A hotel chain wants to use point-of-sale systems to allow customers to check in and out of their rooms without employee assistance. These systems should limit access to a specific set of programs approved to run, with all other programs blocked. Which of the following should the company configure to best support this goal?
A. Application control using a fresh image, with the applications fully configured as a baseline to build and block other applications from execution
B. A host-based intrusion detection system to monitor and block all suspicious activities if they occur on the systems
C. Anti-malware on these systems and only approved application file locations can be bypassed
D. Event logs to be collected from the systems for all security events and some custom application logs
Show Answer
Correct Answer: A
Explanation: Application control (application allowlisting) permits only approved programs to run and blocks all others. A clean, fully configured baseline image provides the approved set of applications for the POS systems.
Question 112
A global company’s Chief Financial Officer (CFO) receives a phone call from someone claiming to be the Chief Executive Officer (CEO). The caller claims to be stranded and in desperate need of money. The CFO is suspicious, but the caller’s voice sounds similar to the CEO’s. Which of the following best describes this type of attack?
A. Smishing
B. Deepfake
C. Automated exploit generation
D. Spear phishing
Show Answer
Correct Answer: B
Explanation: The caller appears to be impersonating the CEO with a voice that sounds similar to theirs, pointing to a voice deepfake. Spear phishing describes targeted deception more broadly, but the voice imitation is the defining clue here.
Question 113
Which of the following is a security concern for DNP3?
A. Free-form messages require support.
B. Available function codes are not standardized.
C. Authentication is not allocated.
D. It is an open source protocol.
Show Answer
Correct Answer: C
Explanation: Traditional DNP3 was not designed with built-in authentication, which can allow unauthorized devices or commands unless additional security measures are used.
Question 114
A security architect examines a section of code and discovers the following:
char username[20]
char password[20]
gets(username)
checkUserExists(username)
Which of the following changes should the security architect require before approving the code for release?
A. Allow only alphanumeric characters for the username.
B. Make the password variable longer to support more secure passwords.
C. Prevent more than 20 characters from being entered.
D. Add a password parameter to the checkUserExists function.
Show Answer
Correct Answer: C
Explanation: `gets()` reads input without checking the destination buffer’s size, so input longer than the `username` array can cause a buffer overflow. Replace it with bounded input (such as `fgets`) and reject or safely handle input that exceeds the buffer’s capacity. A 20-byte array can hold at most 19 characters plus the terminating null byte.
Question 115
An analyst has prepared several possible solutions to a successful attack on the company. The solutions need to be implemented with the least amount of downtime. Which of the following should the analyst perform?
A. Implement all the solutions at once in a virtual lab and then run the attack simulation. Collect the metrics and then choose the best solution based on the metrics.
B. Implement every solution one at a time in a virtual lab, running a metric collection each time. After the collection, run the attack simulation, roll back each solution, and then implement the next. Choose the best solution based on the best metrics.
C. Implement every solution one at a time in a virtual lab, running an attack simulation each time while collecting metrics. Roll back each solution and then implement the next. Choose the best solution based on the best metrics.
D. Implement all the solutions at once in a virtual lab and then collect the metrics. After collection, run the attack simulation. Choose the best solution based on the best metrics.
Show Answer
Correct Answer: C
Explanation: Test each solution separately in the virtual lab by running the attack simulation while collecting metrics. Rolling back before testing the next solution lets the analyst compare each solution’s effectiveness and downtime impact without the results being confounded by other changes.
Question 116
An organization is looking to establish more robust security measures by implementing PKI. Which of the following should the security analyst implement when considering mutual authentication?
A. Perfect forward secrecy on both endpoints
B. Shared secret for both endpoints
C. Public keys on both endpoints
D. A common public key on each endpoint
E. A common private key on each endpoint
Show Answer
Correct Answer: C
Explanation: PKI-based mutual authentication requires each endpoint to present and validate a certificate containing its public key. Each endpoint also proves possession of its corresponding private key; the endpoints do not share a common key.
Question 117
A security architect is analyzing an old application that is not covered for maintenance anymore because the software company is no longer in business. Which of the following techniques should have been implemented to prevent these types of risks?
A. Code reviews
B. Supply chain visibility
C. Software audits
D. Source code escrows
Show Answer
Correct Answer: D
Explanation: Source code escrow places the application’s source code with a trusted third party for release to the customer under agreed conditions, such as the vendor going out of business. This can allow the customer to continue maintaining the application.
Question 118
Based on a recent security audit, a company discovered the perimeter strategy is inadequate for its recent growth. To address this issue, the company is looking for a solution that includes the following requirements:
• Collapse of multiple network security technologies into a single footprint
• Support for multiple VPNs with different security contexts
• Support for application layer security (Layer 7 of the OSI Model)
Which of the following technologies would be the most appropriate solution given these requirements?
A. NAT gateway
B. Reverse proxy
C. NGFW
D. NIDS
Show Answer
Correct Answer: C
Explanation: An NGFW consolidates multiple perimeter security functions in one platform, can support VPNs with separate security contexts, and provides application-layer (Layer 7) inspection and control.
Question 119
A cyberanalyst has been tasked with recovering PDF files from a provided image file. Which of the following is the best file-carving tool for PDF recovery?
A. objdump
B. Strings
C. dd
D. Foremost
Show Answer
Correct Answer: D
Explanation: Foremost is a file-carving tool designed to recover files from disk images by identifying file signatures, including those of PDFs. objdump and strings are analysis utilities, while dd copies raw data rather than carving files.
Question 120
An organization handles sensitive information that must be displayed on call center technicians’ screens to verify the identities of remote callers. The technicians use three randomly selected fields of information to complete the identity verification process. Some of the fields contain PII that are unique identifiers for the remote callers. Which of the following should be implemented to identify remote callers while also reducing the risk that technicians could improperly use the identification information?
A. Data masking
B. Encryption
C. Tokenization
D. Scrubbing
E. Substitution
Show Answer
Correct Answer: A
Explanation: Data masking can hide portions of sensitive identifiers while leaving enough information visible for technicians to verify callers. This reduces exposure of complete PII and the risk of misuse.
$19
Get all 400 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.