An organization receives OSINT reports about an increase in ransomware targeting fileshares at peer companies. The organization wants to deploy hardening policies to its servers and workstations in order to contain potential ransomware. Which of the following should an engineer do to best achieve this goal?
A. Allow only interactive log-in for users on workstations and restrict port 445 traffic to fileshares.
B. Enable biometric authentication mechanisms on user workstations and block port 53 traffic.
C. Instruct users to use a password manager when generating new credentials and secure port 443 traffic.
D. Give users permission to rotate administrator passwords and deny port 80 traffic.
Show Answer
Correct Answer: A
Explanation: Restricting port 445 (SMB) traffic to authorized fileshares limits ransomware’s ability to spread through network file shares. Allowing only interactive logins on workstations also helps reduce remote logon-based lateral movement.
Question 182
A security operations engineer needs to prevent inadvertent data disclosure when encrypted SSDs are reused within an enterprise. Which of the following is the most secure way to achieve this goal?
A. Executing a script that deletes and overwrites all data on the SSD three times
B. Wiping the SSD through degaussing
C. Securely deleting the encryption keys used by the SSD
D. Writing non-zero, random data to all cells of the SSD
Show Answer
Correct Answer: C
Explanation: Securely deleting the encryption keys renders the encrypted data unreadable, providing cryptographic erasure. Repeated overwrites may miss SSD cells because of wear leveling, and degaussing is ineffective on flash storage.
Question 183
A financial services organization is using AI to fully automate the process of deciding client loan rates. Which of the following should the organization be most concerned about from a regulatory perspective?
A. Model explain ability
B. Credential theft
C. Possible prompt injections
D. Exposure to social engineering
Show Answer
Correct Answer: A
Explanation: Automated loan-rate decisions are subject to regulatory scrutiny, including requirements to explain how decisions were made and ensure they are fair and non-discriminatory. Model explainability is therefore the primary regulatory concern among the options.
Question 184
A company wants to implement a three-tier approach to separate the web, database, and application servers. A security administrator must harden the environment. Which of the following is the best solution?
A. Deploying a VPN to prevent remote locations from accessing server VLANs
B. Configuring a SASE solution to restrict users to server communication
C. Implementing microsegmentation on the server VLANs
D. Installing a firewall and making it the network core
Show Answer
Correct Answer: C
Explanation: Microsegmentation enforces granular, least-privilege controls between server workloads, helping isolate the web, application, and database tiers and limit lateral movement. A VPN or SASE solution primarily addresses access from users or remote locations, while making a firewall the network core is less targeted than segmenting communication between the tiers.
Question 185
A cloud engineer needs to identify appropriate solutions to:
• Provide secure access to internal and external cloud resources.
• Eliminate split-tunnel traffic flows.
• Enable identity and access management capabilities.
Which of the following solutions is the most appropriate?
A. Microsegmentation
B. PAM
C. SD-WAN
D. SASE
Show Answer
Correct Answer: D
Explanation: SASE combines cloud-delivered networking and security to provide secure access to internal and external resources, integrate identity-based access controls, and route traffic through the security stack rather than using split tunneling.
Question 186
A security analyst detects a possible RAT infection on a computer in the internal network. After reviewing the details of the alert, the analyst identifies the initial vector of the attack was an email that was forwarded to multiple recipients in the same organizational unit. Which of the following should the analyst do first to minimize this type of threat in the future?
A. Move from an anti-malware software to an EDR solution.
B. Perform a penetration test to detect technology gaps on the anti-spam solution.
C. Configure an IPS solution in the internal network to mitigate infections.
D. Implement a security awareness program in the organization.
Show Answer
Correct Answer: D
Explanation: The infection spread through an email forwarded to coworkers, so a security awareness program is the best first step to help users recognize suspicious messages and avoid forwarding or opening them. The other options may provide additional technical defenses, but they do not address the user behavior identified in the alert.
Question 187
A software vendor provides routine functionality and security updates to its global customer base. The vendor would like to ensure distributed updates are authorized, originate from only the company, and have not been modified by others. Which of the following solutions best supports these objectives?
A. Envelope encryption
B. File integrity monitoring
C. Application control
D. Code signing
Show Answer
Correct Answer: D
Explanation: Code signing uses the vendor’s digital signature to let customers verify that an update came from the vendor and has not been altered. This supports authorization and integrity checks before installation.
Question 188
A manufacturing plant is updating its IT services. During discussions, the senior management team created the following list of considerations:
• Staff turnover is high and seasonal.
• Extreme conditions often damage endpoints.
• Losses from downtime must be minimized.
• Regulatory data retention requirements exist.
Which of the following best addresses the considerations?
A. Establishing further environmental controls to limit equipment damage
B. Using a non-persistent virtual desktop interface with thin clients
C. Deploying redundant file servers and configuring database journaling
D. Maintaining an inventory of spare endpoints for rapid deployment
Show Answer
Correct Answer: B
Explanation: Non-persistent VDI with thin clients makes it easier to onboard and offboard seasonal staff, while damaged endpoints can be replaced without losing locally stored data or user environments. Centralized data also makes retention controls easier to manage. The other options address only part of the listed considerations.
Question 189
An organization is concerned about insider threats from employees who have individual access to encrypted material. Which of the following techniques best addresses this issue?
A. SSO with MFA
B. Salting and hashing
C. Account federation with hardware tokens
D. SAE
E. Key splitting
Show Answer
Correct Answer: E
Explanation: Key splitting divides a decryption key into separate parts so that multiple authorized people must cooperate to reconstruct it. This reduces the risk that one employee can independently decrypt sensitive material.
Question 190
A company wants to protect against the most common attacks and rapidly integrate with different programming languages. Which of the following technologies is most likely to meet this need?
A. RASP
B. Cloud-based IDE
C. DAST
D. NIPS
Show Answer
Correct Answer: A
Explanation: RASP runs within an application and can detect and block attacks at runtime, such as injection and cross-site scripting. It can be integrated with applications written in supported programming languages. DAST identifies vulnerabilities but does not typically block attacks in production; a cloud-based IDE and NIPS do not fit the application-level need as well.
$19
Get all 400 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.