Which of the following risk management decisions should be considered after evaluating all other options?
A. Transfer
B. Acceptance
C. Mitigation
D. Avoidance
Show Answer
Correct Answer: B
Explanation: Risk acceptance is generally the option considered after evaluating avoidance, mitigation, and transfer. If the remaining risk is within the organization's risk tolerance or the cost of further treatment outweighs the benefit, the organization accepts the residual risk.
Question 132
A user is suspected of violating policy by logging in to a Linux VM during non-business hours. Which of the following system files is the best way to track the user’s activities?
A. /var/log/secure
B. /etc/motd
C. /var/log/messages
D. /etc/passwd
Show Answer
Correct Answer: A
Explanation: /var/log/secure records authentication-related events on many Linux distributions, including SSH logins, authentication attempts, and sudo usage. It is the primary log to review for determining whether a user logged in during non-business hours. /etc/motd is only the login message, /var/log/messages contains general system messages, and /etc/passwd stores user account information rather than activity logs.
Question 133
A junior security analyst opened ports on the company’s firewall, and the company experienced a data breach. Which of the following most likely caused the data breach?
A. Environmental hacktivist
B. Accidental insider threat
C. Nation-state
D. Organized crime group
Show Answer
Correct Answer: B
Explanation: The junior security analyst is an authorized internal user whose mistaken firewall configuration (opening ports) enabled the breach. This is an accidental insider threat: an unintentional action by an insider that creates a security vulnerability leading to compromise. The other options describe potential external threat actors that might exploit the vulnerability, not the most likely cause described in the scenario.
Question 134
A security analyst needs to block vulnerable ports and disable legacy protocols. The analyst has ensured NetBIOS trio, Telnet, SMB, and TFTP are blocked and/or disabled. Which of the following additional protocols should the analyst block next?
A. LDAPS v3
B. SNMP v1
C. TLS 1.3
D. Kerberos v5
Show Answer
Correct Answer: B
Explanation: SNMPv1 is a legacy, insecure protocol that uses weak/plaintext community-string authentication and should be disabled in favor of SNMPv3. The other options are current secure or required protocols: LDAPS, TLS 1.3, and Kerberos v5 are not legacy protocols that should generally be blocked.
Question 135
A network security analyst for a large company noticed unusual network activity on a critical system. Which of the following tools should the analyst use to analyze network traffic to search for malicious activity?
A. WAF
B. Wireshark
C. EDR
D. Nmap
Show Answer
Correct Answer: B
Explanation: Wireshark is a packet capture and protocol analysis tool used to inspect network traffic in detail and identify suspicious or malicious activity. A WAF protects web applications, EDR focuses on endpoint detection and response, and Nmap is primarily used for network discovery and port scanning.
Question 136
HOTSPOT
-
A systems administrator is reviewing the output of a vulnerability scan.
INSTRUCTIONS
-
Review the information in each tab.
Based on the organization’s environment architecture and remediation standards, select the server to be patched within 14 days and select the appropriate technique and mitigation.
If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.
Show Answer
Correct Answer: Server: 192.168.60.5
Technique/Mitigation: Patch; upload signed certificate from trusted third-party provider
Explanation: The 14-day remediation window applies to CVSS >7.9 and <9.0 in the production environment. The CVSS 8.1 untrusted X.509 certificate finding affects 192.168.60.5 in production, and the appropriate remediation is replacing the untrusted certificate with one signed by a trusted CA.
Question 137
A security manager is looking at a third-party vulnerability metric (SMITTEN) to improve upon the company’s current method that relies on CVSSv3. Given the following:
Which of the following vulnerabilities should be prioritized?
A. Vulnerability 1
B. Vulnerability 2
C. Vulnerability 3
D. Vulnerability 4
Show Answer
Correct Answer: B
Explanation: Based on the information available, the highest priority is the vulnerability that is actively being exploited on an external-facing system. Metrics that incorporate exploit activity and context (such as SMITTEN) would prioritize real-world exploitation over CVSS severity alone. The prompt references additional data that is not included, so this conclusion is contingent on that context.
Question 138
A security analyst needs to support an organization’s legal case against a threat actor. Which of the following processes provides the best way to assist in the prosecution of the case?
A. Chain of custody
B. Evidence gathering
C. Securing the scene
D. Forensic analysis
Show Answer
Correct Answer: A
Explanation: Chain of custody is the process that best supports prosecution because it preserves and documents the integrity, handling, and ownership of evidence from collection through presentation in court. Proper chain of custody is essential for evidence to be admissible and defensible in legal proceedings. Evidence gathering, securing the scene, and forensic analysis are important investigative activities, but without a documented chain of custody, the evidence may be challenged or excluded.
Question 139
A user clicks on a malicious adware link, and the malware successfully downloads to the machine. The malware has a script that invokes command-and-control activity. Which of the following actions is the best way to contain the incident without any additional impact?
A. Disable the user account until the malware investigation is complete.
B. Review EDR information to determine whether the file was detected and quarantined locally.
C. Block the server on the proxy and firewall.
D. Submit a recategorization update to the vendor.
Show Answer
Correct Answer: C
Explanation: The malware is already installed and attempting command-and-control communication. The primary containment goal is to prevent further attacker interaction and additional payloads or data exfiltration. Blocking the malicious C2 server at the proxy and firewall disrupts communication with minimal additional impact. Disabling the user account does not stop the malware, reviewing EDR is a detection/verification step rather than containment, and recategorizing the site is a longer-term preventive action, not immediate incident containment.
Question 140
Which of the following should be performed first when creating a BCP to ensure that all critical functions and financial implications have been considered?
A. Failover test
B. Tabletop exercise
C. Security policies
D. Business impact analysis
Show Answer
Correct Answer: D
Explanation: A Business Impact Analysis (BIA) is the foundational step in business continuity planning. It identifies critical business functions, dependencies, recovery priorities, and the operational and financial impact of disruptions. This information guides the rest of the BCP. Failover tests and tabletop exercises occur later to validate the plan, and security policies are broader governance documents rather than the first step in creating a BCP.
$19
Get all 534 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.