Which of the following tools is best for logging and monitoring in a cloud environment?
A. IPS
B. FIM
C. NAC
D. SIEM
Show Answer
Correct Answer: D
Explanation: A Security Information and Event Management (SIEM) platform is designed to aggregate, log, correlate, analyze, and monitor security events from multiple systems, making it the best choice for logging and monitoring in a cloud environment. IPS prevents intrusions, FIM monitors file integrity, and NAC controls network access rather than providing centralized logging and monitoring.
Question 192
When trying to access an internal website, an employee reports that a prompt displays, stating that the site is insecure. Which of the following certificate types is the site most likely using?
A. Wildcard
B. Root of trust
C. Third-party
D. Self-signed
Show Answer
Correct Answer: D
Explanation: A browser warning that a site is insecure commonly occurs when the TLS certificate is not signed by a trusted Certificate Authority. Internal websites often use self-signed certificates, which are not trusted by client browsers unless the certificate or issuing CA has been explicitly installed. Wildcard certificates cover multiple subdomains, a root of trust is a trusted CA certificate rather than a site certificate type, and third-party CA-signed certificates are generally trusted by default.
Question 193
An audit reveals that cardholder database logs are exposing account numbers inappropriately. Which of the following mechanisms would help limit the impact of this error?
A. Segmentation
B. Hashing
C. Journaling
D. Masking
Show Answer
Correct Answer: D
Explanation: Masking is specifically designed to obscure sensitive portions of data such as payment card numbers when displayed or logged, reducing exposure if logs are accessed. Segmentation limits network scope, hashing is for one-way transformation rather than safely displaying account numbers in logs, and journaling records events rather than protecting sensitive values.
Question 194
A systems administrator successfully configures VPN access to a cloud environment. Which of the following capabilities should the administrator use to best facilitate remote administration?
A. A jump host in the shared services security zone
B. An SSH server within the corporate LAN
C. A reverse proxy on the firewall
D. An MDM solution with conditional access
Show Answer
Correct Answer: A
Explanation: A jump host (bastion host) placed in a shared services security zone is the standard capability for secure remote administration after VPN access is established. Administrators connect to the jump host and then manage cloud resources, allowing centralized access control, logging, and reduced exposure of management interfaces. An SSH server within the corporate LAN is not the primary cloud administration pattern, a reverse proxy is intended for publishing applications rather than administrative access, and MDM with conditional access manages device compliance rather than providing remote administration.
Question 195
An organization is required to provide assurance that its controls are properly designed and operating effectively. Which of the following reports will best achieve the objective?
A. Red teaming
B. Penetration testing
C. Independent audit
D. Vulnerability assessment
Show Answer
Correct Answer: C
Explanation: An independent audit provides formal assurance that controls are appropriately designed and operating effectively. Red teaming, penetration testing, and vulnerability assessments evaluate security posture or identify weaknesses, but they do not provide comprehensive assurance over the design and operating effectiveness of organizational controls.
Question 196
A malicious insider from the marketing team alters records and transfers company funds to a personal account. Which of the following methods would be the best way to secure company records in the future?
A. Permission restrictions
B. Hashing
C. Input validation
D. Access control list
Show Answer
Correct Answer: A
Explanation: The best preventive control against a malicious insider altering records and transferring funds is to restrict what users are authorized to do. Permission restrictions implement least privilege so marketing staff cannot modify financial records or initiate fund transfers. Hashing can detect unauthorized changes but does not prevent them. Input validation addresses invalid user input, not insider misuse. An access control list is one implementation of permissions, but the broader and best answer is permission restrictions.
Question 197
Which of the following definitions best describes the concept of log correlation?
A. Combining relevant logs from multiple sources into one location
B. Searching and processing data to identify patterns of malicious activity
C. Making a record of the events that occur in the system
D. Analyzing the log files of the system components
Show Answer
Correct Answer: B
Explanation: Log correlation is the process of analyzing and relating events from one or more log sources to identify meaningful patterns, anomalies, or indicators of malicious activity. Option A describes log aggregation (collecting logs into a central location), C describes logging, and D is generic log analysis rather than correlation.
Question 198
A network administrator wants to ensure that network traffic is highly secure while in transit.
Which of the following actions best describes the actions the network administrator should take?
A. Ensure that NAC is enforced on all network segments, and confirm that firewalls have updated policies to block unauthorized traffic.
B. Ensure only TLS and other encrypted protocols are selected for use on the network, and only permit authorized traffic via secure protocols.
C. Configure the perimeter IPS to block inbound HTTPS directory traversal traffic, and verify that signatures are updated on a daily basis.
D. Ensure the EDR software monitors for unauthorized applications that could be used by threat actors, and configure alerts for the security team.
Show Answer
Correct Answer: B
Explanation: To make network traffic highly secure while in transit, the primary control is encrypting data in motion. Enforcing TLS and other encrypted protocols protects confidentiality and integrity against interception and tampering. NAC, firewalls, IPS, and EDR improve overall security but do not directly ensure traffic is encrypted while in transit.
Question 199
Which of the following threat actors would most likely deface the website of a high-profile music group?
A. Unskilled attacker
B. Organized crime
C. Nation-state
D. Insider threat
Show Answer
Correct Answer: A
Explanation: Website defacement is commonly associated with unskilled attackers (often called script kiddies) seeking attention or notoriety using readily available tools. Organized crime is typically financially motivated, nation-state actors focus on espionage or strategic disruption, and insider threats involve misuse of authorized access rather than being the most likely explanation for a public website defacement of a music group.
Question 200
A legal department must maintain a backup from all devices that have been shredded and recycled by a third party. Which of the following best describes this requirement?
A. Data retention
B. Certification
C. Sanitization
D. Destruction
Show Answer
Correct Answer: A
Explanation: The key requirement is to maintain a backup of data from devices even after the physical devices have been shredded and recycled. That describes data retention: preserving data for legal, regulatory, or business purposes despite the underlying media being destroyed. Certification would be documentation proving destruction, sanitization is the process of removing data from media, and destruction is the physical disposal itself.
$19
Get all 608 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.