Security
442 questions
An IT administrator is configuring Local Security Policy (secpol.msc) on corporate Windows 11 Pro workstations. Company compliance mandates that when an administrative user operating under Admin Approval Mode attempts to run a task requiring elevation, the system must require full credential re-authentication on an isolated screen rather than relying on a consent prompt. Which Local Security Policy configuration fulfills this security requirement?
A network technician is configuring networking equipment inside an intermediate distribution frame (IDF) room shared with third-party facility contractors. Although the room itself requires keycard access, several unassigned Ethernet switch ports on the rack remain exposed, creating a risk of unauthorized physical connection to the internal network. Which of the following physical security controls should the technician implement to directly prevent unauthorized network cable insertions into these exposed ports?
A user contacts the IT helpdesk reporting that their Windows workstation is displaying suspicious pop-up messages and experiencing severe performance degradation. An IT technician inspects the device and identifies symptoms of an active malware infection. According to the standard CompTIA 7-step malware remediation process, which action should the technician perform NEXT?
An IT auditor flags unauthorized background network traffic originating from a finance manager's Windows 11 workstation. A technician inspects the system, confirms an active spyware infection, and immediately disconnects the ethernet cable and disables wireless adapters to isolate the device. Next, the technician disables Windows System Restore to prevent infected files from being backed up. According to the CompTIA 7-step malware remediation process, which action should the technician perform next?
An incident responder is investigating a compromised Windows 11 workstation where a trojan dropper disabled local security services and established persistence in system boot configurations. The machine has already been isolated from the network and quarantined. Following the standard CompTIA malware remediation process, which TWO actions should the responder execute immediately prior to performing the system remediation scan? (Select TWO.)
Select all that apply
A network support technician is assisting a user remotely on a Windows 11 Professional workstation. Whenever the user attempts an operation requiring administrative privileges, the technician's remote control software displays a blank black screen instead of showing the User Account Control (UAC) elevation prompt, preventing the technician from typing administrative credentials. Which Local Security Policy setting should be disabled to allow remote viewing of UAC prompts without completely turning off UAC?
A user logged into a Windows workstation with a standard user account attempts to execute a software installer. Before the installation wizard opens, the screen dims and a dialog box pops up asking for an administrator password to proceed. Which Windows security feature is responsible for displaying this credential prompt?
An IT manager hires a third-party disposal service to physically shred decommissioned hard drives containing sensitive company records. Which of the following documents should the manager obtain from the vendor to officially verify compliance with media destruction standards?
A systems administrator is preparing to repurpose several Self-Encrypting Drives (SEDs) from a decommissioned database server that previously held highly confidential patient records. The drives must be sanitized in compliance with organizational policy before being redeployed to a non-sensitive testing environment. Which of the following methods should the administrator execute to instantly render all existing data irrecoverable while keeping the drives fully operational?
Match each workstation security hardening requirement or administrative objective to the most appropriate Windows configuration control or security feature that implements it.
Click a left item, then click its matching right item
Items
Matches
A human resources administrator receives a targeted email appearing to come from the company's payroll software vendor, requesting an urgent update to employee direct deposit banking details via an attached link. On the same day, an IT technician discovers several unlabelled USB flash drives intentionally left on tables in the employee cafeteria. Which of the following social engineering tactics are demonstrated in these security incidents? (Select TWO.)
Select all that apply
A desktop support technician is hardening a standalone Windows 11 Pro workstation to comply with corporate administrative policies. The requirement dictates that administrative users must be forced to enter their password on an isolated desktop whenever an elevation prompt occurs. Place the configuration steps in the correct order to implement and enforce this security baseline.
Drag items to arrange them in the correct order
An IT technician is preparing to return a leased commercial multifunction printer (MFP) to the leasing vendor at the end of its contract term. The MFP contains an internal hard disk drive that cached print jobs, copy histories, and scanned documents containing sensitive organization data. The printer must remain fully functional for the vendor upon return. Which of the following is the most appropriate method to sanitize the internal drive prior to returning the printer?
A security administrator is designing physical security enhancements for an organization's internal server room to prevent tailgating at the room entrance and to protect the internal hardware components of individual servers from physical tampering. Which TWO physical security controls should the administrator implement to meet these specific requirements?
Select all that apply
A IT support technician is tasked with resolving a malware infection reported on a corporate Windows workstation. Place the following steps of the standard CompTIA 7-step malware remediation process in the correct chronological order from first to last.
Drag items to arrange them in the correct order
A cybersecurity technician is responding to a confirmed Trojan infection on an enterprise Windows 11 workstation. Place the following remediation actions in the exact sequential order required by the CompTIA 7-step malware removal process.
Drag items to arrange them in the correct order
A systems administrator needs to configure standalone Windows 11 Pro workstations so that standard users are automatically denied elevation requests without being prompted for administrator credentials. In what sequential order should the administrator perform the steps to enforce this restriction using the Local Security Policy snap-in?
Drag items to arrange them in the correct order
A technician is performing basic workstation hardening on a newly installed Windows computer. Place the following security steps in the logical order they should be performed to secure the system from initial deployment to final user handoff.
Drag items to arrange them in the correct order
An IT security administrator is preparing to return a leased enterprise storage array shelf populated with flash-based NVMe solid-state drives (SSDs) containing confidential financial records. According to organizational compliance policy, all storage media must be sanitized to the NIST SP 800-88 'Purge' standard before transfer. Additionally, the lease contract stipulates that the physical drives must remain fully functional and undamaged upon return to avoid severe financial penalties. Which of the following data disposal actions should the administrator perform to satisfy both constraints?
Match each mobile device and embedded system security feature on the left with its correct operational description or purpose on the right.
Click a left item, then click its matching right item
Items
Matches