Which of the following documents details how to accomplish a technical security task?
A. Standard
B. Policy
C. Guideline
D. Procedure
Show Answer
Correct Answer: D
Explanation: A procedure provides step-by-step, actionable instructions that explain exactly how to perform a specific technical security task. Policies set high-level intent, standards define mandatory requirements, and guidelines offer recommendations, but only procedures detail the concrete steps to accomplish the task.
Question 54
An organization is developing a security program that conveys the responsibilities associated with the general operation of systems and software within the organization. Which of the following documents would most likely communicate these expectations?
A. Business continuity plan
B. Change management procedure
C. Acceptable use policy
D. Software development life cycle policy
Show Answer
Correct Answer: C
Explanation: An Acceptable Use Policy (AUP) defines user responsibilities and expectations for the general operation, security, and proper use of organizational systems and software. It communicates what is permitted and prohibited when accessing company resources. The other options focus on continuity planning, managing changes, or software development processes rather than day-to-day operational responsibilities.
Question 55
A company is aware of a given security risk related to a specific market segment. The business chooses not to accept responsibility and target their services to a different market segment. Which of the following describes this risk management strategy?
A. Exemption
B. Exception
C. Avoid
D. Transfer
Show Answer
Correct Answer: C
Explanation: The company deliberately changes its business strategy to avoid exposure to the known security risk by not serving the affected market segment. This is the definition of risk avoidance. It is not transfer (no third party assumes the risk), nor exception or exemption, which are not standard risk treatment strategies in this context.
Question 56
Which of the following is the best way to provide secure, remote access for employees while minimizing the exposure of a company’s internal network?
A. VPN
B. LDAP
C. FTP
D. RADIUS
Show Answer
Correct Answer: A
Explanation: A VPN is the best option because it provides encrypted, authenticated remote access to internal resources while minimizing network exposure. VPNs securely connect remote employees to only the necessary parts of the internal network and can be enhanced with MFA and access controls. LDAP and RADIUS are authentication/authorization services rather than remote access solutions, and FTP is a file transfer protocol that does not provide secure remote network access.
Question 57
Which of the following are the best security controls for controlling on-premises access? (Choose two.)
A. Swipe card
B. Picture ID
C. Phone authentication application
D. Biometric scanner
E. Camera
F. Memorable question
Show Answer
Correct Answer: A, D
Explanation: On-premises access requires strong physical security controls. Swipe cards provide controlled, auditable physical entry and can be quickly revoked. Biometric scanners offer strong identity verification using unique physical characteristics, preventing credential sharing. Together they represent the most effective controls among the options.
Question 58
An employee clicks a malicious link in an email that appears to be from the company's Chief Executive Officer. The employee's computer is infected with ransomware that encrypts the company's files. Which of the following is the most effective way for the company to prevent similar incidents in the future?
A. Security awareness training
B. Database encryption
C. Segmentation
D. Reporting suspicious emails
Show Answer
Correct Answer: A
Explanation: The incident began with a phishing email impersonating the CEO, which relies on social engineering rather than a technical failure. Security awareness training is the most effective preventive control because it teaches employees how to identify phishing attempts, verify sender authenticity, and avoid clicking malicious links. The other options do not directly address the root cause of the user being deceived into initiating the ransomware infection.
Question 59
In which of the following will unencrypted network traffic most likely be found?
A. SDN
B. IoT
C. VPN
D. SCADA
Show Answer
Correct Answer: B
Explanation: Unencrypted network traffic is most likely found in IoT environments. Many IoT devices prioritize low cost, low power, and simplicity, and often use plaintext protocols or lack proper TLS due to resource constraints or poor security design. VPNs are explicitly designed to encrypt traffic, SDN control/data planes commonly use secure channels, and while legacy SCADA systems may lack encryption, modern SCADA increasingly adopts secure communications. Thus, IoT is the most likely.
Question 60
A help desk employee receives a call from someone impersonating the Chief Executive Officer. The caller asks for assistance with resetting a password. Which of the following best describes this event?
A. Vishing
B. Hacktivism
C. Blackmail
D. Misinformation
Show Answer
Correct Answer: A
Explanation: The event describes a caller impersonating a senior executive over the phone to trick a help desk employee into resetting a password. This is a classic example of vishing (voice phishing), a social engineering attack conducted via voice communication. The other options do not involve impersonation over a phone call to elicit credentials or actions.
Question 61
A new corporate policy requires all staff to use multifactor authentication to access company resources. Which of the following can be utilized to set up this form of identity and access management? (Choose two.)
A. Authentication tokens
B. Least privilege
C. Biometrics
D. LDAP
E. Password vaulting
F. SAML
Show Answer
Correct Answer: A, C
Explanation: Multifactor authentication requires two or more different authentication factors. Authentication tokens represent something you have, while biometrics represent something you are. Both are directly used to implement MFA. The other options relate to access control principles, directory services, or federation, not authentication factors themselves.
Question 62
While updating the security awareness training, a security analyst wants to address issues created if vendors' email accounts are compromised. Which of the following recommendations should the security analyst include in the training?
A. Refrain from clicking on images included in emails from new vendors
B. Delete emails from unknown service provider partners.
C. Require that invoices be sent as attachments
D. Be alert to unexpected requests from familiar email addresses
Show Answer
Correct Answer: D
Explanation: When a vendor’s email account is compromised, attackers often send messages that appear legitimate because they come from a familiar, trusted address. The most effective training recommendation is to warn users to be cautious of unexpected or unusual requests—even if they come from known vendors—since this is a key indicator of business email compromise (BEC). The other options are either too narrow, impractical, or unrelated to the core risk posed by compromised vendor accounts.
$19
Get all 609 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.