A new employee accessed an unauthorized website. An investigation found that the employee violated the company's rules. Which of the following did the employee violate?
A. MOU
B. AUP
C. NDA
D. MOA
Show Answer
Correct Answer: B
Explanation: An Acceptable Use Policy (AUP) defines the rules for how employees may use company systems, networks, and internet resources. Accessing an unauthorized website directly violates these usage guidelines, making the AUP the policy that was breached.
Question 154
A malicious actor is trying to access sensitive financial information from a company's database by intercepting and reusing log-in credentials. Which of the following attacks is the malicious actor attempting?
A. SQL injection
B. On-path
C. Brute-force
D. Password spraying
Show Answer
Correct Answer: B
Explanation: The scenario describes intercepting and reusing valid login credentials in transit. That behavior characterizes an on-path (man-in-the-middle) attack, where an attacker intercepts communications to capture credentials and then uses them for unauthorized access. The other options involve guessing or injecting input, not interception.
Question 155
A company is performing a risk assessment on new software the company plans to use. Which of the following should the company assess during this process?
A. Software vulnerabilities
B. Cost-benefit analysis
C. Ongoing monitoring strategies
D. Network infrastructure compatibility
Show Answer
Correct Answer: A
Explanation: A risk assessment focuses on identifying and evaluating potential risks associated with the software, especially security-related risks. Assessing software vulnerabilities is a core component of this process because it reveals weaknesses that could be exploited and impact confidentiality, integrity, or availability. The other options relate more to planning, implementation, or operational considerations rather than risk identification.
Question 156
Which of the following describes the procedures a penetration tester must follow while conducting a test?
A. Rules of engagement
B. Rules of acceptance
C. Rules of understanding
D. Rules of execution
Show Answer
Correct Answer: A
Explanation: The procedures a penetration tester must follow during a test are defined by the Rules of Engagement (RoE), which specify scope, methods, boundaries, legal considerations, and expectations to ensure the test is conducted safely and appropriately.
Question 157
Which of the following describes the most effective way to address OS vulnerabilities after they are identified?
A. Endpoint protection
B. Removal of unnecessary software
C. Configuration enforcement
D. Patching
Show Answer
Correct Answer: D
Explanation: Patching directly remediates identified OS vulnerabilities by applying vendor-provided fixes that correct security flaws. While endpoint protection, removing unnecessary software, and configuration enforcement reduce attack surface or add defensive layers, they do not eliminate the underlying vulnerability itself. Therefore, patching is the most effective response once vulnerabilities are identified.
Question 158
A security administrator is addressing an issue with a legacy system that communicates data using an unencrypted protocol to transfer sensitive data to a third party. No software updates that use an encrypted protocol are available, so a compensating control is needed. Which of the following are the most appropriate for the administrator to suggest? (Choose two.)
A. Tokenization
B. Cryptographic downgrade
C. SSH tunneling
D. Segmentation
E. Patch installation
F. Data masking
Show Answer
Correct Answer: C, D
Explanation: The problem is unencrypted data in transit from a legacy system with no upgrade path, so compensating controls must reduce exposure without changing the protocol.
SSH tunneling wraps the insecure protocol inside an encrypted channel, directly protecting sensitive data in transit to the third party.
Network segmentation isolates the legacy system and tightly restricts where and how it can communicate, reducing the attack surface and limiting who can observe or exploit the unencrypted protocol.
Tokenization and data masking focus on data at rest or application-level handling, patching is not possible, and cryptographic downgrade weakens security rather than compensating for it.
Question 159
Which of the following types of identification methods can be performed on a deployed application during runtime?
A. Dynamic analysis
B. Code review
C. Package monitoring
D. Bug bounty
Show Answer
Correct Answer: A
Explanation: Dynamic analysis examines an application while it is executing, which means it can be performed on a deployed application during runtime. Code review is a pre-deployment static activity, package monitoring focuses on dependency tracking rather than runtime behavior, and bug bounty programs are engagement models rather than a specific runtime identification method.
Question 160
An administrator wants to automate an account permissions update for a large number of accounts. Which of the following would best accomplish this task?
A. Security groups
B. Federation
C. User provisioning
D. Vertical scaling
Show Answer
Correct Answer: A
Explanation: Security groups are the best choice because they allow an administrator to manage permissions for a large number of existing accounts by changing group membership or group-assigned permissions once, which then applies to all members automatically. This is an efficient and standard way to update permissions at scale. User provisioning focuses on automating account lifecycle tasks (creation, modification, deprovisioning) rather than primarily managing permission changes across many existing users.
Question 161
Which of the following testing techniques uses both defensive and offensive testing methodologies with developers to securely build key applications and software?
A. Blue
B. Yellow
C. Red
D. Green
Show Answer
Correct Answer: B
Explanation: The Yellow Team combines offensive (Red Team) and defensive (Blue Team) security practices and works closely with developers to embed security into the software development lifecycle. Its focus is on securely building applications by proactively identifying and mitigating vulnerabilities during development, which matches the description in the question.
Question 162
The management team reports that employees are missing features on company-provided tablets, which is causing productivity issues. The management team directs the IT team to resolve the issue within 48 hours. Which of the following would be the best solution for the IT team to leverage in this scenario?
A. EDR
B. COPE
C. MDM
D. FDE
Show Answer
Correct Answer: C
Explanation: Mobile Device Management (MDM) allows IT to centrally manage company-provided tablets, including deploying missing applications or features, configuring settings, and pushing updates remotely. This directly addresses productivity issues and can be executed quickly within the 48-hour requirement. EDR focuses on threat detection, COPE is a device ownership model rather than a technical solution, and FDE is for data protection, not feature management.
$19
Get all 609 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.