Which of the following describes the difference between encryption and hashing?
A. Encryption protects data in transit, while hashing protects data at rest.
B. Encryption replaces cleartext with ciphertext, while hashing calculates a checksum.
C. Encryption ensures data integrity, while hashing ensures data confidentiality.
D. Encryption uses a public-key exchange, while hashing uses a private key.
Show Answer
Correct Answer: B
Explanation: Encryption transforms plaintext into ciphertext using a cryptographic algorithm and key so authorized parties can recover the original data. Hashing computes a fixed-length digest from input that is designed to be one-way and is primarily used to verify integrity rather than provide confidentiality. Although a hash is not literally just a checksum in all contexts, this is the best matching option among the choices.
Question 82
A security report shows that during a two-week test period, 80% of employees unwittingly disclosed their SSO credentials when accessing an external website. The organization purposely created the website to simulate a cost-free password complexity test. Which of the following would best help reduce the number of visits to similar websites in the future?
A. Block all outbound traffic from the intranet.
B. Introduce a campaign to recognize phishing attempts.
C. Restrict internet access for the employees who disclosed credentials.
D. Implement a deny list of websites.
Show Answer
Correct Answer: B
Explanation: The best long-term control is user awareness training focused on recognizing phishing and other social engineering attempts. The fake external website was designed to trick users into entering SSO credentials, and educating employees reduces the likelihood they will visit and trust similar malicious sites in the future. Blocking all outbound traffic is impractical, restricting only affected users is punitive rather than preventive, and a deny list cannot keep up with new malicious websites and addresses only known sites.
Question 83
A systems administrator just purchased multiple network devices. Which of the following should the systems administrator perform to prevent attackers from accessing the devices by using publicly available information?
A. Install endpoint protection.
B. Disable ports/protocols.
C. Change default passwords.
D. Remove unnecessary software.
Show Answer
Correct Answer: C
Explanation: New network devices commonly ship with well-known default administrative usernames and passwords that are publicly documented. Changing the default passwords prevents attackers from using this publicly available information to gain access. The other options are general hardening measures but do not specifically address exploitation of publicly known default credentials.
Question 84
Which of the following is the fastest and most cost-effective way to confirm a third-party supplier's compliance with security obligations?
A. Attestation report
B. Third-party audit
C. Vulnerability assessment
D. Penetration testing
Show Answer
Correct Answer: A
Explanation: An attestation report is generally the fastest and most cost-effective way to confirm a third-party supplier's compliance with security obligations because it is an existing independent assurance report (such as a SOC report or certification attestation) that customers can review without commissioning new testing. A third-party audit, vulnerability assessment, and penetration test require additional time, cost, and effort and do not directly provide broad compliance assurance.
Question 85
Which of the following objectives is best achieved by a tabletop exercise?
A. Familiarizing participants with the incident response process
B. Deciding red and blue team rules of engagement
C. Quickly determining the impact of an actual security breach
D. Conducting multiple security investigations in parallel
Show Answer
Correct Answer: A
Explanation: A tabletop exercise is a discussion-based simulation used to familiarize participants with incident response plans, roles, communication, and decision-making in a low-risk environment. It is not intended to define red/blue team rules of engagement, assess an actual live breach, or conduct parallel investigations.
Question 86
An organization has a new regulatory requirement to implement corrective controls on a financial system. Which of the following is the most likely reason for the new requirement?
A. To defend against insider threats altering banking details
B. To ensure that errors are not passed to other systems
C. To allow for business insurance to be purchased
D. To prevent unauthorized changes to financial data
Show Answer
Correct Answer: B
Explanation: Corrective controls are intended to restore systems or data and correct problems after they occur. Among the options, ensuring errors are corrected so they are not propagated to downstream systems best reflects the purpose of a corrective control. Preventing unauthorized changes or insider alterations are preventive objectives, while insurance is unrelated.
Question 87
A Chief Information Security Officer (CISO) wants to:
• Prevent employees from downloading malicious content.
• Establish controls based on departments and users.
• Map internet access for business applications to specific service accounts.
• Restrict content based on categorization.
Which of the following should the CSO implement?
A. Web application firewall
B. Secure DNS server
C. Jump server
D. Next-generation firewall
Show Answer
Correct Answer: D
Explanation: A next-generation firewall (NGFW) best satisfies all the stated requirements: it can block malicious downloads through advanced threat inspection, enforce policies based on users and departments via identity integration, apply application-aware internet access policies including for service accounts, and restrict web access using URL/content categorization. A web application firewall protects hosted web applications rather than users' outbound web access, a secure DNS server alone does not provide the full set of identity- and application-aware controls, and a jump server is for controlled administrative access rather than web filtering.
Question 88
A company evaluates several options that would allow employees to have remote access to the network. The security team wants to ensure the solution includes AAA to comply with internal security policies. Which of the following should the security team recommend?
A. IPSec with RADIUS
B. RDP connection with LDAPS
C. Web proxy for all remote traffic
D. Jump server with 802.1X
Show Answer
Correct Answer: A
Explanation: IPSec is a standard secure remote-access VPN technology, and pairing it with RADIUS provides Authentication, Authorization, and Accounting (AAA). The other options do not provide a complete remote-access solution with AAA: LDAPS is a directory access protocol rather than an AAA service, a web proxy is not a remote-access AAA solution, and 802.1X is for network access control rather than remote-access AAA.
Question 89
A security analyst learns that an attack vector, which was used as a part of a recent incident, was a well-known IoT device exploit. The analyst needs to review logs to identify the time of initial exploit. Which of the following logs should the analyst review first?
A. Endpoint
B. Application
C. Firewall
D. NAC
Show Answer
Correct Answer: C
Explanation: Firewall logs are the best first source to identify the initial exploitation time for a well-known IoT network exploit because they record inbound and outbound network connections, exploit attempts, and allowed/blocked traffic reaching the IoT device. IoT devices often lack robust endpoint logging, making endpoint logs less reliable. Application logs are limited to application events, and NAC logs primarily track authentication and network admission rather than exploit activity.
Question 90
A systems administrator creates a script that validates OS version, patch levels, and installed applications when users log in. Which of the following examples best describes the purpose of this script?
A. Resource scaling
B. Policy enumeration
C. Baseline enforcement
D. Guard rails implementation
Show Answer
Correct Answer: C
Explanation: The script checks whether systems meet predefined configuration standards (OS version, patch levels, and installed applications) at login. This is an example of baseline enforcement, which validates and enforces compliance with an established security/configuration baseline. Resource scaling concerns dynamic resource allocation, policy enumeration is identifying or listing policies rather than enforcing compliance, and guard rails are preventative constraints rather than configuration baseline validation.
$19
Get all 608 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.