss spelling of a popular domain so users who slip on the keyboard land on the fake page. A homograph spoof uses lookalike Unicode characters in a link the victim clicks, not a typing mistake. DNS pharming poisons resolution so the correct name leads to a fake site. DNS hijacking seizes control of the real domain's registration or resolver instead of registering a new name.

  43. An attacker corrupts the cached records of a DNS resolver so that users requesting a legitimate banking site are silently redirected to a malicious server. What is this attack called?

    • A.ARP address spoofing
    • B.TLS cipher downgrade
    • C.SSL stripping attack
    • D.DNS record poisoning
    Show answerHide answer

    Correct answer: DNS record poisoning

    Corrupting the entries a resolver has cached is DNS poisoning: the resolver hands out the attacker's address for a legitimate name, so the victim's browser goes to the wrong server while the address bar still looks correct. ARP spoofing works at the local link layer using hardware addresses. A cipher downgrade forces weaker negotiated protection. SSL stripping removes the upgrade to an encrypted session; none of those three rewrites cached name records.

  44. A piece of malware lies dormant on a server until a specific condition is met, such as a particular date or the deletion of an employee's account, at which point it deletes critical files. Which threat does this describe?

    • A.A Trojan horse
    • B.A wiper
    • C.A logic bomb
    • D.A backdoor
    Show answerHide answer

    Correct answer: A logic bomb

    A logic bomb is code that sits inert until a defined condition, such as a date or an account deletion, is met, and only then fires its payload. A Trojan horse is defined by disguising itself as wanted software, not by a trigger. A wiper describes a destructive payload, but the defining feature here is the dormant conditional trigger. A backdoor waits for an attacker to connect and grants access rather than deleting files on a condition.

  45. A device ships with numerous unnecessary preinstalled applications that consume resources and expand the attack surface without the user's request. What does this describe?

    • A.Shadow IT
    • B.Bloatware
    • C.Sideloading
    • D.Insecure defaults
    Show answerHide answer

    Correct answer: Bloatware

    Bloatware is the pile of unrequested applications a manufacturer preloads: it consumes storage, memory and battery and adds code that must be patched, widening the attack surface. Shadow IT is hardware or software that staff adopt without approval, not something the device ships with. Sideloading is a user installing apps from outside the official store. Insecure defaults are weak factory settings such as open services or default passwords, rather than a collection of preinstalled apps.

  46. Which characteristic best distinguishes fileless malware from traditional malware?

    • A.It encrypts stored volumes and demands anonymous payment
    • B.It occupies volatile memory and abuses approved binaries
    • C.It hooks internal routines and conceals active processes
    • D.It saturates adjacent subnets and generates fresh copies
    Show answerHide answer

    Correct answer: It occupies volatile memory and abuses approved binaries

    Fileless malware never drops an executable on disk: it lives in memory and does its work through binaries the operating system already trusts, such as PowerShell or WMI, so a scanner looking for a malicious file finds nothing to match. Encrypting stored volumes and demanding anonymous payment describes ransomware. Hooking internal routines to conceal active processes describes a rootkit. Saturating adjacent subnets while generating fresh copies describes a worm.

  47. An organization discovers that malicious code was inserted into a software update from a trusted third-party vendor before it was distributed to customers. Which type of attack is this?

    • A.Watering hole attack
    • B.On-path attack
    • C.Supply chain attack
    • D.Code injection attack
    Show answerHide answer

    Correct answer: Supply chain attack

    A supply chain attack compromises a trusted supplier so malicious code reaches customers through a channel they already trust, such as a poisoned vendor update. A watering hole attack compromises a website the targets visit, not a vendor's build. An on-path attack tampers with traffic in transit, whereas this code was inserted before distribution. A code injection attack feeds malicious input to a running application rather than subverting the vendor's release.

  48. A vulnerability arises because an application checks a resource's state and then acts on it in two separate steps, allowing an attacker to alter the resource between the check and the use. What is this flaw called?

    • A.Race condition
    • B.Path traversal
    • C.Stack smashing
    • D.Type confusion
    Show answerHide answer

    Correct answer: Race condition

    This is a race condition, specifically a time-of-check to time-of-use flaw: the resource is validated in one step and used in another, and an attacker who alters it in between gets the benefit of a check that no longer describes reality. Path traversal abuses unsanitized file paths to escape the intended directory. Stack smashing overruns a buffer in order to overwrite a saved return address. Type confusion makes code treat an object as a type it is not.

  49. An attacker exploits a flaw to write code into a running process's memory space and execute it, hijacking the program's control flow. Which vulnerability category does this represent?

    • A.Code obfuscation
    • B.Cookie poisoning
    • C.Domain shadowing
    • D.Memory injection
    Show answerHide answer

    Correct answer: Memory injection

    Memory injection is the vulnerability category for writing code into the address space of a live process and then executing it, which lets the attacker seize the program's control flow from inside a trusted process. Code obfuscation hides the meaning of code from an analyst; it does not place code inside another running process. Cookie poisoning alters session data held in the browser, so it never touches process memory. Domain shadowing creates hidden subdomain records under a hijacked DNS account, which is a name-resolution abuse rather than an in-process execution flaw.

  50. Which attack derives secret information by measuring physical characteristics such as power consumption, electromagnetic emissions, or timing rather than breaking the algorithm directly?

    • A.Firmware implantation
    • B.Side-channel analysis
    • C.Credential harvesting
    • D.Directory enumeration
    Show answerHide answer

    Correct answer: Side-channel analysis

    Side-channel analysis recovers a secret by measuring what the hardware leaks while it computes - power draw, electromagnetic emission or elapsed time - so the mathematics of the cipher is never attacked at all. Firmware implantation writes attacker code into a device's boot image, which changes the device rather than measuring it. Credential harvesting collects passwords from users or stores and yields no information about key material inside a chip. Directory enumeration lists accounts and objects in a directory service and reveals nothing about physical emissions.

  51. A web server is left with default administrative credentials and unnecessary services enabled, allowing easy compromise. Which vulnerability does this represent?

    • A.Certificate mismanagement
    • B.Continuous authentication
    • C.Insufficient segmentation
    • D.Security misconfiguration
    Show answerHide answer

    Correct answer: Security misconfiguration

    Security misconfiguration is the weakness introduced when a system is deployed with its factory administrative account intact and services running that nobody needs, because the settings - not the code - create the exposure. Certificate mismanagement covers expired, untracked or wrongly issued certificates, none of which is implied by unused services being enabled. Insufficient segmentation describes flat networking that lets an intrusion spread, which is a containment failure after compromise. Continuous authentication is a control that re-verifies a session over time, so it names a defence rather than the weakness the server carries.

  52. A user removes the manufacturer's software restrictions on a smartphone to install unauthorized applications, increasing the device's exposure to malware. What is this action commonly called?

    • A.Unknown sources
    • B.USB debugging
    • C.Jailbreaking
    • D.Shadow IT
    Show answerHide answer

    Correct answer: Jailbreaking

    Jailbreaking removes the manufacturer's software restrictions on a smartphone, typically an iPhone, so unsigned and unauthorized applications can run, widening malware exposure. Unknown sources is an Android setting the vendor provides for installing apps from outside the official store; turning it on uses the platform's own controls rather than removing them. USB debugging is a built-in developer option that lets a connected computer issue commands while the platform's protections stay in place. Shadow IT is staff using unsanctioned apps or services without approval, an organizational problem rather than a change to the device's operating system.

  53. An attacker sends unsolicited messages to nearby Bluetooth-enabled devices. Which attack is this?

    • A.Sideloading
    • B.Bluejacking
    • C.Bluebugging
    • D.Obfuscation
    Show answerHide answer

    Correct answer: Bluejacking

    Bluejacking is the nuisance technique of pushing unrequested messages to Bluetooth devices that are in range and discoverable; nothing is read from the target and nothing is controlled. Sideloading installs an application from outside the official store, which is a software-distribution problem rather than a radio-range message push. Bluebugging goes much further by taking command of the handset's functions over Bluetooth, so it is control rather than messaging. Obfuscation makes code or data hard to interpret and is not a way of contacting nearby devices.

  54. An attacker connects to a victim's Bluetooth device without authorization and copies contacts, messages, and files. Which attack is this?

    • A.Bluejacking
    • B.Bluesnarfing
    • C.Bluesmacking
    • D.Evil twin
    Show answerHide answer

    Correct answer: Bluesnarfing

    Bluesnarfing is the unauthorized pull of stored data such as contacts, messages and files from a Bluetooth device, so data theft over the radio link is its defining feature. Bluejacking sends unsolicited messages to nearby Bluetooth devices and copies nothing off them. Bluesmacking floods a Bluetooth device with oversized packets to knock it offline, a denial-of-service attack rather than theft. An evil twin is a rogue Wi-Fi access point that imitates a legitimate network, which is a wireless LAN attack, not a Bluetooth one.

  55. An attacker tries one or a few common passwords across many different user accounts to avoid triggering account lockouts. Which technique is this?

    • A.Password cracking
    • B.Password spraying
    • C.Dictionary attack
    • D.Credential stuffing attack
    Show answerHide answer

    Correct answer: Password spraying

    Password spraying tries one or a few common passwords against many accounts, so each account sees too few failures to hit its lockout threshold. Password cracking recovers plaintext from stolen hashes offline and never touches a live login. A dictionary attack runs a long wordlist against one account and trips lockout quickly. A credential stuffing attack replays username and password pairs leaked from another breach rather than guessing common passwords.

  56. What is the key difference between an online brute-force attack and an offline brute-force attack?

    • A.Offline attacks crack captured hashes, while online attacks probe live endpoints
    • B.Offline attacks need session cookies, while online attacks need encrypted tokens
    • C.Offline attacks recover symmetric keys, while online attacks recover public keys
    • D.Offline attacks disable audit alerts, while online attacks disable lockout rules
    Show answerHide answer

    Correct answer: Offline attacks crack captured hashes, while online attacks probe live endpoints

    An offline attack works on password hashes the attacker has already captured, running on equipment the attacker owns, so there is no lockout counter and no defender watching; an online attack submits each guess to the running authentication service, where rate limits, lockout policy and alerting all apply. Session cookies belong to an already authenticated user and are needed by neither form of guessing. Neither form recovers symmetric or public key material; both target the secret a user chose. And neither switches off audit alerting or lockout policy - the offline case simply never reaches the system where those controls live.

  57. An attacker floods a switch with forged MAC addresses to overflow its address table, causing it to broadcast traffic out all ports so the attacker can capture it. Which attack is this?

    • A.MAC spoofing
    • B.ARP cache poisoning
    • C.MAC flooding
    • D.DNS cache poisoning
    Show answerHide answer

    Correct answer: MAC flooding

    MAC flooding sends a switch so many forged source addresses that its address table overflows, after which the switch fails open and broadcasts frames out of every port for the attacker to capture. MAC spoofing forges a single address to impersonate one device and does not exhaust the table. ARP cache poisoning corrupts hosts' IP-to-MAC mappings to redirect traffic through the attacker, not through a broadcasting switch. DNS cache poisoning plants false name records in a resolver and has nothing to do with the switch's address table.

  58. An attacker sends forged ARP replies on a LAN to associate their MAC address with the default gateway's IP, intercepting victims' traffic. What is this attack?

    • A.ARP poisoning
    • B.ARP flooding
    • C.MAC flooding
    • D.MAC address spoofing
    Show answerHide answer

    Correct answer: ARP poisoning

    ARP poisoning sends forged ARP replies so the attacker's MAC address is cached against the gateway's IP address, putting the attacker on the path of victims' traffic. ARP flooding overwhelms hosts or a switch with a volume of ARP traffic rather than planting a false mapping. MAC flooding fills a switch's CAM table so it floods frames out of every port. MAC address spoofing changes the attacker's own hardware address to impersonate another device, which alone does not rebind the gateway's IP in victims' caches.

  59. A DDoS attack sends small DNS queries with a spoofed source address so that large DNS responses are directed at the victim. What is this technique called?

    • A.DNS amplification
    • B.DNS cache poisoning
    • C.DNS cache snooping
    • D.DNS query flood
    Show answerHide answer

    Correct answer: DNS amplification

    DNS amplification sends small queries carrying the victim's spoofed source address to open resolvers, so the much larger responses all land on the victim and exhaust its bandwidth. DNS cache poisoning plants false records in a resolver to redirect users, not to flood anyone. DNS cache snooping probes a resolver's cache to learn which domains its users visited, which is reconnaissance. A DNS query flood overwhelms a DNS server with direct queries and relies on no spoofed source or larger reply.

  60. Which DDoS variant targets a web application's resource-intensive functions, such as search or login, with seemingly legitimate requests rather than overwhelming raw bandwidth?

    • A.Application-layer flood
    • B.Bandwidth amplification
    • C.Infrastructure flooding
    • D.Reconnaissance scanning
    Show answerHide answer

    Correct answer: Application-layer flood

    An application-layer flood aims a modest number of well-formed requests at the costly parts of a web application - search, login, report generation - so the server exhausts its own processing and database capacity while the raw traffic volume stays unremarkable. Bandwidth amplification depends on multiplying response size to saturate a link, which is the volumetric behaviour the question excludes. Infrastructure flooding overwhelms lower-layer devices and circuits, again through sheer volume. Reconnaissance scanning maps hosts and services before an attack and is not a denial-of-service method.

  61. Security analysts notice an account logging in from New York and, twelve minutes later, from Tokyo. Which indicator of compromise does this represent?

    • A.Anonymous IP address
    • B.Leaked credentials
    • C.Impossible travel
    • D.Unfamiliar location
    Show answerHide answer

    Correct answer: Impossible travel

    Impossible travel is the indicator raised when one identity authenticates from two places no person could move between in the elapsed time, here New York and Tokyo twelve minutes apart. An anonymous IP address flags a sign-in through a VPN, proxy or Tor exit, which says nothing about the time between locations. Leaked credentials flags a password found in a breach dump, not two logins. An unfamiliar location flags a single sign-in from somewhere new; it is the twelve-minute gap, not the novelty of Tokyo, that makes this impossible travel.

  62. An administrator observes that a server's CPU and memory are pegged at near 100% with no legitimate workload to explain it. Which indicator of compromise does this best illustrate?

    • A.Out-of-cycle logging
    • B.Resource consumption
    • C.Unexplained lockouts
    • D.Certificate spoofing
    Show answerHide answer

    Correct answer: Resource consumption

    Resource consumption is the indicator of compromise in which processor, memory, storage or bandwidth is heavily used with no authorised workload to account for it, the pattern left by mining software or another unsanctioned process. Out-of-cycle logging describes log entries appearing at times that do not match the scheduled activity, which is a timing signal rather than a utilisation signal. Unexplained lockouts follow failed authentication against user accounts and appear in identity records, not in utilisation graphs. Certificate spoofing presents a fraudulent certificate to a client and surfaces as a trust error, leaving processor and memory untouched.

  63. Repeated failed authentication attempts that trigger many users being locked out can serve as an indicator of which activity?

    • A.Brute-force attack
    • B.Password spraying
    • C.Credential stuffing
    • D.Rainbow table
    Show answerHide answer

    Correct answer: Brute-force attack

    A brute-force attack is indicated when repeated failed logins lock out many users, because the attacker keeps guessing against each account until the lockout threshold trips. Password spraying is wrong because it tries one common password across many accounts precisely to stay under lockout thresholds. Credential stuffing is wrong because it replays username and password pairs leaked elsewhere, producing few failures per account. A rainbow table is wrong because it cracks stolen hashes offline on the attacker's own machine, so no login attempt or lockout is ever recorded.

  64. Which mitigation technique reduces a system's attack surface by disabling unnecessary services, closing unused ports, and removing default accounts?

    • A.Patching
    • B.Allow listing
    • C.Hardening
    • D.Segmentation
    Show answerHide answer

    Correct answer: Hardening

    Hardening is the mitigation that shrinks the attack surface by turning off services nobody needs, closing unused ports and deleting default accounts, so fewer entry points exist. Patching fixes known flaws in software that stays installed and removes nothing. Allow listing limits which applications may execute but leaves listening services, open ports and default accounts in place. Segmentation divides the network to contain traffic between zones rather than reducing what each system itself exposes.

  65. An organization divides its network into isolated zones so that a compromise in one zone cannot easily spread to others. Which mitigation technique is this?

    • A.Segmentation
    • B.Quarantining
    • C.Containment
    • D.Air gapping
    Show answerHide answer

    Correct answer: Segmentation

    Segmentation divides a network into separate zones with controlled paths between them, so a compromise in one zone cannot easily spread to the others. Quarantining moves a single suspect host or file away from everything else after it is flagged, rather than designing the whole network into zones. Containment is the incident response phase that limits an active incident, not a standing network design. Air gapping disconnects a system from all networks entirely, which removes connectivity instead of dividing a network into zones that still communicate.

  66. Which mitigation directly addresses known software vulnerabilities by applying vendor-released fixes in a timely, managed way?

    • A.Patch management
    • B.Change management
    • C.Change advisory board
    • D.Vulnerability scanning
    Show answerHide answer

    Correct answer: Patch management

    Patch management is the mitigation that applies vendor-released fixes to known vulnerabilities on a timely, managed schedule. Change management is wrong because it governs approval and rollback for any change, including patches, but does not itself obtain or apply fixes. A change advisory board is wrong because it is the group that reviews and approves proposed changes. Vulnerability scanning is wrong because it finds and reports known vulnerabilities, detecting the exposure without remediating it.

  67. Which mitigation ensures that data remains unreadable to attackers even if storage media or backups are stolen?

    • A.Data masking
    • B.Segmentation
    • C.Sanitization
    • D.Encryption
    Show answerHide answer

    Correct answer: Encryption

    Encryption keeps stored data unreadable to anyone without the key, so stolen drives or backup tapes expose nothing useful while the owner can still decrypt and use the data. Data masking hides values from users who view a display or a non-production copy, but the production data and its backups still hold the real values. Segmentation separates networks and systems to limit access, which offers no protection once the media itself is carried away. Sanitization wipes media at disposal, so it protects retired drives, not media in use that is stolen.

  68. An organization deploys continuous log collection and analysis to detect threats as they occur. Which mitigation strategy does this represent?

    • A.Threat hunting
    • B.Hardening
    • C.Isolation
    • D.Monitoring
    Show answerHide answer

    Correct answer: Monitoring

    Monitoring is the mitigation technique of continuously collecting and analyzing logs and other telemetry so that threats are detected as they occur. Threat hunting is a proactive, analyst-led search for hidden attackers based on a hypothesis, run periodically rather than as continuous log collection. Hardening reduces the attack surface by removing services and tightening configuration, which prevents rather than detects. Isolation moves a compromised or risky system away from the rest of the environment, which contains a threat after it is found.

  69. Which mitigation technique uses tools to detect and automatically correct deviations from an approved secure baseline across systems?

    • A.Configuration enforcement
    • B.Enterprise authentication
    • C.Microservice architecture
    • D.Infrastructure monitoring
    Show answerHide answer

    Correct answer: Configuration enforcement

    Configuration enforcement is the mitigation in which tooling compares each system against an approved secure baseline and puts back any setting that has drifted, so the estate is corrected automatically rather than by hand. Enterprise authentication describes how users prove identity to the network and leaves system settings untouched. Microservice architecture is a way of decomposing an application into small services and says nothing about baseline compliance. Infrastructure monitoring reports the deviation once it appears but takes no corrective action of its own.

  70. When an organization retires old equipment, securely wiping and destroying data-bearing media is part of which mitigation activity?

    • A.Data retention policy
    • B.Data loss prevention
    • C.Change management
    • D.Asset decommissioning
    Show answerHide answer

    Correct answer: Asset decommissioning

    Asset decommissioning is the mitigation activity that retires equipment and, as part of it, wipes, degausses or destroys data-bearing media so no residual data leaves with the hardware. A data retention policy sets how long records are kept but is not the retirement process for hardware. Data loss prevention monitors and blocks sensitive data leaving through live channels. Change management approves and records changes, but it does not itself sanitize retired media.

  71. An attacker abuses a flaw to gain higher permissions than originally granted, such as moving from a standard user to an administrator. What is this called?

    • A.Lateral movement
    • B.Pass-the-ticket attack
    • C.Pass-the-hash attack
    • D.Privilege escalation
    Show answerHide answer

    Correct answer: Privilege escalation

    Privilege escalation is abusing a flaw or weak setting to gain rights beyond those granted, such as a standard user becoming an administrator. Lateral movement pivots from one host to another, usually at the same privilege level. A pass-the-ticket attack replays a stolen Kerberos ticket, and a pass-the-hash attack reuses a stolen credential hash; both authenticate as an existing account rather than exploiting a flaw to raise the rights of the current account.

  72. An attacker reuses username and password pairs leaked from one breached site to log in to accounts on other sites. Which attack is this?

    • A.Directory traversal
    • B.Credential stuffing
    • C.Token impersonation
    • D.Volumetric flooding
    Show answerHide answer

    Correct answer: Credential stuffing

    Credential stuffing replays complete username and password pairs taken from one breach against unrelated services, and it succeeds because people reuse the same pair in several places. Directory traversal walks outside a web application's intended path to read files it should not serve, which requires no stolen credentials. Token impersonation reuses an access token already present on a compromised host, so no login pair is submitted anywhere. Volumetric flooding saturates a link with traffic and never attempts authentication at all.

  73. A malicious actor sets up a rogue wireless access point with the same SSID as a legitimate corporate network to lure users into connecting. Which attack is this?

    • A.Karma attack
    • B.Evil twin
    • C.Pharming
    • D.Disassociation
    Show answerHide answer

    Correct answer: Evil twin

    An evil twin is a rogue access point that copies a legitimate network's SSID so users connect to it instead of the real one. A Karma attack answers whatever SSIDs clients probe for from their saved lists rather than cloning one corporate SSID. Pharming redirects users to a fake site by poisoning DNS or hosts files, not with a wireless access point. Disassociation knocks clients off a network and is often paired with an evil twin but impersonates nothing.

  74. An attacker intentionally transmits radio interference to disrupt a wireless network's availability. What is this attack called?

    • A.Beacon flooding
    • B.Jamming
    • C.CTS flooding
    • D.Evil twin
    Show answerHide answer

    Correct answer: Jamming

    Deliberately transmitting radio interference to drown out a wireless channel is jamming, a physical-layer attack on availability. Beacon flooding sends thousands of fake network advertisements in valid 802.11 frames rather than raw noise. CTS flooding abuses clear-to-send control frames so stations defer transmitting, again using protocol frames, not interference. An evil twin is a rogue access point that impersonates a real network to intercept traffic rather than take it down.

  75. Which vulnerability arises when an application includes outdated open-source libraries or components with known flaws?

    • A.Hardcoded credentials
    • B.Outdated cryptography
    • C.Vulnerable components
    • D.Unencrypted transport
    Show answerHide answer

    Correct answer: Vulnerable components

    Vulnerable components is the weakness an application inherits when it ships with third-party libraries that carry publicly documented defects, because the flaw arrives with the dependency rather than with the code the team wrote. Hardcoded credentials are secrets embedded in source or firmware, which is a separate defect that no dependency update creates. Outdated cryptography means weak algorithms or key sizes remain in use and would apply even to code with no external libraries. Unencrypted transport exposes data on the wire and is a protocol choice, not a dependency problem.

  76. A cryptographic attack exploits the mathematics of hash collisions to find two different inputs that produce the same hash. Which attack is this?

    • A.Birthday attack
    • B.Fault injection
    • C.Banner grabbing
    • D.Buffer overflow
    Show answerHide answer

    Correct answer: Birthday attack

    A birthday attack uses the probability result behind the birthday problem to find two distinct inputs that hash to one digest far sooner than the digest length suggests, which is why it targets the collision resistance of a hash. Fault injection disturbs a device with voltage or clock glitches to make it compute incorrectly, so it attacks the hardware rather than the hash mathematics. Banner grabbing reads the version strings a service advertises and is a reconnaissance step. A buffer overflow writes past an allocated region in memory and has no connection to digest collisions.

  77. An attacker forces a secure connection to negotiate an older, weaker protocol or cipher that is easier to break. Which attack is this?

    • A.Downgrade attack
    • B.Replay attack
    • C.Birthday attack
    • D.Brute-force attack
    Show answerHide answer

    Correct answer: Downgrade attack

    A downgrade attack interferes with the handshake so both ends settle on an older protocol version or weaker cipher suite the attacker can then break. A replay attack resends captured valid traffic rather than changing what is negotiated. A birthday attack exploits hash collision probability, not protocol negotiation. A brute-force attack tries keys or passwords exhaustively, which a downgrade may make feasible but which is not the act of forcing the weaker choice.

  78. An attacker captures a user's password hash from memory and uses it to authenticate to other systems without ever cracking the plaintext password. Which attack is this?

    • A.Typosquatting
    • B.Kerberoasting
    • C.Pass-the-hash
    • D.Steganography
    Show answerHide answer

    Correct answer: Pass-the-hash

    Pass-the-hash submits a captured password hash straight to the authentication protocol, so the attacker reaches other systems without ever recovering the plaintext secret. Typosquatting registers misspelled domain names to catch mistyped traffic and involves no credential material. Kerberoasting requests service tickets and then cracks them offline, which is the very recovery of the plaintext that this technique avoids. Steganography conceals a message inside an innocuous file and is a hiding method with no authentication role.

  79. Which insider-related risk involves a trusted employee or partner being manipulated or coerced into aiding an attack without realizing the harm?

    • A.Malicious insider
    • B.Unintentional insider
    • C.Colluding insider
    • D.Disgruntled contractor
    Show answerHide answer

    Correct answer: Unintentional insider

    An unintentional insider is a trusted employee or partner who is manipulated or coerced into helping an attacker while unaware of the harm, so access is abused without intent. A malicious insider deliberately misuses access for personal gain or revenge. A colluding insider knowingly cooperates with an outside attacker. A disgruntled contractor acts out of a grievance against the organization, which also involves intent and awareness of the damage being done.

  80. After compromising one workstation, an attacker uses stolen credentials to access additional internal systems and expand their foothold. Which activity is this?

    • A.Domain shadowing
    • B.Packet capturing
    • C.Code obfuscation
    • D.Lateral movement
    Show answerHide answer

    Correct answer: Lateral movement

    Lateral movement is the stage in which an intruder who already holds one host reuses harvested credentials to reach further systems and widen the foothold inside the perimeter. Domain shadowing adds concealed records beneath a hijacked domain to support external infrastructure, which happens outside the victim network. Packet capturing records traffic for later analysis and gains no additional systems. Code obfuscation makes a payload harder for an analyst or scanner to read, so it protects the tooling rather than extending access.

  81. An IoT thermostat with hardcoded credentials and no patching capability introduces what kind of weakness in an enterprise environment?

    • A.Unsupported legacy firmware
    • B.Insecure default configuration
    • C.Vulnerable embedded device
    • D.Firmware supply chain risk
    Show answerHide answer

    Correct answer: Vulnerable embedded device

    A vulnerable embedded device is the weakness here: the thermostat's credentials are hardcoded and its software cannot be patched by design, so the flaw is permanent and built into the device itself. Unsupported legacy firmware describes code the vendor has stopped maintaining, not a device that was never patchable. An insecure default configuration can be changed by the owner, whereas hardcoded credentials cannot. A firmware supply chain risk concerns tampered or compromised components introduced before delivery, which the stem does not describe.

  82. An attacker on a local network sends forged Address Resolution Protocol replies that map the default gateway's IP address to the attacker's MAC address, causing victim traffic to be routed through the attacker's machine. Which attack is this?

    • A.Supply chain attack
    • B.Stolen token replay
    • C.Rogue DHCP spoofing
    • D.ARP cache poisoning
    Show answerHide answer

    Correct answer: ARP cache poisoning

    ARP cache poisoning floods the segment with falsified address-resolution replies so hosts store the attacker's hardware address against the gateway's network address and send their traffic to the attacker first. A supply chain attack compromises a supplier's product before delivery and needs no presence on the victim's local segment. Stolen token replay reuses a captured session token to impersonate a user at the application layer. Rogue DHCP spoofing hands out false addressing configuration to clients as they join, which subverts leases rather than the address cache.

  83. Security staff discover a wireless access point broadcasting the same SSID as the corporate network, set up by an attacker in the parking lot to trick employees into connecting and exposing their traffic. Which threat does this describe?

    • A.MAC spoofing
    • B.Evil twin
    • C.WPS attack
    • D.IV attack
    Show answerHide answer

    Correct answer: Evil twin

    An evil twin is a rogue access point advertising the same SSID as the corporate network so staff connect to the attacker's radio and expose their traffic. MAC spoofing forges a device's hardware address to bypass filtering or impersonate a client; it does not broadcast a lookalike network. A WPS attack brute-forces the Wi-Fi Protected Setup PIN on an existing router to recover its passphrase. An IV attack exploits reused initialization vectors to crack WEP keys rather than luring users to a fake access point.

  84. An attacker takes a single commonly used password, such as 'Spring2026!', and tries it against hundreds of different user accounts to avoid triggering account-lockout thresholds. Which attack is this?

    • A.Credential stuffing
    • B.Password cracking
    • C.Brute-force cracking
    • D.Password spraying
    Show answerHide answer

    Correct answer: Password spraying

    Password spraying tries one likely password once against many accounts, spreading the failures so thinly that no single account reaches its lockout threshold. Credential stuffing replays username and password pairs leaked from another breach, each pair tried against its own account rather than one common password across hundreds. Password cracking recovers plaintext from captured hashes offline and never submits logins. Brute-force cracking tries every possible combination, whether offline against hashes or online against one account, where it would trip the lockout the attacker is avoiding.

  85. A developer plants malicious code in an application that remains dormant until a specific condition is met, such as the developer's name being removed from the payroll database, at which point it deletes files. What is this threat?

    • A.Time bomb
    • B.Fork bomb
    • C.Logic bomb
    • D.Decompression bomb
    Show answerHide answer

    Correct answer: Logic bomb

    Code planted inside an application that waits for a condition, here the author's removal from payroll, and then deletes files is a logic bomb. A time bomb is the variant that fires on a specific date or time, while this trigger is an event rather than a clock. A fork bomb replicates processes until the host's resources run out and has no dormant trigger. A decompression bomb is an archive that expands to exhaust storage when opened.

  86. Investigators find malicious activity running entirely in memory using legitimate tools such as PowerShell, with no executable written to disk, making it difficult for traditional signature-based antivirus to detect. What type of attack is this?

    • A.Polymorphic malware
    • B.Firmware rootkit
    • C.Fileless malware
    • D.Kernel rootkit
    Show answerHide answer

    Correct answer: Fileless malware

    Fileless malware runs in memory and drives trusted built-in tools such as PowerShell, so no executable is written to disk for a signature engine to match. Polymorphic malware also evades signatures, but it does so by mutating a file on disk rather than avoiding disk altogether. A firmware rootkit persists by rewriting device or boot firmware, which is stored code rather than memory-only activity. A kernel rootkit hides by modifying the operating system, which requires installing a driver or module on the host.

  87. An adversary compromises a trusted software vendor and embeds malicious code into a routine product update, which is then distributed to thousands of downstream customers who trust the vendor's signed package. Which type of attack is this?

    • A.Watering hole attack, frequented portal poisoning
    • B.Password spraying attack, popular secret guessing
    • C.Supply chain attack, corrupted upstream packaging
    • D.Session hijacking attack, harvested cookie replay
    Show answerHide answer

    Correct answer: Supply chain attack, corrupted upstream packaging

    A supply chain attack subverts something the victim already trusts - the vendor, the build system or the update channel - so signed malicious code is delivered by the legitimate distribution path to every downstream customer at once. A watering hole compromises a third-party site the targets happen to browse, so it reaches only visitors of that site and never rides the vendor's own signature. Password spraying tries a few common secrets against many accounts and gains nothing from vendor trust. Session hijacking steals an already authenticated token from a live user and affects only that session.

  88. After gaining access to a standard user account, an attacker exploits a misconfigured service to obtain administrative rights on the same system. Which activity does this describe?

    • A.Privilege escalation, vertical entitlement widening
    • B.Lateral movement, unauthorized workstation crossing
    • C.Credential stuffing, harvested passphrase replaying
    • D.Backdoor installation, surviving restart durability
    Show answerHide answer

    Correct answer: Privilege escalation, vertical entitlement widening

    Privilege escalation is the vertical step: the attacker already holds a foothold and abuses a flaw or a misconfigured service to run with higher rights on that same machine. Lateral movement is the horizontal step to a different host and does not change the rights held. Credential stuffing replays passwords exposed in someone else's breach against other sites, which is an access technique rather than a rights change. Installing a backdoor keeps the access already obtained across reboots but grants no additional rights.

  89. An attacker manipulates a web application's file parameter by submitting '../../etc/passwd' to read files outside the intended web directory. What is this attack called?

    • A.Command injection, shell metacharacter chaining
    • B.Cross-site scripting, visitor browser execution
    • C.Buffer overflow, unchecked boundary overwriting
    • D.Directory traversal, relative pathname climbing
    Show answerHide answer

    Correct answer: Directory traversal, relative pathname climbing

    Directory traversal abuses a parameter that is used to build a file path: relative sequences such as ../ walk the attacker up and out of the intended directory so files elsewhere on the disk can be read. Command injection appends shell metacharacters so the server executes an extra operating system command; no path is walked. Cross-site scripting delivers markup that runs in another user's browser and never reaches the server file system. A buffer overflow writes past the end of an allocation and corrupts adjacent memory instead of resolving a path.

  90. A logged-in user is tricked into clicking a crafted link that causes their authenticated browser to submit an unwanted state-changing request, such as transferring funds, to a banking site without their intent. Which attack is this?

    • A.Clickjacking overlay attack, misleading display framing
    • B.Cross-site request forgery, unauthorized state changing
    • C.Session fixation reuse, predicted identifier implanting
    • D.Open redirect abuse, unvalidated destination forwarding
    Show answerHide answer

    Correct answer: Cross-site request forgery, unauthorized state changing

    Cross-site request forgery works because the browser attaches the victim's existing session automatically: a crafted link or form causes that browser to send a state-changing request, such as a transfer, which the site accepts as genuine. Clickjacking layers an invisible frame over a page so the victim clicks a control they cannot see, which requires the victim to act on the real interface. Session fixation plants an identifier the attacker already knows before the victim signs in, so the attacker rides the session rather than the victim's own request. An open redirect merely bounces a visitor to an unvalidated destination and changes no state on the trusted site.

  91. A laptop ships from the manufacturer with numerous preinstalled trial applications and utilities that the user did not request, consume resources, and may widen the attack surface. What are these programs collectively called?

    • A.Adware, bundled ad-injecting browser software
    • B.Spyware, hidden data-gathering tracking software
    • C.Bloatware, superfluous preloaded vendor software
    • D.Rootkit, hidden privileged kernel-level software
    Show answerHide answer

    Correct answer: Bloatware, superfluous preloaded vendor software

    The answer is bloatware, superfluous preloaded vendor software: the extra programs on a new machine, trial applications and utilities the user never requested that consume resources and widen the attack surface without being written to harm the owner. Adware is software built to display or inject advertisements; some preinstalled packages have included it, but the term names the advertising behaviour, not unrequested trial programs as a group. Spyware covertly gathers data about the user's activity and sends it elsewhere, which is surveillance rather than commercial clutter. A rootkit hides itself with privileged, often kernel-level access to conceal malicious activity, which is deliberate stealth rather than visible trial software.

  92. An attacker forces a secure communication session to negotiate an older, weaker protocol version, such as falling back from TLS 1.3 to SSL 3.0, in order to exploit known weaknesses. What type of attack is this?

    • A.SSL stripping attack, session traffic rewritten as HTTP
    • B.On-path attack, session traffic relayed between hosts
    • C.Replay attack, captured handshake messages resent later
    • D.Downgrade attack, constrained fallback cipher selection
    Show answerHide answer

    Correct answer: Downgrade attack, constrained fallback cipher selection

    Forcing both sides to fall back from TLS 1.3 to SSL 3.0 is a downgrade attack, constrained fallback cipher selection: the attacker tampers with version negotiation so a weak, exploitable protocol is chosen. An SSL stripping attack removes encryption entirely by rewriting HTTPS links to plain HTTP rather than negotiating an older protocol version. An on-path attack is the position an attacker needs to intercept traffic, not the specific act of forcing an older version. A replay attack resends captured messages later and does not change the negotiated protocol.

  93. An organization continues running a server operating system that the vendor no longer supports, meaning no further security patches are released for newly discovered flaws. Which vulnerability does this represent?

    • A.End-of-life legacy platform, terminated maintenance lifecycle
    • B.End-of-sale product status, discontinued purchase lifecycles
    • C.Unpatched known vulnerability, deferred patching cycle window
    • D.Zero-day vulnerability, unknown flaws awaiting patching cycle
    Show answerHide answer

    Correct answer: End-of-life legacy platform, terminated maintenance lifecycle

    The answer is end-of-life legacy platform, terminated maintenance lifecycle: once the vendor ends support, no patch will ever arrive for a newly found flaw, so every new weakness is permanent. End-of-sale only stops new purchases while security patches keep shipping. An unpatched known vulnerability has a released fix the owner has deferred, but here no fix exists. A zero-day is unpatched only until the vendor learns of it and ships a fix, which an unsupported product never receives.

  94. A penetration tester discovers that a network device is still using the credentials 'admin/admin' set by the manufacturer because they were never changed during deployment. Which vulnerability is this?

    • A.Hardcoded vendor credentials, embedded unchangeable accounts
    • B.Unchanged default credentials, provided administrative login
    • C.Weak password complexity, short and easily guessed passwords
    • D.Unpatched vendor firmware, not updated since the deployment
    Show answerHide answer

    Correct answer: Unchanged default credentials, provided administrative login

    The device still accepts the manufacturer's admin/admin pair because no one replaced it at deployment, which is unchanged default credentials, provided administrative login. Hardcoded vendor credentials are embedded in code and cannot be changed by the owner, whereas these could have been. Weak password complexity describes a policy that allows short guessable passwords, but the problem here is that the vendor's published login was never replaced. Unpatched vendor firmware is a missing update and says nothing about the login itself.

  95. A security analyst attributes a sophisticated, well-funded intrusion with long-term strategic objectives and stealthy persistence to a nation-state group. Which threat actor type best describes this adversary?

    • A.Competitive espionage threat, long-term hidden market spying
    • B.State-aligned hacktivist threat, recurring political protest
    • C.Organized crime threat, nation-tolerated long-term extortion
    • D.Nation-state persistent threat, sustained covert sponsorship
    Show answerHide answer

    Correct answer: Nation-state persistent threat, sustained covert sponsorship

    A nation-state persistent threat, backed by sustained covert sponsorship, has government funding, custom tooling and strategic goals pursued quietly over years, which matches both the attribution and the behavior described. Competitive espionage is carried out by a rival company for market advantage, and it is not what the analyst attributed. A state-aligned hacktivist wants publicity for a political cause, so its protests are loud rather than stealthy. Organized crime, even when a nation tolerates it, is driven by money and monetizes access quickly through extortion rather than holding it for strategic intelligence.

  96. To reduce the attack surface of a newly deployed server, an administrator removes unnecessary software, disables unused services and ports, and applies a secure baseline configuration. Which mitigation technique is being applied?

    • A.Network segmentation, isolating broadcast partition
    • B.Software sandboxing, confining unverified processes
    • C.System hardening, shrinking configuration footprint
    • D.Least privilege, restricting delegated entitlements
    Show answerHide answer

    Correct answer: System hardening, shrinking configuration footprint

    Hardening is the work of making one host present as little as possible: uninstall what is not needed, switch off services and listening ports, and apply the secure baseline so the remaining configuration is deliberate. Segmentation changes where a host sits on the network and limits what can reach it, but the host itself still runs everything it did before. Sandboxing confines a single untrusted process inside a restricted execution environment rather than trimming the platform. Least privilege limits what accounts may do once they are on the system and leaves the installed software untouched.

  97. An employee notices a USB cable left in a public charging station and connects their phone, unaware it is a malicious cable designed to inject keystrokes and exfiltrate data. Which attack vector does this best illustrate?

    • A.Weaponized USB peripheral, forged input controller
    • B.Rogue wired network, sniffed phone's USB tethering
    • C.Bluesnarf pairing, phone files taken via Bluetooth
    • D.Supply chain implant, factory-loaded phone spyware
    Show answerHide answer

    Correct answer: Weaponized USB peripheral, forged input controller

    The victim plugged in a cable that announces itself as a keyboard, types commands and copies data out, which is a weaponized USB peripheral, forged input controller, the removable-device vector. A rogue wired network with sniffed USB tethering only watches network traffic the phone shares, and it injects no keystrokes. Bluesnarfing pulls files over a Bluetooth pairing, with no cable involved at all. A supply chain implant is spyware loaded into the phone before it ever reaches the owner, not hardware the owner picks up at a charging station.

  98. Attackers compromise a niche industry news website that is frequently visited by employees of a target company, planting malware so that those employees become infected when browsing. What type of attack is this?

    • A.Watering hole attack, a common technique
    • B.Spear phishing attack, a targeted method
    • C.Malvertising attack, an ad-served method
    • D.Supply chain attack, a third-party route
    Show answerHide answer

    Correct answer: Watering hole attack, a common technique

    A watering hole attack, a common technique against well-defended targets, compromises a legitimate site the intended victims are known to visit and infects them when they browse it. Spear phishing is also targeted, but it reaches victims through crafted messages rather than a site they already visit. Malvertising delivers malware through ads served across many sites, not by compromising one niche site chosen for its audience. A supply chain attack compromises a vendor's product or service that the target installs or uses, not a news site its staff read.

  99. A developer's build system automatically pulls a package from a public repository because an internal package of the same name does not exist there, allowing an attacker who published a malicious public package to execute code. What attack does this describe?

    • A.Command injection, a routine exploit
    • B.Directory traversal, a common method
    • C.Buffer overflow, a familiar approach
    • D.Dependency confusion, a known tactic
    Show answerHide answer

    Correct answer: Dependency confusion, a known tactic

    Dependency confusion exploits a build tool that resolves package names against a public registry when an identically named internal package cannot be found privately, so an attacker who registers that name publicly gets code executed inside the build pipeline. Command injection passes shell metacharacters into an application that hands input to the operating system. Directory traversal walks outside the intended path to read files the application never meant to expose. A buffer overflow writes past the end of an allocation to corrupt adjacent memory, and none of these three involves how a package name is resolved.

  100. Malware injects itself into a user's browser process to silently capture and modify online banking transactions after the user has authenticated, even over an HTTPS session. Which threat best describes this?

    • A.Downgrade attack, a standardized approach
    • B.Replay attack, a well-documented maneuver
    • C.Man-in-the-browser attack, a known method
    • D.Typosquatting attack, a routine technique
    Show answerHide answer

    Correct answer: Man-in-the-browser attack, a known method

    A man-in-the-browser attack places malware inside the browser process itself, so it reads and rewrites transactions after the transport encryption has already been unwrapped and after the user has authenticated, which is exactly why an HTTPS session offers no protection against it. A downgrade attack forces a weaker protocol version or cipher suite during negotiation. A replay attack re-sends captured traffic to make an action happen a second time. A typosquatting attack registers misspelled domain names to catch users who mistype an address.

Security Architecture (82)

  1. What is the primary purpose of using a WAF (Web Application Firewall)?

    • A.To filter packets by port and by address on ingress
    • B.To filter the web pages staff browse on the way out
    • C.To scan the source code of a web app before release
    • D.To inspect the HTTP traffic headed to a live server
    Show answerHide answer

    Correct answer: To inspect the HTTP traffic headed to a live server

    A WAF exists to inspect the HTTP traffic headed to a live server, blocking injection, cross-site scripting and similar web attacks. Filtering packets by port and address at the edge is a network or stateful firewall, which cannot read application content. Filtering the web pages staff browse out to is a forward proxy or URL filter protecting users, not a web server. Scanning a web app's source code before release is static application security testing, which happens in development rather than on live traffic.

  2. In the context of network security, what is the main function of an IPS (Intrusion Prevention System)?

    • A.To log each suspect packet seen on a SPAN port
    • B.To page the analysts about each suspect packet
    • C.To pass traffic whose port is on an allow list
    • D.To block known attack traffic as it flows past
    Show answerHide answer

    Correct answer: To block known attack traffic as it flows past

    An IPS sits inline and its main function is to block known attack traffic as it flows past, dropping or resetting matching sessions itself. Logging suspect packets copied from a SPAN port is passive capture, and paging analysts about suspect packets is what an IDS does; neither stops anything. Passing traffic whose port is on an allow list is basic firewall filtering by port, not signature-based attack prevention.

  3. What is the primary security function of a UTM (Unified Threat Management) appliance?

    • A.To keep an offline copy of yesterday's data sets
    • B.To deliver an address to each machine when asked
    • C.To fold several security tools into a single box
    • D.To time-stamp a receipt so its place is provable
    Show answerHide answer

    Correct answer: To fold several security tools into a single box

    Unified threat management puts firewalling, intrusion prevention, gateway antivirus, web and content filtering, and often VPN termination into one appliance with a single management interface, which is why smaller sites adopt it instead of buying and operating separate devices. Keeping an offline copy of data is backup. Delivering an address to each machine on request is DHCP. Time-stamping a receipt so its place is provable is a non-repudiation control. None of those three consolidates multiple security functions.

  4. Which security technology is primarily used to inspect SSL/TLS encrypted traffic at the perimeter of a network?

    • A.Load balancer, which spreads jobs across servers
    • B.Interception proxy, which breaks the TLS session
    • C.Syslog server, which stores remote device events
    • D.Jump host, which screens the operator connection
    Show answerHide answer

    Correct answer: Interception proxy, which breaks the TLS session

    To read encrypted traffic at the perimeter the device must break the tunnel: the proxy terminates the client's TLS session using a certificate the endpoints already trust, inspects the plaintext, then opens its own TLS session onward to the real server. A load balancer distributes work for capacity and may terminate TLS, but it exists to spread load rather than to inspect content for threats. A syslog server stores records that devices send it and never touches the traffic itself. A jump host screens administrative access to internal systems and inspects nothing.

  5. What is the main function of a CASB (Cloud Access Security Broker)?

    • A.To apply one policy set across many cloud apps
    • B.To spin up more compute when new demand climbs
    • C.To hold the master keys inside a secure module
    • D.To charge each team for the resources it burns
    Show answerHide answer

    Correct answer: To apply one policy set across many cloud apps

    A cloud access security broker sits between users and the cloud services they use, so the organisation's own rules on authentication, data handling, sharing and shadow IT are enforced consistently on services it does not own or operate. Spinning up more compute when new demand climbs is autoscaling. Holding master keys inside a secure module is what an HSM does. Charging each team for what it consumes is cloud cost management. None of those three enforces security policy between users and cloud applications.

  6. What is the primary purpose of a Network Access Control NAC system?

    • A.To lease a fresh address to each new device
    • B.To admit a laptop after a fast health check
    • C.To send voice frames ahead of any bulk data
    • D.To keep a warm standby ready for a failover
    Show answerHide answer

    Correct answer: To admit a laptop after a fast health check

    Network access control evaluates a device as it joins, checking identity and health such as patch level, antivirus state and configuration, then grants full access, places it in a remediation segment or refuses it, according to policy. Leasing a fresh address to each new device is DHCP. Sending voice frames ahead of bulk data is quality of service. Keeping a warm standby ready is high availability. None of those three decides whether a device may join the network.

  7. In cybersecurity, what is the primary function of a Next-Generation Firewall (NGFW)?

    • A.To preserve a signed copy of each audit journal
    • B.To replace a failed uplink with a spare circuit
    • C.To scan a mailbox for unwanted bulk advert mail
    • D.To add threat rules to a stateful packet filter
    Show answerHide answer

    Correct answer: To add threat rules to a stateful packet filter

    A next-generation firewall keeps stateful packet filtering and adds integrated intrusion prevention, application awareness and identity awareness, so one policy can allow a named application for a named group while still inspecting that traffic for exploits. Preserving a signed copy of each audit journal is an integrity control. Replacing a failed uplink with a spare circuit is redundancy. Scanning a mailbox for unwanted bulk advertising is a mail gateway function. None of those three combines intrusion prevention with firewall filtering.

  8. In network security, what is the main function of an IDS (Intrusion Detection System)?

    • A.Alerting analysts about traffic matching a known attack signature
    • B.Alerting analysts about outbound files with a sensitive data label
    • C.Alerting analysts about inbound mail failing the sender SPF check
    • D.Alerting analysts about hosts missing a vendor's critical patches
    Show answerHide answer

    Correct answer: Alerting analysts about traffic matching a known attack signature

    An IDS is a passive sensor whose main function is alerting analysts about traffic matching a known attack signature or a behavioral anomaly. Alerting on outbound files with a sensitive data label is data loss prevention, which guards against exfiltration rather than detecting intrusions. Flagging inbound mail that fails the sender SPF record is an email security gateway check. Reporting hosts lacking critical patches is a vulnerability scanner's job, which finds weaknesses instead of watching for attacks.

  9. Which technology is primarily used for securing wireless networks?

    • A.TKIP
    • B.WPS
    • C.RADIUS
    • D.WPA2
    Show answerHide answer

    Correct answer: WPA2

    WPA2 is the Wi-Fi Alliance security standard that authenticates and encrypts a wireless network, using CCMP with AES, and it is what a wireless deployment relies on to protect traffic over the air. TKIP is the older encryption protocol from the original WPA, now deprecated, and it is a component rather than the network security technology. WPS is a convenience setup feature that pairs devices with a PIN or button and is itself a known weakness. RADIUS is an AAA protocol that WPA2-Enterprise can call for authentication, but it is not what secures the wireless link.

  10. In the context of secure network design, what is the primary purpose of a Demilitarized Zone (DMZ)?

    • A.Encrypting departing traffic flows across a shared carrier connection
    • B.Placing public facing services outside the trusted internal perimeter
    • C.Holding synchronized data copies within a secondary recovery facility
    • D.Storing regulated customer records inside a hardened database cluster
    Show answerHide answer

    Correct answer: Placing public facing services outside the trusted internal perimeter

    A DMZ is a screened segment between the untrusted internet and the internal LAN, so anything the outside world must reach lives there instead of on the internal network and a compromise of one of those hosts does not put the attacker inside. Encrypting a flow between two sites is a site-to-site VPN, which protects data in flight and creates no trust boundary. Keeping synchronized copies at a recovery facility is a backup and continuity control that restores service after a loss rather than limiting exposure. A DMZ is deliberately the least trusted zone in the architecture, which is exactly why regulated records belong on hardened internal storage and never in it.

  11. What is the primary function of a network-based Intrusion Detection System (NIDS)?

    • A.Dropping inline packets to stop suspected attacks before delivery
    • B.Checking host log files to flag changes to critical system files
    • C.Collecting flow records to report bandwidth use on each host link
    • D.Watching mirrored traffic to raise alerts about probable breaches
    Show answerHide answer

    Correct answer: Watching mirrored traffic to raise alerts about probable breaches

    The primary function of a NIDS is watching mirrored traffic to raise alerts about probable breaches: it is passive and detects rather than blocks. Dropping inline packets to stop suspected attacks is what an IPS does, because it sits in the traffic path and can intervene. Checking host log files and critical system files is a host-based IDS or file-integrity function, not a network sensor. Collecting flow records to report bandwidth use is NetFlow monitoring, which measures traffic volume rather than inspecting it for intrusions.

  12. In cloud computing, what is the primary security concern of a Multi-Tenancy environment?

    • A.Higher egress charges during large outbound archive transfers
    • B.Poor separation of stored records between neighboring tenants
    • C.Unpatched middleware inside a rarely rebooted guest appliance
    • D.Expired certificates on an internal management console portal
    Show answerHide answer

    Correct answer: Poor separation of stored records between neighboring tenants

    Multi-tenancy means several customers run on one shared pool of compute, storage and network, so the control that matters most is the boundary that stops one tenant reading, writing or inferring another tenant's data, enforced by the provider's hypervisor, storage layer and identity model. Charges for moving data out of a provider are a cost-model issue that exists on dedicated hosting too. Unpatched middleware in a guest is a genuine risk but it is the tenant's own vulnerability-management failure and it looks identical on single-tenant infrastructure. Expired certificates break trust in one management interface and are answered by certificate lifecycle management, which does nothing about tenant separation.

  13. In the context of virtualization security, what is the main purpose of a hypervisor?

    • A.Creating guest machines from pooled physical host resources
    • B.Scanning stored documents for signatures of current malware
    • C.Encrypting replicated snapshot images under a delegated key
    • D.Balancing storage requests across several linked disk pools
    Show answerHide answer

    Correct answer: Creating guest machines from pooled physical host resources

    A hypervisor owns the physical processor, memory, storage and network and hands each guest a virtual slice of them, creating, scheduling and isolating virtual machines; that mediation is the reason a compromise inside one guest does not automatically reach another. Scanning documents for current malware signatures is antimalware work carried out inside a guest or on a file server, above the virtualization layer. Encrypting replicated snapshot images protects a virtual machine at rest, a storage control applied to the hypervisor's output rather than a function of the hypervisor itself. Distributing storage requests across disk pools is a storage controller's job and creates no guests.

  14. What is the primary security function of a WAF (Web Application Firewall)?

    • A.Comparing IP packets with signatures to block known exploits
    • B.Inspecting inbound HTTP requests to block injection style attacks
    • C.Filtering outbound web requests to block known malicious websites
    • D.Scanning outbound network traffic to stop sensitive files leaking
    Show answerHide answer

    Correct answer: Inspecting inbound HTTP requests to block injection style attacks

    The primary function of a WAF is inspecting inbound HTTP requests to block injection style attacks such as SQL injection and cross-site scripting aimed at a web application. Comparing IP packets with signatures to block known exploits describes a network intrusion prevention system, which works across protocols rather than parsing application requests. Filtering outbound web requests to block known malicious websites is the job of a forward proxy or URL filter protecting users, not the application. Scanning outbound network traffic to stop sensitive files leaking is data loss prevention.

  15. In the context of cloud computing, what is the main purpose of a Cloud Access Security Broker CASB?

    • A.Filtering inbound web requests that target the firm's public web apps
    • B.Filtering outbound web browsing against URL categories and malware
    • C.Granting remote users per-application access to private internal apps
    • D.Enforcing company policy on traffic bound for outside hosted services
    Show answerHide answer

    Correct answer: Enforcing company policy on traffic bound for outside hosted services

    Enforcing company policy on traffic bound for outside hosted services is the core purpose of a CASB, which sits between users and cloud providers to give visibility into sanctioned and shadow cloud use and apply access and data-protection rules. Filtering inbound web requests that target the firm's public web apps is a web application firewall. Filtering outbound browsing by URL category and malware is a secure web gateway. Granting remote users per-application access to private internal apps is zero trust network access.

  16. What is the primary function of Secure Sockets Layer (SSL) / Transport Layer Security (TLS) in network security?

    • A.Encrypting every IP packet at the network layer between gateways
    • B.Encrypting stored files at rest inside secure hardware modules
    • C.Protecting data in transit using freshly negotiated session keys
    • D.Signing every email message end to end with a sender certificate
    Show answerHide answer

    Correct answer: Protecting data in transit using freshly negotiated session keys

    Protecting data in transit using freshly negotiated session keys is the job of TLS: the handshake authenticates the server by certificate and agrees a symmetric session key that encrypts and integrity-protects each record. Encrypting every IP packet at the network layer between gateways describes IPsec, not a transport-layer session. Encrypting stored files at rest inside secure hardware modules is data-at-rest protection. Signing every email message with a sender certificate is S/MIME, which protects the message rather than the connection.

  17. In cybersecurity, what is the primary purpose of employing containerization?

    • A.Running a full guest operating system upon one bare-metal server
    • B.Detonating a suspect file inside a disposable guest on one server
    • C.Separating each tenant into its own virtual network on one switch
    • D.Isolating a bundled application from nearby workloads on one host
    Show answerHide answer

    Correct answer: Isolating a bundled application from nearby workloads on one host

    Containerization exists for isolating a bundled application from nearby workloads on one host: the app ships with its libraries and runs under namespaces and control groups that limit what a compromise can reach. Running a full guest operating system upon one bare-metal server describes a virtual machine on a hypervisor, not a container sharing the host kernel. Detonating a suspect file inside a disposable guest is sandboxing for malware analysis. Separating tenants into virtual networks is network segmentation, which isolates traffic rather than packaged application processes.

  18. In network security, what is the main purpose of a VLAN (Virtual Local Area Network)?

    • A.Doubling the available uplink speeds between two neighboring switches
    • B.Splitting one switched fabric into separate logical broadcast domains
    • C.Encrypting traffic crossing a tagged link using preshared credentials
    • D.Mirroring copied packets toward an attached passive monitoring sensor
    Show answerHide answer

    Correct answer: Splitting one switched fabric into separate logical broadcast domains

    A VLAN divides one physical switch infrastructure into several independent broadcast domains, so ports in different VLANs cannot reach each other at layer 2 and traffic between them must pass a router or firewall where policy can be applied; the grouping follows function rather than cabling. Bonding links to raise available speed between two switches is link aggregation, a bandwidth measure that leaves every port in the same broadcast domain. Encrypting traffic on a tagged link is MACsec, which protects a link against eavesdropping without dividing it. Mirroring copies of packets to a sensor is a SPAN or tap configuration, which feeds monitoring tools and moves no forwarding boundary.

  19. What is the primary purpose of implementing an IDS (Intrusion Detection System) in tandem with an IPS (Intrusion Prevention System)?

    • A.Correlating alerts from many sensors and ranking them for the analyst
    • B.Spotting hostile attempts and blocking them inside one traffic stream
    • C.Launching playbooks from many sensors and quarantining hosts on alert
    • D.Filtering packets by port and IP address before they reach the server
    Show answerHide answer

    Correct answer: Spotting hostile attempts and blocking them inside one traffic stream

    Pairing an IDS with an IPS means spotting hostile attempts and blocking them inside one traffic stream: detection recognises the attack and the inline prevention engine drops or resets it. Correlating alerts from many sensors and ranking them for an analyst is the role of a SIEM. Launching playbooks that quarantine hosts is SOAR orchestration, acting after an alert rather than inline. Filtering packets by port and address is a basic firewall rule set, which does not inspect for attack content.

  20. Which technology is primarily used for isolating network traffic to improve security and performance in a virtualized environment?

    • A.SDN
    • B.NFV
    • C.NAC
    • D.VPN
    Show answerHide answer

    Correct answer: SDN

    Software-defined networking splits the control plane from the forwarding plane and hands path and policy decisions to a central controller, which is what lets a virtualized environment carve traffic into isolated segments programmatically and re-apply that isolation as workloads move. Network function virtualization moves appliances such as routers and load balancers onto commodity servers; it changes where a function runs rather than how traffic is separated. Network access control decides whether an endpoint may join at all, based on posture and identity, and it stops mattering once the device is admitted. A virtual private network builds an encrypted tunnel between two points across an untrusted path, which protects one conversation rather than partitioning a fabric.

  21. In a cloud computing environment, what is the primary security benefit of implementing microsegmentation?

    • A.Encrypting stored partitions so a stolen laptop reveals nothing usable
    • B.Signing container images so tampered builds fail their admission check
    • C.Rotating privileged secrets so a leaked credential expires within days
    • D.Limiting movement between individual workloads so a breach stays local
    Show answerHide answer

    Correct answer: Limiting movement between individual workloads so a breach stays local

    Microsegmentation applies policy at the level of the individual workload rather than the subnet, so each virtual machine or container is permitted only the specific east-west conversations it needs; an attacker who lands on one workload finds the neighboring ones closed, and lateral movement, the step that turns a foothold into a breach, is exactly what gets denied. Encrypting stored partitions protects data on a machine that leaves the building and does nothing about traffic between live workloads. Signing container images stops a tampered build from starting, a supply-chain control applied before runtime. Rotating privileged secrets shortens how long a leaked credential is useful, a credential-management measure that never constrains where an authenticated workload may connect.

  22. After a ransomware event, an organization restores from its most recent backup and discovers it lost roughly four hours of customer transactions. Which resilience metric describes the maximum amount of data, measured in time, that the organization is willing to lose?

    • A.The RTO target
    • B.The RPO figure
    • C.The MTTR timer
    • D.The MTBF value
    Show answerHide answer

    Correct answer: The RPO figure

    The recovery point objective states how much data, expressed as a span of time, the organization accepts losing in a disaster, and it therefore sets how often backups must run; a four-hour loss means the objective was four hours or the schedule missed it. The recovery time objective is about how quickly service must return, not how much data may vanish. Mean time to repair measures restoration effort. Mean time between failures measures reliability of a component.

  23. A business continuity team states that a critical order-entry application must be fully operational within two hours of any outage. Which metric does this two-hour target represent?

    • A.The MTBF gauge
    • B.The RPO window
    • C.The RTO target
    • D.The MTD budget
    Show answerHide answer

    Correct answer: The RTO target

    A deadline for having a service running again is the recovery time objective: it is the maximum period the business will tolerate between the outage starting and the application being usable once more. Mean time between failures describes how long hardware runs before it breaks. The recovery point objective describes acceptable data loss. Maximum tolerable downtime is the outer limit past which the business itself fails, and the recovery time objective is deliberately set inside it.

  24. A reliability engineer reports that a fleet of identical disk controllers has a mean time between failures of 100,000 hours. What does this MTBF value primarily help the organization predict?

    • A.How long a restoration of the failed unit takes
    • B.How long a fixable unit runs between two faults
    • C.How much of the newest data a recovery forfeits
    • D.How many spare units the vendor should hold now
    Show answerHide answer

    Correct answer: How long a fixable unit runs between two faults

    Mean time between failures is a reliability prediction for repairable equipment: it estimates the average span a unit will operate before the next fault, which is what drives maintenance intervals and spare-part planning. How long a restoration takes is mean time to repair. How much of the newest data a recovery forfeits is the recovery point objective. How many spares to hold is a procurement decision that the figure informs but does not state.

  25. An incident manager wants to track how long, on average, the operations team takes to restore a failed service after detecting an outage. Which metric should be reported?

    • A.The average time taken to restore one failed service
    • B.The average time from an outage until it is detected
    • C.The average time from an outage until another outage
    • D.The target for the longest outage to restore service
    Show answerHide answer

    Correct answer: The average time taken to restore one failed service

    The average time taken to restore one failed service is mean time to repair, the measured interval from detection to restoration that shows how effective the response is. The average time from an outage until it is detected is mean time to detect, which ends before repair starts. The average time from one outage until another is mean time between failures, a reliability figure. The target for the longest acceptable outage is the recovery time objective, a planned limit rather than a measured average.

  26. A web application experiences traffic spikes that overwhelm a single server. A security analyst recommends a device that distributes incoming requests across several backend servers and removes unhealthy nodes from rotation. Which technology is being described?

    • A.A forward proxy
    • B.A packet filter
    • C.A load balancer
    • D.A syslog server
    Show answerHide answer

    Correct answer: A load balancer

    A load balancer sits in front of a pool of servers, spreads incoming requests across them, and uses health checks to stop sending work to a node that has failed, which is exactly the behaviour described. A forward proxy brokers outbound requests on behalf of internal clients. A packet filter permits or denies traffic by header fields. A syslog server collects log messages centrally; none of those three distributes a workload across backend servers.

  27. A storage administrator configures four drives so that data and parity are striped across all of them, allowing the array to keep operating if any single drive fails. Which storage resilience technology is in use?

    • A.RAID 0 striped array
    • B.RAID 1 mirrored array
    • C.A JBOD spanned array
    • D.A RAID array
    Show answerHide answer

    Correct answer: A RAID array

    Striping data and parity across four drives so the set survives any single drive failure is a RAID array using parity, such as RAID 5, which rebuilds the lost blocks from parity. A RAID 0 striped array spreads data across drives with no parity, so one failed drive destroys the whole set. A RAID 1 mirrored array writes identical copies to paired drives instead of striping parity. A JBOD spanned array chains drives into one volume with no parity, so a lost drive loses its data.

  28. A network engineer needs administrators to reach internal production servers without exposing those servers directly to remote-access connections. The chosen design routes all administrative sessions through a single hardened, heavily monitored host. What is this host called?

    • A.A jump server
    • B.A relay agent
    • C.A proxy cache
    • D.A web gateway
    Show answerHide answer

    Correct answer: A jump server

    A jump server is a single hardened, closely monitored system that administrators connect to first and from which they reach protected hosts, so production systems never accept remote sessions directly. A relay agent forwards a specific protocol's messages between segments. A proxy cache stores retrieved content to serve it again quickly. A web gateway inspects and filters user browsing; none of those three is designed as the controlled entry point for administrative access.

  29. An organization handles personal data for European customers and must ensure that data is stored and processed according to the laws of the country where it physically resides, even when using a global cloud provider. Which concept governs this requirement?

    • A.Data controller
    • B.Data sovereignty
    • C.Data processor
    • D.Geographic restrictions
    Show answerHide answer

    Correct answer: Data sovereignty

    Data sovereignty is the principle that data is subject to the laws of the country where it is physically stored, so cloud regions must be chosen deliberately. A data controller is the party that decides why and how personal data is processed, and a data processor handles it on the controller's behalf; both are GDPR roles, not location rules. Geographic restrictions are access controls based on a user's location, not the legal jurisdiction over stored data.

  30. To prevent an industrial control system from being reached by malware spreading on the corporate network, engineers physically disconnect it from all other networks so there is no electronic path between them. Which protective measure is this?

    • A.Unidirectional gateway
    • B.Microsegmentation
    • C.Screened subnet
    • D.Air-gap isolation
    Show answerHide answer

    Correct answer: Air-gap isolation

    Air-gap isolation physically disconnects the system from every other network, so no electronic path exists for malware to cross. A unidirectional gateway still links the networks, only restricting traffic to one direction. Microsegmentation applies fine-grained policy between workloads on a connected network. A screened subnet is a buffer zone between trusted and untrusted networks that remains reachable by design.

  31. A company wants remote employees and branch offices to reach cloud applications securely while applying consistent inspection and zero trust access policies from the cloud, converging SD-WAN with security functions such as SWG, CASB, and ZTNA. Which architecture best fits this goal?

    • A.The NGFW model
    • B.The MPLS model
    • C.The SASE model
    • D.The SIEM model
    Show answerHide answer

    Correct answer: The SASE model

    Secure access service edge is the architecture that folds network connectivity and security controls into one cloud-delivered service, so remote users and branches receive the same inspection and zero trust policy wherever they connect from. A next-generation firewall is an appliance model that backhauls remote traffic to a data centre. A multiprotocol label switching network provides transport with no security stack. A security information and event management platform analyses logs after the fact.

  32. A remote worker needs to access internal corporate resources over the public internet as though directly on the office LAN. The solution creates an encrypted tunnel between the worker's device and the corporate gateway. Which technology provides this?

    • A.A virtual private network (VPN) solution
    • B.A secure shell (SSH) port-forward tunnel
    • C.A transport layer security (TLS) tunnel
    • D.A software-defined WAN (SD-WAN) solution
    Show answerHide answer

    Correct answer: A virtual private network (VPN) solution

    A virtual private network (VPN) solution builds an encrypted tunnel from the remote device to the corporate gateway, placing the device on the internal network as though it were cabled to the office LAN. An SSH port-forward tunnel encrypts traffic but carries only the specific ports forwarded, not full network access. A TLS tunnel protects one application connection at a time rather than joining the device to the LAN. An SD-WAN solution links branch sites across carrier circuits rather than connecting an individual remote worker's device.

  33. A security architect is designing a site-to-site connection and wants a protocol suite that authenticates and encrypts IP packets, supporting both an authentication-only mode and an encrypting mode using ESP. Which protocol suite meets this need?

    • A.The SMTP electronic mail protocol
    • B.The IPsec packet protection suite
    • C.The SNMPv3 network device monitor
    • D.The NetBIOS local session service
    Show answerHide answer

    Correct answer: The IPsec packet protection suite

    IPsec secures IP itself: the Authentication Header gives integrity and origin authentication with no encryption, while Encapsulating Security Payload adds confidentiality, and because it works at the network layer every protocol above it inherits the protection. That is exactly what a site-to-site tunnel needs. SMTP only relays mail between servers and carries no packet-level cryptography of its own. SNMPv3 polls and receives traps from managed devices; it protects its own management messages and leaves the rest of the traffic untouched. NetBIOS session service sets up legacy name-based sessions and has no authentication or encryption capability whatsoever.

  34. A network administrator wants to require that any device plugging into a switch port must authenticate to a RADIUS server before being granted network access, using EAP for the authentication exchange. Which standard provides this port-based access control?

    • A.The IEEE 802.1Q frame identification standard
    • B.The IEEE 802.1AE hardware encryption standard
    • C.The IEEE 802.1X supplicant admission standard
    • D.The IEEE 802.1AB adjacency discovery standard
    Show answerHide answer

    Correct answer: The IEEE 802.1X supplicant admission standard

    802.1X defines port-based network access control: the connecting device acts as a supplicant, the switch acts as authenticator, and EAP carries the exchange to a RADIUS server, which decides whether the port is opened for general traffic. It is the foundation most network access control deployments are built on. 802.1Q inserts a VLAN tag into the Ethernet frame so a trunk can identify which VLAN a frame belongs to, which is segmentation rather than authentication. 802.1AE encrypts frames hop by hop once a link is already trusted. 802.1AB lets a device advertise itself so neighbours can be mapped.

  35. A bank wants its public-facing payment service to remain reachable even if an entire data center loses power. Which architectural approach BEST meets this requirement?

    • A.Duplicated power supplies, isolated facility protection
    • B.Multiple availability zones, geographic site redundancy
    • C.Mirrored storage arrays, single-room volume duplication
    • D.Nightly offsite backups, delayed restoration capability
    Show answerHide answer

    Correct answer: Multiple availability zones, geographic site redundancy

    High availability at site level means the workload already runs in more than one physically separate location, so losing an entire building removes capacity but not the service. Redundant feeds and generators harden one building against one class of failure and still leave that building as the single point of failure. Mirrored arrays duplicate a volume inside the same room, so they survive a disk, not a site. Backups are a recovery mechanism measured in hours: the data survives, but the payment service is down while someone restores it.

  36. An organization wants to run a workload without managing the underlying operating system, patching, or server capacity, paying only for execution time. Which cloud model BEST fits this need?

    • A.Infrastructure hosting service, tenant patched instances
    • B.Private hypervisor cluster, self operated virtualization
    • C.Colocation cabinet leasing, customer maintained hardware
    • D.Serverless function platform, event triggered invocation
    Show answerHide answer

    Correct answer: Serverless function platform, event triggered invocation

    In a serverless model the unit of deployment is a function that the provider runs on demand: there is no guest operating system for the customer to patch, no capacity to size, and the meter runs only while the code executes. Infrastructure as a service hands over the virtual machine but the tenant still owns the guest operating system and its patch cycle. A privately run hypervisor cluster leaves the customer operating the virtualization layer as well. Colocation is only floor space, power and cooling, so the customer still buys, racks and maintains the hardware.

  37. A security architect wants to provision identical, repeatable cloud environments and track every configuration change in version control. Which approach BEST achieves this?

    • A.Machine snapshots, replicated appliance blueprints
    • B.Written runbooks, sequential operator instructions
    • C.Infrastructure code, versioned declarative recipes
    • D.Advisory boards, periodic authorization gatherings
    Show answerHide answer

    Correct answer: Infrastructure code, versioned declarative recipes

    Infrastructure as code turns the environment itself into a file: a declarative template that can be diffed, reviewed and rolled back like source, so two deployments from the same commit are identical and every change carries an author and a reason. A machine snapshot reproduces one host but not the network, identity and policy around it, and the image itself is a binary that version control cannot meaningfully diff. A written runbook still depends on a human performing the steps correctly each time. An advisory board records approval for a change, which is governance rather than reproducible provisioning.

  38. A company must store credit card numbers so the production application can still process payments, but it wants to remove the actual card values from its systems and replace them with non-sensitive substitutes. Which data protection technique BEST meets this requirement?

    • A.Data masking, static character substitution of values
    • B.Tokenization, vaulted surrogate identity substitution
    • C.Format-preserving encryption, keyed same-shape values
    • D.Keyed hashing, salted one-way digests of values
    Show answerHide answer

    Correct answer: Tokenization, vaulted surrogate identity substitution

    Tokenization, vaulted surrogate identity substitution, is the answer: the application stores a meaningless token and only the separate token vault can map it back to the card number, so the real values leave the production systems while payments still resolve. Static data masking also substitutes characters, but it overwrites the value permanently, so a masked number can never be used to charge the card. Format-preserving encryption keeps the shape of the number, yet the real card value is still present in the system as ciphertext and can be decrypted with the key. Keyed hashing produces a one-way digest, so the original number cannot be recovered to complete a payment.

  39. Developers need realistic-looking customer records in a test environment but must not expose real personal data. Which technique BEST allows them to keep the format of the data while hiding the true values?

    • A.Data masking, fictitious replacement attribute entries
    • B.Data tokenization, vault-mapped stand-in record values
    • C.Data encryption, ciphertext written into record values
    • D.Data anonymization, generalised bands in record values
    Show answerHide answer

    Correct answer: Data masking, fictitious replacement attribute entries

    Data masking, fictitious replacement attribute entries is the best fit: each field is overwritten with an invented value of the same shape, so test records look real while no genuine person remains in the environment. Tokenization keeps a vault mapping that turns each stand-in back into the real value, which suits production payment systems rather than a test copy. Encryption turns fields into ciphertext that no longer keeps the original format and is still reversible with the key. Anonymization generalises values into bands or ranges, destroying the realistic record format the developers need.

  40. An architect is selecting a protocol to securely manage network devices and wants to replace the cleartext protocol historically used for remote command-line administration. Which protocol should be used?

    • A.FTP, unencrypted server filesystem uploading
    • B.TFTP, unauthenticated firmware image loading
    • C.SSH, encrypted administrative shell wrapping
    • D.SNMP, community string counter interrogating
    Show answerHide answer

    Correct answer: SSH, encrypted administrative shell wrapping

    SSH is the direct replacement for Telnet: the same interactive command line, wrapped in an encrypted, integrity-protected channel with host key verification, so credentials and commands cannot be read or altered on the wire. FTP moves files and sends its own login in the clear, so it repeats the weakness rather than fixing it. TFTP has no authentication at all and exists to fetch configuration or image files. SNMP polls and sets device variables and, in its older versions, authorizes with a community string sent in the clear.

  41. A security team needs to ensure that DNS responses cannot be forged or tampered with in transit by validating their authenticity with digital signatures. Which technology BEST provides this protection?

    • A.DHCP snooping, unauthorized address monitoring
    • B.HTTPS resolution, encrypted request forwarding
    • C.NAT gateway, unroutable perimeter readdressing
    • D.DNSSEC, hierarchical delegated trust anchoring
    Show answerHide answer

    Correct answer: DNSSEC, hierarchical delegated trust anchoring

    DNSSEC signs each zone and links every zone to its parent, so a resolver can follow the chain from a trust anchor down to the record it received and detect anything that was altered or fabricated along the way. DHCP snooping polices address offers on switch ports and never touches name resolution. Encrypted DNS transport hides the query from onlookers, but the resolver still has no way to prove that the answer it decrypts is the one the zone owner published. NAT rewrites addresses at a boundary and makes no statement about authenticity.

  42. A hardware vendor wants a dedicated chip on each laptop motherboard to securely store encryption keys and support measured boot. Which component provides this capability?

    • A.HSM appliance, bulk cryptographic offloading
    • B.TPM chip, tamper-proof measurement anchoring
    • C.SED controller, transparent drive encryption
    • D.UEFI firmware, signed bootloader enforcement
    Show answerHide answer

    Correct answer: TPM chip, tamper-proof measurement anchoring

    A TPM is soldered to one board and serves that one machine: it holds keys in hardware and records each boot component into its platform configuration registers, so a key can be sealed to a known-good measurement and refuse to release on a tampered system. An HSM is a separate network-attached appliance built for many hosts, not a per-laptop chip. A self-encrypting drive holds its own media key and encrypts blocks, but it measures nothing about the boot sequence. UEFI settings decide which bootloader signatures are accepted; the enforcement lives in firmware policy rather than in a key-storage chip.

  43. An enterprise wants a centralized, tamper-resistant appliance to generate, store, and manage cryptographic keys for many applications across the data center. Which device BEST meets this requirement?

    • A.HSM appliance, hardened cryptographic processor
    • B.CA infrastructure, certificate issuance control
    • C.RADIUS server, centralized login authentication
    • D.KVM concentrator, shared administrative console
    Show answerHide answer

    Correct answer: HSM appliance, hardened cryptographic processor

    An HSM is a hardened box whose only job is key material: it generates keys inside the boundary, never exports the private halves in the clear, performs the operations on request for many applications at once, and destroys its contents if the enclosure is opened. A certificate authority decides which identities deserve a certificate and signs them, and it commonly relies on an HSM to hold its own signing key. RADIUS authenticates users against a directory and issues no keys. A KVM switch shares a keyboard and monitor across servers and has no cryptographic role.

  44. A zero trust architecture is being designed. Which component is responsible for making the access decision by evaluating policy before a subject is allowed to reach a resource?

    • A.Implicit trust zone, unverified network segment
    • B.Subject system agent, guarded resource consumer
    • C.Adaptive identity signal, contextual risk input
    • D.Policy decision point, central control assessor
    Show answerHide answer

    Correct answer: Policy decision point, central control assessor

    The decision itself belongs to the control plane: the policy engine weighs identity, device posture and threat signals against the written rules and returns a grant or a deny, which the enforcement point then carries out on the data path. An implicit trust zone is the area behind a gate where traffic moves without further checks, which is exactly what zero trust tries to shrink. The subject is the user or workload asking for something, so it is the party the decision is made about, not the party making it. Adaptive identity signals are inputs consumed during that evaluation rather than the component performing it.

  45. In a zero trust model, which principle dictates that no user or device is trusted by default, even when located inside the corporate network perimeter?

    • A.Perimeter security, trusting every internal connection
    • B.Least privilege, restricting every account entitlement
    • C.Explicit verification, rechecking every single request
    • D.Layered defense, overlapping every protective boundary
    Show answerHide answer

    Correct answer: Explicit verification, rechecking every single request

    The principle is usually quoted as never trust, always verify. Zero trust takes location out of the trust calculation: every request is authenticated and authorized on its own merits whether it came from a branch office, a home network or the rack next door, and a session that was allowed a minute ago is checked again. The perimeter model does the opposite by treating the inside as safe once the boundary is crossed, which is the assumption zero trust was created to remove. Least privilege governs how much access an identity gets after it is trusted, not whether trust is assumed in the first place. Layered defense stacks independent controls and says nothing about implicit trust.

  46. An organization wants outbound user web traffic to pass through a device that filters content and hides internal client addresses from external sites. Which device performs this role?

    • A.Forward proxy, egress blocklist policy enforcement
    • B.Address translation gateway, source header rewrite
    • C.Network tap, silent full-duplex packet duplication
    • D.Load balancer, backend pool distribution scheduler
    Show answerHide answer

    Correct answer: Forward proxy, egress blocklist policy enforcement

    A forward proxy is deployed on behalf of the clients: every outbound session is made by the proxy, so the external site sees only the proxy's address, and because the proxy terminates the request it can apply category, reputation and content rules before letting it out. Address translation also replaces the source address, but it inspects nothing above the header and enforces no content policy. A tap silently copies frames for monitoring and cannot alter or block a session. A load balancer spreads inbound connections over a pool of servers, which is the opposite direction of travel.

  47. A web team wants a device positioned in front of their public web servers to terminate TLS, distribute incoming requests, and shield the servers' identities from clients. Which technology fits this role?

    • A.Jump server, hardened administrative entry waypoint
    • B.Reverse proxy, inbound session termination endpoint
    • C.Protocol analyzer, captured packet inspection suite
    • D.Screened subnet, semitrusted public service enclave
    Show answerHide answer

    Correct answer: Reverse proxy, inbound session termination endpoint

    A reverse proxy answers on behalf of the servers behind it: clients connect to the proxy, the encrypted session ends there, and the proxy opens its own connections to whichever back-end node it chooses, so the origin hostnames and addresses are never exposed. A jump server exists for administrators to log in through and carries no public client traffic. A protocol analyzer observes and decodes packets but terminates nothing. A screened subnet is a network zone created by firewall rules; it describes where the servers sit rather than a device that fronts them.

  48. Administrators must connect to sensitive internal systems only through a single hardened, monitored host rather than directly from their workstations. Which architectural element provides this controlled entry point?

    • A.Syslog collector, centralized message retention archive
    • B.Remote access concentrator, encrypted tunnel terminator
    • C.Directory service, authoritative member attribute store
    • D.Jump server, consolidated administrative pivot waypoint
    Show answerHide answer

    Correct answer: Jump server, consolidated administrative pivot waypoint

    A jump server concentrates privileged access into one place: administrators authenticate to that box, every session from it can be logged and recorded, and the sensitive systems accept management connections only from its address, so a compromised workstation cannot reach them directly. A syslog collector receives the logs those systems emit and grants no one access to anything. A remote access concentrator ends encrypted tunnels and drops users onto the network, which is the broad access a jump host is meant to replace. A directory service answers who a user is and what groups they hold, not where they must connect from.

  49. A network designer wants two firewalls in a configuration where, if the active firewall fails, the standby immediately takes over with no manual intervention. Which capability provides this?

    • A.Link aggregation, redundant physical consolidation
    • B.Cold spare, unscheduled technician reconfiguration
    • C.Active-passive cluster, automatic standby handover
    • D.Rule synchronization, paired appliance replication
    Show answerHide answer

    Correct answer: Active-passive cluster, automatic standby handover

    In an active-passive pair one firewall carries the traffic while the other holds the same configuration and state and watches it over a heartbeat; when the heartbeat stops, the standby claims the shared address and continues the sessions without anyone being paged. Link aggregation combines physical ports into one logical link and protects against a cable or port failure, not the loss of the whole unit. A cold spare is hardware on a shelf that someone has to rack, configure and cable first. Synchronizing rules between a pair keeps them consistent but does not itself decide when one should take over.

  50. A security architect must decide how a critical inline security appliance behaves if it crashes. The business requires that network traffic keep flowing even if inspection is lost. Which design choice meets this requirement?

    • A.Fail-closed policy
    • B.Fail-open behavior
    • C.Fail-back recovery
    • D.Fail-stop shutdown
    Show answerHide answer

    Correct answer: Fail-open behavior

    Fail-open is the availability-first choice: the moment the inline unit stops working, the path around it opens and packets continue to move even though nothing is inspecting them any more. Fail-closed is the opposite trade, dropping the traffic rather than letting anything past unexamined, which the business here has explicitly refused. Fail-back describes returning a workload to its primary once that primary is healthy again, so it applies after a recovery rather than during the outage. Fail-stop means the component halts cleanly and announces its own failure, which is a behavior of the device, not a decision about the traffic around it.

  51. For a device protecting highly sensitive systems, the organization decides that if the security control fails, all traffic must be blocked rather than allowed through uninspected. Which design does this describe?

    • A.Fail-closed design
    • B.Fail-open bypass
    • C.Inline-mode design
    • D.Tap-mode design
    Show answerHide answer

    Correct answer: Fail-closed design

    A fail-closed design blocks all traffic when the security control itself fails, accepting an outage as the safer outcome for highly sensitive systems. A fail-open bypass uses a bypass switch or NIC that passes traffic straight through uninspected when the device fails, which keeps service up but is exactly what this organization forbids. An inline-mode design only places the device in the traffic path so it is able to block; an inline device can still be configured to fail open, so placement alone does not decide failure behavior. A tap-mode design receives a copy of traffic passively and never sits in the path, so its failure blocks nothing.

  52. A power plant must keep its control network completely physically isolated, with no network connection to the corporate network or the internet. Which approach BEST describes this isolation?

    • A.Virtual segmentation, software defined zone division
    • B.Screened subnet, guarded public application boundary
    • C.Air gap, comprehensive physical connectivity removal
    • D.Unidirectional gateway, enforced one-way data egress
    Show answerHide answer

    Correct answer: Air gap, comprehensive physical connectivity removal

    An air gap means there is no path at all: no cable, no wireless bridge, no shared switch, so an attacker on the corporate network has nothing to route over and data crosses only by hand on removable media. Virtual segmentation separates traffic logically while the frames still share the same physical switches and can be reached if the configuration is wrong. A screened subnet is a filtered network that exists specifically to be reachable from outside. A one-way gateway is still a connection, and although it enforces the direction of flow it is not physical separation.

  53. A manufacturer ships industrial equipment that runs a real-time operating system on a low-power chip with fixed functionality and limited ability to receive patches. Which category does this BEST describe?

    • A.Hypervisor host, concurrent guest environments
    • B.General workstation, interactive user endpoint
    • C.Storage appliance, replicated filesystem array
    • D.Embedded system, purpose-built firmware device
    Show answerHide answer

    Correct answer: Embedded system, purpose-built firmware device

    An embedded device is built for one job: the software is burned in as firmware, the processor and memory are sized for that job and nothing else, and updates arrive rarely because they usually require the vendor and a maintenance window on the production line. A hypervisor host is a general platform whose whole purpose is to run arbitrary guest workloads. A workstation runs a general operating system with an interactive user and a routine monthly patch cycle. A storage appliance is purpose-built but sits in a data center serving files, with the capacity and the update path of ordinary server hardware.

  54. A utility uses SCADA systems to monitor and control field devices across remote substations. Which environment do SCADA systems primarily support?

    • A.Corporate office networks, shared productivity infrastructure
    • B.Industrial process control, operational technology deployment
    • C.Public cloud subscription, on-demand application environments
    • D.Retail payment systems, cardholder transaction authorizations
    Show answerHide answer

    Correct answer: Industrial process control, operational technology deployment

    SCADA exists to supervise physical processes: it reads sensors and drives actuators in pumps, breakers and valves spread over a wide area, which is the definition of an operational technology estate and the reason its priorities are availability and safety before confidentiality. Corporate networks move documents and mail between people and are engineered around information rather than physical plant. Cloud tenancy provides elastic compute for software workloads and has no field devices to actuate. Payment systems handle cardholder transactions under card industry rules and again control no physical process.

  55. A facilities team is adding internet-connected sensors, cameras, and thermostats to buildings. Which characteristic is the MOST common security concern for these IoT devices?

    • A.Weak default credentials, infrequent firmware updates
    • B.Excessive administrative privilege, wide domain scope
    • C.Unpatched hypervisor escapes, shared tenancy exposure
    • D.Injection flaws, unsanitized database query execution
    Show answerHide answer

    Correct answer: Weak default credentials, infrequent firmware updates

    Consumer-grade sensors and cameras ship with a published password, often cannot enforce a strong one, and receive firmware fixes rarely or never once the model stops selling, so a known flaw stays exploitable for the life of the device. Excessive domain privilege is an identity problem on managed servers and workstations, not on a thermostat that holds no domain account. Hypervisor escape belongs to virtualized multi-tenant hosting, and these devices are bare hardware. Injection flaws affect applications that build database queries, which most building sensors never do.

  56. An architect wants to separate the network's control plane from the data plane so traffic forwarding can be programmed centrally through software. Which technology provides this capability?

    • A.Spanning tree, distributed switch-local convergence
    • B.Function virtualization, appliance software hosting
    • C.Software-defined networking, unified policy control
    • D.Address translation, internal boundary readdressing
    Show answerHide answer

    Correct answer: Software-defined networking, unified policy control

    Software-defined networking lifts the decision-making out of each switch and puts it in a controller: the devices keep only the fast forwarding path, and an operator or an application programs the whole fabric from one place through the controller's interface. Spanning tree is a distributed protocol that each switch runs for itself to break loops, which is exactly the per-device intelligence this design removes. Network function virtualization moves appliances such as firewalls into software but leaves each of them with its own control logic. Address translation rewrites headers at a boundary and does not program forwarding anywhere.

  57. A company wants to limit each switch access port to a specific number of learned MAC addresses to prevent rogue devices and MAC flooding. Which feature provides this control?

    • A.802.1X, port-based sign-in before switch access
    • B.MAC filtering, static switch allowlist of hosts
    • C.ARP inspection, switch check of MAC-to-IP binds
    • D.Port security, permitted MAC identifier capping
    Show answerHide answer

    Correct answer: Port security, permitted MAC identifier capping

    Port security, permitted MAC identifier capping, limits how many source MAC addresses a switch access port may learn and takes a violation action beyond that, stopping both extra rogue devices and MAC flooding. 802.1X requires port-based sign-in before access but does not cap the number of addresses learned behind an authenticated port. MAC filtering on a static allowlist admits known addresses but sets no per-port count. ARP inspection checks MAC-to-IP bindings against DHCP snooping data to stop ARP spoofing, not table flooding.

  58. An architect must distribute incoming connections across a server pool and wants new sessions sent to the server with the fewest active connections at the moment. Which load balancing method describes this?

    • A.Least connection method, lowest concurrent workload
    • B.Round robin method, consecutive backend progression
    • C.Weighted distribution method, fixed ratio allotment
    • D.Source hash method, deterministic client attachment
    Show answerHide answer

    Correct answer: Least connection method, lowest concurrent workload

    The least-connection scheduler asks a live question before every placement: which member is carrying the smallest number of open sessions right now, and it sends the next one there, so a node stuck with long-running sessions stops receiving work automatically. Round robin walks the list in order and is blind to how busy anyone is. Weighted distribution divides traffic by a static ratio the administrator sets from expected capacity, which never reacts to the current moment. Source hashing computes the destination from the client's address so the same client keeps landing on the same node regardless of load.

  59. A load balancer must ensure a user's session keeps returning to the same back-end server so cached session data remains valid. Which capability provides this behavior?

    • A.Health probing, unresponsive backend eviction
    • B.Session persistence, sticky backend anchoring
    • C.Connection draining, gradual backend shutdown
    • D.Round-robin cycling, ordered backend rotation
    Show answerHide answer

    Correct answer: Session persistence, sticky backend anchoring

    Persistence pins a client to one member for the life of its session, usually with a cookie or a source-address table on the balancer, so the shopping cart or login state cached on that node is still there for the next request. Health probing decides which members are eligible at all and would gladly move a client to a different healthy node. Connection draining lets existing sessions finish while a node is taken out of service, which is the orderly end of persistence rather than the mechanism that provides it. Round robin deliberately spreads consecutive requests around, which is what breaks a cached session.

  60. An organization wants the ability to encrypt data while it is being actively processed in memory, not just at rest or in transit. Which protection BEST addresses data in this state?

    • A.Full-disk encryption, protecting stored volume contents
    • B.Transport layer security, shielding packet transmission
    • C.Encrypted backup archives, safeguarding offline volumes
    • D.Confidential computing, sealed memory execution enclave
    Show answerHide answer

    Correct answer: Confidential computing, sealed memory execution enclave

    Data has three states, and the hardest one to cover is data in use: while a record is loaded into memory and being computed on, it is normally plaintext and visible to anything with sufficient privilege on the host. Confidential computing closes that window with hardware enclaves that keep the working set encrypted and out of reach of the operating system and hypervisor. Full-disk encryption applies to a drive that is at rest and is transparent once the system is running. Transport encryption covers the journey between hosts. Encrypted backups protect stored copies, which is the at-rest state again.

  61. A security architect must protect data at rest on database servers so that stolen drives or files reveal no readable content. Which control BEST addresses this requirement?

    • A.Data masking, obscured sensitive table content in reports
    • B.Password hashing, one-way digests of users' login content
    • C.Stored-volume encryption, unreadable seized drive content
    • D.Database permissions, restricted reading of table content
    Show answerHide answer

    Correct answer: Stored-volume encryption, unreadable seized drive content

    Stored-volume encryption, unreadable seized drive content, is the BEST control: encryption keeps the database files and underlying volumes as ciphertext, so a stolen drive or copied file yields nothing readable without a key held elsewhere. Data masking hides fields only in what users and reports see, while the stored data stays in the clear. Password hashing protects credentials but leaves the rest of the records readable. Database permissions are enforced by the running server, and an attacker holding the raw drive bypasses them entirely.

  62. An architect needs a protocol that authenticates and encrypts IP traffic for a site-to-site tunnel and operates at the network layer. Which protocol suite is the BEST choice?

    • A.MACSEC
    • B.IPSEC
    • C.L2TP
    • D.GRE
    Show answerHide answer

    Correct answer: IPSEC

    IPSEC is the correct choice because it is the network-layer protocol suite that authenticates and encrypts IP packets, which is why site-to-site VPN tunnels are built on it. MACSEC encrypts traffic, but only hop by hop on a single Layer 2 link, so it cannot protect a routed tunnel between sites. L2TP builds a tunnel but provides no encryption on its own and is normally paired with IPsec. GRE encapsulates packets at the network layer but neither encrypts nor authenticates them.

  63. A SaaS provider runs multiple customers on shared infrastructure. Which architectural control BEST ensures one tenant cannot access another tenant's data?

    • A.Edge firewall rules enforced for every tenant workload
    • B.Shared-key volume encryption for every tenant workload
    • C.Logical isolation maintained for every tenant workload
    • D.Single sign-on federation across every tenant workload
    Show answerHide answer

    Correct answer: Logical isolation maintained for every tenant workload

    Logical isolation maintained for every tenant workload is what makes multitenancy safe: separate identities, storage namespaces, network segments and compute boundaries keep one customer from reaching another's data on shared hardware. Edge firewall rules filter traffic entering the platform but do nothing between tenants already inside it. Shared-key volume encryption protects data at rest from the outside, yet a single key shared by all tenants separates no one. Single sign-on federation streamlines authentication but does not decide which tenant's data a signed-in user can reach.

  64. An organization is choosing between cloud and on-premises hosting and wants to keep its most sensitive workloads in its own data center while running elastic, less-sensitive workloads in the public cloud. Which deployment model fits this?

    • A.Hybrid cloud deployment
    • B.Public cloud deployment
    • C.Hosted cloud deployment
    • D.Onsite cloud deployment
    Show answerHide answer

    Correct answer: Hybrid cloud deployment

    Correct answer: hybrid cloud deployment. A hybrid model keeps the most sensitive workloads on private infrastructure the organization controls while running elastic, lower-sensitivity workloads on public cloud capacity, which is exactly the split described. A public-only deployment moves the sensitive workloads out of the organization's own data center. A hosted deployment places every workload with a third party. An onsite-only deployment keeps everything in house and gives up public cloud elasticity.

  65. A development team packages an application with only its required libraries into a lightweight, portable unit that shares the host OS kernel. Which technology are they using?

    • A.Hardware-level emulation
    • B.Container virtualization
    • C.Filesystem deduplication
    • D.Hypervisor introspection
    Show answerHide answer

    Correct answer: Container virtualization

    Correct answer: container virtualization. Containers package an application with only the libraries it requires and execute against the shared host kernel, which is what makes the unit lightweight and portable. Hardware-level emulation runs a complete guest operating system per virtual machine, so no kernel is shared. Filesystem deduplication removes repeated storage blocks and packages no application. Hypervisor introspection inspects running virtual machines from the outside and is a monitoring technique.

  66. A security team configures storage so that data and parity are striped across multiple drives, allowing the array to survive the failure of any single drive. Which RAID level provides this with single-drive fault tolerance and striping with distributed parity?

    • A.RAID 0
    • B.RAID 1
    • C.RAID 3
    • D.RAID 5
    Show answerHide answer

    Correct answer: RAID 5

    Correct answer: RAID 5. RAID 5 stripes data across all members and distributes parity blocks among them, so the array rebuilds after any one drive fails. RAID 0 stripes with no parity, so a single failure destroys the whole set. RAID 1 mirrors rather than stripes and writes no parity. RAID 3 does stripe, but it concentrates parity on one dedicated drive instead of distributing it across the array.

  67. A company wants automatic failover to a secondary database that stays continuously synchronized with the primary so that no committed transactions are lost on failover. Which configuration BEST meets this requirement?

    • A.Asynchronous replication to a warm spare node
    • B.Transaction log shipping to a warm spare node
    • C.Synchronous replication to a hot standby node
    • D.Asynchronous mirroring to a warm standby node
    Show answerHide answer

    Correct answer: Synchronous replication to a hot standby node

    Synchronous replication to a hot standby node is correct because every transaction is committed on the standby before the client receives an acknowledgement, so automatic failover loses no committed work. Asynchronous replication acknowledges first and copies later, so the last transactions can be lost at failover. Transaction log shipping sends logs in batches on a schedule and leaves a gap of unshipped work. Asynchronous mirroring has the same lag as asynchronous replication, and a warm node also needs time before it can take over.

  68. An organization needs to securely transfer files between partners and wants a protocol that runs file transfers over an encrypted SSH channel. Which protocol should be selected?

    • A.TFTP
    • B.SFTP
    • C.FTPS
    • D.SMTP
    Show answerHide answer

    Correct answer: SFTP

    Correct answer: SFTP. SFTP performs its file operations inside an established SSH session, so credentials and file contents are protected by the SSH channel itself. TFTP offers no authentication and no encryption. FTPS is also encrypted, but it wraps classic FTP in TLS rather than running over SSH as the requirement states. SMTP transports mail between servers and is not a file transfer service.

  69. A security architect wants email server administration and directory queries to be encrypted, replacing the legacy cleartext directory access protocol. Which secure protocol should be chosen for directory access?

    • A.IPSEC
    • B.SMTPS
    • C.LDAPS
    • D.HTTPS
    Show answerHide answer

    Correct answer: LDAPS

    Correct answer: LDAPS. LDAPS carries directory queries inside TLS, so the bind credentials and query results that plain LDAP would send in cleartext are encrypted. IPSEC protects IP traffic in general and is not a directory access protocol. SMTPS secures mail submission. HTTPS secures web traffic. None of those three speaks the directory protocol the stem needs to replace.

  70. A company wants branch offices and remote users to reach cloud applications securely with centralized policy and inspection delivered from the cloud edge. Which architecture BEST describes this converged networking and security model?

    • A.SIEM
    • B.CASB
    • C.SOAR
    • D.SASE
    Show answerHide answer

    Correct answer: SASE

    Correct answer: SASE. Secure Access Service Edge converges wide-area networking with security services such as secure web gateway, firewall and zero trust access, all delivered from the provider's cloud edge, so branch offices and remote users receive one centrally managed policy. SIEM aggregates and correlates log data. CASB governs how individual cloud applications are used but does not carry the branch's network traffic. SOAR automates response playbooks after detection.

  71. A security architect must protect data in transit for a public website so that browsers verify the server's identity and encrypt the session. Which combination BEST provides this?

    • A.SHA-256 hashing using a documented algorithm
    • B.TLS encryption using a validated certificate
    • C.IPv4 allowlisting using a perimeter firewall
    • D.HTTP authentication using a lengthy password
    Show answerHide answer

    Correct answer: TLS encryption using a validated certificate

    Correct answer: TLS encryption using a validated certificate. TLS encrypts the session while a certificate that chains to a trusted authority proves the server is who it claims to be, and both properties are required to protect data in transit for a public site. SHA-256 hashing provides integrity evidence but no confidentiality and no proof of identity. IPv4 allowlisting restricts which addresses may connect and encrypts nothing. HTTP authentication sends the credential over an unprotected channel however long that password is.

  72. A network is being segmented so that the finance department's systems are logically separated from general user systems on the same physical switches. Which technology BEST accomplishes this logical separation?

    • A.DMZ segmentation
    • B.VLAN segmentation
    • C.Port ACL enforcement
    • D.NAC port enforcement
    Show answerHide answer

    Correct answer: VLAN segmentation

    VLAN segmentation places the finance ports in their own broadcast domain, so they are logically separated from general users while sharing the same physical switches. DMZ segmentation creates a screened subnet for public-facing servers, not an internal department boundary. Port ACL enforcement filters traffic on individual switch ports but leaves every user in the same broadcast domain. NAC port enforcement decides whether a device may connect at all; it admits or refuses hosts rather than dividing the admitted ones into separate logical networks.

  73. An architect wants extremely granular control where security policy is enforced down to individual workloads in a data center, limiting east-west movement between servers. Which approach BEST describes this?

    • A.Network microsegmentation
    • B.Datacenter virtualization
    • C.Directory synchronization
    • D.Infrastructure templating
    Show answerHide answer

    Correct answer: Network microsegmentation

    Correct answer: network microsegmentation. Microsegmentation writes policy around each individual workload rather than around a subnet, so east-west traffic between two servers inside the same data center is filtered as well. Datacenter virtualization abstracts the underlying hardware without adding any per-workload policy. Directory synchronization copies identity data between stores. Infrastructure templating standardizes how systems are built and enforces nothing at runtime.

  74. A company processing European residents' personal data must keep that data within specific geographic boundaries to satisfy legal obligations. Which architectural consideration directly drives where the data may be stored?

    • A.Data sovereignty
    • B.Data retention
    • C.Data classification
    • D.Geographic dispersion
    Show answerHide answer

    Correct answer: Data sovereignty

    Data sovereignty is the principle that data about a jurisdiction's residents is subject to that jurisdiction's laws, so it dictates which geographic regions may store and process the records. Data retention is also driven by legal obligations, but it governs how long data is kept, not where. Data classification labels data by sensitivity and drives handling controls rather than location. Geographic dispersion spreads data across distant sites for resilience, which can breach residency rules instead of satisfying them.

  75. A company is moving an application to a model where the cloud provider runs individual functions on demand and the customer manages no servers or operating systems at all. Which architecture model is being described, and what is its key security implication for the customer?

    • A.PaaS, where the customer maintains the language runtime and middleware
    • B.IaaS, where the customer patches each hosted operating system instance
    • C.SaaS, where the customer configures the vendor's ready web application
    • D.FaaS, where the customer safeguards its function code and entitlements
    Show answerHide answer

    Correct answer: FaaS, where the customer safeguards its function code and entitlements

    Correct answer: FaaS, where the customer safeguards its function code and entitlements. In a serverless Function as a Service model the provider runs short-lived functions on demand and owns the servers, operating systems and runtime entirely, so under shared responsibility the customer's remaining duties are the function code, its configuration, its identity permissions and its data. PaaS leaves the runtime and middleware with the provider, not the customer. IaaS is wrong for this stem because the customer there still patches guest operating systems, which the stem explicitly rules out. SaaS delivers a finished application the customer only configures, and no function code is deployed at all.

  76. A security architect must select a hardware component that generates, stores, and manages cryptographic keys for an entire enterprise at high volume and is often certified to FIPS 140-2/140-3 for use in data centers. Which component best fits this requirement?

    • A.TPM
    • B.SED
    • C.HSM
    • D.UTM
    Show answerHide answer

    Correct answer: HSM

    Correct answer: HSM. A hardware security module is a dedicated tamper-resistant appliance built to generate, store and manage cryptographic keys for an entire enterprise at high transaction volume, and data center models are commonly validated to FIPS 140-2 or 140-3. A TPM is a chip bound to one host that protects that machine's own keys and boot measurements. An SED encrypts the contents of a single drive with a key it holds internally. A UTM is a consolidated security gateway and performs no enterprise key management.

  77. A database stores credit card numbers and the architect wants to replace each real card number with a non-sensitive substitute value that has no mathematical relationship to the original, with the mapping held in a separate secured vault. Which data protection technique is being used?

    • A.Payment tokenization
    • B.Irreversible hashing
    • C.Attribute encryption
    • D.Column-level masking
    Show answerHide answer

    Correct answer: Payment tokenization

    Correct answer: payment tokenization. Tokenization swaps each card number for a randomly generated surrogate with no mathematical relationship to the original, and the real value can be retrieved only through a separately secured token vault, which is precisely the vault-backed mapping described. Irreversible hashing cannot be reversed at all, so the original card number could never be recovered for a later transaction. Attribute encryption transforms the value with a key, so a mathematical relationship to the original does remain. Column-level masking obscures the value for display while the real number stays in place.

  78. An architect is documenting how an organization protects information across its lifecycle and needs to address the state in which data is actively being processed in a system's memory or CPU. Which protection is specifically designed for data in use?

    • A.Full-disk encryption inside a storage volume
    • B.Transport encryption inside a network tunnel
    • C.Enclave execution inside a processor package
    • D.Immutable archiving inside a duplicate vault
    Show answerHide answer

    Correct answer: Enclave execution inside a processor package

    Correct answer: enclave execution inside a processor package. Data in use is data loaded into memory and actively processed, and confidential computing protects it by running the computation inside a hardware trusted execution environment that the host operating system and hypervisor cannot read. Full-disk encryption protects data at rest and releases plaintext to memory once the volume is unlocked. Transport encryption protects data in transit between endpoints. Immutable archiving serves recovery and retention, not live processing.

  79. An organization needs a recovery site that holds duplicated, continuously synchronized systems and data so it can take over operations almost immediately after a disaster, with minimal downtime. Which recovery site type meets this requirement?

    • A.Warm standby site
    • B.Cold standby site
    • C.Pilot light site
    • D.Hot standby site
    Show answerHide answer

    Correct answer: Hot standby site

    A hot standby site keeps fully duplicated, continuously synchronized systems and data running, so it can take over almost immediately with minimal downtime. A warm standby site holds a scaled-down environment that must be scaled up or brought current before it carries full production load. A cold standby site has equipment that is powered off and must be configured and loaded, which takes much longer. A pilot light site runs only the core data services and must build out the rest after a disaster.

  80. A security architect wants to manage infrastructure through version-controlled definition files so that servers and networks are provisioned consistently and configuration drift is reduced. Which practice provides this capability?

    • A.Templates by operators
    • B.Baselines from imaging
    • C.Deployments via ticket
    • D.Infrastructure as code
    Show answerHide answer

    Correct answer: Infrastructure as code

    Correct answer: infrastructure as code. Infrastructure as code defines servers, networks and their configuration in machine-readable files that live in version control, so every environment is provisioned from the same reviewed definition and drift is reduced. Templates hand-built by operators are not version controlled and diverge as each operator edits them. Baselines captured from golden images capture one point in time and age immediately. Deployments driven by change tickets rely on humans repeating manual steps, which is the source of the drift.

  81. A bank requires that its public-facing web application servers be able to verify their identity to clients using digital certificates issued by a trusted authority. Which architectural component issues and signs those certificates?

    • A.Certificate revocation list
    • B.Certificate signing request
    • C.Certificate issuance server
    • D.Certificate status protocol
    Show answerHide answer

    Correct answer: Certificate issuance server

    Correct answer: certificate issuance server. The certificate authority in a PKI is the component that issues and digitally signs certificates, binding a public key to a verified identity so relying clients can trust the server they reach. A certificate revocation list publishes serial numbers that are no longer trusted and issues nothing. A certificate signing request is the applicant's submission to the authority, not the issuer. A certificate status protocol such as OCSP answers real-time validity queries about certificates that were already issued.

  82. When configuring an IPsec VPN, an engineer must ensure the payload data is encrypted for confidentiality. Which IPsec protocol provides encryption of the data payload, which the other does not?

    • A.IP Authentication Header (AH), a familiar networking convention
    • B.Encapsulating Security Payload (ESP), a known networking format
    • C.Internet Key Exchange (IKE), a defined networking specification
    • D.Payload Compression Protocol (IPComp), a common networking term
    Show answerHide answer

    Correct answer: Encapsulating Security Payload (ESP), a known networking format

    Encapsulating Security Payload is the IPsec protocol that encrypts the data it carries, and it supplies integrity and origin authentication for that protected data as well, which is why it is chosen when confidentiality is required. IP Authentication Header provides integrity and authentication for the packet but performs no encryption whatsoever, so anything it protects still travels in the clear. Internet Key Exchange negotiates the keys and security associations before any user data is protected and is not itself the protection. Payload Compression Protocol shrinks payloads to offset the expansion encryption causes and offers no confidentiality of its own.

Security Operations (127)

  1. Which cybersecurity term describes a small piece of data used to identify and authenticate a user's session?

    • A.Certificate, which binds an owner to a public key
    • B.Checksum, which detects a single change in a file
    • C.Cipher suite, which names the agreed set of codes
    • D.Token, which proves the user is already logged in
    Show answerHide answer

    Correct answer: Token, which proves the user is already logged in

    After a successful login the server issues a short session token, and the client presents that value on each later request so the server can recognise and authorise the session without re-checking the password. A certificate binds a public key to an identity and is issued by a certificate authority for much longer periods. A checksum detects accidental corruption in a file and provides no identity at all. A cipher suite is the negotiated set of algorithms used to protect a connection, not a per-user credential.

  2. What is the primary purpose of a HIDS (Host-based Intrusion Detection System)?

    • A.To review the logs of a single machine carefully
    • B.To hand out addresses to devices at each startup
    • C.To create a private tunnel over a public network
    • D.To bar unsigned code from a locked-down web host
    Show answerHide answer

    Correct answer: To review the logs of a single machine carefully

    A host-based intrusion detection system runs on the host it protects and inspects that machine's own evidence, its logs, file integrity, running processes and local network activity, which lets it see encrypted or internal activity a network sensor never sees. Handing out addresses at startup is DHCP. Creating a private tunnel over a public network is a VPN. Barring unsigned code is application allow-listing, a preventive control rather than a detective one.

  3. In cybersecurity, what is the primary function of a SIEM (Security Information and Event Management) system?

    • A.Handing out one address per joining device
    • B.Correlating live event logs in one console
    • C.Shredding a retired disk after service end
    • D.Patching a server on a quarterly timetable
    Show answerHide answer

    Correct answer: Correlating live event logs in one console

    A security information and event management platform ingests logs from servers, network gear and applications, normalises them, and correlates events in near real time so that a pattern spread across several sources raises one alert an analyst can act on. Handing out an address per joining device is DHCP. Shredding a retired disk after service end is media sanitisation. Patching a server on a fixed timetable is vulnerability management. None of those three performs real-time correlation and alerting across log sources.

  4. Which technology is most effective for preventing data leakage via email?

    • A.Antivirus, which matches a file against known signatures
    • B.Data loss prevention, which blocks the sensitive content
    • C.Load balancer, which shares email traffic across servers
    • D.Password vault, which stores each user's private secrets
    Show answerHide answer

    Correct answer: Data loss prevention, which blocks the sensitive content

    Data loss prevention inspects the content itself, matching patterns such as card numbers, national identifiers or classified markings, and then blocks, quarantines or encrypts the message before it leaves the organisation. Antivirus matches a file against known malware signatures and says nothing about whether the content is confidential. A load balancer distributes traffic for availability. A password vault protects stored credentials at rest. Only content inspection at the gateway stops sensitive material leaving by email.

  5. Which tool is primarily used for vulnerability scanning in a network?

    • A.Wireshark, which decodes a captured packet bit stream
    • B.Snort, which alerts on a suspicious inbound signature
    • C.Nessus, which reports the known unpatched server bugs
    • D.Nmap, which enumerates the open ports per workstation
    Show answerHide answer

    Correct answer: Nessus, which reports the known unpatched server bugs

    Nessus is a vulnerability scanner: it fingerprints hosts and services, tests them against a plugin feed of known flaws and misconfigurations, and reports what is missing or exposed with a severity rating. Wireshark decodes captured traffic and finds no vulnerabilities. Snort is an intrusion detection engine that alerts when live traffic matches a rule signature. Nmap discovers hosts and open ports, which is reconnaissance rather than a vulnerability assessment.

  6. What is the primary purpose of the tcpdump tool in network security?

    • A.Capturing a raw packet for detailed inspection
    • B.Wiping unused space from a decommissioned disk
    • C.Signing a download so later tampering surfaces
    • D.Hardening a database against a vendor baseline
    Show answerHide answer

    Correct answer: Capturing a raw packet for detailed inspection

    tcpdump is a command-line packet capture tool: it puts an interface into promiscuous mode, filters with a Berkeley Packet Filter expression, prints the headers and can write a capture file for later analysis. Wiping unused space from a decommissioned disk is media sanitisation. Signing a download so tampering surfaces is an integrity control. Hardening a database against a vendor baseline is configuration management. None of those three records live traffic from an interface.

  7. Which of the following is a primary use case for a protocol analyzer in network security?

    • A.Reading a handshake to find a broken exchange
    • B.Erasing a handset after it departs the estate
    • C.Issuing a plastic card to each new contractor
    • D.Rotating an access file on a nightly schedule
    Show answerHide answer

    Correct answer: Reading a handshake to find a broken exchange

    A protocol analyser decodes captured frames field by field, so an engineer can follow a session such as a TLS or DHCP handshake, see exactly which message was malformed, rejected or never sent, and decide whether the fault is a configuration error or an attack. Erasing a handset as it departs the estate is asset disposal. Issuing a plastic card to a new contractor is identity provisioning. Rotating an access file on a nightly schedule is log management.

  8. In the context of digital forensics, what is the main purpose of a write blocker?

    • A.To hash each copied image before it travels
    • B.To leave the seized medium exactly as found
    • C.To log the handovers of the sealed evidence
    • D.To carve deleted files out of spare sectors
    Show answerHide answer

    Correct answer: To leave the seized medium exactly as found

    A write blocker sits between the evidence drive and the examiner's workstation and permits read commands while refusing every write, so the operating system cannot mount, journal or timestamp the original and the acquired image still matches the source hash. Hashing each copied image proves integrity but does not stop a write happening. Logging the handovers is chain of custody, a documentation control. Carving deleted files out of unallocated sectors is an analysis technique performed on the copy.

  9. Which tool is used in cybersecurity to simulate attacks on a system or network to identify vulnerabilities?

    • A.Vulnerability scanner, which checks OS versions
    • B.Honeypot decoy, which logs each attack it draws
    • C.Exploit framework, which fires real attack code
    • D.Protocol analyzer, which decodes attack traffic
    Show answerHide answer

    Correct answer: Exploit framework, which fires real attack code

    An exploit framework, which fires real attack code at a target with the owner's permission, is the penetration-testing tool that simulates an attack to prove a weakness can actually be used. A vulnerability scanner checks OS and software versions against known flaws and reports them without exploiting anything. A honeypot decoy logs the attacks it draws in from real adversaries rather than simulating one. A protocol analyzer decodes captured traffic, including attack traffic, but launches nothing.

  10. What is the primary use of a Security Assertion Markup Language (SAML)?

    • A.Sealing outbound message bodies inside a protected mail envelope
    • B.Rating reported software defects against a public severity scale
    • C.Passing signed identity assertions toward a trusting web service
    • D.Filtering inbound packet streams at a stateful boundary firewall
    Show answerHide answer

    Correct answer: Passing signed identity assertions toward a trusting web service

    SAML exists to carry signed authentication and authorization assertions from an identity provider to a service provider, and that assertion exchange is what makes browser-based single sign-on work across separate web applications. Sealing the body of a mail message is the job of S/MIME or PGP, message formats that have nothing to do with identity assertions. Scoring reported software defects against a published severity scale is what a vulnerability scanner and CVSS do, and SAML never inspects code. Deciding which packets may cross a boundary is a firewall function performed on addresses and ports, several layers below the assertion exchange SAML carries out.

  11. What is the primary purpose of Data Loss Prevention (DLP) technology?

    • A.Removing duplicate blocks from stored archives to reclaim expensive capacity
    • B.Rotating cryptographic keys inside a tamperproof module to minimize exposure
    • C.Recording user keystrokes on managed endpoints to build behavioral baselines
    • D.Detecting regulated content in outbound streams to stop unapproved transfers
    Show answerHide answer

    Correct answer: Detecting regulated content in outbound streams to stop unapproved transfers

    DLP works by classifying content such as card numbers, health records or source code and then watching every path that content can take out of the organization, blocking or quarantining a transfer policy does not allow, whether the data is at rest, in use or in motion. Removing duplicate blocks from an archive is deduplication, a storage-efficiency technique that never examines who is sending what to whom. Rotating keys inside a hardware security module shortens the window in which a compromised key is useful, a key-management control that acts on secrets rather than on content. Recording keystrokes to build behavioral baselines is user activity monitoring, which profiles people instead of identifying and halting the movement of regulated data.

  12. What is the main purpose of using a Security Information and Event Management (SIEM) system?

    • A.Executing response playbooks for alert events across security systems
    • B.Recording process events on every endpoint to stop known hostile acts
    • C.Correlating log events from many systems to surface genuine incidents
    • D.Inspecting packet events on each network segment for known signatures
    Show answerHide answer

    Correct answer: Correlating log events from many systems to surface genuine incidents

    A SIEM's main purpose is correlating log events from many systems to surface genuine incidents: it normalizes logs from firewalls, endpoints and servers and applies rules across sources. Executing response playbooks across tools is SOAR, which acts on alerts rather than correlating the logs. Recording process events on each endpoint to stop hostile acts is EDR, confined to one host at a time. Inspecting packet events for known signatures is an IDS or IPS function on network traffic.

  13. In Secure Software Development Life Cycle SDLC models, which phase primarily focuses on defining security requirements and goals?

    • A.Detailed design
    • B.Staged handover
    • C.Formal planning
    • D.Systems testing
    Show answerHide answer

    Correct answer: Formal planning

    Security requirements and goals belong in the earliest phase of a secure SDLC, where the team agrees what the system must protect, which regulations apply, what an acceptable level of residual risk is, and what secure enough will mean at release; every later phase is then measured against that statement. The design phase converts already-agreed requirements into an architecture of trust boundaries, authentication flows and key handling, so it implements goals rather than setting them. Testing verifies that requirements were met, which presupposes they already exist. Handover moves a finished build into production with hardening and monitoring, far too late for a missing requirement to be added cheaply.

  14. What is the primary purpose of a SIEM (Security Information and Event Management) system in a cybersecurity infrastructure?

    • A.Running automated playbooks that isolate each host once an alert fires
    • B.Recording process activity on each host to stop malicious code running
    • C.Gathering log records from many sources into one searchable repository
    • D.Inspecting outbound traffic so regulated data stays inside each host
    Show answerHide answer

    Correct answer: Gathering log records from many sources into one searchable repository

    The primary purpose of a SIEM is gathering log records from many sources into one searchable repository, normalizing and time-aligning them so correlation, alerting and investigation become possible. Running automated playbooks that isolate a host when an alert fires is SOAR, which acts on the SIEM's output rather than collecting it. Recording process activity on each host to stop malicious code is EDR, an endpoint agent that the SIEM reads from. Inspecting outbound traffic so regulated data stays inside is DLP, another source of events rather than the aggregation point.

  15. Which authentication protocol primarily relies on tickets for client-server authentication and does not transmit passwords over the network?

    • A.Diameter sessions
    • B.Terminal accounts
    • C.Directory lookups
    • D.Kerberos requests
    Show answerHide answer

    Correct answer: Kerberos requests

    Kerberos authenticates a client to a service using time-limited tickets issued by a Key Distribution Center; the password is used locally to derive a key and is never sent across the network, and the service validates the ticket rather than a credential. Diameter, the AAA successor to RADIUS, uses a request and answer exchange protected by transport-layer security and carries credentials to the server instead of granting tickets. Terminal device administration under TACACS+ separates authentication from authorization so individual commands can be approved, and it encrypts the packet body, but each login still sends the credential to the server. A directory lookup authenticates through an LDAP simple bind, which transmits the password to the directory server, the opposite of the property described.

  16. In Identity and Access Management, what is the primary purpose of a Federation Service?

    • A.Storing hashed user credentials inside a shared onsite directory store
    • B.Timing out idle sessions after a published inactivity threshold passes
    • C.Letting a partner recognize logins issued by one external organization
    • D.Granting temporary rights for a single assignment then retracting them
    Show answerHide answer

    Correct answer: Letting a partner recognize logins issued by one external organization

    A federation service establishes trust between separate identity domains so a user authenticated by their home organization is accepted by a partner's application without holding an account there; the partner validates a signed assertion from the trusted issuer instead of a local credential. Storing hashed credentials in a directory is what a directory service does inside one organization, the very duplication federation removes the need for. Timing out idle sessions is a session-management control that limits exposure on an unattended device. Granting rights for a single assignment and retracting them afterwards is just-in-time privileged access, which decides how long an entitlement lasts rather than which organization vouched for the identity.

  17. Which of the following best describes a 'Privileged Access Management' (PAM) system?

    • A.Vaulting passwords for highly elevated accounts under live session recording
    • B.Mapping job titles onto permission bundles assigned across whole departments
    • C.Comparing logon sequences against a baseline of established account behavior
    • D.Tunneling remote traffic through an encrypted link toward internal resources
    Show answerHide answer

    Correct answer: Vaulting passwords for highly elevated accounts under live session recording

    Privileged access management concentrates on the small number of accounts that can change everything: it vaults and rotates their credentials, issues them just in time, brokers the connection so the human never handles the secret, and records the session for review. Mapping job titles to permission bundles is role-based access control, which governs ordinary entitlements for the whole workforce rather than the administrative tier. Comparing logons against a behavior baseline is user and entity behavior analytics, a detection technique that holds no credential at all. Building an encrypted tunnel to internal resources is remote access, which decides how a user reaches the network and not what elevated rights they may exercise once there.

  18. What is the main purpose of using a Security Assertion Markup Language (SAML) in web security?

    • A.Reusing one original identity login across many unrelated web services
    • B.Converting readable input into ciphertext under an agreed block cipher
    • C.Checking sender domains against published records held in public zones
    • D.Selecting the resources an endpoint contacts under a quarantine policy
    Show answerHide answer

    Correct answer: Reusing one original identity login across many unrelated web services

    SAML lets a user authenticate once at an identity provider, which then issues a signed assertion that each participating service provider trusts, so one session opens many separate web applications without the user presenting a credential to any of them. Converting readable input into ciphertext under an agreed block cipher is what an encryption algorithm inside TLS or S/MIME does; SAML assertions are signed for authenticity and normally travel over a channel someone else encrypted. Checking a sender domain against records published for that domain is SPF, DKIM and DMARC, an email authentication family with no relationship to web session establishment. Selecting what an endpoint may reach after a posture check is network access control, an admission decision rather than an identity assertion.

  19. What is the primary function of a RADIUS server in network security?

    • A.Filtering inbound packets statefully and dropping what the ruleset forbids
    • B.Validating remote credentials centrally and logging the length of sessions
    • C.Watching host processes closely and flagging what looks clearly unexpected
    • D.Encrypting stored volumes silently and holding keys inside sealed firmware
    Show answerHide answer

    Correct answer: Validating remote credentials centrally and logging the length of sessions

    RADIUS centralizes AAA for network access: a switch, wireless controller or VPN concentrator forwards a user's credentials to the RADIUS server, which authenticates them, returns the authorization attributes that shape the session, and stores accounting records covering its start, stop and duration. Stateful packet filtering against a ruleset is a firewall's work, performed on traffic rather than on identity. Watching host processes and flagging unexpected behavior is host intrusion detection or EDR, which lives on the endpoint and issues no network access decision. Encrypting stored volumes with keys held in firmware is full-disk encryption, a data-at-rest control unrelated to who is allowed onto the network.

  20. Which technology is primarily used for multi-factor authentication to enhance security?

    • A.Certificate pinning
    • B.Screensaver locking
    • C.Passphrase rotation
    • D.Fingerprint scanner
    Show answerHide answer

    Correct answer: Fingerprint scanner

    Multi-factor authentication requires evidence from different categories, and a fingerprint scanner supplies the inherence factor, something the user is, which cannot be shared or typed the way a memorized secret can, so pairing it with a password or a token produces a genuine multi-factor login. Certificate pinning ties a client to an expected server certificate and defends a TLS connection against a fraudulent issuer; it authenticates the server, not the person. Screensaver locking protects an unattended workstation and simply re-presents whatever authentication is already configured. Passphrase rotation replaces one knowledge secret with another knowledge secret, which remains a single factor however often it changes.

  21. What does the OAuth protocol primarily provide in the context of Identity and Access Management?

    • A.Demanding an additional factor beyond a passphrase during interactive logon
    • B.Wrapping wireless frames within a rotating cipher during radio transmission
    • C.Granting one application delegated rights over owner resources using tokens
    • D.Moving stored files between hosts inside an authenticated encrypted channel
    Show answerHide answer

    Correct answer: Granting one application delegated rights over owner resources using tokens

    OAuth is an authorization framework: the resource owner approves a scoped, revocable grant, and the application receives an access token that lets it act on specific resources for a limited time while the owner's password never leaves the identity provider. Demanding an additional factor at logon is multi-factor authentication, which strengthens proof of who the user is and says nothing about what a third-party application may do on their behalf. Wrapping wireless frames in a rotating cipher describes WPA link encryption, a data-in-transit protection at the radio layer. Moving files inside an authenticated encrypted channel is SFTP or SCP, a transfer protocol that carries data rather than delegating rights.

  22. In a Single Sign-On (SSO) implementation, what is the primary security risk?

    • A.One stolen credential opens the whole set of connected services
    • B.One copy of every user's password hash sits in each application
    • C.One expired signing certificate exposes each assertion in clear
    • D.One merged audit log hides which user opened each application
    Show answerHide answer

    Correct answer: One stolen credential opens the whole set of connected services

    The primary SSO risk is that one stolen credential opens the whole set of connected services, which is why SSO is paired with MFA and a hardened identity provider. A copy of every password hash in each application is wrong because SSO keeps credentials at the identity provider and the applications receive assertions instead. An expired signing certificate makes assertions fail validation; it does not expose them in clear. A merged audit log is wrong because SSO assertions carry the user identity, so each application still logs who signed in.

  23. What is the primary function of TACACS+ in network security?

    • A.Detecting known malware signatures inside files copied onto employee endpoints
    • B.Authorizing individual commands issued by an administrator on managed consoles
    • C.Reserving minimum bandwidth for voice traffic crossing congested carrier links
    • D.Producing periodic integrity reports about system binaries on hardened servers
    Show answerHide answer

    Correct answer: Authorizing individual commands issued by an administrator on managed consoles

    TACACS+ is the AAA protocol built for device administration: it separates authentication from authorization so that once an administrator has logged in, each command they issue can be checked against policy and permitted or refused, and it encrypts the entire packet body rather than only the password. Matching files against malware signatures is antimalware scanning performed on an endpoint. Reserving bandwidth for voice on a congested link is quality of service, a traffic-prioritization feature configured on the very routers TACACS+ protects but unrelated to who may configure them. Producing integrity reports on system binaries is file integrity monitoring, which detects unauthorized change after the fact instead of deciding an administrator's rights in advance.

  24. Which term best describes a system where different authentication methods are used at different times or in different contexts for the same user?

    • A.Password authentication
    • B.Kerberos authentication
    • C.Two-step authentication
    • D.Adaptive authentication
    Show answerHide answer

    Correct answer: Adaptive authentication

    Adaptive, or risk-based, authentication evaluates the context of each attempt, including device, location, network, time and recent behavior, and varies what it demands: a routine login passes on a password while a login from an unfamiliar country triggers an additional challenge, so the same user meets different requirements at different moments. Password authentication asks for the same single secret every time and has no notion of context. Kerberos authentication is a ticket-based protocol whose exchange is identical for every session it issues. Two-step authentication always requires the same two factors regardless of circumstance, a fixed policy rather than one that responds to risk.

  25. What is the main advantage of implementing a Role-Based Access Control RBAC system in an organization?

    • A.Evaluating permissions against each user's attributes at every request
    • B.Letting each resource owner give any role or colleague access directly
    • C.Matching each user's clearance label to the label set on each resource
    • D.Gathering permissions under a functional role shared by many employees
    Show answerHide answer

    Correct answer: Gathering permissions under a functional role shared by many employees

    The main advantage of RBAC is gathering permissions under a functional role shared by many employees, so administrators maintain a few role definitions instead of thousands of individual grants and joiners, movers and leavers are handled by changing role membership. Evaluating permissions against each user's attributes at every request describes ABAC, which gains context awareness at the cost of more complex policy. Letting each resource owner give any role or colleague access directly is discretionary access control, which decentralizes rather than simplifies administration. Matching each user's clearance label to the label set on each resource is mandatory access control, which enforces classification rather than job function.

  26. Which authentication factor category does a fingerprint scanner fall under?

    • A.Knowledge authentication
    • B.Ownership authentication
    • C.Proximity authentication
    • D.Inherence authentication
    Show answerHide answer

    Correct answer: Inherence authentication

    Inherence authentication is the right category: a fingerprint is a measured physical trait of the person, the classic "something you are" factor. Knowledge authentication tests a memorised secret such as a PIN or passphrase. Ownership authentication tests a device the person carries, such as a hardware token. Proximity authentication tests where the person is, using location or network context, which a fingerprint reader never evaluates.

  27. In Identity and Access Management, what is a primary security feature of using smart cards as an authentication factor?

    • A.They carry an embedded certificate that proves who the user is
    • B.They carry a signed certificate revocation list for the server
    • C.They carry one shared symmetric key that the server also holds
    • D.They carry the CA root certificate that the servers must trust
    Show answerHide answer

    Correct answer: They carry an embedded certificate that proves who the user is

    The key feature is that they carry an embedded certificate that proves who the user is, backed by a private key that never leaves the chip. A certificate revocation list is published by the CA and checked by the relying server, not stored on the user's card. Smart-card logon uses asymmetric key pairs, not a symmetric key shared with the server. The CA root certificate is installed in the server's trust store; the card holds the user's own certificate.

  28. What is the main purpose of implementing a Directory Service in network security?

    • A.Logging each authentication attempt for a formal audit review
    • B.Centralizing the storage of user records and their attributes
    • C.Issuing and revoking the public key certificates users supply
    • D.Distributing software updates to the machines that are joined
    Show answerHide answer

    Correct answer: Centralizing the storage of user records and their attributes

    A directory service exists to hold identity data in one authoritative place: user, group and device objects with the attributes other systems query when they authenticate or authorize someone. Audit logging of authentication attempts is done by the event log and the collector that reads it. Issuing and revoking certificates is the job of a certificate authority. Pushing software updates is a patch management function, not a directory function.

  29. Which access control model dynamically assigns roles to users based on attributes and environmental conditions?

    • A.MAC, clearance-driven access control
    • B.DAC, owner-controlled access control
    • C.ABAC, attribute-based access control
    • D.RBAC, role-membership access control
    Show answerHide answer

    Correct answer: ABAC, attribute-based access control

    ABAC evaluates attributes of the subject, the object, the action and the environment at the moment of the request, so what is granted changes with conditions such as time of day, device posture or location. MAC decides from fixed clearance and classification labels set by the system, not by conditions. DAC lets the resource owner grant access at their own discretion. RBAC grants permissions through static role memberships that an administrator assigns in advance.

  30. A security operations team wants a single platform that collects log and event data from servers, firewalls, and applications across the enterprise, normalizes it, and correlates events to generate alerts and support investigations. Which type of system provides this capability?

    • A.SOAR, a playbook-run response platform
    • B.EDR, an endpoint response platform
    • C.UEBA, a user behavior anomaly platform
    • D.SIEM, a centralized analytics platform
    Show answerHide answer

    Correct answer: SIEM, a centralized analytics platform

    SIEM, a centralized analytics platform, is the system that ingests logs from servers, firewalls and applications, normalizes them and correlates events into alerts. SOAR is wrong because it runs playbooks that act on alerts a SIEM already produced; it is not the collection and correlation layer. EDR is wrong because it records telemetry from endpoints only, not from firewalls and every application. UEBA is wrong because it baselines user behavior to spot anomalies and depends on the log data a SIEM gathers.

  31. An organization deploys a tool that automatically executes predefined playbooks to enrich, triage, and respond to alerts across multiple security products, reducing manual analyst effort. Which security operations capability is this?

    • A.SOAR, a workflow orchestration platform
    • B.SIEM, a historical correlation platform
    • C.EDR, a workstation containment platform
    • D.FIM, a configuration integrity platform
    Show answerHide answer

    Correct answer: SOAR, a workflow orchestration platform

    SOAR is the layer that holds the playbooks: it connects to the other security products through their APIs and executes enrichment, triage and containment steps in sequence, so work an analyst would otherwise repeat by hand happens automatically. A SIEM detects by correlating collected records and hands the analyst an alert, but it does not drive multi-product response on its own. EDR acts on one endpoint at a time, isolating or cleaning that host rather than coordinating action across a whole toolset. FIM watches specific files and configurations for unexpected change and reports it, with no orchestration role.

  32. A manager is comparing SIEM and SOAR for the SOC. Which statement best captures the primary distinction between the two?

    • A.SIEM encrypts archived documents to guard secrets, while SOAR signs message traffic using gateways
    • B.SIEM rotates account passwords to block misuse, while SOAR filters inbound packets using firewalls
    • C.SIEM images infected laptops to store evidence, while SOAR restores deleted archives using backups
    • D.SIEM correlates logged records to expose threats, while SOAR drives response steps using playbooks
    Show answerHide answer

    Correct answer: SIEM correlates logged records to expose threats, while SOAR drives response steps using playbooks

    The split is detection versus response. A SIEM ingests records from many sources, normalizes them and correlates them so a threat becomes visible as an alert; SOAR takes that alert and runs an automated playbook across the other tools to enrich, decide and contain. Neither product is defined by cryptography: encrypting stored records and signing messages are jobs for storage encryption and mail security. Neither one administers accounts or firewalls: password rotation belongs to identity management and packet filtering to the firewall itself. Neither performs forensic imaging or backup restoration, which sit with the forensics and recovery teams.

  33. A vendor offers a platform that ingests and correlates telemetry from endpoints, network, cloud workloads, identity, and email into one unified detection-and-response console, so analysts can see a full attack chain across layers. Which technology is described?

    • A.MDM, mobile device management
    • B.XDR, extended threat coverage
    • C.WAF, web application firewall
    • D.CASB, cloud service brokering
    Show answerHide answer

    Correct answer: XDR, extended threat coverage

    XDR is defined by breadth: it takes native telemetry from endpoints, network sensors, cloud workloads, identity systems and mail, correlates it centrally and presents one console in which an analyst can follow an attack from the first click to the final action. MDM enrolls and configures phones and tablets and reports only on those devices. A WAF sits in front of a web application and inspects HTTP requests for injection and abuse, seeing nothing beyond that application. A CASB governs how users reach cloud services and enforces policy there, which is one layer of the picture rather than all of them.

  34. A security team installs agents on laptops and servers to continuously record process execution, file changes, and network connections so threats can be detected and the host isolated and remediated. Which capability is being deployed?

    • A.SIEM, historical log correlation
    • B.NAC, device posture verification
    • C.EDR, endpoint behavior telemetry
    • D.DLP, outbound content protection
    Show answerHide answer

    Correct answer: EDR, endpoint behavior telemetry

    EDR puts an agent on each laptop and server that continuously records process execution, file writes and outbound connections, evaluates that behavior for attack patterns, and gives the responder the ability to isolate the machine from the network and remediate it. A SIEM collects records centrally from many systems but owns no agent on the host and cannot quarantine one. NAC evaluates a device at the moment it asks to join and grants or refuses admission, which says nothing about what the device does once it is on the network. DLP inspects outbound content to stop confidential material leaving the organization and does not track process execution.

  35. Before allowing a suspicious email attachment into the production environment, a security team detonates it inside an isolated, instrumented virtual environment to observe its behavior safely. Which technique is this?

    • A.Automated sandboxing
    • B.Static code analysis
    • C.Email quarantining
    • D.Network segmentation
    Show answerHide answer

    Correct answer: Automated sandboxing

    Automated sandboxing detonates the suspect file inside an isolated, instrumented virtual machine where its process, file and network behavior is recorded, so a verdict is reached without the sample touching production. Static code analysis inspects code without ever running it, so nothing is observed in action. Email quarantining holds a message aside for review but does not execute the attachment. Network segmentation isolates zones of the production network rather than providing an instrumented detonation environment.

  36. A web application redirects a user to their corporate identity provider, which returns a signed XML assertion confirming the user's identity so the application grants access without its own login. Which standard is being used?

    • A.LDAP, directory attribute queries
    • B.SMTP, electronic message delivery
    • C.SAML, browser federation exchange
    • D.ICMP, network reachability probes
    Show answerHide answer

    Correct answer: SAML, browser federation exchange

    SAML carries signed XML assertions from the identity provider to the service provider, and that assertion is what lets the application trust the sign-in and grant access without ever running a login of its own; this is the classic web single sign-on flow. LDAP reads and writes entries in a directory tree and answers attribute queries, but it is a lookup protocol, not a federation exchange between two organizations. SMTP moves mail between servers. ICMP carries reachability and error messages such as echo requests and destination-unreachable notices, and it has no identity role at all.

  37. A mobile app needs to access a user's photos stored in a cloud service without ever receiving the user's password, instead receiving a scoped access token granting limited permission. Which framework provides this delegated authorization?

    • A.Kerberos, encrypted ticket exchanges
    • B.RADIUS, centralized password lookups
    • C.SAML, federated identity credentials
    • D.OAuth, restricted application grants
    Show answerHide answer

    Correct answer: OAuth, restricted application grants

    OAuth exists precisely so an application can act on a resource owner's behalf without ever seeing the password: the user approves a limited scope, and the application receives a token that carries only that scope and can be revoked later. Kerberos issues encrypted tickets inside a realm to prove who a principal is, which authenticates a session rather than handing a stranger's app a narrow slice of someone's data. RADIUS centralizes account checks for network and remote-access equipment. SAML passes signed assertions so a site can trust a sign-in, establishing identity rather than granting scoped reach into stored photos.

  38. A developer needs not only to authorize access to an API but also to verify the end user's identity, so they add an identity layer that issues a signed ID token on top of the existing authorization framework. Which protocol provides this identity layer?

    • A.IPsec, network traffic protection
    • B.OIDC, standardized profile claims
    • C.LDAP, hierarchical record lookups
    • D.SCIM, remote account provisioning
    Show answerHide answer

    Correct answer: OIDC, standardized profile claims

    OIDC sits on top of OAuth 2.0 and adds what OAuth deliberately leaves out: a signed ID token plus a standard set of claims describing the end user, so the application learns who signed in as well as what the caller is allowed to reach. IPsec protects packets between two network endpoints and says nothing about who the human is. LDAP answers queries against a directory tree; an application can look a person up there, but no signed assertion is produced for it to trust. SCIM automates creating, updating and deleting accounts across systems, which is provisioning rather than sign-in.

  39. After authenticating once to a central identity service in the morning, an employee can open the email, HR, and expense applications all day without re-entering credentials. Which capability does this describe?

    • A.SSO, multi-application logon reuse
    • B.FIM, cross-domain identity sharing
    • C.IdP, application identity issuer
    • D.MFA, layered identity verification
    Show answerHide answer

    Correct answer: SSO, multi-application logon reuse

    SSO, multi-application logon reuse, is the capability described: one morning authentication is accepted by email, HR and expense applications for the rest of the day. FIM is wrong because federation shares identities across separate organizations or domains, not among one company's internal apps. IdP is wrong because the identity provider is the central service that issues identity assertions to each application, not the capability of reusing its login. MFA is wrong because it adds verification factors to a login rather than letting one login be reused.

  40. An organization assigns permissions to job functions such as 'Help Desk' and 'Accountant,' and users receive access by being placed into the role that matches their position. Which access control model is in use?

    • A.ABAC, position-attribute policy checks
    • B.RuBAC, admin-defined policy rule check
    • C.RBAC, position-based privilege bundles
    • D.DAC, owner-assigned group policy grant
    Show answerHide answer

    Correct answer: RBAC, position-based privilege bundles

    RBAC, position-based privilege bundles, is role-based access control: permissions are attached to a job function and a person gains them by being placed in that role. ABAC could read a position attribute, but it evaluates policies over many attributes per request rather than granting access through membership in a named role. RuBAC applies administrator-written rules, such as time-of-day or source restrictions, to every user alike regardless of job. DAC lets the owner of each resource decide who gets access, so rights would follow the owner's choices rather than the job title.

  41. An organization needs access decisions that consider multiple dynamic conditions at once, such as the user's department, the device's compliance state, the time of day, and the resource's classification. Which access control model evaluates these characteristics to make a decision?

    • A.RBAC, group-linked privilege inheritance
    • B.MAC, system-enforced clearance decisions
    • C.DAC, owner-determined resource authority
    • D.ABAC, policy-driven attribute evaluation
    Show answerHide answer

    Correct answer: ABAC, policy-driven attribute evaluation

    ABAC writes access as policy over attributes, so the decision engine can weigh the requester's department, the posture of the device, the hour of the request and the classification of the resource together, and the answer can differ from one request to the next. RBAC can only ask which role someone holds, so device state and time of day are outside what it can express. MAC compares a fixed clearance against a fixed label and ignores dynamic conditions. DAC leaves the decision with the resource owner, who is not evaluating compliance state at request time.

  42. A security architect must choose between RBAC and ABAC for a system needing fine-grained, context-sensitive decisions. Which statement correctly distinguishes the two models?

    • A.RBAC follows a stored clearance label, while ABAC weighs invoice, ledger and payroll record
    • B.RBAC follows a granted job role, while ABAC weighs subject, resource and environment status
    • C.RBAC follows a shared directory listing, while ABAC weighs cabling, socket and switch ports
    • D.RBAC follows a scheduled backup index, while ABAC weighs banner, footer and template layout
    Show answerHide answer

    Correct answer: RBAC follows a granted job role, while ABAC weighs subject, resource and environment status

    The real difference is what each model is allowed to look at. RBAC resolves a request by asking which job function the person holds and what that function may do, while ABAC evaluates a policy over attributes of the subject, the resource and the surrounding environment, which is why it can express fine-grained, context-sensitive rules. Clearance labels belong to mandatory access control and a directory listing of owner-set rights to discretionary access control, so neither pairing describes these two models. Backup catalogues, cabling and page templates are not inputs either model can evaluate.

  43. On a Windows file server, the user who creates a folder can decide which other users are granted read or write access to it at their own discretion. Which access control model does this illustrate?

    • A.MAC, policy-locked sensitivity checks
    • B.DAC, owner-assigned privilege entries
    • C.RBAC, function-based authority groups
    • D.ABAC, condition-weighted access rules
    Show answerHide answer

    Correct answer: DAC, owner-assigned privilege entries

    DAC is the model in which the person who owns an object controls its access list, which is exactly what happens when the creator of a folder decides who else may read or write it. MAC would take that choice away: the system compares a label it assigned against a clearance, and the owner cannot widen it. RBAC would tie the rights to a job function, so membership of a role rather than the creator's preference would decide. ABAC would evaluate conditions such as device posture or time at the moment of the request, none of which the folder creator is setting.

  44. In a high-security government system, every file is assigned a sensitivity label such as Secret or Top Secret, and the operating system, not the file owner, decides access based on each user's clearance. Which access control model is enforced?

    • A.DAC, owner-delegated permission editing
    • B.RBAC, office-based privilege assignment
    • C.ABAC, runtime-weighted access decisions
    • D.MAC, kernel-enforced label restrictions
    Show answerHide answer

    Correct answer: MAC, kernel-enforced label restrictions

    MAC is enforced by the system itself: each object carries a sensitivity label, each subject carries a clearance, and the operating system compares them on every request, so neither the owner nor the user can widen access. DAC does the opposite by handing that decision to the owner of the object. RBAC decides from the job function a person holds, which classified systems still use for administration but which is not what the clearance comparison here describes. ABAC evaluates dynamic conditions in policy rather than enforcing a fixed classification hierarchy.

  45. A security policy ensures that each user account is given only the permissions strictly necessary to perform that person's job and nothing more. Which principle is being applied?

    • A.Least privilege policy
    • B.Implicit deny access policy
    • C.Role-based access policy
    • D.Just-in-time access
    Show answerHide answer

    Correct answer: Least privilege policy

    A least privilege policy grants each account only the permissions strictly necessary for its job and nothing more, which is exactly what the stem describes. An implicit deny access policy blocks any request that no rule explicitly allows; it governs unmatched traffic, not how many rights an account holds. A role-based access policy assigns permissions by job role, but a role can still carry far more rights than the work needs, so it is a model, not the minimising principle. Just-in-time access limits WHEN elevated rights exist, not how narrowly they are scoped.

  46. A bank requires that initiating a wire transfer and approving it must be performed by two different employees so that no single person can complete the entire transaction alone. Which security principle is being enforced?

    • A.Retention of records
    • B.Escalation of alerts
    • C.Separation of duties
    • D.Validation of inputs
    Show answerHide answer

    Correct answer: Separation of duties

    Separation of duties breaks a sensitive process into steps held by different people, so initiating a payment and approving it are never in the same pair of hands and fraud would require collusion. Retention of records keeps evidence of what happened for a defined period; it supports an investigation afterwards but leaves one clerk able to finish the transfer today. Escalation of alerts routes a suspicious event to a higher tier of responders, which is a monitoring path rather than a division of the work itself. Validation of inputs checks that submitted data is well formed and never asks who submitted it.

  47. An organization deploys a solution so that administrators must check out elevated credentials from a vault for a specific, time-limited session, with all privileged activity recorded and the password rotated afterward. Which capability is this?

    • A.PAM, monitored administrative checkout
    • B.SSO, cross-application session sharing
    • C.MFA, supplementary factor verification
    • D.DLP, sensitive document classification
    Show answerHide answer

    Correct answer: PAM, monitored administrative checkout

    PAM is the discipline built around administrative accounts: the credential lives in a vault, an administrator draws it for a defined window, the whole session is recorded for later review, and the password is changed once the window closes so a copied secret is worthless. SSO removes repeated logins for ordinary applications and grants no elevated rights. MFA strengthens how any account proves itself but does not vault, time-box or rotate anything. DLP examines content leaving the organization and has no role in issuing or auditing administrative credentials.

  48. Employees in a marketing team begin using an unsanctioned cloud file-sharing service to collaborate, without IT's knowledge or approval. What does this situation represent, and why is it a security concern?

    • A.Insider threat, because staff are copying company data to outside apps
    • B.Shadow IT, because unmanaged services sidestep patching and monitoring
    • C.Third-party risk, because outside vendors are storing the team's files
    • D.BYOD risk, because personal devices and accounts are bypassing the MDM
    Show answerHide answer

    Correct answer: Shadow IT, because unmanaged services sidestep patching and monitoring

    Shadow IT, because unmanaged services sidestep patching and monitoring, is correct: the team adopted a cloud tool without IT's knowledge or approval, so nobody secures, logs or offboards it. An insider threat requires an employee to misuse legitimate access with harmful intent, and these staff are only trying to collaborate. Third-party risk concerns vendors the organization has vetted and contracted, whereas this service was never approved at all. BYOD risk concerns personal devices under mobile device management, and the scenario is about an unsanctioned cloud service, not devices.

  49. A SOC analyst documents an attack by mapping each observed adversary behavior, such as spearphishing, credential dumping, and lateral movement, to standardized tactic and technique identifiers in a globally recognized knowledge base. Which framework is being used?

    • A.The OWASP core application weaknesses
    • B.The PCI cardholder audit requirements
    • C.The MITRE ATT&CK reference collection
    • D.The ISO/IEC quality management series
    Show answerHide answer

    Correct answer: The MITRE ATT&CK reference collection

    MITRE ATT&CK is the curated, publicly maintained body of adversary tactics and techniques, each with a stable identifier, which is why analysts use it to describe what an intruder did in language another team will read the same way. OWASP publishes the widely cited list of common web application weaknesses, which describes coding flaws rather than intruder behavior. The PCI requirements govern how cardholder data must be handled by merchants. The ISO/IEC quality management series concerns how an organization runs quality processes and has nothing to do with intrusions.

  50. An organization deploys a tool that computes cryptographic hashes of critical system files and configuration files, then alerts the SOC whenever any of those hashes change unexpectedly. Which control is this?

    • A.NTP, authenticated clock synchronization
    • B.DLP, confidential content classification
    • C.CASB, sanctioned application enforcement
    • D.FIM, unauthorized modification detection
    Show answerHide answer

    Correct answer: FIM, unauthorized modification detection

    FIM takes a cryptographic fingerprint of the files that matter, stores it as a baseline, and re-computes it on a schedule, so any edit to a binary or a configuration file that nobody approved shows up as a mismatch and raises an alert. NTP keeps clocks aligned so that timestamps across systems can be compared; it inspects no files. DLP examines content on its way out of the organization and cares about where data is going rather than whether a system file was altered. CASB governs how users reach cloud services and sees nothing on the host.

  51. A SOC consolidates log records from hundreds of servers, network devices, and applications into a single central repository so analysts can search and correlate them in one place. What is this practice called?

    • A.Log compression
    • B.Log aggregation
    • C.Log obfuscation
    • D.Log attestation
    Show answerHide answer

    Correct answer: Log aggregation

    Aggregation is the act of bringing records from hundreds of separate sources into a single store, which is what makes a cross-system search or correlation possible at all. Compression shrinks the space those records occupy and changes nothing about where they live. Obfuscation deliberately hides field values so a reader cannot recover the original detail, which works against an analyst trying to investigate. Attestation proves a stored record has not been altered since it was written, a valuable integrity property that still leaves the records scattered across every device that produced them.

  52. An IT team establishes a documented, approved standard configuration that defines required settings, enabled services, and security parameters that all newly built web servers must conform to. What is this standard called?

    • A.Security baseline
    • B.Security policy
    • C.Vendor hardening guide
    • D.CIS hardening guide
    Show answerHide answer

    Correct answer: Security baseline

    A security baseline is the documented, approved configuration every new server must match: the required settings, permitted services and mandatory security parameters, and the yardstick later drift is measured against. A security policy states high-level management intent and rules, not per-server settings. A vendor hardening guide is the manufacturer's published recommendation, which the team may draw on but which is not its own approved standard. A CIS hardening guide is likewise an external benchmark of suggested settings; the baseline is the organization's approved configuration built from such sources.

  53. An administrator establishes a structured process to identify missing updates, test fixes, schedule deployment, and verify installation across all endpoints and servers on a regular cadence. Which security operations process is this?

    • A.Change management
    • B.Configuration management
    • C.Patch management
    • D.Asset management
    Show answerHide answer

    Correct answer: Patch management

    Patch management is the full lifecycle of identifying missing updates, testing fixes, scheduling deployment, and verifying installation on a regular cadence. Change management approves and records changes of every kind but does not find missing updates itself. Configuration management maintains secure baselines and settings rather than tracking vendor fixes. Asset management inventories hardware and software, which feeds patching but does not test or deploy anything.

  54. Following a suspected breach, a specialist applies a structured process to identify, collect, preserve, analyze, and report on digital evidence from computers and storage media in a way that maintains its integrity for potential legal proceedings. Which discipline is this?

    • A.Incident response
    • B.E-discovery
    • C.Chain of custody
    • D.Digital forensics
    Show answerHide answer

    Correct answer: Digital forensics

    Digital forensics is the discipline that identifies, collects, preserves, analyzes and reports on digital evidence in a way that keeps its integrity for legal proceedings. Incident response is the broader process of detecting, containing and recovering from a breach, and it calls on forensics rather than being it. E-discovery is the legal process of identifying and producing electronically stored information for litigation, not analyzing a breach. Chain of custody is the record of who handled evidence, one control within forensics rather than the discipline.

  55. Which phase of the incident response process focuses on limiting the spread and impact of an active incident, such as isolating an infected host from the network?

    • A.Incident remediation
    • B.Incident escalation
    • C.Incident containment
    • D.Incident detection
    Show answerHide answer

    Correct answer: Incident containment

    Incident containment is the phase that limits the spread and impact of an active incident, for example by isolating an infected host from the network. Incident remediation fixes the underlying weakness after the threat is removed rather than stopping its spread. Incident escalation passes the incident to a higher authority or team and does not itself limit damage. Incident detection identifies that an incident is occurring and comes before any action to restrict it.

  56. In the incident response lifecycle, which activity is performed during the 'lessons learned' phase?

    • A.Documenting evidence to keep a chain of custody
    • B.Documenting affected hosts to scope eradication
    • C.Documenting findings to improve later responses
    • D.Documenting baselines to catch future anomalies
    Show answerHide answer

    Correct answer: Documenting findings to improve later responses

    Documenting findings to improve later responses is the lessons learned activity: after the incident closes, the team reviews what happened and updates plans, playbooks and controls. Documenting evidence to keep a chain of custody is a forensic task during the response. Documenting affected hosts to scope eradication happens while the incident is still being handled. Documenting baselines to catch future anomalies is preparation and detection work, not a post-incident review.

  57. During which incident response phase would an organization develop its IR plan, assemble the response team, and train staff before any incident occurs?

    • A.Incident preparation
    • B.Post-incident review
    • C.Disaster recovery planning
    • D.Incident recovery planning
    Show answerHide answer

    Correct answer: Incident preparation

    Writing the IR plan, assembling the team and training staff before anything happens is incident preparation, the first phase of the incident response lifecycle. A post-incident review, or lessons learned, happens after an incident and may revise the plan, but it cannot come before any incident occurs. Disaster recovery planning prepares for restoring IT after a major outage, which is a separate plan from the incident response phases. Incident recovery planning concerns restoring systems once a threat has been eradicated, which is later in the lifecycle.

  58. A response team has removed malware and confirmed the threat is gone. They now rebuild systems from clean backups and return them to normal operation while monitoring for reinfection. Which incident response phase is this?

    • A.Malware eradication
    • B.Service restoration
    • C.Network containment
    • D.Evidence collection
    Show answerHide answer

    Correct answer: Service restoration

    Correct answer: service restoration. Recovery is the phase that rebuilds or restores affected systems from clean backups, validates that they function correctly and returns them to production under close monitoring for signs that the threat has returned. Malware eradication is the step that has already been completed in this scenario. Network containment isolated the systems earlier, before the threat was removed. Evidence collection preserves artifacts and restores no service.

  59. Which incident response activity involves completely removing the cause of an incident, such as deleting malicious files, disabling breached accounts, and closing exploited vulnerabilities?

    • A.Incident eradication
    • B.Incident recovery
    • C.Incident isolation
    • D.Incident sanitization
    Show answerHide answer

    Correct answer: Incident eradication

    Incident eradication is the phase that removes the cause entirely: deleting malicious files, disabling breached accounts and closing exploited vulnerabilities. Incident recovery follows eradication and returns cleaned systems to production. Incident isolation is a containment action that stops the spread but leaves the malicious artifacts in place. Incident sanitization is not a response phase; sanitization refers to wiping storage media so data cannot be recovered before reuse or disposal.

  60. An organization runs a discussion-based exercise where the IR team walks through their response to a hypothetical ransomware scenario around a conference table, without touching any production systems. What type of exercise is this?

    • A.Simulation exercise
    • B.Workshop exercise
    • C.Tabletop exercise
    • D.Functional exercise
    Show answerHide answer

    Correct answer: Tabletop exercise

    This is a tabletop exercise: the response team sits around a table and talks through roles, decisions and dependencies for a hypothetical scenario, so the plan is validated without touching production. A simulation exercise acts out the incident with injected events and live tools. A workshop exercise is a discussion session aimed at producing a deliverable such as a plan or policy, not walking through a response. A functional exercise exercises real operations and systems in a controlled setting.

  61. In digital forensics, what is the purpose of maintaining a chain of custody for collected evidence?

    • A.To preserve the evidence from routine purge cycles
    • B.To record the evidence handlers with precise times
    • C.To capture the evidence in order of its volatility
    • D.To image the evidence via a hardware write blocker
    Show answerHide answer

    Correct answer: To record the evidence handlers with precise times

    Chain of custody exists to record the evidence handlers with precise times: every person who collected, accessed, transferred or stored an item, and when, so the evidence can be shown untampered and stays admissible. Preserving evidence from routine purge cycles is a legal hold. Capturing evidence in order of volatility is the collection sequence, not a handling record. Imaging through a hardware write blocker protects the original during acquisition but documents nobody who handled it.

  62. When collecting digital evidence, which principle dictates the order in which sources should be captured, prioritizing the most volatile data first?

    • A.Rules of engagement
    • B.Order of volatility
    • C.Chain of possession
    • D.Right of inspection
    Show answerHide answer

    Correct answer: Order of volatility

    Correct answer: order of volatility. The order of volatility ranks evidence sources by how quickly they disappear, so CPU registers, cache, RAM and network state are captured before disk images and archived logs, because the volatile sources are lost the moment power or connectivity changes. Rules of engagement define the scope and limits of an authorized test. Chain of possession documents who handled evidence, not the sequence in which sources are captured. A right of inspection is a contractual clause permitting review of a partner's controls.

  63. A company instructs employees to stop deleting emails and documents related to a pending lawsuit so the data is preserved as potential evidence. What is this directive called?

    • A.Retention policy
    • B.Chain of custody
    • C.E-discovery
    • D.Litigation hold
    Show answerHide answer

    Correct answer: Litigation hold

    The directive is a litigation hold, also called a legal hold, which suspends normal deletion so records relevant to anticipated or pending litigation are preserved. A retention policy is the standing schedule for keeping and destroying records and is not triggered by a lawsuit. Chain of custody documents who handled evidence after it is collected. E-discovery is the wider process of identifying and producing electronic records, not the instruction to stop deleting them.

  64. In security alerting, what does the term 'false positive' describe?

    • A.A real intrusion that sensors wrongly ignored
    • B.A harmless event the sensors rightly ignored
    • C.A real intrusion that sensors rightly flagged
    • D.A harmless action wrongly reported as hostile
    Show answerHide answer

    Correct answer: A harmless action wrongly reported as hostile

    A false positive is a harmless action wrongly reported as hostile: an alert fires on benign activity, and a high volume of them causes alert fatigue that makes analysts dismiss real detections. A real intrusion that sensors wrongly ignored is a false negative. A harmless event the sensors rightly ignored is a true negative. A real intrusion that sensors rightly flagged is a true positive, a correct detection.

  65. A security tool fails to generate any alert for an actual intrusion that successfully occurred. What is this missed detection called?

    • A.A breach alert drowning in floods of false alarms
    • B.A breach slipping past deployed detection systems
    • C.A breach alert raised, then closed without triage
    • D.A breach alert raised late by the detection tools
    Show answerHide answer

    Correct answer: A breach slipping past deployed detection systems

    A breach slipping past deployed detection systems is a false negative: real malicious activity occurred and the tool generated no alert at all, which lets the compromise continue unnoticed. A breach alert drowning in floods of false alarms describes alert fatigue, where an alert existed but was missed by analysts. A breach alert raised, then closed without triage is a process failure after a true positive. A breach alert raised late by the detection tools is delayed detection, yet the stem says no alert was ever generated.

  66. Which process establishes a definition of typical, normal activity for a system or network so that deviations from it can be flagged as anomalies?

    • A.Baselining
    • B.Heuristics
    • C.Benchmarking
    • D.Normalization
    Show answerHide answer

    Correct answer: Baselining

    Baselining records what normal looks like for a system or network, such as typical traffic volumes, login times and resource use, so monitoring can compare live activity against it and flag anomalies. Heuristics judge a file or behavior by suspicious traits, not against a recorded norm for that environment. Benchmarking compares a configuration with a hardening standard such as a CIS benchmark, which defines secure settings rather than normal activity. Normalization converts logs from different sources into a common format for a SIEM, which is about data structure, not what typical behavior looks like.

  67. An organization continuously evaluates whether its deployed security controls remain effective and compliant by automatically checking system configurations against required standards. Which capability is this?

    • A.Quarterly attestation
    • B.Periodic snapshotting
    • C.Automated remediation
    • D.Continuous monitoring
    Show answerHide answer

    Correct answer: Continuous monitoring

    Correct answer: continuous monitoring. Continuous monitoring is the ongoing automated assessment of systems, configurations and controls against required standards, giving near real-time visibility into posture and flagging drift as soon as it appears. Quarterly attestation samples compliance at four points a year and leaves long blind windows between them. Periodic snapshotting preserves recoverable copies of state and evaluates no control. Automated remediation corrects findings after they have been raised rather than performing the evaluation itself.

  68. Which network management protocol is commonly used to collect device health and performance metrics, but in older versions transmits community strings in plaintext, creating a security concern?

    • A.ICMP
    • B.LDAP
    • C.SMTP
    • D.SNMP
    Show answerHide answer

    Correct answer: SNMP

    Correct answer: SNMP. The Simple Network Management Protocol polls device health and performance data from routers, switches and servers, and in versions 1 and 2c the community string that authorizes those reads travels in cleartext, which is why SNMPv3 with authentication and privacy is required. ICMP carries reachability and error messages, not device metrics. LDAP queries a directory. SMTP transports mail between servers.

  69. What is the key behavioral difference between an Intrusion Detection System (IDS) and an Intrusion Prevention System (IPS)?

    • A.An IDS detects anomalies by baseline while an IPS matches known signatures
    • B.An IDS reports suspected packets passively while an IPS blocks them inline
    • C.An IDS matches known signatures while an IPS detects anomalies by baseline
    • D.An IDS guards a single host while an IPS blocks threats across the network
    Show answerHide answer

    Correct answer: An IDS reports suspected packets passively while an IPS blocks them inline

    An IDS reports suspected packets passively while an IPS blocks them inline: the detection system watches a copy of the traffic and alerts, while the prevention system sits in the path and can drop or reset a session. Signature matching and baseline anomaly detection are methods both systems use, so neither pairing separates them. Both come in host-based and network-based forms, so scope is not the difference either.

  70. A firewall rule set ends with a final rule that denies any traffic not explicitly permitted by earlier rules. What is this concept called?

    • A.Implicit deny
    • B.Explicit deny
    • C.Fail-closed default
    • D.Secure by default
    Show answerHide answer

    Correct answer: Implicit deny

    The catch-all rule at the bottom that refuses anything not permitted earlier is implicit deny. An explicit deny is a written rule that blocks named traffic, such as a specific address or port, rather than everything left over. Fail-closed describes how a device behaves when it crashes or loses power, blocking traffic instead of passing it. Secure by default is a broad design principle for shipping hardened settings, not the name of the final firewall rule.

  71. Which type of firewall can make filtering decisions based on the application and user identity, integrate IPS functions, and perform deep packet inspection, going beyond simple port and protocol rules?

    • A.Next-generation firewall
    • B.Packet-filtered firewall
    • C.Screened-subnet firewall
    • D.Perimeter-based firewall
    Show answerHide answer

    Correct answer: Next-generation firewall

    Correct answer: next-generation firewall. An NGFW adds application awareness, user identity from the directory, deep packet inspection and an integrated intrusion prevention engine on top of traditional firewall functions, so policy can name an application and a user rather than a port. A packet-filtered firewall decides only on addresses, ports and protocol flags. A screened-subnet firewall describes a DMZ topology rather than an inspection capability. A perimeter-based firewall names where the device sits, not how deeply it inspects.

  72. An organization deploys a control that inspects employee web requests and blocks access to gambling, malware-hosting, and other policy-violating sites based on URL categories. Which capability is this?

    • A.Content filtering
    • B.Packet filtering
    • C.Stateful packet filtering
    • D.Web app firewall
    Show answerHide answer

    Correct answer: Content filtering

    Blocking employee web requests by URL category, such as gambling or malware hosting, is content filtering, typically enforced by a proxy or secure web gateway. Packet filtering permits or drops traffic by IP address, port and protocol, and it cannot tell a gambling URL from any other site on the same port. Stateful packet filtering adds connection tracking to those same address and port rules, so it still never sorts destinations into acceptable use categories. A web app firewall protects the organization's own web applications from inbound attacks, not employees' outbound browsing.

  73. Which security control prevents users from reaching known-malicious domains by intercepting and blocking name resolution requests at the DNS layer?

    • A.DNS sinkholing
    • B.DNS forwarding
    • C.DNS delegation
    • D.DNS validation
    Show answerHide answer

    Correct answer: DNS sinkholing

    A DNS sinkhole answers a lookup for a known-malicious domain with a controlled address or a refusal, so the client never learns where the real host is and the session is never opened. DNS forwarding only hands a query to another resolver to answer. DNS delegation points a subdomain at a different authoritative server. DNS validation checks the DNSSEC signatures on a response, which proves the answer was not tampered with but says nothing about whether the domain is malicious.

  74. An email security gateway adds DMARC, DKIM, and SPF checks. What is the primary purpose of these three mechanisms together?

    • A.To shrink the message so that transfers move faster
    • B.To store the message for the whole retention period
    • C.To prove the message came from an authorised sender
    • D.To encrypt the message before it leaves the gateway
    Show answerHide answer

    Correct answer: To prove the message came from an authorised sender

    SPF lists the hosts allowed to send for the domain, DKIM signs the message so a receiver can check that signature against a key published in DNS, and DMARC ties the two together with a policy the domain owner publishes. Their combined job is authenticating the sending domain, which is what removes the value from spoofed mail. Shrinking a message is a transport optimisation. Keeping copies for a retention period is archiving. Encrypting the body protects confidentiality, and an encrypted message can still carry a forged sender address.

  75. Which hardening practice reduces a system's attack surface by removing software, services, and accounts that are not required for its function?

    • A.Blocking the inbound ports at the firewall
    • B.Updating the running services on the image
    • C.Limiting the service accounts on the image
    • D.Deleting the unused services on a new host
    Show answerHide answer

    Correct answer: Deleting the unused services on a new host

    Deleting the unused services on a new host is the hardening practice that removes unnecessary software, services and accounts, so less code listens and fewer credentials exist to attack. Blocking inbound ports at the firewall filters traffic but leaves the software installed and running. Updating the running services on the image patches flaws without removing anything. Limiting the service accounts on the image reduces their privileges but keeps those accounts in place.

  76. What is the security purpose of changing or disabling default vendor credentials on a newly deployed device?

    • A.To stop default services that run on open ports
    • B.To stop admin passwords that cross in cleartext
    • C.To stop admin sessions that cross in cleartext
    • D.To stop logins that use known default passwords
    Show answerHide answer

    Correct answer: To stop logins that use known default passwords

    Changing or disabling vendor default credentials serves to stop logins that use known default passwords, because those usernames and passwords are published in manuals and public lists. Stopping default services that run on open ports is a separate hardening step, disabling unneeded services, and a changed password leaves those services running. Stopping admin passwords that cross in cleartext requires encrypted management protocols such as SSH or HTTPS, since even a new password is readable on the wire. Stopping admin sessions that cross in cleartext likewise depends on encrypting the session, not on which password was set.

  77. An organization uses a configuration management tool to ensure all production servers continuously match an approved secure template, automatically correcting any drift. This is an example of enforcing what?

    • A.A golden image the servers are cloned from
    • B.A patch level the servers must match
    • C.A patch window the servers must restart in
    • D.A hardened baseline the servers must match
    Show answerHide answer

    Correct answer: A hardened baseline the servers must match

    A hardened baseline the servers must match is the approved secure configuration that configuration management compares production against, correcting any drift so every server stays in a known-good state. A golden image is the template new servers are cloned from at build time; it does not continuously check or correct running servers. A patch level covers only which updates are installed, not the full secure configuration. A patch window is the scheduled maintenance period for restarts, a timing control rather than a configuration standard.

  78. Which mobile device deployment model allows employees to use their personally owned devices to access corporate resources, raising data separation and management challenges?

    • A.BYOD
    • B.COSU
    • C.MDM
    • D.MAM
    Show answerHide answer

    Correct answer: BYOD

    BYOD is the deployment model in which employees use personally owned devices for work, which is why separating corporate from personal data and managing hardware the company does not own are the hard problems. COSU is a corporate-owned, single-use device locked to one task. MDM is mobile device management, the tool used to enforce policy on devices, not a model of who owns them. MAM is mobile application management, which controls corporate apps and data and is often used with BYOD but is not itself the deployment model.

  79. A company centrally enforces encryption, app restrictions, and remote-wipe policies across all enrolled smartphones and tablets. Which technology provides this?

    • A.DLP
    • B.MDM
    • C.NAC
    • D.EDR
    Show answerHide answer

    Correct answer: MDM

    MDM enrols phones and tablets and pushes policy to them centrally: encryption requirements, passcode rules, application restrictions and remote lock or wipe. DLP inspects content to stop sensitive data leaving, but it does not enrol or configure a device. NAC decides whether a device is admitted to the network. EDR watches endpoint process behaviour for attacks and supports response. None of the three enforces a device configuration policy across a mobile fleet.

  80. During secure asset disposal, which method guarantees data cannot be recovered by physically destroying the storage media?

    • A.Degaussing the drive under a strong magnet
    • B.Drilling a hole through the drive's casing
    • C.Shredding the drive into small metal chips
    • D.Smashing the drive's controller board flat
    Show answerHide answer

    Correct answer: Shredding the drive into small metal chips

    Shredding the drive into small metal chips physically destroys the media, which is why it guarantees the data cannot be recovered. Degaussing the drive under a strong magnet is a purge method, not physical destruction, and it has no effect on flash-based SSDs. Drilling a hole through the drive's casing damages the enclosure but can leave platter surfaces readable. Smashing the drive's controller board flat destroys only the electronics, so the platters or flash chips can be moved to a working board and read.

  81. On a mobile device, which technology cryptographically and logically separates personal data and apps from corporate data and apps?

    • A.A shared network link through the device
    • B.A fixed zone perimeter around the device
    • C.A private work profile inside the device
    • D.A provider lock released from the device
    Show answerHide answer

    Correct answer: A private work profile inside the device

    Containerization puts corporate apps and data in an encrypted, isolated work profile that the organization manages and can wipe on its own, while the user's personal content stays outside it and untouched. A shared network link is tethering, which lends the handset's connection to other devices. A fixed zone perimeter is geofencing, which triggers actions based on where the device is. Releasing the provider lock is carrier unlocking, which frees the handset for another network. None of the three separates work data from personal data.

  82. After a vulnerability scan, which step prioritizes findings so the most critical, exploitable, and high-impact vulnerabilities are remediated first?

    • A.Sending the findings to the helpdesk queue
    • B.Ordering the findings by the greatest risk
    • C.Checking the findings after the patch runs
    • D.Archiving the findings for the audit trail
    Show answerHide answer

    Correct answer: Ordering the findings by the greatest risk

    Prioritisation is the analysis step between finding and fixing: severity, exploitability, asset criticality and exposure are weighed together so limited remediation capacity goes to the vulnerabilities that carry the most risk. Sending findings to a queue is ticketing, which moves work without ranking it. Checking after a patch runs is remediation validation, which happens once a fix is already applied. Archiving preserves evidence for auditors. None of the three decides what gets fixed first.

  83. Which standardized framework produces a numeric severity score from 0.0 to 10.0 to help organizations rank the criticality of vulnerabilities?

    • A.CVSS
    • B.SBOM
    • C.SIEM
    • D.SOAR
    Show answerHide answer

    Correct answer: CVSS

    CVSS is the open standard that scores a vulnerability from 0.0 to 10.0 out of its exploitability and impact metrics, so findings from different tools can be compared and ranked consistently. An SBOM is an inventory of the components inside a piece of software. A SIEM collects and correlates log data for detection and investigation. SOAR automates response workflows. None of the three produces a severity rating for a vulnerability.

  84. A scanning vendor reports a vulnerability that, upon investigation, does not actually exist on the target system. In vulnerability management, what is this finding called?

    • A.False negative
    • B.True negative
    • C.True positive
    • D.False positive
    Show answerHide answer

    Correct answer: False positive

    A false positive is a finding the scanner reports that is not actually present or exploitable on the target, which is why results are validated before remediation. A false negative is the reverse: a real flaw the scan misses. A true negative correctly reports no flaw where none exists. A true positive is a reported flaw that really is there.

  85. An organization decides to accept the risk of a low-severity vulnerability it will not fix, documenting management approval. In vulnerability management, what is this response called?

    • A.Signing off the risk formally as it stands
    • B.Passing the risk to an insurer by contract
    • C.Deferring the fix to a later change window
    • D.Offsetting the risk with an added control
    Show answerHide answer

    Correct answer: Signing off the risk formally as it stands

    Signing off the risk formally as it stands is risk acceptance: management knowingly keeps the unremediated weakness and records its approval, often as a documented exception. Passing the risk to an insurer by contract is transference, which shifts the financial consequence but not the flaw. Deferring the fix to a later change window still plans remediation, whereas this organization has decided it will not fix the issue. Offsetting the risk with an added control is mitigation through a compensating control, which reduces the exposure instead of accepting it as it is.

  86. Which type of vulnerability assessment requires valid login credentials so the scanner can evaluate the system from an authenticated, insider perspective for deeper accuracy?

    • A.A scan that runs inside the local network
    • B.A scan that signs in with issued credentials
    • C.A scan that uses an agent on each local host
    • D.A scan that tries vendor default credentials
    Show answerHide answer

    Correct answer: A scan that signs in with issued credentials

    A scan that signs in with issued credentials is a credentialed scan: it logs on to the target and reads patch levels, installed packages and configuration directly, which gives the insider view and fewer false positives. A scan that runs inside the local network is an internal scan, which changes where the scanner sits but still probes unauthenticated. A scan that uses an agent on each local host is agent-based scanning, which relies on installed software rather than login credentials handed to the scanner. A scan that tries vendor default credentials is a non-credentialed check for weak logins, not an authenticated assessment.

  87. Which authentication method uses a temporary code that changes every 30 to 60 seconds and is generated by an authenticator app synchronized with the server?

    • A.A code the app derives from the clock
    • B.A code the user keeps for many months
    • C.A code the scanner reads from a badge
    • D.A code the vault stores for each site
    Show answerHide answer

    Correct answer: A code the app derives from the clock

    TOTP combines a shared secret with the current time, so the authenticator app and the server compute the same value independently and it expires within a fixed interval, leaving a captured code useless moments later. A code kept for months is a static password, reusable by anyone who steals it. A code read out of a chip describes a smart card or token, which proves possession with no time element. A code held per site in a vault is a password manager entry, stored rather than regenerated.

  88. An administrator account's elevated permissions are automatically removed after a fixed time window unless explicitly renewed. Which access management concept enforces this?

    • A.Rights that widen when the user changes teams
    • B.Rights that expire when the short window ends
    • C.Rights that apply when the office hours begin
    • D.Rights that renew when the annual review runs
    Show answerHide answer

    Correct answer: Rights that expire when the short window ends

    Just-in-time access grants elevated permissions only for the interval they are needed and revokes them automatically when it closes, so no standing administrative privilege sits on the account waiting to be abused. Rights that widen as someone moves between teams is privilege creep, the accumulation this control exists to prevent. Rights bounded by office hours are time-of-day restrictions, which limit when a standing permission works. Rights renewed at an annual review are periodic recertification, far too slow to be the mechanism described.

  89. Which password policy control prevents users from immediately reusing a recent password by remembering and rejecting a set number of prior passwords?

    • A.A rule that rejects changes within one day
    • B.A rule that rejects any breached passwords
    • C.A rule that rejects the last few passwords
    • D.A rule that rejects passwords past 90 days
    Show answerHide answer

    Correct answer: A rule that rejects the last few passwords

    Password history is a rule that rejects the last few passwords: the system remembers a set number of prior passwords and refuses any match, so a user cannot cycle straight back to a recent one. A rule that rejects changes within one day is minimum password age, which supports history by stopping rapid cycling but remembers nothing itself. A rule that rejects any breached passwords checks a blocklist of compromised values, not the user's own prior ones. A rule that rejects passwords past 90 days is maximum password age, which forces a change but does not refuse reuse.

  90. What is a primary security benefit of automating repetitive security operations tasks through scripting and orchestration?

    • A.It maps each alert to a shared threat model
    • B.It scores each finding on a ten point scale
    • C.It stores each log line in a sealed archive
    • D.It repeats each step the same way each time
    Show answerHide answer

    Correct answer: It repeats each step the same way each time

    The security value of automation is consistency: a script or playbook performs the same steps in the same order on every run, so the outcome does not vary with who is on shift and the slips that come with manual repetition disappear. Mapping alerts to a shared threat model is enrichment that adds context to a detection. Scoring findings is severity rating. Sealing log lines in an archive is retention and evidence preservation. Each is real work, but none of them is what automating a repetitive task buys.

  91. Which potential drawback should an organization weigh before automating a security process?

    • A.A single bot cuts staff retention and team morale
    • B.A single runbook slows reaction speed to an alert
    • C.A single script adds extra manual toil for staff
    • D.A single flawed rule repeats one error many times
    Show answerHide answer

    Correct answer: A single flawed rule repeats one error many times

    A single flawed rule repeats one error many times because automation applies a mistake at machine speed across every target before anyone notices, which is why automated changes need testing, staged rollout and guardrails. Cutting staff retention and morale is backwards; relieving staff of repetitive work is listed as a benefit that improves retention. Slowing reaction speed is also backwards, since faster reaction time is a core benefit of automation. Adding manual toil is the reverse of automation's role as a workforce multiplier.

  92. Which data source records authentication successes and failures, account lockouts, and privilege changes, making it essential for investigating suspicious access?

    • A.The audit log the domain controller writes
    • B.The session log the SSL VPN gateway writes
    • C.The access log the SSL proxy server writes
    • D.The alert log the inline IDS sensor writes
    Show answerHide answer

    Correct answer: The audit log the domain controller writes

    The audit log the domain controller writes is the security event log where logon successes and failures, account lockouts, and privilege or group changes are recorded, so it is the trail for suspicious access. An SSL VPN gateway session log records remote connections but not domain lockouts or privilege changes. A proxy access log records web requests. An IDS alert log records signature matches on traffic, not account events.

  93. During an investigation, analysts review records of which internal IP address was assigned a given private address at a specific time. Which log source provides this mapping?

    • A.The signature file the scanner tool loads
    • B.The cipher list the gateway daemon offers
    • C.The boot log the firmware loader produces
    • D.The lease record the address server keeps
    Show answerHide answer

    Correct answer: The lease record the address server keeps

    DHCP logs record each lease: the address handed out, the client it was given to, and the time it was granted and released, so an investigator can say which machine held a particular internal address when an event occurred. A signature file lists the detection patterns a scanner loads. A cipher list states which algorithms a service will negotiate. A boot log traces startup. None of the three ties an address to a client at a point in time.

  94. Which metadata field, captured in network flow records (such as NetFlow), is most useful for identifying which hosts communicated, how much data moved, and over which ports—without capturing packet payloads?

    • A.The subject, issuer and key size fields
    • B.The address, port and byte count fields
    • C.The file hash, owner and creator fields
    • D.The user agent, host and referer fields
    Show answerHide answer

    Correct answer: The address, port and byte count fields

    A flow record summarises one conversation: source and destination addresses, the ports and protocol, and the packet and byte counts, with no payload stored, which is exactly what is needed to say who talked to whom, over what, and how much moved. Subject, issuer and key size are certificate fields. File hash, owner and creator are filesystem and forensic attributes. User agent, host and referer are HTTP request headers. None of the three appears in a flow record.

  95. An administrator publishes a DNS TXT record listing the mail servers authorized to send email on behalf of the company's domain so receiving servers can reject spoofed messages. Which email authentication mechanism is being configured?

    • A.PGP
    • B.PKI
    • C.SPF
    • D.TLS
    Show answerHide answer

    Correct answer: SPF

    SPF is published as a DNS TXT record listing the hosts allowed to send mail for the domain, so a receiving server can compare the connecting sender against that list and reject a forgery. PGP encrypts and signs message content between users. PKI is the wider framework of certificate authorities and keys that other controls are built on. TLS encrypts the connection between mail servers. None of the three publishes a list of authorised sending hosts.

  96. A mail server attaches a cryptographic signature to outbound messages using a private key, while the matching public key is published in DNS so recipients can verify the message was not altered in transit. Which email security control is described?

    • A.SMTP
    • B.IMAP
    • C.DKIM
    • D.OCSP
    Show answerHide answer

    Correct answer: DKIM

    DKIM signs an outbound message with the sending domain's private key and publishes the matching public key in DNS, so a receiver can verify both where the message came from and that its signed content was not altered in transit. SMTP is the protocol that carries the mail. IMAP is how a client reads mail from a server. OCSP checks whether a certificate has been revoked. None of the three attaches a verifiable signature to a message.

  97. After deploying SPF and DKIM, a security team wants to instruct receiving servers how to handle messages that fail those checks and to receive aggregate reports about spoofing attempts. Which policy framework provides this?

    • A.SMTPS
    • B.LDAPS
    • C.DMARC
    • D.HTTPS
    Show answerHide answer

    Correct answer: DMARC

    DMARC is the policy layer above SPF and DKIM: the domain owner publishes what a receiver should do with mail that fails those checks and where to send the aggregate reports that reveal spoofing attempts. SMTPS and HTTPS are ordinary protocols wrapped in TLS, and LDAPS is directory access over TLS. Each of the three protects a channel between two hosts; none of them states how failing mail should be handled or reports abuse back to the domain owner.

  98. A company wants to enforce screen-lock passcodes, push security policies, and remotely wipe lost devices across hundreds of employee smartphones and tablets. Which solution provides this centralized control?

    • A.A gateway that ends the tunnels remote staff build
    • B.A firewall that inspects the traffic one host sees
    • C.A console that pushes the rules to enrolled phones
    • D.A gatekeeper that admits the hosts a policy clears
    Show answerHide answer

    Correct answer: A console that pushes the rules to enrolled phones

    Mobile device management enrols the fleet and pushes policy to it from one console: passcode and encryption requirements, application restrictions, and remote lock or wipe when a handset goes missing. A gateway that terminates staff tunnels is a VPN concentrator. A firewall that inspects what a single machine sees protects that machine only. A gatekeeper admitting hosts a policy has cleared is network access control, which governs admission rather than device configuration.

  99. An organization allows employees to use their personally owned phones for work, accepting that the company has limited control over the hardware. Which mobile deployment model does this describe?

    • A.Privately bought phones used for work
    • B.Staff-picked phones owned by the firm
    • C.Firm-owned phones staff use privately
    • D.Firm-owned phones set up for work use
    Show answerHide answer

    Correct answer: Privately bought phones used for work

    Privately bought phones used for work describe bring your own device (BYOD): the employee owns the hardware, so the organization has the least control and can manage only its own apps and data. Staff-picked phones owned by the firm describe choose your own device (CYOD), where the employee chooses from an approved list but the company owns the handset. Firm-owned phones staff use privately describe corporate-owned, personally enabled (COPE), which still leaves the hardware under company ownership. Firm-owned phones set up for work use describe corporate-owned, business only (COBO), the model with the most control.

  100. Before donating retired laptops, an organization must guarantee that no recoverable confidential data remains on the solid-state drives. Which action best ensures the data cannot be recovered?

    • A.A DoD seven-pass overwrite of the drive
    • B.A full cryptographic erase of the drive
    • C.A strong magnetic degauss of each drive
    • D.A fast zero-fill overwrite of the drive
    Show answerHide answer

    Correct answer: A full cryptographic erase of the drive

    A full cryptographic erase of the drive destroys the encryption key the solid-state drive's contents are stored under, so every block, including wear-levelled and over-provisioned cells, becomes unreadable while the laptop stays usable for donation. A DoD seven-pass overwrite and a fast zero-fill overwrite were designed for magnetic disks, and SSD wear levelling leaves cells the host can never address. Degaussing relies on magnetic media, so it has no effect on the flash memory in a solid-state drive.

  101. A SOC wants metadata about network conversations such as source and destination IPs, ports, and byte counts to baseline traffic and detect anomalies, without capturing full packet payloads. Which data source provides this?

    • A.Flow records exported by the core routers
    • B.Packet captures written by the tap probes
    • C.Syslog messages queued by the relay hosts
    • D.Virus alerts raised by the desktop agents
    Show answerHide answer

    Correct answer: Flow records exported by the core routers

    Flow records summarise each conversation by address, port, protocol and volume without keeping payload, which is what makes them cheap enough to retain for baselining traffic and spotting anomalies. Packet captures do keep the payload and cost far more storage. Syslog messages carry event text from devices and applications rather than a per-conversation traffic summary. Antivirus alerts report malware findings on individual endpoints. None of the three gives network-wide conversation metadata.

  102. A network team uses a protocol that lets a management station poll routers and switches for performance counters and receive unsolicited trap notifications about device events. Which protocol provides this monitoring capability?

    • A.LDAP
    • B.SFTP
    • C.SNMP
    • D.SMTP
    Show answerHide answer

    Correct answer: SNMP

    SNMP lets a management station poll agents on routers and switches for performance counters and receive traps when a device raises an event, and SNMPv3 adds authentication and encryption to that exchange. LDAP queries a directory for identity objects. SFTP transfers files over SSH. SMTP relays mail between servers. None of the three collects device metrics or receives trap notifications.

  103. A change management policy requires that disruptive infrastructure updates be performed only during a pre-approved, scheduled period when impact to users is minimized. What is this period called?

    • A.The maintenance window
    • B.The change blackout window
    • C.The change approval window
    • D.The rollback window
    Show answerHide answer

    Correct answer: The maintenance window

    The maintenance window is the pre-approved, scheduled period during which disruptive changes may be performed while user impact is minimal. A change blackout window is the opposite, a period when changes are prohibited, often around peak business events. A change approval window is the time the change advisory board takes to review a request, not when the work is carried out. A rollback window is the time allowed after a change to back it out if it fails, not the period scheduled for performing it.

  104. Part of a documented change request specifies the exact steps to return a system to its prior working state if the deployment fails or causes problems. What is this component of change management called?

    • A.The maintenance window
    • B.The backout plan
    • C.The version control
    • D.The test schedule
    Show answerHide answer

    Correct answer: The backout plan

    The backout plan is the documented set of steps that returns a system to its prior working state when a change fails, and it is approved before the change runs. The maintenance window only defines when the change may be performed. The version control system keeps code history but is not the change request's recovery procedure. The test schedule sets when validation happens before deployment, not how to undo a failed deployment.

  105. Before a major change is implemented, a cross-functional group reviews the request, evaluates risk and impact, and grants formal authorization. What is this group called?

    • A.The change advisory board
    • B.The change ownership team
    • C.The security review team
    • D.The impacted stakeholders
    Show answerHide answer

    Correct answer: The change advisory board

    The change advisory board is the cross-functional group that reviews a change request, weighs its risk and impact, and grants or withholds formal authorization before implementation. The change owner is the individual or team accountable for carrying a change through, not the body that approves it. A security review team assesses the security aspects of a design but is not the formal cross-functional approver. Impacted stakeholders are consulted during impact analysis, but they do not grant the authorization.

  106. An administrator configures endpoints so that only an explicitly approved set of applications may execute, and everything else is blocked by default. Which control is being applied?

    • A.An application deny list
    • B.An implicit deny ACL rule
    • C.A default deny ACL rule
    • D.An application allow list
    Show answerHide answer

    Correct answer: An application allow list

    An application allow list names the programs permitted to execute on the endpoint and blocks everything else by default, which is exactly the control described. An application deny list works the other way round: it names forbidden programs, so anything not yet listed still runs. An implicit deny ACL rule and a default deny ACL rule both block by default, but they filter network traffic on routers and firewalls rather than deciding which applications may execute on an endpoint.

  107. In a Windows Active Directory environment, an administrator centrally enforces password complexity, account lockout, and security settings across all domain-joined computers from a single location. Which mechanism provides this?

    • A.The event viewer
    • B.The group policy
    • C.The logon script
    • D.The domain trust
    Show answerHide answer

    Correct answer: The group policy

    Group Policy is defined in Active Directory and applied to every domain-joined computer, which is how password complexity, lockout thresholds and other security settings are set once and enforced everywhere. An event viewer reads the logs those settings produce. A logon script runs commands as a user signs in and enforces nothing once it has finished. A domain trust lets one domain accept another's authentications. None of the three distributes a security configuration across the domain.

  108. While hardening a newly built server, an administrator turns off unused network services and closes ports that no application requires. What is the primary security benefit of this action?

    • A.It leaves the host with less patching work
    • B.It makes the host invisible to port sweeps
    • C.It leaves the host with less memory in use
    • D.It leaves the host with fewer entry points
    Show answerHide answer

    Correct answer: It leaves the host with fewer entry points

    Turning off unused services and closing unneeded ports is chosen because it leaves the host with fewer entry points, shrinking the attack surface an attacker can reach. Less patching work is a side effect of running less software, not the primary security benefit. Closed ports still answer scans with resets, so the host is not made invisible to port sweeps. Less memory in use is a performance gain, not a security benefit.

  109. An EDR platform detects active malware on an employee laptop and the analyst immediately uses the tool to cut the device off from the network while preserving it for analysis. Which response action is this?

    • A.Recovery
    • B.Containment
    • C.Preservation
    • D.Remediation
    Show answerHide answer

    Correct answer: Containment

    Cutting the infected laptop off the network while keeping it intact is containment, the incident response step that stops the spread immediately while the host stays available for analysis. Recovery comes after the threat is removed and restores the cleaned system to normal service. Preservation is the forensic practice of protecting evidence integrity; it happens alongside isolation but is not the response action that stops the threat. Remediation fixes the underlying weakness and returns the system to a secure state, which is later work.

  110. Which incident response phase includes developing the response plan, training staff, establishing communication procedures, and deploying detection tooling before any incident occurs?

    • A.The identification stage
    • B.The preparation stage
    • C.The containment stage
    • D.The testing stage
    Show answerHide answer

    Correct answer: The preparation stage

    The preparation stage covers everything done before any incident occurs: writing the response plan, training staff, setting communication procedures and deploying detection tooling. The identification stage, the SANS name for detection, uses that tooling once an incident begins rather than deploying it. The containment stage limits the spread of an incident already under way. The testing stage is not a phase of the process; tabletop exercises and simulations validate the plan that preparation produces.

  111. To test its incident response plan without disrupting production systems, an organization gathers stakeholders to walk through a simulated breach scenario and discuss how they would respond. Which type of exercise is this?

    • A.Simulation exercise
    • B.Tabletop exercise
    • C.Parallel exercise
    • D.Checklist exercise
    Show answerHide answer

    Correct answer: Tabletop exercise

    A tabletop exercise gathers stakeholders to talk through a simulated scenario and discuss their responses, testing the plan, roles and hand-offs while production runs untouched. A simulation exercise has participants actually perform their response actions against a staged event, which goes beyond discussion. A parallel exercise brings recovery systems up and processes real workloads alongside production to prove they work. A checklist exercise has each team review its own written plan individually for accuracy, without walking through a breach scenario together.

  112. During an investigation, every transfer and handling of seized evidence is documented with who had it, when, and why, so its integrity can be defended in court. What is this documentation called?

    • A.The record of access
    • B.The notice of breach
    • C.The chain of custody
    • D.The order of seizure
    Show answerHide answer

    Correct answer: The chain of custody

    The chain of custody is the unbroken written record of every person who held an item, when they took it and why, and it is what allows a court to accept the exhibit as unaltered. The record of access shows who opened a file or system, not who physically held an exhibit. The notice of breach is the letter sent to regulators and affected people after data is exposed. The order of seizure is the legal authority to take the item in the first place and says nothing about later handling.

  113. When collecting digital evidence from a running system, a forensic analyst captures the data most likely to be lost first, such as CPU registers and RAM, before imaging the disk. Which principle guides this sequence?

    • A.The order of volatility
    • B.The period of retention
    • C.The scope of engagement
    • D.The window of detection
    Show answerHide answer

    Correct answer: The order of volatility

    The order of volatility ranks evidence by how quickly it disappears, so registers, cache and memory are captured before disks and archives that survive a reboot. The period of retention states how long records are kept before disposal. The scope of engagement fixes what a tester is permitted to touch. The window of detection measures how long an intrusion ran before anyone noticed. None of those three governs the sequence in which live data is collected.

  114. Anticipating litigation, an organization issues a directive requiring that all emails and documents related to a specific matter be preserved and exempt from routine deletion. What is this directive called?

    • A.Court filing memo
    • B.Data deletion log
    • C.Vendor audit form
    • D.Legal hold notice
    Show answerHide answer

    Correct answer: Legal hold notice

    A legal hold notice is the instruction that suspends routine destruction so everything relevant to a foreseeable case survives, and it overrides the normal schedule until counsel lifts it. A court filing memo is a submission to the court and tells staff nothing about preserving mailboxes. A data deletion log records what was destroyed, which is the opposite of halting destruction. A vendor audit form documents a supplier review and has no effect on internal records.

  115. A security team configures a vulnerability scanner with valid login accounts so it can authenticate to hosts and inspect installed software, patch levels, and configurations from the inside. Which type of scan is this?

    • A.A credentialed scan
    • B.A segmentation scan
    • C.An application scan
    • D.An enumeration scan
    Show answerHide answer

    Correct answer: A credentialed scan

    A credentialed scan signs in with a real account, so it reads installed package versions, patch state and local settings directly instead of inferring them from the outside, which is why its results are more accurate. A segmentation scan proves that network zones cannot reach one another and never authenticates to a host. An application scan drives a web front end hunting injection and session flaws. An enumeration scan only discovers live hosts, ports and services.

  116. A vulnerability scanner reports that a server is missing a critical patch, but manual verification confirms the patch is already installed and the service is not actually vulnerable. How should this finding be classified?

    • A.Verified true positive
    • B.Benign true positive
    • C.False positive result
    • D.Informational finding
    Show answerHide answer

    Correct answer: False positive result

    The scanner reported a missing patch that manual checking showed was installed, so this is a false positive result: an alert for a weakness that does not exist. A verified true positive would mean the check confirmed the patch really was missing. A benign true positive is an alert that correctly detected real activity that turned out to be harmless, but nothing real was detected here. An informational finding is a low-severity note, not a critical missing-patch alert.

  117. A vulnerability management team needs an industry-standard numeric score from 0.0 to 10.0 to gauge the severity of each discovered flaw and prioritize remediation. Which system provides this score?

    • A.The EPSS model score
    • B.The CWSS rating tool
    • C.The SSVC triage tree
    • D.The CVSS base metric
    Show answerHide answer

    Correct answer: The CVSS base metric

    The CVSS base metric is the industry-standard severity score: its base metric group produces the 0.0 to 10.0 rating teams use to rank flaws and remediate in order. EPSS also produces a number, but it is a 0 to 1 probability that a flaw will be exploited, not a severity rating. CWSS scores weaknesses on a 0 to 100 scale and is far less widely used. SSVC is a decision tree that outputs a priority category such as act or track, not a numeric score.

  118. An analyst gathers threat indicators from publicly available sources such as security blogs, vendor advisories, social media, and public reputation feeds. Which category of intelligence source is this?

    • A.Third-party source intelligence
    • B.Open-source intelligence
    • C.Dark web intelligence
    • D.Human-source intelligence
    Show answerHide answer

    Correct answer: Open-source intelligence

    Blogs, vendor advisories, social media and public reputation feeds are all openly published, so this is open-source intelligence. Third-party source intelligence comes from paid commercial vendor feeds that only subscribers can read. Dark web intelligence is gathered from hidden criminal forums and marketplaces that are not publicly available. Human-source intelligence is collected from people through contacts and interviews rather than from published sources.

  119. Organizations want to exchange machine-readable threat indicators automatically between their security platforms using a standardized language and transport. Which pair of standards supports this?

    • A.SAML and OAuth
    • B.STIX and TAXII
    • C.DKIM and DMARC
    • D.PGP and S/MIME
    Show answerHide answer

    Correct answer: STIX and TAXII

    STIX supplies the structured vocabulary for describing an indicator, an actor or a campaign, and TAXII supplies the transport services that move those objects between platforms, so the two together are what make automated indicator exchange work. SAML and OAuth federate logins and delegate authorization between applications. DKIM and DMARC authenticate the sending domain of email. PGP and S/MIME encrypt and sign individual messages between people.

  120. Rather than waiting for alerts, an analyst forms a hypothesis about a possible undetected intrusion and proactively searches logs and endpoint data for evidence of it. Which security operations activity is this?

    • A.Risk profiling
    • B.Asset tracking
    • C.Threat hunting
    • D.Log forwarding
    Show answerHide answer

    Correct answer: Threat hunting

    Threat hunting is the proactive, hypothesis-led search of telemetry for an intruder that no rule has alerted on; the hunter assumes a compromise already happened and goes looking for it. Risk profiling rates assets and processes by exposure, a governance exercise rather than a search for an active intruder. Asset tracking keeps the inventory of what the organization owns accurate. Log forwarding is the plumbing that ships events into the platform a hunter later queries.

  121. A SOC scripts the routine provisioning of user accounts and the disabling of accounts at termination so the steps run identically every time without manual intervention. Which benefit of automation does this primarily illustrate?

    • A.Uniform repeatable execution
    • B.Enforcing security baselines
    • C.Standardized config builds
    • D.Less analyst time and effort
    Show answerHide answer

    Correct answer: Uniform repeatable execution

    Uniform repeatable execution is the benefit shown: the scripted provisioning and deprovisioning steps run the same way every time with no human variation. Enforcing security baselines is about holding system configurations to an approved standard, not about account workflow consistency. Standardized config builds describe deploying infrastructure from a common template rather than repeating account tasks. Less analyst time and effort is the efficiency benefit, but the stem stresses identical runs, not time saved.

  122. A platform builds behavioral baselines for each user and flags a finance employee who suddenly downloads gigabytes of data at 3 a.m. from an unusual location as anomalous. Which capability is this?

    • A.SOAR
    • B.SASE
    • C.CASB
    • D.UEBA
    Show answerHide answer

    Correct answer: UEBA

    UEBA is the capability that learns what normal looks like for each user and device and then scores departures from it, which is how a finance clerk pulling gigabytes at three in the morning from a strange location gets surfaced. SOAR executes response playbooks once something has already been detected. SASE combines network access and security services at the edge for remote users. CASB governs how sanctioned and unsanctioned cloud applications are used, enforcing policy at the broker rather than baselining individual behaviour.

  123. Before a device is permitted onto the corporate network, a system checks that it has current antivirus signatures, required patches, and an enabled firewall, and quarantines it if it fails. Which technology enforces this?

    • A.IPS
    • B.DLP
    • C.WAF
    • D.NAC
    Show answerHide answer

    Correct answer: NAC

    NAC checks a device against a posture policy before it is admitted to the network, so a machine missing patches, current signatures or an enabled firewall is placed in a quarantine segment until it complies. IPS inspects traffic already flowing and drops what matches an attack signature. DLP examines content for regulated data leaving the organization. WAF filters HTTP requests aimed at a web application and never evaluates the health of the connecting endpoint.

  124. On a quarterly basis, managers must review and re-approve the permissions held by each of their direct reports, removing any access that is no longer needed. Which identity governance practice is this?

    • A.Credential provisioning
    • B.Entitlement attestation
    • C.Identity reconciliation
    • D.Enrollment verification
    Show answerHide answer

    Correct answer: Entitlement attestation

    Entitlement attestation is the periodic cycle in which the manager who knows the job confirms each permission is still warranted and revokes what is not, which is the standard defence against privilege creep. Credential provisioning issues the account and its initial rights at the start of the relationship. Identity reconciliation compares directory accounts against the authoritative personnel record to find orphans. Enrollment verification proves that the person receiving a credential is who they claim to be.

  125. A security operations team must track expiration dates and renew TLS certificates before they lapse to prevent service outages and browser warnings. Which operational practice addresses this?

    • A.Certificate lifecycle management
    • B.Certificate revocation monitoring
    • C.Certificate transparency monitoring
    • D.Certificate policy enforcement
    Show answerHide answer

    Correct answer: Certificate lifecycle management

    Certificate lifecycle management tracks every issued certificate from enrollment through expiry and renewal, which is what prevents lapsed certificates, outages and browser warnings. Certificate revocation monitoring checks whether certificates have been revoked through CRLs or OCSP, not when they expire. Certificate transparency monitoring watches public logs for mis-issued certificates. Certificate policy enforcement applies the rules a CA publishes about how certificates may be issued and used, and does nothing to renew one before it expires.

  126. To ensure every new virtual machine starts in a known, hardened state, the operations team builds golden images with approved configurations and deploys all instances from them automatically. Which security operations practice does this support?

    • A.Continuous integration pipeline
    • B.Distributed workload scheduling
    • C.Immutable baseline provisioning
    • D.Automated evidence preservation
    Show answerHide answer

    Correct answer: Immutable baseline provisioning

    Building approved images once and deploying every instance from them is immutable baseline provisioning: the configuration is fixed before launch, so no machine drifts away from the approved state and nothing is hand-configured after boot. A continuous integration pipeline builds and tests application code, which is a delivery concern rather than a host hardening one. Distributed workload scheduling decides which node runs which job. Automated evidence preservation captures artefacts for an investigation after an incident.

  127. A security team wants vulnerability scanning that does not require installing software on each endpoint and instead queries hosts remotely over the network. Which scanning approach are they choosing?

    • A.Agent-based scanning, a common model
    • B.Credentialed scanning, a known style
    • C.Agentless scanning, a routine method
    • D.Passive monitoring, a defined option
    Show answerHide answer

    Correct answer: Agentless scanning, a routine method

    Agentless scanning reaches each host across the network from a central scanner, so nothing has to be installed or maintained on the endpoint; the trade-off is that a machine which is powered off or unreachable at scan time is simply missed. Agent-based scanning depends on resident software deployed to every endpoint, which is the requirement the team is trying to avoid. Credentialed scanning describes the level of access handed to the scanner and is orthogonal to whether software is installed locally. Passive monitoring only inspects traffic it happens to observe and never queries a host at all.

Security Program Management and Oversight (91)

  1. Which concept in risk management involves determining the impact of an adverse event that may affect the assets, resources, or operations of an organization?

    • A.Quantitative risk analysis
    • B.Qualitative risk analysis
    • C.Business impact analysis
    • D.Risk impact matrix
    Show answerHide answer

    Correct answer: Business impact analysis

    A business impact analysis determines what an adverse event would do to the organization: it identifies critical functions and the assets, resources and operations behind them, then measures the operational and financial consequence of losing them and sets recovery priorities. Quantitative risk analysis puts dollar values on individual risks (SLE, ARO, ALE) to rank them, rather than studying how a disruption affects business operations. Qualitative risk analysis ranks risks with descriptive ratings such as high, medium and low, again scoring risks rather than mapping operational impact. A risk impact matrix is a visual grid plotting likelihood against impact, a presentation tool for prioritizing risks, not the analysis of what an outage costs the business.

  2. In risk management, what does the term 'risk appetite' refer to?

    • A.The amount of risk left after each control works
    • B.The amount of risk found before any control acts
    • C.The most risk the business can take and survive
    • D.The amount of risk the business will freely bear
    Show answerHide answer

    Correct answer: The amount of risk the business will freely bear

    Risk appetite is the amount of risk the business will freely bear in pursuit of its objectives, set by leadership as a strategic stance. The amount of risk left after each control works is residual risk, the outcome that is compared against appetite. The amount of risk found before any control acts is inherent risk, the raw exposure before treatment. The most risk the business can take and survive is risk capacity, the absolute ceiling, which is usually well above the level leadership actually chooses to accept.

  3. Which of the following best describes a 'risk register' in the context of risk management?

    • A.A list of each risk found with its suspected cause
    • B.A list of risk transfers that legal has signed off
    • C.A list of incidents that the risk board has closed
    • D.A list of audits the risk owner must still approve
    Show answerHide answer

    Correct answer: A list of each risk found with its suspected cause

    A risk register is the working inventory of identified risks: each entry records the risk, its suspected cause, its owner, its rating and the treatment chosen. Signed transfer agreements are contract records held by legal, not the register itself. Closed incidents belong in an incident log and describe events that already happened rather than risks that might. A schedule of outstanding audits is an assurance planning document.

  4. In the context of risk management, what is 'residual risk'?

    • A.The risk level measured before a control is applied
    • B.The risk that remains once the controls are present
    • C.The risk a business hands an insurer under contract
    • D.The risk that management signs off and leaves alone
    Show answerHide answer

    Correct answer: The risk that remains once the controls are present

    Residual risk is what is left after the selected controls have been implemented and are working; it is the amount the organization actually carries. The level measured before treatment is inherent risk. Risk handed to an insurer under contract has been transferred, which is a treatment choice rather than the leftover. Risk that management deliberately signs off is accepted risk, a decision that can be taken about either inherent or residual exposure.

  5. What is the primary purpose of 'quantitative risk analysis' in risk management?

    • A.It rates each risk using a descriptive severity band
    • B.It groups each risk beneath its owning business unit
    • C.It expresses each risk as a measured monetary figure
    • D.It escalates each risk to the committee that accepts
    Show answerHide answer

    Correct answer: It expresses each risk as a measured monetary figure

    Quantitative risk analysis puts numbers on exposure: it derives values such as single loss expectancy, annualized rate of occurrence and annualized loss expectancy so that risks can be compared in money. Rating a risk with descriptive words such as high or moderate is qualitative analysis. Sorting risks by owning business unit is a cataloging step. Escalating a risk to a governance committee is part of the response process, after the analysis is finished.

  6. Which approach in risk management prioritizes risks based on their severity and likelihood of occurrence?

    • A.Risk prioritization
    • B.Risk identification
    • C.Risk quantification
    • D.Risk categorization
    Show answerHide answer

    Correct answer: Risk prioritization

    Risk prioritization is the ranking step: risks already on the register are ordered by how severe they would be and how likely they are, so the most pressing get attention and budget first. Risk identification is the earlier step that discovers risks and puts them on the register. Risk quantification assigns numeric probability and loss values but does not itself order the work. Risk categorization groups risks by type or source and produces no ranking at all.

  7. In the context of risk management, what is 'risk transference'?

    • A.Redesigning a process so the risk can no longer arise
    • B.Adding controls that lower the risk to a stated level
    • C.Documenting the risk and opting to live with it today
    • D.Passing the money risk to an insurer under a contract
    Show answerHide answer

    Correct answer: Passing the money risk to an insurer under a contract

    Risk transference moves the financial consequence of a risk to another entity, most often through insurance or a contractual indemnity, although accountability for the risk stays with the organization. Redesigning a process so the exposure cannot arise is avoidance. Adding controls to bring exposure down is mitigation. Documenting a risk and deciding to carry it is acceptance.

  8. What does a 'Single Loss Expectancy' (SLE) calculation involve in risk management?

    • A.The money lost each time a named risk event occurs
    • B.The money gone across a single year of risk events
    • C.The money set aside to fund a planned risk control
    • D.The money a risk can drain before a business folds
    Show answerHide answer

    Correct answer: The money lost each time a named risk event occurs

    Single loss expectancy is the monetary loss expected from one occurrence of a specific risk, calculated as asset value multiplied by exposure factor. Loss summed across a whole year is annualized loss expectancy, which multiplies single loss expectancy by the annualized rate of occurrence. Money set aside to fund a control is a budget line. The amount a firm can absorb before failing is a solvency limit, not an expectancy calculation.

  9. In risk management, what is the primary goal of 'risk mitigation'?

    • A.To shift each risk over to a vendor or insurer
    • B.To drop the odds that a named risk ever occurs
    • C.To trim the likelihood or the impact of a risk
    • D.To grade each risk so the worst is fixed first
    Show answerHide answer

    Correct answer: To trim the likelihood or the impact of a risk

    Risk mitigation reduces exposure by lowering how likely a risk is, how much damage it would do, or both, until what remains is tolerable. Moving a risk to a vendor or insurer is transference. Ending the chance of occurrence altogether is avoidance, and in practice no control drives likelihood to zero. Ranking risks so the worst are handled first is prioritization, which decides the order of treatment rather than reducing anything.

  10. Which document in risk management outlines the steps to be taken in the event of a specific risk occurrence?

    • A.The incident response plan
    • B.The risk response playbook
    • C.The risk treatment plan
    • D.The disaster recovery plan
    Show answerHide answer

    Correct answer: The risk response playbook

    The risk response playbook is the document that lists, in advance, the exact steps to take when one specific risk actually occurs. An incident response plan sets the general phases and roles for handling any incident rather than the steps for a particular risk. A risk treatment plan records how each risk will be reduced, transferred, avoided or accepted before it happens. A disaster recovery plan covers restoring IT systems after a major outage, not the response to each specific risk.

  11. In risk management, what is the purpose of conducting a 'gap analysis'?

    • A.It estimates how much a single failure would cost them
    • B.It counts the steps that a workflow repeats each cycle
    • C.It tests whether the team can follow the recovery plan
    • D.It compares what we do with what the standard requires
    Show answerHide answer

    Correct answer: It compares what we do with what the standard requires

    A gap analysis measures the distance between where an organization's practices actually stand and where a chosen standard, framework or policy requires them to stand, and the difference becomes the remediation plan. Costing a single failure is an impact calculation. Counting repeated steps is a process efficiency exercise. Testing whether a team can execute a recovery plan is a drill, which validates a plan instead of measuring a shortfall against a standard.

  12. What does 'Mean Time Between Failures' (MTBF) represent in the context of risk management?

    • A.The mean time that one repair of failures takes
    • B.The longest outage that a firm can safely stand
    • C.The recent user data that a restore can forfeit
    • D.The mean time that a unit runs between failures
    Show answerHide answer

    Correct answer: The mean time that a unit runs between failures

    Mean time between failures is a reliability figure: it is the average operating interval separating one failure of a repairable item from the next. The average time to bring a failed system back is mean time to repair. The longest outage the business can stand is maximum tolerable downtime. The amount of recent data a restore may sacrifice is the recovery point objective, which is measured in data rather than in reliability.

  13. Which of the following best describes 'Qualitative Risk Analysis' in risk management?

    • A.It converts each risk into an annual dollar estimate
    • B.It rates each risk with a descriptive severity label
    • C.It offloads each risk onto an external named insurer
    • D.It archives each risk after its control is validated
    Show answerHide answer

    Correct answer: It rates each risk with a descriptive severity label

    Qualitative risk analysis uses judgment and descriptive scales, rating likelihood and impact as high, medium or low so risks can be compared quickly without financial modeling. Converting exposure into an annual dollar estimate is quantitative analysis. Offloading a risk onto an outside insurer is transference, a response rather than an analysis. Archiving a risk once its control is validated is a monitoring activity that follows treatment.

  14. What is the primary focus of 'Operational Risk Management'?

    • A.It weighs risk against the long-term firm strategy
    • B.It weighs risk inside an investment fund portfolio
    • C.It weighs risk among the day-to-day work processes
    • D.It weighs risk from newly passed national statutes
    Show answerHide answer

    Correct answer: It weighs risk among the day-to-day work processes

    Operational risk management deals with loss arising from the organization's own day-to-day running: failed processes, human error, and systems that break or are misused. Risk weighed against long-term direction set by the board is strategic risk. Risk inside an investment portfolio is financial or market risk. Risk created by newly passed legislation is compliance risk, which is tracked separately from operations.

  15. In risk management, what is 'Risk Acceptance'?

    • A.Choosing to bear a risk without adding new defenses
    • B.Choosing to ignore a risk the firm has not assessed
    • C.Choosing to define how much risk the firm will take
    • D.Choosing to share a risk with a partner by contract
    Show answerHide answer

    Correct answer: Choosing to bear a risk without adding new defenses

    Risk acceptance means choosing to bear a risk without adding new defenses, a documented decision made after the risk has been analysed and found to sit within tolerance. Ignoring a risk the firm has not assessed is not acceptance, because acceptance requires an informed, recorded decision. Defining how much risk the firm will take describes risk appetite, which sets the threshold rather than deciding on one risk. Sharing a risk with a partner by contract is transference.

  16. What is a 'Risk Threshold' in the context of risk management?

    • A.The total risk left once the safeguards are applied
    • B.The exposure measure at which a risk gets escalated
    • C.The average risk that a whole portfolio now carries
    • D.The share of risk that a contracted partner absorbs
    Show answerHide answer

    Correct answer: The exposure measure at which a risk gets escalated

    A risk threshold is the defined trigger point: once the measured exposure crosses it, the risk can no longer be handled routinely and must be escalated or treated. What is left once safeguards are applied is residual risk. An average across the portfolio is a summary statistic that no decision hangs on. The share a partner contractually absorbs describes transferred risk rather than the point at which action becomes mandatory.

  17. In risk management, what is the primary purpose of 'Continuous Monitoring'?

    • A.It rescores each risk in the register every quarter
    • B.It scans each host for missing updates each quarter
    • C.It stores each log so incidents can be traced later
    • D.It rechecks how well each control performs each day
    Show answerHide answer

    Correct answer: It rechecks how well each control performs each day

    The purpose is that it rechecks how well each control performs each day, keeping near-real-time visibility so control failures and drift surface between formal assessments. Rescoring the risk register every quarter is a periodic risk assessment, not continuous oversight. A quarterly scan for missing updates is periodic vulnerability management with long blind gaps. Storing logs so incidents can be traced later supports after-the-fact forensics rather than ongoing assessment of control effectiveness.

  18. Which document in risk management outlines the overall risk strategy and policies of an organization?

    • A.A policy setting out the firm's overall risk aims
    • B.A plan describing which steps follow a risk event
    • C.A study ranking the overall risk to each function
    • D.A register naming each active risk and its holder
    Show answerHide answer

    Correct answer: A policy setting out the firm's overall risk aims

    A risk management policy is the governing document: it states the organization's overall risk aims, who owns risk decisions, how risk is measured and what tolerances apply. The steps that follow a risk event belong in a response plan. A study ranking exposure across critical functions is a business impact analysis. A register of active risks with named holders is the risk register, an operational record produced under the policy rather than the policy itself.

  19. What role does 'Due Diligence' play in risk management?

    • A.It is the summary of a risk found during a review
    • B.It is the transfer of a risk onto a partner group
    • C.It is the scrutiny needed to spot a risk early on
    • D.It is the decision to run a risk that stays small
    Show answerHide answer

    Correct answer: It is the scrutiny needed to spot a risk early on

    Due diligence is the reasonable investigation an organization performs before committing itself, so that risks in a vendor, an acquisition or a new system are spotted and addressed while there is still time to act. A summary written up after a review is evidence produced after the fact. Shifting a risk onto a partner group is transference. Running a risk that stays inside tolerance is acceptance, a decision that due diligence informs but is not the same as.

  20. Which term describes the process of prioritizing risks for further analysis or action by assessing their likelihood and impact?

    • A.Risk acceptance
    • B.Risk governance
    • C.Risk monitoring
    • D.Risk assessment
    Show answerHide answer

    Correct answer: Risk assessment

    Risk assessment is the process that examines identified risks, judges how likely each is and how much damage it would do, and ranks them so that further analysis or treatment can be aimed at the worst first. Risk acceptance is a treatment decision taken about a single risk. Risk governance is the oversight structure that sets policy and assigns authority. Risk monitoring watches risks and controls over time, after they have already been assessed and treated.

  21. In risk management, what does 'Annual Loss Expectancy' (ALE) represent?

    • A.The cost of the controls bought in one fiscal year
    • B.The largest blow the firm could absorb in one year
    • C.The loss an asset is expected to sustain each year
    • D.The money that a single incident costs in one year
    Show answerHide answer

    Correct answer: The loss an asset is expected to sustain each year

    Annualized loss expectancy is the expected yearly loss for an asset from a given risk, found by multiplying single loss expectancy by the annualized rate of occurrence. The cost of controls bought during the year is spending, not expected loss. The largest blow a firm could survive is a solvency limit. The money one incident costs is single loss expectancy, the per-event figure that annualized loss expectancy is built from.

  22. A U.S. hospital is reviewing the regulations that govern how it stores and shares patient medical records electronically. Which law specifically sets national standards for protecting individuals' protected health information (PHI) and requires safeguards such as access controls and breach notification?

    • A.HITRUST
    • B.HIPAA
    • C.FERPA
    • D.FISMA
    Show answerHide answer

    Correct answer: HIPAA

    HIPAA is the U.S. law that sets national standards for protecting protected health information and requires safeguards such as access controls and breach notification. HITRUST is a private certifiable security framework used by healthcare organizations, not a law. FERPA protects student education records held by schools. FISMA requires federal agencies to secure their information systems and does not set standards for hospital patient records.

  23. An online retailer operating in the EU must comply with a regulation that grants individuals rights such as access, rectification, and erasure of their personal data and requires breach reporting to a supervisory authority within 72 hours. Which regulation is this?

    • A.GLBA
    • B.CFAA
    • C.GDPR
    • D.FCRA
    Show answerHide answer

    Correct answer: GDPR

    GDPR is the European Union regulation that gives data subjects enforceable rights over their own information, including access to it, correction of it and erasure of it, and it obliges a controller to report a qualifying personal data breach to its supervisory authority within 72 hours. GLBA is a United States statute covering how financial institutions handle customer financial information. CFAA is the United States computer crime statute used to prosecute unauthorized access to protected systems. FCRA governs the accuracy and use of consumer credit reports and grants no such erasure right.

  24. Under GDPR, a marketing company decides what customer personal data to collect and why, then hires a cloud email vendor that sends campaigns strictly according to the marketing company's instructions. How are these two parties classified?

    • A.The agency serves as custodian and the vendor serves as supervisor
    • B.The agency serves as subject and the vendor serves as intermediary
    • C.The agency serves as recipient and the vendor serves as originator
    • D.The agency serves as controller and the vendor serves as processor
    Show answerHide answer

    Correct answer: The agency serves as controller and the vendor serves as processor

    Under GDPR the classification follows who decides. The marketing business chooses what personal data is collected and why, which makes it the controller, and the email vendor acts only on those documented instructions, which makes it the processor. Custodian is not a role the regulation defines, and a supervisor is the national authority that enforces the law rather than a hired supplier. The data subject is the individual the records describe, which neither company is. Calling the agency a mere recipient inverts the facts: it is the party setting the purpose, and the vendor originates nothing.

  25. A merchant that stores and transmits cardholder data must comply with a security standard maintained by the major payment card brands rather than by a government. Which framework imposes requirements such as network segmentation, encryption of cardholder data, and regular vulnerability scanning?

    • A.PCI DSS specification
    • B.ISO 27001 publication
    • C.NIST CSF requirements
    • D.CIS Controls guidance
    Show answerHide answer

    Correct answer: PCI DSS specification

    PCI DSS is maintained by the council the major card brands founded, and it binds any organization that stores, processes or transmits cardholder data through the merchant's acquiring contract rather than through legislation. Its content is exactly what the scenario lists: segment the cardholder data environment, encrypt the data, and scan for vulnerabilities on a defined cycle. ISO 27001 is an international management-system standard an organization opts into. The NIST framework is voluntary guidance published by a government agency. The CIS material offers prioritized hardening advice with no card brand behind it.

  26. An organization wants to become formally certified against an internationally recognized standard that specifies requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS). Which standard should it pursue?

    • A.ISO 27001 requirement
    • B.PCI DSS documentation
    • C.NIST CSF publications
    • D.SOC 2 recommendations
    Show answerHide answer

    Correct answer: ISO 27001 requirement

    ISO/IEC 27001 states the requirements for establishing, operating, maintaining and improving an information security management system, and it is the one here an accredited body can audit an organization against and issue a certificate for. PCI DSS applies only where payment card data is handled and is enforced by contract with the card brands. The NIST framework is voluntary guidance organized around outcomes, and no certificate is issued against it. A SOC 2 engagement produces an auditor's report on service organization controls for customers to read, which is an attestation rather than a management-system certification.

  27. A security manager wants to organize the company's cybersecurity program around six core functions: Govern, Identify, Protect, Detect, Respond, and Recover. Which framework provides this voluntary, outcome-based structure?

    • A.MITRE ATT&CK matrix
    • B.OWASP risk rankings
    • C.NIST CSF categories
    • D.Lockheed Kill Chain
    Show answerHide answer

    Correct answer: NIST CSF categories

    The NIST Cybersecurity Framework organizes security outcomes into functions, and version 2.0 added Govern alongside Identify, Protect, Detect, Respond and Recover, giving a voluntary structure a programme can be arranged around and measured against. The MITRE matrix catalogues what adversaries do, technique by technique, which supports detection engineering rather than programme governance. The OWASP material ranks common web application weaknesses for developers. The Lockheed model describes the stages of a single intrusion from reconnaissance to action on objectives, which is an attack narrative, not a management structure.

  28. A CISO is establishing the policies, roles, and oversight committees that direct how security decisions are made and held accountable across the enterprise, aligning them with business objectives and regulatory requirements. This overall practice is best described as which of the following?

    • A.Penetration testing
    • B.Security governance
    • C.Business continuity
    • D.Threat intelligence
    Show answerHide answer

    Correct answer: Security governance

    Governance is the direction-setting layer: it establishes who decides, which committees hold the programme to account, what the policies say, and how all of that maps onto business objectives and regulatory duties. Penetration testing is a point-in-time technical assessment that tries to exploit weaknesses and reports what worked. Business continuity plans how essential operations keep running through a disruption. Threat intelligence gathers and analyses information about adversaries so defenders can anticipate them, and each of these is an activity that governance oversees rather than the oversight itself.

  29. A new employee receives ongoing instruction on recognizing phishing emails, reporting suspicious activity, handling sensitive data, and following the company's policies. According to CompTIA's security program guidance, what is this practice called?

    • A.Phishing simulation campaign
    • B.Security policy onboarding
    • C.Security policy attestation
    • D.Security awareness training
    Show answerHide answer

    Correct answer: Security awareness training

    Security awareness training is the ongoing programme that teaches every employee to recognize phishing, report suspicious activity, handle sensitive data and follow company policies. A phishing simulation campaign sends staged phishing emails to measure how people respond; it is one testing component of the programme, not the ongoing instruction across all four topics. Security policy onboarding is the one-time introduction to the rules when a person joins, not continuing instruction. Security policy attestation is the recorded acknowledgement that a person has read and accepted the policies, which is a signature rather than training.

  30. An organization's security program encompasses the continuous process of identifying threats, assessing their likelihood and impact, and deciding how to treat them so that exposure stays within acceptable limits. Which discipline describes this entire ongoing process?

    • A.Risk assessment
    • B.Threat modeling
    • C.Threat intelligence
    • D.Risk management
    Show answerHide answer

    Correct answer: Risk management

    Risk management is the whole continuous discipline of identifying threats, assessing likelihood and impact, choosing a treatment and monitoring the result. Risk assessment is wrong because it is only the identify-and-analyze step inside that cycle and does not decide treatment. Threat modeling is wrong because it maps how a specific system could be attacked during design. Threat intelligence is wrong because it gathers information about adversaries and their tactics, an input to the process rather than the process itself.

  31. During a quantitative risk assessment, an analyst multiplies the single loss expectancy (SLE) by the annualized rate of occurrence (ARO). Which value does this calculation produce?

    • A.Maximum tolerable downtime
    • B.Exposure factor percentage
    • C.Annualized loss expectancy
    • D.Quantitative risk appetite
    Show answerHide answer

    Correct answer: Annualized loss expectancy

    Multiplying what one occurrence costs by how many occurrences are expected in a year produces the yearly figure a control's cost is weighed against, and that figure is the annualized loss expectancy. Maximum tolerable downtime states how long a function can be unavailable before the damage becomes unacceptable, which comes out of a business impact analysis rather than this multiplication. The exposure factor is the proportion of an asset's value destroyed by a single event, an input that helps produce the per-occurrence cost. Risk appetite is the exposure leadership is willing to carry, a policy statement, not a computed result.

  32. In a quantitative risk assessment, a server is valued at $40,000 and a fire is estimated to destroy 25 percent of it. What is the single loss expectancy (SLE) for one fire event?

    • A.$30,000
    • B.$1,600
    • C.$40,000
    • D.$10,000
    Show answerHide answer

    Correct answer: $10,000

    The single loss expectancy is the asset value multiplied by the exposure factor, so $40,000 times 0.25 gives $10,000 for one fire event. $30,000 is the value of the server that survives the fire, which is the 75 percent left over rather than the 25 percent lost. $1,600 divides the asset value by 25, treating the percentage as a divisor instead of a fraction to multiply by. $40,000 is the full asset value and ignores the exposure factor, treating every fire as a total loss.

  33. While calculating loss for a risk assessment, an analyst needs the percentage of an asset's value that would be lost if a specific threat were realized. Which term describes this percentage?

    • A.Exposure factor
    • B.Event frequency
    • C.Asset valuation
    • D.Impact analysis
    Show answerHide answer

    Correct answer: Exposure factor

    The exposure factor is the share of an asset's value destroyed when one specific threat is realized, expressed as a percentage, and it is multiplied by asset value to produce the single loss expectancy. Event frequency counts how often a threat occurs in a year rather than how much value one occurrence removes. Asset valuation establishes the total worth of the asset, which is the figure the percentage is applied to, not the percentage itself. Impact analysis describes the business consequences of a disruption and yields no such ratio.

  34. An analyst is estimating how many times per year a particular threat, such as a server room flood, is expected to occur for use in an ALE calculation. Which metric is the analyst determining?

    • A.Annualized loss expectancy
    • B.Annualized occurrence rate
    • C.Single loss expectancy
    • D.Mean time between failures
    Show answerHide answer

    Correct answer: Annualized occurrence rate

    The annualized occurrence rate (ARO) is the expected number of times a threat occurs in a year, and multiplying it by the single loss expectancy gives the ALE. Annualized loss expectancy is the result of that calculation, not the frequency input. Single loss expectancy is the cost of one event. Mean time between failures measures hardware reliability rather than how often a threat such as a flood strikes.

  35. A team performs an automated, non-intrusive examination of systems to identify and report known weaknesses such as missing patches and misconfigurations, but it does not attempt to exploit them. What is this activity called?

    • A.A penetration test
    • B.A vulnerability scan
    • C.A security compliance audit
    • D.A security controls audit
    Show answerHide answer

    Correct answer: A vulnerability scan

    A vulnerability scan is the automated, non-intrusive check that compares systems against a database of known flaws and reports missing patches and misconfigurations without trying to exploit them. A penetration test goes further by actively exploiting weaknesses to prove impact, which the stem explicitly rules out. A security compliance audit measures adherence to a regulation, standard or internal policy and produces findings of conformity, not an automated list of known flaws on each host. A security controls audit evaluates whether chosen safeguards are designed and operating effectively, which is a review of controls rather than an enumeration of missing patches.

  36. An organization hires an outside firm to actively attempt to breach its systems by exploiting vulnerabilities, simulating a real attacker to validate defenses. What is this authorized engagement called?

    • A.A threat hunt
    • B.A simulation exercise
    • C.A purple team exercise
    • D.A penetration test
    Show answerHide answer

    Correct answer: A penetration test

    A penetration test is the authorized engagement in which a hired firm actively exploits vulnerabilities, simulating a real attacker to validate defenses. A threat hunt has defenders proactively search their own environment for attackers who may already be present, rather than attacking it. A simulation exercise rehearses the incident response team against a scripted scenario without exploiting live systems. A purple team exercise has attackers and defenders working together to tune detections, rather than an outside firm testing defenses as a real adversary would.

  37. A company commissions an external penetration test in which the testers are given full knowledge of the network architecture, source code, and credentials before they begin. Which testing approach is this?

    • A.Known environment testing
    • B.Partially known pen testing
    • C.Credentialed pen testing
    • D.Integrated pen testing
    Show answerHide answer

    Correct answer: Known environment testing

    Known environment testing, formerly called white box testing, gives the testers full knowledge of the architecture, source code and credentials before they begin. Partially known pen testing (gray box) shares only part of that picture, so it does not fit testers holding everything. Credentialed pen testing describes only being handed login credentials; it says nothing about receiving the architecture and source code as well. Integrated pen testing refers to offensive and defensive teams working together (purple teaming), which describes who takes part, not how much the testers know.

  38. A vendor contract guarantees that a cloud service will be available 99.95 percent of the time each month, with credits owed if that target is missed. Which type of agreement defines these measurable service commitments?

    • A.A cloud hosting agreement
    • B.A joint venture agreement
    • C.A data transfer agreement
    • D.A service level agreement
    Show answerHide answer

    Correct answer: A service level agreement

    A service level agreement is the contract that fixes measurable performance targets, such as an availability percentage and a response time, together with the credits or penalties owed when a target is missed. A cloud hosting agreement covers where a workload runs and who maintains it without committing the provider to any numeric availability figure. A joint venture agreement sets out how two firms share a jointly owned undertaking. A data transfer agreement governs what information may be sent where and on what lawful basis.

  39. Two organizations entering an informal collaboration want to document their mutual intentions and broad responsibilities, while making clear the document is not a legally binding contract. Which agreement best fits this purpose?

    • A.Memorandum of agreement
    • B.Memorandum of understanding
    • C.Business partners agreement
    • D.Interconnection security agreement
    Show answerHide answer

    Correct answer: Memorandum of understanding

    A memorandum of understanding records two parties' mutual intentions and broad responsibilities and is written so it creates no enforceable obligation. A memorandum of agreement is more detailed and sets conditional, often binding, duties for each side. A business partners agreement is a binding contract covering how partners share profits, losses and decisions. An interconnection security agreement is a binding document setting the security requirements for connecting two organizations' systems.

  40. An organization classifies its security documents so that the high-level mandatory statement of management intent sits above more detailed documents. Which document type expresses the broad, enforceable management direction that other documents support?

    • A.Internal standard
    • B.Written procedure
    • C.Current guideline
    • D.Enterprise policy
    Show answerHide answer

    Correct answer: Enterprise policy

    A policy sits at the top of the documentation hierarchy: it is where management states, in binding terms, what the organization will and will not do, and every document below it exists to carry that intent out. A standard is narrower, fixing the specific technical settings that implement the policy. A procedure is narrower still, listing the ordered steps one person performs to complete a single task. A guideline carries no obligation at all and merely recommends.

  41. A security team writes a document that lists the exact, step-by-step instructions an administrator must follow to disable a terminated employee's accounts. Which type of governance document is this?

    • A.Approved procedure
    • B.Operational policy
    • C.Corporate standard
    • D.Existing guideline
    Show answerHide answer

    Correct answer: Approved procedure

    A procedure is the step-by-step instruction set for one task, written so that any qualified administrator performs the work the same way and in the same order, which is exactly what a disable-the-accounts runbook is. A policy states management intent and never descends to individual commands. A standard sets the mandatory technical values a system must meet, not the sequence of actions taken. A guideline is advice that may be followed or set aside.

  42. A company publishes a document offering recommended but non-mandatory advice on choosing strong passphrases. Because it is advisory rather than required, which governance document type best describes it?

    • A.Departmental policy
    • B.Enterprise standard
    • C.Practical guideline
    • D.Operating procedure
    Show answerHide answer

    Correct answer: Practical guideline

    A guideline is the only document type in the hierarchy that is optional: it recommends good practice, here on passphrase choice, and no one is in breach for departing from it. A policy is binding management direction. A standard imposes uniform mandatory requirements on systems. A procedure prescribes the exact steps for a task. All three of those compel, and it is the absence of compulsion that identifies this document.

  43. An organization mandates that all stored passwords be hashed with a specific algorithm and minimum length to ensure consistency across systems. Which governance document type defines these specific, mandatory technical requirements?

    • A.Institutional policy
    • B.Operational standard
    • C.Documented procedure
    • D.Supporting guideline
    Show answerHide answer

    Correct answer: Operational standard

    A standard is where mandatory, uniform technical requirements live, so naming a specific hashing algorithm and a minimum length that every system must implement is standard-setting work. A policy states the broad intent that passwords be protected but does not name an algorithm. A procedure walks an administrator through a task rather than defining the requirement itself. A guideline could only suggest an algorithm, and this requirement is compulsory.

  44. Leadership wants security decisions to be centralized so that a single executive team and committee set direction for the entire enterprise. Which governance structure does this describe?

    • A.Centralized governance
    • B.Decentralized governance
    • C.Committee governance
    • D.Federated governance
    Show answerHide answer

    Correct answer: Centralized governance

    Centralized governance places decision rights in one executive team and one committee that set direction for the whole enterprise, so standards and exceptions resolve at a single point. Decentralized governance pushes those decisions out to business units that each set their own direction. Committee governance names who deliberates, not whether authority is concentrated or spread. Federated governance splits authority between a central body and semi-autonomous units, a hybrid rather than a single point.

  45. A large conglomerate lets each subsidiary set and enforce its own security policies tailored to its local needs, with little central control. Which governance approach is this?

    • A.Institutional governance
    • B.Transactional governance
    • C.Decentralized governance
    • D.Multinational governance
    Show answerHide answer

    Correct answer: Decentralized governance

    When each subsidiary writes and enforces its own security policy with little central direction, decision rights sit at the edges, and that dispersal of authority is the decentralized model. Institutional governance describes oversight exercised through formal institutional structures rather than the location of authority. Transactional governance manages individual dealings and exchanges. Multinational governance simply describes operating in several countries, which says nothing about who holds the authority to set policy.

  46. A board of directors forms a group of senior leaders that meets regularly to review cyber risk, approve security strategy, and hold the program accountable. Which governance body is being described?

    • A.The purchasing council
    • B.The architecture board
    • C.The management cabinet
    • D.The steering committee
    Show answerHide answer

    Correct answer: The steering committee

    A steering committee is the standing body of senior stakeholders that reviews cyber risk, approves strategy and holds the security program to account on behalf of the board, which is precisely the group described. A purchasing council approves spending and selects suppliers, a remit that stops well short of security strategy. An architecture board rules on technical designs and standards for new systems. A management cabinet is a general executive grouping with no defined authority over the security program.

  47. A regulatory framework explicitly applies to an organization and carries legal penalties for non-compliance, leaving the organization no choice but to follow it. How are such considerations categorized?

    • A.Contractual requirements
    • B.Statutory obligations
    • C.Regulatory guidance
    • D.Industry guidance
    Show answerHide answer

    Correct answer: Statutory obligations

    A framework that is imposed by law, applies explicitly to the organization and carries legal penalties creates statutory obligations, which must be met regardless of risk appetite. Contractual requirements are binding only because the organization signed an agreement, and breach brings contract remedies rather than legal penalties. Regulatory guidance explains how a regulator interprets rules but is advisory in itself. Industry guidance is recommended practice from sector bodies that no authority enforces.

  48. Within the data lifecycle, one role holds ultimate accountability for a particular data set, including its classification and authorizing access. Which role is this?

    • A.The designated data owner
    • B.The senior data custodian
    • C.The vendor data processor
    • D.The regional data steward
    Show answerHide answer

    Correct answer: The designated data owner

    The data owner is the senior figure who carries accountability for a specific set of information: they decide its classification, approve who may see it, and answer for it if it is exposed. A custodian implements those decisions technically but does not make them. A processor handles the information on instructions from another organization. A steward looks after quality and definitions, again under authority delegated from the owner.

  49. An IT administrator is responsible for the technical handling of data, such as performing backups, applying access controls, and maintaining storage, but does not decide classification. Which role does this person hold?

    • A.The authorized data owner
    • B.The external data steward
    • C.The legal data controller
    • D.The onsite data custodian
    Show answerHide answer

    Correct answer: The onsite data custodian

    Running the backups, applying the access control lists and looking after the storage is custodial work: the custodian protects the data day to day under rules somebody else has set, and classification is explicitly not their call. The owner is the one who sets that classification and grants approval. The steward governs quality, meaning and appropriate use. The controller decides the purposes and means of processing personal data under privacy law.

  50. Under privacy roles, the individual whose personal data is being collected and processed is given specific rights over that data. What is this person called?

    • A.The joint data controller
    • B.The remote data processor
    • C.The affected data subject
    • D.The backup data custodian
    Show answerHide answer

    Correct answer: The affected data subject

    The data subject is the living person the personal information is about, and privacy law gives that person rights over it, including access, correction and erasure. A controller is the organization that determines why and how the information is processed. A processor acts on the controller's documented instructions. A custodian is the technical caretaker of the storage. None of those three is the human being the record describes.

  51. An organization appoints a role focused on ensuring data quality, consistent definitions, and proper use of data on behalf of the data owner. Which role best fits this responsibility?

    • A.The contracted data owner
    • B.The assigned data steward
    • C.The vendor data processor
    • D.The prime data controller
    Show answerHide answer

    Correct answer: The assigned data steward

    A data steward is charged with the meaning of the data: definitions, quality, consistency across systems and appropriate use, all exercised on behalf of the owner rather than in place of them. An owner holds the accountability and the classification decision itself. A processor handles information under instruction from another party. A controller sets the purposes and means of processing, which is a privacy-law role rather than a quality one.

  52. A company appoints a senior executive accountable for the overall data privacy program and compliance with privacy laws across the enterprise. Which title best describes this role?

    • A.Chief technical officer
    • B.Global security officer
    • C.Lead regulatory officer
    • D.Data protection officer
    Show answerHide answer

    Correct answer: Data protection officer

    The data protection officer is the designated executive for the privacy program: they monitor compliance with privacy law, advise the business on its obligations and act as the contact point for regulators and data subjects. A chief technical officer owns engineering and product direction. A global security officer leads the broad security function, of which privacy is only one strand. A lead regulatory officer tracks the full span of regulation that touches the business rather than the privacy program itself.

  53. Before engaging a new cloud provider, a company thoroughly investigates the vendor's financial stability, security posture, and reputation to ensure it is trustworthy. What is this vetting activity called?

    • A.Vendor risk transfer
    • B.Vendor exit planning
    • C.Vendor due diligence
    • D.Vendor budget review
    Show answerHide answer

    Correct answer: Vendor due diligence

    Investigating a prospective supplier's finances, security posture and reputation before signing anything is due diligence: the work is done up front, and its purpose is to decide whether to enter the relationship at all. Vendor risk transfer shifts residual exposure to an insurer or to the supplier through contract terms. Vendor exit planning prepares for the end of the relationship. Vendor budget review examines cost, which says nothing about whether the supplier can be trusted.

  54. An organization continually re-evaluates an existing vendor's ongoing performance and security posture throughout the contract term. Which third-party risk activity does this describe?

    • A.Continuous vendor oversight
    • B.Vendor due diligence review
    • C.Right-to-audit clause review
    • D.Initial vendor assessment
    Show answerHide answer

    Correct answer: Continuous vendor oversight

    Continuous vendor oversight is the activity of re-evaluating a supplier's performance and security posture throughout the contract term. Vendor due diligence review is wrong because it vets the supplier before the contract is signed. A right-to-audit clause review is wrong because it checks a contract term granting audit rights, which enables oversight but is not the ongoing activity itself. An initial vendor assessment is wrong because it is a one-time evaluation performed when the supplier is first brought in.

  55. Two companies sign a legally binding master contract that establishes the general terms, responsibilities, and liabilities governing all future transactions between them. Which agreement is this?

    • A.Data licensing agreement
    • B.Master service agreement
    • C.Joint research agreement
    • D.Payment escrow agreement
    Show answerHide answer

    Correct answer: Master service agreement

    A master service agreement sets the umbrella terms once, so liability, confidentiality, payment and dispute handling are settled for every engagement that follows and each new project only has to describe the work itself. A data licensing agreement grants rights to use a particular dataset. A joint research agreement governs shared study and the intellectual property arising from it. A payment escrow agreement puts funds with a third party until conditions are met.

  56. After signing a master agreement, a client issues a document that defines the specific deliverables, timelines, and tasks for a single project. Which document is this?

    • A.Service-level agreement
    • B.Statement of work
    • C.Memorandum of understanding
    • D.Memorandum of agreement
    Show answerHide answer

    Correct answer: Statement of work

    A statement of work is issued under an existing master agreement and defines the specific deliverables, timelines and tasks for a single project, leaving legal terms to the master contract. A service-level agreement sets measurable performance targets such as uptime and response times for an ongoing service rather than one project's deliverables. A memorandum of understanding records a non-binding intent to cooperate between parties, with no detailed tasks or schedule. A memorandum of agreement is a more formal, often binding statement of the parties' respective responsibilities, but it is a high-level cooperative arrangement rather than a project-level scope of deliverables.

  57. Before sharing sensitive product designs with a contractor, a company requires the contractor to sign a document legally obligating it to keep that information confidential. Which agreement is this?

    • A.Formal nondisclosure agreement
    • B.Formal service-level agreement
    • C.Business memorandum of understanding
    • D.Formal business partners agreement
    Show answerHide answer

    Correct answer: Formal nondisclosure agreement

    A formal nondisclosure agreement legally binds the receiving party to keep the information it is shown confidential, which protects the product designs given to the contractor. A service-level agreement defines measurable performance commitments such as uptime. A memorandum of understanding records shared intentions and is usually not legally binding. A business partners agreement sets out the ownership, profit and decision terms between partner organizations rather than a confidentiality duty.

  58. Two firms form a formal, legally binding contract to operate a joint venture and share in its profits and liabilities. Which agreement type best describes this relationship?

    • A.Memorandum of agreement
    • B.Memorandum of understanding
    • C.Interconnection security agreement
    • D.Business partnership agreement
    Show answerHide answer

    Correct answer: Business partnership agreement

    A business partnership agreement is the legally binding contract two firms sign to run a venture together, fixing each partner's contributions, profit share, liabilities and exit terms. A memorandum of agreement records cooperation on a defined task but does not create a jointly owned venture sharing profits and liabilities. A memorandum of understanding expresses shared intent and is generally not legally binding. An interconnection security agreement governs the security of a connection between two organizations' systems, not a business venture.

  59. A company negotiates a clause in its vendor contract allowing it to inspect and verify the vendor's security controls and compliance during the engagement. Which contractual provision is this?

    • A.Subcontracting clause
    • B.Data-residency clause
    • C.Right-to-audit clause
    • D.Non-disclosure clause
    Show answerHide answer

    Correct answer: Right-to-audit clause

    A right-to-audit clause is the contractual permission to go and look: it lets the customer examine the supplier's controls, records and evidence of compliance while the engagement is running, instead of relying on the supplier's own assurances. A subcontracting clause governs whether work may be passed to a fourth party. A data-residency clause fixes the countries in which data may be stored. A non-disclosure clause restricts what each side may reveal.

  60. A vendor announces that a product will no longer be sold or actively developed but will still receive limited support for a period. Which term describes this stage?

    • A.End-of-support phase
    • B.End-of-life status
    • C.End-of-service phase
    • D.Deprecation phase
    Show answerHide answer

    Correct answer: End-of-life status

    End-of-life status is the stage at which a vendor stops selling and actively developing a product while a defined period of limited support continues, giving customers time to plan a migration. The end-of-support phase is the later point at which that remaining help, including security patches, stops entirely, so it contradicts the limited support described. The end-of-service phase, often written end-of-service-life, is likewise the point where the vendor provides no service at all. A deprecation phase marks a feature or interface as scheduled for removal inside a product that is still sold and developed.

  61. A piece of network hardware has reached the date after which the manufacturer will provide no patches, updates, or support of any kind. Which term applies?

    • A.End-of-service-life (EOSL), a routine lifecycle marker
    • B.End-of-life (EOL), a documented lifecycle announcement
    • C.End-of-sale (EOS), a standardized lifecycle transition
    • D.Release-to-manufacturing (RTM), a known lifecycle step
    Show answerHide answer

    Correct answer: End-of-service-life (EOSL), a routine lifecycle marker

    End-of-service-life is the date beyond which the manufacturer issues no patches, no updates and no support of any kind, so a device that passes it can never be remediated again and has to be replaced, isolated or compensated for with other controls. End-of-life marks the end of active production and marketing, and a vendor normally still ships fixes for a stated period afterwards, so it is not the point at which support stops. End-of-sale is simply the last date the product can be ordered; units already in service keep their support entitlement. Release-to-manufacturing sits at the opposite end of the lifecycle, when a finished build is handed over for production.

  62. A regulator requires an organization to formally declare, in writing, that it is in compliance with a specific control framework and to provide evidence on demand. This formal declaration is best described as which of the following?

    • A.Gap analysis, a familiar governance deliverable
    • B.Risk register, an ordinary governance procedure
    • C.Compliance attestation, a known governance term
    • D.Due diligence, an accepted governance reference
    Show answerHide answer

    Correct answer: Compliance attestation, a known governance term

    Compliance attestation is the formal, signed declaration in which an organization states that it meets the requirements of a named control framework and undertakes to produce supporting evidence when the regulator asks for it. A gap analysis compares the controls in place against a target standard and produces a list of shortfalls; it is an internal finding, not a declaration to anyone. A risk register is the running inventory of identified risks with their owners, ratings and chosen treatments. Due diligence is the investigation one party performs on another before entering a relationship, and it produces evidence about someone else rather than a statement about oneself.

  63. An organization fails to meet a mandatory regulatory requirement and faces fines, loss of a license, and reputational harm. These outcomes are examples of which compliance concept?

    • A.Residual risk of non-compliance, a known risk metric
    • B.Consequences of non-compliance, a known governance term
    • C.Due care failures in compliance, a known liability term
    • D.Exposure factor for non-compliance, a known risk metric
    Show answerHide answer

    Correct answer: Consequences of non-compliance, a known governance term

    Consequences of non-compliance, a known governance term, covers the outcomes described: fines, loss of a license, sanctions and reputational damage imposed after a mandatory requirement is missed. Residual risk is the risk that remains after controls are applied, a level of exposure rather than the penalties actually suffered. A due care failure is the negligence that can cause non-compliance, not the outcomes that follow it. Exposure factor is the percentage of an asset's value lost in a single event, a quantitative risk metric rather than a compliance concept.

  64. A compliance team continuously tracks systems and processes to confirm the organization stays aligned with applicable laws and standards over time. Which compliance activity is this?

    • A.Compliance attestation, a known governance measure
    • B.Compliance training, a common governance procedure
    • C.Compliance remediation, a familiar governance term
    • D.Compliance monitoring, a defined governance effort
    Show answerHide answer

    Correct answer: Compliance monitoring, a defined governance effort

    Compliance monitoring is the continuous work of checking that systems, processes and controls still satisfy the laws, regulations and internal standards that apply, usually through automated evidence collection and recurring internal reporting. Compliance attestation is a point-in-time declaration made to an outside party, so it captures a moment rather than tracking alignment over time. Compliance training instructs staff on their obligations and changes behavior rather than measuring conformance. Compliance remediation is the corrective work carried out after a shortfall has already been identified.

  65. An auditor employed by the company itself reviews internal controls and reports findings to management to improve the security program. What kind of audit is this?

    • A.External audit, a routine assurance arrangement
    • B.Regulatory audit, a defined assurance reference
    • C.Internal audit, a documented assurance activity
    • D.Control self-assessment, a known assurance step
    Show answerHide answer

    Correct answer: Internal audit, a documented assurance activity

    An internal audit is carried out by auditors on the organization's own payroll who evaluate the control environment and report their findings to management and the audit committee, giving independence from the operations they review while remaining inside the organization. An external audit is performed by an outside firm precisely so that the reviewer has no employment relationship with the organization at all. A regulatory audit is conducted by a government supervisor exercising statutory powers, not by staff who report to management. A control self-assessment is completed by the process owners themselves, with no auditor involved and no independent challenge.

  66. To satisfy a partner's trust requirements, a company hires an independent third-party firm to objectively evaluate and attest to its security controls. What type of audit is this?

    • A.External audit, a familiar security arrangement
    • B.Audit committee review, an internal board check
    • C.Regulatory examination, a mandated agency check
    • D.Self-assessment, an internal security check
    Show answerHide answer

    Correct answer: External audit, a familiar security arrangement

    An external audit, a familiar security arrangement, is the engagement in which an independent outside firm the company hires evaluates its controls and attests to the result, and that independence is what a partner can rely on. An audit committee review is board oversight of the organization's own audit work, so it is internal, not an outside firm. A regulatory examination is imposed by a supervising agency rather than commissioned by the company to satisfy a partner. A self-assessment is performed by the organization's own staff and lacks independent attestation.

  67. Penetration testers are given no prior knowledge of the target environment and must discover everything from scratch, simulating an outside attacker. Which testing approach is this?

    • A.External (outside-in) penetration testing, a network-scoped style
    • B.Unknown environment (black-box) testing, a known assessment style
    • C.Gray-box (partial-info) penetration testing, a test-scoped style
    • D.Passive recon (OSINT) of the target environment, a no-touch style
    Show answerHide answer

    Correct answer: Unknown environment (black-box) testing, a known assessment style

    Unknown environment (black-box) testing, a known assessment style, gives testers no prior information, so they must discover everything as an outside attacker would. External penetration testing describes where the test is launched from, the perimeter, and can be run with full or partial knowledge, so it does not define what testers are told. Gray-box penetration testing supplies limited details such as an account or network map. Passive recon of the target environment is an information-gathering phase within a test, not a testing approach defined by how much testers are told.

  68. Penetration testers are provided some limited information, such as user-level credentials, but not full architecture details, blending insider and outsider perspectives. Which testing approach is this?

    • A.Credentialed (authenticated) scanning, a recognized assessment method
    • B.Purple team (collaborative) testing, a recognized assessment practice
    • C.Internal network (insider) testing, a recognized penetration practice
    • D.Partially known (gray-box) testing, a documented assessment reference
    Show answerHide answer

    Correct answer: Partially known (gray-box) testing, a documented assessment reference

    Partially known (gray-box) testing gives the tester a limited slice of information, such as user-level credentials, blending insider and outsider perspectives. Credentialed scanning logs in to enumerate vulnerabilities but is an automated scan, not a penetration testing approach. Purple team testing pairs attackers and defenders collaboratively and describes who works together, not how much the tester is told. Internal testing describes where the test starts on the network rather than the level of prior knowledge supplied.

  69. Before launching attacks, penetration testers gather information about a target by querying public records and DNS without interacting directly with the target's systems. Which activity is this?

    • A.Active reconnaissance, a known attacker method
    • B.Privilege escalation, a routine attacker phase
    • C.Lateral movement, a defined attacker technique
    • D.Passive reconnaissance, a common attacker step
    Show answerHide answer

    Correct answer: Passive reconnaissance, a common attacker step

    Passive reconnaissance collects intelligence from sources that never touch the target itself, such as registrar and public name records, corporate filings, job adverts and social media, so nothing the tester does appears in the target's own logs. Active reconnaissance sends traffic to the target to enumerate hosts, ports and services, which produces sharper information but is detectable. Privilege escalation happens after access has already been obtained and raises the rights of an existing foothold. Lateral movement is the spread from one compromised host to another inside the environment.

  70. During an engagement, testers send packets to and scan the target's live systems to map open ports and services. Which reconnaissance type is this?

    • A.Active reconnaissance, a common attacker method
    • B.Passive reconnaissance, a known attacker tactic
    • C.Social engineering, a routine attacker activity
    • D.Credential harvesting, a defined attacker phase
    Show answerHide answer

    Correct answer: Active reconnaissance, a common attacker method

    Active reconnaissance interacts directly with the target, sending packets to sweep address ranges, enumerate open ports and fingerprint the services behind them, which yields precise and current information at the cost of leaving evidence in the target's logs. Passive reconnaissance deliberately avoids that contact and relies on third-party and public sources instead. Social engineering manipulates people into disclosing information or taking an action and does not map infrastructure. Credential harvesting gathers usernames and passwords for later authentication rather than discovering which systems exist.

  71. An organization invites the public to find and responsibly report vulnerabilities in its applications in exchange for monetary rewards. Which program is this?

    • A.Coordinated disclosure policy, a public portal
    • B.Crowdsourced pentest program, an invited crowd
    • C.Bug bounty program, an established arrangement
    • D.Capture-the-flag contest, a public prize event
    Show answerHide answer

    Correct answer: Bug bounty program, an established arrangement

    A bug bounty program, an established arrangement, invites the public to find vulnerabilities in the organization's own applications and pays a monetary reward for each valid finding that is reported responsibly. A coordinated disclosure policy publishes a public portal and rules for reporting flaws responsibly, but it does not promise payment. A crowdsourced pentest program uses an invited, vetted crowd of testers under contract rather than an open invitation to the public. A capture-the-flag contest awards prizes for solving staged challenges built for the event, not for flaws found in production applications.

  72. During a security exercise, a designated offensive team attacks while a defensive team protects, and a third group enforces rules and scoring. Which group label refers to the defenders?

    • A.Red team, a common exercise function
    • B.Blue team, a known exercise identity
    • C.White team, a routine exercise label
    • D.Purple team, a defined exercise role
    Show answerHide answer

    Correct answer: Blue team, a known exercise identity

    The blue team is the defending side in an adversarial exercise: it monitors telemetry, detects the intrusion, contains it and restores service while the attack is under way. The red team is the offensive side, emulating an adversary against those defenses. The white team writes the rules, adjudicates disputes and scores the exercise, which is the third group the scenario describes. The purple team is the coordinating arrangement that feeds attacker findings straight into detection engineering, so it improves defenses afterwards rather than operating them during the exercise.

  73. In an attack simulation exercise, the offensive group is tasked with emulating real adversaries to probe the organization's defenses. Which team label applies to this group?

    • A.Purple team, a blended exercise unit
    • B.Red team, a common exercise identity
    • C.White team, a neutral exercise judge
    • D.Blue team, a standard exercise group
    Show answerHide answer

    Correct answer: Red team, a common exercise identity

    The red team is the offensive group that emulates real adversary tradecraft against the organization's defenses, so red team, a common exercise identity, is the label for this attacking group. A purple team blends attackers and defenders to share findings and is not the group assigned to emulate the adversary. The white team acts as a neutral judge that sets rules and scores. The blue team is the defending group that monitors, detects and responds.

  74. A new employee is required to sign a document that defines what is and is not permitted when using company computers, email, and internet. Which policy is this?

    • A.Code of conduct policy, a broad governance charter
    • B.Information security policy, a top governance text
    • C.Acceptable use policy, a defined governance record
    • D.Data handling policy, a written governance charter
    Show answerHide answer

    Correct answer: Acceptable use policy, a defined governance record

    The answer is acceptable use policy, a defined governance record: the document that spells out which uses of company computers, email and internet access are permitted and which are prohibited, and new employees read and sign it before they receive access. A code of conduct policy governs professional and ethical behaviour in general, such as conflicts of interest and harassment, rather than the rules for using IT resources. An information security policy is the top-level statement of the organization's security goals and responsibilities, from which narrower policies such as the acceptable use policy are derived. A data handling policy sets how information is classified, stored, shared and destroyed, not what employees may do with computers, email and the internet.

  75. An organization runs a security awareness campaign that sends fake phishing emails to employees and records who clicks, in order to measure and improve user behavior. What is this technique called?

    • A.Phishing simulation campaign, a known technique
    • B.Phishing awareness training, a common technique
    • C.Spear phishing campaign, a common technique
    • D.Social engineering exercise, a common technique
    Show answerHide answer

    Correct answer: Phishing simulation campaign, a known technique

    The phishing simulation campaign, a known technique in awareness programs, sends controlled fake phishing emails to staff and records who clicks, producing a measured susceptibility rate and a teaching moment for those who fall for it. Phishing awareness training teaches people to spot lures but does not send test messages or measure clicks. A spear phishing campaign is a real, targeted attack by an adversary, not an internal awareness exercise. A social engineering exercise is a penetration-testing engagement that probes defenses for an assessment report rather than an ongoing program to measure and improve staff behavior.

  76. As part of a security awareness program, a company tracks how employee click rates on simulated phishing drop over time and reports the trend to leadership. This use of metrics is best described as which of the following?

    • A.Scoping and staffing of incident response, an ordinary commitment
    • B.Testing and patching of endpoint software, a familiar undertaking
    • C.Drafting and signing of vendor contracts, an accepted arrangement
    • D.Reporting and monitoring of program effectiveness, a known effort
    Show answerHide answer

    Correct answer: Reporting and monitoring of program effectiveness, a known effort

    Reporting and monitoring of program effectiveness is the awareness-program activity that gathers metrics such as the click rate on successive simulations, watches how they move over time and puts the trend in front of leadership so the program can be funded and adjusted on evidence. Scoping and staffing of incident response builds a response capability and does not measure anything about awareness. Testing and patching of endpoint software closes technical weaknesses in machines rather than tracking human behavior. Drafting and signing of vendor contracts is procurement work with no bearing on awareness metrics.

  77. An organization sets rules for how long different categories of records must be kept and when they should be securely destroyed to meet legal and business needs. Which governance policy is this?

    • A.Data classification policy, a formal governance guide
    • B.Media sanitization policy, a formal governance record
    • C.Data retention policy, a routine governance statement
    • D.Backup and restore policy, a formal governance record
    Show answerHide answer

    Correct answer: Data retention policy, a routine governance statement

    A data retention policy, a routine governance statement, sets how long each category of record must be kept and when it must be securely destroyed, balancing legal requirements and business need. A data classification policy labels information by sensitivity but does not set how long it is kept. A media sanitization policy defines how storage is wiped or destroyed, not when records reach end of life. A backup and restore policy governs copies for recovery, not the lifespan of the records themselves.

  78. A formal change management process requires that every proposed change be reviewed and authorized before implementation to prevent unmanaged disruptions. Which body typically performs this review and approval?

    • A.Internal audit group, a common oversight commission
    • B.Change advisory board, a routine oversight function
    • C.Incident response team, a standard oversight entity
    • D.Security governance council, a known oversight body
    Show answerHide answer

    Correct answer: Change advisory board, a routine oversight function

    A change advisory board is the standing group that reviews each proposed change, weighs its risk, impact and backout arrangements, and then authorizes or rejects it before implementation, which is the control point a formal change process depends on. An internal audit group examines whether the process was followed after the fact and does not approve individual changes. An incident response team handles events that have already gone wrong. A security governance council sets priorities, policy direction and funding for the security program rather than ruling on individual change requests.

  79. When responding to a risk, an organization chooses to stop the activity that creates the risk entirely so the threat can no longer affect it. Which risk treatment strategy is this?

    • A.Risk acceptance, a known treatment option
    • B.Risk transfer, a routine treatment choice
    • C.Risk mitigation, a common treatment label
    • D.Risk avoidance, a familiar treatment path
    Show answerHide answer

    Correct answer: Risk avoidance, a familiar treatment path

    Risk avoidance removes the exposure altogether by not undertaking the activity, or by discontinuing it, so there is no longer anything for the threat to act against. Risk acceptance keeps the activity running and knowingly absorbs the exposure as it stands. Risk transfer keeps the activity and shifts the financial consequence to an insurer or a counterparty, leaving the underlying threat in place. Risk mitigation also keeps the activity and applies controls to reduce how likely the event is or how much it would cost, which lowers the exposure without eliminating it.

  80. A governance team is documenting the order of precedence among security documents. Which document type is a high-level, mandatory management statement that defines the organization's overall intent and expectations regarding security?

    • A.Policy, a common governance artifact
    • B.Standard, a routine governance label
    • C.Procedure, a defined governance text
    • D.Guideline, a related governance item
    Show answerHide answer

    Correct answer: Policy, a common governance artifact

    A policy is the high-level, mandatory statement of management intent that sets the organization's security goals and expectations, and it sits at the top of the document hierarchy because every other document is written to support it. A standard specifies the mandatory, measurable technical or operational requirements that implement a policy, so it is subordinate and far more detailed. A procedure gives the step-by-step instructions for performing a specific task. A guideline offers recommended practice that staff are free to adapt, so it is advisory rather than mandatory.

  81. A company publishes a document that all employees must sign, defining permitted and prohibited uses of corporate laptops, email, and internet access. Which security governance document is this?

    • A.Non-disclosure agreement (NDA), a binding staff pact
    • B.Bring your own device (BYOD) policy, a staff ruleset
    • C.Acceptable use policy (AUP), a standard written text
    • D.Information security policy (ISP), a parent rule set
    Show answerHide answer

    Correct answer: Acceptable use policy (AUP), a standard written text

    An acceptable use policy (AUP), a standard written text signed by every employee, defines permitted and prohibited uses of corporate laptops, email and internet access. A non-disclosure agreement is signed too, but it restricts sharing confidential information rather than defining acceptable use of systems. A BYOD policy governs personally owned devices, not corporate laptops. An information security policy is the high-level parent document that sets overall security direction, with specific rules such as acceptable use delegated to subordinate policies.

  82. Before deploying a configuration change to production firewalls, a security team requires that the change be submitted, reviewed, approved, scheduled, and accompanied by a documented backout plan. Which security program process enforces this discipline?

    • A.Change management, a published program capability
    • B.Incident response, a standardized program routine
    • C.Vulnerability remediation, a known program effort
    • D.Configuration enforcement, a defined program task
    Show answerHide answer

    Correct answer: Change management, a published program capability

    Change management is the discipline that requires every change to be requested, reviewed, authorized, given an implementation window and supported by a rollback plan before it touches production, which is precisely the sequence the firewall change has to pass through. Incident response deals with events after something has gone wrong rather than governing planned work. Vulnerability remediation fixes identified weaknesses but says nothing about how any change is authorized or scheduled. Configuration enforcement keeps deployed systems on an approved baseline and corrects drift; it applies settings rather than deciding which settings may be applied.

  83. An organization is sorting its data into categories such as public, internal, confidential, and restricted so that appropriate protections can be applied based on sensitivity. Which governance activity is being performed?

    • A.Data labeling, a routine governance safeguard
    • B.Data classification, a common governance term
    • C.Data inventory, a common governance procedure
    • D.Data discovery, a common governance procedure
    Show answerHide answer

    Correct answer: Data classification, a common governance term

    Data classification, a common governance term, is the activity of sorting information into sensitivity tiers such as public, internal, confidential and restricted so that matching protections can be applied. Data labeling marks each item with the tier after classification has defined the tiers, so it applies the scheme rather than creating it. A data inventory lists what data exists and where it is held. Data discovery scans systems to locate sensitive data but does not assign it to categories.

  84. In a data governance model, an individual holds accountability for a specific data set, including decisions about its classification and who may access it, while delegating day-to-day storage and backup tasks to others. Which role does this individual hold?

    • A.Data user, a common governance designation
    • B.Data custodian, a routine governance title
    • C.Data processor, a defined governance label
    • D.Data owner, a familiar governance position
    Show answerHide answer

    Correct answer: Data owner, a familiar governance position

    The data owner is the senior accountable role that decides how a data set is classified and who may be granted access to it, and that accountability stays with the owner even when the hands-on work is handed to someone else. The data custodian performs exactly that delegated work, running storage, backup and the technical controls the owner has specified. The data processor acts on personal data only under the documented instructions of a controller. The data user is the person who consumes the data to do a job and makes no decisions about its protection.

  85. Two companies forming a long-term strategic partnership want a formal, legally binding contract that defines the responsibilities, expectations, and terms of their ongoing business relationship. Which agreement type best fits this need?

    • A.Business partners agreement (BPA), a routine contractual record
    • B.Memorandum of understanding (MOU), a published contractual form
    • C.Mutual non-disclosure agreement (NDA), a known contractual item
    • D.Master service agreement (MSA), a standard contractual document
    Show answerHide answer

    Correct answer: Business partners agreement (BPA), a routine contractual record

    A business partners agreement is the binding contract two organizations sign to set out the responsibilities, contributions, revenue arrangements and expectations of an ongoing partnership, which is what a long-term strategic relationship needs. A memorandum of understanding records shared intentions and is generally not enforceable, so it cannot carry the obligations the two firms want to fix. A mutual non-disclosure agreement protects information the parties exchange but says nothing about how they will work together. A master service agreement fixes baseline terms for future work orders rather than establishing the partnership itself.

  86. During third-party vendor due diligence, a buyer insists that the contract include a clause permitting it to inspect and review the vendor's security controls and compliance at any time. Which contractual provision is this?

    • A.Security control clause, a vendor contract item
    • B.Assurance report clause, a vendor contract item
    • C.Right-to-audit clause, a familiar contract term
    • D.Breach notice clause, a vendor contract item
    Show answerHide answer

    Correct answer: Right-to-audit clause, a familiar contract term

    The right-to-audit clause, a familiar contract term in vendor agreements, is the provision that lets the customer inspect and review the vendor's security controls and compliance directly, on its own schedule, turning assurances into something verifiable. A security control clause obliges the vendor to maintain named controls but gives the buyer no right to go and check them. An assurance report clause makes the vendor hand over attestations such as a SOC 2 report, so the buyer reviews a third party's findings rather than inspecting anything itself. A breach notice clause only requires the vendor to report incidents within a set time.

  87. Before a penetration test begins, both parties sign a document defining the test's scope, timing, permitted techniques, target systems, and points of contact so the testers stay within authorized boundaries. What is this document called?

    • A.Memorandum of understanding, a known written text
    • B.Statement of applicability, a common written item
    • C.Standards of conduct, a routine written reference
    • D.Rules of engagement, a defined written instrument
    Show answerHide answer

    Correct answer: Rules of engagement, a defined written instrument

    Rules of engagement is the document both sides sign before an authorized test, fixing the scope, the testing window, the techniques that may be used, the systems that are in scope and the emergency contacts, so the testers can be held to agreed limits and the customer knows what to expect. A memorandum of understanding records non-binding intentions between organizations. A statement of applicability lists which controls of a standard an organization has selected and why. Standards of conduct set behavioral expectations for employees and have nothing to do with test boundaries.

  88. An organization wants independent assurance that a cloud provider's stated security controls are designed and operating effectively, so it requests a formal report produced by an external auditor. Which type of audit is the organization relying on?

    • A.Penetration test, a common assurance activity
    • B.Third-party audit, a known assurance activity
    • C.Self-attestation, a common assurance activity
    • D.Right-to-audit clause, a usual assurance tool
    Show answerHide answer

    Correct answer: Third-party audit, a known assurance activity

    Third-party audit, a known assurance activity, is the answer. It is carried out by an independent external firm, and that independence is why its formal report, such as a SOC 2 Type II, is accepted as evidence that controls are designed and operating effectively. A penetration test probes for exploitable weaknesses at a point in time and does not attest to control operation over a period. A self-attestation is the provider vouching for itself, so it lacks the independence the customer wants. A right-to-audit clause is a contract term granting the customer permission to audit; it is not itself a type of audit or an auditor's report.

  89. A company asks a prospective SaaS vendor for an independent auditor's report covering the operating effectiveness of the vendor's security controls over a period of time. Which report should the company request?

    • A.Prior year internal audit memo copy, a recognized deliverable
    • B.Vendor written security policy document set, a common package
    • C.Recent external network vulnerability scan file, a known item
    • D.SOC 2 Type II attestation report, a well-documented reference
    Show answerHide answer

    Correct answer: SOC 2 Type II attestation report, a well-documented reference

    A SOC 2 Type II attestation report is produced by an independent auditor and covers whether the service provider's controls were suitably designed and, crucially, whether they operated effectively across a defined review window, which is precisely the evidence a buyer needs for vendor due diligence. A prior year internal audit memo is the vendor's own work product and carries no independence. A vendor written security policy document set states what the provider intends to do rather than proving the controls ran. A recent external network vulnerability scan file lists technical findings at a single moment and never addresses control effectiveness over time.

  90. Under a privacy regulation, an organization collects only the specific personal data fields strictly necessary to deliver the requested service and nothing more. Which privacy principle is being applied?

    • A.Data minimization, a known privacy notion
    • B.Purpose limitation, a core privacy notion
    • C.Storage limitation, a core privacy notion
    • D.Data sovereignty, a core privacy notion
    Show answerHide answer

    Correct answer: Data minimization, a known privacy notion

    Data minimization, a known privacy notion, is the principle of collecting only the personal data fields strictly necessary for the stated purpose, which is exactly what the organization is doing. Purpose limitation restricts what collected data may be used for, not how much is collected in the first place. Storage limitation restricts how long personal data may be kept once it has been gathered. Data sovereignty concerns which jurisdiction's laws govern data based on where it is stored.

  91. A customer submits a formal request asking a company to disclose all personal information the company holds about them and to provide a copy of that data. Fulfilling this request supports which privacy capability?

    • A.Breach notice duty, a routine obligation
    • B.Subject access request, a common measure
    • C.Privacy impact review, a defined control
    • D.Records retention schedule, a known step
    Show answerHide answer

    Correct answer: Subject access request, a common measure

    A subject access request is the mechanism privacy law gives an individual to make an organization confirm what personal data it holds about them and hand over a copy of it, normally inside a statutory deadline. A breach notice duty obliges the organization to inform regulators and affected people after a compromise, so it is triggered by an incident rather than by a person's request. A privacy impact review assesses the risk of a planned processing activity before it begins. A records retention schedule sets how long each class of record is kept and when it is destroyed.

References

  1. 1.CompTIA. “CompTIA Security+ (SY0-701) Certification Overview.” CompTIA.org, 2026. ↑
  2. 2.CompTIA. “Security+ SY0-701 Exam Objectives (Domains 1–5 and Weightings).” CompTIA.org. ↑
  3. 3.Pearson VUE. “CompTIA Exam Registration and Scheduling.” Pearson VUE. ↑
  4. 4.CompTIA. “Continuing Education (CE) Program / Certification Renewal Policy.” CompTIA.org. ↑
  5. 5.CompTIA. “SY0-701 Launch Announcement (Effective November 7, 2023).” CompTIA.org. ↑
  6. 6.Career Employer. “CompTIA Security+ practice-test performance data.” careeremployer.com, updated daily, CC BY 4.0. ↑
Career Employer

Career Employer is the ultimate resource to help you get started working the job of your dreams. We cover topics from general career information, career searching, exam preparation with free study materials, career interviewing, and becoming successful in your career of choice.

Follow Us:

All Posts

Career Employer’s Editorial Process

Here at Career Employer, we focus a lot on providing factually accurate information that is always up to date. We strive to provide correct information using strict editorial processes, article editing, and fact-checking for all of the information found on our website. We only utilize trustworthy and relevant resources. To find out more, make sure to read our full editorial process page here.