WGU C845 Questions with complete solutions
A+ Guaranteed
1. Ben is concerned about exploits that allow VM escape. What option should
Ben suggest to help limit the impact of VM escape exploits?
A. Separate virtual machines onto separate physical hardware based on
task or data types.
B. Use VM escape detection tools on the underlying hypervisor.
C. Restore machines to their original snapshots on a regular basis.
D. Use a utility like Tripwire to look for changes in the virtual machines.
- ANSWER A. While virtual machine escape has been demonstrated
only in lab environments, the threat is best dealt with by limiting what
access to the underlying hypervisor can prove to a successful tracker.
Segmenting by data types or access levels can limit the potential
impact of a hypervisor compromise.
2. Ben is an information security professional at an organization that is
replacing its physical servers with virtual machines. As the organization
builds its virtual environment, it is decreasing the number of physical servers
it uses while purchasing more powerful servers to act as the virtualization
platforms.
3. The IDS Ben is responsible for is used to monitor communications in the
data center using a mirrored port on the data center switch. What traffic will
Ben see once the majority of servers in the data center have been
virtualized?
A. The same traffic he currently sees
B. All inter-VM traffic
C. Only traffic sent outside of the VM environment
D. All inter-hypervisor traffic - ANSWER C. One of the visibility risks
of virtualization is that communication between servers and systems
using virtual interfaces can occur "inside" the virtual environment.
This means that visibility into traffic in the virtualization environment
has to be purpose-built as part of its design.
, 2
4. Ben is an information security professional at an organization that is
replacing its physical servers with virtual machines. As the organization
builds its virtual environment, it is decreasing the number of physical servers
it uses while purchasing more powerful servers to act as the virtualization
platforms.
5. The VM administrators recommend enabling cut and paste between virtual
machines. What security concern should Ben raise about this practice?
A. It can cause a denial of service condition.
B. It can serve as a covert channel.
C. It can allow viruses to spread.
D. It can bypass authentication controls. - ANSWER B. Cut and paste
between virtual machines can bypass normal network-based data loss
prevention tools and monitoring tools like IDS and/or IPS. Thus, it
can act as a covert channel, allowing the transport of data between
security zones.
6. In an infrastructure as a service (IaaS) environment where a vendor supplies
a customer with access to storage services, who is normally responsible for
removing sensitive data from drives that are taken out of service? -
ANSWER In an infrastructure as a service environment, security duties
follow a shared responsibility model. Since the vendor is responsible for
managing the storage hardware, the vendor would retain responsibility for
destroying or wiping drives as they are taken out of service.
7. In a software as a service cloud computing environment, who is normally
responsible for ensuring that appropriate firewall controls are in place to
protect the application? - ANSWER In a software as a service environment,
the customer has no access to any underlying ifrastructure, so firewall
management is a vendor responsibility under the cloud computing share
responsibility model.
8. Henry wants to ensure resilience for data that is being actively processed in
his organization's cloud environment. Which of the following techniques is
best suited to ensuring that transactions will not be lost if a cloud-hosted
system or container fails during processing?
A. Building retry operations into applications
B. Using a load balancer
, 3
C. Using a cluster
D. Using a CDN - ANSWER A. Resilience on a transactional level is
best accomplished at the application level. Load balancers and clusters
can ensure that a single failed container or system does not interrupt
processing, but first the application or service must know to try again
if it does not get a proper or timely response. A content delivery
network (CDN) is useful for ensuring that failures of web servers or
denial-of-service conditions do not prevent a site or service from
responding.
9. During what phase of the change management process does the organization
conduct peer review of the change for accuracy and completeness? -
ANSWER Analysis/Impact Assessment
10.Steve is responsible for work stations that handle proprietary information.
What is the best option for these workstations at the end of their lifecycle? -
ANSWER Sanitization
11.What is the earliest stage of a fire to use detection technology to identify it? -
ANSWER Incipient
12.What security control would provide the best defense against a threat actor
trying to execute a buffer overflow attack against a custom application? -
ANSWER Parameter Checking/Input Validation
13.Which of the following is NOT true of the ISC2 Code of Ethics?
A. Adherence to the Code of Ethics is a condition of Certification
B. The code of ethics applies to all security professionals
C. Failure to comply with the Code of Ethics could result in revocation
of certification
D. Members who observe a breach of the Code of Ethics are required to
report the possible violation - ANSWER B.
14.Under what type of software license does the recipient of software have an
unlimited right to copy, modify, distribute, or resell a software package? -
ANSWER Public Domain
15.What should Steve do if a FAR/FRR diagram does not provide an acceptable
performance level for his organization's needs? - ANSWER Assess other
, 4
biometric systems to compare them since the CER is used to assess
biometric devices.
16.What is the CER in biometric device measurment? - ANSWER Crossover
Error Rate is the number that results when a biometric device is adjusted to
provide equal false acceptance and false rejection rates.
17.What type of access control would be the best choice for a person that would
like to support a declaration like "Only allow access to customer service on
managed devices on the wireless network between 8 am and 7 pm"? -
ANSWER Attribute Based Access Control ABAC
18.What is the benefit of an ABAC over a RBAC? - ANSWER An ABAC can
be more specific thus more flexible
19.What is the primary advantage of decentralized access control? - ANSWER
It provides control of access to people closer to the resources
20.How are rules set in ABAC systems? - ANSWER Uses boolean logic
statements which allow it to be more flexible than RBAC for temporary
rules such as to allow time limited access.
21.Which of the following is best described as an access control model that
focuses on subjects and identifies the objects that each subject can access?
A. Access control list
B. Capability Table
C. Implicit denial list
D. Rights Management Matrix - ANSWER B
22.Adam is accessing a standalone file server using a username and password
provided by the server administrator. Which one of the following entities is
guaranteed to have information necessary to complete the authorization
process?
A. File Server
B. Adam
C. Server Administrator
D. Adam's Supervisor - ANSWER A. The file server has the correct
information on what activities Adam is AUTHORIZED to perform