and …","url":"https://courseiva.com/questions/comptia/security-plus/a-web-form-stores-a-user-s-comment-and-later-displays-it-to"},{"@type":"ListItem","position":1014,"name":"A desktop engineering team asks for the document that specifies the exact minimum encryption setting, screen-lock timer,…","url":"https://courseiva.com/questions/comptia/security-plus/a-desktop-engineering-team-asks-for-the-document-that-specifies"},{"@type":"ListItem","position":1015,"name":"Based on the exhibit, what additional control is the best fit?\r\n\r\nCurrent controls on the finance share:\r\n- SMB signing …","url":"https://courseiva.com/questions/comptia/security-plus/based-on-the-exhibit-what-additional-control-is-the-best-fit"},{"@type":"ListItem","position":1016,"name":"A user receives an SMS from 'IT Service Desk' saying their MFA enrollment expires today and includes a shortened link. F…","url":"https://courseiva.com/questions/comptia/security-plus/a-user-receives-an-sms-from-it-service-desk-saying-their-mfa"},{"@type":"ListItem","position":1017,"name":"A security analyst receives an alert that a user clicked a link in a phishing email and entered their corporate credenti…","url":"https://courseiva.com/questions/comptia/security-plus/a-security-analyst-receives-an-alert-that-a-user-clicked-a-link"},{"@type":"ListItem","position":1018,"name":"An employee receives an email from someone claiming to be from IT. The message says the employee must read back a one-ti…","url":"https://courseiva.com/questions/comptia/security-plus/an-employee-receives-an-email-from-someone-claiming-to-be-from"},{"@type":"ListItem","position":1019,"name":"Based on the exhibit, what is the best change to improve accountability without removing emergency access?","url":"https://courseiva.com/questions/comptia/security-plus/based-on-the-exhibit-what-is-the-best-change-to-improve"},{"@type":"ListItem","position":1020,"name":"A Linux web server was compromised through an outdated package. The team isolated the host, captured evidence, removed a…","url":"https://courseiva.com/questions/comptia/security-plus/a-linux-web-server-was-compromised-through-an-outdated-package"},{"@type":"ListItem","position":1021,"name":"After a phishing incident, the security team wants to preserve evidence for later review. Which action is most appropria…","url":"https://courseiva.com/questions/comptia/security-plus/after-a-phishing-incident-the-security-team-wants-to-preserve"},{"@type":"ListItem","position":1022,"name":"Based on the exhibit, which access design change best reduces fraud risk without stopping the payroll process?\r\n\r\nExhibi…","url":"https://courseiva.com/questions/comptia/security-plus/based-on-the-exhibit-which-access-design-change-best-reduces"},{"@type":"ListItem","position":1023,"name":"A security architect is designing a solution to process highly sensitive financial transactions in a shared cloud enviro…","url":"https://courseiva.com/questions/comptia/security-plus/a-security-architect-is-designing-a-solution-to-process-highly"},{"@type":"ListItem","position":1024,"name":"HR stores scanned government IDs collected during onboarding. The retention policy says the files may be kept for 90 day…","url":"https://courseiva.com/questions/comptia/security-plus/hr-stores-scanned-government-ids-collected-during-onboarding-the"},{"@type":"ListItem","position":1025,"name":"Match each excerpt from a small enterprise security program to the correct governance artifact.","url":"https://courseiva.com/questions/comptia/security-plus/match-each-excerpt-from-a-small-enterprise-security-program-to"},{"@type":"ListItem","position":1026,"name":"A SIEM alert shows a payroll administrator account signed in at 02:10 from a country the employee has never visited. The…","url":"https://courseiva.com/questions/comptia/security-plus/a-siem-alert-shows-a-payroll-administrator-account-signed-in-at"},{"@type":"ListItem","position":1027,"name":"NetFlow and authentication logs show one workstation opening SMB and WinRM sessions to many internal hosts within ten mi…","url":"https://courseiva.com/questions/comptia/security-plus/netflow-and-authentication-logs-show-one-workstation-opening-smb"},{"@type":"ListItem","position":1028,"name":"Based on the exhibit, which item is the strongest evidence that quarterly privileged access reviews occurred?","url":"https://courseiva.com/questions/comptia/security-plus/based-on-the-exhibit-which-item-is-the-strongest-evidence-that"},{"@type":"ListItem","position":1029,"name":"A security engineer is designing a Zero Trust architecture for a company that has a mix of on-premises and cloud resourc…","url":"https://courseiva.com/questions/comptia/security-plus/a-security-engineer-is-designing-a-zero-trust-architecture-f-foew9"},{"@type":"ListItem","position":1030,"name":"A SIEM reviews VPN authentication logs and sees 36 different usernames each receive one failed login attempt from the sa…","url":"https://courseiva.com/questions/comptia/security-plus/a-siem-reviews-vpn-authentication-logs-and-sees-36-different"}]}
Security+ SY0-701 (SY0-701) — Questions 976–1030
1030 questions total · 14pages · All types, answers revealed
Based on the exhibit, what should the organization do before approving this SaaS vendor to process employee HR records?
A.Approve the vendor now because admin MFA is enabled and the deadline is urgent.
B.Request a formal risk acceptance memo and sign the contract without additional review.
C.Require a security addendum and evidence review before onboarding, including notification timelines, deletion terms, subprocessors, and independent testing.
D.Move the HR data into the vendor environment first and complete the review after production cutover.
AnswerC
This is the best answer because the exhibit reveals several third-party risk gaps that matter for employee PII: no current independent assurance, vague breach notification, weak retention language, and no maintained subprocessor list. A contract addendum and evidence review provide enforceable expectations and reduce legal, privacy, and operational risk before data is shared.
Why this answer
Before processing sensitive employee HR records, the organization must ensure the SaaS vendor meets security and compliance requirements. This includes reviewing contractual terms like notification timelines, data deletion policies, subprocessor usage, and independent testing evidence (e.g., SOC 2 Type II or ISO 27001 certification). Without these, the organization cannot verify the vendor's security posture or contractual obligations, which is critical for protecting PII and meeting regulatory requirements like GDPR or HIPAA.
Exam trap
The trap here is that candidates may assume MFA or a risk acceptance memo alone is sufficient for compliance, but the SY0-701 exam emphasizes that contractual and evidence-based reviews are mandatory before onboarding vendors handling sensitive data.
How to eliminate wrong answers
Option A is wrong because admin MFA alone is insufficient; it does not address data protection, incident notification, deletion terms, or independent testing, and urgency does not justify bypassing due diligence. Option B is wrong because a risk acceptance memo without additional review ignores the need to verify security controls and contractual protections, effectively accepting unknown risks. Option D is wrong because moving HR data into the vendor environment before completing the review exposes sensitive data to unverified risks, violating the principle of 'trust but verify' and potentially leading to compliance violations.
Users on a branch VLAN intermittently reach a fake login page even though DNS records have not changed. A packet capture shows the default gatewayMAC address changing every 60 seconds, and the switch logs list repeated unsolicited ARP replies from one workstation. Which attack is most likely?
A.DNS poisoning, because name resolution is directing users to the wrong server.
B.ARP poisoning, because forged ARP replies are associating the gateway IP with the attacker's MAC address.
C.Replay attack, because previously captured traffic is being resent to the network.
D.Denial of service, because the branch users cannot reliably reach websites.
AnswerB
ARP poisoning is the best fit because the attacker is sending unsolicited ARP replies to rewrite the local IP-to-MAC mapping. The changing gateway MAC address and repeated ARP activity are classic signs of a man-in-the-middle setup on a switched LAN. Once traffic is redirected through the attacker, fake login pages and credential interception become possible.
Why this answer
The repeated unsolicited ARP replies from one workstation, combined with the default gatewayMAC address changing every 60 seconds, directly indicate an ARP poisoning attack. The attacker is sending forged ARP replies to associate the gateway IP with its own MAC address, causing traffic destined for the gateway to be intercepted. This allows the attacker to redirect users to a fake login page without altering DNS records.
Exam trap
The trap here is that candidates see 'fake login page' and 'DNS records have not changed' and jump to DNS poisoning, but the key indicator is the MAC address changing every 60 seconds, which is a classic sign of ARP poisoning, not DNS manipulation.
How to eliminate wrong answers
Option A is wrong because DNS poisoning involves altering DNS records or cache entries to redirect name resolution, but the scenario explicitly states DNS records have not changed and the packet capture shows MAC address changes, not IP resolution changes. Option C is wrong because a replay attack resends captured legitimate traffic to impersonate a user or disrupt a session, but here the attacker is actively sending unsolicited ARP replies to redirect traffic, not replaying old packets. Option D is wrong because a denial of service attack would prevent users from reaching websites entirely, but the users intermittently reach a fake login page, indicating traffic is being redirected, not blocked.
A development team is moving a regulated application to a cloud platform. The security architect wants the strongest practical separation from other customers without buying and operating physical servers. Which hosting option is most appropriate?
A.A shared multi-tenant environment with no additional security configuration.
B.A dedicated host or isolated compute offering from the cloud provider.
C.Any public object storage service because the data will be encrypted by default.
D.A remote desktop service on the cheapest shared instance available.
AnswerB
A dedicated or isolated compute option provides stronger separation from other tenants while avoiding the need to manage physical hardware directly. It is a common architecture choice for regulated workloads that need enhanced tenant isolation, clearer placement controls, and a stronger compliance story than a standard shared environment.
Why this answer
A dedicated host or isolated compute offering (option B) provides the strongest practical separation because it ensures the application runs on a physical server dedicated solely to that customer, preventing any resource sharing or potential side-channel attacks from other tenants. This meets the regulatory requirement for strong isolation without the cost and operational overhead of purchasing and managing physical servers on-premises.
Exam trap
The trap here is that candidates often confuse 'dedicated host' with 'dedicated instance' or assume a shared multi-tenant environment can be secured solely with encryption, overlooking the need for physical isolation in regulated workloads.
How to eliminate wrong answers
Option A is wrong because a shared multi-tenant environment with no additional security configuration offers weak isolation, as other customers' virtual machines may run on the same hypervisor, increasing the risk of data exposure or side-channel attacks. Option C is wrong because public object storage services are not a compute hosting option; they are for storing data, not running applications, and encryption by default does not address the need for compute-level separation. Option D is wrong because a remote desktop service on the cheapest shared instance provides no dedicated hardware or strong isolation, and the instance is still shared with other tenants, failing to meet the required separation.
Several users on the same subnet report intermittent loss of access to the default gateway. A packet capture shows repeated unsolicited ARP replies mapping the gateway IP address to a different MAC address. Traffic is occasionally sent through an unknown workstation. What attack is most likely occurring?
A.ARP poisoning
B.DNS cache poisoning
C.Replay attack
D.Amplification attack
AnswerA
ARP poisoning is a Layer 2 attack that exploits the lack of authentication in the Address Resolution Protocol. An attacker on the same subnet sends forged ARP replies, associating the default gateway IP address with the attacker's MAC address. Victims update their ARP cache incorrectly, so all outbound traffic intended for the gateway is sent to the attacker's device. This causes intermittent connectivity as the attacker may drop, delay, or forward frames selectively, and the unusual ARP traffic would be visible in packet captures.
Why this answer
The attack is ARP poisoning (also known as ARP spoofing). The attacker sends unsolicited ARP replies to associate the gateway's IP address with the attacker's MAC address, causing traffic destined for the gateway to be redirected through the attacker's workstation. This results in intermittent connectivity as the attacker can forward or drop packets, and the repeated unsolicited replies overwrite the legitimate ARP cache entries on the victim hosts.
Exam trap
The trap here is confusing ARP poisoning with DNS cache poisoning because both involve 'poisoning' a cache, but ARP operates at Layer 2 (MAC addresses) while DNS operates at Layer 7 (domain names), and the symptoms of intermittent gateway access and unsolicited ARP replies are unique to ARP attacks.
How to eliminate wrong answers
Option B (DNS cache poisoning) is wrong because that attack corrupts DNS resolver caches to redirect domain names to malicious IP addresses, not to manipulate Layer 2 MAC-to-IP mappings via ARP. Option C (Replay attack) is wrong because a replay attack involves capturing and retransmitting valid data packets to impersonate a user or gain unauthorized access, not sending unsolicited ARP replies to redirect traffic. Option D (Amplification attack) is wrong because amplification attacks (e.g., DNS amplification, NTP amplification) exploit stateless protocols to flood a target with large responses from many servers, not to poison ARP caches on a local subnet.
Based on the exhibit, which integration best lets the SaaS application trust the company's existing identity provider so users can sign in with their corporate credentials?
A.Establish SAML federation so the SaaS app trusts the corporate identity provider.
B.Enable password synchronization so the SaaS app stores the same password as the directory.
C.Create a shared local administrator account for all subsidiary users.
D.Configure MAC address filtering on company laptops to allow portal access.
AnswerA
SAML 2.0 federation establishes the SaaS application as a service provider that trusts the corporate identity provider (IdP). When a user attempts to access the SaaS app, the app redirects them to the IdP, which authenticates them against the corporate directory and issues a digitally signed XML assertion. The SaaS app verifies the signature and grants session access, so users never need a separate SaaS password and account provisioning can be centrally managed.
Why this answer
SAML (Security Assertion Markup Language) federation allows the SaaS application to trust the corporate identity provider (IdP) by exchanging signed XML assertions. This enables users to authenticate against their corporate credentials without the SaaS app ever storing or managing those credentials, providing single sign-on (SSO) across domains.
Exam trap
The trap here is that candidates confuse password synchronization (a legacy or on-premises approach) with federation (SAML), thinking that syncing passwords achieves the same 'trust' without realizing it requires the SaaS app to handle credentials directly, which is less secure and not true federation.
How to eliminate wrong answers
Option B is wrong because password synchronization replicates the password hash to the SaaS app, which still requires the app to store and manage credentials, violating the principle of federated trust and increasing the attack surface. Option C is wrong because creating a shared local administrator account violates the principle of least privilege and non-repudiation, as it cannot tie actions to individual users and poses a massive security risk. Option D is wrong because MAC address filtering is a network access control mechanism that restricts which devices can connect to the network; it does not provide identity-based authentication or trust between the SaaS app and the corporate IdP.
A SIEM alert shows 120 failed logins for one user account from three different countries within 10 minutes, followed by a successful login. What should the analyst do first?
A.Close the alert because the login eventually succeeded.
B.Verify the activity with related logs and check whether the account owner confirms the login.
C.Immediately delete the account to stop further access.
D.Reimage the user's laptop before collecting any information.
AnswerB
The correct first step in alert triage is to validate the alert by correlating related logs—such as authentication servers, VPN gateways, and endpoint activity—to determine the source IPs, geolocation, time patterns, and whether the failures were followed by a success from the same or different origin. Simultaneously, contacting the account owner confirms whether they initiated the logins, which distinguishes a legitimate user's forgotten password from a malicious brute-force attempt. This verification process ensures the alert is not a false positive and provides necessary context for deciding on further containment, eradication, or recovery actions.
Why this answer
The analyst must first validate the alert by correlating the SIEM data with additional logs (e.g., authentication logs, firewall logs) and contacting the account owner to confirm whether the successful login was legitimate. This follows the incident response process of verification before action, preventing unnecessary disruption if the activity is benign (e.g., the user traveling with VPN).
Exam trap
The trap here is that candidates assume a successful login after failures means the attack succeeded and jump to containment (Option C or D), but the SY0-701 emphasizes that verification with the user and additional logs is the mandatory first step in the incident response process.
How to eliminate wrong answers
Option A is wrong because a successful login after multiple failed attempts is a classic sign of a brute-force or credential-stuffing attack; closing the alert ignores the potential compromise. Option C is wrong because immediately deleting the account destroys evidence and may lock out a legitimate user without investigation, violating the principle of least disruption. Option D is wrong because reimaging the laptop is a drastic containment step that should only occur after confirming compromise and preserving forensic evidence; it also assumes the attack vector is local, which may not be the case (e.g., remote credential abuse).
Based on the exhibit, which action best addresses both the unsanctioned software problem and the need for consistent endpoint configuration?
Exhibit:
Device group: Sales-Laptops
Baseline check:
- Approved browser: installed
- Approved EDR: installed
- Unapproved remote admin tool: detected on 14 endpoints
- Local administrator rights: granted to all users in group
- Patch compliance: 68%
Management wants to prevent unauthorized software from running and keep future builds consistent.
A.Deploy application allowlisting through centralized endpoint management and remove local administrator rights.
B.Keep users as local admins but require stronger email passwords for better overall security.
C.Disable the EDR agent during software installs to avoid false alerts from approved apps.
D.Store approved installers on a shared drive and let users choose what to install.
AnswerA
Application allowlisting is the best fit because it prevents unapproved tools from executing even if they are present on a device. Removing local administrator rights also reduces the chance that users can install or alter software outside the baseline. Combined, these controls support consistent endpoint hardening and make it much harder for risky utilities to appear across the fleet.
Why this answer
Application allowlisting (via AppLocker or Windows Defender Application Control) centrally enforces which software can run, directly addressing the unsanctioned remote admin tool. Removing local administrator rights prevents users from bypassing the allowlist or making unauthorized configuration changes, ensuring consistent endpoint builds and improving patch compliance by limiting user-driven modifications.
Exam trap
The trap here is that candidates may think removing admin rights alone is sufficient, but without application allowlisting, users can still run unapproved software from writable directories like AppData or Temp, so both controls are needed together.
How to eliminate wrong answers
Option B is wrong because keeping users as local admins perpetuates the root cause of unsanctioned software installation and inconsistent configurations, and stronger email passwords do not prevent unauthorized software execution. Option C is wrong because disabling the EDR agent during installs would allow malicious software to run undetected, violating the requirement to prevent unauthorized software and undermining endpoint security. Option D is wrong because storing installers on a shared drive and letting users choose what to install does not enforce any control over software execution, failing to prevent unsanctioned software and leading to inconsistent configurations.
A help desk technician receives a ticket asking for a password reset on a manager's account. The requester says the manager is traveling and cannot be reached. What is the best action before making any change?
A.Reset the password immediately to avoid delaying the manager's work.
B.Verify the request through an approved identity-check process before taking action.
C.Tell the requester to ask a coworker to share the manager's existing password.
D.Ignore the ticket until the manager returns from travel.
AnswerB
The best action is to verify the requester and the request using the organization's approved process before changing access. This helps prevent social engineering and unauthorized account changes. Account resets are sensitive because they can give an attacker control if the help desk relies only on a convincing story or urgent pressure.
Why this answer
The principle of least privilege and proper identity verification are critical before performing any privileged action like a password reset. Without verifying the requester's identity through an approved process (e.g., out-of-band verification, knowledge-based authentication, or manager callback), the technician risks unauthorized access, which could lead to a security breach. This aligns with the CompTIA SY0-701 objective on implementing identity and access management controls.
Exam trap
The trap here is that candidates may assume urgency (Option A) is acceptable, but CompTIA emphasizes that security controls must never be bypassed for convenience, and password sharing (Option C) is always a violation of security best practices.
How to eliminate wrong answers
Option A is wrong because resetting the password immediately without verification violates security policy and could enable an impersonation attack or social engineering, potentially compromising the manager's account. Option C is wrong because sharing an existing password violates the principle of non-repudiation and password confidentiality, and it is never an acceptable practice in any secure environment.
A tester enters a crafted search term into an internal web application and sees no error message, but the page response always delays by exactly five seconds when the input includes a single quote followed by a conditional sleep function. The returned results look normal, so the tester repeats the request several times and the timing remains consistent. Which attack is most likely being attempted?
A.Reflected cross-site scripting, because the tester's input is being echoed back into the response.
B.Command injection, because the application is pausing while executing system-level sleep commands.
C.Time-based blind SQL injection, because the attacker is inferring database behavior from delayed responses.
D.Session fixation, because the tester is manipulating how the application handles user input over time.
AnswerC
The timing pattern is the critical clue. When an application does not reveal errors or data directly, an attacker can still infer whether injected SQL changes control flow by measuring response delays. A single quote plus a conditional sleep is a classic sign of time-based blind SQL injection. The normal-looking results and consistent pauses show the query is being influenced even without visible error output.
Why this answer
The consistent five-second delay triggered by a single quote followed by a conditional sleep function (e.g., ' OR SLEEP(5)) indicates a time-based blind SQL injection. The tester is inferring database behavior from response timing because the application does not display error messages or output differences, but the database executes a sleep command when the injected SQL is syntactically valid. This technique exploits the database's ability to conditionally pause execution, allowing an attacker to extract data bit by bit based on true/false conditions.
Exam trap
The trap here is that candidates confuse a time-based delay with command injection (Option B) because both involve a pause, but the key differentiator is the single quote syntax and the database-specific sleep function, not an OS-level command.
How to eliminate wrong answers
Option A is wrong because reflected cross-site scripting requires the tester's input to be echoed back in the HTML/JavaScript context, not a server-side delay; the absence of error messages and the consistent timing point to database-level behavior, not client-side script execution. Option B is wrong because command injection would involve system-level commands (e.g., 'ping -n 5 127.0.0.1') and typically shows a delay from the OS, not a database-specific sleep function triggered by a single quote; the application is a web application, not a command shell. Option D is wrong because session fixation involves an attacker forcing a known session ID on a victim to hijack their session later, not manipulating input to cause server-side delays; the tester's repeated requests and timing analysis are unrelated to session management.
A security scan finds a critical patch missing on a public-facing web server. The patch has already been tested in the lab and approved for deployment. What should the operations team do next?
A.Ignore the finding because the server is already protected by a firewall
B.Deploy the patch through the normal change process as soon as possible
C.Mark the vulnerability as accepted risk without notifying the business
D.Remove the web server from the asset inventory to prevent the scanner from finding it
AnswerB
This is correct because it balances urgency with stability: the patch should already have been tested and validated through the organization's change advisory board, so deploying it through the standard change process minimizes operational risk while eliminating the known vulnerability. Rapid deployment reduces the time-to-exploit, especially since public servers are continuously probed by automated scanners. Deferring the patch leaves a confirmed, vendor-flagged critical vulnerability exposed.
Why this answer
The patch has already been tested and approved, meaning it is ready for deployment. The operations team should follow the normal change management process to deploy the patch as soon as possible, ensuring the public-facing web server is secured against the critical vulnerability without bypassing organizational controls.
Exam trap
The trap here is that candidates assume a firewall or risk acceptance can substitute for patching a known vulnerability, but the exam emphasizes that compensating controls (like firewalls) do not eliminate the need for patch management, and risk acceptance requires formal business notification and approval.
How to eliminate wrong answers
Option A is wrong because a firewall does not patch application-layer vulnerabilities; it only filters traffic at the network and transport layers, leaving the web server's software flaw exploitable if an attacker reaches the service. Option C is wrong because marking a critical vulnerability as an accepted risk without notifying the business bypasses the formal risk acceptance process, which requires documented approval from management and a clear understanding of the business impact.
Based on the exhibit, which finding should the security team remediate first?
A.LAP09 because user devices are always the easiest to patch
B.WEB01 because it is internet-facing and has a critical exploitable vulnerability
C.PRN01 because firmware issues can affect many users
D.FILE02 because internal servers are always more important than public ones
AnswerB
WEB01 should be remediated first because it is public-facing, rated critical, and already has a known exploit. Exposure and exploitability greatly increase risk, so this finding has the highest immediate urgency. When patching resources are limited, internet-facing critical vulnerabilities are typically prioritized before internal or low-severity issues.
Why this answer
WEB01 is internet-facing and has a critical exploitable vulnerability, meaning an attacker can directly compromise it from the public internet with minimal effort. This represents the highest risk because it combines high likelihood (exploit available) with high impact (full compromise of a public-facing server). Remediating this first aligns with the principle of prioritizing externally exposed systems with known critical flaws over internal or less severe issues.
Exam trap
The trap here is that candidates prioritize based on ease of remediation (A) or internal importance (D) instead of applying a risk-based approach that considers both the severity of the vulnerability and the exposure of the asset.
How to eliminate wrong answers
Option A is wrong because LAP09 being 'easiest to patch' does not equate to highest risk; patching ease is irrelevant when a critical internet-facing vulnerability exists. Option C is wrong because PRN01's firmware issue, while potentially affecting many users, is internal and typically lower severity than a critical remote code execution on a public server. Option D is wrong because internal servers are not inherently more important than public ones; the criticality and exposure of the vulnerability determine priority, not a blanket rule about server location.
Employees sign in once to the corporate portal and then open email, the ticketing system, and an HR application without entering credentials again. The external SaaS providers should trust the company's identity provider rather than creating separate user databases. What architecture is being used?
A.Local authentication on each application with synchronized passwords
B.Federation with single sign-on using the corporate identity provider
C.Network access control using 802.1X authentication
D.Role-based access control on the file server
AnswerB
Federation allows one organization to trust authentication performed by another identity provider. When combined with single sign-on, the user signs in once and then accesses multiple applications without repeated logins. This is exactly what the scenario describes, especially across separate SaaS services.
Why this answer
This scenario describes federation with single sign-on (SSO), where the corporate identity provider (IdP) authenticates the user once and issues a security token (e.g., SAML assertion or OIDC token) that external SaaS providers trust. This eliminates the need for separate user databases in each application and allows seamless access across multiple services without re-entering credentials.
Exam trap
The trap here is that candidates confuse 'single sign-on' with 'synchronized passwords' (Option A) or think that any centralized authentication mechanism (like 802.1X) can replace federated identity for external SaaS trust.
How to eliminate wrong answers
Option A is wrong because local authentication with synchronized passwords still requires each application to maintain its own user database and credential verification, which does not achieve the 'trust the company's identity provider' requirement and introduces password synchronization complexity. Option C is wrong because 802.1X network access control is a port-based authentication mechanism for network access (e.g., wired or Wi-Fi), not for web application SSO or federated identity across SaaS providers. Option D is wrong because role-based access control (RBAC) on the file server governs authorization (what a user can do) after authentication, not the authentication architecture or federated trust between an IdP and external applications.
A user forwards an email that says a shared document is available and must be reviewed within 10 minutes. The display name looks like a trusted vendor, but the Reply-To address points to a free webmail account. Which two details are strongest indicators that this is a phishing attempt? Select two.
Select 2 answers
A.The message creates a short deadline and pressures the user to act quickly.
B.The Reply-To address uses a free webmail domain instead of the vendor's corporate domain.
C.The message includes the company's logo and professional-looking formatting.
D.The email refers to a shared document that the user should review.
E.The message was received during normal business hours.
AnswersA, B
Urgency is a classic phishing tactic because it pushes recipients to react before verifying the request. A short deadline increases the chance that the user clicks a link or shares credentials without checking the sender or context.
Why this answer
Phishing attacks frequently use urgency and time pressure to bypass the victim's rational analysis, exploiting the psychological principle of scarcity to trigger impulsive clicks. The 10-minute deadline is a classic social engineering tactic to prevent the user from verifying the email's legitimacy through normal channels.
Exam trap
CompTIA often tests the distinction between easily spoofed visual elements (logos, formatting) and verifiable technical indicators (Reply-To domain mismatch, urgency cues) to catch candidates who rely on superficial appearance rather than email authentication mechanisms.
A security manager wants to require that all company laptops use at least a 14-character password and lock after 10 minutes of inactivity. Which document should define these mandatory settings?
A.Policy, because it is the broad statement of security intent only.
B.Standard, because it defines specific required technical values the company must follow.
C.Guideline, because it gives optional recommendations for device security.
D.Memo, because it is the normal formal document for security baselines.
AnswerB
A standard is the right document when the organization wants specific, mandatory technical requirements. Password length and screen-lock timeout are measurable settings, so they belong in a standard rather than a general policy. Standards make implementation consistent across systems and help administrators configure devices to the same baseline.
Why this answer
A standard is the document type that defines mandatory, specific technical requirements, such as a minimum 14-character password length and a 10-minute inactivity lock. Policies are high-level statements of intent, while standards provide the enforceable, measurable parameters that implement that intent. In this scenario, the security manager needs a binding baseline, which is precisely the role of a standard.
Exam trap
The trap here is confusing a policy (broad intent) with a standard (specific, mandatory technical values), leading candidates to choose Option A because they think all security rules are policies, when in fact standards define the enforceable numbers.
How to eliminate wrong answers
Option A is wrong because a policy is a broad statement of security intent and does not include specific technical values like password length or lockout timers; it would reference a standard for those details. Option C is wrong because a guideline offers optional recommendations, not mandatory settings, so it cannot enforce a required 14-character password or 10-minute lock. Option D is wrong because a memo is an informal communication tool, not a formal document type for defining security baselines; it lacks the authority and structure of a standard.
After a workstation reboot, users see many files renamed with random extensions. A ransom note demands cryptocurrency, and Volume Shadow Copies were deleted from the machine. What malware type is most likely?
A.Trojan, because the malware may have been disguised as a legitimate application.
B.Worm, because the malware likely spread automatically to other systems.
C.Ransomware, because the files were encrypted and payment was demanded.
D.Rootkit, because the attacker would want to hide persistence on the system.
AnswerC
Ransomware commonly encrypts files, deletes recovery options, and leaves a ransom note demanding payment. The random extensions and removed shadow copies are classic clues that the attacker wants to block restoration until payment is made.
Why this answer
The scenario describes files renamed with random extensions (indicating encryption), a ransom note demanding cryptocurrency, and deletion of Volume Shadow Copies (VSS) to prevent file recovery. These are hallmark behaviors of ransomware, specifically a crypto-ransomware variant that encrypts user data and removes backup copies to maximize extortion pressure.
Exam trap
The trap here is that candidates see 'files renamed' and 'ransom note' but may confuse the delivery method (Trojan) or propagation (Worm) with the actual malware type, which is defined by its payload—encryption for extortion—not how it arrived or spread.
How to eliminate wrong answers
Option A is wrong because a Trojan is a type of malware that disguises itself as legitimate software, but the core behavior here is file encryption and ransom demand, not just deception. Option B is wrong because a Worm self-replicates and spreads automatically across networks without user interaction, but the question focuses on the post-reboot encryption and ransom note, not propagation. Option D is wrong because a Rootkit is designed to hide its presence and maintain stealthy persistence, but the visible symptoms are encrypted files and a ransom demand, not hidden processes or stealth.
An employee reports a ransomware note on a finance laptop. The laptop is still powered on, connected to Wi-Fi, and the user says they were just working in a spreadsheet. Management wants the fastest safe response that also preserves evidence. What should the responder do first?
A.Shut the laptop down immediately to prevent further encryption activity.
B.Isolate the laptop from the network while keeping it powered on for volatile evidence collection.
C.Ask the user to close all open applications and log off normally.
D.Start deleting suspicious files to reduce the impact of the ransomware.
AnswerB
The best first action is to contain the threat without destroying live evidence. Disconnecting network access limits further spread or command-and-control activity, while keeping the system powered on preserves memory, running processes, and other volatile artifacts that may be critical to the investigation. This balances containment with evidence preservation, which is exactly what responders need at the start of an incident.
Why this answer
The immediate priority is to contain the ransomware while preserving volatile evidence (e.g., memory contents, running processes, network connections) that could be critical for forensic analysis. Powering off the laptop (Option A) would destroy volatile data and may allow the ransomware to persist or trigger additional encryption on reboot. Isolating the network connection stops the ransomware from communicating with its command-and-control server or spreading laterally, while keeping the system powered on allows a responder to capture memory with tools like FTK Imager or LiME before performing a controlled shutdown.
Exam trap
The SY0-701 exam often tests the misconception that shutting down a compromised system is the safest immediate action, but the trap here is that volatile evidence is lost and the ransomware may have anti-forensic shutdown triggers, making network isolation the correct first step.
How to eliminate wrong answers
Option A is wrong because immediately shutting down the laptop destroys volatile evidence (RAM, running processes, network connections) that could reveal the ransomware variant, encryption keys, or attacker infrastructure; it may also trigger a destructive payload on shutdown. Option C is wrong because asking the user to close applications and log off normally could trigger additional encryption, overwrite evidence in memory, or allow the ransomware to complete its encryption cycle; logging off may also terminate critical forensic artifacts like open network connections or process handles.
A critical vulnerability is discovered on an internet-facing VPN appliance that cannot be patched for six weeks because the vendor has not released a fix. The VPN service must remain available. What is the best operational response?
A.Leave the appliance unchanged until the vendor releases a patch.
B.Apply compensating controls such as restricting source IPs and increasing monitoring.
C.Disable all logging so the appliance performs better under load.
D.Replace the VPN with a less secure remote access method to avoid the vulnerability.
AnswerB
When a patch is not yet available, compensating controls such as restricting source IP addresses via firewall allow-lists, enforcing multi-factor authentication, and increasing security monitoring are the appropriate interim measures. These controls reduce the likelihood of exploitation by limiting who can reach the VPN management interface and by generating alerts on abnormal access patterns, while maintaining essential service availability. The goal is to buy time for a proper patch deployment without leaving the device entirely defenseless.
Why this answer
When a vulnerability cannot be patched immediately, compensating controls such as restricting source IPs via ACLs and increasing monitoring (e.g., enabling detailed logging and alerting on anomalous traffic) reduce the attack surface and improve detection of exploitation attempts. This approach maintains service availability while mitigating risk until the vendor releases a fix.
Exam trap
The trap here is that candidates may think leaving the appliance unchanged (Option A) is acceptable if no patch exists, but the exam expects proactive risk reduction through compensating controls rather than passive acceptance of the vulnerability.
How to eliminate wrong answers
Option A is wrong because leaving the appliance unchanged without any mitigation leaves the organization fully exposed to exploitation of the known vulnerability, which is unacceptable for a critical internet-facing device. Option C is wrong because disabling logging reduces visibility into potential attacks, making it harder to detect and respond to exploitation, and does not address the vulnerability itself. Option D is wrong because replacing the VPN with a less secure remote access method introduces new risks and likely violates security policies, whereas the goal is to maintain security while keeping the service available.
A security operations center (SOC) analyst is overwhelmed by the volume of alerts. The management wants to implement a solution that can automatically respond to common threats, such as blocking an IP address or isolating a compromised endpoint, without requiring human intervention. Which of the following technologies best meets this requirement?
A.Security Information and Event Management (SIEM)
B.Security Orchestration, Automation, and Response (SOAR)
C.Endpoint Detection and Response (EDR)
D.Cloud Access Security Broker (CASB)
AnswerB
SOAR platforms are purpose-built to aggregate alerts from multiple sources, execute predefined playbooks, and automatically trigger response actions such as containing a host, blocking an IoC, or opening a ticket. By orchestrating workflows across disparate security tools (e.g., SIEM, EDR, firewalls), SOAR directly reduces the manual triage and repetitive tasks that overwhelm analysts. This capability to automate complex, multi-step incident response without human intervention makes it the exact fit for the scenario.
Why this answer
SOAR is the correct choice because it is specifically designed to automate response actions to common security incidents, such as blocking an IP address via firewall APIs or isolating an endpoint through EDR integration, without requiring human intervention. This directly addresses the SOC analyst's alert fatigue by enabling playbook-driven, automated remediation.
Exam trap
The trap here is that candidates confuse SIEM's alerting capability with automated response, forgetting that SIEMs require a separate SOAR or custom scripting to perform actions, while SOAR is the dedicated solution for orchestrated, automated remediation.
Why the other options are wrong
A
SIEM aggregates and correlates logs for analysis but lacks native automated response capabilities; it requires human intervention or integration with other tools to block IPs or isolate endpoints.
C
EDR focuses on detecting and investigating threats on endpoints, but it does not inherently provide automated response orchestration across multiple security tools to block IPs or isolate endpoints without human intervention.
D
CASB is designed to enforce security policies for cloud services, not to automate response actions like blocking IPs or isolating endpoints across the enterprise.
When would these options actually be correct?
A
A question asking for a solution to centralize log collection, correlate events across sources, and provide real-time alerting for security incidents, without requiring automated response, would make SIEM the correct answer.
C
An exam question asking for a technology that provides continuous monitoring, detection, and manual or automated response specifically on endpoint devices, such as identifying malware or suspicious processes on a laptop, would make EDR the correct answer.
D
A question asking for a technology that monitors and controls access to cloud applications, enforces data loss prevention policies, and detects shadow IT in a multi-cloud environment.
Why candidates pick the wrong answer
A
Candidates often associate SIEM with security monitoring and incident response, mistakenly believing its alerting features include automated remediation, overlooking that SOAR specifically adds orchestration and automation.
C
Candidates may confuse EDR's automated response capabilities (like isolating an endpoint) with the broader orchestration and automation across multiple systems that SOAR provides, overlooking the need for cross-platform automation.
D
Candidates may confuse CASB's policy enforcement capabilities with automated response, or think it can handle endpoint isolation due to its security control features.
A systems administrator says the backup software reports success every night, but no one has restored a server from backup in over a year. The business wants confidence that a file server can be recovered within the agreed recovery window. What is the best next action?
A.Trust the success status because completed jobs prove the backups are usable.
B.Perform a scheduled restore test in an isolated environment and measure the recovery time.
C.Delete older backups so that only the most recent set remains.
D.Extend retention indefinitely to avoid ever losing a recoverable copy.
AnswerB
Performing a scheduled restore test in an isolated environment directly validates that the backup media contains usable data and that the restore procedure works end-to-end. This practice confirms the organization can meet its recovery point objective (RPO) and recovery time objective (RTO) by measuring how long the restore actually takes. It also surfaces hidden issues such as missing dependencies or permission problems while avoiding production disruption.
Why this answer
The only way to validate that backups are both restorable and meet the recovery time objective (RTO) is to perform a scheduled restore test in an isolated environment. Backup success logs only confirm that data was copied, not that the data is intact or that the restoration process completes within the agreed window. This aligns with the 3-2-1 backup rule and the principle of 'trust but verify' in backup validation.
Exam trap
The trap here is that candidates assume backup success logs are sufficient proof of recoverability, but CompTIA emphasizes that only a documented restore test can verify the backup's usability and adherence to the RTO.
How to eliminate wrong answers
Option A is wrong because backup success status only indicates that the backup job completed without errors, not that the backup data is restorable or that the recovery process will meet the RTO; data corruption, missing files, or incomplete snapshots can still occur. Option C is wrong because deleting older backups reduces the number of recovery points and increases the risk of data loss, especially if the most recent backup is corrupted or fails to restore. Option D is wrong because extending retention indefinitely does not address the core issue of verifying recoverability and can lead to storage bloat, increased costs, and compliance violations without proving that a restore is possible within the RTO.
A user reports that their laptop is suddenly encrypting files and showing a ransom note. What should the incident response team do first?
A.Immediately restore the laptop from backup before collecting any information.
B.Isolate the laptop from the network to limit spread and preserve evidence.
C.Return the laptop to the user and monitor for additional alerts.
D.Apply all pending software updates to the laptop while it remains online.
AnswerB
Isolation is the critical containment step in an active ransomware outbreak: by disconnecting the laptop from the network (unplugging Ethernet, disabling Wi-Fi and Bluetooth), you stop the malware from encrypting any networked file shares or hopping to adjacent hosts via SMB or other propagation mechanisms. This action also preserves the system's live state so that forensic tools can capture memory, running processes, and encryption artifacts without the device being either further contaminated or remotely meddled with by the attacker. Containment must happen before eradication and recovery, per NIST IR lifecycle.
Why this answer
When a laptop suddenly encrypts files and displays a ransom note, it indicates an active ransomware infection. The incident response team's first priority is to isolate the laptop from the network to prevent the ransomware from spreading laterally to other systems and to preserve volatile evidence (e.g., memory contents, running processes) that could be lost if the system is powered off or reconnected. This aligns with the NIST SP 800-61 incident response guidelines, which emphasize containment before eradication or recovery.
Exam trap
The trap here is that candidates may confuse incident response phases and choose a recovery action (like restoring from backup) before containment, or they may mistakenly think applying updates is a valid response to an active infection, when in fact isolation is the mandatory first step per the NIST framework.
How to eliminate wrong answers
Option A is wrong because immediately restoring from backup without first isolating the system could allow the ransomware to re-encrypt the restored files if the infection is still active, and it destroys volatile evidence needed for forensic analysis. Option C is wrong because returning the laptop to the user and monitoring for additional alerts would allow the ransomware to continue encrypting files and potentially spread to other network resources, violating the containment principle. Option D is wrong because applying pending software updates while the laptop remains online does not stop the active encryption process and could trigger additional malicious activity; updates are a preventive measure, not an incident response containment step.
Based on the exhibit, which malware type best explains the behavior?
A.Trojan
B.Rootkit
C.Logic bomb
D.Spyware
AnswerB
The exhibit shows a hidden listener associated with PID 4, an unsigned driver, and a mismatch between user-mode process enumeration and kernel telemetry. Those are classic rootkit indicators because rootkits operate at a low level to conceal processes, ports, or files from standard tools. The suspicious driver name and kernel-level inconsistency are especially strong clues that the malware is trying to hide itself from the operating system and defenders.
Why this answer
A rootkit is designed to hide its presence and the presence of other malware by modifying the operating system's kernel or system calls, allowing it to evade detection by security tools. The exhibit likely shows behavior such as file hiding, process concealment, or system call interception, which are hallmarks of rootkit activity. This aligns with the SY0-701 objective on understanding malware types and their characteristics.
Exam trap
The trap here is that candidates often confuse a rootkit's stealth capabilities with a Trojan's deceptive delivery method, failing to recognize that the exhibit's focus on hiding and persistence at the OS level is unique to rootkits, not general malware types.
How to eliminate wrong answers
Option A (Trojan) is wrong because a Trojan disguises itself as legitimate software to trick users into installing it, but it does not inherently hide its presence or modify the kernel to evade detection; the exhibit's behavior of stealth and system-level concealment is not typical of a Trojan. Option C (Logic bomb) is wrong because a logic bomb is a piece of code that executes a malicious payload when specific conditions are met (e.g., a date or user action), but it does not actively hide itself or its processes; the exhibit's ongoing stealth behavior is inconsistent with a dormant trigger-based mechanism. Option D (Spyware) is wrong because spyware focuses on covertly collecting user data (e.g., keystrokes, browsing habits) and sending it to an attacker, but it does not typically modify the OS kernel or hide its own files and processes at the rootkit level; the exhibit's system-level concealment goes beyond spyware's typical user-space monitoring.
Based on the exhibit, which control should be enabled so corporate data stays separated from personal data on company-owned tablets?
A.Perform a full-device wipe any time a tablet is lost or reassigned.
B.Deploy mobile threat defense scanning on every tablet.
C.Enable a work profile or container with selective wipe for corporate data.
D.Disable Bluetooth and the camera on all tablets to stop data leakage.
AnswerC
Enabling a work profile (e.g., Android Work Profile or iOS managed container) creates a dedicated, encrypted boundary that separates corporate apps and data from personal content on the same device. Policies can enforce selective wipe of only that container when a device is lost, reassigned, or non-compliant, preserving the user's personal data. This also allows IT to manage corporate email, VPN, and app restrictions within the profile without granting full control of the personal side—directly addressing the need for workflow separation.
Why this answer
A work profile or container (e.g., Android Work Profile or iOS Managed Open In) creates a separate, encrypted partition for corporate data on the device. This allows IT to perform a selective wipe of only the corporate data without affecting the user's personal apps, photos, or settings, ensuring data separation while preserving user privacy.
Exam trap
The trap here is that candidates confuse security controls like full-device wipe or threat scanning with data separation mechanisms, failing to recognize that only containerization or work profiles provide the granular isolation needed to keep corporate and personal data separate on the same device.
How to eliminate wrong answers
Option A is wrong because performing a full-device wipe on loss or reassignment destroys both corporate and personal data, violating the requirement to keep corporate data separated from personal data; it does not enable ongoing separation. Option B is wrong because mobile threat defense scanning detects malware or suspicious activity but does not isolate corporate data into a separate container; it provides security monitoring, not data separation. Option D is wrong because disabling Bluetooth and the camera reduces data leakage vectors but does not create any logical separation between corporate and personal data; it is a restrictive control that does not address the core requirement of maintaining separate data stores.
An employee receives an email that says, 'This is the CEO. Buy gift cards now and reply with the codes before the meeting starts.' What should the employee do?
A.Reply with the codes because the request appears urgent
B.Verify the request through an approved channel and report the message
C.Forward the email to coworkers so they can watch for similar messages
D.Delete the email and ignore it without telling anyone
AnswerB
Verifying the request through an approved channel, such as a pre-configured phone number, in-person contact, or the official ticketing system, confirms authenticity without relying on any contact information found in the suspect email itself. Reporting the message to the security or incident response team allows analysts to collect header data, block the sender, and issue warnings to other employees who may have received identical lures. This combination of independent verification and official reporting directly mitigates the current threat and protects the organization from a likely impersonation fraud. Acting alone, either verification or reporting, is insufficient; both together form a complete and secure response.
Why this answer
The email exhibits classic social engineering indicators—spoofed authority, urgency, and a request for non-standard financial transactions (gift cards). The employee must verify the request through an approved communication channel (e.g., a phone call to the CEO's known number) and report the message to the security team for incident response. This aligns with security policy for phishing and business email compromise (BEC) prevention, as per NIST SP 800-61 and organizational security awareness training.
Exam trap
The trap here is that candidates may mistake the urgency and authority in the email as legitimate, choosing Option A, but CompTIA tests the principle that any request for sensitive actions (gift cards, wire transfers, credential changes) must be verified through a separate, trusted channel regardless of apparent sender identity.
How to eliminate wrong answers
Option A is wrong because replying with gift card codes without verification directly enables a BEC attack, violating the principle of least trust and bypassing standard financial controls. Option C is wrong because forwarding the email to coworkers could propagate the phishing link or attachment, increasing the attack surface and potentially bypassing email security filters. Option D is wrong because deleting the email without reporting it prevents the security team from analyzing the threat, updating detection rules, and protecting other users from the same attack.
EDR shows encoded PowerShell launched by a word processor and an outbound connection to a rare domain. What is the best immediate containment action?
A.Isolate the endpoint from the network using the EDR console.
B.Uninstall the word processor from every workstation.
C.Wait to see whether more alerts appear before responding.
D.Send a notice to all users reminding them not to open attachments.
AnswerA
Network isolation through EDR quickly limits attacker access and prevents further command-and-control communication. It also preserves the host for investigation while stopping spread to other systems. This is a standard first containment step when behavior strongly suggests active compromise.
Why this answer
Isolating the endpoint from the network using the EDR console is the best immediate containment action because it stops the outbound connection to the rare domain, preventing potential command-and-control (C2) communication or data exfiltration. The encoded PowerShell launched by a word processor strongly suggests a malicious macro or exploit, and isolating the host contains the threat without disrupting the entire network. This aligns with the incident response priority of containment before eradication or recovery.
Exam trap
The trap here is that candidates may choose a broad administrative action (like uninstalling software or sending user notices) instead of the precise, immediate technical containment step that stops the active threat at the network level.
How to eliminate wrong answers
Option B is wrong because uninstalling the word processor from every workstation is a broad, disruptive action that does not address the immediate threat on the affected host and may remove legitimate software needed for business operations. Option C is wrong because waiting for more alerts allows the potential C2 channel to remain active, increasing the risk of lateral movement or data theft. Option D is wrong because sending a user notice is a preventive or awareness measure, not an immediate containment action, and it does not stop the active malicious process or network connection.
Based on the exhibit, which hardening change best prevents a laptop from booting unapproved tools from external media?
Exhibit:
UEFI Setup
- Secure Boot: Disabled
- Boot order: USB, External NIC, Internal SSD
- Firmware admin password: Not configured
- BitLocker status: Enabled
Incident note:
A technician confirmed the laptop was started from a USB recovery stick that bypassed the normal corporate login workflow.
A.Enable Secure Boot and change the firmware boot order so only the internal SSD is allowed first.
B.Extend the Windows login timeout so users have more time to notice suspicious activity.
C.Turn off BitLocker so recovery tools can boot without errors.
D.Install a host firewall rule to block USB storage devices from the network.
AnswerA
This is the best control because Secure Boot validates that the bootloader is trusted, and restricting the boot order reduces the chance of booting from unapproved removable media. Together, these changes stop many pre-boot attacks and unauthorized recovery tools before the operating system starts. BitLocker helps protect data at rest, but it does not by itself prevent booting alternate media.
Why this answer
Enabling Secure Boot ensures that only signed, trusted firmware and bootloaders can execute, preventing unauthorized tools like USB recovery sticks from loading. Changing the boot order to prioritize the internal SSD over USB media stops the system from even attempting to boot from external devices, directly addressing the incident where the laptop bypassed corporate login via a USB stick.
Exam trap
CompTIA often tests the misconception that host firewall rules can control local device access, but firewalls operate at the network layer and cannot block USB storage devices, which are managed by hardware or OS-level policies.
How to eliminate wrong answers
Option B is wrong because extending the Windows login timeout does not prevent booting from external media; it only affects the login screen after the OS has already loaded, leaving the boot process vulnerable. Option C is wrong because turning off BitLocker would actually make it easier for unauthorized tools to boot and access data, as BitLocker protects against offline attacks and does not cause boot errors for legitimate recovery tools when properly configured. Option D is wrong because a host firewall rule blocks network traffic, not local USB storage devices; USB storage is controlled by hardware policies or Group Policy, not firewall rules.
A manufacturer wants to give partner-company users access to a procurement portal. The partner wants to authenticate its own users, and the manufacturer does not want to create separate local passwords for them. What is the best solution?
A.Create shared portal accounts and distribute credentials to the partner's staff.
B.Federate access with the partner's identity provider and map claims or attributes to portal roles.
C.Issue one VPN account for the partner organization and let them share it internally.
D.Require each partner user to create a password directly in the procurement portal.
AnswerB
Federation lets the partner authenticate its own users while the manufacturer trusts identity assertions from the partner identity provider. Claims or attributes can then be mapped to portal roles so access stays controlled without local password management. This is a strong fit for business-to-business access because it preserves administrative separation while still supporting centralized authorization decisions in the portal.
Why this answer
Federation with the partner's identity provider (IdP) using standards like SAML 2.0 or OIDC allows the partner to authenticate their own users while the manufacturer's portal trusts those assertions. Claims or attributes from the IdP (e.g., group membership) are mapped to portal roles, eliminating the need for local passwords and enabling single sign-on (SSO). This is the best solution because it maintains security boundaries and offloads authentication management to the partner.
Exam trap
The trap here is that candidates confuse federation with simple shared accounts or VPN-based access, failing to recognize that federation is the only option that delegates authentication to the partner while preserving individual accountability and eliminating local password management.
How to eliminate wrong answers
Option A is wrong because shared portal accounts violate the principle of least privilege and non-repudiation—multiple users sharing one set of credentials makes auditing impossible and increases the risk of credential leakage. Option C is wrong because a single VPN account shared internally provides no individual accountability, bypasses proper access controls, and does not solve the authentication delegation requirement; it also introduces a VPN dependency that is unnecessary for a web-based procurement portal.
A security administrator is implementing a new backup strategy. The organization requires that backups be encrypted at rest and that the encryption keys be managed separately from the backup data. Which of the following should the administrator implement to meet these requirements?
A.Use a cloud backup service that encrypts data at rest with a provider-managed key.
B.Enable AES-256 encryption on the backup target storage array and store the encryption key in a configuration file on the backup server.
C.Store backups on an encrypted USB drive and keep the drive in a safe.
D.Use a backup solution that supports client-side encryption with a key management server (KMS).
AnswerD
Client-side encryption with a KMS allows the backup data to be encrypted before it leaves the source, and the keys are stored and managed in a separate KMS. This meets both requirements: encryption at rest and separate key management. The KMS can enforce access controls and key rotation policies independently of the backup storage.
Why this answer
Client-side encryption with a key management server (KMS) ensures that data is encrypted before transmission and stored encrypted, while the keys are managed in a separate, secure system. This separation of duties prevents a compromise of the backup storage from exposing the keys, and allows for centralized key lifecycle management.
Exam trap
The trap here is assuming that any encryption at rest satisfies the requirement, but the key must be managed separately from the data to prevent a single point of compromise.
Based on the exhibit, which security issue should the analyst report first?
A.Outdated component, because the scan did not list software version details.
B.Exposed service, because VNC and the web admin interface are reachable from untrusted networks.
C.Weak permissions, because SSH requires password login only.
D.Default credentials, because the server is in the DMZ.
AnswerB
The most important issue is the exposed service because remote management interfaces are reachable from any source network, and VNC authentication is disabled. That combination creates a high-risk attack surface, especially for a server in the DMZ that stores sensitive customer information.
Why this answer
The scan reveals that VNC (port 5900) and a web admin interface (port 443 or 8080) are exposed to untrusted networks, such as the internet. This violates the principle of least exposure, as these services are known attack vectors for remote code execution and credential theft. The analyst should prioritize this issue because an exposed service directly increases the attack surface and risk of unauthorized access, whereas other findings may be less immediately critical.
Exam trap
The trap here is that candidates often focus on missing version details (Option A) or default credentials (Option D) as the most critical finding, but CompTIA emphasizes that exposed services on untrusted networks pose the highest immediate risk because they are directly exploitable without requiring prior access.
How to eliminate wrong answers
Option A is wrong because the absence of software version details in the scan does not necessarily indicate an outdated component; it may simply mean the scanner could not fingerprint the version due to banner hiding or firewall restrictions. Option C is wrong because SSH requiring password login only is not inherently a weak permission; weak permissions refer to file or directory access controls, not authentication methods, and password-based SSH is still common in many environments. Option D is wrong because default credentials are not indicated by the server being in the DMZ; the scan does not show any evidence of default username/password usage, and the DMZ placement alone does not confirm this vulnerability.
Based on the exhibit, which security principle does the organization appear to be using most clearly?
A.Zero trust, because all access is denied until a user proves identity again.
B.Defense in depth, because several different controls stop or limit the attack at different stages.
C.Least privilege, because the attachment was blocked from having administrator rights.
D.Need-to-know, because only the security team should be aware of the incident.
AnswerB
Defense in depth is demonstrated by multiple layers: email filtering, application control, EDR containment, MFA, and backup recovery. The attack is not stopped by one control alone. Instead, each layer provides a separate barrier or recovery path, reducing the chance that a single failure becomes a full compromise.
Why this answer
The exhibit shows multiple security controls—an email filter blocking the attachment, a web filter blocking the download link, and an endpoint detection and response (EDR) tool blocking execution—each acting at a different stage of the attack chain. This layered approach, where no single control is relied upon to stop the threat, is the hallmark of defense in depth. The correct answer is B because the scenario clearly demonstrates overlapping controls that provide redundancy and mitigate risk at various points.
Exam trap
The trap here is that candidates often confuse defense in depth with zero trust because both involve multiple controls, but zero trust specifically requires explicit verification for every access request, whereas defense in depth focuses on layered, independent safeguards without necessarily re-verifying identity at each layer.
How to eliminate wrong answers
Option A is wrong because zero trust requires continuous verification of identity and device posture for every access request, not just a one-time re-authentication; the exhibit shows no evidence of such per-request validation. Option C is wrong because least privilege restricts user permissions to the minimum necessary for their role, but the attachment was blocked by an email filter before any user could execute it, not by limiting the attachment's administrator rights. Option D is wrong because need-to-know restricts information access to only those who require it for their duties, but the exhibit focuses on technical controls blocking the attack, not on who is informed about the incident.
A security manager is reviewing the organization's incident response plan and notices that it lacks a defined process for handling evidence that may be used in legal proceedings. Which concept should the manager ensure is addressed to maintain the integrity of evidence?
A.Chain of custody
B.Data retention policy
C.Business impact analysis
D.Acceptable use policy
AnswerA
Chain of custody is the documented process that tracks the seizure, custody, control, transfer, analysis, and disposition of evidence. It ensures that evidence is admissible in court by showing that it has not been tampered with. In an incident response plan, defining chain of custody procedures is critical for any investigation that may lead to legal action. This directly addresses the manager's concern about evidence integrity.
Why this answer
Chain of custody is essential for ensuring that evidence collected during an incident remains admissible in legal proceedings. It documents who handled the evidence, when, and why, preventing tampering or contamination. The other options address different areas: retention schedules, user policies, and business continuity.
The incident response plan must include chain of custody procedures to support potential prosecutions or lawsuits.
Exam trap
The trap here is confusing chain of custody with general data retention or incident documentation, missing that chain of custody specifically tracks evidence handling for legal admissibility.
Before contracting with a cloud-based payroll provider, the security team requests a security questionnaire, proof of controls, and an independent audit report. What activity is this?
A.Business continuity testing, because the team is checking recovery procedures.
B.Third-party due diligence, because the team is evaluating vendor risk before onboarding.
C.Security awareness training, because the vendor is being taught safe behavior.
D.Data classification, because the team is labeling the payroll data type.
AnswerB
Third-party due diligence is the process of reviewing a vendor’s security posture, controls, and supporting evidence before trusting them with business data or services. The questionnaire and audit report are classic inputs for that review.
Why this answer
The security team's request for a security questionnaire, proof of controls, and an independent audit report before contracting with a cloud-based payroll provider is a classic example of third-party due diligence. This process evaluates the vendor's security posture, compliance, and risk level before onboarding, ensuring that sensitive payroll data is protected. It is a proactive risk management activity, not a reactive test or training exercise.
Exam trap
The trap here is that candidates confuse third-party due diligence with business continuity testing, because both involve reviewing documentation, but due diligence is pre-contractual risk evaluation, not post-incident recovery verification.
How to eliminate wrong answers
Option A is wrong because business continuity testing focuses on verifying recovery procedures and system resilience, not on evaluating a vendor's security controls before contracting. Option C is wrong because security awareness training is an internal program to educate employees on safe behavior, not a vendor assessment activity. Option D is wrong because data classification involves labeling data by sensitivity level, not requesting audit reports or control evidence from a third party.
After employees transfer departments, they keep access to old SaaS applications because app-specific accounts are removed only after a manual cleanup ticket. Which two changes best close the lifecycle gap? Select two.
Select 2 answers
A.Use automated provisioning and deprovisioning tied to HR events through SCIM or an equivalent interface.
B.Keep app accounts manually managed so each app owner can decide independently.
C.Map entitlements to IdP groups or roles based on job function.
D.Share a generic help desk password for quick access restoration.
E.Require password changes every 30 days for all users.
AnswersA, C
Automated provisioning systems use SCIM, an IETF-standardized RESTful API, to exchange identity lifecycle events between the IdP and service providers. When HR records a role change or termination, a workflow engine dynamically updates or disables accounts across all connected applications, eliminating the delay of human intervention. This enforces least privilege and reduces the risk that a lateral mover retains stale entitlements, because access is revoked in near-real-time to match the employee's current business need.
Why this answer
Automating provisioning and deprovisioning via SCIM (System for Cross-domain Identity Management) ties account lifecycle directly to HR events (e.g., termination, transfer). This eliminates the manual cleanup ticket gap by instantly removing or modifying access when an employee changes departments, ensuring no stale SaaS accounts remain.
Exam trap
The trap here is that candidates confuse password policies (Option E) with account lifecycle management, failing to recognize that frequent password changes do not remove orphaned accounts or close the provisioning gap.
The web team is placing a public customer portal behind a control that can inspect HTTP requests, block malicious payloads such as SQL injection and cross-site scripting, and still allow legitimate application traffic without rewriting the app. Which control should they deploy?
A.An IDS placed on the same network segment as the web server.
B.A DLP appliance between users and the portal.
C.A WAF in front of the application.
D.A NAC solution on the switch ports feeding the portal.
AnswerC
A web application firewall is built to inspect HTTP and HTTPS traffic at the application layer and block common web attacks such as SQL injection and XSS. It can protect a public portal without requiring code changes, making it a practical compensating control while the application team improves secure coding. This is the best fit when the goal is to stop malicious web payloads before they reach the app.
Why this answer
A Web Application Firewall (WAF) is specifically designed to inspect HTTP/HTTPS traffic at the application layer (Layer 7), filtering out malicious payloads like SQL injection and cross-site scripting (XSS) while allowing legitimate requests to pass through. Unlike an IDS, a WAF operates inline and can actively block threats without requiring modifications to the application code, making it the ideal choice for protecting a public-facing web portal.
Exam trap
The trap here is that candidates often confuse an IDS (which only detects) with a WAF (which actively blocks), or they mistakenly think a DLP appliance can filter web application attacks, when in fact DLP focuses on data in motion or at rest, not on application-layer payload inspection.
How to eliminate wrong answers
Option A is wrong because an IDS (Intrusion Detection System) is a passive monitoring device that only alerts on suspicious traffic; it cannot block malicious payloads inline or prevent attacks without additional manual intervention. Option B is wrong because a DLP (Data Loss Prevention) appliance is designed to prevent unauthorized exfiltration of sensitive data, not to inspect and filter HTTP requests for SQL injection or XSS payloads. Option D is wrong because a NAC (Network Access Control) solution controls device access to the network at the switch port level based on compliance policies, but it does not inspect application-layer traffic or block web-based attacks.
Based on the exhibit, what should the team do next after the account has been contained?
A.Close the incident because the password reset removed the attacker from the environment.
B.Remove mailbox persistence, revoke all tokens and app consent, then monitor for reentry.
C.Reimage the user's laptop before reviewing mailbox settings.
D.Restore the mailbox from backup to remove the forwarding rule and keep the user productive.
AnswerB
The exhibit shows post-compromise persistence through a forwarding rule and unauthorized OAuth consent. After containment, the team must eradicate those artifacts, revoke any remaining tokens or sessions, and verify that no attacker-controlled application retains access. That sequence moves the response from containment into eradication and prepares the account for safe recovery and monitoring.
Why this answer
After containing a compromised account (e.g., disabling it or resetting its password), the attacker may still have established persistence mechanisms such as mailbox forwarding rules, OAuth app consent grants, or session tokens that survive a password reset. Removing these artifacts and revoking all tokens and app consents ensures the attacker cannot regain access via delegated permissions or persistent mailbox rules. Monitoring for reentry is critical to detect any residual access or new compromise attempts.
Exam trap
The trap here is that candidates assume a password reset fully evicts an attacker, overlooking that OAuth tokens and mailbox rules provide persistent access independent of the account password.
How to eliminate wrong answers
Option A is wrong because a password reset alone does not remove attacker‑created mailbox forwarding rules, OAuth app grants, or session tokens; the attacker could still access the mailbox via delegated permissions or persistent rules. Option C is wrong because reimaging the user's laptop addresses local device compromise but does not remediate cloud‑based persistence like mailbox forwarding rules or app consents that exist in the tenant. Option D is wrong because restoring the mailbox from backup removes the forwarding rule but does not revoke OAuth tokens or app consents, and it may reintroduce the same rule if the backup contains the malicious configuration; it also fails to address other persistence vectors.
A financial institution updates its access control policy to require that two different system administrators must approve and execute any changes to the core transaction processing database. Which security principle is this practice primarily designed to enforce?
A.Defense in depth
B.Separation of duties
C.Least privilege
D.Need to know
AnswerB
Separation of duties is a core internal control that requires more than one person to complete a critical task or transaction. By splitting the approval and execution of access control changes between two distinct administrators, the policy ensures no single individual has the authority to unilaterally modify security settings, which significantly reduces the risk of fraud, sabotage, or unauthorized changes. This is the correct answer because the scenario explicitly describes dividing the change into approval and implementation steps, which is the hallmark of separation of duties.
Why this answer
Requiring two different system administrators to approve and execute changes to the core transaction processing database enforces separation of duties. This principle ensures that no single individual has the authority to perform both the approval and execution steps, reducing the risk of fraud, error, or unauthorized modifications. In a financial institution, this is critical for maintaining the integrity of transaction data and complying with regulatory standards like SOX or PCI DSS.
Exam trap
The trap here is that candidates confuse separation of duties with least privilege, but least privilege focuses on limiting permissions per role, while separation of duties divides a critical process across multiple roles to prevent conflicts of interest.
Why the other options are wrong
A
Defense in depth is a layered security approach using multiple controls, but the question specifically describes a dual-approval process for changes, which directly enforces separation of duties, not defense in depth.
C
The practice requires two administrators to approve and execute changes, which enforces separation of duties, not least privilege. Least privilege restricts permissions to the minimum necessary, but does not inherently require dual approval.
D
The need-to-know principle restricts access to information based on job necessity, but the question describes a process requiring two administrators to approve changes, which is about dividing responsibilities, not limiting information access.
When would these options actually be correct?
A
A question asks: 'An organization implements firewalls, intrusion detection systems, and antivirus software to protect its network. Which security principle is this an example of?' Here, defense in depth would be correct because multiple layers of defense are used.
C
A question describing a policy where a database administrator is granted only the specific permissions needed to perform their job functions, and no additional access, would make 'Least privilege' the correct answer.
D
A question asks: 'A security analyst is granted access to a database only after demonstrating a legitimate business requirement for specific records. Which principle is being enforced?' Here, need-to-know would be correct because access is limited to information necessary for the job.
Why candidates pick the wrong answer
A
Candidates may confuse the concept of multiple controls (defense in depth) with the dual-approval process, thinking that requiring two administrators is an additional layer of security, but it is actually a separation of duties mechanism.
C
Candidates may confuse the concept of limiting access (least privilege) with the procedural control of requiring multiple approvals, as both aim to reduce risk.
D
Candidates may confuse need-to-know with separation of duties because both involve restricting actions, but need-to-know focuses on information access, not task approval workflows.
A SOC analyst reviews an EDR alert on a Windows workstation. PowerShell was launched by a scheduled task, downloaded an encoded command from an external server, and then spawned rundll32.exe. No suspicious executable was written to disk. Which type of threat best fits this activity?
A.Trojan
B.Fileless attack
C.Rootkit
D.Worm
AnswerB
This is the correct classification. Fileless attacks leverage trusted system tools (e.g., PowerShell, WMI, or .NET) to execute malicious code directly in memory, avoiding writing an executable to disk. The alert's focus on in-memory execution and the absence of a dropped file are hallmarks of this technique. These attacks are particularly dangerous because they leave few forensic traces, evade signature-based detection, and often exploit legitimate administrative capabilities.
Why this answer
The attack is fileless because it executes entirely in memory without writing a malicious executable to disk. PowerShell downloads an encoded command from an external server and spawns rundll32.exe to run code via DLL execution, leveraging living-off-the-land binaries (LOLBins) to evade traditional antivirus and disk-based detection.
Exam trap
The trap here is that candidates see 'downloaded an encoded command' and assume a file was written, but the key distinction is that no executable file was written to disk, making it a fileless attack rather than a Trojan or rootkit.
How to eliminate wrong answers
Option A is wrong because a Trojan is a malicious program disguised as legitimate software that typically writes a file to disk and requires user installation, whereas this attack uses a scheduled task to launch PowerShell and never writes a suspicious executable. Option C is wrong because a rootkit is designed to hide the presence of malware or maintain privileged access by modifying the operating system kernel or boot process, which is not indicated by the PowerShell-to-rundll32 chain and lack of persistence mechanisms described.
A web form stores a user's comment and later displays it to other users. A tester submits <script>alert(1)</script> and the script runs in the browser. What vulnerability is this?
A.SQL injection
B.Cross-site request forgery
C.Cross-site scripting
D.Command injection
AnswerC
The submitted script executes in another user's browser because the comment is rendered without output encoding, which is reflected or stored cross-site scripting. The payload running client-side, rather than server-side execution, distinguishes XSS from injection flaws such as SQL injection.
Why this answer
The tester's input <script>alert(1)</script> is executed in the browser, which is the classic symptom of a stored (persistent) cross-site scripting (XSS) vulnerability. The web form fails to sanitize or encode user-supplied data before storing it and later rendering it in other users' browsers, allowing arbitrary JavaScript to run in the security context of the application's origin.
Exam trap
The trap here is that candidates may confuse XSS with SQL injection because both involve injecting malicious input, but XSS targets the browser's execution context while SQL injection targets the database query layer.
How to eliminate wrong answers
Option A is wrong because SQL injection involves injecting SQL commands into database queries (e.g., ' OR 1=1 --), not client-side script execution; the input here does not alter a database query. Option B is wrong because cross-site request forgery (CSRF) tricks a victim into performing an unintended action on an authenticated site, but the tester's input directly executes script in the browser without requiring a forged request. Option D is wrong because command injection targets server-side operating system commands (e.g., ; ls -la), not client-side JavaScript execution in the browser.
A desktop engineering team asks for the document that specifies the exact minimum encryption setting, screen-lock timer, and password length for company laptops. Which type of document should they follow?
A.Policy, because it states the organization's general intent and high-level direction.
B.Standard, because it defines mandatory uniform requirements for a specific control baseline.
C.Procedure, because it gives the organization-wide security purpose statement.
D.Guideline, because it provides optional suggestions that every laptop must obey.
AnswerB
A standard is the correct document when the organization needs a consistent, mandatory technical baseline such as encryption strength, lock timing, or password length. Standards translate policy into measurable requirements and are suitable for system configuration because they reduce ambiguity and support enforcement across similar assets.
Why this answer
A standard defines mandatory, uniform technical requirements for a specific control baseline, such as exact encryption settings (e.g., AES-256), screen-lock timer (e.g., 15 minutes), and password length (e.g., 14 characters). Unlike a policy, which states high-level intent, a standard provides the precise, enforceable configuration that the desktop engineering team must implement on company laptops.
Exam trap
The trap here is that candidates confuse 'policy' (high-level intent) with 'standard' (specific mandatory baseline), leading them to choose A when the question explicitly asks for the document that specifies exact minimum encryption, timer, and password length values.
How to eliminate wrong answers
Option A is wrong because a policy states the organization's general intent and high-level direction (e.g., 'all laptops must be secured'), but does not specify exact technical values like encryption algorithm, timer duration, or password length. Option C is wrong because a procedure describes step-by-step instructions for performing a task (e.g., how to configure BitLocker), not the mandatory baseline requirements themselves.
Based on the exhibit, what additional control is the best fit?
Current controls on the finance share:
- SMB signing enabled
- Weekly access review
- Nightly backups to immutable storage
- Antivirus scans at 02:00
Incident: a valid VPN account was used to access 40,000 files in 8 minutes and copy them to a local drive.
Goal: detect unauthorized bulk access quickly before exfiltration completes.
A.Add file access auditing with alert thresholds forwarded to the SIEM.
B.Increase the backup schedule from nightly to hourly.
C.Rename the share to a less obvious name.
D.Disable SMB signing so the file transfer runs faster.
AnswerA
File access auditing enables granular tracking of who accessed which files and when. When combined with alert thresholds (e.g., a user reading hundreds of files in minutes), the SIEM can generate real-time alerts for potential bulk data exfiltration. As a detective control, it directly addresses the missing visibility into abnormal access patterns and supports timely incident response.
Why this answer
File access auditing with alert thresholds forwarded to the SIEM directly addresses the goal of detecting unauthorized bulk access quickly. By monitoring for abnormal file access patterns—such as 40,000 files in 8 minutes—the SIEM can trigger an alert before exfiltration completes, enabling rapid response. This control complements the existing weekly access review by providing real-time detection.
Exam trap
The trap here is that candidates may confuse backup frequency (a recovery control) with detection controls, or think that obscuring the share name provides meaningful security, when the question specifically asks for a control to detect unauthorized bulk access quickly.
How to eliminate wrong answers
Option B is wrong because increasing backup frequency from nightly to hourly does not detect or prevent unauthorized bulk access; backups are a recovery control, not a detection control. Option C is wrong because renaming the share to a less obvious name is a form of security through obscurity that does not detect or alert on anomalous access patterns. Option D is wrong because disabling SMB signing would actually reduce security by removing integrity verification of SMB traffic, and it does not provide any detection capability for bulk file access.
A user receives an SMS from 'IT Service Desk' saying their MFA enrollment expires today and includes a shortened link. Five minutes later, the user gets a phone call from the same number asking them to read back the code shown in the authenticator app so the ticket can be closed. Which two attack channels are used in this campaign? Select two.
Select 2 answers
A.Email phishing is used because the attacker is requesting a login action.
B.Smishing is used because the first lure arrives by text message.
C.Vishing is used because the follow-up request occurs by phone call.
D.Baiting is used because the attacker offers a free reward or device.
E.Tailgating is used because the attacker follows someone into a restricted area.
AnswersB, C
Smishing is phishing delivered through SMS or another text-based mobile messaging channel. The fake IT Service Desk text with a shortened link is a classic example because it attempts to get the user to click a link and interact outside the normal support process.
Why this answer
The initial attack vector is an SMS message containing a shortened link, which is the definition of smishing (SMS phishing). The attacker uses this to create urgency and lure the victim into engaging with the MFA enrollment scam.
Exam trap
The trap here is that candidates may focus on the phone call as the only attack channel and overlook the initial SMS, or they may confuse smishing with vishing, not recognizing that both channels are used sequentially in a single campaign.
A security analyst receives an alert that a user clicked a link in a phishing email and entered their corporate credentials on a fake login page. Which of the following should the analyst do FIRST to minimize further damage?
A.Run a full antivirus scan on the user's workstation
B.Reset the user's password and force re-authentication
C.Disable the user's account and block the compromised system from the network
D.Contact law enforcement and report the phishing site
AnswerC
Disabling the user's account terminates the attacker's authenticated sessions and invalidates stolen credentials, while blocking the compromised system at the network layer severs any existing command-and-control, RDP, or file-transfer connections. This containment step is the immediate priority because it prevents lateral movement and data exfiltration without destroying volatile evidence on the host. In contrast to reactive scanning or password resets, isolating first gives the incident response team a clean boundary to perform forensic acquisition and threat hunting.
Why this answer
Immediately disabling the user's account and blocking the compromised system from the network stops the attacker from using the stolen credentials to authenticate to corporate resources, such as email, VPN, or file shares. This containment step is the highest priority in incident response to prevent lateral movement and further compromise, as the attacker already has valid credentials and could be actively using them.
Exam trap
The trap here is that candidates often choose to reset the password first (Option B) because it seems like a direct fix, but they fail to recognize that the compromised system itself may be under attacker control, and without network isolation, the attacker could still pivot or use other stolen credentials.
Why the other options are wrong
A
Running a full antivirus scan is a reactive step that does not immediately prevent further unauthorized access or credential misuse. The priority is to contain the breach by disabling the account and isolating the system.
B
Resetting the password and forcing re-authentication does not immediately isolate the compromised system or prevent the attacker from using the stolen credentials to access other resources before the password change takes effect.
D
Contacting law enforcement is not the first priority; immediate containment actions like disabling the account and blocking the system are needed to prevent further credential misuse.
When would these options actually be correct?
A
This would be correct if the question stated that the user's credentials were already reset and the account was secured, and the next step is to ensure the workstation is free from malware that could exfiltrate data or provide persistent access.
B
This would be correct if the question stated that the user's account was not yet compromised (e.g., the user reported the phishing email before entering credentials) and the goal is to proactively protect the account from potential misuse.
D
This option would be correct if the question asked: 'After containing the incident and preserving evidence, which of the following should the analyst do to assist in the investigation and prosecution of the attacker?'
Why candidates pick the wrong answer
A
Candidates may think that malware is the primary threat from phishing and that scanning will remove any backdoors, overlooking the immediate need to stop credential abuse.
B
Candidates often think that changing the password is the fastest way to revoke access, but they overlook the need to first disable the account and block the system to stop ongoing lateral movement or data exfiltration.
D
Candidates may think reporting the phishing site to law enforcement is a critical early step, but they overlook the need for immediate containment to stop ongoing damage.
An employee receives an email from someone claiming to be from IT. The message says the employee must read back a one-time verification code so their mailbox can be 'repaired.' What social engineering technique is being used?
A.Tailgating, because the attacker is trying to enter a secure area physically.
B.Pretexting, because the attacker is using a fake identity and story to gain trust.
C.DDoS, because the message is designed to overwhelm the mailbox server.
D.Shoulder surfing, because the attacker is watching the screen from nearby.
AnswerB
Pretexting is a social engineering technique where the attacker fabricates a scenario and adopts a trusted role—here, an IT support agent—to elicit sensitive information. The email invents a believable reason, such as account verification or troubleshooting, to lower the victim's suspicion and prompt disclosure of the one-time code. This relies on establishing false trust and exploiting the victim's willingness to comply with an authority figure, making it distinct from technical attacks.
Why this answer
The attacker is using a fabricated identity (IT support) and a false scenario (mailbox repair requiring a verification code) to manipulate the employee into divulging sensitive information. This is the classic definition of pretexting, where the attacker creates a believable pretext to lower the victim's defenses and extract data or access.
Exam trap
The trap here is that candidates confuse pretexting with phishing, but pretexting specifically relies on a fabricated scenario or identity (the 'pretext') rather than a generic lure like a malicious link or attachment.
How to eliminate wrong answers
Option A is wrong because tailgating is a physical security attack where an unauthorized person follows an authorized individual into a restricted area, not a social engineering technique involving email or phone. Option C is wrong because a DDoS (Distributed Denial of Service) attack overwhelms a server with traffic to disrupt service, not to trick a user into revealing a code. Option D is wrong because shoulder surfing involves directly observing someone's screen or keyboard from close proximity to steal information, not using a remote email message.
Based on the exhibit, what is the best change to improve accountability without removing emergency access?
A.Keep the shared account and add more logging of the shared password.
B.Require named accounts with role-based elevation through a privileged access workflow.
C.Remove all command logging to protect administrator privacy.
D.Use a single shared account with a longer password and monthly rotation.
AnswerB
This is the best answer because the issue is accountability. Shared accounts prevent the organization from knowing which person performed the actions in the log. Named accounts plus privileged elevation preserve break-glass access while ensuring each command is tied to an individual identity. That improves accounting and auditability without removing the operational ability to maintain the system.
Why this answer
Implementing named accounts with role-based elevation through a privileged access workflow (PAW) ensures each administrator has a unique identity for auditing, while still allowing temporary privilege escalation for emergency tasks. This directly improves accountability by tying actions to specific users, unlike shared accounts which obscure individual responsibility. The workflow maintains emergency access by granting time-limited elevated permissions through an approval process, avoiding permanent standing privileges.
Exam trap
The trap here is that candidates may think improving logging (Option A) or password rotation (Option D) is sufficient for accountability, but CompTIA emphasizes that shared accounts inherently lack individual attribution, regardless of how much logging or rotation is applied.
How to eliminate wrong answers
Option A is wrong because simply adding more logging to a shared account does not solve the core accountability problem—multiple users still share the same credentials, making it impossible to attribute actions to a specific individual, and logging a shared password is irrelevant to user identification. Option C is wrong because removing command logging destroys the audit trail needed for accountability and incident investigation, violating the principle of non-repudiation and security best practices. Option D is wrong because using a single shared account with a longer password and monthly rotation still lacks individual accountability; password changes do not tie actions to specific users, and emergency access remains unmanaged without a privileged access workflow.
A Linux web server was compromised through an outdated package. The team isolated the host, captured evidence, removed a malicious cron job, patched the vulnerable package, and confirmed no persistence remains. Which incident response phase are they primarily in now?
A.Identification, because the team is still confirming that the event happened.
B.Containment, because the host was isolated from the network.
C.Eradication, because malicious artifacts and the underlying weakness are being removed.
D.Lessons learned, because the server has already been secured.
AnswerC
Eradication is the incident response phase dedicated to removing the adversary's presence entirely — deleting malware, eliminating persistence mechanisms, and remediating the root cause, such as the outdated package that was exploited. The scenario's description of removing malicious artifacts and the underlying weakness directly matches this phase. Unlike containment, which merely limits damage, eradication seeks to ensure the attacker cannot easily return.
Why this answer
The team has already identified the compromise, isolated the host, and removed the malicious cron job. Patching the vulnerable package addresses the root cause, which is the core of the Eradication phase. Confirming no persistence remains verifies that the eradication was successful, making this the current phase.
Exam trap
The trap here is that candidates confuse the isolation step (Containment) with the overall phase, but the question emphasizes the removal of the malicious cron job and patching, which are definitive Eradication actions.
How to eliminate wrong answers
Option A is wrong because Identification is the initial phase where the incident is discovered and confirmed; here, the team has already moved past that to active remediation. Option B is wrong because Containment focuses on limiting damage (e.g., network isolation), which was already performed; the team is now addressing the root cause and removing artifacts. Option D is wrong because Lessons Learned occurs after recovery is complete and involves post-incident review and documentation, not active patching and artifact removal.
After a phishing incident, the security team wants to preserve evidence for later review. Which action is most appropriate?
A.Have the user delete the phishing email to avoid further exposure
B.Capture and save the email headers and message content
C.Forward the email to every employee as a warning
D.Change the user's office seat assignment immediately
AnswerB
Preserving the raw email as an .eml or .msg file, or exporting the full message with headers from the web client, gives investigators a complete, immutable artifact for analysis. The 'Received' header chains can be traced back to the originating IP and MTA path, while SPF, DKIM, and DMARC authentication results in the headers reveal whether the message was spoofed or sent from a compromised legitimate account. The message content is also vital for extracting malicious links, attachments, and other Indicators of Compromise (IOCs) and for providing the full payload context needed for detection rule creation and user awareness training.
Why this answer
Preserving the email headers and message content is essential for forensic analysis. Email headers contain routing information, including the originating IP address, authentication results (SPF, DKIM, DMARC), and timestamps, which are critical for tracing the source of the phishing attack and understanding the attack vector. Deleting or forwarding the email would destroy this evidence, compromising the investigation.
Exam trap
The trap here is that candidates may think deleting or forwarding the email is a quick fix to prevent further harm, but the exam emphasizes that evidence preservation (via capture of headers and content) is the first priority in incident response, not containment or notification.
How to eliminate wrong answers
Option A is wrong because deleting the phishing email destroys the evidence needed for forensic analysis, including headers and metadata that could identify the attacker's infrastructure. Option C is wrong because forwarding the email to all employees increases the risk of further compromise, may violate data protection policies, and alters the original message headers, potentially invalidating the evidence. Option D is wrong because changing the user's office seat assignment has no relevance to preserving digital evidence; it is a physical security measure unrelated to incident response or evidence handling.
Based on the exhibit, which access design change best reduces fraud risk without stopping the payroll process?
Exhibit:
Payroll application roles:
- HR-Editor: can update employee records
- Payroll-Approver: can release payment batches
- Audit-Reader: can view reports only
Current assignment:
User Lisa has both HR-Editor and Payroll-Approver because she "handles payroll end to end."
Management wants to reduce the chance of one person creating and approving a fraudulent payment.
A.Keep both roles assigned but require a manager to review the batch after payment completes.
B.Split duties so record updates and payment approval require separate roles or separate accounts.
C.Remove the audit role and let payroll staff self-review their own work to save time.
D.Use a single shared payroll account so the workflow never pauses for approvals.
AnswerB
This is the best design because it enforces separation of duties, which directly reduces fraud risk. The same person should not be able to create a payment and approve it without independent review. Separate roles or accounts preserve workflow continuity while making collusion or abuse harder, and they provide a cleaner audit trail for accountability.
Why this answer
It enforces separation of duties (SoD) by ensuring that no single user can both create and approve a payment. Splitting the HR-Editor and Payroll-Approver roles into separate accounts or requiring separate users for record updates and payment approval directly mitigates the fraud risk of a single insider creating a fake employee record and then approving a fraudulent payment batch. This aligns with the principle of least privilege and the NIST SP 800-53 AC-5 control for separation of duties, without halting the payroll workflow.
Exam trap
The trap here is that candidates may choose a detective control (like post-payment review) thinking it reduces risk, but the question specifically asks for a change that 'best reduces fraud risk' without stopping the process, and only a preventive control like separation of duties directly addresses the root cause of the conflict of interest.
How to eliminate wrong answers
Option A is wrong because requiring a manager to review the batch after payment completes is a detective control, not a preventive one; fraud could already occur before the review, and the review may be missed or bypassed. Option C is wrong because removing the audit role and letting payroll staff self-review eliminates independent oversight, increasing fraud risk rather than reducing it. Option D is wrong because using a single shared payroll account removes all individual accountability and audit trails, making it impossible to attribute actions to a specific user and actually increasing fraud risk.
A security architect is designing a solution to process highly sensitive financial transactions in a shared cloud environment. The architect needs to ensure that the processor and memory used to handle transaction data are isolated from the host operating system and other virtual machines, even if the hypervisor is compromised. Which technology is specifically designed to provide this level of isolation for code and data during runtime?
A.Trusted Platform Module (TPM)
B.Hardware Security Module (HSM)
C.Secure enclave (e.g., Intel SGX)
D.UEFI Secure Boot
AnswerC
A secure enclave, such as Intel Software Guard Extensions (SGX), creates hardware-enforced encrypted regions of memory that protect code and data from access by the host OS, hypervisor, or other processes, even if those lower layers are compromised.
Why this answer
Secure enclave technology, such as Intel SGX, provides hardware-enforced isolation by creating trusted execution environments (TEEs) within the CPU. Code and data inside an enclave are encrypted in memory and decrypted only within the processor, ensuring that even a compromised hypervisor or host OS cannot access the transaction data during runtime. This meets the requirement for processor and memory isolation in a shared cloud environment.
Exam trap
The trap here is that candidates often confuse a TPM or HSM with runtime memory isolation, but those technologies focus on storage and cryptographic operations, not on protecting code and data during active execution in a compromised hypervisor environment.
Why the other options are wrong
A
TPM provides hardware-based key storage and attestation but does not isolate runtime code and memory from the host OS or hypervisor. It cannot protect data during processing in a shared cloud environment.
B
An HSM provides hardware-based protection for cryptographic keys and operations, but it does not isolate the processor and memory used to run code and data during runtime from the host OS or hypervisor. It is a peripheral device, not a runtime execution environment.
D
UEFI Secure Boot ensures that only signed firmware and bootloaders execute during system startup, but it does not provide runtime isolation for code and data in memory or CPU. It cannot protect against a compromised hypervisor or isolate transaction processing from the host OS.
When would these options actually be correct?
A
A question asking for a hardware root of trust to verify platform integrity at boot time, or to securely store encryption keys and perform platform attestation, would have TPM as the correct answer.
B
A question asking for a dedicated hardware device to securely store cryptographic keys and perform cryptographic operations (e.g., signing, encryption) for a payment processing system, especially when compliance with standards like FIPS 140-2 is required.
D
A question asks: 'Which technology prevents unauthorized operating systems or bootkits from loading during the boot process on a secure system?' In that context, UEFI Secure Boot is the correct answer because it verifies digital signatures of boot components.
Why candidates pick the wrong answer
A
Candidates may confuse TPM's hardware security capabilities with runtime isolation, assuming that any hardware security module can protect data during processing, not just at rest or in transit.
B
Candidates may confuse HSM's hardware security with runtime isolation, assuming that any 'hardware security' module protects code and data execution, not just key storage and crypto operations.
D
Candidates may confuse boot-time integrity with runtime isolation, or think that Secure Boot extends to protect applications during execution, not just the boot chain.
HR stores scanned government IDs collected during onboarding. The retention policy says the files may be kept for 90 days after employment verification, then destroyed. What should security require?
A.Keep the files indefinitely in case a future audit asks for them
B.Move the files to a shared folder so more HR staff can access them
C.Store the files in an encrypted repository and securely dispose of them when retention expires
D.Print the scanned IDs and place them in a locked cabinet instead of keeping digital copies
AnswerC
This is the best answer because it matches the retention schedule and protects sensitive personal data. Encryption reduces exposure while the files are needed, and secure disposal after the retention period supports privacy, legal compliance, and data minimization. The process should also be auditable so the organization can prove it is following its handling requirements.
Why this answer
It aligns with the principle of data minimization and the retention policy: storing scanned government IDs in an encrypted repository ensures confidentiality and integrity, while secure disposal after the 90-day retention period meets compliance requirements (e.g., GDPR, HIPAA) and reduces risk of data breaches. Security must enforce both protection during storage and timely destruction to prevent unauthorized access or legal liability.
Exam trap
The trap here is that candidates may choose indefinite retention (Option A) thinking it helps with audits, but security requires compliance with the stated retention policy, not hoarding data.
How to eliminate wrong answers
Option A is wrong because keeping files indefinitely violates the retention policy and increases exposure to data breaches, legal non-compliance, and storage costs without a security justification. Option B is wrong because moving files to a shared folder broadens access without need, increasing the attack surface and risk of unauthorized disclosure, while ignoring encryption and retention controls. Option D is wrong because printing scanned IDs creates physical copies that are harder to track, secure, and destroy reliably, and it introduces new risks like loss, theft, or improper disposal, while digital encryption and secure deletion are more auditable and compliant.
A SIEM alert shows a payroll administrator account signed in at 02:10 from a country the employee has never visited. The employee says they are on vacation at home and did not travel. What should the analyst do first?
A.Immediately disable the account and wait for the employee to return.
B.Verify the login context with the user or manager and review recent authentication history.
C.Close the alert as a false positive because the user is on vacation.
D.Reimage the user’s workstation before checking any logs.
AnswerB
This is the best first step because alert triage should confirm whether the activity is truly suspicious before disruptive action is taken. Reviewing the user’s normal login patterns, recent sign-in history, and whether a VPN or travel exception exists helps distinguish a real compromise from an unusual but legitimate event. Good triage reduces unnecessary outages and focuses response effort appropriately.
Why this answer
The first step in incident response is to verify the alert's validity and gather context before taking action. The analyst should review the SIEM logs for authentication details (e.g., source IP, geolocation, timestamp) and confirm with the user or manager whether the login was expected. This aligns with the NIST SP 800-61 incident response process, which emphasizes triage and validation before containment.
Exam trap
The trap here is that candidates may jump to containment (disabling the account) or dismissal (false positive) without performing the critical triage step of verifying the login context, which the exam emphasizes as the first action in the incident response process.
How to eliminate wrong answers
Option A is wrong because immediately disabling the account without verification could lock out a legitimate user and disrupt operations, violating the principle of least disruption during initial triage. Option C is wrong because closing the alert as a false positive without investigation ignores the possibility of credential theft or a compromised session, which is a common attack vector. Option D is wrong because reimaging the workstation is a drastic containment step that should only occur after confirming a compromise; it bypasses necessary log analysis and could destroy forensic evidence.
NetFlow and authentication logs show one workstation opening SMB and WinRM sessions to many internal hosts within ten minutes. The same source also generates a sharp rise in Kerberos service-ticket requests and attempts to access administrative shares. Which three observations most strongly support lateral movement rather than normal admin activity? Select three.
Select 3 answers
A.A rapid burst of SMB and WinRM connections to many internal systems from one source host.
B.A sharp increase in Kerberos service-ticket requests from the same workstation.
C.Repeated attempts to access administrative shares such as ADMIN$ or C$.
D.Regular outbound DNS lookups for common internet services like time synchronization or content delivery.
E.A successful sign-in to the user's cloud email account from the employee's home network at lunchtime.
AnswersA, B, C
A sudden fan-out of administrative protocols from one workstation is a classic sign of lateral movement. Normal admin activity is usually more targeted and scheduled. A burst like this suggests an automated attempt to enumerate, authenticate, or execute remotely across the environment.
Why this answer
A rapid burst of SMB and WinRM connections from a single workstation to many internal hosts is a classic indicator of lateral movement. Normal administrative activity typically involves targeted, sequential connections to specific systems for maintenance, not a broad, automated sweep. This pattern suggests an attacker using tools like PsExec or PowerShell remoting to propagate across the network.
Exam trap
The trap here is that candidates may confuse normal administrative tasks with malicious lateral movement, but the key differentiator is the rapid, broad, and automated nature of the connections, combined with the specific targeting of administrative shares and Kerberos ticket requests, which are not typical for routine admin work.
Based on the exhibit, which item is the strongest evidence that quarterly privileged access reviews occurred?
A.SIEM export of administrator logins.
B.Signed access review spreadsheet with reviewer, date, and exceptions.
C.Help desk ticket for a password reset.
D.Screenshot of the access review policy.
AnswerB
A signed access review spreadsheet with the reviewer's name, the date, and listed exceptions is direct evidence that the quarterly privileged access review control was actually performed. It ties the review to a responsible individual, establishes a clear audit trail of when the review occurred, and documents that exceptions were identified and adjudicated. This is the strongest proof because it is a discrete, retained artifact that demonstrates both the process and its outcome.
Why this answer
A signed access review spreadsheet with reviewer, date, and exceptions provides direct, non-repudiable evidence that a formal review of privileged access was completed. Unlike logs or policies, it explicitly documents the reviewer's identity, the date of review, and any exceptions, satisfying audit requirements for quarterly privileged access reviews.
Exam trap
The trap here is that candidates mistake evidence of activity (like login logs) or policy existence for evidence of a completed review process, overlooking the need for documented attestation with reviewer identity and date.
How to eliminate wrong answers
Option A is wrong because a SIEM export of administrator logins only shows that logins occurred, not that a formal review of those accounts' access rights was performed; it lacks reviewer attestation and exception documentation. Option C is wrong because a help desk ticket for a password reset is an operational event unrelated to the periodic review of privileged access entitlements. Option D is wrong because a screenshot of the access review policy only proves the policy exists, not that it was actually followed or that a review occurred.
A security engineer is designing a Zero Trust architecture for a company that has a mix of on-premises and cloud resources. The engineer needs to implement controls that align with the core principles of Zero Trust. Which of the following are core principles of Zero Trust? (Choose two.)
Select 2 answers
A.Rely on network perimeter defenses
B.Trust but verify
C.Use least privilege access
D.Assume breach and verify explicitly
E.Implement single sign-on (SSO) for all users
AnswersC, D
Least privilege access is a core Zero Trust principle that limits user and device access to only what is necessary to perform their tasks. This minimizes the potential blast radius of a compromise. In Zero Trust, permissions are granted just-in-time and just-enough, and are continuously evaluated. This principle is explicitly part of the Zero Trust model as defined by NIST and other frameworks.
Why this answer
Zero Trust is built on principles such as verify explicitly, use least privilege access, and assume breach. These ensure that no entity is trusted by default and that access is continuously evaluated. Trust but verify, perimeter reliance, and SSO are not core principles; they either contradict Zero Trust or are implementation details that may support it but are not foundational requirements.
Exam trap
The trap here is selecting 'trust but verify' because it sounds similar, but Zero Trust actually requires 'never trust, always verify'.
A SIEM reviews VPN authentication logs and sees 36 different usernames each receive one failed login attempt from the same source IP over 20 minutes, followed by one successful login to an unrelated account. Which attack is most likely?
A.Password spraying against many accounts with a low number of attempts per account.
B.A brute-force attack focused on a single locked account.
C.A replay attack using captured authentication data.
D.A port scan that accidentally triggered authentication failures.
AnswerA
The observed pattern is classic password spraying: an attacker tries one or two common passwords (e.g., 'Company123' or 'Winter2024') against 36 distinct usernames, spacing attempts to stay below lockout thresholds. Because each account sees only a single failure, no account locks, and the attack spreads horizontally rather than hammering one user. A SIEM would see many different users with one failed VPN authentication each, exactly matching this low-and-slow credential-stuffing variation.
Why this answer
The SIEM observed 36 different usernames each receiving one failed login attempt from the same source IP over 20 minutes, followed by one successful login to an unrelated account. This pattern is characteristic of a password spraying attack, where an attacker tries a small number of common passwords against many accounts to avoid account lockout thresholds, and then uses a successful credential to pivot to another account. The low number of attempts per account (one each) and the wide spread of usernames distinguish it from brute-force or targeted attacks.
Exam trap
The trap here is that candidates often confuse password spraying with brute-force attacks, but the key differentiator is the distribution of attempts across many accounts versus many attempts on a single account.
How to eliminate wrong answers
Option B is wrong because a brute-force attack focused on a single locked account would show many failed attempts against that one username, not one attempt each across 36 different usernames. Option C is wrong because a replay attack would involve capturing and reusing valid authentication data (e.g., a Kerberos ticket or NTLM hash), not generating new failed login attempts from a source IP. Option D is wrong because a port scan does not generate authentication failures; it probes for open ports using TCP SYN or UDP packets, and any authentication failures would be coincidental and not follow a pattern of one attempt per username.