Jason Dion Practice Exam 2

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/46

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 12:01 AM on 8/27/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

47 Terms

1
New cards

Which of the following strategies is MOST effective for organizations aiming to mitigate the risk of widespread disruptions due to a localized issue in their infrastructure?

Data masking.

Permission restrictions.

Infrastructure diversification.

Geographic restrictions.

Infrastructure diversification

2
New cards

Sasha, a network administrator for Kelly's Technical Innovations, has just recently installed a NGFW on her company’s network to replace the previous traditional stateful firewall they were using. This change was made to keep up with shortcomings that were with the previous firewall. Which of the following improvements does this NGFW provide that were not available previously? (Choose 3)


Can be integrated with various other security products.

Ability to conduct deep packet inspection and use signature-based intrusion detection.

Improved awareness of connection states on layer 4 traffic.

Application awareness that can distinguish between different types of traffic.

Increased focus on HTTP traffic, helping to prevent common web application attacks like cross-site scripting and SQL injections.

Addition of multiple functions, including firewall, intrusion prevention, antivirus, and more.

1.Can be integrated with various other security products.

2.Ability to conduct deep packet inspection and use signature-based intrusion detection.

3.Application awareness that can distinguish between different types of traffic.

3
New cards

What part of a BPA for mission essential functions provides a detailed, step-by-step description of the procedural tasks performed?

Hardware.

Process flow.

Inputs.

Outputs.

Process flow.

4
New cards

As part of their expansion, Kelly Innovations LLC decided to break their monolithic application into microservices. While this provides scalability, which of the following security implications should the organization be MOST concerned with?

Singular deployment cadence.

Reduced monitoring endpoints.

Consolidation of data storage.

Granular access controls requirements.

Granular access controls requirements.

5
New cards

Which of the following terms refers to the method where an attacker directly interacts with computer systems to gather information, potentially alerting the target about the attempted intrusion?

Network enumeration.

OSINT.

Active reconnaissance.

Passive reconnaissance.

Active reconnaissance.

Active reconnaissance involves the attacker directly engaging with the target systems, like scanning ports or attempting direct network connections. It often leaves traces and can alert the target.

6
New cards

Which of the following statements BEST explains the importance of employee retention in securing an organization?

Employee retention helps to maintain institutional knowledge and expertise in managing security automation

Employee retention reduces the likelihood of social engineering attacks because long term employees get more training to spot and avoid such attacks

Employee retention reduces the need for automation and orchestration, leading to a more stable workforce

High employee retention promotes a basic understanding of automated security processes, improving response times

Employee retention helps to maintain institutional knowledge and expertise in managing security automation.

7
New cards

You are an IT security manager for an enterprise that deals with sensitive customer information and intellectual property. The organization is concerned about data loss through email and removable storage devices. As a security manager, you recommend implementing a Data Loss Prevention (DLP) solution to enhance security. Which of the following configurations would be the MOST effective way to implement Data Loss Prevention (DLP) for the given scenario?

Using the DLP solution solely for monitoring purposes without implementing any preventive measures.

Configuring the DLP solution to scan all outbound emails and files leaving the organization for sensitive information.

Implementing DLP on endpoints with a focus on monitoring and preventing data transfers between internal users.

Enabling the DLP solution to block all email attachments and USB storage devices to prevent data leakage.

Configuring the DLP solution to scan all outbound emails and files leaving the organization for sensitive information.

8
New cards

Which of the following terms BEST represents the approach that divides a physical network into multiple distinct units to manage traffic and enhance security?

Logical segmentation.

High availability.

Software-defined networking (SDN).

Containerization.

Logical segmentation.

9
New cards

Kelly Innovations LLC wants to implement a network appliance that focuses on filtering traffic based on source and destination IP addresses and port numbers. Which layer of the OSI model is this appliance primarily operating at?

Layer 3.

Layer 5.

Layer 2.

Layer 4.

Layer 4.

Layer 4, or the transport layer, deals with protocols like TCP and UDP and is concerned with port numbers and connection-oriented communication. Network appliances operating at this layer filter and manage traffic based on source and destination IP addresses, as well as port numbers.

10
New cards

Which of the following BEST defines the term that represents the expected number of times a risk event will occur within a one-year period?

ARO.

EF.

SLE.

ALE.

ARO.

11
New cards

To enhance the privacy of its users, Kelly Innovations LLC is considering a system that can act as an intermediary for internet requests, hiding the origin of the request from the destination server. Which solution would BEST fit this purpose?

Proxy server.

IPS.

Jump server.

Router.

Proxy server.

12
New cards

Which of the following is a disadvantage of agentless posture assessment in Network Access Control (NAC) solutions?

Increased risk of malware infection on client devices.

Inability to support smartphones, tablets, and IoT devices.

Less detailed information about the client is available

Requires more storage space on the client device.

Less detailed information about the client is available.

13
New cards

Which of the following ports should be disabled or carefully monitored to prevent unauthorized Voice over IP (VoIP) signaling, which can be an avenue for toll fraud or unauthorized call control?

Port 110.

Port 5060.

Port 139

Port 161

Port 5060.

Session Initiation Protocol (SIP), port 5060, is used for signaling in Voice over IP (VoIP) services. Unauthorized access to this port can result in toll fraud or unauthorized call control.

14
New cards

Hani, a security analyst, is investigating a malware incident and discovers that the malware had been placed on the computers weeks ago. At midnight, it triggered a virus that spread across four servers and throughout the organization. The CEO found a message from a former employee stating that he had left a "surprise" for the company. Which type of malware is MOST likely responsible for this incident?

Worm.

Ransomware.

Trojan.

Logic bomb.

Logic bomb.

A logic bomb is a type of malware that executes a malicious action when a specific condition or trigger is met, such as a date, time, or event.

Ransomware is a type of malware that encrypts the data or files on a system and demands a ransom for their decryption or restoration. A Trojan is a type of malware that disguises itself as a legitimate or benign program, but performs malicious actions when executed. A worm is a type of malware that self-replicates and spreads to other systems or networks without user interaction.

15
New cards

Jamario, an IT administrator for Dion Training Solutions, is considering deploying an agent-based web filter solution to manage and monitor web traffic for remote employees. Which of the following is the MOST important advantage of implementing agent-based web filters over traditional gateway-based filters for this purpose?

It reduces the total cost of ownership (TCO) due to the absence of hardware.

It can filter traffic at a faster rate than gateway solutions.

It allows for consistent policy enforcement regardless of the user's location.

It doesn’t require any updates or maintenance.

It allows for consistent policy enforcement regardless of the user's location.

16
New cards

Which of the following statements is NOT true about the importance of continuous integration in relation to secure operations?

Continuous integration enables early detection of issues, making it easier to address them before they escalate.

Continuous integration can increase software quality by catching.

Continuous integration may slow down the development process but it provides far more secure systems overall.

Continuous integration automates the building and testing of code, which enhances developer productivity.

Continuous integration may slow down the development process but it provides far more secure systems overall.

17
New cards

In risk analysis, which method involves assigning numerical values to risks based on financial figures, such as costs or potential losses?

Risk Matrix.

Qualitative risk analysis.

Annualized loss expectancy.

Quantitative risk analysis.

Quantitative risk analysis.

18
New cards

Which of the following statements BEST explains the concept of Log aggregation?

Log aggregation collects and normalizes log data from various sources to make it easier to analyze.

Log aggregation is the analysis of wide varieties of log data to identify security breaches.

Log aggregation is the monitoring network traffic and identifying potential security breaches.

Log aggregation is the collecting of data from a scan and making it available to security analysts.

Log aggregation collects and normalizes log data from various sources to make it easier to analyze.

19
New cards

Which of the following is the BEST type of backup that allows for the rapid redeployment of an OS without requiring reinstallation of third-party software, patches, and configurations?

File-level backup.

Incremental backup.

Differential backup.

Image backup.

Image backup.

20
New cards

Data Core, a data processing company, has gathered its security team for a meeting where the Chief Operations Officer presents a scenario involving a newly discovered zero-day vulnerability, to which their systems are particularly vulnerable. The security team discusses various ways to address the issue, with two major competing approaches emerging. What type of exercise are they most likely performing?

Live drill.

Simulation.

Functional exercise.

Tabletop exercise.

Tabletop exercise.

21
New cards

Which of the following terms refers to the delivery of computing services over the internet, such as servers, storage, databases, networking, software, analytics, and intelligence?

On-premises.

IoT.

Virtualization.

Cloud.

Cloud.

22
New cards

Which of the following hardware vulnerability involves the ability to modify the software that controls the functionality of a device?

Firmware vulnerability.

Side loading.

End-of-life vulnerability.

Legacy vulnerability.

Firmware vulnerability.

23
New cards

You are working remotely and you need to access your company’s network resources. You connect to a public Wi-Fi hotspot at a nearby coffee shop and use a VPN client to establish a secure connection. However, you notice that the VPN client is outdated. What type of vulnerability are you exposing yourself to?

Unsecure networks.

Open service ports.

Default credentials.

Vulnerable software.

Vulnerable software.

24
New cards

Lexicon, an AI company, seeks to implement a security measure to systematically identify, evaluate, and prioritize potential risks to their systems and networks. Which of the following is an example of a managerial security control that would help achieve this?

Intrusion detection system.

Risk assessments.

Firewall.

Security Guards.

Risk assessments.

25
New cards

You are making an appointment to get your hair cut. When you enter your personal data into the website for Dye My Darling, the data is placed in a database and paired with a smaller set of symbols that will represent your data. To access your personal data, your stylists' computer will access the database. If an attacker gains access to the computer, they will only see the set of symbols, not your personal data. What method of concealment is Dye My Darling using?

Encryption.

Tokenization.

Steganography.

Data Masking.

Tokenization

26
New cards

Croma Soft, a game company, wants to reduce the public-facing attack surface for their company. They hope to achieve this by using a device that can handle and relay requests for servers. Which type of network appliance would be MOST appropriate for this purpose?

Jump server.

Load balancer.

IDS.

Proxy server.

Proxy server.

A proxy server stands between the user's computer and the internet, intercepting requests and potentially reducing the public-facing attack surface by masking the internal server, meeting the scenario requirements.

27
New cards

Lucas, an executive at Kelly Innovations LLC, started observing some unusual behaviors on his office computer. The system sometimes seemed to be running tasks he hadn't initiated. Lucas asked the IT department to check the machine for signs of malware. IT couldn't find any suspicious files or traditional malware footprints on the system. However, they noticed unauthorized changes in the system's registry values and detected activity suggesting the use of PowerShell scripts to execute tasks. Further, these scripts were leveraging legitimate system scripting tools for scanning and configuration activities. Which type of malware is Lucas's computer MOST likely compromised with?

Spyware.

Worm.

Fileless Malware.

Bloatware.

Fileless Malware.

28
New cards

Jimmy, a Chief Technology Officer, is evaluating different architecture models. His biggest concern is the ease of deployment. Which of the following factors would be MOST critical to consider from a security standpoint?

Integration with existing security protocols.

Scalability potential of the architecture.

The vendor's market reputation.

Total cost of ownership (TCO).

Integration with existing security protocols.

29
New cards

At Jamario Tech, employees often complain about having to remember multiple strong passwords for different platforms, leading some to resort to insecure practices like writing them on sticky notes. The cybersecurity team wants to offer a solution to help employees securely manage and store their numerous credentials. What would be the MOST effective solution for this problem?


Allow their employees to write down their passwords as long as they keep them safe.

Introduce a company-wide password manager.

Advise employees to regularly change passwords.

Encourage employees to use similar passwords for different platforms.

Introduce a company-wide password manager.

30
New cards

Your organization is implementing a new Identity and Access Management (IAM) system to enhance security and streamline user management processes. During the planning phase, you discover that there are multiple existing systems in use that require integration with the new IAM system. Ensuring interoperability between these systems is crucial. What is the BEST approach to achieve interoperability in this scenario?


Implementing SSO to allow users to access multiple systems using a single set of credentials.

Replacing all existing systems with new ones that are guaranteed to be compatible with the new IAM system.

Creating separate user accounts in each system and maintaining them independently to avoid potential compatibility issues.

Assigning different user roles in each system, ensuring no overlap in permissions or access rights.

Implementing SSO to allow users to access multiple systems using a single set of credentials.

Secure Sign-On (SSO) allows users to log in once and gain access to multiple systems that are integrated with the IAM system. This enhances the user experience, reduces the need for multiple credentials, and ensures a unified and secure authentication process. While replacing all existing systems may seem like a straightforward solution, it is often costly, time-consuming, and may disrupt business operations.

31
New cards

64.Which of the following statements BEST explains the importance of 'benchmarks'?


Benchmarks compare a security performance to industry-standard metrics, identifying potential security weaknesses.

Benchmarks are firewall technologies that inspect network traffic and block malicious packets to prevent cyber-attacks.

Benchmarks are intrusion detection systems that monitor and analyze network traffic for potential security breaches.

Benchmarks are cryptographic algorithms used to secure data transmission over the internet.

Benchmarks compare a security performance to industry-standard metrics, identifying potential security weaknesses.

32
New cards

Which of the following methods BEST ensures the security of data at rest?

Storing in remote locations and changing locations frequently

Using passwords for access

Regular backups.

Encryption and ACLs.

Encryption and ACLs.

33
New cards

A company wants to implement a more flexible access control system that can adjust to changing user behavior. Which of the following technologies can help the company achieve this goal?

MAC.

Adaptive identity.

Security zones.

Policy-driven access control.

Adaptive identity.

34
New cards

Manar is reviewing logs and finds that many logon attempts were made using common words followed by numbers or symbols. Each password is attempted on the 20 computers in the accounting department. He suspects that these passwords were generated by an automated tool. Which of the following password attacks is BEST illustrated by this finding?

Spraying.

Downgrade.

Brute force.

Birthday.

Spraying.

A spraying attack is a type of password attack that involves trying common passwords against multiple accounts, hoping to find a match.

35
New cards

Rippled, a drink vendor, is developing a disaster recovery plan to ensure the swift recovery of critical systems and processes in the event of a disruption. They are defining a specific metric which is the amount of acceptable amount of time it will take to return to normal business. What measure are they defining?

MTTR.

RTO.

MTBF.

RPO.

RTO.

The Recovery Time Objective (RTO) is the maximum acceptable time allowed for the recovery of a system or process after a disruption.

36
New cards

At Dion Defenders, the risk management team has completed the risk assessment process and identified various risks to the company's information systems. They are now preparing to communicate the risk-related information to relevant stakeholders and management for informed decision-making. What part of the risk assessment process are they undertaking?

Risk assessment.

Risk reporting.

Risk identification.

Risk analysis.

Risk reporting.

37
New cards

David is analyzing a recent risk report and categorizes risks based on their likelihood and potential impact, without assigning specific financial values. This approach helps his team prioritize which risks to address first but does not offer detailed monetary estimates. What method is David using?

Qualitative Risk Assessment.

Threat Vector Analysis.

Residual Risk Analysis.

Quantitative Risk Assessment.

Qualitative Risk Assessment.

38
New cards

What is the name of the web-based attack that involves entering malicious code into user input fields that are executed by a database server?

Cross-site request forgery (CSRF).

Directory traversal.

Structured Query Language injection.

Cross-site scripting (XSS).

Structured Query Language injection.

39
New cards

Kelly Innovations LLC is keen on adopting technology to ensure the integrity and transparency of its financial transactions. They are looking for a solution where each transaction record is secured using cryptography, and the hash value of one record is used in the hash calculation of the next. Which of the following technologies would be MOST suitable for this requirement?

Digital watermarking.

Public key infrastructure (PKI).

Symmetric encryption.

Blockchain.

Blockchain.

Blockchain employs an expanding list of transactional records, each referred to as a block, and each block validates the hash of the previous one. This process ensures that historical transactions remain untampered with.

40
New cards

A cloud service provider recently underwent an audit to confirm their compliance with international data security standards. The final report provided by the auditors served as an attestation of the provider's security measures. What does this attestation signify to the cloud service provider's clients?

It assures that the provider's security controls comply with established standards.

It certifies that the provider's services are the most cost-effective in the market.

It guarantees that the security controls are impenetrable and all data is securely held.

It acknowledges the provider's marketing strategies are effective.

It assures that the provider's security controls comply with established standards.

Attestation provides clients with a level of assurance that the provider's security controls have been independently assessed and found to comply with specific security standards.

41
New cards

John, a senior executive at Dion Training Solutions, accessed his corporate email from New York at 10:00 AM. The logs also showed a login attempt to the same account from Tokyo at 10:15 AM, and then another one from Paris at 10:30 AM. The IT team at Dion Training Solutions grew concerned about this activity. Which of the following statements BEST describes the activity related to John's account?

Legitimate use of a VPN.

Scheduled system maintenance.

Multi-factor authentication failure.

Detection of impossible travel.

Detection of impossible travel.

42
New cards

Sanford and Sons, a recycling center, has recently decommissioned a number of servers containing confidential client data. Before selling the servers, the organization wants to ensure that all data has been securely removed and seeks a documented affirmation that the process was complete. Which of the following would provide the organization with the assurance it needs?

HCL.

SLA.

Data destruction certification.

Asset inventory report.

Data destruction certification.

43
New cards

When integrating Cloud services with external applications, which of the following considerations is the most crucial in assessing the security risks associated with data transmission to these external service providers?

Virtualization isolation.

Encryption during transmission.

Access control policies.

Endpoint security.

Encryption during transmission.

44
New cards

An attacker sets up a rogue access point mimicking a legitimate one at a local cafe. Unsuspecting customers connect to this access point, enabling the attacker to intercept their data. Which of the following BEST describes this threat vector?

Default credentials.

Wireless network.

Phishing.

Supply chain.

Wireless network.

45
New cards

After a security assessment, Jono has been tasked with replacing his home office AP with one that has the capability of providing WPA3, which his previous one was unable to handle. Which of the following is true when considering WPA3 standards? (Select 4.)


It is the latest and most secure wireless security protocol.

It prevents eavesdropping, forging, and tampering with management frames.

It provides individualized data encryption even in open networks.

It uses a 4-way handshake for initial authentication and key validation.

It utilizes a Diffie-Hellman key agreement.

It encrypts the authentication process using TCP for enhanced security.

1.It is the latest and most secure wireless security protocol.

2.It prevents eavesdropping, forging, and tampering with management frames

3.It provides individualized data encryption even in open networks

4.It utilizes a Diffie-Hellman key agreement.

46
New cards

Dion Training Solutions recently remediated a critical vulnerability on their servers. Which of the following actions is the BEST step to verify the remediation efforts were successful?

Reviewing event logs.

Intrusive scanning.

Rescanning.

Segmentation.

Rescanning.

47
New cards

A drone manufacturer employs a RTOS to ensure timely task executions. While optimizing for real-time performance, which of the following security concerns might arise?

Overhead from virtualization.

Lack of legacy protocol support.

Uncontrolled cloud access.

Inadequate buffer overflow protections.

Inadequate buffer overflow protections.

- RTOSs prioritize performance, sometimes at the expense of security features like buffer overflow protections, potentially leaving the system susceptible to certain attacks.