All practice questions

2232 questions

Question 1701Question

An organization relies on a legacy payment processing gateway that cannot be immediately upgraded due to vendor dependencies. A recent assessment identified multiple unpatched vulnerabilities in the gateway. To manage the associated exposure, the security team implements microsegmentation and deploys an inline web application firewall (WAF) to block exploit attempts, while the executive leadership team purchases a comprehensive cyber liability insurance policy to cover potential financial losses. Which of the following risk response strategies are implemented in this scenario? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: Risk mitigation; Risk transference

Answer

The organization demonstrates risk mitigation by deploying technical security controls (microsegmentation and WAF) and risk transference by purchasing cyber liability insurance.
Risk mitigation is illustrated by deploying technical controls (microsegmentation and a web application firewall) to minimize vulnerability exposure. Risk transference is illustrated by securing a cyber liability insurance policy to pass monetary risk to an insurer.

Step-by-Step Solution

1
Analyze the technical security safeguards deployed by the security team.
Microsegmentation and inline web application firewalls lower the likelihood and impact of attacks against the legacy system, which represents risk mitigation.
Risk mitigation reduces risk exposure to an acceptable level using technical, administrative, or physical controls.
2
Analyze the financial protection measures authorized by executive leadership.
Purchasing cyber liability insurance shifts the monetary burden of potential breach incidents to the insurance carrier, which represents risk transference.
Risk transference reallocates financial risk exposure to a third party.

Key Concept

Risk Response Strategies
Question 1702Question

A financial analyst receives an unexpected telephone call from an individual claiming to be a senior analyst from the corporate internal audit department. The caller states that an urgent financial discrepancy was flagged during an ongoing audit and directs the analyst to verbally confirm their network login credentials and multi-factor authentication code to verify their identity before the system is locked out. Which social engineering attack vector is demonstrated in this scenario?

Show answer & explanation

Answer: Vishing

Answer

The correct attack vector is vishing.
The correct option is vishing because the social engineering attempt was carried out using a direct voice telephone call to manipulate the victim into revealing sensitive login credentials and multi-factor authentication tokens.

Step-by-Step Solution

1
Analyze the communication medium described in the incident scenario.
The attack occurs via a direct telephone call (voice communication).
Identifying the transmission channel differentiates voice-based social engineering from email or text messaging.
2
Evaluate the attacker's tactic and objective.
The caller uses pretexting (impersonating an internal auditor) to create urgency and trick the victim into sharing sensitive authentication factors.
Social engineering attacks often leverage trust and urgency to bypass standard security procedures.
3
Map the medium and tactic to standard security taxonomy terminology.
Voice-based phishing conducted over the telephone is defined as vishing (voice phishing).
CompTIA Security+ distinguishes social engineering variants based on delivery mechanisms and target profiles.

Key Concept

Vishing (Voice Phishing)
Estimated Time:1m 0s
Question 1703Question

A United States-based mortgage technology provider processes personal financial records and loan applications for regional banks. The organization plans to migrate its infrastructure to a multi-tenant public cloud model while maintaining remote administration capabilities for offshore engineering teams. During a compliance evaluation, the Chief Information Security Officer (CISO) must ensure alignment with the Gramm-Leach-Bliley Act (GLBA) Safeguards Rule regarding administrative and technical data protections. Which of the following strategies best fulfills the legal compliance requirements for safeguarding consumer financial data in this architecture?

Show answer & explanation

Answer: Mandate multi-factor authentication for all personnel accessing customer financial systems, enforce data encryption in transit and at rest, and designate a qualified individual to oversee the information security program.

Answer

Mandate multi-factor authentication for all personnel accessing customer financial systems, enforce data encryption in transit and at rest, and designate a qualified individual to oversee the information security program.
The correct option directly implements the explicit requirements outlined in the FTC GLBA Safeguards Rule. Under GLBA, financial entities and their service providers must protect consumer non-public personal information by implementing technical safeguards—such as multi-factor authentication and data encryption both at rest and in transit—and administrative safeguards, such as designating a qualified individual to manage and oversee the security program.

Step-by-Step Solution

1
Identify the primary governing regulation and its scope.
The target organization handles non-public personal financial information for banking customers, bringing it directly under the jurisdiction of the FTC Gramm-Leach-Bliley Act (GLBA) Safeguards Rule.
Regulatory compliance mandates depend on aligning technical controls directly with the statutory obligations of the specific governing framework.
2
Analyze the mandatory administrative and technical safeguards required under the GLBA Safeguards Rule updates.
The rule mandates specific baseline controls: robust access controls including multi-factor authentication (MFA) for accessing customer data, encryption of data at rest and in transit, continuous monitoring or vulnerability testing, and administrative oversight by a designated qualified individual.
Financial privacy regulations mandate both administrative accountability and rigorous technical controls to protect non-public personal information.
3
Evaluate the proposed operational options against these regulatory requirements.
Enforcing MFA, implementing end-to-end encryption for storage and transit in the cloud environment, and appointing a qualified individual directly fulfills the statutory requirements of the GLBA Safeguards Rule.
This combination addresses both technical protection measures for multi-tenant/offshore access and formal governance oversight required by law.

Key Concept

Gramm-Leach-Bliley Act (GLBA) Safeguards Rule Requirements
Estimated Time:2m 0s
Question 1704Question

An enterprise risk manager is formalizing the organization's Business Continuity Management (BCM) testing program to validate recovery assumptions established during the Business Impact Analysis (BIA). Match each business continuity exercise type on the left to its corresponding operational execution methodology on the right.

Click a left item, then click its matching right item

Items

Tabletop Exercise
Structured Walk-Through Test
Parallel Test
Full-Interruption Test

Matches

Show answer & explanation

Answer

Tabletop Exercise matches verbal scenario discussion among key stakeholders. Structured Walk-Through Test matches line-by-line review of continuity documentation. Parallel Test matches concurrent processing on backup systems without disrupting production. Full-Interruption Test matches completely shutting down primary systems to migrate live operations.
Each business continuity exercise type corresponds to a specific level of operational disruption and validation depth. Tabletop exercises involve verbal scenario discussions. Structured walk-through tests involve detailed documentation audits. Parallel tests run recovery systems concurrently alongside live production without risk of downtime. Full-interruption tests intentionally shut down primary systems to validate complete operational failover.

Step-by-Step Solution

1
Analyze discussion-based exercise methods
Identify that Tabletop Exercises focus on verbal scenario walkthroughs without hardware deployment.
Tabletop exercises test decision-making and awareness in a meeting setting.
2
Differentiate documentation validation from scenario discussion
Identify that Structured Walk-Through Tests focus on step-by-step reading and verification of the written plan.
Structured walk-throughs ensure that the disaster recovery documentation itself is complete and accurate.
3
Evaluate operational recovery testing methodologies
Match Parallel Testing with concurrent redundant system processing that maintains active production, and Full-Interruption Testing with disabling live systems to force failover.
Parallel tests minimize business risk while testing hardware readiness, whereas full-interruption tests validate real-time failover under actual outage conditions.

Key Concept

Business Continuity Plan (BCP) Testing and Exercise Methodologies
Question 1705Question

Match each audit or attestation report type to its primary operational purpose.

Click a left item, then click its matching right item

Items

SOC 1 Report
SOC 2 Type I Report
SOC 2 Type II Report
SOC 3 Report

Matches

Show answer & explanation

Answer

SOC 1 matches financial reporting controls; SOC 2 Type I matches point-in-time control design evaluation; SOC 2 Type II matches control design and operational effectiveness over a period of time; SOC 3 matches high-level public summaries.
Each attestation serves a distinct audit purpose: SOC 1 evaluates financial reporting controls; SOC 2 Type I assesses control design at a single snapshot date; SOC 2 Type II verifies control design and operational performance over a specified evaluation period; and SOC 3 provides a publicly distributable summary.

Step-by-Step Solution

1
Differentiate financial assurance reports from trust services security reports.
SOC 1 addresses financial reporting (ICFR), whereas SOC 2 and SOC 3 address security, availability, and confidentiality.
Organizations use SOC 1 when third-party services directly impact financial statements.
2
Distinguish between Type I and Type II report timeframes and depth.
Type I is a snapshot evaluation of control design at a single point in time, while Type II measures operational performance over a multi-month period.
Type II requires extensive historical log review and evidence gathering to prove controls operated as designed over time.
3
Identify the report designed for public distribution.
SOC 3 provides a generalized public summary.
Unlike SOC 2 reports, which contain sensitive architectural details, SOC 3 reports are stripped of confidential data so they can be shared freely.

Key Concept

SOC Report Types and Attestation Scopes
Question 1706Question

A cloud service provider needs to publish a high-level attestation document on its public website to demonstrate compliance with security best practices to prospective clients, without disclosing detailed control design or confidential testing procedures. Which report fulfills this requirement?

Show answer & explanation

Answer: SOC 3 report

Answer

A SOC 3 report provides a general-use, publicly shareable summary of security attestations without exposing confidential system design details.
A SOC 3 report is specifically created for general public distribution. It provides an executive summary of an organization's compliance with Trust Services Criteria without revealing sensitive details regarding system architecture or specific control testing results.

Step-by-Step Solution

1
Identify the primary requirement in the scenario.
The organization requires a publicly accessible security attestation report that excludes sensitive internal architectural and testing details.
Prospective customers need proof of security posture, but public distribution of detailed audit reports poses a security risk.
2
Evaluate the scope and audience of available SOC reports.
SOC 1 and SOC 2 reports are restricted-use documents intended for management and existing clients, whereas SOC 3 reports are designated for public distribution.
SOC 3 provides an executive summary based on SOC 2 Trust Services Criteria without disclosing proprietary system details.

Key Concept

SOC 3 Public Attestation Reports
Question 1707Question

A municipal transit authority is establishing a comprehensive security governance structure to ensure regulatory compliance across all operational departments. The security team must distinguish between mandatory governance directives and discretionary recommendations. Which of the following governance components represent mandatory requirements within an enterprise security governance framework? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: Security Policies defining executive direction and high-level organizational mandates; Security Standards specifying explicit mandatory operational metrics and technical baseline rules

Answer

Security Policies defining executive direction and high-level organizational mandates, and Security Standards specifying explicit mandatory operational metrics and technical baseline rules.
Security policies and security standards are mandatory elements within a security governance framework. Executive management establishes policies to define overarching compliance mandates, while security standards specify obligatory technical requirements and operational baselines required to enforce those policies.

Step-by-Step Solution

1
Analyze governance framework document tiers
Identify that enterprise governance structures categorize documents into compulsory directives and discretionary recommendations.
Governance frameworks establish clear boundaries between obligatory compliance controls and suggested guidance.
2
Evaluate compulsory governance mechanisms
Policies establish top-level executive directives, while standards define specific technical baseline specifications and mandatory operational rules.
Both policies and standards carry mandatory compliance authority within an organization.
3
Differentiate from discretionary items and technical implementation artifacts
Guidelines are non-binding recommendations, control categories are functional classifications, and access matrices are technical authorization artifacts.
Only policies and standards function as mandatory governance framework elements.

Key Concept

Enterprise Security Governance Hierarchy and Mandatory vs. Discretionary Framework Components
Question 1708Question

Match each security audit, assessment, or attestation deliverable with its primary operational purpose and evaluation scope.

Click a left item, then click its matching right item

Items

SOC 2 Type I Report
SOC 2 Type II Report
SOC 3 Report
ISO/IEC 27001 Certification

Matches

Show answer & explanation

Answer

SOC 2 Type I matches point-in-time design suitability; SOC 2 Type II matches design suitability and operating effectiveness over a defined period; SOC 3 matches public-facing executive summary attestation; ISO/IEC 27001 matches accredited ISMS framework certification.
Each deliverable maps strictly to its evaluation scope: SOC 2 Type I assesses control design at a single point in time; SOC 2 Type II assesses design and operating effectiveness over a monitoring period; SOC 3 is a freely distributable public summary; ISO/IEC 27001 certifies the overall Information Security Management System against international standard criteria.

Step-by-Step Solution

1
Analyze the timeframe requirement of SOC 2 attestation reports
Distinguish Type I (point in time, design suitability only) from Type II (over a testing period, design and operating effectiveness).
Type I audits examine control architecture at a specific date snapshot, whereas Type II requires historical evidence of operating consistency.
2
Determine the intended distribution audience for SOC reports
Identify SOC 3 as the publicly distributable version of SOC 2.
SOC 2 reports contain sensitive system descriptions for restricted use, while SOC 3 reports provide high-level assurance for prospective customers and public distribution.
3
Identify international framework certifications
Match ISO/IEC 27001 to the formal accredited audit of an Information Security Management System (ISMS).
ISO 27001 specifies requirements for establishing, implementing, maintaining, and continually improving an organizational ISMS.

Key Concept

Third-Party Security Audits, Attestations, and Framework Certifications
Question 1709Question

Match each regulatory framework or standard to its primary governance scope and legal mandate.

Click a left item, then click its matching right item

Items

FISMA
GDPR
PCI DSS
SOX

Matches

Show answer & explanation

Answer

FISMA matches the security mandate for U.S. federal government agencies; GDPR matches personal privacy rights for EU individuals; PCI DSS matches contractual requirements for credit card processing merchants; SOX matches internal financial reporting controls for public companies.
Each regulation or standard aligns directly with its designated scope: FISMA governs U.S. federal agency systems; GDPR governs European consumer data privacy; PCI DSS governs payment card merchant data environments; and SOX governs internal financial reporting controls for public companies.

Step-by-Step Solution

1
Identify the mandate governing federal information systems.
FISMA establishes information security practices for U.S. federal agencies and their supporting contractors.
Understanding federal scope separates public-sector statutory frameworks from private commercial standards.
2
Determine the regulation protecting European personal privacy rights.
GDPR regulates personal data processing, consumer consent, and international data transfers for EU residents.
GDPR focuses on data subject privacy rights across international boundaries.
3
Identify the standard governing payment card environments.
PCI DSS is a non-governmental contractual standard required by payment brands for entities handling credit card transactions.
Cardholder data environments are regulated by industry contractual standards rather than federal legislation.
4
Determine the legal requirement for public corporate financial transparency.
SOX mandates internal accounting safeguards and audit trails for publicly traded corporate financial disclosures.
SOX targets corporate governance and accounting oversight to protect investors.

Key Concept

Regulatory Compliance Frameworks and Governance Scopes
Question 1710Question

An enterprise application runs in a cloud environment using containerized microservices operating under an immutable infrastructure deployment model. A vulnerability scan detects a critical remote code execution vulnerability within a software library contained inside several active production containers. Which of the following patch and configuration management practices should the security team perform to resolve the vulnerability?

Show answer & explanation

Answer: Update the base container image with the patched library, validate the build in a testing pipeline, and redeploy new container instances to replace the vulnerable ones.

Answer

Update the base container image with the patched library, validate the build in a testing pipeline, and redeploy new container instances to replace the vulnerable ones.
In an immutable infrastructure deployment model, running components (such as containers or virtual machine instances) are never patched or modified directly in production. When a security update or patch is required, the baseline source image (e.g., container image specification) is updated with the new library version, validated in a staging or CI/CD environment, and then used to deploy fresh instances while decommissioning the old, vulnerable ones. This eliminates configuration drift and ensures consistency across environments.

Step-by-Step Solution

1
Identify the core deployment architecture model.
The infrastructure is designated as immutable, meaning running instances are never modified in place.
Configuration changes and updates in immutable environments must follow a build-test-deploy lifecycle via images.
2
Select the appropriate patch management workflow for containerized images.
Modify the base container image file (e.g., Dockerfile) to reference the patched dependency version.
This guarantees that all future deployments inherit the correct security posture consistently.
3
Test and swap running instances.
Pass the updated image through automated staging tests and terminate vulnerable production containers while deploying new instances.
Ensures zero configuration drift and remediates the vulnerability cleanly.

Key Concept

Immutable Infrastructure Patching
Estimated Time:1m 15s
Question 1711Question

A multinational fintech enterprise headquartered in Canada hosts its core payment processing and accounting platform in an IaaS cloud environment. The platform processes customer credit card transactions while also storing records subject to Sarbanes-Oxley (SOX) compliance for financial reporting integrity. Which of the following compliance actions and technical security controls must the organization enforce to satisfy these legal and regulatory frameworks? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: Implement strict access control policies, segregation of duties, and immutable logging for database systems housing financial statements.; Isolate the Cardholder Data Environment (CDE) through network segmentation and enforce strong encryption on stored primary account numbers.

Answer

The organization must implement strict access control policies, segregation of duties, and immutable logging for financial reporting systems (SOX requirement), and isolate the Cardholder Data Environment (CDE) while encrypting stored account numbers (PCI-DSS requirement).
Establishing strict access control policies, segregation of duties, and audit logging for financial databases directly satisfies SOX Section 404 mandates regarding internal control over financial reporting. Simultaneously, isolating the Cardholder Data Environment (CDE) and encrypting primary account numbers directly aligns with PCI-DSS requirements for protecting payment data.

Step-by-Step Solution

1
Analyze regulatory scope requirements for Sarbanes-Oxley (SOX) Act compliance.
Identify that SOX focuses on internal financial reporting controls, access tracking, data integrity, and auditing of financial systems.
SOX Section 404 requires verifiable internal controls over financial disclosures.
2
Analyze regulatory scope requirements for Payment Card Industry Data Security Standard (PCI-DSS).
Identify that processing credit card data mandates Cardholder Data Environment (CDE) scope reduction via segmentation and encryption of primary account numbers (PAN).
PCI-DSS enforces specific technical controls to reduce card fraud and scope exposure.
3
Evaluate distractors against cloud responsibility models and security control types.
Disqualify offloading compliance liability to an IaaS provider and using network firewalls to fix code bugs.
Data governance remains with the tenant in IaaS, and network firewalls do not solve application software code flaws.

Key Concept

Regulatory Compliance Alignment and Mandatory Control Verification
Question 1712Question

An organization is enhancing its third-party governance framework to address vendor oversight and supply chain security. Match each third-party risk management instrument on the left with its primary operational purpose on the right.

Click a left item, then click its matching right item

Items

Vendor Security Assessment Questionnaire (VSAQ)
Right-to-Audit Contractual Clause
Hardware Bill of Materials (HBOM)
Service Level Agreement (SLA)

Matches

Show answer & explanation

Answer

Vendor Security Assessment Questionnaire matches with evaluating self-reported security controls; Right-to-Audit Clause matches with establishing legal authority to inspect controls; Hardware Bill of Materials matches with tracking physical component sourcing and sub-tier provenance; Service Level Agreement matches with defining measurable service performance metrics.
Each instrument fulfills a specific role in third-party risk management: Questionnaires assess self-reported baseline posture during onboarding, Right-to-Audit provisions grant verification permissions, HBOMs track physical component provenance against tampering, and SLAs define operational metrics and breach remedies.

Step-by-Step Solution

1
Identify the primary purpose of pre-onboarding questionnaires.
Match Vendor Security Assessment Questionnaire (VSAQ) with evaluating self-reported security controls during initial onboarding.
VSAQs are standardized tools used during initial risk assessment to gauge vendor compliance and risk profile.
2
Analyze contractual inspection rights.
Match Right-to-Audit Contractual Clause with establishing legal authority to inspect physical and technical controls.
Right-to-audit clauses ensure the client is legally permitted to independently audit or inspect vendor facilities and systems.
3
Evaluate hardware supply chain oversight mechanisms.
Match Hardware Bill of Materials (HBOM) with tracking component sourcing and sub-tier provenance.
An HBOM details all physical sub-components and integrated circuits, ensuring component origin integrity.
4
Determine performance operational contract mechanisms.
Match Service Level Agreement (SLA) with defining measurable service performance metrics and uptime expectations.
SLAs govern operational expectations, availability metrics, and remediation terms.

Key Concept

Third-Party Risk Management and Supply Chain Oversight Instruments
Question 1713Question

An enterprise Security Operations Center (SOC) analyst is reviewing network security monitoring alerts and NetFlow records for an internal workstation. The monitoring tools report suspicious outbound protocol activity originating from the host. Which of the following network security monitoring findings specifically indicate that DNS tunneling is being utilized for data exfiltration? (Select TWO).

Select all that apply

Show answer & explanation

Answer: A high volume of DNS TXT record queries containing high-entropy, encoded strings directed to an external authoritative name server; A significant increase in outbound payload data volume transmitted over UDP port 53 compared to established network baselines

Answer

The network monitoring findings that indicate DNS tunneling for data exfiltration are a high volume of DNS TXT record queries containing high-entropy encoded strings directed to an external authoritative name server, and a significant increase in outbound payload data volume transmitted over UDP port 53 compared to established network baselines.
DNS tunneling abuses standard domain name resolution traffic to exfiltrate sensitive data or maintain covert communications. Network security monitoring tools identify this technique by detecting abnormally large outbound payload transfers on UDP port 53 and uncovering repeated DNS TXT requests containing long, high-entropy encoded subdomains destined for untrusted external name servers.

Step-by-Step Solution

1
Analyze network protocol traffic volume against baseline metrics.
Identify anomalous outbound byte counts originating on UDP port 53.
Standard DNS queries are small in size; a large outbound byte transfer over port 53 indicates data payload encapsulation.
2
Inspect packet payloads and query record types within DNS monitoring logs.
Detect encoded high-entropy subdomain strings in TXT queries sent to external name servers.
Attackers structure exfiltrated data into subdomains resolved by attacker-controlled authoritative name servers to bypass standard egress filtering.

Key Concept

Detecting DNS tunneling and data exfiltration indicators using network security monitoring analysis
Question 1714Question

A hospital system contracts with a cloud-based Electronic Health Records (EHR) vendor. During a risk assessment, the security team discovers that the EHR vendor delegates its database backup and data archiving operations to an external sub-processor. Which of the following risk management controls best ensures that third-party and fourth-party security standards are maintained throughout this supply chain?

Show answer & explanation

Answer: Enforce contractual requirements that compel the primary vendor to flow down security controls and grant right-to-audit permissions for sub-processors

Answer

Enforce contractual requirements that compel the primary vendor to flow down security controls and grant right-to-audit permissions for sub-processors.
Contractual flow-down clauses ensure that the primary vendor binds any sub-processors (fourth parties) to the same security standards and audit obligations agreed upon with the customer. This ensures end-to-end supply chain visibility and accountability.

Step-by-Step Solution

1
Identify the risk vector in the supply chain scenario
Recognize that data handling extends beyond the primary third-party vendor to a fourth-party sub-processor.
Security risks propagate along the supply chain whenever a primary vendor delegates critical data functions to downstream service providers.
2
Evaluate the appropriate governance mechanism for fourth-party risk management
Determine that contractual flow-down obligations and right-to-audit provisions extend governance to sub-processors.
Direct contractual relationship exists only with the primary vendor; thus, contractual terms must obligate the primary vendor to enforce equivalent controls downstream.

Key Concept

Fourth-Party Risk Management and Flow-Down Contractual Provisions
Question 1715Question

Match each enterprise security incident scenario on the left with the specific social engineering attack vector utilized on the right.

Click a left item, then click its matching right item

Items

An attacker registers a domain name containing a common misspelling of a corporate web portal to harvest employee authentication credentials.
An attacker leaves malware-infected USB flash drives scattered in the employee parking lot hoping someone inserts one into a company workstation.
An attacker contacts a shipping department while impersonating a logistics dispatcher to trick staff into redirecting a valuable shipment to an offsite address.
An attacker submits a fraudulent payment request to the accounts payable department designed to mimic a routine bill from an established third-party vendor.

Matches

Show answer & explanation

Answer

The credential harvesting site using a misspelled domain matches Typosquatting; the malware-laden flash drives left in the parking lot match Baiting; the fraudulent redirection of a shipment matches Diversion theft; and the fake vendor payment request matches Invoice fraud.
Each attack vector is correctly paired based on its primary delivery mechanism: Typosquatting uses deceptive URLs based on spelling errors; Baiting relies on physical media traps; Diversion theft manipulates physical delivery routes; and Invoice fraud uses deceptive billing requests to siphon corporate funds.

Step-by-Step Solution

1
Analyze the web portal scenario involving misspelled domain registration.
Identify that exploiting typos in URLs to host spoofed credential-harvesting sites is typosquatting.
Typosquatting relies on user typographical mistakes when typing web addresses.
2
Analyze the physical media scenario involving unattended USB drives.
Identify that leaving physical media to entice curiosity is baiting.
Baiting relies on offering a physical item or incentive that promises a reward or satisfies curiosity.
3
Analyze the logistics scenario involving redirected shipments.
Identify that intercepting or altering courier deliveries is diversion theft.
Diversion theft specifically targets the supply chain or delivery process to steal physical goods.
4
Analyze the financial payment request scenario.
Identify that spoofing vendor billing documents to manipulate accounts payable is invoice fraud.
Invoice fraud uses pretexting and spoofed documentation to trick accounting into unauthorized disbursements.

Key Concept

Social Engineering Attack Vectors
Question 1716Question

An international aerospace technology firm headquartered in Munich, Germany, with active defense and commercial operations in the United States, discovers an unencrypted database snapshot exposed on a public cloud bucket. Investigation reveals that the exposed data contains both European Union customer Personal Identifiable Information (PII) and restricted US defense technical specifications subject to International Traffic in Arms Regulations (ITAR). Which action correctly fulfills the enterprise's concurrent statutory compliance and regulatory reporting duties?

Show answer & explanation

Answer: Report the personal data exposure to the relevant EU supervisory authority within 72 hours under GDPR while executing export control risk assessment and disclosure procedures with the US Department of State Directorate of Defense Trade Controls (DDTC).

Answer

The enterprise must report the PII exposure to the designated EU supervisory authority within 72 hours under GDPR and follow statutory disclosure protocols with the US Directorate of Defense Trade Controls (DDTC) regarding ITAR technical data exposure.
The correct response recognizes that multinational operations dealing with dual-use or multi-jurisdictional data must satisfy independent statutory requirements simultaneously. Under GDPR, personal data breaches must be reported to the supervisory authority within 72 hours. Concurrently, public exposure of ITAR-controlled defense technical data constitutes an unauthorized export under US law, mandating formal disclosure procedures with the Directorate of Defense Trade Controls (DDTC).

Step-by-Step Solution

1
Analyze the affected data classifications present in the incident
Identified European Union customer PII (governed by GDPR) and US export-controlled defense technical data (governed by ITAR).
Regulatory scope and notification bodies depend directly on data jurisdiction and legal governance classification.
2
Evaluate statutory GDPR compliance mandates
GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of a personal data breach unless the breach is unlikely to result in a risk to individuals.
Unencrypted PII publicly exposed on the internet poses clear privacy risks to data subjects.
3
Evaluate statutory ITAR export compliance mandates
Unauthorized foreign or public access to ITAR technical data constitutes an illegal export, requiring voluntary or mandatory disclosure to the US Department of State DDTC.
Export control laws enforce strict statutory notification rules regardless of whether data exposure occurred via cloud misconfiguration.

Key Concept

Multi-Jurisdictional Regulatory Compliance & Breach Notification Mandates
Question 1717Question

A security analyst is reviewing internal security mechanisms to ensure they are properly classified according to CompTIA Security+ control categories. Which of the following mechanisms are classified as technical security controls? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: Configuring a Host-based Intrusion Prevention System (HIPS) agent to block malicious memory execution attempts.; Enforcing 802.1X Network Access Control (NAC) on network switches to dynamically authenticate connecting devices.

Answer

Configuring a Host-based Intrusion Prevention System (HIPS) agent and Enforcing 802.1X Network Access Control (NAC) are both technical security controls.
Technical controls (also known as logical controls) consist of software, hardware, firmware, or network protocol mechanisms implemented to safeguard systems and data. Configuring a Host-based Intrusion Prevention System (HIPS) to block malicious process execution and enforcing 802.1X Network Access Control (NAC) to dynamically validate connection attempts both rely directly on automated software logic and network technology to enforce access rules.

Step-by-Step Solution

1
Define technical control category characteristics according to security frameworks.
Technical (logical) controls are safeguards executed through computer hardware, software, firmware, or network protocols.
Control categorization depends on the execution mechanism used to enforce security.
2
Evaluate each option against the technical control definition.
HIPS software and 802.1X network authentication operate automatically via system software and network devices (technical). Biometric door locks guard physical entry (physical), while facility security walk-through audits are procedural tasks performed by personnel (operational).
Distinguishing between technology-enforced, physical facility-enforced, and human-procedural controls yields the correct technical safeguards.

Key Concept

Security Control Categories (Technical, Operational, Physical, Managerial)
Estimated Time:1m 15s
Question 1718Question

A security administrator is evaluating enterprise cryptographic standards across various system modules. Match each cryptographic algorithm or mechanism on the left with its primary operational security application on the right.

Click a left item, then click its matching right item

Items

PBKDF2 (Password-Based Key Derivation Function 2)
ECDHE (Elliptic Curve Diffie-Hellman Ephemeral)
HMAC-SHA256
AES-CBC with PKCS#7 Padding

Matches

Show answer & explanation

Answer

PBKDF2 matches with mitigating offline brute-force attacks via key stretching. ECDHE matches with providing perfect forward secrecy during key exchange. HMAC-SHA256 matches with verifying data integrity and authenticity via a shared key. AES-CBC with PKCS#7 matches with bulk symmetric confidentiality for block payloads.
Each cryptographic mechanism is accurately matched to its intended operational function based on core security engineering principles: PBKDF2 hardens password authentication via key stretching; ECDHE provides ephemeral session key establishment with forward secrecy; HMAC-SHA256 delivers keyed integrity and authentication; and AES-CBC provides bulk block cipher confidentiality.

Step-by-Step Solution

1
Analyze PBKDF2 function
Identified key stretching mechanism designed specifically to harden password hashes against brute-force attacks.
PBKDF2 applies salting and high iteration counts to increase computational cost per cracking attempt.
2
Analyze ECDHE mechanism
Identified ephemeral asymmetric key exchange algorithm providing perfect forward secrecy.
Ephemeral key generation guarantees that session keys are temporary and independent.
3
Analyze HMAC-SHA256 function
Identified keyed-hash message authentication code.
Combining a symmetric key with SHA-256 guarantees both integrity and message origin verification.
4
Analyze AES-CBC with PKCS#7 padding
Identified symmetric block cipher operating mode with padding.
AES-CBC encrypts 128-bit block units sequentially, requiring padding to fill incomplete final blocks.

Key Concept

Operational application of cryptographic primitives and key management mechanisms
Question 1719Question

An enterprise security risk manager is leading a Business Impact Analysis (BIA) for a newly integrated real-time interbank transaction settlement platform. To configure disaster recovery targets and automated failover policies, the manager must establish baseline metrics that explicitly bound maximum tolerable transactional data loss and the overall maximum timeframe the platform can remain offline before experiencing catastrophic regulatory penalties. Which of the following parameters must be established to satisfy these specific measurement requirements? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: Recovery Point Objective (RPO) to establish the maximum acceptable age of unrecovered data resulting from an outage.; Maximum Tolerable Downtime (MTD) to define the total threshold of operational outage time the business process can sustain before suffering non-recoverable damage.

Answer

The parameters that must be established are the Recovery Point Objective (RPO) to bound acceptable data loss timeframe, and the Maximum Tolerable Downtime (MTD) to establish the maximum allowable system outage duration.
The scenario requires defining metrics for two distinct thresholds: maximum tolerable transactional data loss and total allowable outage duration. Recovery Point Objective (RPO) specifies the maximum acceptable data loss measured in time, defining how recent restored backups must be. Maximum Tolerable Downtime (MTD) sets the absolute longest duration a business process can remain offline before encountering unacceptable consequences.

Step-by-Step Solution

1
Analyze the BIA requirements for measuring data loss tolerance.
Identified Recovery Point Objective (RPO) as the metric determining the maximum acceptable temporal gap in transaction data loss.
RPO dictates backup frequency and replication architecture by defining how far back in time recovery must reach.
2
Analyze the BIA requirements for measuring overall allowable system outage limits.
Identified Maximum Tolerable Downtime (MTD) as the upper boundary for total business process outage duration.
MTD establishes the limit beyond which business operational disruption causes irreparable impact or non-compliance.
3
Evaluate remaining continuity metrics to eliminate non-matching targets.
Disqualified MTBF (a hardware reliability metric) and WRT (a post-recovery testing and process catch-up duration metric).
Neither MTBF nor WRT define maximum tolerable data loss or overall allowable outage duration limits.

Key Concept

Business Impact Analysis (BIA) metrics: RPO defines maximum acceptable data loss timeframe, whereas MTD sets the maximum overall tolerable outage duration.
Question 1720Question

A software development firm is deploying an automated continuous integration pipeline to release signed application updates to enterprise clients. To meet regulatory compliance, the pipeline must ensure that the authenticity of the code publisher can be independently verified by third parties and that the publishing organization cannot repudiate the origin of the software package. Which of the following cryptographic mechanisms best fulfills these requirements?

Show answer & explanation

Answer: Applying a digital signature using the organization's private key

Answer

Applying a digital signature using the organization's private key best fulfills the requirement because asymmetric key pair signing uniquely identifies the origin and prevents non-repudiation.
A digital signature uses an asymmetric key pair where the creator signs data with their private key, and recipients verify it using the corresponding public key. Because only the owner possesses the private key, public verification guarantees both origin authenticity and non-repudiation.

Step-by-Step Solution

1
Identify the required cryptographic properties from the scenario requirements.
The scenario specifically demands origin authenticity, third-party verifiability, and non-repudiation.
Regulatory compliance mandates that the origin of compiled code cannot be denied by the author and must be verifiable by end users.
2
Evaluate symmetric vs. asymmetric mechanisms against non-repudiation constraints.
Symmetric techniques (such as shared keys or symmetric encryption) allow any keyholder to generate valid codes/hashes, failing non-repudiation.
Non-repudiation requires a unique asymmetric private key owned strictly by the publishing entity.
3
Select the appropriate cryptographic mechanism.
Digital signatures generate a hash of the binary encrypted with the publisher's private key, which anyone can verify using the matching public key.
This guarantees integrity, origin authentication, and non-repudiation simultaneously.

Key Concept

Digital Signatures and Non-Repudiation
PreviousPage 86 / 112Next
All practice questions — CompTIA Security+ | Examkin