Courseiva

GIAC Security Essentials (GSEC) — Questions 226–300

351 questions total · 5pages · All types, answers revealed

Page 3

Page 4 of 5

Page 5
226
MCQeasy

A retail chain wants to let customers join a guest WLAN without sharing the corporate preshared key, while still keeping guest traffic isolated from point-of-sale systems. Which design best meets these requirements?

A.Broadcast the corporate SSID with WPA3-SAE and give customers a rotating guest passphrase that changes weekly.
B.Deploy the guest network on the same SSID as corporate users and rely on 802.1X to assign guests a restricted role after authentication.
C.Enable a hidden guest SSID using WEP with a shared key so customers can connect without configuration changes.
D.Configure a separate guest SSID mapped to a dedicated VLAN with client isolation enabled and no route to internal subnets.
AnswerD

A distinct guest SSID bound to its own VLAN keeps guest traffic on a segmented broadcast domain, and client isolation prevents guests from reaching each other. With no routing or ACL permitting access to internal subnets, point-of-sale systems stay unreachable. This satisfies open or captive-portal guest access without distributing the corporate preshared key, which remains protected for internal users.

Why this answer

Guest access is best delivered on its own SSID mapped to a segmented VLAN with client isolation and no internal routing. This keeps the corporate preshared key private, prevents guest-to-guest and guest-to-internal access, and protects point-of-sale systems through network segmentation rather than relying on the guest credential.

Exam trap

The trap here is believing that hiding the SSID or rotating a guest passphrase provides isolation, when only VLAN segmentation and firewall policy actually separate guest traffic from internal systems.

227
MCQeasy

Which Windows component is responsible for the centralized management of security configurations, including password policies and user rights, across a domain?

A.Windows Registry
B.Group Policy Objects
C.Task Scheduler
D.Microsoft Management Console
AnswerB

GPOs provide the primary mechanism for applying security policies and configurations across a domain. They allow for granular control and automated enforcement, ensuring that hardening standards are consistently applied to all managed workstations and servers in the environment.

Why this answer

Group Policy Objects (GPOs) allow administrators to define specific configurations for users and computers across the entire domain. By centralizing these settings, security teams can ensure consistent enforcement of hardening standards and compliance policies. Proper GPO management is essential for minimizing the attack surface and maintaining a uniform security baseline in any enterprise Windows architecture.

Exam trap

Candidates often confuse GPOs with 'Local Security Policy' (secpol.msc). While both manage settings, GPOs are specifically the tool for centralized domain-wide management.

228
MCQeasy

A startup is deploying a web application on a public cloud infrastructure-as-a-service platform. The security lead wants to ensure that the operating system patches, application code, and firewall rules within the guest are the startup's responsibility, while the physical hosts and hypervisor are the provider's. Which cloud concept clarifies this division?

A.Infrastructure as code
B.The shared responsibility model
C.Defense in depth
D.The principle of least privilege
AnswerB

The shared responsibility model defines which security tasks belong to the cloud provider and which belong to the customer. In IaaS, the provider secures the physical facilities, hosts, and hypervisor, while the customer secures the guest operating system, applications, and guest firewall rules. This directly matches the division the security lead wants to clarify.

Why this answer

The shared responsibility model is the framework that assigns security ownership between the cloud provider and the customer. For IaaS, the provider handles the physical datacenter, hardware, and hypervisor, while the customer is responsible for the guest OS, applications, and guest-level firewall configuration. The other concepts address access scope, layered controls, or automation, not the division of duties.

Exam trap

The trap here is selecting a familiar security principle like least privilege or defense in depth when the question specifically asks which concept defines the boundary of provider versus customer security duties.

229
MCQhard

A security analyst is reviewing a suspicious Windows 10 workstation. The analyst finds that a user-level process named 'notepad.exe' has spawned a child process named 'cmd.exe', which then created a scheduled task named 'MicrosoftEdgeUpdateTaskMachineUA' that runs a PowerShell script from the user's AppData folder. The analyst suspects a fileless malware infection. Which of the following techniques is the malware MOST likely using to maintain persistence?

A.Scheduled task created via schtasks.exe
B.Service creation using sc.exe
C.Registry Run key modification
D.Windows Management Instrumentation (WMI) event subscription
AnswerA

The analyst observed that cmd.exe created a scheduled task named 'MicrosoftEdgeUpdateTaskMachineUA' that runs a PowerShell script from AppData. This is a classic persistence technique using the Windows Task Scheduler, often executed via schtasks.exe or the Task Scheduler COM API. The task masquerades as a legitimate Microsoft Edge update task to avoid suspicion, confirming scheduled task persistence.

Why this answer

The malware established persistence by creating a scheduled task that masquerades as a legitimate Microsoft Edge update task. This technique allows the malicious PowerShell script to run at logon or on a schedule. The task name mimics a trusted component to evade detection.

The other options are valid persistence methods but do not align with the observed artifact of a scheduled task created by cmd.exe.

Exam trap

The trap here is assuming that any suspicious child process of notepad.exe indicates a specific persistence method like WMI or registry keys, when the scenario explicitly points to a scheduled task.

230
MCQhard

A security administrator is troubleshooting access issues on a Windows file server. A user, Bob, is a member of the 'Sales' group, which has 'Read & Execute' on a folder. Bob is also a member of the 'Managers' group, which has 'Full Control' on the same folder. However, Bob cannot delete files. What is the most likely cause?

A.The 'Sales' group has an explicit 'Deny' for 'Delete' that overrides the 'Full Control' from 'Managers'.
B.The 'Full Control' permission from 'Managers' does not include the 'Delete' permission.
C.Bob's user account has an explicit 'Deny' for 'Delete' that is inherited from the parent folder.
D.The 'Read & Execute' permission from 'Sales' is more restrictive and overrides the 'Full Control' from 'Managers'.
AnswerA

If the Sales group has an explicit Deny for Delete, that Deny takes precedence over the Allow from Managers. Even though Bob is a Manager with Full Control, the Deny from Sales membership blocks deletion. This is a classic case of Deny overriding Allow, and it explains why Bob cannot delete files despite having Full Control via another group.

Why this answer

In Windows ACLs, an explicit Deny entry overrides any Allow permissions, regardless of the source. If the Sales group has a Deny for Delete, Bob's membership in that group triggers the Deny, preventing deletion even though Managers grants Full Control. This is the most plausible explanation given the information.

Exam trap

The trap here is assuming that having Full Control from one group guarantees all actions, ignoring possible Deny entries from other group memberships.

231
MCQeasy

A small marketing agency has limited IT staff and resources. They are looking to adopt a security framework to protect their assets. They have heard about the CIS Critical Security Controls and want to know which Implementation Group is most appropriate for their situation. Which of the following should they choose?

A.Implementation Group 1 (IG1) because it provides foundational cyber hygiene suitable for organizations with limited resources.
B.Implementation Group 3 (IG3) because it offers the highest level of security.
C.Implementation Group 2 (IG2) because it includes additional safeguards for moderate risk organizations.
D.None of the Implementation Groups; they should develop a custom framework from scratch.
AnswerA

IG1 is designed for small organizations with limited resources and low risk. It includes 56 basic safeguards that represent essential cyber hygiene. For a small marketing agency, IG1 provides a practical starting point to protect against common threats without overwhelming their IT staff. It is the recommended baseline for all organizations, regardless of size, but is particularly suited for those with constrained resources.

Why this answer

Implementation Group 1 (IG1) is specifically designed for small organizations with limited resources. It offers a foundational set of 56 safeguards that address the most common cyber threats. For a small marketing agency, IG1 provides a manageable and effective starting point to improve security posture without requiring extensive resources or expertise.

Exam trap

The trap here is assuming that a higher Implementation Group always means better security, leading to the selection of IG2 or IG3 when IG1 is more appropriate for the organization's size and risk.

232
MCQeasy

A hospital's billing server runs Windows Server 2019 and stores insurance claim data. The security team wants to add a control that will detect unauthorized modification of the claim files even if an attacker gains administrative access to the operating system. Which control best meets this requirement?

A.Configure Windows Audit Policy to log all file access events to the Security event log.
B.Enable Windows BitLocker full-disk encryption on the billing server's data volume.
C.Deploy a host-based intrusion prevention system (HIPS) that blocks suspicious process execution on the billing server.
D.Implement file integrity monitoring (FIM) using SHA-256 hashes of the claim files and schedule regular baseline comparisons.
AnswerD

File integrity monitoring computes cryptographic hashes of the claim files and stores a known-good baseline. On subsequent scans, any modification produces a hash mismatch, alerting the team even if the attacker used legitimate administrative privileges. This directly satisfies the requirement to detect unauthorized modification independently of access controls.

Why this answer

Detecting unauthorized modification of stored data requires a mechanism that can prove whether contents changed, regardless of the attacker's privilege level. Hash-based file integrity monitoring establishes a trusted baseline and alerts on any deviation, which is exactly what the hospital needs. Encryption and auditing address confidentiality and visibility respectively, and neither produces cryptographic evidence of tampering.

Exam trap

The trap here is assuming that administrative access logging or disk encryption will reveal file tampering, when only a hash-based baseline comparison can prove content changes.

233
MCQeasy

A security administrator is hardening a Linux web server. The administrator needs to ensure that the Apache service, which runs as the user 'www-data', cannot be used to escalate privileges if compromised. Which file should the administrator check to verify that 'www-data' does not have a valid login shell?

A./etc/sudoers
B./etc/group
C./etc/shadow
D./etc/passwd
AnswerD

The /etc/passwd file contains the login shell for each user in its seventh field. By checking this file, the administrator can verify that the 'www-data' account has a non-login shell such as /usr/sbin/nologin or /bin/false, which prevents interactive logins and reduces privilege escalation risk if the service is compromised.

Why this answer

The login shell for a user is stored in the seventh field of /etc/passwd. Service accounts like 'www-data' should have a non-interactive shell such as /usr/sbin/nologin to prevent attackers from obtaining a shell if the service is compromised. Other files contain password hashes, group data, or sudo rules, but none store the login shell assignment.

Exam trap

The trap here is confusing the purpose of /etc/shadow with that of /etc/passwd, assuming that password-related security settings are found in the same file as shell assignments.

234
MCQmedium

A security administrator manages a fleet of Windows 10 Enterprise devices that must remain on version 1809 because a critical line-of-business application is only certified for that build. The organization uses Windows Update for Business (WUfB) and wants to prevent these devices from receiving feature updates for 18 months while still receiving quality updates. Which WUfB setting should the administrator configure?

A.Disable the Windows Update service and manage quality updates through a third-party patch management tool.
B.Set the feature update deferral period to 365 days and enable Pause feature updates for 35 days.
C.Assign the devices to the Semi-Annual Channel (Targeted) ring and set a 365-day feature update deferral.
D.Configure a Windows Update for Business target version using the TargetReleaseVersion and TargetReleaseVersionInfo policies.
AnswerD

TargetReleaseVersion and TargetReleaseVersionInfo are the supported WUfB policies to pin a device to a specific Windows feature update version. Setting the target version to 1809 prevents the device from moving to a later feature update while still allowing quality updates. This is the correct way to keep devices on a specific build for compatibility.

Why this answer

TargetReleaseVersion and TargetReleaseVersionInfo allow an administrator to pin Windows 10 devices to a specific feature update version, such as 1809, while continuing to receive quality updates. This is the supported method in Windows Update for Business to prevent feature updates for an extended period without disabling updates entirely. Deferrals and pauses are temporary and do not meet the 18-month requirement.

Exam trap

The trap here is confusing temporary deferral or pause settings with a persistent version pin, which is the only WUfB mechanism that blocks feature updates indefinitely while allowing quality updates.

235
MCQmedium

Refer to the exhibit. What is the security impact of the provided Kubernetes security context configuration?

A.The pod will be unable to pull the image from the registry.
B.The container is protected against setuid-based privilege escalation.
C.The pod will block all network traffic from the container.
D.The application will automatically have its vulnerabilities patched.
AnswerB

By setting 'allowPrivilegeEscalation' to false, the container runtime prevents the process from gaining more privileges than its parent. This effectively neutralizes setuid binaries that could otherwise be leveraged by an attacker to elevate their privileges from a standard user to root within the container's isolated execution environment.

Why this answer

This configuration enforces the principle of least privilege by ensuring the container cannot run as root and preventing any process from gaining more privileges than its parent. 'allowPrivilegeEscalation: false' is a critical setting that prevents setuid binaries from changing the process effective user ID, which is a common technique used by attackers to escalate privileges within a container after achieving initial execution.

Exam trap

Candidates often misread 'allowPrivilegeEscalation: false' as completely disabling the container execution or restricting root file system writes, rather than focusing specifically on blocking setuid escalation vectors.

236
MCQhard

A healthcare provider must protect laptops that store electronic protected health information (ePHI). The security team wants to ensure that if a laptop is lost or stolen, the data on the drive remains confidential even if an attacker removes the drive and connects it to another computer. The team also wants to minimize the risk of cold-boot attacks that could extract encryption keys from memory. Which full disk encryption configuration best meets these requirements?

A.BitLocker with a startup key stored on a USB flash drive
B.BitLocker with TPM and PIN protector, plus pre-boot authentication
C.BitLocker with TPM-only protector and no PIN
D.EFS encryption of the ePHI folders with user certificates
AnswerB

BitLocker with a TPM and PIN protector requires a user-entered PIN before the operating system loads, providing pre-boot authentication. This means an attacker who steals the laptop cannot simply boot it to reach the decryption keys in memory, significantly reducing cold-boot and DMA attack risk. The TPM also seals keys to the platform, so moving the drive to another computer does not allow decryption, meeting the confidentiality requirement.

Why this answer

BitLocker with a TPM and PIN protector enforces pre-boot authentication, so the drive cannot be unlocked without the PIN and the TPM-bound key. This protects against offline drive removal and reduces the window for cold-boot or DMA attacks because the operating system and keys are not loaded until the PIN is entered, satisfying both confidentiality and cold-boot risk reduction.

Exam trap

The trap here is assuming that any BitLocker configuration with a TPM provides pre-boot authentication, when TPM-only mode boots without user input.

237
MCQhard

A software company runs its CI/CD build agents as containers on a Docker Engine host that is shared by several development teams. A security engineer observes that a build job launched by one team was able to read environment variables belonging to a concurrently running build from a different team, and that the job also reached the host's filesystem through a mounted path. Which configuration change most directly prevents both of these cross-tenant exposures on the same host?

A.Run each team's build agents in separate virtual machines on the same physical host rather than as containers on one Docker Engine instance.
B.Configure the Docker daemon to use a different storage driver for each team so image layers are not shared between build jobs.
C.Add the --read-only flag when starting each build container so the container filesystem cannot be modified at runtime.
D.Enable user namespace remapping (userns-remap) on the Docker daemon so container root maps to an unprivileged host UID.
AnswerA

Separate virtual machines on the same host give each team its own kernel and its own isolated process table, so one build cannot inspect another build's environment variables and cannot traverse into another tenant's mounted paths. Because the containers shared one Docker Engine instance, the kernel-mediated isolation was insufficient; moving to per-team VMs restores a hardware-enforced boundary that directly prevents both observed exposures.

Why this answer

The two symptoms — reading another build's environment variables and reaching the host filesystem through a mount — both stem from workloads sharing a single kernel and Docker Engine instance. Container isolation is namespace- and cgroup-based, so a misconfigured or privileged container can see peer processes and host paths. Placing each team's agents in its own virtual machine restores a separate kernel and process table per tenant, which is the change that directly removes both exposures at once.

Exam trap

The trap here is assuming that any single Docker hardening flag, such as a read-only root filesystem or user namespace remapping, provides full multi-tenant isolation when the real gap is the shared kernel and shared daemon.

238
MCQhard

A junior analyst at a healthcare provider receives a call from the help desk: a radiology workstation is behaving erratically and displaying a ransom note. The analyst immediately opens a remote session, logs in with domain administrator credentials, and begins deleting suspicious files in the user's startup folder. The workstation is still powered on and connected to the network. Which incident handling principle did the analyst MOST directly violate?

A.Containment must precede eradication to prevent the threat from spreading to other systems.
B.The analyst used domain administrator credentials, which violates the principle of least privilege.
C.The analyst failed to preserve the chain of custody for the workstation's hard drive.
D.The analyst should have escalated to senior management before taking any action on the workstation.
AnswerA

The analyst deleted files before containing the workstation, leaving it networked and allowing the malware to spread or communicate. Proper sequence is containment then eradication. Deleting files with elevated credentials also risks tipping off the attacker and destroying volatile evidence. This is the most direct violation of the containment-first principle.

Why this answer

The analyst began eradication (deleting files) while the compromised workstation remained powered on and connected to the network. This violates the containment-first principle: without isolating the system, malware can spread laterally, communicate with command-and-control, or re-infect. Proper incident handling isolates the host—via network disconnection or VLAN isolation—before removing malicious artifacts.

Containment limits damage and preserves evidence for later analysis.

Exam trap

The trap here is assuming that immediate deletion of malicious files constitutes effective response, when in fact containment must occur first to prevent spread and preserve evidence.

239
MCQhard

A security analyst is investigating a suspicious file on a Linux server. The analyst wants to determine the file's inode number, permissions, owner, group, size, and last modification time without modifying the file. Which command should the analyst use?

A.file filename
B.du -h filename
C.ls -l filename
D.stat filename
AnswerD

The stat command displays detailed file metadata including the inode number, permissions, owner, group, size, and timestamps (access, modify, change). It provides all the requested information in a single output and does not modify the file. This makes it the ideal tool for forensic analysis where comprehensive file attributes are needed.

Why this answer

The stat command is designed to display comprehensive file metadata, including the inode number, permissions, ownership, size, and timestamps. Unlike ls, it includes the inode number, which is crucial for forensic analysis. Other commands like file and du provide limited information and do not meet the requirement for a complete metadata overview.

Exam trap

The trap here is assuming that ls -l provides all file metadata, overlooking that it omits the inode number, which is often critical in forensic investigations.

240
MCQmedium

A security analyst is tuning a Splunk Enterprise correlation search that detects brute-force attempts against SSH. The current search fires thousands of alerts daily because it counts every failed password event, including those from a single user who mistypes a password once. The analyst needs to reduce noise while still catching distributed brute-force attacks. Which modification should the analyst make to the correlation search?

A.Add a threshold condition that triggers only when more than 10 failed logins occur from the same source IP within 5 minutes.
B.Correlate failed logins across multiple source IPs by counting distinct source IPs per target account over a longer window, and trigger when the distinct count exceeds a threshold.
C.Increase the search time window to 24 hours and lower the alert threshold to 5 failed logins per user.
D.Filter out all failed password events for service accounts and only alert on failed logins for interactive user accounts.
AnswerB

This approach directly addresses distributed brute-force attacks, where many source IPs each try a few passwords against the same account. By counting distinct source IPs per target account over a longer window, the search detects the attack pattern while ignoring isolated mistyped passwords from a single user. It reduces false positives because a single user typically fails from one or two IPs, not many, and it still catches the distributed behavior.

Why this answer

Distributed brute-force attacks spread login attempts across many source IPs to evade per-IP thresholds. The effective detection method is to correlate failed logins by target account and count distinct source IPs over a longer period. This catches the attack while ignoring a single user's occasional mistyped password, reducing false positives without missing the distributed pattern.

Exam trap

The trap here is assuming that a simple per-source-IP threshold will catch all brute-force attacks, when distributed attacks deliberately use many IPs to stay under such thresholds.

241
MCQmedium

When designing a secure container orchestration strategy, which approach best minimizes the impact of a compromised container on the host kernel?

A.Disable all kernel modules on the host operating system.
B.Use a specialized container runtime like gVisor to intercept system calls.
C.Increase the memory limit for every container in the cluster.
D.Run all containers with the --privileged flag to ensure compatibility.
AnswerB

gVisor acts as a user-space kernel that intercepts and handles system calls. By limiting the number of system calls that reach the host kernel, it drastically reduces the available attack surface for privilege escalation and kernel exploits, effectively containing the potential damage from a compromised application within the guest.

Why this answer

Kernel vulnerabilities are a primary vector for container escapes. By using technologies like gVisor or Kata Containers, the container environment uses a hardened kernel or a separate micro-VM, providing an additional layer of isolation. Standard containers share the host kernel directly; if the kernel is exploited via a system call, the attacker can break out of the container boundary entirely, leading to full system compromise of the underlying host node.

Exam trap

Candidates often select standard namespace isolation or network policies, which do not protect the host kernel from system call exploitation, the primary method for container breakouts.

242
MCQhard

An information security auditor discovers a custom compiled binary in a shared directory with the following permissions: -rwsr-xr-x. The file is owned by the root user. What is the primary security implication of this finding?

A.The file can be modified by any user in the group.
B.The binary executes with the privileges of the root user.
C.The file is encrypted and requires a password to run.
D.The binary is restricted to running only in runlevel 1.
AnswerB

The 's' in the owner's execute position indicates the Set User ID bit is active. Since the owner is root, any user running this binary will have their effective user ID changed to root. This allows the program to perform administrative tasks that the standard user would normally be restricted from.

Why this answer

Understanding special permissions like SUID is critical for Linux security because they often lead to privilege escalation vulnerabilities. When the SUID bit is set on a file owned by root, any user who executes that file gains root-level privileges for the duration of the process. If the binary is poorly written, it can be exploited.

Exam trap

Candidates confuse the SUID permission with SGID or standard execution rights, failing to realize that the 's' in the user position elevates execution privileges to the file owner.

243
MCQeasy

Which virtualization security concern occurs when an attacker breaks out of the guest operating system to interact directly with the hypervisor?

A.Resource exhaustion.
B.Virtual Machine escape.
C.Snapshot tampering.
D.Hypervisor misconfiguration.
AnswerB

A VM escape allows an attacker to bypass the isolation provided by the hypervisor and interact with the host OS. This is a severe security vulnerability that compromises the entire virtualization environment, potentially leading to unauthorized data access and total control over all virtualized assets on that host.

Why this answer

A VM escape is a critical vulnerability where an attacker gains access to the host machine from a guest VM. This allows the attacker to compromise other VMs on the same host or the physical hardware itself. Understanding this threat is essential for GSEC professionals, as it represents the highest level of breach in a virtualized infrastructure, requiring rigorous patching and hypervisor hardening.

Exam trap

Candidates sometimes confuse VM escape with lateral movement or privilege escalation. They fail to distinguish between moving within the guest OS and breaking out into the host's privileged domain.

244
MCQmedium

A mid-sized healthcare provider has adopted the CIS Critical Security Controls and wants to measure the effectiveness of its security program over time. The CISO asks you to recommend a method that provides a quantifiable, repeatable score of how well the organization is implementing the CIS Controls. Which approach best meets this requirement?

A.Deploy a vulnerability scanner across all subnets and track the total count of open vulnerabilities as the main indicator.
B.Conduct a penetration test against the external perimeter and use the number of critical findings as the primary metric.
C.Perform a CIS Controls Self Assessment Tool (CIS CSAT) using the CIS Controls Implementation Group criteria to generate a maturity score.
D.Calculate the mean time to remediate (MTTR) security incidents and present that as the sole measure of control effectiveness.
AnswerC

CIS CSAT is the official self-assessment tool that maps an organization's implementation of the CIS Controls to Implementation Groups and produces a quantifiable maturity score. It allows repeatable measurements over time, directly addressing the CISO's need to track program effectiveness and demonstrate progress against the CIS Controls framework.

Why this answer

The CIS Controls Self Assessment Tool (CSAT) is designed specifically to measure an organization's implementation of the CIS Controls and produce a quantifiable maturity score. It aligns with Implementation Groups and enables repeatable tracking over time. Other options focus on narrow technical metrics that do not assess the breadth of the CIS Controls or provide a consistent program-level score.

Exam trap

The trap here is confusing technical metrics like vulnerability counts or MTTR with a structured, control-based maturity assessment.

245
MCQhard

A company stores backup tapes offsite. An auditor notes that the tapes contain sensitive customer data and are transported by a third-party courier. The security manager wants to ensure that a lost tape cannot expose customer information. Which control best addresses this risk?

A.Encrypt the backup tapes using AES-256 with keys managed separately from the tapes.
B.Require the courier to sign a non-disclosure agreement and provide chain-of-custody documentation.
C.Install GPS trackers on the transport vehicle and monitor the route in real time.
D.Reduce the backup retention period from one year to thirty days to limit exposure.
AnswerA

Encrypting the tapes with AES-256 renders the data unreadable without the key, so a lost or stolen tape does not expose customer information. Managing keys separately from the tapes ensures the key is not lost with the media. This is the direct technical control that addresses the confidentiality risk described.

Why this answer

The risk is that a lost or stolen tape exposes customer data, so the control must make the data unreadable without authorization. Encrypting tapes with AES-256 and storing keys separately achieves this directly. NDAs, GPS tracking, and shorter retention periods address accountability, recovery, or exposure windows but leave the tape contents readable if the media falls into the wrong hands.

Exam trap

The trap here is selecting administrative or physical controls that improve accountability or tracking while leaving the actual data on the tape unprotected.

246
MCQmedium

A security engineer is configuring an inline intrusion prevention system (IPS) on a 10 Gbps internal segment. During a pilot, the IPS begins dropping legitimate business traffic because its inspection engine cannot keep pace with bursts. Which deployment adjustment best preserves inline prevention while reducing false drops?

A.Enable fail-open bypass on the IPS so that traffic is forwarded without inspection when the inspection engine is overwhelmed.
B.Move the IPS to a passive TAP and rely on alerts to manually block offending sources at the firewall.
C.Tune the IPS inspection profile to match the segment's actual protocols and disable signatures for services not present on that segment.
D.Increase the IPS fail-closed timeout so that traffic is buffered longer during inspection spikes.
AnswerC

Overload often comes from inspecting irrelevant protocols and signatures, which consumes CPU and causes legitimate packets to be dropped. Profiling the segment and disabling unused signatures reduces processing load without removing inline prevention. This preserves enforcement while lowering false positives and false drops. It is the targeted, operationally sound adjustment because it aligns inspection scope with actual traffic rather than disabling protection.

Why this answer

Inline IPS overload is usually caused by inspecting traffic and signatures that do not apply to the protected segment. Profiling the segment and disabling irrelevant signatures reduces CPU and memory pressure, allowing the engine to keep up with burst traffic while still enforcing inline prevention. The other choices either remove inline enforcement or fail to address the actual capacity bottleneck, so they do not meet the requirement of preserving prevention while reducing false drops.

Exam trap

The trap here is assuming that preserving availability through bypass or passive monitoring is equivalent to preserving inline prevention.

247
MCQeasy

A security administrator is reviewing web server logs and notices a high volume of requests with different User-Agent strings, all targeting the same URL with varying query parameters. The requests appear to be attempting to inject SQL commands. Which of the following is the most effective mitigation to prevent SQL injection in this scenario?

A.Deploy a Web Application Firewall (WAF) with SQL injection signatures.
B.Implement strict input validation to allow only alphanumeric characters.
C.Encode all user input using HTML entity encoding before storing in the database.
D.Use parameterized queries (prepared statements) for all database access.
AnswerD

Parameterized queries ensure that user input is treated as data, not executable code, by separating SQL logic from data. This prevents attackers from altering the query structure, regardless of the input's content. It is the most effective and fundamental mitigation against SQL injection, as it eliminates the vulnerability at the source rather than relying on pattern matching.

Why this answer

SQL injection occurs when user input is improperly concatenated into SQL queries. Parameterized queries, also known as prepared statements, ensure that input is bound as parameters and never interpreted as SQL code. This eliminates the vulnerability entirely.

While WAFs and input validation can help, they are not as reliable or comprehensive. Therefore, using parameterized queries is the most effective mitigation.

Exam trap

The trap here is confusing input validation or encoding with proper query parameterization, which is the definitive fix for SQL injection.

248
MCQhard

A security engineer is hardening a fleet of Windows servers that run a legacy business application. The application vendor requires that the servers retain the ability to run unsigned macros for compatibility. Which mitigation strategy best reduces the risk of malicious macro-based code execution while maintaining the application's required functionality?

A.Enable Microsoft Defender Application Guard for Office and open all macro-enabled documents in the isolated container.
B.Add all internal file servers to the Trusted Locations list so macros in documents from those locations run without security prompts.
C.Set the Trust Center macro notification setting to Disable all macros without notification for all Office applications on the servers.
D.Implement Attack Surface Reduction rules that block Office applications from creating child processes and from injecting code into other processes.
AnswerD

ASR rules such as blocking Office child process creation and process injection target the behaviors that macro-based malware relies on, regardless of whether the macro itself is signed. This preserves the ability to run the required unsigned macros while preventing the most common payload delivery and execution techniques, directly matching the scenario's need to reduce malicious macro risk without breaking functionality.

Why this answer

Because the vendor insists on unsigned macros, the control must target what macros do after they run rather than whether they are trusted. Attack Surface Reduction rules that block Office child process creation and process injection stop the common execution chain used by macro malware while leaving legitimate macro logic intact, achieving the required balance between compatibility and risk reduction.

Exam trap

The trap here is treating macro execution itself as the only thing to block, when the stronger mitigation for mandatory unsigned macros is to constrain the post-exploitation behaviors they enable.

249
MCQhard

A financial services firm is designing a key management process for its internal certificate authority. The security architect wants a single hardware security module (HSM) cluster to protect the CA's signing key while ensuring that a compromise of one HSM appliance does not expose the key in plaintext to an attacker who gains root on that appliance. Which deployment property BEST addresses this requirement?

A.Configure the HSM cluster so the CA key is generated in and never leaves the tamper-protected boundary, with cryptographic operations performed inside the module.
B.Split the CA key using Shamir's Secret Sharing and store one share on each HSM, reconstructing the key in memory when signing is required.
C.Enable FIPS 140-3 Level 1 validation on the HSM and replicate the CA key to a standby appliance using a vendor export command.
D.Store the CA private key in an encrypted file on each HSM's local disk, protected by a passphrase entered at boot.
AnswerA

Generating the key inside the HSM and performing all signing operations within its tamper-responsive boundary means the private key is never exported in plaintext, even to a privileged host process. Root access on the appliance exposes the operating system, not the key material inside the module. This non-exportability is the defining property that satisfies the requirement and is standard practice for CA key protection.

Why this answer

Keeping the CA private key generated within and never exportable from the HSM's tamper-protected boundary ensures that even root compromise of the host operating system cannot yield plaintext key material. Signing occurs inside the module, so the key is never exposed to the host. Validation levels and secret-sharing schemes address adjacent concerns but do not prevent plaintext exposure to a privileged local attacker.

Exam trap

The trap here is treating a FIPS validation level or a secret-sharing scheme as equivalent to non-exportability, when neither prevents a root-level attacker from capturing the key in host memory.

250
MCQmedium

A financial services firm has deployed a next-generation firewall at its internet perimeter, host-based firewalls on every workstation, and VLAN segmentation between departments. During a purple-team exercise, analysts discover that a contractor's laptop, once connected to the internal network, can reach the HR payroll server directly over SMB. The security team wants to enforce the principle of least privilege on this internal traffic. Which control should they implement to best achieve this?

A.Deploy an intrusion prevention system (IPS) on the internal network to block SMB exploits.
B.Implement internal microsegmentation with host-based firewall rules that allow only authorized HR subnets to reach the payroll server on TCP 445.
C.Enable port security on the access switch to limit the number of MAC addresses per port.
D.Configure the perimeter firewall to block all inbound SMB traffic from the internet.
AnswerB

Microsegmentation enforces least privilege by defining granular allow rules between workloads. Restricting SMB access to only the HR subnet prevents the contractor's laptop, which resides elsewhere, from reaching the payroll server, even though it is on the internal network. This directly addresses the lateral movement path discovered in the exercise and aligns with defense in depth at the host and network layers.

Why this answer

The contractor's laptop is an internal host, so perimeter and network-based detective controls do not stop it from reaching the payroll server. Microsegmentation with host-based firewall rules enforces least privilege by permitting only the HR subnet to use SMB against that server. This limits lateral movement and adds a granular layer of defense that complements existing perimeter and segmentation controls.

Exam trap

The trap here is assuming that perimeter firewalls and VLANs alone enforce least privilege internally, when in fact east-west traffic between VLANs or within a flat segment can still allow unauthorized access.

251
MCQmedium

A security engineer is hardening a Kubernetes cluster that runs multi-tenant workloads. Several pods have been observed running as the root user inside their containers, which the engineer wants to prevent. The engineer applies a Pod Security Admission (PSA) label to the namespace that enforces the 'restricted' profile. Which of the following best describes the enforcement action taken by the 'restricted' profile when a pod violates its policy?

A.The pod is rejected and the API server returns an error, preventing it from being scheduled.
B.The pod is admitted but an audit annotation is added to the pod's metadata for later review.
C.The pod is scheduled but the kubelet forcibly changes the container's user to a non-root UID at runtime.
D.The pod is admitted and a warning is written to the API server logs, but no enforcement action is taken.
AnswerA

The restricted profile is the most stringent of the Pod Security Standards and directly rejects pods that violate its controls, such as running as root or lacking a seccomp profile. Rejection occurs at admission time, so the non-compliant pod never reaches a node, which directly addresses the engineer's goal of preventing root-running pods.

Why this answer

The restricted Pod Security Standard is the most restrictive of the three built-in profiles and enforces controls such as requiring non-root execution, dropping all capabilities, and mandating a seccomp profile. When a namespace enforces this profile, non-compliant pods are denied at admission, directly preventing root-running containers from being scheduled.

Exam trap

The trap here is confusing the audit and warn modes with enforce mode, assuming that a violation only produces a log entry rather than a rejection.

252
MCQhard

A security administrator is reviewing the password policy for a high-security environment. The policy requires the use of a hardware token that generates a one-time password (OTP) based on a secret key and the current time. The administrator notices that some tokens are failing authentication because the server and tokens are not time-synchronized. Which of the following should the administrator implement to ensure the OTPs are validated correctly?

A.Enable NTP synchronization on the authentication server only.
B.Switch from time-based to event-based OTP tokens.
C.Increase the OTP length to 8 digits.
D.Configure a time drift window on the authentication server.
AnswerD

Time-based one-time password (TOTP) algorithms rely on synchronized clocks. If the token's clock drifts, the generated OTP will not match the server's expected value. Configuring a time drift window allows the server to accept OTPs from a few time steps before or after the current time, compensating for minor clock differences. This directly resolves the synchronization failures.

Why this answer

Time-based OTP tokens require the server and token to have closely synchronized clocks. When tokens drift, the server can accept OTPs from adjacent time steps by configuring a time drift window. This is a standard feature in TOTP implementations and directly addresses the authentication failures without replacing hardware or altering token generation.

Exam trap

The trap here is assuming that server-side NTP synchronization alone will fix token drift, when the tokens themselves cannot be synchronized and require a tolerance window.

253
MCQeasy

A security team wants to implement application whitelisting on a set of Windows 10 workstations to prevent users from running unauthorized executables. They need a solution that integrates with Group Policy and allows rules based on file path, hash, or publisher. Which built-in Windows feature should they use?

A.Software Restriction Policies (SRP)
B.Windows Defender Application Control (WDAC)
C.AppLocker
D.Windows Defender Firewall
AnswerC

AppLocker is a built-in Windows feature that allows administrators to create rules based on file path, hash, or publisher to control which applications and scripts users can run. It integrates with Group Policy for centralized management. This directly meets the requirement for application whitelisting on Windows 10 workstations. Therefore, AppLocker is the correct choice.

Why this answer

AppLocker is the built-in Windows feature designed for application whitelisting, with rule types based on path, hash, or publisher, and it integrates with Group Policy. WDAC is more complex and less Group Policy-centric, SRP is deprecated, and Windows Defender Firewall does not control application execution. Therefore, AppLocker is the correct solution.

Exam trap

The trap here is confusing AppLocker with WDAC or SRP; while all can restrict applications, AppLocker is the one that best fits the described requirements and is not deprecated.

254
MCQmedium

Which cloud security concept describes the automation of infrastructure deployment using code templates to ensure a consistent, secure, and repeatable environment?

A.Container Orchestration.
B.Infrastructure as Code.
C.Serverless Computing.
D.Hyper-converged Infrastructure.
AnswerB

Infrastructure as Code (IaC) uses machine-readable definition files to automate the deployment of cloud infrastructure. This ensures that security best practices, such as encryption and access control, are baked into the templates, creating a consistent and repeatable security posture across the entire organization.

Why this answer

Infrastructure as Code (IaC) allows for version-controlled, automated, and audited deployment of cloud resources. By treating infrastructure as software, security teams can scan templates for misconfigurations before deployment. This is vital in cloud environments because manual configuration is prone to human error, which is the leading cause of security breaches in modern cloud and virtualization deployments.

Exam trap

Candidates often confuse IaC with CI/CD or automated patching. They fail to identify the core concept of defining infrastructure as code templates for repeatable, secure, and version-controlled deployments.

255
MCQmedium

A security analyst at a financial firm is reviewing wireless traffic captured near the executive conference room. The capture shows a flood of 802.11 management frames with source addresses set to the company's legitimate AP MAC address, but the frames are not encrypted and are arriving at a high rate. Which type of attack is most likely occurring?

A.A deauthentication flood using spoofed management frames.
B.A rogue access point broadcasting a duplicate SSID to lure clients.
C.A KRACK key reinstallation attack against the WPA2 four-way handshake.
D.A WPA3 Dragonblood downgrade attack forcing the use of WPA2.
AnswerA

The flood of unencrypted 802.11 management frames with a spoofed AP MAC address is characteristic of a deauthentication attack. These frames are sent to disconnect clients from the legitimate AP, often as a precursor to an evil twin or capture of the WPA handshake. The high rate and spoofed source confirm this is not normal traffic.

Why this answer

The flood of unencrypted 802.11 management frames with a spoofed AP MAC address is a classic deauthentication attack. Attackers use this to disconnect clients from the legitimate AP, often to capture the WPA handshake or to force clients to connect to a rogue AP. The high rate and spoofed source distinguish it from other wireless attacks that manipulate encrypted frames or handshake processes.

Exam trap

The trap here is confusing a deauthentication flood with a KRACK attack or a rogue AP, because all can disrupt wireless connectivity, but only the flood uses spoofed management frames at a high rate.

256
MCQmedium

Refer to the exhibit. An investigator is auditing logon events. Which Event ID indicates a successful network logon (Type 3) to the machine?

A.Event ID 4625
B.Event ID 4624 with Logon Type 3
C.Event ID 4624 with Logon Type 2
D.Event ID 4672
AnswerB

Event ID 4624 is the standard success audit for logons. Logon Type 3 is explicitly defined by Microsoft as a network logon, which occurs when a user or computer connects to a shared resource or service on the target machine from a remote source location.

Why this answer

Event ID 4624 records successful logons, and the Logon Type field specifies the method used. A Type 3 logon represents a network connection, often associated with remote file access or service authentication. Identifying these events is essential for detecting lateral movement or unauthorized access via SMB, as attackers frequently use network logons to propagate through a compromised environment using stolen credentials.

Exam trap

Candidates often memorize Event ID 4624 but forget to check the specific Logon Type, confusing interactive console logons with remote network connections.

257
MCQhard

A network security team is deploying a web application firewall (WAF) in front of an e-commerce site. The security architect wants the WAF to learn normal application behavior and block deviations without manually writing signatures for every new attack. Which WAF deployment and configuration approach best matches this requirement?

A.Deploy the WAF in reverse proxy mode with anomaly detection and a learning period that builds a baseline of normal application behavior before enforcement.
B.Deploy the WAF as a host-based agent on each web server with a static rule set based on the OWASP Core Rule Set.
C.Deploy the WAF in monitor-only mode with signature-based rules and alert on known attack patterns.
D.Deploy the WAF in transparent bridge mode with a positive security model that only allows explicitly defined methods, parameters, and content types.
AnswerA

Reverse proxy mode places the WAF inline for HTTP/HTTPS traffic, and anomaly detection with a learning period builds a behavioral baseline of legitimate requests. After the baseline is established, deviations from normal parameters, methods, and request patterns can be blocked without hand-written signatures. This directly matches the architect's requirement to learn normal behavior and block deviations, while reverse proxy mode gives the WAF full visibility and control over application traffic.

Why this answer

Behavioral anomaly detection in a reverse proxy WAF builds a baseline of normal application behavior during a learning period, then flags and blocks requests that deviate from that baseline. This reduces reliance on manually written signatures and matches the architect's goal. Transparent bridge with a positive model still needs explicit definitions, monitor-only mode cannot block, and host-based static rules do not learn, so the reverse proxy anomaly approach is the only one that satisfies all stated requirements.

Exam trap

The trap here is confusing a positive security model, which requires explicit allow rules, with anomaly detection, which learns normal behavior and flags deviations.

258
MCQhard

A penetration tester is examining a Windows 10 system and discovers that a recent exploit leveraged a use-after-free vulnerability in a widely used PDF reader application. The exploit successfully achieved code execution. Which of the following mitigation technologies, when enabled, would have made this exploitation significantly more difficult by randomizing the memory locations of key data structures?

A.Address Space Layout Randomization (ASLR)
B.Control Flow Guard (CFG)
C.Data Execution Prevention (DEP)
D.Structured Exception Handling Overwrite Protection (SEHOP)
AnswerA

ASLR randomizes the base addresses of executable modules, stack, and heap, making it difficult for an attacker to predict where to place or find their payload. For a use-after-free, the attacker often needs to know the address of a freed object or a function pointer to overwrite; ASLR forces them to leak addresses first, increasing complexity and reducing reliability.

Why this answer

ASLR is the mitigation that randomizes memory addresses, making it harder for an attacker to predict where to find or place code and data. In a use-after-free scenario, the attacker often needs to control the contents of a freed object and then trigger its reuse; ASLR forces the attacker to first leak a memory address to bypass randomization, adding a significant hurdle. DEP, CFG, and SEHOP address different exploitation techniques and do not provide the same randomization benefit.

Exam trap

The trap here is confusing exploit mitigations: DEP prevents execution from data pages, CFG validates indirect calls, and SEHOP protects exception handlers, but only ASLR randomizes memory layout to hinder address prediction.

259
MCQeasy

A junior administrator is asked to make a web server reachable from the internet without exposing the internal database server that the web application uses. The web server sits in a screened subnet, and the database resides on the internal network. Which architecture correctly implements this requirement?

A.Place the web server in the screened subnet with inbound HTTP and HTTPS permitted from the internet, and permit only the web server's IP to reach the database on its listening port.
B.Place the web server in the screened subnet and enable a database listener that accepts connections from any source, relying on database authentication to prevent unauthorized access.
C.Place both the web server and the database in the screened subnet, and permit inbound HTTP and HTTPS from the internet to the web server.
D.Place the web server on the internal network and publish it through a reverse proxy that forwards requests directly to the database server.
AnswerA

This is the classic screened-subnet design: internet clients reach only the web tier, and the database accepts connections solely from the web server's address on its specific port. If the web server is compromised, the attacker gains no direct path to arbitrary internal hosts, and the database is not exposed to the internet. It satisfies both reachability and isolation.

Why this answer

A screened subnet isolates internet-facing services from internal data stores, and restricting database access to the web server's address enforces that boundary at the network layer. Internet clients reach only the web tier, so compromising it does not grant direct access to the database or the broader internal network. Co-locating the database in the screened subnet or opening its listener to any source undermines the isolation the design requires.

Exam trap

The trap here is assuming that database authentication alone is sufficient protection, when network placement and source restriction are what actually limit exposure.

260
MCQmedium

An organization is migrating to a hybrid cloud environment. Which security control is most effective for preventing unauthorized lateral movement between virtual machines residing on the same physical hypervisor?

A.Deploying a Network Intrusion Detection System (NIDS) at the virtual switch level.
B.Implementing a traditional hardware-based firewall at the edge of the datacenter.
C.Utilizing micro-segmentation policies via distributed firewalls.
D.Enforcing full disk encryption on all virtual hard drives.
AnswerC

Distributed firewalls operate at the virtual NIC level, enabling granular security policies that follow the VM regardless of host migration. This effectively isolates workloads from each other, preventing lateral movement even if the attacker has gained local access, which is fundamental to zero-trust cloud security models.

Why this answer

Micro-segmentation is critical in virtualized environments because traditional network perimeter defenses cannot see traffic moving between VMs on the same host. By applying host-based or hypervisor-level firewalls, security teams restrict traffic based on identity and function rather than IP address. This mitigates the risk of a compromised workload pivoting to sensitive internal assets within the shared virtual infrastructure, which is a key security requirement for modern cloud architectures.

Exam trap

Candidates often suggest traditional perimeter firewalls or VLANs. They fail to realize that traffic between VMs on the same host often bypasses physical network hardware, necessitating host-level micro-segmentation.

261
MCQmedium

Which concept describes the use of security controls that operate at the perimeter, network, host, application, and data layers to protect an organization?

A.Zero Trust Architecture
B.Defense in Depth
C.Security Information and Event Management (SIEM)
D.Privileged Access Management (PAM)
AnswerB

Defense in depth is the systematic application of security controls across multiple layers, including perimeter, network, host, application, and data. This layered approach ensures that if a control at one layer fails or is bypassed, subsequent layers are in place to stop the attacker or limit damage.

Why this answer

This approach is the definition of defense in depth, which utilizes multiple layers of security across the entire IT stack. By distributing controls across these distinct layers, an organization ensures that there are multiple obstacles between an attacker and the sensitive data. This holistic coverage is essential because attackers often use multi-stage campaigns, and having defenses at every level allows for detection and interception at different phases of the attack lifecycle.

Exam trap

Candidates often select zero trust or perimeter security, confusing modern holistic architectural frameworks with the fundamental multi-layered control concept described in the scenario.

262
MCQmedium

You are hardening a Windows environment and must restrict the use of PowerShell to only digitally signed scripts. Which command should you execute?

A.Set-ExecutionPolicy RemoteSigned
B.Set-ExecutionPolicy AllSigned
C.Set-ExecutionPolicy Unrestricted
D.Set-ExecutionPolicy Bypass
AnswerB

The AllSigned policy mandates that all scripts, including local ones, must be digitally signed by a trusted publisher. This is the recommended security posture for preventing unauthorized script execution and ensuring integrity, making it a critical hardening step for any secure environment.

Why this answer

Setting the execution policy to 'AllSigned' forces the system to verify that every script has been signed by a trusted publisher. This is a fundamental security control that prevents the execution of unauthorized or tampered scripts. Implementing this policy significantly reduces the attack surface for fileless malware that relies on unconstrained execution of PowerShell commands and scripts.

Exam trap

Candidates often confuse 'AllSigned' with 'RemoteSigned'. 'AllSigned' requires every script to be signed, whereas 'RemoteSigned' only requires signatures for scripts downloaded from the internet, making it less restrictive.

263
MCQmedium

A penetration tester is reviewing the TLS configuration of an e-commerce web server. The tester observes that the server prefers the cipher suite TLS_RSA_WITH_AES_128_CBC_SHA during the handshake. Which security weakness does this cipher suite selection introduce?

A.It lacks forward secrecy because the RSA key exchange does not generate ephemeral session keys.
B.It uses AES in CBC mode, which is vulnerable to padding oracle attacks such as POODLE.
C.It uses SHA-1 for integrity, which is considered cryptographically broken for MACs.
D.It allows downgrade to export-grade cryptography because of the RSA key exchange.
AnswerA

TLS_RSA_WITH_AES_128_CBC_SHA uses static RSA key exchange, meaning the premaster secret is encrypted with the server's long-term RSA key. If an attacker records the encrypted session and later obtains the server's private key, they can decrypt all past sessions. This violates forward secrecy, a critical property for protecting historical traffic. Modern best practice mandates ECDHE or DHE cipher suites to ensure each session has unique ephemeral keys.

Why this answer

The cipher suite TLS_RSA_WITH_AES_128_CBC_SHA relies on static RSA key exchange, where the client encrypts a premaster secret with the server's public key. This means the session key is tied to the server's long-term private key. If that private key is compromised later, an attacker who recorded the encrypted session can decrypt it retroactively.

Forward secrecy requires ephemeral key exchanges like ECDHE or DHE, which generate unique session keys that are not recoverable from the long-term key.

Exam trap

The trap here is assuming that any cipher suite with AES and SHA-1 is automatically weak due to the hash algorithm, when the critical flaw is actually the static RSA key exchange lacking forward secrecy.

264
MCQeasy

A security analyst is reviewing logs from a Linux web server that has been compromised. The analyst notices a large number of requests to a specific URL that include encoded characters such as %27, %20, and %3D. The web server logs show these requests in the access log with a 200 OK response. Which type of attack is most likely indicated by these log entries?

A.Cross-site scripting (XSS)
B.Directory traversal
C.Command injection
D.SQL injection
AnswerD

SQL injection attempts often use encoded characters like %27 (single quote) to break out of SQL queries, %20 (space) to separate keywords, and %3D (equals) for comparisons. The fact that the server returned 200 OK suggests the requests were successful, possibly indicating a vulnerable application. These encoded characters are classic indicators of SQL injection probing, especially when repeated in URL parameters.

Why this answer

The encoded characters %27 (single quote), %20 (space), and %3D (equals) are commonly used in SQL injection attempts to manipulate SQL queries. The single quote is used to terminate strings, spaces separate SQL keywords, and equals signs are used in comparisons. The successful 200 OK responses suggest the application may be vulnerable.

Other attack types would exhibit different patterns in the logs.

Exam trap

The trap here is assuming that any encoded characters in URLs indicate XSS or directory traversal, when the specific set of characters points to SQL injection.

265
MCQhard

A security analyst is reviewing a web application's HTTP response headers and notices the following header: Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline'. The analyst is concerned about the application's resilience to cross-site scripting (XSS). Which of the following best describes the security implication of this policy?

A.The policy is insecure because it allows inline scripts, which can be exploited by XSS attacks.
B.The policy is insecure because it lacks a report-uri directive, so violations cannot be monitored.
C.The policy is secure because default-src 'self' prevents loading scripts from external domains, mitigating XSS.
D.The policy is secure because it restricts scripts to the same origin and disallows inline scripts.
AnswerA

The presence of 'unsafe-inline' in the script-src directive allows the execution of inline JavaScript. This means that if an attacker can inject a <script> tag with malicious code, it will execute because the CSP does not block inline scripts. This significantly reduces the XSS mitigation that CSP would otherwise provide. Thus, the policy is insecure in this context.

Why this answer

The Content-Security-Policy header includes 'unsafe-inline' in the script-src directive, which permits inline JavaScript execution. This directly undermines CSP's ability to prevent XSS attacks, as injected inline scripts will run. The correct answer identifies that allowing inline scripts makes the policy insecure.

The other options incorrectly focus on external script restrictions or reporting, missing the critical weakness.

Exam trap

The trap here is overlooking the 'unsafe-inline' directive and assuming that 'self' alone provides strong XSS protection.

266
MCQhard

A healthcare provider is designing a defense in depth strategy for its electronic health record (EHR) system. The security architect proposes using a different vendor's endpoint detection and response (EDR) product, a different firewall brand, and a different SIEM platform than those used by the rest of the organization. The CIO asks why heterogeneous controls are preferred over standardizing on a single vendor. Which statement best justifies the architect's recommendation?

A.Heterogeneous controls reduce licensing costs because multiple vendors compete for the same functionality.
B.Using different vendors ensures that a single exploit or misconfiguration cannot simultaneously compromise all layers of defense.
C.Different vendors provide more comprehensive log formats that are easier to correlate in the SIEM.
D.Heterogeneous controls are required by HIPAA for any system that stores electronic protected health information.
AnswerB

Heterogeneous controls mean that a vulnerability, bug, or misconfiguration in one product is unlikely to affect another from a different vendor. If an attacker discovers a bypass in one firewall brand, the EDR or SIEM from another vendor may still detect or block the activity. This diversity creates independent failure domains, which is a core principle of defense in depth and directly supports the architect's recommendation.

Why this answer

Heterogeneous security controls create independent failure domains. If one vendor's product has a vulnerability or is misconfigured, the others are unlikely to share the same flaw, so a single exploit cannot disable all layers. This diversity strengthens defense in depth by preventing common-mode failures, which is the architect's core justification for mixing vendors in the EHR environment.

Exam trap

The trap here is confusing vendor diversity with cost savings or regulatory mandates, when the real security benefit is reducing the risk of a single flaw compromising multiple defensive layers.

267
MCQmedium

A security analyst is reviewing a packet capture of traffic between a user workstation and a public web server. The analyst observes the workstation completing a three-way handshake on TCP port 443, then negotiating encryption parameters, and finally requesting a specific resource path. The analyst wants to confirm that the client verified the identity of the server before any application data was sent. Which protocol mechanism in this exchange provides that server identity verification?

A.The server's TCP initial sequence number, which is randomized to prevent session hijacking.
B.The HTTP Host header, which tells the server which virtual host the client intends to reach.
C.The TCP SYN, SYN-ACK, ACK sequence confirms the server's identity before data transfer.
D.The TLS handshake, where the server presents a certificate and the client validates it against trusted certificate authorities.
AnswerD

During the TLS handshake the server transmits its X.509 certificate, and the client verifies the signature chain up to a trusted root, checks the subject name against the requested host, and confirms validity dates. Only after this validation does the client derive session keys and send the HTTP request. This is precisely the mechanism that authenticates the server's identity before application data flows on port 443.

Why this answer

Server identity in HTTPS is established during the TLS handshake, where the server proves possession of a private key matching a certificate that the client validates against trusted roots and the requested hostname. The TCP handshake merely creates the connection, and application headers such as Host are client-supplied and unauthenticated. Confirming the certificate chain is what binds the session to a verified server identity.

Exam trap

The trap here is assuming the TCP three-way handshake or an application header authenticates the server, when only the TLS certificate validation does.

268
MCQeasy

A retail company is adopting the CIS Critical Security Controls and wants to prioritize its efforts. According to the CIS Controls, which of the following is the first basic control that should be implemented to gain visibility into assets?

A.Email and Web Browser Protections
B.Inventory and Control of Enterprise Assets
C.Continuous Vulnerability Management
D.Controlled Use of Administrative Privileges
AnswerB

CIS Control 1 is Inventory and Control of Enterprise Assets. It is the foundational control that requires maintaining an accurate, detailed inventory of all hardware and software. Without knowing what assets exist, other controls cannot be effectively applied. This is the first step in the CIS Controls.

Why this answer

Inventory and Control of Enterprise Assets is the first CIS Control because it establishes the foundation for all other controls. You cannot protect what you do not know exists. An accurate asset inventory enables effective vulnerability management, privilege control, and incident response.

The CIS Controls are prioritized, with Control 1 as the starting point for any organization.

Exam trap

The trap here is selecting a more technically appealing control like vulnerability management, overlooking that asset inventory is the prerequisite for all other controls.

269
MCQhard

A security engineer is implementing file integrity monitoring on a Linux server. The engineer wants to use AIDE to detect unauthorized changes to critical system files. After initializing the AIDE database, which command should be used to perform a manual check and compare the current file system state against the baseline?

A.aide --update
B.aide --compare
C.aide --init
D.aide --check
AnswerD

The aide --check command compares the current file system state against the previously initialized AIDE database. It reports any changes, such as file additions, deletions, or modifications, based on the rules defined in the AIDE configuration. This is the correct command to perform a manual integrity check. It is typically run after the initial database is created and can be scheduled via cron for regular monitoring.

Why this answer

AIDE (Advanced Intrusion Detection Environment) is a file integrity checker. After initializing the baseline database with aide --init, the administrator uses aide --check to compare the current file system against that baseline. The check reports any discrepancies, which can indicate unauthorized changes.

The --update option is used to accept changes and update the database, while --init creates a new baseline. There is no --compare option. Therefore, aide --check is the correct command for a manual integrity verification.

Exam trap

The trap here is confusing --update with --check; --update modifies the baseline, while --check only reports differences without changing the database.

270
Multi-Selecthard

A security team is designing a resilient perimeter architecture to protect internal services from distributed denial of service attacks and web application exploits. Which THREE architectural components must be incorporated into this design? (Choose THREE)

Select 3 answers
A.A dedicated web application firewall to inspect HTTP and HTTPS traffic for application-layer vulnerabilities and injection attacks.
B.Unmanaged Layer-1 hubs placed directly outside the perimeter firewall to mirror raw traffic into analysis buffers.
C.Upstream cloud or on-premise DDoS mitigation scrubbing centers to filter volumetric network layer flooding attacks.
D.Dual redundant boundary firewalls configured in high-availability clusters to prevent single points of failure.
E.Disabling all stateful inspection engines on perimeter firewalls to maximize throughput for inbound HTTPS sessions.
AnswersA, C, D

A web application firewall terminates and inspects HTTP and HTTPS at layer 7, blocking injection and other application-layer exploits that volumetric scrubbing cannot detect, satisfying the requirement to defend internal services against web application attacks.

Why this answer

A robust perimeter defense requires multiple layers of inspection and mitigation. Web application firewalls inspect application-layer HTTP and HTTPS traffic to block injection attacks, hardware DDoS mitigation scrubbing centers absorb volumetric network floods upstream, and redundant boundary firewalls enforce stateful perimeter access control policies while eliminating single points of failure.

Exam trap

Candidates often include 'IDS/IPS' or 'VPN' as primary components, failing to prioritize the specific combination of WAF, DDoS scrubbing, and redundant firewalls for perimeter resilience.

271
Multi-Selecthard

A security consultant is configuring a Tenable Nessus scan to assess a mixed environment of Windows and Linux servers. The consultant needs to ensure the scan can authenticate to targets and perform local checks without relying on agent installation. Which two Nessus scan settings should the consultant configure to provide credentials for authenticated scanning? (Choose two.)

Select 2 answers
A.Kerberos ticket for domain authentication
B.SSH credentials for Linux hosts
C.Database credentials for SQL Server instances
D.SNMP community strings for network devices
E.SMB credentials for Windows hosts
AnswersB, E

Nessus uses SSH credentials to log into Linux and Unix hosts and run local commands for patch level, configuration, and vulnerability checks. Without valid SSH credentials, the scan falls back to unauthenticated checks, which are less accurate. Configuring SSH credentials is essential for authenticated scanning of Linux systems in a mixed environment.

Why this answer

Authenticated scanning in Nessus for a mixed environment requires SSH credentials for Linux hosts and SMB credentials for Windows hosts. These allow the scanner to log in and perform local checks, increasing accuracy. Other credential types are for network devices or databases and do not fulfill the requirement.

Exam trap

The trap here is assuming that any credential type enables authenticated scanning, when Nessus uses specific protocols like SSH and SMB for host-based checks on Linux and Windows respectively.

272
MCQmedium

A Linux web server was compromised through a vulnerable PHP application. The attacker uploaded a web shell and is now using it to run commands. An incident responder needs to determine how the attacker is maintaining access after reboots. Which artifact should the responder check first to identify a persistent mechanism on this Linux host?

A.The crontab entries for all users and the /etc/cron.* directories.
B.The /etc/passwd file for accounts with UID 0.
C.The Apache access log for POST requests to the vulnerable PHP script.
D.The /var/log/auth.log file for failed SSH login attempts.
AnswerA

Scheduled tasks are one of the most common Linux persistence mechanisms, and checking every user's crontab plus the system cron directories reveals jobs that re-establish access or re-download payloads at regular intervals. Because cron survives reboots, it directly answers how the attacker maintains access. Root crontabs and files under /etc/cron.d, /etc/cron.hourly, and related directories are the highest-value locations to inspect first.

Why this answer

On Linux, cron jobs are a primary persistence mechanism because they run on a schedule and survive reboots. An attacker with web shell access often adds a crontab entry or a file in /etc/cron.d that re-downloads a payload or opens a reverse shell. Checking all user crontabs and the system cron directories is therefore the most direct first step to identify how access is maintained, ahead of logs that only show activity rather than configuration.

Exam trap

The trap here is focusing on logs that prove the intrusion occurred instead of configuration artifacts that explain how access persists after a restart.

273
MCQmedium

A responder is preparing to image a compromised Windows server's memory before shutting it down. The server hosts a critical database and management insists on minimal downtime. Which action best preserves the most volatile evidence while respecting the operational constraint?

A.Disconnect the server from the network, then capture memory after confirming no active sessions remain.
B.Capture a full physical memory dump using a trusted tool, then proceed with containment and shutdown.
C.Shut down the server immediately to prevent lateral movement, then image the disk on a write blocker.
D.Run a full antivirus scan and collect the resulting log before capturing memory.
AnswerB

Physical memory is the most volatile evidence and contains running processes, network connections, and injected code that vanish on shutdown. Capturing it first with a trusted, forensically sound tool satisfies the order of volatility while allowing containment afterward. This balances evidentiary integrity with the operational need to limit downtime, making it the best action in this scenario.

Why this answer

The order of volatility dictates that the most perishable evidence, such as RAM contents, be collected first. A physical memory dump captures running processes, network connections, and in-memory-only malware before containment actions alter or destroy them. Once memory is secured, the responder can contain and shut down the server, satisfying both forensic integrity and the operational requirement to minimize downtime.

Exam trap

The trap here is assuming that shutting down quickly is always the safest containment step, when it actually destroys the most volatile and often most valuable evidence.

274
Multi-Selectmedium

A retail company is deploying a large language model (LLM) based customer support assistant that has access to internal order databases through a tool-calling interface. The security team wants to reduce the risk of sensitive data being exposed through the model's responses. Which two controls best address this risk? (Choose two.)

Select 2 answers
A.Enforce least-privilege access on the tool-calling interface so the model can retrieve only the fields needed for the current request.
B.Increase the model's temperature setting to make responses less predictable.
C.Store the model weights in a versioned object storage bucket with access logging enabled.
D.Fine-tune the model on a dataset of historical customer interactions.
E.Apply output filtering that detects and redacts sensitive data patterns before responses reach the user.
AnswersA, E

Restricting the tools and database fields the model can access limits what sensitive data can enter the prompt or response. If the assistant can only query order status and not full customer records, exposure is minimized even if the model is manipulated. This directly reduces the risk of sensitive data leakage through responses.

Why this answer

Reducing sensitive data exposure in an LLM assistant requires controlling both what data the model can access and what it can emit. Least-privilege tool access limits the sensitive fields available to the model, while output filtering catches and redacts sensitive patterns before the user sees them. Together they provide defense in depth; the other options affect randomness, model artifact storage, or training, none of which govern runtime data flow.

Exam trap

The trap here is assuming that model-level changes such as temperature adjustment or fine-tuning improve data protection, when only access restriction and output filtering control what sensitive data actually reaches the user.

275
MCQmedium

A retail company runs a stateful firewall at its internet edge. Users complain that long-lived SSH sessions to a partner are being dropped roughly every hour even though no idle timeout is configured on the client. Which firewall behavior is the MOST likely cause?

A.The firewall is applying egress filtering that blocks the partner's return traffic after the first hour.
B.The firewall's TCP session table entry is expiring because the connection has been idle longer than the configured state timeout.
C.The firewall is performing full packet reassembly and rejecting out-of-order TCP segments from the partner.
D.The firewall's ALG for SSH is rewriting the sequence numbers and desynchronizing the endpoints.
AnswerB

Stateful firewalls age out entries in the session table based on idle timers, and the default TCP idle timeout is often around an hour for established connections. If the SSH session carries no keepalive traffic during that window, the entry is purged and subsequent packets are treated as a new, unauthorized flow and dropped, matching the observed hourly disconnects.

Why this answer

Stateful inspection maintains a session table whose entries expire according to protocol idle timers. An SSH connection that sends no data for the duration of the TCP established timeout is silently removed, after which the firewall no longer recognizes return packets as part of an existing flow and drops them.

Exam trap

The trap here is focusing on client-side keepalive settings while overlooking that the firewall's own idle timeout governs how long the session entry survives.

276
Multi-Selecthard

A financial institution is implementing a new access control system for its trading floor. The security team must enforce a model that supports dynamic, fine-grained access decisions based on user attributes, resource attributes, and environmental conditions such as time of day. The system must also allow for centralized policy management and auditing. Which TWO of the following access control models best fit these requirements? (Choose two.)

Select 2 answers
A.Role-Based Access Control (RBAC)
B.Mandatory Access Control (MAC)
C.Discretionary Access Control (DAC)
D.Policy-Based Access Control (PBAC)
E.Attribute-Based Access Control (ABAC)
AnswersD, E

PBAC uses policies that can incorporate a wide range of attributes and conditions, including environmental factors. It centralizes policy management and enables dynamic, fine-grained access decisions. Often considered an evolution of ABAC, PBAC explicitly emphasizes policy-driven evaluation. It fits the requirement for centralized policy management and auditing, and supports context-aware decisions such as time-of-day restrictions.

Why this answer

Attribute-Based Access Control and Policy-Based Access Control both support dynamic, fine-grained access decisions using attributes and environmental conditions. They allow centralized policy management and auditing, which are critical for the financial institution. RBAC, MAC, and DAC lack the necessary flexibility and context-awareness.

Therefore, ABAC and PBAC are the correct choices.

Exam trap

The trap here is conflating RBAC with ABAC, assuming that role assignments alone can incorporate environmental conditions like time of day, which they cannot without additional attribute-based logic.

277
MCQmedium

An organization is implementing TLS 1.3 for a new customer portal. During the cipher suite negotiation phase, the security engineer needs to ensure that perfect forward secrecy is maintained for all incoming sessions. Which underlying key exchange mechanism should be prioritized in the configuration?

A.RSA key transport mechanism
B.Elliptic Curve Diffie-Hellman Ephemeral
C.Pre-Shared Key authentication mode
D.Static Diffie-Hellman key agreement
AnswerB

ECDHE leverages transient elliptic curve parameters for each unique handshake transaction. Because the server private key is only used to digitally sign the ephemeral exchange and is never used to derive the session key directly, past sessions remain entirely secure against future key compromises.

Why this answer

Perfect forward secrecy ensures that session keys are not compromised even if the primary private key of the server is compromised in the future. Ephemeral Diffie-Hellman guarantees this by generating unique per-session parameters that are never stored persistently on disk. Proper enforcement prevents long-term bulk decryption of historical intercepted traffic.

Exam trap

Candidates frequently select standard Diffie-Hellman or RSA instead of looking for the ephemeral variant, overlooking the specific requirement that session keys must not be tied to static private keys.

278
MCQeasy

A junior administrator is asked to verify the integrity of a downloaded Linux distribution ISO before installing it on a production server. The vendor publishes a SHA-256 checksum and a detached PGP signature. Which action BEST confirms both that the file is intact and that it genuinely originated from the vendor?

A.Import the vendor's public key, verify the detached signature against the ISO, and confirm the signature is valid.
B.Run the ISO through an antivirus scanner and confirm no malware is detected.
C.Compute the SHA-256 hash of the ISO and compare it to the published checksum only.
D.Encrypt the ISO with the vendor's public key and confirm the operation succeeds.
AnswerA

Verifying the detached PGP signature with the vendor's public key confirms both integrity and origin: a valid signature proves the file was signed by the holder of the corresponding private key and that the content has not changed since signing. This single verification satisfies both requirements. The administrator must first obtain and trust the vendor's public key through an out-of-band channel to avoid a substituted key.

Why this answer

A valid detached PGP signature verified with the vendor's trusted public key simultaneously proves that the file content is unchanged and that it was signed by the vendor's private key. The hash comparison alone provides integrity but not origin, and encryption or antivirus scanning addresses entirely different concerns. The public key must be obtained and validated through a trusted channel.

Exam trap

The trap here is believing that matching a published checksum proves the file came from the vendor, when the checksum itself could have been altered alongside the file.

279
MCQmedium

A security engineer is deploying a network-based intrusion detection system (NIDS) to monitor traffic entering and leaving a data center. The engineer needs to ensure the sensor can see all packets, including those that are fragmented or have errors, without affecting the production traffic flow. Which deployment method should be used?

A.Configure the NIDS to receive a copy of traffic via NetFlow exports from the core routers.
B.Place the NIDS inline between the core switch and the data center router using a fail-open bypass tap.
C.Install the NIDS on a virtual machine and connect it to a virtual switch in promiscuous mode on the same host as the web servers.
D.Connect the NIDS to a switched port analyzer (SPAN) port that mirrors all traffic from the core switch.
AnswerD

A SPAN port mirrors copies of production traffic to the sensor, so the NIDS receives all packets without being inline. This preserves production flow because the sensor is passive and cannot drop or delay traffic. It also captures fragmented and error packets that the switch forwards to the mirror port, assuming the switch is configured to mirror all relevant VLANs and directions.

Why this answer

A passive NIDS deployment using a SPAN port mirrors copies of production traffic to the sensor, allowing full packet inspection without adding latency or risk to the live traffic path. Inline placement can affect production flow, virtual switch promiscuous mode only sees local host traffic, and NetFlow provides summaries rather than full packets. The SPAN port best satisfies the need to see all packets, including fragmented and error frames.

Exam trap

The trap here is equating flow data or inline prevention with full packet capture, when a passive SPAN port is the standard way to feed a NIDS without impacting production traffic.

280
MCQhard

After a major security breach, the incident response team conducts a lessons-learned meeting. The team identifies that the initial detection was delayed because log sources were not properly integrated into the SIEM. Which phase of the incident response lifecycle does this finding primarily aim to improve?

A.Preparation
B.Detection and Analysis
C.Containment, Eradication, and Recovery
D.Post-Incident Activity
AnswerA

The lessons-learned meeting is part of the post-incident activity phase, but the specific finding about log integration directly addresses preparation. Improving log sources and SIEM integration enhances future readiness and detection capabilities. Preparation encompasses building and maintaining the tools and processes needed to respond effectively, so this finding aims to strengthen that phase.

Why this answer

The finding that log sources were not integrated into the SIEM points to a gap in preparation. Preparation involves setting up logging, monitoring, and detection tools. By addressing this, the team enhances future detection capabilities.

While the review occurs in Post-Incident Activity, the corrective action targets Preparation.

Exam trap

The trap here is assuming the phase where the review occurs is the phase being improved, rather than the phase the finding addresses.

281
MCQhard

A security team is configuring an authenticated vulnerability scan of a Linux server farm using SSH. The scanner reports that it cannot log in to several hosts even though the same credentials work manually. Which configuration change is MOST likely to resolve the issue?

A.Allow the scanner's public key in the authorized_keys file for the scan account
B.Enable password authentication on the target hosts
C.Change the SSH port on the targets to 2222
D.Disable SELinux on the target hosts
AnswerA

Authenticated SSH scans typically use a key pair generated by the scanner. If the scanner's public key is not present in the target account's authorized_keys file, the scanner cannot authenticate even when manual password logins succeed. Adding the scanner's public key to the authorized_keys file for the scan account directly resolves this failure.

Why this answer

Authenticated SSH scans rely on the scanner presenting a key that the target accepts. When manual logins work but the scanner fails, the usual cause is that the scanner's public key has not been installed in the scan account's authorized_keys file. Adding that key restores authentication without weakening the host's security posture, unlike enabling password authentication or disabling SELinux.

Exam trap

The trap here is assuming that because manual SSH with a password works, the scanner must also use passwords, when in fact the scanner may be configured for key-based authentication that has not been provisioned.

282
MCQmedium

A security analyst is investigating a compromised Windows Server 2016 that is running an IIS web application. The analyst suspects that the attacker has created a malicious service to maintain persistence. Which of the following Windows Registry locations should the analyst examine to find the service's configuration?

A.HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
B.HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost
C.HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
D.HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
AnswerA

Windows services are configured under HKLM\SYSTEM\CurrentControlSet\Services. Each subkey corresponds to a service and contains values such as ImagePath, Start, and ObjectName. A malicious service would create a subkey here. This is the correct location to examine for service persistence.

Why this answer

Windows services are configured in the registry under HKLM\SYSTEM\CurrentControlSet\Services. Each service has a subkey with values like ImagePath and Start. A malicious service would create a subkey here to ensure it starts automatically.

The other locations are used for different persistence mechanisms, such as user logon scripts or are non-existent.

Exam trap

The trap here is confusing the Run keys, which are for user logon persistence, with the Services key, which is specifically for Windows service configuration.

283
MCQmedium

A security analyst needs to ensure that sensitive data in transit between two internal servers remains confidential and authenticated. Which protocol provides the most robust security for this requirement?

A.Telnet
B.IPsec
C.HTTP
D.SNMPv1
AnswerB

IPsec offers a suite of protocols that provide encryption, integrity, and authentication at the network layer. By securing packets between two hosts, it ensures that even if internal traffic is intercepted, the payload remains unreadable and protected from tampering, which is necessary for sensitive data transmission.

Why this answer

IPsec provides end-to-end security at the network layer, ensuring that all data between the two endpoints is encrypted and authenticated regardless of the underlying application. This is essential for protecting sensitive traffic within a private network from sniffing or spoofing. Implementing IPsec allows for granular control over traffic security policies, making it a standard requirement for high-security environments where network-level protection is prioritized over application-specific encryption.

Exam trap

Candidates often choose application-layer protocols like HTTPS or SSH, overlooking that IPsec provides transparent, robust security directly at the network layer for all traffic.

284
MCQmedium

A software development company wants to protect its source code repositories from insider threats and external attackers. The company already uses network segmentation and endpoint detection. The security team proposes adding a control that requires two distinct factors before developers can access repositories, even from within the corporate network. Which control best meets this requirement?

A.Deploying a bastion host that developers must use to reach repositories
B.Enforcing role-based access control (RBAC) on repositories
C.Implementing multi-factor authentication (MFA) for repository access
D.Configuring IP allowlisting for repository access
AnswerC

MFA requires two or more distinct authentication factors, such as a password plus a hardware token, before granting access. This directly meets the requirement of requiring two distinct factors even from inside the network. It adds an identity-layer control that strengthens defense in depth against credential theft and insider misuse.

Why this answer

The requirement is to require two distinct authentication factors before granting repository access, even from inside the corporate network. Multi-factor authentication is the only option that provides this by combining something the user knows with something they have or are. Bastion hosts, RBAC, and IP allowlisting are valuable defense-in-depth controls but do not enforce two-factor authentication on their own.

Exam trap

The trap here is confusing access control mechanisms like RBAC or bastion hosts with authentication factors; only MFA enforces two distinct factors.

285
Multi-Selecthard

To ensure a Linux server is protected against unauthorized physical access or boot-level modifications, which THREE security controls should be implemented?

Select 3 answers
A.Setting a BIOS/UEFI password
B.Configuring a GRUB bootloader password
C.Enabling the sticky bit on /tmp
D.Disabling the IPv6 network stack
E.Implementing Full Disk Encryption (FDE)
AnswersA, B, E

A BIOS or UEFI password prevents unauthorized users from changing the boot order or modifying hardware-level settings. This is the first line of defense against an attacker trying to boot the system from an external USB drive or optical media to gain access to the underlying data on the disks.

Why this answer

Boot security is often overlooked but is a critical component of overall system hardening. If an attacker has physical access and the boot process is not secured, they can easily bypass operating system security controls by booting into single-user mode or using a live environment to mount and modify the local filesystem.

Exam trap

Candidates often select 'Antivirus' or 'Firewall' as security controls for physical boot-level threats, missing the point that these software-based solutions cannot prevent an attacker from booting into a different OS.

286
MCQeasy

During a routine vulnerability assessment, an analyst discovers that a network router is responding to ICMP Timestamp requests. What is the primary security risk associated with enabling this service on perimeter networking equipment?

A.Enabling remote attackers to execute arbitrary shell commands via buffer overflows in the ICMP daemon.
B.Allowing unauthorized entities to gather precise system uptime and clock synchronization data.
C.Exposing internal private IP address ranges through embedded DNS zone transfer responses.
D.Facilitating high-bandwidth distributed denial-of-service reflection attacks using small spoofed packets.
AnswerB

ICMP Timestamp replies expose a device's current clock and uptime, letting an attacker fingerprint the OS, infer patch cycles, and correlate hosts across the estate. On perimeter routers this reconnaissance data aids targeted exploitation, which is the specific risk the question asks about.

Why this answer

Responding to ICMP Timestamp requests leaks the exact system uptime and local clock settings to unauthenticated external entities. Attackers use this timing information to fingerprint operating systems, map network latency anomalies, and design precise timing attacks against time-dependent cryptographic protocols and authentication tokens.

Exam trap

Candidates frequently select generic denial-of-service impacts, overlooking that ICMP timestamps specifically leak precise system uptime and clock data for reconnaissance.

287
MCQhard

A security engineer is hardening a Windows Server 2022 that hosts a Microsoft SQL Server instance. The server is domain-joined, and the SQL Server service currently runs under a domain user account. The engineer wants to implement a solution that provides automatic password management, supports Kerberos authentication, and allows the service to access network resources. The solution must also minimize the risk of password reuse across multiple servers. Which of the following should the engineer implement?

A.Group Managed Service Account (gMSA)
B.Standalone Managed Service Account (sMSA)
C.Virtual Service Account
D.Local Service account
AnswerA

A gMSA is a domain account whose password is managed by Active Directory and automatically rotated. It supports Kerberos authentication, allows the service to access network resources, and can be shared across multiple servers without password reuse. This directly meets all requirements and is the recommended solution for services like SQL Server.

Why this answer

A Group Managed Service Account (gMSA) is designed for services that need to access network resources and require automatic password management. It supports Kerberos and can be used across multiple servers without sharing the same password, reducing risk. The other account types either lack network access or cannot be shared across servers.

Exam trap

The trap here is confusing sMSA with gMSA; sMSA is single-server only and does not meet the multi-server requirement.

288
Multi-Selectmedium

A security analyst is reviewing how a file encryption tool protects data at rest on employee laptops. The tool must ensure that an attacker who copies the encrypted file cannot decrypt it without also obtaining the user's passphrase, and that modification of the ciphertext is detectable. Which TWO design elements should the analyst verify are present? (Choose two.)

Select 2 answers
A.The file is encrypted with a stream cipher using a nonce that is reused across all files for simplicity.
B.A static initialization vector equal to the file creation timestamp is used for every encryption operation to ensure reproducibility.
C.A password-based key derivation function with a unique random salt and a high iteration count is used to derive the file encryption key.
D.An authenticated encryption mode such as AES-GCM or ChaCha20-Poly1305 is used to provide confidentiality and integrity of the ciphertext.
E.The encryption key is embedded in the file header obfuscated with Base64 so the tool can decrypt without prompting the user.
AnswersC, D

A salted, high-iteration KDF forces an attacker to spend significant work per guessed passphrase and prevents precomputed rainbow-table attacks across files. Because the salt is unique per file, identical passphrases still yield different keys, so copying a file without the passphrase leaves the attacker facing a costly brute-force effort.

Why this answer

A salted, high-iteration KDF makes passphrase guessing expensive and prevents cross-file precomputation, while authenticated encryption binds a tag to the ciphertext so any modification is detected. Together they ensure a copied file cannot be decrypted without the passphrase and that tampering is evident.

Exam trap

The trap here is treating encoding such as Base64 or an obfuscated header as encryption, when it provides no confidentiality and leaves the key trivially recoverable from a copied file.

289
MCQhard

A GSEC consultant is hardening a Kubernetes cluster that runs multi-tenant workloads. A developer reports that a pod in the tenants namespace was able to read the contents of the kubelet's host filesystem at /var/lib/kubelet. The pod spec includes hostPath: {path: /var/lib/kubelet, type: Directory} under volumes and mounts it at /host. The cluster has Pod Security Admission enabled with the restricted profile enforced cluster-wide, but the tenants namespace was labeled pod-security.kubernetes.io/enforce: privileged to unblock a legacy job. Which action most directly closes this exposure?

A.Enable the NodeRestriction admission plugin and rotate the kubelet client certificates on all worker nodes.
B.Add a seccomp profile of RuntimeDefault to the pod and set allowPrivilegeEscalation to false in its securityContext.
C.Create an OPA Gatekeeper constraint that denies pods whose namespaces carry the privileged enforcement label.
D.Remove the privileged label from the tenants namespace so the restricted profile is enforced there, and refactor the legacy job to run without a hostPath mount.
AnswerD

The hostPath volume is what exposes the node's kubelet directory to the pod, and the namespace's privileged enforcement label is what allowed that volume to be admitted despite the cluster-wide restricted profile. Restoring restricted enforcement blocks hostPath volumes entirely and forces the legacy job to be reworked, directly removing the pod's ability to read node files. The other options leave the mount or the permissive label in place.

Why this answer

Pod Security Admission decides admission based on the namespace's pod-security.kubernetes.io/enforce label, and the privileged value on the tenants namespace overrode the cluster-wide restricted profile. That exemption is precisely what let a pod mount the node's /var/lib/kubelet directory via hostPath. Removing the label restores restricted enforcement, which forbids hostPath volumes, and refactoring the legacy job removes the need for the exemption so the exposure cannot be recreated.

Exam trap

The trap here is focusing on pod-level runtime hardening such as seccomp or privilege-escalation flags, when the actual enabler was a namespace-level admission exemption that permitted the hostPath mount in the first place.

290
MCQeasy

A security administrator is configuring a new wireless intrusion prevention system (WIPS) for a corporate campus. The administrator wants the WIPS to automatically contain an unauthorized access point that is broadcasting the corporate SSID. Which WIPS capability should be enabled to achieve this?

A.Location tracking of wireless clients.
B.Wireless intrusion detection with alerting only.
C.Spectrum analysis to identify interference sources.
D.Rogue AP containment via over-the-air deauthentication and disassociation frames.
AnswerD

WIPS can automatically contain a rogue AP by sending deauthentication and disassociation frames to clients connected to that AP, effectively disconnecting them. This is a standard containment method. It disrupts the rogue AP's ability to serve clients. The administrator should enable this containment feature to automatically neutralize the threat without manual intervention, aligning with the scenario's requirement.

Why this answer

Automatic rogue AP containment in a WIPS works by sending deauthentication and disassociation frames to clients associated with the rogue device, preventing them from using it. This meets the requirement for automatic neutralization. Alerting, spectrum analysis, and location tracking are valuable but do not provide containment.

Enabling containment is the direct action that achieves the goal.

Exam trap

The trap here is confusing detection with prevention; a WIPS that only alerts does not automatically contain a rogue AP, even though it identifies it.

291
MCQhard

A vulnerability scan of a production web server reports a critical remote code execution vulnerability, but the system administrator insists the server is fully patched. The scanner used only unauthenticated checks. Which step should the security analyst take FIRST to resolve the discrepancy?

A.Rescan the server with a different unauthenticated scanner to compare results
B.Immediately take the server offline to prevent exploitation
C.Accept the administrator's statement and close the finding as a false positive
D.Perform an authenticated scan and manually verify the vulnerability on the host
AnswerD

Authenticated scanning reads the actual installed package versions and patch levels, providing far more accurate results than banner-based inference. Manually verifying the vulnerability on the host confirms whether the issue truly exists. This approach resolves the discrepancy between the scanner's report and the administrator's claim without causing unnecessary disruption or acting on a possible false positive.

Why this answer

Unauthenticated scans infer vulnerabilities from banners and service responses, which can produce false positives. To resolve the conflict between the scanner and the administrator, the analyst should perform an authenticated scan that reads installed package versions and manually verify the issue on the host. This provides definitive evidence and avoids both unnecessary downtime and premature closure of a critical finding.

Exam trap

The trap here is trusting either the unauthenticated scan or the administrator's assurance without independent verification, when the real answer lies in authenticated, host-level validation.

292
MCQmedium

An administrator observes a series of SYN packets originating from an internal workstation targeting random ports on various external IP addresses. The traffic is not resulting in established TCP connections. What is the most likely purpose of this network behavior?

A.The workstation is performing a standard DNS resolution process.
B.The system is initiating a legitimate peer-to-peer file transfer.
C.The host is performing TCP half-open reconnaissance.
D.The network interface is experiencing a broadcast storm.
AnswerC

TCP half-open scanning, often called SYN scanning, involves sending SYN packets to probe ports. The attacker analyzes the responses to determine if ports are open, closed, or filtered. Because the full handshake is never completed, the scanning activity is harder to log on the target system.

Why this answer

The behavior described is characteristic of a TCP port scan. By sending SYN packets without completing the three-way handshake, the attacker identifies open services while attempting to minimize detection. Understanding reconnaissance techniques is vital for network defense, as these scans often precede targeted exploitation attempts.

Security analysts must identify such patterns early to implement egress filtering or isolate the compromised host before it initiates a more severe attack.

Exam trap

Candidates often mistake half-open SYN packets for a full Denial of Service flood, missing that scanning random ports without completing handshakes indicates reconnaissance.

293
MCQmedium

A security administrator is hardening a Linux web server that hosts customer data. During a review of mount options, the administrator notes that the /tmp and /var/tmp directories are mounted with the 'noexec' and 'nosuid' options, but /home is not. A developer complains that scripts in /home are being executed by a scheduled process. Which action best maintains security while addressing the developer's need?

A.Remove the 'noexec' option from /tmp and /var/tmp so the developer can move scripts there and execute them, keeping /home locked down.
B.Add the 'nosuid' option to /home only, because nosuid prevents all executable files from running and resolves the developer's concern.
C.Remount /home with the 'noexec' option and require the developer to store and execute scripts from /var/tmp instead.
D.Leave /home mounted without 'noexec' and instead enforce execution control through SELinux booleans or AppArmor profiles that restrict which binaries the scheduled process may run.
AnswerD

When legitimate scripts must execute from /home, using mandatory access control such as SELinux booleans or AppArmor profiles restricts execution to approved binaries and paths without breaking the developer's workflow. This maintains defense in depth while allowing required functionality, unlike blunt mount options that would block all execution.

Why this answer

The scenario requires balancing operational need with hardening. Mount options like noexec and nosuid are valuable for directories that should never host executables, but /home may legitimately need to run scripts. Applying mandatory access control lets specific processes execute approved files while blocking everything else, preserving security without breaking the developer's scheduled process.

A blanket noexec on /home is too restrictive, and moving execution to world-writable temporary directories undermines the server's defenses.

Exam trap

The trap here is assuming that noexec is the only way to prevent execution and that nosuid blocks all execution, when nosuid only affects setuid/setgid bits.

294
MCQhard

A security analyst is investigating a suspected credential theft attack on a Windows 10 workstation. The analyst reviews the Security event log and sees Event ID 4648 (A logon was attempted using explicit credentials) occurring repeatedly for a service account. Which of the following best describes the significance of this event in the context of credential theft?

A.It indicates that the service account was granted special privileges, such as SeDebugPrivilege, which is a common post-exploitation step.
B.It indicates that the service account's password was changed, which is a common persistence technique after credential theft.
C.It indicates that the service account was locked out due to multiple failed logon attempts, which is a sign of brute-force attack.
D.It indicates that the service account's credentials were used to run a process with explicit credentials, which could be a sign of pass-the-hash or credential reuse.
AnswerD

Event ID 4648 is logged when a process attempts to log on using explicitly provided credentials, such as when using RunAs or a scheduled task. In a credential theft scenario, an attacker might use stolen credentials to start a process, generating this event. Repeated occurrences for a service account can indicate malicious use of those credentials.

Why this answer

Event ID 4648 is generated when a logon is attempted using explicit credentials, such as with RunAs or a scheduled task. In credential theft, attackers may use stolen credentials to start processes, causing this event. Repeated occurrences for a service account can signal malicious activity.

Other events like 4625, 4740, or 4672 have different meanings and are not directly indicative of explicit credential use.

Exam trap

The trap here is assuming that any security event involving a service account indicates credential theft, without verifying the specific event ID and its meaning.

295
MCQhard

Which TWO of the following statements accurately describe the characteristics of UDP compared to TCP?

A.UDP provides guaranteed delivery of packets.
B.UDP is faster due to the lack of a handshake.
C.UDP uses flow control to manage data transmission rates.
D.UDP is connectionless and does not maintain state.
E.UDP is the primary protocol for HTTP web traffic.
AnswerB, D

UDP eliminates the overhead of the three-way handshake required by TCP. By sending data immediately without establishing a stateful connection, UDP significantly reduces latency, which is essential for time-sensitive applications like DNS queries, streaming media, and VoIP, where retransmission delays would degrade the user experience.

Why this answer

UDP is a connectionless, datagram-oriented protocol that prioritizes speed and efficiency over reliability. It does not perform handshakes, flow control, or error correction, making it ideal for real-time applications like VoIP. TCP, conversely, provides a reliable stream by managing connections and acknowledging packet delivery.

Understanding these differences is crucial for firewall configuration, as security policies must account for the stateless nature of UDP versus the stateful requirements of TCP.

Exam trap

Candidates often confuse UDP with TCP characteristics, specifically claiming that UDP performs flow control or error recovery, which are exclusive to TCP's stateful, reliable delivery mechanism.

296
MCQmedium

An organization is deploying Just-In-Time (JIT) administration. Which Windows feature provides the necessary framework for creating temporary, elevated group memberships for domain administrators?

A.Restricted Groups GPO
B.Privileged Access Management (PAM)
C.User Rights Assignment policy
D.Group Policy Preferences
AnswerB

PAM provides the capability to grant time-limited, Just-In-Time administrative access. By utilizing shadow principals and the MIM platform, organizations can provision temporary group memberships, ensuring that administrative accounts do not remain privileged indefinitely, which significantly mitigates the risk associated with account compromise.

Why this answer

Privileged Access Management (PAM) using Microsoft Identity Manager (MIM) allows for the creation of shadow principals in a separate forest. This approach ensures that administrative rights are only granted for a specific window of time, drastically reducing the impact of a compromised account. This is a vital architectural pattern for securing Active Directory environments against persistent threats that rely on long-lived administrative privileges to maintain access.

Exam trap

Candidates often confuse PAM with 'Just Enough Administration' (JEA). While both are security frameworks, PAM is specific to managing time-bound administrative group memberships.

297
MCQmedium

A security analyst suspects an internal host is communicating with a command-and-control server using DNS tunneling. Which network protocol characteristic should the analyst examine to best identify this malicious behavior?

A.TCP connection state tables showing persistent half-open sessions on port 53.
B.Unusually high frequency and elevated entropy levels within TXT or subdomain record queries.
C.Frequent receipt of ICMP Destination Unreachable messages indicating blocked UDP traffic.
D.Elevated round-trip time latency on standard HTTP GET requests traversing proxy servers.
AnswerB

Malicious actors encode stolen data or remote commands within the subdomains of DNS requests or inside TXT records. Inspecting query frequency, length, and entropy reveals the high-density encoded payloads characteristic of modern tunneling tools like Iodine.क्क

Why this answer

DNS tunneling embeds arbitrary data inside standard DNS queries and responses, primarily utilizing TXT, NULL, or subdomains of A records. Analysing query length and entropy helps security professionals detect abnormal payload sizes that deviate from legitimate domain name resolution patterns, protecting enterprise networks from stealthy data exfiltration and C2 channels.

Exam trap

Candidates often look for 'high bandwidth usage'. DNS tunneling is often slow and stealthy; it relies on the content (entropy/record type) rather than large volumes of data.

298
MCQhard

An incident responder notices suspicious memory usage on a protected host. Which endpoint forensic technique is most reliable for detecting file-less malware that resides only in RAM?

A.Scanning the hard drive for known malicious file signatures.
B.Analyzing the Master File Table (MFT) for deleted entries.
C.Performing a memory dump and analyzing it for anomalous process threads.
D.Checking the Windows Event Logs for failed login attempts.
AnswerC

Memory forensics tools allow responders to examine the contents of RAM to find injected code, hidden processes, or tampered system calls. By comparing the memory state against a known-good baseline, analysts can identify the specific memory regions used by the file-less malware to maintain its stealthy presence.

Why this answer

File-less malware operates by injecting malicious code directly into the memory space of legitimate system processes. Traditional disk-based scanning tools will miss this, as no malicious file exists on the filesystem. Detecting file-less attacks requires inspecting memory for anomalies, such as injected threads or hooked functions, which requires specialized tools capable of analyzing process memory structures in real-time.

Exam trap

Candidates often select file-based scanning tools or antivirus logs, assuming malware always leaves a footprint on the disk, ignoring that file-less malware executes entirely within volatile memory structures.

299
MCQeasy

A small business replaces its aging router with a unified threat management (UTM) appliance. The owner wants one device to provide antivirus scanning, content filtering, and intrusion prevention for all outbound traffic. Which statement BEST describes how the UTM appliance delivers these functions?

A.It relies solely on signature updates pushed to endpoint agents installed on each workstation.
B.It combines multiple security functions in a single platform that inspects traffic as it passes through the appliance.
C.It functions only as a stateful firewall and requires separate appliances for each additional security service.
D.It offloads all inspection to a cloud service, requiring no local processing of network traffic.
AnswerB

A UTM appliance integrates several security services, such as antivirus, content filtering, intrusion prevention, and often VPN, into one device that traffic traverses. This consolidation is exactly what the owner wants: a single platform applying multiple inspection technologies to outbound flows without deploying separate dedicated appliances.

Why this answer

Unified threat management consolidates several inspection technologies into one appliance positioned in the traffic path, letting a small business obtain antivirus, content filtering, and intrusion prevention without procuring and managing separate devices.

Exam trap

The trap here is confusing UTM consolidation with cloud-only or endpoint-only security models, which distribute inspection differently than a single inline appliance.

300
MCQhard

A SIEM administrator is troubleshooting why Windows event logs forwarded from a domain controller are not being parsed correctly. The logs are sent using the Windows Event Forwarding (WEF) subscription, but the SIEM shows raw XML instead of normalized fields. The administrator confirms that the WEF subscription is active and events are arriving. Which action should the administrator take to ensure proper parsing?

A.Install a SIEM agent on the domain controller to read the event logs directly and forward them in a normalized format.
B.Configure the SIEM to use the Windows Event Log collector with the correct channel names and enable XML parsing.
C.Modify the WEF subscription to forward events in JSON format instead of XML.
D.Create a custom parser in the SIEM that extracts fields from the XML structure of the WEF events.
AnswerD

When WEF forwards events, they are encapsulated in XML. If the SIEM's default Windows parser expects a different format (e.g., EVTX or JSON), it will fail to extract fields, resulting in raw XML. Creating a custom parser that understands the WEF XML schema and maps fields like EventID, Computer, and SubjectUserName to the SIEM's normalized schema will enable proper parsing and correlation.

Why this answer

WEF forwards events in XML format. If the SIEM's collector is not configured to parse that XML, it stores raw XML and fields are not normalized. The administrator should create a custom parser that extracts relevant fields from the WEF XML schema and maps them to the SIEM's data model.

Other options either do not address the parsing issue or are technically infeasible.

Exam trap

The trap here is assuming that enabling generic XML parsing will automatically map fields correctly, when a custom parser tailored to the WEF schema is needed.

Page 3

Page 4 of 5

Page 5

All pages