Courseiva

CCNA Itf Security Questions

75 of 123 questions · Page 1/2 · Itf Security topic · Answers revealed

1
MCQmedium

A company requires all employees to use a smart card and a PIN to access the building. This is an example of which concept?

A.Authorization
B.Biometrics
D.Single sign-on
AnswerC

A smart card (something possessed) plus a PIN (something known) combines two different authentication factor categories, which is the definition of multi-factor authentication. Requiring both for building access therefore satisfies the MFA concept the stem describes.

Why this answer

Multi-factor authentication combines something you have (smart card) and something you know (PIN).

2
MCQmedium

Which type of malware is designed to replicate itself and spread to other computers without needing to attach to a host file?

A.Worm
B.Trojan
C.Virus
D.Ransomware
AnswerA

A worm is self-replicating malware that spreads across networks independently, exploiting vulnerabilities or weak credentials to propagate. Unlike viruses, it requires no host file or user action to replicate, which is precisely the defining constraint stated in the stem.

Why this answer

Worms are self-replicating and spread independently, unlike viruses which attach to files.

3
MCQmedium

An attacker gains physical access to a secure area by following an authorized employee through a door that requires a badge. This social engineering technique is known as:

A.Pretexting
B.Phishing
C.Tailgating
D.Baiting
AnswerC

Following an authorised employee through a badge-controlled door without presenting credentials is tailgating, a physical social engineering technique. The stem's unauthorised entry behind a legitimate badge holder matches this definition precisely, distinguishing it from shoulder surfing or dumpster diving.

Why this answer

Tailgating (or piggybacking) is when an unauthorized person follows an authorized person into a restricted area without proper authentication.

4
MCQhard

A small business owner wants to protect customer data stored on laptops in case the devices are stolen. Which encryption method provides the best protection for the entire hard drive?

A.HTTPS encryption for web traffic
B.File-level encryption on individual documents
C.A VPN when connecting to the internet
D.Full disk encryption
AnswerD

Full disk encryption protects the entire drive, including the operating system, applications and all stored files, so data remains unreadable if a laptop is stolen. It satisfies the requirement to safeguard customer data on lost devices.

Why this answer

Full disk encryption (FDE) encrypts the entire storage volume — OS, applications, temp files, and user data — using a key protected by a TPM or pre-boot authentication, so a stolen laptop's drive is unreadable without the credential. Because it covers everything on the disk, it protects customer data regardless of which files or folders it lives in. This is the standard control for lost/stolen device scenarios.

Exam trap

The trap is conflating in-transit encryption (HTTPS, VPN) with at-rest encryption — candidates see 'encryption' and pick a transport control when the scenario is about a stolen device and data on disk.

How to eliminate wrong answers

Option A is wrong because HTTPS only encrypts data in transit between a browser and a web server; it does nothing for data at rest on a stolen laptop's drive. Option B is wrong because file-level encryption only protects the specific documents that were encrypted — it leaves OS artifacts, temp files, swap files, and unencrypted documents exposed, and users often forget to encrypt new files. Option C is wrong because a VPN protects data in transit over untrusted networks; once the laptop is stolen and offline, the VPN provides no at-rest protection.

5
MCQmedium

An employee allows a delivery person to enter a secure office building by holding the door open. The delivery person does not have an access badge. Which social engineering attack is this?

A.Phishing
B.Tailgating
C.Baiting
D.Pretexting
AnswerB

Tailgating occurs when an unauthorised person follows an authorised individual through a secured entry point without presenting credentials. The delivery person gained access solely because the employee held the door, satisfying the stem's scenario of bypassing badge control.

Why this answer

Tailgating (or piggybacking) occurs when an unauthorized person follows an authorized person into a restricted area without proper authentication.

6
Multi-Selectmedium

Which TWO of the following are effective measures to protect against ransomware attacks? (Select two.)

Select 2 answers
A.Using the same password for all accounts
B.Installing the latest software updates and patches
C.Disabling the firewall
D.Regularly backing up important files
E.Opening email attachments from unknown senders
AnswersB, D

Patching closes the software vulnerabilities that ransomware exploits to gain initial access and propagate. Applying the latest updates directly removes the exposure the stem's attack relies on, making it an effective preventive measure alongside user education and endpoint protection.

Why this answer

Option B is correct because installing the latest software updates and patches closes known vulnerabilities (e.g., SMBv1/EternalBlue, RDP flaws) that ransomware such as WannaCry and NotPetya exploit to gain initial access and propagate laterally. Option D is correct because regularly backing up important files—ideally following the 3-2-1 rule with offline or immutable copies—allows restoration of data without paying a ransom, neutralizing the extortion leverage even if encryption occurs. Option A is wrong because reusing the same password across accounts enables credential-stuffing and lateral movement, dramatically increasing ransomware blast radius rather than protecting against it.

Option C is wrong because disabling the firewall removes network traffic filtering and exposes hosts and services to scanning, exploitation, and command-and-control communication. Option E is wrong because opening attachments from unknown senders is a primary ransomware delivery vector via malicious macros, executables, or exploit-laden documents.

Exam trap

The trap is including options that sound like security measures but actually weaken defenses (disabling firewall, reusing passwords) or are obvious attack vectors (opening unknown attachments), distracting from the two genuine best practices.

7
Multi-Selecthard

A security analyst is evaluating risks to the company's network. According to the risk formula (Risk = Likelihood × Impact), which THREE of the following are considered vulnerabilities?

Select 3 answers
A.Weak encryption used for data in transit
B.A hacker attempting to guess passwords
C.A fire in the data center
D.Employees not trained to recognize phishing emails
E.Unpatched software on the company's web server
AnswersA, D, E

Weak encryption for data in transit is a technical weakness in how information is protected, making it exploitable by interception or decryption attacks. It therefore qualifies as a vulnerability under the risk formula, since it is an internal flaw that raises the likelihood of a threat succeeding.

Why this answer

In the risk formula Risk = Likelihood × Impact, vulnerabilities are internal weaknesses or flaws that can be exploited or triggered by a threat. Option A (weak encryption for data in transit) is correct because using outdated or weak ciphers/protocols such as SSLv3, TLS 1.0, or RC4 is a configuration weakness that exposes data to interception. Option D (employees not trained to recognize phishing emails) is correct because lack of security awareness is a human vulnerability that enables social-engineering attacks like credential harvesting.

Option E (unpatched software on the company's web server) is correct because missing security patches leave known CVEs exploitable, a classic technical vulnerability. Option B (a hacker attempting to guess passwords) is a threat actor/action, not a vulnerability, and Option C (a fire in the data center) is a physical threat or hazard, not a vulnerability.

8
MCQmedium

A user receives an email from their bank asking them to click a link and verify their account information. The email contains spelling errors and the sender's address looks suspicious. Which type of social engineering attack is this?

A.Spear phishing
B.Pretexting
C.Vishing
D.Phishing
AnswerD

Phishing is a fraudulent email impersonating a trusted entity, such as a bank, that lures the recipient into clicking a link and disclosing credentials. The suspicious sender address and spelling errors are classic phishing indicators, matching the stem's scenario precisely.

Why this answer

This is a phishing attack because it is a broad, untargeted email attempting to trick the recipient into clicking a link and providing account information. The presence of spelling errors and a suspicious sender address are classic indicators of phishing. Phishing typically targets many users indiscriminately, unlike spear phishing which is highly targeted.

Exam trap

FC0-U71 often tests the distinction between phishing (mass, generic) and spear phishing (targeted, personalized), so candidates may incorrectly choose spear phishing when the email is clearly generic.

How to eliminate wrong answers

Option A is wrong because spear phishing is a targeted attack aimed at specific individuals or organizations, often with personalized content; this email is generic. Option B is wrong because pretexting involves creating a fabricated scenario to gain trust, often over the phone or in person, not necessarily via a mass email. Option C is wrong because vishing is voice phishing conducted over the phone, not email.

9
MCQmedium

A user reports that their computer has been displaying unwanted pop-up advertisements frequently. Which type of malware is most likely responsible?

A.Ransomware
B.Adware
C.Spyware
D.Rootkit
AnswerB

Adware specifically injects or displays unwanted advertisements, matching the frequent pop-ups described. Unlike spyware, which covertly gathers data, or a trojan, which masquerades as legitimate software, adware's primary payload is advertising delivery. This directly satisfies the stem's constraint of persistent unwanted pop-up advertisements on the user's computer.

Why this answer

Adware displays unwanted advertisements, often in pop-ups or banners.

10
MCQeasy

Which of the following is a best practice for creating a strong password?

A.Using a long passphrase that includes symbols and numbers
B.Using a password with 8 characters including letters and numbers
C.Reusing the same password across multiple sites
D.Using your pet's name as a password
AnswerA

Length defeats brute-force and dictionary attacks far more effectively than complexity alone, while mixing symbols and numbers widens the search space. A passphrase remains memorable yet resists guessing, satisfying the best-practice requirement without relying on predictable substitutions or reused credentials.

Why this answer

A long passphrase that includes symbols and numbers is considered a best practice because it increases both length and complexity, making it significantly harder for attackers to crack using brute-force or dictionary attacks. Length is the most critical factor in password strength, and adding symbols and numbers further expands the search space. This approach aligns with guidance from NIST and other security organizations, which recommend passphrases over short, complex passwords.

Exam trap

FC0-U71 often tests the misconception that complexity alone (like 8 characters with letters and numbers) is sufficient for a strong password, when in fact length and uniqueness are more critical.

How to eliminate wrong answers

Option B is wrong because an 8-character password, even with letters and numbers, is no longer considered strong; modern hardware can crack such passwords quickly, and it lacks symbols and sufficient length. Option C is wrong because reusing the same password across multiple sites means a breach on one site compromises all others, violating the principle of unique credentials per account. Option D is wrong because using a pet's name is easily guessable through social engineering or public information, and it lacks complexity and length.

11
MCQhard

A security analyst discovers that a file on a server has been modified without authorization. Which element of the CIA triad has been compromised?

A.Non-repudiation
B.Integrity
C.Availability
D.Confidentiality
AnswerB

Integrity guarantees data remains unaltered unless changed by an authorised process. Because the file was modified without authorisation, its trustworthiness is broken, directly satisfying the scenario's unauthorised-modification constraint. Confidentiality concerns disclosure and availability concerns access, neither of which the stem describes.

Why this answer

Integrity ensures that data has not been altered or tampered with in an unauthorized manner. Since the file was modified without authorization, the integrity of the data has been compromised, which is the definition of an integrity violation in the CIA triad.

Exam trap

FC0-U71 often tests the CIA triad by describing a scenario and asking which element is affected — candidates sometimes pick confidentiality for any 'unauthorized' action, but modification always maps to integrity.

How to eliminate wrong answers

Option A is wrong because non-repudiation is not part of the CIA triad — it is a separate security property ensuring a party cannot deny having performed an action, typically provided by digital signatures. Option C is wrong because availability concerns whether data or systems are accessible when needed (e.g., DoS attacks), not whether data was altered. Option D is wrong because confidentiality concerns unauthorized disclosure of data, not unauthorized modification.

12
MCQmedium

What is the primary risk of using public Wi-Fi without a VPN?

A.The Wi-Fi network may be slower
B.Data transmitted can be intercepted by attackers
C.The device may overheat
D.Increased risk of malware infection from the network
AnswerB

Public Wi-Fi carries traffic unencrypted across a shared medium, letting anyone on the same network capture packets with readily available tools. A VPN defeats this by tunnelling traffic through an encrypted channel, so interception yields only ciphertext. This directly addresses the stem's constraint: exposure of transmitted data to nearby attackers.

Why this answer

Public Wi-Fi is often unencrypted, allowing attackers to intercept data transmitted over the network. A VPN encrypts traffic, protecting data in transit.

13
MCQeasy

What is the primary purpose of a password manager?

A.To store passwords in the cloud for easy access
B.To encrypt all network traffic
C.To share passwords securely with team members
D.To generate and store strong, unique passwords
AnswerD

A password manager generates high-entropy, unique credentials per site and stores them in an encrypted vault unlocked by one master passphrase. This directly counters credential reuse and weak passwords, the primary purpose the question asks for.

Why this answer

A password manager's core function is to create high-entropy, unique passwords for every account and store them in an encrypted vault, eliminating password reuse and weak credentials. It uses a master password and strong encryption (e.g., AES-256) to protect the vault, and can auto-fill credentials, reducing human error. While some managers offer cloud sync or sharing, those are secondary features, not the primary purpose.

Exam trap

The trap here is confusing a password manager's primary purpose with its secondary features like cloud storage or sharing, which are often highlighted in marketing but are not the core function.

How to eliminate wrong answers

Option A is wrong because storing passwords in the cloud is an optional feature for synchronization, not the primary purpose; many password managers are local-only, and cloud storage alone without encryption and generation is insecure. Option B is wrong because encrypting all network traffic is the role of a VPN or TLS, not a password manager. Option C is wrong because secure password sharing is a convenience feature in some team-oriented managers, but it is not the core purpose; the primary goal is individual credential security.

14
MCQeasy

Which component of the CIA triad ensures that data cannot be modified by unauthorized users?

A.Integrity
B.Authentication
C.Availability
D.Confidentiality
AnswerA

Integrity guarantees data remains accurate and unaltered unless changed by an authorised party, directly matching the requirement that unauthorised users cannot modify it. Confidentiality restricts who can read data, and availability ensures timely access, so neither addresses modification.

Why this answer

Integrity, the 'I' in the CIA triad, specifically ensures that data remains accurate, complete, and unaltered unless modified by authorized parties. It protects against unauthorized modification, deletion, or corruption, whether the data is at rest, in transit, or in use. Authentication verifies identity, availability ensures access, and confidentiality prevents unauthorized disclosure—none of these directly address modification prevention.

Exam trap

The trap here is confusing authentication with integrity, as candidates often think that verifying a user's identity (authentication) also ensures data cannot be modified, but authentication only controls access, not the modification itself.

How to eliminate wrong answers

Option B is wrong because authentication is not a component of the CIA triad; it is a separate security principle that verifies the identity of a user or system, often serving as a prerequisite for access control but not ensuring data integrity. Option C is wrong because availability ensures that data and systems are accessible to authorized users when needed, focusing on uptime and resilience rather than preventing unauthorized modification. Option D is wrong because confidentiality ensures that data is not disclosed to unauthorized individuals, typically through encryption or access controls, but it does not prevent authorized users from modifying data or address unauthorized changes.

15
MCQhard

A user's web browser warns that the connection to an online store is not private because the site's certificate cannot be validated. The user ignores the warning and enters payment card details anyway. Which type of attack is the user MOST at risk of in this situation?

A.SQL injection against the store's product database.
B.Denial-of-service attack flooding the store's web server.
C.Cross-site scripting running in the store's checkout page.
D.On-path attack intercepting the unverified connection.
AnswerD

A certificate validation failure often means the browser cannot confirm it is talking to the real store, which is exactly the condition an on-path attacker creates by inserting themselves between the user and the site. Continuing past the warning can send card details through the attacker's system. Trusting an unvalidated certificate defeats the protection TLS is meant to provide.

Why this answer

When a browser cannot validate a site's certificate, the identity of the server is in doubt, which is the hallmark of an on-path attack redirecting traffic to an imposter endpoint. Entering payment details in that state can hand them directly to the attacker. The other listed attacks target availability or server-side application flaws and are not signaled by a certificate validation warning.

Exam trap

The trap here is treating a certificate warning as a harmless glitch, when it actually undermines the identity check that protects against an on-path attacker.

16
MCQmedium

A user is concerned about connecting to a public Wi-Fi network at a coffee shop. Which security measure can best protect their data?

A.Use HTTPS websites only
B.Use a firewall
C.Disable antivirus
D.Use a VPN
AnswerD

A VPN encrypts all traffic between the user's device and the VPN server, creating a protected tunnel that prevents attackers on the public Wi-Fi network from intercepting credentials, messages, or browsing data. This directly satisfies the coffee-shop scenario's constraint: untrusted network traffic requiring confidentiality against local eavesdropping.

Why this answer

A VPN encrypts traffic between the user's device and the VPN server, protecting data on public networks.

17
Multi-Selectmedium

A user is setting up a new wireless router for a home office and wants to secure the wireless network. Which TWO of the following should the user configure to help prevent unauthorized access? (Choose two.)

Select 2 answers
A.Enable DHCP on the router
B.Change the default administrator password
C.Enable WPA3 encryption
D.Disable SSID broadcast
E.Place the router near a window
AnswersB, C

Default administrator credentials are publicly known and are a common entry point for attackers to reconfigure the router. Changing the default password to a strong, unique one prevents unauthorized users from accessing the router's management interface and altering security settings. This is a fundamental step in securing any network device and directly reduces the risk of unauthorized access, making it a correct choice.

Why this answer

To secure a home wireless network, the user should enable strong encryption such as WPA3 and change the router's default administrator password. WPA3 protects data in transit and controls who can join, while changing the default admin password prevents unauthorized reconfiguration. The other options either provide minimal protection, are unrelated to security, or can increase exposure.

Exam trap

The trap here is believing that disabling SSID broadcast or enabling DHCP improves security, when these either provide only obscurity or are convenience features that do not prevent unauthorized access.

18
MCQmedium

Which of the following is the primary purpose of hashing a password before storing it in a database?

A.To make the password longer and more secure
B.To verify the password without storing it in plaintext
C.To compress the password to save storage space
D.To encrypt the password so it can be decrypted later
AnswerB

Hashing is a one-way transformation, so the stored digest cannot be reversed to recover the original password. At login the system hashes the supplied password and compares digests, verifying authenticity without retaining plaintext. This satisfies the stem's requirement of verification without plaintext storage.

Why this answer

Hashing is a one-way function that converts a password into a fixed-length string. It is used to securely store passwords so that even if the database is breached, the actual passwords are not easily recoverable.

19
MCQmedium

An IT technician is configuring a new employee's laptop. The employee will handle payroll data and must access the payroll application from home. The company requires that the connection be encrypted and that the employee's device prove its identity before access is granted. Which technology BEST meets these requirements?

A.A secure web portal that requires a username and password
B.File synchronization to a cloud storage folder shared with the payroll team
C.Remote Desktop Protocol to an office workstation over the internet
D.A VPN connection using IPsec or TLS with certificate-based authentication
AnswerD

A VPN creates an encrypted tunnel between the laptop and the corporate network, protecting payroll data in transit. Certificate-based authentication requires the device to present a valid digital certificate, satisfying the requirement that the device prove its identity before access. Together, encryption and mutual authentication meet both stated conditions, unlike simpler remote-access methods.

Why this answer

The scenario requires two things: encryption of the connection and proof of the device's identity. A VPN with IPsec or TLS supplies the encrypted tunnel, while certificate-based authentication forces the laptop to present a valid digital certificate before the tunnel is established. Remote desktop, password-only web portals, and cloud sync either lack device authentication or fail to provide a private encrypted path to the payroll application.

Exam trap

The trap here is accepting any encrypted connection, such as HTTPS, while overlooking that the requirement also demands the device itself prove its identity.

20
MCQhard

An administrator reviews a server's audit log and finds a long series of failed login attempts against many different usernames, all originating from a single external address within a few minutes. No attempt succeeded. Which term BEST describes this activity?

A.A denial-of-service attack
B.A brute-force attack against one account
C.A man-in-the-middle attack
D.A password spraying attack
AnswerD

Password spraying tries a small number of common passwords against a large set of usernames, hoping to find one account with a weak password while avoiding lockout thresholds tied to a single account. The log's signature, many usernames tried in a short time from one source with no successes yet, matches this technique exactly. It is a low-and-slow credential attack aimed at breadth rather than depth.

Why this answer

The distinguishing feature in the log is breadth: many different usernames targeted from one source in a short window. That pattern matches password spraying, where an attacker tests a few common passwords across a large user list to stay under per-account lockout thresholds. Brute force would hammer one account, a denial-of-service attack would aim at availability, and a man-in-the-middle attack would involve interception rather than direct login attempts.

Exam trap

The trap here is labeling any burst of failed logins as brute force, when the spread across many accounts is what identifies password spraying.

21
MCQeasy

A small office wants to prevent unauthorized individuals from connecting to its wireless network. The office manager enables WPA3-Personal and configures a pre-shared key. Which additional step BEST reduces the risk of unauthorized access?

A.Set the pre-shared key to the office street address for easy recall.
B.Change the default administrator credentials on the wireless access point.
C.Configure the access point to use WEP encryption for backward compatibility.
D.Enable SSID broadcast so devices can find the network easily.
AnswerB

Default administrator credentials are publicly documented and are a common way attackers gain control of an access point, then alter its configuration or add rogue access. Changing them to a unique, strong passphrase protects the management interface. WPA3-Personal secures the wireless link, but it does not protect the device's administrative login, so this step directly reduces the risk of unauthorized access to the network.

Why this answer

WPA3-Personal protects the wireless traffic, but the access point's management interface remains a separate attack surface. If default administrator credentials are left in place, an attacker on the local network or with physical access could log in and change settings, create a backdoor, or disable security. Replacing those defaults with a unique strong passphrase closes that path while preserving the encryption already configured.

Exam trap

The trap here is assuming that enabling strong wireless encryption alone fully secures the network, when the device's default administrative login is an independent and commonly exploited weakness.

22
MCQhard

A company's backup strategy requires three copies of data, on two different media types, with one copy offsite. Which backup rule does this follow?

A.3-2-1 rule
B.Incremental backup
C.Differential backup
D.Full backup
AnswerA

The 3-2-1 rule specifies exactly three copies of data, stored on two distinct media types, with one copy held offsite. That maps precisely onto the company's stated requirements, whereas other schemes such as 3-2-1-1-0 add offline or verified-restore conditions the stem never mentions.

Why this answer

The 3-2-1 backup rule: three copies, two different media types, one offsite.

23
Multi-Selecthard

A company is developing a security policy. Which THREE of the following are examples of physical security controls?

Select 3 answers
A.Employing security guards to monitor entrances
B.Requiring employees to use strong passwords
C.Using a firewall to filter network traffic
D.Installing badge readers on doors
E.Locking server rooms with biometric locks
AnswersA, D, E

Security guards monitoring entrances are a physical control: they restrict and observe direct human access to the facility, deterring intrusion and tailgating. This satisfies the requirement by protecting the tangible premises rather than logical systems, data or user behaviour.

Why this answer

Option A is correct because security guards monitoring entrances are a classic physical security control, providing deterrence and access control at the facility perimeter. Option D is correct because badge readers on doors are physical access control mechanisms that restrict entry to authorized personnel using credentials such as RFID or smart cards. Option E is correct because biometric locks on server rooms are physical controls that authenticate individuals via fingerprints, iris scans, or similar traits before granting access to sensitive areas.

Option B is not a physical control; strong passwords are a logical/technical authentication control. Option C is not a physical control; firewalls are network security devices that filter traffic at the logical layer.

Exam trap

The trap here is confusing logical/technical controls (passwords, firewalls) with physical controls; candidates often pick password policies because they 'secure' the company, but the exam requires recognizing that physical controls must restrict tangible access.

24
Multi-Selectmedium

A user's workstation has become slow and shows unexpected pop-up windows even when no browser is open. A technician suspects malware and wants to reduce the risk of further compromise while investigating. Which TWO actions should the technician take FIRST? (Choose two.)

Select 2 answers
A.Run a full antivirus scan while leaving the machine connected.
B.Share the user's login credentials with the security team by email.
C.Document the observed symptoms and note the time they began.
D.Immediately reinstall the operating system without further checks.
E.Disconnect the workstation from the network.
AnswersC, E

Recording symptoms, timestamps, and the state of the machine preserves evidence and supports later analysis of how the infection occurred and what it affected. This documentation is valuable whether the machine is later reimaged or cleaned, and it helps identify other potentially compromised systems. Capturing this information early, before remediation changes the system, is a core incident-handling practice.

Why this answer

Containment and evidence preservation come before remediation. Disconnecting the workstation stops active communication with external infrastructure and prevents lateral spread, while documenting symptoms and timestamps preserves information needed for analysis. Scanning, reimaging, or sharing credentials either allows the threat to continue operating or destroys evidence, so those actions belong later in the response process.

Exam trap

The trap here is jumping straight to remediation such as scanning or reimaging, which can let active malware keep communicating or destroy the evidence needed to understand the scope of the incident.

25
MCQeasy

What is the primary purpose of a network firewall?

A.To prevent malware infections by scanning files
B.To encrypt data transmitted over the network
C.To block unauthorized network traffic based on rules
D.To provide wireless network access
AnswerC

A firewall inspects packets against configured rule sets, permitting or denying traffic by source, destination, port and protocol. This directly fulfils the stem's requirement of blocking unauthorised network traffic, since each rule defines precisely which connections may pass the boundary between trusted and untrusted networks.

Why this answer

A network firewall's primary purpose is to control incoming and outgoing network traffic by comparing packets against a set of predefined security rules. It acts as a barrier between trusted internal networks and untrusted external networks (like the internet), allowing or denying traffic based on criteria such as IP addresses, ports, and protocols. This rule-based filtering is the core function that distinguishes a firewall from other security tools.

Exam trap

FC0-U71 often tests the distinction between firewall functions and those of other security or networking devices, so candidates may confuse firewalls with antivirus, encryption tools, or wireless access points.

How to eliminate wrong answers

Option A is wrong because scanning files for malware is the function of antivirus or anti-malware software, not a firewall; firewalls operate at the network layer and do not inspect file contents for malicious code. Option B is wrong because encryption of transmitted data is handled by protocols like TLS/SSL, VPNs, or IPsec, not by a firewall; firewalls may allow or block encrypted traffic but do not perform the encryption themselves. Option D is wrong because providing wireless network access is the role of a wireless access point (WAP) or wireless router, not a firewall; while some home routers combine both functions, the firewall component does not enable wireless connectivity.

26
Multi-Selecteasy

Which TWO of the following are examples of multi-factor authentication?

Select 2 answers
A.A smart card and a PIN
B.Two different passwords
C.A password and a fingerprint scan
D.A username and a password
E.A password and a security question
AnswersA, C

Combining a smart card (something you have) with a PIN (something you know) satisfies multi-factor authentication by drawing on two distinct credential categories. This pairing meets the stem's requirement for genuine MFA, unlike methods relying on a single factor repeated or two instances of the same category.

Why this answer

Option A (a smart card and a PIN) is correct because it combines two distinct authentication factors: something you have (the smart card) and something you know (the PIN), which is the definition of multi-factor authentication. Option C (a password and a fingerprint scan) is also correct because it pairs something you know (the password) with something you are (the fingerprint biometric), satisfying MFA's requirement for different factor categories. Option B (two different passwords) is not MFA because both are the same factor type—something you know—so it is merely multi-instance, not multi-factor.

Option D (a username and a password) is not MFA because a username is an identifier, not an authentication factor, and the password alone represents a single factor. Option E (a password and a security question) is not MFA because both are knowledge-based factors (something you know), so they belong to the same factor category.

27
MCQeasy

Which of the following is the strongest password?

A.12345678
B.P@ssw0rd
C.MyD0g!sF1d0
D.password
AnswerC

MyD0g!sF1d0 combines upper and lower case letters, digits and a symbol across twelve characters, giving far greater brute-force resistance than shorter or single-character-class alternatives. Length plus mixed character classes directly increases the search space an attacker must exhaust.

Why this answer

MyD0g!sF1d0 is the strongest because it is the longest option (11 characters) and combines uppercase, lowercase, digits, and special characters in a non-dictionary phrase. Length is the primary driver of password strength, and this password avoids common words or predictable substitutions like 'P@ssw0rd'. It would take significantly longer to crack via brute force or dictionary attacks than the other options.

Exam trap

FC0-U71 often tests the misconception that adding a symbol or number to a common word (like 'P@ssw0rd') makes it strong, when in fact length and randomness are more critical.

How to eliminate wrong answers

Option A is wrong because '12345678' is a sequential numeric string that appears in every common password list and is instantly cracked. Option B is wrong because 'P@ssw0rd' is a dictionary word with predictable leetspeak substitutions, making it highly vulnerable to rule-based cracking. Option D is wrong because 'password' is the single most common password and is cracked immediately.

28
MCQmedium

An organization requires employees to use a password and a one-time code sent to their mobile phone when logging into the network. Which security principle is being implemented?

A.Least privilege
B.Biometrics
C.Single sign-on
AnswerD

Multi-factor authentication combines two distinct credential categories: something the employee knows (the password) and something they possess (the one-time code delivered to their phone). This directly satisfies the stem's requirement for both a password and a phone-based code at login, since possession of the registered device supplies the second, independent authentication factor.

Why this answer

Multi-factor authentication (MFA) requires two or more factors: something you know (password) and something you have (phone).

29
MCQmedium

A technician is configuring a Windows workstation for a finance employee. The employee needs to read and update customer records but should not be able to change the folder's permissions or take ownership. Which NTFS permission should the technician assign?

A.Read & execute
B.Full control
C.Write
D.Modify
AnswerD

Modify allows a user to read, write, edit, and delete files and subfolders, which covers reading and updating customer records. It does not include the change-permissions or take-ownership rights that Full control provides, so the employee cannot alter the folder's access control list. This matches the stated requirement precisely and follows the principle of least privilege for a data-entry role.

Why this answer

Modify grants read, write, edit, and delete capabilities on files and subfolders without allowing the user to change permissions or take ownership. That matches the finance employee's need to read and update records while leaving the folder's security settings under administrative control. Full control would be excessive, while Read & execute and Write each fail to cover the required read-and-update combination.

Exam trap

The trap here is equating the ability to edit files with the ability to change permissions, which only Full control and the special Change permissions right provide.

30
MCQeasy

A user is setting up a new smartphone and wants to protect the data on it in case the device is lost or stolen. The user wants to ensure that if the phone falls into the wrong hands, the data cannot be easily accessed. Which of the following should the user enable FIRST?

A.Enable Bluetooth only when needed.
B.Install a mobile antivirus app.
C.Enable automatic OS updates.
D.Configure a screen lock with a strong PIN or biometric authentication.
AnswerD

A screen lock with a strong PIN or biometrics is the first line of defense against unauthorized physical access. It prevents a thief from unlocking the phone and viewing data or using apps. Most modern phones also encrypt storage by default when a screen lock is set, adding another layer of protection.

Why this answer

The first step to protect a lost or stolen phone is to enable a screen lock with a strong PIN or biometrics. This prevents unauthorized access and often triggers full-disk encryption. Other measures like updates, antivirus, and Bluetooth management are useful but secondary to locking the device.

Exam trap

The trap here is focusing on software protections like antivirus while overlooking the fundamental physical access control of a screen lock.

31
MCQmedium

A user receives an email that appears to be from their bank, asking them to click a link and verify their account details. The email contains urgent language and threats of account closure. What type of attack is this?

A.Spear phishing
B.Smishing
C.Phishing
D.Vishing
AnswerC

Phishing exploits social engineering by masquerading as a trusted entity—here, the user’s bank—to trick the recipient into clicking a fraudulent link. The urgent language and threat of account closure create a false sense of crisis, bypassing rational scrutiny. This satisfies the constraint of unauthorised credential harvesting via deceptive communication, distinguishing it from technical exploits like malware injection.

Why this answer

Phishing is a social engineering attack where attackers impersonate a legitimate entity to steal sensitive information.

32
MCQmedium

A user receives an email that appears to be from their bank, asking them to click a link and verify their account. The email contains urgent language and a generic greeting. Which type of security threat is this?

A.Smishing
B.Spear phishing
C.Vishing
D.Phishing
AnswerD

Phishing is the correct classification because the email impersonates the bank and uses urgency plus a generic greeting to trick the recipient into clicking a link and surrendering credentials. This social-engineering mechanism, delivering a fraudulent lure by email, directly matches the scenario's described threat rather than malware or physical intrusion.

Why this answer

Phishing is a social engineering attack where attackers send deceptive emails to steal credentials. The generic greeting and urgent language are common signs.

33
MCQeasy

Which element of the CIA triad is primarily concerned with ensuring that data is not accessed by unauthorized individuals?

A.Confidentiality
B.Authentication
C.Availability
D.Integrity
AnswerA

Confidentiality directly satisfies the stem's constraint that data must not be accessed by unauthorised individuals. It achieves this through encryption, access controls and authentication mechanisms, which restrict disclosure to approved parties only. Unlike integrity, which guards against improper modification, confidentiality specifically addresses unauthorised read access.

Why this answer

Confidentiality is the CIA triad element that ensures data is only accessible to authorized individuals, typically enforced through encryption, access controls, and authentication mechanisms. It directly addresses the concern of preventing unauthorized access or disclosure. Integrity concerns data accuracy, and availability concerns uptime — neither addresses unauthorized access.

Exam trap

The trap here is that authentication sounds like it belongs in the CIA triad because it is a security control — candidates often pick it over confidentiality, forgetting that the triad is Confidentiality, Integrity, Availability, and authentication is merely a supporting mechanism.

How to eliminate wrong answers

Option B is wrong because authentication is a mechanism (verifying identity) that supports confidentiality, but it is not itself a CIA triad element — the triad consists of Confidentiality, Integrity, and Availability. Option C is wrong because availability ensures data and systems are accessible to authorized users when needed, which is about uptime and resilience, not about preventing unauthorized access. Option D is wrong because integrity ensures data has not been altered or tampered with, which is about accuracy and trustworthiness, not about restricting who can view it.

34
MCQeasy

Which of the following is a characteristic of a worm in the context of malware?

A.It disguises itself as legitimate software
B.It encrypts files and demands a ransom
C.It requires a host file to spread
D.It self-replicates without needing a host file
AnswerD

Worms replicate autonomously across networks by exploiting vulnerabilities, requiring no host file or user action — unlike viruses, which must attach to executable files or documents. This self-propagation mechanism directly satisfies the stem's requirement for a defining worm characteristic, distinguishing it from other malware types such as trojans or ransomware.

Why this answer

A worm is a standalone malware that replicates itself to spread to other computers without needing to attach to a host file, often exploiting network vulnerabilities.

35
Multi-Selectmedium

A technician is helping a small office set up basic physical security for its server closet. Which TWO of the following are physical security controls that would protect the equipment in the closet? (Choose two.)

Select 2 answers
A.Mounting a security camera aimed at the closet entrance.
B.Installing a lockable door with a keypad entry on the server closet.
C.Enabling full-disk encryption on the servers' storage drives.
D.Configuring a firewall rule to block inbound traffic to the servers.
E.Requiring complex passwords for the server administrator accounts.
AnswersA, B

A security camera is a physical control that deters intruders and records activity for later investigation. It supports monitoring of who enters the closet and can capture evidence if equipment is tampered with. While it does not block entry by itself, it is a recognized physical security measure that helps protect the equipment in this scenario.

Why this answer

Physical security controls focus on the tangible environment and who can reach the equipment. A locked, keypad-controlled door and a monitoring camera both restrict or record physical access to the server closet. The other choices are logical or technical controls that protect data and accounts but do not prevent someone from physically touching, unplugging, or removing the servers.

Exam trap

The trap here is mixing logical controls such as encryption, firewalls, and passwords into a question that specifically asks about physical protection of equipment.

36
MCQeasy

A small office wants to prevent unauthorized people from connecting to its wireless network while still allowing visitors to use Wi-Fi. The office manager enables WPA3-Personal on the access point. Which requirement does this configuration satisfy?

A.It requires a shared passphrase before a device can join the wireless network.
B.It encrypts all files stored on the access point's internal memory.
C.It automatically assigns IP addresses to devices that join the network.
D.It blocks malicious websites by filtering DNS requests from connected clients.
AnswerA

WPA3-Personal uses a shared passphrase, and devices must supply it during association before network access is granted. This directly blocks unauthorized users who do not know the passphrase. It is the standard way to secure a home or small-office wireless network, and it satisfies the goal of preventing unknown devices from joining while still letting visitors connect if the passphrase is shared with them.

Why this answer

WPA3-Personal secures a wireless network by requiring a shared passphrase during association, so only devices with the correct passphrase can join. This prevents unauthorized users from connecting while allowing anyone who is given the passphrase, such as visitors, to use the Wi-Fi. The other choices describe unrelated functions such as local storage encryption, DHCP addressing, and DNS filtering.

Exam trap

The trap here is assuming that enabling a wireless security mode also handles IP addressing or content filtering, when WPA3-Personal only controls authentication and link encryption.

37
MCQhard

An organization uses a security model where users are granted the minimum permissions necessary to perform their job functions. This model is known as:

A.Role-based access control
B.Principle of least privilege
C.Mandatory access control
D.Discretionary access control
AnswerB

Least privilege directly enforces the stem's minimum-permissions constraint: each user receives only the access their job function requires, nothing more. This limits blast radius from compromised accounts or insider misuse, since excess entitlements are never granted in the first place.

Why this answer

The principle of least privilege (PoLP) states that users, processes, and systems should be granted only the minimum access rights required to perform their legitimate functions, and only for the duration needed. The scenario's wording — 'minimum permissions necessary to perform their job functions' — is the textbook definition of PoLP. It is a foundational security principle (codified in NIST SP 800-53 AC-6) rather than an access control model per se, though it is often implemented through RBAC.

Exam trap

The trap is that RBAC is a common distractor because it is the usual implementation vehicle for least privilege, but the question asks for the principle itself, not the access control model.

How to eliminate wrong answers

Option A is wrong because role-based access control (RBAC) is a mechanism that assigns permissions to roles rather than individuals — it is a way to implement least privilege, but the question describes the governing principle, not the model. Option C is wrong because mandatory access control (MAC) enforces access based on system-defined labels (e.g., SELinux, Bell-LaPadula) and does not inherently limit permissions to job function. Option D is wrong because discretionary access control (DAC) lets resource owners set permissions at their discretion, which is the opposite of a rigid minimum-necessary constraint.

38
MCQeasy

A user is creating a new password for an online banking account. The bank requires a minimum of 12 characters and recommends using a passphrase. Which of the following passwords BEST follows current security best practices?

A.Banking2024!
B.P@ssw0rd123!
C.qwertyuiopas
D.correcthorsebatterystaple
AnswerD

A long passphrase of four random words is easy to remember and highly resistant to brute-force and dictionary attacks because of its length and unpredictability. Current guidance from NIST and security experts favors length over complexity, and this passphrase exceeds the 12-character minimum while avoiding common substitutions.

Why this answer

The best password is a long, random passphrase that is easy to remember but hard to guess. Length and unpredictability matter more than complexity. Common patterns, service names, and keyboard walks are easily cracked, so a multi-word passphrase is the strongest option here.

Exam trap

The trap here is believing that adding symbols and numbers to a common word automatically makes a password strong.

39
Multi-Selectmedium

A new employee at a software company receives a laptop and must follow the organization's security policy when choosing credentials and handling them day to day. Which TWO of the following practices align with standard authentication security guidance? (Choose two.)

Select 2 answers
A.Using a unique passphrase for each work account rather than reusing one password everywhere
B.Storing passwords in a shared spreadsheet on the team's network drive so coworkers can cover for absences
C.Enabling multifactor authentication on the company email and code repository accounts
D.Reusing the same long passphrase across all work accounts because it is easier to remember
E.Writing the passphrase on a sticky note attached under the laptop keyboard for quick reference
AnswersA, C

Unique credentials per account limit the damage of a breach: if one service is compromised, attackers cannot replay the same password against the employee's other work systems. This directly reduces credential-stuffing risk and is a foundational authentication practice, making it a correct choice for the policy the new employee must follow.

Why this answer

Sound credential practice combines unique secrets per account with a second authentication factor. Unique passphrases contain the blast radius of any single breach, and multifactor authentication ensures a stolen password alone cannot grant access. Shared spreadsheets, sticky notes, and password reuse all weaken authentication by exposing or duplicating secrets, so they fail the policy requirement.

Exam trap

The trap here is treating a long passphrase as automatically safe, when reusing it across accounts still lets one breach compromise every system that shares it.

40
MCQmedium

An employee at a marketing agency connects a personal smartphone to the corporate guest Wi-Fi to check social media. The phone has no screen lock and runs an outdated operating system. The IT administrator is concerned this device could serve as an entry point into the corporate network. Which term BEST describes the risk introduced by this device?

A.Social engineering
B.Privilege escalation
C.Shadow IT
D.Zero-day exploit
AnswerC

Shadow IT refers to technology hardware or software used inside an organization without the IT department's knowledge or approval. The personal phone joining the corporate network for non-work purposes, unmanaged and unpatched, is a classic example because IT never sanctioned or configured the device, creating unmonitored risk on the network.

Why this answer

The scenario centers on a device IT never approved, configured, or can manage, which is the definition of shadow IT. Because the phone lacks a screen lock and current patches, it can be compromised and then used to reach corporate resources. Zero-day, privilege escalation, and social engineering describe different attack mechanics that are not present here.

Exam trap

The trap here is focusing on the phone's outdated software and calling it a zero-day or exploit, when the defining issue is that the device was brought onto the network without IT approval.

41
Multi-Selectmedium

A user is setting up a new smartphone for work and wants to reduce the risk of unauthorized access if the device is lost. Which two measures should the user implement? (Choose two.)

Select 2 answers
A.Disable automatic operating system updates
B.Store passwords in a plain text note on the device
C.Turn on remote wipe and locate services
D.Enable a screen lock with a strong PIN or biometric
E.Root or jailbreak the device to install security tools
AnswersC, D

Remote wipe lets the user erase the device over the internet once it is reported lost, removing work data before it can be extracted. Locate services help recover the device or confirm it is gone so a wipe can be triggered. Together they provide a response capability that complements the preventive screen lock, directly addressing the lost-device scenario.

Why this answer

Protecting a lost phone requires both a preventive control and a response capability. A strong screen lock, backed by a PIN or biometric, keeps a finder from opening the device and leverages the storage encryption tied to the lock credential. Remote wipe and locate services let the user erase work data after the loss is discovered.

Disabling updates, rooting the device, and storing plain text passwords all increase exposure.

Exam trap

The trap here is treating convenience measures like disabling updates or rooting the phone as security improvements, when they actually weaken the device.

42
Multi-Selectmedium

Which TWO of the following are characteristics of ransomware?

Select 2 answers
A.It collects user information without consent.
B.It self-replicates to other systems without user interaction.
C.It encrypts the victim's files.
D.It demands payment in exchange for decryption.
E.It disguises itself as legitimate software.
AnswersC, D

Ransomware encrypts the victim's files using symmetric keys, rendering documents, databases and images inaccessible until decryption occurs. This cryptographic locking is the defining characteristic that distinguishes ransomware from other malware, and it directly satisfies the stem's requirement for a ransomware trait.

Why this answer

Option C is correct because the defining behavior of ransomware is that it encrypts the victim's files (often using strong symmetric ciphers like AES with a per-file key, then wrapping that key with asymmetric encryption such as RSA), rendering the data inaccessible until a key is provided. Option D is correct because ransomware is a form of extortion: after encryption it presents a ransom note demanding payment, typically in cryptocurrency such as Bitcoin or Monero, in exchange for the decryption key or tool. Option A describes spyware, which covertly harvests user information rather than encrypting and holding data hostage.

Option B describes a worm, which propagates across systems autonomously without user interaction, a spreading mechanism rather than the extortion characteristic of ransomware. Option E describes a Trojan, which masquerades as legitimate software to trick users into running it, and while ransomware is often delivered via Trojans, disguise is not its defining characteristic.

Exam trap

FC0-U71 often tests whether candidates can distinguish ransomware from adjacent malware categories — spyware, worms, and Trojans — by focusing on the payment demand and file encryption as the defining pair of traits.

43
Multi-Selecthard

Which THREE of the following are effective methods to protect against malware infections? (Select THREE.)

Select 3 answers
A.Open all email attachments regardless of sender
B.Install and maintain antivirus software
C.Use a firewall to filter incoming and outgoing traffic
D.Disable automatic software updates to avoid changes
E.Keep operating systems and applications up to date
AnswersB, C, E

Antivirus software detects, blocks and removes known malware through signature and behavioural scanning, with regular updates catching new threats. Installing and maintaining it provides continuous host-level protection, satisfying the malware prevention requirement in the stem.

Why this answer

Option B is correct because installing and maintaining antivirus software with current signature/definition databases enables detection, blocking, and removal of known malware before it can execute or spread. Option C is correct because a firewall filters inbound and outbound traffic against defined rules, blocking malicious connections, command-and-control callbacks, and unauthorized remote access that malware relies on. Option E is correct because keeping operating systems and applications patched closes known vulnerabilities (e.g., unpatched RCE flaws) that malware exploits to gain initial access or escalate privileges.

Option A is wrong because opening all email attachments regardless of sender is a primary malware delivery vector, especially via phishing and malicious macros. Option D is wrong because disabling automatic software updates leaves systems exposed to publicly known exploits that vendors have already fixed.

44
MCQhard

An employee calls the help desk claiming to be a manager from another department and requests a password reset. This is an example of which social engineering technique?

A.Baiting
B.Pretexting
C.Tailgating
D.Phishing
AnswerB

Pretexting involves inventing a fabricated scenario or false identity to manipulate a victim into complying. Claiming to be a manager from another department establishes that invented pretext, exploiting the employee's deference to authority to obtain an unauthorised password reset.

Why this answer

Pretexting is a social engineering technique where an attacker invents a fabricated scenario (a pretext) — such as impersonating a manager from another department — to manipulate a victim into divulging information or performing an action like a password reset. The key element is the false identity and fabricated context used to gain trust. Because the caller claims to be a manager requesting a password reset, this is a textbook pretexting attack.

Exam trap

FC0-U71 often tests the distinction between pretexting (fabricated scenario/identity) and phishing (fraudulent email/message), so candidates who see 'phone call' and jump to phishing miss that the core deception is the invented pretext.

How to eliminate wrong answers

Option A (Baiting) is wrong because baiting involves leaving something enticing (like a USB drive or free download) for the victim to pick up and use, not impersonating a person over the phone. Option C (Tailgating) is wrong because tailgating is a physical technique where an unauthorized person follows an authorized person through a secure door, not a phone-based impersonation. Option D (Phishing) is wrong because phishing is typically conducted via email or electronic messaging with fraudulent links or attachments, not a live phone call impersonating a manager.

45
Multi-Selectmedium

Which THREE of the following are best practices for password security?

Select 3 answers
A.Sharing passwords with trusted coworkers when necessary
B.Enabling two-factor authentication where possible
C.Using a password manager to generate and store passwords
D.Reusing the same password across multiple sites
E.Using a password with at least 12 characters including uppercase, lowercase, numbers, and symbols
AnswersB, C, E

Enabling two-factor authentication adds a second verification factor beyond the password, so a stolen or guessed credential alone cannot grant access. This directly satisfies the stem's password-security best-practise requirement by mitigating credential compromise, and Microsoft Entra ID supports it natively through Conditional Access and authentication methods policies.

Why this answer

Option B is correct because enabling two-factor authentication (2FA) adds a second verification factor (e.g., TOTP, hardware token, or push notification) beyond the password, so a stolen or guessed password alone is insufficient to compromise the account. Option C is correct because a password manager generates high-entropy, unique credentials for each site and stores them encrypted (typically under AES-256 with a master passphrase), eliminating weak or reused passwords and reducing the risk of credential-stuffing attacks. Option E is correct because length and character diversity increase the search space, making brute-force and dictionary attacks computationally impractical; 12+ characters mixing uppercase, lowercase, digits, and symbols aligns with NIST and common policy guidance for strong passwords.

Option A is wrong because sharing passwords destroys individual accountability and non-repudiation, and violates least-privilege and audit principles; use delegated accounts or role-based access instead. Option D is wrong because reusing one password across sites means a single breach exposes all accounts via credential stuffing, so every account should have a unique password.

46
MCQeasy

Which of the following best describes the 'Confidentiality' component of the CIA triad?

A.Systems are operational when needed
B.Data is accessible only to authorized users
C.Data is encrypted at rest
D.Data is not modified without authorization
AnswerB

Confidentiality ensures data is disclosed only to authorised users, enforced through encryption, access controls and authentication. This directly matches the stem's requirement that information remains inaccessible to unauthorised parties, distinguishing it from Integrity, which concerns accuracy, and Availability, which concerns timely access.

Why this answer

Confidentiality ensures that data is not accessed by unauthorized individuals. Integrity protects data from unauthorized modification, and availability ensures data is accessible when needed.

47
MCQeasy

Which of the following best describes the principle of least privilege?

A.Users should have all permissions by default
B.Users should have the minimum permissions needed to do their job
C.Users should use multi-factor authentication
D.Users should change passwords every 30 days
AnswerB

Least privilege restricts each account to only the permissions its job function demands, nothing more. This directly satisfies the stem's requirement by minimising the attack surface and limiting blast radius if credentials are compromised, since no user holds rights beyond their operational needs.

Why this answer

The principle of least privilege (PoLP) states that a user, process, or system should be granted only the minimum access rights necessary to perform its legitimate function, and nothing more. Option B captures this exactly: minimum permissions needed to do the job. This limits the blast radius of compromised accounts, insider misuse, and accidental misconfiguration, and is a foundational control in frameworks like NIST SP 800-53 AC-6 and CIS Controls.

Exam trap

FC0-U71 often tests the confusion between authentication controls (MFA, password rotation) and authorization principles (least privilege), so candidates pick C or D because they 'sound secure' without matching the definition asked.

How to eliminate wrong answers

Option A is wrong because granting all permissions by default is the opposite of least privilege — it is effectively 'maximum privilege' and violates the deny-by-default model. Option C is wrong because multi-factor authentication is an authentication control that strengthens identity verification, not an authorization principle governing permission scope. Option D is wrong because mandatory 30-day password rotation is a credential hygiene policy; modern guidance (NIST SP 800-63B) actually discourages arbitrary periodic rotation in favor of length and breach checks.

48
MCQmedium

Which type of malware is disguised as legitimate software but performs malicious actions?

A.Virus
B.Ransomware
C.Trojan
D.Worm
AnswerC

A Trojan masquerades as legitimate software, so users install it willingly, satisfying the disguise requirement. Unlike viruses or worms, it does not self-replicate; its payload executes through user action, such as running the installer. This matches the stem's constraint of apparent legitimacy concealing malicious behaviour.

Why this answer

A Trojan horse appears useful but contains harmful code, unlike viruses or worms that self-replicate.

49
MCQmedium

An employee is working from a coffee shop and needs to access company files. Which of the following is the most secure method?

A.Use a VPN to encrypt all traffic between the laptop and the company
B.Connect directly to the company's network over the public Wi-Fi
C.Disable file sharing on the laptop
D.Use HTTPS websites only
AnswerA

A VPN builds an encrypted tunnel between the laptop and the company network, so credentials and files stay unreadable across the untrusted coffee-shop Wi-Fi. This satisfies the secure-access constraint, whereas plain HTTPS or public hotspots leave traffic exposed to interception.

Why this answer

A VPN encrypts all traffic between the laptop and the company network, protecting data from eavesdropping on the untrusted public Wi-Fi. This ensures that even if the coffee shop's network is compromised, the employee's files and credentials remain secure. It is the most secure method because it provides end-to-end encryption and authenticated access to company resources.

Exam trap

FC0-U71 often tests the misconception that HTTPS alone is sufficient for secure remote access — candidates must recognize that a VPN is required to encrypt all traffic and access internal resources securely.

How to eliminate wrong answers

Option B is wrong because connecting directly to the company's network over public Wi-Fi does not encrypt traffic; it exposes data to interception on the untrusted network. Option C is wrong because disabling file sharing on the laptop reduces local exposure but does not secure the connection to company files, leaving traffic vulnerable. Option D is wrong because using HTTPS websites only encrypts web traffic to those sites but does not protect other protocols or provide access to internal company file shares, which may not be web-based.

50
MCQhard

A security analyst is reviewing access logs and notices that an employee in the marketing department was able to read files in the human resources shared folder. The employee's account should only have access to marketing resources. Which security principle was violated?

A.Zero trust
B.Least privilege
C.Separation of duties
D.Defense in depth
AnswerB

Least privilege means users should have only the minimum access necessary to perform their job. The marketing employee was able to read HR files, which is beyond their required access. This violation of least privilege can lead to data exposure and is a common finding in access control audits.

Why this answer

The principle of least privilege states that users should be granted only the access required for their role. The marketing employee reading HR files indicates excessive permissions. Separation of duties, defense in depth, and zero trust are related concepts but do not directly name the violation of over-provisioned access.

Exam trap

The trap here is confusing least privilege with separation of duties, which is about dividing tasks to prevent fraud, not about limiting access to data.

51
MCQeasy

What is the difference between a threat and a vulnerability?

A.A threat is a potential harm, and a vulnerability is a weakness
B.They are the same thing
C.A threat is a weakness, and a vulnerability is a danger
D.A threat is a type of malware, and a vulnerability is a type of attack
AnswerA

A threat is any potential cause of harm, such as an attacker or malware, whereas a vulnerability is an existing weakness — an unpatched flaw or misconfiguration — that a threat could exploit. This distinction satisfies the stem's requirement to separate the external danger from the internal condition it acts upon.

Why this answer

A threat is a potential source of harm (e.g., a hacker), while a vulnerability is a weakness that can be exploited (e.g., unpatched software).

52
MCQmedium

A user is creating an account on a shopping website and is asked to choose a password. Which of the following passwords BEST follows current security guidance for resisting brute-force and dictionary attacks?

A.correct-horse-battery-staple-42
B.Jk7#pQ2!
C.P@ssw0rd123
D.Summer2024!
AnswerA

A long passphrase of several unrelated words plus a number reaches high length, which is the dominant factor in resisting brute-force attacks. The words are not a common phrase, so dictionary attacks that try famous passphrases fail. Length combined with unpredictability makes this the strongest option against both brute-force and dictionary cracking.

Why this answer

Current guidance favors long, memorable passphrases over short strings with forced complexity. A multi-word passphrase of unrelated words reaches a length that makes brute-force attacks impractical and avoids the predictable patterns that dictionary attacks target. Short complex strings and common word-plus-year patterns remain vulnerable because attackers test those exact constructions first.

Exam trap

The trap here is believing that symbol substitution and mixed case make a short password strong, when length and unpredictability are what actually resist cracking.

53
MCQeasy

A small business owner installs a wireless access point in a coffee shop for customers. The owner wants to prevent strangers outside the building from reading the wireless traffic of paying customers. Which security feature should be enabled on the access point?

A.MAC address filtering on the access point
B.WPA3 encryption with a shared passphrase
C.Disabling the SSID broadcast
D.Reducing the transmit power of the access point
AnswerB

WPA3 encrypts wireless frames between client devices and the access point using SAE, so anyone capturing the radio signals cannot read the customer traffic. It also replaces the weak WPA2 handshake, resisting offline dictionary attacks. Enabling WPA3 with a shared passphrase directly satisfies the goal of stopping outsiders from reading over-the-air data in the coffee shop.

Why this answer

Wireless signals travel through walls and into public spaces, so the only reliable way to keep outsiders from reading customer traffic is strong over-the-air encryption. WPA3 with a shared passphrase encrypts every frame using SAE, preventing passive eavesdroppers from recovering data even if they capture the radio transmissions. Hiding the SSID, filtering MAC addresses, and lowering power are obscurity or access measures that leave traffic readable.

Exam trap

The trap here is assuming that hiding the network name or filtering MAC addresses keeps wireless traffic private, when neither actually encrypts the data.

54
MCQeasy

A small business owner wants to let visitors use the office Wi-Fi without giving them access to the company's file server or networked printers. Which of the following is the BEST way to accomplish this?

A.Change the Wi-Fi password and post it on a sign in the lobby so all visitors can connect.
B.Enable a guest network on the wireless router that is isolated from the internal LAN.
C.Disable SSID broadcast so the wireless network name is hidden from visitors.
D.Turn on WPA3 encryption for the wireless network and require a strong passphrase.
AnswerB

A guest network broadcasts a separate SSID and places visitors on a segmented subnet that is firewalled off from internal resources such as file shares and printers. This directly satisfies the owner's goal because visitors get internet access only, while company data and devices remain unreachable from the guest segment.

Why this answer

Segmenting visitors onto a dedicated guest network keeps them away from internal file servers and printers while still providing internet access. Encryption, hidden SSIDs, and shared passwords all leave guests on the same network as company assets, so only a firewalled guest SSID meets the requirement of access without exposure.

Exam trap

The trap here is assuming that any wireless security feature, such as encryption or a hidden SSID, also limits which internal resources a connected visitor can reach.

55
MCQmedium

A user's web browser displays a warning that the connection to an online store is not private because the site's certificate cannot be validated. The user asks a technician what the warning means. Which explanation is MOST accurate?

A.The browser cannot verify the identity of the site or that the connection is securely encrypted.
B.The online store is using an outdated version of HTML that the browser no longer supports.
C.The user's internet connection has been disconnected and the page is loading from the cache.
D.The store's website has been infected with malware that is stealing payment information.
AnswerA

Browsers rely on certificates issued by trusted certificate authorities to confirm a site's identity and to establish an encrypted TLS session. When the certificate is expired, self-signed, issued for a different hostname, or chained to an untrusted root, the browser cannot validate it and warns the user. This explanation accurately describes what the warning conveys and why the user should be cautious about entering sensitive data.

Why this answer

A certificate warning means the browser could not validate the site's TLS certificate, so it cannot confirm the site's identity or guarantee an encrypted, trustworthy connection. Causes include expired certificates, hostname mismatches, self-signed certificates, or untrusted issuing authorities. Malware infection, a dropped connection, and outdated HTML do not produce this specific warning, so the accurate explanation is the one describing failed identity and encryption verification.

Exam trap

The trap here is treating every browser security warning as evidence of malware, when certificate errors specifically concern trust validation and encryption of the connection.

56
Multi-Selecteasy

Which TWO of the following are best practices for password security?

Select 2 answers
A.Enabling multi-factor authentication whenever possible
B.Using simple patterns like '123456' or 'password'
C.Using the same password for multiple accounts
D.Sharing passwords with coworkers for convenience
E.Using a password manager to generate and store strong passwords
AnswersA, E

Multi-factor authentication demands a second, independent factor beyond the password, so a stolen or guessed credential alone cannot grant access. This directly satisfies the password-security best-practice requirement by neutralising credential theft, replay and brute-force success.

Why this answer

Option A is correct because enabling multi-factor authentication (MFA) adds a second verification factor (something you have, such as a TOTP code or hardware token, or something you are, such as a fingerprint) on top of the password, so a stolen or guessed password alone is no longer sufficient to compromise the account. Option E is correct because a password manager generates high-entropy, unique passwords for each account and stores them encrypted (typically with AES-256) behind a single strong master passphrase, which eliminates password reuse and makes credential stuffing attacks ineffective. The remaining options are poor practices: B uses trivially guessable patterns that appear at the top of every breach wordlist, C enables credential stuffing and lateral movement because one breach exposes all accounts, and D destroys individual accountability and non-repudiation while widening the attack surface to every person who knows the shared secret.

Exam trap

FC0-U71 often tests the misconception that complex-looking but reused passwords are secure — candidates overlook that uniqueness and MFA matter more than raw complexity.

57
Multi-Selecthard

A help desk technician is reviewing security practices with a new employee who works remotely. Which TWO of the following actions BEST reduce the risk of a malware infection on the employee's workstation? (Choose two.)

Select 2 answers
A.Use the same strong password across all work accounts for easier memorization.
B.Turn off the firewall to improve network performance while working remotely.
C.Keep the operating system and installed applications updated with security patches.
D.Install and regularly update reputable antivirus or endpoint protection software.
E.Disable automatic updates so the employee controls when changes are applied.
AnswersC, D

Patches close known vulnerabilities that malware exploits to gain a foothold, so timely updates directly reduce infection risk. Operating system and application updates are a foundational preventive control recommended in every security baseline. For a remote worker without corporate network protections nearby, keeping the endpoint patched is especially important because the device is the last line of defense against exploits delivered through email, downloads, or malicious websites.

Why this answer

Keeping the operating system and applications patched closes vulnerabilities that malware exploits, while updated endpoint protection detects and blocks malicious code. Together they form a layered preventive defense for a remote workstation. Disabling updates, reusing passwords, and turning off the firewall all weaken security and do nothing to reduce malware risk, so only the patching and endpoint protection practices qualify.

Exam trap

The trap here is choosing convenience-oriented actions like disabling updates or the firewall, which feel like performance or simplicity wins but actually remove defenses against malware.

58
MCQeasy

A technician is asked to dispose of several old hard drives that contain sensitive company data. The technician wants to ensure that the data cannot be recovered by anyone who obtains the drives. Which of the following methods is the MOST secure?

A.Physically destroy the drives
B.Quick format each drive
C.Degauss the drives
D.Delete all files and empty the recycle bin
AnswerA

Physically destroying the drives, such as by shredding, drilling, or incinerating, makes the data unrecoverable because the storage media is destroyed. This is the most secure method for disposing of drives containing sensitive data, as it eliminates any possibility of data recovery. It directly fulfills the technician's goal of preventing anyone who obtains the drives from accessing the data.

Why this answer

The most secure way to ensure data cannot be recovered from old hard drives is to physically destroy them. Formatting or deleting files leaves data recoverable, and degaussing is not effective for all drive types. Physical destruction guarantees that the storage media and any data on it are irreversibly damaged, meeting the requirement to prevent unauthorized access.

Exam trap

The trap here is assuming that formatting or deleting files securely erases data, when in fact those methods leave the data recoverable with common tools.

59
Multi-Selectmedium

A company wants to implement the principle of least privilege for its employees. Which TWO of the following actions align with this principle? (Choose TWO.)

Select 2 answers
A.Providing access only to the applications needed for each employee's role
B.Allowing employees to share passwords for convenience
C.Granting all employees administrative rights by default
D.Revoking access to systems when an employee changes roles
E.Giving all employees full access to the company's financial data
AnswersA, D

Least privilege grants each user only the access required for their duties. Restricting applications to those needed for a specific role directly enforces that minimum-access principle, satisfying the stem's requirement for actions that align with least privilege.

Why this answer

Option A is correct because least privilege means granting each user only the minimum access required to perform their job, so providing access only to the applications needed for each employee's role directly enforces that restriction. Option D is correct because least privilege requires continuously right-sizing permissions; revoking access when an employee changes roles prevents privilege accumulation and removes rights no longer needed for the new position. Option B is not correct because sharing passwords destroys individual accountability and grants access beyond what any single user should have.

Option C is not correct because granting administrative rights by default massively exceeds the minimum necessary privileges. Option E is not correct because giving everyone full access to financial data violates least privilege by exposing sensitive data to users who do not need it.

60
MCQhard

A company is implementing a backup strategy. Which of the following best adheres to the 3-2-1 backup rule?

A.Two backups on tape drives, both stored in the server room
B.Original data on a server, a backup on a NAS in the same building, and a backup in the cloud
C.Original data on a laptop, a backup on a USB drive, and a backup on a second USB drive stored in a safe
D.One backup on an external drive stored in the same room as the server
AnswerB

Keeping the original on a server, one copy on a same-building NAS, and another in the cloud satisfies 3-2-1: three total copies, two distinct storage media or systems, and one held off-site. The cloud copy provides the geographic separation that the NAS alone cannot, protecting against localised loss.

Why this answer

The 3-2-1 rule means 3 copies of data, on 2 different media types, with 1 offsite. Option B meets this: 3 copies (original + 2 backups), 2 media (NAS + cloud), 1 offsite (cloud).

61
Multi-Selectmedium

A user receives a text message claiming to be from a package delivery service, saying a package could not be delivered and asking the user to click a link to reschedule. The user is unsure if the message is legitimate. Which TWO of the following actions should the user take to verify the message and avoid becoming a victim? (Choose two.)

Select 2 answers
A.Contact the delivery service using a phone number from its official website to confirm whether the message is real.
B.Reply to the text message asking for more details about the package.
C.Forward the message to a friend to ask if they received a similar one.
D.Click the link to see if the website looks official before entering any information.
E.Report the message as spam or phishing using the phone's built-in reporting feature.
AnswersA, E

Verifying through an independent, trusted channel such as the official website ensures the user is not interacting with the attacker. This confirms whether the message is legitimate without risking exposure to malicious links or providing information to a fraudster. It is a recommended practice for suspected phishing attempts.

Why this answer

The safest actions are to verify the message through an official channel and to report it as phishing. Clicking links, replying, or asking friends do not confirm legitimacy and may expose the user to risk. Reporting helps prevent others from falling victim.

Exam trap

The trap here is thinking that clicking a link just to look is harmless, when it can lead to malware or credential theft.

62
MCQmedium

A company implements a policy where employees must lock their computer screen when leaving their desk. Which security principle does this practice support?

A.Confidentiality
B.Availability
C.Authentication
D.Integrity
AnswerA

Locking the screen prevents unauthorised individuals from viewing or accessing displayed data, directly supporting confidentiality by restricting information to authorised eyes only. It satisfies the stem's requirement to protect sensitive information from exposure when a workstation is left unattended, aligning with the confidentiality pillar of the CIA triad.

Why this answer

Locking the computer screen when leaving a desk supports the confidentiality principle by preventing unauthorized individuals from viewing or accessing sensitive information on the screen or through the unlocked session. It ensures that only authorized users can access the data, aligning with confidentiality's goal of protecting information from unauthorized disclosure. This is a physical and operational control that directly reduces the risk of data exposure.

Exam trap

FC0-U71 often tests the mapping of security practices to CIA triad principles, and candidates may confuse confidentiality with authentication or integrity, especially when the control involves user access.

How to eliminate wrong answers

Option B (Availability) is wrong because locking the screen does not ensure that systems and data are accessible when needed; it actually restricts access, which is unrelated to availability. Option C (Authentication) is wrong because authentication is the process of verifying identity, while screen locking is a preventive measure after authentication has occurred; it does not verify identity itself. Option D (Integrity) is wrong because integrity ensures data is not altered improperly, whereas screen locking primarily prevents unauthorized viewing, not modification.

63
MCQeasy

Which of the following is the best practice for backing up data according to the 3-2-1 rule?

A.Three copies on two different media types, with one copy stored offsite
B.Three copies on three different external hard drives stored in the same building
C.Two copies on the same server, one on a different server
D.One copy on the same drive, one on an external drive, one in the cloud
AnswerA

The 3-2-1 rule demands three total copies, two distinct storage media, and one offsite. This option matches all three constraints exactly, ensuring resilience against local hardware failure, media-specific corruption, and site-wide disasters such as fire or flood.

Why this answer

The 3-2-1 rule means at least three copies of data, on two different types of storage media, with one copy stored offsite.

64
MCQmedium

Which backup strategy involves keeping three copies of data on two different media types with one copy offsite?

A.3-2-1 backup rule
B.Full backup
C.Differential backup
D.Incremental backup
AnswerA

The 3-2-1 rule specifies three copies of data, stored on two different media types, with one copy held offsite. This matches the stem's requirement exactly, providing redundancy against media failure and site-level disasters such as fire or theft.

Why this answer

The 3-2-1 backup rule is a widely recommended strategy that specifies: at least 3 copies of data, on 2 different media types, with 1 copy stored offsite. This ensures redundancy and protection against various failure scenarios, including local disasters. The other options are specific backup types, not strategies for copy distribution.

Exam trap

FC0-U71 often tests the confusion between specific backup types (full, incremental, differential) and overarching backup strategies like the 3-2-1 rule, so candidates must distinguish between the method of copying data and the policy for storing copies.

How to eliminate wrong answers

Option B is wrong because a full backup is a type of backup that copies all data every time, but it does not dictate the number of copies, media types, or offsite storage. Option C is wrong because a differential backup only copies changes since the last full backup, and again does not address the 3-2-1 principle. Option D is wrong because an incremental backup copies only changes since the last backup of any type, and similarly does not involve the 3-2-1 rule.

65
MCQmedium

Which of the following is a key difference between a vulnerability and a threat in cybersecurity?

A.A vulnerability is a potential harm, while a threat is a weakness
B.A vulnerability is always present, while a threat is actively exploited
C.A vulnerability is a weakness, while a threat is a potential danger
D.A vulnerability can be patched, but a threat cannot be mitigated
AnswerC

A vulnerability is an exploitable weakness in a system, whereas a threat is any potential danger or actor that could exploit it. This axis of difference satisfies the stem directly: the weakness versus the danger, not the likelihood or impact of either.

Why this answer

A vulnerability is a weakness or flaw in a system (e.g., unpatched software, misconfiguration) that could be exploited, while a threat is any potential danger or actor that could exploit that weakness (e.g., a hacker, malware, or natural disaster). Option C correctly captures this weakness-versus-danger distinction. Understanding the difference is essential for risk assessment, since risk = threat × vulnerability × impact.

Exam trap

FC0-U71 often tests the vulnerability/threat definition swap; the trap is picking the option that sounds comprehensive (like 'always present' or 'cannot be mitigated') instead of the precise weakness-versus-danger distinction.

How to eliminate wrong answers

Option A is wrong because it reverses the definitions — a vulnerability is a weakness, not a potential harm, and a threat is a potential danger, not a weakness. Option B is wrong because vulnerabilities are not 'always present' (they can be remediated) and threats are not necessarily 'actively exploited' (a threat can be latent). Option D is wrong because threats can absolutely be mitigated (via controls like firewalls, training, or insurance), and some vulnerabilities cannot be patched (e.g., legacy systems), so the statement is both inaccurate and overly absolute.

66
MCQmedium

Which of the following malware types is characterized by self-replication without needing to attach to a host file?

A.Worm
B.Virus
C.Trojan
D.Ransomware
AnswerA

A worm self-replicates across networks without attaching to a host file, satisfying the stem's defining constraint. Unlike viruses, which require a host executable to spread, worms propagate independently via exploits or network shares, consuming bandwidth and executing payloads autonomously. This distinction makes worm the precise match for the scenario described.

Why this answer

A worm is a standalone malware program that self-replicates and spreads across networks without requiring a host file or user intervention. It exploits vulnerabilities or uses social engineering to move between systems, often consuming bandwidth and system resources. Unlike viruses, worms do not need to attach themselves to legitimate files to propagate.

Exam trap

FC0-U71 often tests the misconception that all self-replicating malware are viruses, but the key differentiator is the need for a host file; worms are standalone, viruses are not.

How to eliminate wrong answers

Option B is wrong because a virus requires a host file (e.g., an executable or document) to attach to and replicate; it cannot spread independently. Option C is wrong because a Trojan is a type of malware that disguises itself as legitimate software but does not self-replicate; it relies on user execution. Option D is wrong because ransomware is a payload that encrypts files and demands payment, but it does not self-replicate; it is typically delivered via other means like phishing or exploits.

67
MCQhard

A security analyst is explaining the difference between a threat and a vulnerability. Which statement accurately describes this difference?

A.A vulnerability is a risk, and a threat is a countermeasure.
B.A threat is a weakness in a system, and a vulnerability is an attack that exploits it.
C.A threat is a potential cause of harm, and a vulnerability is a weakness that can be exploited.
D.A vulnerability is a potential harm, and a threat is likelihood times impact.
AnswerC

A threat is any potential occurrence or actor that could cause harm, whereas a vulnerability is an internal weakness — such as a flaw or misconfiguration — that a threat can exploit. This distinction separates external causes from exploitable conditions, matching the stem's request to differentiate the two terms accurately.

Why this answer

A vulnerability is a weakness, while a threat is a potential danger that exploits that weakness.

68
MCQmedium

A company wants to ensure that sensitive documents are not readable if a laptop is stolen. Which of the following provides the best protection?

A.Full disk encryption
B.Antivirus software
D.Strong password on user account
AnswerA

Full disk encryption protects data at rest by encrypting the entire drive, so a thief cannot read sensitive documents without the decryption key. This directly satisfies the constraint that files remain unreadable if the laptop is physically stolen, unlike file-level or password-only protections.

Why this answer

Full disk encryption (FDE) encrypts the entire storage drive, so if a laptop is stolen, the data remains unreadable without the decryption key. It protects data at rest even if the attacker removes the drive or boots from external media. This directly addresses the risk of physical theft.

Exam trap

The trap is that candidates pick 'strong password' thinking it protects the data, but passwords can be bypassed by removing the drive — the exam tests whether you know that only encryption makes data unreadable without the key.

How to eliminate wrong answers

Option B is wrong because antivirus software protects against malware, not physical theft of a device. Option C is wrong because a firewall controls network traffic and does nothing to protect data on a stolen laptop. Option D is wrong because a strong user account password can be bypassed by removing the drive or using offline attacks, and it does not encrypt the data itself.

69
Multi-Selecteasy

Which TWO of the following are recommended practices for physical security in an office environment? (Select two.)

Select 2 answers
A.Locking computer screens when leaving the desk
B.Writing passwords on sticky notes and attaching them to monitors
C.Sharing access badges with colleagues
D.Shredding documents containing sensitive information before disposal
E.Leaving doors propped open for convenience
AnswersA, D

Locking the screen when leaving a desk prevents unauthorised individuals from accessing data or systems on an unattended workstation. This directly addresses physical security by removing the opportunity for shoulder-surfing or walk-up misuse of an open session.

Why this answer

Option A is correct because locking the screen when leaving a desk prevents unauthorized individuals from accessing the system and data in the user's absence, which is a fundamental physical-access control in an office. Option D is correct because shredding documents containing sensitive information before disposal prevents dumpster-diving attacks and unauthorized recovery of confidential data, aligning with secure media disposal practices. Option B is not recommended because writing passwords on sticky notes exposes credentials to anyone who can physically see the monitor, defeating authentication controls.

Option C is not recommended because sharing access badges breaks individual accountability and allows unauthorized entry under someone else's identity. Option E is not recommended because propping doors open bypasses physical access controls and enables tailgating or unauthorized entry into restricted areas.

Exam trap

FC0-U71 often tests whether candidates can distinguish genuine security practices from obviously bad habits; the trap is overthinking and selecting 'sharing badges' as teamwork or 'propping doors' as convenience rather than recognizing them as violations.

70
MCQhard

An organization implements a security control that requires users to swipe a smart card and then enter a PIN to access a secure facility. Which combination of authentication factors does this represent?

A.Something you are and something you have
B.Something you know and something you do
C.Something you have and something you know
D.Something you know and something you are
AnswerC

A smart card is a physical token, satisfying something you have, while the PIN is memorised knowledge, satisfying something you know. Combining these two distinct factor categories constitutes multi-factor authentication, exactly as the stem's swipe-then-PIN control requires.

Why this answer

A smart card is a physical token the user possesses, satisfying 'something you have,' while a PIN is a memorized secret, satisfying 'something you know.' Combining these two different factor categories constitutes multi-factor authentication (MFA), which is stronger than single-factor or same-category authentication. This is a classic two-factor physical access control scenario.

Exam trap

The trap is that candidates must correctly categorize each credential into the right factor class — many mistakenly classify a PIN as 'something you are' or a smart card as 'something you know,' or fail to recognize that two different categories are required for MFA.

How to eliminate wrong answers

Option A is wrong because 'something you are' refers to biometrics (fingerprint, iris, face), and no biometric factor is present here. Option B is wrong because 'something you do' refers to behavioral biometrics like typing rhythm or gait, which are not involved. Option D is wrong because it pairs 'something you know' with 'something you are,' but the smart card is a possession factor, not a biometric.

71
Multi-Selecthard

Which THREE of the following are examples of multi-factor authentication? (Select three.)

Select 3 answers
A.A smart card and a PIN
B.A password and a fingerprint scan
C.A retina scan and a fingerprint scan
D.A username and password
E.A one-time code sent to a phone and a password
AnswersA, B, E

A smart card (something you have) combined with a PIN (something you know) draws on two distinct authentication factors, satisfying multi-factor authentication. Possession of the card alone or knowledge of the PIN alone is insufficient, so both categories must be presented to authenticate.

Why this answer

Multi-factor authentication (MFA) requires combining factors from different categories: something you know (password, PIN), something you have (smart card, phone, token), and something you are (biometrics such as fingerprint or retina scan). Option A is correct because a smart card (something you have) plus a PIN (something you know) combines two distinct factor types. Option B is correct because a password (something you know) plus a fingerprint scan (something you are) also mixes two different factor categories.

Option E is correct because a one-time code sent to a phone (something you have) plus a password (something you know) likewise draws on two separate factor types. Option C does not qualify because a retina scan and a fingerprint scan are both biometrics, i.e., two instances of the same 'something you are' factor. Option D does not qualify because a username and password are both 'something you know' and represent a single authentication factor.

Exam trap

FC0-U71 often tests whether candidates confuse 'multiple authentication steps' with 'multiple authentication factors' — picking two passwords or two biometrics because they look like two checks, when MFA strictly requires different factor categories.

72
Multi-Selecthard

A help desk technician is coaching a new employee on how to recognize social engineering attempts that arrive by phone and text message rather than email. Which TWO characteristics should the technician tell the employee to treat as warning signs? (Choose two.)

Select 2 answers
A.The message is sent during normal business hours from a number the employee does not recognize
B.The caller refuses to provide a callback number and pressures the employee to read aloud a one-time verification code
C.The caller creates urgency by claiming the account will be locked within minutes unless information is confirmed
D.The text message contains a company logo and a polite greeting
E.The message arrives on a company-issued mobile phone
AnswersB, C

Refusing a callback number prevents the target from independently verifying the caller's identity, which is exactly what an impostor wants. Requesting a one-time code is a serious red flag because those codes exist to prove possession of the account holder's device, and sharing one can hand over an active session. Together these behaviors indicate an attempt to bypass multifactor authentication.

Why this answer

Social engineering succeeds by manipulating people rather than technology, so the reliable indicators concern the pressure tactics and verification refusals used by the attacker. Demanding immediate action and blocking independent verification while requesting a one-time code both point to an attempt to bypass normal identity checks. Familiar-looking branding, timing, and the receiving device are all easily imitated and therefore poor signals.

Exam trap

The trap here is treating cosmetic details such as logos, polite wording, or the phone used as evidence of legitimacy instead of focusing on the pressure and verification behavior.

73
MCQeasy

An employee working from a coffee shop connects a laptop to an open wireless network to check webmail. The employee wants to prevent other patrons on that same network from capturing the login credentials in transit. Which technology BEST provides this protection?

A.A virtual private network (VPN) tunnel to the company network
B.Full-disk encryption enabled on the laptop drive
C.A screen privacy filter placed over the laptop display
D.A host-based firewall enabled on the laptop
AnswerA

A VPN encrypts traffic from the laptop to the company gateway, so other users sharing the open wireless link see only ciphertext even if they capture the frames. Because the tunnel is established before the webmail session travels, credentials and content are shielded from local eavesdroppers. This directly addresses the risk of interception on an untrusted network.

Why this answer

On an open wireless network, frames are broadcast over a shared medium where any nearby device can capture them, so confidentiality must come from encryption applied to the traffic itself. A VPN creates an encrypted tunnel from the laptop to a trusted endpoint, hiding credentials and content from local eavesdroppers. Firewalls, screen filters, and disk encryption each defend different assets and none encrypts data in transit.

Exam trap

The trap here is confusing controls that protect data at rest or the physical screen with a control that protects data in transit over an untrusted network.

74
MCQeasy

A small accounting firm stores client tax records on a shared network folder. The owner wants to ensure that only the three staff members who prepare taxes can open those files, while other employees can still access the general office folder. Which security concept should the owner apply to the tax records folder?

A.Full disk encryption on each employee workstation
B.A firewall rule that blocks the file server's SMB port for non-tax staff
C.Access control lists (ACLs) that grant permissions only to the tax preparers group
D.Antivirus software configured to scan the shared folder nightly
AnswerC

ACLs are the standard mechanism for assigning permissions to specific users or groups on file and folder resources. By granting access only to a tax preparers group, the owner enforces authorization so that other employees are denied access to the tax records while remaining able to reach the general office folder, which matches the scenario exactly.

Why this answer

The requirement is an authorization decision about who may read specific files on a shared server. ACLs attached to the tax folder let the owner grant permissions to a tax preparers group and deny everyone else, while leaving the general office folder open to all staff. Encryption, firewalls, and antivirus address different risks and cannot enforce per-user file access.

Exam trap

The trap here is assuming that any protective technology, such as encryption or antivirus, can restrict which users open a file, when only permissions such as ACLs perform that authorization function.

75
Multi-Selecthard

An IT administrator is hardening a server. Which three of the following actions should be taken to improve security? (Select THREE.)

Select 3 answers
A.Disable unused services and ports
B.Implement the principle of least privilege
C.Disable the firewall for better performance
D.Enable automatic software updates
E.Grant all users administrative rights
AnswersA, B, D

Disabling unused services and ports shrinks the attack surface by removing listening daemons and open sockets that attackers could exploit. This directly satisfies the hardening goal, since every unnecessary service is a potential entry point for exploitation or lateral movement.

Why this answer

Option A is correct because disabling unused services and closing unused ports reduces the attack surface, eliminating unnecessary daemons and listening sockets that attackers could exploit. Option B is correct because applying the principle of least privilege ensures users and processes receive only the minimum rights needed, limiting the blast radius of a compromise or insider misuse. Option D is correct because enabling automatic software updates ensures timely patching of known vulnerabilities in the OS and applications, closing exploits before they can be leveraged.

Option C is incorrect because disabling the firewall removes a critical network access control layer and exposes services to unauthorized traffic, harming rather than improving security. Option E is incorrect because granting all users administrative rights violates least privilege and dramatically increases the risk of privilege abuse and malware propagation.

Exam trap

FC0-U71 often tests the misconception that performance or convenience (disabling firewall, granting admin rights) improves security—candidates must recognize that these actions weaken security, while the three correct choices are standard hardening measures.

Page 1 of 2 · 123 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Itf Security questions.