An enterprise security team is researching a new security architecture to better protect the company’s networks and applications against the latest cyberthreats. The company has a fully remote workforce. The solution should be highly redundant and enable users to connect to a VPN with an integrated, software-based firewall. Which of the following solutions meets these requirements?
A. IPS
B. SIEM
C. SASE
D. CASB
Show Answer
Correct Answer: C
Explanation: SASE (Secure Access Service Edge) is designed for distributed and remote workforces by delivering networking and security as cloud-based services. It commonly includes secure remote access, Firewall-as-a-Service (FWaaS), SD-WAN, Zero Trust Network Access (ZTNA), and often CASB capabilities, providing high availability through cloud points of presence. IPS, SIEM, and CASB alone do not provide the integrated remote connectivity and firewall architecture described.
Question 252
Executives at a company are concerned about employees accessing systems and information about sensitive company projects unrelated to the employees’ normal job duties. Which of the following enterprise security capabilities will the security team most likely deploy to detect that activity?
A. UBA
B. EDR
C. NAC
D. DLP
Show Answer
Correct Answer: A
Explanation: User Behavior Analytics (UBA) is designed to establish baselines of normal user activity and detect anomalous behavior, such as employees accessing sensitive systems or project information unrelated to their typical job responsibilities. EDR focuses on endpoint threats, NAC controls network access, and DLP primarily monitors/prevents unauthorized data exfiltration rather than identifying unusual access patterns.
Question 253
A security engineer configured a remote access VPN. The remote access VPN allows end users to connect to the network by using an agent that is installed on the endpoint, which establishes an encrypted tunnel. Which of the following protocols did the engineer most likely implement?
A. GRE
B. IPSec
C. SD-WAN
D. EAP
Show Answer
Correct Answer: B
Explanation: IPSec is the standard protocol suite used to establish encrypted VPN tunnels for both remote-access and site-to-site VPNs. A remote-access VPN client (agent) installed on the endpoint commonly uses IPSec to create the encrypted tunnel. GRE provides tunneling but no encryption, SD-WAN is a WAN architecture rather than a VPN tunneling protocol, and EAP is an authentication framework, not the tunneling/encryption protocol.
Question 254
Which of the following tasks is typically included in the BIA process?
A. Estimating the recovery time of systems
B. Identifying the communication strategy
C. Evaluating the risk management plan
D. Establishing the backup and recovery procedures
E. Developing the incident response plan
Show Answer
Correct Answer: A
Explanation: A Business Impact Analysis (BIA) identifies critical business functions, assesses the impact of disruptions, and determines recovery requirements such as Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs). Estimating the recovery time of systems is therefore a typical BIA task. Communication strategies, backup procedures, incident response plans, and risk management plan evaluation are developed or managed in related continuity, disaster recovery, or risk management processes rather than the BIA itself.
Question 255
A systems administrator is concerned about vulnerabilities within cloud computing instances. Which of the following is most important for the administrator to consider when architecting a cloud computing environment?
A. SQL injection
B. TOC/TOU
C. VM escape
D. Tokenization
E. Password spraying
Show Answer
Correct Answer: C
Explanation: VM escape is the most important cloud-specific architectural vulnerability to consider because it targets the virtualization layer. If an attacker escapes a guest VM, they may compromise the hypervisor or other tenant VMs, breaking isolation that cloud computing relies on. The other options are either general application attacks (SQL injection, password spraying), a race condition (TOC/TOU), or a security control rather than a vulnerability (tokenization).
Question 256
An organization issued new laptops to all employees and wants to provide web filtering both in and out of the office without configuring additional access to the network. Which of the following types of web filtering should a systems administrator configure?
A. Agent-based
B. Centralized proxy
C. URL scanning
D. Content categorization
Show Answer
Correct Answer: A
Explanation: Agent-based web filtering installs a client on each endpoint to enforce web filtering policies regardless of whether the device is on the corporate network or off-site. This meets the requirement to provide filtering in and out of the office without requiring additional network access such as a VPN or proxy. A centralized proxy depends on routing traffic through a central service, while URL scanning and content categorization are filtering techniques rather than deployment models.
Question 257
An organization has recently decided to implement SSO. The requirements are to leverage access tokens and focus on application authorization rather than user authentication. Which of the following solutions would the engineering team most likely configure?
A. LDAP
B. Federation
C. SAML
D. OAuth
Show Answer
Correct Answer: D
Explanation: OAuth is the correct choice because the scenario emphasizes the use of access tokens and application authorization rather than user authentication. OAuth is an authorization framework that issues access tokens to allow applications to access protected resources. SAML is primarily used for authentication and SSO via identity assertions, LDAP is a directory access protocol, and federation is a broader architectural concept rather than the specific token-based authorization solution described.
Question 258
Which of the following should a security team use to document persistent vulnerabilities with related recommendations?
A. Audit report
B. Risk register
C. Compliance report
D. Penetration test
Show Answer
Correct Answer: B
Explanation: A risk register is the appropriate document for tracking ongoing or accepted risks, including persistent vulnerabilities, along with their status, impact, ownership, and recommended mitigation actions. An audit report and compliance report are point-in-time assessments, and a penetration test is an assessment activity/report rather than the living document used to track persistent issues.
Question 259
While investigating a possible incident, a security analyst discovers the following:
Which of the following should the analyst do first?
A. Implement a WAF.
B. Disable the query.php script.
C. Block brute-force attempts on temporary users.
D. Check the users table for new accounts.
Show Answer
Correct Answer: D
Explanation: The scenario indicates a suspected SQL injection attempt intended to create a temporary user account. Since the analyst is still investigating a possible incident, the first priority is analysis: verify whether the attack succeeded by checking the users table for unauthorized accounts. Immediate containment actions such as disabling the script or deploying a WAF may be appropriate later, but they should follow confirmation and assessment unless active compromise requiring urgent containment is established. Blocking brute-force attempts is unrelated to the observed SQL injection activity.
Question 260
Which of the following options will provide the lowest RTO and RPO for a database?
A. Snapshots
B. On-site backups
C. Journaling
D. Hot site
Show Answer
Correct Answer: D
Explanation: A hot site provides the lowest overall RTO because it is a fully operational standby environment that can take over quickly, and with continuous or near-real-time replication it also provides a very low RPO. Journaling primarily improves RPO by preserving transactions, but by itself it does not provide the fastest recovery time because systems and services still need to be restored or failed over. Snapshots and on-site backups generally have higher RPO and RTO.
$19
Get all 608 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.