Security
442 questions
A systems administrator at a healthcare facility is investigating a security incident in the radiology department. Several workstations have lost access to local and network files, which now display a .locked file extension alongside a text file demanding cryptocurrency payment within 48 hours. During the initial investigation, the technician learns that an unidentified individual left several unlabeled USB flash drives labeled 'Q3 Executive Bonuses' in the staff lounge, which multiple employees plugged into their workstations. Which of the following threat types and attack vectors are demonstrated in this scenario? (Select TWO.)
Select all that apply
A system administrator needs to render confidential data completely unrecoverable on several decommissioned magnetic hard disk drives (HDDs) without physically destroying the drives. Which of the following data sanitization methods should the administrator use?
A desktop technician is troubleshooting a legacy 32-bit line-of-business application on a Windows 11 Pro workstation. When a standard user runs the application, configuration changes are saved without issue. However, when an administrative user logs in and opens the application normally (without selecting 'Run as administrator'), the application fails to save changes and throws a permission denied error. An inspection reveals that the application attempts to write settings to C:\Program Files (x86)\LegacyApp\config.ini, where NTFS permissions grant Write access exclusively to the local Administrators group. Which of the following best explains why the application saves configuration changes for the standard user but fails for the administrator?
A security technician needs to configure a standalone Windows 11 Pro workstation so that standard user accounts are automatically denied elevation requests without displaying a UAC prompt. Place the administrative configuration steps in the correct chronological order from first to last.
Drag items to arrange them in the correct order
A network security administrator is deploying a wireless network for an enterprise client's corporate headquarters. The client's security policy strictly requires individual user authentication backed by a centralized RADIUS server, along with modern encryption that eliminates legacy cipher vulnerabilities. Which of the following wireless security configurations should the administrator implement to meet these requirements?
An IT security analyst is investigating a breach where multiple compliance officers' workstations were infected with spyware simultaneously. Email security logs show no suspicious incoming messages, external USB storage devices are blocked via Group Policy, and physical access logs show no unauthorized entry. Analysis reveals that all affected personnel regularly visit a specific third-party industry news website, which had been secretly compromised to serve malicious scripts to site visitors. Which of the following attack types best describes this scenario?
A helpdesk technician is assisting a user on a Windows 11 Home workstation who attempts to open the Local Security Policy console (secpol.msc) to configure password policy settings. When running the command, Windows displays an error stating that the file cannot be found. Which of the following explains why this management console is unavailable?
An IT security technician is designing physical entry security for a high-security server room hosting sensitive financial records. Organization policy mandates implementing measures that actively prevent tailgating (piggybacking) at the doorway, as well as enforcing multi-factor physical authentication that combines a physical security token with a biometric characteristic. Which of the following physical security controls should the technician implement to satisfy these requirements? (Select TWO.)
Select all that apply
A systems administrator is configuring local security policies on standalone Windows 11 Pro workstations in a multi-user clinical environment. Management requires that when a workstation is locked or restarted, the sign-in screen must not display the account name or email address of the user who previously logged in. Which setting within Local Security Policy (`secpol.msc`) must the administrator enable to satisfy this requirement?
A system administrator needs to implement WPA3-Enterprise security on an office wireless network to replace an outdated setup. Which TWO of the following authentication components and protocols are required to support a WPA3-Enterprise deployment?
Select all that apply
A human resources manager receives an urgent phone call from an individual claiming to be a senior network administrator from the corporate help desk. The caller states that an emergency security patch must be applied immediately to the manager's account to prevent a critical data leak, requiring the manager to read back a one-time passcode sent via SMS and approve an incoming multi-factor authentication (MFA) push notification. After the manager complies, an unauthorized user registers a new authentication device and accesses sensitive personnel records. Which of the following social engineering threat types best describes the attack vector used in this scenario?
A technician is tasked with removing a malware infection from a workstation. According to the standard CompTIA 7-step malware remediation process, in what sequence should the technician perform the following steps?
Drag items to arrange them in the correct order
An IT technician is tasked with decommissioning sensitive magnetic hard drives following standard organizational security procedures. Place the following hardware disposal steps in the correct chronological order from first to last.
Drag items to arrange them in the correct order
A network technician is assigned to physically secure desktop computers located in a publicly accessible library area. Recent audits revealed that unauthorized users have been plugging hardware keyloggers into open USB ports on the back of the computer towers. The technician needs to prevent unauthorized physical connections to these ports without replacing the existing computer cases or restricting user access to connected peripherals. Which of the following physical security controls should the technician implement?
A security technician is configuring group policies for Windows 11 Pro workstations in a finance department. To prevent background malware from interacting with or capturing keystrokes during privilege escalation requests, the technician must enforce a policy that dims the screen and isolates the elevation prompt from the interactive user desktop. Which User Account Control (UAC) security policy setting directly controls this behavior?
A desktop technician is reviewing Windows User Account Control (UAC) settings across company workstations. Which TWO of the following statements correctly describe default UAC prompt behaviors for user accounts on Windows systems? (Select TWO.)
Select all that apply
A cybersecurity support technician is dispatched to remediate a corporate desktop that is actively displaying unauthorized ransomware warnings and generating rogue outbound connections. In what sequence should the technician perform the following incident response steps to ensure complete malware eradication according to standard CompTIA guidelines?
Drag items to arrange them in the correct order
An IT administrator is configuring a high-security corporate wireless network for a firm's mobile workforce. Corporate policy mandates mutual authentication using client and server digital certificates integrated with a central RADIUS server. Additionally, legacy non-domain mobile devices that only support shared passphrases must be accommodated on a segregated network segment using current security standards. Which TWO of the following configuration choices must the administrator implement to satisfy all policy requirements?
Select all that apply
A security administrator needs to harden a standalone Windows 11 Enterprise computer by ensuring that only digitally signed executables can request privilege elevation, while requiring administrators to re-enter credentials on a dimmed, isolated desktop. Place the administrative configuration and verification steps in the correct chronological order.
Drag items to arrange them in the correct order
An IT security technician is implementing a hardened security baseline on Windows 11 Pro workstations for a finance company. The compliance policy mandates two specific behaviors: local administrators must be required to explicitly approve administrative privileges on an isolated secure desktop, and standard users must be completely restricted from seeing credential elevation prompts when attempting administrative operations. Which TWO configuration actions in the Local Security Policy snap-in (secpol.msc) under Security Options should be implemented to fulfill these requirements? (Select TWO.)
Select all that apply