A customer has a contract with a CSP and wants to identify which controls should be implemented in the IaaS enclave. Which of the following is most likely to contain this information?
A. Statement of work
B. Responsibility matrix
C. Service-level agreement
D. Master service agreement
Show Answer
Correct Answer: B
Explanation: A responsibility matrix (shared responsibility matrix) identifies which security controls apply in an IaaS environment and assigns responsibility for implementing and maintaining them between the cloud service provider and the customer. An SLA defines service performance and availability commitments, an MSA governs overall contractual terms, and an SOW defines project scope and deliverables.
Question 122
A security manager wants to reduce the number of steps required to identify and contain basic threats. Which of the following will help achieve this goal?
A. SOAR
B. SIEM
C. DMARC
D. NIDS
Show Answer
Correct Answer: A
Explanation: SOAR (Security Orchestration, Automation, and Response) automates and orchestrates incident detection, investigation, and response using predefined workflows and playbooks. This reduces the manual steps required to identify and contain common threats. SIEM primarily aggregates and analyzes logs, DMARC protects email authentication, and NIDS detects network intrusions but does not automate containment.
Question 123
An alert references attacks associated with a zero-day exploit. An analyst places a bastion host in the network to reduce the risk of the exploit. Which of the following types of controls is the analyst implementing?
A. Compensating
B. Detective
C. Operational
D. Physical
Show Answer
Correct Answer: A
Explanation: A bastion host deployed in response to a zero-day vulnerability is being used to mitigate risk when the primary corrective control (such as a vendor patch) is not yet available. That makes it a compensating control. It is not detective because it does not primarily detect events, not operational because that is a control category rather than the best type here, and not physical because it is a logical/technical security measure.
Question 124
The Chief Information Officer (CIO) asked a vendor to provide documentation detailing the specific objectives within the compliance framework that the vendor's services meet. The vendor provided a report and a signed letter stating that the services meet 17 of the 21 objectives. Which of the following did the vendor provide to the CIO?
A. Penetration test results
B. Self-assessment findings
C. Attestation of compliance
D. Third-party audit report
Show Answer
Correct Answer: C
Explanation: A signed letter accompanied by a report stating which compliance objectives are met is an attestation of compliance. It is a formal assertion that the vendor's services satisfy specified control objectives within a compliance framework. Penetration test results only cover security testing, a self-assessment is an internal evaluation, and a third-party audit report would be an independent auditor's detailed report rather than the vendor's signed attestation.
Question 125
A company is using a legacy FTP server to transfer financial data to a third party. The legacy system does not support SFTP, so a compensating control is needed to protect the sensitive, financial data in transit. Which of the following would be the most appropriate for the company to use?
A. Telnet connection
B. SSH tunneling
C. Patch installation
D. Full disk encryption
Show Answer
Correct Answer: B
Explanation: SSH tunneling encrypts otherwise insecure FTP traffic by carrying it through an encrypted SSH channel, providing a compensating control for data in transit when the legacy application cannot use SFTP. Telnet is unencrypted, patch installation does not address the lack of transport encryption, and full disk encryption protects data at rest rather than data in transit.
Question 126
Which of the following should a systems administrator use to decrease the company's hardware attack surface?
A. Replication
B. Isolation
C. Centralization
D. Virtualization
Show Answer
Correct Answer: D
Explanation: Virtualization decreases the hardware attack surface by consolidating workloads onto fewer physical systems, reducing the amount of physical hardware that must be deployed, managed, and exposed. Isolation limits the impact or spread of attacks but does not inherently reduce the quantity of hardware or the hardware attack surface itself. Replication increases infrastructure, and centralization is not specifically a hardware attack surface reduction control.
Question 127
Which of the following is most likely a security concern when installing and using low-cost IoT devices in infrastructure environments?
A. Country of origin
B. Device responsiveness
C. Ease of deployment
D. Storage of data
Show Answer
Correct Answer: D
Explanation: The best answer is D. Storage of data. In Security+ context, a common security concern with low-cost IoT devices is how they collect, store, and protect sensitive data. These devices often have weak security controls, limited encryption, and poor data protection, increasing the risk of data exposure. Device responsiveness and ease of deployment are operational concerns, and while country of origin can be a supply-chain consideration, the general security concern emphasized for IoT devices is protection of the data they store and process.
Sources:
https://medium.com/@techinfintrix/the-internet-of-things-has-17-billion-devices-and-most-of-them-are-a-security-risk-43aa4941f420
Question 128
An administrator has configured a quarantine subnet for all guest devices that connect to the network. Which of the following would be best for the security team to perform before allowing access to corporate resources?
A. Device fingerprinting
B. Compliance attestation
C. Penetration test
D. Application vulnerability test
Show Answer
Correct Answer: B
Explanation: A quarantine subnet is commonly used with Network Access Control (NAC) to isolate devices until they satisfy security policy. Before granting access to corporate resources, the appropriate action is compliance attestation, which verifies the device meets required security baselines such as current patches, antivirus, and firewall status. Device fingerprinting identifies device characteristics but does not confirm security posture. Penetration testing and application vulnerability testing are not practical or standard admission checks for guest devices.
Question 129
A company captures log-in details and reviews them each week to identify conditions such as excessive log-in attempts and frequent lockouts. Which of the following should a security analyst recommend to improve security compliance monitoring?
A. Including the date and person who reviewed the information in a report
B. Adding automated alerting when anomalies occur
C. Requiring a statement each week that no exceptions were noted
D. Masking the username in a report to protect privacy
Show Answer
Correct Answer: B
Explanation: Automated alerting improves security compliance monitoring by detecting excessive log-in attempts and frequent lockouts as they occur, enabling timely response and continuous monitoring rather than relying solely on periodic manual review. Option A improves audit evidence for the review process but does not enhance the monitoring capability itself. Option C is merely an attestation, and D addresses privacy rather than monitoring effectiveness.
Question 130
An engineer has ensured that the switches are using the latest OS, the servers have the latest patches, and the endpoints' definitions are up to date. Which of the following will these actions most effectively prevent?
A. Zero-day attacks
B. Insider threats
C. End-of-life support
D. Known exploits
Show Answer
Correct Answer: D
Explanation: Keeping network devices on the latest OS, applying server patches, and updating endpoint security definitions primarily protects against vulnerabilities and malware signatures that are already known and for which fixes or detection updates exist. These measures do not prevent zero-day attacks, which exploit previously unknown vulnerabilities without available patches. They also do not specifically prevent insider threats or address end-of-life support.
$19
Get all 608 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.