Security

442 questions

Question 41Question

An IT technician is setting up desktop workstations in an unsupervised public library computer room. The facility management wants to prevent visitors from opening the computer cases to steal or tamper with internal components such as RAM and system drives. Which of the following physical security controls should the technician install?

Show answer & explanation

Answer: Chassis locks

Answer

Chassis locks
Chassis locks (or case locks) prevent unauthorized individuals from removing the side panel or cover of a computer case, effectively protecting internal components like memory, storage drives, and processors from physical theft or tampering.

Step-by-Step Solution

1
Identify the primary threat described in the scenario
The main risk is unauthorized physical access to internal system components (RAM, storage drives) by opening the desktop computer case.
Understanding the specific vector of physical access isolates the appropriate physical security control.
2
Evaluate the available physical security controls against the specific requirement
Chassis locks directly restrict physical access to the computer's internal enclosure.
Securing the case physically prevents users from removing panels or accessing internal hardware.

Key Concept

Hardware Enclosure Protection
Estimated Time:1m 0s
Question 42Question

A corporate enterprise houses its database servers in a shared colocation facility where vendors and third-party technicians routinely access adjacent hardware. The company must implement a physical security control specifically for its rack cabinets that physically restricts cabinet opening to designated IT staff while automatically recording electronic audit logs of every individual cabinet access attempt. Which of the following physical security controls best fulfills these requirements?

Show answer & explanation

Answer: Smart rack locks integrated with smart card or biometric authentication

Answer

Smart rack locks integrated with smart card or biometric authentication
Deploying smart rack locks with smart card or biometric readers ensures that only authorized personnel can open specific cabinet doors. Because the lock communicates with an access management system, every lock/unlock event is tied to a specific credential and recorded electronically in an immutable audit log, perfectly satisfying both physical isolation in colocation spaces and compliance logging requirements.

Step-by-Step Solution

1
Analyze the physical security requirement
Identified two primary needs: physical access restriction at the individual rack cabinet level in a shared room, and automated electronic audit logging of access events.
General room-level security is insufficient because third parties share the room space.
2
Evaluate candidate controls against access restriction and logging requirements
Smart rack cabinet locks utilize electronic access control (cards/biometrics) to physically unlock cabinet doors while creating an audit log of who opened the cabinet and when.
Passive surveillance or manual sign-in logs fail to meet automated logging or individual authentication criteria.

Key Concept

Rack Level Physical Access Control and Audit Logging
Estimated Time:1m 30s
Question 43Question

An IT technician is tasked with securing standalone server enclosures located inside a shared office space to prevent unauthorized physical opening of the equipment cases and theft of internal storage drives. Which TWO of the following physical security controls should the technician implement? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: Server chassis locks; Cable locks secured to immovable structural anchors

Answer

The correct physical security controls are server chassis locks and cable locks secured to immovable structural anchors.
Chassis locks restrict physical access to internal system components by securing the server case, while cable locks anchored to permanent fixtures prevent physical removal and theft of the entire server enclosure.

Step-by-Step Solution

1
Identify the physical security objectives given in the scenario.
The requirements are protecting the internal components from unauthorized case opening and preventing theft of the system unit.
Choosing the appropriate physical control requires matching the physical barrier to the specific risk vector.
2
Evaluate which controls address these specific hardware risks.
Chassis locks prevent case opening to secure internal drives; cable locks anchor the equipment to prevent theft of the entire unit.
Both measures directly mitigate physical access and equipment removal in a shared office environment.

Key Concept

Physical Hardware Protection Controls
Question 44Question

During a physical security evaluation at a financial firm's branch site, an auditor observes that unauthorized individuals can easily closely follow authorized personnel through card-swiped entry points into a sensitive data closet. The site manager requires a physical control that specifically restricts entry to one person at a time and actively prevents piggybacking without creating an emergency egress hazard. Which of the following physical security controls should be implemented?

Show answer & explanation

Answer: An access control vestibule equipped with interlocking doors and weight sensors

Answer

An access control vestibule equipped with interlocking doors and weight sensors is the correct physical security control.
An access control vestibule (also known as a mantrap) uses a set of two interlocking doors where the second door will not unlock until the first door closes completely. When combined with weight or optical sensors inside the vestibule, it enforces single-person entry and actively prevents tailgating or piggybacking.

Step-by-Step Solution

1
Analyze the physical security threat in the scenario
Identified tailgating/piggybacking where unauthorized individuals follow legitimate staff through secured doorways.
The scenario explicitly highlights unauthorized visitors walking closely behind authorized employees upon card entry.
2
Evaluate potential physical security mechanisms against anti-tailgating requirements
An access control vestibule (mantrap) enforces single-occupant progression using interlocking doors and presence/weight sensors.
Mantraps physically isolate the entry process so the second door will not unlock if multiple individuals are detected.
3
Differentiate correct control from ineffective alternatives
Biometrics, privacy screens, and bollards address authentication, visual privacy, and vehicle safety respectively, but fail to prevent tailgating.
Only an access control vestibule directly prevents physical piggybacking at pedestrian doorways.

Key Concept

Access Control Vestibules (Mantraps) for Anti-Tailgating
Question 45Question

A security technician is documenting physical security measures for a corporate data facility. Match each physical security control mechanism with its primary security function.

Click a left item, then click its matching right item

Items

Biometric scanner
Access control vestibule
Faraday bag
Bollard

Matches

Show answer & explanation

Answer

Biometric scanner matches with authenticating personnel based on unique biological characteristics. Access control vestibule matches with preventing tailgating by using interlocking doors. Faraday bag matches with blocking electromagnetic signals to shield mobile devices. Bollard matches with preventing vehicle ramming attacks.
Each physical security control serves a specific protective role: biometric scanners verify biological traits; access control vestibules isolate traffic with interlocking doors to stop tailgating; Faraday bags block radio frequency signals to prevent remote access; and bollards provide physical structural protection against vehicle impacts.

Step-by-Step Solution

1
Analyze each physical security control item on the left.
Identified four physical security controls: Biometric scanner, Access control vestibule, Faraday bag, and Bollard.
Matching requires understanding the specific operational purpose of each physical barrier or defense mechanism.
2
Pair each physical control with its corresponding threat mitigation function.
Biometric scanner pairs with biological authentication; Access control vestibule pairs with interlocking door tailgating prevention; Faraday bag pairs with electromagnetic signal blocking; Bollard pairs with vehicle ramming defense.
Each physical control targets a distinct vector of unauthorized access or physical/wireless compromise.

Key Concept

Physical Security Controls and Threat Mitigation Functions
Question 46Question

A technician is investigating a malware infection on a workstation in the accounting department. The employee reports finding an unlabeled USB flash drive in the company breakroom and plugging it into the computer to identify its owner, which immediately executed malicious code. Which of the following social engineering attack types best describes this scenario?

Show answer & explanation

Answer: Baiting

Answer

Baiting
Baiting is a social engineering attack where an attacker leaves malware-infected media, such as a USB flash drive or external storage, in a place where potential victims will find it (like a breakroom or parking lot). The attacker relies on the victim's natural curiosity to plug the device into a computer, which runs the malicious payload.

Step-by-Step Solution

1
Analyze the attack mechanism described in the scenario.
The victim found an enticing physical object (an unlabeled USB drive) in a common area and plugged it in out of curiosity.
Identifying the vector (physical media drop) and psychological trigger (curiosity) isolates the threat category.
2
Match the observed threat vector to standard security definitions.
Leaving physical media loaded with malware to exploit curiosity is defined specifically as baiting.
Baiting lures victims into compromising their own systems through physical media or software promises.

Key Concept

Baiting Social Engineering Attacks
Estimated Time:45s
Question 47Question

Match each social engineering threat type on the left with its corresponding attack methodology on the right.

Click a left item, then click its matching right item

Items

Spear Phishing
Watering Hole Attack
Pretexting
Shoulder Surfing

Matches

Show answer & explanation

Answer

Spear Phishing matches with targeted, customized email communications; Watering Hole Attack matches with compromising frequently visited third-party websites; Pretexting matches with inventing a fabricated scenario to build trust; Shoulder Surfing matches with direct visual observation of screens or keyboards.
Each threat type is paired precisely with its defined attack vector: Spear phishing utilizes highly customized emails aimed at specific individuals, watering hole attacks infect websites frequently accessed by target groups, pretexting relies on fabricated scenarios to extract credentials, and shoulder surfing physically observes screens or keypads.

Step-by-Step Solution

1
Analyze digital versus physical social engineering attack vectors
Identified direct visual observation as shoulder surfing and customized email targeting as spear phishing.
Categorizing the operational vector isolates the specific threat definition.
2
Distinguish between strategic web compromises and identity fabrication scenarios
Watering hole attack targets shared web resources, whereas pretexting relies on impersonation and narrative creation.
Understanding the delivery mechanism differentiates watering hole attacks from pretexting scenarios.
3
Map each threat term to its exact operational description
All four threat pairs correctly aligned based on CompTIA threat taxonomy definitions.
Ensures accurate identification for security incident diagnosis and mitigation.

Key Concept

Social Engineering Threat Methodologies and Classifications
Question 48Question

A facilities security team is auditing physical access controls across a high-security corporate facility. Match each specialized physical security mechanism to the specific security risk it is primarily designed to mitigate.

Click a left item, then click its matching right item

Items

Faraday cage
Mantrap (Access Control Vestibule)
Bollards
Biometric scanner with anti-passback

Matches

Show answer & explanation

Answer

Each physical security control maps directly to its intended threat mitigation: Faraday cage mitigates electromagnetic emissions interception; Mantrap prevents tailgating/piggybacking; Bollards stop vehicle ramming attacks; Biometric scanner with anti-passback prevents credential pass-back and re-entry abuse.
Each physical security mechanism addresses a unique physical threat vector: Faraday cages block RF emissions, mantraps enforce single-person physical access, bollards prevent vehicle ramming, and anti-passback controls stop credential reuse.

Step-by-Step Solution

1
Analyze the protection mechanism of a Faraday cage
Identified that enclosure shielding stops RF emissions.
Faraday cages block electromagnetic signals, addressing eavesdropping or RF leakage.
2
Analyze the access control features of a mantrap (vestibule)
Identified interlocking door control.
Access control vestibules limit physical entry to one authenticated person at a time to prevent tailgating.
3
Analyze the structural role of bollards
Identified vehicle barrier capabilities.
Bollards are short posts designed to block vehicular access and absorb vehicle kinetic energy.
4
Analyze anti-passback security logic on biometric/card scanners
Identified exit/entry tracking constraint.
Anti-passback prevents an authenticated user from passing access credentials back to an unauthorized person to gain entry.

Key Concept

Physical Security Controls and Threat Mitigation Functions
Question 49Question

A network administrator is designing an enterprise wireless infrastructure with varying security requirements across departments. Match each wireless authentication protocol or framework to its specific technical deployment requirement or operational security characteristic.

Click a left item, then click its matching right item

Items

EAP-TLS
PEAP
WPA3-Enterprise (192-bit Mode)
WPA2-Personal

Matches

Show answer & explanation

Answer

EAP-TLS pairs with server and client certificate requirement; PEAP pairs with server-side certificate creating a TLS tunnel for password authentication; WPA3-Enterprise (192-bit Mode) pairs with GCMP-256 encryption and HMAC-SHA384; WPA2-Personal pairs with PSK and CCMP vulnerable to offline dictionary attacks.
Each wireless framework is correctly matched based on standard 802.11 and 802.1X specifications: EAP-TLS mandates mutual PKI certificate verification; PEAP builds a server-authenticated TLS tunnel to protect user password challenges; WPA3-Enterprise (192-bit mode) elevates enterprise security with GCMP-256; and WPA2-Personal relies on static PSKs paired with CCMP encryption.

Step-by-Step Solution

1
Analyze certificate requirements for 802.1X EAP types
Identify that EAP-TLS strictly requires mutual authentication via digital certificates on both server and client endpoints, whereas PEAP requires a certificate only on the server.
Differentiating EAP-TLS from PEAP depends on evaluating certificate management complexity versus password authentication capabilities.
2
Evaluate high-security WPA3 suite specifications
Confirm that 192-bit WPA3-Enterprise specifies Suite B cryptographic standards including GCMP-256 cipher suites and SHA-384 message integrity.
Standard WPA2/WPA3 uses 128-bit CCMP/GCMP, whereas the optional 192-bit mode upgrades symmetric encryption to 256-bit GCMP.
3
Examine legacy SOHO security traits and attack vectors
Determine that WPA2-Personal relies on a static pre-shared key (PSK) with CCMP, which exposes the four-way handshake to offline dictionary attacks.
WPA3 replaced PSK with SAE to prevent offline dictionary attacks, making PSK vulnerability a key trait of WPA2-Personal.

Key Concept

Wireless Authentication Protocols and Enterprise Encryption Standards
Question 50Question

A corporate executive frequently views confidential financial reports on a company laptop while traveling through busy airport lounges and public spaces. To mitigate the risk of shoulder surfing and unauthorized viewing of screen content by nearby individuals, which of the following physical security controls should be installed on the laptop screen?

Show answer & explanation

Answer: Privacy screen filter

Answer

Privacy screen filter
A privacy screen filter is designed specifically to restrict light transmission from side viewing angles, preventing onlookers from seeing sensitive data displayed on a monitor while maintaining clear visibility for the direct user.

Step-by-Step Solution

1
Identify the threat scenario described in the stem.
The primary threat is shoulder surfing (unauthorized visual inspection of screen content in public areas).
Choosing the correct control requires matching the physical security mechanism to the specific risk.
2
Evaluate the function of physical security controls against shoulder surfing.
A privacy screen filter narrows the viewing cone of the display screen, making it unreadable from side viewing angles.
This directly counteracts shoulder surfing while allowing the primary user to work normally.

Key Concept

Physical Security Controls - Privacy Filters
Question 51Question

A network technician discovers an rogue wireless router plugged into an active Ethernet wall jack in an unmonitored building lobby. To prevent visitors from physically attaching unauthorized devices to open network jacks in public areas without requiring major switch reconfiguration, which of the following physical security controls should be implemented?

Show answer & explanation

Answer: Physical RJ45 port locks

Answer

Physical RJ45 port locks
Physical RJ45 port locks fit inside unused network ports and require a special tool/key to remove. They provide a direct physical barrier preventing unauthorized hardware from connecting to active wall jacks in open or public spaces.

Step-by-Step Solution

1
Identify the primary threat vector
Unauthorized physical insertion of network hardware into open RJ45 wall outlets in a public area.
Publicly accessible Ethernet jacks present an open physical attack surface for rogue network access.
2
Evaluate physical security controls designed for open interfaces
RJ45 port locks physically cap and block unused Ethernet ports, requiring a physical key to remove.
This directly prevents unauthorized cable connections at the jack level without altering room permissions or tethering equipment.

Key Concept

Physical interface hardening via RJ45 port locks
Question 52Question

A cybersecurity technician is investigating a malware outbreak affecting several workstations in the research and development department. Network traffic logs indicate that all compromised devices recently accessed a trusted, niche vendor site commonly used by department employees for hardware specifications. Further analysis reveals that malicious actors infected the vendor site and embedded an exploit script specifically designed to target employees visiting from the organization's IP address range. Which of the following social engineering threat types best describes this attack vector?

Show answer & explanation

Answer: Watering hole attack

Answer

The correct threat type is a watering hole attack.
A watering hole attack targets a specific group by compromising a website they frequently visit and trust. Once the site is infected, the attacker delivers malware to visitors associated with the target organization.

Step-by-Step Solution

1
Analyze the incident symptoms and delivery mechanism.
Infection occurred when multiple employees visited a trusted, frequently accessed third-party vendor site.
Identifying the vector requires determining how the malicious payload reached the victim systems.
2
Evaluate the targeting method described in the scenario.
The legitimate site was compromised specifically to exploit users originating from the company's IP block.
This strategy targets a specific group by lying in wait at a place they naturally gather.
3
Match the observed behavior to CompTIA security threat classifications.
A compromised legitimate site used to target a specific organization defines a watering hole attack.
Distinguishing watering hole attacks from direct messaging techniques like spear phishing relies on identifying the passive, site-based compromise mechanism.

Key Concept

Watering Hole Attack
Estimated Time:1m 15s
Question 53Question

Match each social engineering threat vector on the left with its corresponding attack description on the right.

Click a left item, then click its matching right item

Items

Smishing
Typosquatting
Pretexting
Watering Hole

Matches

Show answer & explanation

Answer

Smishing corresponds to SMS text message phishing; Typosquatting corresponds to taking advantage of misspelled domain names; Pretexting corresponds to inventing a false story to gain information; Watering Hole corresponds to compromising websites frequently visited by target groups.
Smishing uses cellular SMS text messages; Typosquatting exploits browser URL entry mistakes; Pretexting relies on an invented narrative to manipulate targets; Watering Hole attacks compromise specific sites visited by targeted organizations.

Step-by-Step Solution

1
Analyze the attack medium and methodology described in each item.
Identify that text messaging maps to Smishing, misspelled web addresses map to Typosquatting, crafted deceptive narratives map to Pretexting, and infected destination websites map to Watering Hole attacks.
Social engineering categories are defined by their specific delivery mechanisms and psychological tactics.

Key Concept

Social Engineering Vectors and Attack Methodologies
Estimated Time:1m 0s
Question 54Question

An IT security technician is auditing physical security for a high-security server room at a branch office. Audit logs indicate that unauthorized individuals have repeatedly gained entry by following authorized personnel closely through the primary entrance door immediately after a valid badge scan. The organization requires a physical security enhancement that enforces single-person entry and prevents tailgating without requiring dedicated physical security guard staff. Which of the following physical security controls should the technician recommend?

Show answer & explanation

Answer: An access control vestibule equipped with interlocking doors and presence sensors

Answer

An access control vestibule equipped with interlocking doors and presence sensors is the most effective physical control to prevent tailgating.
An access control vestibule (mantrap) consists of a small space with two interlocking doors. The inner door will not unlock until the outer door closes completely and internal weight or presence sensors confirm single occupancy, effectively blocking tailgating without requiring physical guards.

Step-by-Step Solution

1
Identify the specific physical security vulnerability described in the scenario
The vulnerability is tailgating (piggybacking), where unauthorized individuals bypass physical entry authentication by closely following authorized staff.
Selecting the correct physical security measure requires matching the control to the exact attack vector.
2
Analyze the operational requirements of the target control
The requirement specifies physical enforcement of single-occupancy entry without relying on manual guard supervision.
Detection-only controls (CCTV) or identity verification controls (biometrics) fail to physically block an unauthorized person from stepping through an unlocked door.
3
Select the physical control mechanism designed for tailgating mitigation
An access control vestibule (mantrap) with interlocking doors and occupancy sensors ensures only one individual passes through at a time.
The interlocking mechanism holds the second door locked until the first door closes and single-person occupancy is validated.

Key Concept

Physical Access Control Vestibule (Mantrap)
Estimated Time:1m 30s
Question 55Question

An IT security administrator is updating the physical security policy for an enterprise organization. Match each physical security control mechanism on the left to its primary protective function on the right.

Click a left item, then click its matching right item

Items

Biometric scanner
Vehicle bollard
Mantrap
Privacy filter

Matches

Show answer & explanation

Answer

Biometric scanner matches with verifying unique physical characteristics for access control; Vehicle bollard matches with blocking physical perimeter access against vehicle ramming; Mantrap matches with enforcing single-person entry to prevent tailgating; Privacy filter matches with limiting display viewing angles to prevent shoulder surfing.
Each physical control addresses a distinct physical threat: biometric scanners evaluate physical traits (fingerprints/retina) for identity verification; bollards provide physical resistance against motor vehicle penetration; mantraps use dual interlocking doors to physically isolate individuals and block tailgating; and privacy filters restrict viewing angles to defeat visual observation (shoulder surfing).

Step-by-Step Solution

1
Examine the physical security mechanisms listed in the left column.
Identified Biometric scanner, Vehicle bollard, Mantrap, and Privacy filter.
Understanding the function of each device is necessary to pair it with its security purpose.
2
Map each control to the specific physical threat or access requirement it addresses.
Biometrics prevent unauthorized credential usage, bollards block vehicles, mantraps stop unauthorized physical follow-through (tailgating), and privacy filters block visual eavesdropping.
Matching each control to its primary objective demonstrates knowledge of physical security controls.

Key Concept

Physical Security Controls and Functions
Question 56Question

A network technician is configuring an enterprise wireless network for a corporate environment. The organization's security policy mandates individual user-based authentication integrated with a RADIUS server, strict mutual authentication enforcing client-side digital certificates on corporate-managed laptops, and strong modern encryption protocols without relying on password-only authentication. Which of the following wireless security standards and EAP protocols best meets these requirements?

Show answer & explanation

Answer: WPA3-Enterprise utilizing EAP-TLS

Answer

WPA3-Enterprise utilizing EAP-TLS is the correct choice because EAP-TLS enforces mutual authentication requiring digital certificates on both the authentication server and the client device.
WPA3-Enterprise uses 802.1X port-based network access control to interface with a RADIUS server. EAP-TLS (Extensible Authentication Protocol - Transport Layer Security) requires mutual authentication, meaning both the authentication server and the client device must present valid, trusted digital certificates. This satisfies the security policy for client certificate enforcement.

Step-by-Step Solution

1
Analyze the organizational security requirements outlined in the prompt.
The requirements demand 802.1X RADIUS integration (enterprise mode) and mandatory client-side digital certificate authentication.
Personal modes (PSK/SAE) rely on shared passphrases, whereas Enterprise modes integrate with RADIUS servers for individual credentials.
2
Evaluate the authentication capabilities of candidate EAP protocols.
EAP-TLS (Transport Layer Security) mandates certificate-based mutual authentication for both client and server. PEAP-MSCHAPv2 uses server certificates but client passwords.
Only EAP-TLS satisfies the strict requirement for client-side digital certificate verification.
3
Select the modern wireless security framework.
WPA3-Enterprise with EAP-TLS provides 192-bit enterprise security mode support alongside robust encryption standards.
WPA3-Enterprise combined with EAP-TLS represents the highest assessment standard for secure corporate wireless deployment.

Key Concept

Wireless Enterprise Authentication Protocols (802.1X, RADIUS, and EAP-TLS)
Question 57Question

A newly hired helpdesk technician at a logistics firm receives a telephone call from an individual claiming to be the senior IT manager. The caller states there is an active server emergency and requires the technician to immediately reset an administrative password and temporarily bypass multi-factor authentication (MFA) for an internal service account. The caller provides detailed context about current company projects to build trust and authority. Which of the following characteristics specifically distinguish this scenario as a pretexting attack? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: The establishment of a fabricated scenario and assumed persona designed to manipulate the target into granting unauthorized privileges; The strategic exploitation of role hierarchy and specific internal background knowledge to prevent the target from questioning the request

Answer

The correct characteristics are the establishment of a fabricated scenario and assumed persona to manipulate the target, and the strategic exploitation of role hierarchy combined with internal background knowledge to discourage verification.
Pretexting involves an attacker crafting an elaborate lie or fake scenario (the pretext) to trick a victim into divulging information or taking sensitive actions. Using an assumed manager persona, citing realistic internal information, and inventing an urgent situation to exploit authority are signature characteristics of pretexting.

Step-by-Step Solution

1
Analyze the incident details provided in the scenario
The caller used a phone call (voice medium), pretended to be an IT manager (authority persona), invented an emergency (fabricated scenario), and cited project details (research/pretext).
Identifying key indicators helps differentiate social engineering threat types from technical malware attacks.
2
Evaluate social engineering definitions against the identified indicators
Pretexting is defined by creating a plausible false situation (pretext) to trick a victim into supplying confidential information or access.
Pretexting goes beyond simple impersonation by actively crafting a background narrative to justify the out-of-band request.
3
Select options that accurately describe pretexting mechanisms
The choices describing the invented narrative/persona and the reliance on organizational context/authority are correct.
These two features explicitly capture the core definition and execution strategy of pretexting.

Key Concept

Pretexting and Threat Identification
Question 58Question

An IT technician is designing physical access controls for an internal server room housing critical enterprise databases. The design must strictly prevent unauthorized personnel from entering the room and maintain an automated audit log of all entry and exit attempts. Which TWO of the following physical security controls should the technician implement to satisfy these requirements?

Select all that apply

Show answer & explanation

Answer: An access control vestibule integrated with biometric scanners; Electronic keycard readers configured with automated access logging

Answer

The technician should implement an access control vestibule integrated with biometric scanners and electronic keycard readers configured with automated access logging.
Implementing an access control vestibule (mantrap) with biometric scanners and electronic keycard readers with access logging satisfies both required outcomes. The access control vestibule ensures that only one authenticated person enters at a time, eliminating tailgating, while electronic keycard readers control the door locks and maintain a detailed electronic record of all entry and exit attempts.

Step-by-Step Solution

1
Analyze the mandatory security requirements
The requirements are restricting room entry exclusively to authorized personnel (preventing tailgating/unauthorized access) and maintaining an automated access audit trail.
Understanding the specific operational goals helps eliminate physical security controls designed for other threats.
2
Evaluate access control and auditing solutions
An access control vestibule (mantrap) with biometric authentication enforces single-person entry and identity verification to prevent tailgating. Electronic keycard readers manage door locks while automatically recording badge scan timestamps to form an entry log.
Both selected measures directly secure the room perimeter access point and capture access history.
3
Evaluate incorrect options against the requirements
Privacy filters guard against visual eavesdropping, cable locks prevent equipment theft, and perimeter bollards mitigate vehicle ramming. None of these choices restrict room entrance access or generate entry logs.
Controls targeting visual privacy, hardware theft, or physical vehicle impact do not meet room access control and logging objectives.

Key Concept

Physical Access Controls and Automated Audit Logging
Question 59Question

During a physical security audit of a corporate office, a technician finds several un-shredded documents containing internal network IP addresses, system user names, and written passwords inside an open recycling bin located outside the facility. Which of the following social engineering threat types is represented by this vulnerability?

Show answer & explanation

Answer: Dumpster diving

Answer

Dumpster diving
Searching through unsecured disposal bins or trash receptacles to find sensitive records, network maps, or user credentials is the exact definition of dumpster diving.

Step-by-Step Solution

1
Analyze the physical security scenario presented in the stem.
Identified sensitive corporate documents discarded intact in an accessible exterior recycling bin.
The threat relies on gathering discarded physical waste containing credentials and network configurations.
2
Classify the observed threat vector according to standard security definitions.
Rummaging through discarded trash or recycling bins for sensitive data is categorized as dumpster diving.
Implementing strict document destruction policies (e.g., cross-cut shredding) mitigates dumpster diving risks.

Key Concept

Dumpster Diving Physical Threat Vector
Question 60Question

A network technician is configuring a secure Wi-Fi network for a corporate office. The security policy requires each employee to authenticate using their individual domain credentials rather than sharing a single pre-shared key. Which of the following wireless security standards should the technician implement?

Show answer & explanation

Answer: WPA3-Enterprise

Answer

WPA3-Enterprise
WPA3-Enterprise implements 802.1X authentication, which integrates with an enterprise authentication server (such as RADIUS) to verify each user's unique credentials before granting network access.

Step-by-Step Solution

1
Identify the authentication requirement from the scenario.
The requirement states that users must log in with individual domain credentials rather than a shared password.
Enterprise wireless security modes integrate with 802.1X/RADIUS RADIUS servers for central user authentication.
2
Evaluate the available wireless security modes against the requirement.
WPA3-Enterprise provides 802.1X authentication support, while Personal modes (WPA2/WPA3-Personal) use a shared passphrase.
Selecting the Enterprise variant fulfills the requirement for unique individual account authentication.

Key Concept

Enterprise vs. Personal Wireless Security Modes (802.1X / RADIUS)
Estimated Time:45s
PreviousPage 3 / 23Next
Security Practice Questions — CompTIA A+ (Core 1 & Core 2) — Page 3 | Examkin