Answers.
During an assessment of a manufacturing plant, a security analyst finds several end-of-
life programmable logic controllers, which have firmware that was last updated three
years ago and known vulnerabilities. Which of the following BEST mitigates the risks
associated with the PLC's? - Correct Answer Implement network segmentation to isolate
the devices
A user is attempting to view and older sent email, but is unable to open the email. Which of
the following is the MOST likely cause? - Correct Answer The private certificate used to
sign the email has expired
An organization's Chief Information Officer recently received an email from human
resources that contained sensitive information. The CIO noticed the email was sent via
unsecure means. A policy has since been put into place stating all emails must be
transmitted using secure technologies. Which of the following should be implemented to
address the new policy? - Correct Answer TLS
Which of the following is a penetration tester performing when running an SMB NULL
session scan of a host to determine valid usernames and share names? - Correct Answer
Credentialed vulnerability scan
A Chief Executive Officer of an organization receives an email stating the CEO's account
may have been compromised. The email further directs the CEO to click on a link to
update the account credentials. Which of the following types of attacks has most likely
occurred? - Correct Answer Pharming
A user is unable to open a file that has a grayed-out icon with a lock. The user receives a
pop-up message indicating that payment must be sent in Bitcoin to unlock the file. Later in
the day, other users in the organization lose the ability to open files on the server. Which of
the following has MOST likely occurred? (Select THREE) - Correct Answer Crypto-
malware, Botnet attack, Ransomware
A company is deploying a file-sharing protocol across a network and needs to select a
protocol for authenticating clients. Management requests that the service be configured in
the most secure way possible. The protocol must also be capable of mutual
authentication, and support SSO and smart card logons. Which of the following would
BEST accomplish this task? - Correct Answer Implement Kerberos
,Which of the following methods is used by internal security teams to assess the security of
internally developed applications? - Correct Answer White box testing
After a significant amount of hiring, an organization would like to simplify the connection
process to its wireless network for employees while ensuring maximum security. The
Chief Information Office want to get rid of any shared network passwords and require
employees to use their company credentials when connecting. Which of the following
should be implemented to BEST meet this requirement? - Correct Answer 802.1x
Which of the following enables sniffing attacks against a switched network? - Correct
Answer ARP poisoning
A security analyst is securing a CA server. One of the requirements is network isolation
with no access to the internet or networked computers. Given this scenario, which of the
following should the analyst implement to BEST address the requirement? - Correct
Answer Set up an air-gapped environment
A developer wants to use an open source, third-party plug-in. The developer downloads
the plug-in from the providers website and from a mirror, and runs the files through and
integrity-checking hash. The output of each file is shown: fileA:
BA411C782AD521740123456789ABCDEF fileB:
BA411C782AD521740123456789ABCDEF Which of the following statements BEST
summarizes what conclusion the developer can draw from the above results? - Correct
Answer Given the output, the developer can assume there is no integrity compromise
Users are able to reach the login page of their company website from home using HTTP.
A network administrator disables HTTP and implements SSL. However, after the
implementation, home users cannot access the login page of the company website.
Which of the following is the MOST likely reason the site is unavailable? - Correct Answer
The company website implements HTTP redirects
Which of the following access management concepts is associated with file permissions?
- Correct Answer Authorization
During a lessons learned meeting regarding a previous incident, the security team
receives a follow-up action item with the following requirements: Allow authentication from
within the United States anytime, Allow authentication if the user is accessing email or a
shared file system, Do not allow authentication if the AV program is two days out of date,
Do not allow authentication if the location of the device is in two specific countries, Given
, the requirements, which of the following mobile deployment authentication types is being
utilized? - Correct Answer Context-aware authentication
An organization has an account management policy that defines parameters around each
type of account. The policy specifies different security attributes, such as longevity, usage
auditing, password complexity, and identity proofing. The goal of the account
management policy is to ensure the highest level of security while providing the greatest
availability without compromising data integrity for users. Which of the following account
types should the policy for service technicians from corporate partners? - Correct Answer
Privileged user account
Ann, a security administrator, wants to ensure credentials are encrypted in transit when
implementing a RADIUS server for SSO. Which of the following are needed given these
requirements? ( Select TWO) - Correct Answer Public key, Private key
An employee has been writing a secure shell around software used to secure executable
files. The employee has conducted the appropriate self-test and is ready to move the
software into the next environment. Within which of the following environments is the
employee currently working? - Correct Answer Test
Which of the following occurs when a vulnerability scan fails to identify an existing
vulnerability? - Correct Answer False negative
A security technician is configuring a new access switch. The switch will be managed
through software that will send status reports and logging details to a central management
console. Which of the following protocols should the technician configure to BEST meet
these requirements? (select TWO) - Correct Answer SNMPv3, Syslog
A technician is evaluating malware that was found on the enterprise network. After
reviewing samples of the malware binaries, the technician finds each has a different hash
associated with it. Which of the following types of malware is MOST likely present in the
environment? - Correct Answer Polymorphic worm
Which of the following would be considered multifactor authentication? - Correct Answer
Strong password and fingerprint
Logs from an IDS alerted on a string entered into the company's website login page. The
following line was pulled from the HTTP POST request. userid=bob' and