1/189
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
You are the Chief Information Security Officer (CISO) at a large corporation. You have been tasked with implementing a new security control to protect sensitive customer data.
The control must be able to automatically detect and prevent unauthorized access to the data.
Which type of control should you implement?
Physical control
Technical control
Operational control
Managerial control
Technical control
You are the head of the cybersecurity team at a large corporation. You notice an increase in network traffic that appears to be legitimate but is causing a slowdown in your systems.
Upon further inspection, you find that the traffic patterns vary each time, making it difficult to distinguish from normal traffic.
What type of security challenge are you MOST likely facing?
Data breach
Sophisticated attack
Proliferation of attack software
Attack scale and velocity
Sophisticated attack
You are the Chief Information Security Officer (CISO) at a large corporation. Your company is expanding rapidly and the complexity of managing security across different business functions is increasing.
You need a dedicated team to monitor and protect critical information assets across the organization.
Which of the following would be the MOST effective solution?
Outsourcing security to a third-party vendor
Implementing a new security policy
Establishing a Security Operations Center (SOC)
Hiring more IT staff
Establishing a Security Operations Center (SOC)
Which of the following security challenges refers to the rapid and broad spread of an attack, often affecting a large number of computers in a relatively short amount of time?
Proliferation of attack software
Sophisticated attacks
Data encryption
Attack scale and velocity
Attack scale and velocity
Which of the following is a method of implementing security controls?
Financial controls
Sales controls
Marketing controls
Managerial controls
Managerial controls
Your computer system is a participant in an asymmetric cryptography system. You've created a message to send to another user. Before transmission, you hash the message and encrypt the hash using your private key. You then attach this encrypted hash to your message as a digital signature before sending it to the other user.
In this example, which protection does the hashing activity provide?
Availability
Non-repudiation
Confidentiality
Integrity
Integrity
You are the Chief Information Security Officer (CISO) at a tech company. Your company is facing issues with silos between the development and operations teams, leading to inefficiencies and security vulnerabilities.
Which approach should you adopt to encourage collaboration and integrate security considerations at every stage of software development and deployment?
Implementing a new security policy
Establishing a Security Operations Center (SOC)
Outsourcing security to a third-party vendor
Adopting a Development and Operations (DevOps) approach
Adopting a Development and Operations (DevOps) approach
A user copies files from her desktop computer to a USB flash device and puts the device into her pocket.
Which of the following security risks is MOST pressing?
Confidentiality
Availability
Integrity
Non-repudiation
Confidentiality
A large multinational corporation has recently experienced a significant data breach. The breach was detected by an external cybersecurity firm, and the corporation's IT department was unable to prevent or detect the breach in its early stages.
The CEO wants to ensure that such a breach does not happen again and is considering several options to enhance the company's security posture.
Which of the following options would be the MOST effective in preventing and detecting future data breaches?
Increasing the budget for the IT department to purchase more advanced security software.
Implementing a dedicated Computer Incident Response Team (CIRT).
Hiring an external cybersecurity firm to conduct regular penetration testing.
Conducting regular cybersecurity training for all employees.
Implementing a dedicated Computer Incident Response Team (CIRT).
Which of the following are often identified as the three main goals of security? (Select three.)
Employees
Assets
Availability
Non-repudiation
Integrity
Policies
Confidentiality
Availability, Integrity, and Confidentiality
A company finds that employees are accessing streaming websites that are not being monitored for malware or viruses.
Which type of control can the network administrator implement to protect the system and keep the employees from viewing unapproved sites?
Corrective
Technical
Detective
Operational
Technical
Which of the following is an example of a preventative control type?
Intrusion detection systems
Network monitoring applications
Real-time monitoring alerts
An advanced network appliance
An advanced network appliance
After a recent server outage, the company discovered that an employee accidentally unplugged the power cable from the server while grabbing some office supplies from the nearby shelf.
What security control did the company lack that led to the server outage?
Operational
Managerial
Technical
Physical
Physical
An acceptable use policy requires the system to encrypt confidential information while in transit. All employees must use secure email when exchanging proprietary information with external vendors.
Which of the following describes this type of acceptable use policy?
Technical
Preventive
Operational
Managerial
Operational
Which type of control makes use of policies, DRPs, and BCPs?
Preventative
Technical
Managerial
Operational
Managerial
The security operations manager of a multinational corporation focuses on enhancing directive operational controls.
Which of the following should the manager implement?
answer
Regular vulnerability assessments using automated tools.
User awareness and training programs.
Firewall to block unauthorized network traffic.
Surveillance cameras installed around the premises.
User awareness and training programs.
Which type of control is used to discourage malicious actors from attempting to breach a network?
Preventative
Physical
Deterrent
Detective
Deterrent
The chief security officer (CSO) at a financial organization wants to implement additional detective security controls.
Which of the following would BEST represent this type of control?
Implementation of biometric authentication systems.
Performing regular system backups.
Enforcement of access control mechanisms.
Installation of surveillance camera.
Installation of surveillance camera.
A company moved its office supplies to another room and instituted a new security system for entry. The company implemented this after a recent server outage.
What category of security control BEST describes the function of this recent implementation?
Operational
Detective
Corrective
Preventive
Corrective
Which of the following BEST describes compensating controls?
Partial control solution that is implemented when a control cannot fully meet a requirement.
Discourages malicious actors from attempting to breach a network.
Attempts to fix any controls that aren't working properly.
Monitors network activity and informs the security team of a potential security event.
Partial control solution that is implemented when a control cannot fully meet a requirement.
Which of the following terms means a cryptography mechanism that hides secret communications within various forms of data?
Steganography
Ciphertext
Algorithm
Cryptanalysis
Steganography
Which of the following cryptographic attacks uses SSL exploitation as a common implementation of this attack?
Dictionary attack
Birthday attack
Collision attack
Downgrade attack
Downgrade attack
Which of the following types of encryption is specifically designed to allow data to be worked on without decrypting it first?
Homomorphic encryption
Block cipher
Lightweight cryptography
Stream cipher
Homomorphic encryption
There are several block cipher modes of operation that can be utilized depending on the application or use.
Which of the following block cipher modes of operation uses a nonce combined with a counter that is encrypted?
Cipher Block Chaining (CBC)
Cipher Feedback Mode (CFB)
Electronic Code Book (ECB)
Counter Mode (CTR)
Counter Mode (CTR)
Blockchain is a unique and increasingly popular implementation of cryptography. A blockchain is a decentralized and distributed ledger that records and verifies transactions between two parties.
The list on the left describes each step a block goes through as part of the blockchain cryptographic process.
From the list on the left, drag a description to its proper step order on the right.
Step 1
User1 requests a transaction with User2.
Step 2
The transaction is represented online as a block.
Step 3
The block is distributed to everyone on a peer-to-peer network.
Step 4
The network users verify the transaction is valid.
Step 5
The block is added to the chain.
Step 6
The contents of the transaction move to User2.
Which of the following encryption mechanisms offers the least security because of weak keys?
DES
TwoFish
IDEA
AES
DES
Which of the following algorithms are used in symmetric encryption? (Select two.)
RSA
DES
Diffie-Hellman
ECC
Blowfish
DES, Blowfish
Above all else, what must be protected to maintain the security and benefit of an asymmetric cryptographic solution, especially if it is widely used for digital certificates?
Hash values
Private keys
Cryptographic algorithm
Public keys
Private keys
Mary wants to send a message to Sam in such a way that only Sam can read it.
Which key should be used to encrypt the message?
Sam's public key
Mary's public key
Mary's private key
Sam's private key
Sam's public key
Which of the following algorithms are used in asymmetric encryption? (Select two.)
Twofish
AES
Diffie-Hellman
RSA
Blowfish
Diffie-Hellman, RSA
A cyber security analyst wants to reduce the attack surface for a computer that contains top secret data. The analyst installs a cryptoprocessor as a module within the central processing unit (CPU) on the designated computer to accomplish this.
What type of cryptoprocessor is the analyst installing?
CRLs
PKI
HSM
TPM
TPM
Which of the following functions are performed by a TPM?
Create a hash of system components
Perform bulk encryption
Provide authentication credentials
Encrypt network data using IPsec
Create a hash of system components
What is the main function of a TPM hardware chip?
Control access to removable media
Generate and store cryptographic keys
Perform bulk encryption in a hardware processor
Provide authentication credentials on a hardware device
Generate and store cryptographic keys
Combining encryption with steganography involves several steps.
From the list on the left, drag a description of a step or result in this process to the correct order on the right.
Step 1
Encrypt plaintext with a private key to generate ciphertext.
Step 2
The ciphertext is hidden inside of a media file, such as an image, using steganography.
Step 3
The recipient extracts the ciphertext and decrypts it using the matching public key.
Step 4
Anyone intercepting the message would have to know its there before being able to decrypt it.
As a cybersecurity expert, you are tasked with implementing a secure enclave in your company's new mobile banking application.
Which of the following statements best describes the primary function and benefit of a secure enclave in this context?
A secure enclave is a cloud-based storage system where encrypted data is stored and can only be accessed with the correct decryption key.
A secure enclave is a network security tool that monitors and controls incoming and outgoing network traffic based on predetermined security rules.
A secure enclave is a protected area within the application's code that prevents users from making unauthorized transactions.
A secure enclave is a separate, isolated environment within the device's processor where sensitive data can be securely stored and processed.
A secure enclave is a separate, isolated environment within the device's processor where sensitive data can be securely stored and processed.
You are a cybersecurity architect at a tech company that is developing a new mobile payment application. The application will handle sensitive user data including credit card information and personal identification numbers (PINs).
Which of the following strategies would best leverage the concept of secure enclaves to protect this sensitive data?
You decide to store all sensitive data in a secure enclave on the company's main server, accessible only by senior IT staff.
You decide to store all sensitive data in a secure enclave on each user's device, accessible only with the user's unique PIN.
You decide to store all sensitive data in a secure enclave within the application, accessible only through a secure API.
You decide to store all sensitive data in a secure enclave within the application, accessible to all application users.
You decide to store all sensitive data in a secure enclave on each user's device, accessible only with the user's unique PIN.
You are a cybersecurity analyst at a large corporation. Your team has been tasked with securing sensitive data within the company's database. One of the strategies you are considering is obfuscation.
Which of the following scenarios would be the most appropriate application of obfuscation?
You use obfuscation to hide the company's financial data within an image file on the company's public website.
You use obfuscation to hide employee personal data within a database field by substituting character strings with x.
You use obfuscation to hide the company's network architecture within a PDF document.
You use obfuscation to hide the source code of the company's proprietary software within a text document.
You use obfuscation to hide employee personal data within a database field by substituting character strings with x.
A cyber technician reduces a computer's attack surface by installing a cryptoprocessor that a plug-in PCIe adaptor card can remove.
What type of cryptoprocessor can support this requirement?
TPM
CRL
HSM
PKI
HSM
You are a cybersecurity manager at a financial institution. Your team is responsible for managing the cryptographic keys used for secure transactions.
Recently, there has been an increase in attempted cyber attacks on your institution.
Which of the following key management strategies would be MOST effective in maintaining the security of your cryptographic keys under these circumstances?
You decide to centralize key generation and storage, moving all keys to a single server for easier management.
You decide to generate new keys for each transaction, but keep the old keys stored in the system for future reference.
You decide to revoke all current keys and generate new ones, informing all users to update their keys immediately.
You decide to set an expiration date for all current keys and inform users that they will need to renew their keys after this date.
You decide to set an expiration date for all current keys and inform users that they will need to renew their keys after this date.
Which form of cryptography is BEST suited for bulk encryption because it is so fast?
Public key cryptography
Symmetric key cryptography
Hashing cryptography
Asymmetric cryptography
Symmetric key cryptography
Which of the following is no longer valid for security purposes?
MD5
AES
SHA-1
DES
MD5
You are a security analyst at a large corporation. The corporation is implementing a new system that requires secure logon credential exchange between different departments.
The corporation decides to use a cryptographic hashing algorithm for this purpose.
Which of the following scenarios best demonstrates the correct use of hashing for secure logon credential exchange?
Each department shares their passwords with each other...
Each department calculates a hash of their password and sends the actual password along with the hash to the other departments.
Each department sends their password to the other departments...
Each department calculates a hash of their password and sends it to the other departments.
Each department calculates a hash of their password and sends it to the other departments.
What is the process of adding random characters at the beginning or end of a password to generate a completely different hash called?
Collision
Deterministic
Avalanche
Salting
Salting
What is the primary use of the RACE Integrity Primitives Evaluation Message Digest (RIPEMD)?
It is primarily used for file compression.
It is primarily used for email encryption.
It is primarily used for creating digital watermarks.
It is primarily used in Bitcoin and other cryptocurrencies.
It is primarily used in Bitcoin and other cryptocurrencies.
An attacker is attempting to crack a system's password by matching the password hash to a hash in a large table of hashes he or she has.
Which type of attack is the attacker using?
Cracking
Rainbow
Brute force
RIPEMD
Rainbow
Which of the following is a message authentication code that allows a user to verify that a file or message is legitimate?
SHA
HMAC
RIPEMD
MD5
HMAC
You have just downloaded a file. You create a hash of the file and compare it to the hash posted on the website. The two hashes match.
What do you know about the file?
No one has read the file contents as it was downloaded.
Your copy is the same as the copy posted on the website.
You can prove the source of the file.
You are the only one able to open the downloaded file.
Your copy is the same as the copy posted on the website.
Which of the following is used to verify that a downloaded file has not been altered?
Symmetric encryption
Asymmetric encryption
Hash
Private key
Hash
Hashing algorithms are used to perform which of the following activities?
Providing for non-repudiation.
Creating a message digest.
Providing a means for exchanging small amounts of data securely over a public network.
Encrypting bulk data for communications exchange.
Creating a message digest.
When two different messages produce the same hash value, what has occurred?
Collision
Hash value
Birthday attack
High amplification
Collision
You have transferred an encrypted file across a network using the Server Message Block (SMB) Protocol.
What happens to the file's encryption?
The encryption carries over to the new location.
The encryption inherits from the new location.
The file is unencrypted when moved.
An encrypted file cannot be moved using SMB.
The file is unencrypted when moved.
Which of the following database encryption methods encrypts the entire database and all backups?
Application-level
Bitlocker
Column-level
Transparent Data Encryption (TDE)
Transparent Data Encryption (TDE)
You want to protect data on hard drives for users with laptops. You want the drive to be encrypted, and you want to prevent the laptops from booting unless a special USB drive is inserted. In addition, the system should not boot if a change is detected in any of the boot files.
What should you do?
Implement BitLocker without a TPM.
Have each user encrypt the entire volume with EFS.
Implement BitLocker with a TPM.
Have each user encrypt user files with EFS.
Implement BitLocker with a TPM.
You would like to implement BitLocker to encrypt data on a hard disk, even if it is moved to another system. You want the system to boot automatically without providing a startup key on an external USB device.
What should you do?
Enable the TPM in the BIOS.
Save the startup key to the boot partition.
Use a PIN instead of a startup key.
Disable USB devices in the BIOS.
Enable the TPM in the BIOS.
Which utility would you MOST likely use on OS X to encrypt and decrypt data and messages?
GPG
VPN
PGP
IPsec
GPG
You've used BitLocker to implement full volume encryption on a notebook system. The notebook motherboard does not have a TPM chip, so you've used an external USB flash drive to store the BitLocker startup key.
You use EFS to encrypt the C:\Secrets folder and its contents.
Which of the following is true in this scenario? (Select two.)
Any user who is able to boot the computer from the encrypted hard disk will be able to open the C:\Secrets\confidential.docx file.
If the C:\Secrets\confidential.docx file is copied to an external USB flash drive, the file will be saved in an unencrypted state.
If the C:\Secrets\confidential.docx file is copied to an external USB flash drive, the file will remain in an encrypted state.
The EFS encryption process will fail.
By default, only the user who encrypted the C:\Secrets\confidential.docx file will be able to open it.
If the C:\Secrets\confidential.docx file is copied to an external USB flash drive, the file will be saved in an unencrypted state.
By default, only the user who encrypted the C:\Secrets\confidential.docx file will be able to open it.
Which of the following security solutions would prevent a user from reading a file that they did not create?
IPsec
VPN
Bitlocker
EFS
EFS
You want a security solution that protects the entire hard drive and prevents access even if the drive is moved to another system.
Which solution should you choose?
VPN
EFS
IPsec
BitLocker
BitLocker
Which of the following should you set up to ensure encrypted files can still be decrypted if the original user account becomes corrupted?
GPG
VPN
PGP
DRA
DRA
You create a new document and save it to a hard drive on a file server on your company's network. Then you employ an encryption tool to encrypt the file using AES.
This activity is an example of accomplishing which security goal?
Confidentiality
Availability
Integrity
Non-repudiation
Confidentiality
In the process of obtaining a digital certificate, which entity may a certificate authority rely on to perform the validation of the certificate signing request (CSR)?
Certificate revocation list
Registration authority
Root authority
Online Certificate Status Protocol
Registration authority
A PKI is an implementation for managing which type of encryption?
Hashing
Symmetric
Steganography
Asymmetric
Asymmetric
Which technology was developed to help improve the efficiency and reliability of checking the validity status of certificates in large, complex environments?
Online Certificate Status Protocol
Certificate revocation list
Key escrow
Private key recovery
Online Certificate Status Protocol
Which of the following would require that a certificate be placed on the CRL?
The encryption key algorithm is revealed.
The private key is compromised.
The certificate validity period is exceeded.
The signature key size is revealed.
The private key is compromised.
An SSL client has determined that the certificate authority (CA) issuing a server's certificate is on its list of trusted CAs.
What is the next step in verifying the server's identity?
The CA's public key validates the CA's digital signature on the server certificate.
The master secret is generated from common key code.
The post-master secret must initiate subsequent communication.
The domain on the server certificate must match the CA's domain name.
The CA's public key validates the CA's digital signature on the server certificate.
The network administrator for an international e-commerce company that operates multiple online stores must ensure secure communication across various subdomains.
To streamline secure sockets layer/transport layer security (SSL/TLS) certificate management and implement a robust public key infrastructure (PKI), the network administrator must identify the most suitable solution for efficiently securing the company's numerous subdomains within the PKI.
What is the MOST suitable solution for efficiently securing the multiple subdomains of the company's online stores within the PKI?
Certificate revocation lists (CRLs)
Self-signed certificates
Certificate pinning
Wildcard certificates
Wildcard certificates
A medium-sized e-commerce company is planning to upgrade their website's security by acquiring a certificate from a certificate authority (CA).
The company wants to ensure that the certificate not only validates their domain ownership but also verifies the legitimacy of their organization. They are also looking for a validation process that can be completed within 1 to 3 days.
As the IT manager for the company, which level of CA validation would you recommend?
Extended validation
Organization validation
Domain validation
Self-signed certificate
Organization validation
Which of the following statements accurately describes the root of trust model in a public key infrastructure (PKI)?
In the root of trust model, the root certificate is issued by a third-party CA, not the organization's own CA.
The root of trust model involves multiple root certificates, each issued by a different certificate authority (CA).
The root of trust model defines how users and different CAs can trust one another, with each CA issuing itself a root certificate.
The root of trust model involves a root certificate that is issued by a user, not a CA.
The root of trust model defines how users and different CAs can trust one another, with each CA issuing itself a root certificate.
You are concerned that if a private key is lost, all documents encrypted with your private key will be inaccessible.
Which service should you use to solve this problem?
Key escrow
OCSP
CSP
RA
Key escrow
A private key has been stolen. Which action should you take to deal with this crisis?
Recover the private key from escrow
Place the private key in escrow
Delete the public key
Add the digital certificate to the CRL
Add the digital certificate to the CRL
Which of the following is an example of rule-based access control?
A member of the accounting team that is given access to the accounting department documents.
A subject with a government clearance that allows access to government classification labels of Confidential, Secret, and Top Secret.
Router access control lists that allow or deny traffic based on the characteristics of an IP packet.
A computer file owner who grants access to the file by adding other users to an access control list.
Router access control lists that allow or deny traffic based on the characteristics of an IP packet.
You have implemented an access control method that only allows users who are managers to access specific data.
Which type of access control model is being used?
Role-based access control (RBAC)
Discretionary access control list (DACL)
Mandatory access control (MAC)
Discretionary access control (DAC)
Role-based access control (RBAC)
You have a system that allows the owner of a file to identify users and their permissions to the file.
Which type of access control model is implemented?
Mandatory access control (MAC)
Discretionary access control (DAC)
Role-based access control (RBAC)
Rule-based access control
Discretionary access control (DAC)
Which access control model is based on assigning attributes to objects and using Boolean logic to grant access based on the attributes of the subject?
Mandatory access control (MAC)
Rule-based access control
Attribute-based access control (ABAC)
Role-based access control (RBAC)
Attribute-based access control (ABAC)
You are a cybersecurity expert implementing a zero trust model in a large organization. You are tasked with designing the control and data planes.
Which of the following strategies should you prioritize and why?
Balance your focus between the control and data planes, ensuring both are optimized for security and efficiency.
Prioritize the data plane to ensure that data traffic flows securely and efficiently across the network.
Neither, focus on the application plane to ensure that applications are secure and function properly.
Focus on the control plane to ensure that all network devices are properly configured and managed.
Balance your focus between the control and data planes, ensuring both are optimized for security and efficiency.
After implementing the National Institute of Standards and Technology (NIST) Cybersecurity Framework, the chief information security officer (CISO) is assessing the company's security posture to identify deficiencies from the framework's recommendations.
What process can the CISO run to get a better sense of what the company needs to improve upon?
Implement disaster recovery plan
Implement business continuity plan
Penetration test
Gap analysis
Gap analysis
A corporation's IT department is integrating a new framework that permits, ascertains, and applies various resources in accordance with established company policies.
Which principle should the department incorporate?
Zero trust
AAA
Policy-driven access control
Authorization models
Policy-driven access control
An organization's IT department wants to implement a security model responsible for verifying user identities, determining access rights, and monitoring activities within a system.
Which concept is MOST appropriate for the department to implement?
AAA
RBAC
Zero trust
Policy engine
AAA
Which of the following principles is implemented in a mandatory access control model to determine object access by classification level?
Need to know
Clearance
Principle of least privilege
Separation of duties
Ownership
Need to know
You want to implement an access control list in which only the users you specifically authorize have access to the resource. Anyone not on the list should be prevented from having access.
Which of the following methods of access control should the access list use?
Implicit allow, implicit deny
Implicit allow, explicit deny
Explicit allow, implicit deny
Explicit allow, explicit deny
Explicit allow, implicit deny
You are a security consultant tasked with implementing a biometric authentication system for a small business. The business owner wants a system that is cost-effective, non-intrusive, and relatively simple for employees to use.
Which biometric authentication method would you recommend?
Facial recognition
Retina scanning
Vein recognition
Iris recognition
Fingerprint recognition
Fingerprint recognition
Which of the following defines the crossover error rate for evaluating biometric systems?
The point where the number of false positives matches the number of false negatives in a biometric system.
The rate of people who are given access when they should be denied access.
The rate of people who are denied access when they should be allowed access.
The number of subjects or authentication attempts that can be validated.
The point where the number of false positives matches the number of false negatives in a biometric system.
After finding a corporate phone unattended in a local mall, an organization decides to enhance its multi-factor authentication (MFA) procedures.
What MFA philosophy applies a location-based factor for authentication?
Somewhere you are
Something you have
Something you are
Something you know
Somewhere you are
The IT security team at a large tech company is strengthening its authentication methods to protect sensitive company data and systems. The team considered implementing various security measures and understood that each authentication method has distinct features and benefits.
However, they must choose the MOST suitable option that aligns with the organization's security requirements and user convenience.
Which authentication method utilizes a physical device or software to generate secure, unique codes and offers convenience and strong security?
Soft authentication tokens
Hard authentication tokens
Biometric authentication
Security keys
Security keys
A leading online retail company wants to improve user experience and security for its customers. The security team aims to eliminate the need for users to remember or input complex passwords, reducing the risk of password breaches.
Instead, they propose a solution where users can access their accounts seamlessly through a secure link sent to their verified email or via a push notification on a trusted device. This approach should not involve traditional passwords, fingerprint scans, or multiple validation steps.
Which authentication method is the security team planning to implement for users?
Multi-factor authentication
Biometric authentication
Attestation
Passwordless authentication
Passwordless authentication
You are a network administrator for a large multinational corporation. The corporation has offices in multiple countries and uses various software products from different vendors.
The CEO wants to implement a system that stores information about users, computers, security groups/roles, and services, and allows for interoperability between different vendors' products.
Which directory service would you recommend?
Novell Directory Services (NDS)
Lightweight Directory Access Protocol (LDAP)
Active Directory
X.500
Lightweight Directory Access Protocol (LDAP)
Your financial planning company is forming a partnership with a real estate property management company. One of the requirements is that your company open up its directory services to the property management company to create and access user accounts.
Which of the following authentication methods will you be implementing?
Federation
Single sign-on
Directory services
Attestation
Federation
Which of the following is the MOST common form of authentication?
Password
Fingerprint
Digital certificate on a smart card
Photo ID
Password
Which of the following identification and authentication factors are often well known or easily discovered by others on the same network or system?
Username
Biometric reference profile
Password
PGP secret key
Username
Which of the following are examples of something you have authentication controls? (Select two.)
Photo ID
Smart card
Cognitive question
Handwriting analysis
Voice recognition
PIN
Photo ID, Smart Card
The IT department at a large corporation noticed an unfamiliar software application running on its network. Upon investigation, they discovered that a team in the marketing department started using a new cloud-based project management tool to improve their workflow efficiency.
The team did not consult with the IT department before implementing this tool.
In the context of cybersecurity threats, what does this situation BEST exemplify?
Nation-state
Insider threat
Careless password management
Shadow IT
Shadow IT
A multinational corporation recently fell victim to a series of cyberattacks, disrupting services and leading to significant financial losses. After an investigation, the corporation found that these attacks were part of a systematic campaign to undermine the corporation's market position.
The highly sophisticated attacks suggest the involvement of a well-resourced entity with specific strategic objectives.
Which of the following motivations BEST describes this scenario?
Political
Revenge
Financial
Chaotic
Political
Which type of threat actor is MOST likely to engage in cyber espionage with strategic or political motivations?
Nation-state
Hacktivist
Organized crime
Competitors
Nation-state
The IT manager in your organization proposes taking steps to deflect a potential threat actor. The proposal includes the following:
- Create and follow onboarding and off-boarding procedures.
- Employ the principal of least privilege.
- Have appropriate physical security controls in place.
Which type of threat actor do these steps guard against?
Script kiddie
Hacktivist
Competitor
Insider
Insider
A prominent multinational corporation has experienced an unexpected spike in unauthorized network traffic aimed at its web servers. Upon investigation, the corporation discovered that the goal of this traffic was to disrupt its online services rather than gain unauthorized access or steal data.
The attack started shortly after the corporation made a controversial policy decision that sparked a public backlash.
Which type of threat actor is MOST likely responsible?
Individual hacker
Insider threat
Hacktivist
Nation-state
Hacktivist
In which phase of an attack does the attacker gather information about the target?
Breach the system
Escalating privileges
Reconnaissance
Exploit the system
Reconnaissance
Match the general attack strategy on the left with the appropriate description on the right. (Each attack strategy may be used once, more than once, or not all.)
Stealing information. = Exploitation
Preparing a computer to perform additional tasks in the attack. = Staging
Crashing systems. = Exploitation
Gathering system hardware information. = Reconnaissance
Penetrating system defenses to gain unauthorized access. = Breaching
Configuring additional rights to do more than breach the system. = Escalating privileges
As a cybersecurity analyst, you are tasked with reducing the supply chain attack surface in your organization.
Which of the following areas should you focus on to MOST effectively mitigate this risk?
Internal IT infrastructure
Customer data protection
Employee training
Vendor management
Vendor management
A group of hackers has been monitoring recent orders from a company involving new laptops and Universal Serial Bus (USB) thumb drives. The group infiltrated the shipping company and added malicious USB thumb drives to the order. The target company received the order without any concerns.
What vectors made this attack successful? (Select two.)
Social media
Cloud access
Supply chain
Direct access
Removable media
Supply Chain, Removable media
CloudSecure is facing a cybersecurity challenge where some of its critical software applications are no longer supported by vendors, making them vulnerable to potential exploits. The IT team is exploring various strategies to mitigate the risk posed by these unsupported apps.
What is the MOST effective approach to enhance the security posture?
Consolidating all operating systems and applications into one product.
Implementing regular patch management to fix the faulty code.
Isolating the unsupported apps from other systems to reduce the attack surface.
Ignoring the vulnerability as it can only be exploited in specific circumstances.
Isolating the unsupported apps from other systems to reduce the attack surface.