1.0

0.0(0)
Studied by 1 person
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/19

Last updated 8:06 PM on 9/14/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

20 Terms

1
New cards

In the Zero Trust model, which of the following components focuses on making decisions about who can access what resources based on policies, identity verification, and threat analysis?

A. Control Plane

B. Implicit trust zones

C. Policy-driven access control

D. Data Plane

A

2
New cards

Which of the following is a part of Zero-Trust Architecture that manages user access based on their roles and responsibilities on the Control Plane?

A. Implicit deny

B. Policy-driven access control

C. Role-based access control

D. Least privilege

B

3
New cards

A21. Which of the following would explain why a company would automatically add a digital signature to each outgoing email message?

A. Confidentiality

B. Integrity

C. Authentication

D. Availability

B

4
New cards

A27. A company would like to examine the credentials of each individual entering the data center building. Which of the following would BEST facilitate this requirement?

A. Access control vestibule

B. Video surveillance

C. Pressure sensors

D. Bollards

A

5
New cards

A64. An organization is implementing a security model where all application requests must be validated at a policy enforcement point. Which of the following would BEST describe this model?

A. Public key infrastructure

B. Zero trust

C. Discretionary access control

D. Federation

B

6
New cards

A83. A user has opened a helpdesk ticket complaining of poor system performance, excessive pop up messages, and the cursor moving without anyone touching the mouse. This issue began after they opened a spreadsheet from a vendor containing part numbers and pricing information. Which of the following is MOST likely the cause of this user's issues?

A. On-path

B. Worm

C. Trojan horse

D. Logic bomb

C

7
New cards

A87. A security administrator has configured a virtual machine in a screened subnet with a guest login account and no password. Which of the following would be the MOST likely reason for this configuration?

A. The server is a honeypot for attracting potential attackers

B. The server is a cloud storage service for remote users

C. The server will be used as a VPN concentrator

D. The server is a development sandbox for third-party programming projects

A

8
New cards

B14. A company is launching a new internal application that will not start until a username and password is entered and a smart card is plugged into the computer. Which of the following BEST describes this process?

A. Federation

B. Accounting

C. Authentication

D. Authorization

C

9
New cards

B36. A company is concerned about security issues at their remote sites. Which of the following would provide the IT team with more information of potential shortcomings?

A. Gap analysis

B. Policy administrator

C. Change management

D. Dependency list


A

10
New cards

B87. When a person enters a data center facility, they must check-in before they are allowed to move further into the building. People who are leaving must be formally checked-out before they are able to exit the building. Which of the following would BEST facilitate this process?

A. Access control vestibule

B. Air gap

C. Pressure sensors

D. Bollards


A

11
New cards

C61. A company is updating components within the control plane of their zero-trust implementation. Which of the following would be part of this update?

A. Policy engine

B. Subjects

C. Policy enforcement point

D. Zone configurations


A

12
New cards

C64. A company would like to automatically monitor and report on any movement occurring in an open field at the data center. Which of the following would be the BEST choice for this task?

A. Bollard

B. Microwave sensor

C. Access control vestibule

D. Fencing


B

13
New cards

C66. A system administrator would like to prove an email message was sent by a specific person. Which of the following describes the verification of this message source?

A. Non-repudiation

B. Key escrow

C. Asymmetric encryption

D. Steganography


A

14
New cards

C82. Visitors to a corporate data center must enter through the main doors of the building. Which of the following security controls would be the BEST choice to successfully guide people to the front door? (Select TWO)

A. Infrared sensors

B. Bollards

C. Biometrics

D. Fencing

E. Access badges

F. Video surveillance

B D

15
New cards

Q5. Trust Us is a company that acts as a trusted entity. They issue and manage security credentials and issue digital signature wrappers for public keys for message encryption. What type of company is Trust Us?

A. Registration Authority

B. Certificate Authority

C. Blockchain

D. Root of Trust

B

16
New cards

Q11. Which type of symmetric encryption is BEST suited for scenarios where the total length of the message is not predetermined and encrypts data one byte or bit at a time?

A. Initialization vector (IV)

B. Block cipher

C. AES256

D. Stream cipher

D

17
New cards

Q27. Sweet as Thyme, a flavoring supplier, uses a peer to peer network which relies on a public ledger to ensure the integrity of transactions and to provide a permanent record of all transactions. What is this technology they are using called?

A. Digital Signatures

B. Key Stretching

C. Blockchain

D. Salting

C

18
New cards

Dion Training wants to increase the trustworthiness of its website for its clients. They are seeking a certificate that is signed and verified by a recognized external authority. What type of certificate should they pursue?

A. Third-party certificate

B. CSR

C. Wildcard certificate

D. Self-signed certificate

A

19
New cards

. What part of PKI allows the storing of encrypted keys with a third party so keys can be recovered if they are lost?

A. Key generation

B. Key escrow

C. Public key infrastructure

D. Key exchange

B

20
New cards

. Reason and Rhyme, a tutoring service, has increased the security of its customers' passwords. They have always converted passwords to fixed length sequences, but now they will do this process more than once to increase the amount of computing power and time it will take for an attacker to decode the password. What is this method known as?

A. Digital Signatures

B. Hashing

C. Salting

D. Key Stretching

D