<< Prev Question Next Question >>

Question 79/410

A security administrator is deploying a DLP solution to prevent the exfiltration of sensitive customer data.
Which of the following should the administrator do first?

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (410q)
Question 1: A group of developers has a shared backup account to access ...
Question 2: Which of the following is the best way to secure an on-site ...
Question 3: An attacker submits a request containing unexpected characte...
Question 4: Which of the following is an example of implementing Zero Tr...
Question 5: Which of the following describes the process of concealing c...
Question 6: Which of the following exercises should an organization use ...
Question 7: Which of the following should be used to ensure that a new s...
Question 8: Which of the following security concepts is accomplished whe...
Question 9: While considering the organization ' s cloud-adoption strate...
Question 10: Which of the following is the most important element when de...
Question 11: Which of the following would be best suited for constantly c...
Question 12: Which of the following actors attacking an organization is t...
Question 13: A systems administrator is auditing all company servers to e...
Question 14: A company must ensure that log searches are conducted in the...
Question 15: An administrator learns that users are receiving large quant...
Question 16: A recent black-box penetration test of http://example.com di...
Question 17: An IT administrator needs to ensure data retention standards...
Question 18: A company performs a risk assessment on the information secu...
Question 19: An organization discovers that its cold site does not have e...
Question 20: A software company currently secures access using a combinat...
Question 21: After an audit, an administrator discovers all users have ac...
Question 22: Which of the following architectures is most suitable to pro...
Question 23: Which security controls is a company implementing by deployi...
Question 24: Which of the following data protection strategies can be use...
Question 25: Which of the following is a preventive physical security con...
Question 26: A company is developing a critical system for the government...
Question 27: An engineer has ensured that the switches are using the late...
Question 28: A security analyst discovers that a large number of employee...
Question 29: A small business initially plans to open common communicatio...
Question 30: A company ' s Chief Information Security Officer (CISO) want...
1 commentQuestion 31: An organization wants to deploy software in a container envi...
Question 32: An organization implemented cloud-managed IP cameras to moni...
Question 33: The private key for a website was stolen, and a new certific...
1 commentQuestion 34: An administrator is Investigating an incident and discovers ...
Question 35: Which of the following agreements defines response time, esc...
Question 36: Which of the following best explains the role of compensatin...
Question 37: Which of the following describes effective change management...
Question 38: Which of the following activities are associated with vulner...
Question 39: Which of the following is the most likely benefit of conduct...
Question 40: Which of the following metrics impacts the backup schedule a...
Question 41: A security analyst is reviewing the security of a SaaS appli...
Question 42: Which of the following activities should a systems administr...
Question 43: An organization has been experiencing issues with deleted ne...
Question 44: Cadets speaking a foreign language are using company phone n...
Question 45: Which of the following security measures is required when us...
Question 46: A security audit of an organization revealed that most of th...
Question 47: A security operations center determines that the malicious a...
Question 48: A security analyst is reviewing the following logs: (Exhibit...
Question 49: An administrator must replace an expired SSL certificate. Wh...
Question 50: While investigating a possible incident, a security analyst ...
Question 51: Which of the following is the best way to consistently deter...
Question 52: Which of the following threat actors would most likely defac...
Question 53: An attacker posing as the Chief Executive Officer calls an e...
Question 54: A company is experiencing issues with employees leaving the ...
Question 55: A systems administrator receives a text message from an unkn...
Question 56: During a security incident, the security operations team ide...
Question 57: During a penetration test in a hypervisor, the security engi...
Question 58: A systems administrator is concerned users are accessing ema...
Question 59: A systems administrator is changing the password policy with...
Question 60: Which of the following is the best safeguard to protect agai...
Question 61: An organization's internet-facing website was compromised wh...
Question 62: A security analyst is reviewing alerts in the SIEM related t...
Question 63: Which of the following would be most useful in determining w...
Question 64: Which of the following would help ensure a security analyst ...
Question 65: A database administrator is updating the company ' s SQL dat...
Question 66: A company is planning a disaster recovery site and needs to ...
Question 67: An IT manager is putting together a documented plan describi...
Question 68: Which of the following would a security administrator use to...
Question 69: Which of the following best explains a concern with OS-based...
Question 70: Which of the following steps in the risk management process ...
Question 71: A company makes a change during the appropriate change windo...
Question 72: Alerts from email protection systems and MSSPs must be enter...
Question 73: Which of the following are the most important considerations...
Question 74: Which of the following describes an executive team that is m...
Question 75: An unknown source has attacked an organization's network mul...
Question 76: Which of the following is most likely to be used as a just-i...
Question 77: An enterprise has been experiencing attacks focused on explo...
Question 78: An organization would like to calculate the time needed to r...
Question 79: A security administrator is deploying a DLP solution to prev...
Question 80: Which of the following should an organization implement to a...
Question 81: Which of the following is a risk of conducting a vulnerabili...
Question 82: A new employee can select a particular make and model of an ...
Question 83: A company ' s antivirus solution is effective in blocking ma...
Question 84: Which of the following security control types does an accept...
Question 85: Which of the following would most likely be deployed to obta...
Question 86: Which of the following should be used to ensure a device is ...
Question 87: An attacker used XSS to compromise a web server. Which of th...
Question 88: Which of the following cryptographic solutions protects data...
Question 89: A business uses Wi-Fi with content filleting enabled. An emp...
Question 90: Which of the following is the best way to provide secure rem...
Question 91: A company wants to improve the availability of its applicati...
Question 92: A spoofed identity was detected for a digital certificate. W...
Question 93: A security analyst is reviewing logs to identify the destina...
Question 94: Which of the following should a company use to provide proof...
Question 95: Which of the following tasks is typically included in the BI...
Question 96: Which of the following types of vulnerabilities involves att...
Question 97: A security analyst wants to better understand the behavior o...
Question 98: A security company informs its customers of a new vulnerabil...
Question 99: Various company stakeholders meet to discuss roles and respo...
Question 100: A security analyst is concerned malicious actors are lurking...
Question 101: Which of the following explains why an attacker cannot easil...
Question 102: A security analyst learns that an attack vector, used as par...
Question 103: A Chief Information Security Officer would like to conduct f...
Question 104: An administrator is estimating the cost associated with an a...
Question 105: An administrator investigating an incident is concerned abou...
Question 106: A security report shows that during a two-week test period. ...
Question 107: Which of the following security concepts is the best reason ...
Question 108: During a recent log review, an analyst found evidence of suc...
Question 109: A company wants to minimize the chance of its outgoing marke...
Question 110: An important patch for a critical application has just been ...
Question 111: Which of the following activities is included in the post-in...
Question 112: An organization recently started hosting a new service that ...
Question 113: Which of the following best describes the main difference be...
Question 114: A security administrator observed the following in a web ser...
Question 115: Which of the following should be used to select a label for ...
Question 116: Which of the following is the best reason to perform a table...
Question 117: Which of the following agreement types defines the time fram...
Question 118: A security administrator is reissuing a former employee ' s ...
Question 119: A company experiences a data loss event due to a stolen lapt...
Question 120: A company ' s accounts payable clerk receives a message from...
Question 121: A company uses its backups to recover from a ransomware atta...
Question 122: Which of the following would be the best way to test resilie...
Question 123: A systems administrator uses deception techniques to help de...
Question 124: Which of the following is the best way to improve the confid...
Question 125: Security controls in a data center are being reviewed to ens...
Question 126: Which of the following vulnerabilities would likely be mitig...
Question 127: A security analyst has determined that a security breach wou...
Question 128: A systems administrator receives an alert that a company ' s...
Question 129: A security analyst is investigating an alert that was produc...
Question 130: Which of the following should a security team do first befor...
Question 131: Which of the following would best prepare a security team fo...
Question 132: The physical security team at a company receives reports tha...
Question 133: The Chief Information Security Officer wants to discuss opti...
Question 134: Which of the following is a feature of a next-generation SIE...
Question 135: Which of the following methods will most likely be used to i...
Question 136: A technician needs to apply a high-priority patch to a produ...
Question 137: Which of the following is a compensating control for providi...
Question 138: A company is concerned with supply chain compromise of new s...
Question 139: After a recent vulnerability scan, a security engineer needs...
Question 140: A forensic engineer determines that the root cause of a comp...
Question 141: A company ' s online shopping website became unusable shortl...
Question 142: An administrator finds that all user workstations and server...
Question 143: An employee asks a security analyst to scan a suspicious ema...
Question 144: A security analyst receives an alert from a corporate endpoi...
Question 145: An employee decides to collect PII data from the company ' s...
Question 146: A new employee accessed an unauthorized website. An investig...
Question 147: A company implemented an MDM policy 10 mitigate risks after ...
Question 148: A wireless administrator sets up a new network in a small of...
Question 149: An administrator is reviewing a single server ' s security l...
Question 150: Which of the following is the most relevant reason a DPO wou...
Question 151: Which of the following security controls would best guard a ...
Question 152: Which of the following are the best methods for hardening en...
Question 153: After failing an audit twice, an organization has been order...
Question 154: When trying to access an internal website, an employee repor...
Question 155: Which of the following is a hardware-specific vulnerability?...
Question 156: A security practitioner completes a vulnerability assessment...
Question 157: Which of the following methods would most likely be used to ...
Question 158: Which of the following should an internal auditor check for ...
Question 159: The security team at a large global company needs to reduce ...
Question 160: Which of the following consequences would a retail chain mos...
Question 161: A company discovers suspicious transactions that were entere...
Question 162: An employee fell for a phishing scam, which allowed an attac...
Question 163: An organization authorizes system deployment on the network ...
Question 164: Which of the following best explains a concern with OS-based...
Question 165: A website user is locked out of an account after clicking an...
Question 166: A security analyst needs to improve the company's authentica...
Question 167: The marketing department set up its own project management s...
Question 168: A technician is opening ports on a firewall for a new system...
Question 169: Which of the following cryptographic methods is preferred fo...
Question 170: A malicious update was distributed to a common software plat...
Question 171: A site reliability engineer is designing a recovery strategy...
Question 172: Employees are missing features on company-provided tablets, ...
Question 173: While troubleshooting a firewall configuration, a technician...
Question 174: Various company stakeholders meet to discuss roles and respo...
Question 175: Which of the following vulnerabilities is associated with in...
Question 176: An attorney prints confidential documents to a copier in an ...
Question 177: A security administrator needs a method to secure data in an...
Question 178: An organization experiences a suspected data breach that aff...
Question 179: Several customers want an organization to verify its securit...
Question 180: Which of the following can be used to mitigate attacks from ...
Question 181: A security technician determines that no additional patches ...
Question 182: A vendor salesperson is a personal friend of a company's Chi...
Question 183: A security analyst investigates abnormal outbound traffic fr...
Question 184: A security analyst estimates that a small security incident ...
Question 185: An analyst discovers a suspicious item in the SQL server log...
Question 186: One of a company ' s vendors sent an analyst a security bull...
Question 187: Which of the following is an example of a certificate that i...
Question 188: A security manager needs an automated solution that will tak...
Question 189: You are security administrator investigating a potential inf...
Question 190: An IT team rolls out a new management application that uses ...
Question 191: A systems administrator is redesigning now devices will perf...
Question 192: A hacker gained access to a system via a phishing attempt th...
Question 193: A security analyst is investigating an application server an...
Question 194: An employee emailed a new systems administrator a malicious ...
Question 195: A security engineer at a large company needs to enhance IAM ...
Question 196: A systems administrator set up a perimeter firewall but cont...
Question 197: A company is adding a clause to its AUP that states employee...
Question 198: Which of the following technologies must be used in an organ...
Question 199: Which of the following is used to protect a computer from vi...
Question 200: A security engineer needs to quickly identify a signature fr...
Question 201: A legal department must maintain a backup from all devices t...
Question 202: Which of the following describes the difference between encr...
Question 203: A security analyst is evaluating a SaaS application that the...
Question 204: A security analyst receives alerts about an internal system ...
Question 205: Several employees received a fraudulent text message from so...
Question 206: Which of the following is a type of vulnerability that refer...
Question 207: A company plans to secure its systems by: Preventing users f...
Question 208: A security team created a document that details the order in...
Question 209: After completing an annual external penetration test, a comp...
Question 210: Which of the following risk analysis attributes measures the...
Question 211: Which of the following best describes a method for ongoing v...
Question 212: A company receives an alert that a network device vendor, wh...
Question 213: A client asked a security company to provide a document outl...
Question 214: Which of the following hardening techniques must be applied ...
Question 215: A systems administrator is creating a script that would save...
Question 216: A penetration tester begins an engagement by performing port...
Question 217: A penetration testing report indicated that an organization ...
Question 218: A university employee logged on to the academic server and a...
Question 219: A security analyst reviews domain activity logs and notices ...
Question 220: An administrator was notified that a user logged in remotely...
Question 221: Users at a company are reporting they are unable to access t...
Question 222: Which of the following describes the understanding between a...
Question 223: An organization plans to expand its operations international...
Question 224: A security administrator needs to reduce the attack surface ...
Question 225: An organization ' s web servers host an online ordering syst...
Question 226: A systems administrate wants to implement a backup solution....
Question 227: A security analyst identifies an incident in the network. Wh...
Question 228: Which of the following must be considered when designing a h...
Question 229: Which of the following environments utilizes a subset of cus...
Question 230: A recent penetration test identified that an attacker could ...
Question 231: Which of the following is the final step of the modem respon...
Question 232: Following a security review, an organization must ensure use...
Question 233: An enterprise is trying to limit outbound DNS traffic origin...
Question 234: Which of the following describes the procedures a penetratio...
Question 235: Which of the following should a systems administrator use to...
Question 236: Which of the following is the primary purpose of a service t...
Question 237: Sine a recent upgrade (o a WLAN infrastructure, several mobi...
Question 238: A software developer wishes to implement an application secu...
Question 239: Which of the following must be considered when designing a h...
Question 240: A company is considering an expansion of access controls for...
Question 241: Which of the following techniques can be used to sanitize th...
Question 242: A company wants to verify that the software the company is d...
Question 243: Which of the following describes the reason root cause analy...
Question 244: Which of the following would be the best ways to ensure only...
Question 245: A company wants to ensure that only authorized devices can e...
Question 246: A security analyst is creating the first draft of a network ...
Question 247: An engineer needs to find a solution that creates an added l...
Question 248: A company ' s website is www. Company. com Attackers purchas...
Question 249: Which of the following tools can assist with detecting an em...
Question 250: Which of the following is a benefit of vendor diversity?...
Question 251: Which of the following types of identification methods can b...
Question 252: An organization disabled unneeded services and placed a fire...
Question 253: A systems administrator is creating a script that would save...
Question 254: A growing company would like to enhance the ability of its s...
Question 255: Which of the following actions would reduce the number of fa...
Question 256: Which of the following definitions best describes the concep...
Question 257: An employee who was working remotely lost a mobile device co...
Question 258: Which of the following is a security benefit of an effective...
Question 259: Which of the following activities should be performed first ...
Question 260: Which of the following best describes the practice of resear...
Question 261: Which of the following is an example of a false negative vul...
Question 262: A security officer observes that a software development team...
Question 263: Attackers created a new domain name that looks similar to a ...
Question 264: An administrator discovers that some files on a database ser...
Question 265: Which of the following is a prerequisite for a DLP solution?...
Question 266: A security engineer would like to enhance the use of automat...
Question 267: Which of the following is required for an organization to pr...
Question 268: Which of the following uses proprietary controls and is desi...
Question 269: Which of the following data types relates to data sovereignt...
Question 270: A business is expanding to a new country and must protect cu...
Question 271: A security administrator protects passwords by using hashing...
Question 272: Which of the following technologies assists in passively ver...
Question 273: Which of the following should a security operations center u...
Question 274: An accounting employee recently used software that was not a...
Question 275: A systems administrator works for a local hospital and needs...
Question 276: A security consultant is working with a client that wants to...
Question 277: While a user reviews their email, a host gets infected by ma...
Question 278: An alert references attacks associated with a zero-day explo...
Question 279: A security administrator recently reset local passwords and ...
Question 280: Which of the following explains how regular patching helps m...
Question 281: Which of the following concepts protects sensitive informati...
Question 282: Which of the following provides the best protection against ...
Question 283: In an effort to reduce costs, a company is implementing a st...
Question 284: A company plans to secure its systems by: Preventing users f...
Question 285: Which of the following involves an attempt to take advantage...
Question 286: A company uses multiple providers to send its marketing, int...
Question 287: An analyst is reviewing an incident in which a user clicked ...
Question 288: An administrator installs an SSL certificate on a new system...
Question 289: An organization experiences a cybersecurity incident involvi...
Question 290: An administrator must implement a solution that provides sec...
Question 291: Which of the following would most likely be used by attacker...
Question 292: A user needs to complete training at https://comptiatraining...
Question 293: A penetration tester visits a client's website and downloads...
Question 294: Which of the following should be used to ensure that a devic...
Question 295: Which of the following is the most common data loss path for...
Question 296: Which of the following will most likely lead an organization...
Question 297: An accountant is transferring information to a bank over FTP...
Question 298: A vendor needs to remotely and securely transfer files from ...
Question 299: A company processes a large volume of business-to-business t...
Question 300: A security analyst sees the following entries in web server ...
Question 301: An organization conducts a self-evaluation with a phishing c...
Question 302: An administrator notices that several users are logging in f...
Question 303: Which of the following threat vectors is most commonly utili...
Question 304: A security analyst is prioritizing vulnerability scan result...
Question 305: Which of the following would best explain why a security ana...
Question 306: Which of the following has been implemented when a host-base...
Question 307: A company decides to purchase an insurance policy. Which of ...
Question 308: In which of the following scenarios is tokenization the best...
Question 309: A nation-state attacker gains access to the email accounts o...
Question 310: After a security awareness training session, a user called t...
Question 311: A security analyst receives an alert that an employee has cl...
Question 312: A new corporate policy requires all staff to use multifactor...
Question 313: A security team receives reports about high latency and comp...
Question 314: Which of the following is a common source of unintentional c...
Question 315: Which of the following methods to secure credit card data is...
Question 316: An organization experiences a compromise in a cloud-hosted s...
Question 317: Which of the following best explains the use of a policy eng...
Question 318: A Chief Information Security Officer (CISO) has developed in...
Question 319: While conducting a business continuity tabletop exercise, th...
Question 320: A penetration test has demonstrated that domain administrato...
Question 321: Various stakeholders are meeting to discuss their hypothetic...
Question 322: Which of the following is the most likely to be used to docu...
Question 323: An administrator has identified and fingerprinted specific f...
Question 324: Which of the following is the best way to prevent data from ...
Question 325: A penetration tester is testing the security of a building's...
Question 326: At the start of a penetration test, the tester checks OSINT ...
Question 327: An organization is adopting cloud services at a rapid pace a...
Question 328: Which of the following activities would involve members of t...
Question 329: A security engineer is working to address the growing risks ...
Question 330: A company prepares for an upcoming regulatory audit. The com...
Question 331: An administrator is creating a secure method for a contracto...
Question 332: As part of new compliance audit requirements, multiple serve...
Question 333: A company ' s accounting department receives an urgent payme...
Question 334: Which of the following enables the use of an input field to ...
Question 335: Which of the following actions is best performed by ticketin...
Question 336: After reviewing the following vulnerability scanning report:...
Question 337: A security analyst is reviewing the following logs about a s...
Question 338: An organization is leveraging a VPN between its headquarters...
Question 339: During a routine audit, an analyst discovers that a departme...
Question 340: Which of the following is used to quantitatively measure the...
Question 341: An employee recently resigned from a company. The employee w...
Question 342: An incident response specialist must stop a malicious attack...
Question 343: Which of the following explains how to determine the global ...
Question 344: Which of the following is the most likely motivation for a h...
Question 345: A company is currently utilizing usernames and passwords, an...
Question 346: A company wants to use new Wi-Fi-enabled environmental senso...
Question 347: A security team must help secure a company site after attack...
Question 348: A security analyst must prevent remote users from accessing ...
Question 349: A data administrator is configuring authentication for a Saa...
Question 350: During a SQL update of a database, a temporary field used as...
Question 351: Which of the following digital forensics activities would a ...
Question 352: A user would like to install software and features that are ...
Question 353: After a security incident, a systems administrator asks the ...
Question 354: Which of the following data states applies to data that is b...
Question 355: During a recent company safety stand-down, the cyber-awarene...
Question 356: Which of the following could potentially be introduced at th...
Question 357: A newly appointed board member with cybersecurity knowledge ...
Question 358: Which of the following best describe the benefits of a micro...
Question 359: Which of the following is the most likely outcome if a large...
Question 360: A legacy device is being decommissioned and is no longer rec...
Question 361: Which of the following should a technician perform to verify...
Question 362: An organization is required to provide assurance that its co...
Question 363: An organization wants a third-party vendor to do a penetrati...
Question 364: A service provider wants a cost-effective way to rapidly exp...
Question 365: Which of the following risk management strategies should an ...
Question 366: Which of the following would a systems administrator follow ...
Question 367: A customer of a large company receives a phone call from som...
Question 368: A security analyst and the management team are reviewing the...
Question 369: A network administrator wants to ensure that network traffic...
Question 370: A user sends an email that includes a digital signature for ...
Question 371: A security analyst reviews the following endpoint log: power...
Question 372: A systems administrator discovers a system that is no longer...
Question 373: An administrator wants to perform a risk assessment without ...
Question 374: A company is considering an expansion of access controls for...
Question 375: A company relies on open-source software libraries to build ...
Question 376: Which of the following phases of an incident response involv...
Question 377: A company wants to reduce the time and expense associated wi...
Question 378: An organization has learned that its data is being exchanged...
Question 379: A malicious insider from the marketing team alters records a...
Question 380: A security analyst developed a script to automate a trivial ...
Question 381: Which solution is most likely used in the financial industry...
Question 382: Which of the following risk management strategies is being u...
Question 383: A company processes personal data from customers in multiple...
Question 384: Which of the following automation use cases would best enhan...
Question 385: A network administrator deploys an FDE solution on all end u...
Question 386: A company processes and stores sensitive data on its own sys...
Question 387: A business provides long-term cold storage services to banks...
Question 388: Which of the following actions best addresses a vulnerabilit...
Question 389: An organization would like to store customer data on a separ...
1 commentQuestion 390: Which of the following is the best method to reduce the atta...
Question 391: Which of the following strategies should an organization use...
Question 392: An analyst wants to move data from production to the UAT ser...
Question 393: Which of the following should a security administrator adher...
Question 394: Which of the following is used to validate a certificate whe...
Question 395: Which of the following is the most effective way to protect ...
Question 396: The Chief Information Security Officer (CISO) requires that ...
Question 397: After a series of account compromises and credential misuse,...
Question 398: A systems administrator needs to provide traveling employees...
Question 399: The security operations center is researching an event conce...
Question 400: A security team wants WAF policies to be automatically creat...
Question 401: A security analyst investigates an incident in which a Power...
Question 402: Which of the following is the best way to validate the integ...
Question 403: A software developer released a new application and is distr...
Question 404: Executives at a company are concerned about employees access...
Question 405: A company is in the process of cutting jobs to manage costs....
Question 406: A company discovered its data was advertised for sale on the...
Question 407: An MSSP manages firewalls for hundreds of clients. Which of ...
Question 408: Which of the following scenarios describes a possible busine...
Question 409: Which of the following threat actors is the most likely to b...
Question 410: A security analyst is reviewing logs and discovers the follo...