General Security Concepts Assessment Study
Guide (Questions and 100% Correct Answer) |
Brand New Version
1. An organization has tasked a cyber security technician with enhancing its
framework after recently experiencing a cyber breach. What is the value
associated with a public key infrastructure (PKI)?
A. It summates all revoked and suspended certificates and must be
accessible to anyone relying on the validity of Certificate Authority's
certificates.
B. It is a crypto processor implemented as a module within the central
processing unit (CPU) of a computer or mobile device.
C. It is a crypto processor implementing hardware through removable or
dedicated form factors, like plug-in peripheral component
interconnect express adaptor cards.
D. It is the framework that establishes trust in using public key
cryptography to sign and encrypt messages via digital signatures. -
ANSWER D. It is the framework that establishes trust in using public
key cryptography to sign and encrypt messages via digital signatures.
2. A network administrator for a technology company is introducing a new
cybersecurity model to limit data breaches. They wish to enforce a strategy
where every system or user inside or outside the network perimeter must
, prove their legitimacy before accessing resources. What principle would be
MOST effective in implementing their new strategy?
A. Zero Trust
B. Adaptive identity
C. Role-based access control
D. Policy-driven access control - ANSWER A. Zero Trust
3. A software specialist is preparing to integrate new software into the
organization's network. To ensure the compatibility and performance of the
software, the specialist first deploys it in a controlled environment. This
process involves closely monitoring the software's functionality and
checking for any compatibility issues or disruptions it might cause to the
existing system. What concept is the specialist primarily utilizing to verify
that the software operates as expected and is safe for implementation in the
actual network?
A. Impact analysis
B. Backout plan
C. Maintenance windows
D. Test results - ANSWER D. Test results
4. After encountering a cyber attack, an organization uses a monitoring
solution that automatically restarts services after it has detected the system
has crashed. What type of functional security control is the company
implementing?
A. Corrective
B. Compensating
C. Technical
D. Managerial - ANSWER A. Corrective
, 5. How can a cybersecurity analyst effectively utilize version control to
maintain a historical record of changes and ensure security in the
organization's IT systems and applications?
A. Revert to previous versions of documents without assessing their
impact on security.
B. Implement version control only for critical documents and code.
C. Use version control to track changes in network diagrams and
configuration files.
D. Use version control solely for policy updates, neglecting changes to
code. - ANSWER C. Use version control to track changes in network
diagrams and configuration files.
6. A cyber security analyst wants to reduce the attack surface for a computer
that contains top secret data. The analyst installs a central processing unit
(CPU) that contains a crypto processor on the designated computer to
accomplish this. What type of crypto processor is the analyst installing?
A. Certificate Revocation Lists (CRL)
B. Hardware Security Module (HSM)
C. Trusted Platform Module (TPM)
D. Public Key Infrastructure (PKI) - ANSWER C. Trusted Platform
Module (TPM)
7. A company installed a new locking cabinet in the computer room to hold
extra flash drives and other supplies. Which type of security control did the
company configure?