A university employee logged on to the academic server and attempted to guess the system administrators’ log-in credentials. Which of the following security measures should the university have implemented to detect the employee’s attempts to gain access to the administrators’ accounts?
A. Two-factor authentication
B. Firewall
C. Intrusion prevention system
D. User activity logs
Show Answer
Correct Answer: D
Explanation: User activity logs record authentication attempts, including failed logins and repeated credential-guessing behavior. They provide the evidence needed to detect attempted unauthorized access. Two-factor authentication and an intrusion prevention system are primarily preventive controls, while a firewall filters network traffic rather than detecting account credential guessing by a logged-in user.
Question 242
Which of the following is a preventive physical security control?
A. Video surveillance system
B. Bollards
C. Alarm system
D. Motion sensors
Show Answer
Correct Answer: B
Explanation: Preventive physical security controls are intended to stop or deter unauthorized access before an incident occurs. Bollards are physical barriers that prevent vehicle access or vehicle-ramming attacks, making them a preventive control. Video surveillance, alarm systems, and motion sensors primarily detect or alert on events, so they are detective controls.
Question 243
Which of the following is the primary reason why false negatives on a vulnerability scan should be a concern?
A. The system has vulnerabilities that are not being detected.
B. The time to remediate vulnerabilities that do not exist is excessive.
C. Vulnerabilities with a lower severity will be prioritized over critical vulnerabilities.
D. The system has vulnerabilities, and a patch has not yet been released.
Show Answer
Correct Answer: A
Explanation: A false negative means the scan incorrectly reports that no vulnerability exists when one actually does. This is the primary concern because real vulnerabilities remain undetected and therefore unremediated, leaving systems exposed to compromise. Option B describes false positives, C is unrelated to false negatives, and D is not specific to scan accuracy.
Question 244
A security administrator documented the following records during an assessment of network services:
Two weeks later, the administrator performed a log review and noticed the records were changed as follows:
When consulting the service owner, the administrator validated that the new address was not part of the company network. Which of the following was the company most likely experiencing?
A. DDoS attack
B. DNS poisoning
C. Ransomware compromise
D. Spyware infection
Show Answer
Correct Answer: B
Explanation: The scenario describes DNS records that originally pointed to legitimate internal addresses but were later changed to an IP address outside the company's network without authorization. Unauthorized modification of DNS records to redirect traffic is characteristic of DNS poisoning (DNS spoofing). A DDoS attack floods services with traffic, ransomware encrypts data, and spyware focuses on covert data collection rather than altering DNS records.
Question 245
Which of the following should be used to ensure an attacker is unable to read the contents of a mobile device's drive if the device is lost?
A. TPM
B. ECC
C. FDE
D. HSM
Show Answer
Correct Answer: C
Explanation: Full Disk Encryption (FDE) encrypts the entire storage device, ensuring that if a mobile device is lost or stolen, an attacker cannot read the drive contents without the decryption key. TPM is a hardware trust module primarily associated with PCs, ECC refers to elliptic curve cryptography or error-correcting code depending on context and is not a disk protection mechanism, and HSM is a dedicated hardware device for key management rather than mobile device drive protection.
Question 246
A user's workstation becomes unresponsive and displays a ransom note demanding payment to decrypt files. Before the attack, the user opened a resume they received in a message, browsed the company's website, and installed OS updates. Which of the following is the most likely vector of this attack?
A. Spear-phishing attachment
B. Watering hole
C. Infected website
D. Typosquatting
Show Answer
Correct Answer: A
Explanation: The most likely attack vector is a spear-phishing attachment. The user opened a resume received in a message, which is a classic delivery mechanism for ransomware via a malicious attachment. Browsing the company's website alone does not indicate a watering hole attack, an infected website would require evidence of compromise of the visited site, and typosquatting involves visiting a lookalike domain rather than the legitimate company website.
Question 247
A security consultant is working with a client that wants to physically isolate its secure systems. Which of the following best describes this architecture?
A. SDN
B. Air gapped
C. Containerized
D. Highly available
Show Answer
Correct Answer: B
Explanation: An air-gapped architecture physically isolates systems or networks from other networks, especially unsecured ones, to prevent direct electronic communication and reduce the risk of unauthorized access or malware propagation. SDN is software-defined networking, containerization isolates applications rather than physically isolating systems, and high availability focuses on uptime, not physical separation.
Question 248
A security analyst has determined that a security breach would have a financial impact of $15,000 and is expected to occur twice within a three-year period. Which of the following is the ALE for this risk?
A. $7,500
B. $10,000
C. $15,000
D. $30,000
Show Answer
Correct Answer: B
Explanation: Annualized Loss Expectancy (ALE) = Single Loss Expectancy (SLE) × Annualized Rate of Occurrence (ARO). The SLE is $15,000. The event is expected to occur twice in three years, so ARO = 2/3 ≈ 0.667 per year. ALE = $15,000 × 2/3 = $10,000 (approximately).
Question 249
Which of the following activities is the first stage in the incident response process?
A. Detection
B. Declaration
C. Containment
D. Verification
Show Answer
Correct Answer: A
Explanation: Among the options given, the incident response process begins with detection (often called identification in common frameworks). Preparation is typically the phase before detection, but it is not listed. Containment occurs after an incident has been detected and confirmed, while declaration and verification are not generally the first standard phase.
Question 250
The private key for a website was stolen, and a new certificate has been issued. Which of the following needs to be updated next?
A. SCEP
B. CRL
C. OCSP
D. CSR
Show Answer
Correct Answer: B
Explanation: If a website's private key is compromised, the associated certificate must be revoked even if a new certificate has already been issued. The revocation information must be published so clients know the old certificate is no longer trusted. Updating the Certificate Revocation List (CRL) is the required next step. SCEP is for certificate enrollment, OCSP is a protocol clients use to query revocation status rather than something typically 'updated' in this context, and the CSR would have been used before the new certificate was issued.
$19
Get all 608 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.