General Security Concepts
268 questions
An IT infrastructure team plans to implement a centralized Privileged Access Management (PAM) solution to manage administrative access across corporate servers. To comply with formal change management policies and minimize operational and security risks, in which sequence should the team perform the following change control steps?
Drag items to arrange them in the correct order
A security administrator is evaluating the AAA implementation for a new enterprise remote access gateway. During connection establishment, the gateway verifies user credentials against an Active Directory domain controller, applies dynamic firewall rules to restrict network access based on role attributes, enforces bandwidth throttling policies according to user subscription tiers, and writes start/stop session timestamps to a central syslog server.
Which of the following operational activities performed by the gateway represent the Authorization pillar of AAA? (Select TWO.)
Select all that apply
A systems administrator is configuring bulk storage encryption for a enterprise cloud file server holding sensitive financial records. The organization requires a cryptographic mechanism that delivers high-speed symmetric data encryption while simultaneously calculating an authentication tag to ensure confidentiality and data integrity during high-throughput disk operations. Which of the following cryptographic algorithms and modes BEST fulfills these requirements?
A security engineer is establishing a secure mutual TLS (mTLS) framework between microservices operating within air-gapped container clusters. During deployment testing, client microservices fail TLS handshakes because they cannot reach external certificate revocation lists (CRLs) or online responders to check server certificate validity. Additionally, security compliance mandates that private keys must originate exclusively within the local trusted execution environment of each microservice during certificate enrollment. Which of the following solutions should the engineer implement to resolve the revocation validation failures and satisfy the key generation compliance requirement? (Select TWO.)
Select all that apply
An organization deploys a centralized Privileged Access Management (PAM) solution to govern administrator access to production databases. When a database administrator requests a session, the PAM system first verifies their identity using a hardware token and PIN. Next, the PAM system evaluates an access policy matrix to determine if the session occurs within an approved maintenance window and applies a restricted read-only role for that specific database instance. Finally, the proxy engine writes a cryptographic audit log of all executed SQL queries. Which pillar of the Security AAA framework is being implemented when the PAM system evaluates the policy matrix to grant the restricted read-only role?
Match each cryptographic primitive or mechanism to its primary operational security function in an enterprise environment.
Click a left item, then click its matching right item
Items
Matches
An enterprise security engineer is auditing identity lifecycle management and access control workflows across the organization. Match each operational access activity on the left with its corresponding identity management or AAA (Authentication, Authorization, and Accounting) component on the right.
Click a left item, then click its matching right item
Items
Matches
A security engineer is designing an authentication microservice for an enterprise web application. The security policy requires storing user credentials in a manner that mitigates offline brute-force and precomputed rainbow table attacks if the credential database is compromised. Which of the following cryptographic techniques should the engineer implement to satisfy this requirement?
A security analyst is investigating a breach where an adversary captured encrypted TLS traffic traversing an enterprise network. Months later, the adversary obtained the web server's private key and successfully decrypted all historical session data. Which of the following cryptographic mechanisms should be implemented to ensure that a future compromise of the server's private key does not expose previously recorded encrypted session communications?
A network security engineer is auditing the AAA implementation for an enterprise 802.1X wireless network backed by a central RADIUS server. Which of the following statements correctly describe how authentication, authorization, or accounting functions operate in this deployment? (Select TWO.)
Select all that apply
A security engineer is updating the cryptographic specifications for an enterprise file ingest service. The system baseline requires high-throughput data confidentiality for large batch data uploads, alongside digital non-repudiation and origin verification for administrative policy manifests submitted with each batch. Which TWO cryptographic algorithms or mechanisms should the security engineer implement to satisfy these specific operational requirements?
Select all that apply
A system administrator configures a central Linux bastion host that allows external contractors to connect via SSH using public key cryptography. Access control policies successfully restrict contractors from accessing unapproved file directories or running root-level processes. However, during a post-incident review, security auditors discover that while login timestamps and initial connection attempts were recorded, there are no log records detailing the specific commands executed or configuration files modified by contractors during their active sessions. Which pillar of the AAA framework is deficient in this configuration?
A security engineer is updating enterprise cryptographic standards across various operational systems. Match each cryptographic algorithm or mechanism on the left to its primary operational security capability on the right.
Click a left item, then click its matching right item
Items
Matches
An organization is updating its enterprise access control policy to comply with strict security standards. Match each operational security task to the corresponding AAA (Authentication, Authorization, and Accounting) or Identification function it represents.
Click a left item, then click its matching right item
Items
Matches
Following an assessment of remote access risks, a network administrator mandates that all system administrators must use hardware security keys to perform multi-factor authentication when logging into administrative portals. Which of the following combinations correctly identifies the control category and functional control type of the hardware security keys?
A lead security architect is designing an automated archival service for high-throughput system audit logs stored at rest. The security policy mandates strong bulk data confidentiality and authenticated integrity while minimizing computational latency for multi-gigabyte log archives. Which of the following cryptographic mechanisms best fulfills these requirements?
A security analyst is reviewing internal security mechanisms to ensure they are properly classified according to CompTIA Security+ control categories. Which of the following mechanisms are classified as technical security controls? (Select TWO.)
Select all that apply
A security administrator is evaluating enterprise cryptographic standards across various system modules. Match each cryptographic algorithm or mechanism on the left with its primary operational security application on the right.
Click a left item, then click its matching right item
Items
Matches
A software development firm is deploying an automated continuous integration pipeline to release signed application updates to enterprise clients. To meet regulatory compliance, the pipeline must ensure that the authenticity of the code publisher can be independently verified by third parties and that the publishing organization cannot repudiate the origin of the software package. Which of the following cryptographic mechanisms best fulfills these requirements?
Following an unauthorized intrusion into a server facility, an enterprise security team installs physical key-locked USB port blockers directly onto all exposed server ports to restrict direct hardware access. According to CompTIA Security+ standards, which control category and functional type best describe this security mechanism?