391. An organization has hired a security analyst to perform a penetration test The analyst captures 1Gb worth of inbound network traffic to the server and transfers the pcap back to the machine for analysis.
Which of the following tools should the analyst use to further review the pcap?
Answer
Nmap
CURL
Neat
Wireshark
Card 62
Question
392. Which of the following roles is responsible for defining the protection type and Classification type for a given set of files?
Answer
Risk manager
Data owner
Chief Information Officer
General counsel
Card 63
Question
393. A systems administrator is required to enforce MFA for corporate email account access, relying on the possession factor.
Which of the following authentication methods should the systems administrator choose? (Select two).
Answer
Facial recognition
Retina scan
passphrase
Hardware token
Time-based one-time password
Fingerprints
Card 64
Question
394. During an assessment, a systems administrator found several hosts running FTP and decided to immediately block FTP communications at the firewall.
Which of the following describes the greatest risk associated with using FTP?
Answer
Users can upload personal files
FTP is prohibited by internal policy
Private data can be leaked
Credentials are sent in cleartext.
Card 65
Question
395. A company's help desk has received calls about the wireless network being down and users being unable to connect to it. The network administrator says all access pcints are up and running. One of the help desk technicians notices the affected users are working in a near the parking Jot.
Which Of the following IS the most likely reason for the outage?
Answer
Someone set up an evil twin access Print in tie affected area
The APS in the affected area have been from the network
A user has set up a rogue access point near building.
Someone near the is jamming the signal.
Card 66
Question
396. Security analysts notice a server login from a user who has been on vacation for two weeks, The analysts confirm that the user did not log in to the system while on vacation After reviewing packet capture the analysts notice the following:
Which of the following occurred?
Answer
An insider threat with username logged in to the account.
The user's account was con-promised, and an attacker changed the login credentials.
A buffer overflow was exploited to gain unauthorized access.
An attacker used a pass-the-hash attack to gain access.
Card 67
Question
397. Which of the following terms should be included in a contract to help a company monitor the ongoing security maturity Of a new vendor?
Answer
Integration of threat intelligence in the companys AV
Requirements for event logs to kept for a minimum of 30 days
A right-to-audit clause allowing for annual security audits
A data-breach clause requiring disclosure of significant data loss
Card 68
Question
398. Which of the following best ensures minimal downtime for organizations with critical computer systems in earthquake-prone areas?
Answer
Off-site replication
Local
Generators and UPS (uninterruptible power supply)
Additional warm site
Card 69
Question
399. An audit has revealed that PII (Personally Identifiable Information) is being used in the development development environment of a critical application. The Chief Privacy Officer (CPO) insists that this data must be removed. However, the developers are concerned that without real data, they cannot perform functionality tests and search for specific data.
search for specific data. Which one should a security professional implement to meet both the requirements of both the CPO and the development team?
Answer
Data erasure
Data de-tokenization
Data encryption
Data masking
Card 70
Question
400. A company has installed badge readers for building access, but discovers that unauthorized persons are unauthorized persons are in the corridors. What is the most likely cause?
Answer
Phishing
Identity fraud
Tailgating
Shoulder Surfing
Card 71
Question
401. Which of the following measures ensures non-repudiation during a forensic examination?
forensic investigation?
Answer
A SHA-2 signature of a hard disk image
Logging all persons who come into contact with evidence
Store volatile memory contents first
Duplicating a hard disk with dd
Encryption of sensitive data
Card 72
Question
402. An organization is repairing damage after an incident. Which Of the following controls is being
implemented?
Answer
Preventive
Detective
Corrective
Compensating
Card 73
Question
403. A research company discovered that an unauthorized piece of software has been detected on a small number of machines in its lab The researchers collaborate with other machines using port 445 and on the internet using port 443 The unau-thorized software is starting to be seen on additional machines outside of the lab and is making outbound communications using HTTPS and SMS. The security team has been instructed to resolve the issue as quickly as possible while causing minimal disruption to the researchers.
Which of the following is the best course Of action in this scenario?
Answer
Update the host firewalls to block outbound Stv1B.
Place the machines with the unapproved software in containment
Implement a content filter to block the unauthorized software communication
Place the unauthorized application in a Bocklist
Card 74
Question
404. Which Of the following is a primary security concern for a setting up a BYOD program?
Answer
Jailbreaking
Buffer overflow
VM escape
End of life
Card 75
Question
405. A security analyst is taking part in an evaluation process that analyzes and categorizes threat actors Of real-world events in order to improve the incident response team's process.
Which Of the following is the analyst most likely participating in?
Answer
Walk-through
Purple team
MITRE ATTACK
TAXI
Red team
Card 76
Question
406. A company wants to build a new website to sell products online. The website wd I host a storefront application that allow visitors to add products to a shopping cart and pay for products using a credit card.
Which Of the following protocols ftf ould be most secure to implement?
Answer
SNMP
TLS
SFTP
SSL
Card 77
Question
407. An annual information security has revealed that several OS-level configurations are not in compliance due to Outdated hardening standards the company is using.
Which Of the following would be best to use to update and reconfigure the OS.level security configurations?
Answer
ISO 27001 standards
CIS benchmarks
GDPR guidance
Regional regulations
Card 78
Question
408. Which Of the following is the best method for ensuring non-repudiation?
Answer
SSH key
Token
Digital certificate
SSO
Card 79
Question
409. A government organization is developing an advanced Al defense system. Develop-ers are using information collected from third-party providers Analysts are no-ticing inconsistencies in the expected powers Of then learning and attribute the Outcome to a recent attack on one of the suppliers.
Which of the following IS the most likely reason for the inaccuracy of the system?
Answer
virus
Tainted training data
Improper algorithms security
Cryptomalware
Card 80
Question
410. Which Of the following will provide the best physical security countermeasures to Stop intruders?
(Select two).
Answer
Fencing
Signage
Access control vestibules
Sensors
Lighting
Alarm
How to use this set
Read the preview and check whether the content and answers suit your learning goal. You can add the public set to your sets to study it. Your account shows the available actions.