A vulnerability scan on a web server identified the following:
Which of the following actions would most likely eliminate on-path decryption attacks? (Choose two.)
A. Disallowing cipher suites that use ephemeral modes of operation for key agreement
B. Removing support for CBC-based key exchange and signing algorithms
C. Adding TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA256
D. Implementing HIPS rules to identify and block BEAST attack attempts
E. Restricting cipher suites to only allow TLS_RSA_WITH_AES_128_CBC_SHA
F. Increasing the key length to 256 for TLS_RSA_WITH_AES_128_CBC_SHA
Show Answer
Correct Answer: B, C
Explanation: Removing CBC-based cipher suites mitigates attacks that exploit CBC-mode TLS encryption. Adding the ECDHE-ECDSA AES-256-GCM suite provides authenticated encryption and ephemeral key agreement, helping protect against on-path decryption. The other options either retain weak configurations or disable forward secrecy.
Question 82
A systems administrator wants to use existing resources to automate reporting from disparate security appliances that do not currently communicate. Which of the following is the best way to meet this objective?
A. Configuring an API integration to aggregate the different data sets
B. Combining back-end application storage into a single, relational database
C. Purchasing and deploying commercial off-the-shelf aggregation software
D. Migrating application usage logs to on-premises storage
Show Answer
Correct Answer: A
Explanation: An API integration can connect otherwise disparate security appliances and aggregate their data for automated reporting, using existing resources without requiring new commercial software or a backend storage migration.
Question 83
A security engineer is reviewing the results of an annual penetration test. The report lists one of the results as "critical severity" on several domain-joined workstations:
SSL/TLS Weak Protocols Supported TLS 1.0, TLS 1.1
Which of the following should the security engineer implement to remediate this finding in the most centralized manner?
A. An SCCM patch to disable weak protocols in the Schannel hive
B. A GPO to disable weak protocols in the Schannel hive
C. A PowerShell script to disable weak protocols in the HKLM Schannel hive
D. A registry script to disable weak protocols in the Schannel hive
Show Answer
Correct Answer: B
Explanation: A Group Policy Object (GPO) centrally configures domain-joined workstations and can apply the Schannel registry settings needed to disable TLS 1.0 and TLS 1.1. This is more centralized and manageable than deploying a script or patch to each system.
Question 84
A security engineer is building a solution to disable weak CBC configurations for remote access connections to Linux systems. Which of the following should the security engineer modify?
A. The /etc/openssl.conf file, updating the virtual site parameter
B. The /etc/nsswitch.conf file, updating the name server
C. The /etc/hosts file, updating the IP parameter
D. The /etc/sshd/ssh_config file, updating the ciphers
Show Answer
Correct Answer: D
Explanation: To disable weak CBC ciphers for SSH remote access, configure the SSH server’s allowed ciphers using the Ciphers directive. The usual server configuration path is /etc/ssh/sshd_config; option D appears to intend this file.
Question 85
A security analyst reviews the following report:
Which of the following assessments is the analyst performing?
A. System
B. Supply chain
C. Quantitative
D. Organizational
Show Answer
Correct Answer: B
Explanation: The report itself is not included in the question. Based on the available context, the assessment is a supply chain assessment, which evaluates risks associated with suppliers, vendors, and third-party products or services.
Question 86
A news organization wants to implement workflows that allow users to request that untruthful data be retraced and scrubbed from online publications to comply with the right to be forgotten. Which of the following regulations is the organization most likely trying to address?
A. GDPR
B. COPPA
C. CCPA
D. DORA
Show Answer
Correct Answer: A
Explanation: The GDPR includes the right to erasure (often called the “right to be forgotten”), allowing individuals in certain circumstances to request deletion of their personal data. COPPA concerns children’s privacy, CCPA is a California privacy law, and DORA covers financial-sector digital resilience.
Question 87
A security officer received several complaints from users about excessive MFA push notifications at night. The security team investigates and suspects malicious activities regarding user account authentication. Which of the following is the best way for the security officer to restrict MFA notifications?
A. Provisioning FIDO2 devices
B. Deploying a text message based on MFA
C. Enabling OTP via email
D. Configuring prompt-driven MFA
Show Answer
Correct Answer: A
Explanation: Provisioning FIDO2 devices replaces push-based approvals with phishing-resistant public-key authentication, preventing attackers from generating repeated MFA push notifications. SMS or email OTP changes the notification channel, while prompt-driven MFA still relies on prompts.
Question 88
An organization recently acquired another company that is running a different EDR solution. A SOC analyst wants to automate the isolation of endpoints that are found to be compromised. Which of the following workflows best mitigates the risk of false positives and reduces the spread of malicious code?
A. Using a SOAR solution to look up entities via a TIP platform and isolate endpoints via APIs
B. Setting a policy on each EDR management console to isolate all endpoints that trigger any alerts
C. Reviewing all alerts manually in the various portals and taking action to isolate them
D. Automating the suppression of all alerts that are not critical and sending an email asking SOC analysts to review these alerts
Show Answer
Correct Answer: A
Explanation: A SOAR workflow can enrich alerts by checking entities against threat intelligence before taking action, helping reduce false-positive isolations. Its API integrations can then isolate compromised endpoints across different EDR platforms quickly, limiting the spread of malicious code.
Question 89
A large organization deployed a generative AI platform for its global user population to use. Based on feedback received during beta testing, engineers have identified issues with user interface latency and page-loading performance for international users. The infrastructure is currently maintained within two separate data centers, which are connected using high-availability networking and load balancers. Which of the following is the best way to address the performance issues?
A. Configuring the application to use a CDN
B. Implementing RASP to enable large language models queuing
C. Remote journaling within a third data center
D. Traffic shaping through the use of a SASE
Show Answer
Correct Answer: A
Explanation: A CDN serves cached content and static assets from edge locations closer to international users, reducing page-load latency and traffic to the data centers.
Question 90
A hospital provides tablets to its medical staff to enable them to more quickly access and edit patients' charts. The hospital wants to ensure that if a tablet is identified as lost or stolen and a remote command is issued, the risk of data loss can be mitigated within seconds. The tablets are configured as follows to meet hospital policy:
• Full disk encryption is enabled.
• "Always On" corporate VPN is enabled.
• eFuse-backed keystore is enabled/ready.
• Wi-Fi 6 is configured with SAE.
• Location services is disabled.
• Application allow list is unconfigured.
Assuming the hospital policy cannot be changed, which of the following is the best way to meet the hospital's objective?
A. Revoke the user VPN and Wi-Fi certificates
B. Cryptographically erase FDE volumes
C. Issue new MFA credentials to all users
D. Configure the application allow list
Show Answer
Correct Answer: B
Explanation: Cryptographically erasing the FDE volumes destroys the encryption keys, making the stored patient data inaccessible within seconds without needing to overwrite the entire device. Revoking certificates or changing MFA credentials does not erase locally stored data, and an application allow list does not address data on a lost tablet.
$19
Get all 400 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.