Start date 2025-10-04 19:07:16 Duration 1 hours 20 minutes 1 seconds Score 79.72% Rate No rate provided - New Sec+ Domain 3: 11 / 14 New Sec+ Domain 4: 17 / 23 New Sec+ Domain 1: 11 / 13 New Sec+ Domain 5: 16 / 16 New Sec+ Domain 2: 12 / 18 Cysa+ PBQs: 3 / 3 SEC+ PBQs: 3 / 3 From <https://certpreps.com/history/> CertPreps CompTIA Security+ Practice Exam 6 Results, October 4th, 2025 1. A financial institution is upgrading its network security and is considering the implementation of an Intrusion Detection System (IDS) and an Intrusion Prevention System (IPS). The IT team needs to understand the key functional difference between these systems. What is the primary distinction between an IDS and an IPS in their operational roles, and how does this affect their deployment in a network environment? A. An IDS encrypts network traffic for security, while an IPS decrypts traffic for analysis. B. An IDS passively monitors and alerts on potential threats, while an IPS actively blocks them. C. An IDS functions as a firewall, while an IPS serves as an antivirus solution. D. An IDS and an IPS are functionally identical but differ in their vendor implementations. The primary functional difference between an Intrusion Detection System (IDS) and an Intrusion Prevention System (IPS) lies in their approach to handling potential security threats. An IDS (Option B) operates in a passive mode, monitoring network traffic and alerting the security team about potential threats or anomalies. It does not take direct action to stop the threat. In contrast, an IPS actively analyzes network traffic and can take immediate action to block or mitigate identified threats, such as dropping malicious packets or closing compromised connections. This distinction affects their deployment: an IDS is typically used for threat detection and situational awareness, while an IPS is positioned to actively protect the network. Options A, C, and D are incorrect as they misrepresent the functionalities of an IDS and an IPS. 2. A security analyst at GlobalTech is reviewing the user account management process. The analyst discovers that several user accounts belonging to former employees are still active months after their departure. What is the PRIMARY security risk associated with this practice? A. Increased cost due to unused licenses. B. Inability to track user account usage effectively. C. Potential for unauthorized access to sensitive information. D. Compliance issues with data protection regulations. The primary security risk of having active user accounts of former employees is the potential for unauthorized access to sensitive information. These accounts can be exploited by malicious actors or even by the former employees if their credentials are still valid. This poses a significant threat to the integrity and confidentiality of the organization's data. Option A, while a valid concern, is not primarily a security risk. Option B is a challenge in monitoring but is secondary to the risk of unauthorized access. Option D is also a valid concern but is more about regulatory compliance than the direct security risk posed by active accounts. 3. An IT company is deploying a new data encryption tool across its network. After implementation, the tool causes significant performance degradation and interferes with critical workflows. The company had a backout plan in place, which it promptly executes, restoring normal operations. What lesson can be learned about backout plans in change management from this scenario? A. The importance of choosing reliable and tested tools for network security. B. The value of having a backout plan to mitigate negative impacts of new implementations. C. The necessity of training employees on new tools to avoid operational issues. D. The need for ongoing monitoring and optimization of new security solutions. This scenario highlights the value of having a backout plan in change management, especially when implementing new tools that can significantly impact network performance and operations. Despite the potential benefits of the new data encryption tool, it unexpectedly caused performance issues and disrupted critical workflows. The presence of a backout plan allowed the company to quickly revert to a stable operational state, mitigating the negative impacts of the new implementation. This prompt action preserved operational integrity and security, demonstrating that backout plans are essential safety nets. They provide a structured approach to revert changes in case of adverse effects, ensuring minimal disruption to business operations and maintaining security standards. 4. A large retail company is evaluating the Single Loss Expectancy (SLE) of a data breach involving the theft of customer credit card information. The company estimates that a breach could result in the loss of 10,000 customer records, with a potential cost of $150 per compromised record in fines, remediation, and lost business. What is the calculated SLE for this data breach scenario? A. $150,000 B. $1,500,000 C. $15,000,000 D. $150,000,000 Single Loss Expectancy (SLE) is a risk management metric that quantifies the financial loss expected from a single occurrence of a specific risk. It is calculated by multiplying the value of each unit of loss by the number of units at risk. In this scenario, the company estimates a potential cost of $150 per compromised record and anticipates the loss of 10,000 customer records. Therefore, the SLE is calculated as $150 (cost per record) x 10,000 (number of records) = $1,500,000. This figure represents the estimated financial impact on the company from a single data breach involving the theft of customer credit card information. 5. A government agency implements strict configuration enforcement on all its devices and systems. As part of this policy, all workstations are configured to disable USB ports and encrypt hard drives. An employee attempts to transfer data using a USB drive and finds the ports non-functional. What is the primary security benefit of enforcing such configuration settings in this scenario? A. Enhancing the processing speed of the workstations. B. Facilitating the remote management of devices. C. Preventing unauthorized data extraction and loss. D. Reducing the need for regular hardware upgrades. The primary security benefit of enforcing strict configuration settings, such as disabling USB ports and encrypting hard drives, is to prevent unauthorized data extraction and loss. By disabling USB ports, the agency ensures that sensitive data cannot be easily transferred to external devices, reducing the risk of data theft or leakage. Hard drive encryption adds an additional layer of security by ensuring that data stored on the device remains confidential and protected, even if the device is lost or stolen. These measures are not aimed at enhancing the processing speed of workstations (Option A), facilitating remote management (Option B), or reducing the need for hardware upgrades (Option D), but are focused on securing sensitive data and preventing unauthorized access. 6. An online retail company has established a Recovery Time Objective (RTO) of 4 hours for its e-commerce platform in the event of a system outage. During a routine risk assessment, it's discovered that the current backup and recovery processes could take up to 8 hours to restore operations. What should be the company's immediate focus to align with its RTO? A. Upgrading the company's website to a more modern e-commerce platform. B. Implementing faster backup and recovery solutions to meet the 4-hour RTO. C. Increasing the frequency of backup operations to minimize data loss. D. Training staff on manual order processing during system outages. Given that the current backup and recovery processes do not meet the established Recovery Time Objective (RTO) of 4 hours, the company's immediate focus should be on implementing faster backup and recovery solutions (Option B). This may involve investing in more advanced technology, optimizing existing processes, or adopting new strategies that enable quicker restoration of operations. While upgrading the e-commerce platform (Option A) might offer long-term benefits, it does not directly address the immediate issue of meeting the RTO. Increasing the frequency of backups (Option C) is important for minimizing data loss but does not necessarily reduce recovery time. Training staff on manual processes (Option D) is a contingency measure but should not replace efforts to meet the RTO. 7. A software development company specializes in creating applications for the healthcare sector. A new national regulation requires enhanced security measures for all software handling patient health information. What should the company prioritize to ensure compliance with this national regulation? A. Continue development as usual, assuming the current security measures are sufficient. B. Focus on marketing efforts to highlight the security features of their products. C. Update the security features of their software to meet the new national regulation requirements. D. Outsource the development of security features to expedite compliance. The company should prioritize updating the security features of their software to meet the new national regulation requirements (Option C). This action ensures that the software is compliant with the enhanced security measures mandated for handling patient health information. Staying current with national regulations is crucial for maintaining the legal operation of their products in the healthcare sector. Continuing development as usual (Option A) risks noncompliance and potential legal issues. While marketing the security features (Option B) is important, it should be based on actual compliance with the new regulations. Outsourcing security development (Option D) can be a strategy to expedite compliance, but it does not replace the need for the company to ensure that the end product meets regulatory standards. Prioritizing the update of security features demonstrates a commitment to legal compliance and the protection of patient health information. 8. After implementing a new security monitoring tool, a company's quarterly security report indicates a lower number of detected security incidents compared to the previous quarter. The IT department has not reported any significant changes in the network or security infrastructure. What should be the primary concern regarding this report, and what should be the initial investigative action? A. Improved security posture; conduct a security audit to verify the findings B. Tool malfunction; perform a functionality test of the security monitoring tool C. Reduced threat landscape; analyze industry threat reports for comparison D. Reporting error; review the data collection and reporting process of the tool Given that there have been no significant changes in the network or security infrastructure, a sudden decrease in detected incidents may indicate a reporting error or issue with the data collection process of the new security monitoring tool. The initial action should be to review the data collection and reporting process to ensure accuracy and completeness. Options A (Improved security posture) and C (Reduced threat landscape) are less likely without additional corroborating evidence. Option B (Tool malfunction) could be considered, but a reporting error is more likely given the context of a new tool implementation. 9. To enhance the security of an air-gapped network used in a financial institution's data center, which two of the following practices should be implemented? (SELECT TWO) A. Ensuring all devices connected to the air-gapped network are free of wireless capabilities. B. Periodically connecting the air-gapped network to the corporate network for data synchronization. C. Implementing strict policies for the use and scanning of removable media on the air-gapped systems. D. Allowing staff to bring personal mobile devices into the area where the airgapped network is located. In an air-gapped network, particularly in a sensitive environment like a financial institution's data center, ensuring that all devices connected to the network are free of wireless capabilities (Option A) is crucial. This prevents any potential wireless connections that could compromise the network's isolation. Implementing strict policies for the use and scanning of removable media (Option C) is also essential. This includes regulating how devices like USB drives are used, ensuring they are scanned for malware, and maintaining strict control over what is transferred to and from the air-gapped network. Periodically connecting the air-gapped network to the corporate network (Option B) would undermine its isolation and expose it to potential cyber threats. Allowing staff to bring personal mobile devices (Option D) into the area poses a security risk, as these devices could potentially be used to breach the network's isolation or to exfiltrate data. 10. An IT security manager in a law firm is tasked with hardening the security of workstations used by attorneys and administrative staff. These workstations contain sensitive client information and are connected to the internet. The firm has already implemented antivirus software and firewalls. However, a recent security audit revealed that some workstations were still vulnerable to phishing attacks. What additional hardening measure should the IT security manager implement to specifically address this vulnerability? A. Enabling full-disk encryption on all workstations. B. Configuring web browsers to block pop-ups and potentially harmful websites. C. Upgrading the hardware components of the workstations for better performance. D. Implementing biometric authentication for workstation access To specifically address the vulnerability to phishing attacks, the IT security manager should configure web browsers to block pop-ups and potentially harmful websites (B). This measure directly targets the common methods used in phishing attacks, such as deceptive pop-ups and malicious websites, reducing the likelihood of staff falling victim to such threats. Full-disk encryption (A) is important for data protection but does not prevent phishing attacks. Upgrading hardware components (C) may improve performance but does not address the issue of phishing. Implementing biometric authentication (D) enhances access security but is not specifically effective against phishing. 11. A legal firm handles private and confidential client information, including case details and personal data. To safeguard this information, which TWO of the following security measures should be implemented? (SELECT TWO) A. Deploying an intrusion detection and prevention system (IDPS). B. Applying data loss prevention (DLP) technology to monitor and control data access. C. Implementing biometric security for access to the firm's office premises. D. Establishing a secure, encrypted email system for client communication. Applying data loss prevention (DLP) technology is crucial for monitoring and controlling access to private and confidential client information in a legal firm. DLP systems help prevent unauthorized access and transmission of sensitive data, ensuring the security and confidentiality of client information. Establishing a secure, encrypted email system for client communication is also essential to protect the privacy of client communications. Encryption ensures that emails containing sensitive information are secure and unreadable to unauthorized parties, maintaining client confidentiality and trust. While an IDPS (A) and biometric security (C) are important for overall security, they do not specifically address the protection of private client information and secure communication as effectively as DLP technology and encrypted email systems. These two measures provide targeted and comprehensive protection for the types of sensitive data handled by a legal firm. 12. You are a senior cybersecurity analyst responsible for monitoring and responding to security incidents on SERVER01. The syslog entries shown here are part of a log file that spans several hours. Your task is to identify the recommended actions based on the provided log entries. What steps should be taken immediately in response to the event logged at 8:45? A. Disconnect the affected server from the network and initiate a full database audit. B. Block the user account associated with the unauthorized access and conduct a root cause analysis. C. Immediately restore the database from a recent backup to a clean state. D. Ignore the entry; it might be a false positive. Blocking the user account associated with the unauthorized access is a critical step to immediately halt further unauthorized activity and prevent potential data breaches. Concurrently, conducting a root cause analysis is essential to understand how the unauthorized access occurred, identify any vulnerabilities or misconfigurations, and determine the extent of the compromise. This analysis informs remediation efforts to address the underlying issues and prevent similar incidents in the future. 13. Arrange the following steps in the correct order for an effective incident response. The correct order for incident response is: Identification (detecting the incident), Containment (limiting its impact), Eradication (removing the threat), and Recovery (restoring systems to normal operation). Documentation is important but not a sequential step in this process. 14. A healthcare organization is implementing a (Software Defined) SD-WAN solution to enhance connectivity and security across its network of clinics. The IT security team is concerned about protecting sensitive patient data while utilizing SD-WAN. Which feature of SD-WAN is particularly important for securing data transmissions in the healthcare environment, and why? A. Quality of Service (QoS) management to prioritize critical healthcare applications. B. End-to-end encryption for securing data transmitted over the SD-WAN. C. Automatic failover to secondary connections for uninterrupted service. D. Bandwidth optimization to handle large volumes of medical imaging data. In a healthcare environment where sensitive patient data is transmitted across the network, end-to-end encryption is a crucial feature of a Software-Defined Wide Area Network (SD-WAN) for ensuring data security (Option B). SD-WAN's end-to-end encryption protects data as it travels from one clinic location to another, safeguarding it against interception and unauthorized access. This is particularly important in healthcare due to the confidential nature of patient information and the need to comply with data protection regulations. Quality of Service (QoS) management (Option A) is important for application performance but does not directly address data security. Automatic failover (Option C) ensures uninterrupted service but is more focused on network reliability than security. Bandwidth optimization (Option D) is critical for handling large data files but is not specifically related to the security of data transmissions. 15. An e-commerce company experienced a breach where customer payment information was exfiltrated. The attack was conducted through a sophisticated phishing campaign that targeted employees, eventually leading to unauthorized access to the payment database. What type of threat actor is most likely responsible for this data exfiltration? A. A nation-state actor targeting economic information B. A malicious insider seeking financial gain C. An external cybercriminal specializing in financial fraud D. A hacktivist group aiming to expose privacy issues The scenario describes a data exfiltration incident involving customer payment information, executed through a sophisticated phishing campaign. This suggests the work of an external cybercriminal (Option C) specializing in financial fraud. The focus on stealing payment information for likely financial gain is a common motive among cybercriminals, as opposed to nation-state actors (Option A) who typically target information for strategic purposes, malicious insiders (Option B) who might have different motivations for data theft, and hacktivist groups (Option D) which usually have political or social motives. 16. The IT team at GlobalTech Inc. has implemented package monitoring to track the security of software packages used in their critical applications. Recently, the monitoring system flagged a vulnerability in a third-party library that is extensively used across various applications. What should be the team's immediate next step to ensure the security of their applications? A. Replace the third-party library with an alternative. B. Conduct a risk assessment to understand the impact of the vulnerability. C. Disable package monitoring to avoid further alerts. D. Temporarily remove the affected applications from production. Package monitoring is a process of tracking the security and updates of software packages used in applications. When a vulnerability is identified in a third-party library, it's important to first understand the potential impact of that vulnerability on the organization's applications. Conducting a risk assessment helps in determining the severity of the vulnerability, the likelihood of exploitation, and the potential consequences if exploited. This information is crucial for making informed decisions about how to best address the vulnerability, such as whether to update the library, implement a workaround, or replace it with an alternative. Option A, replacing the third-party library, may be an eventual course of action, but it should be based on the results of the risk assessment. Option C, disabling package monitoring, is counterproductive as it reduces visibility into potential security issues. Option D, temporarily removing applications from production, is a drastic measure that may not be necessary and can disrupt business operations. 17. A hospital implements a new electronic health record (EHR) system. To protect patient data, the IT department configures permissions so that doctors can edit and view patient records, nurses can only view them, and administrative staff can access neither. A nurse discovers that they are unable to edit patient records. Which security principle is being applied through these permissions? A. Data minimization. B. Least privilege. C. Redundancy. D. Fault tolerance. The principle of least privilege is being applied in this scenario, where permissions are configured to provide only the necessary access levels for each role. Doctors, who need to edit and view patient records, are given those permissions, while nurses are limited to viewing only, and administrative staff are denied access to patient records. This approach minimizes the risk of unauthorized access or modification of sensitive data by ensuring that users have the minimum level of access required to perform their duties. Data minimization (Option A) is a broader concept focused on collecting and retaining only the data that is necessary. Redundancy (Option C) and fault tolerance (Option D) are related to system availability and resilience, not access control. 18. A company's internal network was sabotaged, resulting in significant data loss and operational disruption. The attack was traced back to a recently terminated employee who had retained access to the network. Before leaving, the employee had planted a logic bomb that activated after their departure. This incident is an example of which type of cybersecurity threat? A. External hacking for financial gain B. Insider threat motivated by revenge C. Accidental data breach due to employee negligence D. State-sponsored cyber warfare The scenario describes a deliberate act of sabotage by a recently terminated employee, indicating an insider threat motivated by revenge (Option B). The use of a logic bomb, which is a type of malicious code set to trigger under specific conditions, reflects a premeditated attempt to cause harm to the company in retaliation for the employee's termination. This type of threat differs from external hacking (Option A), which typically involves attackers from outside the organization and is often financially motivated, accidental data breaches due to negligence (Option C), and state-sponsored cyber activities (Option D), which are usually strategic in nature. 19. A tech company, InnovateTech, runs a bug bounty program to enhance the security of its mobile payment application. The program has successfully identified several vulnerabilities. To maximize the effectiveness of the bug bounty program in their vulnerability management strategy, which TWO of the following actions should InnovateTech prioritize? (SELECT TWO) A. Provide detailed feedback to participants on the vulnerabilities they report. B. Focus solely on high-severity vulnerabilities and disregard less critical reports. C. Implement a process for quick verification and remediation of reported vulnerabilities. D. Publicly disclose all reported vulnerabilities immediately after confirmation. To maximize the effectiveness of a bug bounty program, it's important to engage positively with the security researcher community and to manage reported vulnerabilities efficiently. Option A, providing detailed feedback to participants, encourages ongoing participation and contributes to a positive relationship with the security research community. It helps participants understand the value of their contributions and encourages high-quality reports. Option C, implementing a process for quick verification and remediation of reported vulnerabilities, ensures that issues are addressed in a timely manner, reducing the window of opportunity for potential exploitation. This process should include prompt validation of reported vulnerabilities and the development and deployment of fixes or mitigations. Option B, focusing solely on high-severity vulnerabilities, is not advisable as less critical vulnerabilities can also pose risks, especially when combined with other vulnerabilities. Option D, publicly disclosing all reported vulnerabilities immediately, can be risky as it may expose the application to potential attacks before the vulnerabilities are remediated. Public disclosure should be managed carefully, typically after vulnerabilities are fixed and in coordination with the reporting researchers. 20. A large retail organization has implemented an automated incident response system. During a recent cyber attack, the system quickly identified and isolated the attack, minimizing damage. However, the post-incident analysis revealed a delay in alerting the cybersecurity team. What is the MOST likely cause of this delay in the reaction time of the team? A. The intrusion detection system (IDS) failed to detect the attack. B. The automated response did not include immediate notification protocols. C. The cybersecurity team was not adequately trained to handle automated alerts. D. The network bandwidth was insufficient for timely alert transmission. The most likely cause of the delay in alerting the cybersecurity team, despite the automated system quickly identifying and isolating the attack, is that the automated response did not include protocols for immediate notification of the team. This oversight means that while the system effectively handled the initial response, it did not promptly inform the human team for further analysis and action. While the IDS's failure to detect the attack (option A) and insufficient network bandwidth (option D) could contribute to delays, these do not apply here as the attack was identified and isolated quickly. The team's training (option C) is important but less likely to be the direct cause of the delay in this scenario. 21. A cloud service provider is at risk of losing its license due to failing to meet data protection standards required by law. To address this issue and prevent license loss, which actions should the provider take? (SELECT TWO) A. Immediately notify clients about the potential license loss. B. Implement enhanced data encryption and access control measures. C. Undergo an independent audit to identify and rectify compliance gaps. D. Reduce the scope of services offered to limit exposure to data protection laws. Implementing enhanced data encryption and access control measures (Option B) is crucial for strengthening data protection and aligning with required standards. This action directly addresses the deficiencies in data security and demonstrates a commitment to safeguarding client data. Undergoing an independent audit (Option C) helps the provider identify specific areas of noncompliance and develop a targeted plan for rectification. This approach ensures a thorough assessment and provides a roadmap for achieving compliance. Notifying clients about potential license loss (Option A) may be necessary for transparency but does not address the underlying compliance issues. Reducing the scope of services (Option D) may decrease the burden of compliance but is not a sustainable solution and may adversely affect the business. Options B and C represent proactive and concrete steps towards rectifying compliance deficiencies and preventing license loss, focusing on improving data protection measures and obtaining an objective evaluation of current practices. 22. A financial services firm has implemented automation in its security operations, including incident response, vulnerability scanning, and compliance monitoring. To ensure the ongoing supportability of these automated systems, which of the following actions should the firm prioritize? (SELECT TWO) A. Periodically replacing all automated systems with the latest technology. B. Regularly updating and maintaining the automated systems. C. Completely automating all decision-making processes in security operations. D. Training staff to manage and troubleshoot the automated systems. To ensure the ongoing supportability of automated security systems, the financial services firm should prioritize regularly updating and maintaining the automated systems (option B) and training staff to manage and troubleshoot these systems (option D). Regular updates and maintenance are essential to keep the systems effective, secure, and aligned with evolving threats and technologies. Training staff ensures that there are skilled personnel available to manage the systems, address any issues that arise, and maximize the benefits of automation. Option A, periodically replacing all systems, is not practical or costeffective. Option C, completely automating all decision-making processes, overlooks the importance of human oversight and intervention in security operations. 23. A financial institution updates its online banking application to patch a security vulnerability. The application requires a restart, which is performed without prior testing, leading to functionality issues and preventing customers from accessing their accounts. What does this scenario illustrate about the importance of planning and testing application restarts in change management processes, especially for security updates? A. The need for continuous monitoring of application performance post-restart. B. The significance of thorough testing before performing application restarts. C. The value of having a customer support team ready to address user issues. D. The importance of communicating with customers about potential service disruptions. This scenario highlights the critical importance of thorough testing before performing application restarts in change management processes, particularly when the restart is associated with a security update. In this case, the lack of prior testing for the online banking application update resulted in functionality issues that impeded customer access, demonstrating the potential consequences of not adequately preparing for application restarts. Proper testing ensures that the application functions as intended post-restart and that any issues are identified and resolved beforehand. This step is essential to prevent service disruptions and maintain the security and reliability of the application, especially for systems that handle sensitive financial transactions. 24. A healthcare provider is reviewing its IT security posture in light of recent cyber threats. The provider uses a variety of systems and applications for patient data management, billing, and communication. To enhance the overall security and resilience of its IT infrastructure, what key strategies should the healthcare provider implement? (SELECT TWO) A. Standardizing all systems on a single, secure operating system B. Implementing platform diversity across critical systems C. Regularly updating and patching all software and systems D. Using a uniform set of security tools and protocols for all systems To enhance the security and resilience of its IT infrastructure, the healthcare provider should implement platform diversity across critical systems (B) and regularly update and patch all software and systems (C). Platform diversity helps in mitigating risks associated with specific vulnerabilities or targeted attacks, as it reduces the likelihood of a single exploit affecting all systems. Regular updates and patches (C) are crucial for addressing known vulnerabilities and maintaining the security of systems and applications. Standardizing on a single operating system (A) and using a uniform set of security tools and protocols for all systems (D) may simplify management but do not provide the same level of resilience against targeted attacks and vulnerabilities that platform diversity does. Therefore, the correct choices for enhancing IT security in this scenario are B) Implementing platform diversity across critical systems and C) Regularly updating and patching all software and systems. 25. A company contracts a third-party security firm to conduct a penetration test on its network. The Rules of Engagement (RoE) document specifies that testing should only be performed outside of business hours to minimize impact on operations. However, during the test, the security firm inadvertently causes a system outage during business hours, affecting critical operations. What is the most appropriate immediate action for the company to take in this situation? A. Terminate the contract with the security firm for violating the RoE. B. Request an emergency meeting with the firm to review the RoE and incident. C. Overlook the violation, assuming it was a one-time error. D. Conduct an internal investigation to assess the damage caused by the outage. In the scenario where the security firm causes a system outage during business hours, contrary to the RoE, the company's most appropriate immediate action is to request an emergency meeting with the firm (Option B). This meeting provides an opportunity to review the RoE, discuss the circumstances leading to the outage, and understand the reasons behind the violation. It also allows for collaborative discussion on measures to prevent such incidents in the future and to reassess the testing strategy to align with the RoE. Terminating the contract (Option A) may be considered if the firm repeatedly violates the RoE, but it should not be the first course of action. Overlooking the violation (Option C) is not advisable, as it could lead to further operational disruptions. Conducting an internal investigation (Option D) is important to assess the damage but should be conducted alongside the review with the firm. 26. Following a vulnerability assessment at GlobalTech Corp., the security team prepares a report for various departments, including IT, finance, and human resources. Which TWO of the following elements should the report prioritize to effectively communicate the findings to these diverse departments? (SELECT TWO) A. Technical specifications of each identified vulnerability. B. An overview of the vulnerabilities and their potential business impact. C. The projected budget required for implementing recommended security measures. D. Detailed step-by-step remediation instructions for each vulnerability. When preparing a vulnerability assessment report for diverse departments within an organization, it's important to include information that is relevant and accessible to all stakeholders. Option B, providing an overview of the identified vulnerabilities and their potential business impact, is essential for conveying the significance of the findings in a way that is understandable to both technical and non-technical departments. This helps stakeholders grasp the importance of the vulnerabilities and how they may affect the organization. Option C, including the projected budget required for implementing recommended security measures, is important for financial planning and decision-making, particularly for the finance department. It helps in allocating resources and prioritizing remediation efforts. Option A, focusing on technical specifications, may be too detailed for non-technical departments. Option D, detailed remediation instructions, is more suited for the IT department and may not be necessary for other departments' understanding of the report. 27. DataGuard Inc. has a network infrastructure that includes a mix of sensitive customer data systems and general office systems. A recent security audit recommends implementing network segmentation to enhance security. What is the most effective way for DataGuard Inc. to apply network segmentation in this context? A. Segment the network by physical location, separating different office floors. B. Create separate network segments for sensitive customer data systems and general office systems. C. Connect all systems to a single network segment for ease of management. D. Use a single firewall for the entire network to simplify security protocols. Network segmentation is a key strategy in vulnerability management, as it helps in isolating different types of systems and data, reducing the risk of widespread network breaches. For DataGuard Inc., the most effective way to implement network segmentation is to create separate network segments for sensitive customer data systems and general office systems. This approach ensures that critical systems handling sensitive data are isolated from less critical systems, minimizing the risk of sensitive data being compromised in the event of a security breach in the general office systems. Segmentation by physical location (Option A) may not effectively isolate systems based on their data sensitivity. Option C, connecting all systems to a single network segment, increases the risk of lateral movement by attackers within the network. Option D, using a single firewall for the entire network, does not provide the granularity needed for effective segmentation and risk management. 28. In a multinational corporation, the cybersecurity committee plays a vital role in overseeing the company's global security strategy. To effectively fulfill its responsibilities, which TWO of the following actions should be prioritized by the cybersecurity committee? (SELECT TWO) A. Delegating all cybersecurity responsibilities to the IT department. B. Collaborating with various business units to understand their specific security needs. C. Regularly evaluating the effectiveness of the company's cybersecurity measures. D. Ignoring low-risk security threats to focus on high-impact risks only. Collaborating with various business units (Option B) is crucial for the cybersecurity committee to understand the specific security needs and challenges within different parts of the organization. This collaboration ensures that the security strategy is aligned with business objectives and addresses relevant risks. Regularly evaluating the effectiveness of cybersecurity measures (Option C) allows the committee to assess whether the current security strategy is adequate and to make necessary adjustments. Delegating all responsibilities to the IT department (Option A) overlooks the committee's governance role. Ignoring low-risk threats (Option D) is not advisable, as they can still pose a cumulative risk and may escalate if not addressed. 29. A multinational bank is upgrading its online banking platform to enhance security and user experience. The platform handles sensitive financial information, including customer account details and transaction histories. The bank aims to ensure the security of this financial information against emerging cyber threats. Which of the following upgrades would be the MOST effective in protecting customer financial information on the online platform? A. Implementing multi-factor authentication for customer logins. B. Increasing the bandwidth of the bank's internet connection. C. Upgrading the user interface for better customer experience. D. Adding more customer service representatives for user support. Multi-factor authentication (MFA) significantly enhances the security of online banking platforms by requiring users to provide two or more verification factors to gain access to their accounts. This approach is highly effective in protecting sensitive financial information as it adds an additional layer of security beyond just a username and password, making unauthorized access much more difficult. MFA is particularly important in the context of financial information, where the consequences of unauthorized access can be severe. Options B, C, and D, while potentially beneficial in other respects, do not directly enhance the security of financial information in the same way as MFA. 30. An IT security analyst at a company notices multiple failed login attempts across various user accounts, all using common passwords. The analyst suspects a password spraying attack, where an attacker attempts to access multiple accounts using widely used passwords. What is the MOST effective measure to prevent such attacks? A. Implement account lockout policies after a certain number of failed login attempts. B. Enforce the use of multi-factor authentication (MFA) for all user accounts. C. Regularly conduct security awareness training on creating strong passwords. D. Monitor and analyze login attempts to detect patterns indicative of password spraying. The most effective measure to prevent password spraying attacks is to enforce the use of multi-factor authentication (MFA) for all user accounts (Option B). MFA adds an additional layer of security beyond the password, making it significantly more difficult for attackers to gain unauthorized access even if they use common passwords. While account lockout policies (Option A) and monitoring login attempts (Option D) can help detect and mitigate password spraying attacks, they do not provide the same level of security as MFA. Regular security awareness training (Option C) is important, but it does not address the risk posed by attackers using common passwords across multiple accounts. 31. A global corporation with offices in multiple countries has implemented a new identity and access management (IAM) system. The system integrates various authentication methods used across different regions. However, employees in some regions are facing difficulties accessing certain company resources, while others have seamless access. What is the MOST likely cause of these access issues? A. The IAM system does not support multi-factor authentication. B. There are inconsistencies in the IAM system's interoperability with regional authentication methods. C. Employees are using weak passwords, making their accounts vulnerable to attacks. D. The network infrastructure in some regions is not robust enough to support the IAM system. The most likely cause of the access issues faced by employees in some regions is inconsistencies in the IAM system's interoperability with various regional authentication methods (Option B). In a global corporation, different regions may use different authentication technologies and protocols. If the IAM system is not fully interoperable with all these methods, it can lead to difficulties in accessing resources. Options A, C, and D could contribute to general access or security issues but do not directly address the problem of interoperability between the IAM system and the diverse authentication methods used across different regions. 32. During a routine review of an MOU (Memorandum of Understanding) with a third-party vendor for IT support services, an organization realizes that the MOU does not explicitly cover the vendor's access to sensitive company data. This oversight raises concerns about data security. What is the most appropriate action for the organization to take in this situation? A. Continue the partnership without changes, relying on mutual trust. B. Amend the MOU to include specific terms on data access and security. C. Monitor the vendor's activities closely without changing the MOU. D. Cancel the MOU and seek a vendor with a more detailed contract. The realization that the MOU with a third-party vendor for IT support services does not explicitly cover the vendor's access to sensitive company data necessitates a revision of the MOU. The most appropriate action is to amend the MOU to include specific terms on data access and security (Option B). This amendment should clearly define the extent of the vendor's access to sensitive data, the security measures required to protect this data, and any restrictions or protocols that must be followed. Continuing the partnership without changes (Option A) is not advisable as it leaves the organization vulnerable to data security risks. Monitoring the vendor's activities (Option C) is a good practice but does not provide the necessary contractual safeguards. Canceling the MOU (Option D) may be a more drastic measure that might not be necessary if the vendor is willing to agree to the amended terms. 33. TechGuard Solutions discovers a vulnerability in their customer database system that allows unauthorized read access to customer data. Another vulnerability is found in the company's internal communication tool, which could lead to denial of service. Based on vulnerability classification, what should be TechGuard Solutions' approach to addressing these vulnerabilities? A. Prioritize fixing the denial of service vulnerability in the internal communication tool. B. Address the unauthorized read access vulnerability in the customer database system first. C. Focus on upgrading hardware to prevent future vulnerabilities. D. Treat both vulnerabilities as equal and fix them concurrently. Vulnerability classification helps in determining the priority of remediation based on the nature and impact of each vulnerability. In this scenario, the vulnerability that allows unauthorized read access to customer data in the database system is more critical as it directly impacts data confidentiality and customer privacy. This type of vulnerability can lead to significant data breaches and should be addressed as a higher priority. The denial of service vulnerability in the internal communication tool, while disruptive, does not pose the same level of risk to sensitive data and can be prioritized accordingly. Option A, prioritizing the denial of service vulnerability, does not align with the higher risk to sensitive data. Option C, focusing on hardware upgrades, does not directly address the specific vulnerabilities. Option D, treating both vulnerabilities as equal, does not reflect an effective prioritization strategy based on the impact and severity of the vulnerabilities. 34. Match each type of security incident with the most appropriate initial response action. 1. Ransomware infection D. Isolate affected systems F. Negotiate appropriate ransom 2. Data breach D. Isolate affected systems E. Initiate legal proceedings 3. DDoS attack A. Increase network bandwidth C. Compensate affected stakeholders 4. Insider threat detection B. Monitor and investigate employee activity For ransomware, isolation of affected systems is crucial to prevent spread. In a data breach, legal proceedings might be necessary for compliance and investigation. During a DDoS attack, increasing bandwidth can help mitigate the impact. An insider threat requires careful monitoring and investigation. 35. During an investigation of a data breach at a law firm, it was discovered that confidential client information was leaked by an insider. The firm needs to identify the specific individual responsible for this breach. They have a system in place where all users' activities are digitally signed. Which of the following mechanisms would be most effective in providing non-repudiation in this case? A. Implementing an intrusion detection system (IDS) B. Conducting a forensic analysis of network logs C. Utilizing digital certificates associated with user activities D. Enforcing mandatory access controls on sensitive data Non-repudiation ensures that an individual or entity cannot deny the authenticity of their actions or involvement in an activity. Utilizing digital certificates associated with user activities provides non-repudiation by ensuring that actions taken by users can be securely linked to them, and they cannot deny their involvement. Digital certificates offer a reliable way to authenticate the identity of users and the authenticity of their actions, making them effective in providing non-repudiation in this case. Other options, while valuable in a security investigation, do not directly provide non-repudiation as digital certificates do. 36. In managing the security implications of patch availability, which two of the following practices should be prioritized in an organizational setting? (SELECT TWO) A. Disabling automatic updates to maintain control over the patching process. B. Implementing a comprehensive patch management policy and procedure. C. Relying solely on antivirus software to compensate for unpatched vulnerabilities. D. Regularly assessing and prioritizing patches based on their criticality and impact. Implementing a comprehensive patch management policy and procedure (Option B) is essential for effectively managing patch availability. This policy should outline how patches are monitored, tested, and applied, ensuring that they are integrated into the organization's systems in a timely and efficient manner. Regularly assessing and prioritizing patches based on their criticality and impact (Option D) is also crucial. This practice ensures that the most critical patches, especially those addressing severe vulnerabilities, are applied promptly, while less critical updates are scheduled appropriately. Disabling automatic updates (Option A) can lead to delays in applying important patches and increase vulnerability to threats. Relying solely on antivirus software (Option C) is insufficient, as it cannot address all types of vulnerabilities that patches are designed to fix. 37. A national news agency's online platform was targeted, resulting in the publication of several fabricated news stories with political content. The attackers also leaked internal emails revealing biases in news reporting. Considering the nature of the attack, which TWO of the following motivations are most likely driving the attackers behind this incident? (SELECT TWO) A. Influencing public opinion for political purposes B. Stealing sensitive information for financial gain C. Damaging the reputation of the news agency D. Demonstrating technical prowess to other hackers The fabrication of news stories with political content and the leaking of emails to expose biases are actions consistent with a desire to influence public opinion (Option A) and damage the reputation of the news agency (Option C). These motivations align with hacktivist objectives, which often include making a political statement or revealing perceived injustices. The lack of a financial motive makes Option B (stealing sensitive information for financial gain) less likely. While demonstrating technical prowess (Option D) might be a secondary motive, it does not align as closely with the primary goals of influencing public opinion and damaging reputation, which are more characteristic of hacktivist activities. 38. A healthcare organization experienced a phishing attack that resulted in unauthorized access to patient records. In the "lessons learned" review, what should be the PRIMARY focus to enhance the organization's resilience against similar attacks? A. Purchasing cyber insurance to mitigate financial losses from future attacks. B. Upgrading the email server to the latest version for better security features. C. Implementing regular security awareness training for all staff members. D. Encrypting all patient records to secure them against unauthorized access. In this scenario, the phishing attack was the initial entry point for the breach. The primary focus in the "lessons learned" review should be on preventing similar attacks. Implementing regular security awareness training for all staff members (Option C) is a crucial step in achieving this. Training helps employees recognize and respond appropriately to phishing attempts, reducing the likelihood of successful attacks. While options A, B, and D are important security measures, they do not directly address the human factor, which was the key vulnerability exploited in the phishing attack. 39. During a network security audit, a company finds that an unused Ethernet jack in a conference room is active and connected to the main network. A subsequent security test shows that an unauthorized device could easily be connected to this jack, granting access to the network. This finding highlights the need for what specific security measure in a wired network environment? A. Implementing stronger wireless security protocols B. Disabling unused network ports C. Encrypting network data transmissions D. Increasing the complexity of network passwords The need to disable unused network ports (B) is the specific security measure highlighted by this finding. Active but unused Ethernet jacks, especially in areas accessible to non-employees or visitors, pose a security risk as they can be exploited by unauthorized individuals to gain physical access to the network. Disabling ports that are not in use effectively reduces this risk by ensuring that only authorized devices can connect to the network. This measure is particularly relevant in a wired network environment, where physical access to network infrastructure can lead to security breaches. Implementing stronger wireless security protocols (A) is not related to the vulnerability of physical network ports. Encrypting network data transmissions (C) and increasing the complexity of network passwords (D) are important security practices but do not address the specific issue of securing physical access points to the network. 40. During a code review, a security analyst identifies that a new feature in the company's web application lacks input validation, potentially exposing the application to injection attacks. What is the most appropriate next step for the development team in addressing this security concern? A. Deploy the feature as planned and monitor for any security incidents B. Remove the feature entirely from the application to avoid risks C. Implement proper input validation and retest the feature before deployment D. Limit access to the feature to a small group of trusted users The most appropriate next step for the development team in addressing the lack of input validation in a new feature is to implement proper input validation and retest the feature before deployment, as suggested in Option C. Input validation is a critical security measure that prevents injection attacks by ensuring that only properly formatted data is accepted. Retesting the feature after implementing input validation ensures that the security issue is resolved and that the feature functions as intended. Deploying the feature without addressing the security concern (Option A) could expose the application to significant risks. Removing the feature entirely (Option B) may be unnecessary if the security issue can be effectively mitigated. Limiting access to the feature (Option D) does not address the underlying security vulnerability and still poses a risk. 41. An organization has recently automated its user provisioning process. The new system is responsible for managing user accounts, access rights, and group memberships based on employee roles and responsibilities. Which of the following outcomes are expected benefits of this automation? (SELECT TWO) A. Reduction in the time required for onboarding new employees. B. Increased need for IT staff intervention in routine account management tasks. C. Enhanced accuracy in assigning appropriate access rights to users. D. Higher frequency of password reset requests from users. The automation of user provisioning processes is expected to lead to a reduction in the time required for onboarding new employees (option A) and enhanced accuracy in assigning appropriate access rights to users (option C). Automated provisioning allows for rapid and efficient account setup as soon as new employees are added to the system, streamlining the onboarding process. Additionally, it ensures that users are assigned access rights that align with their roles and responsibilities, reducing the likelihood of errors that can occur with manual processes. Option B is incorrect as automation reduces, rather than increases, the need for IT staff intervention in routine tasks. Option D is unrelated to user provisioning and more associated with password management policies. 42. To enhance an organization's security posture against various DNS attacks, which TWO of the following measures should be prioritized? (SELECT TWO) A. Implement DNS Security Extensions (DNSSEC) to authenticate DNS data. B. Regularly monitor and analyze DNS traffic for unusual patterns or volumes. C. Enforce a strict web content filtering policy to block malicious websites. D. Increase the bandwidth of the network to handle potential DNS flood attacks. To effectively defend against DNS attacks, it's important to focus on measures that directly address DNS security and monitoring. Implementing DNS Security Extensions (DNSSEC) (Option A) is crucial as it provides a layer of authentication for DNS data, helping to prevent attacks like DNS Spoofing and DNS Hijacking by ensuring the integrity and authenticity of DNS responses. Regularly monitoring and analyzing DNS traffic (Option B) allows for the early detection of unusual patterns or volumes, indicative of potential DNS-based attacks like DNS Tunneling or DNS Flood Attacks. While enforcing a strict web content filtering policy (Option C) is important for overall network security, it is less directly targeted at defending against DNS-specific attacks. Increasing network bandwidth (Option D) does not effectively mitigate DNS attacks and may not address the root cause of DNS threats. 43. A streaming service offers a variety of TV shows and movies, but due to licensing agreements, some content is only available in certain countries. To comply with these agreements, the streaming service must prevent users in restricted countries from accessing specific content. What is the BEST method for the service to ensure compliance with geographic content restrictions? A. Encrypting all content available on the streaming service. B. Utilizing content delivery networks (CDNs) to distribute content globally. C. Implementing geolocation-based content filtering for users. D. Conducting regular audits of user accounts to detect location violations. Implementing geolocation-based content filtering is the best method for a streaming service to comply with geographic content restrictions set by licensing agreements. This technology allows the service to determine the user's location and restrict access to content that is not licensed for viewing in that region. Geolocation-based content filtering directly addresses the need to adhere to licensing terms by ensuring that only users in authorized countries can access specific TV shows and movies. While encrypting content (A), using CDNs (B), and conducting account audits (D) are important for security and efficient content delivery, they do not address the specific requirement of enforcing geographic content restrictions as effectively as geolocation-based filtering. 44. During a routine audit, an IT auditor discovers that a recent software update on a critical system has not been properly documented in the company's change management logs. Given this finding, what is the most appropriate action for risk identification in this situation? A. Schedule an immediate system downtime to roll back the update. B. Investigate the update's security implications and potential vulnerabilities. C. Update the change management logs and continue regular monitoring. D. Conduct a full security audit of all systems to check for similar issues. The key to this scenario is identifying the risk associated with an undocumented software update. Scheduling an immediate system downtime (Option A) is a drastic measure that may disrupt business operations unnecessarily. Updating the change management logs (Option C) addresses the documentation issue but does not assess the risk of the update itself. Conducting a full security audit of all systems (Option D) is resource-intensive and may not directly address the risk at hand. The most appropriate action is to investigate the security implications and potential vulnerabilities of the update (Option B). This involves examining the update's content, understanding its changes to the system, and assessing any new security risks it may introduce. By doing so, the auditor can identify specific risks and recommend appropriate mitigation strategies. 45. An international non-profit organization provides its employees with company-owned laptops under a COPE policy. These laptops are used for both professional tasks and personal use. To enhance security, the organization plans to implement additional protective measures. What should be the PRIMARY focus of these measures to ensure both data security and user privacy on the COPE laptops? A. Installing robust antivirus software and regularly updating it to protect against malware and viruses. B. Implementing full-disk encryption to secure all data stored on the laptops, both work-related and personal. C. Restricting administrative privileges on the laptops to prevent unauthorized changes to system settings. D. Enabling remote wipe capabilities to erase data on the laptops in case they are lost or stolen. Implementing full-disk encryption (B) is the most effective measure to ensure both data security and user privacy on COPE laptops. This approach encrypts all data stored on the laptops, protecting sensitive work-related information as well as personal data, in case of loss or theft. Antivirus software (A) is important but does not address the protection of data at rest. Restricting administrative privileges (C) is a good practice but mainly prevents unauthorized system changes rather than securing data. Enabling remote wipe capabilities (D) is useful for lost or stolen devices but may raise privacy concerns for personal data and is not the primary focus for data security. 46. A healthcare organization is assessing the risk associated with using a thirdparty billing service. The organization reviews the service's internal audit reports and finds inconsistencies in the application of encryption standards and occasional lapses in employee background checks. Which two of the following actions should the organization take to address these concerns? (SELECT TWO) A. Implement a policy of encrypting all data before sending it to the service. B. Require the service to adhere to consistent encryption standards. C. Discontinue the use of the billing service immediately. D. Request a comprehensive security review of the service's practices. The internal audit reports indicating inconsistencies in encryption standards and lapses in employee background checks present significant security concerns for the healthcare organization. Requiring the billing service to adhere to consistent encryption standards (Option B) is crucial to ensure that all sensitive data, particularly patient information, is protected in transit and at rest. This action directly addresses the concern of inconsistent application of encryption. Additionally, the organization should request a comprehensive security review of the service's practices (Option D). This review will provide an in-depth evaluation of the service's overall security posture, including areas like employee screening, data handling, and access control. Implementing a policy of encrypting all data before sending it to the service (Option A) is a good practice, but it does not address the service provider's internal security practices. Discontinuing the use of the billing service immediately (Option C) may be premature; the focus should first be on working with the service to address and rectify the identified issues. 47. A network security analyst at a large corporation notices that several critical servers are showing irregular system behavior, including altered log files and unusual network traffic. Despite running multiple antivirus scans, no malware is detected. The analyst suspects a rootkit infection. What is the MOST effective way to confirm the presence of a rootkit on these servers? A. Perform a network traffic analysis to look for signs of data exfiltration. B. Use a specialized rootkit detection tool that operates outside the compromised OS. C. Check the integrity of system files and configurations against known good baselines. D. Reinstall the operating system and applications on the suspected servers. Rootkits are designed to evade detection by conventional antivirus software by operating at a low level in the operating system. The most effective way to confirm their presence is to use specialized rootkit detection tools (Option B) that operate outside the compromised operating system, such as bootable antivirus tools or tools that scan from a different OS environment. This approach bypasses the rootkit's ability to hide itself from the operating system. While network traffic analysis (Option A) and checking system file integrity (Option C) are useful techniques, they may not be definitive in confirming a rootkit infection. Reinstalling the operating system (Option D) is a remediation step and does not confirm the presence of a rootkit. 48. A large retail chain is developing a comprehensive business continuity plan to address potential disruptions ranging from cyber attacks to natural disasters. In this scenario, which TWO of the following elements should be prioritized in the business continuity plan? (SELECT TWO) A. Detailed protocols for data recovery and restoration. B. Plans for a complete shutdown of all operations in an emergency. C. Procedures for communication with stakeholders during a crisis. D. Reducing insurance premiums by minimizing coverage. Detailed protocols for data recovery and restoration (Option A) are essential in a business continuity plan to ensure that critical data can be quickly recovered and restored, minimizing downtime and operational impacts. Procedures for communication with stakeholders (Option C) are equally important to maintain transparency, trust, and coordination during a crisis. Option B, planning for a complete shutdown, is counterproductive to the concept of business continuity, which aims to maintain or quickly resume operations. Reducing insurance premiums by minimizing coverage (Option D) could leave the business financially vulnerable in the event of a disaster and does not directly contribute to operational continuity. 49. An organization's office building has multiple floors with various departments, including an IT department that handles sensitive information. Recently, a non-IT employee was found accessing the IT department's restricted area without proper authorization. What is the MOST effective measure to improve physical security and restrict unauthorized access to the IT department? A. Implementing a sign-in sheet for all visitors and employees at the reception. B. Installing keycard access controls on doors leading to the IT department. C. Conducting regular physical security awareness training for all employees. D. Placing additional security guards at the entrance of the IT department. The most effective measure to improve physical security in this scenario is installing keycard access controls on doors leading to the IT department (Option B). Keycard access controls ensure that only authorized personnel can enter the restricted area, directly addressing the issue of unauthorized access. While a sign-in sheet (Option A) provides a record of entry, it does not actively restrict access. Security awareness training (Option C) is important but does not replace the need for physical access controls. Additional security guards (Option D) provide a level of monitoring but may not be as effective as automated access controls in restricting entry. 50. A comprehensive security assessment of a software development company reveals two major issues: weak password policies and the absence of a formal security training program for developers. Which TWO of the following actions should the company prioritize to address these security vulnerabilities? (SELECT TWO) A. Implementing multi-factor authentication for all accounts. B. Developing a formal security training program for developers. C. Enforcing strong password policies with complexity and rotation requirements. D. Increasing the number of security personnel in the IT department. The security assessment identified two specific vulnerabilities: weak password policies and the lack of a formal security training program for developers. To directly address these issues, the company should prioritize developing a formal security training program for developers (Option B). This will ensure that developers are aware of best practices in security and can contribute to a more secure development environment. Additionally, enforcing strong password policies with complexity and rotation requirements (Option C) directly addresses the issue of weak password policies, enhancing the overall security posture of the company. Implementing multi-factor authentication (Option A) is a valuable security measure but does not directly address the specific vulnerabilities identified. Increasing the number of security personnel (Option D) may improve the company's security capabilities but is not specifically related to the issues of password policies and developer training. 51. A large retail company experienced a major cyber attack, resulting in significant data loss and system downtime. The company is now reassessing its recovery strategies. What is a critical factor in improving the company's recovery capabilities to reduce future downtime and data loss? A. Implementing more robust firewalls and intrusion detection systems B. Establishing a clear and well-documented incident response plan C. Increasing the budget for IT security staff and training D. Upgrading all software to the latest versions for enhanced security A critical factor in improving a company's recovery capabilities, especially after experiencing a major cyber attack, is establishing a clear and well-documented incident response plan (B). A comprehensive incident response plan outlines the procedures to be followed during and after a security incident, including steps for containment, eradication, and recovery. This plan is crucial for minimizing downtime and ensuring a structured approach to restoring systems and data. While implementing robust firewalls and intrusion detection systems (A), increasing the budget for IT security staff and training (C), and upgrading software (D) are important security measures, they primarily focus on prevention rather than recovery. The key to reducing future downtime and data loss lies in having a robust incident response plan that can be quickly and effectively executed, making option B the most appropriate answer. 52. An e-commerce company is looking to prevent credit card fraud on its platform. The security team is considering various preventive controls to detect and block fraudulent transactions. Which of the following would most effectively achieve this goal? A. Deploying an intrusion detection system B. Implementing transaction monitoring and alerting systems C. Establishing a security awareness training program D. Conducting regular security audits To prevent credit card fraud on an e-commerce platform, Implementing transaction monitoring and alerting systems (B) is the most effective preventive control. These systems analyze transaction patterns in real-time, flagging unusual or suspicious activities that could indicate fraud. By monitoring transactions for indicators of fraud, such as unusually large purchases or rapid succession of transactions, these systems can alert the security team to potential fraud, allowing for immediate action to block fraudulent transactions and protect customers' financial information. Deploying an intrusion detection system (A) is important for network security but less specific to preventing credit card fraud. Establishing a security awareness training program (C) is crucial for educating employees but does not directly address transactional fraud. Conducting regular security audits (D) helps identify vulnerabilities but is not a direct method for preventing credit card fraud in real-time. 53. A large financial institution is enhancing its cybersecurity measures and considering the use of honeyfiles as part of its data protection strategy. The institution wants to use honeyfiles to detect potential insider threats and external breaches. Which TWO of the following practices should be prioritized when implementing honeyfiles in the financial institution's network? (SELECT TWO) A. Creating honeyfiles that closely resemble sensitive financial documents B. Distributing honeyfiles randomly across all employee workstations C. Monitoring access to honeyfiles and analyzing unauthorized interactions D. Publicizing the use of honeyfiles to deter potential attackers When implementing honeyfiles in a financial institution's network, creating honeyfiles that closely resemble sensitive financial documents (Option A) is crucial. This practice ensures that the honeyfiles are attractive and convincing to potential unauthorized users, whether they are insider threats or external attackers. The honeyfiles should mimic the appearance and content of genuine sensitive documents to effectively serve their purpose as decoys. Additionally, monitoring access to honeyfiles and analyzing unauthorized interactions (Option C) is essential. This involves tracking who accesses the honeyfiles, from where, and what actions are taken upon access. This monitoring enables the institution to detect and respond to potential security breaches or insider threats effectively. Distributing honeyfiles randomly across all employee workstations (Option B) is not necessary and may lead to accidental access by legitimate users. Publicizing the use of honeyfiles (Option D) could diminish their effectiveness, as potential attackers may become more cautious and avoid the decoys. 54. Given the syslog shown here, what security incident is indicated by the entry from IDS1 at Dec 7 2023 11:02:10? A. A potential SQL injection attempt on port 3306. B. A suspicious inbound connection to a mySQL port. C. A successful scan for vulnerabilities on port 3306. D. An unauthorized access to a mySQL database. The syslog entry from IDS1 indicates a suspicious inbound connection to a mySQL port (3306). The signature ID [1:2013498:4] further suggests an anomaly related to a mySQL service, requiring investigation and potential mitigation. 55. To mitigate risks associated with software provider vulnerabilities, an organization is implementing a series of security measures. Which of the following actions should be included in their security strategy? (SELECT TWO) A. Regularly updating software and applying patches B. Training staff on social engineering tactics C. Conducting source code reviews of third-party software D. Implementing network intrusion detection systems (IDS) Regularly updating software and applying patches (Option A) is crucial for mitigating risks associated with software provider vulnerabilities. Keeping software up-to-date ensures that any known vulnerabilities are addressed and reduces the risk of exploitation by attackers. Conducting source code reviews of third-party software (Option C) allows organizations to identify potential security weaknesses in the software they use, especially when the software provider may not have conducted thorough security testing. Training staff on social engineering tactics (Option B) is important for overall security awareness but does not directly address vulnerabilities in third-party software. Implementing network intrusion detection systems (IDS) (Option D) enhances network security but is not specifically targeted at mitigating risks associated with software provider vulnerabilities. 56. Match the appropriate tools to use in response to the listed security incidents. 1. Unauthorized network access D. Firewall 2. Malware infection on a workstation A. Antivirus software B. Remote wipe capabilities 3. Suspicious email activity C. Email filtering system 4. Lost company mobile device B. Remote wipe capabilities E. Hardware Security Module A firewall is essential for preventing unauthorized network access. Antivirus software is crucial for dealing with malware infections. Email filtering systems help manage and investigate suspicious email activities. Remote wipe capabilities are vital for lost or stolen mobile devices to protect company data. 57. A small business is implementing a network infrastructure to support both wired and wireless connectivity for its employees. Considering security best practices, what should be the primary focus when configuring the wireless network to ensure secure connectivity? A. Maximizing wireless signal strength to cover the entire office area. B. Using the latest Wi-Fi technology for faster data transfer rates. C. Implementing strong encryption and authentication mechanisms. D. Providing unrestricted access to facilitate ease of use for employees. When configuring a wireless network, especially in a business environment, the primary focus should be on ensuring secure connectivity. Implementing strong encryption (such as WPA3) and robust authentication mechanisms (Option C) is crucial to protect the wireless network from unauthorized access and data breaches. While maximizing signal strength (Option A) and using the latest technology (Option B) are important for network performance, they do not directly address security concerns. Unrestricted access (Option D) might facilitate ease of use but significantly compromises network security by exposing the network to potential threats. 58. An organization implemented continuous integration and testing in its software development lifecycle. After a recent deployment, users reported performance issues that were not identified during testing. What should the development team review FIRST to address this discrepancy? A. The hardware specifications of the user devices. B. The network infrastructure of the organization. C. The performance testing scenarios included in the continuous testing process. D. The version control system used for code commits. When users report performance issues not identified during testing in a continuous integration and testing environment, the first aspect the development team should review is the performance testing scenarios included in the continuous testing process. This review will help determine if the test scenarios were comprehensive and realistic enough to simulate actual user environments and usage patterns. Adjusting these scenarios to better reflect real-world conditions can help identify performance issues before deployment. Options A, B, and D are less relevant as the primary focus should be on the effectiveness and comprehensiveness of the testing scenarios used in the continuous integration and testing process. 59. A financial services firm is upgrading its IT infrastructure to ensure high availability of its critical applications, especially during peak transaction periods. The firm is implementing a failover strategy to achieve this goal. What type of failover configuration would be most appropriate to ensure continuous operation of critical applications in the event of a system failure? A. Active-passive failover with regularly synchronized backup systems B. Active-active failover with simultaneous operation of all systems C. Manual failover requiring intervention by the IT team for activation D. Passive-active failover with delayed synchronization of backup systems ,kjn In an active-active configuration, all systems operate simultaneously and can handle the load independently. This allows for seamless transition in the event of a system failure, as the other system(s) are already operational and can immediately take over without any downtime. Active-passive failover (A) involves standby systems that activate upon failure but may not provide the immediate transition needed for critical applications. Manual failover (C) requires intervention and can lead to delays in restoring operations. Passive-active failover with delayed synchronization (D) may not provide the required immediacy for high-availability environments. Therefore, option B, Active-active failover with simultaneous operation of all systems, is the most suitable configuration for ensuring continuous operation of critical applications. 60. An IT manager at a healthcare organization is overseeing the sanitization of mobile devices that were used by staff to access patient records. The devices are to be repurposed within the organization. What sanitization method should be used to ensure patient data is securely erased while allowing the devices to be reused? A. Physically destroying the devices. B. Performing a factory reset on the devices. C. Manually deleting patient records from the devices. D. Encrypting the data stored on the devices. In the context of repurposing mobile devices that contained sensitive patient records, the sanitization method must securely erase the data while preserving the devices' functionality. The most appropriate method is B, performing a factory reset on the devices. A factory reset removes all user data, settings, and applications, returning the device to its original state. This ensures that patient data is erased and the device can be safely reused within the organization. Option A, physically destroying the devices, is secure but makes them unusable for repurposing. Option C, manually deleting patient records, may not remove all traces of the data and is not as secure as a factory reset. Option D, encrypting the data, does not erase it and is not a method of sanitization. 61. A company has a file server that stores sensitive project documents. The server is accessed by various departments, including R&D, marketing, and finance. Each department should only have access to its respective project documents. What is the BEST approach to manage access to these documents while ensuring data security? A. Implementing a centralized antivirus system to protect the file server. B. Setting up a virtual private network (VPN) for remote access to the file server. C. Applying permission restrictions based on departmental roles and requirements. D. Encrypting all files stored on the server using a strong encryption algorithm. Applying permission restrictions based on departmental roles and requirements is the most effective approach to manage access to sensitive project documents on a file server. This method involves configuring access controls so that each department can only access the files relevant to its work, thereby preventing unauthorized access to other departments' documents. Such role-based access control (RBAC) ensures that employees only have access to the data necessary for their job functions, reducing the risk of data breaches or accidental data leakage. While implementing a centralized antivirus system (A), setting up a VPN (B), and encrypting files (D) are important security measures, they do not address the specific need to control access to data based on departmental roles as directly as permission restrictions. 62. To protect an organization's IT infrastructure from excessive resource consumption due to malicious activities, which TWO of the following strategies should be prioritized? (SELECT TWO) A. Regularly monitor and analyze system and network performance for signs of abnormal resource usage. B. Implement strong access controls to prevent unauthorized access to systems and network resources. C. Deploy intrusion detection systems (IDS) to identify and alert on potential security threats. D. Conduct regular security awareness training for employees on recognizing and reporting suspicious activities. To effectively defend against excessive resource consumption due to malicious activities, it's important to focus on strategies that enable early detection and response. Regularly monitoring and analyzing system and network performance (Option A) is crucial for identifying signs of abnormal resource usage, which can indicate a security threat such as a DDoS attack or cryptojacking. Deploying IDS (Option C) provides an additional layer of security by identifying and alerting on potential security threats, including those that lead to resource consumption. While implementing strong access controls (Option B) is important for overall security, it does not directly address the monitoring and detection of resource consumption issues. Regular security awareness training (Option D) is essential for raising employee awareness but does not provide the technical means to detect and respond to excessive resource consumption. 63. A financial services firm is implementing measures to reduce the scope of security threats to its network and data. The firm is considering various security controls to achieve this goal. Which TWO of the following controls would be most effective in reducing the threat scope for the firm's network and data? (SELECT TWO) A. Implementing a robust firewall configuration B. Deploying an intrusion detection system (IDS) C. Conducting regular social engineering awareness training D. Using data encryption for sensitive information Implementing a robust firewall configuration (Option A) is a key control in reducing the threat scope by serving as a barrier between the firm's internal network and external networks, including the internet. A well-configured firewall can effectively control incoming and outgoing traffic, blocking unauthorized access and potential threats. Using data encryption for sensitive information (Option D) is another important control that reduces the threat scope by protecting the confidentiality and integrity of data, both in transit and at rest. Encrypted data remains secure even if it is intercepted or accessed by unauthorized parties, thereby limiting the impact of potential breaches. While deploying an intrusion detection system (IDS) (Option B) is valuable for identifying potential security incidents, it does not directly reduce the threat scope in the same way as firewalls and encryption. Conducting regular social engineering awareness training (Option C) is important for employee education but is more focused on reducing human-related risks rather than the overall threat scope to network and data security. 64. A company is setting up a new web server and needs to obtain an SSL/TLS certificate from a certificate authority (CA). The first step involves generating a Certificate Signing Request (CSR). What critical information does the CSR contain that is essential for the CA to issue the certificate? A. The web server's current traffic statistics. B. The private key of the web server. C. The public key and identity information of the web server. D. The list of products and services offered by the company. When setting up a new web server and obtaining an SSL/TLS certificate, generating a Certificate Signing Request (CSR) is a crucial first step. The CSR contains essential information that the certificate authority (CA) requires to issue the certificate. This information includes the public key of the web server and its identity information, such as the domain name, organization name, and location. The CSR is used by the CA to create a digital certificate that binds the web server's public key to its identity, ensuring that clients can establish secure connections to the server with confidence in its authenticity. The inclusion of the public key and identity information in the CSR is fundamental to the process of obtaining a valid SSL/TLS certificate. 65. A network administrator reviews an automated report from the company's intrusion detection system (IDS) and notices repeated alerts for attempted connections to a critical server using an outdated protocol known for its vulnerabilities. The source of these attempts is not from the organization's standard operational IP range. What is the MOST appropriate next step for the administrator to take in response to this report? A. Disable the outdated protocol on the critical server. B. Perform a network scan to identify other devices using the same protocol. C. Change the network configuration to allow only authorized IP ranges. D. Update the IDS to stop generating alerts for the outdated protocol. The most appropriate response to repeated IDS alerts for attempted connections using an outdated and vulnerable protocol is to disable that protocol on the critical server. This action directly addresses the security risk by removing the vulnerable protocol from the server, thereby preventing potential exploitation. Performing a network scan (Option B) is a good practice but should be a secondary action after securing the critical server. Restricting network access to authorized IP ranges (Option C) can help, but the primary concern is the use of a vulnerable protocol. Updating the IDS to stop generating alerts for the outdated protocol (Option D) is counterproductive as it removes visibility into potential security threats. 66. An organization plans to enhance its security measures by implementing an attribute-based access control (ABAC) system. Which TWO of the following actions should the organization prioritize to ensure the effectiveness of the ABAC system? (SELECT TWO) A. Defining comprehensive and precise attributes for users, resources, and environmental conditions. B. Installing physical security measures, such as biometric scanners, at all entry points. C. Regularly reviewing and updating the ABAC policies to align with organizational changes. D. Training employees on basic cybersecurity awareness and best practices. Defining comprehensive and precise attributes for users, resources, and environmental conditions (Option A) is critical in an attribute-based access control (ABAC) system. Accurate and detailed attributes are essential for making correct access decisions based on the policies set within the ABAC system. Regularly reviewing and updating the ABAC policies (Option C) is important to ensure that the access control system remains effective and relevant, especially as the organization undergoes changes that might affect access requirements. While physical security measures (Option B) and employee cybersecurity training (Option D) are important aspects of a comprehensive security strategy, they do not directly relate to the implementation and effectiveness of an ABAC system. 67. A government agency implements a policy to disable unused ports and protocols on its network devices. Which TWO of the following outcomes are directly achieved by this policy? (SELECT TWO) A. Enhancing the efficiency of data transmission across the network. B. Reducing the likelihood of security vulnerabilities being exploited. C. Decreasing the energy consumption of network devices. D. Simplifying the network monitoring and management process. The implementation of a policy to disable unused ports and protocols on network devices in a government agency directly achieves the outcomes of reducing the likelihood of security vulnerabilities being exploited (Option B) and simplifying the network monitoring and management process (Option D). By disabling unused ports and protocols, the agency effectively reduces the number of potential entry points for cyber attacks, thereby lowering the risk of security vulnerabilities being exploited. This measure enhances the overall security of the network. Additionally, simplifying the network infrastructure by disabling unnecessary components makes monitoring and managing the network more straightforward and efficient. Enhancing data transmission efficiency (Option A) and decreasing energy consumption (Option C) are not the primary goals of this policy; the focus is on improving security and network management. 68. When implementing tokenization in an organization, which of the following scenarios would most benefit from this technology? (SELECT TWO) A. Storing employee payroll information in the human resources database. B. Optimizing the network infrastructure for faster data transmission. C. Securing customer payment information in a point-of-sale system. D. Streamlining the email communication system for employees. Tokenization is particularly beneficial in scenarios where protecting sensitive information is crucial. Firstly, storing employee payroll information in the human resources database is a scenario where tokenization can significantly enhance data security. By replacing sensitive data such as Social Security numbers or bank account details with tokens, the risk of exposure of sensitive employee information is greatly reduced. This approach helps maintain the confidentiality of payroll data and protects against potential breaches. Secondly, securing customer payment information in a point-of-sale system is another ideal application of tokenization. In this scenario, tokenization can replace sensitive payment data, such as credit card numbers, with tokens, thereby minimizing the risk of payment data being compromised. This is especially important in retail and e-commerce environments where securing customer payment information is essential for maintaining customer trust and complying with data protection regulations. Both scenarios demonstrate the effectiveness of tokenization in protecting sensitive information within various organizational systems. 69. An organization introduces USB security tokens ("something you have") for two-factor authentication to access its internal systems. However, some employees report that they often forget to carry their tokens, resulting in access issues. What is the MOST practical solution to mitigate this problem without compromising security? A. Replacing the USB security tokens with less secure but more convenient authentication methods. B. Implementing a mobile app-based token system as an alternative to USB tokens. C. Issuing multiple USB tokens to each employee to keep in different locations. D. Relaxing the two-factor authentication requirement for employees who forget their tokens. The most practical solution to mitigate the problem of employees forgetting their USB security tokens is to implement a mobile app-based token system as an alternative (Option B). This approach offers a secure and convenient way for employees to generate authentication tokens using their smartphones, which they are more likely to carry at all times. Options A and D compromise security by relaxing or replacing the two-factor authentication method. Issuing multiple USB tokens (Option C) could be impractical and increase the risk of tokens being lost or stolen. 70. A large tech company implements a password policy requiring users to change their passwords every 90 days. However, a security audit reveals that several user accounts have been compromised shortly after the password change period. Analysis indicates that the compromised passwords were relatively strong. What is the MOST likely cause of these account compromises soon after password changes? A. Users are choosing new passwords that are too similar to their previous ones. B. The company's network is being infiltrated by malware during the password change period. C. Users are writing down their new passwords and leaving them in insecure locations. D. The password management system is leaking new passwords due to a security flaw. The most likely cause of the account compromises soon after password changes is that users are writing down their new passwords and leaving them in insecure locations (Option C). Frequent password changes, especially with the requirement for strong passwords, can lead to users writing down their passwords to remember them, which increases the risk of unauthorized access if these written passwords are discovered. Options A, B, and D are potential security concerns but do not directly address the issue of compromised accounts due to insecure handling of new passwords. 71. When assessing the impact of various IT security risks, what factors should an organization consider to accurately evaluate the potential impact of these risks? (SELECT TWO) A. The sensitivity of the data or assets potentially affected by the risk. B. The cost of implementing additional security measures. C. The potential disruption to business operations and services. D. The organization's current market share and competitive position. In evaluating the impact of IT security risks, it's important to consider factors that directly relate to the consequences of those risks materializing. The sensitivity of the data or assets potentially affected by the risk (Option A) is a key factor, as risks involving sensitive or critical data or assets can have more severe consequences, such as data breaches, loss of intellectual property, or regulatory non-compliance. The potential disruption to business operations and services (Option C) is another crucial factor. Risks that can cause significant operational disruptions, such as system outages or service interruptions, can lead to revenue loss, decreased productivity, and damage to customer relationships. While the cost of implementing additional security measures (Option B) is important for budgeting and resource allocation, it does not directly contribute to the assessment of the risk's impact. Similarly, the organization's current market share and competitive position (Option D) are more related to business strategy and do not directly influence the evaluation of the potential impact of IT security risks. Therefore, focusing on the sensitivity of data or assets and the potential disruption to operations enables an organization to accurately assess the impact of various IT security risks. 72. A high-security data center is reviewing its physical security measures. The data center is located in a suburban area with moderate vehicular traffic. The management team is considering enhancing the security of the facility's main entrance, which currently lacks any physical barriers. Which of the following additions would most effectively improve security against unauthorized vehicle access while allowing authorized vehicles to enter? A. Placing concrete barriers at the entrance B. Installing retractable bollards at the entrance C. Adding more security guards at the entrance D. Implementing a key card access system for vehicles Retractable bollards are an effective physical security measure for controlling vehicular access to sensitive areas like a high-security data center. They can be raised to block unauthorized vehicles and lowered to allow authorized vehicles to enter, providing a flexible and secure solution. This feature makes retractable bollards particularly suitable for the data center's main entrance, where there is a need to balance security against unauthorized vehicle access with the requirement for authorized access. Concrete barriers (Option A) provide a strong physical barrier but lack the flexibility of allowing authorized vehicle access. Adding more security guards (Option C) increases human surveillance but does not provide a physical barrier against vehicle intrusion. A key card access system (Option D) is useful for controlling access but is more effective when combined with a physical barrier like bollards. 73. During a security assessment in a partially known environment of a government agency, it is found that sensitive information is being transmitted over unencrypted channels. What is the most appropriate action for the agency to take to secure the transmission of sensitive information? A. Increasing the physical security of government buildings. B. Encrypting all sensitive information before transmission. C. Implementing a more robust intrusion detection system. D. Conducting background checks on all employees handling sensitive information. In the scenario of a partially known environment where specific vulnerabilities are identified, such as the transmission of sensitive information over unencrypted channels, the most appropriate action is directly addressing that vulnerability. Encrypting all sensitive information before transmission (Option B) is the most direct way to secure the data and ensure its confidentiality and integrity during transit. While increasing physical security (Option A), implementing a robust intrusion detection system (Option C), and conducting background checks on employees (Option D) are important security measures, they do not directly address the issue of unencrypted transmission of sensitive information. 74. A healthcare provider uses database encryption to secure patient medical records. The database administrator needs to perform maintenance on the database while ensuring data security. What is a key consideration for maintaining the security of the encrypted data during maintenance activities? A. Regularly changing database passwords. B. Keeping the encryption keys secure and inaccessible during maintenance. C. Increasing the storage capacity of the database. D. Installing antivirus software on the database server. When performing maintenance on a database that contains encrypted data, such as patient medical records in a healthcare setting, a crucial security consideration is the management and protection of the encryption keys. The encryption keys are the means to decrypt the data, and if they were to fall into the wrong hands during maintenance activities, it could lead to a data breach. Therefore, it is essential to ensure that these keys are kept secure and inaccessible to unauthorized personnel during the maintenance process. This might involve using a key management system, restricting access to the keys to only authorized individuals, or temporarily disabling key access. By prioritizing the security of the encryption keys, the database administrator can maintain the confidentiality and integrity of the encrypted data, even during maintenance activities. 75. A company's IT department is concerned about the increasing use of image files to deliver malware. They are implementing measures to combat this threat. Which TWO of the following actions are most effective in addressing security concerns related to image-based malware? (SELECT TWO) A. Scanning all incoming image files with updated antivirus software B. Restricting the use of external USB drives C. Training employees on the risks of downloading images from untrusted sources D. Implementing network segmentation Scanning all incoming image files with updated antivirus software (A) is a key measure for detecting and preventing image-based malware. Antivirus software that is regularly updated can identify and block malicious code hidden in image files, providing a critical line of defense. Training employees on the risks of downloading images from untrusted sources (C) is also crucial, as human error or lack of awareness can lead to security breaches. Educating staff on the dangers of image-based malware and the importance of verifying the source of image files can significantly reduce the risk of accidental downloads of malicious images. Restricting the use of external USB drives (B) is a good security practice but is less directly related to the specific threat of image-based malware. Implementing network segmentation (D) is beneficial for overall network security but does not specifically address the prevention of image-based malware transmission. 76. A software developer is working on an application that manages sensitive documents. The developer implements a feature that checks user permissions before allowing access to a document. However, the permissions are not rechecked at the time the document is actually used. Which type of vulnerability is the application most at risk of due to this implementation? A. Directory Traversal B. Buffer Overflow C. Time-of-Check to Time-of-Use (TOCTOU) D. Injection Flaws This scenario describes a Time-of-Check to Time-of-Use (TOCTOU) vulnerability. The application is at risk because it checks user permissions before allowing access to a document, but it does not recheck these permissions at the time the document is actually used. This gap between the permission check (time-ofcheck) and the document access (time-of-use) can be exploited by attackers to gain unauthorized access to sensitive documents. Directory Traversal (Option A), Buffer Overflow (Option B), and Injection Flaws (Option D) are different types of vulnerabilities that involve accessing unauthorized files, memory manipulation, and injecting malicious code into an application, respectively, and do not specifically describe the TOCTOU issue. 77. A healthcare organization relies on a legacy patient management system that is no longer supported by the vendor. The IT department is concerned about the system's security vulnerabilities, as it cannot be updated with the latest patches. What is the primary security risk associated with continuing to use this legacy system? A. Decreased user productivity due to outdated features B. Increased risk of compatibility issues with new software C. Elevated potential for data breaches due to unaddressed vulnerabilities D. Higher operational costs due to inefficient processes The primary security risk associated with continuing to use a legacy patient management system that is no longer supported by the vendor is the elevated potential for data breaches due to unaddressed vulnerabilities (Option C). Legacy systems often contain vulnerabilities that cannot be patched or updated, making them susceptible to exploitation by attackers. This risk is particularly concerning in healthcare, where the protection of sensitive patient data is crucial. Decreased user productivity (Option A), compatibility issues with new software (Option B), and higher operational costs (Option D) are potential challenges of using legacy systems, but they do not pose the same level of security threat as unaddressed vulnerabilities. 78. A healthcare facility deploys IoT devices, including wearable health monitors and smart medical equipment, to enhance patient care. With the integration of these devices into the hospital network, what is the primary security concern that needs to be addressed to ensure the safety and privacy of patient data? A. Maximizing the battery life of all IoT devices to ensure uninterrupted operation. B. Segregating IoT devices on a separate network and implementing strict access controls. C. Completely replacing all existing medical equipment with IoT-enabled devices. D. Focusing exclusively on physical security measures for the IoT devices. In a healthcare facility, where IoT devices are used for critical patient care and handle sensitive health data, segregating IoT devices on a separate network and implementing strict access controls (Option B) is a key security measure. Network segregation helps isolate these devices from the main hospital network, reducing the risk of cyber attacks spreading across the network and compromising patient data. Access controls ensure that only authorized personnel can access the devices and the data they generate, further protecting patient privacy and data integrity. Maximizing battery life (Option A) is important for device reliability but does not address security concerns. Completely replacing existing medical equipment with IoT devices (Option C) is not necessarily a security measure and may not be feasible. Focusing solely on physical security (Option D) overlooks the critical aspects of network and data security in an IoT environment. 79. An online banking platform is enhancing its security measures to protect customer transactions and data. The platform's development team is focused on implementing cryptographic protocols to secure communication between the bank's servers and clients' devices. Which cryptographic protocol should be the PRIMARY focus for securing online transactions and safeguarding customer data? A. Secure Shell (SSH) for establishing secure channels between the bank's servers and clients' devices. B. Transport Layer Security (TLS) for encrypting data transmitted between the bank's website and users' browsers. C. None of these D. Simple Mail Transfer Protocol Secure (SMTPS) for encrypting email communications with customers. The primary focus for securing online transactions and safeguarding customer data on an online banking platform should be implementing Transport Layer Security (TLS) (B). TLS provides end-to-end encryption for data transmitted between the bank's website and users' browsers, ensuring the confidentiality and integrity of sensitive information such as transaction details and personal data. While SSH (A) establishes secure channels, it is more commonly used for secure remote login rather than web transactions. IPsec (C) secures network communications but is not specifically tailored for web-based banking transactions. SMTPS (D) is used for securing email communications and does not address the security of online banking transactions. 80. A multinational corporation is upgrading its network infrastructure and needs to select secure protocols for various services. The corporation has a large remote workforce that frequently accesses the corporate network. Which protocol should the IT team select for secure remote access that provides robust encryption and authentication while ensuring compatibility with various client devices? A. Telnet for its simplicity and wide compatibility. B. SSH for secure and encrypted remote command execution. C. FTP for its widespread use and support for file transfers. D. HTTP for easy access and compatibility with web browsers. In this scenario, the goal is to select a secure protocol for remote access that offers robust encryption and authentication while being compatible with various client devices. Option A, Telnet, is not secure as it transmits data in plaintext, including sensitive information like usernames and passwords. Option C, FTP, is also not secure for similar reasons, as it does not encrypt data transmissions. Option D, HTTP, is widely compatible but lacks encryption for secure data transmission. The most appropriate choice is Option B, SSH (Secure Shell). SSH provides secure and encrypted remote command execution, ensuring that data transmitted between remote workers and the corporate network is protected. SSH also supports robust authentication mechanisms and is widely compatible with various client operating systems and devices, making it suitable for a multinational corporation with a large remote workforce. 81. A healthcare organization is implementing SPF to safeguard its email communications and protect sensitive patient data. To maximize the effectiveness of SPF in the organization's email security strategy, which TWO of the following best practices should the IT department follow? (SELECT TWO) A. Regularly update the SPF record to include IP addresses of all authorized email servers. B. Configure SPF to block all emails that do not originate from the organization's domain. C. Implement a DMARC policy in conjunction with SPF to specify handling of SPF failures. D. Eliminate the use of external email services to simplify SPF management. To enhance email security with SPF, especially in a healthcare setting where protecting patient data is critical, implementing best practices is key. Option A, regularly updating the SPF record to include IP addresses of all authorized email servers, ensures that the SPF record accurately reflects the organization's email infrastructure. This prevents legitimate emails from being mistakenly marked as spam or spoofed. Option B, configuring SPF to block all emails not originating from the organization's domain, might be overly restrictive and could hinder legitimate communication with external parties. Option D, eliminating the use of external email services, is not practical and may not be feasible for operational needs. The most effective practices are Options A and C. Implementing a DMARC (Domain-based Message Authentication, Reporting, and Conformance) policy (Option C) in conjunction with SPF provides a comprehensive approach to email security. DMARC allows the organization to define how receiving email servers should handle emails that fail SPF checks, enhancing the organization's ability to protect against email spoofing and phishing. These practices (regular SPF record updates and DMARC implementation) together create a robust defense against email-based threats while ensuring the secure handling of sensitive patient data. 82. During a security audit of a financial firm, an auditor finds that employees frequently use personal devices for work-related tasks, including accessing sensitive customer data. The firm's current security policy does not explicitly address the use of personal devices. Considering the potential risks involved, what should be the firm's immediate action to mitigate the security risks associated with the use of personal devices? A. Ban the use of all personal devices in the workplace B. Implement a Bring Your Own Device (BYOD) policy with strict security controls C. Ignore the issue as long as no security incidents have occurred D. Increase the frequency of security awareness training for employees The most appropriate and effective action for the financial firm to mitigate the security risks associated with the use of personal devices is to implement a Bring Your Own Device (BYOD) policy with strict security controls, as outlined in Option B. This approach acknowledges the reality of employees using personal devices for work while establishing clear guidelines and security measures to protect sensitive data. A well-designed BYOD policy can include requirements for device encryption, secure access to the corporate network, regular security updates, and compliance with data protection regulations. Option A, banning all personal devices, may not be feasible or well-received by employees and could impact productivity. Ignoring the issue (Option C) is not advisable, as it leaves the firm vulnerable to security breaches. While increasing security awareness training (Option D) is beneficial, it does not address the specific risks associated with personal device use without a formal policy in place. 83. A small business is evaluating its cybersecurity strategy and is concerned about the cost implications of different security architectures. The business wants to ensure optimal protection without exceeding its limited budget. In this scenario, what is the most cost-effective approach to achieving a robust cybersecurity posture? A. Investing in the most advanced and expensive security technologies available. B. Implementing a risk-based approach to security, focusing on the most critical assets. C. Completely outsourcing the cybersecurity function to an external service provider. D. Avoiding the use of any cybersecurity tools to minimize expenses. For a small business with budget constraints, implementing a risk-based approach to cybersecurity (Option B) is the most cost-effective strategy. This approach involves identifying the most critical assets and vulnerabilities and prioritizing security measures accordingly. By focusing resources on the areas of greatest risk, the business can achieve optimal protection without overspending. Investing in the most advanced and expensive technologies (Option A) may not be feasible or necessary for a small business. Completely outsourcing cybersecurity (Option C) can be costly and may not provide the tailored approach needed. Avoiding the use of cybersecurity tools (Option D) is not advisable, as it leaves the business vulnerable to cyber threats. 84. In response to an increase in pretexting attempts targeting its employees, a financial institution is updating its security protocols. Which TWO of the following actions should be included to effectively mitigate the risk of pretexting attacks? (SELECT TWO) A. Conducting regular security awareness training focused on identifying pretexting scenarios B. Restricting physical access to sensitive areas within the organization C. Implementing a policy requiring verification of all requests for sensitive information D. Regularly updating firewall and intrusion detection systems Conducting regular security awareness training focused on identifying pretexting scenarios (A) is essential in mitigating the risk of pretexting attacks. Training helps employees recognize the signs of pretexting and understand the importance of verifying the legitimacy of requests, especially those that seem unusual or involve sensitive information. Implementing a policy requiring verification of all requests for sensitive information (C) is another critical action. This policy ensures that employees take steps to authenticate the identity of the person making the request and the validity of their need for the information. Restricting physical access to sensitive areas (B) is important for overall security but is less directly related to preventing pretexting attacks, which often occur via communication channels like phone or email. Regularly updating firewall and intrusion detection systems (D) is crucial for network security but does not specifically address the challenge of combating social engineering tactics like pretexting. 85. A museum is enhancing its security system to protect valuable artifacts. The museum decides to install an infrared (IR) motion detection system in the exhibit areas. One night, the system triggers an alarm. Upon investigation, it is discovered that the alarm was caused by a small animal that entered the exhibit area. What adjustment should the museum make to the IR motion detection system to reduce false alarms while maintaining effective security? A. Increase the sensitivity of the IR sensors B. Decrease the sensitivity and adjust the height of the IR sensors C. Replace the IR sensors with traditional cameras D. Turn off the IR motion detection system at night To reduce false alarms caused by small animals while maintaining effective security, the museum should adjust the infrared (IR) motion detection system by decreasing the sensitivity and adjusting the height of the IR sensors (Option B). This adjustment will help ensure that the sensors are less likely to be triggered by small animals and more focused on detecting human-sized movements. Increasing the sensitivity (Option A) would likely result in more false alarms. Replacing the IR sensors with traditional cameras (Option C) may not provide the same level of motion detection capabilities, especially in low-light conditions. Turning off the IR motion detection system at night (Option D) would leave the exhibit areas vulnerable to security breaches during these hours. 86. A network administrator is configuring a secure email system for an organization. To enhance the security of email communications, which of the following are appropriate uses of the public key? (SELECT TWO) A. Encrypting email content before sending it to the recipient. B. Decrypting received emails on the server. C. Digitally signing sent emails to prove authenticity. D. Generating symmetric encryption keys for email encryption. The public key plays a significant role in enhancing the security of email communications. It is used to encrypt email content before sending, ensuring that only the recipient with the corresponding private key can decrypt and read the email, thereby maintaining its confidentiality. Additionally, the sender uses their private key to digitally sign the email, which can be verified using the sender's public key by the recipient. This verification process assures the email's authenticity and integrity, confirming its origin and ensuring it has not been altered in transit. These applications of the public key are fundamental in securing email communications. 87. You are a senior cybersecurity analyst responsible for monitoring and responding to security incidents on SERVER01. The syslog entries shown here are part of a log file that spans several hours. Your task is to identify the recommended actions based on the provided log entries. What is your recommended response to the event logged at 8:35? A. Block outbound connections to IP 203.0.113.1 and update threat intelligence feeds. B. Investigate the affected system, isolate it from the network, and conduct a thorough malware analysis. C. Continuously monitor the outbound traffic but avoid immediate action to avoid alerting the attacker. D. Share the IoC with external threat intelligence sources and wait for their analysis. Detecting an Indicator of Compromise (IoC) involving outbound connections to a known malicious IP is critical. Immediate investigation is necessary to identify the scope of the compromise and potential data exfiltration. Isolating the affected system from the network helps prevent further communication with the malicious IP and contains the incident. Conducting a thorough malware analysis on the system aids in understanding the nature of the compromise and developing effective remediation strategies. 88. During a routine audit, an IT security specialist notices unusual network traffic originating from an executive's laptop, which recently had new financial analysis software installed. This software is now suspected to be a Trojan. What should be the specialist's FIRST action in responding to this incident? A. Run a full antivirus scan on the executive's laptop. B. Disconnect the laptop from the network immediately. C. Inform the executive about the potential data breach. D. Reinstall the operating system on the laptop. The first action in responding to a suspected Trojan infection, especially one involving sensitive data and an executive's laptop, is to contain the threat. Disconnecting the laptop from the network (Option B) immediately prevents any further unauthorized data transmission and stops the spread of the Trojan to other systems. Running a full antivirus scan (Option A) is important but should be done after isolating the system. Informing the executive (Option C) is a crucial step in incident response but does not take precedence over containing the threat. Reinstalling the operating system (Option D) may be a necessary remediation step but is not the first action to take in this scenario. 89. A company's employees receive an email purporting to be from the IT department, instructing them to click on a link to update their email account settings. The link redirects to a webpage that closely resembles the company's internal portal. However, it is later discovered that the webpage is a phishing site designed to harvest user credentials. This incident exemplifies which common tactic used in phishing attacks? A. Domain spoofing B. Social engineering C. Ransomware dissemination D. Network eavesdropping This incident exemplifies social engineering (B), a common tactic used in phishing attacks. Social engineering involves manipulating individuals into performing actions or divulging confidential information. In this scenario, the phishing email masquerades as a legitimate communication from the IT department, exploiting the trust of employees to trick them into clicking a fraudulent link and entering their credentials on a fake webpage. This tactic relies on psychological manipulation, convincing targets that the request is legitimate. It differs from domain spoofing (A), which involves creating a fraudulent website or email address that mimics a legitimate one. Ransomware dissemination (C) and network eavesdropping (D) are different types of cyber threats that are not directly related to the scenario described, which focuses on the use of deceptive messages to obtain sensitive information. 90. A cloud storage provider needs to ensure the security of stored data against future advancements in computing power and cryptographic attacks. When choosing an encryption algorithm, what should the cloud provider consider regarding key length to enhance long-term data security? A. The compatibility of the key length with older encryption algorithms. B. The impact of key length on the cost of data storage. C. The strength of encryption provided by longer key lengths. D. The ease of remembering keys by the IT staff. In the context of a cloud storage provider securing data against future computing advancements and cryptographic attacks, the key consideration when choosing an encryption algorithm is the strength of encryption provided by longer key lengths. Longer key lengths typically offer stronger encryption, making it more difficult for attackers to decrypt data using brute-force methods or other cryptographic attacks. As computing power continues to increase, longer keys become increasingly important for maintaining the security of encrypted data over time. Choosing an encryption algorithm with a sufficiently long key length is crucial for ensuring that stored data remains secure against future threats, providing long-term protection for the sensitive information entrusted to the cloud storage provider.
0
You can add this document to your study collection(s)
Sign in Available only to authorized usersYou can add this document to your saved list
Sign in Available only to authorized users(For complaints, use another form )