<< Prev Question Next Question >>

Question 28/172

Which layer provides services directly to the user?

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (172q)
Question 1: Which threat is directly associated with malware?...
Question 2: Load balancing primarily safeguards which CIA triad element?...
Question 3: In what way do a victim's files get affected by ransomware?...
Question 4: Which scenario best represents defense in depth?...
Question 5: Who should participate in creating a Business Continuity Pla...
Question 6: Communication between end systems is encrypted using a key, ...
Question 7: To avoid bodily injury claims, a company decides not to offe...
Question 8: A company network experiences a sudden flood of network pack...
Question 9: The method of distributing network traffic equally across a ...
Question 10: Which is related to standards?
Question 11: Which type of attack takes advantage of vulnerabilities in v...
Question 12: Scans networks to determine connected devices and services:...
Question 13: What is the focus of disaster recovery planning after a data...
Question 14: An entity that exploits system vulnerabilities is known as a...
Question 15: Who must follow HIPAA compliance?...
Question 16: Selvaa presents a user ID and password to log on. Which char...
Question 17: Which is the first step in the risk management process?...
Question 18: A one-way spinning door or barrier that allows only one pers...
Question 19: What is the difference between Business Continuity Planning ...
Question 20: An ISC2 member is offered an illicit copy of a movie. What s...
Question 21: Which is a component of a Business Continuity (BC) plan?...
Question 22: A hacker launches a specific attack to exploit a known vulne...
Question 23: Which one of the following cryptographic algorithms does NOT...
Question 24: A company wants to prevent employees from bringing unauthori...
Question 25: What cybersecurity principle focuses on granting users only ...
Question 26: Shaun is planning to protect data in all states (at rest, in...
Question 27: An attack in which an attacker listens passively to the auth...
Question 28: Which layer provides services directly to the user?...
Question 29: Which phase of the access control process (AAA) does a user ...
Question 30: Removing the belief that a network has any trusted space and...
Question 31: Which type of risk involves unauthorized use or disclosure o...
Question 32: What does internal consistency of information refer to?...
Question 33: The prevention of authorized access to resources or delaying...
Question 34: Which of the following is unlikely to be a member of the dis...
Question 35: A type of malware capable of self-propagation and infecting ...
Question 36: Which uses encrypted, machine-generated codes to verify a us...
Question 37: A backup is which type of security control?...
Question 38: What doescriticalityrepresent?
Question 39: The first phase of the System Development Life Cycle (SDLC) ...
Question 40: Why is the recovery of IT often crucial to the recovery and ...
Question 41: What security feature is used in HTTPS?...
Question 42: What is the primary goal of network segmentation in cybersec...
Question 43: What kind of control is it when we add a backup firewall tha...
Question 44: Which element of the security policy framework includes reco...
Question 45: Which access control method uses attributes and rules evalua...
Question 46: A method for risk analysis that is based on the assignment o...
Question 47: Which document identifies the principles and rules governing...
Question 48: The means by which a threat actor carries out their objectiv...
Question 49: Which IR phase involves identifying critical data and system...
Question 50: Which regulation addresses personal privacy?...
Question 51: Information should be consistently and readily accessible fo...
Question 52: A measure of the degree to which an organization depends on ...
Question 53: Malware that disguises itself as legitimate software is call...
Question 54: An event that jeopardizes confidentiality, integrity, or ava...
Question 55: Exhibit. (Exhibit) What is the purpose of a Security Informa...
Question 56: The common term for systems that control temperature and hum...
Question 57: Which of the following is a characteristic of cloud computin...
Question 58: Which access control model grants permissions based ondata s...
Question 59: Which access control model can grant access to a given objec...
Question 60: A company wants to ensure that its employees can evacuate th...
Question 61: Representation of data at OSI Layer 3 is called a:...
Question 62: How do you distinguish authentication and identification?...
Question 63: An unknown person obtains unauthorized access to the company...
Question 64: A set of rules that everyone must comply with and that usual...
Question 65: Difference between sniffing and spoofing:...
Question 66: Created by switches to logically segment a network without c...
Question 67: Why is security training important?...
Question 68: XenServer, LVM, Hyper-V, and ESXi are:...
Question 69: What is the most important aspect of security awareness and ...
Question 70: Which activity is often associated with Disaster Recovery ef...
Question 71: A curated knowledge base modeling adversary behavior across ...
Question 72: Which prevents threats?
Question 73: What is meant by non-repudiation?...
Question 74: How do IT professionals differentiate between IT problems an...
Question 75: An employee launched a privilege escalation attack to gain r...
Question 76: What is the range of well-known ports?...
Question 77: A way to prevent unwanted devices from connecting to a netwo...
Question 78: Who is responsible for publishing and signing the organizati...
Question 79: Which OSI layer associates MAC addresses with network device...
Question 80: Which protocol is used for secure email?...
Question 81: The practice of sending fraudulent communications that appea...
Question 82: A team activates procedures to mitigate a cyberattack. What ...
Question 83: In incident terminology, a zero-day is:...
Question 84: What is the focus of disaster recovery planning after a data...
Question 85: A company's governing board decides that only legal services...
Question 86: Which version of TLS is considered the most secure and recom...
Question 87: A security event in which an intruder gains or attempts unau...
Question 88: An employee launched a privilege escalation attack to gain r...
Question 89: David's team recently implemented a new system that gathers ...
Question 90: Finance Server and Transaction Server have restored their or...
Question 91: Which authentication enables automatic identification across...
Question 92: A company experiences a major IT outage and cannot perform c...
Question 93: Raj wants aphysical deterrent controlto discourage unauthori...
Question 94: Which security measure helps prevent Cross-Site Scripting (X...
Question 95: A tool used to inspect outbound traffic to reduce threats:...
Question 96: A popular way of implementing the principle of least privile...
Question 97: A measure combining impact and likelihood is known as:...
Question 98: The documented set of procedures to detect, respond to, and ...
Question 99: Which is the most efficient and effective way to test a busi...
Question 100: Which type of control minimizes the impact of an attack and ...
Question 101: The concept of integrity applies to:...
Question 102: Which organization defines Internet protocol standards?...
Question 103: Limiting access based on data sensitivity and user authoriza...
Question 104: Which provides integrity services that allow a recipient to ...
Question 105: What is remanence?
Question 106: An unusual occurrence in a system or network is best describ...
Question 107: During an ISC2 CC exam, you observe another candidate cheati...
Question 108: A centralized organizational function that monitors, detects...
Question 109: Ping flood attacks target which OSI layer?...
Question 110: Exhibit. (Exhibit) What is the PRIMARY purpose of a web appl...
Question 111: Common network device used to connect networks?...
Question 112: If a device is found to be non-compliant with the security b...
Question 113: What is the main challenge in achieving non-repudiation in e...
Question 114: The last phase in the data security lifecycle is:...
Question 115: What is the first step in incident response planning?...
Question 116: Which is a component of a Business Continuity (BC) plan?...
Question 117: A security model where no network is trusted by default is c...
Question 118: Methods or mechanisms used to gain unauthorized access are c...
Question 119: Which cloud service model provides the most suitable environ...
Question 120: COVID-19 is an example where which plan sustains business?...
Question 121: A DDoS attack affects which OSI layers?...
Question 122: Access control used in high-security military and government...
Question 123: A DDoS attack flooding ICMP packets is called:...
Question 124: Networks that are heavily microsegmented with firewalls at c...
Question 125: Which addresses are reserved for internal network use and ar...
Question 126: An organization develops procedures to restore critical busi...
Question 127: What is the difference between BCP and DRP?...
Question 128: The order of controls used in defense in depth:...
Question 129: Port scanning attacks target which OSI layer?...
Question 130: The process of applying secure configurations to reduce the ...
Question 131: What is sensitivity in the context of confidentiality?...
Question 132: Exhibit. (Exhibit) What kind of vulnerability is typically n...
Question 133: The prevention of authorized access to resources or the dela...
Question 134: A device that forwards traffic to the port of a known destin...
Question 135: Which is the loopback address?
Question 136: Removing the design belief that the network has any trusted ...
Question 137: After an earthquake disrupts business operations, which docu...
Question 138: Is defined as the process of identifying, estimating, and pr...
Question 139: What is the recommended temperature range for optimal data c...
Question 140: An attack in which a user authenticated to a server unknowin...
Question 141: What is knowledge-based authentication?...
Question 142: Events with negative consequences such as crashes, floods, d...
Question 143: What does the term "Two-factor authentication" refer to in c...
Question 144: A company wants employees to access resources from anywhere ...
Question 145: What is the primary purpose of a firewall?...
Question 146: Which document provides a high-level overview of a Disaster ...
Question 147: Port used by DNS.
Question 148: Dylan is creating a cloud architecture that requires connect...
Question 149: Which security control is designed to prevent unauthorized a...
Question 150: What is the primary factor in the reliability of information...
Question 151: Natalia is concerned that users on her network may be storin...
Question 152: Which plan is activated when Incident Response and BCP fail?...
Question 153: Faking the sender address of a transmission to gain illegal ...
Question 154: Configuration settings or parameters stored as data and mana...
Question 155: What is the highest priority during incident response?...
Question 156: Which fire suppression system is more friendly to electronic...
Question 157: Activities necessary to restore IT and communications servic...
Question 158: Which document serves as specifications for implementing pol...
Question 159: Which of the following best describes a zero-day vulnerabili...
Question 160: A ________ creates an encrypted tunnel to protect your perso...
Question 161: Which protocol would be most suitable to fulfill the secure ...
Question 162: What is the main objective of DRP after a breach shuts down ...
Question 163: VLAN hopping belongs to which OSI layer?...
Question 164: How many bits represent the Organizationally Unique Identifi...
Question 165: David is worried about distributed denial-of-service (DDoS) ...
Question 166: Flooding a server with traffic to make services unavailable ...
Question 167: Juli is listening to network traffic and capturing passwords...
Question 168: Which of these tools is commonly used to crack passwords?...
Question 169: Configuration settings or parameters stored as data and mana...
Question 170: Mark is configuring an automated data transfer between two h...
Question 171: Security controls protecting against fire, floods, and earth...
Question 172: Exhibit. (Exhibit) information security is not built on whic...