ENGINEERING NEWEST ACTUAL EXAM WITH COMPLETE
QUESTIONS AND ANSWERS // VERIFED//GRADED A+//
What would be one of the first steps for a security architect
when building or redesigning a security architecture to secure
an organization?
A) Remove unnecessary egress traffic
B) Perform a perimeter pen test
C) Deploy patches to external systems
D) Identify critical assets
D) Identify critical assets
Which of the following is a method of detecting a BYOAP
problem on a network?
A) Multiple VPN connections from the internal network.
B) Multiple URL requests from the same source IP.
C) Multiple SSIDs in the area.
D) Multiple user agent strings from the same IP address.
D) Multiple user agent strings from the same IP address.
Page 1 of 125
,What could be implemented to mitigate the risk of one client
pivoting to another on the same network?
A) Host-based antipivot
B) Next-gen antivirus
C) NAC controls
D) Private VLANs
D) Private VLANs
What is the term used for when the red team is working
together with the blue team through simulation of specific
threat scenarios?
A) Purple teaming
B) Black-hat teaming
C) Defensive teaming
D) Multi-front teaming
A) Purple teaming
When discussing Prevention (P), Detection (D), and Response
(R) in a time-based security model, which of the following
must be true to achieve a possible effective security?
A) P<D+R
Page 2 of 125
,B) P=D+R
C) P>D+R
D) P=D=R
C) P>D+R
Which of the following is known as a Rubber Ducky?
A) USB keyboard
B) Respberry Pi device
C) Trojan horse executable
D) Rogue AP
A) USB keyboard
Which OSI layer would include ARP cache poisoning and MAC
address spoofing attacks?
A) Layer 4
B) Layer 3
C) Layer 2
D) Layer 5
C) Layer 2
Page 3 of 125
, Which of these methods for delivering software patches in a
Windows enterprise should an organization utilize?
A) Windows Server Update Services
B) Windows Update Delivery Optimization
C) Windows 10 P2P Patching
D) System Patch Management Services
B) Windows Update Delivery Optimization
Which project documents common tactics, techniques, and
procedures that advanced persistent threat groups used
against enterprise networks?
A) DEF3NSE
B) DET3CT
C) ATP&CK
D) ATT&CK
D) ATT&CK
Which type of analysis is less common and is based around
presumption of compromise that the network is already
owned?
Page 4 of 125