An organization is adopting cloud services at a rapid pace and now has multiple SaaS applications in use. Each application has a separate log-in, so the security team wants to reduce the number of credentials each employee must maintain. Which of the following is the first step the security team should take?
A. Enable SAML.
B. Create OAuth tokens.
C. Use password vaulting.
D. Select an IdP.
Show Answer
Correct Answer: D
Explanation: To reduce the number of credentials employees must maintain across multiple SaaS applications, the organization needs a centralized authentication source. Selecting an Identity Provider (IdP) is the foundational first step, as it enables single sign-on (SSO) and federated identity. Protocols like SAML or OAuth are configured after an IdP is chosen, and password vaulting does not actually reduce the number of logins—only stores them.
Question 304
Which of the following control types is AUP an example of?
A. Physical
B. Managerial
C. Technical
D. Operational
Show Answer
Correct Answer: B
Explanation: An Acceptable Use Policy (AUP) is a security policy that defines rules, expectations, and acceptable behavior for users. Policies are administrative in nature and fall under managerial controls, which focus on governance, direction, and alignment of security with organizational goals. Operational controls deal with the execution of day-to-day activities by people, whereas the AUP itself is the directive document that management establishes.
Question 305
Which of the following agreement types is used to limit external discussions?
A. BPA
B. NDA
C. SLA
D. MSA
Show Answer
Correct Answer: B
Explanation: An NDA (Non-Disclosure Agreement) is specifically designed to restrict the sharing of confidential information with external parties, thereby limiting external discussions. The other options govern processes, service levels, or overarching service terms rather than confidentiality.
Question 306
A systems administrator deployed a monitoring solution that does not require installation on the endpoints that the solution is monitoring. Which of the following is described in this scenario?
A. Agentless solution
B. Client-based soon
C. Open port
D. File-based solution
Show Answer
Correct Answer: A
Explanation: An agentless monitoring solution collects data from endpoints without installing software on them, typically using existing protocols like SNMP, WMI, or SSH. The other options either require installed clients or do not describe a monitoring architecture.
Question 307
A security analyst is reviewing the source code of an application in order to identify misconfigurations and vulnerabilities. Which of the following kinds of analysis best describes this review?
A. Dynamic
B. Static
C. Gap
D. Impact
Show Answer
Correct Answer: B
Explanation: Reviewing an application's source code without executing it is static analysis. Dynamic analysis requires running the application, while gap and impact analyses address standards alignment and consequence assessment rather than direct code review.
Question 308
The author of a software package is concerned about bad actors repackaging and inserting malware into the software. The software download is hosted on a website, and the author exclusively controls the website's contents. Which of the following techniques would best ensure the software's integrity?
A. Input validation
B. Code signing
C. Secure cookies
D. Fuzzing
Show Answer
Correct Answer: B
Explanation: Code signing uses a digital signature to ensure the authenticity and integrity of the software. If an attacker repackages the software or inserts malware, the signature validation will fail, alerting users that the software has been tampered with. The other options do not protect distributed software integrity.
Question 309
A multinational bank hosts several servers in its data center. These servers run a business-critical application used by customers to access their account information. Which of the following should the bank use to ensure accessibility during peak usage times?
A. Load balancer
B. Cloud backups
C. Geographic dispersal
D. Disk multipathing
Show Answer
Correct Answer: A
Explanation: A load balancer distributes incoming client requests across multiple servers, preventing any single server from becoming overloaded. This ensures high availability, optimal performance, and continued accessibility during peak usage times. The other options address data protection or storage/network redundancy, not real-time traffic handling.
Question 310
Which of the following is the best reason an organization should enforce a data classification policy to help protect its most sensitive information?
A. End users will be required to consider the classification of data that can be used in documents.
B. The policy will result in the creation of access levels for each level of classification.
C. The organization will have the ability to create security requirements based on classification levels.
D. Security analysts will be able to see the classification of data within a document before opening it.
Show Answer
Correct Answer: C
Explanation: The primary purpose of a data classification policy is to enable the organization to apply appropriate security controls based on the sensitivity of the data. By defining classification levels, the organization can establish specific security requirements—such as access controls, encryption, handling, and monitoring—that ensure the most sensitive information receives the strongest protection.
Question 311
Which of the following best describes a social engineering attack that uses a targeted electronic messaging campaign aimed at a Chief Executive Officer?
A. Whaling
B. Spear phishing
C. Impersonation
D. Identity fraud
Show Answer
Correct Answer: A
Explanation: A targeted electronic messaging attack aimed specifically at a CEO or other senior executive is known as whaling. Whaling is a specialized form of spear phishing that focuses on high-profile, high-value targets such as chief executives.
Question 312
A user is requesting Telnet access to manage a remote development web server. Insecure protocols are not allowed for use within any environment. Which of the following should be configured to allow remote access to this server?
A. HTTPS
B. SNMPv3
C. SSH
D. RDP
E. SMTP
Show Answer
Correct Answer: C
Explanation: Telnet is insecure because it transmits data in plaintext. Since insecure protocols are not allowed and the user needs remote management access to a server, SSH is the appropriate replacement. SSH provides encrypted, authenticated remote command-line access and is the standard secure protocol for managing remote servers. Other options listed do not provide secure interactive shell access for server management.
$19
Get all 609 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.