Tested Q&A 2026 | Latest Study Guide
1. Which two laws protect the privacy of medical records and electronic health
care information?
HIPPA & SOX
PCI-DSS & HITECH
HIPAA & HITECH
GLBA & HIPPA
2. What is the main role of the National Security Agency (NSA)?
To enforce data protection regulations.
To manage cybersecurity for private corporations.
To conduct public awareness campaigns about cybersecurity.
To present leaders with critical security information needed to
defend the country.
3. Which of the following policies is designed to ensure that sensitive
documents and materials are not left unattended for unauthorized persons
to potentially access?
Access control policy
Acceptable use policy
Data classification policy
Clean desk policy
4. Ann, a security administrator, has been instructed to perform fuzz-based
testing on the company's applications. Which of the following best describes
, what she will do?
Work with the developers to eliminate horizontal privilege escalation
opportunities
Test the applications for the existence of built-in back doors left by
the developers
Hash the application to verify it won't cause a false positive on the
HIPS.
Enter random or invalid data into the application in an attempt to
cause it to fault
5. Which rule provides federal protections for individually identifiable health
information held by covered entities and their business associates and gives
patients rights with respect to that information?
HIPAA Patient Safety Rule
HIPAA Security Rule
HIPAA Privacy Rule
None of the above
6. If a web application is vulnerable to clickjacking, what security measure could
be implemented to mitigate this risk?
Implementing X-Frame-Options header
Using stronger encryption algorithms
Increasing server bandwidth
Regularly updating user passwords
7. Which of the following, also known as social engineering, is a methodology
by which an individual impersonates someone else to extract sensitive
, information from them?
Denial of service
Pretexting
System infiltration
Corporate identity theft
8. Describe the process by which an anomaly-based IDS identifies deviations
from normal traffic patterns.
Anomaly-based IDS monitors real-time traffic without any historical
data.
An anomaly-based IDS identifies deviations by comparing current
traffic to a baseline measurement of what is considered normal.
Anomaly-based IDS relies solely on user behavior to identify threats.
An anomaly-based IDS uses predefined attack signatures to detect
threats.
9. Describe the primary focus of the General Data Protection Regulation
(GDPR).
GDPR governs the use of social media platforms in Europe.
GDPR focuses on data protection and privacy for individuals within
the European Union.
GDPR is concerned with cybersecurity measures for businesses.
GDPR regulates financial transactions in the European Union.
10. Which of the following best describes a stateful inspection?
, Allows all internal traffic to share a single public IP when connecting
to an outside entity.
Offers secure connectivity between many entities and uses
encryption to provide an effective defense against sniffing.
Determines the legitimacy of traffic based on the state of the
connection from which the traffic originated.
Designed to sit between a host and a web server and communicate
with the server on behalf of the host.
11. Describe how a stateful packet inspection firewall enhances network security.
It allows all traffic through without restrictions.
It blocks all incoming traffic without analysis.
It only inspects the header of each packet.
It monitors and defends a system based on traffic patterns over a
given connection.
12. What does the 'C' in the CIA triad stand for?
Confidentiality
Control
Clarity
Compliance
13. What does an organization need to do to the attack surface to protect its
devices and network?
Install anti-malware tools
Implement exploit frameworks