and Detailed –Latest Update 2026/2027 | Graded A+
Question 1
A healthcare organization has experienced a significant increase in phishing
attacks targeting employees. During an internal audit, it is discovered that
many employees are unable to identify fraudulent emails. The Chief
Information Security Officer (CISO) wants to implement the MOST effective
administrative safeguard to reduce future successful phishing attempts.
What should the organization implement FIRST?
A. Purchase additional firewalls
B. Conduct mandatory cybersecurity awareness and phishing simulation
training
C. Upgrade all employee laptops
D. Increase internet bandwidth
Correct Answer: B
Rationale
Cybersecurity awareness training is an administrative control designed to
reduce human error, which remains one of the leading causes of successful
cyberattacks. Phishing simulation exercises reinforce recognition of
suspicious emails and improve employee responses.
A is incorrect because firewalls cannot prevent employees from clicking
phishing emails.
C is incorrect because newer hardware does not eliminate phishing
risks.
D is unrelated to phishing prevention.
1|Page
,Question 2
An IT security analyst reviews authentication logs and notices that a user
account successfully logged in from New York at 8:00 AM and then from
Tokyo at 8:30 AM.
What is the MOST likely explanation?
A. Successful multifactor authentication
B. Impossible travel indicating possible credential compromise
C. Proper VPN configuration
D. Scheduled system maintenance
Correct Answer: B
Rationale
Impossible travel occurs when authentication events happen from
geographically distant locations within an impossible timeframe. This
commonly indicates stolen credentials or account compromise.
A does not explain geographically impossible logins.
C may alter apparent locations but should still be investigated.
D has no relationship to user authentication.
Question 3
A company is implementing the Principle of Least Privilege.
Which action BEST demonstrates this principle?
A. Giving every employee administrator privileges
B. Allowing users access only to the systems necessary to perform their jobs
C. Sharing administrator accounts among departments
2|Page
,D. Removing password requirements
Correct Answer: B
Rationale
Least privilege limits access rights to only what is necessary for job
responsibilities, reducing the attack surface and minimizing potential damage
from compromised accounts.
A violates least privilege.
C eliminates accountability.
D weakens security.
Question 4
An organization stores sensitive customer information on portable laptops
used by remote employees. Management wants to ensure that if a laptop is
stolen, the stored information remains unreadable.
Which solution BEST addresses this requirement?
A. Antivirus software
B. Full-disk encryption
C. Additional RAM
D. Screen savers
Correct Answer: B
Rationale
Full-disk encryption protects stored data even if physical devices are stolen.
Without the encryption key, attackers cannot easily access the data.
A detects malware but does not secure stolen data.
C improves performance only.
D provides no data protection.
3|Page
, Question 5
An organization experiences a ransomware attack that encrypts all
production servers. Fortunately, clean backups exist and have been verified.
What should the organization do AFTER containing the attack?
A. Pay the ransom immediately
B. Restore systems from verified backups
C. Ignore the attack
D. Delete all backups
Correct Answer: B
Rationale
After containment and eradication, organizations should recover operations
by restoring from verified, uncompromised backups. Paying the ransom does
not guarantee recovery and may encourage future attacks.
A is generally not recommended.
C allows continued disruption.
D destroys recovery capability.
Question 6
A company wants to verify that transmitted files have not been altered during
transmission.
Which technology provides this assurance?
A. Digital signatures
B. Compression
4|Page