PROFESSOR MESSER SEC+ PRACTICE EXAM 1
QUESTIONS AND ANSWERS 2024/2025 LATEST
UPDATED A COMPLETE SOLUTION CONTAINS 100%
CORRECT VERIFIED/DETAILED ANSWERS BEST
GRADED A+ FOR SUCCESS
You've hired a third-party to gather information about
your company's servers and data. The third-party will not
have direct access to your internal network but can gather
information from any other source.
Which of the following would BEST describe this
approach?
❍ A. Backdoor testing
❍ B. Passive footprinting
❍ C. OS fingerprinting
❍ D. Partially known environment - CORRECT ANSWERS B.
Which of these protocols use TLS to provide secure
communication? (Select TWO)
❍ A. HTTPS
❍ B. SSH
❍ C. FTPS
❍ D. SNMPv2
❍ E. DNSSEC
❍ F. SRTP - CORRECT ANSWERS A. C.
Which of these threat actors would be MOST likely to
attack systems for direct financial gain?
❍ A. Organized crime
,PROFESSOR MESSER SEC+ PRACTICE EXAM 1
QUESTIONS AND ANSWERS 2024/2025 LATEST
UPDATED A COMPLETE SOLUTION CONTAINS 100%
CORRECT VERIFIED/DETAILED ANSWERS BEST
GRADED A+ FOR SUCCESS
❍ B. Hacktivist
❍ C. Nation state
❍ D. Competitor - CORRECT ANSWERS A.
A security incident has occurred on a file server. Which of
the following data sources should be gathered to address
file storage volatility? (Select TWO)
❍ A. Partition data
❍ B. Kernel statistics
❍ C. ROM data
❍ D. Temporary file systems
❍ E. Process table - CORRECT ANSWERS A. D.
An IPS at your company has found a sharp increase
in traffic from all-in-one printers. After researching,
your security team has found a vulnerability associated
with these devices that allows the device to be remotely
controlled by a third-party. Which category would BEST
describe these devices?
❍ A. IoT
❍ B. RTOS
❍ C. MFD
❍ D. SoC - CORRECT ANSWERS C.
,PROFESSOR MESSER SEC+ PRACTICE EXAM 1
QUESTIONS AND ANSWERS 2024/2025 LATEST
UPDATED A COMPLETE SOLUTION CONTAINS 100%
CORRECT VERIFIED/DETAILED ANSWERS BEST
GRADED A+ FOR SUCCESS
Which of the following standards provides information
on privacy and managing PII?
❍ A. ISO 31000
❍ B. ISO 27002
❍ C. ISO 27701
❍ D. ISO 27001 - CORRECT ANSWERS C.
Elizabeth, a security administrator, is concerned about
the potential for data exfiltration using external storage
drives. Which of the following would be the BEST way
to prevent this method of data exfiltration?
❍ A. Create an operating system security policy to
prevent the use of removable media
❍ B. Monitor removable media usage in host-based
firewall logs
❍ C. Only allow applications that do not use
removable media
❍ D. Define a removable media block rule in the UTM - CORRECT ANSWERS A.
A CISO (Chief Information Security Officer) would
like to decrease the response time when addressing
security incidents. Unfortunately, the company does not
, PROFESSOR MESSER SEC+ PRACTICE EXAM 1
QUESTIONS AND ANSWERS 2024/2025 LATEST
UPDATED A COMPLETE SOLUTION CONTAINS 100%
CORRECT VERIFIED/DETAILED ANSWERS BEST
GRADED A+ FOR SUCCESS
have the budget to hire additional security engineers.
Which of the following would assist the CISO with this
requirement?
❍ A. ISO 27701
❍ B. PKI
❍ C. IaaS
❍ D. SOAR - CORRECT ANSWERS D.
An insurance company has created a set of policies to
handle data breaches. The security team has been given
this set of requirements based on these policies:
• Access records from all devices must be
saved and archived
• Any data access outside of normal working hours
must be immediately reported
• Data access must only occur inside of the country
• Access logs and audit reports must be created from a
single database
Which of the following should be implemented by the
security team to meet these requirements?
(Select THREE)
❍ A. Restrict login access by IP address and
GPS location
QUESTIONS AND ANSWERS 2024/2025 LATEST
UPDATED A COMPLETE SOLUTION CONTAINS 100%
CORRECT VERIFIED/DETAILED ANSWERS BEST
GRADED A+ FOR SUCCESS
You've hired a third-party to gather information about
your company's servers and data. The third-party will not
have direct access to your internal network but can gather
information from any other source.
Which of the following would BEST describe this
approach?
❍ A. Backdoor testing
❍ B. Passive footprinting
❍ C. OS fingerprinting
❍ D. Partially known environment - CORRECT ANSWERS B.
Which of these protocols use TLS to provide secure
communication? (Select TWO)
❍ A. HTTPS
❍ B. SSH
❍ C. FTPS
❍ D. SNMPv2
❍ E. DNSSEC
❍ F. SRTP - CORRECT ANSWERS A. C.
Which of these threat actors would be MOST likely to
attack systems for direct financial gain?
❍ A. Organized crime
,PROFESSOR MESSER SEC+ PRACTICE EXAM 1
QUESTIONS AND ANSWERS 2024/2025 LATEST
UPDATED A COMPLETE SOLUTION CONTAINS 100%
CORRECT VERIFIED/DETAILED ANSWERS BEST
GRADED A+ FOR SUCCESS
❍ B. Hacktivist
❍ C. Nation state
❍ D. Competitor - CORRECT ANSWERS A.
A security incident has occurred on a file server. Which of
the following data sources should be gathered to address
file storage volatility? (Select TWO)
❍ A. Partition data
❍ B. Kernel statistics
❍ C. ROM data
❍ D. Temporary file systems
❍ E. Process table - CORRECT ANSWERS A. D.
An IPS at your company has found a sharp increase
in traffic from all-in-one printers. After researching,
your security team has found a vulnerability associated
with these devices that allows the device to be remotely
controlled by a third-party. Which category would BEST
describe these devices?
❍ A. IoT
❍ B. RTOS
❍ C. MFD
❍ D. SoC - CORRECT ANSWERS C.
,PROFESSOR MESSER SEC+ PRACTICE EXAM 1
QUESTIONS AND ANSWERS 2024/2025 LATEST
UPDATED A COMPLETE SOLUTION CONTAINS 100%
CORRECT VERIFIED/DETAILED ANSWERS BEST
GRADED A+ FOR SUCCESS
Which of the following standards provides information
on privacy and managing PII?
❍ A. ISO 31000
❍ B. ISO 27002
❍ C. ISO 27701
❍ D. ISO 27001 - CORRECT ANSWERS C.
Elizabeth, a security administrator, is concerned about
the potential for data exfiltration using external storage
drives. Which of the following would be the BEST way
to prevent this method of data exfiltration?
❍ A. Create an operating system security policy to
prevent the use of removable media
❍ B. Monitor removable media usage in host-based
firewall logs
❍ C. Only allow applications that do not use
removable media
❍ D. Define a removable media block rule in the UTM - CORRECT ANSWERS A.
A CISO (Chief Information Security Officer) would
like to decrease the response time when addressing
security incidents. Unfortunately, the company does not
, PROFESSOR MESSER SEC+ PRACTICE EXAM 1
QUESTIONS AND ANSWERS 2024/2025 LATEST
UPDATED A COMPLETE SOLUTION CONTAINS 100%
CORRECT VERIFIED/DETAILED ANSWERS BEST
GRADED A+ FOR SUCCESS
have the budget to hire additional security engineers.
Which of the following would assist the CISO with this
requirement?
❍ A. ISO 27701
❍ B. PKI
❍ C. IaaS
❍ D. SOAR - CORRECT ANSWERS D.
An insurance company has created a set of policies to
handle data breaches. The security team has been given
this set of requirements based on these policies:
• Access records from all devices must be
saved and archived
• Any data access outside of normal working hours
must be immediately reported
• Data access must only occur inside of the country
• Access logs and audit reports must be created from a
single database
Which of the following should be implemented by the
security team to meet these requirements?
(Select THREE)
❍ A. Restrict login access by IP address and
GPS location