Which of the following security concepts is accomplished when granting access after an individual has logged into a computer network?
A. Authorization
B. Identification
C. Non-repudiation
D. Authentication
Show Answer
Correct Answer: A
Explanation: After a user has logged in, their identity has already been authenticated. The subsequent process of granting or denying access to specific resources and actions is authorization. Identification is the initial claim of identity, authentication verifies that identity, and non-repudiation provides proof that actions cannot later be denied.
Question 142
Which of the following allows a systems administrator to tune permissions for a file?
A. Patching
B. Access control list
C. Configuration enforcement
D. Least privilege
Show Answer
Correct Answer: B
Explanation: An access control list (ACL) is the mechanism used to define and adjust file permissions by specifying which users or groups have read, write, execute, or other permissions on a file. Patching updates software, configuration enforcement maintains desired settings, and least privilege is a security principle rather than the mechanism for tuning file permissions.
Question 143
A company's website is www.company.com. Attackers purchased the domain www.c0mpany.com. Which of the following types of attacks describes this example?
A. Typosquatting
B. Brand impersonation
C. On-path
D. Watering-hole
Show Answer
Correct Answer: A
Explanation: The best answer is Typosquatting. Registering a look-alike domain such as 'www.c0mpany.com' that substitutes a visually similar character ('0' for 'o') is a form of typosquatting (often including homoglyph/look-alike domain variants) used to capture users who mistype or misread the legitimate domain. Brand impersonation typically refers to the broader act of posing as a trusted brand, often using such a domain, but the domain-registration technique itself is typosquatting.
Question 144
Which of the following steps in the risk management process involves establishing the scope and potential risks involved with a project?
A. Risk assessment
B. Risk identification
C. Risk treatment
D. Risk monitoring and review
Show Answer
Correct Answer: B
Explanation: Risk identification is the phase where the project context/scope is established for the purpose of identifying what could affect objectives, and potential risks are identified and documented. Risk assessment follows identification and analyzes the likelihood and impact of those identified risks. Risk treatment is about selecting responses, and monitoring/review is ongoing oversight.
Question 145
A security administrator is implementing encryption on all hard drives in an organization. Which of the following security concepts is the administrator applying?
A. Integrity
B. Authentication
C. Zero Trust
D. Confidentiality
Show Answer
Correct Answer: D
Explanation: Encrypting hard drives protects data at rest from unauthorized disclosure. This primarily implements the security concept of confidentiality, not integrity, authentication, or Zero Trust.
Question 146
Which of the following is the best way to prevent an unauthorized user from plugging a laptop into an employee's phone network port and then using tools to scan for database servers?
A. MAC filtering
B. Segmentation
C. Certification
D. Isolation
Show Answer
Correct Answer: B
Explanation: Network segmentation is the best control for preventing a device connected through an employee's VoIP phone port from discovering or scanning database servers. By placing user/phone access ports on separate VLANs or network segments with ACLs/firewalls controlling access to server networks, an unauthorized laptop cannot reach or enumerate database servers. MAC filtering is easily bypassed by MAC spoofing, certification is ambiguous wording (likely certificate-based auth/802.1X) and is not the listed standard control name, and isolation is too generic.
Sources:
https://routersecurity.org/RouterNews.php
Question 147
A security team is in the process of hardening the network against externally crafted malicious packets. Which of the following is the most secure method to protect the internal network?
A. Anti-malware solutions
B. Host-based firewalls
C. Intrusion prevention systems
D. Network access control
E. Network allow list
Show Answer
Correct Answer: C
Explanation: An Intrusion Prevention System (IPS) is purpose-built to inspect network traffic inline and automatically block malicious or malformed packets before they reach internal systems. Anti-malware and host-based firewalls protect endpoints, NAC controls device admission rather than packet inspection, and a network allow list can reduce exposure but does not generally provide comprehensive protection against externally crafted malicious packets in the way an IPS does.
Question 148
An analyst is reviewing job postings to ensure sensitive company information is not being shared with the general public. Which of the following is the analyst most likely looking for?
A. Office addresses
B. Software versions
C. List of board members
D. Government identification numbers
Show Answer
Correct Answer: B
Explanation: Job postings are commonly reviewed for inadvertent information disclosure that helps attackers profile an environment. Listing specific software products and versions can reveal the organization's technology stack and potentially expose known vulnerabilities, making it valuable reconnaissance information. Office addresses and board members are generally public, and government identification numbers would not normally appear in a job posting or be relevant to the hiring description.
Question 149
A network engineer is increasing the overall security of network devices and needs to harden the devices. Which of the following will best accomplish this task?
A. Configuring centralized logging
B. Generating local administrator accounts
C. Replacing Telnet with SSH
D. Enabling HTTP administration
Show Answer
Correct Answer: C
Explanation: Replacing Telnet with SSH hardens network devices by using encrypted remote administrative access instead of Telnet, which sends credentials and session data in plaintext. Centralized logging aids monitoring rather than hardening, local administrator accounts are not the best hardening measure in this context, and enabling HTTP administration is insecure because HTTP is unencrypted.
Question 150
A systems administrator is reviewing the VPN logs and notices that during non-working hours a user is accessing the company file server and information is being transferred to a suspicious IP address. Which of the following threats is most likely occurring?
A. Typosquatting
B. Root or trust
C. Data exfiltration
D. Blackmail
Show Answer
Correct Answer: C
Explanation: The scenario describes unauthorized transfer of company data from an internal file server to an external suspicious IP address, especially during non-working hours. This is characteristic of data exfiltration, often performed by a malicious insider or a compromised account. The other options do not match: typosquatting involves deceptive domain names, root of trust refers to a security concept, and blackmail is an extortion tactic rather than the observed network activity.
$19
Get all 608 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.