D488-STUDY GUIDE
EXAM LATEST QUESTIONS
AND VERIFIED CORRECT
ANSWERS GRADED A+
RSA - CORRECT ANSWER-Uses prime factorization to generate public and private encryption and
decryption keys
Diffie-Hellman (DH) - CORRECT ANSWER-A key exchange protocol that allows two parties to
securely generate a shared secret key over an insecure channel
Message Authentication Code - CORRECT ANSWER-Confirms the stated identity of the sender
and provides integrity of the message without the need to use any other means
HMAC - CORRECT ANSWER-Confirms identity of sender and integrity using hash values
Cipher Block Chaining (CBC) - CORRECT ANSWER-A process in which each block of unencrypted
text is combined with the block of cipher text immediately preceding it before it is encrypted
using the DES algorithm.
Poly1305 - CORRECT ANSWER-Provides increased speed and efficiency creating MAC, by
utilizing alternative encryption algorithms
Salsa20 - CORRECT ANSWER-Idk
Relational - CORRECT ANSWER-are very widely implemented and designed to support ACID transactions.
,Key-value - CORRECT ANSWER-are optimized to store and retrieve large volumes of data. It offers high-performance under heavy workloads.
In-memory - CORRECT ANSWER-offer real-time access to data and access to applications with microsecond latency.
Document - CORRECT ANSWER-enable developers to build applications quickly by storing data in a semi-structured manner.
Wide-column - CORRECT ANSWER-are a type of NoSQL database.
Graph - CORRECT ANSWER-are designed to support applications that query millions of relationships between highly connected datasets, such as social media
platforms.
Time series - CORRECT ANSWER-are focused on supporting applications that analyze data that evolves and changes over time and is best represented using time
intervals such as in an industrial setting.
Ledger - CORRECT ANSWER-enable a trusted and verifiable authority to support banking transactions and systems of record.
Whitelisting ensures that only approved applications can be installed and executed on company
laptops.
What should a business use to provide non-repudiation for emails between employees?
A - TLS/SSL
B - AES-256
C - S/MIME
D - IPSec - CORRECT ANSWER-C - S/MIME (Secure/Multipurpose Internet Mail Extensions)
S/MIME provides non-repudiation for emails by using digital signatures.
,Which strategy is appropriate for a risk management team to determine if a business has
insufficient security controls?
A - Qualitative assessment
B - Gap assessment
C - Quantitative risk assessment
D - Impact assessment - CORRECT ANSWER-B - Gap assessment
A gap assessment identifies the gaps between the current security control and the desired or
required levels of security.
An organization has leased office space that is suitable for its computer equipment so personnel
and systems can be relocated if the main office location is unavailable. It currently has some
equipment. Which type of site is the organization using?
A - Cold site
B - Warm site
C - Hot site
D - Mobile site - CORRECT ANSWER-B - Warm site
A warm site is a disaster recovery site that provides a partially equipped facility that can be used
to restore critical operations faster than having no equipment at all.
A risk assessment consultant is discussing segmentation options with a client. What are a few
standard options the consultant could offer? Select the best 2 answers.
A - VLANs
B - Transmission Control
C - Physical
D - Access control lists - CORRECT ANSWER-A & C; VLANs & Physical
, A network device can perform segmentation logically, for example, implementing virtual local
area networks (VLANs). A system can bypass VLANs if an attacker gains access to a trunk port
where all VLANs can talk.
Physical segmentation is another type of segmentation more commonly found in industrial
control systems (ICS) and supervisory control and data acquisition (SCADA) networks. This is
where, traditionally, there is an IT and OT (operational technology) network.
Transmission control is not a type of segmentation. Transmission control defines how a system
protects communication channels from infiltration, exploitation, and interception.
Access control lists (ACLs) are used to define permissions on a network, file, or object. While
they can restrict access to resources, they do not segment a network in the same way as VLANs
or physical segmentation.
A disaster recovery manager wants to perform a qualitative analysis on intangible assets but is
unsure how to perform the calculations. Which departments should the manager bring on to
help determine metrics? Select 3 answers.
A - Marketing
B - Sales
C - Human Resources
D - Communications - CORRECT ANSWER-A, B & D; Marketing, Sales, and Communications
Marketing is one of the departments that should help the manager with the metrics. Qualitative
risk assessment is well-suited to the analysis of intangible assets, for example, an organization's
reputation or brand image.
Sales is another department brought on to assist the manager with metrics. These groups are
best-suited to provide input based on their unique insights.
EXAM LATEST QUESTIONS
AND VERIFIED CORRECT
ANSWERS GRADED A+
RSA - CORRECT ANSWER-Uses prime factorization to generate public and private encryption and
decryption keys
Diffie-Hellman (DH) - CORRECT ANSWER-A key exchange protocol that allows two parties to
securely generate a shared secret key over an insecure channel
Message Authentication Code - CORRECT ANSWER-Confirms the stated identity of the sender
and provides integrity of the message without the need to use any other means
HMAC - CORRECT ANSWER-Confirms identity of sender and integrity using hash values
Cipher Block Chaining (CBC) - CORRECT ANSWER-A process in which each block of unencrypted
text is combined with the block of cipher text immediately preceding it before it is encrypted
using the DES algorithm.
Poly1305 - CORRECT ANSWER-Provides increased speed and efficiency creating MAC, by
utilizing alternative encryption algorithms
Salsa20 - CORRECT ANSWER-Idk
Relational - CORRECT ANSWER-are very widely implemented and designed to support ACID transactions.
,Key-value - CORRECT ANSWER-are optimized to store and retrieve large volumes of data. It offers high-performance under heavy workloads.
In-memory - CORRECT ANSWER-offer real-time access to data and access to applications with microsecond latency.
Document - CORRECT ANSWER-enable developers to build applications quickly by storing data in a semi-structured manner.
Wide-column - CORRECT ANSWER-are a type of NoSQL database.
Graph - CORRECT ANSWER-are designed to support applications that query millions of relationships between highly connected datasets, such as social media
platforms.
Time series - CORRECT ANSWER-are focused on supporting applications that analyze data that evolves and changes over time and is best represented using time
intervals such as in an industrial setting.
Ledger - CORRECT ANSWER-enable a trusted and verifiable authority to support banking transactions and systems of record.
Whitelisting ensures that only approved applications can be installed and executed on company
laptops.
What should a business use to provide non-repudiation for emails between employees?
A - TLS/SSL
B - AES-256
C - S/MIME
D - IPSec - CORRECT ANSWER-C - S/MIME (Secure/Multipurpose Internet Mail Extensions)
S/MIME provides non-repudiation for emails by using digital signatures.
,Which strategy is appropriate for a risk management team to determine if a business has
insufficient security controls?
A - Qualitative assessment
B - Gap assessment
C - Quantitative risk assessment
D - Impact assessment - CORRECT ANSWER-B - Gap assessment
A gap assessment identifies the gaps between the current security control and the desired or
required levels of security.
An organization has leased office space that is suitable for its computer equipment so personnel
and systems can be relocated if the main office location is unavailable. It currently has some
equipment. Which type of site is the organization using?
A - Cold site
B - Warm site
C - Hot site
D - Mobile site - CORRECT ANSWER-B - Warm site
A warm site is a disaster recovery site that provides a partially equipped facility that can be used
to restore critical operations faster than having no equipment at all.
A risk assessment consultant is discussing segmentation options with a client. What are a few
standard options the consultant could offer? Select the best 2 answers.
A - VLANs
B - Transmission Control
C - Physical
D - Access control lists - CORRECT ANSWER-A & C; VLANs & Physical
, A network device can perform segmentation logically, for example, implementing virtual local
area networks (VLANs). A system can bypass VLANs if an attacker gains access to a trunk port
where all VLANs can talk.
Physical segmentation is another type of segmentation more commonly found in industrial
control systems (ICS) and supervisory control and data acquisition (SCADA) networks. This is
where, traditionally, there is an IT and OT (operational technology) network.
Transmission control is not a type of segmentation. Transmission control defines how a system
protects communication channels from infiltration, exploitation, and interception.
Access control lists (ACLs) are used to define permissions on a network, file, or object. While
they can restrict access to resources, they do not segment a network in the same way as VLANs
or physical segmentation.
A disaster recovery manager wants to perform a qualitative analysis on intangible assets but is
unsure how to perform the calculations. Which departments should the manager bring on to
help determine metrics? Select 3 answers.
A - Marketing
B - Sales
C - Human Resources
D - Communications - CORRECT ANSWER-A, B & D; Marketing, Sales, and Communications
Marketing is one of the departments that should help the manager with the metrics. Qualitative
risk assessment is well-suited to the analysis of intangible assets, for example, an organization's
reputation or brand image.
Sales is another department brought on to assist the manager with metrics. These groups are
best-suited to provide input based on their unique insights.