Examination Questions And Correct
Answers (Verified Answers) Plus
Rationales 2026 Q&A | Instant
Download Pdf
Q1. Which security principle ensures that users are granted only the minimum
access necessary to perform their job functions?
A. Defense in depth
B. Least privilege
C. Separation of duties
D. Zero trust
Correct Answer: B
Rationale: Least privilege limits user access rights to only what is required for
their role, reducing attack surface and minimizing potential damage from
compromised accounts or insider threats.
Q2. Which of the following BEST describes a zero trust architecture?
A. Trust internal users by default
B. Trust based on physical location
C. Verify every access request regardless of source
D. Trust authenticated VPN users automatically
Correct Answer: C
,Rationale: Zero trust assumes no implicit trust in any user or device, requiring
continuous verification of identity, device posture, and context before granting
access to resources.
Q3. What is the PRIMARY purpose of a Security Information and Event
Management (SIEM) system?
A. Encrypt network traffic
B. Manage firewalls
C. Collect and correlate security logs
D. Patch vulnerabilities automatically
Correct Answer: C
Rationale: SIEM systems aggregate and analyze logs from multiple sources to
detect anomalies, correlate events, and support incident response and
compliance reporting.
Q4. Which risk treatment strategy involves transferring risk to a third party?
A. Mitigation
B. Acceptance
C. Avoidance
D. Transfer
Correct Answer: D
Rationale: Risk transfer shifts responsibility to another entity, such as through
insurance or outsourcing, reducing the organization's direct exposure to the risk.
Q5. Which cryptographic technique ensures data integrity?
A. AES encryption
B. Hashing
C. Symmetric encryption
,D. Tokenization
Correct Answer: B
Rationale: Hashing produces a fixed-size digest of data, allowing verification
that data has not been altered without revealing the original content.
Q6. What is the main goal of a penetration test?
A. Monitor network traffic
B. Identify and exploit vulnerabilities
C. Install security patches
D. Configure firewalls
Correct Answer: B
Rationale: Penetration testing simulates real-world attacks to identify
exploitable vulnerabilities and assess the effectiveness of security controls.
Q7. Which protocol provides secure remote shell access?
A. FTP
B. Telnet
C. SSH
D. SNMP
Correct Answer: C
Rationale: SSH encrypts session data, providing secure remote administration
and protecting credentials and commands from interception.
Q8. What is a key characteristic of symmetric encryption?
A. Uses two different keys
B. Slower than asymmetric encryption
C. Uses the same key for encryption and decryption
D. Requires certificates
Correct Answer: C
, Rationale: Symmetric encryption uses a single shared key for both encryption
and decryption, making it fast but requiring secure key distribution.
Q9. Which attack exploits weaknesses in authentication systems by trying many
password combinations?
A. Phishing
B. Brute force attack
C. SQL injection
D. Man-in-the-middle
Correct Answer: B
Rationale: Brute force attacks systematically attempt multiple password
combinations until the correct one is found, often targeting weak or reused
passwords.
Q10. What does a Digital Signature provide?
A. Confidentiality only
B. Integrity and authenticity
C. Availability
D. Compression
Correct Answer: B
Rationale: Digital signatures verify the sender's identity and ensure that data
has not been altered, providing both authenticity and integrity.
Q11. Which cloud model provides infrastructure resources like virtual machines
and storage?
A. SaaS
B. PaaS
C. IaaS