(MindTap Course List) 4th Edition (Chapters 1-67) Questions and
Answers with Rationale |Grade A+
Dion Training has performed an assessment as part of their disaster recovery planning. The assessment
found that the organization's RAID takes, on average, about 8 hours to repair when two drives within the
RAID fail. Which of the following metrics would best represent this time period?
A. MTTR
b. RTO
c. MTBF
d. RPO
Dion Training has performed an assessment as part of their disaster recovery planning. The assessment
found that their file server has crashed twice in the last two years. The most recent time was in August, and
the time before that was 15 months before. Which of the following metrics would best represent this 15
month time period?
a. RTO
b. MTTR
c. RPO
D. MTBF
Consider the following snippet from a log file collected on the host with the IP address of 10.10.3.6. What
type of activity occurred based on the output above?
a. port scan targeting 10.10.3.2
B. port scan targeting 10.10.3.6
c. Denial of Service on 10.10.3.6
d. Fragmentation attack on 10.10.3.6
Dion Training wants to install a new accounting system and is considering moving to a cloud-based solution
to reduce cost, reduce the information technology overhead costs, improve reliability, and improve
availability. Your Chief Information Officer is supportive of this move since it will be more fiscally
responsible. Still, the Chief Risk Officer is concerned with housing all of the company's confidential financial
data in a cloud provider's network that might be shared with other companies. Since the Chief Information
Officer is determined to move to the cloud, what type of cloud-based solution would you recommend to
account for the Chief Risk Officer's concerns?
a. PaaS in hybrid cloud
b. PaaS in community cloud
1|Page
,C. SaaS in a private cloud
d. SaaS in public cloud
You received an incident response report indicating a piece of malware was introduced into the company's
network through a remote workstation connected to the company's servers over a VPN connection. Which
of the following controls should be applied to prevent this type of incident from occurring again?
a. ACL
B. NAC
c. SPF
d. MAC filtering
A user reports that every time they try to access https://www.diontraining.com, they receive an error
stating "Invalid or Expired Security Certificate." The technician attempts to connect to the same site from
other computers on the network, and no errors or issues are observed. Which of the following settings
needs to be changed on the user's workstation to fix the "Invalid or Expired Security Certificate" error?
A. Date and Time
b. User Access Control
c. UEFI boot mode
d. Logon times
You have noticed some unusual network traffic outbound from a certain host. The host is communicating
with a known malicious server over port 443 using an encrypted TLS tunnel. You ran a full system anti-virus
scan of the host with an updated anti-virus signature file, but the anti-virus did not find any infection signs.
Which of the following has MOST likely occurred?
a. Password spraying
b. Directory traversal
c Session hijacking
D. Zero-day attack
A company's NetFlow collection system can handle up to 2 Gbps. Due to excessive load, this has begun to
approach full utilization at various times of the day. If the security team does not have additional money in
their budget to purchase a more capable collector, which of the following options could they use to collect
useful data?
a. Enable QoS
b. Enable NetFlow compression
C. Enable sampling of the data
d. Enable full packet capture
2|Page
,Your organization requires the use of TLS or IPsec for all communications with an organization's network.
Which of the following is this an example of?
a. DLP
b. Data at rest
C. Data in transit
d. Data in use
(Sample Simulation - On the real exam for this type of question, you would have access to the log files to
determine which server on a network might have been affected, and then choose the appropriate actions.)
A cybersecurity analyst has determined that an attack has occurred against your company's network.
Fortunately, your company uses a good logging system with a centralized Syslog server, so all the logs are
available, collected, and stored properly. According to the cybersecurity analyst, the logs indicate that the
database server was the only company server on the network that appears to have been attacked. The
network is a critical production network for your organization. Therefore, you have been asked to choose
the LEAST disruptive actions on the network while performing the appropriate incident response actions.
Which actions do you recommend as part of the response efforts?
a. Conduct a system restore of the database server, image the hard drive, and maintain chain of custody.
b. Isolate the affected server from the network immediately, format database server, reinstall from a known
good backup
c. Immediately remove the database server from the network, create an image of its hard disk, and maintain
chain of custody.
D. Capture network traffic sing a sniffer, schedule a period of downtime to image and remediate the affected
server, and maintain chain of custody.
Which of the following types of attacks are usually used as part of an on-path attack?
a. Tailgating
b. DDOS
C. Spoofing
d. Brute force
You have just received a phishing email disguised to look like it came from
asking you to send your username and password because your account has been locked out due to
inactivity. Which of the following social engineering principles is being used in this email?
A. Trust
b. Intimidation
c. Urgency
d. Consensus
3|Page
, Your company has decided to move all of its data into the cloud. Your company is concerned about the
privacy of its data due to some recent data breaches that have been in the news. Therefore, they have
decided to purchase cloud storage resources that will be dedicated solely for their use. Which of the
following types of clouds is your company using?
A. Private
b. Hybrid
c. Public
d. Community
You just moved into a new house, and you are worried about a burglar breaking into the home and stealing
your laptop. Unfortunately, the security alarm company cannot get to your home to install the security
system you just purchased for another 3 weeks. In the meantime, they have sent you a little sign that says,
"Protected by Security Inc." for you to place in front of your house. Once installed, which of the following
control types is this sign?
a. Detective
B. Deterrent
c. Corrective
d. Preventative
Dion Training wants to ensure that none of its computers can run a peer-to-peer file-sharing program on its
office computers. Which of the following practices should be implemented to achieve this?
a. Application allow listing
B. Application block listing
c. MAC filtering
d. Enable NAC
Praveen is currently investigating activity from an attacker who compromised a host on the network. The
individual appears to have used credentials belonging to a janitor. After breaching the system, the attacker
entered some unrecognized commands with very long text strings and then began using the sudo command
to carry out actions. What type of attack has just taken place?
a. Social engineering
B. Privilege escalation
c. Phishing
d. Session hijacking
Which type of agreement between companies and employees is used as a legal basis for protecting
information assets?
4|Page