Which of the following exercises should an organization use to improve its incident response process?
- ATabletop (correct answer)
- BReplication
- CFailover
- DRecovery
Reveal answer & explanationHide answer
The correct answer is A. Option A: Tabletop
Page 7 of 31 Β· 603 total questions.
Which of the following exercises should an organization use to improve its incident response process?
The correct answer is A. Option A: Tabletop
Which of the following best ensures minimal downtime and data loss for organizations with critical computing equipment located in earthquake-prone areas?
The correct answer is B. Option B: Off-site replication
A newly identified network access vulnerability has been found in the OS of legacy IoT devices. Which of the following would best mitigate this vulnerability quickly?
The correct answer is C. Option C: Segmentation
After an audit, an administrator discovers all users have access to confidential data on a file server. Which of the following should the administrator use to restrict access to the data quickly?
The correct answer is D. Option D: Access control lists
A client demands at least 99.99% uptime from a service provider's hosted security services. Which of the following documents includes the information the service provider should return to the client?
The correct answer is D. Option D: SLA This option keeps traffic private / properly secured as required.
A company is discarding a classified storage array and hires an outside vendor to complete the disposal. Which of the following should the company request from the vendor?
The correct answer is A. Option A: Certification
A company is planning a disaster recovery site and needs to ensure that a single natural disaster would not result in the complete loss of regulated backup data. Which of the following should the company consider?
The correct answer is A. Option A: Geographic dispersion By spanning multiple Availability Zones / adding redundancy, this option provides the high availability and resilience required.
A security analyst locates a potentially malicious video file on a server and needs to identify both the creation date and the file's creator. Which of the following actions would most likely give the security analyst the information required?
The correct answer is D. Option D: Query the file's metadata. This option keeps traffic private / properly secured as required.
Which of the following teams combines both offensive and defensive testing techniques to protect an organization's critical systems?
The correct answer is C. Option C: Purple
A small business uses kiosks on the sales floor to display product information for customers. A security team discovers the kiosks use end-of-life operating systems. Which of the following is the security team most likely to document as a security implication of the current architecture?
The correct answer is A. Option A: Patch availability This option keeps traffic private / properly secured as required.
Which of the following would help ensure a security analyst is able to accurately measure the overall risk to an organization when a new vulnerability is disclosed?
The correct answer is A. Option A: A full inventory of all hardware and software This option keeps traffic private / properly secured as required.
Which of the following best practices gives administrators a set period to perform changes to an operational system to ensure availability and minimize business impacts?
The correct answer is B. Option B: Scheduled downtime
A company must ensure sensitive data at rest is rendered unreadable. Which of the following will the company most likely use?
The correct answer is C. Option C: Encryption
Explanation
Encryption protects confidentiality by making data unreadable without the appropriate key.
A legacy device is being decommissioned and is no longer receiving updates or patches. Which of the following describes this scenario?
The correct answer is C. Option C: End of support
A bank insists all of its vendors must prevent data loss on stolen laptops. Which of the following strategies is the bank requiring?
The correct answer is A. Option A: Encryption at rest
Explanation
Encryption protects confidentiality by making data unreadable without the appropriate key.
A company's end users are reporting that they are unable to reach external websites. After reviewing the performance data for the DNS severs, the analyst discovers that the CPU, disk, and memory usage are minimal, but the network interface is flooded with inbound traffic. Network logs show only a small number of DNS queries sent to this server. Which of the following best describes what the security analyst is seeing?
The correct answer is D. Option D: Reflected denial of service This option keeps traffic private / properly secured as required.
A systems administrator wants to prevent users from being able to access data based on their responsibilities. The administrator also wants to apply the required access structure via a simplified format. Which of the following should the administrator apply to the site recovery resource group?
The correct answer is A. Option A: RBAC
Explanation
Role-based access control assigns permissions to job roles, simplifying consistent least-privilege administration.
During the onboarding process, an employee needs to create a password for an intranet account. The password must include ten characters, numbers, and letters, and two special characters. Once the password is created, the company will grant the employee access to other company-owned websites based on the intranet profile. Which of the following access management concepts is the company most likely using to safeguard intranet accounts and grant access to multiple sites based on a user's intranet account? (Choose two.)
The correct answer is A, C. Option A: Federation Option C: Password complexity
Which of the following describes a security alerting and monitoring tool that collects system, application, and network logs from multiple sources in a centralized system?
The correct answer is A. Option A: SIEM
Explanation
A SIEM centralizes and correlates security events to support detection, investigation, and reporting. This option keeps traffic private / properly secured as required.
A network manager wants to protect the company's VPN by implementing multifactor authentication that uses: Something you know - Something you have - Something you are - Which of the following would accomplish the manager's goal?
The correct answer is C. Option C: Password, authentication token, thumbprint
Showing questions 121β140 of 603 Β· Page 7 of 31