An organization needs to monitor its users’ activities in order to prevent insider threats. Which of the following solutions would help the organization achieve this goal?
A. Behavioral analytics
B. Access control lists
C. Identity and access management
D. Network intrusion detection system
Show Answer
Correct Answer: A
Explanation: Behavioral analytics (often implemented as User and Entity Behavior Analytics, UEBA) monitors and analyzes user activity patterns to detect anomalies that may indicate insider threats. It focuses specifically on user behavior, unlike access controls, IAM, or network IDS, which primarily enforce permissions or detect external/network-based attacks rather than insider misuse.
Question 174
A penetration tester enters an office building at the same time as a group of employees despite not having an access badge. Which of the following attack types is the penetration tester performing?
A. Tailgating
B. Shoulder surfing
C. RFID cloning
D. Forgery
Show Answer
Correct Answer: A
Explanation: The tester gains unauthorized physical access by entering alongside authorized employees without a badge. This is tailgating, where an attacker follows legitimate users into a restricted area. The other options involve observing credentials, copying RFID data, or document falsification, none of which apply.
Question 175
A company plans to secure its systems by:
• Preventing users from sending sensitive data over corporate email
• Restricting access to potentially harmful websites
Which of the following features should the company set up? (Choose two.)
A. DLP software
B. DNS filtering
C. File integrity monitoring
D. Stateful firewall
E. Guardrails
F. Antivirus signatures
Show Answer
Correct Answer: A, B
Explanation: Preventing users from sending sensitive data over corporate email is accomplished with Data Loss Prevention (DLP) software, which detects and blocks transmission of sensitive information. Restricting access to potentially harmful websites is achieved through DNS filtering, which blocks or redirects requests to known malicious or inappropriate domains.
Question 176
A company is developing a critical system for the government and storing project information on a fileshare. Which of the following describes how this data will most likely be classified? (Choose two.)
A. Private
B. Confidential
C. Public
D. Operational
E. Urgent
F. Restricted
Show Answer
Correct Answer: B, F
Explanation: Project information for a critical government system is sensitive and not meant for public release. It would be classified as Confidential because unauthorized disclosure could cause significant harm. It would also be Restricted because access should be tightly controlled on a strict need-to-know basis, which is typical for critical government-related systems.
Question 177
Which of the following explains how to determine the global regulations that data is subject to regardless of the country where the data is stored?
A. Geographic dispersion
B. Data sovereignty
C. Geographic restrictions
D. Data segmentation
Show Answer
Correct Answer: B
Explanation: Data sovereignty describes how data is governed by the laws and regulations of the country or jurisdiction tied to the data (such as where it is collected or the nationality of data subjects), regardless of where the data is physically stored. This concept explains how global regulations apply across borders.
Question 178
Which of the following actors attacking an organization is the most likely to be motivated by personal beliefs?
A. Nation-state
B. Organized crime
C. Hacktivist
D. Insider threat
Show Answer
Correct Answer: C
Explanation: Hacktivists are primarily driven by personal, ideological, or political beliefs and attack organizations to promote or protest causes. Nation-states are politically strategic, organized crime is financially motivated, and insider threats are often driven by grievances or opportunity rather than broader belief systems.
Question 179
A government official receives a blank envelope containing photos and a note instructing the official to wire a large sum of money by midnight to prevent the photos from being leaked on the internet. Which of the following best describes the threat actor's intent?
A. Organized crime
B. Philosophical beliefs
C. Espionage
D. Blackmail
Show Answer
Correct Answer: D
Explanation: The threat actor is threatening to release compromising photos unless money is paid. This is a classic case of blackmail, where sensitive information is leveraged to coerce the victim into meeting demands. The scenario does not indicate ideological motives, intelligence gathering, or broader criminal organization goals.
Question 180
After failing an audit twice, an organization has been ordered by a government regulatory agency to pay fines. Which of the following causes this action?
A. Non-compliance
B. Contract violations
C. Government sanctions
D. Rules of engagement
Show Answer
Correct Answer: A
Explanation: Being ordered to pay fines by a government regulatory agency after failing audits indicates the organization did not meet required legal or regulatory standards. This situation is defined as non-compliance, which commonly results in penalties such as fines.
Question 181
Which of the following is a type of vulnerability that involves inserting scripts into web-based applications in order to take control of the client's web browser?
A. SQL injection
B. Cross-site scripting
C. Zero-day exploit
D. On-path attack
Show Answer
Correct Answer: B
Explanation: Cross-site scripting (XSS) is a vulnerability where attackers inject malicious scripts into web applications, which then execute in the client’s web browser. This can allow attackers to hijack sessions, steal cookies, or perform actions on behalf of the user.
Question 182
A security team at a large, global company needs to reduce the cost of storing data used for performing investigations. Which of the following types of data should have its retention length reduced?
A. Packet capture
B. Endpoint logs
C. OS security logs
D. Vulnerability scan
Show Answer
Correct Answer: A
Explanation: Packet capture data records full network traffic and grows extremely quickly, making it the most expensive data type to store long term. Its investigative value drops rapidly after an incident window, unlike endpoint logs, OS security logs, or vulnerability scan results, which are more compact and retain longer-term forensic and compliance value. Reducing packet capture retention yields the greatest cost savings with minimal impact.
$19
Get all 609 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.