[GOOGLE CYBERSECURITY CERTIFICATE ASSESSMENT] –
QUESTIONS AND ANSWERS | VERIFIED AND WELL DETAILED
ANSWERS | PLUS RATIONALES | GUARANTEED PASS | LATEST
EXAM UPDATE | EXAM PREP | STUDY GUIDE | PRACTICE TEST
1. A security analyst notices repeated failed login attempts against several employee accounts
from multiple geographic locations within a short period of time. What is the MOST likely
explanation for this activity?
A. Credential stuffing attack
B. Distributed denial-of-service attack
C. Insider threat activity
D. Data backup synchronization issue
════════════════════
Correct Answer: A. Credential stuffing attack
Rationale:
Credential stuffing occurs when attackers use previously compromised usernames and
passwords to attempt logins across multiple accounts and services. The repeated failed
attempts from various locations strongly indicate automated login abuse. A DDoS attack
targets service availability rather than authentication, insider threats usually originate
internally, and backup synchronization would not trigger suspicious login attempts.
════════════════════
2. A company wants to reduce the likelihood of employees falling victim to phishing emails.
Which control would BEST address this risk?
A. Installing additional RAM on employee computers
B. Conducting regular security awareness training
C. Replacing wired connections with wireless access points
D. Disabling all internet browser cookies
════════════════════
Correct Answer: B. Conducting regular security awareness training
Rationale:
Security awareness training helps employees recognize phishing attempts, suspicious links,
and social engineering tactics. Human error is one of the leading causes of successful phishing
,attacks, making training an effective preventive control. The other options do not directly
address phishing threats.
════════════════════
3. During a risk assessment, a cybersecurity professional identifies outdated software running
on critical servers. What should this finding be classified as?
A. Threat actor
B. Security incident
C. Vulnerability
D. Mitigation strategy
════════════════════
Correct Answer: C. Vulnerability
Rationale:
Outdated software represents a vulnerability because it may contain unpatched security
weaknesses that attackers can exploit. A threat actor is the entity exploiting weaknesses, a
security incident is an actual adverse event, and mitigation strategies are actions taken to
reduce risk.
════════════════════
4. Which principle ensures users only receive the minimum level of access necessary to
perform their job duties?
A. Defense in depth
B. Separation of duties
C. Principle of least privilege
D. Zero-day mitigation
════════════════════
Correct Answer: C. Principle of least privilege
Rationale:
The principle of least privilege limits user permissions to only what is required for assigned
tasks, reducing the potential impact of compromised accounts or insider misuse. Defense in
depth involves layered security, separation of duties distributes responsibilities, and zero-day
mitigation focuses on unknown vulnerabilities.
════════════════════
,5. A network administrator wants to prevent unauthorized devices from accessing the
corporate network. Which solution is MOST appropriate?
A. Network Access Control (NAC)
B. File compression software
C. Password reuse policy
D. Screen timeout settings
════════════════════
Correct Answer: A. Network Access Control (NAC)
Rationale:
NAC solutions verify device compliance and authentication before granting network access.
This helps prevent unauthorized or noncompliant systems from connecting to corporate
resources. The remaining options do not effectively control device-level network access.
════════════════════
6. An employee receives a phone call from someone claiming to be from technical support
requesting login credentials. What type of attack is this?
A. Brute-force attack
B. SQL injection
C. Social engineering
D. Session hijacking
════════════════════
Correct Answer: C. Social engineering
Rationale:
Social engineering manipulates individuals into revealing sensitive information. Pretending to
be technical support to obtain credentials is a common example. Brute-force attacks rely on
password guessing, SQL injection targets databases, and session hijacking involves stealing
active sessions.
════════════════════
7. Which security measure would BEST protect sensitive data stored on a stolen laptop?
A. Network segmentation
B. Full disk encryption
C. Browser cache clearing
D. DHCP reservation
, ════════════════════
Correct Answer: B. Full disk encryption
Rationale:
Full disk encryption ensures data remains unreadable without proper authentication, even if a
device is stolen. Network segmentation and DHCP reservations are unrelated to local device
data protection, while browser cache clearing offers minimal security benefit in this scenario.
════════════════════
8. A cybersecurity team is reviewing logs after detecting unusual outbound traffic to an
unfamiliar external server. What is the FIRST step they should take?
A. Publicly disclose the incident
B. Delete all network logs
C. Ignore the activity if systems remain operational
D. Investigate and validate the suspicious activity
════════════════════
Correct Answer: D. Investigate and validate the suspicious activity
Rationale:
The first step in incident response is confirming whether suspicious activity represents a
legitimate threat. Investigating logs and validating indicators helps determine scope and
severity before containment actions occur. Deleting logs or ignoring the activity could worsen
the incident.
════════════════════
9. Which authentication factor is represented by a fingerprint scan?
A. Something you know
B. Something you have
C. Somewhere you are
D. Something you are
════════════════════
Correct Answer: D. Something you are
Rationale:
Biometric authentication such as fingerprint scans falls under “something you are.” Something
you know includes passwords, something you have includes security tokens, and somewhere
you are refers to location-based authentication.
QUESTIONS AND ANSWERS | VERIFIED AND WELL DETAILED
ANSWERS | PLUS RATIONALES | GUARANTEED PASS | LATEST
EXAM UPDATE | EXAM PREP | STUDY GUIDE | PRACTICE TEST
1. A security analyst notices repeated failed login attempts against several employee accounts
from multiple geographic locations within a short period of time. What is the MOST likely
explanation for this activity?
A. Credential stuffing attack
B. Distributed denial-of-service attack
C. Insider threat activity
D. Data backup synchronization issue
════════════════════
Correct Answer: A. Credential stuffing attack
Rationale:
Credential stuffing occurs when attackers use previously compromised usernames and
passwords to attempt logins across multiple accounts and services. The repeated failed
attempts from various locations strongly indicate automated login abuse. A DDoS attack
targets service availability rather than authentication, insider threats usually originate
internally, and backup synchronization would not trigger suspicious login attempts.
════════════════════
2. A company wants to reduce the likelihood of employees falling victim to phishing emails.
Which control would BEST address this risk?
A. Installing additional RAM on employee computers
B. Conducting regular security awareness training
C. Replacing wired connections with wireless access points
D. Disabling all internet browser cookies
════════════════════
Correct Answer: B. Conducting regular security awareness training
Rationale:
Security awareness training helps employees recognize phishing attempts, suspicious links,
and social engineering tactics. Human error is one of the leading causes of successful phishing
,attacks, making training an effective preventive control. The other options do not directly
address phishing threats.
════════════════════
3. During a risk assessment, a cybersecurity professional identifies outdated software running
on critical servers. What should this finding be classified as?
A. Threat actor
B. Security incident
C. Vulnerability
D. Mitigation strategy
════════════════════
Correct Answer: C. Vulnerability
Rationale:
Outdated software represents a vulnerability because it may contain unpatched security
weaknesses that attackers can exploit. A threat actor is the entity exploiting weaknesses, a
security incident is an actual adverse event, and mitigation strategies are actions taken to
reduce risk.
════════════════════
4. Which principle ensures users only receive the minimum level of access necessary to
perform their job duties?
A. Defense in depth
B. Separation of duties
C. Principle of least privilege
D. Zero-day mitigation
════════════════════
Correct Answer: C. Principle of least privilege
Rationale:
The principle of least privilege limits user permissions to only what is required for assigned
tasks, reducing the potential impact of compromised accounts or insider misuse. Defense in
depth involves layered security, separation of duties distributes responsibilities, and zero-day
mitigation focuses on unknown vulnerabilities.
════════════════════
,5. A network administrator wants to prevent unauthorized devices from accessing the
corporate network. Which solution is MOST appropriate?
A. Network Access Control (NAC)
B. File compression software
C. Password reuse policy
D. Screen timeout settings
════════════════════
Correct Answer: A. Network Access Control (NAC)
Rationale:
NAC solutions verify device compliance and authentication before granting network access.
This helps prevent unauthorized or noncompliant systems from connecting to corporate
resources. The remaining options do not effectively control device-level network access.
════════════════════
6. An employee receives a phone call from someone claiming to be from technical support
requesting login credentials. What type of attack is this?
A. Brute-force attack
B. SQL injection
C. Social engineering
D. Session hijacking
════════════════════
Correct Answer: C. Social engineering
Rationale:
Social engineering manipulates individuals into revealing sensitive information. Pretending to
be technical support to obtain credentials is a common example. Brute-force attacks rely on
password guessing, SQL injection targets databases, and session hijacking involves stealing
active sessions.
════════════════════
7. Which security measure would BEST protect sensitive data stored on a stolen laptop?
A. Network segmentation
B. Full disk encryption
C. Browser cache clearing
D. DHCP reservation
, ════════════════════
Correct Answer: B. Full disk encryption
Rationale:
Full disk encryption ensures data remains unreadable without proper authentication, even if a
device is stolen. Network segmentation and DHCP reservations are unrelated to local device
data protection, while browser cache clearing offers minimal security benefit in this scenario.
════════════════════
8. A cybersecurity team is reviewing logs after detecting unusual outbound traffic to an
unfamiliar external server. What is the FIRST step they should take?
A. Publicly disclose the incident
B. Delete all network logs
C. Ignore the activity if systems remain operational
D. Investigate and validate the suspicious activity
════════════════════
Correct Answer: D. Investigate and validate the suspicious activity
Rationale:
The first step in incident response is confirming whether suspicious activity represents a
legitimate threat. Investigating logs and validating indicators helps determine scope and
severity before containment actions occur. Deleting logs or ignoring the activity could worsen
the incident.
════════════════════
9. Which authentication factor is represented by a fingerprint scan?
A. Something you know
B. Something you have
C. Somewhere you are
D. Something you are
════════════════════
Correct Answer: D. Something you are
Rationale:
Biometric authentication such as fingerprint scans falls under “something you are.” Something
you know includes passwords, something you have includes security tokens, and somewhere
you are refers to location-based authentication.