A security administrator wants to detect a potential forged sender claim in the envelope of an email. Which of the following should the security administrator implement? (Choose two).
A. MX record
B. DMARC
C. SPF
D. DNSSEC
E. S/MIME
F. TLS
Show Answer
Correct Answer: B, C
Explanation: SPF checks whether the sending server is authorized for the envelope sender’s domain. DMARC uses SPF and DKIM results, along with domain alignment, to detect and address forged sender claims.
Question 142
A security engineer is assessing a legacy server and needs to determine if FTP is running and on which port. The service cannot be turned off, as it would impact a critical application’s ability to function. Which of the following commands would provide the information necessary to create a firewall rule to prevent that service from being exploited?
A. service --status-all | grep ftpd
B. chkconfig --list
C. netstat -tulpn
D. systemctl list-unit-file --type service ftpd
E. service ftpd status
Show Answer
Correct Answer: C
Explanation: `netstat -tulpn` shows listening TCP/UDP ports and the associated process, allowing the engineer to identify the FTP service’s active port for a firewall rule.
Question 143
A cloud security engineer is setting up a cloud-hosted WAF. The engineer needs to implement a solution to protect the multiple websites the organization hosts. The organization websites are:
• www.mycompany.org
• www.mycompany.com
• campus.mycompany.com
• wiki.mycompany.org
The solution must save costs and be able to protect all websites. Users should be able to notify the cloud security engineer of any on-path attacks. Which of the following is the best solution?
A. Purchase one SAN certificate.
B. Implement self-signed certificates.
C. Purchase one certificate for each website.
D. Purchase one wildcard certificate.
Show Answer
Correct Answer: A
Explanation: A single CA-issued SAN certificate can list all four hostnames, including names under both .com and .org, while costing less and being simpler to manage than separate certificates. CA validation also lets users detect certificate identity or trust errors that may indicate an on-path attack. A wildcard certificate for one domain would not cover both domains.
Question 144
A third-party organization has implemented a system that allows it to analyze customers’ data and deliver analysis results without being able to see the raw data. Which of the following is the organization implementing?
A. Asynchronous keys
B. Homomorphic encryption
C. Data lake
D. Machine learning
Show Answer
Correct Answer: B
Explanation: Homomorphic encryption allows computations to be performed on encrypted data, so an organization can analyze the data and return results without seeing the raw, decrypted data.
Question 145
An organization is prioritizing efforts to remediate or mitigate risks identified during the latest assessment. For one of the risks, a full remediation was not possible, but the organization was able to successfully apply mitigations to reduce the likelihood of the impact. Which of the following should the organization perform next?
A. Assess the residual risk.
B. Update the organization’s threat model.
C. Move to the next risk in the register.
D. Recalculate the magnitude of the impact.
Show Answer
Correct Answer: A
Explanation: After applying mitigations, the organization should assess the residual risk—the risk that remains after the controls—to determine whether it is acceptable or needs further treatment.
Question 146
A security team is concerned with attacks that are taking advantage of return-oriented programming against the company’s public-facing applications. Which of the following should the company implement on the public-facing servers?
A. IDS
B. ASLR
C. TPM
D. HSM
Show Answer
Correct Answer: B
Explanation: ASLR randomizes the locations of memory regions, making it harder for an attacker to reliably chain existing code gadgets in a return-oriented programming attack. IDS, TPM, and HSM do not directly mitigate this memory-exploitation technique.
Question 147
A security consultant has been asked to identify a simple, secure solution for a small business with a single access point. A single SSID and no guest access will be used. The customer facility is located in a crowded area of town. The customer has asked that the solution require low administrative overhead. Which of the following should the security consultant recommend?
A. WPA3-Personal
B. WPA2-TKIP
C. WPA2-Enterprise
D. WPA3-Enterprise
Show Answer
Correct Answer: A
Explanation: WPA3-Personal uses SAE for strong password-based authentication and does not require a RADIUS server, so it provides a secure, low-overhead fit for a small business with one SSID and no guest access. WPA2-TKIP is outdated, while the Enterprise options add authentication infrastructure and administration.
Question 148
A security manager is creating a connection between two networks that process data at different classification levels. The main goal of this connection is to pass data from the higher classification side to the lower classification side without causing spillage. Only approved fie types and content will be allowed. Which of the following technologies would best meet this objective?
A. Network access control
B. File integrity monitoring
C. Cross-domain solution
D. Microsegmentation
Show Answer
Correct Answer: C
Explanation: A cross-domain solution (CDS) provides controlled transfer between networks at different classification levels. It can enforce rules that allow only approved file types and content to pass, helping prevent data spillage.
Question 149
A mobile device hardware manufacturer receives the following requirements from a company that wants to produce and sell a new mobile platform:
• The platform should store biometric data.
• The platform should prevent unapproved firmware from being loaded.
• A tamper-resistant, hardware-based counter should track if unapproved firmware was loaded.
Which of the following should the hardware manufacturer implement? (Choose three).
A. ASLR
B. NX
C. eFuse
D. SED
E. SELinux
F. Secure boot
G. Shell restriction
H. Secure enclave
Show Answer
Correct Answer: C, F, H
Explanation: An eFuse can provide a tamper-resistant hardware record or counter for firmware state changes. Secure boot verifies firmware before loading it, preventing unapproved firmware from running. A secure enclave provides isolated hardware protection for storing and processing biometric data.
Question 150
A software development company needs to mitigate third-party risks to its software supply chain. Which of the following techniques should the company use in the development environment to best meet this objective?
A. Performing software composition analysis
B. Requiring multifactor authentication
C. Establishing coding standards and monitoring for compliance
D. Implementing a robust unit and regression-testing scheme
Show Answer
Correct Answer: A
Explanation: Software composition analysis inventories and evaluates third-party libraries and other dependencies, helping identify vulnerable or otherwise risky components in the software supply chain.
$19
Get all 400 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.