Cybersecurity Essentials FINAL Quiz Answers Full Questions

Cybersecurity Essentials (CyberEss) Course Final Exam Answers v3.0

Cybersecurity Essentials 1.1 Final Quiz Answers Full Questions

1. Which statement best describes a motivation of hacktivists?

  • They are trying to show off their hacking skills.
  • They are interested in discovering new exploits.
  • They are curious and learning hacking skills.
  • They are part of a protest group behind a political cause.

Explanation: Topic 2.2.3
Each type of cybercriminal has a distinct motivation for his or her actions.

2. Which type of cybercriminal is the most likely to create malware to compromise an organization by stealing credit card information?

  • white hat hackers
  • black hat hackers
  • gray hat hackers
  • script kiddies

Explanation: Topic 2.2.2
Malware is a tool used by certain types of hackers to steal information.

3. A specialist in the HR department is invited to promote the cybersecurity program in community schools. Which three topics would the specialist emphasize in the presentation to draw students to this field? (Choose three.)

  • a career-field in high-demand
  • service to the public
  • high earning potential
  • a job with routine, day-to-day tasks
  • a field requiring a PhD degree
  • the CompTIA A+ certification provides an adequate knowledge base for the field

Explanation: Topic 2.1.3
The increased demand for cybersecurity specialists offers several unique career opportunities.

4. An organization allows employees to work from home two days a week. Which technology should be implemented to ensure data confidentiality as data is transmitted?

  • SHS
  • VLANS
  • RAID
  • VPN

Explanation: Topic 10.2.6
Protecting data confidentiality requires an understanding of the technologies used to protect data in all three data states.

5. Which type of networks poses increasing challenges to cybersecurity specialists due to the growth of BYOD on campus?

  • wireless networks
  • wired networks
  • sneaker net
  • virtual networks

Explanation: Topic 10.2.5
A cybersecurity specialist must be familiar with the types of technologies used to store, transmit, and process data.

6. A cybersecurity specialist is working with the IT staff to establish an effective information security plan. Which combination of security principles forms the foundation of a security plan?

  • confidentiality, integrity, and availability
  • technologies, policies, and awareness
  • secrecy, identify, and nonrepudiation
  • encryption, authentication, and identification

Explanation: Topic 10.1.2
The CIA Triad is the foundation upon which all information management systems are developed.

7. Which framework should be recommended for establishing a comprehensive information security management system in an organization?

  • ISO/IEC 27000
  • ISO OSI model
  • NIST/NICE framework
  • CIA Triad

Explanation: Topic 22.3.1
A cybersecurity specialist needs to be familiar with the different frameworks and models for managing information security.

8. What are three states of data during which data is vulnerable? (Choose three.)

  • data in-process
  • stored data
  • data in-transit
  • data encrypted
  • purged data
  • data decrypted

Explanation: Topic 10.2.1
A cybersecurity specialist must be aware of each of the three states of data to effectively protect data and information. Purged data was stored data. Encrypted and decrypted data can be in any of the three states.

9. Users report that the database on the main server cannot be accessed. A database administrator verifies the issue and notices that the database file is now encrypted. The organization receives a threatening email demanding payment for the decryption of the database file. What type of attack has the organization experienced?

  • man-in-the-middle attack
  • ransomeware
  • Trojan horse
  • DoS attack

Explanation: Topic 1.3.3
In a ransomware attack, the attacker compromises the victum computer and encrypts the hard drive so that data can no longer be accessed by the user. The attacker then demands payment from the user to decrypt the drive.

10. What three best practices can help defend against social engineering attacks? (Choose three.)

  • Enable a policy that states that the IT department should supply information over the phone only to managers.
  • Add more security guards.
  • Resist the urge to click on enticing web links.
  • Deploy well-designed firewall appliances.
  • Educate employees regarding policies.
  • Do not provide password resets in a chat window.

Explanation: Topic 1.2.11
A cybersecurity specialist must be aware of the technologies and measures that are used as countermeasures to protect the organization from threats and vulnerabilities.

11. Which statement describes a distributed denial of service attack?

  • An attacker sends an enormous quantity of data that a server cannot handle.
  • An attacker builds a botnet comprised of zombies.
  • An attacker views network traffic to learn authentication credentials.
  • One computer accepts data packets based on the MAC address of another computer.

Explanation: Topic 1.3.5
A cybersecurity specialist needs to be familiar with the characteristics of the different types of malware and attacks that threaten an organization.

12. A cyber criminal sends a series of maliciously formatted packets to the database server. The server cannot parse the packets and the event causes the server crash. What is the type of attack the cyber criminal launches?

  • DoS
  • man-in-the-middle
  • packet Injection
  • SQL injection

Explanation: Topic 1.3.4
A cybersecurity specialist needs to be familiar with the characteristics of the different types of malware and attacks that threaten an organization.

13. An executive manager went to an important meeting. The secretary in the office receives a call from a person claiming that the executive manager is about to give an important presentation but the presentation files are corrupted. The caller sternly recommends that the secretary email the presentation right away to a personal email address. The caller also states that the executive is holding the secretary responsible for the success of this presentation. Which type of social engineering tactic would describe this scenario?

  • urgency
  • intimidation
  • familiarity
  • trusted partners

Explanation: Topic 1.2.2
Social engineering uses several different tactics to gain information from victims.

14. What are the two most effective ways to defend against malware? (Choose two.)

  • Implement network firewalls.
  • Install and update antivirus software.
  • Implement RAID.
  • Update the operating system and other application software.
  • Implement strong passwords.
  • Implement a VPN.

Explanation: Topic 4.3.2
A cybersecurity specialist must be aware of the technologies and measures that are used as countermeasures to protect the organization from threats and vulnerabilities.

15. The employees in a company receive an email stating that the account password will expire immediately and requires a password reset within 5 minutes. Which statement would classify this email?

  • It is a piggy-back attack.
  • It is an impersonation attack.
  • It is a DDoS attack.
  • It is a hoax.

Explanation: Topic 1.2.7
Social engineering uses several different tactics to gain information from victims.

16. In which situation would a detective control be warranted?

  • when the organization needs to look for prohibited activity
  • after the organization has experienced a breach in order to restore everything back to a normal state
  • when the organization cannot use a guard dog, so it is necessary to consider an alternative
  • when the organization needs to repair damage

Explanation: Topic 26.3.2
Access control prevents an unauthorized user from gaining access to sensitive data and networked systems. There are several technologies used to implement effective access control strategies.

17. An organization has implemented antivirus software. What type of security control did the company implement?

  • recovery control
  • deterrent control
  • detective control
  • compensative control

Explanation: Topic 26.3.2
A cybersecurity specialist must be aware of the technologies and measures that are used as countermeasures to protect the organization from threats and vulnerabilities.

18. Alice and Bob are using public key encryption to exchange a message. Which key should Alice use to encrypt a message to Bob?

  • the private key of Alice
  • the public key of Bob
  • the private key of Bob
  • the public key of Alice

Explanation: Topic 18.1.4
Encryption is an important technology used to protect confidentiality. It is important to understand the characteristics of the various encryption methodologies.

19. Which statement describes a characteristics of block ciphers?

  • Block ciphers encrypt plaintext one bit at a time to form a block.
  • Block ciphers result in output data that is larger than the input data most of the time.
  • Block ciphers result in compressed output.
  • Block ciphers are faster than stream ciphers.

Explanation: Topic 18.1.2
Encryption is an important technology used to protect confidentiality. It is important to understand the characteristics of the various encryption methodologies.

20. The IT department is tasked to implement a system that controls what a user can and cannot do on the corporate network. Which process should be implemented to meet the requirement?

  • user login auditing
  • a set of attributes that describes user access rights
  • observations to be provided to all employees
  • a biometric fingerprint reader

Explanation: Topic 13.1.12
Access control prevents unauthorized user from gaining access to sensitive data and networked systems. There are several technologies used to implement effective access control strategies.

21. Alice and Bob use a pre-shared key to exchange a confidential message. If Bob wants to send a confidential message to Carol, what key should he use?

  • the same pre-shared key he used with Alice
  • the private key of Carol
  • a new pre-shared key
  • the public key of Bob

Explanation: Topic 18.1.2
Encryption is an important technology used to protect confidentiality. It is important to understand the characteristics of the various encryption methodologies.

22. Which access control strategy allows an object owner to determine whether to allow access to the object?

  • RBAC
  • DAC
  • MAC
  • ACL

Explanation: Topic 13.3.15
Access control prevents unauthorized user from gaining access to sensitive data and networked systems. There are several technologies used to implement effective access control strategies.

23. Which method is used by steganography to hide text in an image file?

  • data obfuscation
  • data masking
  • least significant bit
  • most significant bit

Explanation: Topic 18.2.5
Encryption is an important technology used to protect confidentiality. It is important to understand the characteristics of the various encryption methodologies.

24. The X.509 standards defines which security technology?

  • digital certificates
  • biometrics
  • strong passwords
  • security tokens

Explanation: Topic 18.6.5
Digital certificates protect the parties involved in a secure communication

25. Which hashing algorithm is recommended for the protection of sensitive, unclassified information?

  • MD5
  • AES-256
  • 3DES
  • SHA-256

Explanation: Topic 13.3.13
Data integrity is one of the three guiding security principles. A cybersecurity specialist should be familiar with the tools and technologies used to ensure data integrity.

26. Technicians are testing the security of an authentication system that uses passwords. When a technician examines the password tables, the technician discovers the passwords are stored as hash values. However, after comparing a simple password hash, the technician then discovers that the values are different from those on other systems. What are two causes of this situation? (Choose two.)

  • Both systems scramble the passwords before hashing.
  • The systems use different hashing algorithms.
  • One system uses hashing and the other uses hashing and salting.
  • Both systems use MD5.
  • One system uses symmetrical hashing and the other uses asymmetrical hashing.

Explanation: Topic 18.4.7
Hashing can be used in many different situations to ensure data integrity.

27. You have been asked to work with the data collection and entry staff in your organization in order to improve data integrity during initial data entry and data modification operations. Several staff members ask you to explain why the new data entry screens limit the types and size of data able to be entered in specific fields. What is an example of a new data integrity control?

  • data encryption operations that prevent any unauthorized users from accessing sensitive data
  • a limitation rule which has been implemented to prevent unauthorized staff from entering sensitive data
  • data entry controls which only allow entry staff to view current data
  • a validation rule which has been implemented to ensure completeness, accuracy, and consistency of data

Explanation: Topic 12.2.6
Data integrity deals with data validation.

28. What technology should be implemented to verify the identity of an organization, to authenticate its website, and to provide an encrypted connection between a client and the website?

  • digital signature
  • salting
  • digital certificate
  • asymmetric encryption

Explanation: Topic 18.6.1
Encryption is an important technology used to protect confidentiality. It is important to understand the characteristics of the various encryption methodologies.

29. Your organization will be handling market trades. You will be required to verify the identify of each customer who is executing a transaction. Which technology should be implemented to authenticate and verify customer electronic transactions?

  • data hashing
  • asymmetrical encryption
  • symmetrical encryption
  • digital certificates

Explanation: Topic 18.5.3
Digital certificates protect the parties involved in secure communications.

30. Alice and Bob are using a digital signature to sign a document. What key should Alice use to sign the document so that Bob can make sure that the document came from Alice?

  • public key from Bob
  • private key from Alice
  • username and password from Alice
  • private key from Bob

Explanation: Topic 18.5.3
Alice and Bob are used to explain asymmetric cryptography used in digital signatures. Alice uses a private key to encrypt the message digest. The message, encrypted message digest, and the public key are used to create the signed document and prepare it for transmission.

31. An organization has determined that an employee has been cracking passwords on administrative accounts in order to access very sensitive payroll information. Which tools would you look for on the system of the employee? (Choose three)

  • rainbow tables
  • lookup tables
  • algorithm tables
  • password digest
  • rouge access points
  • reverse lookup tables

Explanation: Topic 18.4.9
Tables that contain possible password combinations are used to crack passwords.

32. An organization wants to adopt a labeling system based on the value, sensitivity, and criticality of the information. What element of risk management is recommended?

  • asset classification
  • asset identification
  • asset availability
  • asset standardization

Explanation: Topic 11.1.4
One of the most important steps in risk management is asset classification.

33. An organization has recently adopted a five nines program for two critical database servers. What type of controls will this involve?

  • stronger encryption systems
  • improving reliability and uptime of the servers
  • remote access to thousands of external users
  • limiting access to the data on these systems

Explanation: Topic 12.6.3
System and data availability is a critical responsibility of a cybersecurity specialists. It is important to understand the technologies, process, and controls used to provide high availability.

34. Being able to maintain availability during disruptive events describes which of the principles of high availability?

  • single point of failure
  • system resiliency
  • fault tolerance
  • uninterruptible services

Explanation: Topic 12.6.13
High availability can be achieved by eliminating or reducing single points of failure, by implementing system resiliency, and by designing for fault tolerance.

35. Which risk mitigation strategies include outsourcing services and purchasing insurance?

  • avoidance
  • transfer
  • reduction
  • acceptance

Explanation: Topic 26.2.7
Risk mitigation lessens the exposure of an organization to threats and vulnerabilities by transferring, accepting, avoiding, or taking an action to reduce risk.

36. The awareness and identification of vulnerabilities is a critical function of a cybersecurity specialist. Which of the following resources can be used to identify specific details about vulnerabilities?

  • CVE national database
  • NIST/NICE framework
  • ISO/IEC 27000 model
  • Infragard

Explanation: Topic 1.1.20
A cybersecurity specialist needs to be familiar with the resources such as the CVE database, Infragard, and the NIST/NISE framework. All can be used to help plan and implement effective an information security management system.

37. Which technology would you implement to provide high availability for data storage?

  • N+1
  • software updates
  • RAID
  • hot standby

Explanation: Topic 12.6.7
System and data availability is a critical responsibility of a cybersecurity specialist. It is important to understand the technologies, process, and controls used to provide redundancy.

38. Which two values are required to calculate annual loss expectancy? (Choose two.)

  • annual rate of occurrence
  • asset value
  • frequency factor
  • exposure factor
  • single loss expectancy
  • quantitative loss value

Explanation: Topic 26.2.4
Single loss expectancy, annualized rate of occurrence, and annualized loss expectancy are used in a quantitative risk analysis

39. What is it called when an organization only installs applications that meet its guidelines, and administrators increase security by eliminating all other applications?

  • asset availability
  • asset identification
  • asset classification
  • asset standardization

Explanation: Topic 11.1.5
An organization needs to know what hardware and software are present as a prerequisite to knowing what the configuration parameters need to be. Asset management includes a complete inventory of hardware and software. Asset standards identify specific hardware and software products that the organization uses and supports. When a failure occurs, prompt action helps to maintain both access and security.

40. There are many environments that require five nines, but a five nines environment may be cost prohibitive. What is one example of where the five nines environment might be cost prohibitive?

  • department stores at the local mall
  • the front office of a major league sports team
  • the U.S. Department of Education
  • the New York Stock Exchange

Explanation: Topic 12.6.3
System and data availability is a critical responsibility of a cybersecurity specialist. It is important to understand the technologies, process, and controls used to protect provide high availability.

41. Which technology can be used to protect VoIP against eavesdropping?

  • ARP
  • encrypted voice messages
  • strong authentication
  • SSH

Explanation: Topic 12.7.8
Many advanced technologies such as VoIP, streaming video, and electronic conferencing require advanced countermeasures.

42. Mutual authentication can prevent which type of attack?

  • wireless poisoning
  • wireless IP spoofing
  • wireless sniffing
  • man-in-the-middle

Explanation: Topic 12.5.8
A cybersecurity specialist must be aware of the technologies and measures that are used as countermeasures to protect the organization from threats and vulnerabilities.

43. Which of the following products or technologies would you use to establish a baseline for an operating system?

  • SANS Baselining System (SBS)
  • Microsoft Security Baseline Analyzer
  • MS Baseliner
  • CVE Baseline Analyzer

Explanation: Topic 25.1.4
There are many tools that a cybersecurity specialist uses to evaluate the potential vulnerabilities of an organization.

44. What Windows utility should be used to configure password rules and account lockout policies on a system that is not part of a domain?

  • Active Directory Security tool
  • Computer Management
  • Local Security Policy tool
  • Event Viewer security log

Explanation: Topic 13.3.7
A cybersecurity specialist must be aware of the technologies and measures that are used as countermeasures to protect the organization from threats and vulnerabilities. Local Security Policy, Event Viewer, and Computer Management are Windows utilities that are all used in the security equation.

45. What describes the protection provided by a fence that is 1 meter in height?

  • It deters casual trespassers only.
  • It prevents casual trespassers because of its height.
  • The fence deters determined intruders.
  • It offers limited delay to a determined intruder.

Explanation: Topic 12.1.2
Security standards have been developed to assist organizations in implementing the proper controls to mitigate potential threats. The height of a fence determines the level of protection from intruders

46. Which wireless standard made AES and CCM mandatory?

  • WPA2
  • WEP
  • WEP2
  • WPA

Explanation: Topic 12.5.2
Wireless security depends on several industry standards and has progressed from WEP to WPA and finally WPA2.

47. Which three protocols can use Advanced Encryption Standard (AES)? (Choose three.)

  • WEP
  • WPA2
  • WPA
  • 802.11q
  • 802.11i
  • TKIP

Explanation: Topic 12.5.2
Various protocols can be used to provide secure communication systems. AES is the strongest encryption algorithm.

48. Which website offers guidance on putting together a checklist to provide guidance on configuring and hardening operating systems?

  • Internet Storm Center
  • The Advanced Cyber Security Center
  • The National Vulnerability Database website
  • CERT

Explanation: Topic 25.2.6
There are several cybersecurity information websites that a cybersecurity specialist uses to evaluate the potential vulnerabilities of an organization. Some of these websites are the National Vulnerability Database, CERT, the Internet Storm Center, and the Advanced Cyber Security Center.

49. Which law was enacted to prevent corporate accounting-related crimes?

  • The Federal Information Security Management Act
  • Gramm-Leach-Bliley Act
  • Import/Export Encryption Act
  • Sarbanes-Oxley Act

Explanation: Topic 22.2.9
New laws and regulations have come about to protect organizations, citizens, and nations from cybersecurity attacks.

50. Which cybersecurity weapon scans for use of default passwords, missing patches, open ports, misconfigurations, and active IP addresses?

  • packet analyzers
  • vulnerability scanners
  • packet sniffers
  • password crackers

Explanation: Topic 23.1.1
There are many tools that a cybersecurity specialist uses to evaluate the potential vulnerabilities of an organization.

51. A cybersecurity specialist is asked to identify the potential criminals known to attack the organization. Which type of hackers would the cybersecurity specialist be least concerned with?

  • black hat hackers
  • gray hat hackers
  • script kiddies
  • white hat hackers

Explanation: Topic 2.2.2
Hackers are classified by colors to help define the purpose of their break-in activities.

52. What is an example of early warning systems that can be used to thwart cybercriminals?

  • Infragard
  • ISO/IEC 27000 program
  • Honeynet project
  • CVE database

Explanation: Topic 12.7.11
Early warning systems help identify attacks and can be used by cybersecurity specialists to protect systems.

53. Which technology should be used to enforce the security policy that a computing device must be checked against the latest antivirus update before the device is allowed to connect to the campus network?

  • SAN
  • VPN
  • NAC
  • NAS

Explanation: Topic 13.2.3
A cybersecurity specialist must be aware of the technologies available to enforce its organization’s security policy.

54. Which data state is maintained in NAS and SAN services?

  • stored data
  • data in-transit
  • encrypted data
  • data in-process

Explanation: Topic 10.2.2
A cybersecurity specialist must be familiar with the types of technologies used to store, transmit, and process data.

55. Which technology can be used to ensure data confidentiality?

  • hashing
  • identity management
  • encryption
  • RAID

Explanation: Topic 18.1.1
A cybersecurity specialist must be aware of the technologies available which support the CIA triad.

56. What is an impersonation attack that takes advantage of a trusted relationship between two systems?

  • man-in-the-middle
  • spoofing
  • spamming
  • sniffing

Explanation: Topic 1.3.7
In spoofing attacks, hackers can disguise their devices by using a valid address from the network and therefore bypass authentication processes. MAC addresses and IP addresses can be spoofed and can also be used to spoof ARP relationships.

57. Users report that the network access is slow. After questioning the employees, the network administrator learned that one employee downloaded a third-party scanning program for the printer. What type of malware might be introduced that causes slow performance of the network?

  • virus
  • worm
  • spam
  • phishing

Explanation: Topic 1.3.1
A cybersecurity specialist needs to be familiar with the characteristics of the different types of malware and attacks that threaten an organization.

58. What type of application attack occurs when data goes beyond the memory areas allocated to the application?

  • buffer overflow
  • RAM Injection
  • SQL injection
  • RAM spoofing

Explanation: Topic 1.5.4
A cybersecurity specialist needs to be familiar with the characteristics of the different types of malware and attacks that threaten an organization.

59. What type of attack has an organization experienced when an employee installs an unauthorized device on the network to view network traffic?

  • sniffing
  • spoofing
  • phishing
  • spamming

Explanation: Topic 23.4.6
A cybersecurity specialist needs to be familiar with the characteristics of the different types of malware and attacks that threaten an organization.

60. A penetration testing service hired by the company has reported that a backdoor was identified on the network. What action should the organization take to find out if systems have been compromised?

  • Look for policy changes in Event Viewer.
  • Scan the systems for viruses.
  • Look for unauthorized accounts.
  • Look for usernames that do not have passwords.

Explanation: Topic 27.4.7
A cybersecurity specialist needs to be familiar with the characteristics of the different types of malware and attacks that threaten an organization.

61. Smart cards and biometrics are considered to be what type of access control?

  • administrative
  • technological
  • logical
  • physical

Explanation: Topic 13.1.3
Access control prevents an unauthorized user from gaining access to sensitive data and networked systems. There are several technologies used to implement effective access control strategies.

62. Which access control should the IT department use to restore a system back to its normal state?

  • compensative
  • preventive
  • corrective
  • detective

Explanation: Topic 26.3.2
Access control prevents an unauthorized user from gaining access to sensitive data and networked systems. There are several technologies used to implement effective access control strategies.

63. A user has a large amount of data that needs to be kept confidential. Which algorithm would best meet this requirement?

  • 3DES
  • ECC
  • RSA
  • Diffie-Hellman

Explanation: Topic 18.1.7
Encryption is an important technology used to protect confidentiality. It is important to understand the characteristics of the various encryption methodologies.

64. What happens as the key length increases in an encryption application?

  • Keyspace increases proportionally.
  • Keyspace decreases exponentially.
  • Keyspace decreases proportionally.
  • Keyspace increases exponentially.

Explanation: Topic 18.1.2
Encryption is an important technology used to protect confidentiality. It is important to understand the characteristics of the various encryption methodologies.

65. You have been asked to describe data validation to the data entry clerks in accounts receivable. Which of the following are good examples of strings, integers, and decimals?

  • 800-900-4560, 4040-2020-8978-0090, 01/21/2013
  • male, $25.25, veteran
  • female, 9866, $125.50
  • yes/no 345-60-8745, TRF562

Explanation: Topic 12.2.6
A string is a group of letters, numbers and special characters. An integer is whole number. A decimal is a number that is not a fraction.

66. Which hashing technology requires keys to be exchanged?

  • salting
  • AES
  • HMAC
  • MD5

Explanation: Topic 18.3.5
The difference between HMAC and hashing is the use of keys.

67. What is a feature of a cryptographic hash function?

  • Hashing requires a public and a private key.
  • The hash function is a one-way mathematical function.
  • The output has a variable length.
  • The hash input can be calculated given the output value.

Explanation: Topic 18.3.2
Data integrity is one of the three guiding security principles. A cybersecurity specialist should be familiar with the tools and technologies used ensure data integrity.

68. A VPN will be used within the organization to give remote users secure access to the corporate network. What does IPsec use to authenticate the origin of every packet to provide data integrity checking?

  • salting
  • HMAC
  • CRC
  • password

Explanation: Topic 13.3.10
HMAC is an algorithm used to authenticate. The sender and receiver have a secret key that is used along with the data to ensure the message origin as well as the authenticity of the data.

69. Your risk manager just distributed a chart that uses three colors to identify the level of threat to key assets in the information security systems. Red represents high level of risk, yellow represents average level of threat and green represents low level of threat. What type of risk analysis does this chart represent?

  • quantitative analysis
  • exposure factor analysis
  • loss analysis
  • qualitative analysis

Explanation: Topic 26.2.4
A qualitative or quantitative risk analysis is used to identify and prioritize threats to the organization.

70. Keeping data backups offsite is an example of which type of disaster recovery control?

  • management
  • preventive
  • detective
  • corrective

Explanation: Topic 27.5.5
A disaster recovery plan enables an organization to prepare for potential disasters and minimize the resulting downtime.

71. What are two incident response phases? (Choose two.)

  • detection and analysis
  • confidentiality and eradication
  • prevention and containment
  • mitigation and acceptance
  • containment and recovery
  • risk analysis and high availability

Explanation: Topic 27.4.4
When an incident occurs, the organization must know how to respond. An organization needs to develop an incident response plan that includes several phases.

72. The team is in the process of performing a risk analysis on the database services. The information collected includes the initial value of these assets, the threats to the assets and the impact of the threats. What type of risk analysis is the team performing by calculating the annual loss expectancy?

  • quantitative analysis
  • qualitative analysis
  • loss analysis
  • protection analysis

Explanation: Topic 26.2.4
A qualitative or quantitative risk analysis is used to identify and prioritize threats to the organization.

73. What approach to availability provides the most comprehensive protection because multiple defenses coordinate together to prevent attacks?

  • obscurity
  • limiting
  • layering
  • diversity

Explanation: Topic 11.1.11
Defense in depth utilizes multiple layers of security controls.

74. Which utility uses the Internet Control Messaging Protocol (ICMP)?

  • NTP
  • ping
  • RIP
  • DNS

Explanation: Topic 12.3.2
ICMP is used by network devices to send error messages.

75. In a comparison of biometric systems, what is the crossover error rate?

  • rate of false positives and rate of acceptability
  • rate of false negatives and rate of false positives
  • rate of rejection and rate of false negatives
  • rate of acceptability and rate of false negatives

Explanation: Topic 12.1.3
In comparing biometric systems, there are several important factors to consider including accuracy, speed or throughput rate, and acceptability to users.

76. Which protocol would be used to provide security for employees that access systems remotely from home?

  • WPA
  • SSH
  • SCP
  • Telnet

Explanation: Topic 12.3.3
Various application layer protocols are used to for communications between systems. A secure protocol provides a secure channel over an unsecured network.

77. Which threat is mitigated through user awareness training and tying security awareness to performance reviews?

  • user-related threats
  • device-related threats
  • cloud-related threats
  • physical threats

Explanation: Topic 10.3.3
Cybersecurity domains provide a framework for evaluating and implementing controls to protect the assets of an organization. Each domain has various countermeasures available to manage threats.

78. HVAC, water system, and fire systems fall under which of the cybersecurity domains?

  • device
  • network
  • physical facilities
  • user

Explanation: Topic 12.6.17
Cybersecurity domains provide a framework for evaluating and implementing controls to protect the assets of an organization.

79. Technologies like GIS and IoE contribute to the growth of large data stores. What are two reasons that these technologies increase the need for cybersecurity specialists? (Choose two.)

  • They require 24-hour monitoring.
  • They collect sensitive information.
  • They contain personal information.
  • They increase processing requirements.
  • They require more equipment.
  • They make systems more complicated.

Explanation: Topic 12.7.5
The types of information collected by these technologies have increased the need for data protection.

80. Which two groups of people are considered internal attackers? (Choose two.)

  • ex-employees
  • amateurs
  • black hat hackers
  • hacktivists
  • trusted partners

Explanation: Topic 1.1.4
Threats are classified as being from an internal source or external source. A cybersecurity specialist needs to be aware of the source of various threats.

81. Which methods can be used to implement multifactor authentication?

  • IDS and IPS
  • tokens and hashes
  • VPNs and VLANs
  • passwords and fingerprints

Explanation: Topic 13.1.10
A cybersecurity specialist must be aware of the technologies available that support the CIA triad.

82. A security specialist is asked for advice on a security measure to prevent unauthorized hosts from accessing the home network of employees. Which measure would be most effective?

  • Implement a firewall.
  • Implement intrusion detection systems.
  • Implement a VLAN.
  • Implement RAID.

Explanation: Topic 15.1.1
Protecting data confidentiality requires an understanding of the technologies used to protect data in all three data states.

83. What type of attack will make illegitimate websites higher in a web search result list?

  • DNS poisoning
  • browser hijacker
  • spam
  • SEO poisoning

Explanation: Topic 1.2.9
A cybersecurity specialist needs to be familiar with the characteristics of the different types of malware and attacks that threaten an organization.

84. What is a nontechnical method that a cybercriminal would use to gather sensitive information from an organization?

  • man-in-the-middle
  • social engineering
  • pharming
  • ransomeware

Explanation: Topic 1.2.1
A cybersecurity specialist needs to be familiar with the characteristics of the different types of malware and attacks that threaten an organization.

85. Which algorithm will Windows use by default when a user intends to encrypt files and folders in an NTFS volume?

  • RSA
  • DES
  • AES
  • 3DES

Explanation: Topic 18.1.2
Encryption is an important technology used to protect confidentiality. It is important to understand the characteristics of the various encryption methodologies.

86. Before data is sent out for analysis, which technique can be used to replace sensitive data in nonproduction environments to protect the underlying information?

  • data masking substitution
  • steganography
  • software obfuscation
  • steganalysis

Explanation: Topic 18.2.2
Technologies exist to confuse attackers by changing data and using techniques to hide the original data.

87. An organization plans to implement security training to educate employees about security policies. What type of access control is the organization trying to implement?

  • administrative
  • technological
  • physical
  • logical

Explanation: Topic 13.1.4
Access control prevents an unauthorized user from gaining access to sensitive data and networked systems. There are several technologies used to implement effective access control strategies.

88. Passwords, passphrases, and PINs are examples of which security term?

  • authorization
  • access
  • authentication
  • identification

Explanation: Topic 13.1.9
Authentication methods are used to strengthen access control systems. It is important to understand the available authentication methods.

89. What technique creates different hashes for the same password?

  • SHA-256
  • HMAC
  • CRC
  • salting

Explanation: Topic 18.4.7
Data integrity is one of the three guiding security principles. A cybersecurity specialist should be familiar with the tools and technologies used to ensure data integrity.

90. You have been asked to implement a data integrity program to protect data files that need to be electronically downloaded by the sales staff. You have decided to use the strongest hashing algorithm available on your systems. Which hash algorithm would you select?

  • SHA-1
  • AES
  • MD5
  • SHA-256

Explanation: Topic 13.3.13
MD5 and SHA are the two most popular hashing algorithms. SHA-256 uses a 256-bit hash, whereas MD5 produces a 128-bit hash value.

91. What kind of integrity does a database have when all its rows have a unique identifier called a primary key?

  • entity integrity
  • referential integrity
  • domain integrity
  • user-defined integrity

Explanation: Topic 10.1.6
Data integrity is one of the three guiding security principles. A cybersecurity specialist should be familiar with the tools and technologies that are used to ensure data integrity.

92. What approach to availability involves using file permissions?

  • layering
  • simplicity
  • obscurity
  • limiting

Explanation: Topic 11.1.11
System and data availability is a critical responsibility of a cybersecurity specialist. It is important to understand the technologies, process, and controls used to protect provide high availability.

93. Which national resource was developed as a result of a U.S. Executive Order after a ten-month collaborative study involving over 3,000 security professionals?

  • ISO OSI model
  • NIST Framework
  • ISO/IEC 27000
  • the National Vulnerability Database (NVD)

Explanation: Topic 26.3.3
There are many tools that a cybersecurity specialist uses to evaluate the potential vulnerabilities of an organization.

94. Which two protocols pose switching threats? (Choose two.)

  • RIP
  • IP
  • ICMP
  • WPA2
  • STP
  • ARP

Explanation: Topic 9.2.2
Network switches are the heart of the modern data communication network. The main threats to network switches are theft, hacking and remote access, and attacks against network protocols.

95. What is the most difficult part of designing a cryptosystem?

  • encryption algorithm
  • reverse engineering
  • key length
  • key management

Explanation: Topic 18.1.3
Encryption is an important technology used to protect confidentiality. It is important to understand the characteristics of the various encryption methodologies.

96. What technology should you implement to ensure that an individual cannot later claim that he or she did not sign a given document?

  • asymmetric encryption
  • digital certificate
  • digital signature
  • HMAC

Explanation: Topic 18.5.1
A digital signature is used to establish authenticity, integrity, and nonrepudiation.

97. Which type of cybercriminal attack would interfere with established network communication through the use of constructed packets so that the packets look like they are part of the normal communication?

  • packet sniffing
  • DNS spoofing
  • packet forgery
  • rogue Wi-Fi AP

Explanation: Topic 1.3.4
Cybersecurity specialists need to be familiar with the characteristics of various attacks.

98. An organization just completed a security audit. Your division was cited for not conforming to X.509 requirements. What is the first security control you need to examine?

  • VPNs and encryption services
  • hashing operations
  • data validation rules
  • digital certificates

Explanation: Topic 18.6.5

99. Which network logs contain information that a security analyst can use to determine if packets received from the web are in response to legitimate requests or are part of an exploit?

  • NBAR logs
  • content filter logs
  • NetFlow logs
  • proxy logs

Explanation: Topic 20.3.6

100. Which technology can be used to prevent a cracker from launching a dictionary or brute-force attack of a hash?

  • AES
  • MD5
  • HMAC
  • rainbow tables

Explanation: Topic 18.8.1
HMACs use an additional secret key as input to the hash function. This adds another layer of security to the hash in order to defeat man-in-the-middle attacks and provide authentication of the data source.

101. Which technology can be implemented as part of an authentication system to verify the identification of employees?

  • a smart card reader
  • SHA-1 hash
  • a virtual fingerprint
  • a Mantrap

Explanation: Topic 13.1.9
A cybersecurity specialist must be aware of the technologies available that support the CIA triad.

102. Netbus belongs to which malware type?

  • backdoor
  • logic bomb
  • keylogger
  • grayware

Explanation: Topic 1.1.19
Netbus is a backdoor program used by cybercriminals to gain unauthorized access to a system by bypassing the standard authentication procedures. A logic bomb is a malicious program that waits for a trigger, such as a specified date or database entry, to set off the malicious code. Keyboard logging refers to recording or logging every key struck on a computer's keyboard. Grayware is any unwanted application that behaves in an annoying or undesirable manner. It may not carry any recognizable malware, but it may still pose a risk to the user by tracking your location or delivering unwanted advertising.

103. A user complains about frequently receiving messages on the smartphone that urges the user to visit different insurance websites. If the user clicks the link to visit, a user login message will pop up and ask the user to register first. Which wireless and mobile device attack has the user experienced?

  • Grayware
  • SMiShing
  • Bluejacking
  • Bluesnarfing

Explanation: Topic 1.4.2
Short message service phishing or SMiShing is a tactic used by attackers to trick mobile device users. Fake text messages prompt the user to visit a malicious website or call a fraudulent phone number, which may result in malware being downloaded onto the device or personal information being shared.

104. Which two commands could be used to check if DNS name resolution is working properly on a Windows PC? (Choose two.)

  • net cisco.com
  • ipconfig /flushdns
  • nbtstat cisco.com
  • ping cisco.com
  • nslookup cisco.com

Explanation: Topic 7.3.7
The ping command tests the connection between two hosts. When ping uses a host domain name to test the connection, the resolver on the PC will first perform the name resolution to query the DNS server for the IP address of the host. If the ping command is unable to resolve the domain name to an IP address, an error will result.

Nslookup is a tool for testing and troubleshooting DNS servers.

105. A router has an existing ACL that permits all traffic from 172.16.0.0. The administrator wants to block packets from host 172.16.0.1 but receives an error. What action can the administrator take?

  • Create a second access list denying the host and apply it to the same interface.
  • Add a deny any any ACE to access-list 1.
  • Manually add the new deny ACE with a sequence number of 5.
  • Manually add the new deny ACE with a sequence number of 15.

Explanation: Topic 14.4.3

106. Why would an attacker want to spoof a MAC address?

  • so that a switch on the LAN will start forwarding all frames toward the device that is under control of the attacker (that can then capture the LAN traffic)
  • so that the attacker can launch another type of attack in order to gain access to the switch
  • so that the attacker can capture traffic from multiple VLANs rather than from just the VLAN that is assigned to the port to which the attacker device is attached
  • so that a switch on the LAN will start forwarding frames to the attacker instead of to the legitimate host

Explanation: Topic 3.2.5
MAC address spoofing is used to bypass security measures by allowing an attacker to impersonate a legitimate host device, usually for the purpose of collecting network traffic.

107. What is the result in the self zone if a router is the source or destination of traffic?

  • Only traffic that is destined for the router is permitted.
  • No traffic is permitted.
  • All traffic is permitted.
  • Only traffic that originates in the router is permitted.

Explanation: Topic 16.2.3
All traffic is permitted in the self zone if the traffic originates from, or is destined for, the router.

108. What are two shared characteristics of the IDS and the IPS? (Choose two.)

  • Both are deployed as sensors.
  • Both rely on an additional network device to respond to malicious traffic.
  • Both have minimal impact on network performance.
  • Both use signatures to detect malicious traffic.
  • Both analyze copies of network traffic.

Explanation: Topic 6.1.6
Both the IDS and the IPS are deployed as sensors and use signatures to detect malicious traffic. The IDS analyzes copies of network traffic, which results in minimal impact on network performance. The IDS also relies on an IPS to stop malicious traffic. ​​

109. Which two types of hackers are typically classified as grey hat hackers? (Choose two.)

  • cyber criminals
  • script kiddies
  • hacktivists
  • state-sponsored hackers
  • vulnerability brokers

Explanation: Topic 2.2.3
Grey hat hackers may do unethical or illegal things, but not for personal gain or to cause damage. Hacktivists use their hacking as a form of political or social protest, and vulnerability brokers hack to uncover weaknesses and report them to vendors. Depending on the perspective one possesses, state-sponsored hackers are either white hat or black hat operators. Script kiddies create hacking scripts to cause damage or disruption. Cyber criminals use hacking to obtain financial gain by illegal means.

110. Which network security tool can detect open TCP and UDP ports on most versions of Microsoft Windows?

  • SuperScan
  • Nmap
  • Zenmap
  • L0phtcrack

Explanation: Topic 23.3.3
There are various network security tools available for network security testing and evaluation. L0phtcrack can be used to perform password auditing and recovery. SuperScan is a Microsoft port scanning software that detects open TCP and UDP ports on systems. Nmap and Zenmap are low-level network scanners available to the public.

111. What is the motivation of a white hat attacker?

  • fine tuning network devices to improve their performance and efficiency
  • studying operating systems of various platforms to develop a new system
  • taking advantage of any vulnerability for illegal personal gain
  • discovering weaknesses of networks and systems to improve the security level of these systems

Explanation: Topic 2.2.2
White hat attackers break into networks or computer systems in order to discover weaknesses for the purpose of improving the security of these systems. These break-ins are done with permission from the owner or the organization. Any results are reported back to the owner or the organization.

112. What are two uses of an access control list? (Choose two.)

  • ACLs can control which areas a host can access on a network.
  • ACLs provide a basic level of security for network access.
  • ACLs can permit or deny traffic based upon the MAC address originating on the router.
  • ACLs assist the router in determining the best path to a destination.
  • Standard ACLs can restrict access to specific applications and ports.

Explanation: Topic 14.1.1
ACLs can be used for the following:Limit network traffic in order to provide adequate network performance
Restrict the delivery of routing updates
Provide a basic level of security
Filter traffic based on the type of traffic being sent
Filter traffic based on IP addressing

113. What is the investigator attempting to prove about the USB drive when the evidence is submitted in court?

  • The data in the image is an exact copy and nothing has been altered by the process.
  • An exact copy cannot be made of a device.
  • The investigator found a USB drive and was able to make a copy of it.
  • The data is all there.

Explanation: Topic 18.4.1
A hash function ensures the integrity of a program, file, or device.

114. Which two application layer protocols manage the exchange of messages between a client with a web browser and a remote web server? (Choose two.)

  • HTTP
  • DNS
  • HTTPS
  • HTML
  • DHCP

Explanation: Topic 12.3.4
Hypertext Transfer Protocol (HTTP) and HTTP Secure (HTTPS) are two application layer protocols that manage the content requests from clients and the responses from the web server. HTML (Hypertext Mark-up Language) is the encoding language that describes the content and display features of a web page. DNS is for domain name to IP address resolution. DHCP manages and provides dynamic IP configurations to clients.

115. What would be the target of an SQL injection attack?

  • email
  • DNS
  • DHCP
  • database

Explanation: Topic 1.5.3
SQL is the language used to query a relational database. Cybercriminals use SQL injections to get information, create fake or malicious queries, or to breach the database in some other way.

116. Which wireless parameter is used by an access point to broadcast frames that include the SSID?

  • passive mode
  • channel setting
  • security mode
  • active mode

Explanation: Topic 5.1.6
The two scanning or probing modes an access point can be placed into are passive or active. In passive mode, the AP advertises the SSID, supported standards, and security settings in broadcast beacon frames. In active mode, the wireless client must be manually configured for the same wireless parameters as the AP has configured.

117. Match the commonly used ports on a Linux server with the corresponding service:

HTTPS → 443
SMTP → 25
Telnet → 23
DNS → 53

Explanation: Topic 8.3.2

118. What is the outcome when a Linux administrator enters the man man command?

  • The man man command configures the network interface with a manual address.
  • The man man command opens the most recent log file.
  • The man man command provides a list of commands available at the current prompt.
  • The man man command provides documentation about the man command.

Explanation: Topic 8.2.2
The man command is short for manual and is used to obtain documentation about a Linux command. The command man man would provide documentation about how to use the manual.

119. How can IMAP be a security threat to a company?

  • It can be used to encode stolen data and send to a threat actor.
  • Encrypted data is decrypted.
  • Someone inadvertently clicks on a hidden iFrame.
  • An email can be used to bring malware to a host.

Explanation: Topic 19.1.5
IMAP, SMTP, and POP3 are email protocols. SMTP is used to send data from a host to a server or to send data between servers. IMAP and POP3 are used to download email messages and can be responsible for bringing malware to the receiving host.

120. Which information can be provided by the Cisco NetFlow utility?

  • peak usage times and traffic routing
  • source and destination UDP port mapping
  • IDS and IPS capabilities
  • security and user account restrictions

Explanation: Topic 20.3.2
NetFlow efficiently provides an important set of services for IP applications including network traffic accounting, usage-based network billing, network planning, security, denial of service monitoring capabilities, and network monitoring. NetFlow provides valuable information about network users and applications, peak usage times, and traffic routing.

121. Refer to the exhibit. A security analyst is reviewing an alert message generated by Snort. What does the number 2100498 in the message indicate?

  • the message length in bits
  • the session number of the message
  • the Snort rule that is triggered
  • the id of the user that triggers the alert

Explanation: Topic 20.1.1
The sid field in a Snort alert message indicates the Snort security rule that is triggered.

122. What is an example of a privilege escalation attack?

  • A DDoS attack is launched against a government server and causes the server to crash.
  • A port scanning attack finds that the FTP service is running on a server that allows anonymous access.
  • A threat actor sends an email to an IT manager to request the root access.
  • A threat actor performs an access attack and gains the administrator password

Explanation: Topic 13.2.2
With the privilege escalation exploit, vulnerabilities in servers or access control systems are exploited to grant an unauthorized user, or software process, higher levels of privilege than either should have. After the higher privilege is granted, the threat actor can access sensitive information or take control of a system.

123. According to NIST standards, which incident response stakeholder is responsible for coordinating an incident response with other stakeholders to minimize the damage of an incident?

  • human resources
  • IT support
  • management
  • legal department

Explanation: Topic 27.4.3
The management team creates the policies, designs the budget, and is in charge of staffing all departments. Management is also responsible for coordinating the incident response with other stakeholders and minimizing the damage of an incident.

124. Which meta-feature element in the Diamond Model describes information gained by the adversary?

  • methodology
  • resources
  • results
  • direction

Explanation: Topic 27.3.1
The meta-feature element results are used to delineate what the adversary gained from the intrusion event.

125. A network administrator is creating a network profile to generate a network baseline. What is included in the critical asset address space element?

  • the TCP and UDP daemons and ports that are allowed to be open on the server
  • the IP addresses or the logical location of essential systems or data
  • the time between the establishment of a data flow and its termination
  • the list of TCP or UDP processes that are available to accept data

Explanation: Topic 25.1.1
A network profile should include some important elements, such as the following:
Total throughput – the amount of data passing from a given source to a given destination in a given period of time
Session duratio n – the time between the establishment of a data flow and its termination
Ports used – a list of TCP or UDP processes that are available to accept data
Critical asset address space – the IP addresses or the logical location of essential systems or data

126. What is the term used when a malicious party sends a fraudulent email disguised as being from a legitimate, trusted source?

  • phishing
  • Trojan
  • backdoor
  • vishing

Explanation: Topic 1.5.12
Phishing is used by malicious parties who create fraudulent messages that attempt to trick a user into either sharing sensitive information or installing malware.

127. What is indicated by a Snort signature ID (SID) that is below 3464?

  • The SID was created by Sourcefire and distributed under a GPL agreement.
  • This is a custom signature developed by the organization to address locally observed rules.
  • The SID was created by the Snort community and is maintained in Community Rules.
  • The SID was created by members of EmergingThreats.

Explanation: Topic 21.1.6
Snort is an open source network intrusion prevention system (NIPS) and network intrusion detection system (NIDS) developed by Sourcefire. It has the ability to perform real time traffic analysis and packet logging on Internet Protocol (IP) networks and can also be used to detect probes or attacks.

128. What is a characteristic of CybOX?

  • It is a set of standardized schemata for specifying, capturing, characterizing, and communicating events and properties of network operations.
  • It enables the real-time exchange of cyberthreat indicators between the U.S. Federal Government and the private sector.
  • It is a set of specifications for exchanging cyberthreat information between organizations.
  • It is the specification for an application layer protocol that allows the communication of CTI over HTTPS.

Explanation: Topic 24.2.5
CybOX is an open standards set of standardized schemata for specifying, capturing, characterizing, and communicating events and properties of network operations that support many cybersecurity functions.

129. What is a feature of distributed firewalls?

  • They combine the feature of host-based firewalls with centralized management.
  • They all use an open sharing standard platform.
  • They use only iptables to configure network rules.
  • They use only TCP wrappers to configure rule-based access control and logging systems.

Explanation: Topic 9.3.1
Distributed firewalls combine features of host-based firewalls with centralized management, which pushes rules to the hosts.

130. Match the security policy with the description:

Explanation: Topic 11.3.2

specifies network device operating systems and end user application update procedures Network maintenance policy
identifies how remote users can access a network and what is accessible via remote connectivity Remote access policy
identifies network applications and uses that are acceptable to the organization Acceptable use policy (AUP)
specifies authorized persons that can have access to network resources and identity verification procedures Identification and authentication policy

131. What are two differences between stateful and stateless firewalls? (Choose two.)

  • A stateless firewall will provide more logging information than a stateful firewall.
  • A stateless firewall provides more stringent control over security than a stateful firewall.
  • A stateless firewall is able to filter sessions that use dynamic port negotiations while a stateful firewall cannot.
  • A stateless firewall will examine each packet individually while a stateful firewall observes the state of a connection.
  • A stateful firewall will prevent spoofing by determining whether packets belong to an existing connection while a stateless firewall follows pre-configured rule sets.

Explanation: Topic 15.1.5
There are many differences between a stateless and stateful firewall.
Stateless firewalls:
are susceptible to IP spoofing
do not reliably filter fragmented packets
use complex ACLs, which can be difficult to implement and maintain
cannot dynamically filter certain services
examine each packet individually rather than in the context of the state of a connection
Stateful firewalls:
are often used as a primary means of defense by filtering unwanted, unnecessary, or undesirable traffic
strengthen packet filtering by providing more stringent control over security
improve performance over packet filters or proxy servers
defend against spoofing and DoS attacks by determining whether packets belong to an existing connection or are from an unauthorized source
provide more log information than a packet filtering firewall

132. Designing a ZPF requires several steps. Which step involves dictating the number of devices between most-secure and least-secure zones and determining redundant devices?

  • identify subsets within zones and merge traffic requirements
  • design the physical infrastructure
  • establish policies between zones
  • determine the zones

Explanation: Topic 16.1.2
Designing ZPFs involves several steps:
Step 1 . Determine the zones - The administrator focuses on the separation of the network into zones. Zones establish the security borders of a network.
Step 2 . Establish policies between zones - For each pair of "source-destination" zones, define the sessions that clients in the source zones can request from servers in destination zones.
Step 3 . Design the physical infrastructure - After the zones have been identified, and the traffic requirements between them documented, the administrator must design the physical infrastructure. This includes dictating the number of devices between most-secure and least-secure zones and determining redundant devices.
Step 4 . Identify subsets within zones and merge traffic requirements - For each firewall device in the design, the administrator must identify zone subsets that are connected to its interfaces and merge the traffic requirements for those zones.

133. The entrepreneur is concerned about employees having uninterrupted access to important resources and data. Which of the CIA triad components would address the concern?

  • integrity
  • authentication
  • confidentiality
  • availability

Explanation: Topic 10.1.2
Communications security is usually discussed using the CIA triad: confidentiality, integrity, and availability. Confidentiality ensures that only authorized individuals, devices, entities, or processes can access sensitive information. Integrity protects data from unauthorized alteration. Availability provides uninterrupted access for authorized users to important resources and data.

134. Which cloud security domain describes controls related to securing the data itself?

  • Data Security and Encryption
  • Application Security
  • Security as a Service
  • Infrastructure Security

Explanation: Topic 17.2.1
The Security Guidance for Critical Areas of Focus in Cloud Computing v4 document developed by the Cloud Security Alliance (CSA) covers 14 domains of cloud security. Some of these domains are:

  • Infrastructure Security - describes cloud-specific aspects of infrastructure security and the foundation for operating securely in the cloud.
  • Data Security and Encryption - describes those controls related to securing the data itself, of which encryption is one of the most important.
  • Application Security - provides guidance on how to securely build and deploy applications in cloud computing environments, specifically for PaaS and IaaS.
  • Security as a Service - covers the continually evolving security services delivered from the cloud.

135. Which two advantages in security controls are provided by software-defined networks (SDN) over traditional network security solutions? (Choose two.)

  • higher performance than hardware firewalls
  • easier insertion into the traffic path
  • apply to assets based on more flexible criteria than hardware firewalls
  • easier network isolation without constraints of physical hardware
  • offer more security features than hardware firewalls

Explanation: Topic 17.3.1
Software-defined networks (SDN) enable new types of security controls and provide an overall gain for network security including:

  • easy network isolation without the constraints of physical hardware
  • SDN firewalls (security groups in cloud computing) apply to assets based on more flexible criteria than hardware firewalls

136. A SOHO office is using a public cloud provider to host their website. The IT technician is choosing an approach to protect transaction data between the website and visitors from the internet. Which type of encryption key management method should the technician choose?

  • shared-secret key encryption
  • secret key encryption
  • private key encryption
  • public key encryption

Explanation: Topic 18.6.1
The two classes of encryption approaches are symmetric and asymmetric encryption. Symmetric encryption algorithms use the same key, called pre-shared key or shared-secret key, to encrypt and decrypt data. Asymmetric encryption algorithms use one key to encrypt data and a different key to decrypt data. One key is public and the other is private. Asymmetric encryption is also called public key encryption. In this scenario, web visitors are unknown therefore public key encryption should be used.

137. Which role in a data governance program is responsible for compliance, assigning classifications, and determining access criteria for information assets?

  • data controller
  • data protection officer
  • data owner
  • data custodian

Explanation: Topic 22.1.2

138. Match the stages in the risk management process to the description:

Explanation: Topic 26.1.4

Once a risk has been identified, it is assessed and analyzed to determine the severity that the threat poses Assess the risk
Continuously review risk reductions due to elimination, mitigation, and transfer actions Monitor the risk
Identify the threats throughout the organization that increase risk Frame the risk
Develop an action plan to reduce overall risk exposure Respond to the risk

139. A company manages sensitive customer data and currently uses username and passphrase authentication. They want to mitigate the risk of employee credential compromise. What should they do?

  • Purchase an insurance policy
  • Enhance data encryption with an advanced algorithm
  • Implement multi-factor authentication
  • Install fingerprint or retinal scanners

Explanation: Topic 13.1.10
Risk management is the identification, evaluation, and prioritization of risks. Organizations manage risk in one of four ways, avoidance, mitigation, transfer, or accept. In this scenario, implementing multi-factor authentication can reduce the risk of employee credential compromise, which is a mitigation action. Installing fingerprint or retinal scanners eliminates the risk, which is avoidance. Purchasing an insurance policy is transferring the financial risk to the insurance company.

140. As a cybersecurity analyst, which organization maintains the weekly digest called NewsBites?

  • MITRE
  • CIS
  • (ISC)2
  • SANS

Explanation: Topic 24.1.1
The SysAdmin, Audit, Network, Security (SANS) Institute has many resources. One of them is called NewsBites, the weekly digest of news articles about computer security.

141. Match the threat intelligence service with the description.

FireEye blocks attacks across the web and email threat vectors, and latent malware that resides on file shares
Cisco Talos collects information about active, existing, and emerging threats and provides comprehensive protection against these attacks to subscribers
MITRE Corporation creates and maintains a catalog of known security threats called Common Vulnerabilities and Exposures (CVE)
DHS Automated Indicator Sharing provides a real-time exchange of cyber threat indicators between the U.S. Government and the private sector

Explanation: Topic 24.2

142. Which four metrics are key considerations in a Business Impact Analysis (BIA)?

  • Recovery point times (RPTs)
  • Recovery point objectives (RPOs)
  • Mean time to repair (MTTR)
  • Recovery time objectives (RTOs)
  • Mean time between failures (MTBF)
  • Mean time between objectives (RBOs)

Explanation: Topic 27.5.7
Business continuity controls are more than just backing up data and providing redundant hardware. Creating a business continuity plan starts with carrying out a business impact analysis (BIA) to identify critical business processes, resources, and relationships between systems. The BIA focuses on the consequences of the interruption to critical business functions and examines the key considerations listed here: RTOs, RPOs, MTTR, and MTBF. The National Institute of Standards and Technology (NIST) developed best practices in relation to business continuity.

143. An audit revealed weak passwords, stolen credentials, and phishing attacks. What single measure can mitigate all these risks?

  • Institute a password reset for all accounts
  • Change the minimum password length rules
  • Change password complexity rules
  • Implement MFA

Explanation: Topic 13.1.10

144. An IT cybersecurity technician wants to conduct a layer-3 port scan and use decoy hosts on the same LAN to mask the scan source. Which tool should be used?

  • Tripwire
  • SIEM
  • Nmap
  • Superscan

Explanation: Topic 23.3.2

145. Why is it important to conduct server profiling on live networks?

  • Ensure all servers have the same configurations
  • Establish a security baseline for a given server
  • Create a traffic profile to identify data-loss potential
  • Detect attacks using Big Data analytics
  • Detect worm activity

Explanation: Topic 25.1.2

146. Which type of cyber threat could cause electrical power outages?

  • Sabotage
  • Hardware failure
  • Utility interruption
  • Human error

Explanation: Topic 1.1.2

147. A threat actor uses a Smurf attack to overwhelm a target host. What type of threat is this?

  • TCP SYN flood attack
  • MAC address spoofing attack
  • Amplification and reflection attack
  • UDP flood attack

Explanation: Topic 3.2.4

148. Which statement describes a characteristic of WLANs?

  • IEEE 802.11 prescribes CSMA/CD for collision avoidance
  • The 5 GHz band is more prone to interference than 2.4 GHz
  • Tethering is a variation of infrastructure mode
  • An attacker may not have to physically enter the workplace to gain access to a WLAN

Explanation: Topic 5.2.2

149. What cybersecurity mitigation phase involves limiting the spread of a worm infection to areas of the network that are already affected?

  • inoculation
  • quarantine
  • containment
  • treatment

Explanation: Topic 4.3.3

150. Which is a Windows 10 feature that encrypts removable drives?

  • Leafpad
  • BitLocker To Go
  • XProtect
  • MRT

Explanation: Topic 9.1.8

151. Which security strategy applies the terms layering, limiting, and obscurity?

  • defense-in-depth
  • physical security
  • traffic filtering
  • data encryption

Explanation: Topic 11.1.11
This strategy involves creating different layers of protection to ensure data and infrastructure remain secure, which includes the terms layering, limiting, and obscurity.

152. What is a significant factor in the high vulnerability of industrial and embedded systems?

  • These systems often have numerous points of administrative access.
  • Many devices in these systems have poor authentication and cannot be upgraded or patched.
  • Improving the security of these often low-cost systems would increase the cost excessively.
  • Many of these systems have deployed, which means that implementing security is expensive and time-consuming.

Explanation: Topic 12.7.4
Many of these SoC devices have poor authentication and/or they cannot be upgraded or patched. Due to the nature of these devices, a level of implied trust is necessary since there is no formal program in place to verify security controls.

153. What is a feature of a Zero Trust approach to network security?

  • A user must re-authenticate even if they have successfully passed access control.
  • Zone-based Policy Firewalls manage all network traffic.
  • Defense-in-depth policies apply to identifying assets, threats, and vulnerabilities.
  • A hashing algorithm applies to all network traffic.

Explanation: Topic 13.2.1
In a Zero trust approach, any place at which an access control decision is required should be considered a perimeter. This means that although a user or other entity may have successfully passed access control previously, they are not trusted to access another area or resource until they are authenticated. In some cases, users may be required to authenticate multiple times and in different ways, to gain access to different layers of the network.

154 What is used by an application layer gateway to connect to remote servers on behalf of clients?

  • stateful firewall
  • intrusion detection system
  • proxy server
  • packet filter

Explanation: Topic 15.1.2
When a client needs to access a remote server, it connects to a proxy server. The proxy server connects to the remote server on behalf of the client. Therefore, the server only sees a connection from the proxy server.

155. What actions are employed when configuring an IOS ZPF (Zone-Based Policy Firewall) for network traffic?

  • policy-map
  • zone pair
  • class-map
  • inspect action

Explanation: Topic 16.2.1
The actions used in an IOS ZPF:
- Inspect: Performs stateful packet inspection.
- Drop: Blocks traffic (with optional logging).
- Pass: Allows traffic without state tracking.
The "inspect action" is one of these core actions applied to network traffic. The other options (zone pair, class-map, policy-map) are configuration components used to define policies but are not actions directly applied to traffic.

156. How can three algorithms in the SSL/TLS cipher suite be updated if cryptanalysis reveals flaws? (Choose three.)

  • encryption algorithm
  • AAA algorithm
  • authentication algorithm
  • key exchange algorithm
  • Certificate Authority algorithm
  • hashing algorithm

Explanation: Topic 18.7.2
The SSL/TLS protocols are extensible and modular. This is known as a cipher suite. The key components of the cipher suite are the Message Authentication Code Algorithm (MAC), the encryption algorithm, the key exchange algorithm, and the authentication algorithm. These can be changed without replacing the entire protocol. This is very helpful because the different algorithms continue to evolve. As cryptanalysis continues to reveal flaws in these algorithms, the cipher suite can be updated to patch these flaws.

157. What is an example of transaction data recorded by a network security monitoring tool?

  • source and destination IP addresses of two network endpoints
  • source and destination port numbers of two network endpoints
  • the IP code for the protocol in use
  • requests and replies between the two network endpoints

Explanation: Topic 20.1.2
The transactions that represent the requests and replies would be logged in an access log on the server or by a NIDS like Zeek.

158. Why could network Syslog servers be a target for threat actors?

  • Syslog servers could contain information that could lead to the detection of an exploit by a hacker.
  • Syslog servers contain configurations and passwords for all devices on the network.
  • Syslog data could be encrypted by the attacker and used as ransomware.
  • Syslog servers are usually not installed behind a firewall.

Explanation: Topic 19.1.1

159. What is the reason for disabling SSID broadcasting and changing the default SSID on a wireless access point?

  • Anyone with the default SSID can gain access to the access point and change the configuration.
  • Wireless clients must then have the SSID manually configured to connect to the wireless network.
  • The access point stops broadcasting its own MAC address, thus preventing unauthorized wireless clients from connecting to the network.
  • Disabling SSID broadcasting frees up radio frequency bandwidth and increases the data throughput of the access point.

Explanation: Topic 5.3.2
The SSID is the name of the wireless network. Changing the default SSID forces device users to manually enter the SSID in order to gain access to the network. Broadcasting the SSID does not allow other devices to access the configuration, or to discover the MAC address of the device. SSID broadcasts do not affect radio frequency bandwidth.

160. Refer to the exhibit. A router has an existing ACL that permits all traffic from the 172.16.0.0 network. The administrator attempts to add a new ACE to the ACL that denies packets from host 172.16.0.1 and receives the error message that is shown in the exhibit. What action can the administrator take to block packets from host 172.16.0.1 while still permitting all other traffic from the 172.16.0.0 network?

Router(config)# access-list 1 deny 172.16.0.1
% Access rule can't be configured at higher sequence num
as it is part of the existing rule at sequence num 10
Router(config)# exit
Router# show access-lists 1
Standard IP access list 1
    10 permit 172.16.0.0, wildcard bits 0.0.255.255
  • Add a deny any any ACE to access-list 1.
  • Create a second access list denying the host and apply it to the same interface.
  • Manually add the new deny ACE with a sequence number of 15.
  • Manually add the new deny ACE with a sequence number of 5.

Explanation: Topic 14.4.3
Because the new deny ACE is a host address that falls within the existing 172.16.0.0 network that is permitted, the router rejects the command and displays an error message. For the new deny ACE to take effect, it must be manually configured by the administrator with a sequence number that is less than 10.

161. To facilitate the troubleshooting process, which inbound ICMP message should be permitted on an outside interface?

  • Echo request
  • Router advertisement
  • Time-stamp reply
  • Time-stamp request
  • Echo reply

Explanation: Topic 14.6.3
By allowing the ICMP echo reply message inbound to the organization, internal users are allowed to ping external addresses (and the reply message allowed to return).

162. What does a rootkit modify?

  • Programs
  • Operating system
  • Notepad
  • Microsoft Word
  • Screen savers

Explanation: Topic 1.1.19
A rootkit commonly modifies an operating system to create a backdoor to bypass normal authentication mechanisms.

163. What are two types of attacks used on DNS open resolvers? (Choose two.)

  • Fast flux
  • Amplification and reflection
  • Cushioning
  • Resource utilization
  • ARP poisoning

Explanation: Topic 4.1.3
Three types of attacks used on DNS open resolvers are as follows:DNS cache poisoning – attacker sends spoofed falsified information to redirect users from legitimate sites to malicious sites
DNS amplification and reflection attacks – attacker sends an increased volume of attacks to mask the true source of the attack
DNS resource utilization attacks – a denial of service (DoS) attack that consumes server resources

164. Which method can be used to harden a device?

  • Allow default services to remain enabled
  • Maintain use of the same passwords
  • Allow USB auto-detection
  • Use SSH and disable the root account access over SSH

Explanation: Topic 8.4.2
The basic best practices for device hardening are as follows:
Ensure physical security.
Minimize installed packages.
Disable unused services.
Use SSH and disable the root account login over SSH.
Keep the system updated.
Disable USB auto-detection.
Enforce strong passwords.
Force periodic password changes.
Keep users from re-using old passwords.
Review logs regularly.

165. What is the purpose of mobile device management (MDM) software?

  • It is used to implement security policies, setting, and software configurations on mobile devices.
  • It is used by threat actors to penetrate the system.
  • It is used to identify potential mobile device vulnerabilities.
  • It is used to create a security policy.

Explanation: Topic 11.3.3
Mobile device management (MDM) software is used with mobile devices so that corporate IT personnel can track the devices, implement security settings, as well as control software configurations.

166. Which statement describes the anomaly-based intrusion detection approach?

  • It compares the signatures of incoming traffic to a known intrusion database.
  • It compares the behavior of a host to an established baseline to identify potential intrusions.
  • It compares the antivirus definition file to a cloud-based repository for the latest updates.
  • It compares the operations of a host against a well-defined security policy.

Explanation: Topic 9.3.3
With an anomaly-based intrusion detection approach, a baseline of host behaviors is established first. The host behavior is checked against the baseline to detect significant deviations, which might indicate potential intrusions.

167. Which step in the Vulnerability Management Life Cycle performs inventory of all assets across the network and identifies host details, including operating system and open services?

  • Remediate
  • Assess
  • Prioritize assets
  • Discover

Explanation: Topic 25.3.3
The steps in the Vulnerability Management Life Cycle include these:

  • Discover - inventory all assets across the network and identify host details, including operating systems and open services to identify vulnerabilities
  • Prioritize assets - categorize assets into groups or business units, and assign a business value to asset groups based on their criticality to business operations
  • Assess - determine a baseline risk profile to eliminate risks based on asset criticality, vulnerability threats, and asset classification
  • Report - measure the level of business risk associated with your assets according to your security policies. Document a security plan, monitor suspicious activity, and describe known vulnerabilities
  • Remediate - prioritize according to business risk and fix vulnerabilities in order of risk
  • Verify - verify that threats have been eliminated through follow-up audits

168. What are three benefits of using symbolic links over hard links in Linux? (Choose three.)

  • They can show the location of the original file.
  • They can be encrypted.
  • Symbolic links can be exported.
  • They can link to a file in a different file system.
  • They can be compressed.
  • They can link to a directory.

Explanation: Topic 8.5.3
In Linux, a hard link is another file that points to the same location as the original file. A soft link (also called a symbolic link or a symlink) is a link to another file system name. Hard links are limited to the file system in which they are created and they cannot link to a directory; soft links are not limited to the same file system and they can link to a directory. To see the location of the original file for a symbolic link use the ls –l command.

169. Match the security service with the description.

Explanation: Topic 6.2

Allows administrators to manage network devices SNMP
A series of commands that control whether a device forwards or drops packets ACL
Allows a switch to make duplicate copies of traffic that is sent to a traffic analyzer Port mirroring
Provides statistics on packets flowing through a Cisco router or multilayer switch NetFlow

170. Match the security incident stakeholder with the role.

Explanation: Topic 27.4.3

performs disciplinary measures human resources
changes firewall rules information assurance
preserves attack evidence IT support
reviews policies for local or federal guideline violations legal department
designs the budget management

171. Which type of evidence cannot prove an IT security fact on its own?

  • best
  • corroborative
  • hearsay
  • indirect

Explanation: Topic 27.1.4
Indirect evidence cannot prove a fact on its own, but direct evidence can. Corroborative evidence is supporting information. Best evidence is most reliable because it is something concrete such as a signed contract.

172. A company implements a security policy that ensures that a file sent from the headquarters office to the branch office can only be opened with a predetermined code. This code is changed every day. Which two algorithms can be used to achieve this task? (Choose two.)

  • AES
  • SHA-1
  • MD5
  • HMAC
  • 3DES

Explanation: Topic 18.1.1
The task to ensure that only authorized personnel can open a file is data confidentiality, which can be implemented with encryption. AES and 3DES are two encryption algorithms. HMAC can be used for ensuring origin authentication. MD5 and SHA-1 can be used to ensure data integrity.

173. What is the first step taken in risk assessment?

  • Compare to any ongoing risk assessment as a means of evaluating risk management effectiveness.
  • Establish a baseline to indicate risk before security controls are implemented.
  • Perform audits to verify threats are eliminated.
  • Identify threats and vulnerabilities and the matching of threats with vulnerabilities.

Explanation: Topic 25.3.1
The three steps of risk assessment in order are as follows:

  1. Identify threats and vulnerabilities and the matching of threats with vulnerabilities.
  2. Establish a baseline to indicate risk before security controls are implemented.
  3. Compare to an ongoing risk assessment as a means of evaluating risk management effectiveness.

174. Which Windows log contains information about installations of software, including Windows updates?

  • system logs
  • security logs
  • application logs
  • setup logs

Explanation: Topic 20.2.1
On a Windows host, setup logs record information about the installation of software, including Windows updates.

175. What is the function of the pass action on a Cisco IOS Zone-Based Policy Firewall?

  • logging of rejected or dropped packets
  • inspecting traffic between zones for traffic control
  • tracking the state of connections between zones
  • forwarding traffic from one zone to another

Explanation: Topic 16.3.4
The pass action performed by Cisco IOS ZPF permits forwarding of traffic in a manner similar to the permit statement in an access control list.

176. After host A receives a web page from server B, host A terminates the connection with server B. Match each option to its correct step in the normal termination process for a TCP connection.

Explanation: Topic 3.3.3

Step 1 Host A sends FIN to Server B
Step 2 Server B sends ACK to Host A
Step 3 Server B sends FIN to Host A
Step 4 Host A sends ACK to Server B

177. Match the tabs of the Windows 10 Task Manager to their functions.

Explanation: Topic 7.3.6

Allows for a process to have its affinity set Details
Displays resource utilization information for CPU, memory, network, disk, and others Performance
Allows programs that are running on system startup to be disabled Startup
Allows for a start, stop or restart of a particular service Services

178. What is a feature of virtual LANs (VLANs)?

  • A single collision domain is enabled on a switch that is shared between VLANs.
  • Switch port utilization is decreased because each port is only associated with one broadcast domain.
  • Communication between different VLANs on the one switch is enabled by default.
  • Logical segmentation is provided by creating multiple broadcast domains on a single switch.

Explanation: Topic 12.4.2
Virtual LANs (VLANs) provide a logical segmentation by creating multiple broadcast domains on the same network switch. VLANs provide higher utilization of switch ports because a port could be associated to the necessary broadcast domain, and multiple broadcast domains can reside on the same switch. Network devices in one VLAN cannot communicate with devices in a different VLAN without the implementation of inter-VLAN routing.

179. What three security tools does Cisco Talos maintain security incident detection rule sets for? (Choose three.)

  • NetStumbler
  • Snort
  • ClamAV
  • SpamCop
  • Socat

Explanation: Topic 24.2.1
Talos maintains the security incident detection rule sets for the Snort.org, ClamAV, and SpamCop network security tools.

180. A network administrator is reviewing server alerts because of reports of network slowness. The administrator confirms that an alert was an actual security incident. What is the security alert classification of this type of scenario?

  • true negative
  • true positive
  • false positive
  • false negative

Explanation: Topic 21.2.2
True Positive: The alert has been verified to be an actual security incident.
False Positive: The alert does not indicate an actual security incident. Benign activity that results in a false positive is sometimes referred to as a benign trigger.
True Negative: No security incident has occurred. The activity is benign.
False Negative: An undetected incident has occurred.

181. What is an attack vector as it relates to network security?

  • a defense-in-depth approach to security
  • a path by which a threat actor can gain access to an internal network device
  • a particular section of a network design where security is applied
  • a method of reverse engineering binary files

Explanation: Topic 2.1.4
An attack vector is a path used by a threat actor to gain access to a server, host, or network and can originate from within the company or from the outside.

182. When implementing a ZPF, what is the default security setting when forwarding traffic between two interfaces in the same zone?

  • Traffic between interfaces in the same zone is not subject to any policy and passes freely.
  • Traffic between interfaces in the same zone is selectively forwarded based on Layer 3 information.
  • Traffic between interfaces in the same zone is blocked.
  • Traffic between interfaces in the same zone is selectively forwarded based on the default policy restrictions.

Explanation: Topic 15.2.1
A zone-based policy firewall uses the concept of zones to specify where firewall rules and policies should be applied. By default, the traffic between interfaces that exist in the same zone is not subject to any policy and passes freely.

183. A company is deploying a customer service web application on AWS. A network administrator is installing and configuring a VM instance. Which three actions should the administrator take to protect the VM? (Choose three.)

  • Install an IPS appliance in the VM.
  • Enforce account management policies.
  • Plan subnet placement.
  • Configure RAID to ensure storage fault tolerance.
  • Deploy an advanced firewall appliance.
  • Disable unneeded ports and services.

Explanation: Topic 17.6.1
This scenario is a typical SaaS cloud service model. The company is responsible for data security. The company also shares the security responsibilities for endpoints and identity management in the cloud with AWS. AWS is responsible for physical infrastructure implementation and security. Some techniques that the company should consider to protect VMs in the cloud include:

  • Plan subnet placement.
  • Disable unneeded ports and services.
  • Enforce account management policies.
  • Install antivirus/anti-malware software and keep it updated.
  • Install host-based/software firewalls and IDS/IPS.

184. A company is preparing for an ISMS audit. Match the right control for each control objective.

Explanation: Topic 22.3.4

A clean desk policy will be implemented to prevent loss, damage, theft or compromise of sensitive data
Employees will be required to report any observed or suspected information security weakness to ensure a consistent and effective approach to the management of information security incidents
Rules regarding the installation of software by employees will be established and implemented to prevent exploitation of software vulnerabilities

185. An organization is developing a data governance program that follows regulations and policies. Which role in the program is responsible for ensuring compliance with policies and procedures, assigning the proper classification to information assets, and determining the criteria for accessing information assets?

  • data custodian
  • data owner
  • data protection officer
  • data controller

Explanation: Topic 22.1.2
There are several key roles in good data governance programs that are compliant with regulations and policies:

  • Data owner- A person who ensures compliance with policies and procedures, assigns the proper classification to information assets, and determines the criteria for accessing information assets.
  • Data controller- A person who determines the purposes for which, and the way in which, personal data is processed.
  • Data processor- A person or organization who processes personal data on behalf of the data controller.
  • Data custodian- A person who implements the classification and security controls for the data in accordance with the rules set out by the data owner. In other words, data custodians are responsible for the technical control of the data.
  • Data steward- A person who ensures that data supports an organization’s business needs and meets regulatory requirements.
  • Data protection officer- A person who oversees an organization’s data protection strategy.

186. A cybersecurity analyst is testing a new vulnerability scanner on a system. The analyst chooses to run an intrusive credentialed scan. A few moments later, the system that was running the scan crashed. What is the most probable cause of the crash?

  • a false positive
  • a hardware failure
  • a false negative
  • the intrusive scan

Explanation: Topic 23.1.2

187. An IT cybersecurity technician wants to conduct a layer three port scanning on the network systems but wishes to use decoy hosts on the same LAN as target hosts to mask the source of the scan. What security tool functions allow the technician to do this?

  • Tripwire
  • SIEM
  • Superscan
  • Nmap

Explanation: Topic

188. Which file system is for Mac OS X computers, and Windows users may use third-party software to open and save files from this file system?

  • EXT
  • NTFS
  • HFS+
  • exFAT

Explanation: Topic 7.2.3

189. What is the need for data integrity in forums and personal pages on social media?

  • high
  • critical
  • low
  • mid

Explanation: Topic 10.1.6

190. Why can ACLs give a false sense of security if overly relied upon as a network security technology?

  • ACLs can be applied to network interfaces in one direction only.
  • Packets are permitted by default when ACL statements don’t match.
  • ACLs only log denied traffic, not permitted traffic.
  • Attackers can determine which IP addresses, protocols, and ports are allowed by ACLs.

Explanation: Topic 19.2.1

192. What is required in order to connect a Wi-Fi enabled laptop to a WPA secured wireless network?

  • a security encryption key
  • a username and password
  • an updated wireless driver
  • a MAC address

Explanation: Topic 12.5.2
Regardless of the levels of security configured on a WLAN, a WPA secured WLAN always requires the use of an encryption key. Without the proper key, a device cannot connect to the network.

193. Place the steps for configuring zone-based policy (ZPF) firewalls in order from first to last.

1st Create zones.
2nd Create policies.
3rd Apply policies.
4th Assign zones to interfaces.
5th

Explanation: Topic 16.3.1

194. Which two options can limit the information discovered from port scanning? (Choose two.)

  • firewall
  • intrusion prevention system
  • authentication
  • encryption
  • passwords

Explanation: Topic 4.3.4
Using an intrusion prevention system (IPS) and firewall can limit the information that can be discovered with a port scanner. Authentication, encryption, and passwords provide no protection from loss of information from port scanning.

195. What type of security test uses simulated attacks to determine possible consequences of a real threat?

  • penetration testing
  • vulnerability scanning
  • integrity checking
  • network scanning

Explanation: Topic 23.2.3
There are many security tests that can be used to assess a network. Penetration testing is used to determine the possible consequences of successful attacks on the network. Integrity checking is used to detect and report changes made to systems. Vulnerability scanning is used to find weaknesses and misconfigurations on network systems. Network scanning is used to discover available resources on the network.

196. What are two tasks that can be accomplished with the Nmap and Zenmap network tools? (Choose two.)

  • password recovery
  • password auditing
  • validation of IT system configuration
  • TCP and UDP port scanning
  • identification of Layer 3 protocol support on hosts

Explanation: Topic 23.3.2
Nmap is a low-level network scanner that is available to the public and which has the ability to perform port scanning, to identify open TCP and UDP ports, and perform system identification. It can also be used to identify Layer 3 protocols that are running on a system.

197. A new PC is taken out of the box, started up and connected to the Internet. Patches were downloaded and installed. Antivirus was updated. In order to further harden the operating system what can be done?

  • Give the computer a nonroutable address.
  • Install a hardware firewall.
  • Turn off the firewall.
  • Remove unnecessary programs and services.
  • Remove the administrator account.
  • Disconnect the computer from the network.

Explanation: Topic 9.1.2
When hardening an operating system, patching and antivirus are part of the process. Many extra components are added by the manufacturer that are not necessarily needed.

198. What are two methods to maintain certificate revocation status? (Choose two.)

  • CRL
  • OCSP
  • LDAP
  • subordinate CA
  • DNS

Explanation: Topic 18.6.6
A digital certificate might need to be revoked if its key is compromised or it is no longer needed. The certificate revocation list (CRL) and Online Certificate Status Protocol (OCSP), are two common methods to check a certificate revocation status.

199. Match the network service with the description.

Explanation: Topic 6.2.11

syslog notifies the administrator with detailed system messages
SNMP allows administrators to manage network nodes
NTP synchronizes the time across all devices on the network
NetFlow provides statistics on IP packets flowing through network devices

200. Which user can override file permissions on a Linux computer?

  • only the creator of the file
  • any user that has ‘group’ permission to the file
  • any user that has ‘other’ permission to the file
  • root user

Explanation: Topic 8.5.2
A user has as much rights to a file as the file permissions allow. The only user that can override file permission on a Linux computer is the root user. Because the root user has the power to override file permissions, the root user can write to any file.

201. Which two tools have a GUI interface and can be used to view and analyze full packet captures? (Choose two.)

  • tcpdump
  • nfdump
  • Cisco Prime Network Analysis Module
  • Splunk
  • Wireshark

Explanation: Topic 20.1.3
The Network Analysis Module of the Cisco Prime Infrastructure system and Wireshark have GUI interfaces and can display full packet captures. The tcpdump tool is a command-line packet analyzer.

202. A threat actor has identified the potential vulnerability of the web server of an organization and is building an attack. What will the threat actor possibly do to build an attack weapon?

  • Obtain an automated tool in order to deliver the malware payload through the vulnerability.
  • Install a webshell on the web server for persistent access.
  • Collect credentials of the web server developers and administrators.
  • Create a point of persistence by adding services.

Explanation: Topic 27.2.3
One tactic of weaponization used by a threat actor after the vulnerability is identified is to obtain an automated tool to deliver the malware payload through the vulnerability.

203. Which Windows tool can be used by a cybersecurity administrator to secure stand-alone computers that are not part of an active directory domain?

  • Local Security Policy
  • PowerShell
  • Windows Firewall
  • Windows Defender

Explanation: Topic 7.4.4
Windows systems that are not part of an Active Directory Domain can use the Windows Local Security Policy to enforce security settings on each stand-alone system.

204. Which two classes of metrics are included in the CVSS Base Metric Group? (Choose two.)

  • Exploit Code Maturity
  • Exploitability
  • Confidentiality Requirement
  • Modified Base
  • Impact metrics

Explanation: Topic 25.2.2
The Base Metric Group of CVSS represents the characteristics of a vulnerability that are constant over time and across contexts. It contains two classes of metrics, Exploitability and Impact.

205. Which statement describes Cisco IOS Zone-Based Policy Firewall operation?

  • Router management interfaces must be manually assigned to the self zone.
  • Service policies are applied in interface configuration mode.
  • A router interface can belong to multiple zones.
  • The pass action works in only one direction.

Explanation: Topic 16.3.4
The pass action allows traffic only in one direction. Interfaces automatically become members of the self zone. Interfaces are assigned to zones in interface configuration mode, but most configuration takes place in global configuration mode and associated submodes. Interfaces can belong to only one zone at any time.

206. Match the correct sequence of steps typically taken by a threat actor carrying out a domain shadowing attack.

Explanation: Topic 4.2.2

Step 1 The website is compromised
Step 2 HTTP 302 cushioning is used
Step 3 Domain shadowing is used
Step 4 An exploit kit landing page is created
Step 5 Malware is spread through its payload

207. A flood of packets with invalid source IP addresses requests a connection on the network. The server busily tries to respond, resulting in valid requests being ignored. What type of attack has occurred?

  • UDP flood
  • TCP SYN flood
  • TCP session hijacking
  • TCP reset

Explanation: Topic 3.3.3
The TCP SYN Flood attack exploits the TCP three-way handshake. The threat actor continually sends TCP SYN session request packets with a randomly spoofed source IP address to an intended target. The target device replies with a TCP SYN-ACK packet to the spoofed IP address and waits for a TCP ACK packet. Those responses never arrive. Eventually the target host is overwhelmed with half-open TCP connections and denies TCP services.

208. In an attempt to prevent network attacks, cyber analysts share unique identifiable attributes of known attacks with colleagues. What three types of attributes or indicators of compromise are helpful to share? (Choose three.)

  • netbios names of compromised firewalls
  • IP addresses of attack servers
  • features of malware files
  • changes made to end system software
  • BIOS of attacking systems
  • system ID of compromised systems

Explanation: Topic 2.2.6
Many network attacks can be prevented by sharing information about indicators of compromise (IOC). Each attack has unique identifiable attributes. Indicators of compromise are the evidence that an attack has occurred. IOCs can be identifying features of malware files, IP addresses of servers that are used in the attack, filenames, and characteristic changes made to end system software.

209. When ACLs are configured to block IP address spoofing and DoS flood attacks, which ICMP message should be allowed both inbound and outbound?

  • echo
  • echo reply
  • source quench
  • unreachable

Explanation: Topic 14.6.3
Source quench ICMP messages provide the ability to have the sender throttle down the rate of messages when necessary. These messages should be allowed through the firewall in both inbound and outbound directions.

210. What does the telemetry function provide in host-based security software?

  • It updates the heuristic antivirus signature database.
  • It blocks the passage of zero-day attacks.
  • It enables updates of malware signatures.
  • It enables host-based security programs to have comprehensive logging functions.

Explanation: Topic 9.2.3
The telemetry function allows for robust logging functionality that is essential to cybersecurity operations. Some host-based security programs will submit logs to a central location for analysis.

211. A network administrator is trying to download a valid file from an internal server. However, the process triggers an alert on a NMS tool. What condition describes this alert?

  • true positive
  • false positive
  • true negative
  • false negative

Explanation: Topic 21.2.2

Alerts can be classified as follows:

True Positive: The alert has been verified to be an actual security incident.
False Positive: The alert does not indicate an actual security incident. Benign activity that results in a false positive is sometimes referred to as a benign trigger.
An alternative situation is that an alert was not generated. The absence of an alert can be classified as:

True Negative: No security incident has occurred. The activity is benign.
False Negative: An undetected incident has occurred.

212. What device would be used as the third line of defense in a defense-in-depth approach?

  • firewall
  • edge router
  • host
  • internal router

Explanation: Topic 11.1.9
In a defense-in-depth approach, the edge router would form the first line of defense. The firewall would be the second line of defense followed by the internal router making up the third line of defense.

213. Which three security services are provided by digital signatures? (Choose three.)

  • provides nonrepudiation using HMAC functions
  • provides data encryption
  • authenticates the destination
  • guarantees data has not changed in transit
  • provides confidentiality of digitally signed data
  • authenticates the source

Explanation: Topic 18.5.1
Digital signatures are a mathematical technique used to provide three basic security services. Digital signatures have specific properties that enable entity authentication and data integrity. In addition, digital signatures provide nonrepudiation of the transaction. In other words, the digital signature serves as legal proof that the data exchange did take place.

214. A company is using a public cloud provider to host its software development and distribution processes. What two cloud resources is the company solely responsible for in the shared security responsibility model? (Choose two.)

  • application
  • identity management
  • data
  • network control
  • customer endpoints

Explanation: Topic 17.3.2
Hosting software development and distribution processes is an example of the PaaS model. In the shared security responsibility model, the cloud customer is responsible for data and endpoints security.

215. What is the function of SDKs in application development?

  • to prevent software from being reverse engineered by replacing sensitive data with fictional data
  • to store precompiled SQL statements that execute tasks
  • to verify software can run under required security settings
  • to maintain data integrity and identify malicious input
  • to provide a repository of code to reduce time and cost of application development

Explanation: Topic 12.2.3
SDKs, or Software Development Kits, provide a repository of useful code to make application development faster and cheaper.

216. The manager of a new data center requisitions magnetic door locks. The locks will require employees to swipe an ID card to open. Which type of security control is being implemented?

  • corrective
  • compensative
  • recovery
  • preventive

Explanation: Topic 26.3.2
Preventive security controls prevent unwanted or unauthorized activities from occurring and/or apply restrictions to authorized users.

217. Which security organization maintains a list of common vulnerabilities and exposures (CVE) and is used by prominent security organizations?

  • SANS
  • MITRE
  • CIS
  • SecurityNewsWire

Explanation: Topic 24.2.4
The MITRE Corporation maintains a list of common vulnerabilities and exposures (CVE) used by prominent security organizations.

218. As a Cybersecurity Analyst, it is very important to keep current. It was suggested by some colleagues that NewsBites contains many good current articles to read. What network security organization maintains this weekly digest?

  • CIS
  • SANS
  • (ISC)2
  • Mitre

Explanation: Topic 24.1.1
The SysAdmin, Audit, Network, Security (SANS) Institute has many resources. One of them is called NewsBites, the weekly digest of news articles about computer security.

219. Match the IT security governance role with its description.

Data controller A person who determines the purposes for which and how to process personal data.
Data custodian A person who implements the classification and security controls for the data in accordance with the rules set out by the data owner.
Data protection officer A person who oversees an organization’s data protection strategy.
Data processor A person or organization processes personal data on behalf of the data controller.
Data steward A person who ensures that data supports an organization’s business needs and meets regulatory requirements.
Data owner A person who ensures compliance with policies and procedures assigns the proper classification to information assets and determines the criteria for accessing information assets.

Explanation: Topic 22.1.2

220. An organization has experienced several data breaches over the last five years. These data breaches have cost the organization financially and damaged its reputation. The organization has hired a cybersecurity penetration team to perform a full security audit on the entire organization. This independent contractor conducted the audit and found the following vulnerabilities:

  • Several user accounts allowed unauthorized and escalated privileges.
  • Systems and information without formal authorization.

What two steps can the organization take to mitigate these risks? (Choose two.)

  • log when elevated privileges are used
  • assign the least privilege to perform the given task
  • adopt a no reuse of passwords on different applications policy
  • terminate access and reset all passwords

Explanation: Topic 13.3.3

221. Which device is the first line of defense in a defense-in-depth approach to network security?

  • edge router
  • internal router
  • switch
  • firewall

Explanation: Topic 11.1.9
Edge router: The first line of defense is known as an edge router. The edge router has a set of rules specifying which traffic it allows or denies. It passes all connections that are intended for the internal LAN to the firewall.

222. Refer to the exhibit. Which technology generated the event log?

Traffic Contribution: 8% (3/37)

Flow information:
IPv4 SOURCE ADDRESS:        10.1.1.2
IPv4 DESTINATION ADDRESS:   13.1.1.2
INTERFACE INPUT:            Se0/0/1
TRNS SOURCE PORT:           8974
TRNS DESTINATION PORT:      80
IP TOS:                     0x00
IP PROTOCOL:                6
FLOW SAMPLER ID:            0
FLOW DIRECTION:             Input
ipv4 source mask:           /0
ipv4 destination mask:      /8
counter bytes:              205
ipv4 next hop address:      13.1.1.2
tcp flags:                  0x1b
interface output:           Fa0/0
counter packets:            5
timestamp first:            00:09:12.596
timestamp last:             00:09:12.606
ip source as:               0
  • Wireshark
  • web proxy
  • syslog
  • Netflow

Explanation: Topic 20.3.2
The source of the output is Netflow.

223. An investigator finds a USB drive at a crime scene and wants to present it as evidence in court. The investigator takes the USB drive and creates a forensic image of it and takes a hash of both the original USB device and the image that was created. What is the investigator attempting to prove about the USB drive when the evidence is submitted in court?

  • The investigator found a USB drive and was able to make a copy of it.
  • The data is all there.
  • An exact copy cannot be made of a device.
  • The data in the image is an exact copy and nothing has been altered by the process.

Explanation: Topic 18.4.1
A hash function ensures the integrity of a program, file, or device.

224. Match the security concept to the description.

Explanation: Topic 2.2.1

a weakness in a system vulnerability
a potential danger to an asset threat
the likelihood of undesireable consequences risk
a mechanism used to compromise an asset exploit

225. What is the principle behind the nondiscretionary access control model?

  • It applies the strictest access control possible.
  • It allows access decisions to be based on roles and responsibilities of a user within the organization.
  • It allows users to control access to their data as owners of that data.
  • It allows access based on attributes of the object be to accessed.

Explanation: Topic 13.2.2
The nondiscretionary access control model used the roles and responsibilities of the user as the basis for access decisions.

226. What is an example of a local exploit?

  • Port scanning is used to determine if the Telnet service is running on a remote server.
  • A threat actor performs a brute force attack on an enterprise edge router to gain illegal access.
  • A buffer overflow attack is launched against an online shopping website and causes the server crash.
  • A threat actor tries to gain the user password of a remote host by using a keyboard capture software installed on it by a Trojan.

Explanation: Topic 2.2.1
Vulnerability exploits may be remote or local. In a local exploit, the threat actor has some type of user access to the end system, either physically or through remote access. The exploitation activity is within the local network.

227. Why would threat actors prefer to use a zero-day attack in the Cyber Kill Chain weaponization phase?

  • to get a free malware package
  • to launch a DoS attack toward the target
  • to avoid detection by the target
  • to gain faster delivery of the attack on the target

Explanation: Topic 27.2.3
When a threat actor prepares a weapon for an attack, the threat actor chooses an automated tool (weaponizer) that can be deployed through discovered vulnerabilities. Malware that will carry desired attacks is then built into the tool as the payload. The weapon (tool plus malware payload) will be delivered to the target system. By using a zero-day weaponizer, the threat actor hopes that the weapon will not be detected because it is unknown to security professionals and detection methods are not yet developed.

228. A network administrator is checking the system logs and notices unusual connectivity tests to multiple well-known ports on a server. What kind of potential network attack could this indicate?

  • access
  • information theft
  • reconnaissance
  • denial of service

Explanation: A reconnaissance attack is the unauthorized discovery and mapping of systems, services, or vulnerabilities. One of the most common reconnaissance attacks is performed by using utilities that automatically discover hosts on the networks and determine which ports are currently listening for connections.

229. In which configuration would an outbound ACL placement be preferred over an inbound ACL placement?

  • when an outbound ACL is closer to the source of the traffic flow
  • when a router has more than one ACL
  • when an interface is filtered by an outbound ACL and the network attached to the interface is the source network being filtered within the ACL
  • when the ACL is applied to an outbound interface to filter packets coming from multiple inbound interfaces before the packets exit the interface

Explanation: An outbound ACL should be utilized when the same ACL filtering rules will be applied to packets coming from more than one inbound interface before exiting a single outbound interface. The outbound ACL will be applied on the single outbound interface.

230. Which statement describes a DNS stealth attack using threat actors' double IP flux technique?

  • They use it in malware to randomly generate domain names that can then be used as rendezvous points to command and control servers.
  • They hide phishing and malware delivery sites behind a quickly-changing network of compromised DNS hosts.
  • They rapidly change the hostname to IP address mappings and to also change the authoritative name server to be difficult to identify the source of the attack.
  • They gather domain account credentials to silently create multiple sub-domains to be used during the attacks.

231. Which ICMP message type should be stopped inbound?

  • source quench
  • unreachable
  • echo
  • echo-reply

Explanation: The echo ICMP packet should not be allowed inbound on an interface. The echo-reply should be allowed so that when an internal device pings an external device, the reply is allowed to return.

232. A technician has installed a third party utility that is used to manage a Windows 7 computer. However, the utility does not automatically start whenever the computer is started. What can the technician do to resolve this problem?

  • Set the application registry key value to one.
  • Change the startup type for the utility to Automatic in Services.
  • Uninstall the program and then choose Add New Programs in the Add or Remove Programs utility to install the application.
  • Use the Add or Remove Programs utility to set program access and defaults.

Explanation: The Services console in Windows OS allows for the management of all the services on the local and remote computers. The setting of Automatic in the Services console enables the chosen service to start when the computer is started.

233. The IT security personnel of an organization notice that the web server deployed in the DMZ is frequently targeted by threat actors. The decision is made to implement a patch management system to manage the server. Which risk management strategy method is being used to respond to the identified risk?

  • risk reduction
  • risk sharing
  • risk retention
  • risk avoidance

Explanation: There are four potential strategies for responding to risks that have been identified:

Risk avoidance – Stop performing the activities that create risk.
Risk reduction – Decrease the risk by taking measures to reduce vulnerability.
Risk sharing – Shift some of the risk to other parties.
Risk retention – Accept the risk and its consequences.

234. A cybersecurity analyst is going to verify security alerts using the Security Onion. Which tool should the analyst visit first?

  • Sguil
  • Bro
  • ELK
  • CapME

Explanation: The primary duty of a cybersecurity analyst is the verification of security alerts. In the Security Onion, the first place that a cybersecurity analyst will go to verify alerts is Sguil because it provides a high-level console for investigating security alerts from a wide variety of sources.

235. In what order are the steps in the vulnerability management life cycle conducted?

  • discover, prioritize assets, assess, remediate, verify, report
  • discover, prioritize assets, assess, remediate, report, verify
  • discover, prioritize assets, assess, report, remediate, verify
  • discover, assess, prioritize assets, report, remediate, verify

Explanation: There are six steps in the vulnerability management life cycle:
Discover
Prioritize assets
Assess
Report
Remediate
Verify

236. When implementing components into an enterprise network, what is the purpose of a firewall?

  • A firewall is a system that inspects network traffic and makes forwarding decisions based solely on Layer 2 Ethernet MAC addresses.
  • A firewall is a system that stores vast quantities of sensitive and business-critical information.
  • A firewall is a system that is designed to secure, monitor, and manage mobile devices, including corporate-owned devices and employee-owned devices.
  • A firewall is a system that enforces an access control policy between internal corporate networks and external networks.

Explanation: A firewall is a system that enforces an access control policy and prevents the exposure of sensitive hosts, resources, and applications to untrusted users.

237. Which type of firewall makes use of a proxy server to connect to remote servers on behalf of clients?

  • stateful firewall
  • application gateway firewall
  • stateless firewall
  • packet filtering firewall

Explanation: An application gateway firewall, also called a proxy firewall, filters information at Layers 3, 4, 5, and 7 of the OSI model. It uses a proxy server to connect to remote servers on behalf of clients. Remote servers will see only a connection from the proxy server, not from the individual clients.

238. A company is developing security policies. Which security policy would address the rules that determine access to and use of network resources and define the consequences of policy violations?

  • acceptable use policy
  • data policy
  • password policy
  • remote access policy

Explanation: An organization needs to establish clear and detailed security policies. Some of these policies are:
Password policy- Defines minimum password requirements, such as the number and type of characters used and how often they need to be changed.
Acceptable use policy- Highlights a set of rules that determine access to and use of network resources. It may also define the consequences of policy violations.
Remote access policy- Sets out how to remotely connect to the internal network of an organization and explains what information is remotely accessible.
Data policy- Sets out measurable rules for processing data within an organization, such as specifying where data is stored, how data is classified, and how data is handled and disposed of.

239. What key considerations does a business impact analysis (BIA) examine? (Choose four)

  • Mean time between objectives (RBOs)
  • Recovery point objectives (RPOs)
  • Mean time between failures (MTBF)
  • Mean time to repair (MTTR)
  • Recovery time objectives (RTOs)
  • Recovery point times (RPTs)

Explanation: Business continuity controls are more than just backing up data and providing redundant hardware. Creating a business continuity plan starts with carrying out a business impact analysis (BIA) to identify critical business processes, resources, and relationships between systems. The BIA focuses on the consequences of the interruption to critical business functions and examines the key considerations listed here: RTOs, RPOs, MTTR, and MTBF. The National Institute of Standards and Technology (NIST) developed best practices in relation to business continuity.

240. Match the command line tool with its function.

Explanation: Place the options in the following order:

used to assemble and analyze packets, and is used for port scanning, path discovery, OS fingerprinting, and firewall testing. hping
used to gather information from TCP and UDP network connections and can also be used for port scanning, monitoring, banner grabbing, and file copying. netcat
used in security auditing. It locates network hosts, detects operating systems, and identifies services. nmap
used for help troubleshooting NetBIOS name resolution problems in a Windows system. nbtstat
used in Mac/Linux operating systems to display TCP/IP settings (IP address, subnet mask, default gateway, DNS, and MAC information. ifconfig

241. Why are honeypots positioned in the cloud?

  • to have a faster solution to gather information
  • to have easier access to the honeypots
  • to isolate the honeypots from production networks
  • to create DMZ zones within the cloud

242. Which statement describes the characteristics of intrusion detection and intrusion prevention systems?

  • An IDS technology is a host-based approach, while IPS technology is a network-based approach.
  • IDS technology has no impact on network, while IPS technology might impact network traffic.
  • IDS can detect atomic patterns, while IPS can detect composite patterns.
  • IDS and IPS sensors kill the malicious traffic and send it to a "Bit Bucket".

243. What is the function provided by the Burpsuite tool in Kali Linux?

  • penetration test
  • managing
  • scanning
  • logging

244. Which three aspects of an organization must cybersecurity analysts identify before developing a comprehensive security policy? (Choose three.)

  • security budget
  • the placement of firewalls
  • potential threats
  • system vulnerabilities
  • the type of network data traffic
  • organization assets

Explanation: Cybersecurity analysts must prepare for any type of attack. It is their job to secure the assets of the organization’s network. To do this, cybersecurity analysts must first identify:

  • Assets – Anything of value to an organization that must be protected including servers, infrastructure devices, end devices, and the greatest asset, data.
  • Vulnerabilities – A weakness in a system or its design that could be exploited by a threat actor.
  • Threats – Any potential danger to an asset.

245. Which two security alert classifications do cybersecurity analysts prefer? (Choose two.)

  • true positive
  • true negative
  • false positive
  • false negative

Explanation:

  • True positives are the desired type of alert. They mean that the rules that generate alerts have worked correctly.
  • False positives are not desirable. Although they do not indicate that an undetected exploit has occurred, they are costly because cybersecurity analysts must investigate false alarms; therefore, time is taken away from investigation of alerts that indicate true exploits.
  • True negatives are desirable. They indicate that benign normal traffic is correctly ignored, and erroneous alerts are not being issued.
  • False negatives are dangerous. They indicate that exploits are not being detected by the security systems that are in place. These incidents could go undetected for a long time, and ongoing data loss and damage could result.

246. A network security engineer is examining the Zone-based Policy Firewall configuration on a Cisco router and observes the following output:

policy-map type inspect PRIV-TO-PUB-POLICY
 class type inspect HTTP-TRAFFIC
  inspect
 class class-default
  drop

What is the purpose of the class class-default and drop commands in this configuration segment?

  • It will apply default security policies to specified traffic class traffic members.
  • It will cause all traffic that is not a member of the specified traffic class to be dropped.
  • It ensures the logging of all traffic of the specified traffic class.
  • It will apply stated-based traffic control to default traffic allowed to pass between specific zones.

247. How does the Diamond Model of intrusion analysis assist cybersecurity analysts?

  • by illustrating the tactics, techniques, and procedures (TTP) as part of intrusion defense and attribution
  • by illustrating how an adversary pivots from one intrusion event to the next
  • by tracing the stages of an intrusion event from the early reconnaissance stages to the exfiltration of data
  • by conveying the common attributes and severity of intrusion vulnerabilities in computer hardware and software systems

Explanation: Topic 27.3.2
The Diamond Model is ideal for illustrating how an adversary pivots from one intrusion event to the next. By linking core features like infrastructure and capabilities, analysts can use information discovered in one event to identify the attacker or uncover additional victims

Subscribe
Notify of
guest

24 Corrections & Clarifications