QUESTION AND ANSWERS VERIFIED
TO PASS 2026/2027
Which of the following BEST describes an unknown penetration test? - correct answer ✔The
penetration tester has no information regarding the target or network.
Which type of test simulates an insider threat by giving the tester partial information about the network
and computer systems? - correct answer ✔Partially known
Which type of testing is typically done by an internal tester who has full knowledge of the network,
computer system, and infrastructure? - correct answer ✔Known
Threats are usually ranked from high to low. A higher number indicates a dangerous threat. A lower
number indicates threats that may be annoyances but aren't necessarily malicious in nature. What is
this high-to-low scale known as? - correct answer ✔Confidence level
There are five phases in the security intelligence life cycle. During which phase do you gather and
process information from your internal sources, such as system and application logs? - correct answer
✔Collection
Which type of intelligence helps security professionals respond to incidents or make decisions on the
spot? - correct answer ✔Tactical intelligence
Sophisticated attacks executed by highly skilled hackers with a specific target or objective in mind are
classified as which type of threat? - correct answer ✔Advanced persistent threat
Threats that do not have an existing fix, do not have any security fixes, and do not have available
patches are called what? - correct answer ✔Zero-day threats
,Miguel has been practicing his hacking skills. He has discovered a vulnerability on a system that he did
not have permission to attack. Once Miguel discovered the vulnerability, he anonymously alerted the
owner and instructed them on how to secure the system. Which type of hacker is Miguel in this
scenario? - correct answer ✔Semi-authorized
Threat actors can be divided into different types based on their methods and motivations. Which type of
hacker usually targets government agencies, corporations, or other entities they are protesting? -
correct answer ✔Hacktivist
During which phase of the Kill Chain framework does an intruder extract or destroy data? - correct
answer ✔Action on Objectives
Which of the following is true about confidence levels in the intrusion analysis Diamond Model? -
correct answer ✔The higher the value, the higher the confidence.
What seven-phase framework did Lockheed Martin develop to identify an attacker's step-by-step attack
process? - correct answer ✔Kill Chain
Which framework includes the Reconnaissance, Weaponization, Delivery, Exploitation, Installation,
Command and Control, and Actions on Objectives phases? - correct answer ✔Kill Chain
During which phase of the Kill Chain framework is malware code encapsulated into commonly used file
formats, such as PDF files, image files, or Word documents? - correct answer ✔Weaponization
An impact analysis evaluates the cost of an attack. Which of the following would be considered a non-
financial cost? - correct answer ✔Customer satisfaction
Reputation
,Which threat modeling component identifies potential threat sources, what these adversaries can do,
and how likely these attacks are? - correct answer ✔Adversary capability analysis
Which threat modeling measurement is used to describe how an attack can exploit a vulnerability? -
correct answer ✔Attack vector
Which security function reacts quickly and efficiently after an issue has been detected? - correct answer
✔Incident response
Which security function identifies and evaluates threats in hopes of reducing their impact? - correct
answer ✔Risk management
A list of actions and objectives taken to mitigate risk is known as a: - correct answer ✔Framework
What do partial, risk-informed, repeatable, and adaptive achievements indicate? - correct answer
✔How core functions align with an organization's risk management procedures
Which items are included in an acceptable use policy? (Select two.) - correct answer ✔Expectations
for user privacy when using company resources
How information and network resources should be used
Which items should be included in data retention standards? (Select two.) - correct answer ✔How
data should be destroyed
How long to store data
Which type of framework is fairly rigid and requires that specific controls be implemented? - correct
answer ✔Prescriptive
, COBIT, ITIL, and ISO are examples of which type of framework? - correct answer ✔Prescriptive
Restoring data from backup is an example of which type of security control? - correct answer
✔Compensating
Which type of security control identifies, logs, and reports incidents as they happen? - correct answer
✔Detective
Which security control category controls system oversight? - correct answer ✔Managerial
Attackers often target data and intangible assets. Identify what hackers may do with the information
they collect. (Select two.) - correct answer ✔Sell the data to the competition
Harm a company's reputation
An organization's user data server is backed up daily. Referencing the CIA triad, this is an example of
which of the following? - correct answer ✔Availability
What do each of the letters represent in the CIA triad? (Select three.) - correct answer
✔Confidentiality
Integrity
Availability
Access to a database is protected by multi-factor authentication. In the CIA triad, this is an example of
which of the following? - correct answer ✔Confidentiality