A systems administrator is concerned after reviewing the results of a vulnerability scan:
Which of the following mitigation strategies best addresses the risk?
A. Create an exception.
B. Wait for a patch release.
C. Apply compensating controls.
D. Disable the affected application.
Show Answer
Correct Answer: C
Explanation: Applying compensating controls is the best mitigation when a vulnerability cannot be immediately remediated, such as when a patch is unavailable or deployment is delayed. Compensating controls reduce the risk while maintaining operations. Creating an exception accepts the risk, waiting for a patch leaves the system exposed, and disabling the application is generally a last resort unless the risk is critical and no other mitigation is feasible.
Question 12
Which of the following is the term for a predefined set of automated actions that incident responders and SOC analysts can use to enhance operations?
A. Threat modeling
B. Detection set
C. CVSS
D. Playbooks
Show Answer
Correct Answer: D
Explanation: A playbook is a predefined set of documented and often automated response actions used by SOC analysts and incident responders to standardize and accelerate incident handling. Threat modeling identifies potential threats, a detection set refers to detection rules or logic, and CVSS is a vulnerability severity scoring system.
Question 13
Which of the following best explains the importance of security orchestration, automation, and response for security operation activities?
A. Implementing infrastructure as code in the organization
B. Supporting the team's management of remediation tasks
C. Deploying general scripts for automating security engineering operations
D. Collecting threat intelligence feeds for improved threat response
Show Answer
Correct Answer: B
Explanation: SOAR platforms are designed to orchestrate security tools, automate repetitive security workflows, and coordinate incident response. Their key value in security operations is improving the efficiency and consistency of remediation and response tasks by helping teams manage and automate those activities. The other options describe related technologies or capabilities but do not capture the primary importance of SOAR.
Question 14
An analyst uses an AI platform to help correlate events. The AI output contains events that did not happen. This results in inaccurate correlations. Which of the following best describes what has occurred?
A. Hallucinations
B. Data exposure
C. Malicious prompts
D. Model poisoning
Show Answer
Correct Answer: A
Explanation: The AI generated events that did not actually occur, leading to false correlations. This is a hallucination: the model produces plausible-sounding but factually incorrect content. Data exposure involves leakage of sensitive information, malicious prompts are adversarial inputs intended to manipulate behavior, and model poisoning refers to compromising training data or the model to alter its behavior.
Question 15
An analyst reviews code for a sensitive application for their company and uploads it to an AI platform. This application is critical to the company's business operations. Which of the following risks is most important for the analyst to consider?
A. Hallucinations
B. Malicious prompts
C. Data exposure
D. Model poisoning
Show Answer
Correct Answer: C
Explanation: Uploading sensitive proprietary source code for a business-critical application to an AI platform creates the primary risk of unauthorized disclosure or retention of confidential data. While hallucinations, malicious prompts, and model poisoning are valid AI-related concerns, the most immediate and significant risk in this scenario is exposing sensitive company code and intellectual property to the AI service.
Question 16
A security analyst is analyzing two vulnerabilities on a critical router. The analyst must choose only one to patch during this maintenance window. Given the following information:
Vulnerability 1 has not received a CVSS score. The vulnerability has the following characteristics:
• Must be logged in to the router, but elevated privileges are not required
• Trivial to exploit, but user interaction is needed
• Low impact to availability, but high impact to confidentiality and integrity
Vulnerability 2 has a CVSS score of AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
Which of the following conclusions should the analyst reach?
A. Patch Vulnerability 1 because it has a higher overall impact when looking at confidentiality, integrity, and availability, and it requires lower privileges.
B. Patch Vulnerability 1 because it is easier to exploit and has a higher impact on confidentiality.
C. Patch Vulnerability 2 because it has a higher overall impact when looking at confidentiality, integrity, and availability, and it can be exploited by a privileged user.
D. Patch Vulnerability 2 because it is easier to exploit, has a high impact on availability, and it is more likely to be exploited remotely.
Show Answer
Correct Answer: D
Explanation: Vulnerability 1 maps approximately to AV:L (logged in), AC:L (trivial), PR:L (logged in but no elevated privileges), UI:R, S:U, C:H, I:H, A:L. Vulnerability 2 is AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H. Although Vulnerability 1 has higher confidentiality and integrity impact, Vulnerability 2 is remotely exploitable over the network and requires no user interaction, making it easier and more likely to be exploited. Its high availability impact further supports prioritizing it during a limited maintenance window.
Question 17
An organization’s security operations center (SOC) team prioritizes confidentiality and integrity over monetary considerations. The SOC team contains a quickly progressing ransomware incident. Which of the following factors motivated the SOC team to take this action? (Choose two.)
A. Attack vector
B. Risk appetite
C. Scope
D. Impact
E. Common Vulnerability Scoring System (CVSS) score
F. Asset value
Show Answer
Correct Answer: B, D
Explanation: The organization's stated priority of confidentiality and integrity over monetary considerations reflects its risk appetite, which guides response decisions. A rapidly progressing ransomware incident is also prioritized based on its impact on critical security objectives and operations. Attack vector, scope, CVSS score, and asset value may inform analysis, but they do not directly explain the stated motivation.
Question 18
HOTSPOT
-
A healthcare organization must develop an action plan based on the findings from a risk assessment. The action plan must consist of a recommended list of security controls.
INSTRUCTIONS
-
Select the appropriate control to implement for each risk finding. Findings may be used only once.
If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.
Show Answer
Correct Answer: Require data deidentification
Filter echo request replies
Implement file integrity monitoring
Implement SPF
Require user authentication
Implement PIN to print
Explanation: Match each finding with the control that most directly mitigates it: deidentify PHI in non-production, filter ICMP echo traffic, detect unauthorized software via file integrity monitoring, reduce email spoofing with SPF, enforce authentication for protected data, and protect printed/faxed sensitive documents with PIN release.
Question 19
An analyst reviews alerts that indicate a number of different users had a spike in login attempts from the same IP. Using the security information and event management (SIEM) system, the analyst finds that a number of users received the following email:
Which of the following best describes this activity?
A. URL shortening
B. Whaling
C. Spoofing
D. Social engineering
Show Answer
Correct Answer: D
Explanation: The overall activity is a social engineering attack, specifically phishing, in which users are tricked into revealing credentials or visiting a malicious site. Spoofing may be used to impersonate a trusted sender, but it is only a technique within the broader social engineering attack. The login spikes from one IP after the email are consistent with successful credential harvesting.
Question 20
A critical server hosting final exams for an educational institution fails while students are taking their exams. The final exam deadline is in 16 hours. Which of the following is the best source for guidance on remediation for the IT team?
A. MOU
B. KPI
C. SLA
D. BCP
Show Answer
Correct Answer: D
Explanation: A Business Continuity Plan (BCP) provides documented procedures for maintaining or rapidly restoring critical business operations during a major disruption. A server failure during active final exams is a business continuity event, and the BCP guides remediation and recovery priorities. An MOU defines cooperative agreements, a KPI measures performance, and an SLA defines service commitments rather than operational recovery procedures.
$19
Get all 534 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.