A new security regulation was announced that will take effect in the coming year. A company must comply with it to remain in business. Which of the following activities should the company perform next?
A. Gap analysis
B. Policy review
C. Security procedure evaluation
D. Threat scope reduction
Show Answer
Correct Answer: A
Explanation: When a new security regulation is announced, the appropriate next step is to perform a gap analysis. This activity compares the organization’s current security controls, policies, and procedures against the new regulatory requirements to identify what is missing or insufficient. The results then guide subsequent actions such as policy updates, procedure changes, and control implementations. The other options are narrower activities that should follow after the gaps are identified.
Question 224
Which of the following strategies should an organization use to efficiently manage and analyze multiple types of logs?
A. Deploy a SIEM solution
B. Create custom scripts to aggregate and analyze logs.
C. Implement EDR technology.
D. Install a unified threat management appliance.
Show Answer
Correct Answer: A
Explanation: A SIEM solution is purpose-built to centrally collect, normalize, correlate, and analyze logs from many different sources, enabling efficient monitoring, alerting, and reporting. The other options either focus on specific security functions (EDR, UTM) or lack scalability and advanced analytics (custom scripts).
Question 225
A company suffered a critical incident where 30GB of data was exfiltrated from the corporate network. Which of the following actions is the most efficient way to identify where the system data was exfiltrated from and what location the attacker sent the data to?
A. Analyze firewall and network logs for large amounts of outbound traffic to external IP addresses or domains.
B. Analyze IPS and IDS logs to find the IP addresses used by the attacker for reconnaissance scans.
C. Analyze endpoint and application logs to see whether file-sharing programs were running on the company systems.
D. Analyze external vulnerability scans and automated reports to identify the systems the attacker could have exploited a remote code vulnerability.
Show Answer
Correct Answer: A
Explanation: Firewall and network logs directly record outbound connections, traffic volumes, source internal systems, and destination external IPs/domains. Analyzing these logs is the most efficient way to identify both where the data was exfiltrated from inside the network and where it was sent. IDS/IPS, endpoint logs, or vulnerability scans do not reliably provide complete source-to-destination visibility for large data exfiltration.
Question 226
A group of developers has a shared backup account to access the source code repository. Which of the following is best way to secure the backup account if there is an SSO failure?
A. RAS
B. EAP
C. SAML
D. PAM
Show Answer
Correct Answer: D
Explanation: Privileged Access Management (PAM) is designed to secure shared or highly privileged accounts, such as a backup account used when SSO fails. PAM enforces strong authentication, access controls, credential vaulting and rotation, and provides auditing and session monitoring. The other options focus on authentication or access protocols (RAS, EAP, SAML) and do not address secure management of shared privileged accounts.
Question 227
An organization's web servers host an online ordering system. The organization discovers that the servers are vulnerable to a malicious JavaScript injection, which could allow attackers to access customer payment information. Which of the following mitigation strategies would be most effective for preventing an attack on the organization's web servers? (Choose two.)
A. Regularly updating server software and patches
B. Implementing strong password policies
C. Encrypting sensitive data at rest and in transit
D. Utilizing a web-application firewall
E. Performing regular vulnerability scans
F. Removing payment information from the servers
Show Answer
Correct Answer: A, D
Explanation: The vulnerability described is a malicious JavaScript injection (e.g., XSS). Regularly updating and patching server and application software mitigates known injection flaws in web servers, frameworks, and libraries. A web-application firewall (WAF) is specifically designed to inspect HTTP/S traffic and block malicious payloads such as JavaScript injection attempts. Other options either do not directly prevent the attack vector (password policies, encryption), are detective rather than preventive (vulnerability scans), or reduce impact rather than prevent the attack (removing stored payment data).
Question 228
Which of the following security concepts is being followed when implementing a product that offers protection against DDoS attacks?
A. Availability
B. Non-repudiation
C. Integrity
D. Confidentiality
Show Answer
Correct Answer: A
Explanation: Protection against DDoS attacks focuses on keeping systems and services accessible to legitimate users despite attempts to overwhelm them. This directly maps to the security principle of Availability, which ensures reliable and timely access to resources. Non-repudiation, integrity, and confidentiality are not the primary concerns addressed by DDoS mitigation.
Question 229
Which of the following is the best way to securely store an encryption key for a data set in a manner that allows multiple entities to access the key when needed?
A. Public key infrastructure
B. Open public ledger
C. Public key encryption
D. Key escrow
Show Answer
Correct Answer: D
Explanation: Key escrow is specifically designed to securely store encryption keys with a trusted authority so that multiple authorized entities can retrieve the key when needed. The other options describe cryptographic mechanisms or systems but do not address centralized, controlled key storage and shared access.
Question 230
Which of the following should an organization use to protect its environment from external attacks conducted by an unauthorized hacker?
A. ACL
B. IDS
C. HIDS
D. NIPS
Show Answer
Correct Answer: D
Explanation: A Network-based Intrusion Prevention System (NIPS) monitors network traffic inline and can actively block or prevent malicious activity originating from external, unauthorized attackers before it reaches internal systems. Unlike ACLs or IDS/HIDS, NIPS provides real-time prevention at the network perimeter.
Question 231
An organization maintains intellectual property that it wants to protect. Which of the following concepts would be most beneficial to add to the company’s security awareness training program?
A. Insider threat detection
B. Simulated threats
C. Phishing awareness
D. Business continuity planning
Show Answer
Correct Answer: A
Explanation: Intellectual property is most commonly compromised by insiders who already have authorized access, whether through malicious intent or negligence. Security awareness training that includes insider threat detection helps employees recognize risky behaviors, warning signs, and proper reporting procedures, directly supporting the protection of sensitive IP. Other options are valuable but less directly focused on IP protection.
Question 232
A systems administrator needs to ensure the secure communication of sensitive data within the organization’s private cloud. Which of the following is the best choice for the administrator to implement?
A. IPSec
B. SHA-1
C. RSA
D. TGT
Show Answer
Correct Answer: A
Explanation: IPSec is a comprehensive suite of protocols designed to secure IP communications by providing encryption, integrity, and authentication for data in transit. It is commonly used to protect sensitive communications within private cloud environments, such as through VPNs. SHA-1 is only a hashing algorithm, RSA is an encryption/key exchange algorithm but not a full communication security solution, and TGT is part of Kerberos authentication rather than data transmission security.
$19
Get all 609 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.