Courseiva
` into a public comment field, and other visitors see the script run in the…","url":"https://courseiva.com/questions/comptia/security-plus/a-user-enters-alert-test-into-a-public-comment-field-and-other"},{"@type":"ListItem","position":96,"name":"Which two statements describe authorization? Select two.","url":"https://courseiva.com/questions/comptia/security-plus/which-two-statements-describe-authorization-select-two"},{"@type":"ListItem","position":97,"name":"Your company is syncing design files to a cloud object store. The security team wants to reduce risk if the storage acco…","url":"https://courseiva.com/questions/comptia/security-plus/your-company-is-syncing-design-files-to-a-cloud-object-store-the"},{"@type":"ListItem","position":98,"name":"An ERP database is backed up nightly to a NAS that remains online and is managed with the same admin group as production…","url":"https://courseiva.com/questions/comptia/security-plus/an-erp-database-is-backed-up-nightly-to-a-nas-that-remains"},{"@type":"ListItem","position":99,"name":"A restricted server room opens only with a badge, and an alarm sounds if the door is left open too long. Which control t…","url":"https://courseiva.com/questions/comptia/security-plus/a-restricted-server-room-opens-only-with-a-badge-and-an-alarm"},{"@type":"ListItem","position":100,"name":"A support team wants to export customer tickets into a test analytics environment so developers can search real examples…","url":"https://courseiva.com/questions/comptia/security-plus/a-support-team-wants-to-export-customer-tickets-into-a-test"},{"@type":"ListItem","position":101,"name":"A security analyst is reviewing authentication logs from a corporate web application. The logs show thousands of failed …","url":"https://courseiva.com/questions/comptia/security-plus/a-security-analyst-is-reviewing-authentication-logs-from-a"},{"@type":"ListItem","position":102,"name":"Drag and drop the steps to perform a factory reset on a managed switch into the correct order.","url":"https://courseiva.com/questions/comptia/security-plus/drag-and-drop-the-steps-to-perform-a-factory-reset-on-a-mana-c0yk5"},{"@type":"ListItem","position":103,"name":"A security analyst observes a pattern where an account exhibits multiple failed login attempts from an IP address in a f…","url":"https://courseiva.com/questions/comptia/security-plus/a-security-analyst-observes-a-pattern-where-an-account-exhibits"},{"@type":"ListItem","position":104,"name":"Drag and drop the steps for a typical digital forensics investigation process in the correct order.","url":"https://courseiva.com/questions/comptia/security-plus/drag-and-drop-the-steps-for-a-typical-digital-forensics-inve-i8eh0"},{"@type":"ListItem","position":105,"name":"An organization is implementing a third-party vendor risk management program. Which three of the following should be inc…","url":"https://courseiva.com/questions/comptia/security-plus/an-organization-is-implementing-a-third-party-vendor-risk-management-program-whi-jxy5dddv"},{"@type":"ListItem","position":106,"name":"Based on the exhibit, what network attack is most likely occurring on the office LAN?","url":"https://courseiva.com/questions/comptia/security-plus/based-on-the-exhibit-what-network-attack-is-most-likely"},{"@type":"ListItem","position":107,"name":"Based on the exhibit, what should be implemented to reduce the blast radius if a backup server is compromised later?\r\n\r\n…","url":"https://courseiva.com/questions/comptia/security-plus/based-on-the-exhibit-what-should-be-implemented-to-reduce-the"},{"@type":"ListItem","position":108,"name":"Based on the exhibit, what is the best fix so role changes are reflected promptly in the application?\r\n\r\nToken and direc…","url":"https://courseiva.com/questions/comptia/security-plus/based-on-the-exhibit-what-is-the-best-fix-so-role-changes-are"},{"@type":"ListItem","position":109,"name":"Match each security principle to the best description.","url":"https://courseiva.com/questions/comptia/security-plus/match-each-security-principle-to-the-best-description"},{"@type":"ListItem","position":110,"name":"A security tool reports repeated DNS requests for long, random-looking subdomains under the same domain name. What is th…","url":"https://courseiva.com/questions/comptia/security-plus/a-security-tool-reports-repeated-dns-requests-for-long-random"},{"@type":"ListItem","position":111,"name":"Match the security need to the best cryptographic solution.","url":"https://courseiva.com/questions/comptia/security-plus/match-the-security-need-to-the-best-cryptographic-solution"},{"@type":"ListItem","position":112,"name":"Based on the exhibit, what change would best protect the password database against precomputed attacks and make identica…","url":"https://courseiva.com/questions/comptia/security-plus/based-on-the-exhibit-what-change-would-best-protect-the-password"},{"@type":"ListItem","position":113,"name":"A SaaS portal issues signed JWTs in a browser cookie. The help desk confirms a user logged out at 09:10, but SIEM logs s…","url":"https://courseiva.com/questions/comptia/security-plus/a-saas-portal-issues-signed-jwts-in-a-browser-cookie-the-help"},{"@type":"ListItem","position":114,"name":"After restoring a virtual file server from last night’s backup, users can browse shares, but finance reports that severa…","url":"https://courseiva.com/questions/comptia/security-plus/after-restoring-a-virtual-file-server-from-last-night-s-backup"},{"@type":"ListItem","position":115,"name":"A small enterprise is rebuilding its public customer portal. The web front end must be reachable from the internet, the …","url":"https://courseiva.com/questions/comptia/security-plus/a-small-enterprise-is-rebuilding-its-public-customer-portal-the"},{"@type":"ListItem","position":116,"name":"Based on the exhibit, what control type is the file integrity monitor providing?","url":"https://courseiva.com/questions/comptia/security-plus/based-on-the-exhibit-what-control-type-is-the-file-integrity"},{"@type":"ListItem","position":117,"name":"EDR alerts show a finance laptop spawning an unsigned executable from %AppData%, attempting to read LSASS memory, and ma…","url":"https://courseiva.com/questions/comptia/security-plus/edr-alerts-show-a-finance-laptop-spawning-an-unsigned-executable"},{"@type":"ListItem","position":118,"name":"A business owner asks the security team to compare the cost of two controls for a legacy application in dollar terms. Th…","url":"https://courseiva.com/questions/comptia/security-plus/a-business-owner-asks-the-security-team-to-compare-the-cost-of"},{"@type":"ListItem","position":119,"name":"A vulnerability scanner reports a critical issue on a Linux server. The administrator checks the application and confirm…","url":"https://courseiva.com/questions/comptia/security-plus/a-vulnerability-scanner-reports-a-critical-issue-on-a-linux"},{"@type":"ListItem","position":120,"name":"The email security team receives a suspicious invoice attachment from a vendor. The attachment is not blocked by signatu…","url":"https://courseiva.com/questions/comptia/security-plus/the-email-security-team-receives-a-suspicious-invoice-attachment"},{"@type":"ListItem","position":121,"name":"A firewall rule was changed in production to allow a new vendor IP range, and payroll users immediately lost access to a…","url":"https://courseiva.com/questions/comptia/security-plus/a-firewall-rule-was-changed-in-production-to-allow-a-new-vendor"},{"@type":"ListItem","position":122,"name":"A nightly patch script restarts services on 40 Linux servers. Security does not want an administrator to log in interact…","url":"https://courseiva.com/questions/comptia/security-plus/a-nightly-patch-script-restarts-services-on-40-linux-servers"},{"@type":"ListItem","position":123,"name":"Based on the exhibit, which change best improves accountability while still allowing emergency access?\r\n\r\nA finance team…","url":"https://courseiva.com/questions/comptia/security-plus/based-on-the-exhibit-which-change-best-improves-accountability"},{"@type":"ListItem","position":124,"name":"An internal finance application has an RTO of 2 hours and an RPO of 30 minutes. Current backups restore in about 6 hours…","url":"https://courseiva.com/questions/comptia/security-plus/an-internal-finance-application-has-an-rto-of-2-hours-and-an-rpo"},{"@type":"ListItem","position":125,"name":"Match each audit request to the best evidence artifact.\r\n1. Auditors want proof that managers reviewed privileged access…","url":"https://courseiva.com/questions/comptia/security-plus/match-each-audit-request-to-the-best-evidence-artifact-1"},{"@type":"ListItem","position":126,"name":"A marketing analyst asks for a spreadsheet containing customer names, email addresses, purchase history, and government …","url":"https://courseiva.com/questions/comptia/security-plus/a-marketing-analyst-asks-for-a-spreadsheet-containing-customer"},{"@type":"ListItem","position":127,"name":"An investigator needs a copy of a suspect laptop drive for analysis without changing the original media. What should be …","url":"https://courseiva.com/questions/comptia/security-plus/an-investigator-needs-a-copy-of-a-suspect-laptop-drive-for"},{"@type":"ListItem","position":128,"name":"Employees in a server room often prop the door open while carrying equipment. What control best helps detect and prevent…","url":"https://courseiva.com/questions/comptia/security-plus/employees-in-a-server-room-often-prop-the-door-open-while"},{"@type":"ListItem","position":129,"name":"An HR analyst must share a spreadsheet with an external auditor. The spreadsheet includes employee names, Social Securit…","url":"https://courseiva.com/questions/comptia/security-plus/an-hr-analyst-must-share-a-spreadsheet-with-an-external-auditor"},{"@type":"ListItem","position":130,"name":"A SIEM alert shows five failed logins to a SaaS admin portal from one IP, followed by a successful login from a new city…","url":"https://courseiva.com/questions/comptia/security-plus/a-siem-alert-shows-five-failed-logins-to-a-saas-admin-portal"},{"@type":"ListItem","position":131,"name":"A help desk manager wants sample customer tickets copied into a test environment so developers can reproduce support iss…","url":"https://courseiva.com/questions/comptia/security-plus/a-help-desk-manager-wants-sample-customer-tickets-copied-into-a"},{"@type":"ListItem","position":132,"name":"A customer service application shows the same session ID being used from two countries within five minutes. The legitima…","url":"https://courseiva.com/questions/comptia/security-plus/a-customer-service-application-shows-the-same-session-id-being"},{"@type":"ListItem","position":133,"name":"A security analyst receives reports that several employees are being redirected to a fraudulent login page after typing …","url":"https://courseiva.com/questions/comptia/security-plus/a-security-analyst-receives-reports-that-several-employees-are"},{"@type":"ListItem","position":134,"name":"An investigator must collect data from a suspected insider-threat laptop so the evidence could be used in an HR and lega…","url":"https://courseiva.com/questions/comptia/security-plus/an-investigator-must-collect-data-from-a-suspected-insider"},{"@type":"ListItem","position":135,"name":"Based on the exhibit, what wireless threat is most likely occurring?","url":"https://courseiva.com/questions/comptia/security-plus/based-on-the-exhibit-what-wireless-threat-is-most-likely"},{"@type":"ListItem","position":136,"name":"A laptop repeatedly starts with an unapproved bootloader, and the security team wants the firmware to refuse boot code t…","url":"https://courseiva.com/questions/comptia/security-plus/a-laptop-repeatedly-starts-with-an-unapproved-bootloader-and-the"},{"@type":"ListItem","position":137,"name":"During morning SIEM review, an analyst sees 37 failed SSH logins followed by a successful login to a Linux server from a…","url":"https://courseiva.com/questions/comptia/security-plus/during-morning-siem-review-an-analyst-sees-37-failed-ssh-logins"},{"@type":"ListItem","position":138,"name":"A department identifies a low-likelihood software risk that would be expensive to fix right now. Leadership decides the …","url":"https://courseiva.com/questions/comptia/security-plus/a-department-identifies-a-low-likelihood-software-risk-that"},{"@type":"ListItem","position":139,"name":"Based on the exhibit, which governance artifact is the security team reviewing?","url":"https://courseiva.com/questions/comptia/security-plus/based-on-the-exhibit-which-governance-artifact-is-the-security"},{"@type":"ListItem","position":140,"name":"A supplier tells your company it wants to use a new subcontractor to process customer data. What is the BEST contract co…","url":"https://courseiva.com/questions/comptia/security-plus/a-supplier-tells-your-company-it-wants-to-use-a-new"},{"@type":"ListItem","position":141,"name":"A procurement team is evaluating a payroll SaaS vendor. They want independent evidence that the vendor's controls were d…","url":"https://courseiva.com/questions/comptia/security-plus/a-procurement-team-is-evaluating-a-payroll-saas-vendor-they-want"},{"@type":"ListItem","position":142,"name":"A small company is deploying a public web application with a front-end server, an API server, and a database. The web se…","url":"https://courseiva.com/questions/comptia/security-plus/a-small-company-is-deploying-a-public-web-application-with-a"},{"@type":"ListItem","position":143,"name":"A SOC analyst is investigating an alert triggered when a user clicked a link in an email. The email appeared to be from …","url":"https://courseiva.com/questions/comptia/security-plus/a-soc-analyst-is-investigating-an-alert-triggered-when-a-user"},{"@type":"ListItem","position":144,"name":"A team is deploying a containerized API to a public cloud. The service must be reachable only by internal corporate appl…","url":"https://courseiva.com/questions/comptia/security-plus/deploying-a-containerized-api-to-a-public-cloud-the-service-must"},{"@type":"ListItem","position":145,"name":"A workstation is suspected of malware infection, and it is still powered on and connected to the network. Which action b…","url":"https://courseiva.com/questions/comptia/security-plus/suspected-of-malware-infection-and-it-is-still-powered-on-and"},{"@type":"ListItem","position":146,"name":"Based on the exhibit, which system should be restored first after a total site outage?","url":"https://courseiva.com/questions/comptia/security-plus/based-on-the-exhibit-which-system-should-be-restored-first-after"},{"@type":"ListItem","position":147,"name":"Leadership wants to compare two controls for protecting a customer portal. Option A costs $40,000 and reduces annual los…","url":"https://courseiva.com/questions/comptia/security-plus/leadership-wants-to-compare-two-controls-for-protecting-a"},{"@type":"ListItem","position":148,"name":"Users on one VLAN report that their traffic to the default gateway is intermittently slow and sometimes reaches the wron…","url":"https://courseiva.com/questions/comptia/security-plus/users-on-one-vlan-report-that-their-traffic-to-the-default"},{"@type":"ListItem","position":149,"name":"An attacker calls the service desk claiming to be a traveling contractor whose phone was stolen. They know the contracto…","url":"https://courseiva.com/questions/comptia/security-plus/an-attacker-calls-the-service-desk-claiming-to-be-a-traveling"},{"@type":"ListItem","position":150,"name":"After installing a free utility from an unofficial website, a user's laptop starts quietly sending browsing data to an u…","url":"https://courseiva.com/questions/comptia/security-plus/after-installing-a-free-utility-from-an-unofficial-website-a"}]}` into a public comment field, and other visitors see the script run in their browsers. What attack is this?","url":"https://courseiva.com/questions/comptia/security-plus/a-user-enters-alert-test-into-a-public-comment-field-and-other","acceptedAnswer":{"@type":"Answer","text":"Cross-site scripting","comment":{"@type":"Comment","text":"Cross-site scripting (XSS) occurs when an application includes unvalidated user-supplied data in a web page, allowing attacker-controlled script to execute in the context of any victim's browser. In stored XSS, the malicious payload is permanently saved—such as in a comment field—and then served to every subsequent visitor. The 'alert' confirms script execution; an attacker could instead steal session cookies or perform actions on behalf of the user. This is the textbook explanation for why this is correct."}},"suggestedAnswer":[{"@type":"Answer","text":"SQL injection","comment":{"@type":"Comment","text":"SQL injection targets the database layer by inserting or modifying SQL commands through input fields, typically via query string parameters or form data. This input is interpreted as a database query, not as browser-rendered script. The comment field's text is stored and then served as HTML/JavaScript to clients, causing execution in the browser. While SQL injection can also access data, the specified behavior—executing 'alert' in a page—is exclusively a browser-side scripting issue, not a database attack."}},{"@type":"Answer","text":"Broken authentication","comment":{"@type":"Comment","text":"Broken authentication is a server-side vulnerability that encompasses flaws in login mechanisms, session token generation, and password recovery processes. It does not involve client-side script execution. Even if the comment system had broken authentication, the submitted text would not run as code in a browser simply because of that weakness. The observed behavior is a browser rendering and executing input, which points to XSS rather than an auth flaw."}},{"@type":"Answer","text":"Insecure deserialization","comment":{"@type":"Comment","text":"Insecure deserialization is a server-side vulnerability where untrusted data is deserialized into objects, allowing attackers to manipulate application logic or achieve remote code execution at the application server. It does not involve storing user text that later executes in another user's browser. The comment field scenario is a classic stored XSS attack, where the script runs in the client's browser due to inadequate output encoding. Entering text that triggers a JavaScript alert on page load is in no way related to object deserialization pipelines."}}]},{"@context":"https://schema.org","@type":"Quiz","name":"Which two statements describe authorization? Select two.","url":"https://courseiva.com/questions/comptia/security-plus/which-two-statements-describe-authorization-select-two","acceptedAnswer":{"@type":"Answer","text":"It determines what a user can access after sign-in","comment":{"@type":"Comment","text":"Authorization is the phase of access control that maps an authenticated identity to specific permissions, roles, or policy rules, thereby defining what resources, functions, or data that identity may use. It occurs after authentication because the system must first establish who the user is before it can apply any access decisions. Common implementations include role-based access control (RBAC), attribute-based access control (ABAC), and discretionary access control (DAC), all of which determine the scope of a user's post-login activity."}},"suggestedAnswer":[{"@type":"Answer","text":"It proves a user is who they claim to be","comment":{"@type":"Comment","text":"That describes authentication, not authorization. Authentication verifies identity using something the user knows, has, or is, such as a password, token, or biometric factor; authorization comes later and decides what that authenticated identity can access."}},{"@type":"Answer","text":"It records every packet a device sends","comment":{"@type":"Comment","text":"Recording every packet a device sends is a function of accounting, logging, or network monitoring, not authorization. Authorization is a decision-making process that grants or denies access based on permissions and policies; it does not capture or store traffic data. While accounting in the AAA framework tracks user actions for auditing or billing purposes, that is a separate step from determining what a user is allowed to do. Confusing packet capture with authorization misidentifies the distinct roles of access control versus activity logging."}},{"@type":"Answer","text":"It replaces the need for authentication","comment":{"@type":"Comment","text":"Authorization cannot replace authentication because the system must first establish who the user is before it can apply permissions. Access control rules depend on an authenticated identity, such as a user account or service principal."}}]},{"@context":"https://schema.org","@type":"Quiz","name":"Your company is syncing design files to a cloud object store. The security team wants to reduce risk if the storage account is stolen and also protect the files while they travel across the internet. ","url":"https://courseiva.com/questions/comptia/security-plus/your-company-is-syncing-design-files-to-a-cloud-object-store-the","acceptedAnswer":{"@type":"Answer","text":"Encrypt data in transit with TLS and enable encryption at rest with managed keys.","comment":{"@type":"Comment","text":"Correct. TLS protects the files while they move across the network, and encryption at rest protects stored objects if the storage account or media is exposed. Using managed keys also reduces key-handling mistakes and keeps the protection aligned with standard cloud security practices. This combination addresses both major exposure points in the scenario."}},"suggestedAnswer":[{"@type":"Answer","text":"Password-protect each archive and upload it over plain HTTP.","comment":{"@type":"Comment","text":"Password-protecting archives and transmitting them over plain HTTP leaves data vulnerable in two ways: the archive password is often weak or reused, and the HTTP session can be intercepted, allowing attackers to capture the encrypted file and perform offline password attacks. Even with a strong password, plain HTTP lacks the integrity and authenticity guarantees of TLS, and the protection vanishes if the password is compromised or shared. This approach fails to satisfy cloud security standards for both in-transit and at-rest encryption."}},{"@type":"Answer","text":"Rename the files before upload so attackers cannot identify them.","comment":{"@type":"Comment","text":"Renaming files before upload is a form of security through obscurity; it does not encrypt the content, so anyone who gains access to the storage bucket or discovers the object URLs can still read the files. Attackers can enumerate object names or exploit misconfigured access policies, and metadata such as file hashes and sizes remains exposed. True confidentiality requires cryptographic protection like encryption at rest, not hidden filenames."}},{"@type":"Answer","text":"Place the storage service on a private IP address and skip encryption.","comment":{"@type":"Comment","text":"Placing the storage service on a private IP address limits network exposure, but it does not safeguard data once it is stored; unencrypted objects remain readable if the underlying storage volume is physically stolen, misconfigured into a public policy, or if an attacker gains access to a VM within the same VPC or pod. Traffic on the private network may still traverse shared infrastructure, and without TLS, an attacker with network position can intercept it. Encryption at rest and in transit are mandatory for protecting data, regardless of network addressing."}}]},{"@context":"https://schema.org","@type":"Quiz","name":"An ERP database is backed up nightly to a NAS that remains online and is managed with the same admin group as production servers. After a ransomware incident, management wants the most effective chang","url":"https://courseiva.com/questions/comptia/security-plus/an-erp-database-is-backed-up-nightly-to-a-nas-that-remains","acceptedAnswer":{"@type":"Answer","text":"Use an offline or immutable backup copy and perform regular restore tests.","comment":{"@type":"Comment","text":"An offline or immutable backup reduces the chance that ransomware can encrypt or delete recovery data, and restore testing proves that the backups actually work. This combination improves resilience more effectively than simply storing more data on the same always-online system."}},"suggestedAnswer":[{"@type":"Answer","text":"Increase the NAS capacity so more backup jobs can be stored.","comment":{"@type":"Comment","text":"Expanding NAS capacity only extends the retention window, letting more nightly jobs accumulate on the same always-online storage system. It provides no isolation, immutability, or access control change, so ransomware that compromises the NAS or the backup account can still encrypt or delete every stored copy. Storage growth also does nothing to verify that any backup can actually be restored, so recovery confidence remains unchanged."}},{"@type":"Answer","text":"Add another full backup each night to create more copies on the same NAS.","comment":{"@type":"Comment","text":"Adding a second nightly full backup onto the same NAS creates redundant copies but leaves them in the same trust domain and failure domain as the original. A single ransomware event that encrypts the share, a corrupted volume, or a compromised backup credential will destroy both copies simultaneously, so the blast radius is unchanged. It also remains unverified because no restore testing is performed, meaning the organization cannot prove the data is recoverable."}},{"@type":"Answer","text":"Compress the backup files to reduce network usage during the nightly job.","comment":{"@type":"Comment","text":"Compressing the backup stream reduces bandwidth consumption and storage footprint, which is purely an efficiency optimization for the nightly job. It does not alter the backup's exposure on the network, add immutability, or restrict who can access the NAS, so ransomware can still encrypt the compressed files just as easily as uncompressed ones. Because compression also lacks any integrity or restore verification, it provides no assurance that the compressed data is usable after an incident."}}]},{"@context":"https://schema.org","@type":"Quiz","name":"A restricted server room opens only with a badge, and an alarm sounds if the door is left open too long. Which control type is the alarm?","url":"https://courseiva.com/questions/comptia/security-plus/a-restricted-server-room-opens-only-with-a-badge-and-an-alarm","acceptedAnswer":{"@type":"Answer","text":"Detective control","comment":{"@type":"Comment","text":"A door alarm is a detective control because it alerts staff after a condition occurs, such as the door being left open too long or forced open. It helps security personnel notice a problem quickly so they can respond. In this scenario, the badge controls access, while the alarm detects an abnormal state and signals that action is needed."}},"suggestedAnswer":[{"@type":"Answer","text":"Preventive control","comment":{"@type":"Comment","text":"A door alarm is not a preventive control because it does not stop the door from being opened or left ajar. Preventive controls, such as the badge reader or a mantraplock, physically block or restrict access before an incident occurs. The alarm only triggers after the abnormal condition exists, meaning it cannot prevent the initial event. Therefore, classifying it as preventive misrepresents its role in the security timeline."}},{"@type":"Answer","text":"Corrective control","comment":{"@type":"Comment","text":"A corrective control is meant to remediate or restore the system after an actual security breach or incident occurs—for example, automatically relocking the door or reverting to a default secure state. The door alarm does not take any corrective action; it merely reports the abnormal condition so that staff can respond manually. It alerts to a problem but does not fix the problem itself, so it cannot be considered a corrective control."}},{"@type":"Answer","text":"Deterrent control","comment":{"@type":"Comment","text":"A deterrent control is designed to discourage a potential attacker from attempting an action in the first place—such as warning signs, visible cameras, or patrols. A door alarm triggered only after a door is forced open or left open too long does not provide any psychological or physical deterrent before the event. Its primary function is to detect and announce a condition that already exists, not to prevent the initial decision or action. Thus, it is not a deterrent control."}}]},{"@context":"https://schema.org","@type":"Quiz","name":"A support team wants to export customer tickets into a test analytics environment so developers can search real examples while minimizing privacy exposure. The exported data includes names, email addr","url":"https://courseiva.com/questions/comptia/security-plus/a-support-team-wants-to-export-customer-tickets-into-a-test","acceptedAnswer":{"@type":"Answer","text":"Remove or tokenize unneeded personal identifiers before export","comment":{"@type":"Comment","text":"Removing or tokenizing unneeded personal identifiers before export directly implements data minimization and privacy-by-design, ensuring that only the minimum necessary information leaves the production environment. Tokenization replaces sensitive values with random placeholders that retain data format or logic for testing while preventing the recovery of original personal data without access to the token mapping. This significantly reduces the risk of unintended exposure and aligns with data protection regulations like GDPR and HIPAA."}},"suggestedAnswer":[{"@type":"Answer","text":"Export the full dataset and restrict access with a shared password","comment":{"@type":"Comment","text":"Exporting the full dataset with a shared password does not reduce the volume of exposed personal data and provides no individual accountability, as everyone uses the same credential. A password alone is a weak and easily shared access control, failing to support data minimization or privacy requirements. The support team should instead de-identify unnecessary identifiers, ensuring the export contains only relevant non-sensitive information."}},{"@type":"Answer","text":"Keep the data unchanged because the test environment is internal","comment":{"@type":"Comment","text":"The belief that an internal test environment makes unchanged data acceptable is false because insider threats, misconfigured environments, or future re-purposing can still expose personal information. Data protection laws apply regardless of where data resides, and copying production data to an internal test environment without sanitization violates the principle of purpose limitation. The team should generate synthetic or masked test data that preserves realistic relationships without carrying actual personal identifiers."}},{"@type":"Answer","text":"Store the export indefinitely because development data is exempt from retention rules","comment":{"@type":"Comment","text":"Development data is not automatically exempt from retention rules, and indefinite storage of exported customer tickets creates a larger attack surface and increases the duration of compliance obligations. Most regulations explicitly require personal data not be kept longer than necessary, with retention schedules applying equally to dev, test, or staging environments. The support team should apply the company's data retention policy to the export, establishing a defined deletion window and auditing its lifecycle."}}]},{"@context":"https://schema.org","@type":"Quiz","name":"A security analyst is reviewing authentication logs from a corporate web application. The logs show thousands of failed login attempts over the past hour. Each attempt uses a different username, but a","url":"https://courseiva.com/questions/comptia/security-plus/a-security-analyst-is-reviewing-authentication-logs-from-a","acceptedAnswer":{"@type":"Answer","text":"Password spraying attack","comment":{"@type":"Comment","text":"Password spraying is an attack technique where a single common password (or a short list) is attempted against a large number of user accounts, typically once per account to avoid triggering account lockout policies. The observed authentication log pattern—many distinct usernames each tried with the same password—is the classic signature of this attack. Because each account sees only one or a few authentication failures, standard threshold-based detection often misses it until the analyst correlates across endpoints."}},"suggestedAnswer":[{"@type":"Answer","text":"Brute-force attack","comment":{"@type":"Comment","text":"A brute-force attack focuses the attacker's efforts on a single target account, systematically trying every possible password or a massive password list until one succeeds. This produces a telltale log pattern of many repeated authentication failures for the same username in a short window, which contrasts sharply with the observed logs showing one password attempted against many different usernames. Brute-force attacks are also more conspicuous and more likely to be stopped by lockout policies than password spraying."}},{"@type":"Answer","text":"Credential stuffing attack","comment":{"@type":"Comment","text":"Credential stuffing relies on breached username/password pairs, so each authentication attempt uses a different, previously known password associated with that specific username. In the observed logs, the identical password is repeated across all attempts, which means the attacker is not using compromised pairs; they are leveraging password reuse across accounts. Credential stuffing would produce a log pattern where both usernames and passwords vary, often with the same password appearing only if the breach contained multiple accounts with the same password."}},{"@type":"Answer","text":"Dictionary attack","comment":{"@type":"Comment","text":"A dictionary attack typically targets a single user account by iterating through a list of common passwords—such as 'Password1' or '123456'—until one matches. The observed pattern is the inverse: a single password is tried against a wide range of usernames, indicating vertical rather than horizontal brute-forcing. Dictionary attacks are also more frequent in logs, but they concentrate their attempts on one account, which does not align with the multi-account failure pattern described."}}]}]

Security+ SY0-701 (SY0-701) — Questions 76150

1013 questions total · 14pages · All types, answers revealed

Page 1

Page 2 of 14

Page 3
76
MCQeasy

A team is moving an application to a cloud provider. The cloud provider will secure the physical data center and core infrastructure, while the company must still secure its own application settings and user access. What concept does this describe?

A.Fail-open design
B.Shared responsibility model
C.Air gap
D.Data masking
AnswerB

The shared responsibility model is the framework that defines how cloud security duties are split: the provider secures the physical infrastructure, hardware, network, and hypervisor, while the customer secures data, identities, access policies, and configurations, with the exact boundary depending on the service model (IaaS, PaaS, or SaaS). When migrating an application to the cloud, this model tells you which security controls you still own and which the provider manages. That is precisely why it is the correct answer.

Why this answer

The shared responsibility model defines the division of security obligations between a cloud provider and its customer. In this scenario, the provider secures the physical data center and core infrastructure (the 'security of the cloud'), while the company retains responsibility for application settings and user access (the 'security in the cloud'). This model is foundational to all major cloud providers, including AWS, Azure, and Google Cloud.

Exam trap

The trap here is that candidates often confuse the shared responsibility model with a simple 'provider does everything' or 'customer does everything' approach, failing to recognize that security obligations are split based on the service model (IaaS, PaaS, SaaS) and that the customer always retains responsibility for data and access management.

How to eliminate wrong answers

Option A is wrong because a fail-open design refers to a security mechanism that defaults to allowing access when it fails (e.g., a firewall that passes all traffic upon crash), not to the division of security responsibilities in cloud computing. Option C is wrong because an air gap is a physical or logical isolation of a network from unsecured networks (e.g., no network connection at all), which is unrelated to the shared security duties between a cloud provider and its customer. Option D is wrong because data masking is a technique used to obfuscate sensitive data (e.g., replacing real credit card numbers with fictitious ones for testing), not a model for distributing security controls between parties.

77
MCQmedium

A security analyst receives an alert that a user's workstation is communicating with a known malicious IP address during off-hours. The analyst reviews the firewall logs and confirms the connection was established. Which of the following should the analyst perform NEXT to contain the threat?

A.Disable the user's account immediately.
B.Isolate the workstation from the network.
C.Run a full antivirus scan on the workstation.
D.Notify the user's manager of the policy violation.
AnswerB

Isolating the workstation stops all network communication, including the connection to the malicious IP. This is a direct containment action that prevents further exfiltration, command-and-control activity, or lateral spread.

Why this answer

Isolating the workstation from the network (Option B) is the immediate containment step because it stops the active communication with the known malicious IP address, preventing further data exfiltration, lateral movement, or command-and-control (C2) activity. This aligns with the NIST incident response framework's containment phase, which prioritizes stopping the threat before investigation or remediation. Disabling the user account (A) does not stop the network-level communication if the malware is running as a service or using cached credentials, and running a scan (C) or notifying management (D) are post-containment actions.

Exam trap

CompTIA often tests the distinction between containment and remediation, trapping candidates who choose to run an antivirus scan (Option C) first, when the correct incident response order is to isolate the host to stop the active threat before any scanning or notification.

Why the other options are wrong

A

Disabling the user's account does not stop the active network communication from the compromised workstation to the malicious IP; the threat remains active on the network.

C

Running a full antivirus scan is a detection and remediation step, not a containment step. The immediate priority is to stop communication with the malicious IP, which isolation achieves; scanning can occur after containment.

D

Notifying the user's manager of a policy violation does not directly contain the threat; the workstation is still communicating with a malicious IP, and containment (e.g., isolation) is the immediate priority.

When would these options actually be correct?

A

If the alert indicated that the user's account credentials were compromised and being used from an unauthorized location, disabling the account would be the immediate step to prevent further unauthorized access.

C

A security analyst receives an alert that a user's workstation is exhibiting signs of malware infection (e.g., unusual file modifications). The analyst has already isolated the workstation. Which of the following should the analyst perform NEXT to determine the extent of the infection?

D

In a scenario where an alert indicates a policy violation (e.g., accessing prohibited websites during work hours) with no active security threat, the analyst should notify the manager for disciplinary action after confirming the violation.

Why candidates pick the wrong answer

A

Candidates may think that disabling the account is a quick way to stop malicious activity, but they overlook that the workstation itself is already compromised and still communicating externally.

C

Candidates often think scanning is the first response to any malware indicator, confusing detection/remediation with containment, and underestimate the urgency of stopping active malicious communication.

D

Candidates may think that reporting the incident to management is a standard step, but they overlook that containment must occur first to prevent further damage from the active malicious connection.

78
MCQmedium

A security analyst in a SOC receives an alert indicating that a large volume of data was transferred from a user's workstation to an external IP address at 2:00 AM. The analyst suspects a data exfiltration attack. According to incident response best practices, what should the analyst do FIRST?

A.Block the external IP address at the firewall.
B.Review the user's login and activity logs.
C.Contact the user to inquire about the transfer.
D.Restore the workstation from a known good backup.
AnswerB

Reviewing logs is the correct first step. It allows the analyst to verify the alert, see if the user was logged in, identify the process responsible for the transfer, and gather details necessary for informed decision-making.

Why this answer

In incident response, the first step is to gather evidence and understand the scope of the incident. Reviewing the user's login and activity logs (e.g., Windows Event Logs, authentication logs, and process creation logs) allows the analyst to verify if the user was actually logged in at 2:00 AM, identify any anomalous behavior (e.g., use of unauthorized tools or unusual file access patterns), and determine whether the data transfer was initiated by the user or by malware. This aligns with the NIST SP 800-61 incident response lifecycle, specifically the identification and analysis phase, where initial triage focuses on log review before taking containment actions.

Exam trap

The trap here is that candidates often jump to immediate containment (blocking the IP) or recovery (restoring from backup) without first verifying the alert through log analysis, which is a fundamental incident response principle emphasized in the SY0-701 exam.

Why the other options are wrong

A

Blocking the external IP at the firewall is a containment step that should be taken after verifying the alert is a true positive. The first step is to gather more information to confirm the incident, not to take immediate action that could disrupt legitimate traffic.

C

Contacting the user immediately may alert a potential insider threat or disrupt forensic preservation; the analyst should first gather objective evidence from logs to confirm the incident before involving personnel.

D

Restoring from backup is a containment/recovery step that occurs after the incident has been confirmed and analyzed; it is premature before verifying the alert and gathering evidence.

When would these options actually be correct?

A

This option would be correct if the question stated that the analyst has already confirmed the data exfiltration is occurring in real-time and immediate containment is required to prevent further data loss, such as in a scenario where the alert is verified and the external IP is known malicious.

C

If the question stated that the transfer was flagged during business hours and the user is available, and the analyst needs to quickly verify if the transfer was authorized (e.g., a legitimate large file upload), then contacting the user first would be appropriate to avoid unnecessary escalation.

D

If the question stated that the workstation was confirmed compromised (e.g., via forensic analysis) and the priority is to remove malware and restore normal operations, then restoring from a known good backup would be the correct first step.

Why candidates pick the wrong answer

A

Candidates may think that stopping the data transfer immediately is the top priority, but they overlook the need for verification first, as per incident response frameworks like NIST SP 800-61.

C

Candidates often think that asking the user is the fastest way to clarify the situation, but they overlook the risk of tipping off a malicious insider and the need for evidence-based investigation first.

D

Candidates may think that restoring from backup quickly stops data loss and removes any malicious software, but they overlook the need to first confirm the incident and preserve evidence.

79
MCQmedium

Based on the exhibit, which network change best isolates finance workstations from general user PCs while still allowing printing and application access? VLAN table: - VLAN 20 Users: 10.20.20.0/24 - VLAN 30 Finance: 10.20.30.0/24 - VLAN 40 Printers: 10.20.40.0/24 - VLAN 50 Accounting App: 10.20.50.0/24 Current SVI routing policy: permit ip any any Management goal: Finance devices must not initiate traffic to User VLAN 20, but they must be able to print and access the accounting application.

A.Put finance workstations on the same VLAN as the printers to simplify access.
B.Add inter-VLAN ACLs that deny Finance VLAN access to User VLAN 20 while permitting Finance VLAN traffic to VLAN 40 and VLAN 50.
C.Remove routing between all VLANs and let users print through email attachments.
D.Place the accounting application in the User VLAN so finance devices no longer need segmentation.
AnswerB

This is the best option because it keeps the finance systems isolated from general user devices while still allowing the required business functions. The ACL can allow only the exact destinations and services needed for printing and the accounting application, which reduces lateral movement risk without breaking the workflow. It is a practical example of subnet isolation with traffic filtering.

Why this answer

It uses inter-VLAN ACLs to enforce the principle of least privilege: denying traffic from the Finance VLAN (10.20.30.0/24) to the User VLAN (10.20.20.0/24) while explicitly permitting traffic to the Printer VLAN (10.20.40.0/24) and the Accounting App VLAN (10.20.50.0/24). This preserves the required segmentation and still allows the necessary services (printing and application access) without altering the existing VLAN structure or routing policy.

Exam trap

The trap here is that candidates often assume VLANs alone provide security isolation, forgetting that by default inter-VLAN routing permits all traffic (as shown by the 'permit ip any any' SVI policy), so additional ACLs are required to enforce directional restrictions while still allowing specific services.

How to eliminate wrong answers

Option A is wrong because placing finance workstations on the same VLAN as printers would collapse segmentation, allowing unrestricted traffic between finance devices and printers, and would not isolate finance from user PCs—it also violates the management goal of preventing finance-initiated traffic to the User VLAN. Option C is wrong because removing routing between all VLANs would completely block inter-VLAN communication, preventing finance devices from accessing the printers and accounting application, which directly contradicts the requirement to allow printing and application access. Option D is wrong because placing the accounting application in the User VLAN would expose it to all user PCs, defeating the purpose of segmentation and potentially allowing unauthorized access from the User VLAN to the application, while still not isolating finance workstations from user PCs.

80
MCQmedium

A legal team must send a confidential contract to a partner so only the intended recipient can read it, and the partner also needs assurance the file really came from your company. Which approach best meets both needs?

A.Hash the contract and email the hash value separately.
B.Encrypt the file with the recipient's public key and sign it with the sender's private key.
C.Use a shared symmetric key and send the key in the same email message.
D.Compress the file and password-protect the archive with a simple passphrase.
AnswerB

Using the recipient's public key ensures only the intended recipient can decrypt the file, which provides confidentiality. Adding a digital signature with the sender's private key gives the partner a way to verify the file came from your company and has not been altered. Together, these controls address both privacy and authenticity, which is exactly what the scenario requires.

Why this answer

It uses asymmetric encryption to ensure confidentiality (encrypting with the recipient's public key ensures only the intended recipient can decrypt it with their private key) and digital signing (signing with the sender's private key provides non-repudiation and authenticity, proving the file came from the sender). This combination directly addresses both requirements: only the partner can read the contract, and the partner can verify the sender's identity.

Exam trap

The trap here is that candidates often confuse hashing with encryption or think that password-protecting a zip file provides strong security and sender authentication, when in fact only a proper public-key infrastructure (PKI) with encryption and digital signatures meets both confidentiality and non-repudiation requirements.

How to eliminate wrong answers

Option A is wrong because hashing the contract and emailing the hash separately only provides integrity verification (detecting tampering) but does not encrypt the contract or authenticate the sender; anyone can read the contract in the email, and the hash alone does not prove the sender's identity. Option C is wrong because using a shared symmetric key and sending it in the same email message completely defeats confidentiality; if an attacker intercepts the email, they have both the encrypted file and the key, allowing them to decrypt it immediately. Option D is wrong because compressing and password-protecting the archive with a simple passphrase is weak encryption that can be easily brute-forced or guessed, and it provides no cryptographic proof of the sender's identity; the recipient has no assurance the file truly came from your company.

81
MCQeasy

At a conference, employees connect to a Wi-Fi network named "CorpGuest" and then see certificate warnings in their browsers. The network has a stronger signal than the hotel's legitimate guest Wi-Fi. What attack is this?

A.Rogue access point
B.ARP poisoning
C.Replay attack
D.Denial of service
AnswerA

A rogue access point, often called an evil twin, imitates a real network to lure users onto it.

Why this answer

This scenario describes a rogue access point attack. The attacker sets up a Wi-Fi network named "CorpGuest" with a stronger signal than the legitimate hotel guest Wi-Fi, tricking employees into connecting to it. Once connected, the attacker can intercept traffic and present a fake certificate, causing browser certificate warnings.

This is a classic evil twin variant of a rogue access point attack.

Exam trap

The trap here is that candidates may confuse a rogue access point with ARP poisoning because both can enable man-in-the-middle attacks, but the key differentiator is the method of initial access — rogue AP uses a fake wireless network, while ARP poisoning operates on an existing wired or wireless LAN.

How to eliminate wrong answers

Option B (ARP poisoning) is wrong because ARP poisoning involves sending forged ARP messages over a local network to associate the attacker's MAC address with the IP address of a legitimate host, enabling man-in-the-middle attacks on switched networks; it does not involve setting up a fake Wi-Fi network. Option C (Replay attack) is wrong because a replay attack captures and retransmits valid data transmissions to trick the receiver, not to create a fraudulent wireless network or cause certificate warnings. Option D (Denial of service) is wrong because a denial of service attack aims to disrupt or degrade network services, not to impersonate a legitimate access point and intercept user traffic.

82
Matchinghard

Match each detection pattern to the most likely security issue. Each item has one best match.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Living-off-the-land or fileless malware execution

DNS tunneling or command-and-control beaconing

Password spraying or credential stuffing that succeeded

Compromised privileged credentials with persistence and post-exploitation activity

Why these pairings

Repeated login failures indicate brute-force; Outbound connections to malicious IPs suggest C2; Large data transfers at odd hours indicate exfiltration; Random DNS subdomains are typical of tunneling; Conflicting ARP replies show spoofing; Multiple ICMP requests from many sources indicate DDoS.

83
MCQmedium

Based on the exhibit, what security issue is most likely present?

A.Weak permissions, because the camera streams video to multiple ports.
B.Default credentials, because the admin login is enabled.
C.Exposed service, because management and streaming ports are listening on all interfaces and allowed from anywhere.
D.Outdated component, because firmware version 1.0.3 is listed.
AnswerC

The main issue is exposed service. The camera-web and RTSP services listen on 0.0.0.0, which means all interfaces, and the ACL allows any source to connect. That exposes the device to the network far beyond the intended management scope, creating an easy attack path.

Why this answer

The exhibit shows that both the management interface (TCP 443) and the streaming interface (TCP 554) are bound to 0.0.0.0 (all interfaces) and the firewall rules allow traffic from 0.0.0.0/0 (any source). This exposes the camera's web management and RTSP streaming services to the entire internet, making it vulnerable to unauthorized access, reconnaissance, and potential exploitation. An exposed service of this nature is a common entry point for attackers to compromise IoT devices.

Exam trap

The trap here is that candidates may focus on the presence of default credentials or outdated firmware as obvious vulnerabilities, but the exhibit does not provide evidence of those—instead, the clear misconfiguration is the service exposure, which is a distinct and common threat in IoT and network device security.

How to eliminate wrong answers

Option A is wrong because streaming video to multiple ports is a normal function of an IP camera (e.g., RTSP on port 554 and HTTP on port 80 for web viewing), and does not inherently indicate weak permissions; weak permissions would refer to misconfigured access control lists or user privileges, not the number of ports used. Option B is wrong because the admin login being enabled is not itself a security issue; the vulnerability arises only if default credentials (e.g., admin/admin) are still in use, which is not indicated in the exhibit. Option D is wrong because firmware version 1.0.3 being listed does not automatically mean it is outdated or vulnerable; without a known CVE or version comparison, the version number alone is not evidence of an outdated component.

84
MCQhard

Based on the exhibit, which document type should the organization update if it wants the listed endpoint settings to be mandatory baseline requirements?

A.Policy, because it defines the organization's broad security intent and direction.
B.Standard, because it defines mandatory minimum settings that all systems must meet.
C.Procedure, because it provides the exact steps administrators follow to configure the setting.
D.Guideline, because it is the least restrictive document for endpoint protection.
AnswerB

Standards are the right place for mandatory, measurable requirements like encryption, lock timers, and password length. The exhibit already shows those exact settings in the standard excerpt. Policy states the broad intent, procedures describe how to implement it, and guidelines remain advisory rather than compulsory.

Why this answer

A standard is the correct document type because it defines mandatory, minimum-security configuration requirements that all systems must meet, such as specific endpoint settings. Unlike a policy, which states broad intent, a standard provides the enforceable baseline that ensures consistent security posture across the organization.

Exam trap

The trap here is confusing a policy's broad intent with a standard's enforceable baseline, leading candidates to select 'Policy' because they think it is the highest-level document, when in fact standards are the correct document type for mandatory technical requirements.

How to eliminate wrong answers

Option A is wrong because a policy defines the organization's broad security intent and direction, not the specific mandatory baseline settings for endpoints. Option C is wrong because a procedure provides the exact step-by-step instructions for administrators to configure settings, but it does not define the mandatory baseline requirements themselves. Option D is wrong because a guideline is advisory and the least restrictive document, offering recommendations rather than mandatory minimum requirements.

85
Multi-Selectmedium

A regulated analytics workload is moving to a public cloud. The business wants the strongest practical tenant isolation without managing physical servers, and it also needs an audit trail for changes made to the cloud environment. Which two design choices best meet those requirements? Select two.

Select 2 answers
A.Place the workload in a dedicated account, project, or subscription with restricted cross-account access.
B.Enable cloud control-plane logging and retain the logs centrally.
C.Deploy the workload in a shared public subnet to simplify routing between tenants.
D.Assume the cloud provider will record every guest operating system event automatically.
E.Disable logging to reduce storage costs because the provider already has all necessary records.
AnswersA, B

A dedicated account, project, or subscription provides stronger logical isolation than placing the workload in a shared environment. Restricting cross-account access reduces accidental or unauthorized sharing and makes governance easier. This is a common cloud architecture pattern for regulated workloads that need separation without the overhead of managing physical infrastructure.

Why this answer

Placing the workload in a dedicated account, project, or subscription with restricted cross-account access provides strong logical isolation at the cloud provider's control plane. This approach meets the requirement for tenant isolation without managing physical servers, as it leverages the provider's built-in resource boundaries and IAM policies to prevent unauthorized access between tenants.

Exam trap

The trap here is that candidates often confuse network-level isolation (like subnets) with tenant isolation at the control plane, or assume cloud providers automatically handle guest OS auditing, leading them to select C or D instead of the correct combination of A and B.

86
MCQmedium

After a ransomware incident, management learns the attacker's stolen domain admin credentials were used to delete recent online backups from the same backup network. Which backup strategy would have most reduced the chance of permanent backup loss?

A.Nightly incremental backups stored on the same file server as production data.
B.Immutable backups stored in a separate repository or offline location.
C.Hypervisor snapshots only, because they are always safer than backups.
D.Longer retention on the same backup share to keep more versions available.
AnswerB

Immutable backups in a separate repository or offline location are the correct defense because they make recovery data both tamper-proof and network-isolated. Object locking (e.g., S3 Object Lock with WORM mode) or filesystem-level immutable flags (such as chattr +i on Linux) prevent deletion or modification even by accounts with administrative privileges, as the data is retained until an explicitly set retention period expires. Offline media like rotated tape or an air-gapped storage array ensures that the ransomware cannot reach the repository via the production network or lateral movement. This design adheres to the 3-2-1 rule and satisfies CISA/NIST guidance for ransomware-resilient backups.

Why this answer

Immutable backups stored in a separate repository or offline location prevent deletion or modification by an attacker, even with domain admin credentials. This is because immutability enforces a write-once-read-many (WORM) policy, often implemented via object lock (e.g., S3 Object Lock) or a physical air gap, ensuring that backups cannot be altered or deleted before their retention period expires. In this scenario, the attacker's ability to delete online backups from the same network is mitigated because the immutable repository is isolated and resistant to credential-based tampering.

Exam trap

The trap here is that candidates may assume longer retention or same-server backups are sufficient, but the key is that immutability and isolation (air gap) are required to prevent an attacker with elevated credentials from deleting backups, which is a core concept tested in SY0-701 Domain 3.0 (Security Operations).

How to eliminate wrong answers

Option A is wrong because nightly incremental backups stored on the same file server as production data are vulnerable to the same ransomware attack and credential compromise, as the attacker can delete or encrypt them using the same domain admin credentials. Option C is wrong because hypervisor snapshots are not always safer than backups; they are typically stored on the same storage array as the VMs and can be deleted by an attacker with administrative access to the hypervisor, and they lack the isolation and immutability features of dedicated backup solutions. Option D is wrong because longer retention on the same backup share does not protect against deletion; the attacker can still delete all versions from the same share using the stolen credentials, as retention policies do not enforce immutability or separation.

87
MCQmedium

After a phishing simulation, many users still almost submitted credentials to a fake Microsoft login page. Security wants to reduce repeat mistakes quickly without interrupting daily work. Which approach is best?

A.Send one enterprise-wide warning email listing every phishing indicator the users should memorize.
B.Require all employees to retake the full annual security course immediately.
C.Use short, targeted awareness messages with screenshots of the actual lure and an easy reporting path.
D.Remove email access for any user who clicked the simulation link.
AnswerC

Short, targeted awareness messages that show the actual simulated lure give users a concrete, contextual example of what they encountered, which is far more memorable than abstract rules. By keeping the message brief, you respect the user's time and maximize attention, while an easy reporting path lowers the barrier to action in real future incidents. This just-in-time coaching turns the simulation into a constructive learning opportunity rather than a punitive test, promoting a positive security culture.

Why this answer

It uses just-in-time, context-specific training that directly addresses the observed behavior without disrupting workflow. By showing users the exact lure they encountered and providing a simple reporting path, the organization reinforces recognition of the specific phishing technique and encourages immediate reporting, which is more effective than generic warnings or lengthy retraining for reducing repeat mistakes quickly.

Exam trap

The trap here is that candidates may choose Option A (broad warning) because it seems quick and comprehensive, but they overlook that targeted, behavior-specific messaging is far more effective for changing user behavior than generic information overload.

How to eliminate wrong answers

Option A is wrong because a single enterprise-wide warning email listing every phishing indicator is too generic and overwhelming; users are unlikely to memorize a long list, and the lack of context-specific examples reduces retention and behavioral change. Option B is wrong because requiring all employees to retake the full annual security course immediately is disruptive to daily work, time-consuming, and not targeted to the specific phishing lure that was used, making it inefficient for quick remediation. Option D is wrong because removing email access for users who clicked the simulation link is punitive and counterproductive; it does not educate users, may create resentment, and removes the opportunity for them to practice safe reporting behaviors, while also potentially hindering their daily work.

88
Multi-Selectmedium

A help desk manager is hardening a fleet of Windows laptops. The goal is to prevent booting from untrusted external media and to ensure only approved software can run on the devices. Which two controls best address those goals? Select two.

Select 2 answers
A.Enable Secure Boot in firmware.
B.Implement application allowlisting or application control.
C.Rely only on full-disk encryption to stop unauthorized boot code.
D.Increase the screen-lock timeout so users are interrupted less often.
E.Use a stronger Wi-Fi password so malware cannot start.
AnswersA, B

Secure Boot helps ensure the device only starts trusted boot components that are signed by a trusted key. That reduces the risk of booting unapproved loaders or malicious recovery media. It is a platform hardening control that directly addresses firmware-level trust during startup, which is exactly what the scenario calls for.

Why this answer

Secure Boot is a UEFI firmware feature that verifies the digital signature of the bootloader against a database of trusted signatures stored in the firmware. By enabling Secure Boot, the system will refuse to boot from any external media (e.g., USB drives) that does not have a valid, trusted signature, directly preventing unauthorized boot code from executing.

Exam trap

The trap here is that candidates often confuse full-disk encryption with boot security, mistakenly thinking encryption prevents unauthorized boot media, when in fact encryption only protects data confidentiality and does not control the boot process or software execution.

89
MCQeasy

A company requires MFA, endpoint protection, and network filtering so that if one control misses a threat, another control still helps stop it. Which security principle is this?

A.Single sign-on
B.Defense in depth
C.Nonrepudiation
D.Data masking
AnswerB

Defense in depth is a security architecture that layers multiple independent controls so that if one fails or is bypassed, another still provides protection. Here, MFA, endpoint protection, and network filtering operate at different layers—identity, device, and network—creating overlapping barriers against attackers. This approach embodies the principle that no single control is infallible, and combined layers raise the overall cost and complexity of an attack, matching the company's stated requirements.

Why this answer

Defense in depth is a layered security strategy where multiple, independent controls (e.g., MFA, endpoint protection, network filtering) are deployed so that if one layer fails, another still provides protection. This ensures no single point of failure can compromise the entire system, directly matching the scenario where overlapping controls compensate for each other's gaps.

Exam trap

The trap here is that candidates confuse 'defense in depth' with 'single sign-on' because both involve multiple systems, but SSO is about convenience and identity federation, not layered security controls.

How to eliminate wrong answers

Option A is wrong because single sign-on (SSO) is an authentication mechanism that allows users to log in once and access multiple systems, not a layered security approach; it does not provide overlapping controls to catch missed threats. Option C is wrong because nonrepudiation ensures that a party cannot deny an action (e.g., via digital signatures or audit logs), but it does not involve multiple defensive layers to stop threats. Option D is wrong because data masking obscures sensitive data (e.g., replacing real credit card numbers with tokens) for privacy or testing, not to provide layered protection against threats.

90
MCQmedium

A software vendor distributes critical security updates for its application through a public download website. The vendor wants to allow customers to verify that each update originated from the vendor and has not been modified in transit. Which of the following cryptographic techniques should the vendor apply to the update files before posting them for download?

A.Digital signature
B.Cryptographic hash
C.Antivirus scan report
D.TLS certificate
AnswerA

A digital signature is created with the vendor's private key and verified using the vendor's public key, ensuring the update originated from the claimed source (authentication) and was not altered after signing (integrity). Because private keys are kept secret and the public key is bound to the vendor via a trusted certificate authority, this provides strong, cryptographically verifiable proof of authenticity that persists beyond the download.

Why this answer

A digital signature provides both authentication (proving the update originated from the vendor) and integrity (detecting any modification in transit). The vendor signs the file with their private key, and customers verify the signature using the vendor's public key, ensuring the file has not been altered since signing.

Exam trap

The trap here is that candidates confuse a cryptographic hash (which only ensures integrity) with a digital signature (which ensures both integrity and non-repudiation/authentication), or they mistakenly think TLS certificates alone can verify the file's origin after download.

Why the other options are wrong

B

A cryptographic hash alone provides integrity (detects modification) but does not provide authentication (prove origin). The vendor needs to prove the update originated from them, which requires a digital signature using their private key.

D

A TLS certificate secures the communication channel (e.g., HTTPS) between the client and server, but it does not provide a mechanism for the client to verify the integrity and origin of the downloaded file itself after it has been received. The question asks for a technique applied to the update files, not to the transmission.

When would these options actually be correct?

B

A cryptographic hash would be correct if the question asked: 'Which technique ensures that a file has not been altered during download, assuming the hash is obtained from a trusted source?'

D

A TLS certificate would be correct if the question asked: 'Which technique ensures that the download connection between the vendor's website and the customer is encrypted and authenticated?' or 'Which technology prevents man-in-the-middle attacks during the download process?'

Why candidates pick the wrong answer

B

Candidates often confuse integrity (hash) with authenticity (signature), thinking that verifying a hash against a known value also proves the source, but it does not without a trusted channel for the hash.

D

Candidates may confuse securing the download channel (TLS) with verifying the file's authenticity and integrity. They might think that because TLS provides encryption and server authentication, it also protects the file after download, which is incorrect.

91
MCQmedium

An employee receives a text message from an unknown number pretending to be IT. It includes a shortened URL for "urgent MFA re-enrollment" and says the account will be locked in 15 minutes. What is the best response?

A.Open the link and enter the requested information if the page looks legitimate.
B.Report the message through the official security channel and verify the request using known IT contact information.
C.Forward the text to coworkers so they can check whether they received the same message.
D.Reply to the text asking for a company badge number before proceeding.
AnswerB

The safest response is to avoid the link and use an established internal reporting or verification process. This prevents credential theft and helps security track suspicious messages quickly. Verifying through a known contact method, not the message itself, protects the user from smishing and MFA baiting.

Why this answer

It follows the principle of verifying unsolicited requests through trusted channels, which is a key defense against social engineering and phishing attacks. The message exhibits classic phishing indicators: an unknown sender, a shortened URL (which can mask the true destination), a false sense of urgency, and a request for MFA re-enrollment—a common pretext to harvest credentials or MFA tokens. Reporting through the official security channel ensures the incident is logged and investigated, while verifying with known IT contact information prevents falling for a spoofed or compromised source.

Exam trap

The trap here is that candidates may choose Option A because the message appears urgent and the page looks legitimate, overlooking that attackers can perfectly clone authentication portals and that shortened URLs are a common obfuscation technique in phishing campaigns.

How to eliminate wrong answers

Option A is wrong because opening a shortened URL from an unknown sender and entering credentials, even if the page looks legitimate, risks credential theft via a phishing site that may mimic the real MFA portal; attackers can clone login pages and intercept tokens in real time. Option C is wrong because forwarding the text to coworkers amplifies the threat by spreading a potential phishing link, increasing the likelihood of compromise across the organization; it also bypasses proper incident reporting procedures. Option D is wrong because replying to the text confirms the phone number is active and monitored, which can lead to targeted follow-up attacks, and asking for a badge number is ineffective since attackers can easily fabricate such identifiers.

92
MCQeasy

A security manager wants evidence that annual security awareness training was completed by employees. Which artifact is the best proof?

A.A training completion report exported from the learning system
B.A copy of the company logo used on the training slides
C.A list of office supplies purchased last quarter
D.A screenshot of the company's public homepage
AnswerA

A training completion report exported from the learning management system (LMS) provides authoritative evidence by listing each employee, their completion date, and course status, often including graded results and access history. This system-generated report creates a verifiable audit trail that can be cross-referenced with the LMS database, making it acceptable to internal and external auditors. It specifically demonstrates that the annual security awareness training was fulfilled by the required population.

Why this answer

A training completion report exported from the learning system is the best proof because it provides a verifiable, timestamped record of each employee's completion status, including user IDs, course names, completion dates, and scores. This artifact directly demonstrates that the training was actually completed, not just assigned or attended, and can be audited against the organization's training policy.

Exam trap

The trap here is that candidates might think a visual artifact like a logo or homepage screenshot proves training occurred, but CompTIA tests the understanding that only a system-generated, auditable report with user-specific completion data constitutes valid evidence.

How to eliminate wrong answers

Option B is wrong because a copy of the company logo used on training slides is merely a branding element and provides no evidence of employee participation or completion. Option C is wrong because a list of office supplies purchased last quarter is unrelated to security awareness training and cannot demonstrate any training activity. Option D is wrong because a screenshot of the company's public homepage shows only the external-facing website and contains no data about internal training records or employee completion status.

93
MCQmedium

Leadership is deciding between two security controls for a customer portal outage risk. Finance wants to compare the options in dollars, using expected loss, not just a high/medium/low rating. Which approach should the analyst use?

A.Quantitative risk analysis, because it expresses likelihood and impact in monetary terms.
B.Qualitative risk analysis, because it uses categories like critical, medium, and low.
C.Business impact analysis, because it identifies which business processes are important.
D.Risk avoidance, because eliminating the activity removes the threat completely.
AnswerA

Quantitative risk analysis is the right method when decision-makers want financial comparisons. It uses numerical estimates such as annual loss expectancy, cost of control, and probable impact in dollars. That allows leadership to compare mitigation options against the expected reduction in loss and make a budget-based decision. In this situation, the business specifically wants a dollar-based analysis rather than a subjective ranking.

Why this answer

Quantitative risk analysis (A) is correct because it assigns monetary values to both the likelihood and impact of a risk, enabling a direct dollar-based comparison of expected loss. The Finance team's requirement for a dollar comparison rules out qualitative ratings, making quantitative analysis the only approach that meets their needs.

Exam trap

The trap here is that candidates often confuse qualitative risk analysis with quantitative, thinking that any risk assessment that uses categories is sufficient, but the question explicitly demands monetary comparison, which only quantitative analysis provides.

How to eliminate wrong answers

Option B is wrong because qualitative risk analysis uses categories like high/medium/low, not monetary values, so it cannot provide the dollar-based comparison Finance requested. Option C is wrong because a business impact analysis (BIA) identifies critical processes and recovery priorities, but it does not calculate expected loss in monetary terms for comparing security controls. Option D is wrong because risk avoidance eliminates the activity entirely, which is a risk treatment strategy, not an analysis method for comparing control costs in dollars.

94
MCQeasy

Before applying a major patch to a virtual machine, the administrator wants a quick way to return the VM to its exact pre-change state if the patch fails. What should the administrator create?

A.A full backup to removable media
B.A snapshot of the virtual machine
C.A separate VLAN for the virtual machine
D.A digital certificate for the patch server
AnswerB

A snapshot captures the VM state at a specific moment, making rollback fast after a failed patch.

Why this answer

A snapshot captures the exact state of the virtual machine (disk, memory, and power state) at a point in time, allowing the administrator to revert instantly if the patch fails. This is the fastest and most storage-efficient method for a quick rollback compared to a full backup, which is slower and more resource-intensive.

Exam trap

The trap here is that candidates confuse a snapshot with a full backup, but the question emphasizes 'quick way to return to exact pre-change state,' which is the defining characteristic of a snapshot, not a backup.

How to eliminate wrong answers

Option A is wrong because a full backup to removable media is a slower, more cumbersome process that requires restoring the entire VM from external storage, not a quick revert. Option C is wrong because a separate VLAN isolates network traffic but does not preserve or restore the VM's operating system or application state. Option D is wrong because a digital certificate authenticates the patch server but provides no mechanism to revert the VM to a previous state.

95
MCQeasy

A user enters `<script>alert('test')</script>` into a public comment field, and other visitors see the script run in their browsers. What attack is this?

A.Cross-site scripting
B.SQL injection
C.Broken authentication
D.Insecure deserialization
AnswerA

Cross-site scripting (XSS) occurs when an application includes unvalidated user-supplied data in a web page, allowing attacker-controlled script to execute in the context of any victim's browser. In stored XSS, the malicious payload is permanently saved—such as in a comment field—and then served to every subsequent visitor. The 'alert' confirms script execution; an attacker could instead steal session cookies or perform actions on behalf of the user. This is the textbook explanation for why this is correct.

Why this answer

This is a classic cross-site scripting (XSS) attack because the user-supplied input containing a script tag is echoed back to other visitors' browsers without proper sanitization or encoding. The script executes in the context of the victim's browser, allowing the attacker to steal cookies, redirect users, or deface the page. XSS exploits the trust a user has for a particular website, unlike SQL injection which targets the database.

Exam trap

The trap here is that candidates confuse client-side attacks (XSS) with server-side attacks (SQL injection) because both involve user input, but XSS targets the browser's execution context while SQL injection targets the database query parser.

How to eliminate wrong answers

Option B (SQL injection) is wrong because SQL injection involves injecting malicious SQL queries into input fields to manipulate a backend database, not to execute client-side scripts in a browser. Option C (Broken authentication) is wrong because broken authentication refers to flaws in session management or credential handling (e.g., weak passwords, session fixation), not the injection of client-side code that runs in other users' browsers.

96
Multi-Selecteasy

Which two statements describe authorization? Select two.

Select 2 answers
A.It determines what a user can access after sign-in
B.It usually happens after authentication
C.It proves a user is who they claim to be
D.It records every packet a device sends
E.It replaces the need for authentication
AnswersA, B

Authorization is the phase of access control that maps an authenticated identity to specific permissions, roles, or policy rules, thereby defining what resources, functions, or data that identity may use. It occurs after authentication because the system must first establish who the user is before it can apply any access decisions. Common implementations include role-based access control (RBAC), attribute-based access control (ABAC), and discretionary access control (DAC), all of which determine the scope of a user's post-login activity.

Why this answer

Authorization determines the resources and actions a user can access after successful authentication. It enforces access control policies, such as those defined by RBAC or ACLs, ensuring users only interact with permitted data or systems. This aligns with the NIST definition of authorization as the process of granting or denying rights to a user.

Exam trap

The trap here is confusing authorization with authentication, as many candidates mistakenly think proving identity (authentication) also grants access rights, but authorization is a distinct step that occurs after authentication.

97
MCQmedium

Your company is syncing design files to a cloud object store. The security team wants to reduce risk if the storage account is stolen and also protect the files while they travel across the internet. Which approach is the best fit?

A.Password-protect each archive and upload it over plain HTTP.
B.Encrypt data in transit with TLS and enable encryption at rest with managed keys.
C.Rename the files before upload so attackers cannot identify them.
D.Place the storage service on a private IP address and skip encryption.
AnswerB

Correct. TLS protects the files while they move across the network, and encryption at rest protects stored objects if the storage account or media is exposed. Using managed keys also reduces key-handling mistakes and keeps the protection aligned with standard cloud security practices. This combination addresses both major exposure points in the scenario.

Why this answer

It addresses both risks: TLS (Transport Layer Security) encrypts data in transit, preventing interception or tampering during upload, while managed keys for encryption at rest protect the files if the storage account credentials are compromised. This dual-layer approach aligns with defense-in-depth and is a standard best practice for cloud object stores like Amazon S3 or Azure Blob Storage.

Exam trap

The trap here is that candidates may think renaming files (Option C) or using a private IP (Option D) provides security, but these measures do not address encryption requirements for data at rest or in transit as specified in the scenario.

How to eliminate wrong answers

Option A is wrong because password-protecting archives does not encrypt the data in transit over plain HTTP, leaving it vulnerable to eavesdropping and man-in-the-middle attacks; also, password protection is weaker than full encryption and can be brute-forced. Option C is wrong because renaming files provides no cryptographic protection; attackers who gain access to the storage account can still read the file contents regardless of the name. Option D is wrong because placing the storage service on a private IP address does not protect data in transit across the internet (it would still traverse public networks unless using a VPN or dedicated link), and skipping encryption leaves data at rest exposed if the account is stolen.

98
MCQmedium

An ERP database is backed up nightly to a NAS that remains online and is managed with the same admin group as production servers. After a ransomware incident, management wants the most effective change to improve recovery assurance without redesigning the whole environment. What should be implemented?

A.Increase the NAS capacity so more backup jobs can be stored.
B.Add another full backup each night to create more copies on the same NAS.
C.Use an offline or immutable backup copy and perform regular restore tests.
D.Compress the backup files to reduce network usage during the nightly job.
AnswerC

An offline or immutable backup reduces the chance that ransomware can encrypt or delete recovery data, and restore testing proves that the backups actually work. This combination improves resilience more effectively than simply storing more data on the same always-online system.

Why this answer

An offline or immutable backup copy ensures that ransomware cannot encrypt or delete the backup data, and regular restore tests verify that the backups are actually recoverable. This directly addresses the core requirement of improving recovery assurance without redesigning the environment, as it protects the backup from the same attack vector that compromised the production servers and the NAS managed by the same admin group.

Exam trap

The trap here is that candidates often assume more copies or more storage (options A and B) improve recovery assurance, but they fail to recognize that all copies on the same online, writable NAS are equally vulnerable to ransomware encryption or deletion, making isolation and immutability the key differentiators.

How to eliminate wrong answers

Option A is wrong because increasing NAS capacity only stores more backup jobs but does not protect existing backups from being encrypted or deleted by ransomware if the NAS remains online and accessible to the same admin group. Option B is wrong because adding another full backup to the same NAS creates more copies that are all equally vulnerable to the same ransomware attack, offering no isolation or protection. Option D is wrong because compressing backup files reduces network usage but does not improve recovery assurance; compressed files on the same online NAS are still susceptible to encryption or deletion by ransomware.

99
MCQeasy

A restricted server room opens only with a badge, and an alarm sounds if the door is left open too long. Which control type is the alarm?

A.Preventive control
B.Detective control
C.Corrective control
D.Deterrent control
AnswerB

A door alarm is a detective control because it alerts staff after a condition occurs, such as the door being left open too long or forced open. It helps security personnel notice a problem quickly so they can respond. In this scenario, the badge controls access, while the alarm detects an abnormal state and signals that action is needed.

Why this answer

The alarm is a detective control because it detects and alerts when a door is left open too long, indicating a potential security breach. It does not prevent the door from being opened or correct the situation; it simply notifies personnel of an ongoing or past violation.

Exam trap

CompTIA often tests the distinction between detective and corrective controls, and the trap here is that candidates mistakenly think the alarm 'corrects' the situation by alerting, but corrective controls actually take action to restore security, such as automatically closing the door.

How to eliminate wrong answers

Option A is wrong because a preventive control would stop the door from being opened or prevent the alarm condition, such as a magnetic lock that keeps the door closed. Option C is wrong because a corrective control would actively remediate the issue after detection, like automatically closing and relocking the door. Option D is wrong because a deterrent control discourages unauthorized access before it occurs, such as a visible security camera or warning sign, not an alarm that triggers after the door is left open.

100
MCQmedium

A support team wants to export customer tickets into a test analytics environment so developers can search real examples while minimizing privacy exposure. The exported data includes names, email addresses, and account IDs that are not needed for the test. What is the best first step?

A.Export the full dataset and restrict access with a shared password
B.Remove or tokenize unneeded personal identifiers before export
C.Keep the data unchanged because the test environment is internal
D.Store the export indefinitely because development data is exempt from retention rules
AnswerB

Removing or tokenizing unneeded personal identifiers before export directly implements data minimization and privacy-by-design, ensuring that only the minimum necessary information leaves the production environment. Tokenization replaces sensitive values with random placeholders that retain data format or logic for testing while preventing the recovery of original personal data without access to the token mapping. This significantly reduces the risk of unintended exposure and aligns with data protection regulations like GDPR and HIPAA.

Why this answer

Data minimization is a core privacy principle: before exporting data to a test environment, any personally identifiable information (PII) not required for the analytics task should be removed or tokenized. This reduces the attack surface and ensures compliance with privacy regulations (e.g., GDPR, CCPA) without sacrificing the utility of the real customer ticket examples.

Exam trap

The trap here is that candidates assume internal environments are automatically secure, leading them to choose Option C, but the SY0-701 exam emphasizes that data protection controls must be applied consistently regardless of environment boundaries.

How to eliminate wrong answers

Option A is wrong because restricting access with a shared password does not remove the unneeded personal identifiers; it only adds a weak, shared credential that can be easily compromised, leaving the full PII exposed in the test environment. Option C is wrong because keeping the data unchanged assumes an internal test environment is inherently safe, which ignores the risk of insider threats, misconfigurations, or data leaks; privacy protections must be applied regardless of environment classification.

101
MCQmedium

A security analyst is reviewing authentication logs from a corporate web application. The logs show thousands of failed login attempts over the past hour. Each attempt uses a different username, but all attempts use the same password 'Spring2024!'. The source IP addresses are widely distributed across several different geographic regions. Which type of attack is the analyst most likely observing?

A.Brute-force attack
B.Password spraying attack
C.Credential stuffing attack
D.Dictionary attack
AnswerB

Password spraying is an attack technique where a single common password (or a short list) is attempted against a large number of user accounts, typically once per account to avoid triggering account lockout policies. The observed authentication log pattern—many distinct usernames each tried with the same password—is the classic signature of this attack. Because each account sees only one or a few authentication failures, standard threshold-based detection often misses it until the analyst correlates across endpoints.

Why this answer

The attack uses a single common password ('Spring2024!') against many different usernames, which is the hallmark of a password spraying attack. Unlike brute-force attacks that target one account with many passwords, password spraying avoids account lockout by trying one password across many accounts. The wide distribution of source IPs is consistent with a distributed password spraying campaign, often using botnets or proxies.

Exam trap

The trap here is confusing password spraying with credential stuffing: candidates see 'different usernames' and assume stolen credentials are being used, but the single reused password across all attempts is the key differentiator for password spraying.

Why the other options are wrong

A

A brute-force attack typically targets a single username with many password attempts, but here many usernames are tried with one password, which is the opposite pattern.

C

Credential stuffing uses previously breached username/password pairs, not a single password with many usernames. The log shows the same password across different usernames, which is characteristic of password spraying, not credential stuffing.

D

A dictionary attack typically uses a list of common passwords against a single username, but here the same password is tried against many usernames, which is the opposite pattern.

When would these options actually be correct?

A

A brute-force attack would be correct if the logs showed many failed attempts for a single username with different passwords, or if the question specified that the attacker is trying all possible passwords for one account.

C

An analyst sees thousands of failed login attempts with various username/password combinations that match credentials from a known data breach. The attempts originate from multiple IPs and target a web application. This would indicate credential stuffing.

D

A dictionary attack would be correct if logs showed many failed attempts using a list of common passwords (e.g., 'password123', 'admin', '123456') against a single username, with the same source IP.

Why candidates pick the wrong answer

A

Candidates may confuse 'many attempts' with brute-force, not realizing that the key distinction is the number of usernames versus passwords tried.

C

Candidates may confuse password spraying with credential stuffing because both involve many usernames, but they fail to note that credential stuffing uses unique passwords per username from breach data, not a single password.

D

Candidates may confuse 'dictionary attack' with any attack using a wordlist, not realizing that the defining characteristic is trying many passwords per username, not many usernames per password.

102
Drag & Dropmedium

Drag and drop the steps to perform a factory reset on a managed switch into the correct order.

Drag steps to the numbered slots on the right, or tap a step then tap a slot.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Factory reset clears all configuration; the exact method may vary by vendor, but typically involves holding a button during power-on.

103
MCQmedium

A security analyst observes a pattern where an account exhibits multiple failed login attempts from an IP address in a foreign country, followed by a successful login from the same account but from a different IP address in another foreign country minutes later. The analyst wants to deploy a control that can automatically detect and alert on this type of anomalous user behavior, even if the individual login events are not blocked by existing rules. Which of the following security controls is BEST suited for this task?

A.Geofencing
B.Account lockout policy
C.User Behavior Analytics (UBA)
D.SIEM correlation rules
AnswerC

UBA establishes baselines of normal user activity and uses analytics to detect anomalies such as a series of failed logins followed by a successful login from a new geographic region. It is designed to identify suspicious behavioral patterns that other controls might miss.

Why this answer

User Behavior Analytics (UBA) is the best control because it uses machine learning to establish a baseline of normal user behavior (e.g., typical login locations, times, and IP ranges) and then detects anomalies such as a rapid sequence of failed logins from one foreign country followed by a successful login from another foreign country. Unlike static rules, UBA can identify this pattern as suspicious even if each individual login event is not blocked by existing rules, triggering an alert for further investigation.

Exam trap

The trap here is that candidates often choose geofencing because they focus on the 'foreign country' aspect, but they miss that the question requires detection of a behavioral pattern (failed then successful logins from different locations), not just location-based blocking.

Why the other options are wrong

A

Geofencing blocks or allows access based on geographic location, but it does not analyze sequential behavior patterns like multiple failed logins from one country followed by a successful login from another. It would block the second login if the country is restricted, but it cannot detect the anomalous sequence of events.

B

An account lockout policy would block further attempts after a threshold of failed logins, but it would not detect or alert on the anomalous pattern of failed logins from one foreign IP followed by a successful login from another foreign IP, as the successful login occurs after the lockout threshold may have reset or not been reached.

D

SIEM correlation rules require predefined patterns to trigger alerts, but the question describes anomalous behavior that may not have a known pattern. UBA is better suited because it uses machine learning to establish a baseline and detect deviations without predefined rules.

When would these options actually be correct?

A

A company wants to prevent any login attempts from specific high-risk countries, regardless of user behavior. The analyst needs a control that blocks access based on geographic location alone. Geofencing would be the correct answer.

B

An account lockout policy would be the correct answer for a question asking: 'Which control should be implemented to prevent brute-force attacks on user accounts by disabling the account after a specified number of failed login attempts?'

D

A question asks: 'A security team needs to correlate logs from multiple sources to detect a known attack pattern involving multiple failed logins followed by a successful login from the same IP. Which control should be used?' In that case, SIEM correlation rules would be correct because the pattern is known and can be defined.

Why candidates pick the wrong answer

A

Candidates may think geofencing can detect anomalous location changes, but it only enforces static location-based rules, not behavioral patterns across multiple events.

B

Candidates may think that locking the account after multiple failed attempts would prevent the subsequent successful login, but the question focuses on detection and alerting of anomalous behavior, not prevention of the successful login.

D

Candidates may think SIEM correlation rules can detect any sequence of events, but they require explicit rule definitions, whereas UBA can automatically learn normal behavior and detect anomalies without manual rule creation.

104
Drag & Dropmedium

Drag and drop the steps for a typical digital forensics investigation process in the correct order.

Drag steps to the numbered slots on the right, or tap a step then tap a slot.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Digital forensics follows a structured process: identification, preservation, collection, examination, analysis, and reporting.

105
Multi-Selectmedium

An organization is implementing a third-party vendor risk management program. Which three of the following should be included as key activities to maintain oversight of vendor security? (Choose three.)

Select 3 answers
.Performing due diligence assessments before onboarding new vendors
.Requiring all vendors to use the same password manager as the organization
.Including security requirements in contracts and service-level agreements
.Conducting periodic security reviews or audits of critical vendors
.Providing vendor staff with direct access to internal source code repositories
.Automatically renewing vendor contracts unless a security incident occurs

Why this answer

Performing due diligence assessments before onboarding new vendors is correct because it allows the organization to evaluate a vendor's security posture, compliance, and risk level before any contractual relationship begins. This proactive step helps identify potential vulnerabilities or gaps that could expose the organization to third-party risks, aligning with the NIST SP 800-161 supply chain risk management framework.

Exam trap

The trap here is that candidates may mistakenly think requiring vendors to use the same password manager is a valid oversight activity, but it is an operational control that violates vendor autonomy and does not fit the definition of key vendor risk management program activities.

106
MCQmedium

Based on the exhibit, what network attack is most likely occurring on the office LAN?

A.ARP poisoning, because a rogue system is sending false layer 2 address mappings.
B.Replay attack, because the same ARP reply appears multiple times.
C.Denial of service, because users notice certificate warnings.
D.DNS poisoning, because the users cannot reach internal sites cleanly.
AnswerA

ARP poisoning is the best answer because the capture shows false ARP replies mapping the gateway IP to a different MAC address. The alternating gateway cache entries and certificate warnings are consistent with traffic being redirected through an attacker in a man-in-the-middle position.

Why this answer

ARP poisoning is the correct answer because the exhibit shows a rogue system sending unsolicited ARP replies that map the gateway's IP address to the attacker's MAC address. This causes traffic destined for the gateway to be redirected to the attacker, enabling man-in-the-middle interception. The attack exploits the lack of authentication in ARP, allowing false layer 2 address mappings to corrupt the ARP cache of other hosts on the LAN.

Exam trap

The trap here is that candidates may confuse ARP poisoning with DNS poisoning because both involve false mappings, but ARP poisoning operates at layer 2 (MAC addresses) while DNS poisoning operates at the application layer (domain names), and the exhibit's focus on MAC address mappings clearly points to ARP.

How to eliminate wrong answers

Option B is wrong because replay attacks involve capturing and retransmitting valid packets, but the exhibit shows multiple identical ARP replies from a single rogue source, not a replay of a legitimate ARP response. Option C is wrong because certificate warnings are typically associated with TLS/SSL interception or rogue access points, not directly with ARP poisoning, and the exhibit does not indicate a denial of service condition. Option D is wrong because DNS poisoning targets the DNS resolver cache with false domain-to-IP mappings, whereas the exhibit shows ARP replies manipulating MAC-to-IP mappings at layer 2, not DNS records.

107
MCQhard

Based on the exhibit, what should be implemented to reduce the blast radius if a backup server is compromised later? Backup job configuration: algorithm=AES-256-GCM key_file=/opt/backup/key.bin rotation=disabled same_key_for_all_sites=true backup_media copied to an offsite vault each night

A.Use envelope encryption with unique data encryption keys protected by a KMS-managed key encryption key.
B.Store the same key in a password-protected ZIP archive on the backup server.
C.Replace AES with SHA-256 so the files cannot be opened directly.
D.Keep one key forever and increase the backup frequency.
AnswerA

Envelope encryption creates a key hierarchy in which each backup gets a unique data encryption key (DEK), and that DEK is wrapped by a key encryption key (KEK) managed inside a KMS. Because the KEK never leaves the KMS and can be rotated or access-controlled independently, compromise of one backup's wrapped DEK does not reveal the KEK or unlock other backups. Unique per-backup DEKs also make forensic isolation, cryptoperiod limits, and revocation practical, directly reducing the blast radius of any single key exposure.

Why this answer

Envelope encryption with unique data encryption keys (DEKs) protected by a KMS-managed key encryption key (KEK) ensures that even if the backup server is compromised, the attacker cannot decrypt all backups because each backup uses a different DEK, and the KEK is stored externally in a KMS. This limits the blast radius to only the data encrypted with the compromised DEK, rather than exposing all historical backups encrypted with a single static key.

Exam trap

CompTIA often tests the distinction between encryption and hashing, and the trap here is that candidates may confuse SHA-256 (a hash) with AES (an encryption algorithm), or assume that storing the key in a password-protected archive provides adequate security, ignoring that the key is still co-located with the data on the compromised server.

How to eliminate wrong answers

Option B is wrong because storing the same key in a password-protected ZIP archive on the backup server does not reduce the blast radius; if the backup server is compromised, the attacker can access the ZIP file and attempt to crack the password, potentially exposing all backups. Option C is wrong because SHA-256 is a hashing algorithm, not an encryption algorithm; it cannot be used to encrypt files, and replacing AES with SHA-256 would make the data irreversible, not securely encrypted. Option D is wrong because keeping one key forever and increasing backup frequency actually increases the blast radius; if that single key is compromised, all backups (past and future) are exposed, and more frequent backups mean more data at risk.

108
MCQhard

Based on the exhibit, what is the best fix so role changes are reflected promptly in the application? Token and directory data: 09:10 Token issued for user jdoe groups=[Finance_Approver, Expense_Reviewer] auth_time=09:10 exp=17:10 09:15 HR updated directory: jdoe moved to Sales 11:00 The application still accepts the original token and allows expense approval 11:01 Identity provider logs show no token revocation event

A.Increase the token lifetime so users reauthenticate less often.
B.Shorten token and session lifetime and revoke active tokens when the directory role changes.
C.Move the application to a different subnet to isolate it from HR systems.
D.Disable group-based authorization and let any authenticated user approve expenses.
AnswerB

This is the correct fix because it combines two complementary controls: shortening token and session lifetimes limits the maximum time any token can carry stale role claims, while revoking active tokens at the moment the directory role changes actively invalidates already-issued tokens so the authorization change is enforced immediately. Together these ensure that after a role change, the user cannot continue using old tokens with outdated permissions — they must obtain a new token with the updated role. This directly addresses the root cause of stale claims persisting in the system.

Why this answer

The token's long lifetime (issued at 09:10, expires at 17:10) allows the application to continue accepting the original token even after the user's directory role changes at 09:15. Shortening the token lifetime forces more frequent reauthentication, and revoking active tokens when the directory role changes ensures that the application immediately reflects the updated authorization. This aligns with the principle of dynamic access control and token lifecycle management.

Exam trap

The trap here is that candidates may think increasing token lifetime improves user experience, but the question specifically asks for the best fix to reflect role changes promptly, which requires shorter lifetimes and revocation, not longer ones.

How to eliminate wrong answers

Option A is wrong because increasing the token lifetime would make the problem worse, as the stale token would remain valid even longer, delaying role change reflection. Option C is wrong because moving the application to a different subnet does not address the token validity or directory synchronization issue; it is a network isolation measure unrelated to authorization updates. Option D is wrong because disabling group-based authorization removes the security control entirely, allowing any authenticated user to approve expenses, which violates the principle of least privilege and could lead to unauthorized actions.

109
Matchingeasy

Match each security principle to the best description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Preventing unauthorized disclosure of information.

Ensuring data is not altered without authorization.

Keeping systems and data accessible when needed.

Giving a user only the permissions required to do the job.

Limiting access to information that a person specifically needs for their role.

Why these pairings

These pairings match the CIA triad plus additional principles: confidentiality restricts access, integrity prevents unauthorized changes, availability ensures uptime, non-repudiation provides proof of actions, authentication verifies identity, and authorization defines permissions.

110
MCQeasy

A security tool reports repeated DNS requests for long, random-looking subdomains under the same domain name. What is the most likely explanation?

A.DNS tunneling used to hide command-and-control traffic.
B.A normal software update process from the operating system.
C.A successful password reset workflow for users.
D.A hardware failure on the network adapter.
AnswerA

Repeated DNS queries for long, random subdomains are a hallmark of DNS tunneling, where an attacker encodes exfiltrated data or command-and-control messages in the domain name labels of DNS requests. Because most networks permit outbound DNS traffic, malware can use this channel to bypass firewalls and proxies, with responses from the authoritative server carrying the opposite direction of the conversation. The high entropy and volume of the subdomains make the traffic stand out to security monitoring tools.

Why this answer

DNS tunneling encodes non-DNS traffic (e.g., C2 commands) into DNS queries and responses, often using long, random-looking subdomains to evade detection. Repeated requests for such subdomains under a single domain are a classic indicator of data exfiltration or covert channel activity, as each query can carry a small payload.

Exam trap

The trap here is that candidates may confuse DNS tunneling with legitimate DNS behavior like load balancing or CDN resolution, but the randomness and repetition of subdomains under a single domain are the key differentiators for malicious covert channels.

How to eliminate wrong answers

Option B is wrong because normal software updates use predictable, vendor-specific domains and do not generate random-looking subdomains; they typically fetch files from known URLs or CDNs. Option C is wrong because password reset workflows involve HTTP/HTTPS traffic to a web application, not DNS queries with random subdomains; DNS is not used to carry password reset data.

111
Matchingeasy

Match the security need to the best cryptographic solution.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Use a hash value.

Use symmetric encryption.

Use asymmetric encryption.

Use a digital signature.

Why these pairings

Confidentiality uses encryption; integrity uses hashes; authentication uses certificates; non-repudiation uses signatures; access control uses PKI; availability uses redundancy.

112
MCQhard

Based on the exhibit, what change would best protect the password database against precomputed attacks and make identical passwords less obvious?

A.Encrypt each password with the same server key before storing it in the database.
B.Add a unique salt to each password before hashing it.
C.Use a digital signature on each password record so the database can verify authenticity.
D.Store the password hashes in uppercase so attackers cannot compare them easily.
AnswerB

Salting is the best fix because it adds unique random data to each password before hashing, so identical passwords no longer produce the same stored value. That defeats rainbow tables and makes precomputed attacks far less useful. It also means attackers cannot easily compare two users' hashes to confirm they chose the same password, which improves both security and privacy.

Why this answer

Adding a unique salt to each password before hashing ensures that even if two users have the same password, their hashes will differ. This defeats precomputed attacks like rainbow tables because the attacker would need to compute a separate table for each salt value, which is computationally infeasible. Salting is a standard defense recommended by NIST SP 800-63B and implemented in modern systems like bcrypt, scrypt, and PBKDF2.

Exam trap

The trap here is that candidates often confuse encryption with hashing or think that obfuscation techniques like case changes provide security, when in fact only salting with a unique random value prevents precomputed attacks and hides password equality.

How to eliminate wrong answers

Option A is wrong because encrypting passwords with a server key still allows identical passwords to produce identical ciphertexts, making them obvious to an attacker who obtains the encrypted database; encryption is reversible if the key is compromised, whereas hashing with salt is one-way. Option C is wrong because a digital signature verifies the integrity and authenticity of the password record but does not prevent precomputed attacks or mask identical passwords; it addresses tampering, not password storage security. Option D is wrong because converting hashes to uppercase is a trivial transformation that does not change the underlying hash value; an attacker can simply convert their rainbow table hashes to uppercase and still match identical passwords.

113
MCQhard

A SaaS portal issues signed JWTs in a browser cookie. The help desk confirms a user logged out at 09:10, but SIEM logs show the same token was accepted from a different IP at 09:12 and continued working until the token expired. The application does not keep a server-side revocation list. What weakness is most likely being abused?

A.SQL injection, because the attacker must be manipulating backend database logic to reuse the token.
B.Session hijacking or session abuse, because the attacker can replay a valid token after logout without revocation.
C.Insecure deserialization, because the token is being decoded and reconstructed on the server.
D.Cross-site request forgery, because the request is coming from a different IP address.
AnswerB

This is session hijacking or session abuse because the attacker is using a valid session token outside the original user context. JWTs are often stateless, so if the application does not track revocation, logout may not immediately invalidate a copied token. The cross-IP reuse after logout strongly suggests the token was stolen or replayed and remained acceptable until its normal expiration.

Why this answer

The scenario describes a classic session hijacking or session abuse attack. The application issues signed JWTs in cookies and does not maintain a server-side revocation list, meaning once a token is issued, it remains valid until its expiration. Even after the legitimate user logs out at 09:10, the attacker can replay the same JWT from a different IP at 09:12, and the server will accept it because there is no mechanism to invalidate the token.

This lack of revocation is the core weakness being exploited.

Exam trap

The trap here is that candidates may confuse session hijacking with CSRF, but CSRF requires a forged request from a different site, not simply a different IP address, and the key issue is the lack of token revocation after logout.

How to eliminate wrong answers

Option A is wrong because SQL injection involves manipulating database queries through input fields, not replaying a valid JWT; the attacker is not altering backend logic but simply reusing a stolen token. Option C is wrong because insecure deserialization refers to vulnerabilities when untrusted data is deserialized, potentially leading to remote code execution, but JWTs are typically decoded and verified using cryptographic signatures, not deserialized in a way that allows code injection. Option D is wrong because cross-site request forgery (CSRF) exploits the trust a site has in a user's browser by forging requests from a different origin, not by replaying a token from a different IP address; the IP change alone does not indicate CSRF.

114
MCQmedium

After restoring a virtual file server from last night’s backup, users can browse shares, but finance reports that several spreadsheet edits from yesterday are missing. What should the administrator verify next before declaring the restore successful?

A.Whether the backup job used the correct restore point and included the needed transaction logs.
B.Whether the file server antivirus signatures are fully up to date.
C.Whether the share permissions were tightened during the restore.
D.Whether the virtual machine has enough CPU and memory allocated.
AnswerA

This is the best next verification because the missing spreadsheet edits suggest the restore point may be older than the required recovery window, or application-related log data may not have been captured. Confirming the exact backup set, restore timestamp, and transaction log coverage helps determine whether the restore actually meets the business recovery objective. It also shows whether the issue is incomplete backup scope or simple user expectation mismatch.

Why this answer

The missing spreadsheet edits indicate that the backup may have been taken before those changes were committed. The administrator must verify that the restore point includes the necessary transaction logs (e.g., from a VSS-aware backup or application-consistent snapshot) to recover the most recent data. Without these logs, any edits made after the last full backup are lost, so confirming the correct restore point and log inclusion is the next logical step before declaring success.

Exam trap

The trap here is that candidates assume a successful restore of shares means all data is intact, overlooking the critical distinction between crash-consistent and application-consistent backups and the role of transaction logs in recovering recent changes.

How to eliminate wrong answers

Option B is wrong because antivirus signature updates are unrelated to data loss from a backup restore; they address malware protection, not file version recovery. Option C is wrong because share permissions control access rights, not the content or version of files; tightening permissions during restore would not cause missing edits. Option D is wrong because CPU and memory allocation affect performance, not the integrity or completeness of restored data; insufficient resources might slow access but cannot cause specific edits to vanish.

115
Multi-Selectmedium

A small enterprise is rebuilding its public customer portal. The web front end must be reachable from the internet, the application tier should never be directly exposed, and the database must remain private even if the web server is compromised. Which two design changes best meet those goals? Select two.

Select 2 answers
A.Place the web front end in a DMZ behind a firewall rule allowing only HTTPS from the internet.
B.Put the database on the same subnet as the web front end so internal calls have lower latency.
C.Place the application tier on an internal subnet and allow only the web front end to reach it on the app port.
D.Allow the database to accept connections from the internet if strong passwords are used.
E.Disable all inbound filtering on the DMZ so troubleshooting is simpler.
AnswersA, C

A DMZ is the correct place for the internet-facing web front end because it limits exposure if the server is attacked. Allowing only HTTPS from the internet reduces unnecessary access and supports a tight inbound filtering strategy. This choice fits a common secure web architecture pattern and keeps the higher-value internal systems separate from direct public reach.

Why this answer

Placing the web front end in a DMZ behind a firewall rule that permits only HTTPS (TCP/443) from the internet ensures the public-facing component is isolated from internal networks. This design prevents direct inbound access to the application or database tiers, reducing the attack surface while still allowing legitimate web traffic.

Exam trap

The trap here is that candidates often assume placing the database on the same subnet as the web server improves performance (Option B) without recognizing that it sacrifices security isolation, which is the primary goal in this scenario.

116
MCQhard

Based on the exhibit, what control type is the file integrity monitor providing?

A.Preventive control, because the file monitor stopped the change from occurring.
B.Detective control, because the tool identifies the unauthorized change and alerts the SOC.
C.Corrective control, because the monitor automatically fixed the configuration after the change.
D.Directive control, because the alert tells administrators what they should review next.
AnswerB

Detective control is correct because the tool notices that a protected file changed and notifies the security team. It does not stop the change or restore the original configuration automatically. That means its role is to discover suspicious activity so analysts can investigate and respond. The recorded hashes and alert timing clearly show post-event detection.

Why this answer

A file integrity monitor (FIM) operates by comparing current file hashes against a known good baseline. When it detects a hash mismatch, it generates an alert to the Security Operations Center (SOC). This is a detective control because it identifies and reports the unauthorized change after it has occurred, rather than preventing or automatically correcting it.

Exam trap

The trap here is that candidates confuse the alerting mechanism of a detective control with the action of a preventive or corrective control, mistakenly thinking that because the tool 'monitors' it must be preventing or fixing changes.

How to eliminate wrong answers

Option A is wrong because a file integrity monitor does not stop changes from occurring; it only detects changes after they happen, making it a detective control, not a preventive one. Option C is wrong because corrective controls automatically remediate issues, but a standard FIM does not automatically fix configuration changes; it only alerts. Option D is wrong because directive controls are policies or guidelines that define acceptable behavior, not tools that generate alerts; the alert is a detective function, not a directive one.

117
MCQmedium

EDR alerts show a finance laptop spawning an unsigned executable from %AppData%, attempting to read LSASS memory, and making outbound HTTPS connections to a rare domain. The user says they only opened a spreadsheet attachment. What is the best immediate action?

A.Reboot the laptop to clear any malicious process from memory.
B.Isolate the laptop from the network using the EDR platform.
C.Run a full antivirus scan and wait for the results before taking further action.
D.Reset the user's password and keep the laptop online for monitoring.
AnswerB

Network isolation immediately stops outbound command-and-control traffic and reduces the chance of lateral movement. It also preserves the endpoint for later forensics better than powering it off or wiping it. Because the host is still active, isolation is the safest containment step while the team gathers volatile evidence and decides on eradication.

Why this answer

The EDR alerts indicate a likely credential theft attempt (LSASS read) and C2 communication (rare domain). Isolating the laptop immediately stops data exfiltration and lateral movement, which is the priority before any remediation. Reboot, scan, or password reset would not prevent the attacker from already having access to credentials or the network.

Exam trap

The trap here is that candidates think rebooting or scanning is sufficient, but CompTIA emphasizes that containment (isolation) is the immediate step to stop active compromise before any remediation or investigation.

How to eliminate wrong answers

Option A is wrong because rebooting only clears volatile memory but does not prevent the malware from persisting via the %AppData% executable or re-establishing C2; it also destroys forensic evidence. Option C is wrong because running a full antivirus scan while the laptop remains online allows continued data exfiltration and potential lateral movement; waiting for results wastes critical time. Option D is wrong because resetting the user's password does not remove the malware or stop its outbound C2 traffic, and keeping the laptop online risks further compromise.

118
MCQmedium

A business owner asks the security team to compare the cost of two controls for a legacy application in dollar terms. The team estimates the annual chance of a breach, the potential loss per event, and the expected yearly loss after each control is applied. Which risk analysis approach is being used?

A.Qualitative risk analysis
B.Quantitative risk analysis
C.Business impact analysis
D.Risk acceptance
AnswerB

Quantitative risk analysis assigns numeric values to risk components, enabling direct cost comparison. It calculates metrics such as asset value, exposure factor, single loss expectancy (SLE), annualized rate of occurrence (ARO), and annualized loss expectancy (ALE). With these figures, an organization can compare the ALE before and after implementing a control, subtract the control's annual cost, and determine if the safeguard provides a positive return on investment. This makes it the correct method for comparing the cost of security measures.

Why this answer

The question describes a risk analysis that uses dollar values for the annual chance of a breach, potential loss per event, and expected yearly loss after controls are applied. This is the hallmark of quantitative risk analysis, which assigns monetary or numerical values to risk components (e.g., ALE = SLE × ARO) to compare control costs in objective financial terms. The scenario explicitly asks for a cost comparison in dollar terms, which only a quantitative approach can provide.

Exam trap

The SY0-701 exam often tests the distinction between quantitative and qualitative risk analysis by embedding monetary terms in the scenario, leading candidates to mistakenly choose qualitative analysis when they see subjective-sounding phrases like 'annual chance' without recognizing that dollar values are the key indicator of a quantitative approach.

How to eliminate wrong answers

Option A is wrong because qualitative risk analysis uses subjective ratings (e.g., high/medium/low) rather than specific dollar amounts to assess risk, so it cannot produce the precise cost comparison described. Option C is wrong because business impact analysis (BIA) focuses on identifying critical business functions and their recovery priorities, not on comparing the cost of controls in dollar terms. Option D is wrong because risk acceptance is a risk treatment strategy where the organization acknowledges the risk without implementing additional controls, not a method for analyzing or comparing control costs.

119
MCQeasy

A vulnerability scanner reports a critical issue on a Linux server. The administrator checks the application and confirms the vulnerable package is installed, but the affected feature is not enabled anywhere in production. What should the security team do next?

A.Ignore the finding permanently because the package is installed
B.Validate whether the issue is a false positive or lower-risk finding before prioritizing remediation
C.Immediately shut down the server without further investigation
D.Apply an exception without documenting any compensating controls
AnswerB

Validating the finding first is the correct initial response because vulnerability scanners use heuristics and version matching that routinely produce false positives or conflate local attack requirements with remote exploitability. You should correlate the report against the actual running services, enabled modules, patch levels, egress/ingress filtering, and existing compensating controls; only then can you assign a realistic severity and decide whether remediation, a rescan, or an exception is warranted.

Why this answer

The vulnerability scanner reports a critical issue, but the administrator has confirmed the vulnerable package is installed while the affected feature is not enabled in production. This means the actual risk is lower than the scanner's severity rating, as exploitation requires the feature to be active. The security team should validate whether this is a false positive or a lower-risk finding to prioritize remediation efforts appropriately, ensuring resources are allocated to genuine threats.

Exam trap

The trap here is that candidates assume any 'critical' scanner finding must be immediately remediated or ignored, failing to recognize that risk assessment requires verifying the actual exploitability in the specific environment.

How to eliminate wrong answers

Option A is wrong because ignoring a finding permanently without further analysis violates security best practices; the package could be exploited if the feature is inadvertently enabled or if a different attack vector emerges. Option C is wrong because immediately shutting down the server is an overreaction that disrupts production without evidence of active exploitation, and it bypasses proper incident response procedures. Option D is wrong because applying an exception without documenting compensating controls fails to provide a risk acceptance record or mitigation strategy, which is required for auditability and future reference.

120
MCQmedium

The email security team receives a suspicious invoice attachment from a vendor. The attachment is not blocked by signature-based detection, but the team wants to observe its behavior in a safe environment before delivery to users. What tool best fits this requirement?

A.Sandboxing the attachment in an isolated analysis environment
B.Network access control for unmanaged devices
C.A data loss prevention rule on outbound email
D.An intrusion prevention system placed on the Wi-Fi network
AnswerA

A sandbox detonates the attachment in a virtualized, isolated environment, executing the file while monitoring system calls, network connections, and file-system modifications for indicators of compromise. This dynamic analysis reveals malicious behavior that static inspection might miss, such as obfuscated macros or exploit payloads. Because the environment is isolated, any malicious payload is contained and cannot affect production hosts, and the resulting behavioral telemetry can be used to update detection signatures before the email reaches users.

Why this answer

A sandbox provides an isolated, controlled environment where the suspicious attachment can be executed and monitored for malicious behavior without risking the production network. This allows the security team to observe dynamic indicators such as file system changes, registry modifications, or outbound connections that signature-based detection might miss. The goal is to analyze the attachment's true intent before deciding whether to deliver it to users.

Exam trap

The trap here is that candidates may confuse signature-based detection with behavioral analysis, thinking that a signature-based tool (like an IPS or antivirus) can analyze unknown threats, when in fact only a sandbox can safely execute and observe the behavior of a suspicious file.

How to eliminate wrong answers

Option B is wrong because Network Access Control (NAC) is used to enforce security policies on devices attempting to connect to the network, not to analyze the behavior of email attachments. Option C is wrong because a Data Loss Prevention (DLP) rule on outbound email is designed to prevent sensitive data from leaving the organization, not to observe the behavior of an incoming attachment. Option D is wrong because an Intrusion Prevention System (IPS) on the Wi-Fi network monitors and blocks malicious network traffic in real time, but it cannot execute or sandbox an email attachment to observe its behavior.

121
Multi-Selectmedium

A firewall rule was changed in production to allow a new vendor IP range, and payroll users immediately lost access to an internal service. Which two change-management practices would have reduced the risk of this outage? Select two.

Select 2 answers
A.Test the rule in a staging environment with representative traffic before production deployment.
B.Require a rollback or backout plan that can quickly restore the previous rule set.
C.Make the change during the busiest business hour so the team can observe the effect immediately.
D.Remove logging on the firewall so only the new rule is visible during troubleshooting.
E.Skip approval because the vendor was already known to the organization.
AnswersA, B

Staging validation helps reveal rule-order problems, unintended blocks, and missing dependencies before users are affected. A representative test environment is especially important for firewall changes because small syntax or sequencing errors can have large business impacts. Testing reduces the chance that a production change will break unrelated services.

Why this answer

Testing the firewall rule in a staging environment with representative traffic allows you to validate that the new vendor IP range does not inadvertently block or conflict with existing rules before impacting production. This practice catches misconfigurations—such as an overly broad permit that shadows a deny rule for payroll users—without risking service disruption. Staging mirrors production ACL logic, so you can verify that the rule order and match criteria (e.g., source IP, destination port) behave as intended.

Exam trap

The trap here is that candidates often think testing in staging is unnecessary if the change seems small, or they confuse 'testing' with 'monitoring in production'—but the question specifically asks for practices that reduce risk before the outage occurs.

122
MCQmedium

A nightly patch script restarts services on 40 Linux servers. Security does not want an administrator to log in interactively, and the script should only have the permissions needed to install approved patches and restart those services. What is the best design?

A.Run the script with a dedicated automation account that has only the required sudo permissions
B.Use the root account for every scheduled execution to avoid permission errors
C.Hard-code the administrator password in the script so it never prompts
D.Ask each server owner to manually patch their system during the maintenance window
AnswerA

Using a dedicated automation account bound to a narrowly scoped sudoers policy is the correct application of least privilege. This approach grants only the specific commands the patch script needs—such as systemctl restart and package manager updates—while preventing interactive login and any access beyond the maintenance task. Because the account is non-human and non-interactive, its credentials can be securely stored in a vault or secrets manager, and its actions are fully auditable through the sudo and auditd logs. This design minimizes the blast radius if the account is compromised and ensures unattended patching remains compliant with defense-in-depth practices.

Why this answer

It follows the principle of least privilege by using a dedicated automation account with only the specific sudo permissions needed to install approved patches and restart services. This prevents interactive login (as the account is configured for non-interactive use) and ensures the script cannot perform unauthorized actions, aligning with security best practices for automated tasks.

Exam trap

The trap here is that candidates may assume root is necessary for scheduled tasks to avoid permission errors, overlooking that dedicated accounts with specific sudo rules can achieve the same goal with far less risk.

How to eliminate wrong answers

Option B is wrong because using the root account for every scheduled execution violates the principle of least privilege, granting full system access to the script, which increases the risk of accidental or malicious damage. Option C is wrong because hard-coding the administrator password in the script is a severe security risk; it exposes credentials in plaintext, allowing anyone with file read access to compromise the account, and it does not address the requirement to prevent interactive login.

123
MCQhard

Based on the exhibit, which change best improves accountability while still allowing emergency access? A finance team uses the following shared account on a jump host: 07:55:12 Account=FIN-ADMIN Action=ApproveInvoice Host=JUMP-02 IP=10.30.8.21 07:56:03 Account=FIN-ADMIN Action=ChangeVendorBank Host=JUMP-02 IP=10.30.8.21 07:57:44 Account=FIN-ADMIN Action=ExportReport Host=JUMP-02 IP=10.30.8.21 Note: FIN-ADMIN is used by three finance managers during after-hours support.

A.Require the shared account password to be changed every 24 hours.
B.Replace the shared account with named user accounts, role-based access, and a separate break-glass account for rare emergencies.
C.Enable automatic account lockout after five failed logons.
D.Restrict the jump host by MAC address and subnet only.
AnswerB

Replacing the shared account with named user accounts establishes a one-to-one binding between a human and a security principal, so access logs and system audit trails can be directly attributed to an individual for reviews or investigations. Role-based access control then enforces least privilege by granting only the permissions needed for each person's job function, while a break-glass account, protected by MFA, vaulting, and automatic alerting, retains emergency availability without sacrificing attribution. This combination directly satisfies the NIST accountability principle: knowing who did what, when, and why.

Why this answer

Replacing the shared account with named user accounts ensures individual accountability through unique credentials and audit trails, while a separate break-glass account provides emergency access without compromising security. This aligns with the principle of least privilege and non-repudiation, as each finance manager's actions are logged under their own identity, and the break-glass account can be tightly controlled and monitored for rare use.

Exam trap

The trap here is that candidates often choose password rotation (Option A) thinking it improves security, but it fails to address the core issue of non-repudiation and accountability required for audit trails.

How to eliminate wrong answers

Option A is wrong because changing the shared password every 24 hours does not eliminate the lack of individual accountability; multiple users still share the same credentials, so logs cannot distinguish which manager performed which action. Option C is wrong because account lockout after five failed logons addresses brute-force prevention, not accountability or emergency access; it does not solve the shared account issue. Option D is wrong because restricting by MAC address and subnet only controls network-level access, not user identity; it still allows multiple users to share the same FIN-ADMIN account without individual audit trails.

124
MCQmedium

An internal finance application has an RTO of 2 hours and an RPO of 30 minutes. Current backups restore in about 6 hours because the team must rebuild the server from scratch. Which change best aligns the recovery design to the business requirement?

A.Add a warm standby or replicated recovery system that can be brought online within the RTO
B.Keep the same design and simply increase backup retention
C.Switch to weekly full backups only
D.Reduce logging on the application server to improve restore speed
AnswerA

A warm standby keeps a replicated copy of the application and its data on standby infrastructure that is powered on and ready. On failure, you can redirect traffic and promote the standby in minutes, which directly satisfies the 2-hour RTO. Because replication continuously updates the recovery point, the RPO is kept small, and you avoid the long rebuild and restore process from backup media.

Why this answer

The business requires an RTO of 2 hours and an RPO of 30 minutes, but current backups take 6 hours to restore because the server must be rebuilt from scratch. Adding a warm standby or replicated recovery system allows the application to be brought online within the RTO by maintaining a pre-configured, partially synchronized environment that can be activated quickly, reducing recovery time from hours to minutes. This aligns the recovery design with the business continuity requirements by meeting both the RTO and RPO targets.

Exam trap

The trap here is that candidates may think increasing backup frequency or retention solves the RTO problem, but RTO is about recovery time, not data loss tolerance (RPO), and only a pre-staged recovery system like a warm standby can reduce the time to bring the application online.

How to eliminate wrong answers

Option B is wrong because increasing backup retention only extends the history of backups, not the speed of recovery; it does nothing to address the 6-hour restore time that violates the 2-hour RTO. Option C is wrong because switching to weekly full backups only increases the RPO to up to 7 days, far exceeding the required 30-minute RPO, and does not improve restore speed. Option D is wrong because reducing logging on the application server may slightly decrease backup size but does not eliminate the need to rebuild the server from scratch, and it can compromise audit trails and security monitoring.

125
Matchingmedium

Match each audit request to the best evidence artifact. 1. Auditors want proof that managers reviewed privileged access last quarter. 2. Auditors want evidence that an emergency firewall change was approved before implementation. 3. Auditors want to verify that annual security training was completed by staff. 4. Auditors want to confirm that records were deleted after the retention period expired.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Access review attestation report

Approved change ticket

LMS completion export

Retention deletion log

Why these pairings

Each audit request requires specific evidence: access reviews show manager sign-offs, change requests prove pre-approval, training records confirm completion, and deletion logs demonstrate data disposal per policy.

126
MCQmedium

A marketing analyst asks for a spreadsheet containing customer names, email addresses, purchase history, and government ID numbers so the team can build a campaign list. What is the BEST security response?

A.Approve the request because the data is needed for any marketing activity.
B.Provide only the minimum fields required and remove the government ID numbers.
C.Send the full file, but ask the analyst not to store it permanently.
D.Classify the file as public so it can be shared more easily with the marketing team.
AnswerB

This follows data minimization and handling requirements by sharing only what is necessary for the business purpose. Government ID numbers are highly sensitive and are not needed for a typical marketing campaign. Limiting the dataset reduces privacy exposure, lowers compliance risk, and helps ensure the data is used appropriately.

Why this answer

The best security response is to apply the principle of least privilege and data minimization. Government ID numbers are sensitive personally identifiable information (PII) that are not necessary for building a marketing campaign list; providing only the minimum required fields (e.g., names and email addresses) reduces the risk of exposure and complies with data protection regulations like GDPR or CCPA.

Exam trap

The trap here is that candidates may think 'asking not to store it permanently' is a sufficient control, but the SY0-701 exam emphasizes that administrative controls without technical enforcement (like DLP policies or data classification labels) are ineffective against data leakage.

How to eliminate wrong answers

Option A is wrong because approving the request without any data reduction violates the principle of least privilege and exposes unnecessary sensitive PII, which could lead to compliance violations and data breaches. Option C is wrong because sending the full file with only a verbal request not to store it permanently provides no technical enforcement; data can be easily copied, stored, or leaked, and this approach ignores the need for access controls and data classification. Option D is wrong because classifying the file as public would allow unrestricted access to sensitive PII, directly contradicting security policies and data protection requirements.

127
MCQeasy

An investigator needs a copy of a suspect laptop drive for analysis without changing the original media. What should be used?

A.A simple file copy of the user folder
B.A full forensic image taken with a write blocker
C.A compressed archive of the desktop contents
D.The original drive mounted normally on the investigator machine
AnswerB

This is the best answer because a forensic image creates a bit-for-bit copy of the drive while a write blocker prevents accidental changes to the original media. That combination preserves evidentiary integrity and allows the investigator to analyze the copy safely. It is the standard approach when the original disk may later be needed in court or for formal review.

Why this answer

A full forensic image taken with a write blocker is the correct method because it creates a bit-for-bit copy of the entire drive, including all partitions, unallocated space, and metadata, without altering the original media. The write blocker hardware or software ensures that no write commands reach the suspect drive, preserving its integrity for legal and evidentiary purposes. This approach is required by forensic standards such as NIST SP 800-86 and ensures the copy is admissible as evidence.

Exam trap

The trap here is that candidates confuse a simple file copy or archive with a forensically sound image, overlooking the need for a bit-for-bit copy and write protection to preserve evidence integrity.

How to eliminate wrong answers

Option A is wrong because a simple file copy of the user folder only captures visible files, not deleted data, file system metadata, or unallocated space, and it does not prevent writes to the original drive. Option C is wrong because a compressed archive of the desktop contents similarly omits critical forensic artifacts like slack space, partition tables, and hidden data, and it does not use a write blocker to protect the original media. Option D is wrong because mounting the original drive normally on the investigator machine allows the operating system to write to the drive (e.g., updating timestamps, logs, or file system metadata), which alters the evidence and violates forensic best practices.

128
MCQeasy

Employees in a server room often prop the door open while carrying equipment. What control best helps detect and prevent this behavior?

A.Install a door-ajar alarm and use a self-closing door mechanism.
B.Add more desk chairs outside the server room for convenience.
C.Increase the screen brightness on the monitoring workstation.
D.Move backup tapes to a nearby shelf for easier access.
AnswerA

A door-ajar alarm combined with a self-closing mechanism directly addresses the problem by alerting staff when the door is left open and reducing the chance that it stays open. This is a practical physical security control because it supports both detection and prevention. It helps protect restricted areas without relying only on user behavior.

Why this answer

A door-ajar alarm provides immediate notification when the door is left open, while a self-closing door mechanism physically ensures the door closes automatically after each use. Together, they directly address the behavior of propping the door open by both detecting the violation and preventing it from remaining open, which is critical for maintaining physical security controls in a server room.

Exam trap

The trap here is that candidates may choose a convenience-based option (like adding chairs or moving tapes) thinking it addresses the root cause, but the question specifically asks for a control that both detects and prevents the behavior, which only a combination of a door-ajar alarm and a self-closing mechanism achieves.

How to eliminate wrong answers

Option B is wrong because adding more desk chairs outside the server room does not detect or prevent the door from being propped open; it only addresses convenience, not security. Option C is wrong because increasing screen brightness on the monitoring workstation has no effect on door position or access control; it is a display setting unrelated to physical security. Option D is wrong because moving backup tapes to a nearby shelf does not prevent or detect the door being propped open; it only changes storage location and could even increase risk by placing sensitive media outside the secure area.

129
Multi-Selectmedium

An HR analyst must share a spreadsheet with an external auditor. The spreadsheet includes employee names, Social Security numbers, bank account numbers, and salary data, but the auditor only needs employee names and total payroll. Which three actions best protect the data? Select three.

Select 3 answers
A.Remove fields the auditor does not need before sharing the file.
B.Send the file using an encrypted transfer method.
C.Share the file only with the named auditor account or approved firm contact.
D.Leave the full spreadsheet intact because the auditor requested a copy.
E.Post the spreadsheet in a shared public portal for easier access.
AnswersA, B, C

Applying data minimization means stripping the spreadsheet to only the audit-relevant fields (e.g., payroll totals) and eliminating personally identifiable information (PII) such as Social Security numbers, birth dates, or home addresses. This limits the potential impact of a data breach and aligns with privacy frameworks like GDPR and HIPAA, which require that only necessary data be processed. By reducing the dataset before transfer, the HR analyst also shortens the retention exposure window and makes the file less attractive to attackers.

Why this answer

Removing unnecessary fields (e.g., Social Security numbers, bank account numbers) before sharing the spreadsheet minimizes the exposure of sensitive personally identifiable information (PII) and financial data. This practice, known as data minimization, aligns with the principle of least privilege and reduces the risk of unauthorized access or data breach. By stripping out extraneous columns, the HR analyst ensures the auditor receives only the required data (employee names and total payroll), thereby protecting the organization from compliance violations under regulations like GDPR or PCI DSS.

Exam trap

The trap here is that candidates may think leaving the full spreadsheet intact is acceptable because the auditor 'requested a copy,' but CompTIA tests the principle of least privilege and data minimization, meaning you must always remove unnecessary sensitive data before sharing with external parties.

130
Multi-Selectmedium

A SIEM alert shows five failed logins to a SaaS admin portal from one IP, followed by a successful login from a new city three minutes later. Which two actions are the best next steps for the analyst to validate the event before containment? Select two.

Select 2 answers
A.Review the identity provider and MFA logs to confirm the successful login came from the same account and device context.
B.Correlate the source IP with corporate VPN, CASB, or known cloud egress ranges.
C.Immediately disable the SaaS platform for every user until the investigation is finished.
D.Reimage the user’s laptop immediately to remove any possible malware.
E.Delete the failed login records to reduce noise in the SIEM.
AnswersA, B

This is the best first validation step because identity provider logs can confirm whether the login sequence used the expected MFA method, device, and authentication path. It helps distinguish suspicious access from legitimate use, such as a new browser session or a reauthentication event. Correlating the alert with authoritative identity logs also reduces reliance on a single SIEM record and improves triage accuracy.

Why this answer

Reviewing the identity provider (IdP) and MFA logs allows the analyst to verify whether the successful login originated from the same user account and device context as the failed attempts. This step is critical to determine if the successful login was an attacker who bypassed MFA or a legitimate user who eventually succeeded, providing evidence of account compromise or a false positive.

Exam trap

The trap here is that candidates may rush to containment (Option C) without first performing validation steps, failing to recognize that the question specifically asks for actions to 'validate the event before containment'.

131
MCQmedium

A help desk manager wants sample customer tickets copied into a test environment so developers can reproduce support issues. The tickets include names, phone numbers, and account details. Which action best reduces privacy exposure while still supporting testing?

A.Export the full tickets because the developers need realistic records.
B.Mask or tokenize the personal data and restrict access to approved testers only.
C.Copy the tickets to a shared cloud drive and protect it with a simple password.
D.Remove the account numbers only and leave the rest of the ticket untouched.
AnswerB

Masking or tokenizing personal data follows privacy-by-design principles by reducing exposure while preserving enough structure for testing. Limiting access further reduces the chance of improper handling. This approach allows developers to reproduce issues without using unnecessary real customer information, which supports data minimization and secure sharing requirements.

Why this answer

Masking or tokenizing personal data (e.g., replacing names with pseudonyms, scrambling phone numbers) ensures that developers can work with realistic data structures without exposing personally identifiable information (PII). Restricting access to approved testers further enforces the principle of least privilege, which is a core security control for test environments. This approach balances the need for functional testing with compliance requirements like GDPR or HIPAA.

Exam trap

The trap here is that candidates may choose Option A, thinking that 'realistic records' are essential for testing, without recognizing that realistic data can be achieved through masking rather than exposing raw PII.

How to eliminate wrong answers

Option A is wrong because exporting full tickets with unredacted PII directly violates data minimization and exposes sensitive data unnecessarily, increasing the risk of a breach even in a test environment. Option C is wrong because copying tickets to a shared cloud drive with only a simple password lacks encryption, access controls, and audit logging, which are essential for protecting PII; a simple password is easily compromised and does not meet security best practices for handling sensitive data.

132
MCQmedium

A customer service application shows the same session ID being used from two countries within five minutes. The legitimate user did not report a password change, but an order shipping address was modified successfully without reauthentication. What attack pattern is most likely?

A.Broken authentication, because the application failed to verify the user again.
B.Session abuse, because a stolen or replayed session token allowed unauthorized actions.
C.Cross-site request forgery, because the attacker may have tricked the browser into sending a request.
D.Credential stuffing, because the account was likely accessed using reused passwords.
AnswerB

Session abuse is the best fit when an attacker reuses a valid token or session ID to impersonate a user. The address change without reauthentication strongly suggests the attacker hijacked an active session instead of successfully guessing a password.

Why this answer

The simultaneous use of the same session ID from two different countries within five minutes, combined with a successful address change without reauthentication, indicates that an attacker has obtained and reused the legitimate user's session token. This is session abuse, where the attacker leverages a stolen or replayed session token to perform unauthorized actions, bypassing the need for credentials or reauthentication.

Exam trap

The trap here is that candidates confuse session abuse with broken authentication, but the key distinction is that the session token was already valid and reused, not that the authentication mechanism itself was flawed during login.

How to eliminate wrong answers

Option A is wrong because broken authentication typically refers to flaws in the login or credential verification process, not the reuse of a valid session token; the application did verify the user initially, but failed to detect token theft or enforce reauthentication for sensitive actions. Option C is wrong because cross-site request forgery (CSRF) relies on tricking the user's browser into making an unintended request using the user's existing session, but the scenario describes the same session ID being used from two different countries, which is a sign of token theft, not a forged request from the user's browser. Option D is wrong because credential stuffing involves using stolen username/password pairs to gain access, but the session ID is already active and the password was not changed, indicating the attacker bypassed authentication entirely by reusing the session token.

133
MCQmedium

A security analyst receives reports that several employees are being redirected to a fraudulent login page after typing the correct URL for a company application into their browser. Further investigation reveals that the company's internal DNS server has been compromised. Which type of attack best describes this scenario?

A.Phishing
B.Spear phishing
C.Pharming
D.Vishing
AnswerC

Pharming is an attack that manipulates the domain resolution process, typically by poisoning a DNS server or altering a local hosts file. When an employee enters the correct URL, the system receives a malicious IP address and silently lands on a fraudulent website, so no click on a poisoned link is required. Because this scenario explicitly mentions a DNS server compromise that redirects users system-wide, pharming directly matches the mechanism and scope described.

Why this answer

Pharming is correct because the attack redirects users from a legitimate website to a fraudulent one without their knowledge or interaction, typically by compromising the DNS resolution process. In this scenario, the internal DNS server has been compromised, so when employees type the correct URL, the DNS server returns the IP address of a fake login page instead of the real one. This is a classic example of DNS poisoning, a form of pharming.

Exam trap

The trap here is that candidates often confuse pharming with phishing because both involve fake login pages, but pharming does not require the user to click a link—it subverts the DNS resolution process, making it a technical infrastructure attack rather than a social engineering one.

Why the other options are wrong

A

Phishing typically involves deceptive emails or messages to trick users into revealing credentials, not compromising a DNS server to redirect users to a fraudulent site.

B

Spear phishing targets specific individuals via email, not DNS manipulation. The scenario involves DNS compromise redirecting users to a fake site, which is pharming.

D

Vishing (voice phishing) uses phone calls or voice messages to trick victims, not DNS manipulation to redirect web traffic.

When would these options actually be correct?

A

Phishing would be correct if the question described employees receiving fraudulent emails with links to a fake login page, without any mention of DNS compromise.

B

A security analyst finds that employees received personalized emails with a link to a fraudulent login page that mimics the company application, and the emails were crafted using information from social media. This would be spear phishing.

D

A security analyst receives reports that employees are getting fraudulent calls asking them to disclose their login credentials for a company application. Which type of attack best describes this scenario?

Why candidates pick the wrong answer

A

Candidates may confuse pharming with phishing because both involve redirecting users to fake sites, but phishing relies on social engineering via messages, while pharming manipulates DNS or host files.

B

Candidates may confuse targeted redirection (pharming) with targeted email attacks (spear phishing) because both involve deceiving users into entering credentials on fake pages.

D

Candidates may confuse vishing with other phishing variants because all involve social engineering, but they overlook the technical mechanism (DNS compromise) that distinguishes pharming from voice-based attacks.

134
MCQmedium

An investigator must collect data from a suspected insider-threat laptop so the evidence could be used in an HR and legal review. Which action best preserves admissibility?

A.Boot the laptop normally and browse the user's files for clues
B.Create a forensic image through a write blocker and record hashes before and after acquisition
C.Copy the user's documents to a USB drive and continue the investigation later
D.Take screenshots of the desktop and delete the original drive contents afterward
AnswerB

This is the correct preservation method because it avoids altering the original disk and creates verifiable integrity checks. Using a write blocker prevents writes to the source media, and hashes document that the image matches the evidence. Detailed chain-of-custody records then support admissibility in HR, disciplinary, or legal proceedings.

Why this answer

Creating a forensic image through a write blocker ensures the original evidence is not altered, preserving its integrity for admissibility in HR and legal proceedings. Recording hashes before and after acquisition allows verification that the image is an exact, unmodified copy, which is critical for chain of custody and meeting legal standards such as Daubert or Federal Rules of Evidence.

Exam trap

The trap here is that candidates may think booting normally or copying files is sufficient for evidence collection, but the exam emphasizes that any action that modifies the original media breaks the chain of custody and makes evidence inadmissible in legal proceedings.

How to eliminate wrong answers

Option A is wrong because booting the laptop normally modifies the system (e.g., writes to the page file, updates timestamps, and alters registry keys), which can destroy volatile evidence and render the data inadmissible due to lack of integrity. Option C is wrong because copying user documents to a USB drive without using a write blocker or imaging tool alters file metadata (e.g., last access times) and does not capture deleted files or slack space, breaking the forensic soundness required for legal review. Option D is wrong because taking screenshots only captures a superficial view and does not preserve the full disk state, while deleting the original drive contents destroys the primary evidence, making it impossible to verify or challenge the screenshots later.

135
MCQeasy

Based on the exhibit, what wireless threat is most likely occurring?

A.Evil twin access point
B.Bluetooth pairing abuse
C.NFC skimming
D.DNS poisoning
AnswerA

Two access points are broadcasting the same SSID, but one has a much stronger signal and triggers a suspicious captive portal. That pattern fits an evil twin access point, which imitates a legitimate network to lure users into connecting. The attacker can then intercept traffic or harvest credentials.

Why this answer

The exhibit shows a legitimate access point (SSID: 'CorpNet') with a second, rogue access point broadcasting the same SSID but with a stronger signal. This is the classic behavior of an evil twin attack, where an attacker sets up a fraudulent AP to intercept client connections and capture credentials or sensitive data. The victim's device automatically associates with the stronger signal, believing it is the legitimate network.

Exam trap

The trap here is that candidates confuse an evil twin with a rogue access point—a rogue AP is an unauthorized device plugged into the wired network, while an evil twin is a standalone attacker AP that mimics a legitimate SSID over the air.

How to eliminate wrong answers

Option B is wrong because Bluetooth pairing abuse involves exploiting Bluetooth connections (e.g., Bluejacking, Bluesnarfing), not Wi-Fi SSID spoofing or signal strength manipulation. Option C is wrong because NFC skimming targets contactless payment or data exchange via near-field communication, which operates at a range of ~4 cm and does not involve Wi-Fi access points or SSIDs. Option D is wrong because DNS poisoning corrupts DNS resolver caches to redirect traffic to malicious sites, but the exhibit shows no DNS server manipulation or altered IP resolution—only two APs with the same SSID.

136
MCQeasy

A laptop repeatedly starts with an unapproved bootloader, and the security team wants the firmware to refuse boot code that is not signed by a trusted key. Which feature should be used?

A.Secure Boot.
B.BitLocker full-disk encryption.
C.A DHCP reservation.
D.A local administrator password policy.
AnswerA

This is the best answer because Secure Boot verifies that boot components are signed by trusted keys before allowing them to load. That helps prevent bootkits and other pre-boot tampering from taking control before the operating system starts. It is a core platform hardening feature on modern systems and directly addresses trust in the boot process.

Why this answer

Secure Boot is a UEFI firmware feature that verifies the digital signature of bootloaders and kernel code against a database of trusted keys before allowing execution. By configuring Secure Boot to only accept boot code signed by a trusted key, the firmware will reject any unapproved bootloader, preventing unauthorized code from running during the boot process.

Exam trap

The trap here is that candidates often confuse Secure Boot with BitLocker, thinking that disk encryption also verifies boot integrity, but BitLocker only protects data after the OS loads and does not validate the bootloader's signature.

How to eliminate wrong answers

Option B is wrong because BitLocker full-disk encryption protects data at rest by encrypting the entire drive, but it does not validate the integrity or signature of boot code before execution. Option C is wrong because a DHCP reservation assigns a fixed IP address to a device based on its MAC address and has no role in verifying bootloader signatures or firmware-level security. Option D is wrong because a local administrator password policy controls password complexity and expiration for local user accounts, but it does not enforce cryptographic verification of boot components.

137
MCQmedium

During morning SIEM review, an analyst sees 37 failed SSH logins followed by a successful login to a Linux server from a jump host. The account belongs to a configuration-management service account, and the activity occurred inside the normal maintenance window. What should the analyst do next to determine whether the alert is a true positive or a false positive?

A.Immediately isolate the Linux server from the network and begin recovery.
B.Correlate the event with the approved maintenance ticket and automation job logs.
C.Reset the service account password before reviewing any additional evidence.
D.Disable SSH on the server until the next patch cycle is complete.
AnswerB

Matching the authentication pattern to a change ticket and automation logs is the best validation step. It confirms whether the repeated failures and successful login were produced by an approved task rather than malicious activity. This is the most efficient way to distinguish a true positive from an expected operational event without disrupting a legitimate maintenance process.

Why this answer

The analyst should correlate the failed SSH logins with the approved maintenance ticket and automation job logs to verify if the activity is expected. The failed logins followed by a successful login from a jump host during a maintenance window are consistent with a configuration-management tool (e.g., Ansible, Puppet) retrying authentication. This correlation confirms whether the alert is a true positive (unauthorized access) or a false positive (routine automation).

Exam trap

The trap here is that candidates assume any failed logins followed by a success indicate a brute-force attack, but the context of a maintenance window and a service account points to legitimate automation retries, not malicious activity.

How to eliminate wrong answers

Option A is wrong because immediately isolating the Linux server is premature and disruptive; the activity occurred during a maintenance window and may be legitimate automation, so isolation should only occur after confirming malicious intent. Option C is wrong because resetting the service account password without reviewing evidence could break legitimate automation jobs and does not address the need to determine if the alert is a true or false positive. Option D is wrong because disabling SSH on the server is an overreaction that would block all remote administration, including legitimate maintenance, and is not a diagnostic step.

138
MCQeasy

A department identifies a low-likelihood software risk that would be expensive to fix right now. Leadership decides the business can live with the exposure for now, but wants it documented and reviewed later. What risk treatment is this?

A.Mitigate the risk by applying a technical control immediately
B.Accept the risk with documented approval and periodic review
C.Transfer the risk to an insurer or third party
D.Avoid the risk by stopping the business activity entirely
AnswerB

Acceptance is a formal risk response in which the risk owner acknowledges the residual risk and documents the decision to tolerate it, often with a justification such as low likelihood and minimal impact. In this case, because the business has decided not to fix the issue now, the correct step is to record that approval and schedule periodic reviews to ensure the risk remains within the organization's risk appetite. This differs from ignoring the risk; it requires ongoing monitoring and reassessment to detect when the risk level changes and the cost of mitigation eventually becomes justified.

Why this answer

The scenario describes a low-likelihood, high-cost software risk that leadership chooses to tolerate rather than fix immediately. This is the definition of risk acceptance, which requires documented approval and periodic review to ensure the risk remains acceptable over time. The correct risk treatment is to formally accept the exposure with a record of the decision and a schedule for reassessment.

Exam trap

The trap here is that candidates often confuse risk acceptance with risk mitigation, thinking that documenting a risk means a control is applied, but acceptance explicitly means no control is implemented and the exposure is tolerated with formal sign-off.

How to eliminate wrong answers

Option A is wrong because mitigation would require applying a technical control immediately, which contradicts the scenario's premise that the fix is too expensive and the business can live with the exposure. Option C is wrong because transferring the risk would involve shifting the financial impact to an insurer or third party via a contract or insurance policy, not simply documenting and reviewing the risk internally. Option D is wrong because avoidance means stopping the business activity entirely, which is not what leadership wants; they want to continue the activity while accepting the residual risk.

139
MCQeasy

Based on the exhibit, which governance artifact is the security team reviewing?

A.Policy, because it describes the organization's overall intent and direction.
B.Standard, because it sets mandatory technical requirements for systems.
C.Baseline, because it defines the approved minimum configuration for a system type.
D.Procedure, because it gives step-by-step instructions for completing a task.
AnswerC

A baseline is the correct term when a document defines the minimum approved configuration for a class of systems. The exhibit shows a named configuration for all production Linux servers, includes specific required settings, and is approved for consistent use. That matches the purpose of a baseline much better than a policy, guideline, or procedure.

Why this answer

The exhibit shows a list of approved operating systems, software versions, and patches for a specific system type (e.g., Windows 10 22H2 with specific security updates). This is a baseline, which defines the minimum acceptable configuration for a system type. Option C is correct because a baseline establishes a known good state that systems must meet, not just intent (policy), mandatory technical requirements (standard), or step-by-step instructions (procedure).

Exam trap

The trap here is that candidates confuse a baseline with a standard, but a standard is broader (e.g., 'use HTTPS') while a baseline is specific (e.g., 'TLS 1.2 with these cipher suites'), so the detailed version list in the exhibit points to a baseline, not a standard.

How to eliminate wrong answers

Option A is wrong because a policy describes high-level intent and direction (e.g., 'All systems must be secured'), not the specific approved configuration list shown. Option B is wrong because a standard sets mandatory technical requirements (e.g., 'All systems must use AES-256 encryption'), but the exhibit lists exact versions and patches, which is a baseline, not a broad requirement. Option D is wrong because a procedure provides step-by-step instructions (e.g., 'How to apply the baseline'), whereas the exhibit itself is the configuration list, not the steps to implement it.

140
MCQeasy

A supplier tells your company it wants to use a new subcontractor to process customer data. What is the BEST contract control to reduce this risk?

A.Require the vendor to notify the company before adding subcontractors
B.Allow subcontractors without review if the vendor remains responsible
C.Only require a verbal promise that the subcontractor is secure
D.Remove all contract language related to third parties
AnswerA

Notification requirements help the company know when the supplier changes its processing model, especially when customer data may move to a new organization. This gives security, legal, and privacy teams a chance to review the new arrangement, confirm acceptable terms, and decide whether additional controls or approval are needed before the change takes effect.

Why this answer

Requiring the vendor to notify the company before adding subcontractors is the best contract control because it ensures the company retains visibility and approval authority over any third party that will process customer data. This aligns with the principle of due diligence and third-party risk management, as the company can assess the subcontractor's security posture before data is shared. Without such a clause, the vendor could unilaterally introduce a subcontractor with inadequate security controls, increasing the risk of a data breach or compliance violation.

Exam trap

The trap here is that candidates may assume 'vendor remains responsible' (Option B) is sufficient, but the exam tests the understanding that contractual responsibility does not eliminate the need for proactive risk assessment and notification controls to prevent unauthorized data exposure.

How to eliminate wrong answers

Option B is wrong because allowing subcontractors without review, even if the vendor remains responsible, removes the company's ability to vet the subcontractor's security practices, which could lead to a breach that the vendor may not be able to remediate effectively. Option C is wrong because a verbal promise is not enforceable and provides no documented evidence of security compliance, making it impossible to audit or hold the vendor accountable. Option D is wrong because removing all contract language related to third parties eliminates any contractual safeguards, leaving the company with no legal recourse or control over how customer data is handled by the vendor or its subcontractors.

141
MCQmedium

A procurement team is evaluating a payroll SaaS vendor. They want independent evidence that the vendor's controls were designed and operating effectively over the last six months, not just at a single point in time. Which report should they request?

A.SOC 1 Type I report
B.SOC 2 Type II report
C.Non-disclosure agreement
D.Network penetration test letter
AnswerB

A Type II report covers a period of time and evaluates whether controls operated effectively during that period.

Why this answer

A SOC 2 Type II report provides independent assurance that a vendor's controls related to security, availability, processing integrity, confidentiality, or privacy were designed and operating effectively over a period of time (typically 6–12 months). This matches the procurement team's requirement for evidence of sustained control effectiveness, not just a point-in-time snapshot.

Exam trap

The trap here is that candidates often confuse Type I (point-in-time design) with Type II (operating effectiveness over time), or mistakenly think a SOC 1 report covers security controls when it is actually focused on financial reporting controls.

How to eliminate wrong answers

Option A is wrong because a SOC 1 Type I report evaluates the design of controls at a single point in time, not their operating effectiveness over a period, and it focuses on controls relevant to financial reporting rather than the broader security and privacy controls needed for a payroll SaaS vendor. Option C is wrong because a non-disclosure agreement is a legal contract to protect confidential information, not an audit report that provides evidence of control design and operating effectiveness.

142
MCQmedium

A small company is deploying a public web application with a front-end server, an API server, and a database. The web server must be reachable from the internet, the API must be reachable only from the web server, and the database must never be accessible from user subnets. Which design best meets the requirement?

A.Place all three servers on the same internal VLAN and use host firewalls only.
B.Place the web server in a DMZ, the API server in an internal subnet, and the database in a separate restricted subnet.
C.Place the database in the DMZ so the web server can connect to it with fewer firewall rules.
D.Use a single NAT gateway for all servers and rely on public IP filtering at the edge.
AnswerB

This architecture implements defense-in-depth by separating workloads into distinct trust zones: the web server sits in a demilitarized zone (DMZ) exposed to the internet, the API resides in an internal subnet, and the database is isolated in a restricted subnet with allow-list rules. The web server is the only component with direct internet exposure, while the API and database remain inaccessible from outside, and strict firewall policies govern east-west traffic between tiers. This containment limits the blast radius of a compromise, as an attacker who breaches the web server must still traverse multiple security controls to reach sensitive data.

Why this answer

It implements a layered security architecture: the web server resides in a DMZ (demilitarized zone) to be publicly accessible, the API server is placed in an internal subnet with firewall rules allowing only traffic from the web server, and the database is isolated in a restricted subnet with no access from user subnets. This design enforces the principle of least privilege and prevents direct internet exposure of the API and database, which is critical for protecting sensitive data.

Exam trap

The trap here is that candidates often think placing the database in the DMZ simplifies connectivity, but they overlook that the DMZ is inherently less secure and directly violates the requirement that the database must never be accessible from user subnets.

How to eliminate wrong answers

Option A is wrong because placing all three servers on the same internal VLAN with only host firewalls fails to isolate the database from the web server and API, and does not prevent direct internet access to the API or database if the web server is compromised. Option C is wrong because placing the database in the DMZ exposes it to the internet and increases the attack surface, violating the requirement that the database must never be accessible from user subnets. Option D is wrong because relying on a single NAT gateway and public IP filtering at the edge does not provide subnet-level segmentation; all servers would share the same public IP, making it impossible to restrict API access to only the web server and database access to internal subnets.

143
MCQmedium

A SOC analyst is investigating an alert triggered when a user clicked a link in an email. The email appeared to be from a trusted vendor and included a PDF attachment with a macro, but the user did not run the macro. Upon reviewing the email headers, the analyst notices that the sender's domain is a common misspelling of the vendor's legitimate domain. Which of the following is the most direct indicator that this email is a phishing attempt?

A.The macro embedded in the PDF attachment
B.The misspelled sender domain in the email headers
C.The alert generated by the user clicking the link
D.The email appeared to be from a known vendor
AnswerB

This is the strongest indicator because it directly shows the email's origin is fraudulent. Attackers register domains that are visually similar to legitimate ones to trick users. The domain mismatch confirms the email is not from the vendor.

Why this answer

The misspelled sender domain in the email headers is the most direct indicator of a phishing attempt because it reveals the attacker's use of domain spoofing or a lookalike domain to impersonate a trusted vendor. This is a classic social engineering technique that bypasses the user's visual inspection, and since the user did not run the macro, the macro itself is not an active threat. The email headers provide forensic evidence of the domain mismatch, which is a definitive sign of phishing regardless of user actions.

Exam trap

CompTIA often tests the distinction between a potential threat (like an unexecuted macro) and an actual indicator of an attack (like a spoofed domain in headers), trapping candidates who focus on the payload rather than the evidence of impersonation.

Why the other options are wrong

A

The macro was not executed by the user, so it is not a direct indicator of phishing in this alert; the misspelled domain is a more immediate red flag.

C

The alert is a consequence of the user's action, not a direct indicator of phishing. The question asks for the most direct indicator that the email itself is a phishing attempt, and the alert is a system response, not a characteristic of the email.

D

The email appearing to be from a known vendor is not a direct indicator of phishing; attackers often spoof trusted names. The misspelled domain in the headers is the actual evidence of impersonation.

When would these options actually be correct?

A

In a scenario where a user reports a suspicious email attachment and the SOC analyst finds that the attachment contains a macro that auto-executes or is known to be malicious, the macro itself would be the direct indicator of a phishing attempt.

C

This option would be correct in a question asking: 'Which of the following is the most direct indicator that a user's action has triggered a security incident?' or 'What is the first sign that a security event has occurred?'

D

This option would be correct in a question asking: 'Which social engineering principle is being exploited when an email claims to be from a known vendor to gain trust?' In that context, the appearance of a known vendor directly indicates the use of authority or familiarity.

Why candidates pick the wrong answer

A

Candidates often associate macros with phishing, but overlook that the macro was not run, making it a potential threat rather than a direct indicator in this context.

C

Candidates may confuse the alert (the system's detection mechanism) with the actual evidence of phishing, thinking that any triggered alert directly indicates the nature of the threat, rather than understanding that the alert is a result of policy-based detection.

D

Candidates may think that any email claiming to be from a trusted source is suspicious, but here the question asks for the most direct indicator, and the misspelled domain is more concrete evidence than the mere appearance of a known vendor.

144
Multi-Selecthard

A team is deploying a containerized API to a public cloud. The service must be reachable only by internal corporate applications, and secrets must not be embedded in images or readable as plaintext by administrators of the underlying host. Which two actions best fit the design? Select two.

Select 2 answers
A.Place the API in a private subnet and expose it only through an internal load balancer or private endpoint.
B.Give each container a public IP and restrict access by source IP allowlist.
C.Store secrets in a managed vault and retrieve them at runtime with short-lived IAM permissions.
D.Bake database passwords into the container image so deployment is simpler.
E.Assume the cloud provider's tenant isolation alone is enough to protect secrets from misuse.
AnswersA, C

Private subnets and internal endpoints keep the service off the public internet while still allowing controlled access from trusted corporate systems. This reduces exposure, simplifies firewall policy, and supports the requirement that only internal applications can reach the API. It is a common secure cloud architecture pattern for internal services.

Why this answer

Placing the API in a private subnet and exposing it only through an internal load balancer or private endpoint ensures that the service is reachable only by internal corporate applications, as traffic never traverses the public internet. This design leverages network segmentation and private IP addressing to enforce access control at the network layer, aligning with the requirement for internal-only reachability.

Exam trap

The trap here is that candidates often confuse network-level access control (public IP with allowlist) with true private connectivity, or they underestimate the risk of host administrators reading secrets from container images or environment variables, assuming that tenant isolation or encryption at rest alone is sufficient.

145
MCQeasy

A workstation is suspected of malware infection, and it is still powered on and connected to the network. Which action best preserves volatile evidence before the system is shut down?

A.Immediately power off the workstation to stop any malicious activity.
B.Capture memory and note running processes before taking further action.
C.Run a full antivirus scan before documenting anything.
D.Delete temporary files to reduce the chance of reinfection.
AnswerB

Volatile data such as memory, active network connections, and running processes can disappear if the system is powered down. Capturing that information first preserves evidence that may show malware behavior, injected code, or command-and-control activity. This is a core incident-response practice when the system is still live.

Why this answer

Volatile evidence, such as the contents of RAM (running processes, network connections, open files), is lost when the system is powered off. Capturing a memory dump and recording running processes preserves this critical data for forensic analysis, allowing investigators to identify malware artifacts (e.g., injected code, hidden processes) that exist only in memory. This aligns with the NIST SP 800-86 forensic procedure of prioritizing volatile data collection before system shutdown.

Exam trap

CompTIA often tests the misconception that immediate shutdown stops malware activity, but the trap here is that volatile evidence is lost on power-off, and the correct forensic priority is to capture memory and process data first.

How to eliminate wrong answers

Option A is wrong because immediately powering off the workstation destroys volatile evidence (RAM contents, network state, running processes) and may cause malware to lose its in-memory footprint, hindering forensic analysis. Option C is wrong because running a full antivirus scan modifies the system state (e.g., quarantining files, altering file timestamps) and can overwrite or destroy volatile evidence before it is captured. Option D is wrong because deleting temporary files actively destroys potential evidence (e.g., malware droppers, logs) and does not preserve volatile data like memory or process lists.

146
MCQhard

Based on the exhibit, which system should be restored first after a total site outage?

A.Payroll, because it has the shortest maximum tolerable downtime and the strongest compliance impact.
B.Customer portal, because it produces the largest daily revenue loss and has the shortest RPO.
C.Email, because restoring communication always takes precedence over all other services.
D.Dev test lab, because lower business impact means it is easiest to restore first.
AnswerA

Payroll must be restored first because its maximum tolerable downtime is only eight hours, which is tighter than every other system listed. The exhibit also notes regulatory penalties if a payroll cycle is missed, making this system both time-sensitive and business-critical. In a recovery sequence, the system with the most restrictive business requirement generally receives priority.

Why this answer

Payroll should be restored first because it has the shortest maximum tolerable downtime (MTD) and the strongest compliance impact. In disaster recovery, systems with the lowest MTD must be prioritized to avoid exceeding the recovery time objective (RTO), and compliance-driven systems like payroll often carry legal or regulatory penalties for extended outages.

Exam trap

The trap here is that candidates often prioritize systems based solely on revenue loss or a general assumption (like communication first), ignoring the critical role of MTD and compliance impact in determining restoration order.

How to eliminate wrong answers

Option B is wrong because while the customer portal produces the largest daily revenue loss, its RPO (recovery point objective) is not the primary factor for restoration order—MTD and business impact criticality are. Option C is wrong because restoring communication (email) does not always take precedence; prioritization is based on MTD, compliance, and revenue impact, not a blanket rule. Option D is wrong because the dev test lab has lower business impact, meaning it should be restored last, not first, as it is not critical to core operations.

147
MCQmedium

Leadership wants to compare two controls for protecting a customer portal. Option A costs $40,000 and reduces annual loss expectancy from $120,000 to $30,000. Option B costs $15,000 and reduces annual loss expectancy to $70,000. Which analysis method best supports this decision?

A.Qualitative risk analysis
B.Quantitative risk analysis
C.Business impact analysis
D.Risk acceptance
AnswerB

Quantitative risk analysis calculates risk in monetary terms using methods such as Single Loss Expectancy (SLE), Annualized Rate of Occurrence (ARO), and Annualized Loss Expectancy (ALE). By comparing the ALE reduction from a control against its annual cost, it yields metrics like Return on Investment (ROI) or residual risk, enabling a direct financial cost-benefit comparison. Leadership's request to compare controls financially points to this approach because it converts threat and mitigation data into dollar figures.

Why this answer

Quantitative risk analysis uses monetary values and numerical data to calculate risk, making it the best method to compare the cost-benefit of Option A (ALE reduction from $120,000 to $30,000 with a $40,000 cost) versus Option B (ALE reduction to $70,000 with a $15,000 cost). By computing the annualized loss expectancy (ALE) and comparing the cost of each control against the reduction in expected loss, leadership can determine which option provides a better return on investment. This approach directly supports the decision because it provides objective, dollar-based metrics for comparison.

Exam trap

The trap here is that candidates may choose qualitative risk analysis because it is simpler and more common, but the presence of specific monetary values in the question explicitly requires quantitative analysis to make a data-driven comparison.

How to eliminate wrong answers

Option A is wrong because qualitative risk analysis uses subjective ratings (e.g., high, medium, low) rather than monetary values, so it cannot precisely compare the cost-effectiveness of two controls with specific dollar amounts. Option C is wrong because business impact analysis (BIA) focuses on identifying critical business functions and their recovery priorities, not on comparing the cost-benefit of different security controls. Option D is wrong because risk acceptance is a risk response strategy where the organization acknowledges the risk and chooses not to implement a control, which does not involve comparing multiple control options.

148
Multi-Selectmedium

Users on one VLAN report that their traffic to the default gateway is intermittently slow and sometimes reaches the wrong device. A packet capture shows unsolicited ARP replies claiming to be the gateway. Which two actions are the best mitigations on managed switches? Select two.

Select 2 answers
A.enable DHCP snooping so trusted IP-to-MAC bindings can be validated
B.enable dynamic ARP inspection to block forged ARP replies
C.change the default gateway IP address on the subnet
D.disable spanning tree protocol to reduce switching delays
E.replace private addressing with NAT on every endpoint
AnswersA, B

DHCP snooping builds a trusted binding table that helps security controls distinguish valid host mappings from forged ones. On many managed switches, that table is used to support protections against spoofed layer 2 traffic. It is a standard companion control for preventing local network poisoning attacks.

Why this answer

DHCP snooping creates a trusted database of IP-to-MAC bindings by monitoring DHCP messages. This database is then used by Dynamic ARP Inspection (DAI) to validate ARP packets, ensuring that only legitimate gateway addresses are accepted. Without DHCP snooping, DAI has no reliable source of truth to compare against, making it ineffective against ARP spoofing attacks.

Exam trap

CompTIA often tests the dependency between DHCP snooping and Dynamic ARP Inspection, so candidates may incorrectly select DAI alone without realizing that DHCP snooping must be enabled first to populate the binding table.

149
MCQmedium

An attacker calls the service desk claiming to be a traveling contractor whose phone was stolen. They know the contractor's manager name and ask for an MFA reset to a new number 'just for today.' Which control would best reduce the success of this attack?

A.Trust any caller who can provide a manager's name and employee ID.
B.Require a callback to a previously verified number and ticket approval before reset.
C.Remove MFA so users are less likely to get locked out while traveling.
D.Use caller ID alone to confirm the person is legitimate.
AnswerB

A callback to a known-good number, combined with ticket validation and approval workflow, forces the request to be verified through independent channels. This defeats the attacker’s ability to rely on stolen or guessed details during the call. It is a practical anti-pretexting control because it reduces trust in information provided by the caller alone.

Why this answer

It introduces two verification factors that directly counter the social engineering vector: a callback to a previously verified number ensures the requestor is reachable at a known trusted contact point, and ticket approval creates an audit trail and requires secondary authorization. This combination prevents an attacker from simply claiming an identity and requesting a change without independent confirmation, which is the core weakness the attacker exploits.

Exam trap

The trap here is that candidates may think providing a manager's name and employee ID is sufficient proof of identity, but the exam tests that these are easily obtained via reconnaissance and do not constitute multi-factor authentication or out-of-band verification.

How to eliminate wrong answers

Option A is wrong because trusting any caller who provides a manager's name and employee ID is exactly the social engineering trap—the attacker has already demonstrated they possess that information (likely from OSINT or a prior breach), so it provides no real authentication. Option C is wrong because removing MFA entirely weakens security posture and increases the risk of account compromise; the problem is not MFA itself but the process for resetting it, and removing MFA would make all accounts more vulnerable. Option D is wrong because caller ID can be spoofed (e.g., via VoIP or trunk manipulation) and is not a reliable authentication factor; it provides no cryptographic or out-of-band verification.

150
MCQeasy

After installing a free utility from an unofficial website, a user's laptop starts quietly sending browsing data to an unknown server. What type of malware is most likely present?

A.Spyware
B.Ransomware
C.Worm
D.Rootkit
AnswerA

Spyware is a type of malicious software that covertly monitors user activity and transmits that information to a remote attacker. In this scenario, quietly harvesting browsing data is a hallmark behavior of spyware, which often arrives bundled with free utilities from unofficial sources. Unlike outright destructive malware, spyware focuses on data exfiltration and typically operates in the background without the user's knowledge, making it the best match for the described symptoms.

Why this answer

Spyware is designed to covertly collect user data, such as browsing habits, and transmit it to a remote server without consent. The scenario describes a free utility from an unofficial website that quietly exfiltrates browsing data, which is the classic behavior of spyware. Unlike other malware types, spyware focuses on surveillance and data theft rather than system damage or self-replication.

Exam trap

The trap here is that candidates may confuse spyware with a rootkit because both can operate stealthily, but the key differentiator is the primary objective: spyware focuses on data theft, while a rootkit focuses on hiding other malware or maintaining persistent access.

How to eliminate wrong answers

Option B is wrong because ransomware encrypts files or locks the system to demand a ransom, not to quietly exfiltrate browsing data. Option C is wrong because a worm self-replicates across networks without user interaction, whereas this infection required manual installation of a utility. Option D is wrong because a rootkit hides its presence by subverting OS-level functions (e.g., hooking system calls), but the described symptom—data exfiltration—is not the defining trait; spyware is the more direct classification for data theft.

Page 1

Page 2 of 14

Page 3