Which of the following is the best way to validate the integrity and availability of a disaster recovery site?
A. Lead a simulated failover.
B. Conduct a tabletop exercise.
C. Periodically test the generators.
D. Develop requirements for database encryption.
Show Answer
Correct Answer: A
Explanation: Leading a simulated failover directly tests whether the disaster recovery site can actually take over operations, validating both availability (services can run from the DR site) and integrity (data and systems are intact and usable). Tabletop exercises are discussion-based only, generator testing is limited in scope, and encryption requirements are unrelated to DR site availability.
Question 164
An organization wants a third-party vendor to do a penetration test that targets a specific device. The organization has provided basic information about the device. Which of the following best describes this kind of penetration test?
A. Partially known environment
B. Unknown environment
C. Integrated
D. Known environment
Show Answer
Correct Answer: A
Explanation: The vendor is given some basic information about the specific device, but not full details of the environment. This places the test between a fully known (white box) and unknown (black box) assessment. Such scenarios are best described as a partially known environment (often called gray-box) penetration testing.
Question 165
An organization wants to implement a secure solution for remote users. The users handle sensitive PHI on a regular basis and need to access an internally developed corporate application. Which of the following best meet the organization's security requirements? (Choose two.)
A. Local administrative password
B. Perimeter network
C. Jump server
D. WAF
E. MFA
F. VPN
Show Answer
Correct Answer: E, F
Explanation: Remote users handling sensitive PHI require encrypted connectivity and strong authentication. A VPN provides a secure, encrypted tunnel into the internal network to access the corporate application, protecting data in transit. MFA strengthens authentication by requiring multiple factors, significantly reducing the risk of unauthorized access. Other options (jump server, DMZ, WAF) are not primary controls for secure end‑user remote access.
Question 166
A security officer is implementing a security awareness program and is placing security-themed posters around the building and is assigning online user training. Which of the following would the security officer most likely implement?
A. Password policy
B. Access badges
C. Phishing campaign
D. Risk assessment
Show Answer
Correct Answer: C
Explanation: Security-themed posters and mandatory online training are elements of a security awareness program. Among the options, a phishing campaign (specifically simulated phishing) is commonly used as part of awareness training to educate users on recognizing and avoiding attacks. The other options are technical or administrative controls, not awareness activities.
Question 167
An organization is implementing a COPE mobile device management policy. Which of the following should the organization include in the COPE policy? (Choose two.)
A. Remote wiping of the device
B. Data encryption
C. Requiring passwords with eight characters
D. Data usage caps
E. Employee data ownership
F. Personal application store access
Show Answer
Correct Answer: A, B
Explanation: COPE (Corporate-Owned, Personally Enabled) devices are owned and managed by the organization, so the policy should emphasize protecting corporate data while allowing personal use. Remote wiping is essential to remove corporate data if the device is lost, stolen, or an employee leaves. Data encryption ensures sensitive organizational data remains protected even if the device is compromised. The other options are either general configuration choices, cost controls, or less central to COPE security objectives.
Question 168
A systems administrator receives an alert that a company’s internal file server is very slow and is only working intermittently. The systems administrator reviews the server management software and finds the following information about the server:
Which of the following indicators most likely triggered this alert?
A. Concurrent session usage
B. Network saturation
C. Account lockout
D. Resource consumption
Show Answer
Correct Answer: D
Explanation: An internal file server that is very slow and only intermittently available most commonly triggers alerts related to excessive CPU, memory, disk I/O, or storage usage. These are indicators of resource consumption problems, which directly degrade performance and availability. The other options do not best explain intermittent slowness across the entire server.
Question 169
Which of the following techniques would attract the attention of a malicious attacker in an insider threat scenario?
A. Creating a false text file in /docs/salaries
B. Setting weak passwords in /etc/shadow
C. Scheduling vulnerable jobs in /etc/crontab
D. Adding a fake account to /etc/passwd
Show Answer
Correct Answer: A
Explanation: The question asks about a technique designed to *attract* and detect a malicious insider, not to weaken security. Creating a false or enticing file (e.g., a fake salaries document) is a classic honeypot/decoy technique used to lure insiders into revealing malicious intent through access attempts. The other options actively reduce system security and create real vulnerabilities rather than serving as controlled detection mechanisms.
Question 170
An organization is looking to optimize its environment and reduce the number of patches necessary for operating systems. Which of the following will best help to achieve this objective?
A. Microservices
B. Virtualization
C. Real-time operating system
D. Containers
Show Answer
Correct Answer: D
Explanation: Containers share a single host operating system kernel while isolating applications and their dependencies. By running many workloads on one OS instead of multiple full operating systems, the organization significantly reduces the number of operating systems that must be maintained and patched, directly meeting the goal of minimizing OS patching requirements.
Question 171
A security architect wants to prevent employees from receiving malicious attachments by email. Which of the following functions should the chosen solution do?
A. Apply IP address reputation data.
B. Tap and monitor the email feed.
C. Scan email traffic inline.
D. Check SPF records.
Show Answer
Correct Answer: C
Explanation: To prevent malicious attachments, the solution must inspect email content and attachments before delivery. Scanning email traffic inline allows real-time detection and blocking of malware-laden attachments. IP reputation and SPF focus on sender trustworthiness, not attachment content, and tapping/monitoring alone does not prevent delivery.
Question 172
Which of the following techniques can be used to sanitize the data contained on a hard drive while allowing for the hard drive to be repurposed?
A. Degaussing
B. Drive shredder
C. Retention platform
D. Wipe tool
Show Answer
Correct Answer: D
Explanation: A wipe tool securely overwrites the data on a hard drive, sanitizing its contents while leaving the hardware functional for reuse. Degaussing and shredding render the drive unusable, and a retention platform is for storing data, not sanitizing drives.
$19
Get all 609 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.