A security analyst is designing a network structure to support a virtual server that is running an unsupported operating system The unsupported operating system contains PII and is business critical. Given the following information:
• The PII server name is legacy-box, and the machine IP is 192.168.1.100.
• The jump-box server name is jump-box with an IP of 192.168.1.10
• The IP address scheme for the corporate network is 192.168.1.0/24
The machines with the following IP addresses need access
• 192.168.1.3
• 192.168.1.4
Which of the following actions should the analyst do to best secure the PII server?
A. Configure jump-box and legacy-box with dual NICs, giving them both virtual network and corporate network IP addresses
B. Modify host firewall rules and routes on legacy-box to permit only 192.168.1.3 and 192.168.1.4 to RDP
C. Set up host firewall rules and routes on jump-box to permit only 192.168.1.3 and 192.168.1.4 to RDP
D. Implement host firewall rules and routes on legacy-box to permit only 192.168.1.0/24 to RDP and deny everything else
Show Answer
Correct Answer: B
Explanation: Restricting RDP on legacy-box to 192.168.1.3 and 192.168.1.4 directly limits access to the PII server. Restricting only jump-box would not prevent other corporate hosts from connecting directly to legacy-box, which is also on the corporate subnet.
Sources:
https://community.cisco.com/t5/network-management/what-is-jump-server-or-jump-box/td-p/4684022
Question 42
During post-incident analysis of a recent website outage, an incident response team identifies the following commands that were run from a compromised internal machine:
Which of the following should the team do?
A. Sinkhole suspicious DNS traffic
B. Implement DKIM
C. Restrict host and dig command executions
D. Prevent successful zone transfers
Show Answer
Correct Answer: D
Explanation: The commands are missing from the question, so the answer cannot be confirmed. If they were `host` or `dig` commands requesting a DNS zone transfer (AXFR), the team should prevent unauthorized zone transfers rather than block those diagnostic tools.
Question 43
A penetration tester reviews the following output:
Which of the following mitigations should the security engineer recommend?
A. Removing domain users from the administrator group on the reporting server
B. Disabling NTLM hash transmission over the network to prevent sniffing
C. Blocking the Kerberos protocol on servers that are shared by many users
D. Implementing password complexity requirements in the domain
Show Answer
Correct Answer: B
Explanation: The output likely indicates NTLM challenge-response credentials are being exposed to network capture. Restricting or disabling NTLM authentication prevents those NTLM responses from being transmitted; the other options do not directly address that exposure.
Question 44
A company's headquarters is in an area with a high rate of severe weather. An engineer must update the enterprise architecture to meet the following requirements:
• Critical services must remain functional without downtime.
• Backups of data and configurations must be securely implemented.
• Company workstations must be highly available and remotely reachable.
Which of the following solutions is the best way to meet these requirements?
A. Transition physical resources to virtual resources with standby redundant servers, and install a high capacity, diesel-powered backup generator.
B. Open and staff a second data center at least 100 miles away with robust, network-attached storage, and include DAR encryption for offline backups of customer data to enable rapid recovery.
C. Lease a cross-country workspace to support as-needed relocation of staff and equipment, and continuously back up and test VM images with automatic recovery orchestration.
D. Implement a geographically distributed allocation of physical resources and VDI with continuous replication connected via site-to-site and load-balanced IPSec VPNs.
Show Answer
Correct Answer: D
Explanation: Geographically distributed resources keep critical services available if severe weather disables headquarters. Continuous replication protects data and configurations, while VDI provides remotely accessible workstations. Site-to-site IPSec VPNs secure connectivity between locations.
Sources:
https://web.archive.org/web/20160826030504/http://itpeernetwork.intel.com/visual-cloud-remote-workstations-in-the-enterprise
Question 45
Multiple users are continuously being prompted to use MFA to log in to their systems. The security team plans to implement policy changes that could address this type of issue for users without reducing the security of user accounts. Which of the following rule changes is the most secure?
A. Creating a conditional access rule that does not require MFA upon login when the activity originates from the corporate network
B. Creating a conditional access rule that does not require MFA when logging in with any user accounts, regardless of where the login occurs
C. Creating a conditional access rule that requires MFA only when logging in to the company email provider
D. Creating a conditional access rule that requires MFA upon all logins, but taking away some password complexity requirements
Show Answer
Correct Answer: D
Explanation: Requiring MFA for every login preserves a consistent second factor regardless of location or application. Relaxing some password complexity requirements may reduce repeated MFA prompts indirectly only if paired with policy tuning, but among these options it avoids creating an MFA-exempt network, account, or service. Passwords should still meet a strong minimum standard.
Question 46
A medical device manufacturer is establishing a risk management strategy for its devices Patient safety is its top concern. These devices automatically adapt to specific patient needs without human intervention and rely heavily on software. Which of the following is the most important risk factor to prioritize?
A. The integrity of the data provided as input to the device
B. The longevity of the device's integrated battery backup
C. The availability of the device's actuator history
D. The reliability of connectivity to monitoring peripherals
E. The confidentiality of PII
Show Answer
Correct Answer: A
Explanation: Because the device adjusts treatment autonomously, corrupted or inaccurate input data can directly cause it to make unsafe decisions. Input-data integrity is therefore the highest priority for patient safety.
Sources:
https://censinet.com/perspectives/iso-14971-ai-medical-device-risk-management
Question 47
A SOC engineer is designing a solution to automate a sequence of tasks in a timely manner with the least amount of effort. The following objectives must be met:
• IOCs must be verified
• Malicious domains must be blocked on all firewalls and email gateways
• An email must be sent confirming the status of the operations
Which of the following is the best way to achieve this goal?
A. Using APIs to perform queries over the IOC
B. Using a TAXII server to share STIX files
C. Running SCAP to configure the baseline
D. Deploying and executing playbooks
Show Answer
Correct Answer: D
Explanation: Playbooks automate a coordinated sequence of actions: verify IOCs, block confirmed malicious domains across firewalls and email gateways, and send a status email. The other options address only parts of that workflow.
Sources:
https://aimultiple.com/soar-use-cases
https://www.adaptivesecurity.com/blog/email-incident-response-lifecycle
Question 48
The security team at a hospital has proposed redesigning the lobby to change the orientation of employee monitors in order to prevent patients from seeing anything displayed onscreen. Which of the following concerns is team most likely trying to address?
A. Situational awareness
B. Social engineering
C. Privacy
D. Physical security
Show Answer
Correct Answer: C
Explanation: Reorienting monitors prevents patients from viewing confidential information on employee screens, addressing privacy.
Question 49
SIMULATION
An organization is planning for disaster recovery and continuity of operations, and has noted the following relevant findings:
1. A natural disaster may disrupt operations at Site A, which would then cause an evacuation. Users are unable to log into the domain from their workstations after relocating to Site B.
2. A natural disaster may disrupt operations at Site A, which would then cause the pump room at Site В to become inoperable.
3. A natural disaster may disrupt operations at Site A, which would then cause unreliable internet connectivity at Site В due to route flapping.
INSTRUCTIONS
Match each relevant finding to the affected host by clicking on the host name and selecting the appropriate number.
For findings 1 and 2, select the items that should be replicated to Site B. For finding 3, select the item in Site В requiring configuration changes, then select the appropriate corrective action from the drop-down menu.
If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.
Show Answer
Correct Answer: 1. Domain controller (Site A) → replicate to Site B
2. SCADA master controller (Site A) → replicate to Site B
3. VPN concentrator (Site B) → Modify the BGP configuration
Explanation: Site B needs a domain controller for logins and a SCADA master controller to operate its pumps. Route flapping calls for a BGP configuration change on Site B’s network device.
Question 50
An organization receives intelligence information about a foreign adversary targeting instances of a web server application that the organization uses. The information includes:
• The originating IP addresses of the attack
• The common commands run on the affected device
• The indicators that a device has been affected
• The actions that can be taken on the device to stop the attack
Which of the following should the organization do first?
A. Draft an incident response playbook
B. Build tactics, techniques, and procedures
C. Create Snort and YARA rules
D. Configure user behavior analytics
Show Answer
Correct Answer: C
Explanation: The organization should first turn the supplied indicators into detection rules. Snort rules can detect relevant network traffic, while YARA rules can identify matching files or artifacts on affected systems. Those detections help identify an attack so the provided response actions can be applied. TTPs are adversary behaviors to document or map, and user behavior analytics is not the best fit for these indicators.
$19
Get all 400 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.