EC-COUNCIL CERTIFIED SECURE
COMPUTER USER (CSCU) EXAM WITH
QUESTIONS AND VERIFIED ANSWERS,
PLUS DETAILED RATIONALES/EXPERT
VERIFIED FOR GUARANTEED PASS
2026/LATEST UPDATE/INSTANT
DOWNLOAD PDF
1. A user receives an email appearing to come from a company's IT
department stating that the user's account will be disabled within
30 minutes unless they click a provided link and verify their
password. The email contains the company's logo and appears
professionally written. What is the MOST appropriate action?
A. Click the link and change the password immediately
B. Reply to the email asking whether it is legitimate
C. Independently contact the IT department using a trusted
communication channel
D. Forward the email to coworkers to determine whether they received it
Answer: C. Independently contact the IT department using a
trusted communication channel
Rationale: Phishing attacks commonly create urgency, authority, and
fear to manipulate users into disclosing credentials or clicking
malicious links. A legitimate-looking logo or professional formatting
does not establish authenticity. The safest approach is to verify the
request through a known, trusted channel rather than using contact
information contained in the suspicious message.
1
, 2. Which password provides the strongest resistance to common
password-cracking techniques?
A. Password123!
B. Nairobi2026
C. Summer!2026
D. vQ7#Lm92!xP4@tR8
Answer: D. vQ7#Lm92!xP4@tR8
Rationale: A strong password should be sufficiently long,
unpredictable, and resistant to dictionary, brute-force, and password-
guessing attacks. Passwords containing names, seasons, years, and
predictable substitutions are comparatively weak. A randomly
generated password with a substantial length and varied character set
provides considerably greater resistance.
3. An employee uses the same password for email, social media,
cloud storage, and an online banking account. A breach occurs at
the social-media provider and the password becomes publicly
available. What is the primary security risk?
A. Shoulder surfing
B. Credential stuffing
C. Tailgating
D. Dumpster diving
Answer: B. Credential stuffing
Rationale: Credential stuffing occurs when attackers take usernames
and passwords obtained from one breach and attempt them against
other services. Password reuse makes this attack particularly effective
because compromise of one account can lead to compromise of
multiple unrelated accounts. Unique passwords for every important
service significantly reduce this risk.
2
, 4. Which security principle requires a user to receive only the
permissions necessary to perform assigned duties?
A. Defense in depth
B. Least privilege
C. Separation of duties
D. Nonrepudiation
Answer: B. Least privilege
Rationale: Least privilege limits users, applications, and processes to
the minimum permissions required for legitimate tasks. This reduces
the potential damage caused by compromised accounts, malware,
accidental actions, or insider threats.
5. A user leaves their workstation unattended for several minutes
while logged into a corporate application containing confidential
information. Which control BEST protects the workstation?
A. Disable antivirus
B. Enable automatic screen locking
C. Increase display brightness
D. Disable password authentication
Answer: B. Enable automatic screen locking
Rationale: Automatic screen locking reduces the opportunity for an
unauthorized person to access information through an unattended
workstation. Users should also manually lock their computers
whenever they step away, particularly in shared or public
environments.
3
, 6. What is the PRIMARY purpose of antivirus or endpoint security
software?
A. Guarantee that no malware can ever infect a computer
B. Detect, prevent, and respond to malicious software
C. Replace the need for operating-system updates
D. Encrypt every file stored on the computer
Answer: B. Detect, prevent, and respond to malicious software
Rationale: Endpoint security software can detect known malicious
files, suspicious behavior, potentially unwanted applications, and other
threats. It is an important defense layer but cannot guarantee complete
protection. Secure computing requires multiple controls, including
patching, safe browsing, access control, backups, and user awareness.
7. A malicious program encrypts a victim's files and demands
cryptocurrency in exchange for a decryption key. What type of
malware is this?
A. Spyware
B. Ransomware
C. Adware
D. Rootkit
Answer: B. Ransomware
Rationale: Ransomware is designed to deny access to data or systems,
commonly by encrypting files, and then demands payment from the
victim. Maintaining tested offline or otherwise protected backups is an
important defense against the impact of ransomware.
8. Which type of malware is specifically designed to secretly monitor
a user's activities and collect information?
4
COMPUTER USER (CSCU) EXAM WITH
QUESTIONS AND VERIFIED ANSWERS,
PLUS DETAILED RATIONALES/EXPERT
VERIFIED FOR GUARANTEED PASS
2026/LATEST UPDATE/INSTANT
DOWNLOAD PDF
1. A user receives an email appearing to come from a company's IT
department stating that the user's account will be disabled within
30 minutes unless they click a provided link and verify their
password. The email contains the company's logo and appears
professionally written. What is the MOST appropriate action?
A. Click the link and change the password immediately
B. Reply to the email asking whether it is legitimate
C. Independently contact the IT department using a trusted
communication channel
D. Forward the email to coworkers to determine whether they received it
Answer: C. Independently contact the IT department using a
trusted communication channel
Rationale: Phishing attacks commonly create urgency, authority, and
fear to manipulate users into disclosing credentials or clicking
malicious links. A legitimate-looking logo or professional formatting
does not establish authenticity. The safest approach is to verify the
request through a known, trusted channel rather than using contact
information contained in the suspicious message.
1
, 2. Which password provides the strongest resistance to common
password-cracking techniques?
A. Password123!
B. Nairobi2026
C. Summer!2026
D. vQ7#Lm92!xP4@tR8
Answer: D. vQ7#Lm92!xP4@tR8
Rationale: A strong password should be sufficiently long,
unpredictable, and resistant to dictionary, brute-force, and password-
guessing attacks. Passwords containing names, seasons, years, and
predictable substitutions are comparatively weak. A randomly
generated password with a substantial length and varied character set
provides considerably greater resistance.
3. An employee uses the same password for email, social media,
cloud storage, and an online banking account. A breach occurs at
the social-media provider and the password becomes publicly
available. What is the primary security risk?
A. Shoulder surfing
B. Credential stuffing
C. Tailgating
D. Dumpster diving
Answer: B. Credential stuffing
Rationale: Credential stuffing occurs when attackers take usernames
and passwords obtained from one breach and attempt them against
other services. Password reuse makes this attack particularly effective
because compromise of one account can lead to compromise of
multiple unrelated accounts. Unique passwords for every important
service significantly reduce this risk.
2
, 4. Which security principle requires a user to receive only the
permissions necessary to perform assigned duties?
A. Defense in depth
B. Least privilege
C. Separation of duties
D. Nonrepudiation
Answer: B. Least privilege
Rationale: Least privilege limits users, applications, and processes to
the minimum permissions required for legitimate tasks. This reduces
the potential damage caused by compromised accounts, malware,
accidental actions, or insider threats.
5. A user leaves their workstation unattended for several minutes
while logged into a corporate application containing confidential
information. Which control BEST protects the workstation?
A. Disable antivirus
B. Enable automatic screen locking
C. Increase display brightness
D. Disable password authentication
Answer: B. Enable automatic screen locking
Rationale: Automatic screen locking reduces the opportunity for an
unauthorized person to access information through an unattended
workstation. Users should also manually lock their computers
whenever they step away, particularly in shared or public
environments.
3
, 6. What is the PRIMARY purpose of antivirus or endpoint security
software?
A. Guarantee that no malware can ever infect a computer
B. Detect, prevent, and respond to malicious software
C. Replace the need for operating-system updates
D. Encrypt every file stored on the computer
Answer: B. Detect, prevent, and respond to malicious software
Rationale: Endpoint security software can detect known malicious
files, suspicious behavior, potentially unwanted applications, and other
threats. It is an important defense layer but cannot guarantee complete
protection. Secure computing requires multiple controls, including
patching, safe browsing, access control, backups, and user awareness.
7. A malicious program encrypts a victim's files and demands
cryptocurrency in exchange for a decryption key. What type of
malware is this?
A. Spyware
B. Ransomware
C. Adware
D. Rootkit
Answer: B. Ransomware
Rationale: Ransomware is designed to deny access to data or systems,
commonly by encrypting files, and then demands payment from the
victim. Maintaining tested offline or otherwise protected backups is an
important defense against the impact of ransomware.
8. Which type of malware is specifically designed to secretly monitor
a user's activities and collect information?
4