Which of the following cryptographic solutions protects data at rest?
A. Digital signatures
B. Full disk encryption
C. Private key
D. Steganography
Show Answer
Correct Answer: B
Explanation: Full disk encryption encrypts the contents of an entire storage device, protecting data at rest from unauthorized access if the device is lost, stolen, or accessed offline. Digital signatures provide authenticity and integrity, a private key is a cryptographic key rather than a data-at-rest protection solution, and steganography hides data but does not secure stored data through encryption.
Question 112
HOTSPOT
-
A security architect is tasked with designing a highly resilient, business-critical application. The application SLA is 99.999%.
INSTRUCTIONS
-
Select the network, power, and server components for the appropriate locations to achieve application resiliency.
A component should be selected for each location, and components may be selected more than once.
If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.
Show Answer
Correct Answer: Top: ISP
Next row (L→R): Active-active routers | ISP | Cloud Service Provider
Next row (L→R): Active-active firewalls | Load balancers | Active-passive firewalls
Server power (L→R): Power supply A | Power supply B | Power supply A | Power supply B
Bottom power (L→R): Generator | UPS A | UPS B
Explanation: For five-nines availability, use redundant networking and split server power across independent UPS feeds. The commonly accepted exam solution maps the hotspot locations as above.
Question 113
Which of the following is an example of a data protection strategy that uses tokenization?
A. Encrypting databases containing sensitive data
B. Replacing sensitive data with surrogate values
C. Removing sensitive data from production systems
D. Hashing sensitive data in critical systems
Show Answer
Correct Answer: B
Explanation: Tokenization protects sensitive data by replacing it with non-sensitive surrogate values (tokens). The original data is stored securely and retrieved only when needed. Encryption transforms data but retains it, hashing is one-way, and removing data is not tokenization.
Question 114
Which of the following should a company use to provide proof of external network security testing?
A. Business impact analysis
B. Supply chain analysis
C. Vulnerability assessment
D. Third-party attestation
Show Answer
Correct Answer: D
Explanation: Third-party attestation provides independent evidence that external network security testing has been performed and can be shared with customers, auditors, or regulators. A vulnerability assessment is a type of testing, but it is not, by itself, independent proof for external parties. Business impact analysis and supply chain analysis do not provide evidence of external network security testing.
Question 115
A security engineer needs to quickly identify a signature from a known malicious file. Which of the following analysis methods would the security engineer most likely use?
A. Static
B. Sandbox
C. Network traffic
D. Package monitoring
Show Answer
Correct Answer: A
Explanation: Static analysis examines a file without executing it, allowing rapid identification of known malicious signatures such as hashes, strings, headers, or byte patterns. Sandbox analysis focuses on runtime behavior, network traffic analysis inspects communications rather than file signatures, and package monitoring is not used to identify malware signatures.
Question 116
Which of the following steps should be taken before mitigating a vulnerability in a production server?
A. Escalate the issue to the SDLC team.
B. Use the IR plan to evaluate the changes.
C. Perform a risk assessment to classify the vulnerability.
D. Refer to the change management policy.
Show Answer
Correct Answer: D
Explanation: Before making changes to a production server, organizations should follow the change management policy to ensure the mitigation is reviewed, approved, tested as appropriate, scheduled, and documented. An incident response plan is for active incidents, SDLC is not relevant for production remediation, and while risk assessment is important in vulnerability management, the question asks what should be done before mitigating a vulnerability on a production server, making change management the best answer.
Question 117
Various company stakeholders meet to discuss roles and responsibilities in the event of a security breach that would affect offshore offices. Which of the following is this an example of?
A. Tabletop exercise
B. Penetration test
C. Geographic dispersion
D. Incident response
Show Answer
Correct Answer: A
Explanation: A tabletop exercise is a discussion-based walkthrough in which stakeholders review and practice their roles, responsibilities, communication, and decision-making for a simulated incident, such as a security breach affecting offshore offices. This differs from a penetration test (technical security assessment), geographic dispersion (a resilience concept), and incident response (the actual process of responding to an incident rather than a planning exercise).
Question 118
Which of the following cryptographic solutions is used to hide the fact that communication is occurring?
A. Steganography
B. Data masking
C. Tokenization
D. Private key
Show Answer
Correct Answer: A
Explanation: Steganography conceals the existence of a message by embedding it within another medium (such as an image, audio, or video), hiding the fact that communication is occurring. Data masking and tokenization protect sensitive data but do not hide that communication exists. A private key is simply a component of asymmetric cryptography.
Question 119
A company is implementing a policy to allow employees to use their personal equipment for work. However, the company wants to ensure that only company-approved applications can be installed. Which of the following addresses this concern?
A. MDM
B. Containerization
C. DLP
D. FIM
Show Answer
Correct Answer: A
Explanation: MDM (Mobile Device Management) is the standard solution for BYOD environments when an organization needs to enforce application policies such as app whitelisting/blacklisting, restricting installations, and managing approved software. Containerization isolates corporate apps and data from personal content, but its primary purpose is separation of work and personal environments rather than controlling all application installation. DLP prevents data exfiltration, and FIM monitors file changes.
Question 120
A company wants to ensure employees are allowed to copy files from a virtual desktop during the workday but are restricted during non-working hours. Which of the following security measures should the company set up?
A. Digital rights management
B. Role-based access control
C. Time-based access control
D. Network access control
Show Answer
Correct Answer: C
Explanation: Time-based access control grants or restricts permissions according to configured time windows. Allowing file copying during working hours and denying it during non-working hours is a direct use of time-based access control. DRM protects content usage, RBAC assigns permissions by role, and NAC controls device/network access rather than time-based file copy permissions.
$19
Get all 608 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.