Which of the following security concepts is accomplished when granting access after an individual has logged into a computer network?
A. Authorization
B. Identification
C. Non-repudiation
D. Authentication
Show Answer
Correct Answer: A
Explanation: Granting access to resources after a user has already logged in refers to authorization. Authentication verifies identity during login, while authorization determines what the authenticated user is allowed to access or do. Identification and non-repudiation do not involve post-login access control.
Question 144
Which of the following allows a systems administrator to tune permissions for a file?
A. Patching
B. Access control list
C. Configuration enforcement
D. Least privilege
Show Answer
Correct Answer: B
Explanation: An Access Control List (ACL) lets an administrator precisely define which users or groups can access a file and what actions (read, write, execute) they are allowed, which is exactly how file permissions are tuned.
Question 145
A company's website is www.company.com. Attackers purchased the domain www.c0mpany.com. Which of the following types of attacks describes this example?
A. Typosquatting
B. Brand impersonation
C. On-path
D. Watering-hole
Show Answer
Correct Answer: A
Explanation: Registering a look‑alike domain that differs by a small character change (using "0" instead of "o") to capture users who mistake the legitimate URL is typosquatting. It is not on‑path or watering‑hole, and brand impersonation is broader, while this example specifically describes a deceptive, typo-based domain.
Question 146
Which of the following steps in the risk management process involves establishing the scope and potential risks involved with a project?
A. Risk assessment
B. Risk identification
C. Risk treatment
D. Risk monitoring and review
Show Answer
Correct Answer: B
Explanation: The step that establishes the project scope and identifies potential risks is risk identification. This phase focuses on recognizing and listing what could go wrong within the defined project context. Risk assessment comes afterward and analyzes the likelihood and impact of those identified risks, while treatment and monitoring occur later in the process.
Question 147
A security administrator is implementing encryption on all hard drives in an organization. Which of the following security concepts is the administrator applying?
A. Integrity
B. Authentication
C. Zero Trust
D. Confidentiality
Show Answer
Correct Answer: D
Explanation: Encrypting hard drives protects data at rest from unauthorized access, ensuring that only authorized parties with the decryption key can read it. This directly applies the security concept of confidentiality.
Question 148
Which of the following is the best way to prevent an unauthorized user from plugging a laptop into an employee's phone network port and then using tools to scan for database servers?
A. MAC filtering
B. Segmentation
C. Certification
D. Isolation
Show Answer
Correct Answer: C
Explanation: The question asks for the *best* way to prevent an unauthorized laptop from gaining network access and scanning for database servers when plugged into a phone network port. Certificate-based authentication (e.g., 802.1X with EAP-TLS) enforces authentication at the switch port before any network access is granted. Unlike MAC filtering, which is easily spoofed, certification uses cryptographic credentials that cannot be trivially bypassed. Segmentation limits what can be seen after access is granted, but does not stop the unauthorized device from connecting in the first place. Therefore, certification is the strongest and most effective control.
Question 149
A security team is in the process of hardening the network against externally crafted malicious packets. Which of the following is the most secure method to protect the internal network?
A. Anti-malware solutions
B. Host-based firewalls
C. Intrusion prevention systems
D. Network access control
E. Network allow list
Show Answer
Correct Answer: C
Explanation: An Intrusion Prevention System (IPS) is specifically designed to inspect network traffic in real time and block malicious or malformed packets before they reach the internal network. It directly addresses the threat of externally crafted malicious packets at the network level, providing proactive and centralized protection. Other options either focus on endpoints (anti-malware, host-based firewalls), access control rather than packet inspection (NAC), or are less flexible and comprehensive against diverse attack techniques (network allow lists).
Question 150
An analyst is reviewing job postings to ensure sensitive company information is not being shared with the general public. Which of the following is the analyst most likely looking for?
A. Office addresses
B. Software versions
C. List of board members
D. Government identification numbers
Show Answer
Correct Answer: B
Explanation: In job postings, analysts commonly watch for inadvertent disclosure of information that reveals the organization’s technical environment or security posture. Listing specific software versions can expose potential vulnerabilities that attackers could target. Government identification numbers are highly sensitive but would not realistically appear in job ads, making software versions the most plausible concern.
Question 151
A network engineer is increasing the overall security of network devices and needs to harden the devices. Which of the following will best accomplish this task?
A. Configuring centralized logging
B. Generating local administrator accounts
C. Replacing Telnet with SSH
D. Enabling HTTP administration
Show Answer
Correct Answer: C
Explanation: Hardening network devices focuses on reducing vulnerabilities and securing management access. Replacing Telnet with SSH encrypts authentication credentials and management traffic, preventing interception and unauthorized access. The other options either do not directly harden devices or reduce security.
Question 152
A systems administrator is reviewing the VPN logs and notices that during non-working hours a user is accessing the company file server and information is being transferred to a suspicious IP address. Which of the following threats is most likely occurring?
A. Typosquatting
B. Root or trust
C. Data exfiltration
D. Blackmail
Show Answer
Correct Answer: C
Explanation: The logs show a user accessing internal file servers outside normal hours and transferring information to a suspicious external IP address. This behavior matches data exfiltration, which is the unauthorized extraction and transfer of data from an organization to an external destination. The other options do not involve covert data transfer from internal systems.
$19
Get all 609 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.