1. The Chief Technology Officer (CTO) of a company, Ann, is putting together a hardware budget
for the next 10 years. She is asking for the average lifespan of each hardware device so that she
can calculate when she will have to replace each device. Which of the following categories BEST
describes what she is looking for?
A. ALE
B. MTTR
C. MTBF
D. MTTF
2. A security administrator wishes to implement a secure method of file transfer when
communicating with outside organizations.
Which of the following protocols would BEST facilitate secure file transfers? (Select TWO)
A. SCP
B. TFTP
C. SNMP
D. FTP
E. SMTP
F. FTPS
3. An organization requires users to provide their fingerprints to access an application.
To improve security, the application developers intend to implement multifactor authentication.
Which of the following should be implemented?
A. Use a camera for facial recognition
B. Have users sign their name naturally
, C. Require a palm geometry scan
D. Implement iris recognition
4. A company's AUP requires:
- Passwords must meet complexity requirements.
- Passwords are changed at least once every six months.
- Passwords must be at least eight characters long.s
5. An auditor is reviewing the following report:
Which of the following controls should the auditor recommend to enforce the AUP?
A. Account lockout thresholds
B. Account recovery
C. Password expiration
D. Prohibit password reuse
6. Which of the following are used to increase the computing time it takes to brute force a password
using an offline attack? (Select TWO)
A. XOR
B. PBKDF2
C. bcrypt
D. HMAC
E. RIPEMD
7. A datacenter recently experienced a breach. When access was gained, an RF device was used to
access an air-gapped and locked server rack. Which of the following would BEST prevent this
type of attack?
A. Faraday cage