3.0 ASSESSMENT QUESTIONS WITH CORRECT
ANSWERS 2025
AnQauthoritativeQserverQforQaQzoneQcreatesQaQResourceQRecordsQSetQ(RRSet)QsignedQwithQaQzoneQsigningQk
ey.QFromQtheQfollowingQDomainQNameQSystemQ(DNS)QtraitsQandQfunctions,QwhatQdoesQthisQscenarioQdem
onstrate?Q-QCORRECTQANSWERQ-DNSQSecurityQExtensions
TheQadministratorQinQanQexchangeQserverQneedsQtoQsendQdigitallyQsignedQandQencryptedQmessages.QWhat
QshouldQtheQadministratorQuse?Q-QCORRECTQANSWERQ-S/MIME
AnQorganizationQusesQaQSessionQInitiationQProtocolQ(SIP)QendpointQforQestablishingQcommunicationsQwithQ
remoteQbranchQoffices.QWhichQofQtheQfollowingQprotocolsQwillQprovideQencryptionQforQstreamingQdataQdu
ringQtheQcall?Q-QCORRECTQANSWERQ-SRTP
AQwebQserverQwillQutilizeQaQdirectoryQprotocolQtoQenableQusersQtoQauthenticateQwithQdomainQcredentials.Q
AQcertificateQwillQbeQissuedQtoQtheQserverQtoQsetQupQaQsecureQtunnel.QWhichQprotocolQisQidealQforQthisQsitu
ation?Q-QCORRECTQANSWERQ-LDAPS
AQTransportQLayerQSecurityQ(TLS)QVirtualQPrivateQNetworkQ(VPN)QrequiresQaQremoteQaccessQserverQlistenin
gQonQportQ443QtoQencryptQtrafficQwithQaQclientQmachine.QAnQIPSecQ(InternetQProtocolQSecurity)QVPNQcanQd
eliverQtrafficQinQtwoQmodes.QOneQmodeQencryptsQonlyQtheQpayloadQofQtheQIPQpacket.QTheQotherQmodeQen
cryptsQtheQwholeQIPQpacketQ(headerQandQpayload).QTheseQtwoQmodesQdescribeQwhichQofQtheQfollowing?Q(
SelectQallQthatQapply.)Q-QCORRECTQANSWERQ-Tunnel
Transport
ConsiderQtheQprinciplesQofQwebQserverQhardeningQandQdetermineQwhichQactionsQaQsystemQadministratorQ
shouldQtakeQwhenQdeployingQaQnewQwebQserverQinQaQdemilitarizedQzoneQ(DMZ).Q(SelectQallQthatQapply.)Q-
QCORRECTQANSWERQ-EstablishQaQguestQzone
UploadQfilesQusingQSSH
UseQconfigurationQtemplates
WhichQofQtheQfollowingQprotocolsQwouldQsecureQfileQtransferQservicesQforQanQinternalQnetwork?Q-
QCORRECTQANSWERQ-FTPES
, ImplementingQLightweightQDirectoryQAccessQProtocolQSecureQ(LDAPS)QonQaQwebQserverQsecuresQdirectQqu
eriesQtoQwhichQofQtheQfollowing?Q-QCORRECTQANSWERQ-DirectoryQservices
SelectQtheQvulnerabilitiesQthatQcanQinfluenceQrouting.Q(SelectQallQthatQapply.)Q-QCORRECTQANSWERQ-
SourceQrouting
RouteQinjection
SoftwareQexploits
ManagementQhasQsetQupQaQfeedQorQsubscriptionQserviceQtoQinformQusersQonQregularQupdatesQtoQtheQnetw
orkQandQitsQvariousQsystemsQandQservices.QTheQfeedQisQonlyQaccessibleQfromQtheQinternalQnetwork.QWhatQ
elseQcanQsystemsQadministratorsQdoQtoQlimitQtheQserviceQtoQinternalQaccess?Q-QCORRECTQANSWERQ-
ProvisionQSSOQaccess.
AQsmallQorganizationQoperatesQseveralQvirtualQserversQinQaQsingleQhostQenvironment.QTheQphysicalQnetwor
kQutilizesQaQphysicalQfirewallQwithQNIDSQforQsecurity.QWhatQwouldQbeQtheQbenefitsQofQinstallingQaQHostQIntr
usionQPreventionQSystemQ(HIPS)QatQtheQendQpoints?Q(SelectQallQthatQapply.)Q-QCORRECTQANSWERQ-
PreventQmaliciousQtrafficQbetweenQVMs
ProtectionQfromQzeroQdayQattacks
WhichQofQtheQfollowingQwouldQsecureQanQendpointQandQprovideQattestationQsignedQbyQaQtrustedQplatform
QmoduleQ(TPM)?Q-QCORRECTQANSWERQ-MeasuredQboot
AQsupportQtechnicianQreviewsQaQcomputer'sQbootQintegrityQcapabilitiesQandQdiscoversQthatQtheQsystemQsu
pportsQaQmeasuredQbootQprocess.QWhichQstatementQaccuratelyQdescribesQthisQprocess?Q-
QCORRECTQANSWERQ-MeasuredQbootQwillQrecordQtheQpresenceQofQunsignedQkernel-levelQcode.
AQdeveloperQwritesQcodeQforQaQnewQapplication,QandQwantsQtoQensureQprotectiveQcountermeasuresQagain
stQtheQexecutionQofQSQLQinjectionQattacks.QWhatQsecureQcodingQtechniqueQwillQprovideQthis?Q-
QCORRECTQANSWERQ-InputQvalidation
AQwebQadministratorQnoticesQaQfewQsecurityQvulnerabilitiesQthatQneedQtoQbeQaddressedQonQtheQcompanyQ
IntranetQsite.QTheQportalQmustQforceQaQsecureQbrowsingQconnection,QmitigateQscriptQinjection,QandQpreve
ntQcachingQonQsharedQclientQdevices.QDetermineQtheQsecureQoptionsQtoQsetQonQtheQwebQserver'sQrespons
eQheaders.Q(SelectQallQthatQapply.)Q-QCORRECTQANSWERQ-HTTPQStrictQTransportQSecurityQ(HSTS)