All practice questions
2232 questions
An organization relies on a legacy payment processing gateway that cannot be immediately upgraded due to vendor dependencies. A recent assessment identified multiple unpatched vulnerabilities in the gateway. To manage the associated exposure, the security team implements microsegmentation and deploys an inline web application firewall (WAF) to block exploit attempts, while the executive leadership team purchases a comprehensive cyber liability insurance policy to cover potential financial losses. Which of the following risk response strategies are implemented in this scenario? (Select TWO.)
Select all that apply
A financial analyst receives an unexpected telephone call from an individual claiming to be a senior analyst from the corporate internal audit department. The caller states that an urgent financial discrepancy was flagged during an ongoing audit and directs the analyst to verbally confirm their network login credentials and multi-factor authentication code to verify their identity before the system is locked out. Which social engineering attack vector is demonstrated in this scenario?
A United States-based mortgage technology provider processes personal financial records and loan applications for regional banks. The organization plans to migrate its infrastructure to a multi-tenant public cloud model while maintaining remote administration capabilities for offshore engineering teams. During a compliance evaluation, the Chief Information Security Officer (CISO) must ensure alignment with the Gramm-Leach-Bliley Act (GLBA) Safeguards Rule regarding administrative and technical data protections. Which of the following strategies best fulfills the legal compliance requirements for safeguarding consumer financial data in this architecture?
An enterprise risk manager is formalizing the organization's Business Continuity Management (BCM) testing program to validate recovery assumptions established during the Business Impact Analysis (BIA). Match each business continuity exercise type on the left to its corresponding operational execution methodology on the right.
Click a left item, then click its matching right item
Items
Matches
Match each audit or attestation report type to its primary operational purpose.
Click a left item, then click its matching right item
Items
Matches
A cloud service provider needs to publish a high-level attestation document on its public website to demonstrate compliance with security best practices to prospective clients, without disclosing detailed control design or confidential testing procedures. Which report fulfills this requirement?
A municipal transit authority is establishing a comprehensive security governance structure to ensure regulatory compliance across all operational departments. The security team must distinguish between mandatory governance directives and discretionary recommendations. Which of the following governance components represent mandatory requirements within an enterprise security governance framework? (Select TWO.)
Select all that apply
Match each security audit, assessment, or attestation deliverable with its primary operational purpose and evaluation scope.
Click a left item, then click its matching right item
Items
Matches
Match each regulatory framework or standard to its primary governance scope and legal mandate.
Click a left item, then click its matching right item
Items
Matches
An enterprise application runs in a cloud environment using containerized microservices operating under an immutable infrastructure deployment model. A vulnerability scan detects a critical remote code execution vulnerability within a software library contained inside several active production containers. Which of the following patch and configuration management practices should the security team perform to resolve the vulnerability?
A multinational fintech enterprise headquartered in Canada hosts its core payment processing and accounting platform in an IaaS cloud environment. The platform processes customer credit card transactions while also storing records subject to Sarbanes-Oxley (SOX) compliance for financial reporting integrity. Which of the following compliance actions and technical security controls must the organization enforce to satisfy these legal and regulatory frameworks? (Select TWO.)
Select all that apply
An organization is enhancing its third-party governance framework to address vendor oversight and supply chain security. Match each third-party risk management instrument on the left with its primary operational purpose on the right.
Click a left item, then click its matching right item
Items
Matches
An enterprise Security Operations Center (SOC) analyst is reviewing network security monitoring alerts and NetFlow records for an internal workstation. The monitoring tools report suspicious outbound protocol activity originating from the host. Which of the following network security monitoring findings specifically indicate that DNS tunneling is being utilized for data exfiltration? (Select TWO).
Select all that apply
A hospital system contracts with a cloud-based Electronic Health Records (EHR) vendor. During a risk assessment, the security team discovers that the EHR vendor delegates its database backup and data archiving operations to an external sub-processor. Which of the following risk management controls best ensures that third-party and fourth-party security standards are maintained throughout this supply chain?
Match each enterprise security incident scenario on the left with the specific social engineering attack vector utilized on the right.
Click a left item, then click its matching right item
Items
Matches
An international aerospace technology firm headquartered in Munich, Germany, with active defense and commercial operations in the United States, discovers an unencrypted database snapshot exposed on a public cloud bucket. Investigation reveals that the exposed data contains both European Union customer Personal Identifiable Information (PII) and restricted US defense technical specifications subject to International Traffic in Arms Regulations (ITAR). Which action correctly fulfills the enterprise's concurrent statutory compliance and regulatory reporting duties?
A security analyst is reviewing internal security mechanisms to ensure they are properly classified according to CompTIA Security+ control categories. Which of the following mechanisms are classified as technical security controls? (Select TWO.)
Select all that apply
A security administrator is evaluating enterprise cryptographic standards across various system modules. Match each cryptographic algorithm or mechanism on the left with its primary operational security application on the right.
Click a left item, then click its matching right item
Items
Matches
An enterprise security risk manager is leading a Business Impact Analysis (BIA) for a newly integrated real-time interbank transaction settlement platform. To configure disaster recovery targets and automated failover policies, the manager must establish baseline metrics that explicitly bound maximum tolerable transactional data loss and the overall maximum timeframe the platform can remain offline before experiencing catastrophic regulatory penalties. Which of the following parameters must be established to satisfy these specific measurement requirements? (Select TWO.)
Select all that apply
A software development firm is deploying an automated continuous integration pipeline to release signed application updates to enterprise clients. To meet regulatory compliance, the pipeline must ensure that the authenticity of the code publisher can be independently verified by third parties and that the publishing organization cannot repudiate the origin of the software package. Which of the following cryptographic mechanisms best fulfills these requirements?