Which of the following is the best reason to perform a tabletop exercise?
A. To address audit findings
B. To collect remediation response times
C. To update the IRP
D. To calculate the ROI
Show Answer
Correct Answer: C
Explanation: A tabletop exercise is designed to walk through hypothetical incidents so participants can validate roles, decision-making, and procedures. Its primary value is identifying gaps, ambiguities, or outdated elements in the Incident Response Plan (IRP) and improving it. It is not intended to calculate ROI, formally address audit findings, or measure actual remediation response times.
Question 74
Which of the following should be used to ensure a device is inaccessible to a network-connected resource?
A. Disablement of unused services
B. Web application firewall
C. Host isolation
D. Network-based IDS
Show Answer
Correct Answer: C
Explanation: Host isolation directly prevents a device from communicating with other network-connected resources by quarantining or segmenting it from the network. The other options either harden or monitor systems but do not make a device inaccessible to the network.
Question 75
An organization is preparing to export proprietary software to a customer. Which of the following would be the best way to prevent the loss of intellectual property?
A. Code signing
B. Obfuscation
C. Tokenization
D. Blockchain
Show Answer
Correct Answer: B
Explanation: Obfuscation makes software code difficult to understand or reverse-engineer while preserving functionality, which directly helps protect proprietary logic and intellectual property when software is exported to customers. Code signing only ensures authenticity and integrity, tokenization protects sensitive data rather than code, and blockchain does not prevent analysis or copying of software.
Question 76
Which of the following is used to improve security and overall functionality without losing critical application data?
A. Reformatting
B. Decommissioning
C. Patching
D. Encryption
Show Answer
Correct Answer: C
Explanation: Patching applies updates that fix security vulnerabilities and improve functionality while preserving existing application data. The other options either risk data loss (reformatting), retire systems (decommissioning), or secure data without improving functionality or fixing flaws (encryption).
Question 77
Which of the following are the first steps an analyst should perform when developing a heat map? (Choose two.)
A. Methodically walk around the office noting Wi-Fi signal strength.
B. Log in to each access point and check the settings.
C. Create or obtain a layout of the office.
D. Measure cable lengths between access points.
E. Review access logs to determine the most active devices.
F. Remove possible impediments to radio transmissions.
Show Answer
Correct Answer: A, C
Explanation: Developing a Wi‑Fi heat map starts with understanding the physical space and then collecting signal data. An analyst must first create or obtain an accurate layout of the office to serve as the base map. Next, they walk the area with a Wi‑Fi analysis tool to measure signal strength at multiple locations. Tasks like checking AP settings, cable lengths, or logs occur later and are not required to generate the initial heat map.
Question 78
Prior to implementing a design change, the change must go through multiple steps to ensure that it does not cause any security issues. Which of the following is most likely to be one of those steps?
A. Board review
B. Service restart
C. Backout planning
D. Maintenance
Show Answer
Correct Answer: C
Explanation: In formal change management, a required pre-implementation step is backout (rollback) planning. It ensures that if a design change introduces security or operational issues, the organization can safely and quickly revert to the previous known-good state. The other options are either operational actions or too high-level to be standard change-control steps.
Question 79
An organization wants to deploy software in a container environment to increase security. Which of the following would limit the organization's ability to achieve this goal?
A. Regulatory compliance
B. Patch availability
C. Kernel version
D. Monolithic code
Show Answer
Correct Answer: C
Explanation: Containers share the host operating system kernel. If the kernel version is outdated, unpatched, or lacks required security features, all containers inherit those weaknesses, significantly limiting the security benefits of containerization. Monolithic applications can still be containerized and secured, whereas kernel limitations directly constrain isolation and security controls.
Question 80
Which of the following is an example of a treatment strategy for a continuous risk?
A. Email gateway to block phishing attempts
B. Background checks for new employees
C. Dual control requirements for wire transfers
D. Branch protection as part of the CI/CD pipeline
Show Answer
Correct Answer: A
Explanation: A continuous risk is an ongoing, persistent threat that requires constant mitigation. Phishing is a classic continuous risk, as attacks occur constantly. An email gateway provides automated, always-on filtering and blocking of malicious emails, making it a clear example of a treatment strategy for a continuous risk. The other options are valid controls, but they are more periodic (background checks), situational (dual control for specific transactions), or tied to a specific process domain (CI/CD) rather than the most universally recognized continuous risk scenario.
Question 81
The internal audit team determines a software application is no longer in scope for external reporting requirements. Which of the following will confirm that the application is no longer applicable?
A. Data inventory and retention
B. Right to be forgotten
C. Due care and due diligence
D. Acknowledgement and attestation
Show Answer
Correct Answer: D
Explanation: To confirm that a software application is no longer in scope for external reporting requirements, auditors need formal evidence of the decision. Acknowledgement and attestation provide documented sign-off by responsible stakeholders that the application is no longer applicable, creating an auditable record. The other options describe data management principles or privacy rights, not formal confirmation of scope removal.
Question 82
A security analyst created a fake account and saved the password in a non-readily accessible directory in a spreadsheet. An alert was also configured to notify the security team if the spreadsheet is opened. Which of the following best describes the deception method being deployed?
A. Honeypot
B. Honeyfile
C. Honeytoken
D. Honeynet
Show Answer
Correct Answer: B
Explanation: The deception is centered on a decoy spreadsheet placed in a monitored location that triggers an alert when opened. That is the defining characteristic of a honeyfile: a fake or sensitive-looking file used to detect unauthorized access. While the credentials inside are fake, the detection mechanism is tied to interaction with the file itself, not use of the credentials.
$19
Get all 609 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.