Which of the following aspects of the data management life cycle is most directly impacted by local and international regulations?
A. Destruction
B. Certification
C. Retention
D. Sanitization
Show Answer
Correct Answer: C
Explanation: Retention is the data management life cycle phase most directly driven by local and international laws and regulations. Legal and regulatory requirements often specify minimum or maximum periods for keeping different types of data (such as financial, healthcare, or personal records). Destruction and sanitization occur after retention requirements are met, while certification is not a core life cycle phase governed in the same direct way.
Question 132
A company filed a complaint with its IT service provider after the company discovered the service provider's external audit team had access to some of the company's confidential information. Which of the following is the most likely reason the company filed the complaint?
A. The MOU had basic clauses from a template.
B. A SOW had not been agreed to by the client.
C. A WO had not been mutually approved.
D. A required NDA had not been signed.
Show Answer
Correct Answer: D
Explanation: The most likely reason for the complaint is that a required Non-Disclosure Agreement (NDA) was not signed. External auditors may legitimately need access to confidential information during an audit, but they should be bound by confidentiality obligations. An MOU, SOW, or Work Order define relationships, scope, or tasks and do not primarily establish confidentiality protections.
Question 133
A company's accounting department receives an urgent payment message from the company's bank domain with instructions to wire transfer funds. The sender requests that the transfer be completed as soon as possible. Which of the following attacks is described?
A. Business email compromise
B. Vishing
C. Spear phishing
D. Impersonation
Show Answer
Correct Answer: A
Explanation: The scenario describes a fraudulent email requesting an urgent wire transfer while appearing to come from a trusted business entity (the company's bank). This is characteristic of a Business Email Compromise (BEC) attack, which uses email impersonation and urgency to induce financial transactions. Vishing is voice-based, spear phishing is a broader category of targeted phishing, and impersonation is a tactic rather than the specific attack type.
Question 134
A company discovers suspicious transactions that were entered into the company's database and attached to a user account that was created as a trap for malicious activity. Which of the following is the user account an example of?
A. Honeytoken
B. Honeynet
C. Honeypot
D. Honeyfile
Show Answer
Correct Answer: A
Explanation: A honeytoken is a decoy piece of data or fake digital asset, such as a user account, credential, database record, or API key, created to detect unauthorized access or malicious activity. A trap user account that attracts attackers and reveals suspicious transactions is a honeytoken. A honeypot is typically a decoy system or service, a honeynet is a network of honeypots, and a honeyfile is a decoy file.
Question 135
A company wants to add an MFA solution for all employees who access the corporate network remotely. Log-in requirements include something you know, are, and have. The company wants a solution that does not require purchasing third-party applications or specialized hardware. Which of the following MFA solutions would best meet the company's requirements?
A. Smart card with PIN and password
B. Security questions and a one-time passcode sent via email
C. Voice and fingerprint verification with an SMS one-time passcode
D. Mobile application-generated, one-time passcode with facial recognition
Show Answer
Correct Answer: D
Explanation: The stated requirements are the three authentication factor categories: something you know, have, and are. A smart card requires specialized hardware, eliminating A. Security questions plus email OTP lacks a biometric factor, eliminating B. Between C and D, D best aligns with common modern MFA deployments by using an existing mobile device (possession) and built-in facial recognition (biometric), with the knowledge factor supplied by the user's password as part of the login process. The reference to avoiding purchasing third-party applications is best interpreted as avoiding additional purchased solutions; authenticator apps are commonly available without purchase.
Question 136
A systems administrator is concerned users are accessing emails through a duplicate site that is not run by the company. Which of the following is used in this scenario?
A. Impersonation
B. Replication
C. Phishing
D. Smishing
Show Answer
Correct Answer: A
Explanation: The scenario emphasizes a duplicate website that is not operated by the company and is being used as the email access portal. A duplicate site that masquerades as the legitimate service is an example of impersonation. Phishing is a broader social engineering attack that commonly uses impersonation, but the prompt asks what is being used in this specific scenario rather than how users were lured to the site. Replication is unrelated, and smishing is phishing via SMS.
Question 137
A Chief Information Security Officer is developing procedures to guide detective and corrective activities associated with common threats, including phishing, social engineering, and business email compromise. Which of the following documents would be most relevant to revise as part of this process?
A. SDLC
B. IRP
C. BCP
D. AUP
Show Answer
Correct Answer: B
Explanation: The Incident Response Plan (IRP) is the document that defines procedures for detecting, responding to, containing, eradicating, and recovering from security incidents. Detective and corrective activities for phishing, social engineering, and business email compromise are core incident response functions. SDLC governs software development, BCP focuses on maintaining business operations during disruptions, and AUP defines acceptable user behavior rather than incident handling procedures.
Question 138
Which of the following is an example of memory injection?
A. Two processes access the same variable, allowing one to cause a privilege escalation.
B. A process receives an unexpected amount of data, which causes malicious code to be executed.
C. Malicious code is copied to the allocated space of an already running process.
D. An executable is overwritten on the disk, and malicious code runs the next time it is executed.
Show Answer
Correct Answer: C
Explanation: Memory injection is the technique of placing malicious code into the address space of an already running process so that it executes within that process. Option B describes a buffer overflow vulnerability, A is a race condition/shared-memory issue, and D describes file infection or executable tampering on disk rather than memory injection.
Question 139
A penetration test has demonstrated that domain administrator accounts were vulnerable to pass-the-hash attacks. Which of the following would have been the best strategy to prevent the threat actor from using domain administrator accounts?
A. Audit each domain administrator account weekly for password compliance.
B. Implement a privileged access management solution.
C. Create IDS policies to monitor domain controller access.
D. Use Group Policy to enforce password expiration.
Show Answer
Correct Answer: B
Explanation: A privileged access management (PAM) solution is the best preventive control against misuse of domain administrator accounts in pass-the-hash attacks. PAM reduces persistent privileged credential exposure through techniques such as just-in-time administration, credential vaulting, privileged session controls, and limiting where privileged credentials are present. Auditing password compliance and password expiration do not prevent pass-the-hash because the attack reuses NTLM hashes rather than needing the plaintext password. IDS policies provide detection rather than prevention.
Question 140
Due to a cyberattack, a company's IT systems were not operational for an extended period of time. The company wants to measure how quickly the systems must be restored in order to minimize business disruption. Which of the following would the company most likely use?
A. Recovery point objective
B. Risk appetite
C. Risk tolerance
D. Recovery time objective
E. Mean time between failure
Show Answer
Correct Answer: D
Explanation: Recovery Time Objective (RTO) defines the maximum acceptable downtime and the target time to restore systems after a disruption to minimize business impact. Recovery Point Objective (RPO) measures acceptable data loss, while risk appetite/tolerance relate to organizational risk acceptance, and MTBF measures reliability between failures.
$19
Get all 608 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.