Which of the following includes best practices for validating perimeter firewall configurations?
- ACIS controls (correct answer)
- BMITRE ATT&CK
- CNIST CSF
- DISO 27001
Reveal answer & explanationHide answer
The correct answer is A. Option A: CIS controls
Page 17 of 20 Β· 393 total questions.
Which of the following includes best practices for validating perimeter firewall configurations?
The correct answer is A. Option A: CIS controls
A company SIEM collects information about the log sources. Given the following report information: Which of the following actions should a security engineer take to enhance the security monitoring posture?

The correct answer is C. Option C: Perform a non-reporting device assessment to collect missing log sources. This option keeps traffic private / properly secured as required.
A security manager at a local hospital wants to secure patient medical records. The manager needs to: β’ Choose an access control model that clearly defines who has access to sensitive information. β’ Prevent those who enter new patient information from specifying who has access to this data. Which of the following access control models is the best way to ensure the lowest risk of granting unintentional access?
The correct answer is C. Option C: Mandatory This option keeps traffic private / properly secured as required.
An organization recently experienced a security incident due to an exterior door in a busy area getting stuck open. The organization launches a security campaign focused on the motto. "See Something. Say Something." Which of the following best describes what the organization wants to educate employees about?
The correct answer is A. Option A: Situational awareness This option keeps traffic private / properly secured as required.
After a leak of important documents, a company decides to implement a data protection program to avoid similar incidents in the future. Which of the following should the company do first?
The correct answer is D. Option D: Develop data labeling standards.
An organization is developing an in-house software platform to support capital planning and reporting functions. In addition to role-based access controls and auditing/logging capabilities, the product manager must include requirements associated with archiving data and immutable backups. Which of the following organizational considerations are most likely associated with this requirement? (Choose two.)
The correct answer is E, F. Option E: Legal hold compliance Option F: Ransomware resilience
Explanation
Ransomware disrupts access by encrypting or stealing data; resilient backups, segmentation, and endpoint controls reduce impact.
A threat intelligence company's business objective is to allow customers to integrate data directly to different TIPs through an API. The company would like to address as many of the following objectives as possible: β’ Reduce compute spend as much as possible. β’ Ensure availability for all users. β’ Reduce the potential attack surface. β’ Ensure the integrity of the data provided. Which of the following should the company consider to best meet the objectives?
The correct answer is C. Option C: Implementing rate limiting for each registered user
A company's Chief Information Security Officer learns that the senior leadership team is traveling to a country accused of attempting to steal intellectual property saved on laptops. Which of the following is the best method to protect against this attack?
The correct answer is B. Option B: Use sanitized devices with remote connections to VDI. This option keeps traffic private / properly secured as required.
An organization would like to increase the effectiveness of its incident response process across its multiplatform environment. A security engineer needs to implement the improvements using the organization's existing incident response tools. Which of the following should the security engineer use?
The correct answer is A. Option A: Playbooks This option keeps traffic private / properly secured as required.
A company sells a security appliance assembled from globally sourced hardware and software components. Installing the security appliance requires enabling administrative permissions for the service accounts on the appliance. Which of the following allows the company to reassure new and existing customers that the risk introduced by the appliance is minimal?
The correct answer is D. Option D: A transparent supply chain risk management and testing program This option keeps traffic private / properly secured as required.
An organization is deploying a new data lake that will centralize records from several applications. During the design phase, the security architect identifies the following requirements: β’ The sensitivity levels of the data is different. β’ The data must be accessed through stateless API calls after authentication. β’ Different users will have access to different data sets. Which of the following should the architect implement to best meet these requirements?
The correct answer is C. Option C: OpenID Connect This option keeps traffic private / properly secured as required.
A penetration tester is drafting a report of findings and recommendations. Multiple EOL biomedical devices were compromised using a combination of known-exploit payloads for CVEs and VLAN hopping. The tester acknowledges that the systems cannot be changed or replaced in the hospital due to regulatory, safety, and cost reasons. Which of the following are the most effective controls for this scenario? (Choose two.)
The correct answer is D. Option D: Adding a proxy and requiring medical staff to authenticate every connection
A security engineer needs to secure the OT environment based on the following requirements: β’ Isolate the OT network segment. β’ Restrict internet access. β’ Apply security updates to workstations. β’ Provide remote access to third-party vendors. Which of the following design strategies should the engineer implement to best meet these requirements?
The correct answer is B. Option B: Implement a bastion host in the ΠΠ’ network with security tools in place to monitor access and use a dedicated update server for the workstations. This option keeps traffic private / properly secured as required.
Which of the following best explains an AI model denial-of-service attack?
The correct answer is D. Option D: Using the model output to understand its parameters or architecture
A security architect is designing Zero Trust enforcement policies for all end users. The majority of users work remotely and travel frequently for work. Which of the following controls should the security architect do first?
The correct answer is D. Option D: Deploy context-aware reauthentication with UBA baseline deviations. This option keeps traffic private / properly secured as required.
Multiple users are continuously being prompted to use MFA to log in to their systems. The security team plans to implement policy changes that could address this type of issue for users without reducing the security of user accounts. Which of the following rule changes is the most secure?
The correct answer is D. Option D: Creating a conditional access rule that requires MFA upon all logins, but taking away some password complexity requirements
Explanation
Multifactor authentication combines independent authentication factors so one compromised credential is insufficient. This option keeps traffic private / properly secured as required.
A security analyst is performing threat modeling for a new AI chatbot. The AI chatbot will be rolled out to help customers develop configuration information within the company's SaaS offering. Which of the following issues would require involvement from the company's internal legal team?
The correct answer is A. Option A: An internal user finds a way to use prompt injection to disregard guardrails. This option keeps traffic private / properly secured as required.
A network security architect is working on capturing network traffic to support the following objectives in the pictured network: β’ Capture relevant traffic to share with a threat intelligence vendor. β’ Collect only traffic that could indicate a potential network intrusion. β’ Minimize the budget and resource requirements of the collected traffic. Which of the following is the best way for the network security architect to capture network traffic?

The correct answer is B. Option B: Configuring a span port on the core switch This option keeps traffic private / properly secured as required.
A security analyst is attempting to determine which user accessed an internal web server. The analyst obtains the following address assignment logs from the VPN and logs from the domain when authenticating for the VPN from the SIEM: Which of the following actions should the analyst take?

The correct answer is C. Option C: Ensure that all log sources are configured to the same time zone. This option keeps traffic private / properly secured as required.
A company in a regulated industry experiences a data breach after an employee clicks on an email phishing link and enters credentials, leading to the exposure of sensitive information. Which of the following should the company do to prevent future attacks? (Choose two.)
The correct answer is C. Option C: Establish password complexity requirements.
Showing questions 321β340 of 393 Β· Page 17 of 20