Success Pack 2026 | Latest Update | Exam Prep
1. What is the primary concern when selecting backup media for a military
installation operating in harsh environmental conditions?
Integrity of backups
Cost of media
Ease of use
Speed of data retrieval
2. If an organization experiences a brute force attack on its administrator
account, which combination of security measures should be prioritized to
enhance protection against future attacks?
Disabling all user accounts temporarily
Installing antivirus software only
Implementing multi-factor authentication and enforcing strong
password policies
Increasing user account privileges for administrators
3. What is the term for the control that restricts employee access to data based
on their assigned customers?
Encryption
Access control
Data integrity
Audit trail
,4. What is the term used to describe the act of creating a fabricated scenario to
obtain sensitive information from individuals in information security?
Pretexting
Vishing
Phishing
Spoofing
5. What is the primary goal of encrypting data in transit?
Confidentiality
Availability
Integrity
Authentication
6. What is the term for the web attack that exploits insufficient input validation?
Cross-Site Scripting
SQL Injection
Phishing
Denial of Service
7. A bank website accepts online loan applications. It requires applicants to
review and sign a disclosure document explaining the organization's
information sharing practices. Which federal law protects consumers' financial
information?
HIPAA
GLBA
, SOX
FERPA
8. What is the primary tool used to identify input validation vulnerabilities in
applications?
Encryption software
Static analysis tool
Antivirus software
Firewall
9. What is the primary purpose of the Secure Socket Layer (SSL)?
To manage user account privileges.
To encrypt data at rest.
To monitor network traffic.
To secure communications over a computer network.
10. Describe the purpose of the PCI DSS regulation in relation to credit card
payment processing.
The PCI DSS regulation focuses on protecting personal health
information in healthcare settings.
The PCI DSS regulation is designed to ensure financial transparency
in publicly traded companies.
The PCI DSS regulation aims to ensure that all companies that
accept, process, store or transmit credit card information maintain
a secure environment.
The PCI DSS regulation governs the protection of personal data for
European citizens.
, 11. AES allows to entities to communicate in a manner that prevents others from
reading the messages passed. This is an example of which form of computer
security?
privacy
integrity
availability
confidentiality
12. Describe how modifying patching procedures can enhance an organization's
information security posture.
Modifying patching procedures solely focuses on data encryption.
Modifying patching procedures increases user account privileges.
Modifying patching procedures is irrelevant to information security.
Modifying patching procedures helps to quickly mitigate
vulnerabilities, reducing the risk of exploitation.
13. Describe how Cross Site Scripting (XSS) can compromise the security of a
web application.
XSS encrypts user data to protect it from unauthorized access.
XSS allows attackers to inject malicious scripts into web pages
viewed by users, potentially stealing sensitive information.
XSS is a method to enhance web application performance.
XSS prevents unauthorized access to user accounts.
14. If a small IT firm implements two-factor authentication for remote customer
access, what potential security risk would be mitigated?