Which of the following documents details how to accomplish a technical security task?
A. Standard
B. Policy
C. Guideline
D. Procedure
Show Answer
Correct Answer: D
Explanation: A procedure provides detailed, step-by-step instructions for performing a specific technical or operational security task. Policies define high-level intent, standards specify mandatory requirements, and guidelines provide recommended but non-mandatory practices.
Question 52
An organization is developing a security program that conveys the responsibilities associated with the general operation of systems and software within the organization. Which of the following documents would most likely communicate these expectations?
A. Business continuity plan
B. Change management procedure
C. Acceptable use policy
D. Software development life cycle policy
Show Answer
Correct Answer: C
Explanation: An Acceptable Use Policy (AUP) communicates organization-wide expectations and user responsibilities for the proper and secure use of systems, software, and other IT resources. A business continuity plan addresses resilience during disruptions, a change management procedure governs how changes are requested and implemented, and an SDLC policy applies specifically to software development processes rather than general operation of systems and software.
Question 53
A company is aware of a given security risk related to a specific market segment. The business chooses not to accept responsibility and target their services to a different market segment. Which of the following describes this risk management strategy?
A. Exemption
B. Exception
C. Avoid
D. Transfer
Show Answer
Correct Answer: C
Explanation: The correct answer is C. Avoid. Risk avoidance means changing plans or business activities to eliminate exposure to a known risk. By choosing not to serve the market segment associated with the security risk and instead targeting a different segment, the company is avoiding the risk rather than accepting, transferring, or mitigating it.
Question 54
Which of the following is the best way to provide secure, remote access for employees while minimizing the exposure of a company’s internal network?
A. VPN
B. LDAP
C. FTP
D. RADIUS
Show Answer
Correct Answer: A
Explanation: A VPN is the standard solution for providing secure remote access by creating an encrypted tunnel between remote employees and the corporate network. LDAP is a directory service protocol, FTP is a file transfer protocol (and insecure in its basic form), and RADIUS provides AAA (authentication, authorization, and accounting) but is not itself a remote access transport.
Question 55
Which of the following are the best security controls for controlling on-premises access? (Choose two.)
A. Swipe card
B. Picture ID
C. Phone authentication application
D. Biometric scanner
E. Camera
F. Memorable question
Show Answer
Correct Answer: A, D
Explanation: The strongest controls for controlling on-premises physical access are a swipe card and a biometric scanner. Swipe cards enforce authorized entry and provide audit logs, while biometrics verify that the person presenting credentials is the authorized individual. Picture IDs are easily forged or borrowed and are primarily for visual verification, cameras are detective rather than preventive controls, and phone authentication apps and memorable questions are intended for logical access rather than physical access.
Question 56
An employee clicks a malicious link in an email that appears to be from the company's Chief Executive Officer. The employee's computer is infected with ransomware that encrypts the company's files. Which of the following is the most effective way for the company to prevent similar incidents in the future?
A. Security awareness training
B. Database encryption
C. Segmentation
D. Reporting suspicious emails
Show Answer
Correct Answer: A
Explanation: Security awareness training is the most effective preventive measure because the initial compromise occurred when an employee clicked a phishing link impersonating the CEO. Training helps users recognize phishing, social engineering, and suspicious links, reducing the likelihood of successful ransomware infections. Database encryption does not prevent phishing or ransomware execution, network segmentation limits spread rather than preventing the initial compromise, and reporting suspicious emails is helpful but is less effective without user training to recognize them.
Question 57
In which of the following will unencrypted network traffic most likely be found?
A. SDN
B. IoT
C. VPN
D. SCADA
Show Answer
Correct Answer: B
Explanation: IoT environments are the most likely to contain unencrypted network traffic because many embedded and low-cost devices use insecure or legacy protocols without TLS to reduce cost, complexity, or power consumption. VPN traffic is specifically encrypted by design, SDN does not inherently imply unencrypted traffic, and while legacy SCADA systems may use unencrypted protocols, the broadest and most likely environment for unencrypted traffic among these options is IoT.
Question 58
A help desk employee receives a call from someone impersonating the Chief Executive Officer. The caller asks for assistance with resetting a password. Which of the following best describes this event?
A. Vishing
B. Hacktivism
C. Blackmail
D. Misinformation
Show Answer
Correct Answer: A
Explanation: The scenario describes an attacker calling the help desk while impersonating the CEO to convince the employee to reset a password. This is voice phishing (vishing), a social engineering attack conducted over the phone. The other options do not fit: hacktivism is politically motivated hacking, blackmail involves coercion through threats, and misinformation is the spread of false information rather than this impersonation attack.
Question 59
A new corporate policy requires all staff to use multifactor authentication to access company resources. Which of the following can be utilized to set up this form of identity and access management? (Choose two.)
A. Authentication tokens
B. Least privilege
C. Biometrics
D. LDAP
E. Password vaulting
F. SAML
Show Answer
Correct Answer: A, C
Explanation: Multifactor authentication requires two or more different authentication factors. Authentication tokens provide a possession factor (something you have), and biometrics provide an inherence factor (something you are). Least privilege is an authorization principle, LDAP is a directory protocol, password vaulting manages credentials but is not itself an MFA factor, and SAML is a federation/SSO protocol rather than an authentication factor.
Question 60
While updating the security awareness training, a security analyst wants to address issues created if vendors' email accounts are compromised. Which of the following recommendations should the security analyst include in the training?
A. Refrain from clicking on images included in emails from new vendors
B. Delete emails from unknown service provider partners.
C. Require that invoices be sent as attachments
D. Be alert to unexpected requests from familiar email addresses
Show Answer
Correct Answer: D
Explanation: A compromised vendor email account means messages may come from a legitimate, familiar address but contain fraudulent or unusual requests (such as changed payment instructions or urgent actions). Security awareness should emphasize verifying unexpected requests even when they originate from trusted contacts. The other options are either overly narrow (A), encourage unsafe assumptions (C), or are impractical and unrelated to compromised known vendor accounts (B).
$19
Get all 608 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.