Which of the following is the best way to validate the integrity and availability of a disaster recovery site?
A. Lead a simulated failover.
B. Conduct a tabletop exercise.
C. Periodically test the generators.
D. Develop requirements for database encryption.
Show Answer
Correct Answer: A
Explanation: A simulated failover is the most effective way to validate both the availability and integrity of a disaster recovery site because it exercises the actual recovery environment, verifies systems can be brought online, and confirms that recovered data and configurations are usable. A tabletop exercise only reviews procedures, generator testing validates a single infrastructure component, and database encryption requirements are unrelated to validating DR site operation.
Question 162
An organization wants a third-party vendor to do a penetration test that targets a specific device. The organization has provided basic information about the device. Which of the following best describes this kind of penetration test?
A. Partially known environment
B. Unknown environment
C. Integrated
D. Known environment
Show Answer
Correct Answer: A
Explanation: A partially known environment penetration test provides the tester with limited information about the target, such as basic details about a specific device. This is between an unknown (black-box) test, where no prior information is given, and a known environment (white-box) test, where comprehensive information is provided. 'Integrated' is not a standard classification for the level of prior knowledge.
Question 163
An organization wants to implement a secure solution for remote users. The users handle sensitive PHI on a regular basis and need to access an internally developed corporate application. Which of the following best meet the organization's security requirements? (Choose two.)
A. Local administrative password
B. Perimeter network
C. Jump server
D. WAF
E. MFA
F. VPN
Show Answer
Correct Answer: E, F
Explanation: The best combination for remote users accessing an internal application while handling sensitive PHI is MFA and VPN. A VPN provides an encrypted tunnel for secure remote access to the internal network, and MFA strengthens authentication to reduce the risk of unauthorized access. A jump server is typically intended for administrative access rather than general end-user application access. A WAF protects web applications, a perimeter network hosts externally accessible services, and a local administrative password is unrelated to secure remote connectivity.
Question 164
A security officer is implementing a security awareness program and is placing security-themed posters around the building and is assigning online user training. Which of the following would the security officer most likely implement?
A. Password policy
B. Access badges
C. Phishing campaign
D. Risk assessment
Show Answer
Correct Answer: C
Explanation: Security awareness programs commonly include simulated phishing campaigns along with posters and online training to educate users and measure their ability to recognize phishing attempts. The other options are security controls or governance activities rather than awareness program components.
Question 165
An organization is implementing a COPE mobile device management policy. Which of the following should the organization include in the COPE policy? (Choose two.)
A. Remote wiping of the device
B. Data encryption
C. Requiring passwords with eight characters
D. Data usage caps
E. Employee data ownership
F. Personal application store access
Show Answer
Correct Answer: A, B
Explanation: COPE (Corporate-Owned, Personally Enabled) devices are organization-owned and centrally managed. A COPE policy should include security controls that protect corporate data, including the ability to remotely wipe a lost, stolen, or decommissioned device and requiring device data encryption. Data usage caps are administrative rather than core COPE security controls, employee data ownership is a legal/privacy consideration rather than a standard MDM control in this context, personal app store access is typically restricted or managed rather than required, and a specific eight-character password requirement is too implementation-specific compared with the broader security controls.
Question 166
A systems administrator receives an alert that a company’s internal file server is very slow and is only working intermittently. The systems administrator reviews the server management software and finds the following information about the server:
Which of the following indicators most likely triggered this alert?
A. Concurrent session usage
B. Network saturation
C. Account lockout
D. Resource consumption
Show Answer
Correct Answer: D
Explanation: The alert is most likely due to resource consumption. Extremely high CPU and memory utilization commonly causes a file server to become slow and intermittently responsive. Concurrent sessions, network saturation, or account lockouts do not as directly explain severe server-wide performance degradation based on the described management metrics.
Question 167
Which of the following techniques would attract the attention of a malicious attacker in an insider threat scenario?
A. Creating a false text file in /docs/salaries
B. Setting weak passwords in /etc/shadow
C. Scheduling vulnerable jobs in /etc/crontab
D. Adding a fake account to /etc/passwd
Show Answer
Correct Answer: A
Explanation: Creating a false file with an enticing name (a honeyfile/decoy) is a classic insider-threat detection technique. It is designed to attract unauthorized curiosity and generate alerts when accessed. The other options intentionally weaken the system or create real vulnerabilities rather than safely detecting malicious insider behavior.
Question 168
An organization is looking to optimize its environment and reduce the number of patches necessary for operating systems. Which of the following will best help to achieve this objective?
A. Microservices
B. Virtualization
C. Real-time operating system
D. Containers
Show Answer
Correct Answer: D
Explanation: Containers allow multiple applications to share a single host operating system kernel while remaining isolated. This reduces the number of full operating system instances that must be maintained and patched compared with deploying separate virtual machines. Microservices are an application architecture, virtualization typically increases the number of guest operating systems requiring patches, and a real-time operating system does not address patch reduction.
Question 169
A security architect wants to prevent employees from receiving malicious attachments by email. Which of the following functions should the chosen solution do?
A. Apply IP address reputation data.
B. Tap and monitor the email feed.
C. Scan email traffic inline.
D. Check SPF records.
Show Answer
Correct Answer: C
Explanation: The correct function is to scan email traffic inline so attachments can be inspected and blocked before delivery to users. IP reputation and SPF help identify suspicious senders or spoofing, but they do not inspect attachment content. Tapping and monitoring the email feed is passive monitoring rather than preventive blocking.
Question 170
Which of the following techniques can be used to sanitize the data contained on a hard drive while allowing for the hard drive to be repurposed?
A. Degaussing
B. Drive shredder
C. Retention platform
D. Wipe tool
Show Answer
Correct Answer: D
Explanation: A wipe tool securely overwrites the data on the hard drive, sanitizing its contents while preserving the drive for future use. Degaussing renders many modern drives unusable or unreliable and is not appropriate if the goal is repurposing the drive. A drive shredder physically destroys the drive, and a retention platform is for data retention, not sanitization.
$19
Get all 608 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.