Which of the following allows for the attribution of messages to individuals?
- AAdaptive identity
- BNon-repudiation (correct answer)
- CAuthentication
- DAccess logs
Reveal answer & explanationHide answer
The correct answer is B. Option B: Non-repudiation
Page 4 of 31 Β· 603 total questions.
Which of the following allows for the attribution of messages to individuals?
The correct answer is B. Option B: Non-repudiation
Which of the following is the best way to consistently determine on a daily basis whether security settings on servers have been modified?
The correct answer is A. Option A: Automation This option keeps traffic private / properly secured as required.
Which of the following tools can assist with detecting an employee who has accidentally emailed a file containing a customerβs PII?
The correct answer is D. Option D: DLP
Explanation
Data loss prevention identifies sensitive data and prevents unauthorized disclosure or transfer.
An organization recently updated its security policy to include the following statement: Regular expressions are included in source code to remove special characters such as $, |, ;. &, `, and ? from variables set by forms in a web application. Which of the following best explains the security technique the organization adopted by making this addition to the policy?
The correct answer is C. Option C: Input validation This option keeps traffic private / properly secured as required.
A security analyst and the management team are reviewing the organizational performance of a recent phishing campaign. The user click-through rate exceeded the acceptable risk threshold, and the management team wants to reduce the impact when a user clicks on a link in a phishing message. Which of the following should the analyst do?
The correct answer is C. Option C: Update the EDR policies to block automatic execution of downloaded programs.
Explanation
Endpoint detection and response monitors endpoint activity and supports detection, containment, and investigation. This option keeps traffic private / properly secured as required.
Which of the following has been implemented when a host-based firewall on a legacy Linux system allows connections from only specific internal IP addresses?
The correct answer is A. Option A: Compensating control
The management team notices that new accounts that are set up manually do not always have correct access or permissions. Which of the following automation techniques should a systems administrator use to streamline account creation?
The correct answer is D. Option D: User provisioning script
A company is planning to set up a SIEM system and assign an analyst to review the logs on a weekly basis. Which of the following types of controls is the company setting up?
The correct answer is C. Option C: Detective
A systems administrator is looking for a low-cost application-hosting solution that is cloud-based. Which of the following meets these requirements?
The correct answer is A. Option A: Serverless framework
A security operations center determines that the malicious activity detected on a server is normal. Which of the following activities describes the act of ignoring detected activity in the future?
The correct answer is A. Option A: Tuning This option keeps traffic private / properly secured as required.
A security analyst reviews domain activity logs and notices the following: Which of the following is the best explanation for what the security analyst has discovered?

The correct answer is C. Option C: An attacker is attempting to brute force jsmithβs account. This option keeps traffic private / properly secured as required.
A company is concerned about weather events causing damage to the server room and downtime. Which of the following should the company consider?
The correct answer is B. Option B: Geographic dispersion
Which of the following is a primary security concern for a company setting up a BYOD program?
The correct answer is D. Option D: Jailbreaking This option keeps traffic private / properly secured as required.
A company decided to reduce the cost of its annual cyber insurance policy by removing the coverage for ransomware attacks. Which of the following analysis elements did the company most likely use in making this decision?
The correct answer is C. Option C: ARO
Which of the following is the most likely to be included as an element of communication in a security awareness program?
The correct answer is A. Option A: Reporting phishing attempts or other suspicious activities
Explanation
Phishing uses deceptive communication to obtain credentials, money, or execution of malicious content. This option keeps traffic private / properly secured as required.
Which of the following is the phase in the incident response process when a security analyst reviews roles and responsibilities?
The correct answer is A. Option A: Preparation This option keeps traffic private / properly secured as required.
After a recent vulnerability scan, a security engineer needs to harden the routers within the corporate network. Which of the following is the most appropriate to disable?
The correct answer is D. Option D: Web-based administration This option keeps traffic private / properly secured as required.
A security administrator needs a method to secure data in an environment that includes some form of checks so track any changes. Which of the following should the administrator set up to achieve this goal?
The correct answer is D. Option D: FIM This option keeps traffic private / properly secured as required.
An administrator is reviewing a single server's security logs and discovers the following: Which of the following best describes the action captured in this log file?

The correct answer is A. Option A: Brute-force attack This option keeps traffic private / properly secured as required.
A security engineer is implementing FDE for all laptops in an organization. Which of the following are the most important for the engineer to consider as part of the planning process? (Choose two.)
The correct answer is A, B. Option A: Key escrow Option B: TPM presence This option keeps traffic private / properly secured as required.
Showing questions 61β80 of 603 Β· Page 4 of 31