Courseiva

CCNA Security Questions

48 of 123 questions · Page 2/2 · Security · Answers revealed

76
MCQmedium

An organization adopts the 3-2-1 backup rule. Which of the following practices aligns with this rule?

A.Three copies of data on two different media types, with one offsite
B.Four backups all stored on tape
C.One backup stored in the same location as the original
D.Two copies of data on the same hard drive
AnswerA

The 3-2-1 rule specifies exactly three copies of data, stored on two different media types, with one copy held offsite. Option A restates this structure precisely, satisfying all three elements of the rule rather than only part of it.

Why this answer

The 3-2-1 rule means three total copies of data (the original plus two backups), stored on two different media types, with at least one copy kept offsite. Option A matches this definition exactly.

Exam trap

FC0-U71 often tests whether candidates can distinguish the 3-2-1 rule from generic 'multiple backups' answers — options that increase copy count but ignore media diversity or offsite placement are the common distractors.

How to eliminate wrong answers

Option B is wrong because four backups all on tape violates the 'two different media types' requirement and does not specify offsite storage — quantity alone does not satisfy 3-2-1. Option C is wrong because a single backup stored in the same location as the original violates both the 'three copies' and 'one offsite' requirements, leaving data vulnerable to site-wide disasters. Option D is wrong because two copies on the same hard drive provides no redundancy against drive failure and violates the media diversity and offsite requirements.

77
MCQhard

A security analyst notices that a user's computer is running slowly and displaying many pop-up ads. Which type of malware is most likely causing this?

A.Spyware
B.Ransomware
C.Rootkit
D.Adware
AnswerD

Adware specifically injects unwanted advertisements and pop-ups into the user's browsing or desktop environment, which directly matches the symptoms described. Unlike ransomware or worms, adware's primary payload is persistent advertising delivery, and the resulting background processes and browser injections also consume CPU and memory, explaining the reported slowdown.

Why this answer

Adware displays unwanted advertisements and often causes performance issues. Spyware collects information, ransomware encrypts files, and a rootkit hides itself.

78
MCQeasy

Which of the following is a characteristic of a strong password?

A.Contains a combination of uppercase, lowercase, numbers, and symbols
B.Is exactly 8 characters long
C.Uses only lowercase letters
D.Is the same as the username
AnswerA

Length alone is insufficient; complexity across character classes defeats dictionary and brute-force attacks. Mixing uppercase, lowercase, digits and symbols expands the search space, satisfying the stem's requirement for a strong password characteristic rather than a weak, easily guessed one.

Why this answer

A strong password uses a mix of character types — uppercase, lowercase, numbers, and symbols — to increase entropy and resist brute-force and dictionary attacks. This complexity requirement is a widely accepted characteristic of strong passwords. Length also matters, but among the options, the combination of character classes is the defining characteristic.

Exam trap

The trap is fixating on a specific length (like 8 characters) as the hallmark of strength — candidates may overlook that character diversity and overall length together determine resistance to cracking.

How to eliminate wrong answers

Option B is wrong because exactly 8 characters is generally considered too short by modern standards (NIST recommends at least 8, but longer is better); length alone without complexity is weak. Option C is wrong because using only lowercase letters drastically reduces the search space, making the password easy to crack. Option D is wrong because using the same as the username is a critical weakness — it is easily guessed and violates basic password policy.

79
Multi-Selecteasy

Which TWO of the following are examples of physical security controls?

Select 2 answers
A.A security guard at the entrance
B.A firewall
C.Antivirus software
D.An intrusion detection system
E.A lock on a server room door
AnswersA, E

A security guard is a personnel-based physical control that deters, detects and responds to unauthorised entry at a facility. Guards operate on the physical plane rather than through logical access mechanisms, satisfying the stem's requirement for a physical security control example.

Why this answer

A security guard at the entrance (A) is a physical security control because it involves a human presence that deters, detects, and responds to unauthorized physical access to a facility. A lock on a server room door (E) is also a physical security control, as it is a mechanical barrier that restricts physical access to the servers and other hardware inside. In contrast, a firewall (B) is a logical/network security control that filters traffic based on rules, not a physical barrier.

Antivirus software (C) is a host-based logical control that detects and removes malicious code. An intrusion detection system (D) is a logical monitoring control that analyzes network or host activity for signs of attacks, so it is not a physical control either.

80
MCQhard

A security administrator is reviewing authentication logs and notices hundreds of failed login attempts against many user accounts from a single external IP address within a few minutes. No accounts were successfully accessed. Which type of attack is occurring?

A.Phishing campaign
B.Denial-of-service attack
C.Man-in-the-middle attack
D.Brute-force attack
AnswerD

A brute-force attack systematically tries many username and password combinations rapidly from one or more sources, producing exactly the pattern of hundreds of failed logins across many accounts in a short window. The absence of successful logins indicates the guesses have not yet succeeded. This signature distinguishes it from attacks that manipulate trust or intercept traffic.

Why this answer

The log shows automated, high-volume login attempts against many accounts from one source with no successes, which is the classic fingerprint of a brute-force attack. Phishing requires user interaction and would not produce this server-side pattern. Man-in-the-middle and denial-of-service attacks have different goals and signatures, so brute force is the accurate classification.

Exam trap

The trap here is seeing many failed logins and assuming a denial-of-service attack, when the attempts target credentials rather than service availability.

81
MCQmedium

A company implements a policy requiring employees to use a password and a one-time code sent to their mobile phone when logging into the corporate network. Which security concept is being employed?

A.Role-based access control
B.Single sign-on
C.Multi-factor authentication
D.Biometrics
AnswerC

Combining a password (something known) with a one-time code sent to a mobile phone (something possessed) satisfies two distinct authentication factors, which is precisely what multi-factor authentication requires. The policy's two-step login therefore instantiates MFA rather than single-factor or knowledge-based authentication alone.

Why this answer

Multi-factor authentication (MFA) requires two or more verification factors to gain access, such as a password (something you know) and a one-time code sent to a mobile phone (something you have). This combination enhances security by adding a layer beyond just a password.

Exam trap

FC0-U71 often tests security concepts, and candidates might confuse MFA with SSO or RBAC, especially when the scenario involves multiple steps for authentication.

How to eliminate wrong answers

Option A is wrong because role-based access control (RBAC) restricts access based on user roles, not on authentication factors. Option B is wrong because single sign-on (SSO) allows users to authenticate once and access multiple applications, but it does not inherently require multiple factors. Option D is wrong because biometrics uses physical characteristics like fingerprints, which is not the case here; the second factor is a code sent to a phone.

82
MCQmedium

A user receives an email that appears to be from their bank, asking them to click a link and verify their account details. The user notices the email address is slightly misspelled (e.g., 'support@bankk.com' instead of 'support@bank.com'). Which type of attack is this?

A.Smishing
B.Phishing
C.Spear phishing
D.Vishing
AnswerB

Phishing is a broad, untargeted campaign that impersonates a trusted entity, here a bank, to trick recipients into clicking links and disclosing credentials. The misspelled sender domain is a classic spoofing indicator, and the mass, generic nature of the lure distinguishes it from targeted spear phishing.

Why this answer

This is a phishing attack because it uses a fraudulent email impersonating a trusted institution (the bank) to trick the recipient into clicking a link and revealing account credentials. The misspelled domain is a classic phishing indicator designed to look legitimate at a glance. It is a broad, untargeted credential-harvesting attempt.

Exam trap

FC0-U71 often tests the distinction between phishing, spear phishing, smishing, and vishing, and candidates commonly pick spear phishing whenever a specific organization is named, even though the attack is generic and untargeted.

How to eliminate wrong answers

Option A is wrong because smishing is phishing conducted via SMS text messages, not email. Option C is wrong because spear phishing is a targeted attack aimed at a specific individual or small group using personalized details, whereas this email is a generic mass attempt. Option D is wrong because vishing is voice phishing conducted over phone calls, not email.

83
MCQmedium

A technician is asked to dispose of several old hard drives that contained customer records. The drives still function and the company wants to reuse them in a different department. Which action BEST protects the data while allowing reuse?

A.Store the drives in a locked cabinet until they are needed again.
B.Reformat the drive with a different file system.
C.Delete all files and empty the recycle bin.
D.Overwrite the entire drive with random data using a secure wipe utility.
AnswerD

Overwriting every addressable sector with random data destroys the original contents so they cannot be recovered through normal forensic recovery. Because the procedure leaves the drive functional, it satisfies both requirements: protecting customer records and allowing the hardware to be reused in another department. A full-drive overwrite is the standard sanitization method for magnetic media that will remain in service.

Why this answer

When magnetic media will be reused, the data must be rendered unrecoverable without destroying the hardware. A full-drive overwrite with random data replaces the original contents at the sector level, so forensic recovery tools cannot reconstruct the customer records. Deleting, reformatting, or merely locking up the drives leaves the original data intact and therefore does not meet the confidentiality requirement.

Exam trap

The trap here is treating deletion or reformatting as if it removes data, when those operations only remove file system references and leave the original sectors readable.

84
MCQeasy

Which of the following is the best practice for creating a strong password?

A.Using your pet's name
B.Using the same password for multiple accounts
C.Using a sequence of 8 characters with letters only
D.Using a 14-character phrase with numbers and symbols
AnswerD

A 14-character passphrase with numbers and symbols combines length with character variety, producing high entropy that resists brute-force and dictionary attacks. This satisfies the stem's best-practise requirement, outperforming short complex strings or single words with trivial substitutions.

Why this answer

A strong password is at least 12 characters with a mix of uppercase, lowercase, numbers, and symbols.

85
Multi-Selectmedium

Which TWO of the following are examples of social engineering attacks? (Select TWO.)

Select 2 answers
A.Rootkit
B.Pretexting
C.Worm
D.Tailgating
E.Ransomware
AnswersB, D

Pretexting is a social engineering technique where an attacker invents a fabricated scenario, such as posing as IT support or an auditor, to manipulate a victim into divulging information or performing actions. It relies on human trust rather than technical exploits, matching the stem's social engineering criterion.

Why this answer

Pretexting (B) is a social engineering attack because it manipulates a person through a fabricated scenario or false identity to obtain information or access, exploiting human trust rather than technical vulnerabilities. Tailgating (D) is also a social engineering attack, as it relies on physically following an authorized person into a restricted area without proper credentials, exploiting human courtesy or inattention. The remaining options are technical malware or attack types rather than social engineering: a rootkit (A) is stealthy software that hides privileged access, a worm (C) is self-replicating malware that spreads across networks, and ransomware (E) is malware that encrypts data and demands payment.

Exam trap

FC0-U71 often mixes malware categories with social engineering categories in the same option list — candidates must recognize that rootkits, worms, and ransomware are technical attacks, not human manipulation.

86
MCQhard

An attacker sets up a fake wireless access point named "Cafe_Free_WiFi" in a coffee shop and uses it to capture the traffic of customers who connect. Which type of attack is this?

A.Evil twin
B.Denial of service
C.Cross-site scripting
D.SQL injection
AnswerA

An evil twin is a rogue access point that imitates a legitimate hotspot to lure users into connecting, allowing the attacker to intercept or manipulate their traffic. The scenario describes exactly this: a fraudulent access point with an appealing name capturing customer data. It is a wireless-specific attack that exploits users' willingness to join open networks without verifying the hotspot's authenticity.

Why this answer

An evil twin is a rogue access point that impersonates a legitimate hotspot to trick users into connecting, enabling the attacker to capture or alter their traffic. The scenario's fake "Cafe_Free_WiFi" access point matches this definition precisely. Denial of service disrupts availability, while SQL injection and cross-site scripting are web application attacks unrelated to wireless impersonation and traffic interception.

Exam trap

The trap here is confusing an evil twin with a denial-of-service attack, because both can involve wireless interference, but only the evil twin impersonates a hotspot to intercept traffic.

87
MCQmedium

A small accounting firm's wireless network currently uses WPA2-Personal with a shared passphrase that all 20 employees know. The office manager reports that a former contractor who was given the passphrase can still connect to the Wi-Fi from the parking lot. The firm wants each user to authenticate with their own unique credentials and wants to be able to revoke access for one person without disrupting everyone else. Which wireless security method should the firm implement?

A.MAC address filtering on the wireless access point
B.Wi-Fi Protected Setup (WPS) with push-button configuration for each employee
C.WPA2-Enterprise with 802.1X authentication against a RADIUS server
D.WPA3-Personal with Simultaneous Authentication of Equals (SAE)
AnswerC

WPA2-Enterprise uses IEEE 802.1X so each user authenticates with individual credentials validated by a RADIUS server, and the firm can disable just the former contractor's account. The shared passphrase problem disappears because no pre-shared key is distributed to clients. This directly satisfies both requirements: unique per-user credentials and selective, non-disruptive revocation.

Why this answer

The firm needs two things a shared passphrase cannot provide: distinct credentials per person and the ability to cut off one account without rekeying the whole office. WPA2-Enterprise pairs 802.1X with a RADIUS server so each login is validated individually against a directory, and disabling the contractor's account instantly blocks that person. Personal modes, MAC filtering, and WPS all rely on a network-wide secret or device identifiers rather than user identity.

Exam trap

The trap here is assuming that moving from WPA2-Personal to WPA3-Personal fixes shared-credential problems, when WPA3-Personal still uses one passphrase for all users.

88
MCQmedium

Which of the following is an example of something you are in multi-factor authentication?

A.Password
B.Fingerprint scan
C.Smart card
D.One-time passcode
AnswerB

A fingerprint scan is a biometric characteristic inherent to the user's body, making it an inherence factor — the "something you are" category. It differs from possession factors such as tokens and knowledge factors such as passwords, matching the stem's requirement for a multi-factor authentication example.

Why this answer

In multi-factor authentication, the three factor categories are something you know (password, PIN), something you have (smart card, token, phone), and something you are (biometric — fingerprint, retina, face). A fingerprint scan is a biometric, which falls under 'something you are,' making it the correct example of an 'are' factor.

Exam trap

The trap is that candidates confuse authentication factors with authentication methods — they may pick 'one-time passcode' thinking it's a distinct factor, but OTP is a possession factor, and only biometrics qualify as 'something you are.'

How to eliminate wrong answers

Option A (Password) is wrong because a password is 'something you know,' not 'something you are.' Option C (Smart card) is wrong because a smart card is a physical token, which is 'something you have,' not 'something you are.' Option D (One-time passcode) is wrong because an OTP is typically delivered to a device you possess or generated by an app, making it 'something you have' (or in some interpretations a knowledge factor if memorized), not a biometric 'are' factor.

89
MCQeasy

Which of the following best describes the principle of confidentiality in the CIA triad?

A.Data is not altered unexpectedly
B.Systems are accessible when needed
C.Ensuring data is backed up regularly
D.Preventing unauthorized access to information
AnswerD

Preventing unauthorized access to information directly satisfies the confidentiality principle, which safeguards data from disclosure to parties lacking authorisation. Unlike integrity, which preserves data accuracy, or availability, which ensures timely access, confidentiality centres on restricting read access through controls such as encryption, access permissions and Microsoft Entra ID authentication policies.

Why this answer

Confidentiality in the CIA triad means ensuring information is not disclosed to unauthorized individuals, entities, or processes — i.e., preventing unauthorized access to information. It is enforced through encryption, access controls, and authentication. The scenario's phrasing 'preventing unauthorized access to information' is the textbook definition of confidentiality.

Exam trap

The trap is that backup-related answers sound security-relevant, so candidates pick them for confidentiality — but backups map to availability and integrity, while confidentiality is specifically about preventing unauthorized disclosure.

How to eliminate wrong answers

Option A is wrong because 'data is not altered unexpectedly' describes integrity, which protects against unauthorized modification. Option B is wrong because 'systems are accessible when needed' describes availability, which ensures timely and reliable access to resources. Option C is wrong because regular backups support availability and recovery (and can support integrity), but backups alone do not prevent unauthorized disclosure — confidentiality is about access control and encryption, not backup frequency.

90
MCQmedium

A help desk technician receives a call from someone claiming to be a company vice president who is traveling and urgently needs their password reset over the phone. The caller's number matches an internal extension. Which action should the technician take FIRST?

A.Provide a temporary password that expires in one hour and end the call.
B.Verify the caller's identity using the organization's established out-of-band procedure.
C.Reset the password immediately to avoid delaying the executive.
D.Ask the caller to email the request from their company address instead.
AnswerB

Following the documented verification process, such as calling back a known number or using a shared challenge, confirms the request is genuine before any account change. This counters pretexting and caller ID spoofing while still allowing legitimate urgent requests to be handled. Verification first is the correct sequence for any sensitive account action.

Why this answer

Urgency and a spoofable phone number are classic pretexting indicators. The technician should first confirm the caller's identity through the organization's out-of-band verification procedure, such as calling back a number from the directory or using a shared challenge. Only after verification should any password reset occur, which protects high-value accounts while still serving legitimate users.

Exam trap

The trap here is letting the claimed executive title and urgency override identity verification, when caller ID and pressure are exactly what pretexting relies on.

91
MCQmedium

A user is working from a coffee shop and needs to access the corporate file server. The user connects to the coffee shop's open Wi-Fi network and wants to ensure that the data transmitted between the laptop and the corporate network cannot be read by others on the same network. Which of the following should the user implement?

A.Use a VPN connection to the corporate network
B.Change the Wi-Fi network password
C.Enable the laptop's host-based firewall
D.Disable file sharing on the laptop
AnswerA

A VPN creates an encrypted tunnel between the laptop and the corporate network, protecting data from being read by others on the coffee shop Wi-Fi. Even if an attacker captures the traffic, it remains encrypted and unreadable. This directly addresses the need to keep transmitted data confidential while using an untrusted network, making it the correct solution.

Why this answer

When using an untrusted network such as open Wi-Fi, data in transit can be intercepted. A VPN encrypts the connection between the user's device and the corporate network, ensuring confidentiality. The other choices either do not encrypt traffic or address local sharing rather than protecting data as it travels, so they fail to meet the user's security need.

Exam trap

The trap here is assuming that a firewall or disabling file sharing protects data in transit, when only encryption such as a VPN provides confidentiality on an untrusted network.

92
MCQmedium

A user is browsing the web on a public Wi-Fi network at a coffee shop and needs to check a personal bank account. The bank's website address begins with https. Which statement BEST describes how the user's connection is protected?

A.HTTPS encrypts the connection between the browser and the bank's web server.
B.The bank's firewall prevents anyone on the same Wi-Fi network from viewing the user's traffic.
C.The public Wi-Fi network encrypts all traffic between the user and the bank automatically.
D.The browser's private browsing or incognito mode protects the session from interception.
AnswerA

HTTPS uses TLS to encrypt data exchanged between the browser and the bank's server, and it authenticates the server with a digital certificate. Even on an untrusted public Wi-Fi network, an attacker who captures the traffic sees ciphertext rather than account details. This is why the address beginning with https materially changes the risk compared with a plain HTTP site.

Why this answer

HTTPS wraps HTTP in TLS, which encrypts the session between the browser and the bank's server and verifies the server's identity through a certificate. That encryption persists regardless of how untrusted the local Wi-Fi network is, so an eavesdropper on the same network captures unreadable data. The other options either misattribute the protection to the network or describe local privacy features that do not secure the connection.

Exam trap

The trap here is assuming that a public Wi-Fi network or a browser privacy mode provides the encryption, when the actual protection comes from TLS in the HTTPS connection to the bank.

93
MCQhard

A company requires employees to use a one-time code from a smartphone app in addition to their password to log into the corporate VPN. This is an example of:

A.Single factor authentication
B.Multi-factor authentication
C.Two-step verification using the same factor
D.Biometric authentication
AnswerB

Multi-factor authentication combines something you know (the password) with something you have (the smartphone app generating the one-time code), satisfying the requirement for two distinct credential categories at VPN login. Because the code is time-limited and device-bound, a stolen password alone cannot grant access, which is precisely the layered verification the scenario demands.

Why this answer

Using a one-time code from a smartphone app in addition to a password combines two different authentication factors: something you know (the password) and something you have (the smartphone app generating the OTP). This satisfies the definition of multi-factor authentication because it uses two distinct factor categories.

Exam trap

The trap is that candidates may pick 'two-step verification using the same factor' because they see two steps (password + code) and assume both are knowledge factors — but the smartphone app OTP is a possession factor, making this true MFA, not same-factor two-step verification.

How to eliminate wrong answers

Option A (Single factor authentication) is wrong because two distinct factors are being used, not one. Option C (Two-step verification using the same factor) is wrong because the password (knowledge) and the smartphone app OTP (possession) are different factor categories, not the same factor used twice. Option D (Biometric authentication) is wrong because no biometric (fingerprint, face, iris) is involved — the OTP app is a possession factor, not an inherence factor.

94
Multi-Selecthard

Which THREE of the following are characteristics of a strong password? (Select THREE)

Select 3 answers
A.At least 12 characters in length
B.Contains uppercase, lowercase, numbers, and symbols
C.Includes the user's birth date
D.Is unique and not used on other accounts
E.Is reused across multiple accounts
AnswersA, B, D

A 12-character minimum directly increases the search space an attacker must exhaust, making brute-force and hash-cracking attacks computationally impractical. Length is the dominant factor in password entropy, so this satisfies the stem's requirement for a strong-password characteristic, independent of complexity rules or composition.

Why this answer

Option A is correct because a minimum length of at least 12 characters increases the search space an attacker must cover in a brute-force or dictionary attack, making the password substantially harder to crack. Option B is correct because mixing uppercase letters, lowercase letters, numbers, and symbols expands the character set and defeats simple dictionary and pattern-based guessing techniques. Option D is correct because using a unique password that is not reused on other accounts prevents credential-stuffing attacks, where a breach of one service would otherwise compromise multiple accounts.

Option C is incorrect because including a user's birth date creates a predictable, easily guessable value often obtainable from social media or public records. Option E is incorrect because reusing a password across multiple accounts is a dangerous practice that amplifies the impact of any single credential leak.

Exam trap

The trap here is that candidates may select 'includes the user's birth date' thinking personalization adds security, or miss that 'unique and not reused' is a strength characteristic rather than a convenience feature.

95
MCQmedium

A company wants to protect its network from unauthorized external access. Which of the following devices should be configured to filter traffic based on port and protocol?

A.Network firewall
B.Host-based firewall
C.VPN concentrator
D.Antivirus software
AnswerA

A network firewall inspects inbound and outbound packets, applying rules that permit or deny traffic by TCP/UDP port and protocol. This directly satisfies the requirement to filter unauthorised external access at the network perimeter, unlike switches or access points that forward traffic without such policy enforcement.

Why this answer

A network firewall is specifically designed to inspect and filter traffic traversing the network perimeter based on rules that match port numbers, protocols (TCP/UDP/ICMP), and source/destination IP addresses. It sits between the internal network and external networks, making it the correct device to block unauthorized external access at the network boundary.

Exam trap

The trap is confusing host-based firewalls with network firewalls — candidates see 'firewall' in both options and pick the host-based one, forgetting the question asks about protecting the entire network from external access, which requires a perimeter device.

How to eliminate wrong answers

Option B is wrong because a host-based firewall protects only the individual host it is installed on, not the entire network perimeter — it cannot filter traffic for all devices on the network. Option C is wrong because a VPN concentrator's role is to terminate encrypted VPN tunnels and authenticate remote users; while it may have limited ACL capabilities, its primary function is secure remote access, not general port/protocol traffic filtering. Option D is wrong because antivirus software detects and removes malicious software on endpoints — it operates at the application/file level and does not filter network traffic by port or protocol.

96
MCQhard

Which of the following is a characteristic of a worm compared to a virus?

A.A worm is always disguised as legitimate software
B.A worm is a type of ransomware
C.A worm can self-replicate without user intervention
D.A worm requires a host file to replicate
AnswerC

Worms self-replicate autonomously across networks by exploiting vulnerabilities, requiring no host file or user action. This directly satisfies the stem's comparison: unlike viruses, which need a user to execute an infected file, a worm propagates independently, enabling rapid, self-sustaining spread without human intervention.

Why this answer

A worm is defined by its ability to self-replicate and propagate across networks without requiring user interaction or a host file. It exploits vulnerabilities or uses network shares to spread autonomously, distinguishing it from a virus, which requires a host file and typically user action (like opening an attachment) to execute and replicate.

Exam trap

FC0-U71 often tests the worm/virus distinction by offering 'requires a host file' as a distractor — candidates who confuse replication mechanisms with delivery mechanisms pick the wrong answer.

How to eliminate wrong answers

Option A is wrong because disguising as legitimate software describes a Trojan, not a worm — Trojans rely on social engineering to trick users into running them. Option B is wrong because ransomware is a payload category (encrypts files for extortion); a worm is a propagation mechanism, and while some worms deliver ransomware, the two are not synonymous. Option D is wrong because requiring a host file to replicate is the defining characteristic of a virus, not a worm — worms are standalone programs.

97
MCQmedium

A finance team member must share a spreadsheet containing customer account numbers with an external auditor. The team member wants to ensure that only the intended recipient can read the file contents. Which action BEST accomplishes this?

A.Encrypt the file using the auditor's public key
B.Compress the spreadsheet into a password-protected ZIP archive and email the password separately
C.Rename the file with a .txt extension before attaching it to the email
D.Apply a read-only permission to the file before sending it
AnswerA

Encrypting with the recipient's public key means only the matching private key, held by the auditor, can decrypt the contents. Even if the message is intercepted in transit or lands in the wrong mailbox, the ciphertext is useless without that private key. This is the standard way to guarantee that a specific individual is the only party able to read a file.

Why this answer

Ensuring that only the intended recipient can read a file requires confidentiality that survives interception, which means cryptography tied to that recipient's identity. Encrypting with the auditor's public key ensures only the auditor's private key can decrypt the contents. Renaming, read-only attributes, and weak archive passwords all leave the data readable or easily recovered by anyone who obtains the file.

Exam trap

The trap here is mistaking measures that discourage casual access, such as read-only flags or renamed extensions, for actual cryptographic confidentiality.

98
MCQmedium

A warehouse supervisor reports that an unknown person wearing a delivery uniform walked through the open loading dock, entered the server room, and left with a backup drive. The company wants to prevent unauthorized entry into the server room without rebuilding the entire facility. Which control should be implemented FIRST?

A.Deploy a security information and event management (SIEM) platform to correlate logs
B.Install an electronic badge reader on the server room door that logs each entry attempt
C.Encrypt the backup drives stored in the server room
D.Provide security awareness training to all warehouse employees
AnswerB

A badge reader enforces authentication at the specific point of weakness: the server room door. Only staff with valid badges can enter, and the audit log records who attempted access and when. This directly stops the walk-in intrusion described while also providing accountability, making it the most targeted and immediate fix.

Why this answer

The incident shows an outsider reaching a restricted area through an uncontrolled opening, so the first fix must prevent unauthorized entry at that boundary. A badge reader on the server room door authenticates individuals and logs attempts, directly addressing the gap. A SIEM, awareness training, and drive encryption are valuable but do not stop someone from walking in and carrying equipment out.

Exam trap

The trap here is choosing a monitoring or awareness tool, which detects or discourages, instead of a preventive access control that physically stops the unauthorized entry.

99
MCQhard

A security analyst discovers that a file on a server has been modified without authorization. However, the system logs show that the modification was made by an authenticated user who had legitimate access to the file. Which aspect of the CIA triad has been violated?

A.Non-repudiation
B.Integrity
C.Availability
D.Confidentiality
AnswerB

Integrity means data remains unaltered except by authorised action. Although the user was authenticated and had legitimate access, the modification itself was unauthorised, so the file's trustworthiness was compromised. Confidentiality and availability are unaffected, as no data was exposed or made inaccessible.

Why this answer

Integrity ensures that data is not modified or altered without authorization. Even though the user was authenticated and had legitimate access, the modification was unauthorized, which violates the integrity of the file. The CIA triad's integrity aspect is about protecting data from unauthorized changes.

Exam trap

FC0-U71 often tests the CIA triad by presenting scenarios where the user is authorized but the action is unauthorized; candidates may incorrectly choose confidentiality or availability because they focus on the user's access rather than the nature of the violation.

How to eliminate wrong answers

Option A is wrong because non-repudiation is not part of the CIA triad; it is a separate concept ensuring that a party cannot deny having performed an action. Option C is wrong because availability ensures data is accessible when needed; the scenario does not mention data being unavailable. Option D is wrong because confidentiality ensures data is not disclosed to unauthorized parties; the scenario is about modification, not disclosure.

100
MCQhard

A security administrator wants to protect data at rest on a laptop that may be lost or stolen. Which of the following is the BEST solution?

A.Use a VPN when connecting to the internet
B.Install a host-based firewall
C.Enable full disk encryption
D.Implement strong password policies
AnswerC

Full disk encryption renders the entire drive unreadable without the decryption key, so a lost or stolen laptop's data at rest stays protected even if the disk is removed. It covers all files and the operating system, satisfying the requirement without relying on per-file user action.

Why this answer

Full disk encryption (FDE) protects data at rest by encrypting the entire volume, so if the laptop is lost or stolen the data is unreadable without the decryption key. This directly addresses the threat of physical device compromise, which is the scenario described.

Exam trap

FC0-U71 often tests the distinction between data-at-rest and data-in-transit controls — candidates pick VPN or firewall when the scenario is specifically about a lost/stolen device.

How to eliminate wrong answers

Option A is wrong because a VPN protects data in transit over untrusted networks; it does nothing for data at rest on a stolen laptop. Option B is wrong because a host-based firewall filters network traffic to/from the host and does not encrypt stored data. Option D is wrong because strong password policies improve authentication but do not protect the data if the disk is removed and read offline — an attacker can bypass the OS login by mounting the drive.

101
MCQeasy

Which of the following is an example of a physical security control?

A.Password policy
B.Antivirus software
C.Biometric door lock
D.Firewall
AnswerC

A biometric door lock restricts entry to a physical space by verifying a fingerprint or iris, so it operates on the tangible premises rather than on data, accounts or logical permissions. That places it squarely within physical security controls, unlike encryption or access lists.

Why this answer

Physical security controls include measures like locks, guards, and biometric scanners to protect physical assets.

102
MCQhard

An attacker gains physical access to a building by following an employee through a secured door without using a badge. This is an example of which social engineering technique?

A.Phishing
B.Baiting
C.Pretexting
D.Tailgating
AnswerD

Tailgating occurs when an unauthorised person physically follows an authorised individual through a secured door, exploiting courtesy rather than defeating the badge reader. The stem's badge-less entry behind an employee matches this technique exactly, distinguishing it from phishing or pretexting.

Why this answer

Tailgating (also called piggybacking) is the social engineering technique where an attacker follows an authorized employee through a secured door without using their own credentials. It exploits politeness or inattention rather than technical vulnerabilities, and it is a physical social engineering attack.

Exam trap

FC0-U71 often tests the confusion between tailgating (following through a door) and pretexting (creating a false scenario), since both are social engineering techniques but differ in mechanism.

How to eliminate wrong answers

Option A is wrong because phishing is a digital attack that uses fraudulent emails or messages to trick users into revealing credentials or clicking malicious links — it does not involve physical access. Option B is wrong because baiting involves leaving a physical or digital item (such as a USB drive) to entice a victim to plug it in or interact with it. Option C is wrong because pretexting involves creating a fabricated scenario or false identity to manipulate a victim into providing information or access, not physically following someone through a door.

103
MCQmedium

What is the primary purpose of a firewall?

A.To encrypt data on the hard drive
B.To detect and remove viruses
C.To prevent unauthorized network access
D.To manage user passwords
AnswerC

A firewall inspects incoming and outgoing traffic against configured rules, permitting or blocking packets based on source, destination, port and protocol. This filtering enforces the boundary between trusted and untrusted networks, directly fulfilling the stem's stated purpose of preventing unauthorised network access.

Why this answer

A firewall controls incoming and outgoing network traffic based on predetermined security rules. It filters traffic by port, protocol, or IP address to block unauthorized access.

104
MCQmedium

Which type of malware attaches to legitimate files and spreads when those files are executed?

A.Ransomware
B.Virus
C.Worm
D.Trojan
AnswerB

A virus inserts its code into legitimate host files, so execution of the infected file triggers replication and further spread. This directly satisfies the stem's requirement for malware that attaches to legitimate files, unlike worms, which self-replicate across networks without a host file.

Why this answer

A virus attaches itself to files or programs and replicates when the infected file is executed. Worms spread without a host file; trojans disguise as legitimate software.

105
MCQmedium

A small business owner wants to secure the wireless network at a retail store. The owner wants customers to have internet access without needing a password, but also wants to keep the internal point-of-sale (POS) network separate and protected. Which of the following should the owner configure?

A.Enable WPA3-Personal on the main network and share the passphrase only with employees.
B.Configure MAC address filtering to allow only known customer devices on the wireless network.
C.Disable SSID broadcasting on the wireless access point.
D.Set up a guest network with SSID isolation and client isolation enabled.
AnswerD

A guest network with a separate SSID, VLAN, and client isolation allows customers to connect without a password while keeping their traffic and the internal POS network separate. This is the standard method to provide public access without exposing internal resources, and it directly meets both stated requirements.

Why this answer

The requirement is to give customers open internet access while keeping the POS network protected. A separate guest network with client isolation achieves this by segmenting traffic and preventing guests from reaching internal devices. Other options either require credentials, do not segment traffic, or rely on easily bypassed controls.

Exam trap

The trap here is assuming that hiding the SSID or filtering MAC addresses provides security equivalent to network segmentation for guest access.

106
Multi-Selecteasy

Which TWO of the following are characteristics of a strong password? (Select TWO.)

Select 2 answers
A.Includes uppercase letters, numbers, and symbols
B.Uses a common dictionary word
C.At least 12 characters long
D.Based on your birth date
E.Contains only lowercase letters
AnswersA, C

Mixing uppercase letters, numbers, and symbols increases the search space an attacker must exhaust, directly satisfying the complexity requirement for strong passwords. This character-variety approach makes brute-force and dictionary attacks substantially harder, since each added character class multiplies the possible combinations. It complements length, the other core strength factor.

Why this answer

Option A is correct because a strong password should combine uppercase letters, numbers, and symbols to increase its character-set complexity, making brute-force and dictionary attacks far less effective. Option C is correct because a minimum length of at least 12 characters significantly increases the number of possible combinations, which is a key factor in resisting cracking attempts. Options B, D, and E are not correct: a common dictionary word (B) is easily guessed via dictionary attacks, a birth date (D) is predictable personal information, and using only lowercase letters (E) severely limits the character set and thus the password's strength.

107
Multi-Selecthard

A user receives a suspicious email with an attachment claiming to be an invoice. Which three practices should the user follow? (Select THREE.)

Select 3 answers
A.Do not download unexpected attachments
B.Verify the sender's email address carefully
C.Forward the email to all employees for awareness
D.Hover over any links to see the actual URL before clicking
E.Download and open the attachment to check its content
AnswersA, B, D

Avoiding unexpected attachments removes the malware delivery vector entirely, since invoice-themed phishing relies on the user opening the file to execute its payload. This satisfies the stem's suspicious-email constraint without depending on antivirus detection or sender verification, both of which can fail against newly crafted lures.

Why this answer

Option A is correct because unexpected attachments are a primary malware and phishing delivery vector, so the user should not download or open them. Option B is correct because attackers often spoof or typosquat sender addresses, so carefully verifying the sender's actual email address helps confirm legitimacy. Option D is correct because hovering over a link reveals the true destination URL in the status bar or tooltip, exposing mismatched or malicious domains before any click.

Option C is wrong because forwarding a suspicious email to all employees can spread malicious links or attachments and cause panic; it should instead be reported to IT/security. Option E is wrong because downloading and opening the attachment to inspect it can execute malicious code and compromise the user's system.

Exam trap

FC0-U71 often tests the misconception that opening an attachment to verify its content is a safe practice, when in fact it directly triggers the malware.

108
MCQhard

A company implements a policy where employees must swipe their ID card and then enter a PIN to access the server room. Which two authentication factors are being used?

A.Something you know and something you are
B.Something you have and something you are
C.Something you have and something you know
D.Something you know and somewhere you are
AnswerC

The ID card supplies something you have, while the PIN supplies something you know. Combining a physical token with memorised secret satisfies two distinct authentication factor categories, which is the two-factor requirement described in the policy.

Why this answer

The ID card is 'something you have' (possession factor) and the PIN is 'something you know' (knowledge factor). This is multi-factor authentication.

109
MCQmedium

An organization wants to ensure that employees only have access to the data necessary to perform their job functions. Which principle should be applied?

A.Defense in depth
B.Separation of duties
C.Mandatory access control
D.Least privilege
AnswerD

Least privilege grants users only the minimum access needed for their job tasks, directly satisfying the requirement that employees reach solely the data necessary for their functions. It limits blast radius from compromised or misused accounts.

Why this answer

The principle of least privilege grants users only the permissions they need to do their work, minimizing potential damage.

110
Multi-Selectmedium

Which TWO of the following are examples of multi-factor authentication? (Choose TWO.)

Select 2 answers
A.Password and a security question
B.Username and password
C.Smart card and a PIN
D.Two different passwords
E.Password and a fingerprint scan
AnswersC, E

A smart card (something you have) combined with a PIN (something you know) satisfies multi-factor authentication by drawing on two distinct factor categories. This pairing meets the stem's requirement for MFA, unlike single-category methods such as two passwords, which remain knowledge-based only.

Why this answer

Option C (Smart card and a PIN) is correct because it combines two different authentication factor categories: a smart card is something you have (a physical token holding a certificate or key), while a PIN is something you know, satisfying multi-factor authentication. Option E (Password and a fingerprint scan) is correct because it pairs something you know (the password) with something you are (a biometric fingerprint), which are distinct factor types. Options A, B, and D are not multi-factor: A uses two things you know (password and security question), B is a single factor (something you know), and D is also two instances of the same knowledge factor, so none combine different factor categories.

111
MCQmedium

A user receives an email that appears to be from their bank, asking them to click a link and verify their account details. The user notices the sender's email address is slightly misspelled. Which type of threat is this?

A.Rootkit
B.Phishing
C.Tailgating
D.Ransomware
AnswerB

Phishing impersonates a trusted entity by email to trick the recipient into clicking a link and surrendering credentials. The misspelled sender address is the classic spoofing indicator, distinguishing it from malware, which requires execution, or social engineering conducted through other channels.

Why this answer

Phishing is a social engineering attack where attackers send fraudulent emails to steal sensitive information.

112
Multi-Selecteasy

Which TWO of the following are types of malware? (Select TWO)

Select 2 answers
A.Firewall
B.Ransomware
C.Encryption
D.Phishing
E.Spyware
AnswersB, E

Ransomware is malware that encrypts a victim's files or locks their system, then demands payment for the decryption key. This extortion mechanism, holding data hostage until a ransom is paid, places it squarely within the malware category the question asks candidates to identify.

Why this answer

Ransomware (B) is a type of malware that encrypts a victim's files or locks a system and demands payment for restoration, making it a classic malicious software category. Spyware (E) is also malware, designed to covertly monitor user activity and harvest sensitive information such as credentials or browsing habits. A firewall (A) is a security control that filters network traffic, not malware.

Encryption (C) is a legitimate cryptographic technique for protecting data confidentiality, not malicious software. Phishing (D) is a social-engineering attack that tricks users into revealing information, but it is an attack method rather than a malware type.

113
MCQhard

An organization's security policy requires that users prove their identity with something they know and something they have when accessing the payroll system from outside the office. A user enters a password and then a code generated by a mobile app. Which security concept does this scenario illustrate?

A.Single sign-on
B.Role-based access control
C.Federation
D.Multifactor authentication
AnswerD

Multifactor authentication requires evidence from at least two different categories: something the user knows, something the user has, or something the user is. The password represents knowledge, and the code generated by the mobile app represents possession of the enrolled device. Because the two factors come from different categories, this scenario is a textbook example of multifactor authentication protecting access to the payroll system.

Why this answer

Multifactor authentication combines evidence from different categories, such as knowledge, possession, and inherence. A password is something the user knows, and a code generated on an enrolled mobile app is tied to something the user has. Together they satisfy the policy requiring two distinct factor types and make stolen passwords alone insufficient to reach the payroll system.

Exam trap

The trap here is confusing authentication strength with access control or federation, when the deciding detail is that two different factor categories are being presented.

114
Multi-Selectmedium

A user wants to protect their laptop in case it is stolen. Which TWO of the following measures would help protect the confidentiality of the data?

Select 2 answers
A.A strong password set in the BIOS
B.Full disk encryption
C.Using a VPN when connected to public Wi-Fi
D.Using a strong password for the user account
E.Enabling the screen lock with a password
AnswersB, D

Full disk encryption renders the laptop's stored data unreadable without the decryption key, so a thief who removes the drive cannot access its contents. This directly preserves confidentiality of data at rest, satisfying the scenario's requirement should the device be stolen.

Why this answer

Full disk encryption (B) is correct because it encrypts the entire drive, so if the laptop is stolen the data remains unreadable without the decryption key, directly preserving confidentiality. A strong user account password (D) is correct because it prevents a thief from logging into the OS and accessing files under that account, adding an authentication barrier to the data. A BIOS password (A) only restricts firmware/startup access and can often be bypassed or reset, so it does not protect data confidentiality by itself.

A VPN (C) protects data in transit on untrusted networks and does nothing for a stolen device. Screen lock with a password (E) only secures the current session and is trivially bypassed by removing the drive or booting another OS.

Exam trap

The question asks for two measures, and the correct answers are full disk encryption (B) and a strong user account password (D). Option E (screen lock) only helps when the laptop is on and locked, but does not protect data if the device is shut down. Candidates should not confuse screen lock with full data protection.

115
MCQmedium

A small office's wireless router still ships with the administrator username and default password printed in its manual. A technician is asked to harden the device before it goes into production. Which action BEST addresses this specific risk?

A.Disable the SSID broadcast so the network name is hidden
B.Change the default administrative credentials to a unique strong password
C.Enable WPA3 encryption on the wireless network
D.Place the router behind a surge protector in the wiring closet
AnswerB

Default credentials are published in manuals and vendor documentation, so anyone with physical or network access to the management interface can authenticate. Replacing the factory username and password with unique, strong values removes that known-entry path and directly closes the risk described. This is the specific remediation for a device that still uses out-of-box login details.

Why this answer

Factory-default administrative credentials are documented publicly, so a device left with them can be taken over by anyone who reaches its management interface. Replacing those credentials with unique, strong values eliminates the known login path and hardens the device's configuration. Wireless encryption, SSID hiding, and power protection each address different concerns and do not remove the default-account exposure.

Exam trap

The trap here is assuming that enabling strong wireless encryption also secures the router's management login, when the two are entirely separate layers.

116
MCQmedium

A company wants to ensure that data on lost laptops cannot be accessed. Which technology should be used?

A.VPN
B.Firewall
C.Full disk encryption
D.Antivirus software
AnswerC

Full disk encryption protects data at rest by encrypting the entire drive, so a lost laptop's contents are unreadable without the decryption key. This directly satisfies the requirement that data on lost laptops cannot be accessed, since the volume stays encrypted even if the device is stolen.

Why this answer

Full disk encryption (FDE) encrypts the entire storage volume so that if a laptop is lost or stolen, the data is unreadable without the decryption key (typically tied to a TPM or user credential). This directly addresses the requirement that data on lost laptops cannot be accessed, even if the drive is removed and mounted elsewhere.

Exam trap

The trap is confusing network security controls (VPN, firewall) with data-at-rest protection. The question specifies 'lost laptops,' which is a physical theft scenario — only encryption addresses that threat.

How to eliminate wrong answers

Option A is wrong because a VPN protects data in transit over untrusted networks; it does nothing to protect data at rest on a stolen laptop. Option B is wrong because a firewall filters network traffic at the perimeter or host; it has no role in protecting data on a lost device's disk. Option D is wrong because antivirus software detects and removes malware; it does not encrypt data at rest and cannot prevent access to files on a stolen drive.

117
MCQmedium

An employee at a marketing firm plugs an unknown USB flash drive found in the parking lot into a workstation to identify its owner. Within minutes, files on a shared network folder begin to be renamed with a .locked extension and a ransom note appears. Which type of malware most likely caused this behavior?

A.Keylogger
B.Worm
C.Rootkit
D.Ransomware
AnswerD

Ransomware encrypts files and appends a distinctive extension such as .locked, then displays a note demanding payment for the decryption key. The rapid spread from one workstation to a shared network folder matches ransomware that enumerates mapped drives and network shares. The vehicle being a found USB drive is a classic delivery method, but the file-renaming and ransom note identify the payload as ransomware.

Why this answer

The telltale signs are files renamed with a new extension and a ransom note demanding payment, which are the defining behaviors of ransomware. Ransomware often arrives via removable media and then enumerates mapped drives and network shares to encrypt as many files as possible. Other malware types may be involved in delivery, but the destructive encryption and extortion identify the payload itself.

Exam trap

The trap here is focusing on the USB delivery method and choosing a propagation category, when the observed file encryption and ransom note identify the payload.

118
MCQeasy

A small business owner wants to keep a record of the software installed on each employee laptop and receive an alert if unauthorized software is installed later. The owner asks a technician for the BEST tool to accomplish this. Which of the following should the technician recommend?

A.File integrity monitoring
B.Asset inventory system
C.Host-based firewall
D.Software inventory tool
AnswerD

A software inventory tool discovers and records the applications installed on each managed device, creating a baseline of authorized software. When it detects a new or unapproved application, it can generate an alert. This directly matches the owner's goal of knowing what is installed and being notified of unauthorized installations, making it the best fit for the described requirement.

Why this answer

The business owner needs both a current list of installed applications and an alert when unauthorized software appears. A software inventory tool provides this by scanning systems, maintaining a baseline, and flagging deviations. Other options address network traffic filtering, general asset tracking, or file change detection, none of which deliver the specific software installation monitoring and alerting required here.

Exam trap

The trap here is confusing general asset inventory or file integrity monitoring with the specific need to track installed applications and alert on unauthorized software installations.

119
MCQmedium

A user downloads a free game from an untrusted website. After installation, the user's computer begins displaying pop-up advertisements frequently. Which type of malware is most likely installed?

A.Ransomware
B.Adware
C.Rootkit
D.Spyware
AnswerB

Adware specifically injects or displays unwanted pop-up advertisements, matching the symptom described after installing the untrusted game. Unlike ransomware, which encrypts files for extortion, or a trojan, which masquerades as legitimate software to deliver payloads, adware's primary function is advertising delivery, satisfying the stem's frequent pop-up constraint.

Why this answer

Adware is malware that automatically displays or downloads unwanted advertisements, often bundled with free software from untrusted sources. The symptom described—frequent pop-up ads after installing a free game—matches adware's defining behavior. Unlike spyware, adware's primary goal is forced advertising rather than covert data collection.

Exam trap

FC0-U71 often tests the distinction between adware (visible ads) and spyware (hidden monitoring), so candidates who see 'untrusted download' and jump to spyware miss the explicit pop-up symptom.

How to eliminate wrong answers

Option A is wrong because ransomware encrypts files and demands payment, which is not described here. Option C is wrong because a rootkit hides itself and provides persistent privileged access, not pop-up ads. Option D is wrong because spyware secretly monitors and exfiltrates user activity, whereas the visible symptom here is advertising.

120
MCQhard

A hospital's pharmacy system requires that every time a pharmacist adjusts a medication order, the system records who made the change, the exact time, and the previous value. Auditors later need to prove that no record was altered after the fact. Which security principle is the hospital primarily implementing?

A.Fault tolerance
B.Confidentiality
C.Availability
D.Non-repudiation
AnswerD

Non-repudiation provides proof of the origin and integrity of an action so a party cannot later deny performing it. Capturing the identity, timestamp, and prior value of each medication change creates evidence that the pharmacist made the adjustment, which is exactly what the auditors need to trust the record and hold users accountable.

Why this answer

Recording the actor, timestamp, and previous value of every medication adjustment creates an auditable trail that proves who performed the action and that the entries were not altered afterward. That is the essence of non-repudiation, which combines authentication with tamper-evident logging so users cannot credibly deny their actions. Availability, confidentiality, and fault tolerance address different goals.

Exam trap

The trap here is reading 'medication records' and choosing confidentiality, when the requirement is really about proving who changed a record and preventing denial of that action.

121
MCQmedium

An employee is tailgated into a secure office building by someone without a badge. Which type of security threat does this represent?

A.Phishing
B.Tailgating
C.Baiting
D.Pretexting
AnswerB

Tailgating occurs when an unauthorised person follows an employee through a secured entrance without presenting credentials. The scenario describes exactly this physical social-engineering technique, where the attacker exploits the employee's authorised badge access rather than defeating the access control system itself.

Why this answer

Tailgating is the correct answer because it specifically describes an unauthorized person following an authorized employee through a secure door without presenting credentials. This is a physical security threat, not a social engineering attack conducted remotely. The scenario matches the definition exactly.

Exam trap

The trap is confusing tailgating with other social engineering tactics like pretexting or baiting, especially when the scenario involves a physical building; candidates may overlook that tailgating is specifically the act of following through a door.

How to eliminate wrong answers

Option A is wrong because phishing is a social engineering attack typically conducted via email or messaging to steal credentials, not a physical entry technique. Option C is wrong because baiting involves leaving a physical item like a USB drive for a victim to plug in, which is different from following someone through a door. Option D is wrong because pretexting is creating a fabricated scenario to obtain information, usually over the phone or in person, but it does not describe the act of following someone through a secure entrance.

122
MCQhard

An organization implements a security policy where users must provide a password and a one-time code generated by a mobile app to log in. Which type of authentication is being used?

A.Two-factor authentication
B.Biometric authentication
C.Token-based authentication
D.Single-factor authentication
AnswerA

Combining a knowledge factor (password) with a possession factor (app-generated one-time code) satisfies the stem's two distinct authentication categories. The mobile app produces a time-based code, so compromise of the password alone cannot grant access, meeting the multi-factor requirement.

Why this answer

Two-factor authentication (2FA) requires two different categories of authentication factors: something you know (the password) and something you have (the one-time code generated by the mobile app). Because the password and the OTP come from separate factor classes, this satisfies the definition of 2FA rather than single-factor or a single-category method. The mobile app acts as a soft token, but the overall scheme is still classified as two-factor authentication.

Exam trap

The trap here is confusing 'token-based authentication' with 'two-factor authentication' — candidates see the mobile app token and pick token-based, forgetting that the password plus OTP together constitute two distinct factors.

How to eliminate wrong answers

Option B is wrong because biometric authentication relies on something you are (fingerprint, face, iris) and the scenario uses no biometric factor. Option C is wrong because token-based authentication alone describes only the possession factor; a token by itself without a password would be single-factor, and the question explicitly includes a password plus OTP. Option D is wrong because single-factor authentication uses only one factor (e.g., password only), whereas the scenario combines a password with a one-time code.

123
MCQhard

A security analyst is explaining the CIA triad to new employees. Which scenario best illustrates a breach of integrity?

A.An employee accidentally deletes a critical file
B.An attacker modifies financial records in a database without authorization
C.An attacker steals customer credit card numbers from a database
D.A denial-of-service attack makes a website unavailable
AnswerB

Integrity concerns unauthorised alteration of data, not its disclosure or availability. Modifying financial records without authorisation corrupts their accuracy and trustworthiness, so this scenario illustrates an integrity breach rather than a confidentiality or availability failure.

Why this answer

Integrity in the CIA triad refers to protecting data from unauthorized modification. An attacker modifying financial records in a database without authorization directly violates integrity because the data is altered, potentially leading to incorrect decisions or fraud. This scenario best illustrates a breach of integrity.

Exam trap

FC0-U71 often tests the ability to distinguish between confidentiality, integrity, and availability by presenting scenarios that sound similar but map to different pillars; candidates may confuse data theft (confidentiality) with data modification (integrity).

How to eliminate wrong answers

Option A is wrong because accidental deletion affects availability (data is no longer accessible) rather than integrity, although it could also be considered a loss of integrity if the deletion is unauthorized, but the primary impact is availability. Option C is wrong because stealing customer credit card numbers is a confidentiality breach, as it involves unauthorized access to data. Option D is wrong because a denial-of-service attack affects availability by making a website unavailable, not integrity.

← PreviousPage 2 of 2 · 123 questions total

Ready to test yourself?

Try a timed practice session using only Security questions.