An unexpected and out-of-character email message from a Chief Executive Officer's corporate account asked an employee to provide financial information and to change the recipient's contact number. Which of the following attack vectors is most likely being used?
A. Business email compromise
B. Phishing
C. Brand impersonation
D. Pretexting
Show Answer
Correct Answer: A
Explanation: The scenario matches a Business Email Compromise (BEC) attack: an email appearing to come from the CEO's corporate account makes an unusual request involving financial information and changing contact details. BEC specifically involves impersonating or compromising trusted business email accounts, often executives, to manipulate employees into financial or sensitive-information actions. While phishing is a broader category and pretexting is a social engineering technique used within such attacks, BEC is the most specific and accurate attack vector here.
Question 12
An employee receives a text message from an unrecognized number claiming to be the Chief Executive Officer and asking the employee to purchase gift cards. Which of the following types of attacks describes this example?
A. Watering-hole
B. Disinformation
C. Phishing
D. Impersonation
Show Answer
Correct Answer: D
Explanation: The scenario centers on an attacker pretending to be the CEO to convince an employee to buy gift cards. This is an impersonation (executive impersonation/CEO fraud) social engineering attack. If 'smishing' were an option, the text-message medium would make that more specific; if only 'phishing' and 'impersonation' are available, the defining characteristic described is impersonating the CEO.
Question 13
Which of the following phases of the incident response process attempts to minimize disruption?
A. Recovery
B. Containment
C. Preparation
D. Analysis
Show Answer
Correct Answer: B
Explanation: Containment is the incident response phase focused on limiting the scope and impact of an incident by isolating affected systems and preventing further spread, thereby minimizing disruption. Recovery restores systems to normal operation after the incident is contained, Preparation occurs before incidents, and Analysis identifies and investigates the incident.
Question 14
Which of the following should be used to ensure a user has the permissions needed to effectively do an assigned job role?
A. Changing default passwords
B. Implementing least privilege
C. Enforcing baseline configurations
D. Applying network segmentation
Show Answer
Correct Answer: B
Explanation: The principle of least privilege ensures users are granted only the minimum permissions required to perform their assigned job responsibilities. This both enables them to do their work and reduces the risk of excessive access. The other options address different security controls: changing default passwords secures accounts, baseline configurations standardize systems, and network segmentation limits network access.
Question 15
A security analyst receives an alert that there was an attempt to download known malware. Which of the following actions would allow the best chance to analyze the malware?
A. Review the IPS logs and determine which command-and-control IPs were blocked.
B. Analyze application logs to see how the malware attempted to maintain persistence.
C. Run vulnerability scans to check for systems and applications that are vulnerable to the malware
D. Obtain and execute the malware in a sandbox environment and perform packet captures.
Show Answer
Correct Answer: D
Explanation: Executing the malware in an isolated sandbox provides the best opportunity for dynamic analysis. It allows the analyst to safely observe the malware's behavior, persistence mechanisms, file and registry changes, process activity, and network communications. Performing packet captures during execution reveals command-and-control traffic and other network indicators. The other options provide indirect information or defensive assessment but do not enable comprehensive malware analysis.
Question 16
Which of the following is the first step to secure a newly deployed server?
A. Close unnecessary service ports.
B. Update the current version of the software.
C. Add the device to the ACL.
D. Upgrade the OS version.
Show Answer
Correct Answer: B
Explanation: The best first step for a newly deployed server is to update the currently installed software and apply security patches. This addresses known vulnerabilities before the server is placed into normal operation. Closing unnecessary ports, configuring ACLs, and upgrading the OS version are all valuable hardening measures, but patching the existing software is the more fundamental initial action. An OS upgrade is not always required, whereas applying current updates is standard practice.
Question 17
During a recent log review, an analyst discovers evidence of successful injection attacks. Which of the following will best address this issue?
A. Authentication
B. Secure cookies
C. Static code analysis
D. Input validation
Show Answer
Correct Answer: D
Explanation: Successful injection attacks are most effectively mitigated by implementing proper input validation. Validating and sanitizing user-supplied input helps prevent malicious data from being interpreted as commands or queries. Authentication does not stop injection vulnerabilities, secure cookies address cookie security rather than injection, and static code analysis can help identify vulnerabilities during development but does not directly address the issue as effectively as input validation.
Question 18
Which of the following would most likely be a hacktivist's motive?
A. Financial gain
B. Espionage
C. Philosophical beliefs
D. Revenge
Show Answer
Correct Answer: C
Explanation: Hacktivists are primarily motivated by ideological, political, or social causes. Their actions are intended to promote or protest issues aligned with their philosophical beliefs rather than to achieve financial gain, conduct espionage, or seek personal revenge.
Question 19
The physical security team at a company receives reports that employees are not displaying their badges. The team also observes employees tailgating at controlled entrances. Which of the following topics will the security team most likely emphasize in upcoming security training?
A. Social engineering
B. Situational awareness
C. Phishing
D. Acceptable use policy
Show Answer
Correct Answer: B
Explanation: Situational awareness is the best fit because the observed issues are employees failing to display badges and allowing tailgating at controlled entrances. Training would emphasize paying attention to surroundings, verifying identities, following badge procedures, and preventing unauthorized entry. While tailgating is a social engineering technique, the question asks what topic the security team would emphasize given employee behavior, making situational awareness the most appropriate choice.
Question 20
A business provides long-term cold storage services to banks that are required to follow regulator-imposed data retention guidelines. Banks that use these services require that data is disposed of in a specific manner at the conclusion of the regulatory threshold for data retention. Which of the following aspects of data management is the most important to the bank in the destruction of this data?
A. Encryption
B. Classification
C. Certification
D. Procurement
Show Answer
Correct Answer: C
Explanation: The key concern is being able to demonstrate that retained data was destroyed in accordance with regulatory and contractual requirements. Certification (such as a certificate of destruction or documented attestation of compliant media sanitization) provides evidence for audits and compliance. Encryption protects data at rest or in transit, classification identifies data sensitivity, and procurement relates to acquiring services rather than verifying secure destruction.
$19
Get all 608 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.