1/19
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
In the Zero Trust model, which of the following components focuses on making decisions about who can access what resources based on policies, identity verification, and threat analysis?
A. Control Plane
B. Implicit trust zones
C. Policy-driven access control
D. Data Plane
A
Which of the following is a part of Zero-Trust Architecture that manages user access based on their roles and responsibilities on the Control Plane?
A. Implicit deny
B. Policy-driven access control
C. Role-based access control
D. Least privilege
B
A21. Which of the following would explain why a company would automatically add a digital signature to each outgoing email message?
A. Confidentiality
B. Integrity
C. Authentication
D. Availability
B
A27. A company would like to examine the credentials of each individual entering the data center building. Which of the following would BEST facilitate this requirement?
A. Access control vestibule
B. Video surveillance
C. Pressure sensors
D. Bollards
A
A64. An organization is implementing a security model where all application requests must be validated at a policy enforcement point. Which of the following would BEST describe this model?
A. Public key infrastructure
B. Zero trust
C. Discretionary access control
D. Federation
B
A83. A user has opened a helpdesk ticket complaining of poor system performance, excessive pop up messages, and the cursor moving without anyone touching the mouse. This issue began after they opened a spreadsheet from a vendor containing part numbers and pricing information. Which of the following is MOST likely the cause of this user's issues?
A. On-path
B. Worm
C. Trojan horse
D. Logic bomb
C
A87. A security administrator has configured a virtual machine in a screened subnet with a guest login account and no password. Which of the following would be the MOST likely reason for this configuration?
A. The server is a honeypot for attracting potential attackers
B. The server is a cloud storage service for remote users
C. The server will be used as a VPN concentrator
D. The server is a development sandbox for third-party programming projects
A
B14. A company is launching a new internal application that will not start until a username and password is entered and a smart card is plugged into the computer. Which of the following BEST describes this process?
A. Federation
B. Accounting
C. Authentication
D. Authorization
C
B36. A company is concerned about security issues at their remote sites. Which of the following would provide the IT team with more information of potential shortcomings?
A. Gap analysis
B. Policy administrator
C. Change management
D. Dependency list
A
B87. When a person enters a data center facility, they must check-in before they are allowed to move further into the building. People who are leaving must be formally checked-out before they are able to exit the building. Which of the following would BEST facilitate this process?
A. Access control vestibule
B. Air gap
C. Pressure sensors
D. Bollards
A
C61. A company is updating components within the control plane of their zero-trust implementation. Which of the following would be part of this update?
A. Policy engine
B. Subjects
C. Policy enforcement point
D. Zone configurations
A
C64. A company would like to automatically monitor and report on any movement occurring in an open field at the data center. Which of the following would be the BEST choice for this task?
A. Bollard
B. Microwave sensor
C. Access control vestibule
D. Fencing
B
C66. A system administrator would like to prove an email message was sent by a specific person. Which of the following describes the verification of this message source?
A. Non-repudiation
B. Key escrow
C. Asymmetric encryption
D. Steganography
A
C82. Visitors to a corporate data center must enter through the main doors of the building. Which of the following security controls would be the BEST choice to successfully guide people to the front door? (Select TWO)
A. Infrared sensors
B. Bollards
C. Biometrics
D. Fencing
E. Access badges
F. Video surveillance
B D
Q5. Trust Us is a company that acts as a trusted entity. They issue and manage security credentials and issue digital signature wrappers for public keys for message encryption. What type of company is Trust Us?
A. Registration Authority
B. Certificate Authority
C. Blockchain
D. Root of Trust
B
Q11. Which type of symmetric encryption is BEST suited for scenarios where the total length of the message is not predetermined and encrypts data one byte or bit at a time?
A. Initialization vector (IV)
B. Block cipher
C. AES256
D. Stream cipher
D
Q27. Sweet as Thyme, a flavoring supplier, uses a peer to peer network which relies on a public ledger to ensure the integrity of transactions and to provide a permanent record of all transactions. What is this technology they are using called?
A. Digital Signatures
B. Key Stretching
C. Blockchain
D. Salting
C
Dion Training wants to increase the trustworthiness of its website for its clients. They are seeking a certificate that is signed and verified by a recognized external authority. What type of certificate should they pursue?
A. Third-party certificate
B. CSR
C. Wildcard certificate
D. Self-signed certificate
A
. What part of PKI allows the storing of encrypted keys with a third party so keys can be recovered if they are lost?
A. Key generation
B. Key escrow
C. Public key infrastructure
D. Key exchange
B
. Reason and Rhyme, a tutoring service, has increased the security of its customers' passwords. They have always converted passwords to fixed length sequences, but now they will do this process more than once to increase the amount of computing power and time it will take for an attacker to decode the password. What is this method known as?
A. Digital Signatures
B. Hashing
C. Salting
D. Key Stretching
D