Which of the following cryptographic solutions protects data at rest?
A. Digital signatures
B. Full disk encryption
C. Private key
D. Steganography
Show Answer
Correct Answer: B
Explanation: Data at rest refers to data stored on physical media. Full disk encryption encrypts all contents of a storage device, protecting stored data from unauthorized access if the device is lost, stolen, or accessed offline. The other options do not specifically protect stored data.
Question 114
HOTSPOT
-
A security architect is tasked with designing a highly resilient, business-critical application. The application SLA is 99.999%.
INSTRUCTIONS
-
Select the network, power, and server components for the appropriate locations to achieve application resiliency.
A component should be selected for each location, and components may be selected more than once.
If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.
Show Answer
Correct Answer: Internet
↓
ISP (left) | ISP (right)
↓
Active-active routers (both paths)
↓
Active-active firewalls
↓
Load balancers
↓
Layer 3 device
↓
Web Server A | Web Server B
Power (both servers):
UPS A → Power supply A
UPS B → Power supply B
Utility side:
Utility → Generator → UPS A & UPS B
Explanation: To reach 99.999% availability, every layer must avoid single points of failure. Use dual ISPs feeding active-active routers, then active-active firewalls and load balancers. Servers are connected through a Layer 3 device. Each server uses dual power supplies fed by separate UPS units, both backed by a generator. This matches the hotspot layout and maximizes network, server, and power resiliency.
Question 115
Which of the following is an example of a data protection strategy that uses tokenization?
A. Encrypting databases containing sensitive data
B. Replacing sensitive data with surrogate values
C. Removing sensitive data from production systems
D. Hashing sensitive data in critical systems
Show Answer
Correct Answer: B
Explanation: Tokenization protects data by replacing sensitive values with non-sensitive surrogate tokens that have no exploitable meaning on their own, while the original data is stored securely elsewhere. This matches option B; the other options describe encryption, data removal, or hashing, which are different strategies.
Question 116
Which of the following should a company use to provide proof of external network security testing?
A. Business impact analysis
B. Supply chain analysis
C. Vulnerability assessment
D. Third-party attestation
Show Answer
Correct Answer: D
Explanation: Proof of external network security testing is best provided by third-party attestation, which documents that an independent organization has performed or validated security testing. This offers credible, unbiased evidence suitable for regulators, customers, and partners. The other options are internal analyses and do not constitute external proof.
Question 117
A security engineer needs to quickly identify a signature from a known malicious file. Which of the following analysis methods would the security engineer most likely use?
A. Static
B. Sandbox
C. Network traffic
D. Package monitoring
Show Answer
Correct Answer: A
Explanation: Static analysis examines a file without executing it, allowing quick identification of known malicious signatures such as hashes, byte patterns, or embedded metadata. This is the fastest and most appropriate method for matching a known malicious file signature compared to behavioral or network-based analyses.
Question 118
Which of the following steps should be taken before mitigating a vulnerability in a production server?
A. Escalate the issue to the SDLC team.
B. Use the IR plan to evaluate the changes.
C. Perform a risk assessment to classify the vulnerability.
D. Refer to the change management policy.
Show Answer
Correct Answer: D
Explanation: When mitigating a vulnerability on a **production server**, any remediation (patching, configuration changes, service restarts) constitutes a controlled change that can affect availability and stability. Best practice is to **refer to the change management policy first** to ensure proper approval, scheduling, testing, rollback planning, and communication. While risk assessment is important, it is typically part of the broader vulnerability management process; the key prerequisite specific to acting in production is adherence to change management.
Question 119
Various company stakeholders meet to discuss roles and responsibilities in the event of a security breach that would affect offshore offices. Which of the following is this an example of?
A. Tabletop exercise
B. Penetration test
C. Geographic dispersion
D. Incident response
Show Answer
Correct Answer: A
Explanation: The scenario describes a discussion-based meeting where stakeholders review roles and responsibilities during a potential security breach affecting offshore offices. This is characteristic of a tabletop exercise, which simulates incidents through discussion rather than live testing. It is not a penetration test (technical testing), geographic dispersion (a structural concept), or an actual incident response (real event handling).
Question 120
Which of the following cryptographic solutions is used to hide the fact that communication is occurring?
A. Steganography
B. Data masking
C. Tokenization
D. Private key
Show Answer
Correct Answer: A
Explanation: Steganography is specifically designed to conceal the existence of communication by hiding a message within another medium (such as an image, audio, or video). Unlike encryption, which hides content but not the fact that communication is occurring, steganography makes the communication itself difficult to detect.
Question 121
A company is implementing a policy to allow employees to use their personal equipment for work. However, the company wants to ensure that only company-approved applications can be installed. Which of the following addresses this concern?
A. MDM
B. Containerization
C. DLP
D. FIM
Show Answer
Correct Answer: A
Explanation: The requirement is to allow employees to use personal devices (BYOD) while ensuring that only company-approved applications can be installed. Mobile Device Management (MDM) directly addresses this by enforcing application whitelisting/blacklisting, policy enforcement, and compliance controls on employee-owned devices. Containerization focuses on isolating corporate data/apps but does not inherently manage or restrict overall app installation. DLP and FIM address data protection and file change monitoring, not application control.
Question 122
A company wants to ensure employees are allowed to copy files from a virtual desktop during the workday but are restricted during non-working hours. Which of the following security measures should the company set up?
A. Digital rights management
B. Role-based access control
C. Time-based access control
D. Network access control
Show Answer
Correct Answer: C
Explanation: The requirement is to allow or restrict an action (copying files from a virtual desktop) based on working versus non-working hours. Time-based access control enforces permissions according to defined time windows, matching this scenario. The other options control access by content (DRM), user role (RBAC), or network posture (NAC), not time.
$19
Get all 609 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.