1/24
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
A security analyst reviews firewall logs every morning to identify suspicious activity and investigate potential incidents. Which type of security control is being performed?
Operational control
An organization deploys firewalls, encryption, and intrusion prevention systems to automatically protect its network infrastructure. Which type of security control is being implemented?
Technical control
A company requires all employees to complete annual security awareness training and establishes an incident response policy. Which type of security control is being implemented?
Managerial control
A data center installs biometric readers, security cameras, and mantraps to prevent unauthorized entry. Which type of security control is being implemented?
Physical control
A company wants to create a site-to-site VPN that authenticates traffic and ensures confidentiality and integrity at the network layer. Which technology should be implemented?
IPSec
A company adopts a cloud-native security platform that combines SD-WAN, secure web gateways, CASB, and Zero Trust Network Access into a single service. Which architecture BEST describes this solution?
Secure Access Service Edge (SASE)
A company deploys a hardened server that administrators must connect to before accessing sensitive production servers. Which security solution has been implemented?
Jump server
An organization wants a flexible authentication framework capable of supporting certificates, passwords, smart cards, and biometrics over network connections. Which authentication framework should it use?
Extensible Authentication Protocol (EAP)
A manufacturer develops embedded controllers for power plants where predictable response times are critical for safety. Which operating system BEST fits this environment?
Real-Time Operating System (RTOS)
A software company redesigns its application into dozens of independent services that communicate over APIs. Which security concern becomes MOST important in this architecture?
Complexity of interactions
A digital forensic investigator is preparing a report for senior executives following a ransomware attack. What should the investigator consider FIRST when determining how to write the report?
Intended audience
A cloud administrator wants infrastructure to automatically allocate additional virtual machines during periods of increased demand without manual intervention. What is the PRIMARY benefit of automated resource provisioning?
Rapid scaling of resources
A security architect reviews an automated response platform and discovers one server failure could stop every automated security workflow. Which security concern should be addressed FIRST?
Single point of failure
A risk manager performs a complete risk assessment only after a major merger introduces new systems into the environment. Which type of risk assessment is being performed?
Ad hoc risk assessment
A network engineer deploys a VPN that encrypts communications between remote users and the corporate network but recognizes that infected laptops can still introduce malware after connecting. Which limitation of this VPN solution is being considered?
Endpoint security
A government-sponsored group combines hacking, espionage, propaganda campaigns, diplomatic influence, and misinformation to weaken another nation. Which strategy BEST describes these coordinated activities?
Hybrid warfare
An organization does not operate its own mail server and wants to reduce the risk of attackers abusing email relay services on internal hosts. Which TCP port should remain closed?
Port 25 (SMTP)
An antivirus solution detects a suspicious executable and immediately isolates it so the user cannot interact with it while administrators investigate. What action has the antivirus performed?
File quarantine
A vendor recommends a security product because they receive a commission for every unit sold. Which conflict of interest does this represent?
Financial interest
A security team wants to inspect web traffic for malicious content, block dangerous URLs, enforce browsing policies, and prevent sensitive information from leaving the organization. Which technology BEST meets these requirements?
Secure Web Gateway (SWG)
A network administrator wants routers, switches, and servers to automatically report CPU utilization, interface failures, and device status to a centralized monitoring system. Which protocol should be implemented?
Simple Network Management Protocol (SNMP)
An enterprise establishes policies governing how encryption keys are generated, rotated, archived, revoked, and destroyed throughout their lifecycle. Which solution is responsible for these processes?
Key Management System (KMS)
A company assigns every server, laptop, and software application to a specific individual who is responsible for approving access requests and ensuring proper security controls are maintained. Which asset management principle is being implemented?
Ownership
During a quantitative risk assessment, an analyst estimates that a successful ransomware attack would destroy approximately 40% of a server's total value. Which metric represents this percentage?
Exposure Factor (EF)
A data owner reviews employee permissions every quarter to verify users still require access to confidential financial records. Which Identity and Access Management process is being performed?
Attestation