Tüm alıştırma soruları

521 soru

Soru 341Soru

A system administrator manages a mixed corporate network consisting of macOS workstations and Linux servers. Match each native operating system tool or terminal command to its correct administrative function.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

sw_vers
iwconfig
killall
du

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

The correct matches associate sw_vers with displaying macOS version info, iwconfig with Linux wireless interface configuration, killall with terminating processes by name, and du with directory disk space estimation.
Each tool matches its specific administrative function: sw_vers reports macOS system version metadata; iwconfig adjusts Linux wireless settings; killall halts programs by process name; and du reports directory storage consumption.

Adım Adım Çözüm

1
Identify the primary function of the macOS sw_vers utility.
Map sw_vers to displaying installed macOS version and build details.
sw_vers stands for software version and is native to macOS CLI environment.
2
Analyze Linux wireless networking commands.
Map iwconfig to configuring Linux wireless interfaces.
iwconfig specifically targets wireless interface parameters like SSID and encryption keys.
3
Evaluate process management commands in Linux and macOS.
Map killall to ending processes using process names.
Unlike kill which requires a PID number, killall targets matching process binary names.
4
Differentiate storage analysis utilities.
Map du to estimating file space consumption.
du (disk usage) summarizes file and folder size usage, whereas df (disk free) checks overall volume availability.

Anahtar Kavram

macOS and Linux Command-Line Utilities and Administrative Tools
Soru 342Soru

An IT security administrator is auditing the endpoint security baseline for mobile devices and embedded systems across the organization. Match each security operational control on the left with its corresponding security implementation objective on the right.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Storage Containerization
Remote Wipe
Geofencing
Firmware Hardening

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Storage Containerization matches isolating enterprise data on BYOD endpoints; Remote Wipe matches sending an over-the-air command to sanitize data on lost or stolen endpoints; Geofencing matches enforcing access policies based on physical GPS coordinates; Firmware Hardening matches disabling unneeded services and changing default credentials on IoT sensors.
Each security control targets a specific domain requirement: Storage Containerization segregates enterprise apps on personal endpoints; Remote Wipe remotely erases storage upon endpoint loss; Geofencing triggers location-based security policies; and Firmware Hardening reduces the attack surface on embedded IoT hardware.

Adım Adım Çözüm

1
Identify the purpose of Storage Containerization.
Selected the option describing logical isolation of business assets from personal data on BYOD endpoints.
Containerization creates a distinct partition on personal mobile devices so corporate data can be secured independently.
2
Identify the purpose of Remote Wipe.
Selected the option describing an over-the-air data sanitization command for lost or stolen hardware.
Remote wipe protects data confidentiality when physical control of an endpoint is compromised.
3
Identify the purpose of Geofencing.
Selected the option describing policy enforcement based on physical location/GPS boundaries.
Geofencing establishes virtual geographic perimeters to dynamically grant or restrict system functions.
4
Identify the purpose of Firmware Hardening.
Selected the option describing service minimization and credential updates on IoT hardware.
Hardening embedded systems mitigates risks associated with unpatched software and factory default settings.

Anahtar Kavram

Mobile and Embedded Security Controls
Soru 343Soru

A technician is inventorying motherboard connections while assembling a custom computer system. Match each motherboard internal connector or header to its correct functional description.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

24-pin ATX Main Connector
8-pin EPS12V Connector
USB 3.2 Gen 2 (Type-E) Header
Front Panel System Header

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

The 24-pin ATX Main Connector matches with delivering primary multi-rail DC power (+3.3V, +5V, +12V) to motherboard logic circuits. The 8-pin EPS12V Connector matches with supplying dedicated +12V power directly to the CPU VRM. The USB 3.2 Gen 2 (Type-E) Header matches with connecting chassis front-panel USB Type-C ports up to 10 Gbps. The Front Panel System Header matches with connecting chassis wiring for switches and LEDs.
Each motherboard internal connector has a specific role: the 24-pin ATX connector delivers main power to motherboard components; the 8-pin EPS12V connector delivers dedicated +12V power to the CPU; the USB 3.2 Gen 2 Type-E header drives chassis USB-C front ports; and the front panel system header links chassis switches and activity LEDs.

Adım Adım Çözüm

1
Distinguish between main motherboard power and CPU-specific power connectors.
The 24-pin ATX connector supplies overall motherboard logic and bus power (+3.3V, +5V, +12V), while the 8-pin EPS12V supplies dedicated +12V power for the CPU VRM.
Modern CPUs consume substantial power requiring dedicated +12V power leads separate from main motherboard traces.
2
Identify high-speed internal peripheral data headers versus chassis control pin blocks.
The USB 3.2 Gen 2 Type-E header provides front-panel USB-C port connectivity, whereas the front panel system header uses individual pin pairs for power/reset switches and status LEDs.
Front-panel headers separate high-speed data throughput interfaces from basic low-voltage mechanical switches and diagnostic indicator LEDs.

Anahtar Kavram

Motherboard Power Connectors and Header Pinouts
Soru 344Soru

A system administrator for a regional healthcare provider is reviewing cloud deployment features. Match each scenario on the left with the NIST cloud computing characteristic on the right that best describes it.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

A patient records system dynamically adjusts compute resources up or down automatically during high-volume clinic hours without administrative delay.
Multiple clinical departments access data hosted on shared physical hardware server racks where storage and memory are dynamically reassigned based on demand.
A medical research team provisions new testing virtual machines using a cloud administration panel without submitting an IT ticket or requiring human provider intervention.

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Rapid Elasticity matches automatic resource scaling according to real-time demand; Resource Pooling matches shared physical infrastructure dynamically allocated across tenants; On-Demand Self-Service matches user self-provisioning via portal without administrative interaction.
Rapid elasticity allows systems to expand and contract automatically based on workload. Resource pooling aggregates multi-tenant resources on shared hardware. On-demand self-service permits users to deploy resources independently through automated web dashboards.

Adım Adım Çözüm

1
Analyze the patient records system scenario that scales automatically up and down during workload surges.
Matched to Rapid Elasticity.
Rapid elasticity refers to the automated provisioning and deprovisioning of cloud capacity in real-time.
2
Analyze the clinical departments sharing physical hardware resources allocated dynamically.
Matched to Resource Pooling.
Resource pooling aggregates physical computing resources to serve multiple consumers in a multi-tenant model.
3
Analyze the medical research team independently provisioning server capacity through a portal.
Matched to On-Demand Self-Service.
On-demand self-service allows users to request and deploy cloud services automatically without interacting with cloud support staff.

Anahtar Kavram

Cloud Characteristics and Features (Elasticity, On-Demand, Resource Pooling)
Soru 345Soru

Match each wireless security implementation or authentication component on the left with its defining operational mechanism or technical requirement on the right.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

WPA3-Personal
EAP-TLS
RADIUS Server
Captive Portal

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

WPA3-Personal matches with Simultaneous Authentication of Equals (SAE); EAP-TLS matches with mutual certificate authentication; RADIUS Server matches with centralized AAA 802.1X validation; Captive Portal matches with guest web page redirection.
WPA3-Personal uses Simultaneous Authentication of Equals (SAE) for robust password-based authentication. EAP-TLS delivers strong mutual authentication using digital certificates on both the RADIUS server and client devices. A RADIUS server acts as a centralized AAA service verifying 802.1X user credentials against active directory or database services. A Captive Portal intercepts HTTP traffic to present terms or web login screens to guest users.

Adım Adım Çözüm

1
Identify the key security mechanism of WPA3-Personal.
Recognize that WPA3-Personal utilizes Simultaneous Authentication of Equals (SAE) to prevent offline brute-force attacks.
SAE replaces traditional PSK four-way handshakes with Dragonfly key exchange.
2
Determine the certificate requirements for EAP-TLS.
Identify that EAP-TLS enforces mutual authentication using PKI certificates on both endpoints.
Unlike PEAP or EAP-TTLS, EAP-TLS mandates client-side X.509 certificates in addition to server certificates.
3
Identify the infrastructure role of a RADIUS server.
Associate RADIUS with backend centralized AAA validation in an 802.1X wireless architecture.
Wireless access points act as authenticators and delegate user authentication to the RADIUS server.
4
Analyze the purpose of a Captive Portal.
Associate Captive Portals with HTTP/HTTPS session redirection for guest access management.
It forces unauthenticated web traffic to a portal landing page prior to authorizing outbound network access.

Anahtar Kavram

Wireless Authentication Protocols and Access Control Components
Soru 346Soru

A system administrator manages a mixed environment of macOS workstations and Linux servers. Match each native operating system tool or command on the left with its primary administrative purpose on the right.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

dd
chmod
Time Machine
Spotlight

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

dd matches block-level data copying; chmod matches altering file access permissions; Time Machine matches native macOS automated incremental backups; Spotlight matches native macOS indexing utility.
Each tool is accurately matched to its intended administrative function: dd is used for low-level block copying, chmod manages permission bits, Time Machine handles automated macOS backups, and Spotlight performs index searching across macOS.

Adım Adım Çözüm

1
Identify the function of the Linux/macOS CLI tool dd.
dd is a low-level utility used for raw block-level drive cloning and disk image creation.
It reads and writes raw data blocks directly across storage devices or files.
2
Identify the function of the command-line utility chmod.
chmod is used to modify mode/permission bits (read, write, execute) on files and directories.
Security administration relies on chmod for restricting or granting file access privileges.
3
Identify the function of the macOS GUI tool Time Machine.
Time Machine provides continuous, automated incremental backups for macOS.
It allows system recovery to specific historical snapshots.
4
Identify the function of the macOS tool Spotlight.
Spotlight creates a indexed database of files, metadata, and application shortcuts for fast searching.
It is the main search tool built into the macOS desktop.

Anahtar Kavram

Distinguishing core administrative CLI commands and native OS features in macOS and Linux environments.
Soru 347Soru

A systems administrator is configuring Mobile Device Management (MDM) security controls across an enterprise fleet of smartphones and tablets. Match each mobile device security control on the left with its corresponding operational description on the right.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Containerization
Geofencing
Selective Wipe
Full Device Encryption (FDE)

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Containerization pairs with isolating enterprise applications and sensitive data from personal data. Geofencing pairs with triggering security restrictions based on the physical location of the endpoint. Selective Wipe pairs with erasing corporate profile data without impacting personal files. Full Device Encryption pairs with protecting stored data at rest across system storage.
The paired definitions accurately describe the key technical operational capabilities of MDM security mechanisms: Containerization isolates corporate environments on personal devices; Geofencing enforces policy dynamically based on location coordinates; Selective Wipe target-deletes corporate data only; and Full Device Encryption protects all underlying data at rest.

Adım Adım Çözüm

1
Analyze Containerization requirements.
Identified as logical isolation between work and personal data structures on a single endpoint.
Containerization enforces BYOD privacy and compliance by creating a dedicated encrypted sandbox.
2
Analyze Geofencing features.
Identified as location-based policy enforcement.
Geofencing leverages spatial coordinates (GPS/Wi-Fi) to restrict capabilities dynamically based on physical presence.
3
Analyze Selective Wipe vs Full Wipe.
Identified as enterprise-only data removal.
Selective wipe targets managed profiles specifically, preserving non-corporate user assets.
4
Analyze Full Device Encryption (FDE).
Identified as full volume data-at-rest protection.
FDE encrypts the whole storage partition, preventing unauthorized offline data access.

Anahtar Kavram

Mobile Device Management (MDM) Controls and Security Measures
Soru 348Soru

A systems administrator is configuring Windows local group security baseline controls across newly deployed workstations. Match each workstation hardening policy control on the left to its corresponding primary risk mitigation on the right.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Account Lockout Threshold Policy
Disabling Unused Network Ports and Services
Screen Lock Timeout with Re-authentication
Disabling AutoPlay and AutoRun features

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Account Lockout Threshold Policy matches automated brute-force mitigation; Disabling Unused Network Ports and Services matches attack surface reduction of network channels; Screen Lock Timeout matches prevention of unattended physical access; Disabling AutoPlay/AutoRun matches prevention of automatic executable launching from removable storage.
Each workstation hardening policy directly addresses a distinct attack vector: account lockout limits online password cracking, service/port disabling removes latent attack surface, screen locking secures unattended physical hardware, and disabling AutoPlay blocks weaponized removable media.

Adım Adım Çözüm

1
Analyze each security hardening baseline control
Identified four standard CompTIA A+ Security domain workstation hardening techniques.
Security baseline hardening controls target specific threat vectors across physical, network, system, and media domains.
2
Correlate each control to its primary risk reduction mechanism
Account lockout protects credentials, service disabling protects listening endpoints, screen timeout protects physical sessions, and AutoPlay disabling protects against malicious media execution.
Proper matching requires understanding defense-in-depth principles for local OS configuration.

Anahtar Kavram

Workstation Hardening & Risk Mitigation Alignment
Soru 349Soru

An IT security administrator is updating the enterprise Mobile Device Management (MDM) baseline for corporate endpoints and field devices. Match each mobile security control on the left with its primary security objective on the right.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Containerization
Geofencing
Sideloading restriction
Remote wipe

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Containerization matches isolating corporate data into encrypted logical storage spaces. Geofencing matches enforcing context-aware security profiles based on physical location. Sideloading restriction matches preventing installation of unverified software binaries. Remote wipe matches sanitizing storage and returning endpoints to factory defaults.
Each security control targets a distinct endpoint protection layer: containerization isolates corporate data partitions on mobile devices; geofencing adjusts device behavior using physical boundaries; sideloading restrictions mitigate untrusted application installations; and remote wipe protects data on missing hardware by wiping local storage.

Adım Adım Çözüm

1
Identify the purpose of Containerization
Matches isolating corporate data into an encrypted logical storage space
Containerization creates a secure virtual compartment on mobile endpoints to prevent data leakage between personal and business applications.
2
Identify the purpose of Geofencing
Matches enforcing context-aware security profiles based on physical location
Geofencing establishes virtual geographic boundaries to trigger security controls, such as disabling camera features inside secure facilities.
3
Identify the purpose of Sideloading restriction
Matches preventing the installation of unverified software binaries
Disabling application sideloading mitigates malware exposure by restricting installation sources exclusively to enterprise-managed repositories or official stores.
4
Identify the purpose of Remote wipe
Matches sanitizing storage and returning an endpoint to factory defaults
Remote wipe commands ensure that compromised or stolen devices are completely cleared of sensitive organizational assets.

Anahtar Kavram

Mobile Device Security Controls and Management Features
Soru 350Soru

A cybersecurity technician is establishing baseline operational policies for workstation security across an enterprise network. Match each workstation hardening control on the left with the primary security risk it directly mitigates on the right.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Disabling unneeded operating system services
Configuring account lockout threshold rules
Enforcing password-protected screen saver timeouts
Disabling AutoRun and AutoPlay policies

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Matching pairs: Disabling unneeded OS services matches reducing attack surface by closing network listening ports; Account lockout thresholds match mitigating online brute-force password attacks; Password-protected screen saver timeouts match preventing unauthorized physical access to unattended terminals; Disabling AutoRun and AutoPlay policies matches blocking automatic script execution from plugged-in storage drives.
Each security control targets a specific vulnerability vector: disabling unnecessary services minimizes open ports and attack surface; account lockout policies defend against automated brute-force login attempts; enforcing screen saver password locks guards against local unauthorized access to unattended desktops; and turning off AutoRun/AutoPlay stops rogue USB drives from auto-launching malicious software.

Adım Adım Çözüm

1
Analyze service disabling hardening principles
Disabling unnecessary services stops background listeners and unused system daemons.
Eliminating running processes directly shrinks the workstation's attack surface and closes listening ports.
2
Evaluate account security policies
Account lockout thresholds limit consecutive incorrect password attempts.
Locking out accounts after repeated failures thwarts automated password-guessing and brute-force tools.
3
Assess physical display access controls
Screen saver timeout locking requires credentials to resume session access.
Secures active sessions from walk-up physical access when users leave their desk.
4
Examine removable storage media policies
Disabling AutoRun/AutoPlay blocks automatic launcher script execution upon media connection.
Stops malicious payloads stored on USB flash drives from executing automatically without user interaction.

Anahtar Kavram

Workstation Hardening Controls and Risk Mitigation Mapping
Soru 351Soru

A systems administrator is configuring endpoint security profiles for enterprise mobile devices and specialized embedded hardware. Which mobile and embedded security control correctly matches each operational requirement?

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Containerization
Geofencing
Selective Wipe
Network Segmentation

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Containerization matches isolating corporate apps into an encrypted sandbox on personal endpoints. Geofencing matches restricting features based on GPS or location data. Selective wipe matches removing corporate files while preserving personal user data. Network segmentation matches placing legacy IoT sensors onto an isolated VLAN.
Containerization logically segregates enterprise software from personal data; Geofencing triggers location-based security policies via GPS or radio signals; Selective wipe targets company data for deletion without affecting user content; and Network segmentation isolates vulnerable embedded systems on segregated network zones.

Adım Adım Çözüm

1
Identify the mechanism that segregates work content on personal devices.
Containerization creates a distinct secure workspace on BYOD endpoints.
Containerization ensures corporate data is segregated and encrypted separately from personal user content.
2
Identify the technology enforcing location-aware security restrictions.
Geofencing dynamically adjusts security options based on device coordinates.
Geofencing relies on location metrics (GPS/cellular) to apply site-specific rules.
3
Identify the command used to clean business records from departing employee endpoints.
Selective wipe removes managed enterprise assets while leaving personal assets unaffected.
MDM selective wipe actions target corporate containers without affecting user storage.
4
Identify the security approach suited for embedded or IoT hardware.
Network segmentation restricts embedded device network exposure.
Because IoT devices often lack endpoint antimalware agents, isolating them on separate VLANs prevents lateral threat movement.

Anahtar Kavram

Mobile Device and Embedded System Security Controls
Soru 352Soru

A network administrator is configuring virtual networking settings for multiple virtual machines (VMs) deployed on a hypervisor host. Match each virtual network interface card (vNIC) mode on the left with its corresponding network access requirement on the right.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Bridged Mode
Network Address Translation (NAT) Mode
Host-Only Mode
Internal / Private Mode

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Bridged Mode pairs with direct physical subnet access and unique IP assignment; NAT Mode pairs with outbound external access using host IP address translation; Host-Only Mode pairs with restricted communication between guest VMs and host OS only; Internal / Private Mode pairs with complete network isolation restricted strictly to inter-VM communication.
Each virtual networking mode defines specific communication boundaries between the guest VM, the hypervisor host OS, and external physical networks. Bridged mode treats the VM as an independent entity on the physical subnet. NAT mode uses host address translation for outbound requests. Host-Only mode limits traffic to the host and local VMs. Internal mode restricts traffic exclusively to local VMs on the host.

Adım Adım Çözüm

1
Analyze physical local area network integration requirements.
Identify that Bridged Mode connects the VM's vNIC directly to the physical adapter, giving it a separate IP address on the physical LAN.
Bridged networking allows the VM to participate as a full peer node on the physical network.
2
Analyze outbound routing and host protection requirements.
Identify that NAT Mode routes traffic using the host IP address.
NAT mode provides internet connectivity to guest VMs while preventing unsolicited inbound traffic from reaching the VM directly.
3
Evaluate host-to-guest isolated communication requirements.
Identify that Host-Only Mode connects the VM to a virtual switch accessible only by the host OS and other VMs on that switch.
Host-Only mode blocks external physical network connectivity while maintaining access for administrative management from the host.
4
Evaluate sandbox or strictly inter-VM isolation requirements.
Identify that Internal / Private Mode completely isolates traffic to connected VMs only.
Internal networking prevents any traffic from reaching the host OS or external network, creating a secure environment for testing or multi-tier VM communication.

Anahtar Kavram

Virtual Network Adapter Operating Modes and Isolation Boundaries
Soru 353Soru

An IT security analyst is establishing security baseline controls for enterprise mobile devices and embedded systems. Match each mobile or embedded security technology to its primary operational capability.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Geofencing
Containerization
Remote Wipe
Secure Boot

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Geofencing matches with location-based policy enforcement; Containerization matches with isolating corporate apps on BYOD devices; Remote Wipe matches with issuing an over-the-air command to sanitize data; Secure Boot matches with cryptographically authenticating firmware signatures prior to OS initialization.
Each listed term directly aligns with its fundamental security function: Geofencing manages location-based parameters, Containerization isolates corporate data on BYOD devices, Remote Wipe provides loss mitigation via over-the-air erasure, and Secure Boot guarantees low-level firmware integrity.

Adım Adım Çözüm

1
Identify the technology used to enforce location-aware security policies on mobile endpoints.
Pair Geofencing with restricting device features based on physical location.
Geofencing relies on geographic coordinates to trigger or block specific features.
2
Identify the storage and application isolation mechanism used for BYOD environments.
Pair Containerization with isolating corporate applications and data in an encrypted workspace.
Containerization ensures corporate assets remain segregated from personal data.
3
Determine the administrative capability used when a mobile device is reported lost or stolen.
Pair Remote Wipe with issuing an over-the-air command to sanitize endpoint storage.
Remote wipe clears sensitive data over the network to prevent data exposure.
4
Identify the embedded hardware verification feature that prevents malicious firmware execution.
Pair Secure Boot with cryptographically authenticating firmware and bootloader signatures.
Secure Boot establishes a hardware root of trust to verify software integrity before booting.

Anahtar Kavram

Mobile Device and Embedded System Security Controls
Soru 354Soru

An IT technician is establishing standard security hardening configurations across enterprise desktops. Match each workstation security control on the left with the primary risk mitigation it provides on the right.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Disabling unnecessary background services and open network ports
Configuring an aggressive screen lock timeout policy
Disabling the built-in Guest user account
Disabling Autorun and Autoplay features

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Disabling unnecessary services and ports matches reducing the system attack surface. Configuring a screen lock timeout matches mitigating unauthorized access to unattended desktop sessions. Disabling the Guest account matches preventing unauthenticated logons using default local credentials. Disabling Autorun/Autoplay matches preventing automatic execution of malicious payloads upon inserting external storage media.
Each hardening control directly addresses a specific vulnerability vector: disabling unnecessary services minimizes overall network entry points; screen lock timeouts protect against physical access to unattended active sessions; turning off the Guest account eliminates default unauthenticated logon access; and disabling Autorun prevents drive-by execution of malware from attached removable media.

Adım Adım Çözüm

1
Analyze service and port management controls
Turning off unneeded system services closes corresponding network ports and listening sockets.
Closing unused open entry points directly decreases the exposed attack surface of the OS.
2
Analyze desktop inactivity policies
Setting screen lock timeouts requires password re-entry after specified minutes of idle time.
Protects active user contexts when a physical workspace is left unattended.
3
Analyze account security controls
Disabling built-in default accounts neutralizes known account targets that do not require complex setup.
Prevents unauthenticated users from leveraging default Guest privileges for network or local access.
4
Analyze media execution policies
Turning off Autorun and Autoplay prevents OS auto-execution triggers.
Blocks flash drives or optical media from running startup scripts automatically upon insertion.

Anahtar Kavram

Workstation Hardening and Best Practices
Soru 355Soru

A systems administrator is configuring virtual network settings for several virtual machines deployed on a local hypervisor. Match each operational deployment requirement to its corresponding virtual network adapter mode.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

A virtual machine requires its own unique IP address from the physical network's DHCP server and must act as an independent host on the physical local subnet.
A isolated virtual machine needs outbound internet access to fetch system updates while remaining hidden from direct incoming access from external physical network hosts.
A testing virtual machine must communicate directly and exclusively with the hypervisor host OS for administrative management, with no traffic routed to external physical networks.
Multiple sandbox virtual machines must communicate only with each other across a private virtual switch, completely isolated from both the hypervisor host and external networks.

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Bridged Mode maps to requiring an independent IP address on the physical network. NAT Mode maps to requiring outbound access while concealing the guest from incoming external traffic. Host-Only Mode maps to restricting communication strictly to the guest and the hypervisor host. Internal/Private Mode maps to restricting network communication strictly between designated guest VMs, isolating them from the host and external network.
Each virtual network mode defines explicit boundaries for network exposure. Bridged mode integrates the VM into the physical local network. NAT mode provides outbound access via host IP translation. Host-Only restricts traffic to the guest and host OS. Internal/Private mode isolates network traffic exclusively to guest VMs on the hypervisor.

Adım Adım Çözüm

1
Analyze requirement 1 (independent physical subnet presence)
Bridged mode connects the virtual interface card directly to the physical network card, binding it to the physical subnet infrastructure.
Bridging allows a VM to request its own network IP address from the external physical DHCP server.
2
Analyze requirement 2 (outbound access with inbound network translation)
NAT mode translates internal VM network traffic through the host's IP address.
NAT provides single-direction outbound internet accessibility without exposing open ports to the physical LAN.
3
Analyze requirement 3 (communication limited strictly to host-to-guest link)
Host-Only mode configures a virtual network adapter accessible only by the physical host OS.
Host-Only mode isolates guest network interfaces from physical network adapters while leaving a local loop interface to the host.
4
Analyze requirement 4 (inter-VM communication isolated completely from host and physical network)
Internal / Private mode isolates network switches purely within hypervisor VM boundaries.
Private virtual networking prevents packets from reaching even the management hypervisor OS host interface.

Anahtar Kavram

Virtual Network Adapter Modes and Isolation Boundaries
Tahmini Süre:2m 0s
Soru 356Soru

An IT technician is configuring network adapters and security isolation rules for several virtual machines running on a desktop hypervisor. Match each virtual network configuration mode to the operational scenario or connectivity requirement that best describes its traffic profile.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Bridged Networking
Network Address Translation (NAT)
Host-Only Networking
Internal / Private Virtual Switch

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Bridged Networking corresponds to receiving a unique IP on the physical subnet; NAT corresponds to sharing the host IP for outbound traffic while blocking external inbound traffic; Host-Only corresponds to communicating exclusively with the host OS and peer VMs; Internal/Private Switch corresponds to isolating traffic strictly to peer VMs while excluding the host OS.
Each virtual network adapter mode enforces specific boundary conditions. Bridged mode places the guest directly onto the physical network subnet. NAT mode translates outbound requests through the host IP to provide internet access without exposing inbound interfaces. Host-Only mode restricts connectivity to a closed network between the host OS and guest VMs. Internal/Private mode completely isolates the guest VMs from both external networks and the host OS network stack.

Adım Adım Çözüm

1
Evaluate Bridged Networking characteristics
Bridged mode binds the vNIC directly to the host's physical network adapter.
This allows the guest VM to obtain its own IP address on the physical network and interact directly with physical devices.
2
Evaluate Network Address Translation (NAT) characteristics
NAT translates guest VM private IP requests through the host's IP address.
It grants outbound internet connectivity while shielding the guest VM from inbound network scans or unsolicited external traffic.
3
Evaluate Host-Only Networking characteristics
Host-Only creates a dedicated virtual interface connecting the host OS to guest VMs.
It prevents external network access while allowing management connections directly between the host system and guest VMs.
4
Evaluate Internal / Private Virtual Switch characteristics
Internal switches disconnect the virtual network segment from the host OS adapter.
This creates maximum isolation where VMs can interact only with each other, keeping the host OS and external network completely isolated.

Anahtar Kavram

Virtual Adapter Modes and Network Isolation Levels
Soru 357Soru

Match each workstation security hardening control on the left with its corresponding primary risk mitigation objective on the right.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Account Lockout Threshold
Disabling the Built-in Guest Account
Closing Unused Listening Ports
Screen Saver Lock Timeout

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Account Lockout Threshold matches with mitigating brute-force credential attacks; Disabling the Built-in Guest Account matches with eliminating unauthenticated anonymous local system logon; Closing Unused Listening Ports matches with reducing the network attack surface by blocking unapproved remote connections; Screen Saver Lock Timeout matches with preventing unauthorized physical console access when workstations are unattended.
Each hardening control directly addresses a distinct attack vector: account lockout thresholds mitigate credential brute-forcing, disabling default guest accounts prevents unauthenticated anonymous access, closing unused ports shrinks the network attack surface, and enforcing a screen lock timeout prevents local physical tampering when the system is unattended.

Adım Adım Çözüm

1
Analyze the role of the Account Lockout Threshold policy.
Identifies that locking an account after multiple invalid attempts prevents credential brute-forcing.
Restricts automated password guessing attempts.
2
Evaluate the risk of leaving default accounts enabled.
Determines that disabling the Guest account removes an inherent anonymous logon vector.
Enforces proper identification and user authentication baseline.
3
Assess the defensive benefit of closing unused network listening ports.
Recognizes that shutting down unneeded network services reduces entry points for remote exploits.
Shrinks the local device attack surface.
4
Examine the protection provided by setting a Screen Saver Lock Timeout.
Confirms that requiring re-authentication after inactivity secures unattended hardware.
Mitigates physical security exposure in open office or shared environments.

Anahtar Kavram

Workstation Security Hardening Control Objectives
Soru 358Soru

An IT security analyst is defining baseline workstation security standards to protect enterprise desktops against common attack vectors. Match each workstation security hardening control on the left with its corresponding risk mitigation objective on the right.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Disabling NetBIOS over TCP/IP
Implementing Local Administrator Password Solution (LAPS)
Enforcing Application Allowlisting (AppLocker)
Configuring Screensaver Lock Timeout

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Disabling NetBIOS over TCP/IP matches with blocking LLMNR/NBT-NS spoofing; Implementing LAPS matches with mitigating lateral movement from reused local admin credentials; Enforcing Application Allowlisting matches with preventing execution of untrusted binaries; Configuring Screensaver Lock Timeout matches with preventing unauthorized session access to unattended devices.
Each security control targets a specific workstation vulnerability: disabling NetBIOS prevents broadcast name resolution spoofing; LAPS prevents credential reuse and lateral movement; AppLocker restricts binary execution to trusted software; screensaver timeout protects open physical sessions on idle machines.

Adım Adım Çözüm

1
Analyze the purpose of network protocol hardening controls
Disabling NetBIOS over TCP/IP eliminates unauthenticated broadcast name resolution traffic, neutralizing NBT-NS/LLMNR spoofing vectors.
Legacy protocols broadcast requests across the local subnet, which malicious actors on the segment can easily intercept.
2
Analyze local account privilege management solutions
LAPS ensures unique, randomized passwords for local administrator accounts on every endpoint.
If local administrator passwords are standard across machines, compromising one system leads to lateral movement across the entire network.
3
Analyze software execution restriction policies
AppLocker enforce allowlisting rules to block unauthorized executables, installers, and scripts.
Allowlisting operates on a default-deny principle, blocking malware or unauthorized software even if the user attempts to launch it.
4
Analyze physical and environmental workstation controls
Screensaver lock policies require user re-authentication after a set interval of system inactivity.
This control mitigates physical security risks when users leave their desks unattended without manually locking their operating system.

Anahtar Kavram

Workstation Hardening and Risk Mitigation
Soru 359Soru

Match each network server role on the left with its primary service function on the right.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

DHCP Server
DNS Server
Syslog Server
Web Server

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

The DHCP Server dynamically provides IP parameters to host devices; the DNS Server maps human-readable domain names to numerical IP addresses; the Syslog Server aggregates event log data from remote devices; and the Web Server serves web site pages via HTTP/HTTPS protocols.
Each server role performs a distinct service: DHCP automates IP configuration, DNS converts hostnames to IP addresses, Syslog aggregates remote device logs, and Web servers store and serve web content.

Adım Adım Çözüm

1
Analyze the core responsibilities of a DHCP server.
DHCP is responsible for dynamic automated assignment of network settings (IP address, default gateway, subnet mask).
Hosts require valid network configurations to communicate without manual administrator assignment.
2
Analyze the core responsibilities of a DNS server.
DNS converts human-friendly hostnames to IP addresses.
Network protocols require numerical IP addresses to route packets, while human users rely on readable names.
3
Analyze the core responsibilities of a Syslog server.
Syslog collects and stores event messages sent across the network by system daemons and hardware devices.
Consolidating log messages into a central repository simplifies monitoring, auditing, and troubleshooting.
4
Analyze the core responsibilities of a Web server.
A web server processes client web requests over HTTP or HTTPS and returns requested web documents.
Web browsing relies on dedicated servers configured to listen on web ports and deliver hypermedia files.

Anahtar Kavram

Network Host Services and Server Roles
Soru 360Soru

Match each mobile application security term on the left with its corresponding operational description on the right.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Sideloading
Containerization
Remote Wipe
Multifactor Authentication (MFA)

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Sideloading matches installing apps from third-party sources; Containerization matches isolating corporate data from personal data; Remote Wipe matches sanitizing lost device storage over a network command; Multifactor Authentication matches requiring two or more distinct verification credentials.
Each mobile application security term matches its designated definition: Sideloading involves installing software outside official app stores, Containerization isolates corporate workspaces from personal data, Remote Wipe erases device storage remotely, and MFA enforces multiple independent authentication methods.

Adım Adım Çözüm

1
Identify the process of installing application files outside approved vendor stores.
Matches Sideloading with unapproved third-party source installation.
Sideloading allows application installation without official vendor app store verification.
2
Identify the technology used to separate corporate and personal environments on a single mobile device.
Matches Containerization with encrypted corporate data isolation.
Containerization partitions corporate apps and data into an isolated workspace.
3
Identify the remote management command used to erase data on lost hardware.
Matches Remote Wipe with network-driven device data sanitization.
Remote wiping allows administrators to clear confidential information over the network when a physical device is lost.
4
Identify the security policy requiring multiple proof points for user access.
Matches Multifactor Authentication with requiring two or more distinct verification factors.
MFA combines distinct authentication categories like knowledge and inherence to secure application access.

Anahtar Kavram

Mobile Application Support and Security Settings
ÖncekiSayfa 18 / 27Sonraki
Tüm alıştırma soruları — CompTIA A+ (Core 1 & Core 2) | Examkin