Security
442 questions
A remote software engineer receives an unexpected phone call from an individual claiming to be a senior network administrator from the corporate IT helpdesk. The caller states that an urgent security patch requires immediate account validation and requests that the engineer approve a multifactor authentication (MFA) push notification sent to their mobile device. Which social engineering threat vector is primarily being conducted in this scenario?
A desktop technician is setting up a workstation in a corporate lobby for visitor registration. To prevent unauthorized users from accessing the system when the desk is left unattended, which workstation hardening control should the technician implement?
Match each data destruction and sanitization method to its correct operational description and capability.
Click a left item, then click its matching right item
Items
Matches
A system administrator is hardening corporate-issued smart Point-of-Sale (PoS) handheld devices running an embedded operating system used by field merchants. The devices process sensitive customer payment data, are frequently operated in public venues, and are at high risk of physical theft or untrusted app installation. Which TWO of the following security measures should the administrator enforce on these embedded endpoints to mitigate these risks?
Select all that apply
A system administrator is tasked with hardening standalone Windows workstations deployed in a building lobby for public visitor registration. The workstations must be secured against unauthorized access, privilege escalation, and automated malicious code execution from external drives. Which TWO of the following account and system policy configurations should the administrator implement to meet these hardening requirements?
Select all that apply
A user reports that after changing their corporate network domain password, Windows continues to automatically attempt authentication to an internal shared folder using their old password, causing repeated account lockouts. Which Control Panel utility should a technician access to update or remove these cached network authentication details?
A network technician is configuring wireless security settings across various company locations and access scenarios. Match each wireless security requirement or deployment scenario on the left to its corresponding technology or protocol on the right.
Click a left item, then click its matching right item
Items
Matches
A network technician is preparing a newly imaged desktop computer for deployment in an accounting office. To minimize the workstation's attack surface against potential network-based threats, which security hardening best practice should the technician implement?
As an IT support technician, you are implementing standard security controls across office desktop systems. Match each workstation hardening technique on the left to its primary risk mitigation objective on the right.
Click a left item, then click its matching right item
Items
Matches
During a security audit at a logistics company, an administrator discovers a Windows 11 workstation exhibiting unauthorized rootkit activity that compromised low-level system drivers. To remediate the breach, the administrator disconnects the network cable, disables System Restore, boots the system into a clean pre-installation environment, and successfully executes a bootable anti-malware utility to eradicate the infection. After booting into Safe Mode and completing a secondary scan that verifies the system is entirely clean, which of the following actions should the administrator take NEXT to follow the standard CompTIA malware remediation process?
A helpdesk technician is reviewing several recent security incident logs across the organization. Match each reported security incident scenario on the left to its corresponding threat type on the right.
Click a left item, then click its matching right item
Items
Matches
A system technician is tasked with preparing a leased enterprise multifunction printer (MFP) for return to a third-party vendor. The MFP contains an internal magnetic hard disk drive that cached confidential scanned documents. Corporate policy mandates that all stored data must be sanitized so it is completely unrecoverable, but the vendor lease contract requires that the device and its storage hardware remain fully functional upon return. Which of the following is the BEST method to fulfill these requirements?
An IT technician is configuring legacy embedded environmental monitoring units throughout a datacenter facility. The embedded operating system on these units cannot host endpoint security agents, lacks native full-disk encryption capabilities, and cannot be enrolled in the enterprise Mobile Device Management (MDM) solution. To prevent unauthorized access and protect the core network from lateral movement if a monitor is compromised, which of the following is the BEST primary security measure to implement?
A technician is implementing security baselines on standalone Windows 11 computers deployed in a sensitive research facility. To harden the workstations against unauthorized network name spoofing and lateral movement attempts without interfering with required administrative tasks, the technician must turn off vulnerable legacy broadcast protocols and shut down unused background operating system services. Which of the following security actions best accomplishes these hardening goals?
A systems administrator is configuring a wireless network for a medical office. Company policy mandates that every employee must authenticate individually using their corporate Active Directory network credentials, and all wireless traffic must be encrypted using modern AES encryption. Which of the following wireless security configurations best meets these security requirements?
A desktop support technician is configuring Local Security Policy (secpol.msc) settings on standalone Windows 11 Pro workstations. The organization's security policy mandates two specific conditions: standard users must be prompted to enter administrator credentials whenever attempting a task requiring elevation, and administrators logged into their accounts must be presented with a prompt asking for explicit consent without needing to re-enter their password. Which of the following User Account Control (UAC) policy settings should the technician configure to meet these requirements? (Select TWO.)
Select all that apply
A security technician at a corporate facility reviews badge access logs and camera footage following an unauthorized entry into a restricted server room. The footage reveals an unknown individual carrying several large, heavy boxes who asked an employee to hold the badge-restricted electronic door open. The employee complied out of courtesy and held the door, allowing the individual to enter the facility without scanning a security credential. Which of the following social engineering techniques occurred in this scenario?
An IT technician in an engineering laboratory responds to a workstation flagged for suspicious file-encrypting worm activity. The technician has already quarantined the machine by disconnecting its network cable and disabling all wireless adapters. Which of the following actions should the technician perform NEXT before conducting a full system anti-malware scan? (Select TWO.)
Select all that apply
An IT technician is decommissioning legacy corporate workstations that contain a mix of magnetic hard disk drives (HDDs) and solid-state drives (SSDs) containing confidential employee information. The drives must be sanitized prior to transferring the hardware to an external recycling facility. Which of the following actions represent valid data destruction methods for these storage media? (Select TWO.)
Select all that apply
An IT security administrator is establishing mobile endpoint and embedded system security policies for an enterprise organization. Match each operational security goal on the left with the correct policy control or technical implementation on the right.
Click a left item, then click its matching right item
Items
Matches