Courseiva
and …","url":"https://courseiva.com/questions/comptia/security-plus/a-web-form-stores-a-user-s-comment-and-later-displays-it-to"},{"@type":"ListItem","position":996,"name":"A desktop engineering team asks for the document that specifies the exact minimum encryption setting, screen-lock timer,…","url":"https://courseiva.com/questions/comptia/security-plus/a-desktop-engineering-team-asks-for-the-document-that-specifies"},{"@type":"ListItem","position":997,"name":"Based on the exhibit, what additional control is the best fit?\r\n\r\nCurrent controls on the finance share:\r\n- SMB signing …","url":"https://courseiva.com/questions/comptia/security-plus/based-on-the-exhibit-what-additional-control-is-the-best-fit"},{"@type":"ListItem","position":998,"name":"A user receives an SMS from 'IT Service Desk' saying their MFA enrollment expires today and includes a shortened link. F…","url":"https://courseiva.com/questions/comptia/security-plus/a-user-receives-an-sms-from-it-service-desk-saying-their-mfa"},{"@type":"ListItem","position":999,"name":"A security analyst receives an alert that a user clicked a link in a phishing email and entered their corporate credenti…","url":"https://courseiva.com/questions/comptia/security-plus/a-security-analyst-receives-an-alert-that-a-user-clicked-a-link"},{"@type":"ListItem","position":1000,"name":"An employee receives an email from someone claiming to be from IT. The message says the employee must read back a one-ti…","url":"https://courseiva.com/questions/comptia/security-plus/an-employee-receives-an-email-from-someone-claiming-to-be-from"},{"@type":"ListItem","position":1001,"name":"Match each principle to the workplace scenario.","url":"https://courseiva.com/questions/comptia/security-plus/match-each-principle-to-the-workplace-scenario"},{"@type":"ListItem","position":1002,"name":"Based on the exhibit, what is the best change to improve accountability without removing emergency access?","url":"https://courseiva.com/questions/comptia/security-plus/based-on-the-exhibit-what-is-the-best-change-to-improve"},{"@type":"ListItem","position":1003,"name":"A Linux web server was compromised through an outdated package. The team isolated the host, captured evidence, removed a…","url":"https://courseiva.com/questions/comptia/security-plus/a-linux-web-server-was-compromised-through-an-outdated-package"},{"@type":"ListItem","position":1004,"name":"After a phishing incident, the security team wants to preserve evidence for later review. Which action is most appropria…","url":"https://courseiva.com/questions/comptia/security-plus/after-a-phishing-incident-the-security-team-wants-to-preserve"},{"@type":"ListItem","position":1005,"name":"Based on the exhibit, which access design change best reduces fraud risk without stopping the payroll process?\r\n\r\nExhibi…","url":"https://courseiva.com/questions/comptia/security-plus/based-on-the-exhibit-which-access-design-change-best-reduces"},{"@type":"ListItem","position":1006,"name":"A security architect is designing a solution to process highly sensitive financial transactions in a shared cloud enviro…","url":"https://courseiva.com/questions/comptia/security-plus/a-security-architect-is-designing-a-solution-to-process-highly"},{"@type":"ListItem","position":1007,"name":"HR stores scanned government IDs collected during onboarding. The retention policy says the files may be kept for 90 day…","url":"https://courseiva.com/questions/comptia/security-plus/hr-stores-scanned-government-ids-collected-during-onboarding-the"},{"@type":"ListItem","position":1008,"name":"Match each excerpt from a small enterprise security program to the correct governance artifact.","url":"https://courseiva.com/questions/comptia/security-plus/match-each-excerpt-from-a-small-enterprise-security-program-to"},{"@type":"ListItem","position":1009,"name":"A SIEM alert shows a payroll administrator account signed in at 02:10 from a country the employee has never visited. The…","url":"https://courseiva.com/questions/comptia/security-plus/a-siem-alert-shows-a-payroll-administrator-account-signed-in-at"},{"@type":"ListItem","position":1010,"name":"Management wants to ensure a file server backed up every night can actually be restored within a 4-hour recovery time ob…","url":"https://courseiva.com/questions/comptia/security-plus/management-wants-to-ensure-a-file-server-backed-up-every-night"},{"@type":"ListItem","position":1011,"name":"NetFlow and authentication logs show one workstation opening SMB and WinRM sessions to many internal hosts within ten mi…","url":"https://courseiva.com/questions/comptia/security-plus/netflow-and-authentication-logs-show-one-workstation-opening-smb"},{"@type":"ListItem","position":1012,"name":"Based on the exhibit, which item is the strongest evidence that quarterly privileged access reviews occurred?","url":"https://courseiva.com/questions/comptia/security-plus/based-on-the-exhibit-which-item-is-the-strongest-evidence-that"},{"@type":"ListItem","position":1013,"name":"A SIEM reviews VPN authentication logs and sees 36 different usernames each receive one failed login attempt from the sa…","url":"https://courseiva.com/questions/comptia/security-plus/a-siem-reviews-vpn-authentication-logs-and-sees-36-different"}]} and the script runs in the browser. What vulnerability is this?","url":"https://courseiva.com/questions/comptia/security-plus/a-web-form-stores-a-user-s-comment-and-later-displays-it-to","acceptedAnswer":{"@type":"Answer","text":"Cross-site scripting","comment":{"@type":"Comment","text":"The application reflects untrusted input into a page without proper encoding, allowing script execution."}},"suggestedAnswer":[{"@type":"Answer","text":"SQL injection","comment":{"@type":"Comment","text":"SQL injection targets database queries, not browser execution of injected script code."}},{"@type":"Answer","text":"Cross-site request forgery","comment":{"@type":"Comment","text":"CSRF tricks a logged-in user into making unwanted actions, not running injected script."}},{"@type":"Answer","text":"Command injection","comment":{"@type":"Comment","text":"Command injection abuses server-side OS commands, not JavaScript running in a browser."}}]},{"@context":"https://schema.org","@type":"Quiz","name":"A desktop engineering team asks for the document that specifies the exact minimum encryption setting, screen-lock timer, and password length for company laptops. Which type of document should they fol","url":"https://courseiva.com/questions/comptia/security-plus/a-desktop-engineering-team-asks-for-the-document-that-specifies","acceptedAnswer":{"@type":"Answer","text":"Standard, because it defines mandatory uniform requirements for a specific control baseline.","comment":{"@type":"Comment","text":"A standard is the correct document when the organization needs a consistent, mandatory technical baseline such as encryption strength, lock timing, or password length. Standards translate policy into measurable requirements and are suitable for system configuration because they reduce ambiguity and support enforcement across similar assets."}},"suggestedAnswer":[{"@type":"Answer","text":"Policy, because it states the organization's general intent and high-level direction.","comment":{"@type":"Comment","text":"A policy articulates the organization's security intent, risk appetite, and executive-level expectations, but it deliberately avoids concrete technical parameters such as exact password lengths or encryption algorithms. Consequently, while a policy can mandate that systems be baselined, it is not the document that specifies the precise control settings required for a homogeneous laptop build. The standard supplies those measurable, enforceable values."}},{"@type":"Answer","text":"Procedure, because it gives the organization-wide security purpose statement.","comment":{"@type":"Comment","text":"A procedure is a chronological, step-by-step work instruction used to perform a task, such as provisioning a laptop or applying a patch, rather than a declaration of organization-wide security purpose. It answers \"how to do it\" and typically cites an underlying standard or guideline for the actual configuration values. Therefore, it cannot be the document that defines the mandatory baseline itself, and its role is operational, not direction-setting."}},{"@type":"Answer","text":"Guideline, because it provides optional suggestions that every laptop must obey.","comment":{"@type":"Comment","text":"A guideline offers recommended, often best-practice approaches that teams may adapt to their environment, making it inherently flexible and non-mandatory. The option's phrase \"every laptop must obey\" is internally inconsistent because guidelines explicitly allow discretion and alternatives, unlike a standard's required uniform control baseline. For a consistent enterprise desktop configuration, enforceable numeric thresholds must live in a standard, not a suggestion document."}}]},{"@context":"https://schema.org","@type":"Quiz","name":"Based on the exhibit, what additional control is the best fit?\r\n\r\nCurrent controls on the finance share:\r\n- SMB signing enabled\r\n- Weekly access review\r\n- Nightly backups to immutable storage\r\n- Antiv","url":"https://courseiva.com/questions/comptia/security-plus/based-on-the-exhibit-what-additional-control-is-the-best-fit","acceptedAnswer":{"@type":"Answer","text":"Add file access auditing with alert thresholds forwarded to the SIEM.","comment":{"@type":"Comment","text":"File access auditing enables granular tracking of who accessed which files and when. When combined with alert thresholds (e.g., a user reading hundreds of files in minutes), the SIEM can generate real-time alerts for potential bulk data exfiltration. As a detective control, it directly addresses the missing visibility into abnormal access patterns and supports timely incident response."}},"suggestedAnswer":[{"@type":"Answer","text":"Increase the backup schedule from nightly to hourly.","comment":{"@type":"Comment","text":"Increasing backup frequency from nightly to hourly improves recovery point objectives, reducing data loss in a disaster or ransomware event. However, backups operate in the background and simply copy data to secondary storage; they provide no analysis of access patterns. Suspicious bulk reads by a valid account would still go unnoticed because the control does not generate security alerts or audit events."}},{"@type":"Answer","text":"Rename the share to a less obvious name.","comment":{"@type":"Comment","text":"Renaming the share to something less obvious is a form of security through obscurity. It might reduce casual discovery, but it does not authenticate, authorize, or monitor access, and it will not stop an attacker who enumerates network shares or already possesses valid credentials. Moreover, it produces no audit trail, so abnormal usage cannot be detected or investigated."}},{"@type":"Answer","text":"Disable SMB signing so the file transfer runs faster.","comment":{"@type":"Comment","text":"Disabling SMB signing to improve transfer speed removes integrity and authenticity protections from SMB sessions, exposing traffic to potential tampering or man-in-the-middle attacks. While the performance gain may be real, this change is a security regression and has no relationship to detecting bulk reads. It would not flag abnormal file access; in fact, it could make exfiltration easier for an attacker."}}]},{"@context":"https://schema.org","@type":"Quiz","name":"A user receives an SMS from 'IT Service Desk' saying their MFA enrollment expires today and includes a shortened link. Five minutes later, the user gets a phone call from the same number asking them t","url":"https://courseiva.com/questions/comptia/security-plus/a-user-receives-an-sms-from-it-service-desk-saying-their-mfa","acceptedAnswer":{"@type":"Answer","text":"Smishing is used because the first lure arrives by text message.","comment":{"@type":"Comment","text":"Smishing is phishing delivered through SMS or another text-based mobile messaging channel. The fake IT Service Desk text with a shortened link is a classic example because it attempts to get the user to click a link and interact outside the normal support process."}},"suggestedAnswer":[{"@type":"Answer","text":"Email phishing is used because the attacker is requesting a login action.","comment":{"@type":"Comment","text":"Phishing is a broad term, but this scenario is specifically about SMS and voice, not email. Since the channel is not email, calling it email phishing would be inaccurate. The attacker may still be phishing generally, but the more precise attack channels are different and more useful for response."}},{"@type":"Answer","text":"Baiting is used because the attacker offers a free reward or device.","comment":{"@type":"Comment","text":"Baiting usually involves enticing the victim with something attractive, such as free media, hardware, or a promised benefit. This scenario instead uses a fake service request and a follow-up call. There is no lure of a reward, so baiting is not the best fit."}},{"@type":"Answer","text":"Tailgating is used because the attacker follows someone into a restricted area.","comment":{"@type":"Comment","text":"Tailgating is a physical social engineering tactic involving unauthorized entry into a secured space. This scenario takes place over SMS and phone, so it does not involve a person following another through a door or into a controlled area. That makes tailgating irrelevant here."}}]},{"@context":"https://schema.org","@type":"Quiz","name":"A security analyst receives an alert that a user clicked a link in a phishing email and entered their corporate credentials on a fake login page. Which of the following should the analyst do FIRST to ","url":"https://courseiva.com/questions/comptia/security-plus/a-security-analyst-receives-an-alert-that-a-user-clicked-a-link","acceptedAnswer":{"@type":"Answer","text":"Disable the user's account and block the compromised system from the network","comment":{"@type":"Comment","text":"Disabling the user's account terminates the attacker's authenticated sessions and invalidates stolen credentials, while blocking the compromised system at the network layer severs any existing command-and-control, RDP, or file-transfer connections. This containment step is the immediate priority because it prevents lateral movement and data exfiltration without destroying volatile evidence on the host. In contrast to reactive scanning or password resets, isolating first gives the incident response team a clean boundary to perform forensic acquisition and threat hunting."}},"suggestedAnswer":[{"@type":"Answer","text":"Run a full antivirus scan on the user's workstation","comment":{"@type":"Comment","text":"Running an antivirus scan is not the first step because the incident is a credential theft via phishing, not a malware infection. While the system may have been compromised, containment of the credentials is more urgent."}},{"@type":"Answer","text":"Reset the user's password and force re-authentication","comment":{"@type":"Comment","text":"Resetting the user's password and forcing re-authentication fails as a first step because password resets do not revoke already-issued session tokens, cookies, or OAuth refresh tokens in many SSO and federated identity systems, allowing the attacker to remain authenticated. It also leaves the compromised endpoint connected to the network, so any keylogger or credential-stealing malware on that host can simply capture the new password when the user types it. Worse, an active attacker who notices the forced re-auth prompt knows their access was detected and may accelerate exfiltration or plant backdoors before you regain control. Containment — disabling the account and isolating the host — must precede any credential-reset action."}},{"@type":"Answer","text":"Contact law enforcement and report the phishing site","comment":{"@type":"Comment","text":"Contacting law enforcement and reporting the phishing site is an important post-containment step, but it does nothing to stop an attacker who currently holds valid credentials. Law enforcement processes are inherently slow and require chain-of-custody documentation that is only meaningful after the organization has secured its own environment. Furthermore, initiating external communication before containment can alert the adversary through publicly observable actions, giving them time to destroy logs or deploy persistence. The IR plan should first mitigate the verified threat, then escalate to authorities with a preserved evidence package."}}]},{"@context":"https://schema.org","@type":"Quiz","name":"An employee receives an email from someone claiming to be from IT. The message says the employee must read back a one-time verification code so their mailbox can be 'repaired.' What social engineering","url":"https://courseiva.com/questions/comptia/security-plus/an-employee-receives-an-email-from-someone-claiming-to-be-from","acceptedAnswer":{"@type":"Answer","text":"Pretexting, because the attacker is using a fake identity and story to gain trust.","comment":{"@type":"Comment","text":"Pretexting is a social engineering technique where the attacker fabricates a scenario and adopts a trusted role—here, an IT support agent—to elicit sensitive information. The email invents a believable reason, such as account verification or troubleshooting, to lower the victim's suspicion and prompt disclosure of the one-time code. This relies on establishing false trust and exploiting the victim's willingness to comply with an authority figure, making it distinct from technical attacks."}},"suggestedAnswer":[{"@type":"Answer","text":"Tailgating, because the attacker is trying to enter a secure area physically.","comment":{"@type":"Comment","text":"Tailgating, also known as piggybacking, exploits physical access controls by following an authorized person through a secure doorway without presenting credentials. The described attack is purely digital and relies on psychological manipulation via email to obtain a one-time code, with no physical presence or access-control bypass involved. Tailgating would require the attacker to be at the facility and does not explain the request for a secret code."}},{"@type":"Answer","text":"DDoS, because the message is designed to overwhelm the mailbox server.","comment":{"@type":"Comment","text":"A distributed denial-of-service (DDoS) attack aims to exhaust a target server's or network's resources by flooding it with traffic from many compromised systems. It is an availability attack, not a confidentiality attack, and does not involve sending a deceptive email or requesting a one-time passcode. The email targets a single user's trust and secrets, whereas DDoS would be directed at the mail server's infrastructure and would not require a response from the victim."}},{"@type":"Answer","text":"Shoulder surfing, because the attacker is watching the screen from nearby.","comment":{"@type":"Comment","text":"Shoulder surfing is a direct observation attack where the attacker visually captures sensitive data, such as a one-time code, by looking over the victim's shoulder or using recording devices. This scenario involves an email-based request, so the threat actor never needs to be physically near the victim. Even if the attacker later uses the code, the initial compromise vector is a fabricated communication, not line-of-sight surveillance."}}]}]

Security+ SY0-701 (SY0-701) — Questions 9761013

1013 questions total · 14pages · All types, answers revealed

Page 13

Page 14 of 14

976
MCQmedium

An employee reports a ransomware note on a finance laptop. The laptop is still powered on, connected to Wi-Fi, and the user says they were just working in a spreadsheet. Management wants the fastest safe response that also preserves evidence. What should the responder do first?

A.Shut the laptop down immediately to prevent further encryption activity.
B.Isolate the laptop from the network while keeping it powered on for volatile evidence collection.
C.Ask the user to close all open applications and log off normally.
D.Start deleting suspicious files to reduce the impact of the ransomware.
AnswerB

The best first action is to contain the threat without destroying live evidence. Disconnecting network access limits further spread or command-and-control activity, while keeping the system powered on preserves memory, running processes, and other volatile artifacts that may be critical to the investigation. This balances containment with evidence preservation, which is exactly what responders need at the start of an incident.

Why this answer

The immediate priority is to contain the ransomware while preserving volatile evidence (e.g., memory contents, running processes, network connections) that could be critical for forensic analysis. Powering off the laptop (Option A) would destroy volatile data and may allow the ransomware to persist or trigger additional encryption on reboot. Isolating the network connection stops the ransomware from communicating with its command-and-control server or spreading laterally, while keeping the system powered on allows a responder to capture memory with tools like FTK Imager or LiME before performing a controlled shutdown.

Exam trap

The SY0-701 exam often tests the misconception that shutting down a compromised system is the safest immediate action, but the trap here is that volatile evidence is lost and the ransomware may have anti-forensic shutdown triggers, making network isolation the correct first step.

How to eliminate wrong answers

Option A is wrong because immediately shutting down the laptop destroys volatile evidence (RAM, running processes, network connections) that could reveal the ransomware variant, encryption keys, or attacker infrastructure; it may also trigger a destructive payload on shutdown. Option C is wrong because asking the user to close applications and log off normally could trigger additional encryption, overwrite evidence in memory, or allow the ransomware to complete its encryption cycle; logging off may also terminate critical forensic artifacts like open network connections or process handles.

977
MCQmedium

A critical vulnerability is discovered on an internet-facing VPN appliance that cannot be patched for six weeks because the vendor has not released a fix. The VPN service must remain available. What is the best operational response?

A.Leave the appliance unchanged until the vendor releases a patch.
B.Apply compensating controls such as restricting source IPs and increasing monitoring.
C.Disable all logging so the appliance performs better under load.
D.Replace the VPN with a less secure remote access method to avoid the vulnerability.
AnswerB

When a patch is not yet available, compensating controls such as restricting source IP addresses via firewall allow-lists, enforcing multi-factor authentication, and increasing security monitoring are the appropriate interim measures. These controls reduce the likelihood of exploitation by limiting who can reach the VPN management interface and by generating alerts on abnormal access patterns, while maintaining essential service availability. The goal is to buy time for a proper patch deployment without leaving the device entirely defenseless.

Why this answer

When a vulnerability cannot be patched immediately, compensating controls such as restricting source IPs via ACLs and increasing monitoring (e.g., enabling detailed logging and alerting on anomalous traffic) reduce the attack surface and improve detection of exploitation attempts. This approach maintains service availability while mitigating risk until the vendor releases a fix.

Exam trap

The trap here is that candidates may think leaving the appliance unchanged (Option A) is acceptable if no patch exists, but the exam expects proactive risk reduction through compensating controls rather than passive acceptance of the vulnerability.

How to eliminate wrong answers

Option A is wrong because leaving the appliance unchanged without any mitigation leaves the organization fully exposed to exploitation of the known vulnerability, which is unacceptable for a critical internet-facing device. Option C is wrong because disabling logging reduces visibility into potential attacks, making it harder to detect and respond to exploitation, and does not address the vulnerability itself. Option D is wrong because replacing the VPN with a less secure remote access method introduces new risks and likely violates security policies, whereas the goal is to maintain security while keeping the service available.

978
MCQmedium

A security operations center (SOC) analyst is overwhelmed by the volume of alerts. The management wants to implement a solution that can automatically respond to common threats, such as blocking an IP address or isolating a compromised endpoint, without requiring human intervention. Which of the following technologies best meets this requirement?

A.Security Information and Event Management (SIEM)
B.Security Orchestration, Automation, and Response (SOAR)
C.Endpoint Detection and Response (EDR)
D.Cloud Access Security Broker (CASB)
AnswerB

SOAR platforms are purpose-built to aggregate alerts from multiple sources, execute predefined playbooks, and automatically trigger response actions such as containing a host, blocking an IoC, or opening a ticket. By orchestrating workflows across disparate security tools (e.g., SIEM, EDR, firewalls), SOAR directly reduces the manual triage and repetitive tasks that overwhelm analysts. This capability to automate complex, multi-step incident response without human intervention makes it the exact fit for the scenario.

Why this answer

SOAR is the correct choice because it is specifically designed to automate response actions to common security incidents, such as blocking an IP address via firewall APIs or isolating an endpoint through EDR integration, without requiring human intervention. This directly addresses the SOC analyst's alert fatigue by enabling playbook-driven, automated remediation.

Exam trap

The trap here is that candidates confuse SIEM's alerting capability with automated response, forgetting that SIEMs require a separate SOAR or custom scripting to perform actions, while SOAR is the dedicated solution for orchestrated, automated remediation.

Why the other options are wrong

A

SIEM aggregates and correlates logs for analysis but lacks native automated response capabilities; it requires human intervention or integration with other tools to block IPs or isolate endpoints.

C

EDR focuses on detecting and investigating threats on endpoints, but it does not inherently provide automated response orchestration across multiple security tools to block IPs or isolate endpoints without human intervention.

D

CASB is designed to enforce security policies for cloud services, not to automate response actions like blocking IPs or isolating endpoints across the enterprise.

When would these options actually be correct?

A

A question asking for a solution to centralize log collection, correlate events across sources, and provide real-time alerting for security incidents, without requiring automated response, would make SIEM the correct answer.

C

An exam question asking for a technology that provides continuous monitoring, detection, and manual or automated response specifically on endpoint devices, such as identifying malware or suspicious processes on a laptop, would make EDR the correct answer.

D

A question asking for a technology that monitors and controls access to cloud applications, enforces data loss prevention policies, and detects shadow IT in a multi-cloud environment.

Why candidates pick the wrong answer

A

Candidates often associate SIEM with security monitoring and incident response, mistakenly believing its alerting features include automated remediation, overlooking that SOAR specifically adds orchestration and automation.

C

Candidates may confuse EDR's automated response capabilities (like isolating an endpoint) with the broader orchestration and automation across multiple systems that SOAR provides, overlooking the need for cross-platform automation.

D

Candidates may confuse CASB's policy enforcement capabilities with automated response, or think it can handle endpoint isolation due to its security control features.

979
MCQmedium

A systems administrator says the backup software reports success every night, but no one has restored a server from backup in over a year. The business wants confidence that a file server can be recovered within the agreed recovery window. What is the best next action?

A.Trust the success status because completed jobs prove the backups are usable.
B.Perform a scheduled restore test in an isolated environment and measure the recovery time.
C.Delete older backups so that only the most recent set remains.
D.Extend retention indefinitely to avoid ever losing a recoverable copy.
AnswerB

Performing a scheduled restore test in an isolated environment directly validates that the backup media contains usable data and that the restore procedure works end-to-end. This practice confirms the organization can meet its recovery point objective (RPO) and recovery time objective (RTO) by measuring how long the restore actually takes. It also surfaces hidden issues such as missing dependencies or permission problems while avoiding production disruption.

Why this answer

The only way to validate that backups are both restorable and meet the recovery time objective (RTO) is to perform a scheduled restore test in an isolated environment. Backup success logs only confirm that data was copied, not that the data is intact or that the restoration process completes within the agreed window. This aligns with the 3-2-1 backup rule and the principle of 'trust but verify' in backup validation.

Exam trap

The trap here is that candidates assume backup success logs are sufficient proof of recoverability, but CompTIA emphasizes that only a documented restore test can verify the backup's usability and adherence to the RTO.

How to eliminate wrong answers

Option A is wrong because backup success status only indicates that the backup job completed without errors, not that the backup data is restorable or that the recovery process will meet the RTO; data corruption, missing files, or incomplete snapshots can still occur. Option C is wrong because deleting older backups reduces the number of recovery points and increases the risk of data loss, especially if the most recent backup is corrupted or fails to restore. Option D is wrong because extending retention indefinitely does not address the core issue of verifying recoverability and can lead to storage bloat, increased costs, and compliance violations without proving that a restore is possible within the RTO.

980
MCQeasy

A user reports that their laptop is suddenly encrypting files and showing a ransom note. What should the incident response team do first?

A.Immediately restore the laptop from backup before collecting any information.
B.Isolate the laptop from the network to limit spread and preserve evidence.
C.Return the laptop to the user and monitor for additional alerts.
D.Apply all pending software updates to the laptop while it remains online.
AnswerB

Isolation is the critical containment step in an active ransomware outbreak: by disconnecting the laptop from the network (unplugging Ethernet, disabling Wi-Fi and Bluetooth), you stop the malware from encrypting any networked file shares or hopping to adjacent hosts via SMB or other propagation mechanisms. This action also preserves the system's live state so that forensic tools can capture memory, running processes, and encryption artifacts without the device being either further contaminated or remotely meddled with by the attacker. Containment must happen before eradication and recovery, per NIST IR lifecycle.

Why this answer

When a laptop suddenly encrypts files and displays a ransom note, it indicates an active ransomware infection. The incident response team's first priority is to isolate the laptop from the network to prevent the ransomware from spreading laterally to other systems and to preserve volatile evidence (e.g., memory contents, running processes) that could be lost if the system is powered off or reconnected. This aligns with the NIST SP 800-61 incident response guidelines, which emphasize containment before eradication or recovery.

Exam trap

The trap here is that candidates may confuse incident response phases and choose a recovery action (like restoring from backup) before containment, or they may mistakenly think applying updates is a valid response to an active infection, when in fact isolation is the mandatory first step per the NIST framework.

How to eliminate wrong answers

Option A is wrong because immediately restoring from backup without first isolating the system could allow the ransomware to re-encrypt the restored files if the infection is still active, and it destroys volatile evidence needed for forensic analysis. Option C is wrong because returning the laptop to the user and monitoring for additional alerts would allow the ransomware to continue encrypting files and potentially spread to other network resources, violating the containment principle. Option D is wrong because applying pending software updates while the laptop remains online does not stop the active encryption process and could trigger additional malicious activity; updates are a preventive measure, not an incident response containment step.

981
MCQhard

Based on the exhibit, which malware type best explains the behavior?

A.Trojan
B.Rootkit
C.Logic bomb
D.Spyware
AnswerB

The exhibit shows a hidden listener associated with PID 4, an unsigned driver, and a mismatch between user-mode process enumeration and kernel telemetry. Those are classic rootkit indicators because rootkits operate at a low level to conceal processes, ports, or files from standard tools. The suspicious driver name and kernel-level inconsistency are especially strong clues that the malware is trying to hide itself from the operating system and defenders.

Why this answer

A rootkit is designed to hide its presence and the presence of other malware by modifying the operating system's kernel or system calls, allowing it to evade detection by security tools. The exhibit likely shows behavior such as file hiding, process concealment, or system call interception, which are hallmarks of rootkit activity. This aligns with the SY0-701 objective on understanding malware types and their characteristics.

Exam trap

The trap here is that candidates often confuse a rootkit's stealth capabilities with a Trojan's deceptive delivery method, failing to recognize that the exhibit's focus on hiding and persistence at the OS level is unique to rootkits, not general malware types.

How to eliminate wrong answers

Option A (Trojan) is wrong because a Trojan disguises itself as legitimate software to trick users into installing it, but it does not inherently hide its presence or modify the kernel to evade detection; the exhibit's behavior of stealth and system-level concealment is not typical of a Trojan. Option C (Logic bomb) is wrong because a logic bomb is a piece of code that executes a malicious payload when specific conditions are met (e.g., a date or user action), but it does not actively hide itself or its processes; the exhibit's ongoing stealth behavior is inconsistent with a dormant trigger-based mechanism. Option D (Spyware) is wrong because spyware focuses on covertly collecting user data (e.g., keystrokes, browsing habits) and sending it to an attacker, but it does not typically modify the OS kernel or hide its own files and processes at the rootkit level; the exhibit's system-level concealment goes beyond spyware's typical user-space monitoring.

982
MCQmedium

Based on the exhibit, which control should be enabled so corporate data stays separated from personal data on company-owned tablets?

A.Perform a full-device wipe any time a tablet is lost or reassigned.
B.Deploy mobile threat defense scanning on every tablet.
C.Enable a work profile or container with selective wipe for corporate data.
D.Disable Bluetooth and the camera on all tablets to stop data leakage.
AnswerC

Enabling a work profile (e.g., Android Work Profile or iOS managed container) creates a dedicated, encrypted boundary that separates corporate apps and data from personal content on the same device. Policies can enforce selective wipe of only that container when a device is lost, reassigned, or non-compliant, preserving the user's personal data. This also allows IT to manage corporate email, VPN, and app restrictions within the profile without granting full control of the personal side—directly addressing the need for workflow separation.

Why this answer

A work profile or container (e.g., Android Work Profile or iOS Managed Open In) creates a separate, encrypted partition for corporate data on the device. This allows IT to perform a selective wipe of only the corporate data without affecting the user's personal apps, photos, or settings, ensuring data separation while preserving user privacy.

Exam trap

The trap here is that candidates confuse security controls like full-device wipe or threat scanning with data separation mechanisms, failing to recognize that only containerization or work profiles provide the granular isolation needed to keep corporate and personal data separate on the same device.

How to eliminate wrong answers

Option A is wrong because performing a full-device wipe on loss or reassignment destroys both corporate and personal data, violating the requirement to keep corporate data separated from personal data; it does not enable ongoing separation. Option B is wrong because mobile threat defense scanning detects malware or suspicious activity but does not isolate corporate data into a separate container; it provides security monitoring, not data separation. Option D is wrong because disabling Bluetooth and the camera reduces data leakage vectors but does not create any logical separation between corporate and personal data; it is a restrictive control that does not address the core requirement of maintaining separate data stores.

983
MCQeasy

An employee receives an email that says, 'This is the CEO. Buy gift cards now and reply with the codes before the meeting starts.' What should the employee do?

A.Reply with the codes because the request appears urgent
B.Verify the request through an approved channel and report the message
C.Forward the email to coworkers so they can watch for similar messages
D.Delete the email and ignore it without telling anyone
AnswerB

Verifying the request through an approved channel, such as a pre-configured phone number, in-person contact, or the official ticketing system, confirms authenticity without relying on any contact information found in the suspect email itself. Reporting the message to the security or incident response team allows analysts to collect header data, block the sender, and issue warnings to other employees who may have received identical lures. This combination of independent verification and official reporting directly mitigates the current threat and protects the organization from a likely impersonation fraud. Acting alone, either verification or reporting, is insufficient; both together form a complete and secure response.

Why this answer

The email exhibits classic social engineering indicators—spoofed authority, urgency, and a request for non-standard financial transactions (gift cards). The employee must verify the request through an approved communication channel (e.g., a phone call to the CEO's known number) and report the message to the security team for incident response. This aligns with security policy for phishing and business email compromise (BEC) prevention, as per NIST SP 800-61 and organizational security awareness training.

Exam trap

The trap here is that candidates may mistake the urgency and authority in the email as legitimate, choosing Option A, but CompTIA tests the principle that any request for sensitive actions (gift cards, wire transfers, credential changes) must be verified through a separate, trusted channel regardless of apparent sender identity.

How to eliminate wrong answers

Option A is wrong because replying with gift card codes without verification directly enables a BEC attack, violating the principle of least trust and bypassing standard financial controls. Option C is wrong because forwarding the email to coworkers could propagate the phishing link or attachment, increasing the attack surface and potentially bypassing email security filters. Option D is wrong because deleting the email without reporting it prevents the security team from analyzing the threat, updating detection rules, and protecting other users from the same attack.

984
MCQeasy

EDR shows encoded PowerShell launched by a word processor and an outbound connection to a rare domain. What is the best immediate containment action?

A.Isolate the endpoint from the network using the EDR console.
B.Uninstall the word processor from every workstation.
C.Wait to see whether more alerts appear before responding.
D.Send a notice to all users reminding them not to open attachments.
AnswerA

Network isolation through EDR quickly limits attacker access and prevents further command-and-control communication. It also preserves the host for investigation while stopping spread to other systems. This is a standard first containment step when behavior strongly suggests active compromise.

Why this answer

Isolating the endpoint from the network using the EDR console is the best immediate containment action because it stops the outbound connection to the rare domain, preventing potential command-and-control (C2) communication or data exfiltration. The encoded PowerShell launched by a word processor strongly suggests a malicious macro or exploit, and isolating the host contains the threat without disrupting the entire network. This aligns with the incident response priority of containment before eradication or recovery.

Exam trap

The trap here is that candidates may choose a broad administrative action (like uninstalling software or sending user notices) instead of the precise, immediate technical containment step that stops the active threat at the network level.

How to eliminate wrong answers

Option B is wrong because uninstalling the word processor from every workstation is a broad, disruptive action that does not address the immediate threat on the affected host and may remove legitimate software needed for business operations. Option C is wrong because waiting for more alerts allows the potential C2 channel to remain active, increasing the risk of lateral movement or data theft. Option D is wrong because sending a user notice is a preventive or awareness measure, not an immediate containment action, and it does not stop the active malicious process or network connection.

985
MCQmedium

Based on the exhibit, which hardening change best prevents a laptop from booting unapproved tools from external media? Exhibit: UEFI Setup - Secure Boot: Disabled - Boot order: USB, External NIC, Internal SSD - Firmware admin password: Not configured - BitLocker status: Enabled Incident note: A technician confirmed the laptop was started from a USB recovery stick that bypassed the normal corporate login workflow.

A.Enable Secure Boot and change the firmware boot order so only the internal SSD is allowed first.
B.Extend the Windows login timeout so users have more time to notice suspicious activity.
C.Turn off BitLocker so recovery tools can boot without errors.
D.Install a host firewall rule to block USB storage devices from the network.
AnswerA

This is the best control because Secure Boot validates that the bootloader is trusted, and restricting the boot order reduces the chance of booting from unapproved removable media. Together, these changes stop many pre-boot attacks and unauthorized recovery tools before the operating system starts. BitLocker helps protect data at rest, but it does not by itself prevent booting alternate media.

Why this answer

Enabling Secure Boot ensures that only signed, trusted firmware and bootloaders can execute, preventing unauthorized tools like USB recovery sticks from loading. Changing the boot order to prioritize the internal SSD over USB media stops the system from even attempting to boot from external devices, directly addressing the incident where the laptop bypassed corporate login via a USB stick.

Exam trap

CompTIA often tests the misconception that host firewall rules can control local device access, but firewalls operate at the network layer and cannot block USB storage devices, which are managed by hardware or OS-level policies.

How to eliminate wrong answers

Option B is wrong because extending the Windows login timeout does not prevent booting from external media; it only affects the login screen after the OS has already loaded, leaving the boot process vulnerable. Option C is wrong because turning off BitLocker would actually make it easier for unauthorized tools to boot and access data, as BitLocker protects against offline attacks and does not cause boot errors for legitimate recovery tools when properly configured. Option D is wrong because a host firewall rule blocks network traffic, not local USB storage devices; USB storage is controlled by hardware policies or Group Policy, not firewall rules.

986
MCQmedium

A manufacturer wants to give partner-company users access to a procurement portal. The partner wants to authenticate its own users, and the manufacturer does not want to create separate local passwords for them. What is the best solution?

A.Create shared portal accounts and distribute credentials to the partner's staff.
B.Federate access with the partner's identity provider and map claims or attributes to portal roles.
C.Issue one VPN account for the partner organization and let them share it internally.
D.Require each partner user to create a password directly in the procurement portal.
AnswerB

Federation lets the partner authenticate its own users while the manufacturer trusts identity assertions from the partner identity provider. Claims or attributes can then be mapped to portal roles so access stays controlled without local password management. This is a strong fit for business-to-business access because it preserves administrative separation while still supporting centralized authorization decisions in the portal.

Why this answer

Federation with the partner's identity provider (IdP) using standards like SAML 2.0 or OIDC allows the partner to authenticate their own users while the manufacturer's portal trusts those assertions. Claims or attributes from the IdP (e.g., group membership) are mapped to portal roles, eliminating the need for local passwords and enabling single sign-on (SSO). This is the best solution because it maintains security boundaries and offloads authentication management to the partner.

Exam trap

The trap here is that candidates confuse federation with simple shared accounts or VPN-based access, failing to recognize that federation is the only option that delegates authentication to the partner while preserving individual accountability and eliminating local password management.

How to eliminate wrong answers

Option A is wrong because shared portal accounts violate the principle of least privilege and non-repudiation—multiple users sharing one set of credentials makes auditing impossible and increases the risk of credential leakage. Option C is wrong because a single VPN account shared internally provides no individual accountability, bypasses proper access controls, and does not solve the authentication delegation requirement; it also introduces a VPN dependency that is unnecessary for a web-based procurement portal.

987
MCQmedium

Based on the exhibit, which security issue should the analyst report first?

A.Outdated component, because the scan did not list software version details.
B.Exposed service, because VNC and the web admin interface are reachable from untrusted networks.
C.Weak permissions, because SSH requires password login only.
D.Default credentials, because the server is in the DMZ.
AnswerB

The most important issue is the exposed service because remote management interfaces are reachable from any source network, and VNC authentication is disabled. That combination creates a high-risk attack surface, especially for a server in the DMZ that stores sensitive customer information.

Why this answer

The scan reveals that VNC (port 5900) and a web admin interface (port 443 or 8080) are exposed to untrusted networks, such as the internet. This violates the principle of least exposure, as these services are known attack vectors for remote code execution and credential theft. The analyst should prioritize this issue because an exposed service directly increases the attack surface and risk of unauthorized access, whereas other findings may be less immediately critical.

Exam trap

The trap here is that candidates often focus on missing version details (Option A) or default credentials (Option D) as the most critical finding, but CompTIA emphasizes that exposed services on untrusted networks pose the highest immediate risk because they are directly exploitable without requiring prior access.

How to eliminate wrong answers

Option A is wrong because the absence of software version details in the scan does not necessarily indicate an outdated component; it may simply mean the scanner could not fingerprint the version due to banner hiding or firewall restrictions. Option C is wrong because SSH requiring password login only is not inherently a weak permission; weak permissions refer to file or directory access controls, not authentication methods, and password-based SSH is still common in many environments. Option D is wrong because default credentials are not indicated by the server being in the DMZ; the scan does not show any evidence of default username/password usage, and the DMZ placement alone does not confirm this vulnerability.

988
MCQhard

Based on the exhibit, which security principle does the organization appear to be using most clearly?

A.Zero trust, because all access is denied until a user proves identity again.
B.Defense in depth, because several different controls stop or limit the attack at different stages.
C.Least privilege, because the attachment was blocked from having administrator rights.
D.Need-to-know, because only the security team should be aware of the incident.
AnswerB

Defense in depth is demonstrated by multiple layers: email filtering, application control, EDR containment, MFA, and backup recovery. The attack is not stopped by one control alone. Instead, each layer provides a separate barrier or recovery path, reducing the chance that a single failure becomes a full compromise.

Why this answer

The exhibit shows multiple security controls—an email filter blocking the attachment, a web filter blocking the download link, and an endpoint detection and response (EDR) tool blocking execution—each acting at a different stage of the attack chain. This layered approach, where no single control is relied upon to stop the threat, is the hallmark of defense in depth. The correct answer is B because the scenario clearly demonstrates overlapping controls that provide redundancy and mitigate risk at various points.

Exam trap

The trap here is that candidates often confuse defense in depth with zero trust because both involve multiple controls, but zero trust specifically requires explicit verification for every access request, whereas defense in depth focuses on layered, independent safeguards without necessarily re-verifying identity at each layer.

How to eliminate wrong answers

Option A is wrong because zero trust requires continuous verification of identity and device posture for every access request, not just a one-time re-authentication; the exhibit shows no evidence of such per-request validation. Option C is wrong because least privilege restricts user permissions to the minimum necessary for their role, but the attachment was blocked by an email filter before any user could execute it, not by limiting the attachment's administrator rights. Option D is wrong because need-to-know restricts information access to only those who require it for their duties, but the exhibit focuses on technical controls blocking the attack, not on who is informed about the incident.

989
MCQeasy

Before contracting with a cloud-based payroll provider, the security team requests a security questionnaire, proof of controls, and an independent audit report. What activity is this?

A.Business continuity testing, because the team is checking recovery procedures.
B.Third-party due diligence, because the team is evaluating vendor risk before onboarding.
C.Security awareness training, because the vendor is being taught safe behavior.
D.Data classification, because the team is labeling the payroll data type.
AnswerB

Third-party due diligence is the process of reviewing a vendor’s security posture, controls, and supporting evidence before trusting them with business data or services. The questionnaire and audit report are classic inputs for that review.

Why this answer

The security team's request for a security questionnaire, proof of controls, and an independent audit report before contracting with a cloud-based payroll provider is a classic example of third-party due diligence. This process evaluates the vendor's security posture, compliance, and risk level before onboarding, ensuring that sensitive payroll data is protected. It is a proactive risk management activity, not a reactive test or training exercise.

Exam trap

The trap here is that candidates confuse third-party due diligence with business continuity testing, because both involve reviewing documentation, but due diligence is pre-contractual risk evaluation, not post-incident recovery verification.

How to eliminate wrong answers

Option A is wrong because business continuity testing focuses on verifying recovery procedures and system resilience, not on evaluating a vendor's security controls before contracting. Option C is wrong because security awareness training is an internal program to educate employees on safe behavior, not a vendor assessment activity. Option D is wrong because data classification involves labeling data by sensitivity level, not requesting audit reports or control evidence from a third party.

990
Multi-Selecthard

After employees transfer departments, they keep access to old SaaS applications because app-specific accounts are removed only after a manual cleanup ticket. Which two changes best close the lifecycle gap? Select two.

Select 2 answers
A.Use automated provisioning and deprovisioning tied to HR events through SCIM or an equivalent interface.
B.Keep app accounts manually managed so each app owner can decide independently.
C.Map entitlements to IdP groups or roles based on job function.
D.Share a generic help desk password for quick access restoration.
E.Require password changes every 30 days for all users.
AnswersA, C

Automated provisioning systems use SCIM, an IETF-standardized RESTful API, to exchange identity lifecycle events between the IdP and service providers. When HR records a role change or termination, a workflow engine dynamically updates or disables accounts across all connected applications, eliminating the delay of human intervention. This enforces least privilege and reduces the risk that a lateral mover retains stale entitlements, because access is revoked in near-real-time to match the employee's current business need.

Why this answer

Automating provisioning and deprovisioning via SCIM (System for Cross-domain Identity Management) ties account lifecycle directly to HR events (e.g., termination, transfer). This eliminates the manual cleanup ticket gap by instantly removing or modifying access when an employee changes departments, ensuring no stale SaaS accounts remain.

Exam trap

The trap here is that candidates confuse password policies (Option E) with account lifecycle management, failing to recognize that frequent password changes do not remove orphaned accounts or close the provisioning gap.

991
MCQmedium

The web team is placing a public customer portal behind a control that can inspect HTTP requests, block malicious payloads such as SQL injection and cross-site scripting, and still allow legitimate application traffic without rewriting the app. Which control should they deploy?

A.An IDS placed on the same network segment as the web server.
B.A DLP appliance between users and the portal.
C.A WAF in front of the application.
D.A NAC solution on the switch ports feeding the portal.
AnswerC

A web application firewall is built to inspect HTTP and HTTPS traffic at the application layer and block common web attacks such as SQL injection and XSS. It can protect a public portal without requiring code changes, making it a practical compensating control while the application team improves secure coding. This is the best fit when the goal is to stop malicious web payloads before they reach the app.

Why this answer

A Web Application Firewall (WAF) is specifically designed to inspect HTTP/HTTPS traffic at the application layer (Layer 7), filtering out malicious payloads like SQL injection and cross-site scripting (XSS) while allowing legitimate requests to pass through. Unlike an IDS, a WAF operates inline and can actively block threats without requiring modifications to the application code, making it the ideal choice for protecting a public-facing web portal.

Exam trap

The trap here is that candidates often confuse an IDS (which only detects) with a WAF (which actively blocks), or they mistakenly think a DLP appliance can filter web application attacks, when in fact DLP focuses on data in motion or at rest, not on application-layer payload inspection.

How to eliminate wrong answers

Option A is wrong because an IDS (Intrusion Detection System) is a passive monitoring device that only alerts on suspicious traffic; it cannot block malicious payloads inline or prevent attacks without additional manual intervention. Option B is wrong because a DLP (Data Loss Prevention) appliance is designed to prevent unauthorized exfiltration of sensitive data, not to inspect and filter HTTP requests for SQL injection or XSS payloads. Option D is wrong because a NAC (Network Access Control) solution controls device access to the network at the switch port level based on compliance policies, but it does not inspect application-layer traffic or block web-based attacks.

992
MCQmedium

Based on the exhibit, what should the team do next after the account has been contained?

A.Close the incident because the password reset removed the attacker from the environment.
B.Remove mailbox persistence, revoke all tokens and app consent, then monitor for reentry.
C.Reimage the user's laptop before reviewing mailbox settings.
D.Restore the mailbox from backup to remove the forwarding rule and keep the user productive.
AnswerB

The exhibit shows post-compromise persistence through a forwarding rule and unauthorized OAuth consent. After containment, the team must eradicate those artifacts, revoke any remaining tokens or sessions, and verify that no attacker-controlled application retains access. That sequence moves the response from containment into eradication and prepares the account for safe recovery and monitoring.

Why this answer

After containing a compromised account (e.g., disabling it or resetting its password), the attacker may still have established persistence mechanisms such as mailbox forwarding rules, OAuth app consent grants, or session tokens that survive a password reset. Removing these artifacts and revoking all tokens and app consents ensures the attacker cannot regain access via delegated permissions or persistent mailbox rules. Monitoring for reentry is critical to detect any residual access or new compromise attempts.

Exam trap

The trap here is that candidates assume a password reset fully evicts an attacker, overlooking that OAuth tokens and mailbox rules provide persistent access independent of the account password.

How to eliminate wrong answers

Option A is wrong because a password reset alone does not remove attacker‑created mailbox forwarding rules, OAuth app grants, or session tokens; the attacker could still access the mailbox via delegated permissions or persistent rules. Option C is wrong because reimaging the user's laptop addresses local device compromise but does not remediate cloud‑based persistence like mailbox forwarding rules or app consents that exist in the tenant. Option D is wrong because restoring the mailbox from backup removes the forwarding rule but does not revoke OAuth tokens or app consents, and it may reintroduce the same rule if the backup contains the malicious configuration; it also fails to address other persistence vectors.

993
MCQmedium

A financial institution updates its access control policy to require that two different system administrators must approve and execute any changes to the core transaction processing database. Which security principle is this practice primarily designed to enforce?

A.Defense in depth
B.Separation of duties
C.Least privilege
D.Need to know
AnswerB

Separation of duties is a core internal control that requires more than one person to complete a critical task or transaction. By splitting the approval and execution of access control changes between two distinct administrators, the policy ensures no single individual has the authority to unilaterally modify security settings, which significantly reduces the risk of fraud, sabotage, or unauthorized changes. This is the correct answer because the scenario explicitly describes dividing the change into approval and implementation steps, which is the hallmark of separation of duties.

Why this answer

Requiring two different system administrators to approve and execute changes to the core transaction processing database enforces separation of duties. This principle ensures that no single individual has the authority to perform both the approval and execution steps, reducing the risk of fraud, error, or unauthorized modifications. In a financial institution, this is critical for maintaining the integrity of transaction data and complying with regulatory standards like SOX or PCI DSS.

Exam trap

The trap here is that candidates confuse separation of duties with least privilege, but least privilege focuses on limiting permissions per role, while separation of duties divides a critical process across multiple roles to prevent conflicts of interest.

Why the other options are wrong

A

Defense in depth is a layered security approach using multiple controls, but the question specifically describes a dual-approval process for changes, which directly enforces separation of duties, not defense in depth.

C

The practice requires two administrators to approve and execute changes, which enforces separation of duties, not least privilege. Least privilege restricts permissions to the minimum necessary, but does not inherently require dual approval.

D

The need-to-know principle restricts access to information based on job necessity, but the question describes a process requiring two administrators to approve changes, which is about dividing responsibilities, not limiting information access.

When would these options actually be correct?

A

A question asks: 'An organization implements firewalls, intrusion detection systems, and antivirus software to protect its network. Which security principle is this an example of?' Here, defense in depth would be correct because multiple layers of defense are used.

C

A question describing a policy where a database administrator is granted only the specific permissions needed to perform their job functions, and no additional access, would make 'Least privilege' the correct answer.

D

A question asks: 'A security analyst is granted access to a database only after demonstrating a legitimate business requirement for specific records. Which principle is being enforced?' Here, need-to-know would be correct because access is limited to information necessary for the job.

Why candidates pick the wrong answer

A

Candidates may confuse the concept of multiple controls (defense in depth) with the dual-approval process, thinking that requiring two administrators is an additional layer of security, but it is actually a separation of duties mechanism.

C

Candidates may confuse the concept of limiting access (least privilege) with the procedural control of requiring multiple approvals, as both aim to reduce risk.

D

Candidates may confuse need-to-know with separation of duties because both involve restricting actions, but need-to-know focuses on information access, not task approval workflows.

994
MCQmedium

A SOC analyst reviews an EDR alert on a Windows workstation. PowerShell was launched by a scheduled task, downloaded an encoded command from an external server, and then spawned rundll32.exe. No suspicious executable was written to disk. Which type of threat best fits this activity?

A.Trojan
B.Fileless attack
C.Rootkit
D.Worm
AnswerB

This is the correct classification. Fileless attacks leverage trusted system tools (e.g., PowerShell, WMI, or .NET) to execute malicious code directly in memory, avoiding writing an executable to disk. The alert's focus on in-memory execution and the absence of a dropped file are hallmarks of this technique. These attacks are particularly dangerous because they leave few forensic traces, evade signature-based detection, and often exploit legitimate administrative capabilities.

Why this answer

The attack is fileless because it executes entirely in memory without writing a malicious executable to disk. PowerShell downloads an encoded command from an external server and spawns rundll32.exe to run code via DLL execution, leveraging living-off-the-land binaries (LOLBins) to evade traditional antivirus and disk-based detection.

Exam trap

The trap here is that candidates see 'downloaded an encoded command' and assume a file was written, but the key distinction is that no executable file was written to disk, making it a fileless attack rather than a Trojan or rootkit.

How to eliminate wrong answers

Option A is wrong because a Trojan is a malicious program disguised as legitimate software that typically writes a file to disk and requires user installation, whereas this attack uses a scheduled task to launch PowerShell and never writes a suspicious executable. Option C is wrong because a rootkit is designed to hide the presence of malware or maintain privileged access by modifying the operating system kernel or boot process, which is not indicated by the PowerShell-to-rundll32 chain and lack of persistence mechanisms described.

995
MCQeasy

A web form stores a user's comment and later displays it to other users. A tester submits <script>alert(1)</script> and the script runs in the browser. What vulnerability is this?

A.SQL injection
B.Cross-site request forgery
C.Cross-site scripting
D.Command injection
AnswerC

The application reflects untrusted input into a page without proper encoding, allowing script execution.

Why this answer

The tester's input <script>alert(1)</script> is executed in the browser, which is the classic symptom of a stored (persistent) cross-site scripting (XSS) vulnerability. The web form fails to sanitize or encode user-supplied data before storing it and later rendering it in other users' browsers, allowing arbitrary JavaScript to run in the security context of the application's origin.

Exam trap

The trap here is that candidates may confuse XSS with SQL injection because both involve injecting malicious input, but XSS targets the browser's execution context while SQL injection targets the database query layer.

How to eliminate wrong answers

Option A is wrong because SQL injection involves injecting SQL commands into database queries (e.g., ' OR 1=1 --), not client-side script execution; the input here does not alter a database query. Option B is wrong because cross-site request forgery (CSRF) tricks a victim into performing an unintended action on an authenticated site, but the tester's input directly executes script in the browser without requiring a forged request. Option D is wrong because command injection targets server-side operating system commands (e.g., ; ls -la), not client-side JavaScript execution in the browser.

996
MCQmedium

A desktop engineering team asks for the document that specifies the exact minimum encryption setting, screen-lock timer, and password length for company laptops. Which type of document should they follow?

A.Policy, because it states the organization's general intent and high-level direction.
B.Standard, because it defines mandatory uniform requirements for a specific control baseline.
C.Procedure, because it gives the organization-wide security purpose statement.
D.Guideline, because it provides optional suggestions that every laptop must obey.
AnswerB

A standard is the correct document when the organization needs a consistent, mandatory technical baseline such as encryption strength, lock timing, or password length. Standards translate policy into measurable requirements and are suitable for system configuration because they reduce ambiguity and support enforcement across similar assets.

Why this answer

A standard defines mandatory, uniform technical requirements for a specific control baseline, such as exact encryption settings (e.g., AES-256), screen-lock timer (e.g., 15 minutes), and password length (e.g., 14 characters). Unlike a policy, which states high-level intent, a standard provides the precise, enforceable configuration that the desktop engineering team must implement on company laptops.

Exam trap

The trap here is that candidates confuse 'policy' (high-level intent) with 'standard' (specific mandatory baseline), leading them to choose A when the question explicitly asks for the document that specifies exact minimum encryption, timer, and password length values.

How to eliminate wrong answers

Option A is wrong because a policy states the organization's general intent and high-level direction (e.g., 'all laptops must be secured'), but does not specify exact technical values like encryption algorithm, timer duration, or password length. Option C is wrong because a procedure describes step-by-step instructions for performing a task (e.g., how to configure BitLocker), not the mandatory baseline requirements themselves.

997
MCQhard

Based on the exhibit, what additional control is the best fit? Current controls on the finance share: - SMB signing enabled - Weekly access review - Nightly backups to immutable storage - Antivirus scans at 02:00 Incident: a valid VPN account was used to access 40,000 files in 8 minutes and copy them to a local drive. Goal: detect unauthorized bulk access quickly before exfiltration completes.

A.Add file access auditing with alert thresholds forwarded to the SIEM.
B.Increase the backup schedule from nightly to hourly.
C.Rename the share to a less obvious name.
D.Disable SMB signing so the file transfer runs faster.
AnswerA

File access auditing enables granular tracking of who accessed which files and when. When combined with alert thresholds (e.g., a user reading hundreds of files in minutes), the SIEM can generate real-time alerts for potential bulk data exfiltration. As a detective control, it directly addresses the missing visibility into abnormal access patterns and supports timely incident response.

Why this answer

File access auditing with alert thresholds forwarded to the SIEM directly addresses the goal of detecting unauthorized bulk access quickly. By monitoring for abnormal file access patterns—such as 40,000 files in 8 minutes—the SIEM can trigger an alert before exfiltration completes, enabling rapid response. This control complements the existing weekly access review by providing real-time detection.

Exam trap

The trap here is that candidates may confuse backup frequency (a recovery control) with detection controls, or think that obscuring the share name provides meaningful security, when the question specifically asks for a control to detect unauthorized bulk access quickly.

How to eliminate wrong answers

Option B is wrong because increasing backup frequency from nightly to hourly does not detect or prevent unauthorized bulk access; backups are a recovery control, not a detection control. Option C is wrong because renaming the share to a less obvious name is a form of security through obscurity that does not detect or alert on anomalous access patterns. Option D is wrong because disabling SMB signing would actually reduce security by removing integrity verification of SMB traffic, and it does not provide any detection capability for bulk file access.

998
Multi-Selecthard

A user receives an SMS from 'IT Service Desk' saying their MFA enrollment expires today and includes a shortened link. Five minutes later, the user gets a phone call from the same number asking them to read back the code shown in the authenticator app so the ticket can be closed. Which two attack channels are used in this campaign? Select two.

Select 2 answers
A.Email phishing is used because the attacker is requesting a login action.
B.Smishing is used because the first lure arrives by text message.
C.Vishing is used because the follow-up request occurs by phone call.
D.Baiting is used because the attacker offers a free reward or device.
E.Tailgating is used because the attacker follows someone into a restricted area.
AnswersB, C

Smishing is phishing delivered through SMS or another text-based mobile messaging channel. The fake IT Service Desk text with a shortened link is a classic example because it attempts to get the user to click a link and interact outside the normal support process.

Why this answer

The initial attack vector is an SMS message containing a shortened link, which is the definition of smishing (SMS phishing). The attacker uses this to create urgency and lure the victim into engaging with the MFA enrollment scam.

Exam trap

The trap here is that candidates may focus on the phone call as the only attack channel and overlook the initial SMS, or they may confuse smishing with vishing, not recognizing that both channels are used sequentially in a single campaign.

999
MCQmedium

A security analyst receives an alert that a user clicked a link in a phishing email and entered their corporate credentials on a fake login page. Which of the following should the analyst do FIRST to minimize further damage?

A.Run a full antivirus scan on the user's workstation
B.Reset the user's password and force re-authentication
C.Disable the user's account and block the compromised system from the network
D.Contact law enforcement and report the phishing site
AnswerC

Disabling the user's account terminates the attacker's authenticated sessions and invalidates stolen credentials, while blocking the compromised system at the network layer severs any existing command-and-control, RDP, or file-transfer connections. This containment step is the immediate priority because it prevents lateral movement and data exfiltration without destroying volatile evidence on the host. In contrast to reactive scanning or password resets, isolating first gives the incident response team a clean boundary to perform forensic acquisition and threat hunting.

Why this answer

Immediately disabling the user's account and blocking the compromised system from the network stops the attacker from using the stolen credentials to authenticate to corporate resources, such as email, VPN, or file shares. This containment step is the highest priority in incident response to prevent lateral movement and further compromise, as the attacker already has valid credentials and could be actively using them.

Exam trap

The trap here is that candidates often choose to reset the password first (Option B) because it seems like a direct fix, but they fail to recognize that the compromised system itself may be under attacker control, and without network isolation, the attacker could still pivot or use other stolen credentials.

Why the other options are wrong

A

Running a full antivirus scan is a reactive step that does not immediately prevent further unauthorized access or credential misuse. The priority is to contain the breach by disabling the account and isolating the system.

B

Resetting the password and forcing re-authentication does not immediately isolate the compromised system or prevent the attacker from using the stolen credentials to access other resources before the password change takes effect.

D

Contacting law enforcement is not the first priority; immediate containment actions like disabling the account and blocking the system are needed to prevent further credential misuse.

When would these options actually be correct?

A

This would be correct if the question stated that the user's credentials were already reset and the account was secured, and the next step is to ensure the workstation is free from malware that could exfiltrate data or provide persistent access.

B

This would be correct if the question stated that the user's account was not yet compromised (e.g., the user reported the phishing email before entering credentials) and the goal is to proactively protect the account from potential misuse.

D

This option would be correct if the question asked: 'After containing the incident and preserving evidence, which of the following should the analyst do to assist in the investigation and prosecution of the attacker?'

Why candidates pick the wrong answer

A

Candidates may think that malware is the primary threat from phishing and that scanning will remove any backdoors, overlooking the immediate need to stop credential abuse.

B

Candidates often think that changing the password is the fastest way to revoke access, but they overlook the need to first disable the account and block the system to stop ongoing lateral movement or data exfiltration.

D

Candidates may think reporting the phishing site to law enforcement is a critical early step, but they overlook the need for immediate containment to stop ongoing damage.

1000
MCQeasy

An employee receives an email from someone claiming to be from IT. The message says the employee must read back a one-time verification code so their mailbox can be 'repaired.' What social engineering technique is being used?

A.Tailgating, because the attacker is trying to enter a secure area physically.
B.Pretexting, because the attacker is using a fake identity and story to gain trust.
C.DDoS, because the message is designed to overwhelm the mailbox server.
D.Shoulder surfing, because the attacker is watching the screen from nearby.
AnswerB

Pretexting is a social engineering technique where the attacker fabricates a scenario and adopts a trusted role—here, an IT support agent—to elicit sensitive information. The email invents a believable reason, such as account verification or troubleshooting, to lower the victim's suspicion and prompt disclosure of the one-time code. This relies on establishing false trust and exploiting the victim's willingness to comply with an authority figure, making it distinct from technical attacks.

Why this answer

The attacker is using a fabricated identity (IT support) and a false scenario (mailbox repair requiring a verification code) to manipulate the employee into divulging sensitive information. This is the classic definition of pretexting, where the attacker creates a believable pretext to lower the victim's defenses and extract data or access.

Exam trap

The trap here is that candidates confuse pretexting with phishing, but pretexting specifically relies on a fabricated scenario or identity (the 'pretext') rather than a generic lure like a malicious link or attachment.

How to eliminate wrong answers

Option A is wrong because tailgating is a physical security attack where an unauthorized person follows an authorized individual into a restricted area, not a social engineering technique involving email or phone. Option C is wrong because a DDoS (Distributed Denial of Service) attack overwhelms a server with traffic to disrupt service, not to trick a user into revealing a code. Option D is wrong because shoulder surfing involves directly observing someone's screen or keyboard from close proximity to steal information, not using a remote email message.

1001
Matchingeasy

Match each principle to the workplace scenario.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

A user must be verified each time they request access, even from inside the network.

The organization uses layered controls such as MFA, filtering, and endpoint protection.

A contractor can view only the project files required for assigned tasks.

A support technician receives only the minimum permissions needed to close tickets.

A website stays online after one server fails because another takes over.

Why these pairings

Least privilege restricts access to necessary functions; separation of duties prevents fraud; defense in depth layers security; need to know limits data access; accountability ties actions to individuals; fail safe maintains security during failures.

1002
MCQhard

Based on the exhibit, what is the best change to improve accountability without removing emergency access?

A.Keep the shared account and add more logging of the shared password.
B.Require named accounts with role-based elevation through a privileged access workflow.
C.Remove all command logging to protect administrator privacy.
D.Use a single shared account with a longer password and monthly rotation.
AnswerB

This is the best answer because the issue is accountability. Shared accounts prevent the organization from knowing which person performed the actions in the log. Named accounts plus privileged elevation preserve break-glass access while ensuring each command is tied to an individual identity. That improves accounting and auditability without removing the operational ability to maintain the system.

Why this answer

Implementing named accounts with role-based elevation through a privileged access workflow (PAW) ensures each administrator has a unique identity for auditing, while still allowing temporary privilege escalation for emergency tasks. This directly improves accountability by tying actions to specific users, unlike shared accounts which obscure individual responsibility. The workflow maintains emergency access by granting time-limited elevated permissions through an approval process, avoiding permanent standing privileges.

Exam trap

The trap here is that candidates may think improving logging (Option A) or password rotation (Option D) is sufficient for accountability, but CompTIA emphasizes that shared accounts inherently lack individual attribution, regardless of how much logging or rotation is applied.

How to eliminate wrong answers

Option A is wrong because simply adding more logging to a shared account does not solve the core accountability problem—multiple users still share the same credentials, making it impossible to attribute actions to a specific individual, and logging a shared password is irrelevant to user identification. Option C is wrong because removing command logging destroys the audit trail needed for accountability and incident investigation, violating the principle of non-repudiation and security best practices. Option D is wrong because using a single shared account with a longer password and monthly rotation still lacks individual accountability; password changes do not tie actions to specific users, and emergency access remains unmanaged without a privileged access workflow.

1003
MCQmedium

A Linux web server was compromised through an outdated package. The team isolated the host, captured evidence, removed a malicious cron job, patched the vulnerable package, and confirmed no persistence remains. Which incident response phase are they primarily in now?

A.Identification, because the team is still confirming that the event happened.
B.Containment, because the host was isolated from the network.
C.Eradication, because malicious artifacts and the underlying weakness are being removed.
D.Lessons learned, because the server has already been secured.
AnswerC

Eradication is the incident response phase dedicated to removing the adversary's presence entirely — deleting malware, eliminating persistence mechanisms, and remediating the root cause, such as the outdated package that was exploited. The scenario's description of removing malicious artifacts and the underlying weakness directly matches this phase. Unlike containment, which merely limits damage, eradication seeks to ensure the attacker cannot easily return.

Why this answer

The team has already identified the compromise, isolated the host, and removed the malicious cron job. Patching the vulnerable package addresses the root cause, which is the core of the Eradication phase. Confirming no persistence remains verifies that the eradication was successful, making this the current phase.

Exam trap

The trap here is that candidates confuse the isolation step (Containment) with the overall phase, but the question emphasizes the removal of the malicious cron job and patching, which are definitive Eradication actions.

How to eliminate wrong answers

Option A is wrong because Identification is the initial phase where the incident is discovered and confirmed; here, the team has already moved past that to active remediation. Option B is wrong because Containment focuses on limiting damage (e.g., network isolation), which was already performed; the team is now addressing the root cause and removing artifacts. Option D is wrong because Lessons Learned occurs after recovery is complete and involves post-incident review and documentation, not active patching and artifact removal.

1004
MCQeasy

After a phishing incident, the security team wants to preserve evidence for later review. Which action is most appropriate?

A.Have the user delete the phishing email to avoid further exposure
B.Capture and save the email headers and message content
C.Forward the email to every employee as a warning
D.Change the user's office seat assignment immediately
AnswerB

Preserving the raw email as an .eml or .msg file, or exporting the full message with headers from the web client, gives investigators a complete, immutable artifact for analysis. The 'Received' header chains can be traced back to the originating IP and MTA path, while SPF, DKIM, and DMARC authentication results in the headers reveal whether the message was spoofed or sent from a compromised legitimate account. The message content is also vital for extracting malicious links, attachments, and other Indicators of Compromise (IOCs) and for providing the full payload context needed for detection rule creation and user awareness training.

Why this answer

Preserving the email headers and message content is essential for forensic analysis. Email headers contain routing information, including the originating IP address, authentication results (SPF, DKIM, DMARC), and timestamps, which are critical for tracing the source of the phishing attack and understanding the attack vector. Deleting or forwarding the email would destroy this evidence, compromising the investigation.

Exam trap

The trap here is that candidates may think deleting or forwarding the email is a quick fix to prevent further harm, but the exam emphasizes that evidence preservation (via capture of headers and content) is the first priority in incident response, not containment or notification.

How to eliminate wrong answers

Option A is wrong because deleting the phishing email destroys the evidence needed for forensic analysis, including headers and metadata that could identify the attacker's infrastructure. Option C is wrong because forwarding the email to all employees increases the risk of further compromise, may violate data protection policies, and alters the original message headers, potentially invalidating the evidence. Option D is wrong because changing the user's office seat assignment has no relevance to preserving digital evidence; it is a physical security measure unrelated to incident response or evidence handling.

1005
MCQmedium

Based on the exhibit, which access design change best reduces fraud risk without stopping the payroll process? Exhibit: Payroll application roles: - HR-Editor: can update employee records - Payroll-Approver: can release payment batches - Audit-Reader: can view reports only Current assignment: User Lisa has both HR-Editor and Payroll-Approver because she "handles payroll end to end." Management wants to reduce the chance of one person creating and approving a fraudulent payment.

A.Keep both roles assigned but require a manager to review the batch after payment completes.
B.Split duties so record updates and payment approval require separate roles or separate accounts.
C.Remove the audit role and let payroll staff self-review their own work to save time.
D.Use a single shared payroll account so the workflow never pauses for approvals.
AnswerB

This is the best design because it enforces separation of duties, which directly reduces fraud risk. The same person should not be able to create a payment and approve it without independent review. Separate roles or accounts preserve workflow continuity while making collusion or abuse harder, and they provide a cleaner audit trail for accountability.

Why this answer

It enforces separation of duties (SoD) by ensuring that no single user can both create and approve a payment. Splitting the HR-Editor and Payroll-Approver roles into separate accounts or requiring separate users for record updates and payment approval directly mitigates the fraud risk of a single insider creating a fake employee record and then approving a fraudulent payment batch. This aligns with the principle of least privilege and the NIST SP 800-53 AC-5 control for separation of duties, without halting the payroll workflow.

Exam trap

The trap here is that candidates may choose a detective control (like post-payment review) thinking it reduces risk, but the question specifically asks for a change that 'best reduces fraud risk' without stopping the process, and only a preventive control like separation of duties directly addresses the root cause of the conflict of interest.

How to eliminate wrong answers

Option A is wrong because requiring a manager to review the batch after payment completes is a detective control, not a preventive one; fraud could already occur before the review, and the review may be missed or bypassed. Option C is wrong because removing the audit role and letting payroll staff self-review eliminates independent oversight, increasing fraud risk rather than reducing it. Option D is wrong because using a single shared payroll account removes all individual accountability and audit trails, making it impossible to attribute actions to a specific user and actually increasing fraud risk.

1006
MCQmedium

A security architect is designing a solution to process highly sensitive financial transactions in a shared cloud environment. The architect needs to ensure that the processor and memory used to handle transaction data are isolated from the host operating system and other virtual machines, even if the hypervisor is compromised. Which technology is specifically designed to provide this level of isolation for code and data during runtime?

A.Trusted Platform Module (TPM)
B.Hardware Security Module (HSM)
C.Secure enclave (e.g., Intel SGX)
D.UEFI Secure Boot
AnswerC

A secure enclave, such as Intel Software Guard Extensions (SGX), creates hardware-enforced encrypted regions of memory that protect code and data from access by the host OS, hypervisor, or other processes, even if those lower layers are compromised.

Why this answer

Secure enclave technology, such as Intel SGX, provides hardware-enforced isolation by creating trusted execution environments (TEEs) within the CPU. Code and data inside an enclave are encrypted in memory and decrypted only within the processor, ensuring that even a compromised hypervisor or host OS cannot access the transaction data during runtime. This meets the requirement for processor and memory isolation in a shared cloud environment.

Exam trap

The trap here is that candidates often confuse a TPM or HSM with runtime memory isolation, but those technologies focus on storage and cryptographic operations, not on protecting code and data during active execution in a compromised hypervisor environment.

Why the other options are wrong

A

TPM provides hardware-based key storage and attestation but does not isolate runtime code and memory from the host OS or hypervisor. It cannot protect data during processing in a shared cloud environment.

B

An HSM provides hardware-based protection for cryptographic keys and operations, but it does not isolate the processor and memory used to run code and data during runtime from the host OS or hypervisor. It is a peripheral device, not a runtime execution environment.

D

UEFI Secure Boot ensures that only signed firmware and bootloaders execute during system startup, but it does not provide runtime isolation for code and data in memory or CPU. It cannot protect against a compromised hypervisor or isolate transaction processing from the host OS.

When would these options actually be correct?

A

A question asking for a hardware root of trust to verify platform integrity at boot time, or to securely store encryption keys and perform platform attestation, would have TPM as the correct answer.

B

A question asking for a dedicated hardware device to securely store cryptographic keys and perform cryptographic operations (e.g., signing, encryption) for a payment processing system, especially when compliance with standards like FIPS 140-2 is required.

D

A question asks: 'Which technology prevents unauthorized operating systems or bootkits from loading during the boot process on a secure system?' In that context, UEFI Secure Boot is the correct answer because it verifies digital signatures of boot components.

Why candidates pick the wrong answer

A

Candidates may confuse TPM's hardware security capabilities with runtime isolation, assuming that any hardware security module can protect data during processing, not just at rest or in transit.

B

Candidates may confuse HSM's hardware security with runtime isolation, assuming that any 'hardware security' module protects code and data execution, not just key storage and crypto operations.

D

Candidates may confuse boot-time integrity with runtime isolation, or think that Secure Boot extends to protect applications during execution, not just the boot chain.

1007
MCQmedium

HR stores scanned government IDs collected during onboarding. The retention policy says the files may be kept for 90 days after employment verification, then destroyed. What should security require?

A.Keep the files indefinitely in case a future audit asks for them
B.Move the files to a shared folder so more HR staff can access them
C.Store the files in an encrypted repository and securely dispose of them when retention expires
D.Print the scanned IDs and place them in a locked cabinet instead of keeping digital copies
AnswerC

This is the best answer because it matches the retention schedule and protects sensitive personal data. Encryption reduces exposure while the files are needed, and secure disposal after the retention period supports privacy, legal compliance, and data minimization. The process should also be auditable so the organization can prove it is following its handling requirements.

Why this answer

It aligns with the principle of data minimization and the retention policy: storing scanned government IDs in an encrypted repository ensures confidentiality and integrity, while secure disposal after the 90-day retention period meets compliance requirements (e.g., GDPR, HIPAA) and reduces risk of data breaches. Security must enforce both protection during storage and timely destruction to prevent unauthorized access or legal liability.

Exam trap

The trap here is that candidates may choose indefinite retention (Option A) thinking it helps with audits, but security requires compliance with the stated retention policy, not hoarding data.

How to eliminate wrong answers

Option A is wrong because keeping files indefinitely violates the retention policy and increases exposure to data breaches, legal non-compliance, and storage costs without a security justification. Option B is wrong because moving files to a shared folder broadens access without need, increasing the attack surface and risk of unauthorized disclosure, while ignoring encryption and retention controls. Option D is wrong because printing scanned IDs creates physical copies that are harder to track, secure, and destroy reliably, and it introduces new risks like loss, theft, or improper disposal, while digital encryption and secure deletion are more auditable and compliant.

1008
Matchinghard

Match each excerpt from a small enterprise security program to the correct governance artifact.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Standard

Procedure

Guideline

Exception

Policy

Why these pairings

Policy defines mandatory rules; Procedure gives step-by-step instructions; Standard specifies technical requirements; Guideline offers best practices.

1009
MCQeasy

A SIEM alert shows a payroll administrator account signed in at 02:10 from a country the employee has never visited. The employee says they are on vacation at home and did not travel. What should the analyst do first?

A.Immediately disable the account and wait for the employee to return.
B.Verify the login context with the user or manager and review recent authentication history.
C.Close the alert as a false positive because the user is on vacation.
D.Reimage the user’s workstation before checking any logs.
AnswerB

This is the best first step because alert triage should confirm whether the activity is truly suspicious before disruptive action is taken. Reviewing the user’s normal login patterns, recent sign-in history, and whether a VPN or travel exception exists helps distinguish a real compromise from an unusual but legitimate event. Good triage reduces unnecessary outages and focuses response effort appropriately.

Why this answer

The first step in incident response is to verify the alert's validity and gather context before taking action. The analyst should review the SIEM logs for authentication details (e.g., source IP, geolocation, timestamp) and confirm with the user or manager whether the login was expected. This aligns with the NIST SP 800-61 incident response process, which emphasizes triage and validation before containment.

Exam trap

The trap here is that candidates may jump to containment (disabling the account) or dismissal (false positive) without performing the critical triage step of verifying the login context, which the exam emphasizes as the first action in the incident response process.

How to eliminate wrong answers

Option A is wrong because immediately disabling the account without verification could lock out a legitimate user and disrupt operations, violating the principle of least disruption during initial triage. Option C is wrong because closing the alert as a false positive without investigation ignores the possibility of credential theft or a compromised session, which is a common attack vector. Option D is wrong because reimaging the workstation is a drastic containment step that should only occur after confirming a compromise; it bypasses necessary log analysis and could destroy forensic evidence.

1010
Multi-Selectmedium

Management wants to ensure a file server backed up every night can actually be restored within a 4-hour recovery time objective after an incident. Which two actions best improve recovery confidence? Select two.

Select 2 answers
A.Perform scheduled restore tests to an isolated environment.
B.Keep at least one backup copy offline or immutable.
C.Increase retention to keep backups for two years without changing restore testing.
D.Move the backup repository onto the same always-mounted file share as production data.
E.Reduce the number of user permissions on the file server without changing backup design.
AnswersA, B

Correct because restore testing proves the backups are usable and helps measure actual recovery time. A backup that has never been restored cannot be assumed to meet the recovery objective.

Why this answer

Performing scheduled restore tests to an isolated environment validates that the backup data is both readable and usable without risking corruption of the production environment. This directly confirms the ability to meet the 4-hour RTO by measuring actual restore times and identifying any issues with the backup process or media before a real incident occurs.

Exam trap

The trap here is that candidates often confuse backup retention (how long backups are kept) with backup recoverability, assuming that longer retention inherently improves recovery confidence, when in fact only periodic restore testing proves that backups are viable and can meet the RTO.

1011
Multi-Selecthard

NetFlow and authentication logs show one workstation opening SMB and WinRM sessions to many internal hosts within ten minutes. The same source also generates a sharp rise in Kerberos service-ticket requests and attempts to access administrative shares. Which three observations most strongly support lateral movement rather than normal admin activity? Select three.

Select 3 answers
A.A rapid burst of SMB and WinRM connections to many internal systems from one source host.
B.A sharp increase in Kerberos service-ticket requests from the same workstation.
C.Repeated attempts to access administrative shares such as ADMIN$ or C$.
D.Regular outbound DNS lookups for common internet services like time synchronization or content delivery.
E.A successful sign-in to the user's cloud email account from the employee's home network at lunchtime.
AnswersA, B, C

A sudden fan-out of administrative protocols from one workstation is a classic sign of lateral movement. Normal admin activity is usually more targeted and scheduled. A burst like this suggests an automated attempt to enumerate, authenticate, or execute remotely across the environment.

Why this answer

A rapid burst of SMB and WinRM connections from a single workstation to many internal hosts is a classic indicator of lateral movement. Normal administrative activity typically involves targeted, sequential connections to specific systems for maintenance, not a broad, automated sweep. This pattern suggests an attacker using tools like PsExec or PowerShell remoting to propagate across the network.

Exam trap

The trap here is that candidates may confuse normal administrative tasks with malicious lateral movement, but the key differentiator is the rapid, broad, and automated nature of the connections, combined with the specific targeting of administrative shares and Kerberos ticket requests, which are not typical for routine admin work.

1012
MCQmedium

Based on the exhibit, which item is the strongest evidence that quarterly privileged access reviews occurred?

A.SIEM export of administrator logins.
B.Signed access review spreadsheet with reviewer, date, and exceptions.
C.Help desk ticket for a password reset.
D.Screenshot of the access review policy.
AnswerB

A signed access review spreadsheet with the reviewer's name, the date, and listed exceptions is direct evidence that the quarterly privileged access review control was actually performed. It ties the review to a responsible individual, establishes a clear audit trail of when the review occurred, and documents that exceptions were identified and adjudicated. This is the strongest proof because it is a discrete, retained artifact that demonstrates both the process and its outcome.

Why this answer

A signed access review spreadsheet with reviewer, date, and exceptions provides direct, non-repudiable evidence that a formal review of privileged access was completed. Unlike logs or policies, it explicitly documents the reviewer's identity, the date of review, and any exceptions, satisfying audit requirements for quarterly privileged access reviews.

Exam trap

The trap here is that candidates mistake evidence of activity (like login logs) or policy existence for evidence of a completed review process, overlooking the need for documented attestation with reviewer identity and date.

How to eliminate wrong answers

Option A is wrong because a SIEM export of administrator logins only shows that logins occurred, not that a formal review of those accounts' access rights was performed; it lacks reviewer attestation and exception documentation. Option C is wrong because a help desk ticket for a password reset is an operational event unrelated to the periodic review of privileged access entitlements. Option D is wrong because a screenshot of the access review policy only proves the policy exists, not that it was actually followed or that a review occurred.

1013
MCQmedium

A SIEM reviews VPN authentication logs and sees 36 different usernames each receive one failed login attempt from the same source IP over 20 minutes, followed by one successful login to an unrelated account. Which attack is most likely?

A.Password spraying against many accounts with a low number of attempts per account.
B.A brute-force attack focused on a single locked account.
C.A replay attack using captured authentication data.
D.A port scan that accidentally triggered authentication failures.
AnswerA

The observed pattern is classic password spraying: an attacker tries one or two common passwords (e.g., 'Company123' or 'Winter2024') against 36 distinct usernames, spacing attempts to stay below lockout thresholds. Because each account sees only a single failure, no account locks, and the attack spreads horizontally rather than hammering one user. A SIEM would see many different users with one failed VPN authentication each, exactly matching this low-and-slow credential-stuffing variation.

Why this answer

The SIEM observed 36 different usernames each receiving one failed login attempt from the same source IP over 20 minutes, followed by one successful login to an unrelated account. This pattern is characteristic of a password spraying attack, where an attacker tries a small number of common passwords against many accounts to avoid account lockout thresholds, and then uses a successful credential to pivot to another account. The low number of attempts per account (one each) and the wide spread of usernames distinguish it from brute-force or targeted attacks.

Exam trap

The trap here is that candidates often confuse password spraying with brute-force attacks, but the key differentiator is the distribution of attempts across many accounts versus many attempts on a single account.

How to eliminate wrong answers

Option B is wrong because a brute-force attack focused on a single locked account would show many failed attempts against that one username, not one attempt each across 36 different usernames. Option C is wrong because a replay attack would involve capturing and reusing valid authentication data (e.g., a Kerberos ticket or NTLM hash), not generating new failed login attempts from a source IP. Option D is wrong because a port scan does not generate authentication failures; it probes for open ports using TCP SYN or UDP packets, and any authentication failures would be coincidental and not follow a pattern of one attempt per username.

Page 13

Page 14 of 14