Informational Assurance Security Final
Exam 2025 Questions and Answers 100%
Pass
Tom would like to deploy consistent security settings to all of his Windows
systems simultaneously. What technology can he use to achieve this goal? -
ANSWER-Group Policy Objects (GPOs)
Kevin would like to implement a specialized firewall that can protect against SQL
injection, cross-site scripting, and similar attacks. What technology should he
choose? - ANSWER-Web application firewalls (WAFs)
What drove the creation of ISACs (Information Sharing and Analysis Center) in
the United States? - ANSWER-Threat information sharing for infrastructure
owners
What is not a common technique used to defend against command and control
(C2) capabilities deployed by attackers?
-Deploying detection capabilities
COPYRIGHT ©️ 2025 ALL RIGHTS RESERVED...TRUSTED & VERIFIED 1
,-Tracking new C2 methods and technology
-Network hardening
-Patching against zero-day attacks - ANSWER-Patching against zero-day attacks
What type of analysis is best suited to identify a previously unknown malware
package operating on a compromised system? - ANSWER-Heuristic analysis
What flag does nmap use to enable operating system identification? - ANSWER--o
Barry placed all of his organization's credit card processing systems on an isolated
network dedicated to card processing. He has implemented appropriate
segmentation controls to limit the scope of PCI DSS to those systems through the
use of VLANs and firewalls. When Barry goes to conduct vulnerability scans for
PCI DSS compliance purposes, what systems must he scan? - ANSWER-Systems
on the isolated network
Sarah would like to run an external vulnerability scan on a system for PCI DSS
compliance purposes. Who is authorized to complete one of these scans? -
ANSWER-An Approved Scanning Vendor
Tom is reviewing a vulnerability scan report and finds that one of the servers on
his network suffers from an internal IP address disclosure vulnerability. What
technology is likely in use on this network that resulted in this vulnerability? -
ANSWER-Network Address Translation (NAT)
COPYRIGHT ©️ 2025 ALL RIGHTS RESERVED...TRUSTED & VERIFIED 2
, In what type of attack does the attacker seek to gain access to resources assigned to
a different virtual machine? - ANSWER-VM escape
Which one of the following values for the CVSS attack complexity metric would
indicate that the specified attack is simplest to exploit? - ANSWER-Low
Kevin is using a service where a cloud provider offers a platform that executes his
code in response to discrete events. He is billed based on the actual resources
consumed during each code execution event. What term best describes this
service? - ANSWER-function as a service (FaaS)
Amanda would like to run a security configuration scan of her Microsoft Azure
cloud environment. Which one of the following tools would be most appropriate
for her needs? - ANSWER-ScoutSuite
Ben sets up a system that acts like a vulnerable host in order to observe attacker
behavior. What type of system has he set up? - ANSWER-A honeypot
Michelle has been asked to review her corporate network's design for single points
of failure that would impact the core network operations. The following graphic
shows a redundant network design with a critical fault: a single point of failure that
could take the network offline if it failed. Where is this single point of failure? -
ANSWER-Point A
Internet service provider <---> Internet
COPYRIGHT ©️ 2025 ALL RIGHTS RESERVED...TRUSTED & VERIFIED 3
Exam 2025 Questions and Answers 100%
Pass
Tom would like to deploy consistent security settings to all of his Windows
systems simultaneously. What technology can he use to achieve this goal? -
ANSWER-Group Policy Objects (GPOs)
Kevin would like to implement a specialized firewall that can protect against SQL
injection, cross-site scripting, and similar attacks. What technology should he
choose? - ANSWER-Web application firewalls (WAFs)
What drove the creation of ISACs (Information Sharing and Analysis Center) in
the United States? - ANSWER-Threat information sharing for infrastructure
owners
What is not a common technique used to defend against command and control
(C2) capabilities deployed by attackers?
-Deploying detection capabilities
COPYRIGHT ©️ 2025 ALL RIGHTS RESERVED...TRUSTED & VERIFIED 1
,-Tracking new C2 methods and technology
-Network hardening
-Patching against zero-day attacks - ANSWER-Patching against zero-day attacks
What type of analysis is best suited to identify a previously unknown malware
package operating on a compromised system? - ANSWER-Heuristic analysis
What flag does nmap use to enable operating system identification? - ANSWER--o
Barry placed all of his organization's credit card processing systems on an isolated
network dedicated to card processing. He has implemented appropriate
segmentation controls to limit the scope of PCI DSS to those systems through the
use of VLANs and firewalls. When Barry goes to conduct vulnerability scans for
PCI DSS compliance purposes, what systems must he scan? - ANSWER-Systems
on the isolated network
Sarah would like to run an external vulnerability scan on a system for PCI DSS
compliance purposes. Who is authorized to complete one of these scans? -
ANSWER-An Approved Scanning Vendor
Tom is reviewing a vulnerability scan report and finds that one of the servers on
his network suffers from an internal IP address disclosure vulnerability. What
technology is likely in use on this network that resulted in this vulnerability? -
ANSWER-Network Address Translation (NAT)
COPYRIGHT ©️ 2025 ALL RIGHTS RESERVED...TRUSTED & VERIFIED 2
, In what type of attack does the attacker seek to gain access to resources assigned to
a different virtual machine? - ANSWER-VM escape
Which one of the following values for the CVSS attack complexity metric would
indicate that the specified attack is simplest to exploit? - ANSWER-Low
Kevin is using a service where a cloud provider offers a platform that executes his
code in response to discrete events. He is billed based on the actual resources
consumed during each code execution event. What term best describes this
service? - ANSWER-function as a service (FaaS)
Amanda would like to run a security configuration scan of her Microsoft Azure
cloud environment. Which one of the following tools would be most appropriate
for her needs? - ANSWER-ScoutSuite
Ben sets up a system that acts like a vulnerable host in order to observe attacker
behavior. What type of system has he set up? - ANSWER-A honeypot
Michelle has been asked to review her corporate network's design for single points
of failure that would impact the core network operations. The following graphic
shows a redundant network design with a critical fault: a single point of failure that
could take the network offline if it failed. Where is this single point of failure? -
ANSWER-Point A
Internet service provider <---> Internet
COPYRIGHT ©️ 2025 ALL RIGHTS RESERVED...TRUSTED & VERIFIED 3