<< Prev Question Next Question >>

Question 945/1066

During a routine audit it is discovered that someone has been using a state administrator account to log into a seldom used server. The person used server. The person has been using the server to view inappropriate websites that are prohibited to end users. Which of the following could BEST prevent this from occurring again?

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (1066q)
Question 1: A company is trying to implement physical deterrent controls...
Question 2: When employing PKI to send signed and encrypted data the ind...
Question 3: Which of the following, if properly implemented, would preve...
Question 4: A user has unknowingly gone to a fraudulent site. The securi...
Question 5: A software security concern when dealing with hardware and d...
Question 6: Which of the following is the LEAST volatile when performing...
Question 7: Pete, the security administrator, has been notified by the I...
Question 8: How must user accounts for exiting employees be handled?...
Question 9: Which of the following is a black box testing methodology?...
Question 10: A small business needs to incorporate fault tolerance into t...
Question 11: Which of the following can Joe, a security administrator, im...
Question 12: Speaking a passphrase into a voice print analyzer is an exam...
Question 13: Given the following set of firewall rules: From the inside t...
Question 14: Several users report to the administrator that they are havi...
Question 15: Ann, the security administrator, has been reviewing logs and...
Question 16: A recent audit has revealed weaknesses in the process of dep...
Question 17: A company has a BYOD policy that includes tablets and smart ...
Question 18: Which of the following can a security administrator implemen...
Question 19: Ann, the software security engineer, works for a major softw...
Question 20: Which of the following hardware based encryption devices is ...
Question 21: If an organization wants to implement a BYOD policy, which o...
Question 22: Which of the following controls mitigates the risk of Matt, ...
Question 23: To protect corporate data on removable media, a security pol...
Question 24: It is important to staff who use email messaging to provide ...
Question 25: The system administrator is tasked with changing the adminis...
Question 26: Ann, a newly hired human resource employee, sent out confide...
Question 27: Which of the following is true about input validation in a c...
Question 28: A security administrator has installed a new KDC for the cor...
Question 29: Which of the following application attacks is used against a...
Question 30: A company has two server administrators that work overnight ...
Question 31: Which of the following security strategies allows a company ...
Question 32: An administrator notices that former temporary employees' ac...
Question 33: A security analyst must ensure that the company's web server...
Question 34: During a recent audit, the auditors cited the company's curr...
Question 35: A network administrator has a separate user account with rig...
Question 36: Which of the following techniques describes the use of appli...
Question 37: DRAG DROP A security administrator is given the security and...
Question 38: Which of the following can be used as an equipment theft det...
Question 39: Which of the following would be used to allow a subset of tr...
Question 40: During a server audit, a security administrator does not not...
Question 41: Joe wants to employ MD5 hashing on the company file server. ...
Question 42: During a routine audit a web server is flagged for allowing ...
Question 43: Which of the following protocols provides for mutual authent...
Question 44: Which of the following could a security administrator implem...
Question 45: A Chief Privacy Officer, Joe, is concerned that employees ar...
Question 46: An IT auditor tests an application as an authenticated user....
Question 47: Which of the following protocols is vulnerable to man-in-the...
Question 48: A military base wants to incorporate biometrics into its new...
Question 49: Sara, the Chief Information Officer (CIO), has requested an ...
Question 50: Which of the following techniques enables a highly secured o...
Question 51: An incident occurred when an outside attacker was able to ga...
Question 52: Which of the following authentication services uses a defaul...
Question 53: A security administrator is concerned about the strength of ...
Question 54: A network security engineer notices unusual traffic on the n...
Question 55: The Chief Technology Officer (CTO) wants to improve security...
Question 56: Sara, a company's security officer, often receives reports o...
Question 57: Which of the following is the best practice to put at the en...
Question 58: After running into the data center with a vehicle, attackers...
Question 59: Which of the following can BEST help prevent cross-site scri...
Question 60: A security technician would like an application to use rando...
Question 61: The security administrator receives a service ticket saying ...
Question 62: A network security administrator is trying to determine how ...
Question 63: Which of the following can Pete, a security administrator, u...
Question 64: An organization is required to log all user internet activit...
Question 65: An administrator implements SELinux on a production web serv...
Question 66: Which of the following would BEST be used to calculate the e...
Question 67: Some customers have reported receiving an untrusted certific...
Question 68: A security administrator is using a software program to test...
Question 69: A webpage displays a potentially offensive advertisement on ...
Question 70: Which of the following would a security administrator implem...
Question 71: A company hosts a web server that requires entropy in encryp...
Question 72: An SSL session is taking place. After the handshake phase ha...
Question 73: Which of the following documents outlines the responsibility...
Question 74: After a new RADIUS server is added to the network, an employ...
Question 75: Vendors typically ship software applications with security s...
Question 76: A company has 5 users. Users 1, 2 and 3 need access to payro...
Question 77: Which of the following is a security risk regarding the use ...
Question 78: A security administrator finds that an intermediate CA withi...
Question 79: Which of the following is the process in which a law enforce...
Question 80: An advantage of virtualizing servers, databases, and office ...
Question 81: A technician is investigating intermittent switch degradatio...
Question 82: Methods to test the responses of software and web applicatio...
Question 83: A systems engineer has been presented with storage performan...
Question 84: After a security incident involving a physical asset, which ...
Question 85: A security team has established a security awareness program...
Question 86: Which of the following application security testing techniqu...
Question 87: A network administrator argues that WPA2 encryption is not n...
Question 88: Which of the following BEST describes using a smart card and...
Question 89: Ann, the IT director, wants to ensure that as hoc changes ar...
Question 90: Which of the following would provide the MOST objective resu...
Question 91: Ann a new security specialist is attempting to access the in...
Question 92: An attacker went to a local bank and collected disposed pape...
Question 93: Ann works at a small company and she is concerned that there...
Question 94: A recent audit has discovered that at the time of password e...
Question 95: The sales force in an organization frequently travel to remo...
Question 96: While preparing for an audit a security analyst is reviewing...
Question 97: Which of the following is characterized by an attack against...
Question 98: Which of the following devices will help prevent a laptop fr...
Question 99: A security administrator discovered that all communication o...
Question 100: Which of the following wireless security measures can an att...
Question 101: Which of the following will allow Pete, a security analyst, ...
Question 102: A team of firewall administrators have access to a `master p...
Question 103: An administrator is implementing a new management system for...
Question 104: A security engineer is given new application extensions each...
Question 105: Which of the following controls can be implemented together ...
Question 106: Ann, a technician, received a spear-phishing email asking he...
Question 107: Digital signatures are used for ensuring which of the follow...
Question 108: A network inventory discovery application requires non-privi...
Question 109: A group policy requires users in an organization to use stro...
Question 110: Users require access to a certain server depending on their ...
Question 111: A security administrator is reviewing the below output from ...
Question 112: Which of the following is the GREATEST security concern of a...
Question 113: Which of the following authentication services combines auth...
Question 114: An administrator was asked to review user accounts. Which of...
Question 115: The chief information officer (CIO) of a major company inten...
Question 116: A new employee has joined the accounting department and is u...
Question 117: A security engineer is tasked with encrypting corporate emai...
Question 118: Which of the following attacks involves the use of previousl...
Question 119: Which of the following password attacks involves attempting ...
Question 120: Pete, a security auditor, has detected clear text passwords ...
Question 121: The software developer is responsible for writing the code a...
Question 122: Ann a security technician receives a report from a user that...
Question 123: Matt, a forensic analyst, wants to obtain the digital finger...
Question 124: Identifying a list of all approved software on a system is a...
Question 125: Which of the following provides dedicated hardware-based cry...
Question 126: Which of the following tools would allow Ann, the security a...
Question 127: An auditing team has found that passwords do not meet the be...
Question 128: Which of the following is BEST carried out immediately after...
Question 129: A security administrator wants to ensure that the message th...
Question 130: A malicious user has collected the following list of informa...
Question 131: A datacenter has suffered repeated burglaries which led to e...
Question 132: The security administrator notices a user logging into a cor...
Question 133: Which of the following ports should be opened on a firewall ...
Question 134: Which of the following should be used to authenticate and lo...
Question 135: A fiber company has acquired permission to bury a fiber cabl...
Question 136: Which of the following relies on the use of shared secrets t...
Question 137: An administrator performs a risk calculation to determine if...
Question 138: A company hired Joe, an accountant. The IT administrator wil...
Question 139: Which of the following types of encryption will help in prot...
Question 140: When Ann an employee returns to work and logs into her works...
Question 141: A software developer wants to prevent stored passwords from ...
Question 142: Which of the following should be done before resetting a use...
Question 143: Which of the following risk concepts requires an organizatio...
Question 144: The security manager received a report that an employee was ...
Question 145: A security analyst, while doing a security scan using packet...
Question 146: Which of the following may be used with a BNC connector?...
Question 147: A security administrator has just finished creating a hot si...
Question 148: One month after a software developer was terminated, the hel...
Question 149: Sara, an application developer, implemented error and except...
Question 150: A company has been attacked and their website has been alter...
Question 151: An auditor's report discovered several accounts with no acti...
Question 152: A Windows- based computer is infected with malware and is ru...
Question 153: Which of the following should be enabled in a laptop's BIOS ...
Question 154: A security researcher wants to reverse engineer an executabl...
Question 155: A recent review of accounts on various systems has found tha...
Question 156: An assessment too reports that the company's web server may ...
Question 157: Ann was reviewing her company's event logs and observed seve...
Question 158: A security analyst implemented group-based privileges within...
Question 159: A security administrator is selecting an MDM solution for an...
Question 160: An agent wants to create fast and efficient cryptographic ke...
Question 161: What is the term for the process of luring someone in (usual...
Question 162: A security administrator has been tasked with assisting in t...
Question 163: Upper management decides which risk to mitigate based on cos...
Question 164: A router was shut down as a result of a DoS attack. Upon rev...
Question 165: Several employees have been printing files that include pers...
Question 166: A periodic update that corrects problems in one version of a...
Question 167: Which of the following is a common coding error in which bou...
Question 168: A security analyst is working on a project team responsible ...
Question 169: An online store wants to protect user credentials and credit...
Question 170: An application developer needs to allow employees to use the...
Question 171: An attacker used an undocumented and unknown application exp...
Question 172: A forensic analyst is reviewing electronic evidence after a ...
Question 173: An organization's security policy states that users must aut...
Question 174: A server dedicated to the storage and processing of sensitiv...
Question 175: A company's chief information officer (CIO) has analyzed the...
Question 176: A company's employees were victims of a spear phishing campa...
Question 177: In which of the following categories would creating a corpor...
Question 178: Which of the following concepts describes the use of a one-w...
Question 179: A security administrator needs to determine which system a p...
Question 180: Which of the following is a hardware-based security technolo...
Question 181: Which of the following software allows a network administrat...
Question 182: Ann would like to forward some Personal Identifiable Informa...
Question 183: The Quality Assurance team is testing a new third party deve...
Question 184: Users are utilizing thumb drives to connect to USB ports on ...
Question 185: A security administrator wants to get a real time look at wh...
Question 186: Ann is the data owner of financial records for a company. Sh...
Question 187: A security administrator is responsible for ensuring that th...
Question 188: Joe, the information security manager, is tasked with calcul...
Question 189: The string: 'or 1=1-- - Which of the following represents it...
Question 190: An administrator discovers that many users have used their s...
Question 191: A security administrator looking through IDS logs notices th...
Question 192: Joe a company's new security specialist is assigned a role t...
Question 193: A classroom utilizes workstations running virtualization sof...
Question 194: When an order was submitted via the corporate website, an ad...
Question 195: The security department has implemented a new laptop encrypt...
Question 196: A company requires that all users enroll in the corporate PK...
Question 197: The act of magnetically erasing all of the data on a disk is...
Question 198: A security director has contracted an outside testing compan...
Question 199: Joe, a web developer, wants to make sure his application is ...
Question 200: Which of the following was launched against a company based ...
Question 201: Which of the following is provided by RADIUS?...
Question 202: An administrator has successfully implemented SSL on srv4.co...
Question 203: An employee attempts to go to a well-known bank site using t...
Question 204: At the outside break area, an employee, Ann, asked another e...
Question 205: XYZ Corporation is about to purchase another company to expa...
Question 206: Pete, the security engineer, would like to prevent wireless ...
Question 207: A system administrator has been instructed by the head of se...
Question 208: Which of the following malware types typically allows an att...
Question 209: Which of the following tools will allow a technician to dete...
Question 210: Which of the following types of logs could provide clues tha...
Question 211: An administrator has to determine host operating systems on ...
Question 212: A user casually browsing the Internet is redirected to a war...
Question 213: A security administrator is reviewing the company's continui...
Question 214: The database server used by the payroll system crashed at 3 ...
Question 215: A network administrator was to implement a solution that wil...
Question 216: An attacker Joe configures his service identifier to be the ...
Question 217: The security administrator is currently unaware of an incide...
Question 218: While responding to an incident on a Linux server, the admin...
Question 219: A programmer must write a piece of code to encrypt passwords...
Question 220: The security administration team at a company has been taske...
Question 221: Which of the following ports is used for TELNET by default?...
Question 222: A website is breached, exposing the usernames and MD5 passwo...
Question 223: Joe, a security analyst, is attempting to determine if a new...
Question 224: After a recent breach, the security administrator performs a...
Question 225: Several employees clicked on a link in a malicious message t...
Question 226: Which of the following includes environmental control measur...
Question 227: A server administrator notes that a fully patched applicatio...
Question 228: A chief information security officer (CISO) is providing a p...
Question 229: A security technician wishes to gather and analyze all Web t...
Question 230: Which of the following is an example of multifactor authenti...
Question 231: Ann has recently transferred from the payroll department to ...
Question 232: After connecting to the corporate network a user types the U...
Question 233: Highly sensitive data is stored in a database and is accesse...
Question 234: Ann is traveling for business and is attempting to use the h...
Question 235: Pete, the Chief Executive Officer (CEO) of a company, has in...
Question 236: Which of the following practices reduces the management burd...
Question 237: A Company has recently identified critical systems that supp...
Question 238: Which of the following internal security controls is aimed a...
Question 239: Which of the following is the BEST reason to provide user aw...
Question 240: A network stream needs to be encrypted. Sara, the network ad...
Question 241: Which of the following data security techniques will allow M...
Question 242: A recent spike in virus detections has been attributed to en...
Question 243: Which of the following are Data Loss Prevention (DLP) strate...
Question 244: Which of the following is an attack vector that can cause ex...
Question 245: A recent intrusion has resulted in the need to perform incid...
Question 246: A company is installing a new security measure that would al...
Question 247: The Chief Technical Officer (CTO) has tasked The Computer Em...
Question 248: A security administrator suspects that an employee in the IT...
Question 249: Pete, the system administrator, has concerns regarding users...
Question 250: If Organization A trusts Organization B and Organization B t...
Question 251: Which of the following types of data encryption would Matt, ...
Question 252: Pete's corporation has outsourced help desk services to a la...
Question 253: Which of the following attacks impact the availability of a ...
Question 254: Users at a company report that a popular news website keeps ...
Question 255: Ann, a security administrator is hardening the user password...
Question 256: A user has forgotten their account password. Which of the fo...
Question 257: A datacenter requires that staff be able to identify whether...
Question 258: The security consultant is assigned to test a client's new s...
Question 259: A security administrator is troubleshooting an authenticatio...
Question 260: After copying a sensitive document from his desktop to a fla...
Question 261: While troubleshooting a new wireless 802.11 ac network an ad...
Question 262: Joe, a technician, is tasked with finding a way to test oper...
Question 263: An investigator recently discovered that an attacker placed ...
Question 264: Which of the following is a measure of biometrics performanc...
Question 265: Users have been reporting that their wireless access point i...
Question 266: While an Internet café a malicious user is causing all surro...
Question 267: Ann, a security administrator, is strengthening the security...
Question 268: A system security analyst using an enterprise monitoring too...
Question 269: A company needs to receive data that contains personally ide...
Question 270: One of the most consistently reported software security vuln...
Question 271: Client computers login at specified times to check and updat...
Question 272: An internal auditor is concerned with privilege creep that i...
Question 273: Ann an employee is visiting Joe, an employee in the Human Re...
Question 274: Which of the following is an example of establishing a publi...
Question 275: Ann is a member of the Sales group. She needs to collaborate...
Question 276: An organization is recovering data following a datacenter ou...
Question 277: A security technician has been asked to recommend an authent...
Question 278: A server with the IP address of 10.10.2.4 has been having in...
Question 279: A bank is planning to implement a third factor to protect cu...
Question 280: In which of the following scenarios would it be preferable t...
Question 281: A large bank has moved back office operations offshore to an...
Question 282: Which of the following security architecture elements also h...
Question 283: Ann, an employee, is cleaning out her desk and disposes of p...
Question 284: Which of the following technologies when applied to android ...
Question 285: Which of the following describes purposefully injecting extr...
Question 286: Matt, a security analyst, needs to implement encryption for ...
Question 287: A recently installed application update caused a vital appli...
Question 288: Which of the following risks could IT management be mitigati...
Question 289: A large corporation has data centers geographically distribu...
Question 290: Which of the following is the MOST intrusive type of testing...
Question 291: A user commuting to work via public transport received an of...
Question 292: Which of the following may significantly reduce data loss if...
Question 293: After a user performed a war driving attack, the network adm...
Question 294: A forensic analyst is reviewing electronic evidence after a ...
Question 295: A security audit identifies a number of large email messages...
Question 296: Which of the following types of technologies is used by secu...
Question 297: A network technician has received comments from several user...
Question 298: A network administrator is configuring access control for th...
Question 299: The security administrator is implementing a malware storage...
Question 300: DRAG DROP Determine the types of attacks below by selecting ...
Question 301: In which of the following steps of incident response does a ...
Question 302: A hacker has discovered a simple way to disrupt business for...
Question 303: A company wants to ensure that all credentials for various s...
Question 304: A company has identified a watering hole attack. Which of th...
Question 305: The manager has a need to secure physical documents every ni...
Question 306: Which of the following is mainly used for remote access into...
Question 307: Each server on a subnet is configured to only allow SSH acce...
Question 308: In Kerberos, the Ticket Granting Ticket (TGT) is used for th...
Question 309: A security analyst, Ann, is reviewing an IRC channel and not...
Question 310: Which of the following should Jane, a security administrator...
Question 311: Which of the following attacks would cause all mobile device...
Question 312: Which of the following attacks initiates a connection by sen...
Question 313: A system administrator is responding to a legal order to tur...
Question 314: The Chief Information Officer (CIO) receives an anonymous th...
Question 315: A company has recently allowed employees to take advantage o...
Question 316: A computer supply company is located in a building with thre...
Question 317: Mike, a security professional, is tasked with actively verif...
Question 318: A security administrator wants to test the reliability of an...
Question 319: A system administrator has made several unauthorized changes...
Question 320: Which of the following is a control that allows a mobile app...
Question 321: A software firm posts patches and updates to a publicly acce...
Question 322: Joe analyzed the following log and determined the security t...
Question 323: Ann is concerned that the application her team is currently ...
Question 324: The use of social networking sites introduces the risk of:...
Question 325: Which of the following is a security concern regarding users...
Question 326: After an assessment, auditors recommended that an applicatio...
Question 327: Which of the following attacks allows access to contact list...
Question 328: Which of the following concepts is enforced by certifying th...
Question 329: Which of the following is the BEST practice when dealing wit...
Question 330: The helpdesk reports increased calls from clients reporting ...
Question 331: A system administrator wants to prevent password compromises...
Question 332: Anne, an employee, receives the following email: From: Human...
Question 333: Human Resources suspects an employee is accessing the employ...
Question 334: When implementing a Public Key Infrastructure, which of the ...
Question 335: A security technician has been tasked with opening ports on ...
Question 336: Which of the following presents the STRONGEST access control...
Question 337: Which of the following is an authentication service that use...
Question 338: Which of the following BEST describes a protective counterme...
Question 339: The Chief Information Officer (CIO) wants to implement a red...
Question 340: A new mobile banking application is being developed and uses...
Question 341: An employee connects a wireless access point to the only jac...
Question 342: Which of the following is a way to implement a technical con...
Question 343: The security manager reports that the process of revoking ce...
Question 344: Ann, a security administrator, wants to limit access to the ...
Question 345: Which of the following is used by the recipient of a digital...
Question 346: The Chief Executive Officer (CEO) receives a suspicious voic...
Question 347: Several employee accounts appear to have been cracked by an ...
Question 348: An organization has introduced token-based authentication to...
Question 349: Users report that they are unable to access network printing...
Question 350: Which of the following types of attacks is based on coordina...
Question 351: Which of the following helps to establish an accurate timeli...
Question 352: A distributed denial of service attack can BEST be described...
Question 353: Physical documents must be incinerated after a set retention...
Question 354: Which of the following would BEST deter an attacker trying t...
Question 355: Which of the following can be implemented in hardware or sof...
Question 356: Input validation is an important security defense because it...
Question 357: Which of the following is BEST utilized to actively test sec...
Question 358: Joe, the system administrator, is performing an overnight sy...
Question 359: A small company has a website that provides online customer ...
Question 360: Sara, an attacker, is recording a person typing in their ID ...
Question 361: Which of the following protocols uses an asymmetric key to o...
Question 362: During a penetration test from the Internet, Jane, the syste...
Question 363: Which of the following is used to inform users of the reperc...
Question 364: An administrator would like users to authenticate to the net...
Question 365: Certificates are used for: (Choose two.)...
Question 366: SIMULATION A security administrator discovers that an attack...
Question 367: During a recent investigation, an auditor discovered that an...
Question 368: Which of the following BEST describes malware that tracks a ...
Question 369: Which of the following controls would allow a company to red...
Question 370: The marketing department wants to distribute pens with embed...
Question 371: A resent OS patch caused an extended outage. It took the IT ...
Question 372: Data confidentiality must be enforced on a secure database. ...
Question 373: Which of the following would prevent a user from installing ...
Question 374: A system administrator has noticed vulnerability on a high i...
Question 375: Which of the following concepts allows an organization to gr...
Question 376: Which of the following is an advantage of implementing indiv...
Question 377: Which of the following are examples of network segmentation?...
Question 378: Which of the following automated or semi-automated software ...
Question 379: Which of the following can be performed when an element of t...
Question 380: Which of the following is where an unauthorized device is fo...
Question 381: Which of the following wireless protocols could be vulnerabl...
Question 382: Using a heuristic system to detect an anomaly in a computer'...
Question 383: The IT department noticed that there was a significant decre...
Question 384: A network administrator uses an RFID card to enter the datac...
Question 385: Which of the following should an administrator implement to ...
Question 386: The access control list (ACL) for a file on a server is as f...
Question 387: Which of the following incident response plan steps would MO...
Question 388: The Chief Security Officer (CSO) is contacted by a first res...
Question 389: The key management organization has implemented a key escrow...
Question 390: Which of the following means a password history value of thr...
Question 391: A security administrator is auditing a database server to en...
Question 392: A small IT security form has an internal network composed of...
Question 393: Prior to leaving for an extended vacation, Joe uses his mobi...
Question 394: Which of the following allows a network administrator to imp...
Question 395: Which of the following types of authentication solutions use...
Question 396: A computer is suspected of being compromised by malware. The...
Question 397: Several departments in a corporation have a critical need fo...
Question 398: A technician has been tasked with installing and configuring...
Question 399: A security administrator wishes to prevent certain company d...
Question 400: A company has purchased an application that integrates into ...
Question 401: A security administrator notices large amounts of traffic wi...
Question 402: Which of the following implementation steps would be appropr...
Question 403: During a security assessment, an administrator wishes to see...
Question 404: Which of the following will help prevent smurf attacks?...
Question 405: Privilege creep among long-term employees can be mitigated b...
Question 406: Use of group accounts should be minimized to ensure the foll...
Question 407: A financial company requires a new private network link with...
Question 408: A company is rolling out a new e-commerce website. The secur...
Question 409: Which of the following can be used by a security administrat...
Question 410: A technician has deployed a new VPN concentrator. The device...
Question 411: During an audit, the security administrator discovers that t...
Question 412: Which of the following should be connected to the fire alarm...
Question 413: An application developer has tested some of the known exploi...
Question 414: A security technician is implementing PKI on a Network. The ...
Question 415: A system administrator has noticed that users change their p...
Question 416: Various employees have lost valuable customer data due to ha...
Question 417: Symmetric encryption utilizes __________, while asymmetric e...
Question 418: A security administrator must implement all requirements in ...
Question 419: An attacker attempted to compromise a web form by inserting ...
Question 420: Which of the following is the BEST way to prevent Cross-Site...
Question 421: A company that purchased an HVAC system for the datacenter i...
Question 422: Failure to validate the size of a variable before writing it...
Question 423: The Chief Information Officer (CIO) has asked a security ana...
Question 424: The system administrator has been notified that many users a...
Question 425: Which of the following can take advantage of man-in-the-midd...
Question 426: An administrator has concerns regarding the company's server...
Question 427: A company needs to provide a secure backup mechanism for key...
Question 428: Which of the following security account management technique...
Question 429: Without validating user input, an application becomes vulner...
Question 430: Jane, an IT security technician, needs to create a way to se...
Question 431: A software development company has hired a programmer to dev...
Question 432: A malicious person gained access to a datacenter by ripping ...
Question 433: Which of the following describes a type of malware which is ...
Question 434: A worker dressed in a fire suppression company's uniform ask...
Question 435: During a company-wide initiative to harden network security,...
Question 436: When an authorized application is installed on a server, the...
Question 437: A user attempts to install a new and relatively unknown soft...
Question 438: Pete, the compliance manager, wants to meet regulations. Pet...
Question 439: Which of the following will allow the live state of the virt...
Question 440: A company's password and authentication policies prohibit th...
Question 441: A user has received an email from an external source which a...
Question 442: Which of the following technologies uses multiple devices to...
Question 443: The help desk is experiencing a higher than normal amount of...
Question 444: Two programmers write a new secure application for the human...
Question 445: A recent audit of a company's identity management system sho...
Question 446: Using proximity card readers instead of the traditional key ...
Question 447: A program displays: ERROR: this program has caught an except...
Question 448: On a train, an individual is watching a proprietary video on...
Question 449: Which of the following is commonly LDAP and Kerberos used fo...
Question 450: Timestamps and sequence numbers act as countermeasures again...
Question 451: An administrator finds that non-production servers are being...
Question 452: In an environment where availability is critical such as Ind...
Question 453: Which of the following may cause Jane, the security administ...
Question 454: Which of the following is a notification that an unusual con...
Question 455: Which of the following encompasses application patch managem...
Question 456: A user Ann has her assigned token but she forgotten her pass...
Question 457: Users need to exchange a shared secret to begin communicatin...
Question 458: The chief security officer (CSO) has issued a new policy to ...
Question 459: Jane, a security analyst, is reviewing logs from hosts acros...
Question 460: In performing an authorized penetration test of an organizat...
Question 461: Ann a network administrator has been tasked with strengtheni...
Question 462: An administrator has advised against the use of Bluetooth ph...
Question 463: A company hires a penetration testing team to test its overa...
Question 464: Who should be contacted FIRST in the event of a security bre...
Question 465: A network analyst received a number of reports that imperson...
Question 466: A network administrator has recently updated their network d...
Question 467: Pete, an IT Administrator, needs to secure his server room. ...
Question 468: Joe, the chief technical officer (CTO) is concerned that the...
Question 469: Which of the following types of application attacks would be...
Question 470: A company has several public conference room areas with expo...
Question 471: A company wants to ensure that all aspects if data are prote...
Question 472: A database administrator would like to start encrypting data...
Question 473: A network administrator is responsible for securing applicat...
Question 474: An attacker impersonates a fire marshal and demands access t...
Question 475: A file on a Linux server has default permissions of rw-rw-r-...
Question 476: A security administrator is reviewing the company's data bac...
Question 477: In order to securely communicate using PGP, the sender of an...
Question 478: A system administrator is configuring a new file server and ...
Question 479: Which of the following is a hardware based encryption device...
Question 480: Which of the following is the BEST reason for placing a pass...
Question 481: Which of the following services are used to support authenti...
Question 482: Which of the following types of cloud computing would be MOS...
Question 483: A user was reissued a smart card after the previous smart ca...
Question 484: A security administrator would like to ensure that system ad...
Question 485: A company replaces a number of devices with a mobile applian...
Question 486: Ann, the Chief Technology Officer (CTO), has agreed to allow...
Question 487: Joe the system administrator has noticed an increase in netw...
Question 488: The company's sales team plans to work late to provide the C...
Question 489: Which of the following devices would be the MOST efficient w...
Question 490: Which of the following types of malware is designed to provi...
Question 491: Users have reported receiving unsolicited emails in their in...
Question 492: Which of the following does full disk encryption prevent?...
Question 493: Which of the following is an attack designed to activate bas...
Question 494: The process of making certain that an entity (operating syst...
Question 495: The programmer confirms that there is potential for a buffer...
Question 496: Ann, a security analyst, has discovered that her company has...
Question 497: An administrator, Ann, wants to ensure that only authorized ...
Question 498: An administrator must select an algorithm to encrypt data at...
Question 499: Which of the following best describes the reason for using h...
Question 500: When implementing fire suppression controls in a datacenter ...
Question 501: Ann is starting a disaster recovery program. She has gathere...
Question 502: Which of the following common access control models is commo...
Question 503: Which of the following would be a reason for developers to u...
Question 504: A company uses SSH to support internal users. They want to b...
Question 505: What is a system that is intended or designed to be broken i...
Question 506: A security administrator implements access controls based on...
Question 507: After several thefts a Chief Executive Officer (CEO) wants t...
Question 508: Joe, a company's network engineer, is concerned that protoco...
Question 509: A security assurance officer is preparing a plan to measure ...
Question 510: The security team would like to gather intelligence about th...
Question 511: An internal auditing team would like to strengthen the passw...
Question 512: Sara, a security administrator, is noticing a slowdown in th...
Question 513: Datacenter access is controlled with proximity badges that r...
Question 514: A security technician at a small business is worried about t...
Question 515: A company recently experienced data loss when a server crash...
Question 516: The security administrator is analyzing a user's history fil...
Question 517: Suspicious traffic without a specific signature was detected...
Question 518: A custom PKI application downloads a certificate revocation ...
Question 519: The IT department has set up a share point site to be used o...
Question 520: Ann has taken over as the new head of the IT department. One...
Question 521: Which of the following is the BEST method for ensuring all f...
Question 522: An attacker crafts a message that appears to be from a trust...
Question 523: By hijacking unencrypted cookies an application allows an at...
Question 524: A penetration tester is measuring a company's posture on soc...
Question 525: Matt, a security administrator, wants to ensure that the mes...
Question 526: A security administrator is aware that a portion of the comp...
Question 527: A system administrator has concerns regarding their users ac...
Question 528: A company has implemented full disk encryption. Clients must...
Question 529: Human Resources (HR) would like executives to undergo only t...
Question 530: In the case of a major outage or business interruption, the ...
Question 531: A victim is logged onto a popular home router forum site in ...
Question 532: An SSL/TLS private key is installed on a corporate web proxy...
Question 533: Which of the following is an authentication and accounting s...
Question 534: Which of the following would be used when a higher level of ...
Question 535: Company A and Company B both supply contractual services to ...
Question 536: A customer has provided an email address and password to a w...
Question 537: Which of the following concepts is BEST described as develop...
Question 538: Which of the following concepts is used by digital signature...
Question 539: An administrator notices an unusual spike in network traffic...
Question 540: A network engineer is configuring a VPN tunnel connecting a ...
Question 541: Which of the following solutions provides the most flexibili...
Question 542: Company XYZ has encountered an increased amount of buffer ov...
Question 543: An administrator would like to utilize encryption that has c...
Question 544: A security administrator must implement a system that will s...
Question 545: Jane, a security administrator, needs to implement a secure ...
Question 546: Joe, an application developer, is building an external facin...
Question 547: A malicious individual is attempting to write too much data ...
Question 548: Which of the following is an example of a false positive?...
Question 549: A company needs to provide web-based access to shared data s...
Question 550: Which of the following transportation encryption protocols s...
Question 551: Which of the following functions provides an output which ca...
Question 552: A Company transfers millions of files a day between their se...
Question 553: Employee badges are encoded with a private encryption key an...
Question 554: Which of the following pseudocodes can be used to handle pro...
Question 555: An encrypted message is sent using PKI from Sara, a client, ...
Question 556: All of the following are valid cryptographic hash functions ...
Question 557: Which of the following is an application security coding pro...
Question 558: A company hires outside security experts to evaluate the sec...
Question 559: A user attempting to log on to a workstation for the first t...
Question 560: While opening an email attachment, Pete, a customer, receive...
Question 561: A security administrator is tasked with calculating the tota...
Question 562: Which of the following fire suppression systems is MOST like...
Question 563: A user has several random browser windows opening on their c...
Question 564: Jane, a security administrator, has been tasked with explain...
Question 565: Which of the following can be used on a smartphone to BEST p...
Question 566: Ann, the security administrator, received a report from the ...
Question 567: A security engineer would like to analyze the effect of depl...
Question 568: An outside security consultant produces a report of several ...
Question 569: Company A submitted a bid on a contract to do work for Compa...
Question 570: Which of the following practices is used to mitigate a known...
Question 571: Joe, the security administrator, has determined that one of ...
Question 572: Which of the following malware types is MOST likely to execu...
Question 573: Joe, a user, wants to send an encrypted email to Ann. Which ...
Question 574: A company plans to expand by hiring new engineers who work i...
Question 575: Which of the following security concepts identifies input va...
Question 576: Based on information leaked to industry websites, business m...
Question 577: Joe, a network administrator, is able to manage the backup s...
Question 578: One of the most basic ways to protect the confidentiality of...
Question 579: Joe, the system administrator, has been asked to calculate t...
Question 580: Which of the following should a company implement to BEST mi...
Question 581: During a review a company was cited for allowing requestors ...
Question 582: An employee recently lost a USB drive containing confidentia...
Question 583: Which of the following would an attacker use to generate and...
Question 584: Which of the following is it MOST difficult to harden agains...
Question 585: A network administrator noticed various chain messages have ...
Question 586: The concept of rendering data passing between two points ove...
Question 587: Which of the following is the BEST concept to maintain requi...
Question 588: A security technician wants to improve the strength of a wea...
Question 589: A user has plugged in a wireless router from home with defau...
Question 590: The IT department has been tasked with reducing the risk of ...
Question 591: A company is about to release a very large patch to its cust...
Question 592: A server administrator notes that a legacy application often...
Question 593: DRAG DROP Drag the items on the left to show the different t...
Question 594: Why would a technician use a password cracker?...
Question 595: Which of the following cryptographic methods is most secure ...
Question 596: In order to maintain oversight of a third party service prov...
Question 597: A company requires that all wireless communication be compli...
Question 598: A risk assessment team is concerned about hosting data with ...
Question 599: One of the servers on the network stops responding due to la...
Question 600: To ensure proper evidence collection, which of the following...
Question 601: DRAG DROP You have been tasked with designing a security pla...
Question 602: Joe needs to track employees who log into a confidential dat...
Question 603: An employee finds a USB drive in the employee lunch room and...
Question 604: While working on a new project a security administrator want...
Question 605: Which of the following, if implemented, would improve securi...
Question 606: Which of the following assets is MOST likely considered for ...
Question 607: Which of the following exploits either a host file on a targ...
Question 608: Which of the following would be used to identify the securit...
Question 609: Users are encouraged to click on a link in an email to obtai...
Question 610: Which of the following is an important step in the initial s...
Question 611: The ore-sales engineering team needs to quickly provide accu...
Question 612: A system security analyst wants to capture data flowing in a...
Question 613: Which of the following preventative controls would be approp...
Question 614: A security analyst informs the Chief Executive Officer (CEO)...
Question 615: An administrator is configuring a network for all users in a...
Question 616: A security administrator has been tasked to ensure access to...
Question 617: Which of the following is a best practice when a mistake is ...
Question 618: Pete, a developer, writes an application. Jane, the security...
Question 619: The system administrator has deployed updated security contr...
Question 620: A security administrator wants to implement a solution which...
Question 621: In order for Sara, a client, to logon to her desktop compute...
Question 622: A security administrator is reviewing logs and notices multi...
Question 623: The network manager has obtained a public IP address for use...
Question 624: Employees are reporting that they have been receiving a larg...
Question 625: Jane has implemented an array of four servers to accomplish ...
Question 626: A security technician would like to use ciphers that generat...
Question 627: A security administrator is designing an access control syst...
Question 628: Sara, a security analyst, is trying to prove to management w...
Question 629: Sara, a security architect, has developed a framework in whi...
Question 630: An administrator has a network subnet dedicated to a group o...
Question 631: A company's application is hosted at a data center. The data...
Question 632: The chief Risk officer is concerned about the new employee B...
Question 633: Pete, a security analyst, has been tasked with explaining th...
Question 634: Computer evidence at a crime scene is documented with a tag ...
Question 635: The system administrator wishes to implement a hardware-base...
Question 636: After a production outage, which of the following documents ...
Question 637: Allowing unauthorized removable devices to connect to comput...
Question 638: An organization currently uses FTP for the transfer of large...
Question 639: HOTSPOT For each of the given items, select the appropriate ...
Question 640: An employee from the fire Marshall's office arrives to inspe...
Question 641: Ann, a security administrator at a call center, has been exp...
Question 642: A security administrator wishes to protect session leys shou...
Question 643: The system administrator notices that many employees are usi...
Question 644: Which of the following are examples of detective controls?...
Question 645: Joe, a security administrator, is concerned with users tailg...
Question 646: A company has a corporate infrastructure where end users man...
Question 647: A database administrator receives a call on an outside telep...
Question 648: Two organizations want to share sensitive data with one anot...
Question 649: After receiving the hard drive from detectives, the forensic...
Question 650: The IT department has setup a website with a series of quest...
Question 651: A user reports being unable to access a file on a network sh...
Question 652: A new application needs to be deployed on a virtual server. ...
Question 653: A company used a partner company to develop critical compone...
Question 654: A security analyst has a sample of malicious software and ne...
Question 655: A bank Chief Information Security Officer (CISO) is responsi...
Question 656: Which of the following is a penetration testing method?...
Question 657: HOTSPOT For each of the given items, select the appropriate ...
Question 658: After analyzing and correlating activity from multiple senso...
Question 659: Which of the following should be considered to mitigate data...
Question 660: A security administrator needs to implement a technology tha...
Question 661: A new security analyst is given the task of determining whet...
Question 662: A security administrator wants to deploy security controls t...
Question 663: Ann, a security analyst, is preparing for an upcoming securi...
Question 664: Which of the following is built into the hardware of most la...
Question 665: A security technician received notification of a remotely ex...
Question 666: Matt, a developer, recently attended a workshop on a new app...
Question 667: One of the senior managers at a company called the help desk...
Question 668: A company hosts its public websites internally. The administ...
Question 669: After Matt, a user, enters his username and password at the ...
Question 670: A computer is found to be infected with malware and a techni...
Question 671: Which of the following security concepts would Sara, the sec...
Question 672: A company wants to improve its overall security posture by d...
Question 673: An organization processes credit card transactions and is co...
Question 674: During which of the following phases of the Incident Respons...
Question 675: A malicious individual used an unattended customer service k...
Question 676: Mike, a user, states that he is receiving several unwanted e...
Question 677: A company is trying to limit the risk associated with the us...
Question 678: In order to enter a high-security data center, users are req...
Question 679: Ann, a member of the Sales Department, has been issued a com...
Question 680: A supervisor in the human resources department has been give...
Question 681: Which of the following is an important implementation consid...
Question 682: A security analyst has been notified that trade secrets are ...
Question 683: One of the findings of risk assessment is that many of the s...
Question 684: In order to gain an understanding of the latest attack tools...
Question 685: A company has recently begun to provide internal security aw...
Question 686: An organizations' security policy requires that users change...
Question 687: A one-time security audit revealed that employees do not hav...
Question 688: Sara, an employee, tethers her smartphone to her work PC to ...
Question 689: A network administrator has purchased two devices that will ...
Question 690: Which of the following is a security advantage of using NoSQ...
Question 691: Which of the following statements is MOST likely to be inclu...
Question 692: Which of the following are unique to white box testing metho...
Question 693: Which of the following would a security administrator implem...
Question 694: Jane has recently implemented a new network design at her or...
Question 695: The datacenter manager is reviewing a problem with a humidit...
Question 696: Which of the following is the practice of marking open wirel...
Question 697: A user, Ann, is reporting to the company IT support group th...
Question 698: Joe, a security technician, is configuring two new firewalls...
Question 699: Sara, a user, downloads a keygen to install pirated software...
Question 700: A technician installed two ground plane antennae on 802.11n ...
Question 701: Which of the following techniques can be used to prevent the...
Question 702: Which of the following types of wireless attacks would be us...
Question 703: Which of the following is characterized by an attacker attem...
Question 704: Key cards at a bank are not tied to individuals, but rather ...
Question 705: Which of the following documents outlines the technical and ...
Question 706: Which of the following would a security administrator implem...
Question 707: A security administrator has implemented a policy to prevent...
Question 708: A company's BYOD policy requires the installation of a compa...
Question 709: A security administrator has concerns about new types of med...
Question 710: Joe uses his badge to enter the server room, Ann follows Joe...
Question 711: A company has had several security incidents in the past six...
Question 712: Which of the following is being tested when a company's payr...
Question 713: Joe has hired several new security administrators and have b...
Question 714: An employee in the accounting department recently received a...
Question 715: A new web server has been provisioned at a third party hosti...
Question 716: Which of the following password attacks is MOST likely to cr...
Question 717: Which of the following authentication methods requires the u...
Question 718: When confidentiality is the primary concern, which of the fo...
Question 719: Which of the following steps in incident response procedures...
Question 720: Sara, a hacker, is completing a website form to request a fr...
Question 721: When a new network drop was installed, the cable was run acr...
Question 722: Which of the following is the term for a fix for a known sof...
Question 723: Joe, a network security engineer, has visibility to network ...
Question 724: Which of the following types of authentication packages user...
Question 725: A company would like to implement two-factor authentication ...
Question 726: After a number of highly publicized and embarrassing custome...
Question 727: Which of the following helps to apply the proper security co...
Question 728: All executive officers have changed their monitor location s...
Question 729: A security administrator wants to check user password comple...
Question 730: Which of the following file systems is from Microsoft and wa...
Question 731: A company uses port security based on an approved MAC list t...
Question 732: Which of the following has serious security implications for...
Question 733: Which of the following security concepts can prevent a user ...
Question 734: A load balancer has the ability to remember which server a p...
Question 735: Which of the following is an indication of an ongoing curren...
Question 736: Ann, a software developer, has installed some code to reacti...
Question 737: Fuzzing is a security assessment technique that allows teste...
Question 738: A server administrator discovers the web farm is using weak ...
Question 739: A technician has implemented a system in which all workstati...
Question 740: The Chief Information Officer (CIO) is concerned with moving...
Question 741: Matt, an IT administrator, wants to protect a newly built se...
Question 742: Searching for systems infected with malware is considered to...
Question 743: Ann a new small business owner decides to implement WiFi acc...
Question 744: Ann, the network administrator, has learned from the helpdes...
Question 745: Which of the following protocols is MOST likely to be levera...
Question 746: Joe, a user, in a coffee shop is checking his email over a w...
Question 747: Results from a vulnerability analysis indicate that all enab...
Question 748: An internal audit has detected that a number of archived tap...
Question 749: A company wants to ensure that its hot site is prepared and ...
Question 750: When a communications plan is developed for disaster recover...
Question 751: Which of the following devices is used for the transparent s...
Question 752: Matt, an administrator, is concerned about the wireless netw...
Question 753: An attacker Joe configures his service identifier to be as a...
Question 754: A security administrator has concerns regarding employees sa...
Question 755: A bank has recently deployed mobile tablets to all loan offi...
Question 756: A technician is configuring a switch to support VOPIP phones...
Question 757: During a routine configuration audit, a systems administrato...
Question 758: Given a class C network a technician has been tasked with cr...
Question 759: Which of the following is BEST utilized to identify common m...
Question 760: A security administrator must implement a network that is im...
Question 761: Purchasing receives a phone call from a vendor asking for a ...
Question 762: A user tries to visit a website with a revoked certificate. ...
Question 763: A way to assure data at-rest is secure even in the event of ...
Question 764: Which of the following controls should critical application ...
Question 765: A corporate wireless guest network uses an open SSID with a ...
Question 766: Sara, a security administrator, manually hashes all network ...
Question 767: Which of the following BEST explains Platform as a Service?...
Question 768: Disabling unnecessary services, restricting administrative a...
Question 769: To mitigate the risk of intrusion, an IT Manager is concerne...
Question 770: Sara, a security manager, has decided to force expiration of...
Question 771: Visitors entering a building are required to close the back ...
Question 772: An organization has an internal PKI that utilizes client cer...
Question 773: An administrator wants to ensure that the reclaimed space of...
Question 774: Which of the following policies is implemented in order to m...
Question 775: Requiring technicians to report spyware infections is a step...
Question 776: RC4 is a strong encryption protocol that is general used wit...
Question 777: A trojan was recently discovered on a server. There are now ...
Question 778: Which of the following is an attack designed to activate bas...
Question 779: A rogue programmer included a piece of code in an applicatio...
Question 780: The security officer is preparing a read-only USB stick with...
Question 781: A business has set up a Customer Service kiosk within a shop...
Question 782: An IT security technician needs to establish host based secu...
Question 783: A switch is set up to allow only 2 simultaneous MAC addresse...
Question 784: After an audit, it was discovered that the security group me...
Question 785: Matt, a security consultant, has been tasked with increasing...
Question 786: Which of the following utilities can be used in Linux to vie...
Question 787: A security administrator has deployed all laptops with Self ...
Question 788: After a recent security breach, the network administrator ha...
Question 789: A company uses PGP to ensure that sensitive email is protect...
Question 790: Using a protocol analyzer, a security consultant was able to...
Question 791: A company would like to take electronic orders from a partne...
Question 792: Establishing a method to erase or clear cluster tips is an e...
Question 793: When considering a vendor-specific vulnerability in critical...
Question 794: Although a vulnerability scan report shows no vulnerabilitie...
Question 795: Which of the following BEST describes the type of attack tha...
Question 796: An administrator is implementing a security control that onl...
Question 797: A security administrator is tackling issues related to authe...
Question 798: Which of the following tools would a security administrator ...
Question 799: Which of the following would be MOST appropriate if an organ...
Question 800: The Chief Executive Officer (CEO) Joe notices an increase in...
Question 801: Which of the following is the below pseudo-code an example o...
Question 802: Which of the following BEST explains the use of an HSM withi...
Question 803: A system administrator is using a packet sniffer to troubles...
Question 804: An administrator uses a server with a trusted OS and is conf...
Question 805: A security administrator needs to image a large hard drive f...
Question 806: A security manager installed a standalone fingerprint reader...
Question 807: An IT security technician is actively involved in identifyin...
Question 808: Used in conjunction, which of the following are PII? (Choose...
Question 809: Which of the following is a Data Loss Prevention (DLP) strat...
Question 810: A vulnerability assessment indicates that a router can be ac...
Question 811: A certificate used on an e-commerce web server is about to e...
Question 812: Which of the following authentication services should be rep...
Question 813: Which of the following controls can be used to prevent the d...
Question 814: A new network administrator is setting up a new file server ...
Question 815: Which of the following BEST allows Pete, a security administ...
Question 816: A company is starting to allow employees to use their own pe...
Question 817: Which of the following types of security controls are visibl...
Question 818: Customers' credit card information was stolen from a popular...
Question 819: End-user awareness training for handling sensitive personall...
Question 820: Which of the following provides the BEST application availab...
Question 821: A project team is developing requirements of the new version...
Question 822: A company wants to prevent unauthorized access to its secure...
Question 823: Which of the following is a best practice when setting up a ...
Question 824: Which of the following is described as an attack against an ...
Question 825: A group of users from multiple departments are working toget...
Question 826: During an anonymous penetration test, Jane, a system adminis...
Question 827: A technician reports a suspicious individual is seen walking...
Question 828: A security manager is discussing change in the security post...
Question 829: Which of the following is a security benefit of providing ad...
Question 830: Use of a smart card to authenticate remote servers remains M...
Question 831: A security specialist has been asked to evaluate a corporate...
Question 832: Which of the following controls would prevent an employee fr...
Question 833: Which of the following describes the implementation of PAT?...
Question 834: In regard to secure coding practices, why is input validatio...
Question 835: A network manager needs a cost-effective solution to allow f...
Question 836: Which of the following tasks should key elements of a busine...
Question 837: A security administrator wants to deploy a physical security...
Question 838: Which of the following passwords is the LEAST complex?...
Question 839: In the course of troubleshooting wireless issues from users,...
Question 840: Which of the following application attacks is used to gain a...
Question 841: A new virtual server was created for the marketing departmen...
Question 842: A set of standardized system images with a pre-defined set o...
Question 843: Joe, a user, wants to send an encrypted email to Ann. Which ...
Question 844: Joe is the accounts payable agent for ABC Company. Joe has b...
Question 845: Which of the following would MOST likely involve GPS?...
Question 846: Purchasing receives an automated phone call from a bank aski...
Question 847: The security manager wants to unify the storage of credentia...
Question 848: Which of the following concepts defines the requirement for ...
Question 849: Users in the HR department were recently informed that they ...
Question 850: A merchant acquirer has the need to store credit card number...
Question 851: Matt, the Chief Information Security Officer (CISO), tells t...
Question 852: ABC company has a lot of contractors working for them. The p...
Question 853: Ann, a security administrator, wishes to replace their RADIU...
Question 854: A password audit has revealed that a significant percentage ...
Question 855: Pete, the system administrator, has blocked users from acces...
Question 856: A network technician is configuring clients for VLAN access....
Question 857: Which of the following types of attacks involves interceptio...
Question 858: Data execution prevention is a feature in most operating sys...
Question 859: An administrator receives a security alert that appears to b...
Question 860: Which of the following is BEST used to capture and analyze n...
Question 861: The main corporate website has a service level agreement tha...
Question 862: Joe, an administrator, installs a web server on the Internet...
Question 863: Joe, an employee is taking a taxi through a busy city and st...
Question 864: In order to secure additional budget, a security manager wan...
Question 865: A recent audit has revealed that several users have retained...
Question 866: A web administrator has just implemented a new web server to...
Question 867: The information security technician wants to ensure security...
Question 868: Which of the following provides data the best fault toleranc...
Question 869: A network administrator recently updated various network dev...
Question 870: A small company has recently purchased cell phones for manag...
Question 871: A program has been discovered that infects a critical Window...
Question 872: Which of the following can be used to ensure digital certifi...
Question 873: Which of the following is the BEST approach to perform risk ...
Question 874: An application developer has coded a new application with a ...
Question 875: Due to issues with building keys being duplicated and distri...
Question 876: Which of the following assessment techniques would a securit...
Question 877: The security administrator is observing unusual network beha...
Question 878: Encryption used by RADIUS is BEST described as:...
Question 879: Which of the following can be used for both encryption and d...
Question 880: A security administrator forgets their card to access the se...
Question 881: Several users' computers are no longer responding normally a...
Question 882: A system administrator needs to ensure that certain departme...
Question 883: A workstation is exhibiting symptoms of malware and the netw...
Question 884: After a company has standardized to a single operating syste...
Question 885: After a recent internal audit, the security administrator wa...
Question 886: The network security manager has been notified by customer s...
Question 887: A network administrator identifies sensitive files being tra...
Question 888: A company recently received accreditation for a secure netwo...
Question 889: DRAG DROP A forensic analyst is asked to respond to an ongoi...
Question 890: A recent online password audit has identified that stale acc...
Question 891: A company recently experienced several security breaches tha...
Question 892: A compromised workstation utilized in a Distributed Denial o...
Question 893: In the initial stages of an incident response, Matt, the sec...
Question 894: A user authenticates to a local directory server. The user t...
Question 895: Ann, the system administrator, is installing an extremely cr...
Question 896: Joe, a sales employee, is connecting to a wireless network a...
Question 897: Company policy requires employees to change their passwords ...
Question 898: Jane, a security administrator, has observed repeated attemp...
Question 899: Which of the following could cause a browser to display the ...
Question 900: A computer security officer has investigated a possible data...
Question 901: A cyber security administrator receives a list of IPs that h...
Question 902: Ann, the security administrator, wishes to implement multifa...
Question 903: Which of the following access controls enforces permissions ...
Question 904: During the information gathering stage of a deploying role-b...
Question 905: The librarian wants to secure the public Internet kiosk PCs ...
Question 906: Jane, an individual, has recently been calling various finan...
Question 907: Several departments within a company have a business need to...
Question 908: How often, at a MINIMUM, should Sara, an administrator, revi...
Question 909: A major medical corporation is investigating deploying a web...
Question 910: Pete, the system administrator, is reviewing his disaster re...
Question 911: An Information Systems Security Officer (ISSO) has been plac...
Question 912: Which of the following can be utilized in order to provide t...
Question 913: A security administrator examines a network session to a com...
Question 914: Which of the following can be used to maintain a higher leve...
Question 915: A company's Chief Information Officer realizes the company c...
Question 916: Which of the following types of application attacks would be...
Question 917: Several employees submit the same phishing email to the admi...
Question 918: Which of the following would allow users from outside of an ...
Question 919: The datacenter design team is implementing a system, which r...
Question 920: Users in an organization are experiencing when attempting to...
Question 921: A company has had their web application become unavailable s...
Question 922: Which of the following can only be mitigated through the use...
Question 923: A risk management team indicated an elevated level of risk d...
Question 924: Which of the following is the best practice for error and ex...
Question 925: A security analyst has a sample of malicious software and ne...
Question 926: Corporate IM presents multiple concerns to enterprise IT. Wh...
Question 927: Attempting to inject 50 alphanumeric key strokes including s...
Question 928: Which statement is TRUE about the operation of a packet snif...
Question 929: An email client says a digital signature is invalid and the ...
Question 930: Which of the following would a security administrator implem...
Question 931: A security technician has removed the sample configuration f...
Question 932: A security analyst performs the following activities: monito...
Question 933: The internal audit group discovered that unauthorized users ...
Question 934: Joe, an end user, has received a virus detection warning. Wh...
Question 935: Which of the following tests a number of security controls i...
Question 936: Account lockout is a mitigation strategy used by Jane, the a...
Question 937: An organization is implementing a password management applic...
Question 938: Which of the following MOST specifically defines the procedu...
Question 939: Access mechanisms to data on encrypted USB hard drives must ...
Question 940: Verifying the integrity of data submitted to a computer prog...
Question 941: A company is deploying a new video conferencing system to be...
Question 942: Which of the following is an effective way to ensure the BES...
Question 943: Which of the following BEST represents the goal of a vulnera...
Question 944: Which of the following forms of software testing can best be...
Question 945: During a routine audit it is discovered that someone has bee...
Question 946: A company executive's laptop was compromised, leading to a s...
Question 947: The new Chief Information Officer (CIO) of company ABC, Joe ...
Question 948: After visiting a website, a user receives an email thanking ...
Question 949: Which of the following network devices is used to analyze tr...
Question 950: In order for network monitoring to work properly, you need a...
Question 951: Which of the following is a vulnerability associated with di...
Question 952: A user has an Android smartphone that supports full device e...
Question 953: Various network outages have occurred recently due to unappr...
Question 954: Which of the following attacks targets high level executives...
Question 955: A hospital IT department wanted to secure its doctor's table...
Question 956: Which of the following protocols uses TCP instead of UDP and...
Question 957: After Ann, a user, logs into her banking websites she has ac...
Question 958: An administrator is concerned that a company's web server ha...
Question 959: The Chief Information Security Officer (CISO) is concerned t...
Question 960: The security administrator generates a key pair and sends on...
Question 961: Which of the following types of malware, attempts to circumv...
Question 962: Encryption of data at rest is important for sensitive inform...
Question 963: A security manager must remain aware of the security posture...
Question 964: Joe, a network administrator, is setting up a virtualization...
Question 965: Which of the following BEST describes the type of attack tha...
Question 966: Joe, a technician, is tasked with finding a way to test oper...
Question 967: A security manager requires fencing around the perimeter, an...
Question 968: Which of the following would Jane, an administrator, use to ...
Question 969: A company with a US-based sales force has requested that the...
Question 970: Which of the following is considered an environmental contro...
Question 971: Which of the following authentication services uses a ticket...
Question 972: A server crashes at 6 pm. Senior management has determined t...
Question 973: Which of the following should Matt, a security administrator...
Question 974: Which of the following would a security administrator use to...
Question 975: A process in which the functionality of an application is te...
Question 976: An attacker is attempting to insert malicious code into an i...
Question 977: A security administrator is notified that users attached to ...
Question 978: A security administrator develops a web page and limits inpu...
Question 979: After viewing wireless traffic, an attacker notices the foll...
Question 980: Which of the following is the MOST important step for preser...
Question 981: Which of the following MOST interferes with network-based de...
Question 982: Which of the following can be used to mitigate risk if a mob...
Question 983: An insurance company requires an account recovery process so...
Question 984: Which of the following types of security services are used t...
Question 985: Which of the following assessments would Pete, the security ...
Question 986: A chief information officer (CIO) is concerned about PII con...
Question 987: During a disaster recovery planning session, a security admi...
Question 988: Which of the following security benefits would be gained by ...
Question 989: Which of the following concepts is a term that directly rela...
Question 990: An attacker unplugs the access point at a coffee shop. The a...
Question 991: Which of the following authentication services requires the ...
Question 992: A technician has been assigned a service request to investig...
Question 993: Which of the following can be implemented if a security admi...
Question 994: A technician wants to implement a dual factor authentication...
Question 995: A security administrator is responsible for performing perio...
Question 996: It has been discovered that students are using kiosk tablets...
Question 997: A company wishes to prevent unauthorized employee access to ...
Question 998: An employee's mobile device associates with the company's gu...
Question 999: Which of the following is the MOST specific plan for various...
Question 1000: Which of the following is BEST described by a scenario where...
Question 1001: Which of the following results in datacenters with failed hu...
Question 1002: A Human Resources user is issued a virtual desktop typically...
Question 1003: An administrator is assigned to monitor servers in a data ce...
Question 1004: An administrator is investigating a system that may potentia...
Question 1005: A customer service department has a business need to send hi...
Question 1006: An incident response team member needs to perform a forensic...
Question 1007: After working on his doctoral dissertation for two years, Jo...
Question 1008: The information security team does a presentation on social ...
Question 1009: A security technician is working with the network firewall t...
Question 1010: A user has called the help desk to report an enterprise mobi...
Question 1011: A thief has stolen mobile device and removed its battery to ...
Question 1012: Which of the following malware types may require user intera...
Question 1013: A company requires that a user's credentials include providi...
Question 1014: Computer evidence at a crime is preserved by making an exact...
Question 1015: Which of the following has a storage root key?...
Question 1016: Maintenance workers find an active network switch hidden abo...
Question 1017: Several bins are located throughout a building for secure di...
Question 1018: Full disk encryption is MOST effective against the following...
Question 1019: A company has experienced problems with their ISP, which has...
Question 1020: A system administrator is conducting baseline audit and dete...
Question 1021: Which of the following disaster recovery strategies has the ...
Question 1022: The call center supervisor has reported that many employees ...
Question 1023: The incident response team has received the following email ...
Question 1024: A review of administrative access has discovered that too ma...
Question 1025: A company is looking to improve their security posture by ad...
Question 1026: Which of the following will provide data encryption, key man...
Question 1027: An administrator is building a development environment and r...
Question 1028: The method to provide end users of IT systems and applicatio...
Question 1029: An organization must implement controls to protect the confi...
Question 1030: Company XYZ recently salvaged company laptops and removed al...
Question 1031: A technician is reviewing the logical access control method ...
Question 1032: Which of the following technical controls helps to prevent S...
Question 1033: Joe has read and write access to his own home directory. Joe...
Question 1034: An employee reports work was being completed on a company ow...
Question 1035: A large multinational corporation with networks in 30 countr...
Question 1036: The BEST methods for a web developer to prevent the website ...
Question 1037: A user, Ann, has been issued a smart card and is having prob...
Question 1038: Which of the following attacks could be used to initiate a s...
Question 1039: The Quality Assurance team is testing a third party applicat...
Question 1040: A security administrator wants to perform routine tests on t...
Question 1041: A Chief Information Security Officer (CISO) wants to impleme...
Question 1042: A company has just deployed a centralized event log storage ...
Question 1043: The system administrator is reviewing the following logs fro...
Question 1044: A video surveillance audit recently uncovered that an employ...
Question 1045: Which of the following describes the process of removing unn...
Question 1046: Which of the following is true about asymmetric encryption?...
Question 1047: Four weeks ago, a network administrator applied a new IDS an...
Question 1048: A security technician is attempting to improve the overall s...
Question 1049: Ann, a security administrator at a call center, has been exp...
Question 1050: Which device monitors network traffic in a passive manner?...
Question 1051: An administrator is instructed to disable IP-directed broadc...
Question 1052: After recovering from a data breach in which customer data w...
Question 1053: Which of the following provides the LEAST availability?...
Question 1054: A quality assurance analyst is reviewing a new software prod...
Question 1055: Which of the following application security principles invol...
Question 1056: For high availability which of the following would be MOST a...
Question 1057: Which of the following BEST describes disk striping with par...
Question 1058: A network administrator, Joe, arrives at his new job to find...
Question 1059: HOTSPOT Select the appropriate attack from each drop down li...
Question 1060: Joe, a system administrator, receives reports that users att...
Question 1061: Joe, a technician, initiated scans if the company's 10 route...
Question 1062: Which of the following BEST describes a SQL Injection attack...
Question 1063: A new intern was assigned to the system engineering departme...
Question 1064: Which of the following describes how Sara, an attacker, can ...
Question 1065: A cafe provides laptops for Internet access to their custome...
Question 1066: A security technician wants to implement stringent security ...