All practice questions

378 questions

Question 261Question

A newly established fintech firm is defining its formal security governance architecture to ensure consistent risk oversight across cloud services. Match each governance document type on the left with its corresponding operational characteristic on the right.

Click a left item, then click its matching right item

Items

Security Policy
Security Standard
Security Baseline
Security Guideline

Matches

Show answer & explanation

Answer

Security Policy pairs with the high-level mandatory directive outlining security goals; Security Standard pairs with the mandatory requirement specifying technical controls and operational rules; Security Baseline pairs with the minimum mandatory operational configuration benchmark; Security Guideline pairs with the discretionary recommendation providing best practices.
The correct pairings accurately place documents in the governance hierarchy: Security Policy serves as the executive mandatory directive; Security Standard sets mandatory operational and technical rules; Security Baseline establishes the mandatory minimum configuration benchmark for target assets; and Security Guideline offers optional best-practice advice.

Step-by-Step Solution

1
Analyze the high-level authority tier of governance documentation.
Identify that overall organizational intent and high-level requirements form a Security Policy.
Policies establish top-down mandatory direction without defining implementation details.
2
Differentiate mandatory technical specs from mandatory configuration states.
Map specific required protocols and controls to Security Standards, and minimum system hardening thresholds to Security Baselines.
Standards dictate mandatory rules or tools, whereas baselines define the mandatory minimum secure state for system deployments.
3
Identify non-mandatory or discretionary advisory documentation.
Map recommended best practices to Security Guidelines.
Guidelines provide suggested approaches and flexibility rather than compulsory enforcement.

Key Concept

Security Governance Document Hierarchy and Enforcement Levels
Question 262Question

A security operations manager is updating operational procedures for vulnerability assessments across an enterprise network. Match each assessment methodology with the scenario where it is most appropriately applied.

Click a left item, then click its matching right item

Items

Credentialed Vulnerability Scan
Non-Credentialed Vulnerability Scan
Passive Network Assessment
Intrusive Penetration Testing

Matches

Show answer & explanation

Answer

Credentialed vulnerability scanning matches host internal auditing for missing patches. Non-credentialed scanning matches external adversary perspective mapping. Passive network assessment matches non-disruptive device identification on sensitive operational technology networks. Intrusive testing matches active exploitation of vulnerabilities to verify real-world impact.
Each matching pair correctly aligns the specific vulnerability scanning or testing technique with its primary use case: Credentialed scans provide deep host visibility; Non-credentialed scans simulate external attack surfaces; Passive assessments safeguard fragile SCADA/ICS environments; and Intrusive penetration testing validates exploitation potential.

Step-by-Step Solution

1
Analyze each operational requirement to determine authentication, network impact, and safety constraints.
Identify that host patch audits require host privileges, external reconnaissance requires unauthenticated probes, sensitive legacy OT requires zero injected traffic, and impact validation requires active exploitation.
Vulnerability assessment techniques vary primarily by authorization level (credentialed vs unauthenticated), traffic interaction (active vs passive), and operational risk (intrusive vs non-intrusive).
2
Pair credentialed and non-credentialed techniques with host-based and perimeter-based scenarios respectively.
Assign credentialed scan to host configuration/patch audits, and non-credentialed scan to perimeter service mapping.
Credentials allow host registry and package manager queries, whereas non-credentialed scans rely strictly on network service responses.
3
Distinguish between passive network monitoring and intrusive penetration testing based on target sensitivity and operational goal.
Assign passive assessment to fragile ICS/SCADA networks and intrusive testing to staging environment exploitation.
Passive tools capture existing packet streams safely without causing denial of service on fragile devices, while intrusive tools actively attempt exploitation.

Key Concept

Vulnerability Assessment Methodologies and Selection Criteria
Question 263Question

An organization is updating its enterprise access control policy to comply with strict security standards. Match each operational security task to the corresponding AAA (Authentication, Authorization, and Accounting) or Identification function it represents.

Click a left item, then click its matching right item

Items

A network access server validates a user's digital certificate and smart card PIN against the central identity provider during domain logon.
A database gateway checks an enterprise role matrix to permit read-only query execution on financial records.
A centralized syslog server records administrative session timestamps, executed PowerShell commands, and egress data volume.
A web portal prompts an incoming visitor to enter their unique username before initiating any credentials verification.

Matches

Show answer & explanation

Answer

Task 1 maps to Authentication; Task 2 maps to Authorization; Task 3 maps to Accounting; Task 4 maps to Identification.
Each task directly corresponds to a fundamental identity and AAA principle: entering a username claims an identity (Identification); checking certificates and PINs verifies that claim (Authentication); evaluating role-based query permissions determines access rights (Authorization); and recording command execution and timestamps provides accountability and auditability (Accounting).

Step-by-Step Solution

1
Analyze Task 1
The process of verifying proof of identity (smart card PIN and certificate) corresponds to Authentication.
Authentication is the verification of a claimed identity using credentials.
2
Analyze Task 2
Determining what actions or data access a verified identity is allowed to perform corresponds to Authorization.
Authorization enforces access control permissions and privilege limitations.
3
Analyze Task 3
Logging actions, command usage, and session metrics for auditability corresponds to Accounting.
Accounting focuses on tracking resource utilization and maintaining audit trails.
4
Analyze Task 4
Providing a unique identifier (username) to claim an identity corresponds to Identification.
Identification is the initial statement of who a user or system claims to be.

Key Concept

Core Pillars of Identification, Authentication, Authorization, and Accounting (AAA)
Question 264Question

An organization is enhancing its vendor governance framework to address distinct third-party operational and supply chain security risks. Match each risk assessment artifact or agreement on the left to its corresponding enterprise application on the right.

Click a left item, then click its matching right item

Items

Vendor Security Questionnaire (e.g., SIG / CAIQ)
Software Bill of Materials (SBOM)
SOC 2 Type II Report
Interconnection Security Agreement (ISA)

Matches

Show answer & explanation

Answer

Vendor Security Questionnaires pair with gathering self-reported baseline control information; Software Bill of Materials (SBOM) pairs with identifying nested open-source software supply chain vulnerabilities; SOC 2 Type II Reports pair with evaluating operational control effectiveness over an extended monitoring period; Interconnection Security Agreements (ISAs) pair with defining technical security parameters for direct network connections.
Each vendor oversight tool fulfills a unique governance function: Vendor Security Questionnaires provide preliminary self-attested control baselines; SBOMs grant visibility into third-party software component supply chains; SOC 2 Type II reports offer independent audit evidence of operational control performance over time; and ISAs define technical security requirements for dedicated system-to-system interconnections.

Step-by-Step Solution

1
Analyze the purpose of initial vendor intake self-assessments.
Map Vendor Security Questionnaire to gathering self-reported baseline control posture during vendor intake.
Standardized questionnaires collect foundational information directly from the vendor prior to formal independent verification.
2
Evaluate software supply chain visibility tools.
Link Software Bill of Materials (SBOM) to component-level vulnerability analysis and nested library inventorying.
An SBOM explicitly details code ingredients, allowing organizations to trace downstream exposure to upstream software package vulnerabilities.
3
Distinguish independent third-party audit report scope based on operational duration.
Associate SOC 2 Type II Report with evaluating operational control effectiveness over an extended period.
Unlike Type I reports which only attest to design at a single point in time, Type II reports verify that controls operated effectively over time.
4
Differentiate inter-organizational network connectivity governance.
Connect Interconnection Security Agreement (ISA) to establishing technical security requirements for direct network links.
An ISA specifies technical and security parameters governing dedicated network interconnections between separate entities.

Key Concept

Third-Party Risk Assessment Artifacts and Inter-Organizational Security Agreements
Question 265Question

Match each business continuity and Business Impact Analysis (BIA) metric with its corresponding operational definition.

Click a left item, then click its matching right item

Items

Recovery Time Objective (RTO)
Recovery Point Objective (RPO)
Maximum Tolerable Downtime (MTD)
Mean Time Between Failures (MTBF)

Matches

Show answer & explanation

Answer

Recovery Time Objective (RTO) corresponds to the target restoration timeframe; Recovery Point Objective (RPO) corresponds to the maximum acceptable data loss timeframe; Maximum Tolerable Downtime (MTD) corresponds to the absolute maximum outage duration before irreparable harm; Mean Time Between Failures (MTBF) corresponds to the expected operational reliability between failures.
Each business continuity metric aligns directly with its primary focus area: Recovery Time Objective (RTO) focuses on restoration duration, Recovery Point Objective (RPO) focuses on data loss windows, Maximum Tolerable Downtime (MTD) sets the upper threshold for business survival, and Mean Time Between Failures (MTBF) quantifies hardware reliability.

Step-by-Step Solution

1
Identify the data loss boundary metric
Recovery Point Objective (RPO) defines maximum acceptable data loss measured backwards in time from the moment of disruption.
RPO focuses strictly on transactional and data retention loss windows.
2
Identify the targeted service restoration metric
Recovery Time Objective (RTO) represents the targeted goal duration for recovering systems.
RTO measures recovery effort time from interruption to operational readiness.
3
Identify the business limit threshold metric
Maximum Tolerable Downtime (MTD) specifies the maximum survival threshold of system downtime.
Exceeding MTD results in catastrophic operational loss.
4
Identify the equipment reliability metric
Mean Time Between Failures (MTBF) tracks average system availability between breakdowns.
MTBF measures overall component and system reliability over time.

Key Concept

Business Impact Analysis Metrics (RTO, RPO, MTD, MTBF)
Estimated Time:1m 0s
Question 266Question

An enterprise risk manager is formalizing the organization's Business Continuity Management (BCM) testing program to validate recovery assumptions established during the Business Impact Analysis (BIA). Match each business continuity exercise type on the left to its corresponding operational execution methodology on the right.

Click a left item, then click its matching right item

Items

Tabletop Exercise
Structured Walk-Through Test
Parallel Test
Full-Interruption Test

Matches

Show answer & explanation

Answer

Tabletop Exercise matches verbal scenario discussion among key stakeholders. Structured Walk-Through Test matches line-by-line review of continuity documentation. Parallel Test matches concurrent processing on backup systems without disrupting production. Full-Interruption Test matches completely shutting down primary systems to migrate live operations.
Each business continuity exercise type corresponds to a specific level of operational disruption and validation depth. Tabletop exercises involve verbal scenario discussions. Structured walk-through tests involve detailed documentation audits. Parallel tests run recovery systems concurrently alongside live production without risk of downtime. Full-interruption tests intentionally shut down primary systems to validate complete operational failover.

Step-by-Step Solution

1
Analyze discussion-based exercise methods
Identify that Tabletop Exercises focus on verbal scenario walkthroughs without hardware deployment.
Tabletop exercises test decision-making and awareness in a meeting setting.
2
Differentiate documentation validation from scenario discussion
Identify that Structured Walk-Through Tests focus on step-by-step reading and verification of the written plan.
Structured walk-throughs ensure that the disaster recovery documentation itself is complete and accurate.
3
Evaluate operational recovery testing methodologies
Match Parallel Testing with concurrent redundant system processing that maintains active production, and Full-Interruption Testing with disabling live systems to force failover.
Parallel tests minimize business risk while testing hardware readiness, whereas full-interruption tests validate real-time failover under actual outage conditions.

Key Concept

Business Continuity Plan (BCP) Testing and Exercise Methodologies
Question 267Question

Match each audit or attestation report type to its primary operational purpose.

Click a left item, then click its matching right item

Items

SOC 1 Report
SOC 2 Type I Report
SOC 2 Type II Report
SOC 3 Report

Matches

Show answer & explanation

Answer

SOC 1 matches financial reporting controls; SOC 2 Type I matches point-in-time control design evaluation; SOC 2 Type II matches control design and operational effectiveness over a period of time; SOC 3 matches high-level public summaries.
Each attestation serves a distinct audit purpose: SOC 1 evaluates financial reporting controls; SOC 2 Type I assesses control design at a single snapshot date; SOC 2 Type II verifies control design and operational performance over a specified evaluation period; and SOC 3 provides a publicly distributable summary.

Step-by-Step Solution

1
Differentiate financial assurance reports from trust services security reports.
SOC 1 addresses financial reporting (ICFR), whereas SOC 2 and SOC 3 address security, availability, and confidentiality.
Organizations use SOC 1 when third-party services directly impact financial statements.
2
Distinguish between Type I and Type II report timeframes and depth.
Type I is a snapshot evaluation of control design at a single point in time, while Type II measures operational performance over a multi-month period.
Type II requires extensive historical log review and evidence gathering to prove controls operated as designed over time.
3
Identify the report designed for public distribution.
SOC 3 provides a generalized public summary.
Unlike SOC 2 reports, which contain sensitive architectural details, SOC 3 reports are stripped of confidential data so they can be shared freely.

Key Concept

SOC Report Types and Attestation Scopes
Question 268Question

Match each security audit, assessment, or attestation deliverable with its primary operational purpose and evaluation scope.

Click a left item, then click its matching right item

Items

SOC 2 Type I Report
SOC 2 Type II Report
SOC 3 Report
ISO/IEC 27001 Certification

Matches

Show answer & explanation

Answer

SOC 2 Type I matches point-in-time design suitability; SOC 2 Type II matches design suitability and operating effectiveness over a defined period; SOC 3 matches public-facing executive summary attestation; ISO/IEC 27001 matches accredited ISMS framework certification.
Each deliverable maps strictly to its evaluation scope: SOC 2 Type I assesses control design at a single point in time; SOC 2 Type II assesses design and operating effectiveness over a monitoring period; SOC 3 is a freely distributable public summary; ISO/IEC 27001 certifies the overall Information Security Management System against international standard criteria.

Step-by-Step Solution

1
Analyze the timeframe requirement of SOC 2 attestation reports
Distinguish Type I (point in time, design suitability only) from Type II (over a testing period, design and operating effectiveness).
Type I audits examine control architecture at a specific date snapshot, whereas Type II requires historical evidence of operating consistency.
2
Determine the intended distribution audience for SOC reports
Identify SOC 3 as the publicly distributable version of SOC 2.
SOC 2 reports contain sensitive system descriptions for restricted use, while SOC 3 reports provide high-level assurance for prospective customers and public distribution.
3
Identify international framework certifications
Match ISO/IEC 27001 to the formal accredited audit of an Information Security Management System (ISMS).
ISO 27001 specifies requirements for establishing, implementing, maintaining, and continually improving an organizational ISMS.

Key Concept

Third-Party Security Audits, Attestations, and Framework Certifications
Question 269Question

Match each regulatory framework or standard to its primary governance scope and legal mandate.

Click a left item, then click its matching right item

Items

FISMA
GDPR
PCI DSS
SOX

Matches

Show answer & explanation

Answer

FISMA matches the security mandate for U.S. federal government agencies; GDPR matches personal privacy rights for EU individuals; PCI DSS matches contractual requirements for credit card processing merchants; SOX matches internal financial reporting controls for public companies.
Each regulation or standard aligns directly with its designated scope: FISMA governs U.S. federal agency systems; GDPR governs European consumer data privacy; PCI DSS governs payment card merchant data environments; and SOX governs internal financial reporting controls for public companies.

Step-by-Step Solution

1
Identify the mandate governing federal information systems.
FISMA establishes information security practices for U.S. federal agencies and their supporting contractors.
Understanding federal scope separates public-sector statutory frameworks from private commercial standards.
2
Determine the regulation protecting European personal privacy rights.
GDPR regulates personal data processing, consumer consent, and international data transfers for EU residents.
GDPR focuses on data subject privacy rights across international boundaries.
3
Identify the standard governing payment card environments.
PCI DSS is a non-governmental contractual standard required by payment brands for entities handling credit card transactions.
Cardholder data environments are regulated by industry contractual standards rather than federal legislation.
4
Determine the legal requirement for public corporate financial transparency.
SOX mandates internal accounting safeguards and audit trails for publicly traded corporate financial disclosures.
SOX targets corporate governance and accounting oversight to protect investors.

Key Concept

Regulatory Compliance Frameworks and Governance Scopes
Question 270Question

An organization is enhancing its third-party governance framework to address vendor oversight and supply chain security. Match each third-party risk management instrument on the left with its primary operational purpose on the right.

Click a left item, then click its matching right item

Items

Vendor Security Assessment Questionnaire (VSAQ)
Right-to-Audit Contractual Clause
Hardware Bill of Materials (HBOM)
Service Level Agreement (SLA)

Matches

Show answer & explanation

Answer

Vendor Security Assessment Questionnaire matches with evaluating self-reported security controls; Right-to-Audit Clause matches with establishing legal authority to inspect controls; Hardware Bill of Materials matches with tracking physical component sourcing and sub-tier provenance; Service Level Agreement matches with defining measurable service performance metrics.
Each instrument fulfills a specific role in third-party risk management: Questionnaires assess self-reported baseline posture during onboarding, Right-to-Audit provisions grant verification permissions, HBOMs track physical component provenance against tampering, and SLAs define operational metrics and breach remedies.

Step-by-Step Solution

1
Identify the primary purpose of pre-onboarding questionnaires.
Match Vendor Security Assessment Questionnaire (VSAQ) with evaluating self-reported security controls during initial onboarding.
VSAQs are standardized tools used during initial risk assessment to gauge vendor compliance and risk profile.
2
Analyze contractual inspection rights.
Match Right-to-Audit Contractual Clause with establishing legal authority to inspect physical and technical controls.
Right-to-audit clauses ensure the client is legally permitted to independently audit or inspect vendor facilities and systems.
3
Evaluate hardware supply chain oversight mechanisms.
Match Hardware Bill of Materials (HBOM) with tracking component sourcing and sub-tier provenance.
An HBOM details all physical sub-components and integrated circuits, ensuring component origin integrity.
4
Determine performance operational contract mechanisms.
Match Service Level Agreement (SLA) with defining measurable service performance metrics and uptime expectations.
SLAs govern operational expectations, availability metrics, and remediation terms.

Key Concept

Third-Party Risk Management and Supply Chain Oversight Instruments
Question 271Question

Match each enterprise security incident scenario on the left with the specific social engineering attack vector utilized on the right.

Click a left item, then click its matching right item

Items

An attacker registers a domain name containing a common misspelling of a corporate web portal to harvest employee authentication credentials.
An attacker leaves malware-infected USB flash drives scattered in the employee parking lot hoping someone inserts one into a company workstation.
An attacker contacts a shipping department while impersonating a logistics dispatcher to trick staff into redirecting a valuable shipment to an offsite address.
An attacker submits a fraudulent payment request to the accounts payable department designed to mimic a routine bill from an established third-party vendor.

Matches

Show answer & explanation

Answer

The credential harvesting site using a misspelled domain matches Typosquatting; the malware-laden flash drives left in the parking lot match Baiting; the fraudulent redirection of a shipment matches Diversion theft; and the fake vendor payment request matches Invoice fraud.
Each attack vector is correctly paired based on its primary delivery mechanism: Typosquatting uses deceptive URLs based on spelling errors; Baiting relies on physical media traps; Diversion theft manipulates physical delivery routes; and Invoice fraud uses deceptive billing requests to siphon corporate funds.

Step-by-Step Solution

1
Analyze the web portal scenario involving misspelled domain registration.
Identify that exploiting typos in URLs to host spoofed credential-harvesting sites is typosquatting.
Typosquatting relies on user typographical mistakes when typing web addresses.
2
Analyze the physical media scenario involving unattended USB drives.
Identify that leaving physical media to entice curiosity is baiting.
Baiting relies on offering a physical item or incentive that promises a reward or satisfies curiosity.
3
Analyze the logistics scenario involving redirected shipments.
Identify that intercepting or altering courier deliveries is diversion theft.
Diversion theft specifically targets the supply chain or delivery process to steal physical goods.
4
Analyze the financial payment request scenario.
Identify that spoofing vendor billing documents to manipulate accounts payable is invoice fraud.
Invoice fraud uses pretexting and spoofed documentation to trick accounting into unauthorized disbursements.

Key Concept

Social Engineering Attack Vectors
Question 272Question

A security administrator is evaluating enterprise cryptographic standards across various system modules. Match each cryptographic algorithm or mechanism on the left with its primary operational security application on the right.

Click a left item, then click its matching right item

Items

PBKDF2 (Password-Based Key Derivation Function 2)
ECDHE (Elliptic Curve Diffie-Hellman Ephemeral)
HMAC-SHA256
AES-CBC with PKCS#7 Padding

Matches

Show answer & explanation

Answer

PBKDF2 matches with mitigating offline brute-force attacks via key stretching. ECDHE matches with providing perfect forward secrecy during key exchange. HMAC-SHA256 matches with verifying data integrity and authenticity via a shared key. AES-CBC with PKCS#7 matches with bulk symmetric confidentiality for block payloads.
Each cryptographic mechanism is accurately matched to its intended operational function based on core security engineering principles: PBKDF2 hardens password authentication via key stretching; ECDHE provides ephemeral session key establishment with forward secrecy; HMAC-SHA256 delivers keyed integrity and authentication; and AES-CBC provides bulk block cipher confidentiality.

Step-by-Step Solution

1
Analyze PBKDF2 function
Identified key stretching mechanism designed specifically to harden password hashes against brute-force attacks.
PBKDF2 applies salting and high iteration counts to increase computational cost per cracking attempt.
2
Analyze ECDHE mechanism
Identified ephemeral asymmetric key exchange algorithm providing perfect forward secrecy.
Ephemeral key generation guarantees that session keys are temporary and independent.
3
Analyze HMAC-SHA256 function
Identified keyed-hash message authentication code.
Combining a symmetric key with SHA-256 guarantees both integrity and message origin verification.
4
Analyze AES-CBC with PKCS#7 padding
Identified symmetric block cipher operating mode with padding.
AES-CBC encrypts 128-bit block units sequentially, requiring padding to fill incomplete final blocks.

Key Concept

Operational application of cryptographic primitives and key management mechanisms
Question 273Question

An enterprise risk committee is structuring its organizational governance framework. Match each policy framework document type on the left with its defining enforcement requirement and operational characteristics on the right.

Click a left item, then click its matching right item

Items

Security Policy
Security Standard
Security Baseline
Security Guideline

Matches

Show answer & explanation

Answer

Security Policy matches the high-level executive directive; Security Standard matches mandatory specific technical rules; Security Baseline matches mandatory minimum configuration thresholds; Security Guideline matches discretionary operational recommendations.
Each governance document plays a specific role within the governance hierarchy. Security Policies provide broad management authorization and intent. Security Standards enforce mandatory specific technical parameters. Security Baselines establish minimum operational hardening rules for deployed systems. Security Guidelines provide non-mandatory best practices.

Step-by-Step Solution

1
Analyze the enforceability and scope of each governance document type.
Identified whether each document is mandatory or discretionary, and whether it operates at a strategic or technical level.
Governance documents strictly follow a hierarchy where intent flows from high-level management strategy down to operational implementation.
2
Pair each document type with its corresponding role in enterprise security governance.
Mapped policies to strategic directives, standards to mandatory technical rules, baselines to minimum platform configurations, and guidelines to advisory best practices.
Differentiating between mandatory controls (policy, standard, baseline) and discretionary guidance (guideline) prevents compliance misunderstandings.

Key Concept

Security Governance Policy Hierarchy
Estimated Time:1m 30s
Question 274Question

An enterprise security team is categorizing various security controls according to CompTIA Security+ framework classifications. Match each security control implementation on the left with its corresponding control category and functional type on the right.

Click a left item, then click its matching right item

Items

Developing and enforcing an enterprise Information Security Policy that specifies mandatory data handling rules.
Deploying web application firewalls (WAF) to automatically block SQL injection attempts against web applications.
Restoring system configurations and databases from isolated backups following a malware encryption incident.
Installing high-visibility warning signs along the perimeter fencing of a secure data center facility.

Matches

Show answer & explanation

Answer

Developing security policies matches Managerial Category / Directive Type; Web application firewalls match Technical Category / Preventive Type; Restoring systems from backups matches Operational Category / Corrective Type; Installing perimeter warning signs matches Physical Category / Deterrent Type.
Each control is correctly classified based on CompTIA Security+ standards: Enterprise policies are governance-driven (Managerial) rules (Directive); WAFs are technology safeguards (Technical) that proactively block attacks (Preventive); data restoration is a procedural task (Operational) that remedies post-incident damage (Corrective); and physical warning signs are tangible facility measures (Physical) meant to discourage intruders (Deterrent).

Step-by-Step Solution

1
Analyze control implementation mechanisms to determine their primary category (Managerial, Technical, Operational, or Physical).
Policies reflect Managerial governance; WAFs reflect Technical software; backup restoration reflects Operational procedures; warning signs reflect Physical facility controls.
Control categories are defined by how the security control is implemented and administered.
2
Determine the functional goal of each control (Preventive, Deterrent, Detective, Corrective, Compensating, or Directive).
Policies direct behavior; WAFs prevent attacks; backups correct damage post-incident; warning signs deter potential intruders.
Functional types are classified by the control's purpose in the security incident lifecycle.
3
Combine the identified category and functional type for each security control to complete the matching pairs.
All four controls are accurately mapped to their unique dual-axis classifications.
Each control satisfies exactly one category and one functional type combination provided.

Key Concept

Dual-axis classification of security controls by category (Managerial, Technical, Operational, Physical) and functional type (Preventive, Deterrent, Detective, Corrective, Compensating, Directive).
Question 275Question

A security analyst is establishing a comprehensive vulnerability scanning framework for an enterprise network containing diverse operational environments. Match each vulnerability assessment requirement on the left with the scanner deployment methodology or configuration option on the right that best satisfies it.

Click a left item, then click its matching right item

Items

Evaluating public-facing web applications behind an inline Web Application Firewall (WAF) without active security filters altering or dropping vulnerability probes.
Auditing internal system configurations and local missing patches across remote endpoints with minimal network bandwidth overhead.
Assessing sensitive legacy Operational Technology (OT) and Supervisory Control and Data Acquisition (SCADA) networks where active probing may cause device instability.
Simulating an initial external reconnaissance phase conducted by an untrusted remote attacker targeting perimeter assets.

Matches

Show answer & explanation

Answer

Evaluating public-facing web applications behind a WAF matches with Scanner IP address whitelisting. Auditing internal configurations across remote endpoints with minimal bandwidth matches with Credentialed agent-based scanning deployment. Assessing sensitive legacy OT/SCADA networks without causing instability matches with Passive network listening and traffic monitoring. Simulating an initial external reconnaissance phase by an untrusted attacker matches with Non-credentialed network-based perimeter scanning.
Each scanner deployment method directly addresses distinct environmental constraints: WAF IP whitelisting prevents scan interference on web applications; agent-based scanning minimizes network overhead and provides deep host visibility; passive monitoring protects legacy OT/SCADA devices from crash risks caused by active probes; and non-credentialed external scanning provides a realistic view of perimeter exposure from an attacker's perspective.

Step-by-Step Solution

1
Analyze the web application security assessment requirement behind a WAF.
Inline WAF security controls drop or alter aggressive scanner payloads, producing incomplete scan results. Configured IP whitelisting bypasses blocking rules for legitimate scan traffic.
Security controls like WAFs must be informed of security testing to prevent false negatives caused by active payload blocking.
2
Identify the optimal scanning mechanism for remote endpoints and low-bandwidth constraints.
Agent-based scanners execute locally on the operating system, collecting inventory and patch state directly without streaming network port probes.
Agent architectures offload scanning execution to local system processes and transfer only compressed result manifests.
3
Select the appropriate technique for fragile, high-availability OT/SCADA environments.
Passive traffic monitoring analyzes network packets non-intrusively, identifying OS versions and known vulnerabilities without sending active probes.
Legacy industrial controllers frequently fault or crash when receiving unexpected or malformed TCP/IP probes generated by active vulnerability scanners.
4
Determine the methodology for simulating external threat actor perspectives.
Non-credentialed external scans inspect perimeter targets without system privileges, revealing exposed services and unpatched vulnerabilities accessible from the internet.
An unauthenticated remote attack simulation requires scanning from an external network segment without supplying valid host login credentials.

Key Concept

Vulnerability Scanner Deployment Methodologies and Operational Impact
Estimated Time:2m 0s
Question 276Question

Match each enterprise security incident scenario on the left with the corresponding social engineering attack vector or technique on the right.

Click a left item, then click its matching right item

Items

An attacker leaves custom USB drives labeled 'Q3 Executive Salary Review' on tables in the corporate cafeteria to trick curious employees into plugging them into company workstations.
An attacker fabricates a detailed persona as an external compliance auditor and calls human resources to request temporary administrative access credentials under the guise of an unannounced regulatory review.
An attacker intercepts communication between a firm and its regular supplier, replacing the supplier's legitimate wire transfer payment instructions with attacker-controlled bank details.
An attacker sends a highly targeted email directly to the Chief Executive Officer, referencing private board meeting topics to urgently demand a transfer of funds to avoid a fictitious regulatory fine.

Matches

Show answer & explanation

Answer

The correct pairings match: (1) USB drives left in the cafeteria to Baiting; (2) Fictional compliance auditor identity requesting access to Pretexting; (3) Intercepting supplier wire payment details to Invoice Switching; and (4) Highly targeted email aimed at the CEO to Whaling.
Each attack vector is correctly identified by evaluating its delivery channel, target profile, and deception technique: Baiting uses physical curiosity triggers; Pretexting uses a crafted false persona; Invoice Switching alters legitimate transaction details; and Whaling specifically targets high-ranking executives.

Step-by-Step Solution

1
Analyze the physical media scenario (cafeteria USB drives)
Identified as Baiting, which relies on offering an appealing item (curiosity hook) to entice a victim into executing malware.
Baiting relies on physical or digital promises that exploit curiosity or greed.
2
Analyze the identity fraud scenario (fake auditor calling HR)
Identified as Pretexting, which involves inventing a believable context or role to manipulation individuals into surrendering information.
Pretexting requires establishing a fictional background story and role prior to requesting sensitive access.
3
Analyze the payment detail tampering scenario (modifying vendor bank info)
Identified as Invoice Switching, where legitimate transactional data is modified to divert money.
Invoice switching explicitly targets financial workflows by modifying beneficiary banking details.
4
Analyze the high-level executive targeting scenario (email to CEO)
Identified as Whaling, a specialized subcategory of spear phishing directed specifically at C-suite personnel.
Phishing attempts specifically aimed at senior leadership or high-value targets are categorized as whaling.

Key Concept

Social Engineering Attack Classification
Question 277Question

Match each regulatory framework or standard to its primary compliance mandate.

Click a left item, then click its matching right item

Items

Payment Card Industry Data Security Standard (PCI DSS)
Health Insurance Portability and Accountability Act (HIPAA)
General Data Protection Regulation (GDPR)
Sarbanes-Oxley Act (SOX)

Matches

Show answer & explanation

Answer

PCI DSS matches cardholder data protection; HIPAA matches Protected Health Information (PHI) safeguards; GDPR matches EU personal data privacy rights; SOX matches corporate financial reporting and internal audit controls.
Each regulatory framework targets a distinct sector or data classification: PCI DSS protects cardholder data, HIPAA protects healthcare PHI, GDPR protects EU personal privacy rights, and SOX regulates public company financial accounting and audit logging.

Step-by-Step Solution

1
Identify the primary domain governed by PCI DSS.
PCI DSS focuses specifically on securing payment card transactions and credit/debit cardholder data.
Merchants and payment gateways must comply with PCI DSS to prevent payment fraud.
2
Identify the primary focus of HIPAA.
HIPAA establishes privacy and security rules for medical records and health data (PHI).
Healthcare providers must secure patient data under US federal regulations.
3
Identify the scope of GDPR.
GDPR governs privacy, consent, and rights regarding personal data for EU data subjects.
It applies broadly to any entity processing personal data of EU residents.
4
Identify the mandate of SOX.
SOX regulates financial record integrity, log retention, and internal auditing for publicly traded corporations.
It prevents accounting fraud and ensures transparency in corporate disclosures.

Key Concept

Regulatory Framework Mandates and Compliance Data Scope
Question 278Question

Match each Business Impact Analysis (BIA) metric or continuity planning parameter with its corresponding operational description.

Click a left item, then click its matching right item

Items

Work Recovery Time (WRT)
Maximum Tolerable Downtime (MTD)
Recovery Point Objective (RPO)
Mean Time Between Failures (MTBF)

Matches

Show answer & explanation

Answer

Work Recovery Time (WRT) matches system validation and process restoration duration; Maximum Tolerable Downtime (MTD) matches the total upper limit of tolerable business disruption; Recovery Point Objective (RPO) matches maximum acceptable data loss timeframe; Mean Time Between Failures (MTBF) matches component operational reliability between breakdowns.
Each business continuity metric serves a distinct purpose in a BIA: Work Recovery Time (WRT) covers business validation and process resumption post-technical recovery; Maximum Tolerable Downtime (MTD) sets the overarching threshold for enterprise viability; Recovery Point Objective (RPO) dictates acceptable data loss measured back in time; and Mean Time Between Failures (MTBF) measures hardware component reliability.

Step-by-Step Solution

1
Analyze data loss parameters
Identify RPO as the metric measuring acceptable data loss measured backwards in time.
RPO sets backup frequency requirements based on how much transactional data the business can afford to lose.
2
Distinguish between infrastructure recovery and business process recovery
Identify WRT as the period focused on post-RTO verification, testing, and business workflow restoration.
Technical restoration (RTO) brings infrastructure online, but WRT is required to ensure data integrity and operational readiness.
3
Evaluate total outage limits
Identify MTD as the overarching limit representing the point of irreversible enterprise damage.
MTD acts as the sum envelope (MTDRTO+WRTMTD \geq RTO + WRT) beyond which business survival is compromised.
4
Assess hardware reliability metrics
Identify MTBF as the metric predicting hardware longevity between failure events.
MTBF evaluates system component durability to determine maintenance cycles and redundancy needs.

Key Concept

Business Impact Analysis Metrics and Recovery Parameters
Question 279Question

Match each security audit, assessment, or attestation deliverable with its primary operational scope and objective.

Click a left item, then click its matching right item

Items

SOC 1 Type II Report
ISO/IEC 27001 Certification
Penetration Testing Assessment
PCI DSS Attestation of Compliance (AoC)

Matches

Show answer & explanation

Answer

SOC 1 Type II Report matches with financial reporting internal control evaluation over a period of time; ISO/IEC 27001 Certification matches with international ISMS compliance certification; Penetration Testing Assessment matches with proof-of-concept exploitation of technical vulnerabilities; PCI DSS Attestation of Compliance (AoC) matches with credit card data handling compliance validation.
Each deliverable serves a specific audit objective: SOC 1 Type II verifies internal controls related to financial reporting over a defined period; ISO/IEC 27001 certifies the enterprise ISMS against global standards; Penetration testing demonstrates active exploitability of technical vulnerabilities; PCI DSS AoC validates compliance with cardholder data protection requirements.

Step-by-Step Solution

1
Analyze the financial reporting aspect of SOC reports
Identify that SOC 1 specifically targets internal controls impacting financial reporting, with Type II covering a historical testing period.
SOC 1 is distinct from SOC 2 (trust services criteria) and focuses solely on financial controls.
2
Differentiate management system certifications from technical testing deliverables
Map ISO/IEC 27001 to formal ISMS certification and Penetration Testing to active technical vulnerability exploitation.
ISO 27001 evaluates holistic governance frameworks, whereas penetration testing evaluates dynamic technical defenses.
3
Identify cardholder data regulatory requirements
Link the PCI DSS Attestation of Compliance (AoC) to payment card security validation.
PCI DSS specifically governs entities processing, storing, or transmitting credit card information.

Key Concept

Distinguishing between security audit deliverables, attestations, and assessment methodologies based on scope and purpose.
Question 280Question

An organization is evaluating its third-party risk management governance framework to ensure proper compliance, software oversight, and vendor auditability. Match each third-party documentation artifact or agreement to its primary security function.

Click a left item, then click its matching right item

Items

Data Processing Agreement (DPA)
Software Bill of Materials (SBOM)
SOC 3 Report
Supply Chain Risk Management (SCRM) Plan

Matches

Show answer & explanation

Answer

Data Processing Agreement (DPA) matches with personal data processing compliance mandates; Software Bill of Materials (SBOM) matches with the nested inventory of software dependencies; SOC 3 Report matches with the publicly distributable executive summary of security controls; Supply Chain Risk Management (SCRM) Plan matches with the strategies for mitigating hardware tampering and supplier disruptions.
Each artifact correctly aligns with its specialized third-party risk oversight role: DPAs govern data privacy, SBOMs disclose software code components, SOC 3 reports serve as public attestations of security posture, and SCRM plans manage physical supply chain and hardware risks.

Step-by-Step Solution

1
Analyze the legal and privacy requirements for third-party data processing.
Identify that the Data Processing Agreement (DPA) governs third-party data protection responsibilities.
DPAs are legally binding addendums required for privacy regulation compliance when personal data is processed by vendors.
2
Evaluate component visibility in modern software supply chains.
Map the Software Bill of Materials (SBOM) to the structural list of software dependencies and open-source packages.
An SBOM gives organizations transparency into embedded software components and potential vulnerabilities.
3
Differentiate between audit reports meant for confidential operational review versus public distribution.
Associate the SOC 3 Report with the general executive summary intended for public distribution.
Unlike SOC 2, SOC 3 reports omit confidential technical details so they can be freely distributed to prospective clients.
4
Examine risk strategies aimed at physical components, procurement lines, and vendor logistics.
Link the Supply Chain Risk Management (SCRM) Plan to hardware provenance, counter-tampering, and supplier continuity.
SCRM plans specifically address systemic risks in hardware acquisition, counterfeit parts, and logistics pathways.

Key Concept

Third-Party Risk Management and Supply Chain Oversight
PreviousPage 14 / 19Next
All practice questions — CompTIA Security+ | Examkin