A company is concerned about theft of client data from decommissioned laptops. Which of the following is the most cost-effective method to decrease this risk?
A. Wiping
B. Recycling
C. Shredding
D. Deletion
Show Answer
Correct Answer: A
Explanation: The question asks for the most cost-effective way to reduce the risk of data theft from decommissioned laptops. Secure wiping overwrites the storage so data cannot be recovered with normal tools, while allowing the laptop or drive to be reused or resold. Deletion is insufficient, recycling does not guarantee data destruction, and shredding—while very effective—is more expensive due to specialized equipment and loss of hardware value. Therefore, wiping provides the best balance of security and cost.
Question 234
Which of the following should a security team do first before a new web server goes live?
A. Harden the virtual host.
B. Create WAF rules.
C. Enable network intrusion detection.
D. Apply patch management.
Show Answer
Correct Answer: A
Explanation: The first action before a new web server goes live is to establish a secure baseline by hardening the host. Hardening reduces the attack surface through secure configuration, removal of unnecessary services, least‑privilege settings, and baseline protections; patching is typically a component of this process. WAF rules and network intrusion detection are important but are layered controls that come after the server itself is secured. Therefore, hardening the virtual host is the correct first step.
Question 235
Which of the following provides the best protection against unwanted or insecure communications to and from a device?
A. System hardening
B. Host-based firewall
C. Intrusion detection system
D. Anti-malware software
Show Answer
Correct Answer: B
Explanation: A host-based firewall directly controls inbound and outbound network traffic on a specific device using security rules, making it the most effective protection against unwanted or insecure communications to and from that device. System hardening reduces attack surface but does not actively filter traffic, an IDS primarily detects rather than blocks traffic, and anti-malware focuses on malicious software rather than network communications.
Question 236
Which of the following is most likely to be used as a just-in-time reference document within a security operations center?
A. Change management policy
B. Risk profile
C. Playbook
D. SIEM profile
Show Answer
Correct Answer: C
Explanation: A playbook is a just-in-time, action-oriented document used by SOC analysts during active incidents. It provides step-by-step procedures for responding to specific scenarios, making it ideal for real-time reference, unlike higher-level policies or profiles.
Question 237
Which of the following attacks exploits a potential vulnerability as a result of using weak cryptographic algorithms?
A. Password cracking
B. On-path
C. Digital signing
D. Side-channel
Show Answer
Correct Answer: A
Explanation: Weak cryptographic algorithms (e.g., unsalted or fast hashes like MD5 or SHA-1) make it feasible to recover passwords using brute-force, dictionary, or rainbow-table attacks. Password cracking directly exploits such weaknesses. On-path attacks target communication channels rather than weak algorithms themselves, digital signing is not an attack, and side-channel attacks exploit implementation characteristics rather than algorithm strength.
Question 238
Which of the following is the most relevant reason a DPO would develop a data inventory?
A. To manage data storage requirements better
B. To determine the impact in the event of a breach
C. To extend the length of time data can be retained
D. To automate the reduction of duplicated data
Show Answer
Correct Answer: B
Explanation: A data inventory (data map) gives the DPO visibility into what personal data exists, where it is stored, how it is processed, and who has access to it. This understanding is most critical for assessing risk and, in particular, for determining scope and impact if a data breach occurs, enabling accurate regulatory notifications and response. The other options are operational or IT-focused benefits, not the primary compliance-driven reason for a DPO.
Question 239
An employee used a company’s billing system to issue fraudulent checks. The administrator is looking for evidence of other occurrences of this activity. Which of the following should the administrator examine?
A. Application logs
B. Vulnerability scanner logs
C. IDS/IPS logs
D. Firewall logs
Show Answer
Correct Answer: A
Explanation: The fraudulent activity occurred within the company’s billing system, so the most relevant evidence will be found in logs generated by that application. Application logs record user actions, transactions, timestamps, and system events, allowing the administrator to identify similar fraudulent check issuances or patterns of misuse. Other logs (vulnerability scanner, IDS/IPS, firewall) focus on security posture or network traffic, not detailed application-level transactions.
Question 240
Which of the following would a systems administrator follow when upgrading the firmware of an organization’s router?
A. Software development life cycle
B. Risk tolerance
C. Certificate signing request
D. Maintenance window
Show Answer
Correct Answer: D
Explanation: Upgrading router firmware can cause downtime or service disruption, so administrators schedule it during an approved maintenance window to minimize impact on users and allow time for testing or rollback.
Question 241
Which of the following consequences would a retail chain most likely face from customers in the event the retailer is non-compliant with PCI DSS?
A. Contractual impacts
B. Sanctions
C. Fines
D. Reputational damage
Show Answer
Correct Answer: D
Explanation: The question specifies consequences faced **from customers** due to PCI DSS non-compliance. Customers do not impose fines, sanctions, or contractual penalties—those come from card brands, banks, or regulators. Customers react through loss of trust, negative publicity, and reduced patronage, which results in reputational damage. Therefore, reputational damage is the most likely consequence from customers.
Question 242
A systems administrator discovers a system that is no longer receiving support from the vendor. However, this system and its environment are critical to running the business, cannot be modified, and must stay online. Which of the following risk treatments is the most appropriate in this situation?
A. Reject
B. Accept
C. Transfer
D. Avoid
Show Answer
Correct Answer: B
Explanation: The system is critical to business operations, cannot be modified or replaced, and must remain online. Avoidance is impossible because the system cannot be removed, rejection is not a valid treatment, and transfer (e.g., insurance) does not eliminate the operational and security risk itself. With no feasible way to avoid, mitigate through change, or fully transfer the risk, the organization must formally acknowledge and live with it. Therefore, the most appropriate risk treatment is to accept the risk, typically with compensating controls and monitoring.
$19
Get all 609 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.