A program manager wants to ensure contract employees can only access the company's computers Monday through Friday from 9 a m. to 5 p.m. Which of the following would best enforce this access control?
A. Creating a GPO for all contract employees and setting time-of-day log-in restrictions
B. Creating a discretionary access policy and setting rule-based access for contract employees
C. Implementing an OAuth server and then setting least privilege for contract employees
D. Implementing SAML with federation to the contract employees’ authentication server
Show Answer
Correct Answer: A
Explanation: Time-of-day access restrictions are natively supported through Group Policy Objects in domain environments, allowing administrators to enforce login hours for a specific user group such as contract employees. The other options relate to authorization models or federated authentication, which do not directly enforce workstation login time restrictions.
Question 32
A growing organization, which hosts an externally accessible application, adds multiple virtual servers to improve application performance and decrease the resource usage on individual servers. Which of the following solutions is the organization most likely to employ to further increase performance and availability?
A. Load balancer
B. Jump server
C. Proxy server
D. SD-WAN
Show Answer
Correct Answer: A
Explanation: A load balancer distributes incoming requests across multiple virtual servers, preventing any single server from becoming a bottleneck. This improves performance through better resource utilization and increases availability by providing redundancy and failover if a server becomes unavailable.
Question 33
Which of the following would most likely be deployed to obtain and analyze attacker activity and techniques?
A. Firewall
B. IDS
C. Honeypot
D. Layer 3 switch
Show Answer
Correct Answer: C
Explanation: A honeypot is specifically designed to attract attackers and monitor their behavior in a controlled environment, allowing defenders to collect and analyze attacker techniques, tools, and tactics. Firewalls, IDS, and Layer 3 switches primarily focus on prevention, detection, or traffic handling rather than detailed attacker behavior analysis.
Question 34
Employees sign an agreement that restricts specific activities when leaving the company. Violating the agreement can result in legal consequences. Which of the following agreements does this best describe?
A. SLA
B. BPA
C. NDA
D. MOA
Show Answer
Correct Answer: C
Explanation: An NDA (Non-Disclosure Agreement) is a legal contract employees commonly sign that restricts what they can do with confidential or proprietary information after leaving a company, and violations can lead to legal consequences. The other options do not primarily govern post-employment restrictions on information or conduct.
Question 35
Which of the following is prevented by proper data sanitization?
A. Hackers’ ability to obtain data from used hard drives
B. Devices reaching end-of-life and losing support
C. Disclosure of sensitive data through incorrect classification
D. Incorrect inventory data leading to a laptop shortage
Show Answer
Correct Answer: A
Explanation: Proper data sanitization securely and irreversibly removes data from storage media before reuse or disposal, preventing unauthorized recovery of information from used hard drives. The other options relate to lifecycle management, data classification, or inventory control, which are not addressed by data sanitization.
Question 36
The number of tickets the help desk has been receiving has increased recently due to numerous false-positive phishing reports. Which of the following would be best to help to reduce the false positives?
A. Performing more phishing simulation campaigns
B. Improving security awareness training
C. Hiring more help desk staff
D. Implementing an incident reporting web page
Show Answer
Correct Answer: B
Explanation: False-positive phishing reports happen when users misidentify legitimate emails as malicious. Improving security awareness training directly addresses the root cause by teaching users how to better distinguish real phishing attempts from legitimate messages, which reduces unnecessary help desk tickets. The other options either test users, add resources, or streamline reporting but do not reduce false positives.
Question 37
A systems administrator receives a text message from an unknown number claiming to be the Chief Executive Officer of the company. The message states an emergency situation requires a password reset. Which of the following threat vectors is being used?
A. Typosquatting
B. Smishing
C. Pretexting
D. Impersonation
Show Answer
Correct Answer: B
Explanation: The attack is delivered via a text message (SMS) that attempts to socially engineer the recipient into resetting a password. SMS-based phishing is specifically known as smishing. While the attacker is impersonating the CEO and using a pretext, the threat vector being used is smishing.
Question 38
Which of the following most accurately describes the order in which a security engineer should implement secure baselines?
A. Deploy, maintain, establish
B. Establish, maintain, deploy
C. Establish, deploy, maintain
D. Deploy, establish, maintain
Show Answer
Correct Answer: C
Explanation: Secure baselines follow a logical lifecycle: first establish the baseline by defining secure configurations based on standards and requirements; then deploy those configurations across systems; and finally maintain them through monitoring, patching, and updates as threats and environments change.
Question 39
A CVE in a key back-end component of an application has been disclosed. The systems administrator is identifying all of the systems in the environment that are susceptible to this risk. Which of the following should the systems administrator perform?
A. Packet capture
B. Vulnerability scan
C. Metadata analysis
D. Automated reporting
Show Answer
Correct Answer: B
Explanation: A vulnerability scan checks systems against databases of known CVEs to identify which hosts, applications, or services are affected by the disclosed vulnerability. The other options do not systematically identify susceptible systems.
Question 40
Which of the following would be the greatest concern for a company that is aware of the consequences of non-compliance with government regulations?
A. Right to be forgotten
B. Sanctions
C. External compliance reporting
D. Attestation
Show Answer
Correct Answer: B
Explanation: The greatest concern from non-compliance with government regulations is sanctions, as they represent the direct consequences regulators impose. Sanctions can include heavy fines, legal actions, operational restrictions, loss of licenses, or criminal liability, all of which have immediate and severe financial, operational, and reputational impact. The other options describe requirements or mechanisms related to compliance, not the punitive outcome itself.
$19
Get all 609 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.