Security
442 questions
A security technician is establishing physical defense-in-depth controls for a newly constructed enterprise data center situated on the ground floor near a public street. The organization mandates protection against physical vehicle breach into the facility, anti-tailgating controls at the server room access point, and physical protection against internal disk theft from rack-mounted equipment. Which of the following physical security controls should be implemented to satisfy ALL of these requirements? (Select THREE.)
Select all that apply
A cybersecurity consultant is hardening a healthcare organization's wireless network infrastructure across multiple clinics. The organization must comply with strict data confidentiality standards and protect against rogue access point impersonation, rogue client connection, and offline password cracking attacks. The infrastructure includes a centralized RADIUS server infrastructure and PKI (Public Key Infrastructure). Which TWO of the following configuration options should be implemented on the enterprise wireless networks to satisfy these security mandates?
Select all that apply
A cybersecurity technician reviews logs following a security breach at a remote call center. The investigation reveals that an unauthorized individual telephoned several newly hired support representatives while impersonating an internal IT service desk manager conducting routine system maintenance. The caller established trust by referencing actual internal ticket numbers and supervisor names, subsequently convincing the representatives to divulge their domain credentials and active multi-factor authentication (MFA) push approval tokens. Which of the following social engineering techniques primarily describes the attacker's strategy of establishing a fabricated scenario to manipulate targets?
A facility security team is upgrading the exterior defenses of a corporate headquarters to protect ground-floor glass entrances and perimeter walls against physical vehicle ramming attacks. Which of the following physical security controls should be installed around the building perimeter to prevent vehicles from breaching the entryways?
A payroll specialist at a healthcare organization receives an unsolicited telephone call from an individual claiming to be a senior support engineer for the company's VoIP telephony provider. The caller claims that critical system upgrades are underway and requests that the specialist verify their network password over the phone to prevent service disruption. Which of the following social engineering threat types is occurring?
An IT technician needs to update an organization's wireless network configuration so that employees authenticate with their own individual domain credentials rather than using a single shared password. Which of the following options must be implemented to support this authentication method? (Select TWO).
Select all that apply
A security technician is leading a training session on workplace security for a healthcare organization. The technician explains the difference between digital and physical attack vectors. Which of the following options represent physical social engineering attack methods? (Select TWO.)
Select all that apply
A network administrator discovers that multiple employees in the legal department received text messages on their corporate mobile devices containing a link to reset their domain credentials due to a mandatory security update. The link directs users to a fraudulent web page whose URL replaces the letter 'o' with the digit '0' in the company's official domain name to harvest login details. Which of the following social engineering attack vectors did the threat actor combine to execute this attack?
A system administrator is upgrading an enterprise wireless network to meet a strict zero-trust compliance policy. The policy mandates full mutual authentication, requiring both the RADIUS authentication server and the connecting wireless client devices to present valid X.509 digital certificates before network access is granted. Additionally, the authentication protocol must not rely on password-based inner tunnel methods. Which Extensible Authentication Protocol (EAP) method must the administrator deploy on the network?
A systems administrator needs to protect legacy database servers housed in a shared facility room where multiple third-party contractors have valid door key access. The administrator must ensure that any unauthorized physical opening of the server chassis to access internal drives is visibly detectable during audits, without requiring continuous electrical power or active network monitoring. Which of the following physical security controls should the administrator implement?
An IT security team is implementing physical defense controls across an enterprise facility. Match each physical security control mechanism on the left to its corresponding protective security objective on the right.
Click a left item, then click its matching right item
Items
Matches
Match each security threat or social engineering vector on the left with its corresponding attack scenario description on the right.
Click a left item, then click its matching right item
Items
Matches
Match each wireless authentication protocol or security framework on the left with its correct operational requirement and cryptographic mechanism on the right.
Click a left item, then click its matching right item
Items
Matches
A user logged into a Windows 10 workstation with a standard user account attempts to install a hardware driver update. Immediately after double-clicking the installer, a User Account Control (UAC) dialog box appears asking for an administrator password. Which of the following best explains why this prompt is displayed?
A cybersecurity technician is reviewing recent security incident logs and physical security reports across an enterprise. Match each reported security incident scenario to its corresponding social engineering attack vector or threat classification.
Click a left item, then click its matching right item
Items
Matches
A desktop administrator needs to monitor for unauthorized physical opening of computer cases deployed in unattended remote branch offices. The administrator requires a solution that logs an immediate hardware-level event whenever an enclosure panel is removed. Which of the following physical security controls best satisfies this requirement?
A IT support specialist is reviewing wireless security protocols and authentication mechanisms for an upcoming network refresh. Match each wireless security term on the left with its corresponding operational definition or characteristic on the right.
Click a left item, then click its matching right item
Items
Matches
A cybersecurity analyst is investigating an unauthorized network intrusion at a mid-sized engineering firm. System logs indicate that several high-level research engineers were infected with keylogger malware after visiting a legitimate, specialized computer-aided design (CAD) software forum that they frequently use for industry updates. Further analysis confirms the attacker compromised the forum site's web server beforehand to serve exploit code specifically targeting site visitors originating from the engineering firm's public IP address range. Which of the following social engineering threat types best describes this attack strategy?
A desktop support technician is deploying physical and hardware security controls across multiple corporate facilities. Match each physical security control mechanism on the left to its corresponding primary protective function on the right.
Click a left item, then click its matching right item
Items
Matches
A systems administrator needs to enforce specific administrative privilege policies on standalone Windows 11 Pro workstations. Specifically, the administrator must configure User Account Control (UAC) settings so that built-in administrative accounts are explicitly prompted for credentials on the Secure Desktop whenever an elevation request occurs. Which tool should the administrator open to modify these detailed UAC security options?