2025/2026 Complete All 100 Questions And Correct Detailed Answers |Already Graded
A+||Already Graded A+
A disaster recovery planner needs to focus prioritization efforts around operational impact. The
disaster recovery planner should focus on which system?
A - Demilitarized Zone
B - External systems
C - Systems with critical vulnerabilities
D - Mission critical - ANSWER=D - Mission Critical
A small business is looking at migrating to the cloud but wants as little administration
responsibility as possible. Which of the following solutions would best suit them?
A - IaaS
B - PaaS
C - SaaS
D - DRaaS - ANSWER=C - SaaS
The security operations center (SOC) team for a global company is planning an initiative to
defend against security breaches. Leadership wants the team to monitor for threats against the
organization's data, credentials, and brand reputation by scanning networks that can not be
accessed via search engines. Which type of network should be scanned based on the
requirements?
A - Wireless fidelity
B - Intranet
C - Deep web
D - Supervisory control and data acquisition - ANSWER=C - Deep web
Which security technique should be used to detect a weak password that may match common
dictionary words?
A - Password Spraying
,2|Page
B - Password Auditing
C - Password Guessing
D - Password History - ANSWER=B - Password Auditing
A security consultant is conducting a security assessment and is trying to communicate
reasons that flaws may exist. What are the primary categories in which these flaws exist?
Select 3 answers.
A - Communication
B - People
C - Process
D - Technology - ANSWER=B, C, & D; People, Process, and Technology
Password auditing allows for existing passwords to be compared against known weak passwords
to help determine the security of a credential.
What should an organization implement if it wants users of their site to provide a password,
memorable word, and pin?
A - Multi-factor authentication (MFA)
B - Two-factor authentication (2FA)
C - Two-step verification
D - Single-factor authentication - ANSWER=A - Multi-factor authentication
The security team recently enabled public access to a web application hosted on a server inside
the corporate network. The developers of the application report that the server has received
several structured query language (SQL) injection attacks in the past several days. The team
needs to deploy a solution that will block the SQL injection attacks. Which solution fulfills these
requirements?
A - Virtual private network (VPN)
B - Security information and event management (SIEM)
,3|Page
C - Web application firewall (WAF)
D - Secure Socket Shell (SSH) - ANSWER=C - Web application firewall (WAF)
A financial services company has experienced several incidents of data breaches in recent
months. The company has analyzed the indicators of compromise and determined that the data
breaches were caused by insider threats. The company has decided to implement hardening
techniques and endpoint security controls to mitigate the risk. What should be used to prevent
data breaches caused by insider threats based on the indicators of compromise?
A - Network monitoring
B - Intrusion detection systems (IDS)
C - Data loss prevention (DLP)
D - Access control systems (ACS) - ANSWER=C - Data loss prevention (DLP)
The cybersecurity analyst at a software company conducted a vulnerability assessment to
identify potential security risks to the organization and discovered multiple vulnerabilities on
the company's webpage. The analyst then provided the results to the chief information security
officer (CISO), who then decided not to fix the discrepancies due to the vulnerabilities being
outside of the organization's resources. Which risk mitigation strategy is demonstrated in this
scenario?
A - Accept
B - Mitigate
C - Avoid
D - Transfer - ANSWER=A - Accept
A company wants to implement a policy to reduce the risk of unauthorized access to sensitive
information. Which policy should be implemented?
A - Least privilege
B - Separation of duties
C - Job rotation
D - Data encryption - ANSWER=A - Least privilege
1|Page
y y y y y
, 4|Page
y y y y y
A company is developing a cybersecurity risk management program and wants to establish
y y y y y y y y y y y y
metrics to measure the program's effectiveness. What should the company consider?
y y y y y y y y y y y
A - Key performance indicators (KPIs)
y y y y y
B - Key risk indicators (KRIs)
y y y y y
C - Risk appetite
y y y
D - Risk tolerance - ANSWER=A - Key performance indicators (KPIs)
y y y y y y y y y y
An IT security team has been notified that external contractors are using their personal laptops to
y y y y y y y y y y y y y y y
gain access to the corporate network. The team needs to recommend a solution that will
y y y y y y y y y y y y y y y
prevent unapproved devices from accessing the network. Which solution fulfills these
y y y y y y y y y y y
requirements?
A - Implementing a demilitarized zone (DMZ)
y y y y y y
B - Installing a hardware security module
y y y y y y
C - Implementing port security
y y y y
D - Deploying a software firewall - ANSWER=C - Implementing port security
y y y y y y y y y y y
The chief technology officer for a small publishing company has been tasked with improving the
y y y y y y y y y y y y y y
ycompany's security posture. As part of a network upgrade, the company has decided to
y y y y y y y y y y y y y
implement intrusion detection, spam filtering, content filtering, and antivirus controls. The
y y y y y y y y y y
yproject needs to be completed using the least amount of infrastructure while meeting all
y y y y y y y y y y y y y
yrequirements. Which solution fulfills these requirements? y y y y y
A - Deploying an anti-spam gateway
y y y y y
B - Deploying a proxy server
y y y y y
C - Deploying a unified threat management (UTM) appliance
y y y y y y y y
D - Deploying a web application firewall (WAF) - ANSWER=C - Deploying a unified threat
y y y y y y y y y y y y y y
management (UTM) appliance
y y y