A company relies on open-source software libraries to build the software used by its customers. Which of the following vulnerability types would be the most difficult to remediate due to the company’s reliance on open-source libraries?
A. Buffer overflow
B. SQL injection
C. Cross-site scripting
D. Zero-day
Show Answer
Correct Answer: D
Explanation: Zero-day vulnerabilities are the most difficult to remediate in software that depends on open-source libraries because there is no available patch when they are discovered. The organization cannot directly fix third-party library code in many cases and must often wait for maintainers to release an update or develop its own temporary mitigation. Buffer overflows, SQL injection, and cross-site scripting are vulnerability classes with established prevention and remediation techniques.
Question 102
To which of the following security categories does an EDR solution belong?
A. Physical
B. Operational
C. Managerial
D. Technical
Show Answer
Correct Answer: D
Explanation: An Endpoint Detection and Response (EDR) solution is a technical security control. It is software that monitors endpoint activity, detects threats, and enables automated or guided response, making it part of the technical (logical) security category rather than physical, operational, or managerial controls.
Question 103
A security analyst notices unusual behavior on the network. The IDS on the network was not able to detect the activities. Which of the following should the security analyst use to help the IDS detect such attacks in the future?
A. Signatures
B. Trends
C. Honeypot
D. Reputation
Show Answer
Correct Answer: A
Explanation: An IDS that failed to detect an attack can often be improved by updating or adding detection signatures so it can recognize that attack pattern in the future. Trends are for analysis rather than detection, a honeypot is used to attract and study attackers, and reputation services help assess trustworthiness but do not directly teach a signature-based IDS to detect new attack patterns.
Question 104
A company’s gate access logs show multiple entries from an employee’s ID badge within a two-minute period. Which of the following is this an example of?
A. RFID cloning
B. Side-channel attack
C. Shoulder surfing
D. Tailgating
Show Answer
Correct Answer: A
Explanation: Multiple gate access log entries from the same employee badge within a very short period suggest the badge credential is being used in more than one place or by more than one device. Tailgating typically results in a single legitimate badge swipe followed by an unauthorized person entering without an additional badge read, so it would not normally create multiple badge log entries. Side-channel attacks and shoulder surfing are unrelated to physical access log patterns.
Question 105
An administrator must replace an expired SSL certificate. Which of the following does the administrator need to create the new SSL certificate?
A. CSR
B. OCSP
C. Key
D. CRL
Show Answer
Correct Answer: A
Explanation: A new SSL/TLS certificate is typically requested by generating a Certificate Signing Request (CSR), which contains the public key and identifying information for the Certificate Authority to sign. OCSP and CRL are revocation status mechanisms, and while a private key is associated with the certificate, the standard artifact created to obtain a new certificate is the CSR.
Question 106
A company wants to track modifications to the code that is used to build new virtual servers. Which of the following will the company most likely deploy?
A. Change management ticketing system
B. Behavioral analyzer
C. Collaboration platform
D. Version control tool
Show Answer
Correct Answer: D
Explanation: A version control tool is specifically designed to track changes to source code and infrastructure-as-code used to build virtual servers, maintaining history, enabling collaboration, and supporting rollback. A change management ticketing system tracks approvals and process, not code changes; a behavioral analyzer monitors activity; and a collaboration platform facilitates communication rather than code versioning.
Question 107
A certificate authority needs to post information about expired certificates. Which of the following would accomplish this task?
A. TPM
B. CRL
C. PKI
D. CSR
Show Answer
Correct Answer: B
Explanation: A Certificate Revocation List (CRL) is published by a Certificate Authority to provide information about certificates that should no longer be trusted. Among the options, CRL is the mechanism used to publish certificate status information. TPM is secure hardware, PKI is the overall certificate infrastructure, and CSR is a certificate signing request.
Question 108
Which of the following is the act of proving to a customer that software developers are trained on secure coding?
A. Assurance
B. Contract
C. Due diligence
D. Attestation
Show Answer
Correct Answer: D
Explanation: Attestation is the formal act of certifying or providing evidence that a claim is true. Demonstrating to a customer that developers have completed secure coding training is an attestation. Assurance is broader confidence in controls, a contract is a legal agreement, and due diligence is the process of investigating or taking reasonable care rather than formally proving compliance.
Question 109
A security analyst needs to improve the company’s authentication policy following a password audit. Which of the following should be included in the policy? (Choose two.)
A. Length
B. Complexity
C. Least privilege
D. Something you have
E. Security keys
F. Biometrics
Show Answer
Correct Answer: A, B
Explanation: Following a password audit, the password policy should specify minimum password length and password complexity requirements. Least privilege is an authorization principle, while something you have, security keys, and biometrics are authentication factors or MFA methods rather than password policy elements.
Question 110
A SOC analyst establishes a remote control session on an end user’s machine and discovers the following in a file:
gmail.com[ENT]
[ENT]NoOneCanGuessThis123! [ENT]Hello Susan, it was great to see you the other day! Let’s plan a followup[BACKSPACE]follow-up meeting soon. Here is the link to register. [RTN][CTRL]c [CTRL]v [RTN]after[BACKSPACE]After you register give me a call on my cellphone.
Which of the following actions should the SOC analyst perform first?
A. Advise the user to change passwords.
B. Reimage the end user’s machine.
C. Check the policy on personal email at work.
D. Check host firewall logs.
Show Answer
Correct Answer: B
Explanation: The file contents are characteristic of a keystroke log, showing typed text along with special key events such as [ENT], [BACKSPACE], [CTRL]c, [CTRL]v, and [RTN]. This indicates the endpoint is likely compromised by a keylogger. The first priority is to eradicate the compromise by reimaging the machine. Advising a password change before the malware is removed risks capturing the new credentials if done on the infected system. Password changes should follow from a known-clean device after containment.
$19
Get all 608 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.