SSCP · domain
scenario questions
Practise Systems Security Certified Practitioner SSCP scenario questions practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice scenario questions questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about scenario questions
scenario questions questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common scenario questions exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All scenario questions questions (920)
Click any question to see the full explanation, or start a practice session above.
An organization wants to prevent unauthorized devices from connecting to its wired network. Which security control should be implemented?
Easy2An organization has implemented a SIEM solution and wants to reduce false positives. Which of the following is the most effective approach?
Hard3During a forensic investigation, you find that the attacker used a legitimate Windows tool to exfiltrate data. Which tool is commonly abused for this purpose?
Hard4An incident responder needs to create a forensic image of a suspect hard drive. What is the correct procedure to ensure evidence integrity?
Medium5A security team is implementing a PKI for a large enterprise. Which TWO of the following are commonly used methods for certificate revocation checking? (Select TWO.)
Medium6A security administrator discovers that a web application is vulnerable to SQL injection. Which of the following is the most effective mitigation to implement at the application layer?
Medium7Which protocol is used to automatically assign IP addresses to devices on a network?
Easy8Match each incident response phase to its activity.
Medium9A cloud security team wants to continuously monitor for misconfigured cloud resources that could expose data. Which tool category is specifically designed for this purpose?
Medium10In which access control model does the owner of a resource have full discretion over who can access it and with what permissions?
Easy11A security analyst is reviewing network device logs and finds multiple failed SSH login attempts from a single external IP. Which three actions should the analyst take to mitigate this brute-force attack? (Choose three.)
Hard12A user reports that their computer is displaying a fake antivirus warning that demands payment. This is an example of which type of attack?
Easy13A security professional is implementing a solution to verify the authenticity of a digital certificate. Which component of a PKI is responsible for issuing and revoking certificates?
Easy14A large financial institution has deployed a new web application for customer account management. The application uses role-based access control (RBAC) with roles such as Customer, Teller, Manager, and Admin. Recently, an audit revealed that a Teller was able to view and modify account details belonging to customers outside their assigned branch. The application authenticates users via the corporate Active Directory and uses AD groups for role mapping. The Teller's AD group membership was verified to be correct. The security team suspects a flaw in the authorization logic. Which of the following is the MOST likely root cause?
Hard15During a penetration test, an attacker was able to bypass input validation and execute commands on a web server. The server runs a PHP application. Which of the following is the MOST likely root cause?
Hard16A security engineer is configuring a site-to-site VPN between two branch offices using IPsec in tunnel mode. Which protocol provides both authentication and encryption of the entire original IP packet?
Hard17An organization uses smart cards with PKI certificates for authentication. Users must insert the card and enter a PIN. This is an example of which authentication method?
Hard18A vulnerability scanner identifies a high-severity vulnerability in a web server that is exposed to the internet. According to common remediation SLAs, what is the typical timeframe to remediate a critical vulnerability?
Easy19A security analyst is reviewing a TLS 1.3 deployment. Which THREE of the following are features of TLS 1.3?
Hard20A network administrator notices that wireless users are experiencing intermittent connectivity. The controller shows excessive deauthentication frames. What is the most likely cause?
Medium21An analyst runs the netstat command on a web server. Based on the output, which connection is the MOST suspicious?
Medium22Which THREE types of evidence are MOST important to collect from a compromised Linux server during forensic acquisition?
Hard23A small company with 50 employees uses a local file server for sharing documents. Each employee has a username and password for authentication. The company wants to implement an additional layer of security to protect sensitive data without incurring high costs. They are considering using smart cards or biometric scanners. However, the budget is limited, and employees often work remotely. Which of the following is the most cost-effective and practical approach to strengthen authentication?
Easy24Which THREE of the following are common types of malware?
Easy25A BYOD policy allows personal devices to access corporate email. What is the best control to enforce device encryption and remote wipe?
Hard26Refer to the exhibit. An administrator implements this firewall rule. What is the intended effect?
Medium27During a wireless penetration test, an attacker captures the four-way handshake of a WPA2-PSK network and attempts to crack the passphrase offline. Which attack is the attacker likely using?
Hard28An attacker sends a forged ARP reply associating the attacker's MAC address with the IP address of the default gateway. What type of attack is this?
Medium29Refer to the exhibit. A network engineer is configuring an IPsec VPN. Which protocol does this configuration apply to?
Medium30Which TCP port is commonly used for secure web traffic (HTTPS) and is often allowed through firewalls for web browsing?
Easy31A company is implementing application whitelisting on all endpoints. Which of the following is a primary consideration for maintaining operational efficiency?
Easy32A medium-sized company recently experienced a phishing attack where an employee downloaded a malicious attachment, leading to a data breach. The incident response team has identified the affected user and the malware. However, the team is unsure whether the attacker has established persistence. The security analyst must recommend the next step. The company has a standard incident response plan that includes detection, containment, eradication, recovery, and lessons learned. The malware sample has been isolated for analysis. The user's account has been disabled temporarily. The network team has quarantined the user's workstation. The analyst needs to ensure the attacker cannot regain access after the initial cleanup. What should the analyst recommend next?
Easy33A company is implementing a Single Sign-On (SSO) solution that uses XML-based assertions to exchange authentication and authorization data between an identity provider and a service provider. Which protocol is being used?
Medium34Which TWO of the following are common indicators of a ransomware attack?
Easy35An organization wants to ensure that only authorized devices can connect to the corporate wired network. Which technology should they implement to enforce this?
Medium36An organization uses Infrastructure as a Service (IaaS) in the public cloud. Which of the following security responsibilities is the customer responsible for?
Easy37A medium-sized company with 200 employees has a single office with a flat network topology. Recently, the IT team noticed that network performance has degraded significantly during peak hours. A network analysis reveals excessive broadcast traffic and a high number of ARP requests. Additionally, the security team is concerned about the lack of segmentation, as a workstation infected with malware was able to spread rapidly to other systems. The company uses a single /24 subnet (192.168.1.0/24) and all devices are connected to a layer 2 switch. The IT manager wants to improve both performance and security without purchasing new hardware. The existing switch is a managed layer 2 switch that supports VLANs, but the router is a basic home-grade device that does not support VLAN routing. The company's internet connection is provided by a cable modem. What is the BEST course of action to address both performance and security concerns?
Hard38A security analyst is reviewing SIEM alerts and wants to identify potential data exfiltration. Which TWO of the following indicators are most relevant?
Medium39A security administrator is implementing change management for a critical financial system. Which of the following is the MOST important control to prevent unauthorized changes?
Hard40A company is deploying a VPN using IPsec. They want to ensure that even if the private key of the server is compromised, past session keys cannot be derived. Which key exchange method should they use?
Medium41An organization's backup policy states: 'Maintain three copies of data on two different media types, with one copy stored offsite.' This is known as:
Medium42Which TWO of the following are examples of physical security controls? (Select TWO)
Easy43An organization is migrating from 3DES to AES-256 for encrypting data at rest. Which mode of AES is recommended for authenticated encryption?
Medium44A company is developing an incident response plan. Which of the following stakeholders should be included in the initial planning phase?
Easy45A network administrator is tasked with segmenting the network to isolate a DMZ containing public-facing web servers from the internal corporate network. Which device should be placed between the DMZ and internal network, and what type of traffic should it allow?
Medium46Which THREE of the following are valid risk treatment options according to ISO 31000? (Select three.)
Hard47If the web server is compromised, which of the following is a likely immediate risk?
Easy48A security analyst detects unusual outbound traffic from a server that normally communicates only with internal systems. The firewall logs show connections to an external IP address on port 443/tcp. Which incident response step should the analyst perform FIRST?
Medium49A network administrator is troubleshooting a DNS poisoning attack. Which TWO countermeasures can help prevent such attacks? (Select two)
Medium50An organization uses a central syslog server to collect logs from firewalls, servers, and network devices. Recently, the security team noticed that some critical events from the firewall are missing from the syslog server. The firewall configuration sends syslog messages using UDP to the syslog server. The syslog server administrator reports that the server is receiving a high volume of logs and occasionally drops packets due to buffer overflow. The team needs to ensure reliable delivery of all syslog messages without losing any. Which solution should the team implement?
Medium51A company implements a password policy requiring a minimum length of 12 characters, including uppercase, lowercase, digits, and special characters. Passwords must be changed every 90 days, and the last 10 passwords cannot be reused. After a brute-force attack, several accounts were compromised despite the policy. Which additional control would most effectively mitigate such attacks?
Hard52During forensic analysis, which THREE pieces of evidence should be preserved in original form?
Hard53A company is developing a DR plan for a critical database. The maximum acceptable downtime is 2 hours, and the maximum data loss is 1 hour. What are the RTO and RPO?
Medium54During the detection and analysis phase, an analyst receives a user report of unusual system behavior. The analyst reviews logs and finds several failed login attempts followed by a successful login from an unusual IP address. What is the next step?
Medium55Match each security control to its type (administrative, technical, physical).
Medium56Which TWO of the following are key components of a data classification policy? (Select the two best answers.)
Easy57An organization implements a hybrid encryption scheme to secure sensitive emails. The email body is encrypted with AES-256, and the AES key is encrypted with RSA-2048. What is the primary advantage of this approach?
Hard58A security administrator needs to set file permissions on a shared folder so that only members of the 'Finance' group can read and write to it. All existing permissions should be removed. Which command should the administrator use?
Easy59A security operations team is developing an incident response plan. Which TWO steps are part of the 'containment, eradication, and recovery' phase? (Choose two.)
Easy60A multinational corporation is migrating its on-premises applications to a cloud provider. The identity management infrastructure must support single sign-on (SSO) across multiple cloud services and maintain on-premises Active Directory as the authoritative identity source. The security team is concerned about credential stuffing attacks and password spray attacks. They want to implement a risk-based access policy that requires additional verification when logins originate from unusual locations or devices. Additionally, they need to ensure that user accounts are provisioned and deprovisioned in the cloud in near real-time based on AD changes. Which of the following solutions BEST meets these requirements?
Hard61An organization uses ABAC to control access to a document. Which attribute combination would be used to allow access only during business hours from a managed device?
Hard62Which type of IDS uses a database of known attack patterns to identify malicious activity?
Easy63During a security assessment, a penetration tester discovers that a web application allows users to upload files without proper validation. The tester successfully uploads a PHP web shell. Which control would have MOST effectively prevented this exploitation?
Hard64In RSA, the public exponent e is often chosen as 65537. What is the primary reason for this choice?
Hard65Which TWO of the following are examples of technical threat sources that should be considered during risk identification?
Medium66A user reports that they cannot access a network share. The administrator checks the share permissions and NTFS permissions. The share permission allows Everyone: Read, and the NTFS permission allows the user: Full Control. What is the user's effective access?
Medium67During a quarterly risk review, a hospital's security team identifies that legacy medical devices cannot be patched and run outdated operating systems. Which risk treatment strategy is most appropriate for these devices?
Medium68An organization's web application experienced a data breach due to a SQL injection vulnerability. During the risk analysis phase, the security team calculated the SLE as $25,000 and the ARO as 0.5. What is the ALE?
Medium69A system administrator is applying CIS Benchmarks to a Windows server. Which TWO hardening measures are typically recommended by CIS? (Select TWO.)
Easy70An organization wants to identify risks related to a new cloud-based customer relationship management (CRM) system. Which approach would best identify threats and vulnerabilities specific to this system?
Medium71Which security control can prevent a rogue DHCP server from assigning incorrect gateway addresses to clients?
Medium72Refer to the exhibit. A security analyst reviews these iptables rules and expects SSH access to be blocked, but it is still allowed. What is the MOST likely reason?
Hard73Refer to the exhibit. A web server at 10.0.0.50 received the payload shown. What is the MOST likely impact if the web application is vulnerable?
Easy74During a forensic investigation, an examiner needs to preserve volatile evidence. Which of the following lists the correct order of collection for volatile data?
Hard75A security administrator is tasked with managing user access. Which THREE of the following are principles of least privilege? (Choose three.)
Hard76During the eradication phase of incident response, which of the following actions is MOST critical to ensure the threat is completely removed from a compromised system?
Medium77An organization is implementing multi-factor authentication (MFA). Which TWO of the following are examples of something you have?
Medium78An organization requires that all laptops used by employees be encrypted. Which type of encryption should be used to protect the entire hard drive?
Easy79During an access control audit, you find that a user has been assigned to two mutually exclusive roles. Which TWO principles are most likely violated?
Hard80An organization detects that an attacker is performing a MAC flooding attack on a switch. What is the primary goal of this attack?
Hard81You are the security analyst for a mid-sized e-commerce company that processes credit card payments. The company uses a legacy payment application on a Windows Server 2012 R2 system, which is scheduled for decommission in six months. The server is isolated in a separate VLAN with strict firewall rules allowing only outbound HTTPS to the payment processor and inbound management from a jump box on a different subnet. During a routine vulnerability scan, you discover that the server is missing over 50 critical patches, including one for a remote code execution vulnerability (CVE-2023-XXXX) that is being actively exploited in the wild. The server cannot be patched because the vendor stopped support and patches are not available. The company's risk appetite is low due to PCI DSS requirements. You need to recommend a course of action that balances risk reduction with business continuity. What should you do?
Hard82A company has a backup policy that performs a full backup every Sunday and incremental backups on other days. On Wednesday, a server fails. How many backup sets are needed to restore the server to its state on Tuesday night?
Hard83After a ransomware incident, an organization decides to restore data from backups. The RPO (Recovery Point Objective) is 4 hours. What does this RPO indicate?
Medium84A security analyst notices repeated failed login attempts from a single IP address targeting a domain controller. The SIEM alerts after 10 failed attempts within 5 minutes. Which detection type is most likely used?
Medium85In IPsec VPNs, which protocol provides authentication and encryption of the entire IP packet, including the IP header, in tunnel mode?
Hard86An organization experiences a ransomware attack that encrypts critical data. The incident response team isolates affected systems. What is the NEXT step?
Easy87Which of the following protocols is used to securely transfer files over SSH and is considered a replacement for FTP?
Medium88An organization is calculating the Annualized Loss Expectancy (ALE) for a server. The Asset Value (AV) is $50,000, the Exposure Factor (EF) is 40%, and the Annualized Rate of Occurrence (ARO) is 0.5. What is the Single Loss Expectancy (SLE) and ALE?
Hard89You are the security administrator for a mid-sized financial company that processes credit card transactions. The company has a mix of on-premises servers and cloud-based services. Recently, the company experienced a data breach where an attacker exfiltrated customer data from a database server. The investigation reveals that the attacker used compromised credentials of a database administrator (DBA) account. The DBA account had been used by multiple administrators without proper auditing. The company wants to implement a solution to prevent such incidents in the future. The solution must: 1) ensure that each administrator has a unique account for database access, 2) require approval for privileged actions, 3) provide a full audit trail of all privileged activities, and 4) be cost-effective. Which of the following is the best course of action?
Hard90An organization using PaaS (Platform as a Service) for application hosting wants to ensure the application code is secure. Which of the following is the customer's responsibility under the shared responsibility model?
Hard91Which of the following best describes the function of SYN cookies in mitigating SYN flood attacks?
Hard92Which backup type copies all data that has changed since the last full backup, regardless of subsequent backups?
Easy93An organization is migrating a legacy application to a PaaS cloud environment. According to the shared responsibility model, which security control is the organization still responsible for?
Hard94An organization is implementing a digital signature solution to ensure non-repudiation of documents. Which combination of keys is used during the signing process?
Medium95Which attack sends a flood of forged ICMP echo requests to a network's broadcast address to overwhelm a target?
Easy96A certificate authority (CA) issues a certificate with the extended key usage (EKU) extension specifying 'serverAuth'. Which of the following is this certificate allowed to do?
Hard97A company's risk management policy states that all risks with a residual risk score of 8 or higher (on a scale of 1-10) must be treated. A risk is identified with an inherent risk score of 9, and after applying controls, the residual risk score is 7. What is the appropriate action?
Hard98An organization's help desk receives multiple reports of employees unable to access a critical internal application. The IT team confirms the application server is running. What is the FIRST step in the incident response process?
Medium99A company's disaster recovery plan specifies an RTO of 4 hours for its customer relationship management (CRM) system. Which of the following DR site types is MOST appropriate to meet this RTO?
Hard100An organization's incident response plan is tested annually. After a real incident, the team finds that the plan did not address cloud-based assets. What is the BEST action?
Medium101A security analyst notices multiple failed login attempts on a critical server followed by a successful login from an unusual IP address. Which metric would BEST capture this event?
Medium102Which TWO are components of the AAA framework? (Choose two.)
Easy103A vulnerability management team is scanning a network. Which THREE factors should be considered to minimize false positives?
Medium104Match each disaster recovery site type to its description.
Medium105A vulnerability scan identifies a critical vulnerability with a CVSS score of 9.8. According to standard remediation SLAs, within what timeframe should this vulnerability typically be remediated?
Hard106A financial firm is implementing a new access control system for its critical trading application. The application currently uses local accounts and password authentication. The security team wants to enforce multi-factor authentication (MFA) and centralized user management. The firm has an existing Active Directory (AD) infrastructure and a certificate authority (CA). However, the trading application only supports smart card authentication via PKI and does not support integration with AD directly. The IT team must design a solution that meets security requirements while minimizing changes to the application. Which approach should the team take?
Hard107Which TWO of the following are effective measures to prevent buffer overflow attacks in a custom-developed application?
Easy108Refer to the exhibit. An administrator runs an OpenSSL s_client command and receives the output shown. What is the most likely cause of the 'unable to get local issuer certificate' error?
Hard109A multinational company has a headquarters (HQ) and several branch offices connected via site-to-site IPsec VPN tunnels. The branch offices use a single internet connection and a VPN concentrator at HQ. Recently, users in the Asia branch report intermittent connectivity to the HQ file server, with high latency and occasional packet loss. The network team runs a traceroute from Asia branch to the HQ server; it shows the path goes through multiple hops with high latency at the second hop, which is the ISP router. The VPN tunnel status shows 'up' but with increasing rekey failures. The team has verified that the local internet link is stable and there are no bandwidth saturation issues. Which action should the team take first?
Medium110An organization wants to implement a key exchange mechanism that provides forward secrecy. Which of the following should be used?
Medium111Which TWO of the following are best practices for securing a wireless network?
Medium112Which access control model allows the owner of a resource to grant permissions to others?
Easy113A cloud security team is using Cloud Security Posture Management (CSPM) to identify misconfigurations. Which of the following scenarios is MOST likely to be detected by CSPM?
Hard114A security team is implementing a risk treatment plan for a high-risk vulnerability. The cost to fix the vulnerability is $100,000, but the expected loss if exploited is $1,000,000. The annual likelihood of exploitation is 2%. Which risk treatment strategy is most appropriate?
Medium115What does this log entry most likely indicate?
Hard116Which THREE of the following are common methods to identify risks in an organization?
Easy117An organization uses an ABAC system to control access to documents. Policies are defined using attributes such as user department, document classification, and time of day. Which of the following is an example of an ABAC policy rule?
Hard118An organization is configuring a VPN using IPsec. To ensure forward secrecy, which key exchange method should be used?
Hard119During a security audit, it is discovered that several employees have access to shared network drives containing sensitive HR data. The HR manager states that these employees no longer need access. What is the most efficient way to revoke access?
Hard120A security administrator is evaluating backup strategies for a critical database with a recovery time objective (RTO) of 4 hours and a recovery point objective (RPO) of 1 hour. Which backup approach best meets these requirements?
Medium121An employee is leaving the company. As part of the offboarding process, which action should be taken regarding the hardware assigned to the employee?
Medium122A company's policy requires that all data at rest be encrypted. Which of the following is the most effective method to encrypt files on a laptop?
Medium123An organization uses a cloud-based file synchronization service to share project files with external partners. The security team discovers that an unauthorized third party accessed sensitive documents by guessing weak passwords. Which additional control would most effectively mitigate this risk?
Hard124Which three of the following are best practices for securing a wireless network? (Choose three.)
Medium125A security awareness program is being developed. Which topic is MOST critical for all employees to understand to reduce the risk of social engineering?
Hard126Which THREE of the following are valid considerations when deploying a remote access VPN using SSL/TLS? (Select THREE)
Hard127Which of the following is a method to check the revocation status of a digital certificate in real-time without the client downloading a full list?
Easy128An organization is reviewing its account lifecycle management process. Which TWO activities are part of the provisioning phase? (Select TWO.)
Medium129A company uses a SIEM to detect anomalies. An alert indicates a user logged in from two geographically distant locations within 5 minutes. What is the most likely indication?
Medium130An organization wants to ensure that sensitive data on laptops is protected in case of loss or theft. Which control is MOST effective?
Medium131A company wants to ensure that employees connecting from home use a secure tunnel to access internal resources. Which protocol should be implemented?
Easy132Which Windows feature provides mandatory integrity controls and helps prevent unauthorized changes to system settings by requiring administrator approval?
Easy133A company is migrating from 3DES to a modern encryption algorithm. Which of the following are acceptable choices? (Select TWO)
Medium134During a security assessment, a penetration tester discovers that the network uses WPA2-PSK. Which attack could be used to recover the pre-shared key without interacting with the access point after capturing a single handshake?
Medium135A security analyst is reviewing traffic logs and sees that a host is sending ICMP echo requests to multiple external IPs. This behavior is most likely indicative of:
Hard136A security analyst notices that a Linux server has an unusual number of failed login attempts for the root account. To strengthen authentication security while preserving administrative access, which of the following configurations would be most effective?
Hard137Which wireless security protocol uses the Simultaneous Authentication of Equals (SAE) handshake to replace the Pre-Shared Key (PSK) method and provides stronger protection against offline dictionary attacks?
Medium138An organization is implementing 802.1X authentication for wired network access. Which server is required to authenticate users?
Hard139Which TWO of the following are essential components of a disaster recovery plan (DRP)?
Medium140Which of the following is a connectionless transport layer protocol primarily used for services like DNS and DHCP?
Easy141In a Kerberos environment, what is the primary function of the Ticket Granting Ticket (TGT)?
Medium142A government contractor is required to comply with the Federal Information Security Management Act (FISMA). The security officer must implement a continuous monitoring program for all information systems. The contractor uses a mix of on-premises servers and cloud services. The contractor has a SIEM tool that collects logs from all systems. However, the SIEM generates a high number of alerts, many of which are false positives, overwhelming the security team. The team wants to improve the effectiveness of the monitoring program without increasing staff. Which of the following actions would MOST effectively address the issue?
Medium143A security administrator is implementing a change management process. Which TWO of the following are essential components of a change management policy? (Choose two.)
Medium144A remote employee needs secure access to corporate resources over the internet. Which protocol is considered best practice for site-to-site VPN?
Easy145A security policy requires that all access to sensitive data be logged. Which access control function does this support?
Easy146A company uses virtualization extensively. The security team discovers that developers have created many unmanaged virtual machines that are not tracked in the configuration management database (CMDB). Which risk is MOST directly associated with this situation?
Medium147Which TWO of the following cryptographic algorithms are considered secure for modern use?
Medium148Based on the exhibit, which type of attack is most likely occurring?
Medium149Based on the exhibit, what is the most critical observation?
Hard150An administrator configures a Kerberos authentication system. After implementation, users are able to authenticate but cannot access network resources. The administrator verifies that the client time is synchronized with the KDC. What is the most likely cause?
Medium151A security administrator is configuring a VPN between two branch offices. The requirement is to encrypt the entire original IP packet and add a new IP header for routing over the internet. Which IPsec mode should be used?
Medium152A company deploys a new web application and wants to ensure that session tokens are not vulnerable to session hijacking. Which of the following controls is most effective?
Medium153You are a security consultant for a hospital that is deploying a new IoT medical device system. The devices wirelessly transmit patient vital signs to a central server. The hospital is subject to HIPAA. The devices were developed by a startup and are not widely field-tested. The IT department wants to connect the devices to the existing network for real-time monitoring. The risk management team has identified potential threats including data interception, device tampering, and denial of service. They have no prior experience with IoT security. Which of the following risk treatment strategies is MOST appropriate given the high uncertainty?
Hard154Which TWO of the following are considered key components of a disaster recovery plan?
Easy155An analyst detects outbound traffic from a workstation to a known malicious IP address. The workstation is a developer machine with local admin rights. Which containment action should be taken first?
Hard156Which TWO factors are most critical when selecting a cryptographic algorithm for a government application?
Medium157A security engineer is designing a system to store passwords securely. Which of the following is the most robust approach for password storage?
Hard158A security engineer is designing a DMZ to host public-facing services. Which two security best practices should be applied? (Choose two.)
Easy159A security analyst notices that a user's account was used to access sensitive files after the user had left the company. Which access control principle was most likely violated?
Hard160During a physical security audit, it is discovered that employees often prop open the mantrap door to allow easier access. What is the BEST control to address this?
Hard161A system administrator needs to securely transfer log files from a Linux server to a central log collector. Which protocol should be used to ensure confidentiality and integrity?
Easy162A small business needs basic protection against malware. Which solution is MOST cost-effective and provides real-time protection?
Easy163Which TWO of the following are best practices for securing an application programming interface (API)?
Medium164A system administrator is configuring a Linux server to ensure that only authorized users can execute commands with superuser privileges. Which file should be edited to control sudo access?
Medium165A user reports they cannot access the internet. The network administrator verifies that the user's workstation has an IP address of 192.168.1.100/24 and a default gateway of 192.168.1.1. The administrator can ping the default gateway but cannot ping 8.8.8.8. What is the most likely cause?
Easy166A company uses a Cloud Workload Protection Platform (CWPP) to secure IaaS workloads. They discover that a virtual machine (VM) is communicating with a known command-and-control server. What is the FIRST action the security team should take?
Hard167A company is deploying a new mobile application that handles sensitive customer data. Which practice BEST ensures data confidentiality on the device?
Easy168A system administrator is hardening a Linux server. After installing the OS, which of the following steps should be taken to ensure that only authorized users can execute commands with elevated privileges?
Medium169A Linux server is being hardened. The security team wants to enforce mandatory access control policies that confine processes to limited access to files and resources. Which technology should be implemented?
Medium170A change request to update a critical database server has been approved by the Change Advisory Board (CAB). During testing, a major compatibility issue is discovered. What is the best course of action?
Hard171Which UDP port is used by the Domain Name System (DNS) for name resolution queries?
Easy172Refer to the exhibit. A security administrator is troubleshooting connectivity to a web server. Users report they can access the website via HTTP and HTTPS, but cannot establish new SSH connections. Which of the following best explains this issue?
Medium173During a qualitative risk analysis, an organization assesses a threat of a data breach due to weak encryption. The likelihood is rated as 'Medium' and the impact as 'High'. According to a standard 3x3 risk matrix, what is the overall risk rating?
Medium174An organization implements RBAC to enforce separation of duties. Which of the following is a key benefit of using role-based access control in this context?
Medium175A military system uses mandatory access control with classifications Unclassified, Confidential, Secret, and Top Secret. A user with Secret clearance attempts to read a file labeled Top Secret. What will occur?
Medium176An organization uses mandatory access control (MAC) with the Bell-LaPadula model. A subject has a clearance of 'Secret' and an object has a classification of 'Top Secret'. What is the result if the subject attempts to read the object?
Hard177An organization is required to maintain audit logs for at least one year for compliance purposes. Which log management practice best ensures the integrity of these logs?
Medium178An organization uses OAuth 2.0 for delegated access to a cloud storage API. A third-party application requests an access token to read user files. What is the primary purpose of the access token in OAuth?
Medium179An organization's security policy prohibits employees from sharing passwords. What type of policy is this?
Easy180An IT auditor reports that firewall logs are not being reviewed regularly. Which control should be implemented to address this finding?
Medium181A vulnerability scan identifies a critical vulnerability on a web server with a CVSS score of 9.8. The server hosts a public-facing application. However, the patch would require a reboot that would cause downtime during business hours. What should the security administrator do FIRST?
Hard182A forensic investigator is collecting evidence from a compromised Windows server. According to the order of volatility, which THREE pieces of evidence should be collected FIRST? (Select THREE)
Hard183Refer to the exhibit. The security analyst sees this event from a user workstation. What is the most likely conclusion?
Medium184A company wants to implement multi-factor authentication (MFA) for remote access. Which THREE of the following are examples of different authentication factors? (Choose THREE.)
Medium185An employee reports that they cannot access a shared folder on the network. The security administrator checks the permission and finds that the user is in the correct group, but the 'Deny' entry for a different group is blocking access. What is the MOST likely cause?
Easy186Which protocol and port combination is commonly used for secure remote administration of a server?
Easy187An organization uses AWS IAM to manage access. Which best practice ensures least privilege?
Medium188A network administrator is configuring a firewall rule to allow inbound HTTPS traffic to a web server. Which protocol and port should be allowed?
Easy189During a security audit, it is found that several employees have written their passwords on sticky notes attached to their monitors. Which policy is being violated?
Medium190A university IT department manages a lab of 50 computers running Windows 10 that are used by students for coursework. The computers are joined to a domain and have Group Policy applied to restrict administrative access. Recently, several students were able to install unauthorized software by using the built-in Administrator account, which had the same password on all lab computers. The IT department wants to prevent this without affecting the students' ability to run required academic software. Which of the following is the most effective solution?
Easy191A security administrator is tasked with ensuring that only authorized software can run on company workstations. Which security control should be implemented?
Easy192A company detects ransomware on a file server. The ransomware is currently encrypting files. Which containment strategy should be implemented FIRST?
Medium193A company deploys a web application and wants to protect against SQL injection and XSS attacks. Which security control is specifically designed to inspect HTTP traffic and block such attacks?
Medium194Based on the exhibit, what is the most appropriate immediate action?
Hard195Refer to the exhibit. An AWS S3 bucket policy is defined as shown. Which statement about this policy is TRUE?
Easy196A company has a policy requiring segregation of duties (SoD) for financial transactions. Which scenario represents a violation of this principle?
Hard197An organization uses a SIEM to correlate events. The SIEM receives Windows Security Event ID 4625 (failed login) and 4776 (credential validation). An analyst wants to detect a brute-force attack against a service account. Which correlation rule is most effective?
Hard198A change request to update a firewall rule has been submitted. After impact assessment, the change is approved by the Change Advisory Board (CAB). What is the NEXT step in the change management process?
Medium199Match each vulnerability assessment tool to its use.
Medium200A company wants to deploy a network IDS that can analyze traffic patterns and detect anomalies. Where should the IDS sensor be placed to monitor all traffic on a network segment without introducing latency?
Medium201Which of the following best describes the difference between HMAC and a simple hash function like SHA-256 when used for message authentication?
Hard202During a post-incident review, the incident response team identifies several areas for improvement. According to NIST SP 800-61, which THREE activities are typically part of the post-incident activity phase?
Hard203An organization experiences a ransomware attack that encrypts file servers. The annualized loss expectancy (ALE) for this risk is calculated as $150,000. The single loss expectancy (SLE) is $30,000. What is the annualized rate of occurrence (ARO)?
Hard204An attacker sends a gratuitous ARP reply associating the attacker's MAC address with the default gateway's IP address. Which attack is being performed, and what is the primary risk?
Medium205An organization deploys a firewall that examines the entire packet, including application-layer data, and can block specific commands or content. Which type of firewall is this?
Hard206During a risk assessment, a team identifies that the annualized loss expectancy (ALE) for a critical asset is $50,000. A proposed control costs $15,000 per year and will reduce the annualized rate of occurrence (ARO) from 5 to 1. The single loss expectancy (SLE) is unchanged at $10,000. What is the net benefit of implementing the control?
Hard207A company's log management solution is overwhelmed by high-volume logs from network devices, causing storage and analysis delays. Which strategy would best improve the efficiency of the log management process?
Medium208A company wants to ensure that employees understand the proper use of corporate email and internet. Which policy should they implement?
Easy209A security engineer is designing a federated identity solution for cross-domain authentication. Which THREE of the following technologies are commonly used?
Hard210What is the primary purpose of a baseline configuration in configuration management?
Easy211Which of the following is the primary purpose of a chain of custody form in digital forensics?
Easy212A company wants to deploy a firewall that can track the state of active connections and make decisions based on the context of traffic flows. Which firewall type should they choose?
Medium213A security administrator is configuring a system to enforce separation of duties. In which access control model is this principle most directly implemented?
Medium214A small business wants to protect its data from ransomware. Which backup strategy provides the BEST protection against an attack where the backup files are also encrypted?
Easy215During a post-incident review, the incident response team identifies that the mean time to detect (MTTD) was 14 days. Which improvement would most directly reduce MTTD?
Hard216Refer to the exhibit. A network administrator implements this ACL on a border router. What is the effect?
Easy217An attacker sends a flood of DHCP request packets with spoofed MAC addresses to exhaust the DHCP server's IP address pool, preventing legitimate clients from obtaining IP addresses. This attack is known as:
Medium218Which wireless security standard introduced the Simultaneous Authentication of Equals (SAE) handshake to replace the pre-shared key (PSK) method?
Medium219Which THREE of the following are best practices for securely managing cryptographic keys in an enterprise environment?
Hard220A Linux administrator needs to configure access controls so that a specific user can run certain commands with root privileges without entering a password. Which configuration file should be modified?
Medium221An organization wants to prevent unauthorized persons from entering a secure server room. Which control is the MOST effective?
Easy222An analyst reviews a Windows security log. Given the event, what is the MOST likely cause of the lockout?
Hard223An organization wants to ensure that only authorized devices can connect to its internal network. Which of the following should be implemented?
Easy224An organization is experiencing VM sprawl, with many unmanaged virtual machines running in the environment. Which of the following is the most significant security risk associated with VM sprawl?
Medium225An e-commerce company runs its web application on a Windows Server 2019 with IIS 10. The security team runs a vulnerability scan and discovers that the server supports TLS 1.0 and several CBC-mode cipher suites, which are prohibited by the company's security policy. The policy requires disabling all versions of TLS below 1.2 and all cipher suites that do not use GCM mode. The administrator needs to implement the required changes without affecting the application's functionality, as it still needs to support a small number of legacy clients that require TLS 1.2 but not CBC. Which action should the administrator take?
Easy226A company uses a backup strategy that backs up all data every Sunday and backs up only data that has changed since the last full backup on other days. This is an example of which backup type?
Medium227Which TWO actions are part of the containment phase of incident response?
Medium228A security analyst is reviewing access controls for a database server. The database administrator has granted all users in the 'sales' role SELECT, INSERT, UPDATE, and DELETE permissions on the 'orders' table. Which access control principle is being violated?
Medium229A security administrator is selecting security metrics for the organization. Which TWO metrics are most useful for measuring the effectiveness of patching? (Select TWO)
Medium230Which THREE of the following are valid methods for authenticating users in a web application? (Choose three.)
Medium231A company is designing a network with multiple security zones. Which TWO of the following are best practices for network segmentation? (Select TWO)
Medium232Which of the following is the correct order of steps in the change management process?
Easy233During which phase of the NIST SP 800-61 incident response lifecycle are lessons learned meetings conducted and metrics such as MTTD and MTTR tracked?
Easy234A large e-commerce company has a disaster recovery (DR) plan that requires Recovery Time Objective (RTO) of 4 hours and Recovery Point Objective (RPO) of 1 hour for its customer database. The database runs on a clustered SQL server with synchronous replication to a standby server in a different data center. During a recent test, the IT team found that failover took 3 hours, but due to a replication lag of 45 minutes, some transactions were lost. The team needs to meet both RTO and RPO. Which of the following changes should the team implement FIRST?
Hard235A company is implementing a PKI for internal use. What is the primary purpose of a Certificate Revocation List (CRL)?
Medium236A security analyst is reviewing vulnerability scan results and finds a critical vulnerability on a web server. The patch is available but requires a reboot. What should the analyst do first?
Easy237A small business uses a single Windows Server 2016 machine that also acts as a domain controller, file server, and runs a custom application for inventory management. The server recently exhibited slow performance and frequent crashes. The system administrator runs antivirus and finds no malware. The event log shows several 'Event ID 7000' errors from the Service Control Manager, indicating certain services failed to start. The administrator also notices that the server has not been restarted in 180 days and has several pending updates. What is the most likely cause of the performance issues?
Easy238A security architect is reviewing cloud security for a SaaS application used by the company. According to the shared responsibility model, which security controls are PRIMARILY the customer's responsibility?
Hard239A security analyst is reviewing logs and notices that an application log shows an error message indicating 'unhandled exception' followed by a stack trace. This log is most likely categorized as which type?
Easy240A security analyst reviews the TLS configuration of a web server and notices that the cipher suite TLS_RSA_WITH_AES_128_CBC_SHA is enabled. The analyst recommends disabling RSA key exchange and enabling ECDHE. Which security property does ECDHE provide that RSA key exchange lacks?
Medium241Which TWO of the following are key components of the risk identification process?
Easy242Which THREE are effective controls against internal network threats?
Medium243A system administrator notices a high number of half-open TCP connections to the company's web server. The server is becoming unresponsive. Which attack is likely occurring, and which mitigation is effective?
Medium244During a code review, you discover that an application stores passwords in plaintext. What is the most secure remediation?
Hard245An organization has suffered a sophisticated attack where the attacker compromised a domain controller and used it to move laterally to several file servers. The incident response team has isolated the domain controller and some file servers, but they suspect that the attacker may have created hidden accounts and modified permissions to maintain access. The team needs to ensure that the attacker's access is entirely removed before restoring operations. The organization has a large number of users and complex Active Directory structure. The incident response plan outlines containment, eradication, recovery, and post-incident analysis. The team has forensic imaging of the domain controller and file servers. What is the MOST comprehensive approach to eradicate the attacker's presence?
Hard246A small business with 20 employees uses a legacy customer relationship management (CRM) application that supports only RC4 encryption for data transmission between the client and server. The company must comply with a new industry regulation that mandates the use of strong encryption (e.g., AES or TLS 1.2+). The IT manager has attempted to upgrade the CRM application, but the vendor has discontinued support and no updates are available. The company cannot afford to replace the CRM immediately, but must achieve compliance within 60 days. The network consists of a single Windows Server 2016 running the CRM server application and 20 Windows 10 workstations. All systems are on a flat internal network. The IT manager proposes several options. Which action is the most appropriate to achieve compliance?
Easy247A company runs containerized applications in a Kubernetes cluster. They need to ensure that containers run with the least privilege and cannot escalate privileges. Which configuration change is MOST effective?
Hard248You are the security analyst at a mid-sized retail company with 500 employees. The company recently experienced a ransomware attack that encrypted files on a file server. The infection was traced to a phishing email opened by an employee in accounting. The company has antivirus software, a firewall, and daily backups. After the incident, management wants to improve risk identification to prevent future attacks. Which of the following is the MOST effective first step to improve risk identification?
Easy249Refer to the exhibit. A user reports being unable to remote desktop (RDP) into a Windows server. Given the event log, what is the most likely cause?
Medium250You are the incident response lead for a medium-sized financial services company. The company uses a hybrid infrastructure with on-premises servers (Active Directory, file shares, and a SQL database) and cloud services (Office 365, Azure VMs). At 2:00 PM on a Tuesday, the helpdesk receives multiple calls that users cannot access the file shares. Simultaneously, the SOC alerts on unusual outbound traffic from the domain controller (DC) to an external IP on port 443. The DC is also running a scheduled antivirus scan. The file server (FS) shows no signs of compromise but is responding slowly. The backup system reports that last night's backup of the DC failed due to a 'volume shadow copy error'. The backup of the FS succeeded. You need to take immediate action. What should you do FIRST?
Hard251Drag and drop the steps for setting up a certificate authority (CA) in Windows Server into the correct order.
Medium252During a risk assessment, a bank identifies the following threats: flood, phishing attack, hardware failure, and power outage. Which TWO of these are considered environmental threat sources?
Medium253An organization decides to outsource its data center operations to a cloud provider. The cloud provider is responsible for physical security and hardware maintenance. This is an example of which risk response strategy?
Medium254A company implements a policy that requires all employees to change their passwords every 60 days. Which of the following is the PRIMARY security benefit of this requirement?
Easy255During a post-implementation review of a change, it is discovered that the change introduced a configuration deviation from the baseline. The deviation was not detected during testing. What is the BEST way to prevent this in the future?
Hard256Which protocol is used for secure web browsing and operates on TCP port 443?
Easy257A security analyst discovers that an attacker has set up a fake wireless access point with the same SSID as the corporate network. Users are unknowingly connecting to it. What is this attack called?
Medium258An organization is moving away from legacy encryption and wants to avoid stream ciphers due to known vulnerabilities. Which of the following algorithms should be avoided because it is a stream cipher with known weaknesses like the BEAST attack?
Medium259A company is conducting a disaster recovery test. Which TWO types of tests involve minimal risk to production operations?
Medium260Which TWO of the following are key components of an organization's security policy framework? (Choose two.)
Medium261A government agency requires all employees to use smart cards for network access. The security team notices a pattern of failed authentication attempts from a specific building after hours. The attempts occur every night at 2:00 AM for about 10 minutes. The building has a badge reader at the entrance. The team suspects an attacker is trying to brute-force smart card PINs. However, the building's door logs show no entry at that time. Which of the following should the security team do FIRST to identify the risk?
Medium262A security administrator needs to store sensitive customer data in a database. To protect the data at rest, which encryption method should be used?
Easy263In a forensic investigation, a hash of a suspect file is computed. Which of the following is the primary purpose of hashing in this context?
Medium264A company is migrating to the cloud and wants to understand the shared responsibility model. For an IaaS deployment, which THREE are customer responsibilities? (Select THREE.)
Medium265An organization is developing its incident response plan. According to NIST SP 800-61, which phase should include establishing a communication plan, acquiring necessary tools, and conducting exercises?
Easy266A company is implementing a new access control system for its data center. Which physical security control is best for preventing tailgating?
Medium267Refer to the exhibit. A security analyst reviews the log and determines that the system was under a brute force attack. However, the analyst notices that the attack stopped after 5 minutes, and the IP address was not blocked. Which of the following is the MOST likely reason the attack stopped?
Hard268A developer wants to ensure that a web application is protected against cross-site request forgery (CSRF). Which mitigation technique is most commonly recommended?
Medium269A company is selecting a disaster recovery site for its critical applications. Which THREE characteristics differentiate a warm site from a cold site? (Select three.)
Hard270An organization wants to ensure that a software update has not been tampered with during download. Which cryptographic technique should be used?
Easy271A security analyst notices repeated failed login attempts from a single IP address on the VPN gateway. The analyst adjusts the threshold for account lockout and enables geo-ip blocking. This activity is part of which risk management process?
Easy272What is the primary purpose of establishing a chain of custody for digital evidence?
Easy273A network administrator configured the above port security on an access port connected to a VoIP phone and a PC. A third device is connected to the phone's passthrough port. What will happen when the third device attempts to communicate?
Medium274Based on the exhibit, which of the following best describes the firewall configuration?
Hard275Which THREE of the following are data loss prevention (DLP) controls that can be implemented to protect sensitive data?
Easy276Which TWO of the following are key components of a Security Information and Event Management (SIEM) system? (Select two.)
Medium277A company's incident response plan includes a step to preserve evidence. Which action BEST ensures the integrity of forensic evidence?
Easy278A company uses AWS for critical workloads. An analyst notices unauthorized API calls from an IP address outside the company. The logs show that the attacker used stolen access keys belonging to an IAM user with administrative privileges. The incident response team must contain the breach as quickly as possible. The analyst has access to the AWS Management Console and can use the CLI. The team is following the incident response plan. Which action should be taken FIRST to prevent further unauthorized actions?
Medium279A biometric system has a high false rejection rate (FRR). Which of the following is a likely consequence?
Medium280Drag and drop the steps for properly disposing of a hard drive containing sensitive data into the correct order.
Medium281During a security audit, it is discovered that a service account has been used to log in interactively to a server. The account was originally provisioned only for running a background service. Which PAM (Privileged Access Management) control would best prevent such misuse in the future?
Hard282A security analyst is investigating a potential data exfiltration incident. The logs show a large number of outbound DNS queries to a domain that resolves to an IP address in a foreign country. The queries contain encoded strings in the subdomain. Which type of attack is MOST likely occurring?
Hard283A company is implementing a new file-sharing application for employees. Which of the following is the most important security control to prevent unauthorized access to shared files?
Easy284A security analyst is evaluating the cryptographic settings for a new application that requires both confidentiality and integrity for data in transit. The analyst needs to choose a symmetric cipher that provides authenticated encryption. Which of the following is the best choice?
Medium285A security analyst is reviewing the configuration of an enterprise wireless network. Which TWO of the following are best practices for securing the wireless network against unauthorized access and eavesdropping?
Medium286Refer to the exhibit. An organization's incident response policy defines these actions. In what sequence should these phases be applied?
Hard287A security administrator is hardening a wireless network. Which TWO of the following should be avoided due to known vulnerabilities?
Medium288In X.509 certificate format, which field is used to specify the fully qualified domain name(s) for which the certificate is valid?
Medium289An organization is designing a secure email system using S/MIME. Which of the following are essential components of the PKI that must be in place? (Select THREE)
Hard290Drag and drop the steps for conducting a security incident response under the NIST framework into the correct order.
Medium291A company is implementing a VPN for remote employees. The security policy requires that all traffic from the remote device to the corporate network be encrypted, but internet-bound traffic should go directly to the internet. Which VPN configuration should be used?
Medium292A financial institution uses a risk management framework based on ISO 31000. During a quarterly risk review, the risk manager identifies that the residual risk for a critical trading application remains high despite multiple controls. The application's risk score has not decreased after implementing two-factor authentication and encryption. The risk appetite statement says 'no high residual risk for systems processing transactions over $10M.' What should the risk manager do next?
Medium293An organization allows employees to use personal smartphones to access corporate email and data. Which control is MOST important to protect corporate data if a device is lost or stolen?
Medium294Refer to the exhibit. A network administrator is reviewing the VPN configuration on a site-to-site VPN hub. Which of the following is the most significant security vulnerability in this configuration?
Hard295An organization is setting up a site-to-site VPN between two branch offices. They require encryption of the entire IP packet, including the original IP header, and plan to use IPsec. Which mode should they configure?
Hard296After an incident, what is the primary purpose of a lessons learned meeting?
Easy297Which type of disaster recovery test involves running the DR systems alongside the production systems to validate functionality without impacting live operations?
Medium298Refer to the exhibit. The analyst sees this IDS alert. What is the most likely outcome if the target web application is vulnerable?
Medium299A security metric tracking the percentage of systems with critical patches applied within 48 hours is an example of which type of metric?
Medium300An organization is deploying a network-based intrusion detection system (NIDS). The security team must decide on placement and configuration. Which THREE considerations are critical for effective NIDS deployment?
Hard301Which term describes the process of verifying the identity of a user, system, or entity?
Easy302An organization's security policy requires that all portable media containing sensitive data be encrypted. Which type of control does this requirement represent?
Medium303To prevent VM escape attacks in a virtualized environment, which of the following is the most critical security measure?
Medium304Which UDP port is used by the Dynamic Host Configuration Protocol (DHCP) for server communication?
Easy305A security analyst is reviewing a digital signature implementation. The signer uses their private key to encrypt the hash of a message. What does the recipient use to verify the signature?
Medium306An organization implements a new security policy requiring all portable storage devices to be encrypted. Which of the following is the MOST effective control to enforce this policy?
Easy307A company's incident response plan includes a requirement to notify law enforcement within 24 hours of certain security incidents. Which regulation most likely mandates this requirement?
Hard308A security analyst sees the event log exhibit. What does this indicate?
Medium309A company wants to implement a security baseline for its Windows servers. Which of the following frameworks is most commonly used for this purpose?
Medium310An organization is implementing a secure software development lifecycle (SDLC). Which activity should be performed during the design phase to minimize security flaws?
Medium311You are a risk analyst at a healthcare organization. The organization recently deployed a new electronic health records (EHR) system. During the first month of operation, the IT helpdesk received multiple reports from doctors that the system becomes unresponsive for 10-15 seconds several times a day. The EHR vendor attributes this to insufficient database connection pooling, but the organization's system administrator notes that the database server's CPU and memory utilization never exceed 30%. The organization has a risk management policy that requires any system with availability <99.5% to be treated as a high risk. Based on initial data, the system has been unavailable for about 0.1% of the time (excluding planned maintenance). However, doctors report that the brief unresponsiveness is causing frustration and potential misdiagnosis due to interrupted workflows. You need to recommend a risk treatment approach. What should you do?
Medium312Which of the following is a technical threat source that could lead to a security breach?
Easy313A security auditor reviews a system that uses HMAC-SHA256 for message authentication. Which property does HMAC provide that a simple hash of the message does not?
Hard314A security engineer is hardening a Windows server. Which TWO actions should be taken to reduce the attack surface? (Select TWO.)
Medium315A system administrator needs to ensure that a Linux server is hardened against common attacks. Which configuration change is MOST effective in preventing privilege escalation via SUID binaries?
Medium316Which physical security control is designed to prevent tailgating by allowing only one person to enter at a time?
Easy317Which THREE of the following are examples of detective controls?
Medium318A company has deployed an intrusion detection system (IDS) that generates numerous false positives. Which approach would best reduce false positives while maintaining detection capability?
Medium319An organization's security policy requires that all data at rest be encrypted. A database administrator objects, stating that encryption will degrade performance. What is the best response?
Medium320A security analyst is configuring a SIEM to detect potential insider threats. Which TWO of the following data sources would be most relevant for detecting an employee exfiltrating sensitive data via email?
Medium321Refer to the exhibit. A security administrator notices repeated events with the same failure reason for the Administrator account. What is the MOST likely type of attack?
Easy322During a security assessment, it is discovered that a Linux server has unnecessary services running, including Telnet and FTP. The server is also missing critical security patches. Which of the following is the MOST effective approach to harden this server according to industry best practices?
Medium323In Linux, which command is used to change file permissions to restrict access so that only the owner can read and write, and the group and others have no access?
Easy324Which access control model enforces the principle of least privilege by granting permissions based on job functions and requires separation of duties?
Easy325Which two of the following measures ensure the integrity of backup data? (Choose two.)
Easy326Refer to the exhibit. A web server log shows two requests from the same IP. What type of attack is being attempted, and which mitigation is MOST effective?
Hard327Which TWO components are essential for an effective disaster recovery plan (DRP)?
Easy328An organization uses a mantrap at its main entrance. An employee badges in, enters the first door, but then the second door fails to open. What should the employee do?
Hard329Which TWO of the following are common weaknesses in cryptographic implementations that an SSCP should be aware of? (Select exactly 2.)
Easy330Drag and drop the steps for implementing mandatory access control (MAC) using security labels into the correct order.
Medium331Which of the following OWASP Top 10 vulnerabilities involves an attacker sending malicious data to an interpreter as part of a command or query?
Easy332Given the exhibit, what is the most likely conclusion?
Medium333Which of the following is a key advantage of using a behavior-based detection approach in a User and Entity Behavior Analytics (UEBA) system?
Medium334A cloud application uses OAuth 2.0 to authorize a third-party app to access user data. What is the primary purpose of the access token issued by the authorization server?
Medium335A security administrator needs to implement an access control model that grants access based on attributes of the user, resource, and environment, using policy rules. Which model is most appropriate?
Medium336During a vulnerability scan, a security team discovers that several virtual machine snapshots contain outdated software with known vulnerabilities. Which risk is most directly associated with this scenario?
Hard337Which of the following is a common method for implementing multi-factor authentication (MFA) using something you have and something you know?
Easy338A security analyst needs to verify that a downloaded file has not been tampered with. The publisher provides a SHA-256 hash. Which property of the hash function is being relied upon?
Easy339Which TWO of the following are key components of a configuration management database (CMDB)? (Select TWO)
Medium340During an incident response, a forensic analyst captures a memory dump from a compromised server. Which of the following is the MOST important step to ensure the integrity of the evidence?
Hard341Which of the following best describes the purpose of a Hardware Security Module (HSM) in key management?
Medium342A security administrator is designing physical security for a high-security area. Which TWO controls are most effective for preventing unauthorized entry? (Select TWO)
Easy343A system administrator needs to grant a temporary contractor access to a specific shared folder for two weeks. Which access control approach is most appropriate?
Easy344In the Bell-LaPadula model, which property prevents a subject from reading an object at a higher classification level?
Medium345A company uses a cloud storage service that encrypts files with a key derived from the user's password (e.g., using PBKDF2). The security team recommends migrating to a separate key management service (KMS) that generates and manages encryption keys independently of user passwords. What is the most critical security advantage of using a KMS in this scenario?
Hard346Refer to the exhibit. The firewall rule is attached to a database server. Which hosts can connect to the database?
Hard347An organization is hardening a Linux server. Which TWO of the following are effective steps to reduce the attack surface?
Medium348Which TWO of the following are examples of administrative controls in a security program? (Choose two.)
Easy349A network has multiple VLANs with an IDS deployed on the core switch using SPAN ports. The IDS is missing some packets during high traffic periods. What is the best course of action to improve packet capture reliability?
Hard350A company is implementing a change management process. Which THREE elements are essential for every change request? (Select THREE)
Medium351A security analyst is investigating an account compromise. The organization uses Kerberos for single sign-on. Which TWO of the following would help in tracking the source of the compromise?
Hard352Refer to the exhibit. What security issue is present in this firewall policy?
Hard353Which TWO of the following are valid reasons for implementing a separation of duties policy? (Choose two.)
Medium354A company deploys a web application that handles sensitive financial transactions. To protect data in transit, which protocol should be used?
Medium355An organization wants to implement multi-factor authentication (MFA) for remote access. Which combination represents something you have and something you are?
Medium356A cloud security team is implementing a Cloud Security Posture Management (CSPM) tool. What is the primary purpose of a CSPM solution?
Medium357An organization is implementing a new remote access VPN for employees using IPsec. Which TWO of the following are best practices for securing the IPsec VPN?
Medium358A security analyst notices that a user’s account has been used to access sensitive files at 3:00 AM from an IP address outside the company’s country. The analyst suspects a compromised account. Which action should be taken FIRST?
Medium359During a vulnerability scan, a critical vulnerability is found on a publicly accessible web server. The server hosts a legacy application that cannot be patched immediately. What should the risk manager do first?
Medium360During the detection and analysis phase, an analyst classifies an incident as P1 (critical) because it involves a breach of sensitive customer data. What is the IMMEDIATE next step the analyst should take?
Easy361A security analyst is responding to a malware incident on a Windows server. Which TWO actions should be taken to properly collect volatile evidence?
Medium362A company is migrating from WPA2-PSK to WPA3 for its wireless network. Which THREE benefits does WPA3 provide compared to WPA2?
Medium363Refer to the exhibit. An administrator applies this ACL to the external interface. What specific traffic is blocked?
Medium364Which of the following wireless security protocols uses AES-CCMP and is based on the 802.11i standard?
Easy365A security analyst detects unusual outbound traffic from a server to a known malicious IP. The server is running a critical business application. What should the analyst do FIRST?
Medium366An organization is redesigning its DMZ to host a public web server and an internal file server. Which architecture provides the strongest security?
Medium367Drag and drop the steps for establishing a VPN using IPsec in tunnel mode into the correct order.
Medium368A security awareness training program is being developed. Which topic is most important to include to reduce the risk of credential theft?
Easy369An organization is implementing a software inventory management process. Which TWO of the following should be tracked for each software asset?
Medium370Which DR testing type involves running recovery systems in parallel with production systems to verify functionality without impacting live operations?
Easy371A security engineer is designing a network segmentation strategy to isolate a DMZ containing public-facing web servers from the internal corporate network. Which TWO controls should be implemented? (Select two)
Hard372Which wireless security standard replaces WPA2 and mandates Protected Management Frames (PMF) to prevent certain types of attacks?
Easy373After a ransomware attack, the recovery team restored systems from backups. However, some files remain encrypted. What is the most probable cause?
Hard374Which of the following hash algorithms is considered cryptographically broken and should be avoided due to collision attacks?
Easy375A system administrator notices that a server's certificate was issued by a CA that is not in the trusted root store of client machines. What is the most likely impact on clients connecting via TLS?
Hard376In an OAuth 2.0 authorization flow, a client application receives an access token. This token is used to:
Hard377A security auditor is reviewing the cryptographic algorithms used in an organization. Which THREE of the following are considered insecure or deprecated and should be avoided? (Select THREE.)
Hard378A company is migrating to a PaaS cloud environment. According to the shared responsibility model, which THREE security responsibilities remain with the customer? (Select THREE.)
Hard379A company wants to secure wireless communication for guests. Which protocol provides the strongest encryption for a wireless network?
Easy380In a biometric system, the point at which the false rejection rate (FRR) equals the false acceptance rate (FAR) is known as the:
Hard381Which TWO of the following are examples of administrative controls? (Choose two.)
Easy382Which THREE of the following are common use cases for public key infrastructure (PKI)? (Select exactly three.)
Hard383Which TWO of the following are required properties of a cryptographically secure hash function? (Select exactly 2.)
Medium384Refer to the exhibit. What is the effect of this access control list on traffic entering the interface?
Easy385A company is migrating its on-premises applications to a public cloud. Which security control is MOST important to implement to protect data in transit?
Easy386A company wants to ensure that employees use strong passwords. Which policy is most effective?
Easy387During a security audit, it is discovered that a system administrator shared their personal credentials with a colleague to troubleshoot an issue after hours. This violates the company's policy regarding password sharing. Which control would BEST prevent this type of incident in the future?
Hard388A security administrator is drafting an acceptable use policy (AUP). Which of the following should be included to address the use of personal devices for work purposes?
Easy389A security engineer is reviewing system logs and notices that the log file size has not changed for several days, despite high system activity. Which log management concern does this indicate?
Medium390Based on the exhibit, which conclusion is most likely?
Medium391An organization wants to ensure that servers are configured securely before deployment. They plan to use a hardened operating system image and regularly scan for deviations using SCAP. Which concept does this represent?
Hard392A network administrator wants to block all inbound traffic except for web and email services. Which firewall rule configuration would achieve this?
Medium393After implementing security controls, a risk assessment shows that a residual risk of data exfiltration remains. Which document should formally record this residual risk and the decision to accept it?
Medium394In the context of risk assessment, which of the following best describes a vulnerability?
Easy395Match each network security device to its function.
Medium396A SOC analyst reviews an alert for a user who downloaded a large amount of data from a sensitive database at 3:00 AM. The user's manager confirms the user was not on call. Which type of risk indicator is this activity best described as?
Hard397A Linux administrator is hardening a server. Which TWO commands are used to manage file permissions? (Select TWO.)
Easy398A security analyst is evaluating a biometric system. The system currently has a high number of false rejections. Which metric is most directly related to this issue?
Medium399Which THREE of the following are examples of security awareness training topics?
Easy400An organization wants to ensure that all new servers are deployed with a hardened baseline configuration. Which of the following is the most effective control to enforce this?
Hard401A network administrator wants to prevent unauthorized devices from connecting to the wired network. Which technology can be used to enforce authentication at the switch port level before granting network access?
Medium402Match each security policy type to its purpose.
Medium403Which access control model enforces security based on classification labels assigned to subjects and objects, commonly used for confidentiality?
Easy404In Role-Based Access Control (RBAC), what is the purpose of role hierarchy?
Medium405Refer to the exhibit. A security analyst observes this event on a workstation. What is the MOST likely explanation?
Medium406Which of the following is a vulnerability source explicitly based on publicly known flaws?
Easy407A company is implementing a new patch management process. After scanning for missing patches, the team must prioritize which patches to apply first. Which combination of factors is most critical for prioritization?
Hard408An organization implements a policy requiring passwords to be at least 12 characters, include uppercase, lowercase, digits, and special characters, and be changed every 60 days. Which password policy elements are being enforced?
Medium409A security analyst reviews the syslog message from a router. What does this log entry indicate?
Hard410A company is deploying a VPN for remote employees. They require strong encryption and authentication, and the solution must be compatible with native OS clients without additional software. Which VPN protocol is most appropriate?
Medium411A security administrator is configuring a firewall to allow HTTPS traffic from the internet to a web server. Which default port must be permitted?
Easy412A network administrator needs to ensure that internal users can access only approved external websites. Which technology should be implemented?
Medium413Drag and drop the steps for implementing a patch management process into the correct order.
Medium414A help desk technician receives multiple reports that users cannot access a critical web application. The application's error log shows repeated '403 Forbidden' errors. Which of the following is the most likely cause?
Easy415Which two components are integral to a Kerberos authentication system? (Select TWO)
Medium416An organization implements an attribute-based access control (ABAC) system with the following policy: if user.role == 'doctor' and resource.type == 'patient_record' and environment.time between 08:00-18:00 then permit. A doctor tries to access a patient record at 20:00. What is the result?
Hard417What is the analyst's BEST next step?
Hard418Which THREE of the following are common techniques for identifying risks?
Hard419A Linux server administrator configures SSH key-based authentication for user 'admin'. The authentication fails with the error 'Authentication refused: bad permissions' in the logs. What is the most likely cause?
Hard420Which THREE of the following are key elements of a security incident response plan?
Hard421Which of the following is a primary function of a firewall?
Easy422A small financial services company has deployed a SIEM solution collecting logs from their firewall, web server, and domain controller. They also have an IDS monitoring the network perimeter. The security analyst receives an alert from the IDS indicating a potential exploit attempt against the web server from an external IP. The analyst checks the SIEM and sees that the firewall log shows the connection was allowed, but the web server log does not show any corresponding request. The domain controller logs show no abnormal activity. The company has a policy to immediately contain any confirmed threats. What should the analyst do first based on this information?
Easy423During a change management process, the Change Advisory Board (CAB) approves a high-risk change. What is the NEXT step according to standard change management?
Hard424Which backup strategy is MOST suitable for a server with an RTO of 4 hours and an RPO of 15 minutes?
Easy425A security administrator is configuring password policies to meet compliance. Which combination of settings provides the strongest protection against brute-force attacks?
Medium426A security administrator needs to ensure that all servers are configured with a hardened baseline. Which tool is best suited to detect deviations from the baseline configuration?
Medium427During a security incident, the IR team collects memory dumps from an infected workstation. The analysis reveals a process injecting code into 'svchost.exe'. Which technique is most likely being used?
Hard428An analyst detects suspicious outbound traffic from a workstation to a known command-and-control IP. Which IoC blocking method is MOST appropriate as an immediate containment measure?
Medium429Which TWO of the following are effective measures to prevent cross-site scripting (XSS) vulnerabilities in a web application?
Medium430Which THREE of the following are common indicators of a cross-site scripting (XSS) attack? (Choose three.)
Hard431Which of the following backup methods copies all data that has changed since the last full backup, regardless of any intermediate backups?
Easy432Refer to the exhibit. What does this event indicate?
Easy433An organization wants to implement a centralized authentication system that supports single sign-on and uses tickets. Which technology should they choose?
Hard434A security administrator is configuring a new system and wants to enforce a mandatory access control model to ensure confidentiality of classified data. Which access control model should the administrator implement?
Medium435What is the default port for Microsoft SQL Server?
Easy436During a malware containment operation, the incident response team decides to isolate an infected endpoint using network access controls. However, the malware is spreading via removable media. Which additional containment measure should the team implement?
Hard437A security analyst is reviewing logs and sees an alert for a known malware signature on an endpoint. Upon investigation, the file is identified as a false positive. What should the analyst do next?
Hard438A security analyst is reviewing Linux server logs after a suspected breach. Which auditing tool should be used to examine detailed records of system calls and file access events?
Medium439A security analyst notices repeated failed login attempts from a single IP address within a short time window. Which control should be implemented to automatically mitigate this behavior?
Easy440A security engineer needs to choose an asymmetric algorithm for a system with limited computational resources, such as an IoT device. The algorithm must provide equivalent security to RSA 2048-bit while using smaller key sizes. Which algorithm should they choose?
Medium441A company's security policy requires that all logs be stored in a write-once, read-many (WORM) format. What is the primary security objective of this requirement?
Medium442To determine how malware initially infected a workstation, which artifact would be MOST useful?
Hard443A security analyst needs to ensure that a legacy application running on an unsupported operating system remains secure until it can be replaced. Which strategy provides the most effective risk reduction?
Medium444Drag and drop the steps for performing a risk assessment according to NIST SP 800-30 into the correct order.
Medium445A network security team is implementing a defense-in-depth strategy. Which three layers should be included? (Choose three.)
Hard446A company's backup strategy uses a full backup on Sundays and differential backups on other days. On Thursday, the storage system fails. How many backups are required to restore the data?
Hard447Refer to the exhibit. A network engineer is configuring a site-to-site VPN. The remote peer is using AES-256 encryption and SHA-1 for integrity. Which configuration parameter is likely misconfigured?
Hard448An organization uses attribute-based access control (ABAC) for its cloud storage. The policy states that a user can read a document only if the user’s department attribute matches the document’s department attribute AND the current time is within business hours (9AM-5PM). A user from Engineering tries to read a document classified for Engineering at 8:55 AM. What is the expected result?
Hard449Which of the following is the PRIMARY purpose of establishing a chain of custody when handling digital evidence?
Medium450A company wants to prevent unauthorized applications from running on employee workstations. Which of the following is the most effective control?
Easy451Which THREE of the following are common methods for identifying risks? (Select three.)
Easy452A company's disaster recovery plan includes offsite tape backups. During a test, it is discovered that the tapes are stored at a location that shares the same power grid as the primary site. Which risk does this pose?
Medium453An organization uses a network-based intrusion detection system (NIDS). An analyst receives an alert for a known exploit signature. Which type of detection is the NIDS using?
Medium454An organization wants to ensure that privileged accounts are used only when needed and that all activities are recorded. Which Privileged Access Management (PAM) control should be implemented?
Medium455A company uses Infrastructure as a Service (IaaS) for its production workloads. According to the shared responsibility model, which of the following security tasks is the customer responsible for?
Hard456During a security audit, an analyst finds that a server's audit log shows repeated failed login attempts from a single IP, followed by a successful login from the same IP five minutes later. What is the most likely type of attack that occurred?
Hard457An administrator reports that a TLS handshake fails between a web server and client. The server supports TLS 1.2 with ciphers ECDHE-RSA-AES128-GCM-SHA256 and RSA-AES256-CBC-SHA256. The client supports only TLS 1.0 with ciphers RSA-RC4-SHA and RSA-AES128-SHA. What is the most likely cause?
Medium458A company's internal network uses a /24 subnet and has a single firewall connecting to the internet. Employees report that they cannot access an external web server at 203.0.113.50. The firewall has a rule that allows outbound HTTP. What is the most likely cause?
Medium459Which of the following is the primary purpose of a security awareness program?
Easy460An organization uses VMware ESXi in a production environment. Which of the following is the most effective mitigation against VM escape attacks?
Hard461Which TWO are security implications of using deprecated cryptographic protocols such as SSL 3.0 and TLS 1.0?
Hard462Which of the following is a primary security concern when using VM snapshots in a virtualized environment?
Easy463A company uses digital signatures to ensure the integrity and non-repudiation of internal contracts. The private key used for signing is stored in a hardware security module (HSM). A junior administrator asks why the HSM is necessary. What is the primary reason?
Easy464After a security incident, the CSIRT is conducting lessons learned. Which output is most directly used to update the risk management process?
Medium465In a qualitative risk analysis, a risk is assigned a probability of 'High' and an impact of 'Medium'. According to common probability/impact matrices, what is the overall risk rating?
Easy466What is the primary risk associated with service accounts in an enterprise?
Medium467Which attack exploits the lack of IV (Initialization Vector) randomness in the RC4 algorithm to recover the Wi-Fi password, and is considered completely broken?
Hard468A security auditor is reviewing the account lifecycle process. Which TWO of the following are mandatory steps during the deprovisioning (offboarding) process?
Hard469A security engineer is hardening a Linux server. Which TWO actions are recommended to reduce the attack surface? (Select TWO.)
Medium470Based on the exhibit, which security threat is likely being attempted?
Medium471Which TWO of the following are symmetric encryption algorithms? (Select exactly two.)
Medium472A security analyst is reviewing logs from a SIEM and notices multiple failed login attempts for a privileged account from an IP address in a foreign country, followed by a successful login after hours. Which type of security monitoring tool would be most effective at detecting this pattern as anomalous behavior based on user baseline?
Medium473A small business wants to identify vulnerabilities in its network. Which type of scan should they perform first to get an overview?
Easy474A security team discovers that a legacy system uses ECB mode to encrypt credit card numbers. What is the primary security concern with this mode?
Medium475A company uses a federated identity system where partner employees access internal applications via SAML assertions. Recently, a partner employee who should have been terminated was still able to log in. Which missing control is the most likely root cause?
Hard476During an audit, it is discovered that a contractor’s account has read access to a financial database even though the contractor’s project ended six months ago. Which type of access control failure is this?
Hard477A security administrator is setting up a public key infrastructure (PKI) for internal use. Which two of the following components are essential for establishing a chain of trust from the root CA to end-entity certificates?
Easy478A company needs to encrypt large volumes of data at rest on a file server. Which type of cryptography is most appropriate for this task?
Easy479An organization is hardening a new Windows server for production use. Which of the following is the most effective method to ensure that only approved applications can run?
Easy480Which access control model is best suited for a military environment where data classification (Unclassified, Confidential, Secret, Top Secret) and subject clearance levels are the primary factors for access decisions?
Easy481A help desk technician needs to reset a user's password but should not be able to modify other user attributes. Which access control principle should be applied to enforce this restriction?
Easy482A security administrator needs to choose an encryption algorithm for a high-speed network where data is encrypted at the link layer. Which algorithm is most appropriate?
Medium483A security analyst is hardening a new Windows server. Which configuration would MOST effectively reduce the attack surface by limiting the software that can execute?
Easy484A security engineer is evaluating cloud security tools. Which TWO of the following are primarily used to protect cloud workloads? (Select two.)
Hard485During a security incident, the IR team discovers that an attacker used a valid user account to access sensitive data. The account had multifactor authentication (MFA) enabled. Which attack technique most likely bypassed the MFA?
Hard486Which of the following is a characteristic of TLS 1.3 that improves security over previous versions?
Hard487An organization is hardening its Windows servers. Which built-in Windows feature can be used to enforce application whitelisting, ensuring only approved executables run?
Easy488A security administrator notices that a critical server's event log shows repeated failed login attempts from an internal IP address that normally does not generate any traffic. The administrator immediately blocks the IP at the firewall and resets the account password. However, the incident response team later determines that the attacker had already gained access to the server. What is the MOST likely reason the administrator's actions were insufficient?
Medium489A critical vulnerability with a CVSS score of 9.8 is discovered in a web server that cannot be patched due to vendor dependency. What is the best compensating control?
Hard490Refer to the exhibit. What is the purpose of the 'group 14' parameter in the IKEv2 proposal?
Medium491An attacker sends a large number of DHCP request messages with spoofed MAC addresses to a network's DHCP server, causing the server to exhaust its IP address pool and deny service to legitimate clients. This attack is known as:
Medium492A security analyst receives an alert indicating a large number of failed login attempts from a single IP. The analyst blocks the IP. What should be done next?
Easy493Which THREE of the following are common types of network attacks?
Hard494Refer to the exhibit. A security analyst reviews a Windows Security event log entry showing multiple logon failures for user 'admin' from IP 10.0.0.100 within 5 minutes. What type of attack is most likely occurring?
Medium495A network engineer is troubleshooting a site-to-site VPN that is failing to establish. The pre-shared key is correct and both sides use IKEv2. The VPN logs show 'no proposal chosen'. What is the most likely cause?
Medium496A university's IT department manages a network used by students and faculty. The security team notices an unusual increase in outbound traffic from the student dormitory network during late hours. Upon investigation, they discover that several student laptops are infected with malware that is attempting to connect to external command-and-control (C2) servers. The team needs to contain the incident quickly while minimizing impact on legitimate users. Which of the following is the BEST immediate containment measure?
Easy497Which TWO of the following are effective methods for monitoring risk in real-time?
Medium498A medium-sized e-commerce company uses a SIEM with correlation rules. During peak sales hours, the SIEM generates an alert: multiple failed login attempts from internal IP 172.16.10.50 followed by a successful login to a critical database server. The account used is 'dbadmin', which normally only authenticates from the IT department subnet. The user 'dbadmin' reports that they had to try several passwords because they forgot theirs earlier. The incident responder is under pressure to quickly restore normal operations. Which course of action should the responder take?
Hard499An incident responder is collecting volatile evidence from a compromised Linux server. Which TWO of the following should be collected first? (Select two.)
Medium500Which authentication method generates a one-time password that is valid for only a short time window?
Easy501A PKI administrator needs to check the revocation status of a digital certificate without requiring the client to download the entire CRL. Which method is designed for online, real-time certificate status checking?
Hard502An organization's security team detects a potential data breach. After confirming the incident, they classify it as P2 (high severity) and begin containment. Which action should be performed FIRST to preserve evidence for forensic analysis?
Medium503Which Windows feature allows an administrator to define security policies such as password complexity and account lockout across multiple systems in a domain?
Easy504Based on the exhibit, what type of attack is most likely occurring?
Easy505A company wants to implement a key management system. They need to generate cryptographic keys that are unpredictable. Which source of randomness should be used?
Medium506A security analyst reviews a firewall log showing an internal IP attempting outbound connections to multiple external IPs on port 443. The analyst suspects command and control. Which additional data source would be MOST useful for confirmation?
Hard507You are the security administrator for a mid-sized financial services company. The company uses Active Directory (AD) for identity management and has implemented role-based access control (RBAC) for its core banking application. Recently, the company acquired a smaller firm and is integrating its employees into AD. During the integration, you notice that many of the new employees have been assigned multiple roles that grant them access to sensitive financial data, despite their job descriptions indicating they need only limited access. Additionally, some users who left the acquired company have not been disabled in AD. The company's security policy mandates the principle of least privilege and requires that access reviews be conducted quarterly, but no review has been performed in the past year. You have been tasked with remediating these issues. Which of the following approaches is the MOST effective initial step to address the immediate risk of excessive access?
Hard508An organization wants to ensure that only corporate-managed devices can connect to the internal network. Non-compliant devices should be placed in a restricted VLAN with limited access. Which technology should be deployed?
Medium509Which TWO are valid reasons to revoke a user's access? (Choose two.)
Medium510Which three statements are true regarding mandatory access control (MAC) systems? (Select THREE)
Hard511An organization is restoring a critical database from a backup after a ransomware attack. Which of the following steps should be performed BEFORE restoring the data to ensure the restoration is successful and secure?
Hard512A security analyst reviews firewall logs and sees multiple 'ACL drop' entries for a specific internal IP trying to connect to a database server on port 1433. The rule base has an explicit permit for this traffic. What is the most likely reason for the drops?
Hard513Which THREE steps are essential during the identification phase of incident response?
Hard514Which wireless encryption protocol is currently considered the most secure for home use?
Easy515A security analyst reviews log files and sees multiple failed SSH attempts from various IP addresses. The analyst implements a rate-limiting rule on the firewall to block IPs after 5 failed attempts in 10 minutes. This is an example of which type of security control?
Hard516A financial services firm with 500 servers and 2000 workstations uses an internal public key infrastructure (PKI) for authentication and secure communication. The root CA certificate is self-signed and stored on an offline root CA server. Recently, the root CA server was physically stolen from a locked data center. Although the server was encrypted, forensic analysis confirms that the root CA private key was extracted. The security team must immediately revoke trust in the compromised root CA and issue new certificates to all devices. The environment includes Active Directory and Group Policy. Which approach best ensures all systems trust the new CA hierarchy and obtain valid certificates with minimal disruption?
Medium517During incident response, a team needs to isolate an infected workstation that is part of a critical manufacturing network. Which containment method is MOST appropriate to minimize disruption while preventing the spread of malware?
Medium518After containing a ransomware incident, the incident response team identifies that the attacker gained initial access through a phishing email that installed a backdoor. Which of the following eradication steps is MOST critical to prevent re-infection?
Hard519During a security awareness training session, an employee asks how to identify a phishing email. Which of the following is the most reliable indicator of a phishing attempt?
Medium520Which of the following protocols operates on TCP port 443 and provides encrypted communication between a web browser and a web server?
Easy521An organization uses a hot disaster recovery (DR) site and has a Recovery Time Objective (RTO) of 4 hours. During a DR test, the team discovers that data replication from the primary site fails. Which TWO actions should the team take to meet the RTO while ensuring data integrity? (Choose two.)
Medium522You are the security administrator for a healthcare organization that uses a Windows Active Directory domain. The organization has recently implemented a new electronic health record (EHR) system that requires users to authenticate before accessing patient data. The EHR system uses Kerberos for authentication. Users report that they can access the EHR system from their office workstations, but when they attempt to access it remotely via VPN, they receive an 'Access Denied' error. The VPN uses RADIUS for authentication and assigns IP addresses from a separate subnet. The EHR server is in the same domain as the workstations. You verify that the users are able to connect to the VPN successfully and can access other internal resources. What is the most likely cause of the issue?
Hard523A security auditor discovers that a Linux server has a user who can execute any command as root via sudo without a password. Which file should be reviewed to verify this configuration?
Medium524In a Bell-LaPadula model implementation, a user with a Secret clearance attempts to read a document classified as Top Secret. Additionally, they try to write to a document classified as Unclassified. What are the results of these actions?
Hard525Based on the exhibit, which type of attack is most likely occurring?
Easy526Which of the following is a common defense against ARP spoofing attacks on a local area network?
Easy527During a security assessment, you discover that a Windows server has the Telnet service running. Which of the following is the BEST action to harden the server against this finding?
Easy528An organization wants to deploy a firewall that can inspect the payload of application-layer protocols such as HTTP and FTP, and make access decisions based on application data. Which type of firewall best meets this requirement?
Medium529Which of the following is a secure remote access VPN protocol that uses TLS for encryption and is commonly used with Cisco AnyConnect?
Easy530A security administrator is implementing an access control model that assigns permissions based on the clearance of the subject and the classification of the object. Which model is being implemented?
Easy531A network administrator notices that legitimate clients are unable to obtain IP addresses from the DHCP server. The network logs show a high volume of DHCP Discover messages from different MAC addresses. Which attack is most likely occurring?
Medium532Which TWO are benefits of network segmentation using VLANs? (Choose two.)
Medium533A forensic analyst needs to review security events from multiple Windows servers. To ensure that logs are centrally collected and resistant to tampering, which of the following should be implemented?
Hard534A vulnerability management program requires that critical vulnerabilities be remediated within 72 hours. A scanner identifies a critical vulnerability on a server, but after patching, the scanner still reports it as vulnerable. What is the most likely cause?
Medium535Which access control model allows the owner of a resource to grant access permissions to other users?
Easy536During a virtualized environment security assessment, which THREE of the following are considered risks associated with virtual machine snapshots? (Select three.)
Medium537Which of the following is a key principle of the 3-2-1 backup rule?
Easy538A hospital is implementing an access control system for its electronic health record (EHR) system. The system must comply with HIPAA regulations, which require that access to patient records is limited to personnel who need it to perform their job duties. The hospital has many roles: doctors, nurses, lab technicians, and administrative staff. Each role can access different types of records. The system currently uses a DAC model where each user sets permissions on their own files. However, a recent risk assessment identified that some nurses have been sharing their accounts with each other to access records outside their unit. The hospital wants to implement a more restrictive model that enforces access based on job roles and prevents sharing of accounts. Which access control model should the hospital adopt?
Medium539During a risk assessment, a company identifies that a legacy system cannot be patched due to vendor end-of-life. The system is critical to operations. Which risk response strategy is most appropriate initially?
Medium540Which of the following is the primary purpose of network segmentation?
Easy541Which TWO of the following are effective controls to prevent buffer overflow attacks? (Choose two.)
Medium542During a risk assessment, the team identifies that a critical database server is not included in the backup schedule. Which risk term best describes this condition?
Easy543A company wants to implement a firewall that can track the state of network connections and make decisions based on the context of traffic (e.g., allowing return packets for an established connection). Which type of firewall should they choose?
Medium544Which THREE of the following are key steps in performing a business impact analysis (BIA)?
Hard545The security team discovers that a user in the finance department can read files in the human resources share. The share permissions on the HR folder are set to deny all except the HR group, and the user is not a member of HR. What is the most likely cause?
Medium546An organization wants to implement an access control model where data owners decide who can access resources. Which model should they choose?
Medium547Refer to the exhibit. A security engineer is reviewing an S3 bucket policy. Which risk is most directly introduced by this policy?
Hard548What is the primary purpose of a Privileged Access Management (PAM) solution?
Easy549An alert shows a successful login from an unusual geographic location. Which of the following is the BEST initial response?
Medium550An organization uses smart cards combined with a PIN to access secure facilities. This is an example of which type of authentication factor?
Easy551A company has implemented a new vulnerability scanner and the first scan reports 200 vulnerabilities. The security team needs to prioritize remediation. Which approach should they use first?
Medium552According to the shared responsibility model in cloud computing, which security responsibility belongs to the customer in a SaaS deployment?
Easy553Refer to the exhibit. Which component of the cipher suite provides perfect forward secrecy?
Easy554What is the primary purpose of account deprovisioning?
Easy555A system administrator needs to assign permissions to a new employee who will be performing database backups. The employee should only be able to execute the backup command but not read or modify the data. Which access control principle should be applied?
Easy556A security team is implementing Network Access Control (NAC) to enforce endpoint compliance before granting network access. Which technology allows port-based authentication on wired networks?
Medium557A database administrator notices unusual queries that seem to be trying to extract data via SQL injection. The application uses parameterized queries for most queries, but some dynamic queries are built using string concatenation. What is the BEST remediation?
Medium558A security team uses a risk matrix with likelihood (Low, Medium, High) and impact (Low, Medium, High). A vulnerability scan finds a buffer overflow in a customer-facing web application. The application is not critical but has high availability requirements. The likelihood of exploitation is considered Medium due to internal network segmentation. What is the risk level?
Medium559A small business wants to implement an access control system where employees can access files based on their department (e.g., HR, Finance). They want simplicity and ease of administration. Which access control model is BEST suited?
Easy560A financial services organization deploys a new web application that allows customers to check account balances and transfer funds. The application uses a RESTful API with JSON payloads. Shortly after deployment, the security team notices unusual traffic patterns: many requests contain excessively long JSON strings in the 'amount' field, and some of these requests return 500 Internal Server Errors. The application logs show that these requests cause high CPU usage on the application server. The developers confirm that the input validation only checks for negative numbers and characters. Which type of attack is most likely occurring, and what is the best immediate mitigation?
Hard561Which TWO protocols are used to secure email communication at the message level?
Hard562During a risk assessment, a company identifies that a legacy system has a known CVE with a CVSS score of 9.8. The system is critical but cannot be patched immediately. The management decides to implement strict network segmentation and monitor the system continuously. This risk response is best described as:
Hard563Which of the following encryption protocols should be used to secure wireless traffic in an enterprise environment?
Medium564A security administrator needs to ensure that only authorized personnel can reset user passwords in Active Directory. Which of the following is the BEST method to delegate this responsibility without granting unnecessary privileges?
Medium565During a wireless site survey, a security engineer identifies several security weaknesses. Which TWO measures should be implemented to improve wireless security for a corporate network using WPA2-Enterprise?
Medium566Which of the following is the FIRST step in the volatile evidence collection order when responding to an incident on a live system?
Easy567A software developer wants to ensure the authenticity and integrity of an API request but does not require non-repudiation. Which cryptographic method should be used?
Medium568What is the primary purpose of account deprovisioning in the account lifecycle?
Easy569A network engineer configures a VLAN hopping attack prevention by setting all unused switch ports to an unused VLAN and disabling trunking. What vulnerability is being mitigated?
Hard570During a penetration test, the tester captures traffic on a switch port that is part of a VLAN other than the native VLAN. The tester is able to receive traffic destined for the management VLAN. What configuration flaw is exploited?
Hard571An attacker is performing a man-in-the-middle attack at Layer 2 by sending forged ARP messages to associate their MAC address with the IP address of a legitimate host on the same subnet. This attack is known as:
Medium572A security analyst is reviewing Linux audit logs with auditd. Which TWO events would be of greatest concern for a server that should not have interactive logins? (Select TWO.)
Hard573Which TWO of the following are key components of an incident response plan (IRP) according to NIST SP 800-61?
Medium574Match each authentication factor to its category.
Medium575A company is deploying a web application and wants to protect against OWASP Top 10 attacks. Which THREE controls should be implemented? (Select THREE.)
Hard576During a risk assessment, a team identifies that a legacy application cannot be patched due to vendor end-of-life. The business decides to continue using the application but implement compensating controls such as network segmentation and strict access controls. This risk response strategy is best classified as:
Medium577An organization requires users to authenticate using a password and a one-time code from a mobile app. Which authentication method is being used?
Easy578An organization experiences malware that injects code into legitimate processes. Which security feature should be enabled to prevent code execution in memory pages?
Hard579An organization suspects a security incident. Which initial step should the incident response team take?
Easy580During a qualitative risk analysis, an organization assigns a risk rating of 'High' for a specific threat. Which combination of factors most directly leads to this rating?
Medium581A security engineer is hardening a Windows workstation. Which TWO configurations reduce the attack surface by limiting execution of unauthorized code? (Select TWO.)
Medium582A healthcare organization uses an electronic health records (EHR) system that stores patient data in a relational database. The system is accessed by doctors and nurses via tablet devices on a wireless network. The security team has detected that some patient records were accessed outside of normal business hours from an IP address not belonging to the organization. The database logs show that the queries originated from the application server. The application logs indicate that the access was performed using a legitimate user account that had been disabled due to employee departure two weeks earlier. Which of the following is the most effective step to prevent recurrence?
Medium583Which TWO of the following are effective measures to prevent buffer overflow attacks in software development?
Hard584A security administrator is configuring a wireless network for a branch office. The office has legacy devices that only support WPA2-PSK. The administrator wants to provide the highest level of security while maintaining compatibility. Which configuration should be used?
Hard585Refer to the exhibit. What is the most likely cause of this error?
Hard586An organization is implementing system hardening. Which of the following actions are recommended by CIS Benchmarks? (Select all that apply.)
Medium587Which protocol is used to securely transfer files between a client and server, typically over TCP port 22?
Easy588A security team is investigating a potential data exfiltration incident. They notice that a large amount of data was transferred to an external IP address during off-hours. What should be the first step?
Medium589A security administrator is designing an identity federation solution. Which THREE of the following are commonly used federation standards?
Medium590A network administrator is unable to ping the server at 10.2.2.100 from a host on the 192.168.1.0/24 network. Based on the exhibit, what is the most likely cause?
Medium591A company's vulnerability scanner reports a critical vulnerability in a third-party library. The remediation SLA for critical vulnerabilities is 48 hours. However, the patch is not yet available from the vendor. Which of the following is the most appropriate immediate action?
Medium592A security analyst is reviewing firewall logs and notices a high rate of TCP SYN packets to multiple ports on a server, but no corresponding ACK or RST packets. This is characteristic of which type of attack?
Hard593Which term describes the risk that remains after implementing risk mitigation controls?
Easy594What is the PRIMARY purpose of a lessons learned meeting after an incident?
Easy595Which TWO of the following are types of intrusion detection systems (IDS) based on the detection method?
Medium596A security analyst notices a sudden increase in failed login attempts from a single IP address across multiple user accounts. Which risk response strategy is most appropriate to implement immediately?
Medium597A security administrator is reviewing backup procedures for a database server. The current backup policy mandates a full backup every Sunday and differential backups Tuesday through Friday. On Wednesday, a failure occurs, and the database is lost. The last successful full backup was completed on Sunday, and the last differential backup was completed on Tuesday. How many backup sets are needed to restore the database to its state as of Tuesday?
Medium598A company is implementing single sign-on (SSO) for its internal applications. Which TWO of the following protocols are commonly used for SSO?
Medium599Which THREE of the following are considered cryptographic best practices for key management? (Select exactly 3.)
Hard600Which TWO of the following are examples of key risk indicators (KRIs)?
Easy601An organization is enhancing its backup strategy. According to the 3-2-1 rule, which THREE characteristics must the backup strategy include? (Select THREE)
Hard602An organization is implementing configuration management and wants to detect unauthorized changes to server configurations. Which of the following tools would be most effective for this purpose?
Hard603Which THREE are required components of a core role-based access control (RBAC) system according to NIST? (Choose three.)
Hard604A cloud security team is deploying a new web application on an IaaS platform. According to the shared responsibility model, which of the following security tasks is the customer responsible for?
Hard605A security analyst discovers that an internal DNS server is returning incorrect IP addresses for legitimate domains. The analyst suspects that an attacker has compromised the DNS resolver's cache. Which type of attack has likely occurred?
Hard606Based on the exhibit, if the user attempts to upload (write) a file to the shared data repository corporate-data, what is the result?
Hard607Refer to the exhibit. An analyst sees these logs and is concerned about a potential attack. What is the most likely scenario?
Easy608When implementing a digital signature, which key is used to create the signature?
Easy609After a security incident, the CISO asks for a report detailing which assets were affected, the attack vector, and the financial impact. Which of the following best describes this report?
Easy610During a forensic investigation, a responder must collect evidence from a live Windows system. Which of the following represents the correct order for collecting volatile data?
Hard611An organization wants to implement separation of duties to reduce the risk of fraud. Which THREE of the following are common techniques used to enforce separation of duties?
Medium612A company's security policy requires that employees must change their passwords every 60 days. However, help desk tickets show that many users are locked out after forgetting their new passwords. Which of the following would BEST balance security and usability?
Medium613A security analyst is evaluating encryption modes for a new system that requires authenticated encryption to ensure both confidentiality and integrity of data in transit. Which AES mode should the analyst recommend?
Medium614A security analyst notices unusual outbound traffic from a server in the DMZ to an external IP address on port 4444. The server runs a web application. Which action should the analyst take first?
Medium615After an incident, the team identifies that the incident was caused by a missing security patch. Which of the following is the MOST effective way to prevent recurrence?
Medium616A network administrator is implementing segmentation to limit the spread of malware. Which two technologies can achieve network segmentation? (Choose two.)
Easy617A security administrator is implementing an access control system that uses sensitivity labels on subjects and objects. The policy dictates that a subject can only read objects with a label equal to or lower than the subject's clearance, and can only write to objects with a label equal to or higher than the subject's clearance. Which access control model and principle is being enforced?
Medium618A network administrator implements the firewall rules above. What is the effect of this rulebase?
Easy619A company wants to ensure that data transmitted between its two branch offices remains confidential. Which cryptographic goal is primarily being addressed?
Easy620A company is preparing for a PCI DSS assessment. According to PCI DSS requirements, how frequently must internal vulnerability scans be performed?
Hard621A system administrator receives an alert from the SIEM indicating a possible brute-force attack on a server. The logs show 100 failed logins in 2 minutes from a single source. Which of the following is the best immediate action to verify and respond?
Medium622During a post-implementation review of a recent change, it is found that the change introduced a security vulnerability. What TWO actions should be taken? (Select TWO)
Hard623Which THREE of the following are appropriate techniques for securely disposing of magnetic hard disk drives that contain sensitive data? (Choose three.)
Hard624Which TWO of the following are characteristics of a Mandatory Access Control (MAC) system?
Medium625During which phase of the NIST SP 800-61 incident response lifecycle are incident response plan updates and lessons learned typically documented?
Easy626Which THREE of the following are critical elements of a patch management policy? (Select THREE)
Hard627A security analyst notices an unusual number of ARP replies on the network where one MAC address is claiming to be multiple IP addresses. Which type of attack is most likely occurring?
Medium628During a user offboarding process, the security team must ensure that the former employee's access is revoked immediately. However, the user's manager requests that the account remain active for a week to review files. What is the BEST practice?
Hard629A company experiences a security breach where an attacker gained access to the network through a compromised vendor account. Which of the following controls would have BEST prevented this attack?
Medium630You are a security analyst at a financial institution. The company uses a role-based access control (RBAC) system for its internal banking application. Recently, the compliance team discovered that a teller, who should only have access to customer account information for their branch, was able to view account details for customers in other branches. The RBAC system assigns roles based on job titles. You review the configuration and find that the 'Teller' role has a permission that allows viewing all customer accounts, regardless of branch. The company wants to enforce branch-level restrictions. Which of the following is the best approach to address this issue?
Medium631Which TWO of the following are key indicators of a potential data exfiltration attempt?
Hard632Which THREE activities are part of the post-incident phase?
Medium633A vulnerability scanner reports a medium-severity finding on a server. After investigation, the security team determines that the vulnerability is not exploitable due to existing compensating controls. How should this finding be classified in the vulnerability management process?
Hard634Which THREE of the following are characteristics of a stateful firewall?
Hard635Which TWO of the following are best practices for securing a wireless network? (Choose two.)
Easy636Which TWO of the following are key components of a Business Impact Analysis (BIA)?
Medium637A security engineer is designing a system that must ensure data integrity at all costs, even if it means sacrificing availability. Which access control model and corresponding principle should be applied?
Hard638A security analyst reviews a cryptographic implementation and notices that the same initialization vector (IV) is used repeatedly with the same key in CBC mode. What is the primary risk?
Medium639Which of the following is a secure hash algorithm currently recommended by NIST?
Easy640Which of the following is a primary advantage of using TLS 1.3 over earlier versions?
Medium641A security engineer is designing a key management system for a large enterprise. Which two of the following practices are essential for securing cryptographic keys throughout their lifecycle?
Hard642A security administrator is implementing the 3-2-1 backup rule. Which THREE actions are required to comply with this rule? (Select THREE.)
Medium643A company implements a DMZ to host public services. Which of the following is the best practice for securing the DMZ?
Medium644A security analyst is tuning a SIEM and needs to reduce false positives from a rule that alerts on failed logins. The rule currently triggers on any single failed login. Which modification would best reduce false positives while still detecting brute-force attacks?
Hard645An organization is implementing a jump server architecture for managing critical servers. Which additional control BEST reduces the risk of lateral movement if the jump server is compromised?
Hard646A small business uses a wireless network for employees and guests. The network uses WPA2-PSK with a single SSID, and the guest network is separate but broadcasts the same SSID. Recently, employees report intermittent connection drops and slow internet speeds. A site survey shows multiple access points from neighboring businesses operating on channels 1, 6, and 11. The business's access points are set to auto-channel selection. What is the most likely cause of the issue?
Easy647Which protocol is used to securely transfer files over a network and operates on TCP port 22?
Easy648A company is upgrading its legacy systems to use modern cryptographic standards. Which two of the following algorithms should be avoided due to known weaknesses or deprecation?
Medium649Based on the TLS connection output, what is a potential security vulnerability?
Hard650An organization is migrating its on-premises applications to a cloud provider. Which of the following security controls should be implemented to protect data at rest in the cloud?
Easy651A healthcare organization stores patient records in a database that is encrypted at rest using AES-256-CBC. The encryption key is stored in a plaintext configuration file on the database server, with file permissions set to read-only for the database service account and administrators. During an internal audit, the security team flags this as a critical vulnerability because the key is co-located with the encrypted data. The system administrator argues that the file permissions are sufficient to prevent unauthorized access. Separately, the organization must comply with HIPAA requirements for encryption key management. Which remediation most effectively addresses the vulnerability and meets compliance requirements?
Hard652Which TWO of the following are characteristics of the Biba integrity model? (Choose TWO.)
Medium653A security administrator receives an alert from the SIEM indicating a configuration change on a critical server. The change was not part of any approved change request. What should be the first step?
Medium654A healthcare organization is implementing an access control system to ensure that employees can only access patient records necessary for their job functions. Which model best enforces this principle?
Medium655Which network security control can enforce that only authorized devices with current antivirus and patches can connect to the network?
Hard656Based on the exhibit, what is the most likely cause of the web application outage?
Medium657A security metric shows that patch compliance is at 85%. The goal is 95%. Which action should be taken first?
Medium658After containing a malware outbreak, the incident response team needs to ensure the malware is completely removed from all systems. Which phase of the incident response process is this?
Easy659A network administrator is designing a secure remote access solution for employees using company laptops. The solution must support strong authentication, encryption, and be resistant to man-in-the-middle attacks. Which THREE components should be included?
Hard660A security analyst is tuning a SIEM to reduce false positives. Which of the following actions is most likely to reduce false positives while maintaining detection of real threats?
Medium661A company is adopting a role-based access control (RBAC) model. Which TWO principles are fundamental to RBAC?
Easy662A financial institution uses a quantitative risk analysis to evaluate a new online payment system. The asset value is $5 million, the exposure factor is 40%, and the annualized rate of occurrence (ARO) is 0.5. What is the annualized loss expectancy (ALE)?
Hard663Match each access control model to its description.
Medium664Which THREE of the following are security features of WPA3 compared to WPA2? (Select THREE)
Hard665A company is migrating from WPA2 to WPA3 for wireless security. Which THREE features does WPA3 introduce? (Select three)
Medium666An administrator wants to ensure that users cannot share passwords. Which control is most effective at reducing the risk of password sharing?
Easy667A company uses multiple virtual machines on a single hypervisor. To prevent a VM from escaping its virtualized environment and compromising the hypervisor, which of the following should be implemented?
Medium668An organization wants to protect endpoints from ransomware that encrypts files and demands payment. Which control should be implemented FIRST?
Easy669A security analyst is reviewing application security and identifies risks related to the OWASP Top 10. Which THREE are examples of OWASP Top 10 vulnerabilities? (Select THREE.)
Medium670A new employee needs access to the CRM, email, and file servers. The security policy requires that access privileges are granted based on job function. Which process should be used?
Medium671An organization's disaster recovery plan specifies an RTO of 4 hours and an RPO of 1 hour for its critical database. Which of the following DR site configurations BEST meets these requirements?
Medium672During an incident, the IR team needs to collect volatile data. Which order should they follow?
Easy673Which access control mechanism most likely failed to prevent this unauthorized privilege escalation?
Medium674A Linux system administrator needs to restrict network traffic to a server, allowing only HTTP and HTTPS from the internet. Which tool should be used to configure packet filtering rules?
Medium675Which of the following is a secure protocol for remote administration of a server, replacing insecure protocols like Telnet?
Easy676During the containment phase of incident response, a security analyst identifies malware on a critical server. Which TWO actions should be taken FIRST to contain the threat and preserve evidence? (Choose two.)
Easy677A security analyst is investigating a network incident. Which TWO of the following are indicators of a man-in-the-middle attack using ARP spoofing? (Select TWO)
Medium678A helpdesk ticket reports that users can browse internal web servers but cannot access external websites. The IT team checks firewall logs and sees dropped packets with the DF flag set. What is the most likely cause?
Hard679A web application is vulnerable to SQL injection. Which security control would be MOST effective at detecting and blocking such attacks at the network perimeter?
Easy680Which UDP port is used by the Simple Network Management Protocol (SNMP) for receiving traps?
Medium681A security analyst receives a user report about a workstation exhibiting unusual behavior, such as unexpected pop-ups and slow performance. The analyst first checks the antivirus logs and finds no alerts. What is the NEXT step in the detection and analysis phase?
Medium682Which THREE of the following are common methods for implementing multifactor authentication (MFA)?
Hard683During a full interruption test of the disaster recovery plan, which of the following is the PRIMARY risk?
Medium684A company has a Recovery Time Objective (RTO) of 4 hours for its critical database. Which backup strategy best supports this RTO?
Medium685You work for a hospital that has recently transitioned to an electronic health record (EHR) system. The system stores protected health information (PHI) and must comply with HIPAA. The hospital's security policy requires that all access to PHI be logged and that any unauthorized access be detected promptly. The IT department has implemented logging on the EHR system, but the security team is overwhelmed by the volume of logs and cannot review them in a timely manner. Additionally, there have been incidents where employees accessed patient records without a legitimate need, but these were only discovered months later during random audits. The hospital needs to improve its detection capabilities. Which of the following is the most effective solution?
Medium686A security analyst is reviewing logs and finds multiple failed login attempts from an external IP address followed by a successful login. Which type of attack is most likely occurring?
Easy687A security analyst is reviewing the access control policy and notices that some users have been granted 'write' access to a directory that contains sensitive financial reports. Which principle of information security is being violated?
Easy688An organization uses role-based access control (RBAC). An employee transfers from the Sales department to the Marketing department. What is the most secure way to update the employee's access?
Easy689Which THREE of the following are essential elements of an effective incident response plan? (Choose three.)
Hard690A company uses role-based access control (RBAC). A user is assigned to the 'Sales' role, which grants access to CRM and reporting, and also to the 'Sales Manager' role, which grants additional access to team reports. However, the user cannot access team reports. What is the most likely cause?
Medium691Which TWO of the following are functions of a network firewall?
Medium692After a ransomware attack, the recovery team must restore encrypted files from backups. The backups are stored on a separate network segment and were last verified three days ago. What should the team do FIRST?
Medium693A company's VPN logs show that a user's account authenticated from two different geographic locations within a span of 10 minutes. The distances between locations make physical travel impossible. The security team investigates and finds that the user's password is complex and not shared. What is the MOST likely explanation?
Medium694Which TWO of the following are considered secure cryptographic hash functions as of current standards? (Select TWO.)
Easy695Match each cryptography term to its definition.
Medium696A network analyst reviews firewall logs and sees multiple SYN packets to various ports from the same external IP in a short time, with no subsequent ACK. What is the most likely cause?
Hard697An incident responder is tasked with collecting forensic evidence from a compromised Linux server. Which command would the responder use to capture the contents of volatile memory (RAM) for analysis?
Hard698A company uses virtual machines for development. To ensure isolation between VMs on the same host, which control is most important?
Medium699An organization is migrating from on-premises servers to a cloud IaaS model. The security team must ensure that virtual machine (VM) images are hardened before deployment. Which of the following is the MOST effective control to ensure consistency and compliance with security baselines?
Hard700A security analyst notices that an employee's account has been sending large amounts of data to an external IP address during non-business hours. The analyst suspects the employee's credentials have been compromised. What is the FIRST step the analyst should take according to incident response procedures?
Medium701A security analyst is investigating a network where an attacker successfully redirected traffic from a legitimate web server to a malicious server by corrupting the target domain's DNS records in a local resolver cache. Which attack technique was used?
Hard702During a vulnerability scan, a tool reports a critical vulnerability on a web server. The system owner claims it is a false positive because the server is not accessible from the internet. However, the server is accessible from the internal network. What is the best course of action?
Hard703A security analyst is reviewing logs and notices multiple failed login attempts from a single IP address against an administrative account. The SIEM has not generated an alert. Which configuration change would best detect this scenario?
Medium704A security administrator receives an alert about a potential SYN flood attack on a web server. At which OSI layer does this attack occur?
Medium705A company uses a SOAR platform for incident response. Which factor is most critical for effective automation?
Medium706When using CBC mode encryption, what is the purpose of the initialization vector (IV)?
Easy707An Identity Provider (IdP) sends an XML-based assertion to a Service Provider (SP) to grant access. Which federated identity standard is being used?
Medium708Which TWO of the following are appropriate actions when preserving digital evidence at a crime/incident scene?
Hard709An employee receives an email with an attachment claiming to be an invoice but contains a macro virus. What control would have blocked this?
Easy710A security analyst detects a workstation communicating with a known command-and-control server. The workstation is running critical applications. What should be the analyst's first step according to the NIST incident response lifecycle?
Medium711A financial services company has recently deployed a new customer-facing web application on port 443. The application is essential for client transactions. Within the first week, the security team's monitoring system detected thousands of failed login attempts originating from a wide range of IP addresses across multiple countries. The attempts are using common usernames and passwords, indicating a coordinated brute-force attack. The company's perimeter firewall is configured with a default allow rule for inbound TCP traffic on port 443 to the web server's public IP address. The company operates with a small IT team and has a limited security budget. The web application is custom-developed and cannot be modified quickly. The security analyst must recommend a solution to mitigate the attack while maintaining availability for legitimate users. Which of the following is the most effective first step?
Easy712Which TWO of the following are essential steps in a security incident response process according to the SSCP common body of knowledge? (Select the two best answers.)
Medium713Which TWO of the following are best practices for password management?
Medium714Which THREE characteristics are important for a password hashing algorithm?
Easy715Which TWO of the following are methods to defend against SYN flood attacks? (Select TWO)
Medium716A user reports they can now access files in a shared drive that were previously denied. Upon investigation, the IT team discovers the user was added to a new group that has read/write permissions to the drive. This situation is best described as:
Medium717A patch management process is being audited. Which finding indicates a critical gap in the process?
Hard718An organization's risk register lists a vulnerability with an annualized loss expectancy (ALE) of $50,000. The cost of implementing a mitigation control is $40,000 with an expected lifespan of 5 years. The control is expected to reduce the ALE by 80%. What is the net present value (NPV) of implementing this control over 5 years, assuming a discount rate of 5%? (Ignore residual risk for simplicity.)
Hard719An organization is planning to deploy a remote access VPN for employees. The solution must support strong encryption, mutual authentication, and work through firewalls without requiring additional ports. Which technology is most suitable?
Medium720A security analyst receives an alert from the EDR system indicating that a workstation has been communicating with a known malicious IP address. The analyst confirms the alert and notes that the user is still logged in. Which immediate containment action should the analyst take FIRST?
Medium721A small business has 50 employees and uses a cloud-based email service. The IT manager receives a report that several employees have been receiving phishing emails that appear to come from the company's CEO. The emails request that employees purchase gift cards and send the codes urgently. Two employees have already complied, losing $500 total. The manager wants to prevent this from recurring. The company has a limited budget and no dedicated security staff. Which of the following actions should the manager take FIRST?
Easy722A company is migrating to a cloud-based SaaS application and wants to implement federated identity. Users will authenticate using their existing corporate Active Directory credentials. Which THREE components are essential for a SAML-based federation? (Select THREE.)
Hard723A company's backup strategy includes weekly full backups and daily differential backups. A ransomware attack occurred on Wednesday, corrupting data. The last full backup was Sunday. Which backup set should be restored first?
Easy724A security administrator is configuring a Linux server to enforce mandatory access control (MAC). Which of the following tools provides MAC on Linux?
Medium725Which THREE of the following are valid steps in the change management process? (Select THREE)
Hard726A network engineer is designing a secure WAN link between two offices using IPsec VPN. The company requires encryption of all traffic, authentication of both endpoints, and protection against replay attacks. Which combination of IPsec protocols and modes should be used?
Hard727During a security audit, it is discovered that a legacy system uses SNMPv1 for network monitoring. Which of the following is the primary security concern?
Medium728A company is selecting a cryptographic algorithm for digital signatures. Which THREE of the following algorithms can be used for digital signatures? (Select THREE.)
Hard729In a federated identity scenario, a user authenticates to their home domain and accesses a resource in a partner domain. The partner domain trusts the authentication performed by the home domain. What is the home domain's role in this trust relationship?
Hard730An organization uses Kerberos for single sign-on (SSO) within its Windows domain. Which component issues ticket-granting tickets (TGTs) after verifying user credentials?
Medium731Which TWO of the following are examples of biometric authentication? (Choose two.)
Medium732Which TWO of the following are key components of the 3-2-1 backup rule?
Medium733Which transport layer protocol is used by DNS for its queries and responses, and why is it appropriate?
Easy734Drag and drop the steps for configuring a Windows Firewall rule to allow inbound RDP traffic into the correct order.
Medium735Refer to the exhibit. Which of the following is most likely a web browsing session?
Medium736An organization has implemented a PAM solution for managing privileged accounts. Which feature allows administrators to request temporary elevated access for a specific task?
Medium737Based on the exhibit, which type of attack is most likely being attempted?
Medium738An organization is implementing a federated identity system to allow employees to access a partner's cloud application using their corporate credentials. The solution must support single sign-on and use XML-based assertions. Which technology should be used?
Hard739A company is implementing a risk monitoring program. Which of the following is the best key performance indicator (KPI) to measure the effectiveness of the vulnerability management process?
Hard740An administrator notices that a certificate used for code signing is about to expire. The certificate is signed by a trusted root CA. What is the correct procedure to ensure continued trust?
Hard741An organization is planning to implement a Single Sign-On (SSO) solution. Which THREE of the following are commonly associated with SSO technologies?
Medium742Which THREE of the following are key objectives of data classification?
Hard743A security awareness training program aims to reduce successful phishing attacks. Which metric is most appropriate for measuring the effectiveness of this training?
Medium744A security analyst is investigating a phishing incident that led to credential theft. Which TWO actions are appropriate during the containment phase? (Select TWO)
Medium745A cloud security architect is designing a solution to protect workloads running in a public cloud. Which THREE of the following are key security controls that should be implemented?
Medium746A company wants to track all hardware assets including serial numbers and locations. What is the primary repository for this information?
Medium747Which THREE of the following are valid methods for enforcing separation of duties in an IT environment? (Select the three best answers.)
Hard748Which THREE of the following are standard phases of the incident response lifecycle?
Easy749Match each security control type to its example.
Medium750An organization is planning to implement multi-factor authentication. Which TWO of the following are valid authentication factors?
Easy751A security analyst is troubleshooting a network issue where users on VLAN 10 cannot reach a server on VLAN 20. The router has an ACL applied to the interface connected to VLAN 10. Which step should the analyst take first to isolate the problem?
Medium752A security team identifies a vulnerability in a web application that allows SQL injection. Which risk response strategy involves implementing input validation and parameterized queries to reduce the risk to an acceptable level?
Easy753During incident response, a team member uses a tool to capture memory from a compromised Windows system. Which of the following best describes the order of volatility?
Medium754An organization uses Kerberos for SSO. A user reports that after entering their password, they receive a 'ticket expired' error when trying to access a network share. The system administrator checks the Kerberos configuration. Which ticket is most likely expired?
Medium755Which of the following is the primary purpose of a risk register?
Easy756A security analyst notices that a service account has been granted domain administrator privileges. Which principle of access control is being violated?
Medium757An organization is implementing a password policy that requires passwords to be at least 12 characters, include uppercase, lowercase, digits, and special characters, and be changed every 90 days. Additionally, users cannot reuse any of the last 10 passwords. Which password policy element does the last requirement address?
Hard758A security engineer needs to select a hashing algorithm for storing user passwords in a database. Which of the following is the most secure choice?
Hard759A security auditor is reviewing the configuration of a remote access VPN. Which TWO features are considered best practices for securing the VPN connection?
Medium760A user claims to be 'jsmith' and provides a password. What is the term for the step where the system verifies that the password matches the one on file for 'jsmith'?
Medium761Which TWO of the following are characteristics of mandatory access control (MAC)?
Medium762Refer to the exhibit. A security analyst reviews the firewall configuration for a Windows workstation on a private network. What is the MOST significant weakness?
Medium763An organization uses role-based access control (RBAC). After a merger, a user account from the acquired company is migrated into the parent company's domain. The user is assigned to multiple roles, but is unable to access a critical application that requires a specific role. The administrator verified that the user's account is enabled and the application server is reachable. What is the MOST likely cause?
Hard764An organization implements a policy that the same individual cannot both create a purchase order and approve it in the financial system. Which security principle does this control primarily enforce?
Hard765A vulnerability scan identifies a critical flaw in a web server. The server is currently in production and cannot be patched immediately due to compatibility issues. The risk response chosen is to implement a web application firewall (WAF) rule to block exploitation attempts. This is an example of which risk response?
Medium766A security administrator is configuring a web server to use TLS. They want to optimize performance while maintaining strong security. Which cipher suite should they prioritize?
Hard767An organization has suffered a ransomware attack that encrypted files on several file servers. The incident response team is planning recovery. Which TWO actions should be performed to verify that the restored systems are clean before returning them to production? (Select TWO)
Medium768Which of the following is the PRIMARY purpose of implementing a clean desk policy?
Easy769A security engineer is configuring a firewall to block all inbound traffic except for specific services. Which of the following design principles is being applied?
Hard770A security analyst notices that a web application is vulnerable to SQL injection. The application uses parameterized queries for most inputs but concatenates user input directly into a query for a legacy module. Which is the BEST immediate remediation?
Medium771A security analyst reviews the exhibit. The internal IP 10.0.0.1 is a web server, and 203.0.113.5 is an external IP. What is the most likely issue?
Medium772A company has 200 employees using a Windows Active Directory environment. The security administrator receives multiple alerts that user accounts are being locked out every 15 minutes. The help desk confirms that users who report the issue are able to log in successfully after unlocking their accounts, but they get locked out again shortly after. The administrator checks the domain controller security logs and sees many failed logon attempts with a specific service account name 'svc_backup' from multiple workstations. The svc_backup account is used for a backup application that runs scheduled tasks. What should the administrator do to resolve the issue?
Easy773An organization is designing network segmentation to protect sensitive data. Which TWO of the following are effective methods for implementing network segmentation?
Medium774Drag and drop the steps for a typical TLS 1.3 handshake into the correct order.
Medium775An organization wants to implement a cryptographic solution that ensures forward secrecy for its internal communications. Which key exchange method should be used?
Hard776Which TWO of the following are essential components of a secure configuration baseline for a new server deployment?
Medium777Which of the following is the correct order of the access control process?
Easy778Refer to the exhibit. User bob, a member of the projectdev group, attempts to create a new file in /data/project but gets 'Permission denied'. What is the most likely reason?
Hard779A cloud security team is implementing CSPM (Cloud Security Posture Management) for their IaaS environment. Which THREE issues is CSPM MOST likely to detect? (Select THREE.)
Medium780An organization's risk register shows a high risk for phishing attacks. Which controls are considered detective controls for this risk?
Hard781A company runs a critical web application on an internal server that authenticates users against a Microsoft SQL Server database. The application was developed by a vendor that is no longer in business, and the source code is unavailable. The current authentication process stores user passwords using reversible encryption. The security team has identified this as a high-risk vulnerability. They propose implementing a database-level trigger that hashes the password column during INSERT and UPDATE operations, and modifying the application's stored procedures to compare hashed values during login. However, after implementation, users report that they cannot log in. The authentication logs show that the password comparison always fails. The database administrator confirms that the trigger is working and that new user registrations store the SHA-256 hash. What is the most likely cause of the login failures?
Hard782A SIEM correlation rule triggers when an administrative account logs in after hours and subsequently performs a bulk export of a customer database. Which THREE threat types does this scenario most likely indicate?
Hard783A network technician needs to ensure that only authorized DHCP servers can assign IP addresses on the network. Which switch feature should be enabled?
Easy784A security analyst is reviewing security events on a Linux server and needs to ensure that all authentication attempts, including both successful and failed logins, are logged. Which configuration should be used?
Medium785Refer to the exhibit. A systems administrator configures this Group Policy setting. What is the direct consequence?
Hard786Which access control model allows the owner of a resource to determine who can access it and what permissions they have?
Medium787A system administrator is configuring a file encryption solution for a shared network drive. The solution must allow multiple users to read the files without sharing a single symmetric key. Which approach should be used?
Medium788A company implements mandatory access control (MAC) on its classified document system. A user with a security clearance of Secret attempts to read a document labeled Top Secret. What happens?
Medium789A security professional is designing a key management system and needs to ensure that keys are generated using a truly random source. Which of the following is the most appropriate method for generating cryptographic keys?
Hard790Which TWO of the following are primary purposes of a risk register?
Medium791An organization wants to allow secure remote access for employees. Which protocol is most appropriate for a site-to-site VPN?
Easy792A network administrator is configuring a VPN using IPsec. Which two protocols are used within IPsec to ensure data integrity and confidentiality? (Choose two.)
Medium793A security analyst is reviewing a web application for OWASP Top 10 vulnerabilities. Which THREE of the following are examples of injection flaws?
Hard794A company deploys a guest Wi-Fi network that must be isolated from the internal network. The network team uses VLANs and a firewall. Which configuration best ensures isolation?
Medium795Which backup type copies all data that has changed since the last full backup, regardless of any incremental backups?
Easy796A security analyst is configuring a SIEM to detect data exfiltration. Which of the following correlation rules would best identify potential data exfiltration via DNS tunneling?
Hard797Refer to the exhibit. An analyst reviews the sshd log. What should be the immediate response?
Hard798A large data center uses a three-tier architecture with core, aggregation, and access switches. The security team detects anomalous traffic patterns: every night at 2:00 AM, a single server (IP 10.10.10.50) sends large ICMP Echo requests to multiple external IPs, followed by a flood of TCP SYN packets from those external IPs back to the server. The server is a critical database server that should not initiate outbound connections. The team suspects the server is compromised. The network team wants to contain the threat without taking the server offline immediately. Which action should they take first?
Hard799A system administrator is hardening a Windows server. Which two of the following are effective hardening measures? (Choose two.)
Medium800An organization has detected a ransomware infection on a critical file server. The incident response team has been activated. Which TWO actions should be performed FIRST during the initial response phase?
Medium801An organization is implementing a digital signature solution to ensure non-repudiation and integrity of documents. Which three of the following are true regarding digital signatures?
Medium802A company needs to ensure that when an employee leaves the organization, their accounts are disabled promptly to prevent unauthorized access. Which approach is MOST effective for timely account deactivation?
Medium803A security analyst is investigating a potential ARP spoofing attack on a local network segment. Which TWO network security controls would be most effective in preventing or detecting such an attack at Layer 2?
Medium804In a federated identity environment using SAML, what is the role of the Identity Provider (IdP) when a user requests access to a service provider (SP)?
Hard805A security administrator is reviewing Linux audit logs to detect unauthorized file access. Which Linux component is primarily responsible for generating these security audit logs?
Medium806A security team is conducting a qualitative risk assessment for a new cloud application. They want to prioritize risks based on likelihood and impact. Which method should they use to combine these factors?
Medium807During a change management process, the Change Advisory Board (CAB) has approved a change to update a critical database server. After implementation, a rollback is necessary due to unforeseen performance issues. What should the change manager do next?
Medium808An organization is designing an access control policy for a new system. Which THREE of the following are fundamental principles that should be incorporated? (Choose THREE.)
Hard809A company implements a new policy requiring all privileged access requests to be approved by a manager. However, after deployment, analysts report that they cannot perform emergency changes outside business hours. What is the best solution?
Hard810A small company uses a single firewall at the network perimeter. The security team receives alerts from an IDS but cannot correlate them with firewall logs because logs are stored on separate servers with different timestamps. The CEO wants to reduce false positives and improve incident response. What should the security team do first?
Easy811A security analyst discovers that an internal host is sending traffic to an external IP address known to be a command-and-control server. The analyst wants to block only that specific traffic without affecting other traffic. Which firewall rule should be implemented?
Hard812Which TWO of the following are key components of the 3-2-1 backup rule? (Select TWO)
Medium813An organization uses a SIEM to alert when a server's configuration changes from its hardened baseline. This is an example of:
Medium814Which TWO of the following are key components of a security awareness program?
Medium815An organization decides to implement CIS Benchmarks on all Windows servers. They choose Level 1 settings. What does Level 1 represent?
Medium816A security analyst receives an alert that a user account has been locked out multiple times within 10 minutes. The analyst checks the account and finds it is a service account used for automated backups. What is the most likely cause?
Medium817An organization uses a PKI with a root CA that issues certificates to intermediate CAs, which then issue end-entity certificates. A client receives an end-entity certificate signed by an intermediate CA. During validation, which certificates are required to build the chain of trust?
Medium818An organization uses Linux servers and wants to implement mandatory access control (MAC) to enhance security. Which TWO technologies can be used? (Select TWO.)
Medium819A Windows workstation is unable to authenticate to a Kerberos-based application. The time on the workstation is 5 minutes ahead of the domain controller. What is the impact?
Hard820A system administrator receives a report that a critical server is running low on disk space. After investigation, it is determined that the log files are not being rotated properly. Which of the following is the BEST solution to prevent this issue in the future?
Medium821A security team discovers that an employee's credentials were used to access the HR database from an unrecognized IP address in a foreign country. The employee is currently in the office. Which risk identification technique is most directly responsible for detecting this anomaly?
Medium822During a qualitative risk analysis, an organization rates the likelihood of a flood as 'Low' and the impact as 'High'. Using a standard 3x3 risk matrix, what is the overall risk rating?
Easy823A company's IDS generated an alert for a suspicious outbound connection to a known C2 server. The incident team discovers the host has been communicating for 2 weeks. Which containment strategy is most appropriate?
Hard824Which metric is used to measure the potential loss from a single occurrence of a risk?
Easy825A security administrator is prioritizing patches for a vulnerability with a CVSS score of 9.8 that is being actively exploited in the wild. The affected server has a low criticality classification. What should the administrator do?
Hard826During the preparation phase of incident response, which TWO components are essential for an effective incident response plan? (Select TWO)
Medium827Which THREE are appropriate controls to prevent unauthorized access to a data center? (Choose three.)
Hard828An incident responder is handling a malware outbreak. The malware has been identified as a fileless threat that persists via registry run keys. Which eradication step is most appropriate?
Hard829An IT administrator needs to deprovision a user who has been terminated. Which of the following actions should be performed first to ensure security?
Medium830A security team is conducting a penetration test. In which phase would they attempt to exploit vulnerabilities found during scanning?
Medium831During a security audit, it is discovered that network devices are using Telnet for management. Which of the following is the most secure replacement to ensure encrypted remote access?
Hard832A company uses an identity management system that requires users to authenticate using a smart card and a PIN. This is an example of:
Medium833A small medical office has 10 employees who use laptops to access electronic health records (EHR) via a web application hosted at a colocation facility. The office currently uses a consumer-grade wireless router with WPA2-PSK for internet access. The EHR vendor requires all connections to be encrypted with TLS 1.2 and recommends using a VPN for remote access. The office manager wants to ensure secure connections from the office to the EHR system, while keeping costs low. The network consultant proposes several options. Which option best balances security and cost?
Easy834A mid-sized company has deployed a web application that handles sensitive customer data. The application uses TLS to encrypt data in transit. Recently, the company received a penetration test report indicating that an attacker could potentially downgrade the TLS connection to an older, weaker version (e.g., TLS 1.0) by performing a man-in-the-middle attack. The application server runs on Windows Server 2022 with IIS 10. The security team wants to disable all versions of TLS below 1.2 on the server. However, after making registry changes to disable TLS 1.0 and 1.1, some legacy clients that only support TLS 1.0 are unable to connect. The business requires that these legacy clients still be able to access the application securely, but the security team insists on disabling weak protocols. The server currently has a valid certificate from a public CA. Which of the following is the most appropriate course of action?
Hard835During a code review, a developer identifies that a web application directly concatenates user input into SQL queries without sanitization. This vulnerability is classified under which OWASP Top 10 category?
Hard836Which TWO of the following are examples of multifactor authentication? (Choose two.)
Easy837During a security awareness training session, an employee reports receiving an email that appears to be from the CEO requesting an urgent wire transfer. The email has a suspicious domain and poor grammar. Which type of attack is this an example of?
Medium838You work for a financial services firm that must comply with GDPR and PCI DSS. The company uses a cloud-based CRM to store customer data. The security team recently discovered that the CRM vendor had a data breach that exposed the company's customer records. An investigation shows that the breach occurred because the vendor did not have multi-factor authentication (MFA) enabled for administrative accounts. The contract with the vendor states that the vendor is responsible for security of their platform. However, your company had not conducted a risk assessment of the vendor before signing the contract. Management wants to improve risk identification for third-party relationships. Which of the following is the BEST long-term solution?
Medium839Which TWO of the following are characteristics of a Smurf attack? (Select TWO)
Medium840Which of the following tools would best help a security team detect misconfigurations in a cloud environment, such as open storage buckets or overly permissive IAM roles?
Medium841A DevOps team implements a CI/CD pipeline for a web application. Which security control is BEST to ensure that only properly reviewed code reaches production?
Hard842A company wants to enforce network access control (NAC) for both wired and wireless devices. Which protocol is used for this purpose?
Medium843A company's security policy requires that all servers be hardened according to CIS Level 1 benchmarks. During an audit, it is discovered that a server has password complexity settings that exceed Level 1 requirements. Which of the following is the most appropriate action?
Hard844A security analyst reviews logs and finds that an attacker exploited a vulnerability in a web application to read arbitrary files from the server. The application runs on Apache with mod_php. Which of the following is the MOST likely vulnerability?
Hard845An organization uses Kerberos for single sign-on. When a user logs in, they receive a Ticket Granting Ticket (TGT). What is the primary purpose of the TGT?
Medium846An administrator wants to ensure that a Linux web server only allows the www-data user to run specific commands with elevated privileges. Which configuration file should be modified?
Medium847A Windows system administrator needs to enforce a security policy that prevents users from installing unauthorized software. Which feature should be configured via Group Policy?
Medium848Refer to the exhibit. During a security review, an analyst finds these firewall rules. Which recommendation should be made to reduce risk?
Medium849Which TWO roles are typically part of an incident response team?
Easy850Which of the following best describes the concept of accountability in access controls?
Medium851Which TWO of the following are examples of preventive controls for data leakage?
Hard852Refer to the exhibit. A security analyst notices that multiple internal hosts are using the same inside global IP address but different port numbers. Which technology is being used?
Easy853An organization is implementing Windows Defender Application Control (WDAC) to prevent unauthorized applications from running on company workstations. Which of the following best describes the primary security benefit of this approach?
Medium854Which authentication method uses a time-based one-time password (TOTP) generated by a hardware or software token?
Easy855Which TWO of the following are key components of a risk assessment process?
Easy856A risk manager is calculating the annualized loss expectancy (ALE) for a server. The single loss expectancy (SLE) is $5,000 and the annualized rate of occurrence (ARO) is 0.2. What is the ALE?
Easy857A software development team is implementing input validation for a web application that accepts user email addresses. Which approach BEST prevents email injection attacks?
Medium858A security architect is designing an access control system for a healthcare application. The system must ensure that a nurse can view patient records but cannot modify them, and that a doctor can both view and update records. Additionally, the system must prevent a single user from both ordering a medication and approving its administration. Which TWO access control principles are being applied? (Select TWO.)
Medium859An organization is implementing a privileged access management (PAM) solution. Which THREE of the following are common PAM capabilities?
Medium860A small business uses MAC address filtering on its wireless network to prevent unauthorized access. Which attack is most likely to bypass this control?
Easy861An incident responder needs to create a forensic image of a suspect hard drive. Which of the following steps is ESSENTIAL to ensure the integrity of the evidence?
Medium862A hospital's IT department manages a network with hundreds of medical devices, including patient monitors and infusion pumps, all connected to a separate VLAN. The security team has identified that several devices are running outdated firmware with known vulnerabilities. The vendor has not released patches for these legacy devices. The hospital cannot replace them immediately due to budget constraints. The network team proposes moving the devices to a more restrictive firewall zone and implementing intrusion detection. Which of the following additional controls should be implemented to BEST reduce the risk of a breach exploiting these devices?
Medium863A medium-sized financial services company has recently deployed a new web application that processes sensitive customer data, including Social Security numbers and account balances. The security team implemented network segmentation, a web application firewall (WAF) from a reputable vendor, and quarterly vulnerability scans. The developers assert that they use parameterized queries for all database calls in the main application code. During a recent penetration test, testers successfully exploited a SQL injection vulnerability, extracting the entire customer database. Further investigation reveals that the main application indeed uses parameterized queries, but a third-party reporting module, integrated to generate compliance reports, constructs SQL queries by concatenating user-supplied date range inputs directly into SQL strings. The WAF is configured with a generic rule set and has not been tuned to the application's specific traffic patterns. What is the most effective course of action to remediate this vulnerability and prevent future occurrences?
Hard864A company is implementing encryption for data at rest in a file server. Which TWO of the following algorithms are suitable for this purpose? (Select TWO.)
Medium865After implementing a new IDS, the security team receives numerous alerts about legitimate traffic being flagged as malicious. This phenomenon is known as:
Medium866Which type of disaster recovery test involves running the DR systems alongside production systems to verify functionality without impacting operations?
Easy867An administrator notices that a terminated employee's account is still active. Which access control process was likely skipped?
Easy868A security analyst receives a chain of custody form for a hard drive that was seized from a suspected insider threat. The form shows that the drive was handled by three individuals over two days. Which of the following is the PRIMARY reason for maintaining a chain of custody?
Hard869An analyst notices unusual outbound traffic from a workstation to an external IP on port 445. Which protocol is likely being used?
Easy870During a penetration test, a security analyst captures a packet containing a gratuitous ARP reply that associates the attacker's MAC address with the default gateway's IP address. This is a classic indicator of which attack?
Hard871A security administrator needs to dispose of hard drives that contain sensitive data. Which method provides the highest assurance that data cannot be recovered?
Medium872Which THREE of the following are types of application security testing that should be included in a secure SDLC?
Hard873Which three of the following are best practices for securing a database? (Choose three.)
Hard874A security team is implementing User Behavior Analytics (UBA) to detect insider threats. Which THREE types of activities would most likely indicate a compromised account?
Hard875Which two commands can be used to modify existing file permissions on a Linux system? (Select TWO)
Medium876An organization needs to recover data from a backup after a ransomware attack. The backup was taken 12 hours ago, and the RPO is 4 hours. What is the impact?
Medium877Which TWO actions are appropriate during the containment phase of incident response?
Medium878A company uses a hub-and-spoke VPN topology with a central site and multiple branch offices. The central site's firewall is being upgraded. Which technology can provide link redundancy with automatic failover for the VPN connections?
Medium879An organization wants to prevent unauthorized applications from running on Windows workstations. Which Windows feature should be used to enforce application whitelisting?
Easy880An organization uses role-based access control (RBAC). A user complains that they can access a resource they were previously denied. The security administrator finds that the user's role was recently changed. What is the most likely cause?
Hard881A PKI administrator is designing a key management lifecycle for a high-security environment. Which practice is most critical for ensuring long-term security of asymmetric keys?
Hard882A small business experienced a ransomware attack that encrypted all files on the file server. They have no backups. The attacker demands a ransom. The CEO asks for advice. Which recommendation should the incident responder give?
Medium883Which access control model allows the owner of a resource to determine who can access it and what privileges they have?
Easy884A company is implementing an access control system for a high-security environment. Which TWO of the following are characteristics of Mandatory Access Control (MAC)?
Easy885A company wants to implement a policy where no single individual can approve a purchase order and also receive the goods. Which access control principle does this enforce?
Easy886A company deploys a web application that processes credit card payments. The development team uses parameterized queries for all database interactions. However, during a penetration test, the tester successfully injects malicious code into a search field and retrieves sensitive customer data. Which of the following is the most likely cause?
Medium887During a security assessment, a penetration tester successfully performs a DHCP starvation attack followed by a DHCP spoofing attack. Which TWO outcomes are the most likely consequences of this combined attack?
Easy888An organization implements a Privileged Access Management (PAM) solution. Which capability best describes granting temporary administrative rights just when needed?
Hard889During a security assessment, an analyst finds that multiple snapshots of a critical virtual machine are stored on the hypervisor host. Some snapshots are several months old. Which risk is MOST likely?
Hard890Refer to the exhibit. A user at IP 10.0.0.1 reports that they cannot access a web server at 203.0.113.5 on port 443. What is the most likely cause?
Medium891A security administrator is configuring a firewall to allow outbound web traffic from internal users. The firewall must inspect the application layer data to block malicious URLs. Which type of firewall should be used?
Hard892A company has segmented its network into VLANs for different departments: HR, Finance, and IT. The router interconnecting the VLANs has ACLs configured to block traffic from HR to Finance. However, IT has noticed that traffic from HR VLAN is reaching the Finance VLAN. The network uses managed switches with 802.1Q trunking. All access ports are configured as untagged members of their respective VLANs. What is the most likely cause of this unauthorized traffic flow?
Medium893A security team detects lateral movement within the network. Which containment strategy should be applied first to limit the spread of the threat?
Medium894During a security audit, a penetration tester successfully extracts the PMKID from a wireless beacon. What information can be derived from this attack?
Hard895Refer to the exhibit. A security incident responder sees this alert in the SIEM. What should the responder do first?
Medium896A company uses a SIEM to monitor security events. Recently, they are experiencing false positives from a new IDS rule. Which approach would best reduce false positives while maintaining detection?
Hard897A security architect is designing an access control system for a healthcare application that requires fine-grained access decisions based on user role, location, time of day, and patient consent. Which TWO access control models are best suited for this requirement?
Hard898Which federated identity protocol uses XML-based assertions and provides single sign-on across different security domains?
Medium899A critical vulnerability is discovered in an application currently in use. What should be done first?
Easy900During incident analysis, a forensic examiner finds that the system logs were cleared using a command that writes null bytes. Which artifact is most likely preserved?
Hard901During an application security review, a penetration tester discovers that a web application allows users to view other users' profiles by changing an ID parameter in the URL (e.g., /profile?id=123). Which OWASP Top 10 vulnerability does this represent?
Hard902A security manager is evaluating log sources for a SIEM implementation. Which THREE of the following are considered log types that should be included?
Easy903An organization wants to perform a risk analysis for a new cloud application. Which quantitative metric is most commonly used to calculate risk?
Easy904Which of the following network protocols operates on TCP port 22 and provides secure remote administration of network devices?
Easy905A security analyst is reviewing OWASP Top 10 vulnerabilities in a web application. Which TWO are injection-related attacks? (Select TWO.)
Hard906Refer to the exhibit. A firewall log shows repeated outbound connection attempts from an internal workstation (192.168.1.50) to an external IP (203.0.113.50) on TCP port 445. What is the most likely cause?
Hard907A healthcare organization must comply with HIPAA and requires that access to electronic protected health information (ePHI) be logged and audited. They consider using an identity management system that supports single sign-on (SSO). What is the PRIMARY security concern with SSO in this environment?
Hard908During a quantitative risk analysis, the asset value is $500,000, the exposure factor is 40%, and the annual rate of occurrence is 0.5. What is the annualized loss expectancy (ALE)?
Easy909Your organization has a mixed environment of Windows and Linux servers. You receive an alert from the EDR that a Linux server is beaconing to a suspicious IP. The server runs a critical application that cannot be taken offline. The security team needs to investigate while maintaining availability. You have access to a jump box with network monitoring tools. Which course of action is most appropriate?
Hard910During a ransomware incident, the incident response team needs to recover encrypted servers. Which THREE steps are essential for successful recovery? (Select THREE)
Hard911A system administrator needs to implement a control that ensures users can only access files necessary for their job functions. Which principle is being applied?
Easy912A financial firm has deployed network-based IDS/IPS sensors at key points to detect and prevent intrusions. During a recent security audit, it was discovered that an attacker exfiltrated sensitive data using DNS over HTTPS (DoH) queries. The IDS/IPS did not generate any alerts. The firm's network policy allows all outbound HTTPS traffic to any destination. To prevent such exfiltration in the future, what is the most effective corrective action?
Hard913A security team is collecting evidence from a compromised server. They need to create a forensic image. Which of the following is the CORRECT procedure to ensure data integrity?
Medium914An application security team is reviewing code for vulnerabilities. They find that user input is directly concatenated into an SQL query without sanitization. This is an example of which OWASP Top 10 vulnerability?
Medium915A security analyst notices an increase in failed login attempts from a single IP address. What is the best immediate action?
Easy916A security analyst reviews the firewall log exhibit. Which type of activity is indicated?
Hard917A company is deploying virtual machines (VMs) in a private cloud environment. To prevent VM escape attacks, which of the following is the most critical security control?
Medium918A security analyst is reviewing an OWASP Top 10 vulnerability report. Which vulnerability involves an attacker accessing unauthorized data by modifying URLs or API parameters?
Medium919A company is concerned about VM sprawl in its data center. Which of the following is the most effective mitigation strategy?
Medium920A security analyst is recommending a symmetric encryption algorithm for a new application that requires both confidentiality and authentication. Which algorithm and mode combination should they select?
EasyOther domains
All SSCP exam domains
Frequently asked questions
- What does the scenario questions domain cover on the SSCP exam?
- scenario questions questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 920 scenario questions questions in the SSCP question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only scenario questions questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.