Due to an infrastructure optimization plan, a company has moved from a unified architecture to a federated architecture divided by region. Long-term employees now have a better experience, but new employees are experiencing major performance issues when traveling between regions. The company is reviewing the following information:
Which of the following is the most effective action to remediate the issue?
A. Creating a new user entry in the affected region for the affected employee
B. Synchronizing all regions' user identities and ensuring ongoing synchronization
C. Restarting European region physical access control systems
D. Resyncing single sign-on application with connected security appliances
Show Answer
Correct Answer: B
Explanation: In a regionally federated architecture, users need identities synchronized across regions so they can be recognized when traveling. Synchronizing identities and maintaining ongoing synchronization addresses the issue for new employees without requiring manual regional accounts.
Question 102
A security review revealed that not all of the client proxy traffic is being captured. Which of the following architectural changes best enables the capture of traffic for analysis?
A. Adding an additional proxy server to each segmented VLAN
B. Setting up a reverse proxy for client logging at the gateway
C. Configuring a span port on the perimeter firewall to ingest logs
D. Enabling client device logging and system event auditing
Show Answer
Correct Answer: A
Explanation: Adding a proxy server in each segmented VLAN helps ensure clients in every network segment send their proxy traffic through a point where it can be captured and analyzed. A reverse proxy serves inbound requests, while a firewall SPAN port or endpoint auditing does not ensure complete capture of client proxy traffic.
Question 103
An organization recently implemented a policy that requires all passwords to be rotated every 90 days. An administrator sees a large volume of failed sign-on logs from multiple servers that are often accessed by users. The administrator determines users are disconnecting from the RDP session but not logging off. Which of the following should the administrator do to prevent account lockouts?
A. Increase the account lockout threshold
B. Enforce password complexity
C. Automate logout of inactive sessions
D. Extend the allowed session length
Show Answer
Correct Answer: C
Explanation: Automating logout of inactive RDP sessions terminates disconnected sessions that may continue attempting authentication with a password that was changed during the 90-day rotation, preventing repeated failures from causing account lockouts.
Question 104
A security team is responding to malicious activity and needs to determine the scope of impact. The malicious activity appears to affect a certain version of an application used by the organization. Which of the following actions best enables the team to determine the scope of impact?
A. Performing a port scan
B. Inspecting egress network traffic
C. Reviewing the asset inventory
D. Analyzing user behavior
Show Answer
Correct Answer: C
Explanation: Reviewing the asset inventory helps identify which systems run the affected application version, allowing the team to determine the potential scope of impact.
Question 105
A company wants to perform threat modeling on an internally developed, business-critical application. The Chief Information Security Officer (CISO) is most concerned that the application should maintain 99.999% availability and authorized users should only be able to gain access to data they are explicitly authorized to view. Which of the following threat-modeling frameworks directly addresses the CISO’s concerns about this system?
A. CAPEC
B. STRIDE
C. ATT&CK
D. TAXII
Show Answer
Correct Answer: B
Explanation: STRIDE directly covers both concerns: Denial of Service addresses availability, while Elevation of Privilege addresses whether users can gain access beyond their authorization. CAPEC catalogs attack patterns, ATT&CK catalogs adversary tactics and techniques, and TAXII is a threat-intelligence sharing protocol.
Question 106
A global manufacturing company has an internal application that is critical to making products. This application cannot be updated and must be available in the production area. A security architect is implementing security for the application. Which of the following best describes the action the architect should take?
A. Disallow wireless access to the application.
B. Deploy intrusion detection capabilities using a network tap
C. Create an acceptable use policy for the use of the application
D. Create a separate network for users who need access to the application
Show Answer
Correct Answer: D
Explanation: Because the application cannot be updated but must remain operational, the best action is to isolate it from other systems through network segmentation. A separate network limits exposure and reduces the paths an attacker could use to reach it.
Question 107
During a recent audit, a company's systems were assessed Given the following information:
Which of the following is the best way to reduce the attack surface?
A. Deploying an EDR solution to all impacted machines in manufacturing
B. Segmenting the manufacturing network with a firewall and placing the rules in monitor mode
C. Setting up an IDS inline to monitor and detect any threats to the software
D. Implementing an application-aware firewall and writing strict rules for the application access
Show Answer
Correct Answer: D
Explanation: An application-aware firewall with strict access rules limits which applications and services can communicate, reducing exposed paths and therefore the attack surface. EDR and IDS primarily detect threats, while monitor-mode firewall rules do not block traffic.
Question 108
A security analyst received a notification from a cloud service provider regarding an attack detected on a web server. The cloud service provider shared the following information about the attack:
• The attack came from inside the network.
• The attacking source IP was from the internal vulnerability scanners
• The scanner is not configured to target the cloud servers.
Which of the following actions should the security analyst take first?
A. Create an allow list for the vulnerability scanner IPs in order to avoid false positives
B. Configure the scan policy to avoid targeting an out-of-scope host
C. Set network behavior analysis rules.
D. Quarantine the scanner sensor to perform a forensic analysis
Show Answer
Correct Answer: B
Explanation: The scanner is generating traffic toward a cloud server that is out of scope. First correct the scan policy so it excludes that host. Allowlisting the scanner could mask genuine malicious activity, while quarantining it is premature without evidence of compromise.
Question 109
A compliance officer is facilitating a business impact analysis and wants business unit leaders to collect meaningful data. Several business unit leaders want more information about the types of data the officer needs. Which of the following data types would be the most beneficial for the compliance officer? (Choose two.)
A. Inventory details
B. Applicable contract obligations
C. Costs associated with downtime
D. Network diagrams
E. Contingency plans
F. Critical processes
Show Answer
Correct Answer: C, F
Explanation: A business impact analysis identifies critical business processes and assesses the consequences of their disruption, including the costs associated with downtime. Inventory details, network diagrams, and contingency plans are more relevant to other planning activities.
Question 110
An administrator needs to craft a single certificate-signing request for a web-server certificate. The server should be able to use the following identities to mutually authenticate other resources over TLS:
• www.int.comptia.org
• webserver01 .int.comptia.org
• 10.5.100.10
Which of the following certificate fields must be set properly to support this objective?
A. Subject alternative name
B. Organizational unit
C. Extended key usage
D. Certificate extension
Show Answer
Correct Answer: A
Explanation: The Subject Alternative Name (SAN) field can include multiple identities in one certificate, including DNS names and an IP address. The listed hostnames and 10.5.100.10 should be added as SAN entries.
$19
Get all 400 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.