Security
442 questions
An IT technician is setting up desktop workstations in an unsupervised public library computer room. The facility management wants to prevent visitors from opening the computer cases to steal or tamper with internal components such as RAM and system drives. Which of the following physical security controls should the technician install?
A corporate enterprise houses its database servers in a shared colocation facility where vendors and third-party technicians routinely access adjacent hardware. The company must implement a physical security control specifically for its rack cabinets that physically restricts cabinet opening to designated IT staff while automatically recording electronic audit logs of every individual cabinet access attempt. Which of the following physical security controls best fulfills these requirements?
An IT technician is tasked with securing standalone server enclosures located inside a shared office space to prevent unauthorized physical opening of the equipment cases and theft of internal storage drives. Which TWO of the following physical security controls should the technician implement? (Select TWO.)
Select all that apply
During a physical security evaluation at a financial firm's branch site, an auditor observes that unauthorized individuals can easily closely follow authorized personnel through card-swiped entry points into a sensitive data closet. The site manager requires a physical control that specifically restricts entry to one person at a time and actively prevents piggybacking without creating an emergency egress hazard. Which of the following physical security controls should be implemented?
A security technician is documenting physical security measures for a corporate data facility. Match each physical security control mechanism with its primary security function.
Click a left item, then click its matching right item
Items
Matches
A technician is investigating a malware infection on a workstation in the accounting department. The employee reports finding an unlabeled USB flash drive in the company breakroom and plugging it into the computer to identify its owner, which immediately executed malicious code. Which of the following social engineering attack types best describes this scenario?
Match each social engineering threat type on the left with its corresponding attack methodology on the right.
Click a left item, then click its matching right item
Items
Matches
A facilities security team is auditing physical access controls across a high-security corporate facility. Match each specialized physical security mechanism to the specific security risk it is primarily designed to mitigate.
Click a left item, then click its matching right item
Items
Matches
A network administrator is designing an enterprise wireless infrastructure with varying security requirements across departments. Match each wireless authentication protocol or framework to its specific technical deployment requirement or operational security characteristic.
Click a left item, then click its matching right item
Items
Matches
A corporate executive frequently views confidential financial reports on a company laptop while traveling through busy airport lounges and public spaces. To mitigate the risk of shoulder surfing and unauthorized viewing of screen content by nearby individuals, which of the following physical security controls should be installed on the laptop screen?
A network technician discovers an rogue wireless router plugged into an active Ethernet wall jack in an unmonitored building lobby. To prevent visitors from physically attaching unauthorized devices to open network jacks in public areas without requiring major switch reconfiguration, which of the following physical security controls should be implemented?
A cybersecurity technician is investigating a malware outbreak affecting several workstations in the research and development department. Network traffic logs indicate that all compromised devices recently accessed a trusted, niche vendor site commonly used by department employees for hardware specifications. Further analysis reveals that malicious actors infected the vendor site and embedded an exploit script specifically designed to target employees visiting from the organization's IP address range. Which of the following social engineering threat types best describes this attack vector?
Match each social engineering threat vector on the left with its corresponding attack description on the right.
Click a left item, then click its matching right item
Items
Matches
An IT security technician is auditing physical security for a high-security server room at a branch office. Audit logs indicate that unauthorized individuals have repeatedly gained entry by following authorized personnel closely through the primary entrance door immediately after a valid badge scan. The organization requires a physical security enhancement that enforces single-person entry and prevents tailgating without requiring dedicated physical security guard staff. Which of the following physical security controls should the technician recommend?
An IT security administrator is updating the physical security policy for an enterprise organization. Match each physical security control mechanism on the left to its primary protective function on the right.
Click a left item, then click its matching right item
Items
Matches
A network technician is configuring an enterprise wireless network for a corporate environment. The organization's security policy mandates individual user-based authentication integrated with a RADIUS server, strict mutual authentication enforcing client-side digital certificates on corporate-managed laptops, and strong modern encryption protocols without relying on password-only authentication. Which of the following wireless security standards and EAP protocols best meets these requirements?
A newly hired helpdesk technician at a logistics firm receives a telephone call from an individual claiming to be the senior IT manager. The caller states there is an active server emergency and requires the technician to immediately reset an administrative password and temporarily bypass multi-factor authentication (MFA) for an internal service account. The caller provides detailed context about current company projects to build trust and authority. Which of the following characteristics specifically distinguish this scenario as a pretexting attack? (Select TWO.)
Select all that apply
An IT technician is designing physical access controls for an internal server room housing critical enterprise databases. The design must strictly prevent unauthorized personnel from entering the room and maintain an automated audit log of all entry and exit attempts. Which TWO of the following physical security controls should the technician implement to satisfy these requirements?
Select all that apply
During a physical security audit of a corporate office, a technician finds several un-shredded documents containing internal network IP addresses, system user names, and written passwords inside an open recycling bin located outside the facility. Which of the following social engineering threat types is represented by this vulnerability?
A network technician is configuring a secure Wi-Fi network for a corporate office. The security policy requires each employee to authenticate using their individual domain credentials rather than sharing a single pre-shared key. Which of the following wireless security standards should the technician implement?