Courseiva

GIAC Security Essentials (GSEC) — Questions 76–150

351 questions total · 5pages · All types, answers revealed

Page 1

Page 2 of 5

Page 3
76
MCQhard

A security engineer is selecting a hash function to protect stored user passwords in a new application. The threat model assumes an attacker who steals the password database and has substantial GPU resources for offline cracking. Which choice best addresses this threat?

A.A memory-hard password hashing function such as Argon2id with a tuned memory cost, time cost, and parallelism, plus a unique per-user salt.
B.HMAC-SHA-1 keyed with a single global application secret, because the secret prevents attackers from computing hashes without it.
C.SHA-256 applied twice to each password with a per-user salt, because iterating a fast hash twice doubles the attacker's work.
D.AES-256 in CBC mode encrypting each password with a key stored in the same database, because encryption hides the password values.
AnswerA

Argon2id is purpose-built for password storage and its memory-hard design sharply limits GPU parallelism, because each guess requires substantial memory that GPUs cannot multiply cheaply. Tuned time and memory costs plus unique per-user salts make offline cracking of a stolen database far more expensive than with fast general-purpose hashes.

Why this answer

Password storage needs a deliberately slow, memory-hard function so each offline guess is expensive and GPU parallelism is blunted. Argon2id with tuned parameters and unique per-user salts achieves this, whereas fast hashes, reversible encryption, and a single global secret all fail against an attacker with stolen data and strong cracking hardware.

Exam trap

The trap here is assuming that salting or iterating a fast general-purpose hash like SHA-256 is sufficient, when only a memory-hard function meaningfully raises the cost of GPU-accelerated offline cracking.

77
MCQmedium

A financial services firm deploys 802.1X with EAP-TLS on its corporate WLAN. During an assessment, a consultant captures the 802.11 four-way handshake and observes that the attacker cannot derive the PMK because the exchange never leaves the client and RADIUS-issued credentials exposed. Which property of EAP-TLS best explains why this capture alone cannot be used to impersonate a legitimate client?

A.EAP-TLS encrypts the entire four-way handshake inside the TLS tunnel, so the ANonce and SNonce are never visible to a passive observer.
B.EAP-TLS performs mutual authentication using X.509 client and server certificates, so no reusable password-derived secret traverses the wireless medium.
C.EAP-TLS relies on PEAP inner-method tunneling, which wraps the client credential exchange in a protected TLS channel so offline dictionary attacks are impossible.
D.EAP-TLS uses a per-session PSK that the RADIUS server generates and transmits to the client over the encrypted tunnel, so each session key is unique and unrecoverable from the capture.
AnswerB

EAP-TLS authenticates both the supplicant and the authentication server with X.509 certificates and completes a TLS tunnel whose keys never expose a shared password. An attacker capturing the four-way handshake only obtains the ANonce, SNonce, and MIC values tied to that session, which cannot be replayed to derive the PMK for a new association, so impersonation fails without the client's private key.

Why this answer

EAP-TLS bases authentication on mutual X.509 certificate exchange, so neither a password nor a shared secret crosses the air. A captured four-way handshake yields only session-specific values that cannot be replayed or brute-forced into the PMK. Impersonation would require possession of the legitimate client's private key, which the passive capture does not provide.

Exam trap

The trap here is assuming that capturing the four-way handshake always yields crackable key material, which only holds for password-derived methods like WPA2-Personal or PEAP-MSCHAPv2.

78
MCQmedium

Refer to the exhibit. An administrator applies this policy to a Windows workstation. What is the expected behavior for a user attempting to execute a legitimate application installed in their AppData folder?

A.The application will run normally because AppData is a standard location.
B.The application will be blocked from execution.
C.The application will run, but the activity will be logged for review.
D.The system will automatically move the application to Program Files.
AnswerB

The JSON policy clearly specifies an action of 'Deny' for any file path matching the AppData directory pattern. Because the policy is in 'Enforce' mode, the security agent will block any attempt to execute a binary from this location, effectively stopping the user from running their application.

Why this answer

The policy explicitly defines a 'Deny' rule for the AppData directory. Since the policy mode is set to 'Enforce', the endpoint security engine will block any executable residing in that path. This is a common security practice to prevent the execution of malicious payloads frequently dropped into temporary user directories, though it may inadvertently block legitimate software that installs to the user profile instead of Program Files.

Exam trap

Examinees often assume legitimate software paths bypass security policies, forgetting that explicitly enforced deny rules in application control policies override application legitimacy.

79
Multi-Selecthard

You are a security administrator for a Windows environment. You need to audit changes to critical files on a file server to detect unauthorized modifications. You decide to use Windows auditing features. Which TWO of the following steps must you perform to enable and capture file modification events? (Choose two.)

Select 2 answers
A.Set up a Windows Management Instrumentation (WMI) event subscription to monitor file changes.
B.Configure a System Access Control List (SACL) on the files to be monitored.
C.Enable the 'Audit process tracking' policy.
D.Configure a Discretionary Access Control List (DACL) to deny write access to all users.
E.Enable the 'Audit object access' policy in Group Policy.
AnswersB, E

A SACL defines which users or groups and which access types (e.g., Write, Delete) should be audited. You must set a SACL on each file or folder you want to monitor. This is done via the file's Properties -> Security -> Advanced -> Auditing tab. Without a SACL, no auditing occurs for that object, even if the audit policy is enabled.

Why this answer

To audit file modifications, you must first enable the 'Audit object access' policy, which allows the system to log access attempts. Then, you must set a SACL on each file or folder to specify what to audit. Only with both steps will Event ID 4663 (an attempt was made to access an object) be logged for modifications.

The other options do not enable file auditing.

Exam trap

The trap here is assuming that setting a SACL alone is sufficient, or confusing DACLs with SACLs; both audit policy and SACL are required.

80
MCQhard

A financial institution uses a stateful firewall between its internal network and the internet. An administrator notices that return traffic for outbound connections is being blocked even though the outbound rules are correct. The firewall logs show that the return packets are being dropped because they do not match any existing session. Which feature should the administrator verify is enabled to allow return traffic for legitimate outbound sessions?

A.Stateful inspection with session tracking
B.Access control lists (ACLs) applied to the inbound interface
C.Deep packet inspection (DPI) with application signatures
D.Network address translation (NAT) with port forwarding
AnswerA

Stateful inspection maintains a session table that tracks the state of each connection. When an outbound connection is initiated, the firewall creates an entry, and return traffic matching that session is automatically allowed. If session tracking is disabled or the table is full, return packets may be dropped. This feature is essential for allowing return traffic without explicit inbound rules.

Why this answer

Stateful inspection with session tracking allows the firewall to dynamically permit return traffic for outbound connections by maintaining a session table. Without it, return packets are treated as new inbound traffic and may be blocked by default. The administrator should verify that stateful inspection is enabled and that the session table is not exhausted, which can cause drops.

Exam trap

The trap here is confusing stateful session tracking with other firewall features like DPI or NAT, or assuming that an ACL must be added to allow return traffic, when the real issue is that stateful inspection is not functioning correctly.

81
MCQmedium

A healthcare company runs a three-tier application on VMware ESXi hosts. An auditor discovers that vMotion traffic between hosts is transmitted over the same physical switch as guest virtual machine data traffic. The security team must ensure that live migration traffic cannot be sniffed or tampered with by a compromised guest VM on the same network segment. Which action best addresses this finding?

A.Apply a Layer 2 ACL on the physical switch to permit only ESXi management IP addresses on the guest VLAN.
B.Configure a dedicated vMotion VMkernel port group on an isolated VLAN and enable encryption for vMotion.
C.Move all virtual machines to a single ESXi host so that vMotion is never used.
D.Enable promiscuous mode on the vSwitch so that vMotion frames can be inspected by the host firewall.
AnswerB

A dedicated vMotion VMkernel interface placed on a separate VLAN segments migration traffic away from guest data paths, and vMotion encryption protects the transferred memory contents even if the underlying network is observed. This directly mitigates both sniffing and tampering by a compromised guest because the migration stream never shares the guest-facing segment and is cryptographically protected.

Why this answer

Live migration traffic carries complete guest memory contents, so it must be both isolated and protected. Placing vMotion on a dedicated VMkernel port group in an isolated VLAN removes it from the guest data path, and enabling vMotion encryption ensures that even a compromised guest or a tapped uplink cannot read or alter the migration stream. Together these controls directly remediate the auditor's concern.

Exam trap

The trap here is assuming that enabling promiscuous mode or an IP-based ACL improves visibility or control, when it actually broadens exposure and never protects the vMotion stream.

82
MCQmedium

A hospital's IT team is designing layered defenses for its electronic health record (EHR) system. They already have perimeter firewalls, network intrusion prevention, and endpoint antivirus. The CISO wants to add a control that detects unauthorized modification of EHR database records and alerts the security team in near real time. Which control best fills this gap while preserving defense in depth?

A.Implementing full-disk encryption on the EHR database servers
B.File integrity monitoring (FIM) with cryptographic hashing on the EHR database files
C.Configuring syslog forwarding from the EHR servers to a central SIEM
D.Deploying an additional host-based firewall on the EHR application servers
AnswerB

FIM computes cryptographic hashes of critical files and compares them against a known-good baseline, so any unauthorized modification of EHR database records triggers an alert. This adds a detective control at the data layer, complementing existing preventive network and host controls. It directly addresses the need for near-real-time detection of record tampering without disrupting clinical workflows.

Why this answer

The scenario requires a detective control that specifically identifies unauthorized changes to EHR database records. File integrity monitoring with cryptographic hashing provides exactly that by comparing current file hashes to a trusted baseline and alerting on mismatch. The other options either duplicate existing preventive controls or provide logging without integrity detection, leaving the data-layer gap unaddressed.

Exam trap

The trap here is assuming that any logging or encryption control will detect data tampering, when only integrity-focused monitoring actually compares content against a known-good state.

83
Multi-Selecthard

A security engineer is implementing a digital signature solution using RSA. The engineer must ensure that signatures provide authenticity, integrity, and non-repudiation. Which TWO of the following practices are essential to achieve these goals? (Choose two.)

Select 2 answers
A.Hash the message with a collision-resistant hash function before signing.
B.Include a timestamp from a trusted Time Stamping Authority (TSA) in the signature.
C.Use the recipient's public key to encrypt the hash before signing.
D.Encrypt the entire message with the sender's private key.
E.Sign the hash with the sender's private key.
AnswersA, E

Signing a hash of the message rather than the raw message is essential for performance and security. A collision-resistant hash ensures that it is infeasible to find two different messages with the same hash, which would allow signature forgery. This practice is fundamental to achieving integrity and non-repudiation in digital signatures.

Why this answer

To create a digital signature with RSA, the sender must hash the message using a collision-resistant hash function and then sign that hash with their private key. This provides integrity (via the hash), authenticity and non-repudiation (via the private key signature). The recipient can verify by hashing the message and decrypting the signature with the sender's public key.

Exam trap

The trap here is confusing digital signatures with encryption, leading to the misconception that the recipient's public key or the sender's private key is used to encrypt the whole message.

84
MCQhard

Refer to the exhibit. An investigator identifies this registry key. What is the primary purpose of this information in a forensic investigation?

A.It defines the system's default language settings.
B.It maps Security Identifiers (SIDs) to user profile directories.
C.It logs every application the user has executed.
D.It lists all installed software on the system.
AnswerB

ProfileList is the authoritative source for locating where a user's profile resides on the disk. For an investigator, this is essential to verify account existence and identify the correct directory path for further analysis of user-specific artifacts that might contain evidence of attacker activity.

Why this answer

The ProfileList key maps SIDs to user profile paths. This is critical because an attacker may create a temporary or hidden account. By identifying the exact path to the user profile, the investigator knows where to look for user-specific artifacts like NTUSER.DAT, browser history, and temporary files.

This mapping is the starting point for scoping user-level malicious activities and ensuring that no hidden accounts are overlooked during the investigation.

Exam trap

Candidates often confuse the ProfileList registry key with general system configuration keys. They fail to recognize that this specific key is the primary link between user SIDs and profile paths.

85
MCQmedium

A user reports they cannot open a downloaded application because macOS states the developer cannot be verified. Which security feature is preventing the execution of this application?

A.XProtect
B.Gatekeeper
C.System Integrity Protection
D.FileVault 2
AnswerB

Gatekeeper is the security feature that checks if an application is signed by an identified developer and notarized by Apple. If an application fails these checks, Gatekeeper prevents it from executing to ensure that the software has not been altered or created by an untrusted entity.

Why this answer

Gatekeeper is the security technology that verifies that software is from a trusted developer and has not been tampered with. By requiring code signing and notarization, Gatekeeper helps prevent the execution of malicious software. For a GSEC professional, recognizing Gatekeeper's role is key to troubleshooting deployment issues while maintaining the organization's security policy, as it is the first line of defense against unauthorized applications running on the user's desktop.

Exam trap

Candidates often confuse Gatekeeper with XProtect or FileVault, mixing up the application verification framework with antivirus signatures or disk encryption technologies.

86
MCQhard

A utility company must protect a SCADA network that uses proprietary Modbus/TCP communications on a segmented OT VLAN. The security team wants to block unauthorized function codes while allowing a small set of approved read operations, and it cannot tolerate latency or protocol-breaking behavior. Which control is MOST appropriate?

A.A web application firewall placed in front of the SCADA historian's HTTP interface.
B.An industrial protocol-aware firewall or IPS module that performs deep packet inspection of Modbus/TCP function codes.
C.An email and web gateway performing TLS interception on the OT VLAN.
D.A stateless packet filter permitting only TCP port 502 between the engineering workstation and the PLC.
AnswerB

Deep packet inspection that understands Modbus/TCP can parse the function code field and enforce an allowlist of approved read operations while dropping others, which matches the requirement to block unauthorized function codes. Because it is purpose-built for OT protocols, it can do this without the latency and compatibility problems a general-purpose proxy would introduce.

Why this answer

Enforcing an allowlist of Modbus/TCP function codes requires inspecting the protocol payload, which only a control-system-aware firewall or IPS can do reliably. Port-based filtering cannot separate reads from writes because all Modbus/TCP operations share the same transport port.

Exam trap

The trap here is assuming that restricting traffic to TCP port 502 secures Modbus, when that port carries both benign reads and dangerous write or diagnostic function codes.

87
MCQmedium

A security engineer is segmenting a data center so that contractors who maintain HVAC systems cannot initiate connections into the server VLAN, but the internal monitoring platform must still reach the contractor subnet to poll building-management sensors. The chosen design uses a stateful firewall between the two zones with the contractor zone as the untrusted side. Which configuration best enforces the required traffic direction while preserving monitoring?

A.Place both zones behind a single perimeter firewall and permit all inter-zone traffic, relying on the contractor VLAN's private IP addressing to prevent reachability.
B.Configure the firewall so the monitoring platform initiates sessions into the contractor zone, allowing only established, return traffic back to the monitoring platform.
C.Apply an ACL on the contractor zone's router interface that permits only the monitoring platform's IP to the sensor subnet and denies all other traffic in both directions.
D.Configure a stateful firewall rule permitting the contractor subnet to the sensor subnet on the management ports, and add an implicit deny at the end of the rule base.
AnswerB

This enforces the required direction: the trusted monitoring platform originates the session, and the stateful firewall builds a session table entry so only return traffic for that flow is allowed back. Contractors cannot initiate inbound connections to the server VLAN, and monitoring still works because the firewall tracks the established session rather than trusting source addresses.

Why this answer

The requirement is directional control between zones, so a stateful firewall must see the trusted monitoring platform initiate the session and then allow only the return traffic for that established flow. Contractors are thereby unable to originate connections into the server VLAN, while polling of building-management sensors continues. Stateless ACLs and private addressing do not provide this session-aware, one-way enforcement.

Exam trap

The trap here is assuming that private IP addressing or a stateless ACL provides the same directional enforcement as a stateful firewall session table.

88
MCQeasy

A junior security analyst at a healthcare company must scan a subnet of 254 hosts for known vulnerabilities. The analyst has no budget for commercial tools and needs a scanner that is open source, actively maintained, and capable of authenticated and unauthenticated checks. Which tool BEST meets these requirements?

A.OpenVAS (Greenbone Vulnerability Management)
B.Nessus Essentials
C.Nmap with the NSE vuln category
D.Wireshark
AnswerA

OpenVAS, now delivered through Greenbone Vulnerability Management, is an open-source vulnerability scanner with a continuously updated feed and support for both authenticated and unauthenticated scans. It has no per-host licensing limit, making it suitable for scanning a 254-host subnet at no cost while still meeting the maintenance and capability requirements.

Why this answer

OpenVAS, maintained as Greenbone Vulnerability Management, is the only option that is open source, actively updated, and free of per-host licensing limits. It supports both authenticated and unauthenticated scanning across large subnets, which matches the analyst's constraints. The other tools are either license-limited, not true vulnerability scanners, or designed for traffic analysis rather than vulnerability assessment.

Exam trap

The trap here is assuming that any free security tool can substitute for a dedicated, feed-driven vulnerability scanner when the requirement explicitly calls for maintained authenticated and unauthenticated checks.

89
MCQeasy

A compliance officer wants to confirm that full disk encryption is active on a MacBook so that data at rest is protected if the device is lost. Which command should the officer run to check the FileVault status?

A.fdesetup status
B.csrutil status
C.spctl --status
D.diskutil apfs list
AnswerA

fdesetup status reports whether FileVault is On or Off and, when in progress, the percentage of encryption completed. It directly answers the compliance question about full disk encryption being active on the MacBook, making it the correct tool for verifying FileVault state.

Why this answer

FileVault is macOS full disk encryption, and its state is queried with the fdesetup utility. Running fdesetup status returns whether encryption is on, off, or in progress, which is precisely the evidence a compliance officer needs to confirm data-at-rest protection. Other tools report unrelated security features such as SIP or Gatekeeper.

Exam trap

The trap here is confusing volume-level APFS encryption reporting from diskutil with the user-facing FileVault configuration that fdesetup reports.

90
MCQhard

A security consultant is reviewing a Windows Server 2019 file server. The folder C:\Projects has a DACL that includes an entry for the group 'Contractors' with the following advanced permissions: 'List folder / read data', 'Read attributes', 'Read extended attributes', 'Read permissions', and 'Synchronize'. The consultant notices that a contractor user can open and read files in the folder but cannot create new files or modify existing ones. Which access control concept best explains this behavior?

A.The contractor user has the 'Modify' permission, but a Deny entry for 'Write' is present.
B.The contractor user is a member of the 'Users' group, which has the Read & execute permission by default.
C.The contractor user has been assigned the Read & execute basic permission, which includes the listed advanced permissions.
D.The contractor user has been assigned the Write basic permission, but inheritance is blocked on the folder.
AnswerC

The listed advanced permissions (List folder/read data, Read attributes, Read extended attributes, Read permissions, Synchronize) are exactly those that comprise the Read & execute basic permission (plus Read for files). This explains why the contractor can read but not write. The basic permission is a shorthand for this set of advanced permissions, and it is commonly used to grant read-only access to folders and files.

Why this answer

The advanced permissions listed are the components of the Read & execute basic permission. This permission allows reading and executing files but not writing or modifying them. The contractor's inability to create or modify files is directly explained by this permission set, which is commonly used for read-only access.

Exam trap

The trap here is assuming that any advanced permission entry must correspond to a custom set, overlooking that these specific advanced permissions are exactly the Read & execute basic permission.

91
MCQmedium

A GSEC candidate is reviewing a Docker Compose file for a web application. The file includes a service definition that mounts the Docker socket into the container. What is the primary security risk of this configuration?

A.It prevents the container from writing to its own filesystem, causing application failures.
B.It allows the container to access the host's Docker daemon, enabling privilege escalation and full host compromise.
C.It exposes the container's internal ports to the host network, increasing the attack surface.
D.It allows the container to bypass network policies and communicate with other containers without restriction.
AnswerB

Mounting the Docker socket (/var/run/docker.sock) into a container grants that container control over the Docker daemon, which typically runs as root. An attacker could use the Docker API to create privileged containers, mount host filesystems, or escape to the host, leading to full compromise.

Why this answer

Mounting the Docker socket into a container effectively gives that container root-level control over the host's Docker daemon. An attacker who compromises the container can use the Docker API to start privileged containers, mount host directories, or execute commands on the host, resulting in full system compromise. This is a critical misconfiguration that should be avoided.

Exam trap

The trap here is assuming that mounting the Docker socket only affects container networking or filesystem isolation, when in fact it grants control over the host's Docker daemon and can lead to full host compromise.

92
MCQmedium

A security team is configuring password policies for a Windows Active Directory domain. They need to enforce a setting that prevents users from reusing any of their last 24 passwords. Which password policy setting should they configure?

A.Enforce password history
B.Minimum password age
C.Password must meet complexity requirements
D.Maximum password age
AnswerA

Enforce password history determines how many unique new passwords must be used before an old password can be reused. Setting it to 24 prevents reuse of the last 24 passwords, directly meeting the requirement. This is the correct setting because it specifically tracks and blocks previous password hashes, ensuring users cannot cycle back to recent passwords.

Why this answer

The Enforce password history policy setting in Active Directory allows administrators to specify the number of previous passwords that cannot be reused. Setting it to 24 ensures users must choose 24 unique passwords before they can reuse an old one. This directly addresses the requirement to prevent reuse of the last 24 passwords.

Other settings like maximum age, minimum age, or complexity do not track password reuse and therefore do not meet the stated goal.

Exam trap

The trap here is confusing password history with password complexity or age policies, which do not prevent reuse of previous passwords.

93
MCQmedium

Your organization is adopting the CIS Critical Security Controls to bolster defense. You are currently focused on establishing a secure baseline configuration for all workstation images. Which specific CIS Control should you prioritize to ensure that unauthorized software and unauthorized configuration changes are mitigated?

A.CIS Control 1: Inventory and Control of Enterprise Assets
B.CIS Control 2: Data Protection
C.CIS Control 4: Secure Configuration of Enterprise Assets and Software
D.CIS Control 8: Audit Log Management
AnswerC

Control 4 specifically requires the establishment and maintenance of secure configurations for all enterprise assets. It ensures that systems are deployed with hardened settings, unnecessary ports are closed, and only authorized software is permitted. This effectively mitigates the risk of exploitation through default settings or unauthorized application execution.

Why this answer

CIS Control 4, Secure Configuration of Enterprise Assets and Software, focuses on establishing and maintaining security configurations for hardware and software. By mandating a standardized, hardened baseline for all workstations, the organization reduces the attack surface by eliminating unnecessary services and insecure settings. This is a foundational control that directly supports other security measures by ensuring that endpoints are in a known, secure state before they are deployed into the production network environment.

Exam trap

Candidates frequently confuse Control 4 (Secure Configuration) with Control 5 (Account Management) or Control 7 (Vulnerability Management), missing that the prompt specifically asks about workstation images and unauthorized configuration changes.

94
MCQmedium

An administrator needs to restrict sensitive file access on a Windows Server 2022 environment while ensuring that users only access resources based on their job titles. Which Windows technology should be implemented to leverage Dynamic Access Control (DAC) for this requirement?

A.Implement Kerberos Constrained Delegation
B.Configure Central Access Policies
C.Apply AppLocker Software Restriction Policies
D.Utilize Encrypting File System (EFS)
AnswerB

Central Access Policies are the core component of Dynamic Access Control. They allow administrators to define resource authorization policies centrally in Active Directory and apply them to files and folders using resource properties, effectively enforcing access based on user attributes like department or job title globally.

Why this answer

Dynamic Access Control allows administrators to apply access policies based on user claims and resource properties rather than traditional security groups alone. By integrating Active Directory claims and resource attributes, you can automate permissions, which significantly reduces the administrative overhead of managing thousands of individual NTFS permissions. This is critical for maintaining the principle of least privilege in scaling enterprise environments where group-based memberships become too complex to manage effectively.

Exam trap

Examinees frequently confuse basic NTFS security groups with Dynamic Access Control components, selecting standard permission modification tools instead of Central Access Policies.

95
MCQmedium

An incident responder is analyzing a Windows 10 workstation that is suspected of being used to exfiltrate data. The responder runs 'wevtutil qe Security /q:"*[System[(EventID=5156)]]" /f:text' but finds no events. Which action will most reliably produce the network connection telemetry the responder needs for this investigation?

A.Set the Security log retention method to 'Overwrite events as needed' and increase the maximum log size to 1 GB.
B.Run 'netsh trace start capture=yes' and review the resulting ETL file in Event Viewer under the Microsoft-Windows-TCPIP operational log.
C.Enable the 'Audit Process Creation' policy and configure the 'Include command line in process creation events' setting to capture outbound connections.
D.Enable the 'Audit Filtering Platform Connection' policy under Advanced Audit Policy Configuration and ensure the Security log is large enough to retain events.
AnswerD

Event ID 5156 is logged only when the Filtering Platform Connection subcategory is audited. By default it is not enabled, so the query returns nothing. Enabling this subcategory via Advanced Audit Policy Configuration and provisioning sufficient Security log capacity allows the responder to capture allowed and blocked connection events with process, user, and port details needed to trace exfiltration.

Why this answer

Event ID 5156 is generated only when the Filtering Platform Connection audit subcategory is enabled through Advanced Audit Policy Configuration; the default configuration does not log these events, which explains the empty query result. Enabling the subcategory and providing adequate log capacity gives the responder the process, user, and endpoint details required to trace the suspected exfiltration activity on the workstation.

Exam trap

The trap here is assuming that the Security log records network connections by default, when the Filtering Platform Connection subcategory must be explicitly enabled.

96
MCQmedium

Which THREE of the following represent critical log sources that should be ingested into a SIEM for effective network-wide security visibility? (Choose three)

A.Firewall logs
B.Local printer spooler temporary files
C.Authentication (Active Directory) logs
D.Antivirus/EDR alerts
E.Office document metadata templates
AnswerA, C, D

Firewall logs document allowed and denied traffic at network boundaries. They are essential for identifying reconnaissance, data exfiltration, and communication with known malicious command-and-control servers. Analyzing these logs helps security teams understand how traffic flows through the perimeter and identify potential entry points for attackers or internal threats.

Why this answer

Effective SIEM visibility requires a diverse set of data sources to correlate activities across the infrastructure. Combining endpoint, network, and identity logs allows for comprehensive monitoring. These sources provide the raw telemetry necessary for detecting lateral movement, command-and-control communication, and unauthorized privilege escalation.

Without this breadth of information, security teams are likely to miss the early indicators of a sophisticated attack transitioning through different segments of the enterprise network.

Exam trap

Candidates often include 'physical access logs' or 'printer logs'. While potentially useful, these are not high-priority security telemetry compared to identity, network, and endpoint alerts.

97
MCQeasy

A security administrator is configuring a screened subnet (DMZ) firewall rule set. The organization wants to allow external users to reach a public web server on TCP 443 while preventing the web server from initiating connections back into the internal network. Which rule set BEST enforces this requirement?

A.Permit any external IP to the web server on any port; deny the web server to any internal IP on all ports.
B.Permit any external IP to the web server on TCP 443; deny the web server to any internal IP on all ports; permit established return traffic from the web server to external clients.
C.Deny all external IPs to the web server; permit the web server to any external IP on TCP 443.
D.Permit any external IP to the web server on TCP 443; permit the web server to any internal IP on TCP 443 only.
AnswerB

This rule set allows inbound HTTPS to the public server and explicitly blocks the server from initiating connections to internal addresses. Permitting established return traffic lets responses to external clients flow back without opening new inbound sessions. It enforces the one-way trust boundary that a screened subnet is meant to provide while keeping the public service reachable.

Why this answer

A screened subnet firewall policy should permit only the specific public service, block the DMZ host from initiating connections into the internal network, and allow return traffic for established sessions. The rule set that permits external HTTPS, denies the web server to internal IPs, and permits established return traffic achieves this. Overly broad inbound rules or rules that allow inward initiation from the DMZ undermine the security boundary.

Exam trap

The trap here is focusing only on the inbound permit and overlooking the need to both block outbound initiation to internal networks and allow established return traffic.

98
MCQmedium

Refer to the exhibit. What is the current configuration state for auditing 'Account Logon' events based on the provided output?

A.Only failure events are being audited
B.Both success and failure are being audited
C.Auditing is completely disabled for this category
D.Only success events are being audited
AnswerB

The display lists 'Success and Failure' under the credential validation subcategory. This confirms that the security policy is set to log every authentication event, allowing for full visibility into legitimate login patterns and potential unauthorized access attempts targeting user credentials.

Why this answer

The output indicates that the 'Account Logon' category is configured to audit both success and failure for credential validation. Auditing this is essential because it captures domain-wide authentication attempts occurring on the domain controller. This visibility is vital for identifying brute-force attacks or anomalous login behavior, providing a foundation for effective incident response and forensic analysis within the Windows infrastructure.

Exam trap

Candidates often misread the audit policy output format, failing to distinguish between the 'Success' and 'Failure' columns, leading them to assume only one is being audited.

99
MCQeasy

A small business wants to protect its Windows endpoints from malware delivered through email attachments and malicious websites. The owner asks a security consultant for a single built-in Windows feature that can provide real-time antivirus scanning, cloud-based protection, and automatic updates without purchasing third-party software. Which Windows feature should the consultant recommend?

A.BitLocker Drive Encryption
B.Windows Information Protection (WIP)
C.Windows Defender Firewall
D.Microsoft Defender Antivirus
AnswerD

Microsoft Defender Antivirus is the built-in antivirus component of Windows that provides real-time scanning, cloud-delivered protection, and automatic signature updates through Windows Update. It scans files, email attachments, and downloads, and it integrates with Windows Security. It requires no additional purchase and is enabled by default on modern Windows versions, directly matching the consultant's recommendation for a single built-in feature.

Why this answer

Microsoft Defender Antivirus is the correct built-in Windows feature because it delivers real-time antivirus scanning, cloud-based protection, and automatic updates without additional cost. It covers files, email attachments, and web downloads, and it is managed through Windows Security, making it the single feature that satisfies the small business's malware protection needs.

Exam trap

The trap here is confusing Windows Defender Firewall with Microsoft Defender Antivirus because both share the Defender name but serve different security functions.

100
MCQmedium

A security analyst is reviewing a web application that allows users to upload profile pictures. The application accepts files with .jpg and .png extensions, but the analyst discovers that an attacker can upload a file named 'avatar.php.jpg' and then access it directly via a URL. The server executes the file as PHP. Which security control would most directly prevent this type of attack?

A.Store uploaded files outside the web root and serve them via a handler that validates file content.
B.Implement a strict Content Security Policy (CSP) that disallows inline scripts.
C.Enforce HTTPS for all upload and download requests to prevent man-in-the-middle attacks.
D.Set the 'secure' attribute on session cookies to ensure they are only sent over encrypted connections.
AnswerA

Storing files outside the web root prevents direct URL access, and a validating handler ensures only safe file types are served. This combination stops the server from executing the uploaded file, because the file is never placed in a location where the web server would interpret it as code. It directly mitigates the vulnerability by removing the execution path and enforcing content validation.

Why this answer

The vulnerability arises because the server executes uploaded files based on their extension or content. Storing files outside the web root and serving them through a validating handler prevents direct execution and ensures only safe content is delivered. This approach directly addresses the root cause, whereas other controls like CSP, HTTPS, or cookie flags do not stop server-side code execution.

Exam trap

The trap here is assuming that client-side controls like CSP or transport encryption can mitigate server-side file execution vulnerabilities.

101
MCQmedium

A financial services company runs sensitive workloads on a Type 1 hypervisor. The security team wants to detect if a guest VM attempts to escape and directly access the hypervisor's memory. Which virtualization-specific security control should they implement?

A.Host-based intrusion detection system (HIDS) on each guest
B.Virtual firewall
C.Hypervisor introspection
D.Security information and event management (SIEM) correlation
AnswerC

Hypervisor introspection allows the hypervisor to monitor and analyze the memory and state of guest VMs from outside the guest, enabling detection of malicious activity such as escape attempts. It operates at the hypervisor layer, providing visibility that traditional in-guest agents cannot achieve, and is specifically designed to identify anomalies like unauthorized memory access from a guest to the hypervisor.

Why this answer

Hypervisor introspection is specifically designed to monitor guest VM memory and state from the hypervisor level, enabling detection of escape attempts. Other controls like virtual firewalls or guest-based HIDS operate at different layers and cannot observe the hypervisor-guest boundary. For detecting direct hypervisor memory access by a guest, introspection is the appropriate virtualization-specific control.

Exam trap

The trap here is assuming that a HIDS on each guest can detect hypervisor escapes, but once the guest is compromised, the HIDS is bypassed.

102
MCQeasy

A security analyst is reviewing a legacy application that uses RSA for digital signatures. The application generates a 1024-bit RSA key pair and signs messages using SHA-1. The analyst must recommend an upgrade that maintains the same algorithm family but meets current security standards. Which change should be recommended?

A.Keep the 1024-bit RSA key but replace SHA-1 with SHA-3.
B.Replace RSA with HMAC-SHA256 for signing.
C.Increase the RSA key size to 2048 bits and replace SHA-1 with SHA-256.
D.Switch to Elliptic Curve Digital Signature Algorithm (ECDSA) with P-256 and SHA-256.
AnswerC

Increasing RSA key size to 2048 bits and replacing SHA-1 with SHA-256 aligns with current standards such as NIST SP 800-57 and CA/Browser Forum requirements. This maintains the RSA algorithm family while addressing vulnerabilities in both key length and hash function. It provides a stronger security margin without changing the underlying cryptographic approach.

Why this answer

To meet current security standards while preserving the RSA algorithm family, the analyst should recommend increasing the RSA key size to 2048 bits and replacing SHA-1 with SHA-256. This addresses both the weak key length and the deprecated hash function, providing a secure and compliant digital signature solution without changing the underlying public-key algorithm.

Exam trap

The trap here is focusing only on the hash function and overlooking the insufficient RSA key size, which also requires upgrading to meet modern standards.

103
MCQhard

A security analyst is investigating a potential data exfiltration incident. The SIEM has ingested firewall logs that show outbound connections, but the analyst notices that the logs do not include the number of bytes transferred. The analyst needs to correlate this with other log sources to estimate the volume of data exfiltrated. Which additional log source would provide the most direct and reliable measurement of data volume for outbound connections?

A.NetFlow records from core routers and switches.
B.DNS server query logs.
C.Windows Security event logs from the source host.
D.Antivirus application logs from the endpoint.
AnswerA

NetFlow records include byte and packet counts for each flow, providing a direct measurement of data volume for outbound connections. They are generated by network devices and can be correlated with firewall logs by source/destination IP, port, and timestamp. This allows the analyst to estimate exfiltration volume accurately. NetFlow is widely supported and can be exported to the SIEM, making it the most reliable source for volume data in this scenario.

Why this answer

NetFlow provides byte and packet counts per flow, directly measuring data volume for outbound connections. Firewall logs often lack this detail, so NetFlow is the best additional source to quantify exfiltration. It can be correlated by IP, port, and time to estimate how much data left the network, making it the most direct and reliable choice.

Exam trap

The trap here is assuming that host-based logs or DNS logs contain byte counts for network connections, when only flow-based sources like NetFlow provide that level of detail.

104
MCQeasy

When analyzing Windows event logs to detect brute-force activity, which Event ID indicates a failed logon attempt?

A.Event ID 4624
B.Event ID 4625
C.Event ID 4740
D.Event ID 4768
AnswerB

Event ID 4625 is the definitive log entry for a failed logon attempt in the Windows Security event log. It contains valuable metadata such as the username, source IP address, and logon type, which are necessary for identifying the origin and target of a brute-force attack.

Why this answer

Event ID 4625 is the standard Windows Security log identifier for a failed logon. Monitoring this ID is essential for identifying brute-force or credential-stuffing attacks. By correlating these logs across multiple systems, security teams can detect patterns of malicious behavior, allowing for automated account lockouts or IP blocking, which are critical components of an effective incident response strategy for Windows infrastructure.

Exam trap

Test-takers frequently confuse Event ID 4625 (failed logons) with Event ID 4624 (successful logons) when writing detection queries for brute-force attacks.

105
MCQmedium

A security analyst is reviewing an incident where a user's browser was exploited by a drive-by download. The analyst wants to confirm whether the exploit achieved code execution and established persistence. Which artifact should the analyst examine first to determine if a new service was created for persistence on the Windows host?

A.The Application event log for Windows Error Reporting crash entries.
B.The browser's cache folder for recently downloaded JavaScript files.
C.The Windows Security event log for event ID 4688 process creation.
D.The System event log for event ID 7045 Service Control Manager entries.
AnswerD

Event ID 7045 in the System log is written by the Service Control Manager when a new service is installed, and it records the service name, image path, service type, and start type. This directly answers whether a new service was created for persistence. It is generated by default on modern Windows systems, requires no pre-enabled auditing, and provides the exact evidence needed to confirm service installation after a drive-by exploit.

Why this answer

The System event log entry with ID 7045 is generated by the Service Control Manager whenever a new service is installed on Windows. It captures the service name, binary path, start type, and account, which lets the analyst confirm both installation and the persistence mechanism. Unlike process creation auditing, 7045 is enabled by default and directly answers whether a service was created, making it the correct first artifact to examine.

Exam trap

The trap here is confusing process creation telemetry with service installation telemetry; event ID 4688 shows that a process ran, while event ID 7045 proves a service was actually installed.

106
MCQhard

Refer to the exhibit. A user attempts to delete a file located inside '/opt/backup', but the operation fails with a 'Permission denied' error. Given the directory permissions shown, what is the most likely cause?

A.The user lacks the execute permission on the /opt/backup directory.
B.The user lacks write permission on the /opt/backup directory.
C.The file inside the directory is owned by root and is immutable.
D.The user does not have the 'sudo' command available in their path.
AnswerB

Deleting a file requires the write permission on the parent directory because it involves removing a directory entry. The 'r-x' permissions for others demonstrate that the user does not have write access, which is the mandatory requirement for modifying the contents of a directory, including file deletion.

Why this answer

The directory permissions 'drwxr-xr-x' indicate that the owner (root) has full control, while others have read and execute access. However, because the user is neither root nor the directory owner, they lack write permission (w) on the parent directory. In Linux, deleting a file requires write and execute permissions on the directory containing it, not just the file itself.

This mechanism protects directory integrity from unauthorized modifications by non-privileged users.

Exam trap

Test-takers frequently assume file deletion requires write permissions on the file itself, rather than recognizing that deleting or creating files depends entirely on parent directory permissions.

107
MCQmedium

You are a security analyst at a company that suspects an insider is exfiltrating files from a Windows Server 2019 file server. You need to enable auditing to record every time a file is read or written on a specific shared folder, while minimizing the volume of unrelated events. Which of the following should you do first?

A.Enable the "Audit Handle Manipulation" subcategory to capture file access attempts.
B.Configure a basic audit policy by enabling "Audit object access" in the Local Security Policy.
C.Enable the "Audit File System" subcategory under Object Access in Advanced Audit Policy Configuration.
D.Create a new Data Collector Set in Performance Monitor to track file access on the shared folder.
AnswerC

Advanced Audit Policy Configuration provides granular control over object access auditing. Enabling the Audit File System subcategory allows you to log file read/write events only when a system access control list (SACL) is set on the target folder. This minimizes noise by targeting the specific subcategory rather than the broad legacy policy, and it is the necessary first step before configuring the SACL on the folder itself.

Why this answer

To audit file reads and writes on a specific folder, you must first enable the Audit File System subcategory in Advanced Audit Policy Configuration. This provides granular control and reduces noise compared to legacy basic auditing. After enabling this subcategory, you would then configure a system access control list (SACL) on the folder to specify which users and access types to audit.

This combination ensures that only relevant events are logged, aligning with the principle of least privilege and efficient monitoring.

Exam trap

The trap here is confusing basic audit policy with advanced audit policy, or selecting a performance monitoring tool instead of a security auditing feature.

108
MCQmedium

A security analyst at a financial firm suspects that an attacker used a service account to create a new local administrator on a Windows 10 workstation. The analyst runs `auditpol /get /category:*` and sees that the 'Account Management' subcategory is set to 'No Auditing'. Which action should the analyst take to capture future events of this type while minimizing noise?

A.Enable the 'Account Management' subcategory with both Success and Failure auditing.
B.Enable the 'Policy Change' subcategory with Success auditing only.
C.Enable the 'Detailed Tracking' subcategory with Success auditing only.
D.Enable the 'Logon/Logoff' subcategory with Failure auditing only.
AnswerA

Enabling Success and Failure auditing for the Account Management subcategory captures events such as user account creation (Event ID 4720) and group membership changes (Event ID 4728/4732). This directly addresses the scenario by logging both successful and failed attempts to create or modify local accounts, which is necessary to detect an attacker adding a local administrator. It also provides a balance of visibility without enabling entire categories that would generate excessive noise.

Why this answer

The Account Management subcategory is specifically designed to log changes to user accounts and groups, including creation, deletion, and membership modifications. Enabling both Success and Failure auditing ensures that any attempt to add a local administrator is recorded, whether it succeeds or fails. This directly targets the suspicious activity while avoiding the overhead of unrelated audit categories.

Exam trap

The trap here is assuming that Logon/Logoff or Policy Change auditing will capture account creation events, when only the Account Management subcategory records those specific actions.

109
MCQhard

An examiner is analyzing a Windows 10 endpoint and finds that the user account was deleted before acquisition, but the examiner still needs to determine which files that user recently opened from a network share. The user's profile folder was also removed. Which artifact is most likely to retain this information?

A.The Security event log's object access auditing entries in the Security.evtx file
B.The SRUM database's Application Resource Usage table
C.The NTUSER.DAT hive from the deleted user's profile folder
D.The UsrClass.dat hive from the deleted user's profile folder
AnswerA

If object access auditing was enabled, the Security event log records file access events, including the account name, the object path, and the share accessed. Because the log is stored in C:\Windows\System32\winevt\Logs and is system-scoped, it survives deletion of the user profile and account. It is the most likely remaining source for the user's recent file opens from a network share.

Why this answer

Object access auditing, when enabled, writes file access events to the Security event log, which is system-scoped and stored under winevt\Logs, so it survives deletion of the user account and profile. Per-user hives such as NTUSER.DAT and UsrClass.dat are removed with the profile, and SRUM records resource usage rather than file opens.

Exam trap

The trap here is assuming that user-scoped artifacts such as NTUSER.DAT and UsrClass.dat remain available after the profile is deleted, when in fact they are removed with the profile folder.

110
MCQhard

Refer to the exhibit. An analyst observes the provided log output. What is the most likely security incident occurring, and what is the best immediate action?

A.Hardware failure; replace the server network interface card immediately.
B.Brute-force attack; investigate the source IP and block it if unauthorized.
C.Network congestion; increase the logging frequency of the server.
D.User error; reset the user's password to clear the event logs.
AnswerB

The rapid cadence of failed attempts from a single source strongly suggests an automated brute-force attack. Investigating the source IP allows the analyst to verify if the machine is a known asset or an unauthorized intruder, and blocking it is the correct containment strategy to protect the server.

Why this answer

The exhibit shows a rapid sequence of failed login attempts from a single internal IP address, which is indicative of a brute-force or credential-stuffing attack. Security professionals must identify this pattern quickly to prevent account compromise. The standard response involves investigating the source IP for malicious intent and blocking the traffic at the network perimeter or host level to mitigate the risk of unauthorized access to the server.

Exam trap

Candidates often jump to the conclusion of a DoS attack rather than a brute-force attack, or they suggest overly aggressive actions like shutting down the entire server instead of blocking the IP.

111
MCQhard

A forensic examiner is reviewing an NTFS volume from a Windows 11 laptop. The user claims a sensitive spreadsheet was only opened and never modified or renamed. The examiner notes that the $STANDARD_INFORMATION timestamps for the file are all recent, but the $FILE_NAME timestamps are from several months earlier. Which explanation best accounts for this discrepancy?

A.Windows 11 disables $FILE_NAME timestamp updates by default for user documents, so the older values simply reflect the file's creation date.
B.The file was accessed by a program that updated the $STANDARD_INFORMATION timestamps, and this behavior is a known anti-forensic technique or normal filesystem behavior depending on the API used.
C.The $FILE_NAME timestamps record when the file was last backed up, while the $STANDARD_INFORMATION timestamps record live activity, so they legitimately differ after any backup.
D.The file was copied onto the volume from a remote share, which rewrote the $STANDARD_INFORMATION times while preserving the $FILE_NAME times from the source.
AnswerB

NTFS stores two sets of timestamps: $STANDARD_INFORMATION, which many APIs update, and $FILE_NAME, which is typically updated only on rename or certain metadata changes. Tools and some APIs can modify $STANDARD_INFORMATION times without touching $FILE_NAME, producing exactly this discrepancy. It is a well-documented artifact and a common timestomping indicator, so this explanation fits the evidence best.

Why this answer

NTFS maintains parallel timestamps in $STANDARD_INFORMATION and $FILE_NAME. Many APIs and many anti-forensic tools update only the $STANDARD_INFORMATION set, leaving $FILE_NAME untouched. A recent $STANDARD_INFORMATION paired with an older $FILE_NAME is a classic timestomping indicator and directly explains the discrepancy the examiner observed.

Exam trap

The trap here is treating the two NTFS timestamp sets as always identical and therefore dismissing the discrepancy instead of recognizing it as a timestomping or API-behavior indicator.

112
MCQeasy

A system administrator is hardening a Linux server and wants to ensure that users cannot log in with empty passwords. Which command should the administrator use to check for accounts with empty password fields in /etc/shadow?

A.cut -d: -f1,2 /etc/shadow | grep ':$'
B.passwd -S $(cut -d: -f1 /etc/shadow) | grep 'NP'
C.grep -v '^[^:]*:[^:]*:' /etc/shadow
D.awk -F: '($2 == "") {print $1}' /etc/shadow
AnswerD

This awk command parses /etc/shadow using colon as the field separator and checks if the second field (the password hash) is empty. If so, it prints the username. This directly identifies accounts with empty passwords, which is a critical security risk. It is a precise and efficient way to audit for this specific misconfiguration.

Why this answer

To identify accounts with empty passwords, the most direct method is to parse /etc/shadow and check if the password hash field is empty. The awk command with field separator ':' and condition $2 == "" accomplishes this by printing the username for any line where the second field is empty. This is a common security audit technique.

Other methods may work but are less precise or efficient. Ensuring no accounts have empty passwords is a fundamental Linux hardening step.

Exam trap

The trap here is using a command that checks for password status via passwd -S, which is slower and may not work for all accounts, instead of directly inspecting the shadow file.

113
Multi-Selectmedium

A security team is designing a network segmentation scheme for a new data center. They want to restrict lateral movement between workloads and enforce policy based on workload identity rather than IP address. Which TWO technologies best support this goal? (Choose two.)

Select 2 answers
A.Microsegmentation using a software-defined overlay with workload-level policy enforcement.
B.A next-generation firewall with identity-based rules applied to workload-to-workload flows.
C.VLANs assigned by physical switch port with inter-VLAN routing disabled.
D.A perimeter firewall with rules based on source and destination IP addresses.
E.802.1X port-based network access control on all switch ports.
AnswersA, B

Microsegmentation applies granular security policy to individual workloads or groups, often using an overlay that decouples policy from physical topology. Because enforcement is tied to workload identity and tags rather than subnet boundaries, an attacker who compromises one workload cannot freely reach others. This directly satisfies the requirement to restrict lateral movement and enforce identity-based policy, making it a correct choice for the scenario.

Why this answer

Restricting lateral movement and enforcing workload-identity policy requires controls that operate on east-west traffic and understand workload context. Microsegmentation with a software-defined overlay enforces per-workload policy regardless of IP, and a next-generation firewall with identity-based rules can inspect and permit only authorized workload flows. Together they address both the segmentation and identity-policy requirements.

Exam trap

The trap here is choosing perimeter or admission-control technologies that govern initial access or north-south traffic, when the requirement is specifically about east-west workload-to-workload policy based on identity.

114
MCQeasy

Which of the following describes the 'Principle of Least Privilege' in an access control context?

A.Granting all employees access to the root directory for troubleshooting
B.Providing users only the access required to complete their tasks
C.Using the same shared password for all administrative accounts
D.Ensuring all users have administrator rights for software updates
AnswerB

This definition aligns perfectly with the Principle of Least Privilege. By restricting access to only what is strictly necessary, an organization significantly reduces the impact of accidental mistakes, insider threats, and external attacks, as an attacker will find themselves limited by the restricted permissions of the compromised account.

Why this answer

The Principle of Least Privilege (PoLP) mandates that users should only be granted the minimum level of access necessary to perform their job functions. This minimizes the attack surface; if a user account is compromised, the potential damage is restricted to the limited permissions assigned to that account. This is a fundamental security concept for preventing lateral movement and privilege escalation during an active incident or breach.

Exam trap

Candidates often confuse the Principle of Least Privilege with 'Need to Know' or general access control policies, failing to recognize that PoLP specifically mandates the minimum permissions required for task completion.

115
MCQmedium

An organization is applying CIS Control 9: Email and Web Browser Protections. They have successfully implemented domain-based message authentication (DMARC). What is the primary security goal being achieved by this implementation?

A.Encryption of email traffic between mail servers.
B.Prevention of unauthorized use of the organization's domain for spoofing.
C.Hardening web browser settings to prevent XSS attacks.
D.Scanning of inbound email attachments for malware signatures.
AnswerB

DMARC specifically enables domain owners to protect their domain from being used for email spoofing. It provides a feedback mechanism and policy enforcement that tells receiving mail servers how to reject or quarantine emails that do not pass SPF or DKIM authentication, directly preventing domain impersonation and phishing.

Why this answer

DMARC is a critical component of CIS Control 9 because it builds upon SPF and DKIM to prevent email spoofing and phishing attacks. By allowing domain owners to publish instructions on how receiving servers should handle emails that fail authentication, it significantly reduces the efficacy of fraudulent emails, thereby protecting the organization's reputation and preventing users from interacting with malicious content that leverages the organization's legitimate email domain.

Exam trap

Candidates often confuse DMARC with encryption protocols like TLS or general spam filtering, missing its specific focus on domain spoofing prevention.

116
MCQmedium

You are a security analyst at a financial firm. A Windows Server 2019 domain controller is suspected of unauthorized access. You need to determine which user accounts were used to log on interactively to that server during the past week. Which Windows Event ID should you examine?

A.Event ID 4648
B.Event ID 4624
C.Event ID 4672
D.Event ID 4634
AnswerB

Event ID 4624 is logged on the local computer when a logon session is created. It includes the Logon Type, which indicates how the logon occurred. For interactive logons, the Logon Type is 2. By filtering 4624 events with Logon Type 2 on the domain controller, you can identify which accounts were used for interactive logons, directly answering the scenario.

Why this answer

Interactive logons generate Event ID 4624 with Logon Type 2. This event records the account name, logon type, and other details, making it the primary source for identifying which accounts were used for interactive access. Other events like 4634, 4648, and 4672 serve different purposes and do not directly show interactive logon activity.

Exam trap

The trap here is confusing logon-related events, such as 4634 (logoff) or 4648 (explicit credential use), with the event that actually records interactive logons.

117
MCQeasy

A security operations center (SOC) uses a SIEM to collect logs from various sources. The SOC manager wants to ensure that log data is retained for at least one year to meet regulatory requirements, but the SIEM's primary storage is expensive and limited. Which log management strategy should the SOC implement to meet the retention requirement cost-effectively?

A.Configure the SIEM to compress and archive older logs to a secondary storage tier, such as a network-attached storage (NAS) or cloud object storage, after a defined period.
B.Reduce the log retention period to 30 days and rely on the original log sources to retain their own logs for one year.
C.Increase the SIEM's primary storage capacity by adding more high-performance disks to accommodate one year of logs.
D.Disable logging for low-priority sources and keep only high-priority logs for one year on primary storage.
AnswerA

Archiving older logs to cheaper secondary storage is a standard cost-effective approach for long-term retention. The SIEM keeps recent, frequently queried data on expensive primary storage, while older logs are moved to a lower-cost tier. This meets the one-year retention requirement without overprovisioning primary storage. It also allows retrieval for investigations or compliance audits, though search performance on archived data may be slower.

Why this answer

The most cost-effective way to meet long-term retention is to tier storage: keep recent logs on fast, expensive primary storage and archive older logs to cheaper secondary storage. This balances performance for active investigations with compliance retention, avoiding unnecessary primary storage expansion or risky reliance on source systems.

Exam trap

The trap here is assuming that all logs must remain on primary SIEM storage for the entire retention period, which leads to unnecessary cost and scalability issues.

118
MCQhard

You are auditing a Windows Server environment and identify that a service is configured to log on as a 'Group Managed Service Account' (gMSA). What is the primary security advantage of using this account type over a standard domain user account?

A.They enable Kerberos constrained delegation by default.
B.They automatically rotate passwords without service restarts.
C.They bypass the need for an SPN registration.
D.They allow for local interactive logons on all domain controllers.
AnswerB

gMSAs manage complex, long, and randomly generated passwords that are automatically rotated by the Active Directory Key Distribution Service. This eliminates the risk associated with human-managed static passwords and prevents service interruptions during rotation, ensuring that credentials are never stale or vulnerable to offline cracking attempts.

Why this answer

gMSAs provide automatic password management, where the Windows OS handles password rotation without manual intervention or service downtime. This significantly reduces the risk of password compromise or credential theft via brute-force or persistent local storage. By removing the need for human administrators to manage long-lived static credentials, gMSAs enforce a robust security posture that adheres to modern standards for service identity lifecycle management and long-term protection against credential-based lateral movement.

Exam trap

Candidates often assume the advantage is 'increased permissions' or 'easier deployment', missing the core security value of automatic password rotation which prevents long-term credential reuse.

119
MCQeasy

What is the primary purpose of Salt in password hashing?

A.To shorten the length of the stored hash
B.To prevent the use of rainbow tables
C.To increase the complexity of the user's password
D.To facilitate easier password recovery
AnswerB

Rainbow tables are pre-computed tables of hashes used to crack passwords quickly. By using a unique salt for every user, the set of possible hashes becomes effectively infinite for any given password, rendering rainbow tables useless because they cannot account for the random salt value injected into the hash function.

Why this answer

A salt is a unique, random string added to a password before it is hashed. This ensures that even if two users have the same password, their resulting hashes will be different. This prevents attackers from using pre-computed tables, such as rainbow tables, to quickly reverse the hashes of stolen passwords.

By forcing attackers to calculate hashes for each individual user, the salt significantly increases the computational cost of brute-force and dictionary attacks.

Exam trap

Examinees often confuse salts with pepper or general key stretching functions, incorrectly believing that the primary goal is simply to slow down brute-force guessing rather than neutralizing pre-computed lookup tables.

120
MCQhard

A hospital's wireless intrusion prevention system reports that a nearby attacker is broadcasting beacon frames that clone the SSID and BSSID of the hospital's legitimate access point at a higher signal strength, luring staff laptops to associate with the attacker's hardware. Which attack is being described, and which defense most directly addresses it?

A.A deauthentication flood; enabling Management Frame Protection forces the attacker's forged frames to be discarded by clients.
B.A MAC spoofing attack; deploying 802.1X with MAC authentication bypass on switch ports eliminates the rogue association.
C.An evil twin attack; requiring server certificate validation in the supplicant profile prevents clients from trusting the rogue AP.
D.A karma attack; disabling the SSID broadcast on legitimate APs prevents clients from probing for and joining the rogue device.
AnswerC

An evil twin impersonates a legitimate AP by cloning its SSID and BSSID, and a stronger signal persuades clients to associate. In WPA2/WPA3-Enterprise, the rogue cannot complete the TLS handshake without a certificate the client trusts, so enforcing server certificate validation in the supplicant stops the association. This directly defeats the impersonation rather than merely detecting it after the fact.

Why this answer

Cloning an AP's SSID and BSSID with a stronger signal to attract clients is an evil twin attack. In an enterprise deployment the rogue cannot present a certificate signed by the trusted CA, so configuring the supplicant to validate the RADIUS server certificate causes the association to fail. Detection alone is weaker than preventing the trust decision.

Exam trap

The trap here is treating a rogue AP that merely broadcasts a matching SSID as harmless reconnaissance, when the cloned BSSID plus stronger signal is what drives client association.

121
MCQeasy

A small business owner is concerned about ransomware encrypting critical files on a shared network drive. The owner wants a solution that can restore files quickly after an attack without paying the ransom. Which of the following is the MOST effective control to achieve this?

A.Deploy antivirus software with real-time scanning on all endpoints.
B.Implement a regular backup strategy that includes offline and offsite copies.
C.Configure the network drive to be read-only for all users.
D.Enable file versioning on the shared network drive.
AnswerB

Regular backups that are kept offline and offsite ensure that even if ransomware encrypts the network drive, a clean copy of the data exists and can be restored. This is the most reliable way to recover from ransomware without paying. It directly addresses the need to restore files quickly and effectively.

Why this answer

A robust backup strategy with offline and offsite copies is the most effective way to recover from ransomware. It ensures that a clean copy of data is available regardless of the attack's success. While other controls can help prevent or limit damage, only backups provide a reliable restoration path without paying the ransom.

Exam trap

The trap here is assuming that antivirus or file versioning alone can guarantee recovery, when in fact ransomware often targets or encrypts those very mechanisms, making offline backups essential.

122
MCQeasy

A user attempts to launch a newly installed application on a macOS Monterey system, but the application fails to open with a message that it cannot be verified. The user is certain the application was downloaded from the developer's official website. Which macOS feature is responsible for this behavior?

A.XProtect
B.Gatekeeper
C.System Integrity Protection (SIP)
D.Transparency, Consent, and Control (TCC)
AnswerB

Gatekeeper is the macOS feature that verifies the authenticity and integrity of applications downloaded from the internet. It checks whether the app is notarized by Apple and signed with a valid Developer ID. If the app cannot be verified, Gatekeeper blocks it from launching, which matches the scenario. This is the primary defense against malware disguised as legitimate software.

Why this answer

Gatekeeper is designed to ensure that only trusted software runs on macOS. When an application is downloaded from the internet, Gatekeeper checks its code signature and notarization status. If the app is not signed with a valid Developer ID or not notarized, Gatekeeper blocks it and displays a warning.

This matches the user's experience. The other features address different security aspects and would not produce this specific message.

Exam trap

The trap here is confusing Gatekeeper with other macOS security features like SIP or TCC, which handle different protection layers and do not verify app authenticity.

123
MCQhard

A security administrator is troubleshooting an enterprise client that repeatedly fails to complete a major Windows feature upgrade, automatically triggering a rollback. Which built-in command-line utility should the administrator use to examine detailed migration logs, error codes, and rollback triggers?

A.SFC.exe /scannow to inspect operating system file integrity
B.DISM.exe /Online /Cleanup-Image /RestoreHealth to repair component stores
C.SetupDiag.exe to automatically parse update setup logs and identify failure reasons
D.GPResult.exe /h report.html to generate a comprehensive group policy diagnostic report
AnswerC

SetupDiag is the designated Microsoft utility that scans setup log files, extracts error codes, and details the exact conditions that caused a Windows feature update to fail and rollback. This tool dramatically accelerates troubleshooting by pointing directly to offending drivers or software.

Why this answer

SetupDiag is a specialized diagnostic tool designed to analyze Windows setup logs and pinpoint the exact root cause of a failed feature update or rollback. Reviewing these logs allows security and systems engineers to rapidly identify blocking drivers, incompatible applications, or registry corruption preventing successful Windows as a Service upgrades.

Exam trap

Test-takers frequently look into standard event viewer logs like Application or System for rollback causes, missing the dedicated standalone troubleshooting tool built specifically for upgrades.

124
MCQmedium

A security engineer is configuring a new AWS S3 bucket to store sensitive PII. Which combination of settings best adheres to the principle of least privilege for the bucket policy?

A.Enable public access and rely on bucket ACLs for granular object permission.
B.Restrict access to specific IAM roles and require Secure Transport.
C.Assign full administrative rights to the bucket root user for ease of management.
D.Use a wildcard principal in the bucket policy to allow internal cross-account access.
AnswerB

Restricting access to specific IAM roles ensures that only authorized entities can interact with the bucket. Requiring Secure Transport (HTTPS) ensures that data in transit is encrypted, protecting against interception. This combination adheres to the principle of least privilege and robust data protection standards.

Why this answer

Proper S3 configuration requires a defense-in-depth approach that prevents public access while explicitly restricting actions to necessary services. By blocking public access, enforcing TLS for transit, and using explicit IAM roles, the organization minimizes the attack surface. This is vital because S3 buckets are frequent targets for misconfiguration that leads to data exposure, making granular policy control an essential defensive requirement for protecting cloud-based sensitive information.

Exam trap

Candidates often choose broad bucket policies granting open access to all principals or omit Secure Transport requirements, confusing general bucket creation with strict least-privilege principles.

125
MCQhard

A security administrator is hardening authentication on a set of Linux servers that will be accessed by third-party contractors. Management requires that contractors authenticate with a one-time code delivered by a hardware token, while local administrators continue to use their existing passwords, and that both methods can be used on the same SSH service without changing the client software. Which approach best meets these requirements?

A.Deploy RADIUS backed by a token server, point sshd at PAM's pam_radius_auth.so, and let the RADIUS policy assign token authentication to contractor accounts and password authentication to administrator accounts.
B.Configure PAM to stack pam_unix.so and pam_google_authenticator.so with the requisite control flag in /etc/pam.d/sshd so both factors are required for every account.
C.Set PasswordAuthentication to no and ChallengeResponseAuthentication to yes in sshd_config, then distribute hardware tokens to all accounts so every user supplies a one-time code.
D.Issue each contractor an SSH certificate signed by an internal CA and configure sshd with TrustedUserCAKeys, leaving administrator accounts on password authentication.
AnswerA

RADIUS centralizes the decision of which authentication method each account must satisfy. Contractors are mapped to token-based policies while administrators retain password authentication, and because sshd still calls PAM, the existing SSH clients need no changes. This satisfies every constraint in the scenario without duplicating credentials locally.

Why this answer

The requirement is per-account, per-method authentication on a shared SSH service with no client changes. A RADIUS-backed token server reached through PAM lets the authentication policy decide which accounts need a hardware token and which may use a password, while sshd continues to use its normal PAM stack. This preserves existing clients and separates the two populations cleanly, matching every stated constraint.

Exam trap

The trap here is assuming that stacking every PAM module with a requisite flag automatically satisfies mixed authentication requirements, when it actually forces all factors on all accounts.

126
MCQmedium

A retail company's e-commerce site is being targeted by credential stuffing attacks. The security team wants to add a control that slows automated login attempts while preserving a smooth experience for legitimate customers. Which control best fits this requirement?

A.Block all inbound traffic from countries where the company has no customers.
B.Deploy a CAPTCHA challenge after several failed login attempts from the same source.
C.Enforce a strict account lockout after three failed login attempts for all users.
D.Require all customers to use a hardware security key for authentication.
AnswerB

A CAPTCHA challenge presented after a threshold of failures forces automated tools to solve a human-verification task, breaking the economics of credential stuffing. Legitimate users who mistype a password a few times still pass through normally, so the customer experience is largely preserved. This is a targeted application-layer control.

Why this answer

Credential stuffing succeeds through automation, so the most effective layered control is one that imposes a human-verification cost after suspicious failure patterns. A CAPTCHA challenge achieves this while letting normal users proceed. Account lockout creates denial of service, hardware keys are impractical for retail customers, and geo-blocking is easily evaded and overly broad.

Exam trap

The trap here is choosing account lockout because it stops brute force, without recognizing that it enables attackers to lock out legitimate customers.

127
Multi-Selecthard

Which THREE of the following are examples of how network segmentation supports the principle of defense in depth?

Select 3 answers
A.It restricts lateral movement for an attacker who has compromised a device.
B.It allows for the implementation of zone-specific access control lists.
C.It eliminates the need for host-based firewalls on individual servers.
D.It facilitates better logging and monitoring of inter-zone traffic.
E.It automatically encrypts all data in transit between segments.
AnswersA, B, D

If a workstation is compromised, segmentation limits the attacker's ability to scan or connect to other network segments. By placing servers in a separate VLAN from end-user devices, the organization forces the attacker to find another way to move through the network, adding friction to the attack.

Why this answer

Network segmentation breaks a flat network into smaller, isolated subnets. This limits the blast radius of a breach by preventing lateral movement, restricting access to sensitive data, and providing points to inspect traffic between zones. By enforcing boundaries, the organization ensures that an attacker who compromises a workstation in one zone cannot easily pivot to critical servers in another, thus creating multiple functional barriers that the attacker must overcome to reach the high-value targets.

Exam trap

Candidates often select options related to 'network performance' or 'bandwidth optimization,' which are irrelevant to the security objectives of defense in depth and lateral movement prevention.

128
Multi-Selectmedium

A security team is implementing a new access control system for a research lab. They need to ensure that access decisions are based on the user's role and the sensitivity of the resource, and that users are only granted the minimum permissions necessary to perform their job. Which two access control principles should they apply? (Choose two.)

Select 2 answers
A.Discretionary Access Control (DAC)
B.Rule-Based Access Control
C.Principle of Least Privilege
D.Mandatory Access Control (MAC)
E.Role-Based Access Control (RBAC)
AnswersC, E

The principle of least privilege states that users should be granted only the minimum access rights required to perform their job functions. This directly matches the requirement to grant minimum permissions necessary. Applying this principle reduces the attack surface and limits potential damage from compromised accounts, making it a core component of the desired access control system.

Why this answer

Role-Based Access Control (RBAC) bases access decisions on the user's role, and the principle of least privilege ensures users only have the minimum permissions needed. Together, they meet the requirement to use role and resource sensitivity while enforcing least privilege. DAC, MAC, and rule-based access control do not specifically combine role-based decisions with least privilege in the same way.

Exam trap

The trap here is selecting MAC or DAC because they sound strict or familiar, but they do not directly address role-based decisions and least privilege as required.

129
MCQeasy

When designing a defense in depth strategy, why is it recommended to use heterogeneous security controls rather than homogeneous ones?

A.To reduce the overall cost of software licensing and maintenance.
B.To ensure that a single vulnerability does not bypass all defense layers.
C.To simplify the process of configuring and managing security logs.
D.To minimize the need for external security audits and compliance checks.
AnswerB

Heterogeneous controls prevent single points of failure. If all layers used the same technology, a single zero-day exploit could potentially compromise every layer simultaneously. Diversity ensures that an attacker must possess multiple, distinct exploits to traverse the various security layers, drastically increasing the difficulty for the adversary.

Why this answer

Heterogeneous controls provide diversity, ensuring that a single flaw or vulnerability in one vendor's product does not compromise the entire defense. In a homogeneous environment, if an attacker discovers a bypass for one control, they can apply that same technique across all layers. Using different technologies or vendors increases the probability that at least one layer will successfully stop the threat, thereby making the overall environment significantly more resilient against targeted attacks.

Exam trap

Candidates often think heterogeneity is for 'performance' or 'cost reduction.' They fail to grasp that the primary security goal is to prevent a single vendor's vulnerability from compromising every layer.

130
MCQeasy

A security analyst is preparing to run an authenticated vulnerability scan against a Windows Server 2019 host. The analyst has domain credentials with local administrator rights on the target. Which Nmap scan type should the analyst use to perform a full TCP connect scan without requiring raw packet privileges?

A.nmap -sU
B.nmap -sA
C.nmap -sS
D.nmap -sT
AnswerD

The -sT option performs a TCP connect scan using the operating system's connect() system call, which does not require raw socket privileges. This makes it ideal when running Nmap as a non-root user or when the analyst lacks the ability to send raw packets. It completes the full TCP three-way handshake against each target port.

Why this answer

The TCP connect scan (-sT) is the correct choice because it relies on the operating system's networking stack and does not need raw socket access, making it usable by unprivileged users. Other scan types such as SYN, UDP, or ACK scanning require raw packet privileges and serve different purposes.

Exam trap

The trap here is assuming that all Nmap scan types require root or administrator privileges, when the TCP connect scan is specifically designed to work without them.

131
MCQhard

A platform team runs a Kubernetes cluster where a container was compromised through a remote code execution flaw in a web application. The attacker attempted to read the service account token, query the API server, and list secrets in the namespace. The team wants to reduce the impact of such a compromise in the future. Which of the following changes most directly limits what the compromised pod's service account can do against the API server?

A.Enabling audit logging on the API server to record all requests made by service accounts.
B.Disabling the automountServiceAccountToken field on the pod spec so no token is projected into the container.
C.Applying a NetworkPolicy that blocks egress from the pod to the API server's ClusterIP.
D.Binding a tightly scoped Role to the service account that grants only the specific verbs and resources the application requires, instead of cluster-admin or broad default permissions.
AnswerD

RBAC bindings define exactly which API verbs and resources a service account may access. Replacing broad permissions with a least-privilege Role ensures that even if the container is compromised, the token cannot list secrets or perform privileged operations. This directly limits the blast radius against the API server, matching the team's objective.

Why this answer

RBAC least privilege is the authoritative control over what a service account can do against the API server. Binding a narrowly scoped Role that grants only the required verbs and resources means a compromised pod's token cannot enumerate secrets or perform privileged actions, directly containing the blast radius from the RCE compromise.

Exam trap

The trap here is treating observability or network controls as equivalent to authorization, when only RBAC scope determines what a service account is permitted to do.

132
MCQeasy

A junior administrator is setting up a shared folder on a Windows Server 2022 member server. The folder will be accessed by a group called 'SalesTeam'. The administrator wants to ensure that members of SalesTeam can read and write files, but cannot change permissions or take ownership. Which NTFS permission should the administrator assign to the SalesTeam group?

A.Write
B.Read & execute
C.Full Control
D.Modify
AnswerD

The Modify permission includes Read & execute, Write, and Delete, but does not include Change permissions or Take ownership. This allows SalesTeam members to read and write files without the ability to alter ACLs or ownership. It is the appropriate standard permission for collaborative file access where users need to edit content but not manage security.

Why this answer

The Modify permission provides the necessary read and write access without granting the ability to change permissions or take ownership. It is the standard choice for groups that need to collaborate on files. Full Control would be excessive, while Write and Read & execute each lack essential capabilities for the scenario.

Exam trap

The trap here is confusing the Modify permission with Full Control, forgetting that Modify excludes the ability to change permissions or take ownership.

133
MCQmedium

An administrator observes that internal users are receiving certificate warnings when accessing a new internal web application. The organization uses an internal Certificate Authority (CA). What is the primary cause of this behavior?

A.The server certificate has expired, triggering a validity date error in the browser.
B.The web server failed to send the intermediate certificate in the handshake process.
C.The internal Root CA certificate is not installed in the client's local trust store.
D.The web application is utilizing an outdated TLS version that browsers no longer support.
AnswerC

Web browsers rely on the local certificate store to validate the identity of web servers. If the issuing CA's root certificate is not present in the user's trusted root certification authorities store, the browser will signal that the site's identity cannot be verified, resulting in a security warning.

Why this answer

Certificate warnings occur when a client cannot establish a chain of trust back to a trusted Root CA. In internal environments, the internal CA certificate must be explicitly imported into the client's trusted root store. Without this root trust, the browser cannot verify the digital signature of the server's certificate, resulting in a trust error.

This is a fundamental concept in PKI management for enterprise web security.

Exam trap

Candidates often blame expired server certificates or incorrect cipher suites rather than recognizing missing trust stores for internal CAs.

134
MCQmedium

Why does the inclusion of detective controls improve a defense in depth strategy?

A.They automatically block all malicious traffic before it reaches the network.
B.They provide visibility into successful bypasses of preventive controls.
C.They remove the need for regular vulnerability assessments.
D.They ensure that all user actions are strictly restricted by policy.
AnswerB

No preventive control is 100% effective. Detective controls like IDS, log analysis, and file integrity monitoring provide the necessary visibility to identify when a preventive control has failed. This allows the security team to act quickly, minimizing the damage caused by an attacker who has successfully gained unauthorized access.

Why this answer

Preventive controls are not always effective against every threat; therefore, detective controls are necessary to identify breaches that successfully penetrate the perimeter. By monitoring for indicators of compromise, security teams can respond to incidents in progress. This reduces the dwell time of an attacker, preventing a minor initial compromise from escalating into a major data exfiltration event.

Detective controls effectively close the loop between prevention and response in a defense in depth model.

Exam trap

Candidates often assume detective controls prevent breaches. They confuse the role of detection with prevention, failing to realize that detective controls identify failures rather than stop the initial unauthorized access attempt.

135
MCQeasy

A security analyst is examining a Kubernetes Pod specification that includes the following securityContext: runAsUser: 0. What is the security implication of this setting?

A.The container will be unable to write to any mounted volumes due to permission restrictions.
B.The container will run as the root user, increasing the risk of privilege escalation if compromised.
C.The container will run as a non-privileged user, enhancing security by default.
D.The container will automatically drop all Linux capabilities, reducing its attack surface.
AnswerB

Setting runAsUser: 0 explicitly runs the container process as the root user (UID 0). If an attacker compromises the container, they gain root privileges within the container, which can be leveraged to escape to the host or access sensitive resources, especially if combined with other misconfigurations like hostPath mounts.

Why this answer

Specifying runAsUser: 0 in a Kubernetes securityContext forces the container to run as the root user. This violates the principle of least privilege and increases the potential impact of a container compromise. Best practice is to run containers as a non-root user, often defined in the image or via runAsUser with a high UID.

Exam trap

The trap here is misinterpreting runAsUser: 0 as a security hardening measure, when it actually runs the container as root and weakens security.

136
MCQmedium

A security auditor notices that wireless clients are frequently disconnected by de-authentication frames that contain a spoofed MAC address of the access point. What is the auditor witnessing?

A.A standard re-keying process defined by WPA2 standards.
B.A de-authentication Denial of Service (DoS) attack.
C.An automated load balancing mechanism on the AP.
D.A probe response flood from an adjacent network.
AnswerB

De-authentication attacks exploit the lack of management frame integrity in older 802.11 standards. By spoofing the AP's address, the attacker forces clients to drop their connection. This is a common method for disrupting service or preparing a target for an Evil Twin or packet interception attack.

Why this answer

This behavior is characteristic of an 802.11 de-authentication attack. By sending spoofed management frames that appear to originate from the legitimate access point, an attacker can force clients to disconnect. This is often a precursor to forcing clients to reconnect to an attacker-controlled Evil Twin AP, enabling the interception of credentials or the execution of further man-in-the-middle attacks.

Exam trap

Students commonly mistake de-authentication attacks for Rogue AP installations or Evil Twin scenarios, confusing the initial disconnection phase with the subsequent credential capture phase.

137
MCQmedium

A security administrator is hardening the boot process of a production Ubuntu 22.04 server that uses GRUB 2. The policy requires that any interactive modification to the kernel command line at the GRUB menu must be blocked, and that the bootloader configuration file must be unreadable by unprivileged users. Which action should the administrator take to meet these requirements?

A.Enable the UEFI Secure Boot option in firmware and reinstall the operating system with a signed kernel.
B.Run grub-mkpasswd-pbkdf2, add a superuser entry with the resulting hash to /etc/grub.d/40_custom, and set chmod 600 on /boot/grub/grub.cfg.
C.Set GRUB_TIMEOUT=0 in /etc/default/grub and run update-grub to hide the menu.
D.Add the kernel parameter init=/bin/bash to /etc/default/grub and regenerate the bootloader configuration.
AnswerB

Password-protecting the GRUB 2 menu with a superuser entry prevents interactive editing of kernel parameters at boot, and restricting permissions on grub.cfg blocks unprivileged reading of the bootloader configuration. Together these satisfy the stated hardening policy, because only users who supply the GRUB password can modify boot entries, and other local users cannot inspect the configuration file.

Why this answer

Blocking interactive GRUB edits requires a bootloader password so the menu cannot be modified without authentication, and protecting grub.cfg with restrictive permissions prevents unprivileged users from reading boot parameters. The other choices either only hide the menu, rely on firmware verification that does not restrict menu editing, or introduce a recovery parameter that reduces security. Together, the password and file permission changes satisfy both parts of the policy.

Exam trap

The trap here is assuming that hiding the GRUB menu or enabling Secure Boot alone prevents kernel command-line tampering, when only a GRUB superuser password actually blocks interactive edits.

138
MCQhard

An assessor is standing in a parking lot outside a warehouse and needs to map the coverage footprint and identify all BSSIDs in range, including hidden networks, using a passive approach that does not associate to any AP. Which tool and technique fit this requirement?

A.Deploy a Wireshark capture on the wired uplink of the wireless controller to enumerate all BSSIDs in the coverage area.
B.Use Nmap with the wireless scripts enabled to enumerate BSSIDs by sending 802.11 probe requests from a managed interface.
C.Use Kismet in monitor mode with a supported adapter to passively capture beacon, probe response, and data frames across channels.
D.Run airodump-ng in managed mode and associate to each detected SSID to confirm its encryption type.
AnswerC

Kismet places the adapter in monitor mode, which captures all 802.11 frames on the channel without associating. Beacons and probe responses reveal BSSIDs, SSIDs, channels, and encryption settings, while hidden networks appear through probe responses and data frames. Because no association occurs, the assessor stays passive and avoids altering or alerting the target network.

Why this answer

A passive site survey requires monitor mode so the adapter captures every frame on the channel without associating. Kismet in monitor mode reveals beacons, probe responses, and data frames, exposing BSSIDs, hidden SSIDs through client probing, channels, and encryption. This maps coverage and discovers APs while leaving the target network untouched.

Exam trap

The trap here is confusing a passive monitor-mode survey with tools that require association or operate above the radio layer, which hides beacon-only information such as BSSIDs and hidden networks.

139
MCQhard

A security engineer is designing an internal Public Key Infrastructure (PKI) and needs to issue a subordinate certificate authority (sub-CA) certificate. To prevent this sub-CA from accidentally or maliciously issuing certificates for unauthorized domains, what specific X.509 extension must be correctly configured?

A.Key Usage extension populated solely with Digital Signature, Non-Repudiation, and Key Encipherment flags.
B.Authority Information Access extension pointing directly to the organization's primary online OCSP responder.
C.Name Constraints extension configured with explicit permitted and excluded subtree subdirectories for domain namespaces.
D.Extended Key Usage extension restricted strictly to TLS Web Server Authentication and Code Signing.
AnswerC

Name Constraints enforce strict boundaries on subordinate CAs by defining exact permitted and excluded domain namespaces. If a sub-CA attempts to issue a certificate outside these boundaries, relying parties will immediately reject it as invalid.

Why this answer

Name Constraints restrict the namespace within which all subject names in certificates issued by the CA must reside. This crucial X.509 extension prevents a compromised subordinate CA from generating trusted certificates for domains outside its permitted organizational scope, thereby containing blast radius in enterprise PKI hierarchies.

Exam trap

Candidates often select certificate revocation lists or basic constraints, missing that namespace restriction specifically requires the name constraints extension.

140
MCQeasy

A security analyst is reviewing authentication logs and notices that an attacker attempted to log in using a list of previously breached username and password combinations. The attack failed because the organization had implemented a control that requires users to provide a second factor in addition to their password. Which type of attack was mitigated?

A.Rainbow table attack
B.Credential stuffing
C.Brute force
D.Password spraying
AnswerB

Credential stuffing uses lists of username and password pairs obtained from data breaches on other sites. Attackers assume users reuse credentials across services. The scenario explicitly mentions a list of previously breached combinations, which is the hallmark of credential stuffing. Requiring a second factor (like a one-time code) prevents unauthorized access even if the password is correct, effectively mitigating this attack.

Why this answer

Credential stuffing specifically uses breached username and password pairs to gain unauthorized access. The presence of a second authentication factor prevents the attacker from succeeding even with valid credentials. Other attacks like password spraying, brute force, or rainbow tables do not rely on breached credential lists in the same way.

Therefore, the mitigated attack is credential stuffing.

Exam trap

The trap here is confusing credential stuffing with password spraying, as both involve multiple login attempts, but credential stuffing uniquely uses breached credentials from other services.

141
MCQeasy

A security administrator is planning to deploy Windows 10 feature updates to a pilot group of devices using Windows Update for Business. The administrator wants to ensure that the pilot group receives the feature update before the rest of the organization, so that any issues can be identified early. Which Windows Update for Business configuration should the administrator use?

A.Set a feature update deferral of 365 days for the pilot group.
B.Assign the pilot group to a ring with a feature update pause of 35 days.
C.Configure a quality update deferral of 0 days for the pilot group.
D.Create a deployment ring with a feature update deferral of 0 days for the pilot group.
AnswerD

A deployment ring with a feature update deferral of 0 days means the pilot group will receive feature updates as soon as they are released, before other rings with longer deferrals. This allows early testing and identification of issues. It is the standard approach for pilot deployments in Windows Update for Business.

Why this answer

The correct answer is to create a deployment ring with a feature update deferral of 0 days for the pilot group. This ensures the pilot group receives feature updates immediately upon release, allowing early testing. Other settings either delay updates or affect the wrong update type, which would not achieve the goal of early pilot deployment.

Exam trap

The trap here is mixing up feature and quality update deferrals, or thinking that a pause or long deferral would help a pilot group receive updates early.

142
MCQmedium

Which Windows feature allows for fine-grained access control based on user attributes like department or project code rather than just security groups?

A.Access-Based Enumeration (ABE)
B.Dynamic Access Control (DAC)
C.NTFS Permissions
D.User Account Control (UAC)
AnswerB

DAC uses claims-based identity and resource properties to enforce access. It allows for complex rules, such as 'only managers in the Finance department can access files marked as sensitive,' which is far more efficient than managing membership in dozens of static security groups across the domain.

Why this answer

Dynamic Access Control (DAC) allows administrators to create policies based on resource and user properties, providing a more flexible and scalable alternative to traditional security groups. This is essential in large organizations where maintaining thousands of security groups becomes unmanageable. DAC enhances the GSEC focus on least privilege by enabling context-aware access decisions that adapt automatically as user attributes change within Active Directory or file metadata.

Exam trap

Candidates often default to 'Group Policy' or 'Active Directory Groups' as the answer. They fail to distinguish between group-based access and the attribute-based flexibility offered by Dynamic Access Control.

143
MCQmedium

A security engineer at a hospital is deploying an inline network Intrusion Prevention System (IPS) on a 10 Gbps link between the clinical VLAN and the data center. The IPS must block exploits without introducing latency that would disrupt real-time patient monitoring. Which deployment consideration is MOST critical to meet this requirement?

A.Verify the IPS can perform inspection at line rate with low latency and has a hardware bypass mechanism to maintain availability if it fails.
B.Configure the IPS in tap mode with a fail-open bypass so it can inspect traffic without being in the forwarding path.
C.Enable full packet capture on the IPS to record all traffic for forensic analysis, accepting the performance overhead.
D.Deploy the IPS in promiscuous mode and rely on span ports to mirror traffic from the core switch.
AnswerA

For an inline IPS on a high-speed clinical link, the device must handle 10 Gbps of traffic without adding latency that affects real-time monitoring. A hardware bypass or fail-to-wire capability ensures that if the IPS fails or loses power, traffic continues to flow, preserving patient safety. This combination of performance and availability is the primary deployment consideration for this scenario.

Why this answer

An inline IPS on a critical 10 Gbps link must inspect and block at line rate while not introducing latency that disrupts real-time applications. A hardware bypass or fail-to-wire mechanism is essential to maintain network availability if the IPS fails, which is especially important in a hospital setting. Performance and availability are the key considerations for this deployment.

Exam trap

The trap here is assuming that any inline IPS can handle 10 Gbps without verifying its throughput and latency specifications, or overlooking the need for a hardware bypass to prevent a single point of failure.

144
MCQmedium

A security engineer is configuring a Linux server to enforce password quality for all local accounts. The requirement is that passwords must be at least 14 characters long, contain at least one uppercase letter, one lowercase letter, one digit, and one special character, and must not repeat any of the last 5 passwords. Which file should the engineer edit to enforce these settings?

A./etc/pam.d/login
B./etc/login.defs
C./etc/security/pwquality.conf
D./etc/shadow
AnswerC

The /etc/security/pwquality.conf file is used by the pam_pwquality PAM module to enforce password complexity requirements such as minimum length (minlen), required character classes (ucredit, lcredit, dcredit, ocredit), and password history via the remember parameter (often set in PAM configuration but also influenced by pwquality). This is the correct location to define the specified password policy for local accounts on modern Linux distributions.

Why this answer

Password complexity and history requirements on Linux are enforced by the pam_pwquality module, which reads its configuration from /etc/security/pwquality.conf. This file allows administrators to set minlen, character class requirements, and other constraints. While PAM configuration files like system-auth or common-password reference the module, the policy parameters themselves are defined in pwquality.conf.

Therefore, editing /etc/security/pwquality.conf is the correct action to meet the stated password policy.

Exam trap

The trap here is confusing password aging settings in /etc/login.defs with password complexity enforcement, which is handled by PAM and pwquality.conf.

145
Multi-Selectmedium

When configuring endpoint security, which THREE of the following are considered 'defense-in-depth' measures to protect against ransomware?

Select 3 answers
A.Applying the Principle of Least Privilege (PoLP) to user file shares.
B.Disabling all network connections to the endpoint.
C.Utilizing offline or immutable backups.
D.Deploying Endpoint Detection and Response (EDR) with behavioral blocking.
E.Enabling guest access for easier file sharing across departments.
AnswersA, C, D

Limiting user permissions ensures that if a workstation is compromised, the attacker can only encrypt the files that user has permission to modify. This prevents the ransomware from spreading to critical shared network drives or sensitive directories, effectively containing the potential impact of the infection to a single user's profile.

Why this answer

Defense-in-depth requires multiple layers of security to ensure that if one control fails, others are present to mitigate the impact. For ransomware, this includes preventing the execution, limiting the scope of damage through permissions, and maintaining immutable backups. These layers ensure that an attacker must overcome multiple, diverse obstacles to achieve their objective of data encryption, significantly increasing the difficulty of a successful attack.

Exam trap

Candidates sometimes select single-layer preventative solutions like basic password policies, missing that defense-in-depth requires multiple complementary layers spanning permissions, detection, and recovery.

146
MCQmedium

When evaluating an endpoint's disk encryption, why is 'Pre-Boot Authentication' (PBA) considered a critical security component?

A.It improves the speed of system startup and file indexing.
B.It ensures that the computer cannot be booted from an external drive.
C.It requires authentication before the encryption keys are released to memory.
D.It automatically syncs the encryption keys to a cloud-based backup.
AnswerC

Pre-Boot Authentication forces the user to input a secret before the decryption keys are loaded into RAM. This ensures that the data is truly protected against cold-boot attacks and unauthorized access if the machine is powered off, as the drive remains encrypted until that specific challenge is successfully met.

Why this answer

PBA ensures that the encryption keys are not loaded into memory until the user provides the correct credentials at boot time. Without PBA, the encryption is transparent once the OS starts, meaning if the device is stolen while powered on or in sleep mode, an attacker could potentially access the data. PBA provides a strong gatekeeper that protects the data at rest even before the OS loads.

Exam trap

Candidates often confuse PBA with Full Disk Encryption (FDE) generally, failing to realize that without PBA, the keys are loaded automatically at boot, leaving data vulnerable to cold-boot or memory attacks.

147
Multi-Selecthard

A security architect is designing a defensible network architecture for a new campus. The architect must implement controls that limit the spread of malware from an infected endpoint to other endpoints on the same VLAN. Which TWO actions should be included in the design? (Choose two.)

Select 2 answers
A.Implement a host-based intrusion prevention system (HIPS) on every endpoint to block malicious traffic at the source.
B.Implement 802.1X with dynamic VLAN assignment so endpoints are placed into role-based segments based on identity and posture.
C.Deploy a honeypot on each VLAN to detect and automatically blackhole infected endpoints.
D.Configure DHCP snooping and IP Source Guard on all access ports to validate endpoint IP and MAC bindings.
E.Enable private VLANs on access switches to isolate endpoints within the same VLAN from one another while allowing them to reach the default gateway.
AnswersB, E

802.1X with dynamic VLAN assignment groups endpoints by role, such as employee, contractor, or guest, and can place unpatched devices into a remediation VLAN. This limits lateral spread because an infected endpoint in one role segment cannot directly reach endpoints in another segment. It is a foundational control for defensible network architecture and directly addresses same-VLAN spread by making VLANs smaller and identity-driven.

Why this answer

Limiting malware spread on a campus network requires segmenting endpoints at Layer 2. 802.1X with dynamic VLAN assignment places devices into role-based segments, and private VLANs prevent direct host-to-host communication within a VLAN. Together they reduce the blast radius of an infection. Honeypots, DHCP snooping with IP Source Guard, and host-based IPS improve detection or integrity but do not provide the network segmentation needed to contain lateral movement.

Exam trap

The trap here is selecting integrity or detection controls like DHCP snooping or honeypots when the requirement is specifically to prevent endpoint-to-endpoint spread through network segmentation.

148
MCQhard

Refer to the exhibit. What is the effect of the (OI)(CI) flags on the 'Finance_Users' group for the C:\Data directory?

A.Files and subfolders inherit the permissions from the parent.
B.Only existing files are modified.
C.The permissions are applied to C:\Data only, not children.
D.The user cannot delete the folder.
AnswerA

Object Inherit (OI) ensures files inherit the ACE, and Container Inherit (CI) ensures subfolders inherit the ACE. These flags are critical for administrative efficiency, as they automatically propagate security settings to all child objects, ensuring consistent application of the least privilege principle throughout the file hierarchy.

Why this answer

The (OI) flag stands for Object Inherit, and (CI) stands for Container Inherit. These flags ensure that permissions assigned to the parent folder propagate to all files and subfolders within the directory. This is essential for maintaining consistent access control in environments with deep directory structures.

Without these flags, newly created files or subfolders might not inherit the necessary security descriptors, leading to potential access gaps or security policy bypasses.

Exam trap

Candidates frequently confuse inheritance flags with explicit permission grants or deny rules, misinterpreting how permissions flow down directory trees.

149
MCQmedium

A security engineer wants to ensure that container images are not modified after they are built and pushed to a registry. Which mechanism provides the strongest assurance of image integrity and authenticity?

A.Implementing a read-only filesystem for the container at runtime.
B.Using SHA-256 image digests instead of mutable image tags.
C.Applying cryptographic digital signatures to container images.
D.Scanning images for known vulnerabilities using a static analyzer.
AnswerC

Digital signatures provide a verifiable link between the image and the build process. By using a private key to sign the image manifest, the organization ensures that any subsequent modifications to the image data will cause the signature validation check to fail upon deployment.

Why this answer

Content trust and image signing using tools like Notary or Cosign ensure that the image pulled by a runtime is exactly the same one pushed by the CI/CD pipeline. By cryptographically signing the manifest, organizations prevent man-in-the-middle attacks and unauthorized registry modifications. This is vital in modern DevSecOps, as compromised images could introduce persistent backdoors or vulnerabilities into the production environment without triggering standard application-level alerts.

Exam trap

Candidates often confuse vulnerability scanning tools with integrity mechanisms, incorrectly assuming that finding bugs prevents unauthorized modification or guarantees the authenticity of the container image pushed to the registry.

150
MCQmedium

A financial services company is aligning its security program with the CIS Critical Security Controls. The CISO asks you to identify which Implementation Group (IG) is most appropriate for a small startup with limited IT staff that handles only publicly available data and has no regulatory compliance obligations. Which IG should you recommend?

A.IG1
B.IG0
C.IG2
D.IG3
AnswerA

IG1 is designed for small organizations with limited resources and low data sensitivity. It consists of essential cyber hygiene safeguards that provide a baseline defense against general, non-targeted attacks. Since the startup handles only public data and has no compliance mandates, IG1 is the proportionate starting point.

Why this answer

IG1 is the correct choice because it provides a foundational set of safeguards tailored to small organizations with limited resources and low-risk data. It focuses on essential cyber hygiene that addresses the most common attack vectors. For a startup with no sensitive data or regulatory requirements, IG1 offers a realistic and effective starting point without overburdening its IT staff.

Exam trap

The trap here is assuming that a higher Implementation Group always provides better security, when in fact the appropriate IG depends on risk profile and available resources.

Page 1

Page 2 of 5

Page 3

All pages