An organization needs to monitor its users’ activities in order to prevent insider threats. Which of the following solutions would help the organization achieve this goal?
A. Behavioral analytics
B. Access control lists
C. Identity and access management
D. Network intrusion detection system
Show Answer
Correct Answer: A
Explanation: Behavioral analytics (often implemented as User and Entity Behavior Analytics, UEBA) monitors and analyzes user activity to detect anomalous behavior that may indicate insider threats. ACLs and IAM manage or restrict access but do not continuously analyze behavior for insider threat detection. A network intrusion detection system primarily detects malicious network activity, especially external or network-based threats, rather than user behavior.
Question 172
A penetration tester enters an office building at the same time as a group of employees despite not having an access badge. Which of the following attack types is the penetration tester performing?
A. Tailgating
B. Shoulder surfing
C. RFID cloning
D. Forgery
Show Answer
Correct Answer: A
Explanation: The described scenario is tailgating: an unauthorized person gains entry to a restricted area by following authorized employees through a secured entrance without using their own access badge. Shoulder surfing involves observing someone enter sensitive information, RFID cloning involves copying a badge's RFID credentials, and forgery involves creating fake documents or credentials.
Question 173
A company plans to secure its systems by:
• Preventing users from sending sensitive data over corporate email
• Restricting access to potentially harmful websites
Which of the following features should the company set up? (Choose two.)
A. DLP software
B. DNS filtering
C. File integrity monitoring
D. Stateful firewall
E. Guardrails
F. Antivirus signatures
Show Answer
Correct Answer: A, B
Explanation: Data Loss Prevention (DLP) software is designed to detect and prevent users from transmitting sensitive data through channels such as corporate email. DNS filtering restricts access to malicious or inappropriate websites by controlling DNS resolution. File integrity monitoring detects unauthorized file changes, stateful firewalls track network connections but do not specifically prevent sensitive email transmission or filter websites by DNS, guardrails are governance controls rather than the required security features here, and antivirus signatures detect known malware.
Question 174
A company is developing a critical system for the government and storing project information on a fileshare. Which of the following describes how this data will most likely be classified? (Choose two.)
A. Private
B. Confidential
C. Public
D. Operational
E. Urgent
F. Restricted
Show Answer
Correct Answer: B, F
Explanation: Government project information for a critical system would typically be classified as Confidential because unauthorized disclosure could cause significant harm, and Restricted because access should be limited to authorized personnel on a need-to-know basis. The other options are either not standard sensitivity classifications for this context (Operational, Urgent), too broad or inappropriate (Public), or generally refer to personal information rather than sensitive government project data (Private).
Question 175
Which of the following explains how to determine the global regulations that data is subject to regardless of the country where the data is stored?
A. Geographic dispersion
B. Data sovereignty
C. Geographic restrictions
D. Data segmentation
Show Answer
Correct Answer: B
Explanation: Data sovereignty is the principle that data is governed by the laws and regulations applicable to its jurisdiction, often based on where it is collected, processed, or associated, and in many regulatory regimes regardless of where it is physically stored. Geographic dispersion describes distribution of data, geographic restrictions are limits on access or movement, and data segmentation refers to separating data into categories, not determining applicable regulations.
Question 176
Which of the following actors attacking an organization is the most likely to be motivated by personal beliefs?
A. Nation-state
B. Organized crime
C. Hacktivist
D. Insider threat
Show Answer
Correct Answer: C
Explanation: Hacktivists are primarily motivated by ideological, social, or political beliefs and target organizations to promote a cause or protest. Nation-states are driven by national interests, organized crime by financial gain, and insider threats can have varied motives but are not most commonly defined by personal beliefs.
Question 177
A government official receives a blank envelope containing photos and a note instructing the official to wire a large sum of money by midnight to prevent the photos from being leaked on the internet. Which of the following best describes the threat actor's intent?
A. Organized crime
B. Philosophical beliefs
C. Espionage
D. Blackmail
Show Answer
Correct Answer: D
Explanation: The threat actor is demanding money while threatening to publicly release compromising photos if the demand is not met. This is blackmail, where sensitive information is used as leverage to extort payment.
Question 178
After failing an audit twice, an organization has been ordered by a government regulatory agency to pay fines. Which of the following causes this action?
A. Non-compliance
B. Contract violations
C. Government sanctions
D. Rules of engagement
Show Answer
Correct Answer: A
Explanation: Regulatory fines imposed after repeated audit failures are caused by the organization's failure to meet required regulatory or legal requirements. That underlying cause is non-compliance. Government sanctions are the penalty imposed, not the cause; contract violations relate to agreements between parties; and rules of engagement define testing boundaries, not regulatory audit outcomes.
Question 179
Which of the following is a type of vulnerability that involves inserting scripts into web-based applications in order to take control of the client's web browser?
A. SQL injection
B. Cross-site scripting
C. Zero-day exploit
D. On-path attack
Show Answer
Correct Answer: B
Explanation: Cross-site scripting (XSS) is the vulnerability in which attackers inject malicious client-side scripts into web applications. Those scripts execute in users' browsers and can steal session cookies, hijack sessions, or perform actions in the context of the victim. SQL injection targets databases, a zero-day exploit refers to exploiting an unknown/unpatched vulnerability, and an on-path attack intercepts communications rather than injecting scripts into web pages.
Question 180
A security team at a large, global company needs to reduce the cost of storing data used for performing investigations. Which of the following types of data should have its retention length reduced?
A. Packet capture
B. Endpoint logs
C. OS security logs
D. Vulnerability scan
Show Answer
Correct Answer: A
Explanation: Packet capture (PCAP) data is by far the most storage-intensive of the listed data types because it contains raw network traffic. Organizations commonly retain PCAP for much shorter periods than logs to control storage costs while keeping endpoint, OS security, and vulnerability data longer for historical investigations, detection, and compliance. Reducing PCAP retention yields the greatest storage savings with the least impact on long-term investigative capability.
$19
Get all 608 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.