Security
442 questions
A network security administrator is standardizing wireless security protocols and access controls across corporate offices, remote sites, and guest facilities. Match each wireless security protocol or access control mechanism on the left with its primary technical function on the right.
Click a left item, then click its matching right item
Items
Matches
A security administrator must harden standalone Windows 11 Pro workstations in a financial audit unit. Company compliance mandates two specific User Account Control (UAC) security controls: standard user accounts must be completely blocked from receiving elevation credential prompts (automatically denying elevation attempts), and administrative accounts operating in Admin Approval Mode must be forced to re-enter their administrative passwords on an isolated screen during any privilege elevation attempt rather than clicking a simple consent prompt. Which TWO configuration settings in Local Security Policy (secpol.msc) under Security Options must the administrator implement to satisfy these mandates?
Select all that apply
A system administrator is configuring security baselines on standalone Windows 11 Pro workstations. Company policy dictates that standard users must never be prompted to enter administrator credentials when attempting tasks that require elevated privileges; instead, any privilege elevation attempt by a standard user must be silently rejected by default. Which Local Security Policy setting under Security Options should the administrator modify to meet this requirement?
Following a severe hardware malfunction in a storage array, a technician receives three magnetic hard disk drives (HDDs) with physically broken read/write head assemblies. Corporate policy requires that all drive platters be sanitized of sensitive corporate data before the physical chassis components are submitted for scrap recycling. Because software-based sanitization tools cannot communicate with the non-functional drive controllers, which method will effectively purge the data from these magnetic drives?
An IT security technician is investigating a multi-stage security incident at a corporate facility. The investigation reveals that an attacker contacted a junior financial accountant via a phone call, posing as an internal IT service desk engineer to trick the accountant into verifying their credentials and approving an unauthorized multi-factor authentication (MFA) push notification. Additionally, physical security footage indicates that the attacker entered the restricted server room by closely following an authorized employee through a badge-protected security door before it latched. Which of the following social engineering threat types were executed during this incident? (Select TWO.)
Select all that apply
A technician needs to sanitize several retired magnetic hard disk drives (HDDs) containing sensitive company data. The technician wants to completely disrupt and neutralize the magnetic domains on the drive platters so the data cannot be recovered. Which of the following methods should the technician use?
A security administrator needs to harden a standalone Windows 11 Pro system by enforcing credential prompts on the Secure Desktop for administrative elevations and enabling Admin Approval Mode for the local Built-in Administrator account using administrative tools. In what correct sequential order should the technician execute these administrative steps from start to finish?
Drag items to arrange them in the correct order
A user logged in with a standard user account on a Windows workstation attempts to run a software installer that modifies system files. Before the installation can start, a User Account Control (UAC) dialog box appears requesting administrator credentials. Which of the following explains why this prompt was displayed?
A systems technician must secure an organization's dedicated hardware equipment housed inside a shared colocation data center floor. Although the facility provides general building perimeter security, the technician must prevent unauthorized personnel from opening server enclosures to access internal components, as well as prevent unauthorized physical cable connections into unused network ports on rack-mounted switches. Which TWO of the following physical security controls should the technician deploy to meet these objectives?
Select all that apply
A network technician is configuring wireless access for specialized barcode scanners in a distribution warehouse. The primary corporate wireless network relies on WPA3-Enterprise with 802.1X/RADIUS authentication using EAP-TLS client certificates. The new handheld scanners cannot store digital certificates or perform 802.1X authentication, but they fully support WPA3-Personal utilizing Simultaneous Authentication of Equals (SAE). Company policy requires network isolation for non-802.1X devices while maintaining the strongest possible wireless security controls without lowering the authentication requirements of the primary corporate network. Which of the following is the BEST solution for the technician to implement?
A desktop technician needs to configure a standalone Windows 11 workstation to the maximum User Account Control (UAC) security level using the Graphical User Interface (GUI). Place the following steps in the correct chronological order to complete this task.
Drag items to arrange them in the correct order
A security administrator is hardening corporate Windows 11 Pro workstations against potential malware threats. Company security policy mandates that User Account Control (UAC) must strictly enforce Public Key Infrastructure (PKI) validation, automatically denying elevation requests for any executable file or setup installer that lacks a verified, trusted digital signature. Which policy setting under Local Security Policy (secpol.msc) directly achieves this requirement?
A systems engineer is responding to a security incident involving a Windows 11 point-of-sale terminal that was flagged for stealthy spyware behavior. The engineer has identified the infection symptoms and successfully isolated the system by disabling all network interfaces and unplugging physical connections. According to the standard CompTIA 7-step malware remediation process, which action must the engineer perform NEXT prior to updating anti-malware signatures or initiating a scan?
A systems support technician is troubleshooting a legacy 32-bit line-of-business application installed on standalone Windows 11 Pro workstations. When standard domain users run the application, it crashes upon attempting to write log data to its installation directory under C:\Program Files (x86)\VendorApp. Running the application as an administrator allows it to function, but corporate security policy strictly prohibits granting local administrative rights or disabling User Account Control (UAC). Which policy under Local Security Policy (secpol.msc) should be enabled to resolve the application errors while adhering to security mandates?
A desktop support technician is reviewing default User Account Control (UAC) settings and behaviors on a Windows 11 Pro workstation. Which TWO of the following statements accurately describe how UAC functions to safeguard the operating system?
Select all that apply
A security technician is preparing to decommission server rack disk arrays containing retired magnetic Hard Disk Drives (HDDs) that stored unencrypted sensitive employee data. According to organizational security policy and CompTIA A+ guidelines, which TWO of the following sanitization and disposal methods are appropriate for destroying the data on these magnetic HDDs? (Select TWO.)
Select all that apply
A financial controller at a manufacturing company receives an urgent telephone call from an individual claiming to be a senior network technician from the firm's internet service provider (ISP). The caller states that an impending line outage will disrupt business operations unless the controller immediately verifies their administrative portal login credentials and provides a one-time multi-factor authentication passcode. Which of the following social engineering threat types is described in this scenario?
A technician has successfully remediated an infected Windows workstation by running updated anti-malware scans and removing the detected threats. Which TWO of the following steps should the technician perform NEXT to complete the standard CompTIA malware remediation process?
Select all that apply
An IT technician is updating the company's storage media disposition policy to ensure compliance with NIST data security standards across different drive types and physical conditions. Match each data destruction method on the left with its appropriate operational description on the right.
Click a left item, then click its matching right item
Items
Matches
A network administrator is hardening a financial institution's wireless infrastructure to comply with updated security policies. The requirements state that all connecting wireless clients must authenticate individually using client-side digital certificates against a central RADIUS server, and the access points must completely eliminate susceptibility to wireless protocol downgrade attacks. Which TWO of the following configurations should the administrator implement to meet these requirements?
Select all that apply