Which of the following aspects of the data management life cycle is most directly impacted by local and international regulations?
A. Destruction
B. Certification
C. Retention
D. Sanitization
Show Answer
Correct Answer: C
Explanation: Local and international regulations (such as GDPR, HIPAA, and financial record laws) most directly govern how long data must be kept and when it must be deleted. These legal requirements define mandatory retention periods and conditions, making retention the life-cycle aspect most directly impacted by regulation.
Question 134
A company filed a complaint with its IT service provider after the company discovered the service provider's external audit team had access to some of the company's confidential information. Which of the following is the most likely reason the company filed the complaint?
A. The MOU had basic clauses from a template.
B. A SOW had not been agreed to by the client.
C. A WO had not been mutually approved.
D. A required NDA had not been signed.
Show Answer
Correct Answer: D
Explanation: The most likely reason for the complaint is that a required NDA was not signed. An external audit team accessing confidential company information without proper authorization indicates a failure in confidentiality controls. NDAs are specifically designed to legally restrict access to and disclosure of sensitive information by third parties. The absence of an NDA would allow such access to occur improperly, whereas MOUs, SOWs, or WOs govern scope, intent, or work authorization rather than confidentiality protections.
Question 135
A company's accounting department receives an urgent payment message from the company's bank domain with instructions to wire transfer funds. The sender requests that the transfer be completed as soon as possible. Which of the following attacks is described?
A. Business email compromise
B. Vishing
C. Spear phishing
D. Impersonation
Show Answer
Correct Answer: A
Explanation: The scenario describes an urgent wire transfer request sent via email that appears to come from a trusted bank domain. This is characteristic of Business Email Compromise (BEC), where attackers impersonate trusted entities to fraudulently induce financial transactions. Vishing involves phone calls, spear phishing is broader and often focused on credential theft, and impersonation is a tactic rather than the specific attack category.
Question 136
A company discovers suspicious transactions that were entered into the company's database and attached to a user account that was created as a trap for malicious activity. Which of the following is the user account an example of?
A. Honeytoken
B. Honeynet
C. Honeypot
D. Honeyfile
Show Answer
Correct Answer: A
Explanation: The account was intentionally created as a decoy to detect and study malicious activity. Such fake data elements—like user accounts, credentials, or transactions—are known as honeytokens. Honeypots and honeynets refer to decoy systems or networks, and a honeyfile is a decoy file, not an account.
Question 137
A company wants to add an MFA solution for all employees who access the corporate network remotely. Log-in requirements include something you know, are, and have. The company wants a solution that does not require purchasing third-party applications or specialized hardware. Which of the following MFA solutions would best meet the company's requirements?
A. Smart card with PIN and password
B. Security questions and a one-time passcode sent via email
C. Voice and fingerprint verification with an SMS one-time passcode
D. Mobile application-generated, one-time passcode with facial recognition
Show Answer
Correct Answer: C
Explanation: The requirements are something you know, have, and are, without purchasing third‑party applications or specialized hardware. Option C satisfies all three: a password (something you know), an SMS one‑time passcode received on an existing mobile phone (something you have), and built‑in biometrics like voice and fingerprint verification (something you are). Option D relies on a mobile application–generated OTP, which typically implies a third‑party authenticator app, violating the stated constraint.
Question 138
A systems administrator is concerned users are accessing emails through a duplicate site that is not run by the company. Which of the following is used in this scenario?
A. Impersonation
B. Replication
C. Phishing
D. Smishing
Show Answer
Correct Answer: C
Explanation: The scenario describes users being deceived into using a duplicate website that mimics the company’s legitimate email site. Creating a fake site to trick users into entering credentials is a classic phishing attack. Impersonation is a broader concept of pretending to be someone else, but phishing specifically covers fraudulent websites designed to harvest information. Smishing is SMS-based phishing, and replication is unrelated.
Question 139
A Chief Information Security Officer is developing procedures to guide detective and corrective activities associated with common threats, including phishing, social engineering, and business email compromise. Which of the following documents would be most relevant to revise as part of this process?
A. SDLC
B. IRP
C. BCP
D. AUP
Show Answer
Correct Answer: B
Explanation: Detective and corrective activities for threats like phishing, social engineering, and business email compromise are handled through formal incident handling processes. The Incident Response Plan (IRP) defines how incidents are detected, analyzed, contained, eradicated, and recovered from, making it the most relevant document to revise. SDLC focuses on development, BCP on continuity after major disruptions, and AUP on user behavior, not incident response.
Question 140
Which of the following is an example of memory injection?
A. Two processes access the same variable, allowing one to cause a privilege escalation.
B. A process receives an unexpected amount of data, which causes malicious code to be executed.
C. Malicious code is copied to the allocated space of an already running process.
D. An executable is overwritten on the disk, and malicious code runs the next time it is executed.
Show Answer
Correct Answer: C
Explanation: Memory injection refers to placing malicious code directly into the memory space of an already running process so it executes without being written to disk. Option C explicitly describes this behavior. The other options describe different concepts: A is a race condition/privilege escalation, B is a buffer overflow scenario, and D is a disk-based persistence attack.
Question 141
A penetration test has demonstrated that domain administrator accounts were vulnerable to pass-the-hash attacks. Which of the following would have been the best strategy to prevent the threat actor from using domain administrator accounts?
A. Audit each domain administrator account weekly for password compliance.
B. Implement a privileged access management solution.
C. Create IDS policies to monitor domain controller access.
D. Use Group Policy to enforce password expiration.
Show Answer
Correct Answer: B
Explanation: Pass-the-hash attacks abuse stored or reused credential hashes rather than cracking passwords. A privileged access management (PAM) solution reduces this risk by vaulting and rotating privileged credentials, enforcing just-in-time access, isolating admin sessions, and limiting where credentials can be used, thereby preventing attackers from leveraging domain administrator hashes. Auditing, monitoring, or password expiration alone do not stop hash reuse.
Question 142
Due to a cyberattack, a company's IT systems were not operational for an extended period of time. The company wants to measure how quickly the systems must be restored in order to minimize business disruption. Which of the following would the company most likely use?
A. Recovery point objective
B. Risk appetite
C. Risk tolerance
D. Recovery time objective
E. Mean time between failure
Show Answer
Correct Answer: D
Explanation: The company wants to measure how quickly systems must be restored after an outage to minimize business disruption. This is defined by the Recovery Time Objective (RTO), which specifies the maximum acceptable downtime for systems following an incident. Other options address data loss (RPO), risk preferences, or failure frequency, not restoration speed.
$19
Get all 609 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.