1
-exam elaborations with 100% verified answer/solutions-
Excel & Succeed - academic year (2026-2027)
72 Q&A
A security team is implementing various security controls across the
organization. After several configurations and applications, a final
agreed-on set of security controls are put into place; However, not all
risks are mitigated by the controls. of the following, which is the next
best step?: Continue applying controls until all risk is eliminated, Ignore
any remaining risk as "best effort controlled," Ensure that any remaining
risk is residual or low and accept the risk. Remove all controls.
Ensure that any remaining risk is residual or low and accept the risk.
A Certified Ethical Hacker (CEH) follows a specific methodology for
testing a system. Which step comes after footprinting in the CEH
methodology? Scanning, Enumeration, Reconnaissance, Application
attack.
Reconnaissance
Which of the following best describes a newly discovered flaw in a
software application?
Zero-day
Which type of security control is met by encryption?
Preventative
, You've been hired as part of pen test team. During the brief, you learn
the client wants the pen test attack to simulate a normal user who finds
ways to elevate privileges and create attacks. Which test type does the
client want?
A gray Box
Which of the following is defined as ensuring the enforcement of
organizational security policy does not rely on voluntary user
compliance by assigning sensitivity labels on information and
comparing this to the level of security a user is operating at?
Mandatory Access Control
You begin your first pen test assignment by checking out IP address
ranges owned by the target as well as details of their domain name
registration. Additionally, you visit job boards and financial websites to
gather any technical information online. What activity are you
performing?
Passive footprinting
Of the following choices, which best defines a formal written document
defining what employees are allowed to use organization systems for,
what is not allowed, and what the repercussions are for breaking the
rules?
Information security policy (ISP)
An ethical hacker is given no prior knowledge of the network and has a
specific framework in which to work. The agreement specifies
boundaries, nondisclosure agreements, and a completion date
definition. Which of the following is true?
A white hat is attempting a black-box test
Which of the following is a detective control?
Audit trail
As part of a pen test on a U.S. government system, you discover files
containing Social Security numbers and other sensitive personally