▪Security Engineering (Domain 3)
-exam elaborations with 100% verified answer/solutions-
Excel & Succeed - academic year (2026-2027)
100 Q&A
1. Matthew is the security administrator for a consulting firm and must
enforce access controls that restrict users' access based upon their
previous activity. For example, once a consultant accesses data
belonging to Acme Cola, a consulting client, they may no longer access
data belonging to any of Acme's competitors. What security model best
fits Matthew's needs?
A. Clarke-Wilson
B. Biba
C. Bell-LaPadula
D. Brewer-Nash
D. Brewer-Nash
2.Referring to the figure shown below, what is the earliest stageof a fire
where it is possible to use detection technology to identify it?
TEMPERATURE/TIME
Stage 1: Incipient▪ Stage 2: Smoke ▪Stage 3: Flame ▪Stage 4: Heat
A. Incipient
B. Smoke
C. Flame
D. Heat
A. Incipient
,3. Ralph is designing a physical security infrastructure for a new
computing facility that will remain largely unstaffed. He plans to
implement motion detectors in the facility but would also like to include
a secondary verification control for physical presence. Which one of the
following would best meet his needs?
A. CCTV
B. IPS
C. Turnstiles
D. Faraday cages
A. CCTV
4. Harry would like to retrieve a lost encryption key from a database that
uses m of n control with m = 4 and n = 8. What is the minimum number
of escrow agents required to retrieve the key?
A. 2
B. 4
C. 8
D. 12
B. 4
5.Fran's company is considering purchasing a web-based email service
from a vendor and eliminating its own email serve environment as a
cost-saving measure. What type of cloud computing environment is
Fran's company considering?
A. SaaS
B. IaaS
C. CaaS
D. PaaS
A. SaaS
6. Bob is a security administrator with the federal government and
wishes to choose a digital signature approach that is an approved part
of the federal Digital Signature Standard under FIPS 186-4. Which one of
the following encryption algorithms is not an acceptable choice for use
in digital signature?
A. DSA
B. HAVAL
C. RSA
D. ECDSA
, B. HAVAL
7. Harry who like to access a document owned by Sally and stored on a
file server. Applying the subject/object model to this scenario, who or
what is the subject of the resource request?
A. Harry
B. Sally
C. Server
D. Document
A. Harry
8. Michael is responsible for forensic investigations and investigating a
medium severity security incident that involved the defacement of a
corporate website. The web server in question ran on a virtualization
platform, and the markrting team would like to get the website up and
running as quickly as possible. What would be the most reasonable next
step for Michael to take?
A. Keep the website offline until the investigation is complete.
B. Take the virtualization platform offline as evidence.
C. Take a snapshot of the compromised system and use that for the
investigation.
D. Ignore the incident and focus on quickly restoring the website.
C. Take a snapshot of the compromised system and use that for the
investigation.
9 Helen is a software engineer and is developing code that she would
like to restrict to running within an isolated sandbox for security
purposes. What software development technique is Helen using?
A. Bounds
B. Input validation
C. Confinement
D. TCB
C. Confinement
10. What concept describes the degree of confidence that an
organization has that its controls satisfy security requirements?
A. Trust
B. Credentialing