and Answers.
You've hired a third-party to gather information about your company's servers and data.
The third-party will not have direct access to your internal network but can gather
information from any other source. Which of the following would BEST describe this
approach?
A. Backdoor testing
B. Passive footprinting
C. OS fingerprinting
D. Partially known environment - Correct Answer B :
Passive footprinting focuses on learning as much information from open sources such as
social media, corporate websites, and business organizations.
Which of these protocols use TLS to provide secure communication? (Select TWO)
A. HTTPS
B. SSH
C. FTPS
D. SNMPv2
E. DNSSEC
F. SRTP - Correct Answer A and C :
TLS (Transport Layer Security) is a cryptographic protocol used to encrypt network
communication. HTTPS is the Hypertext Transfer Protocol over TLS, and FTPS is the File
Transfer Protocol over TLS. An earlier version of TLS is SSL (Secure Sockets Layer).
Although we don't commonly see SSL in use any longer, you may see TLS
communication referenced as SSL.
Which of these threat actors would be MOST likely to attack systems for direct financial
gain?
A. Organized crime
B. Hacktivist
C. Nation state
,D. Competitor - Correct Answer A :
An organized crime actor is motivated by money, and their hacking objectives are usually
based around objectives that can be easily exchanged for financial capital.
A security incident has occurred on a file server. Which of the following data sources
should be gathered to address file storage volatility? (Select TWO)
A. Partition data
B. Kernel statistics
C. ROM data
D. Temporary file systems
E. Process table - Correct Answer A and D :
Both temporary file system data and partition data are part of the file storage subsystem.
An IPS at your company has found a sharp increase in traffic from all-in-one printers. After
researching, your security team has found a vulnerability associated with these devices
that allows the device to be remotely controlled by a third-party. Which category would
BEST describe these devices?
A. IoT
B. RTOS
C. MFD
D. SoC - Correct Answer C :
An all-in-one printer that can print, scan, and fax is often categorized as an MFD
(Multifunction Device)
Which of the following standards provides information on privacy and managing PII?
A. ISO 31000
B. ISO 27002
C. ISO 27701
D. ISO 27001 - Correct Answer C :
The ISO (International Organization for Standardization) 27701 standard extends the ISO
27001 and 27002 standards to include detailed management of PII (Personally
Identifiable Information) and data privacy.
, Elizabeth, a security administrator, is concerned about the potential for data exfiltration
using external storage drives. Which of the following would be the BEST way to prevent
this method of data exfiltration?
A. Create an operating system security policy to prevent the use of removable media
B. Monitor removable media usage in host-based firewall logs
C. Only allow applications that do not use removable media
D. Define a removable media block rule in the UTM - Correct Answer A :
Removable media uses hot-pluggable interfaces such as USB to connect storage drives.
A security policy in the operating system can prevent any files from being written to a
removable drive.
A CISO (Chief Information Security Officer) would like to decrease the response time
when addressing security incidents. Unfortunately, the company does not have the
budget to hire additional security engineers. Which of the following would assist the CISO
with this requirement?
A. ISO 27701
B. PKI
C. IaaS
D. SOAR - Correct Answer D :
SOAR (Security Orchestration, Automation, and Response) is designed to make security
teams more effective by automating processes and integrating third-party security tools.
An insurance company has created a set of policies to handle data breaches. The security
team has been given this set of requirements based on these policies:
• Access records from all devices must be saved and archived
• Any data access outside of normal working hours must be immediately reported • Data
access must only occur inside of the country
• Access logs and audit reports must be created from a single database Which of the
following should be implemented by the security team to meet these requirements?
(Select THREE)
A. Restrict login access by IP address and GPS location
B. Require government-issued identification during the onboarding process