Which of the following is a prerequisite for a DLP solution?
A. Data destruction
B. Data sanitization
C. Data classification
D. Data masking
Show Answer
Correct Answer: C
Explanation: A Data Loss Prevention (DLP) solution relies on identifying which information is sensitive so it can monitor, control, and prevent unauthorized disclosure. Data classification provides the labels or categories that define sensitive data and is therefore a prerequisite for effective DLP policies. Data destruction, sanitization, and masking are protective techniques but are not prerequisites for deploying DLP.
Question 22
Which of the following is a type of vulnerability that may result from outdated algorithms or keys?
A. Hash collision
B. Cryptographic
C. Buffer overflow
D. Input validation
Show Answer
Correct Answer: B
Explanation: Outdated cryptographic algorithms (such as DES or RC4) and weak, short, or compromised keys create cryptographic vulnerabilities because they reduce the strength of encryption and related security mechanisms. A hash collision is a specific cryptographic issue, not the broad vulnerability type described. Buffer overflow and input validation are unrelated software security vulnerability categories.
Question 23
A company wants to prevent proprietary and confidential company information from being shared to outsiders. Which of the following would this best describe?
A. MOA
B. SLA
C. MSA
D. NDA
Show Answer
Correct Answer: D
Explanation: An NDA (Non-Disclosure Agreement) is specifically designed to protect proprietary and confidential information by legally restricting parties from disclosing it to unauthorized outsiders. An MOA (Memorandum of Agreement), SLA (Service Level Agreement), and MSA (Master Service Agreement) serve different contractual purposes and are not primarily confidentiality agreements.
Question 24
Which of the following solutions would most likely be used in the financial industry to mask sensitive data?
A. Tokenization
B. Hashing
C. Salting
D. Steganography
Show Answer
Correct Answer: A
Explanation: Tokenization is the standard approach in the financial industry for masking sensitive data such as payment card numbers by replacing the original value with a non-sensitive token. Hashing is primarily for integrity and password verification, salting strengthens hashes, and steganography hides the existence of data rather than masking sensitive values for transactional use.
Question 25
Which of the following is used to calculate the impact to an organization per cybersecurity incident?
A. SLE
B. ALE
C. ARO
D. SLA
Show Answer
Correct Answer: A
Explanation: SLE (Single Loss Expectancy) measures the expected financial impact of a single cybersecurity incident. ALE (Annual Loss Expectancy) is calculated as SLE × ARO and represents expected annual loss, ARO is the expected frequency per year, and SLA is a service agreement, not a risk calculation metric.
Question 26
A security administrator needs to reduce the attack surface in the company's data centers. Which of the following should the security administrator do to complete this task?
A. Implement a honeynet.
B. Define Group Policy on the servers.
C. Configure the servers for high availability.
D. Upgrade end-of-support operating systems.
Show Answer
Correct Answer: D
Explanation: Upgrading end-of-support operating systems reduces the attack surface by eliminating unsupported, unpatched platforms that are more vulnerable to exploitation. Honeynets are detection/deception controls, Group Policy can harden systems but is not inherently an attack surface reduction measure in this context, and high availability improves resilience rather than reducing exposed attack vectors.
Question 27
A site reliability engineer is designing a recovery strategy that requires quick failover to an identical site if the primary facility goes down. Which of the following types of sites should the engineer consider?
A. Recovery site
B. Hot site
C. Cold site
D. Warm site
Show Answer
Correct Answer: B
Explanation: A hot site is a fully equipped, operational duplicate of the primary environment with current systems and data, enabling rapid failover and minimal downtime. A warm site requires additional setup and synchronization before use, a cold site provides only basic infrastructure, and 'recovery site' is a generic term rather than a specific recovery readiness level.
Question 28
Which of the following would an organization most likely use to minimize the loss of data on a file server in the event data needs to be restored?
A. Snapshots
B. Journaling
C. Obfuscation
D. Tokenization
Show Answer
Correct Answer: A
Explanation: Snapshots create point-in-time copies of a file system or storage volume, enabling restoration to a recent state and thereby minimizing data loss after accidental deletion, corruption, or system failure. Journaling helps maintain file system consistency after crashes but is not a backup or restore mechanism. Obfuscation and tokenization are data protection techniques, not recovery methods.
Question 29
SIMULATION
-
A security analyst is creating the first draft of a network diagram for the company’s new customer-facing payment application that will be hosted by a third-party cloud service provider.
INSTRUCTIONS
-
Click the ? to select the appropriate icons to create a secure, redundant web application. Then use the dropdown menu to select the appropriate subnet type. Every space in the diagram must be filled.
If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.
Explanation: A secure redundant web application places a WAF in front of redundant public load balancers. Application servers run in a private subnet behind the load balancers, with an autoscaling group managing instances. The database resides in a separate private subnet.
Question 30
A program manager wants to ensure contract employees can only access the company's computers Monday through Friday from 9 a m. to 5 p.m. Which of the following would best enforce this access control?
A. Creating a GPO for all contract employees and setting time-of-day log-in restrictions
B. Creating a discretionary access policy and setting rule-based access for contract employees
C. Implementing an OAuth server and then setting least privilege for contract employees
D. Implementing SAML with federation to the contract employees’ authentication server
Show Answer
Correct Answer: A
Explanation: Time-of-day logon restrictions are designed to limit when users can authenticate. In a Windows Active Directory environment, applying these settings through a Group Policy Object (GPO) for contract employees is the appropriate way to enforce access only Monday through Friday from 9 a.m. to 5 p.m. The other options do not specifically enforce logon time restrictions: discretionary access control governs resource permissions, OAuth handles authorization, and SAML provides federated authentication.
$19
Get all 608 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.