Valid SY0-401 Dumps shared by EduDump.com for Helping Passing SY0-401 Exam! EduDump.com now offer the newest SY0-401 exam dumps, the EduDump.com SY0-401 exam questions have been updated and answers have been corrected get the newest EduDump.com SY0-401 dumps with Test Engine here:

Access SY0-401 Dumps Premium Version
(1790 Q&As Dumps, 35%OFF Special Discount Code: freecram)

<< Prev Question Next Question >>

Question 656/1066

Which of the following is a penetration testing method?

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (1066q)
Question 1: A company is trying to implement physical deterrent controls...
Question 2: When employing PKI to send signed and encrypted data the ind...
Question 3: Which of the following, if properly implemented, would preve...
Question 4: A user has unknowingly gone to a fraudulent site. The securi...
Question 5: A software security concern when dealing with hardware and d...
Question 6: Which of the following is the LEAST volatile when performing...
Question 7: Pete, the security administrator, has been notified by the I...
Question 8: How must user accounts for exiting employees be handled?...
Question 9: Which of the following is a black box testing methodology?...
Question 10: A small business needs to incorporate fault tolerance into t...
Question 11: Which of the following can Joe, a security administrator, im...
Question 12: Speaking a passphrase into a voice print analyzer is an exam...
Question 13: Given the following set of firewall rules: From the inside t...
Question 14: Several users report to the administrator that they are havi...
Question 15: Ann, the security administrator, has been reviewing logs and...
Question 16: A recent audit has revealed weaknesses in the process of dep...
Question 17: A company has a BYOD policy that includes tablets and smart ...
Question 18: Which of the following can a security administrator implemen...
Question 19: Ann, the software security engineer, works for a major softw...
Question 20: Which of the following hardware based encryption devices is ...
Question 21: If an organization wants to implement a BYOD policy, which o...
Question 22: Which of the following controls mitigates the risk of Matt, ...
Question 23: To protect corporate data on removable media, a security pol...
Question 24: It is important to staff who use email messaging to provide ...
Question 25: The system administrator is tasked with changing the adminis...
Question 26: Ann, a newly hired human resource employee, sent out confide...
Question 27: Which of the following is true about input validation in a c...
Question 28: A security administrator has installed a new KDC for the cor...
Question 29: Which of the following application attacks is used against a...
Question 30: A company has two server administrators that work overnight ...
Question 31: Which of the following security strategies allows a company ...
Question 32: An administrator notices that former temporary employees' ac...
Question 33: A security analyst must ensure that the company's web server...
Question 34: During a recent audit, the auditors cited the company's curr...
Question 35: A network administrator has a separate user account with rig...
Question 36: Which of the following techniques describes the use of appli...
Question 37: DRAG DROP A security administrator is given the security and...
Question 38: Which of the following can be used as an equipment theft det...
Question 39: Which of the following would be used to allow a subset of tr...
Question 40: During a server audit, a security administrator does not not...
Question 41: Joe wants to employ MD5 hashing on the company file server. ...
Question 42: During a routine audit a web server is flagged for allowing ...
Question 43: Which of the following protocols provides for mutual authent...
Question 44: Which of the following could a security administrator implem...
Question 45: A Chief Privacy Officer, Joe, is concerned that employees ar...
Question 46: An IT auditor tests an application as an authenticated user....
Question 47: Which of the following protocols is vulnerable to man-in-the...
Question 48: A military base wants to incorporate biometrics into its new...
Question 49: Sara, the Chief Information Officer (CIO), has requested an ...
Question 50: Which of the following techniques enables a highly secured o...
Question 51: An incident occurred when an outside attacker was able to ga...
Question 52: Which of the following authentication services uses a defaul...
Question 53: A security administrator is concerned about the strength of ...
Question 54: A network security engineer notices unusual traffic on the n...
Question 55: The Chief Technology Officer (CTO) wants to improve security...
Question 56: Sara, a company's security officer, often receives reports o...
Question 57: Which of the following is the best practice to put at the en...
Question 58: After running into the data center with a vehicle, attackers...
Question 59: Which of the following can BEST help prevent cross-site scri...
Question 60: A security technician would like an application to use rando...
Question 61: The security administrator receives a service ticket saying ...
Question 62: A network security administrator is trying to determine how ...
Question 63: Which of the following can Pete, a security administrator, u...
Question 64: An organization is required to log all user internet activit...
Question 65: An administrator implements SELinux on a production web serv...
Question 66: Which of the following would BEST be used to calculate the e...
Question 67: Some customers have reported receiving an untrusted certific...
Question 68: A security administrator is using a software program to test...
Question 69: A webpage displays a potentially offensive advertisement on ...
Question 70: Which of the following would a security administrator implem...
Question 71: A company hosts a web server that requires entropy in encryp...
Question 72: An SSL session is taking place. After the handshake phase ha...
Question 73: Which of the following documents outlines the responsibility...
Question 74: After a new RADIUS server is added to the network, an employ...
Question 75: Vendors typically ship software applications with security s...
Question 76: A company has 5 users. Users 1, 2 and 3 need access to payro...
Question 77: Which of the following is a security risk regarding the use ...
Question 78: A security administrator finds that an intermediate CA withi...
Question 79: Which of the following is the process in which a law enforce...
Question 80: An advantage of virtualizing servers, databases, and office ...
Question 81: A technician is investigating intermittent switch degradatio...
Question 82: Methods to test the responses of software and web applicatio...
Question 83: A systems engineer has been presented with storage performan...
Question 84: After a security incident involving a physical asset, which ...
Question 85: A security team has established a security awareness program...
Question 86: Which of the following application security testing techniqu...
Question 87: A network administrator argues that WPA2 encryption is not n...
Question 88: Which of the following BEST describes using a smart card and...
Question 89: Ann, the IT director, wants to ensure that as hoc changes ar...
Question 90: Which of the following would provide the MOST objective resu...
Question 91: Ann a new security specialist is attempting to access the in...
Question 92: An attacker went to a local bank and collected disposed pape...
Question 93: Ann works at a small company and she is concerned that there...
Question 94: A recent audit has discovered that at the time of password e...
Question 95: The sales force in an organization frequently travel to remo...
Question 96: While preparing for an audit a security analyst is reviewing...
Question 97: Which of the following is characterized by an attack against...
Question 98: Which of the following devices will help prevent a laptop fr...
Question 99: A security administrator discovered that all communication o...
Question 100: Which of the following wireless security measures can an att...
Question 101: Which of the following will allow Pete, a security analyst, ...
Question 102: A team of firewall administrators have access to a `master p...
Question 103: An administrator is implementing a new management system for...
Question 104: A security engineer is given new application extensions each...
Question 105: Which of the following controls can be implemented together ...
Question 106: Ann, a technician, received a spear-phishing email asking he...
Question 107: Digital signatures are used for ensuring which of the follow...
Question 108: A network inventory discovery application requires non-privi...
Question 109: A group policy requires users in an organization to use stro...
Question 110: Users require access to a certain server depending on their ...
Question 111: A security administrator is reviewing the below output from ...
Question 112: Which of the following is the GREATEST security concern of a...
Question 113: Which of the following authentication services combines auth...
Question 114: An administrator was asked to review user accounts. Which of...
Question 115: The chief information officer (CIO) of a major company inten...
Question 116: A new employee has joined the accounting department and is u...
Question 117: A security engineer is tasked with encrypting corporate emai...
Question 118: Which of the following attacks involves the use of previousl...
Question 119: Which of the following password attacks involves attempting ...
Question 120: Pete, a security auditor, has detected clear text passwords ...
Question 121: The software developer is responsible for writing the code a...
Question 122: Ann a security technician receives a report from a user that...
Question 123: Matt, a forensic analyst, wants to obtain the digital finger...
Question 124: Identifying a list of all approved software on a system is a...
Question 125: Which of the following provides dedicated hardware-based cry...
Question 126: Which of the following tools would allow Ann, the security a...
Question 127: An auditing team has found that passwords do not meet the be...
Question 128: Which of the following is BEST carried out immediately after...
Question 129: A security administrator wants to ensure that the message th...
Question 130: A malicious user has collected the following list of informa...
Question 131: A datacenter has suffered repeated burglaries which led to e...
Question 132: The security administrator notices a user logging into a cor...
Question 133: Which of the following ports should be opened on a firewall ...
Question 134: Which of the following should be used to authenticate and lo...
Question 135: A fiber company has acquired permission to bury a fiber cabl...
Question 136: Which of the following relies on the use of shared secrets t...
Question 137: An administrator performs a risk calculation to determine if...
Question 138: A company hired Joe, an accountant. The IT administrator wil...
Question 139: Which of the following types of encryption will help in prot...
Question 140: When Ann an employee returns to work and logs into her works...
Question 141: A software developer wants to prevent stored passwords from ...
Question 142: Which of the following should be done before resetting a use...
Question 143: Which of the following risk concepts requires an organizatio...
Question 144: The security manager received a report that an employee was ...
Question 145: A security analyst, while doing a security scan using packet...
Question 146: Which of the following may be used with a BNC connector?...
Question 147: A security administrator has just finished creating a hot si...
Question 148: One month after a software developer was terminated, the hel...
Question 149: Sara, an application developer, implemented error and except...
Question 150: A company has been attacked and their website has been alter...
Question 151: An auditor's report discovered several accounts with no acti...
Question 152: A Windows- based computer is infected with malware and is ru...
Question 153: Which of the following should be enabled in a laptop's BIOS ...
Question 154: A security researcher wants to reverse engineer an executabl...
Question 155: A recent review of accounts on various systems has found tha...
Question 156: An assessment too reports that the company's web server may ...
Question 157: Ann was reviewing her company's event logs and observed seve...
Question 158: A security analyst implemented group-based privileges within...
Question 159: A security administrator is selecting an MDM solution for an...
Question 160: An agent wants to create fast and efficient cryptographic ke...
Question 161: What is the term for the process of luring someone in (usual...
Question 162: A security administrator has been tasked with assisting in t...
Question 163: Upper management decides which risk to mitigate based on cos...
Question 164: A router was shut down as a result of a DoS attack. Upon rev...
Question 165: Several employees have been printing files that include pers...
Question 166: A periodic update that corrects problems in one version of a...
Question 167: Which of the following is a common coding error in which bou...
Question 168: A security analyst is working on a project team responsible ...
Question 169: An online store wants to protect user credentials and credit...
Question 170: An application developer needs to allow employees to use the...
Question 171: An attacker used an undocumented and unknown application exp...
Question 172: A forensic analyst is reviewing electronic evidence after a ...
Question 173: An organization's security policy states that users must aut...
Question 174: A server dedicated to the storage and processing of sensitiv...
Question 175: A company's chief information officer (CIO) has analyzed the...
Question 176: A company's employees were victims of a spear phishing campa...
Question 177: In which of the following categories would creating a corpor...
Question 178: Which of the following concepts describes the use of a one-w...
Question 179: A security administrator needs to determine which system a p...
Question 180: Which of the following is a hardware-based security technolo...
Question 181: Which of the following software allows a network administrat...
Question 182: Ann would like to forward some Personal Identifiable Informa...
Question 183: The Quality Assurance team is testing a new third party deve...
Question 184: Users are utilizing thumb drives to connect to USB ports on ...
Question 185: A security administrator wants to get a real time look at wh...
Question 186: Ann is the data owner of financial records for a company. Sh...
Question 187: A security administrator is responsible for ensuring that th...
Question 188: Joe, the information security manager, is tasked with calcul...
Question 189: The string: 'or 1=1-- - Which of the following represents it...
Question 190: An administrator discovers that many users have used their s...
Question 191: A security administrator looking through IDS logs notices th...
Question 192: Joe a company's new security specialist is assigned a role t...
Question 193: A classroom utilizes workstations running virtualization sof...
Question 194: When an order was submitted via the corporate website, an ad...
Question 195: The security department has implemented a new laptop encrypt...
Question 196: A company requires that all users enroll in the corporate PK...
Question 197: The act of magnetically erasing all of the data on a disk is...
Question 198: A security director has contracted an outside testing compan...
Question 199: Joe, a web developer, wants to make sure his application is ...
Question 200: Which of the following was launched against a company based ...
Question 201: Which of the following is provided by RADIUS?...
Question 202: An administrator has successfully implemented SSL on srv4.co...
Question 203: An employee attempts to go to a well-known bank site using t...
Question 204: At the outside break area, an employee, Ann, asked another e...
Question 205: XYZ Corporation is about to purchase another company to expa...
Question 206: Pete, the security engineer, would like to prevent wireless ...
Question 207: A system administrator has been instructed by the head of se...
Question 208: Which of the following malware types typically allows an att...
Question 209: Which of the following tools will allow a technician to dete...
Question 210: Which of the following types of logs could provide clues tha...
Question 211: An administrator has to determine host operating systems on ...
Question 212: A user casually browsing the Internet is redirected to a war...
Question 213: A security administrator is reviewing the company's continui...
Question 214: The database server used by the payroll system crashed at 3 ...
Question 215: A network administrator was to implement a solution that wil...
Question 216: An attacker Joe configures his service identifier to be the ...
Question 217: The security administrator is currently unaware of an incide...
Question 218: While responding to an incident on a Linux server, the admin...
Question 219: A programmer must write a piece of code to encrypt passwords...
Question 220: The security administration team at a company has been taske...
Question 221: Which of the following ports is used for TELNET by default?...
Question 222: A website is breached, exposing the usernames and MD5 passwo...
Question 223: Joe, a security analyst, is attempting to determine if a new...
Question 224: After a recent breach, the security administrator performs a...
Question 225: Several employees clicked on a link in a malicious message t...
Question 226: Which of the following includes environmental control measur...
Question 227: A server administrator notes that a fully patched applicatio...
Question 228: A chief information security officer (CISO) is providing a p...
Question 229: A security technician wishes to gather and analyze all Web t...
Question 230: Which of the following is an example of multifactor authenti...
Question 231: Ann has recently transferred from the payroll department to ...
Question 232: After connecting to the corporate network a user types the U...
Question 233: Highly sensitive data is stored in a database and is accesse...
Question 234: Ann is traveling for business and is attempting to use the h...
Question 235: Pete, the Chief Executive Officer (CEO) of a company, has in...
Question 236: Which of the following practices reduces the management burd...
Question 237: A Company has recently identified critical systems that supp...
Question 238: Which of the following internal security controls is aimed a...
Question 239: Which of the following is the BEST reason to provide user aw...
Question 240: A network stream needs to be encrypted. Sara, the network ad...
Question 241: Which of the following data security techniques will allow M...
Question 242: A recent spike in virus detections has been attributed to en...
Question 243: Which of the following are Data Loss Prevention (DLP) strate...
Question 244: Which of the following is an attack vector that can cause ex...
Question 245: A recent intrusion has resulted in the need to perform incid...
Question 246: A company is installing a new security measure that would al...
Question 247: The Chief Technical Officer (CTO) has tasked The Computer Em...
Question 248: A security administrator suspects that an employee in the IT...
Question 249: Pete, the system administrator, has concerns regarding users...
Question 250: If Organization A trusts Organization B and Organization B t...
Question 251: Which of the following types of data encryption would Matt, ...
Question 252: Pete's corporation has outsourced help desk services to a la...
Question 253: Which of the following attacks impact the availability of a ...
Question 254: Users at a company report that a popular news website keeps ...
Question 255: Ann, a security administrator is hardening the user password...
Question 256: A user has forgotten their account password. Which of the fo...
Question 257: A datacenter requires that staff be able to identify whether...
Question 258: The security consultant is assigned to test a client's new s...
Question 259: A security administrator is troubleshooting an authenticatio...
Question 260: After copying a sensitive document from his desktop to a fla...
Question 261: While troubleshooting a new wireless 802.11 ac network an ad...
Question 262: Joe, a technician, is tasked with finding a way to test oper...
Question 263: An investigator recently discovered that an attacker placed ...
Question 264: Which of the following is a measure of biometrics performanc...
Question 265: Users have been reporting that their wireless access point i...
Question 266: While an Internet café a malicious user is causing all surro...
Question 267: Ann, a security administrator, is strengthening the security...
Question 268: A system security analyst using an enterprise monitoring too...
Question 269: A company needs to receive data that contains personally ide...
Question 270: One of the most consistently reported software security vuln...
Question 271: Client computers login at specified times to check and updat...
Question 272: An internal auditor is concerned with privilege creep that i...
Question 273: Ann an employee is visiting Joe, an employee in the Human Re...
Question 274: Which of the following is an example of establishing a publi...
Question 275: Ann is a member of the Sales group. She needs to collaborate...
Question 276: An organization is recovering data following a datacenter ou...
Question 277: A security technician has been asked to recommend an authent...
Question 278: A server with the IP address of 10.10.2.4 has been having in...
Question 279: A bank is planning to implement a third factor to protect cu...
Question 280: In which of the following scenarios would it be preferable t...
Question 281: A large bank has moved back office operations offshore to an...
Question 282: Which of the following security architecture elements also h...
Question 283: Ann, an employee, is cleaning out her desk and disposes of p...
Question 284: Which of the following technologies when applied to android ...
Question 285: Which of the following describes purposefully injecting extr...
Question 286: Matt, a security analyst, needs to implement encryption for ...
Question 287: A recently installed application update caused a vital appli...
Question 288: Which of the following risks could IT management be mitigati...
Question 289: A large corporation has data centers geographically distribu...
Question 290: Which of the following is the MOST intrusive type of testing...
Question 291: A user commuting to work via public transport received an of...
Question 292: Which of the following may significantly reduce data loss if...
Question 293: After a user performed a war driving attack, the network adm...
Question 294: A forensic analyst is reviewing electronic evidence after a ...
Question 295: A security audit identifies a number of large email messages...
Question 296: Which of the following types of technologies is used by secu...
Question 297: A network technician has received comments from several user...
Question 298: A network administrator is configuring access control for th...
Question 299: The security administrator is implementing a malware storage...
Question 300: DRAG DROP Determine the types of attacks below by selecting ...
Question 301: In which of the following steps of incident response does a ...
Question 302: A hacker has discovered a simple way to disrupt business for...
Question 303: A company wants to ensure that all credentials for various s...
Question 304: A company has identified a watering hole attack. Which of th...
Question 305: The manager has a need to secure physical documents every ni...
Question 306: Which of the following is mainly used for remote access into...
Question 307: Each server on a subnet is configured to only allow SSH acce...
Question 308: In Kerberos, the Ticket Granting Ticket (TGT) is used for th...
Question 309: A security analyst, Ann, is reviewing an IRC channel and not...
Question 310: Which of the following should Jane, a security administrator...
Question 311: Which of the following attacks would cause all mobile device...
Question 312: Which of the following attacks initiates a connection by sen...
Question 313: A system administrator is responding to a legal order to tur...
Question 314: The Chief Information Officer (CIO) receives an anonymous th...
Question 315: A company has recently allowed employees to take advantage o...
Question 316: A computer supply company is located in a building with thre...
Question 317: Mike, a security professional, is tasked with actively verif...
Question 318: A security administrator wants to test the reliability of an...
Question 319: A system administrator has made several unauthorized changes...
Question 320: Which of the following is a control that allows a mobile app...
Question 321: A software firm posts patches and updates to a publicly acce...
Question 322: Joe analyzed the following log and determined the security t...
Question 323: Ann is concerned that the application her team is currently ...
Question 324: The use of social networking sites introduces the risk of:...
Question 325: Which of the following is a security concern regarding users...
Question 326: After an assessment, auditors recommended that an applicatio...
Question 327: Which of the following attacks allows access to contact list...
Question 328: Which of the following concepts is enforced by certifying th...
Question 329: Which of the following is the BEST practice when dealing wit...
Question 330: The helpdesk reports increased calls from clients reporting ...
Question 331: A system administrator wants to prevent password compromises...
Question 332: Anne, an employee, receives the following email: From: Human...
Question 333: Human Resources suspects an employee is accessing the employ...
Question 334: When implementing a Public Key Infrastructure, which of the ...
Question 335: A security technician has been tasked with opening ports on ...
Question 336: Which of the following presents the STRONGEST access control...
Question 337: Which of the following is an authentication service that use...
Question 338: Which of the following BEST describes a protective counterme...
Question 339: The Chief Information Officer (CIO) wants to implement a red...
Question 340: A new mobile banking application is being developed and uses...
Question 341: An employee connects a wireless access point to the only jac...
Question 342: Which of the following is a way to implement a technical con...
Question 343: The security manager reports that the process of revoking ce...
Question 344: Ann, a security administrator, wants to limit access to the ...
Question 345: Which of the following is used by the recipient of a digital...
Question 346: The Chief Executive Officer (CEO) receives a suspicious voic...
Question 347: Several employee accounts appear to have been cracked by an ...
Question 348: An organization has introduced token-based authentication to...
Question 349: Users report that they are unable to access network printing...
Question 350: Which of the following types of attacks is based on coordina...
Question 351: Which of the following helps to establish an accurate timeli...
Question 352: A distributed denial of service attack can BEST be described...
Question 353: Physical documents must be incinerated after a set retention...
Question 354: Which of the following would BEST deter an attacker trying t...
Question 355: Which of the following can be implemented in hardware or sof...
Question 356: Input validation is an important security defense because it...
Question 357: Which of the following is BEST utilized to actively test sec...
Question 358: Joe, the system administrator, is performing an overnight sy...
Question 359: A small company has a website that provides online customer ...
Question 360: Sara, an attacker, is recording a person typing in their ID ...
Question 361: Which of the following protocols uses an asymmetric key to o...
Question 362: During a penetration test from the Internet, Jane, the syste...
Question 363: Which of the following is used to inform users of the reperc...
Question 364: An administrator would like users to authenticate to the net...
Question 365: Certificates are used for: (Choose two.)...
Question 366: SIMULATION A security administrator discovers that an attack...
Question 367: During a recent investigation, an auditor discovered that an...
Question 368: Which of the following BEST describes malware that tracks a ...
Question 369: Which of the following controls would allow a company to red...
Question 370: The marketing department wants to distribute pens with embed...
Question 371: A resent OS patch caused an extended outage. It took the IT ...
Question 372: Data confidentiality must be enforced on a secure database. ...
Question 373: Which of the following would prevent a user from installing ...
Question 374: A system administrator has noticed vulnerability on a high i...
Question 375: Which of the following concepts allows an organization to gr...
Question 376: Which of the following is an advantage of implementing indiv...
Question 377: Which of the following are examples of network segmentation?...
Question 378: Which of the following automated or semi-automated software ...
Question 379: Which of the following can be performed when an element of t...
Question 380: Which of the following is where an unauthorized device is fo...
Question 381: Which of the following wireless protocols could be vulnerabl...
Question 382: Using a heuristic system to detect an anomaly in a computer'...
Question 383: The IT department noticed that there was a significant decre...
Question 384: A network administrator uses an RFID card to enter the datac...
Question 385: Which of the following should an administrator implement to ...
Question 386: The access control list (ACL) for a file on a server is as f...
Question 387: Which of the following incident response plan steps would MO...
Question 388: The Chief Security Officer (CSO) is contacted by a first res...
Question 389: The key management organization has implemented a key escrow...
Question 390: Which of the following means a password history value of thr...
Question 391: A security administrator is auditing a database server to en...
Question 392: A small IT security form has an internal network composed of...
Question 393: Prior to leaving for an extended vacation, Joe uses his mobi...
Question 394: Which of the following allows a network administrator to imp...
Question 395: Which of the following types of authentication solutions use...
Question 396: A computer is suspected of being compromised by malware. The...
Question 397: Several departments in a corporation have a critical need fo...
Question 398: A technician has been tasked with installing and configuring...
Question 399: A security administrator wishes to prevent certain company d...
Question 400: A company has purchased an application that integrates into ...
Question 401: A security administrator notices large amounts of traffic wi...
Question 402: Which of the following implementation steps would be appropr...
Question 403: During a security assessment, an administrator wishes to see...
Question 404: Which of the following will help prevent smurf attacks?...
Question 405: Privilege creep among long-term employees can be mitigated b...
Question 406: Use of group accounts should be minimized to ensure the foll...
Question 407: A financial company requires a new private network link with...
Question 408: A company is rolling out a new e-commerce website. The secur...
Question 409: Which of the following can be used by a security administrat...
Question 410: A technician has deployed a new VPN concentrator. The device...
Question 411: During an audit, the security administrator discovers that t...
Question 412: Which of the following should be connected to the fire alarm...
Question 413: An application developer has tested some of the known exploi...
Question 414: A security technician is implementing PKI on a Network. The ...
Question 415: A system administrator has noticed that users change their p...
Question 416: Various employees have lost valuable customer data due to ha...
Question 417: Symmetric encryption utilizes __________, while asymmetric e...
Question 418: A security administrator must implement all requirements in ...
Question 419: An attacker attempted to compromise a web form by inserting ...
Question 420: Which of the following is the BEST way to prevent Cross-Site...
Question 421: A company that purchased an HVAC system for the datacenter i...
Question 422: Failure to validate the size of a variable before writing it...
Question 423: The Chief Information Officer (CIO) has asked a security ana...
Question 424: The system administrator has been notified that many users a...
Question 425: Which of the following can take advantage of man-in-the-midd...
Question 426: An administrator has concerns regarding the company's server...
Question 427: A company needs to provide a secure backup mechanism for key...
Question 428: Which of the following security account management technique...
Question 429: Without validating user input, an application becomes vulner...
Question 430: Jane, an IT security technician, needs to create a way to se...
Question 431: A software development company has hired a programmer to dev...
Question 432: A malicious person gained access to a datacenter by ripping ...
Question 433: Which of the following describes a type of malware which is ...
Question 434: A worker dressed in a fire suppression company's uniform ask...
Question 435: During a company-wide initiative to harden network security,...
Question 436: When an authorized application is installed on a server, the...
Question 437: A user attempts to install a new and relatively unknown soft...
Question 438: Pete, the compliance manager, wants to meet regulations. Pet...
Question 439: Which of the following will allow the live state of the virt...
Question 440: A company's password and authentication policies prohibit th...
Question 441: A user has received an email from an external source which a...
Question 442: Which of the following technologies uses multiple devices to...
Question 443: The help desk is experiencing a higher than normal amount of...
Question 444: Two programmers write a new secure application for the human...
Question 445: A recent audit of a company's identity management system sho...
Question 446: Using proximity card readers instead of the traditional key ...
Question 447: A program displays: ERROR: this program has caught an except...
Question 448: On a train, an individual is watching a proprietary video on...
Question 449: Which of the following is commonly LDAP and Kerberos used fo...
Question 450: Timestamps and sequence numbers act as countermeasures again...
Question 451: An administrator finds that non-production servers are being...
Question 452: In an environment where availability is critical such as Ind...
Question 453: Which of the following may cause Jane, the security administ...
Question 454: Which of the following is a notification that an unusual con...
Question 455: Which of the following encompasses application patch managem...
Question 456: A user Ann has her assigned token but she forgotten her pass...
Question 457: Users need to exchange a shared secret to begin communicatin...
Question 458: The chief security officer (CSO) has issued a new policy to ...
Question 459: Jane, a security analyst, is reviewing logs from hosts acros...
Question 460: In performing an authorized penetration test of an organizat...
Question 461: Ann a network administrator has been tasked with strengtheni...
Question 462: An administrator has advised against the use of Bluetooth ph...
Question 463: A company hires a penetration testing team to test its overa...
Question 464: Who should be contacted FIRST in the event of a security bre...
Question 465: A network analyst received a number of reports that imperson...
Question 466: A network administrator has recently updated their network d...
Question 467: Pete, an IT Administrator, needs to secure his server room. ...
Question 468: Joe, the chief technical officer (CTO) is concerned that the...
Question 469: Which of the following types of application attacks would be...
Question 470: A company has several public conference room areas with expo...
Question 471: A company wants to ensure that all aspects if data are prote...
Question 472: A database administrator would like to start encrypting data...
Question 473: A network administrator is responsible for securing applicat...
Question 474: An attacker impersonates a fire marshal and demands access t...
Question 475: A file on a Linux server has default permissions of rw-rw-r-...
Question 476: A security administrator is reviewing the company's data bac...
Question 477: In order to securely communicate using PGP, the sender of an...
Question 478: A system administrator is configuring a new file server and ...
Question 479: Which of the following is a hardware based encryption device...
Question 480: Which of the following is the BEST reason for placing a pass...
Question 481: Which of the following services are used to support authenti...
Question 482: Which of the following types of cloud computing would be MOS...
Question 483: A user was reissued a smart card after the previous smart ca...
Question 484: A security administrator would like to ensure that system ad...
Question 485: A company replaces a number of devices with a mobile applian...
Question 486: Ann, the Chief Technology Officer (CTO), has agreed to allow...
Question 487: Joe the system administrator has noticed an increase in netw...
Question 488: The company's sales team plans to work late to provide the C...
Question 489: Which of the following devices would be the MOST efficient w...
Question 490: Which of the following types of malware is designed to provi...
Question 491: Users have reported receiving unsolicited emails in their in...
Question 492: Which of the following does full disk encryption prevent?...
Question 493: Which of the following is an attack designed to activate bas...
Question 494: The process of making certain that an entity (operating syst...
Question 495: The programmer confirms that there is potential for a buffer...
Question 496: Ann, a security analyst, has discovered that her company has...
Question 497: An administrator, Ann, wants to ensure that only authorized ...
Question 498: An administrator must select an algorithm to encrypt data at...
Question 499: Which of the following best describes the reason for using h...
Question 500: When implementing fire suppression controls in a datacenter ...
Question 501: Ann is starting a disaster recovery program. She has gathere...
Question 502: Which of the following common access control models is commo...
Question 503: Which of the following would be a reason for developers to u...
Question 504: A company uses SSH to support internal users. They want to b...
Question 505: What is a system that is intended or designed to be broken i...
Question 506: A security administrator implements access controls based on...
Question 507: After several thefts a Chief Executive Officer (CEO) wants t...
Question 508: Joe, a company's network engineer, is concerned that protoco...
Question 509: A security assurance officer is preparing a plan to measure ...
Question 510: The security team would like to gather intelligence about th...
Question 511: An internal auditing team would like to strengthen the passw...
Question 512: Sara, a security administrator, is noticing a slowdown in th...
Question 513: Datacenter access is controlled with proximity badges that r...
Question 514: A security technician at a small business is worried about t...
Question 515: A company recently experienced data loss when a server crash...
Question 516: The security administrator is analyzing a user's history fil...
Question 517: Suspicious traffic without a specific signature was detected...
Question 518: A custom PKI application downloads a certificate revocation ...
Question 519: The IT department has set up a share point site to be used o...
Question 520: Ann has taken over as the new head of the IT department. One...
Question 521: Which of the following is the BEST method for ensuring all f...
Question 522: An attacker crafts a message that appears to be from a trust...
Question 523: By hijacking unencrypted cookies an application allows an at...
Question 524: A penetration tester is measuring a company's posture on soc...
Question 525: Matt, a security administrator, wants to ensure that the mes...
Question 526: A security administrator is aware that a portion of the comp...
Question 527: A system administrator has concerns regarding their users ac...
Question 528: A company has implemented full disk encryption. Clients must...
Question 529: Human Resources (HR) would like executives to undergo only t...
Question 530: In the case of a major outage or business interruption, the ...
Question 531: A victim is logged onto a popular home router forum site in ...
Question 532: An SSL/TLS private key is installed on a corporate web proxy...
Question 533: Which of the following is an authentication and accounting s...
Question 534: Which of the following would be used when a higher level of ...
Question 535: Company A and Company B both supply contractual services to ...
Question 536: A customer has provided an email address and password to a w...
Question 537: Which of the following concepts is BEST described as develop...
Question 538: Which of the following concepts is used by digital signature...
Question 539: An administrator notices an unusual spike in network traffic...
Question 540: A network engineer is configuring a VPN tunnel connecting a ...
Question 541: Which of the following solutions provides the most flexibili...
Question 542: Company XYZ has encountered an increased amount of buffer ov...
Question 543: An administrator would like to utilize encryption that has c...
Question 544: A security administrator must implement a system that will s...
Question 545: Jane, a security administrator, needs to implement a secure ...
Question 546: Joe, an application developer, is building an external facin...
Question 547: A malicious individual is attempting to write too much data ...
Question 548: Which of the following is an example of a false positive?...
Question 549: A company needs to provide web-based access to shared data s...
Question 550: Which of the following transportation encryption protocols s...
Question 551: Which of the following functions provides an output which ca...
Question 552: A Company transfers millions of files a day between their se...
Question 553: Employee badges are encoded with a private encryption key an...
Question 554: Which of the following pseudocodes can be used to handle pro...
Question 555: An encrypted message is sent using PKI from Sara, a client, ...
Question 556: All of the following are valid cryptographic hash functions ...
Question 557: Which of the following is an application security coding pro...
Question 558: A company hires outside security experts to evaluate the sec...
Question 559: A user attempting to log on to a workstation for the first t...
Question 560: While opening an email attachment, Pete, a customer, receive...
Question 561: A security administrator is tasked with calculating the tota...
Question 562: Which of the following fire suppression systems is MOST like...
Question 563: A user has several random browser windows opening on their c...
Question 564: Jane, a security administrator, has been tasked with explain...
Question 565: Which of the following can be used on a smartphone to BEST p...
Question 566: Ann, the security administrator, received a report from the ...
Question 567: A security engineer would like to analyze the effect of depl...
Question 568: An outside security consultant produces a report of several ...
Question 569: Company A submitted a bid on a contract to do work for Compa...
Question 570: Which of the following practices is used to mitigate a known...
Question 571: Joe, the security administrator, has determined that one of ...
Question 572: Which of the following malware types is MOST likely to execu...
Question 573: Joe, a user, wants to send an encrypted email to Ann. Which ...
Question 574: A company plans to expand by hiring new engineers who work i...
Question 575: Which of the following security concepts identifies input va...
Question 576: Based on information leaked to industry websites, business m...
Question 577: Joe, a network administrator, is able to manage the backup s...
Question 578: One of the most basic ways to protect the confidentiality of...
Question 579: Joe, the system administrator, has been asked to calculate t...
Question 580: Which of the following should a company implement to BEST mi...
Question 581: During a review a company was cited for allowing requestors ...
Question 582: An employee recently lost a USB drive containing confidentia...
Question 583: Which of the following would an attacker use to generate and...
Question 584: Which of the following is it MOST difficult to harden agains...
Question 585: A network administrator noticed various chain messages have ...
Question 586: The concept of rendering data passing between two points ove...
Question 587: Which of the following is the BEST concept to maintain requi...
Question 588: A security technician wants to improve the strength of a wea...
Question 589: A user has plugged in a wireless router from home with defau...
Question 590: The IT department has been tasked with reducing the risk of ...
Question 591: A company is about to release a very large patch to its cust...
Question 592: A server administrator notes that a legacy application often...
Question 593: DRAG DROP Drag the items on the left to show the different t...
Question 594: Why would a technician use a password cracker?...
Question 595: Which of the following cryptographic methods is most secure ...
Question 596: In order to maintain oversight of a third party service prov...
Question 597: A company requires that all wireless communication be compli...
Question 598: A risk assessment team is concerned about hosting data with ...
Question 599: One of the servers on the network stops responding due to la...
Question 600: To ensure proper evidence collection, which of the following...
Question 601: DRAG DROP You have been tasked with designing a security pla...
Question 602: Joe needs to track employees who log into a confidential dat...
Question 603: An employee finds a USB drive in the employee lunch room and...
Question 604: While working on a new project a security administrator want...
Question 605: Which of the following, if implemented, would improve securi...
Question 606: Which of the following assets is MOST likely considered for ...
Question 607: Which of the following exploits either a host file on a targ...
Question 608: Which of the following would be used to identify the securit...
Question 609: Users are encouraged to click on a link in an email to obtai...
Question 610: Which of the following is an important step in the initial s...
Question 611: The ore-sales engineering team needs to quickly provide accu...
Question 612: A system security analyst wants to capture data flowing in a...
Question 613: Which of the following preventative controls would be approp...
Question 614: A security analyst informs the Chief Executive Officer (CEO)...
Question 615: An administrator is configuring a network for all users in a...
Question 616: A security administrator has been tasked to ensure access to...
Question 617: Which of the following is a best practice when a mistake is ...
Question 618: Pete, a developer, writes an application. Jane, the security...
Question 619: The system administrator has deployed updated security contr...
Question 620: A security administrator wants to implement a solution which...
Question 621: In order for Sara, a client, to logon to her desktop compute...
Question 622: A security administrator is reviewing logs and notices multi...
Question 623: The network manager has obtained a public IP address for use...
Question 624: Employees are reporting that they have been receiving a larg...
Question 625: Jane has implemented an array of four servers to accomplish ...
Question 626: A security technician would like to use ciphers that generat...
Question 627: A security administrator is designing an access control syst...
Question 628: Sara, a security analyst, is trying to prove to management w...
Question 629: Sara, a security architect, has developed a framework in whi...
Question 630: An administrator has a network subnet dedicated to a group o...
Question 631: A company's application is hosted at a data center. The data...
Question 632: The chief Risk officer is concerned about the new employee B...
Question 633: Pete, a security analyst, has been tasked with explaining th...
Question 634: Computer evidence at a crime scene is documented with a tag ...
Question 635: The system administrator wishes to implement a hardware-base...
Question 636: After a production outage, which of the following documents ...
Question 637: Allowing unauthorized removable devices to connect to comput...
Question 638: An organization currently uses FTP for the transfer of large...
Question 639: HOTSPOT For each of the given items, select the appropriate ...
Question 640: An employee from the fire Marshall's office arrives to inspe...
Question 641: Ann, a security administrator at a call center, has been exp...
Question 642: A security administrator wishes to protect session leys shou...
Question 643: The system administrator notices that many employees are usi...
Question 644: Which of the following are examples of detective controls?...
Question 645: Joe, a security administrator, is concerned with users tailg...
Question 646: A company has a corporate infrastructure where end users man...
Question 647: A database administrator receives a call on an outside telep...
Question 648: Two organizations want to share sensitive data with one anot...
Question 649: After receiving the hard drive from detectives, the forensic...
Question 650: The IT department has setup a website with a series of quest...
Question 651: A user reports being unable to access a file on a network sh...
Question 652: A new application needs to be deployed on a virtual server. ...
Question 653: A company used a partner company to develop critical compone...
Question 654: A security analyst has a sample of malicious software and ne...
Question 655: A bank Chief Information Security Officer (CISO) is responsi...
Question 656: Which of the following is a penetration testing method?...
Question 657: HOTSPOT For each of the given items, select the appropriate ...
Question 658: After analyzing and correlating activity from multiple senso...
Question 659: Which of the following should be considered to mitigate data...
Question 660: A security administrator needs to implement a technology tha...
Question 661: A new security analyst is given the task of determining whet...
Question 662: A security administrator wants to deploy security controls t...
Question 663: Ann, a security analyst, is preparing for an upcoming securi...
Question 664: Which of the following is built into the hardware of most la...
Question 665: A security technician received notification of a remotely ex...
Question 666: Matt, a developer, recently attended a workshop on a new app...
Question 667: One of the senior managers at a company called the help desk...
Question 668: A company hosts its public websites internally. The administ...
Question 669: After Matt, a user, enters his username and password at the ...
Question 670: A computer is found to be infected with malware and a techni...
Question 671: Which of the following security concepts would Sara, the sec...
Question 672: A company wants to improve its overall security posture by d...
Question 673: An organization processes credit card transactions and is co...
Question 674: During which of the following phases of the Incident Respons...
Question 675: A malicious individual used an unattended customer service k...
Question 676: Mike, a user, states that he is receiving several unwanted e...
Question 677: A company is trying to limit the risk associated with the us...
Question 678: In order to enter a high-security data center, users are req...
Question 679: Ann, a member of the Sales Department, has been issued a com...
Question 680: A supervisor in the human resources department has been give...
Question 681: Which of the following is an important implementation consid...
Question 682: A security analyst has been notified that trade secrets are ...
Question 683: One of the findings of risk assessment is that many of the s...
Question 684: In order to gain an understanding of the latest attack tools...
Question 685: A company has recently begun to provide internal security aw...
Question 686: An organizations' security policy requires that users change...
Question 687: A one-time security audit revealed that employees do not hav...
Question 688: Sara, an employee, tethers her smartphone to her work PC to ...
Question 689: A network administrator has purchased two devices that will ...
Question 690: Which of the following is a security advantage of using NoSQ...
Question 691: Which of the following statements is MOST likely to be inclu...
Question 692: Which of the following are unique to white box testing metho...
Question 693: Which of the following would a security administrator implem...
Question 694: Jane has recently implemented a new network design at her or...
Question 695: The datacenter manager is reviewing a problem with a humidit...
Question 696: Which of the following is the practice of marking open wirel...
Question 697: A user, Ann, is reporting to the company IT support group th...
Question 698: Joe, a security technician, is configuring two new firewalls...
Question 699: Sara, a user, downloads a keygen to install pirated software...
Question 700: A technician installed two ground plane antennae on 802.11n ...
Question 701: Which of the following techniques can be used to prevent the...
Question 702: Which of the following types of wireless attacks would be us...
Question 703: Which of the following is characterized by an attacker attem...
Question 704: Key cards at a bank are not tied to individuals, but rather ...
Question 705: Which of the following documents outlines the technical and ...
Question 706: Which of the following would a security administrator implem...
Question 707: A security administrator has implemented a policy to prevent...
Question 708: A company's BYOD policy requires the installation of a compa...
Question 709: A security administrator has concerns about new types of med...
Question 710: Joe uses his badge to enter the server room, Ann follows Joe...
Question 711: A company has had several security incidents in the past six...
Question 712: Which of the following is being tested when a company's payr...
Question 713: Joe has hired several new security administrators and have b...
Question 714: An employee in the accounting department recently received a...
Question 715: A new web server has been provisioned at a third party hosti...
Question 716: Which of the following password attacks is MOST likely to cr...
Question 717: Which of the following authentication methods requires the u...
Question 718: When confidentiality is the primary concern, which of the fo...
Question 719: Which of the following steps in incident response procedures...
Question 720: Sara, a hacker, is completing a website form to request a fr...
Question 721: When a new network drop was installed, the cable was run acr...
Question 722: Which of the following is the term for a fix for a known sof...
Question 723: Joe, a network security engineer, has visibility to network ...
Question 724: Which of the following types of authentication packages user...
Question 725: A company would like to implement two-factor authentication ...
Question 726: After a number of highly publicized and embarrassing custome...
Question 727: Which of the following helps to apply the proper security co...
Question 728: All executive officers have changed their monitor location s...
Question 729: A security administrator wants to check user password comple...
Question 730: Which of the following file systems is from Microsoft and wa...
Question 731: A company uses port security based on an approved MAC list t...
Question 732: Which of the following has serious security implications for...
Question 733: Which of the following security concepts can prevent a user ...
Question 734: A load balancer has the ability to remember which server a p...
Question 735: Which of the following is an indication of an ongoing curren...
Question 736: Ann, a software developer, has installed some code to reacti...
Question 737: Fuzzing is a security assessment technique that allows teste...
Question 738: A server administrator discovers the web farm is using weak ...
Question 739: A technician has implemented a system in which all workstati...
Question 740: The Chief Information Officer (CIO) is concerned with moving...
Question 741: Matt, an IT administrator, wants to protect a newly built se...
Question 742: Searching for systems infected with malware is considered to...
Question 743: Ann a new small business owner decides to implement WiFi acc...
Question 744: Ann, the network administrator, has learned from the helpdes...
Question 745: Which of the following protocols is MOST likely to be levera...
Question 746: Joe, a user, in a coffee shop is checking his email over a w...
Question 747: Results from a vulnerability analysis indicate that all enab...
Question 748: An internal audit has detected that a number of archived tap...
Question 749: A company wants to ensure that its hot site is prepared and ...
Question 750: When a communications plan is developed for disaster recover...
Question 751: Which of the following devices is used for the transparent s...
Question 752: Matt, an administrator, is concerned about the wireless netw...
Question 753: An attacker Joe configures his service identifier to be as a...
Question 754: A security administrator has concerns regarding employees sa...
Question 755: A bank has recently deployed mobile tablets to all loan offi...
Question 756: A technician is configuring a switch to support VOPIP phones...
Question 757: During a routine configuration audit, a systems administrato...
Question 758: Given a class C network a technician has been tasked with cr...
Question 759: Which of the following is BEST utilized to identify common m...
Question 760: A security administrator must implement a network that is im...
Question 761: Purchasing receives a phone call from a vendor asking for a ...
Question 762: A user tries to visit a website with a revoked certificate. ...
Question 763: A way to assure data at-rest is secure even in the event of ...
Question 764: Which of the following controls should critical application ...
Question 765: A corporate wireless guest network uses an open SSID with a ...
Question 766: Sara, a security administrator, manually hashes all network ...
Question 767: Which of the following BEST explains Platform as a Service?...
Question 768: Disabling unnecessary services, restricting administrative a...
Question 769: To mitigate the risk of intrusion, an IT Manager is concerne...
Question 770: Sara, a security manager, has decided to force expiration of...
Question 771: Visitors entering a building are required to close the back ...
Question 772: An organization has an internal PKI that utilizes client cer...
Question 773: An administrator wants to ensure that the reclaimed space of...
Question 774: Which of the following policies is implemented in order to m...
Question 775: Requiring technicians to report spyware infections is a step...
Question 776: RC4 is a strong encryption protocol that is general used wit...
Question 777: A trojan was recently discovered on a server. There are now ...
Question 778: Which of the following is an attack designed to activate bas...
Question 779: A rogue programmer included a piece of code in an applicatio...
Question 780: The security officer is preparing a read-only USB stick with...
Question 781: A business has set up a Customer Service kiosk within a shop...
Question 782: An IT security technician needs to establish host based secu...
Question 783: A switch is set up to allow only 2 simultaneous MAC addresse...
Question 784: After an audit, it was discovered that the security group me...
Question 785: Matt, a security consultant, has been tasked with increasing...
Question 786: Which of the following utilities can be used in Linux to vie...
Question 787: A security administrator has deployed all laptops with Self ...
Question 788: After a recent security breach, the network administrator ha...
Question 789: A company uses PGP to ensure that sensitive email is protect...
Question 790: Using a protocol analyzer, a security consultant was able to...
Question 791: A company would like to take electronic orders from a partne...
Question 792: Establishing a method to erase or clear cluster tips is an e...
Question 793: When considering a vendor-specific vulnerability in critical...
Question 794: Although a vulnerability scan report shows no vulnerabilitie...
Question 795: Which of the following BEST describes the type of attack tha...
Question 796: An administrator is implementing a security control that onl...
Question 797: A security administrator is tackling issues related to authe...
Question 798: Which of the following tools would a security administrator ...
Question 799: Which of the following would be MOST appropriate if an organ...
Question 800: The Chief Executive Officer (CEO) Joe notices an increase in...
Question 801: Which of the following is the below pseudo-code an example o...
Question 802: Which of the following BEST explains the use of an HSM withi...
Question 803: A system administrator is using a packet sniffer to troubles...
Question 804: An administrator uses a server with a trusted OS and is conf...
Question 805: A security administrator needs to image a large hard drive f...
Question 806: A security manager installed a standalone fingerprint reader...
Question 807: An IT security technician is actively involved in identifyin...
Question 808: Used in conjunction, which of the following are PII? (Choose...
Question 809: Which of the following is a Data Loss Prevention (DLP) strat...
Question 810: A vulnerability assessment indicates that a router can be ac...
Question 811: A certificate used on an e-commerce web server is about to e...
Question 812: Which of the following authentication services should be rep...
Question 813: Which of the following controls can be used to prevent the d...
Question 814: A new network administrator is setting up a new file server ...
Question 815: Which of the following BEST allows Pete, a security administ...
Question 816: A company is starting to allow employees to use their own pe...
Question 817: Which of the following types of security controls are visibl...
Question 818: Customers' credit card information was stolen from a popular...
Question 819: End-user awareness training for handling sensitive personall...
Question 820: Which of the following provides the BEST application availab...
Question 821: A project team is developing requirements of the new version...
Question 822: A company wants to prevent unauthorized access to its secure...
Question 823: Which of the following is a best practice when setting up a ...
Question 824: Which of the following is described as an attack against an ...
Question 825: A group of users from multiple departments are working toget...
Question 826: During an anonymous penetration test, Jane, a system adminis...
Question 827: A technician reports a suspicious individual is seen walking...
Question 828: A security manager is discussing change in the security post...
Question 829: Which of the following is a security benefit of providing ad...
Question 830: Use of a smart card to authenticate remote servers remains M...
Question 831: A security specialist has been asked to evaluate a corporate...
Question 832: Which of the following controls would prevent an employee fr...
Question 833: Which of the following describes the implementation of PAT?...
Question 834: In regard to secure coding practices, why is input validatio...
Question 835: A network manager needs a cost-effective solution to allow f...
Question 836: Which of the following tasks should key elements of a busine...
Question 837: A security administrator wants to deploy a physical security...
Question 838: Which of the following passwords is the LEAST complex?...
Question 839: In the course of troubleshooting wireless issues from users,...
Question 840: Which of the following application attacks is used to gain a...
Question 841: A new virtual server was created for the marketing departmen...
Question 842: A set of standardized system images with a pre-defined set o...
Question 843: Joe, a user, wants to send an encrypted email to Ann. Which ...
Question 844: Joe is the accounts payable agent for ABC Company. Joe has b...
Question 845: Which of the following would MOST likely involve GPS?...
Question 846: Purchasing receives an automated phone call from a bank aski...
Question 847: The security manager wants to unify the storage of credentia...
Question 848: Which of the following concepts defines the requirement for ...
Question 849: Users in the HR department were recently informed that they ...
Question 850: A merchant acquirer has the need to store credit card number...
Question 851: Matt, the Chief Information Security Officer (CISO), tells t...
Question 852: ABC company has a lot of contractors working for them. The p...
Question 853: Ann, a security administrator, wishes to replace their RADIU...
Question 854: A password audit has revealed that a significant percentage ...
Question 855: Pete, the system administrator, has blocked users from acces...
Question 856: A network technician is configuring clients for VLAN access....
Question 857: Which of the following types of attacks involves interceptio...
Question 858: Data execution prevention is a feature in most operating sys...
Question 859: An administrator receives a security alert that appears to b...
Question 860: Which of the following is BEST used to capture and analyze n...
Question 861: The main corporate website has a service level agreement tha...
Question 862: Joe, an administrator, installs a web server on the Internet...
Question 863: Joe, an employee is taking a taxi through a busy city and st...
Question 864: In order to secure additional budget, a security manager wan...
Question 865: A recent audit has revealed that several users have retained...
Question 866: A web administrator has just implemented a new web server to...
Question 867: The information security technician wants to ensure security...
Question 868: Which of the following provides data the best fault toleranc...
Question 869: A network administrator recently updated various network dev...
Question 870: A small company has recently purchased cell phones for manag...
Question 871: A program has been discovered that infects a critical Window...
Question 872: Which of the following can be used to ensure digital certifi...
Question 873: Which of the following is the BEST approach to perform risk ...
Question 874: An application developer has coded a new application with a ...
Question 875: Due to issues with building keys being duplicated and distri...
Question 876: Which of the following assessment techniques would a securit...
Question 877: The security administrator is observing unusual network beha...
Question 878: Encryption used by RADIUS is BEST described as:...
Question 879: Which of the following can be used for both encryption and d...
Question 880: A security administrator forgets their card to access the se...
Question 881: Several users' computers are no longer responding normally a...
Question 882: A system administrator needs to ensure that certain departme...
Question 883: A workstation is exhibiting symptoms of malware and the netw...
Question 884: After a company has standardized to a single operating syste...
Question 885: After a recent internal audit, the security administrator wa...
Question 886: The network security manager has been notified by customer s...
Question 887: A network administrator identifies sensitive files being tra...
Question 888: A company recently received accreditation for a secure netwo...
Question 889: DRAG DROP A forensic analyst is asked to respond to an ongoi...
Question 890: A recent online password audit has identified that stale acc...
Question 891: A company recently experienced several security breaches tha...
Question 892: A compromised workstation utilized in a Distributed Denial o...
Question 893: In the initial stages of an incident response, Matt, the sec...
Question 894: A user authenticates to a local directory server. The user t...
Question 895: Ann, the system administrator, is installing an extremely cr...
Question 896: Joe, a sales employee, is connecting to a wireless network a...
Question 897: Company policy requires employees to change their passwords ...
Question 898: Jane, a security administrator, has observed repeated attemp...
Question 899: Which of the following could cause a browser to display the ...
Question 900: A computer security officer has investigated a possible data...
Question 901: A cyber security administrator receives a list of IPs that h...
Question 902: Ann, the security administrator, wishes to implement multifa...
Question 903: Which of the following access controls enforces permissions ...
Question 904: During the information gathering stage of a deploying role-b...
Question 905: The librarian wants to secure the public Internet kiosk PCs ...
Question 906: Jane, an individual, has recently been calling various finan...
Question 907: Several departments within a company have a business need to...
Question 908: How often, at a MINIMUM, should Sara, an administrator, revi...
Question 909: A major medical corporation is investigating deploying a web...
Question 910: Pete, the system administrator, is reviewing his disaster re...
Question 911: An Information Systems Security Officer (ISSO) has been plac...
Question 912: Which of the following can be utilized in order to provide t...
Question 913: A security administrator examines a network session to a com...
Question 914: Which of the following can be used to maintain a higher leve...
Question 915: A company's Chief Information Officer realizes the company c...
Question 916: Which of the following types of application attacks would be...
Question 917: Several employees submit the same phishing email to the admi...
Question 918: Which of the following would allow users from outside of an ...
Question 919: The datacenter design team is implementing a system, which r...
Question 920: Users in an organization are experiencing when attempting to...
Question 921: A company has had their web application become unavailable s...
Question 922: Which of the following can only be mitigated through the use...
Question 923: A risk management team indicated an elevated level of risk d...
Question 924: Which of the following is the best practice for error and ex...
Question 925: A security analyst has a sample of malicious software and ne...
Question 926: Corporate IM presents multiple concerns to enterprise IT. Wh...
Question 927: Attempting to inject 50 alphanumeric key strokes including s...
Question 928: Which statement is TRUE about the operation of a packet snif...
Question 929: An email client says a digital signature is invalid and the ...
Question 930: Which of the following would a security administrator implem...
Question 931: A security technician has removed the sample configuration f...
Question 932: A security analyst performs the following activities: monito...
Question 933: The internal audit group discovered that unauthorized users ...
Question 934: Joe, an end user, has received a virus detection warning. Wh...
Question 935: Which of the following tests a number of security controls i...
Question 936: Account lockout is a mitigation strategy used by Jane, the a...
Question 937: An organization is implementing a password management applic...
Question 938: Which of the following MOST specifically defines the procedu...
Question 939: Access mechanisms to data on encrypted USB hard drives must ...
Question 940: Verifying the integrity of data submitted to a computer prog...
Question 941: A company is deploying a new video conferencing system to be...
Question 942: Which of the following is an effective way to ensure the BES...
Question 943: Which of the following BEST represents the goal of a vulnera...
Question 944: Which of the following forms of software testing can best be...
Question 945: During a routine audit it is discovered that someone has bee...
Question 946: A company executive's laptop was compromised, leading to a s...
Question 947: The new Chief Information Officer (CIO) of company ABC, Joe ...
Question 948: After visiting a website, a user receives an email thanking ...
Question 949: Which of the following network devices is used to analyze tr...
Question 950: In order for network monitoring to work properly, you need a...
Question 951: Which of the following is a vulnerability associated with di...
Question 952: A user has an Android smartphone that supports full device e...
Question 953: Various network outages have occurred recently due to unappr...
Question 954: Which of the following attacks targets high level executives...
Question 955: A hospital IT department wanted to secure its doctor's table...
Question 956: Which of the following protocols uses TCP instead of UDP and...
Question 957: After Ann, a user, logs into her banking websites she has ac...
Question 958: An administrator is concerned that a company's web server ha...
Question 959: The Chief Information Security Officer (CISO) is concerned t...
Question 960: The security administrator generates a key pair and sends on...
Question 961: Which of the following types of malware, attempts to circumv...
Question 962: Encryption of data at rest is important for sensitive inform...
Question 963: A security manager must remain aware of the security posture...
Question 964: Joe, a network administrator, is setting up a virtualization...
Question 965: Which of the following BEST describes the type of attack tha...
Question 966: Joe, a technician, is tasked with finding a way to test oper...
Question 967: A security manager requires fencing around the perimeter, an...
Question 968: Which of the following would Jane, an administrator, use to ...
Question 969: A company with a US-based sales force has requested that the...
Question 970: Which of the following is considered an environmental contro...
Question 971: Which of the following authentication services uses a ticket...
Question 972: A server crashes at 6 pm. Senior management has determined t...
Question 973: Which of the following should Matt, a security administrator...
Question 974: Which of the following would a security administrator use to...
Question 975: A process in which the functionality of an application is te...
Question 976: An attacker is attempting to insert malicious code into an i...
Question 977: A security administrator is notified that users attached to ...
Question 978: A security administrator develops a web page and limits inpu...
Question 979: After viewing wireless traffic, an attacker notices the foll...
Question 980: Which of the following is the MOST important step for preser...
Question 981: Which of the following MOST interferes with network-based de...
Question 982: Which of the following can be used to mitigate risk if a mob...
Question 983: An insurance company requires an account recovery process so...
Question 984: Which of the following types of security services are used t...
Question 985: Which of the following assessments would Pete, the security ...
Question 986: A chief information officer (CIO) is concerned about PII con...
Question 987: During a disaster recovery planning session, a security admi...
Question 988: Which of the following security benefits would be gained by ...
Question 989: Which of the following concepts is a term that directly rela...
Question 990: An attacker unplugs the access point at a coffee shop. The a...
Question 991: Which of the following authentication services requires the ...
Question 992: A technician has been assigned a service request to investig...
Question 993: Which of the following can be implemented if a security admi...
Question 994: A technician wants to implement a dual factor authentication...
Question 995: A security administrator is responsible for performing perio...
Question 996: It has been discovered that students are using kiosk tablets...
Question 997: A company wishes to prevent unauthorized employee access to ...
Question 998: An employee's mobile device associates with the company's gu...
Question 999: Which of the following is the MOST specific plan for various...
Question 1000: Which of the following is BEST described by a scenario where...
Question 1001: Which of the following results in datacenters with failed hu...
Question 1002: A Human Resources user is issued a virtual desktop typically...
Question 1003: An administrator is assigned to monitor servers in a data ce...
Question 1004: An administrator is investigating a system that may potentia...
Question 1005: A customer service department has a business need to send hi...
Question 1006: An incident response team member needs to perform a forensic...
Question 1007: After working on his doctoral dissertation for two years, Jo...
Question 1008: The information security team does a presentation on social ...
Question 1009: A security technician is working with the network firewall t...
Question 1010: A user has called the help desk to report an enterprise mobi...
Question 1011: A thief has stolen mobile device and removed its battery to ...
Question 1012: Which of the following malware types may require user intera...
Question 1013: A company requires that a user's credentials include providi...
Question 1014: Computer evidence at a crime is preserved by making an exact...
Question 1015: Which of the following has a storage root key?...
Question 1016: Maintenance workers find an active network switch hidden abo...
Question 1017: Several bins are located throughout a building for secure di...
Question 1018: Full disk encryption is MOST effective against the following...
Question 1019: A company has experienced problems with their ISP, which has...
Question 1020: A system administrator is conducting baseline audit and dete...
Question 1021: Which of the following disaster recovery strategies has the ...
Question 1022: The call center supervisor has reported that many employees ...
Question 1023: The incident response team has received the following email ...
Question 1024: A review of administrative access has discovered that too ma...
Question 1025: A company is looking to improve their security posture by ad...
Question 1026: Which of the following will provide data encryption, key man...
Question 1027: An administrator is building a development environment and r...
Question 1028: The method to provide end users of IT systems and applicatio...
Question 1029: An organization must implement controls to protect the confi...
Question 1030: Company XYZ recently salvaged company laptops and removed al...
Question 1031: A technician is reviewing the logical access control method ...
Question 1032: Which of the following technical controls helps to prevent S...
Question 1033: Joe has read and write access to his own home directory. Joe...
Question 1034: An employee reports work was being completed on a company ow...
Question 1035: A large multinational corporation with networks in 30 countr...
Question 1036: The BEST methods for a web developer to prevent the website ...
Question 1037: A user, Ann, has been issued a smart card and is having prob...
Question 1038: Which of the following attacks could be used to initiate a s...
Question 1039: The Quality Assurance team is testing a third party applicat...
Question 1040: A security administrator wants to perform routine tests on t...
Question 1041: A Chief Information Security Officer (CISO) wants to impleme...
Question 1042: A company has just deployed a centralized event log storage ...
Question 1043: The system administrator is reviewing the following logs fro...
Question 1044: A video surveillance audit recently uncovered that an employ...
Question 1045: Which of the following describes the process of removing unn...
Question 1046: Which of the following is true about asymmetric encryption?...
Question 1047: Four weeks ago, a network administrator applied a new IDS an...
Question 1048: A security technician is attempting to improve the overall s...
Question 1049: Ann, a security administrator at a call center, has been exp...
Question 1050: Which device monitors network traffic in a passive manner?...
Question 1051: An administrator is instructed to disable IP-directed broadc...
Question 1052: After recovering from a data breach in which customer data w...
Question 1053: Which of the following provides the LEAST availability?...
Question 1054: A quality assurance analyst is reviewing a new software prod...
Question 1055: Which of the following application security principles invol...
Question 1056: For high availability which of the following would be MOST a...
Question 1057: Which of the following BEST describes disk striping with par...
Question 1058: A network administrator, Joe, arrives at his new job to find...
Question 1059: HOTSPOT Select the appropriate attack from each drop down li...
Question 1060: Joe, a system administrator, receives reports that users att...
Question 1061: Joe, a technician, initiated scans if the company's 10 route...
Question 1062: Which of the following BEST describes a SQL Injection attack...
Question 1063: A new intern was assigned to the system engineering departme...
Question 1064: Which of the following describes how Sara, an attacker, can ...
Question 1065: A cafe provides laptops for Internet access to their custome...
Question 1066: A security technician wants to implement stringent security ...