A security architect must make sure that the least number of services as possible is exposed in order to limit an adversary's ability to access the systems. Which of the following should the architect do first?
A. Enforce Secure Boot.
B. Perform attack surface reduction.
C. Disable third-party integrations.
D. Limit access to the systems.
Show Answer
Correct Answer: B
Explanation: Attack surface reduction minimizes exposed services, ports, and other entry points, limiting opportunities for an adversary to access the systems.
Question 172
A global organization wants to manage all endpoint and user telemetry. The organization also needs to differentiate this data based on which office it is correlated to. Which of the following strategies best aligns with this goal?
A. Sensor placement
B. Data labeling
C. Continuous monitoring
D. Centralized logging
Show Answer
Correct Answer: B
Explanation: Data labeling adds metadata—such as the associated office—to endpoint and user telemetry, allowing the organization to distinguish and manage records by office. Centralized logging gathers data in one place but does not, by itself, identify which office the data relates to.
Question 173
A company notices that cloud environment costs increased after using a new serverless solution based on API requests. Many invalid requests from unknown IPs were found, often within a short time. Which of the following solutions would most likely solve this issue, reduce cost, and improve security?
A. Using digital certificates for known customers and performing API authorization through those certificates
B. Defining request rate limits and comparing new requests from unknown IPs with a list of known-malicious IPs
C. Setting authentication processes for the API requests as well as proper rate limits according to regular usage
D. Only allowing API requests coming from regions with known customers
Show Answer
Correct Answer: C
Explanation: API authentication helps reject unauthorized requests, while rate limits constrain request bursts and reduce serverless invocation costs. The limits should be set to match normal usage. IP allowlists or malicious-IP lists alone may miss attackers or block legitimate users.
Question 174
A security engineer is reviewing the following vulnerability scan report:
Which of the following should the engineer prioritize for remediation?
A. Apache HTTP Server
B. OpenSSH
C. Google Chrome
D. Migration to TLS 1.3
Show Answer
Correct Answer: B
Explanation: Prioritize OpenSSH if the scan identifies it as the highest-risk, remotely exploitable issue on an internet-facing system. Its exposure can enable direct compromise, making it more urgent than Chrome or a general TLS 1.3 migration; remediation should ultimately be guided by the report’s severity and asset exposure.
Question 175
An organization decides to move to a distributed workforce model. Several legacy systems exist on premises and cannot be migrated because of existing compliance requirements. However, all new systems are required to be cloud-based. Which of the following would best ensure network access security?
A. Utilizing a VPN for all users who require legacy system access
B. Shifting all legacy systems to the existing public cloud infrastructure
C. Configuring an SDN to block malicious traffic to on-premises networks
D. Deploying microsegmentation with a firewall acting as the core router
Show Answer
Correct Answer: A
Explanation: A VPN provides remote users with an encrypted, authenticated connection to the on-premises legacy systems while allowing new systems to remain cloud-based. The other options either conflict with the compliance requirement or do not provide secure remote access.
Question 176
An organization plans to deploy new software. The project manager compiles a list of roles that will be involved in different phases of the deployment life cycle. Which of the following should the project manager use to track these roles?
A. CMDB
B. Recall tree
C. ITIL
D. RACI matrix
Show Answer
Correct Answer: D
Explanation: A RACI matrix tracks who is Responsible, Accountable, Consulted, and Informed for tasks or phases of the deployment life cycle.
Question 177
A company receives reports about misconfigurations and vulnerabilities in a third-party hardware device that is part of its released products. Which of the following solutions is the best way for the company to identify possible issues at an earlier stage?
A. Performing vulnerability tests on each device delivered by the providers
B. Performing regular red-team exercises on the vendor production line
C. Implementing a monitoring process for the integration between the application and the vendor appliance
D. Implementing a proper supply chain risk management program
Show Answer
Correct Answer: D
Explanation: A supply chain risk management program assesses and manages risks from vendors and third-party components earlier in the product lifecycle, helping identify potential hardware vulnerabilities and misconfigurations before release.
Question 178
A security architect is implementing a SOAR solution in an organization’s cloud production environment to support detection capabilities. Which of the following will be the most likely benefit?
A. Improved security operations center performance
B. Automated firewall log collection tasks
C. Optimized cloud resource utilization
D. Increased risk visibility
Show Answer
Correct Answer: A
Explanation: SOAR automates and orchestrates security workflows, helping analysts respond more efficiently and improving overall SOC performance. Log collection is more typically a SIEM function, while cloud resource utilization is unrelated.
Question 179
A security engineer receives an alert from the SIEM platform indicating a possible malicious action on the internal network. The engineer generates a report that outputs the logs associated with the incident:
Which of the following actions best enables the engineer to investigate further?
A. Consulting logs from the enterprise password manager
B. Searching dark web monitoring resources for exposure
C. Reviewing audit logs from privileged actions
D. Querying user behavior analytics data
Show Answer
Correct Answer: D
Explanation: Querying user behavior analytics data can reveal whether the activity fits a broader suspicious pattern for the account or device, helping the engineer investigate the SIEM alert further.
Question 180
Emails that the marketing department is sending to customers are going to the customers’ spam folders. The security team is investigating the issue and discovers that the certificates used by the email server were reissued, but DNS records had not been updated. Which of the following should the security team update in order to fix this issue? (Choose three.)
A. DMARC
B. SPF
C. DKIM
D. DNSSEC
E. SASE
F. SAN
G. SOA
H. MX
Show Answer
Correct Answer: A, B, C
Explanation: Update the email-authentication DNS records: SPF authorizes the sending servers, DKIM publishes the public key used to verify message signatures, and DMARC specifies how receiving servers handle messages that fail SPF or DKIM checks. MX records route incoming mail and are not the relevant authentication records here.
$19
Get all 400 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.