Tüm alıştırma soruları

3551 soru

Soru 1341Soru

An IT technician is investigating a security incident on a graphic designer's workstation. The designer reports that while visiting a popular, reputable industry news forum they browse daily, a malicious script executed in the background and attempted to steal their corporate login credentials. Forensic analysis confirms that attackers compromised the third-party website specifically to target users in the graphic design sector. Which of the following social engineering attacks occurred in this scenario?

Cevabı ve açıklamayı göster

Cevap: Watering hole attack

Cevap

Watering hole attack
A watering hole attack specifically targets a group of users by identifying and infecting a legitimate, trusted website that the group frequently visits. The attacker waits for the targets to visit the compromised site to execute malicious code or harvest credentials.

Adım Adım Çözüm

1
Analyze the attack vector described in the scenario.
The attacker compromised a legitimate, frequently visited industry website rather than directly contacting the user.
Identifying the medium of attack helps distinguish web-based social engineering from direct communications.
2
Evaluate the intent and target group.
The attack specifically aimed at users within a particular industry sector who regularly visit that resource.
Targeting a specific demographic through a common resource site is the defining characteristic of a watering hole attack.
3
Map the observed behavior to standard CompTIA threat classifications.
Compromising a gathering site frequented by target victims matches the definition of a watering hole attack.
This confirms the correct social engineering classification.

Anahtar Kavram

Watering Hole Attack
Soru 1342Soru

A network administrator receives multiple helpdesk tickets regarding an enterprise laser printer in the finance department. Users report that when sending print jobs to Tray 2, the printer makes a continuous spinning noise, but paper fails to enter the paper path, resulting in a persistent paper jam error message on the control panel. Upon inspecting the paper tray, the administrator confirms that paper is loaded correctly and meets manufacturer weight specifications, but the top sheet shows rubber traction marks without being pulled forward. Which of the following components is most likely causing this issue?

Cevabı ve açıklamayı göster

Cevap: Worn or dirty pickup rollers

Cevap

Worn or dirty pickup rollers are the primary cause of paper failing to feed from the paper tray into the printer engine.
Worn or dirty pickup rollers lose their rubber grip over time due to friction and paper dust accumulation. When the roller turns against the paper stack without adequate friction, it slips and leaves smudged rubber traction marks while failing to feed the paper into the paper path.

Adım Adım Çözüm

1
Analyze the observed symptom
The printer motor spins and leaves rubber traction marks on the paper, but the sheet does not move into the paper path.
This indicates a failure in friction grip at the paper tray entry point rather than a mechanical blockage inside the transfer or fusing assembly.
2
Evaluate the paper feed mechanism components
Identify the pickup rollers as the primary interface responsible for pulling the top page from the tray.
Accumulated paper dust and rubber degradation over time cause the rollers to lose their grip surface, leading to slipping and paper feed failure.
3
Determine the appropriate corrective action
Clean the pickup rollers with isopropyl alcohol or replace them using a printer maintenance kit.
Restoring surface friction enables proper paper intake and resolves the paper feed jam error.

Anahtar Kavram

Laser Printer Feed Mechanism and Pickup Roller Degradation
Soru 1343Soru

A technician needs to perform a thorough file system repair and bad sector scan on a workstation's primary system volume (C:C:). Because the volume is actively used by the Windows operating system, the repair operation must be scheduled for the next boot cycle. Place the administrative command-line actions in the correct sequential order to schedule and execute this operation.

Öğeleri doğru sıraya koymak için sürükleyin

Cevabı ve açıklamayı göster

Cevap

The correct sequence begins by launching an elevated Command Prompt, issuing the `chkdsk C: /f /r` command, confirming the prompt to schedule the scan on the next reboot by typing 'Y', and restarting the workstation immediately using `shutdown /r /t 0`.
The procedure requires elevated administrative context first because disk repair affects core storage structures. Executing `chkdsk C: /f /r` requests a full repair, but because Windows is actively running from drive C:C:, the utility cannot dismount the volume. Accepting the prompt ('Y') schedules the scan for startup, and calling `shutdown /r /t 0` restarts the system immediately to launch the check.

Adım Adım Çözüm

1
Launch elevated Command Prompt
Command Prompt opens with Administrator privileges in `C:\Windows\System32`.
Disk checking utilities require full administrative permissions to access raw storage structures.
2
Issue CHKDSK command with repair switches
The utility detects that drive C:C: is currently in use and cannot be locked.
The `/f` switch fixes errors on the disk, while `/r` locates bad sectors and recovers readable information (implicitly including `/f`).
3
Confirm boot-time scheduling
Windows queues the Autochk utility to execute during the early boot phase.
Since the active OS drive cannot be dismounted online, the check must run before system files are locked by Windows startup.
4
Restart the system immediately
The computer reboots without delay and commences the disk check.
The `shutdown` command with `/r` (reboot) and `/t 0` (zero-second delay) forces an immediate restart to execute the scheduled task.

Anahtar Kavram

Scheduling boot-time CHKDSK scans on locked system volumes
Tahmini Süre:1m 30s
Soru 1344Soru

A technician is troubleshooting a small-form-factor (SFF) desktop workstation that fails to display video upon powering on. The power LED lights up solid amber, internal cooling fans spin at high speed, and the system motherboard emits a repeating pattern of three short beeps. Which of the following troubleshooting actions should the technician perform first? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Verify that all installed memory modules are properly seated and secured by their slot retention clips.; Remove all memory modules and test each stick individually in a single slot to isolate potential hardware defects.

Cevap

The technician should verify that the memory modules are fully seated and test the RAM modules individually in a single slot to isolate any defective hardware.
Beep codes occurring immediately after powering on indicate a hardware diagnostic failure detected by the system BIOS/UEFI prior to display initialization. Three short beeps generally point to a memory initialization or detection issue. Re-seating memory modules ensures proper contact with the bus, and testing RAM modules individually isolates whether a specific stick or slot is defective.

Adım Adım Çözüm

1
Analyze system POST symptoms and beep codes
Identify that three short beeps prior to video initialization indicate a memory subsystem detection or validation failure during POST.
Motherboard beep codes provide pre-boot diagnostic signals indicating specific core hardware failures.
2
Check physical memory seating
Reseat the memory modules firmly until side retention tabs click into position.
Thermal expansion or physical movement can cause RAM modules to unseat slightly, disrupting contact pins.
3
Perform component isolation testing
Test each memory module one at a time in slot 1.
Isolating modules determines whether the system failure is caused by one bad RAM stick or a failed motherboard slot channel.

Anahtar Kavram

RAM POST Beep Code Isolation and Hardware Diagnostics
Soru 1345Soru

An IT support specialist is installing a secondary access point to expand coverage in an office suite. The primary access point is configured to broadcast on 2.4 GHz channel 1. Which channel should the specialist select for the secondary access point to ensure zero channel overlap?

Cevabı ve açıklamayı göster

Cevap: Channel 6

Cevap

Channel 6 should be selected because it is a standard non-overlapping 2.4 GHz channel relative to channel 1.
In 2.4 GHz Wi-Fi networks, channels 1, 6, and 11 are the primary non-overlapping channels. Selecting Channel 6 ensures complete frequency separation from Channel 1, eliminating adjacent-channel interference.

Adım Adım Çözüm

1
Identify the frequency band used by the existing access point.
The network operates in the 2.4 GHz wireless frequency spectrum on channel 1.
Channel assignment rules differ between 2.4 GHz and 5 GHz bands.
2
Recall the standard non-overlapping channels for 2.4 GHz Wi-Fi deployments.
The standard non-overlapping channels in North America are 1, 6, and 11.
Each 2.4 GHz channel is 22 MHz wide, spaced 5 MHz apart, meaning channels closer than 5 increments overlap.
3
Select an available non-overlapping channel relative to channel 1.
Channel 6 (or channel 11) provides 25 MHz of separation from channel 1.
Using channel 6 prevents both co-channel and adjacent-channel interference.

Anahtar Kavram

2.4 GHz Wi-Fi non-overlapping channels (1, 6, and 11)
Soru 1346Soru

An IT technician is preparing to decommission an enterprise storage system containing magnetic backup tapes, traditional magnetic Hard Disk Drives (HDDs), and Solid-State Drives (SSDs). The organization plans to refurbish and resell the SSDs, while the magnetic tapes and HDDs will be rendered completely unreadable before physical disposal. Which TWO of the following statements represent proper data destruction or sanitization practices for these media types?

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Degaussing is effective for rendering data unrecoverable on magnetic tapes and HDDs, but it is ineffective for sanitizing SSDs.; Performing an ATA Secure Erase or cryptographic erase is an appropriate sanitization method for SSDs intended for resale.

Cevap

The correct practices are using degaussing for magnetic media (tapes and HDDs) while recognizing its ineffectiveness on SSDs, and executing an ATA Secure Erase or cryptographic erase on SSDs intended for resale.
Degaussing is effective exclusively for magnetic media such as magnetic tapes and traditional hard drives because it disrupts magnetic alignment. Solid-state drives use non-magnetic NAND flash storage, making degaussing ineffective. For SSDs planned for resale, methods such as ATA Secure Erase or cryptographic erase sanitize all NAND cells while maintaining drive usability.

Adım Adım Çözüm

1
Identify the media types and disposition goals in the scenario.
The media includes magnetic tapes and HDDs targeted for destruction, and SSDs designated for refurbishment/resale.
Different storage technologies require specific sanitization and disposal techniques based on whether hardware will be reused or destroyed.
2
Select sanitization methods for hardware intended for resale.
SSDs intended for resale require logical sanitization methods like ATA Secure Erase or cryptographic erase that purge all memory cells without damaging hardware functionality.
Physical destruction or degaussing would render the drive unusable or fail to sanitize flash memory.
3
Evaluate destruction methods for magnetic media.
Magnetic tapes and HDDs can be degaussed using strong magnetic fields, whereas degaussing has no impact on non-magnetic SSD semiconductor chips.
Degaussing disrupts magnetic domains on platters and tapes, whereas SSDs store electrical charges in floating-gate transistors.

Anahtar Kavram

Selecting appropriate data sanitization and destruction techniques based on storage media architecture (magnetic vs. flash) and hardware disposition goals.
Soru 1347Soru

An IT administrator is configuring Local Security Policy (secpol.msc) on corporate Windows 11 Pro workstations. Company compliance mandates that when an administrative user operating under Admin Approval Mode attempts to run a task requiring elevation, the system must require full credential re-authentication on an isolated screen rather than relying on a consent prompt. Which Local Security Policy configuration fulfills this security requirement?

Cevabı ve açıklamayı göster

Cevap: Set "User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode" to "Prompt for credentials on the secure desktop"

Cevap

Set "User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode" to "Prompt for credentials on the secure desktop"
The setting 'User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode' determines how administrative users are prompted during privilege elevation. Configuring it to 'Prompt for credentials on the secure desktop' requires the administrator to re-type their account password on an isolated secure desktop screen.

Adım Adım Çözüm

1
Identify the targeted user account type and prompt restriction
The requirement applies to administrators in Admin Approval Mode and requires password re-entry on a secure desktop screen.
Windows UAC distinguishes between administrator elevation policies and standard user elevation policies.
2
Navigate to the appropriate administrative tool and branch
Open Local Security Policy (secpol.msc) and go to Security Settings > Local Policies > Security Options.
Security Options under Local Policies contains all specific UAC policy definitions.
3
Configure the policy to require credential entry on the secure desktop
Setting 'User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode' to 'Prompt for credentials on the secure desktop' forces password re-authentication on an isolated desktop environment.
This mitigates risks of unauthorized click-through elevation or background script exploitation.

Anahtar Kavram

Windows UAC Admin Approval Mode Local Security Policy Configuration
Tahmini Süre:1m 30s
Soru 1348Soru

A desktop support technician needs to deploy Windows 11 Pro across 15 standalone PCs in a small branch office that lacks Windows Deployment Services (WDS) or network boot infrastructure. To streamline setup, the technician wants the Windows setup wizard to automatically create disk partitions, configure regional settings, and create the default local user account without requiring manual input during installation. Which file should be created and placed in the root directory of the bootable USB installation media to perform this unattended installation?

Cevabı ve açıklamayı göster

Cevap: autounattend.xml

Cevap

The technician must create an autounattend.xml file and place it in the root directory of the bootable USB installation media.
The autounattend.xml file is an XML-based answer file created using tools like Windows SIM (System Image Manager). When placed in the root directory of a bootable USB drive, Windows Setup automatically detects and applies its configuration passes without user intervention.

Adım Adım Çözüm

1
Identify the deployment requirement
The scenario requires automating a local Windows OS installation without network deployment infrastructure (WDS/PXE).
Unattended installations on standalone hardware require an answer file embedded on the boot media.
2
Determine the correct answer file naming convention
Windows Setup automatically searches the root of removable media for a file specifically named autounattend.xml.
When Windows setup initializes from removable media, it parses autounattend.xml to automatically answer installation prompts such as partitioning, user account creation, and product keys.

Anahtar Kavram

Unattended OS Installation via Answer Files (autounattend.xml)
Tahmini Süre:1m 0s
Soru 1349Soru

A network technician is configuring networking equipment inside an intermediate distribution frame (IDF) room shared with third-party facility contractors. Although the room itself requires keycard access, several unassigned Ethernet switch ports on the rack remain exposed, creating a risk of unauthorized physical connection to the internal network. Which of the following physical security controls should the technician implement to directly prevent unauthorized network cable insertions into these exposed ports?

Cevabı ve açıklamayı göster

Cevap: Physical port locks

Cevap

Physical port locks are the correct choice because they physically block unused RJ-45 switch ports from unauthorized network connections.
Physical port locks (such as RJ-45 port blockers) fit directly into open networking ports and require a specific key to remove. This prevents unauthorized users from physically connecting rogue devices or network cables into the switch.

Adım Adım Çözüm

1
Analyze the physical security vulnerability described in the scenario.
Unused Ethernet switch ports in a shared room are physically accessible and vulnerable to unauthorized device connections.
Identify the precise physical threat vector (unauthorized wired connection to network switch interfaces).
2
Evaluate the controls against the requirement to secure individual interface ports.
Physical port locks prevent network cables or hardware dongles from being inserted into RJ-45 or USB interfaces without a specialized removal key.
Port locks provide granular interface-level protection when general room access cannot completely eliminate unauthorized personnel presence.

Anahtar Kavram

Physical Port Locks and Interface Security
Tahmini Süre:1m 0s
Soru 1350Soru

A user contacts the IT helpdesk reporting that their Windows workstation is displaying suspicious pop-up messages and experiencing severe performance degradation. An IT technician inspects the device and identifies symptoms of an active malware infection. According to the standard CompTIA 7-step malware remediation process, which action should the technician perform NEXT?

Cevabı ve açıklamayı göster

Cevap: Isolate the workstation by disconnecting it from the local network.

Cevap

Isolate the workstation by disconnecting it from the local network.
According to the official CompTIA 7-step malware remediation process, Step 2 requires quarantining the infected system immediately after identifying symptoms (Step 1). Disconnecting the system from the wired and wireless network isolates the threat and prevents lateral propagation.

Adım Adım Çözüm

1
Identify the current step in the CompTIA 7-step malware remediation process.
The technician has already performed Step 1 (Identify and research malware symptoms).
The scenario states that malware symptoms have been confirmed on the workstation.
2
Determine the mandatory next step in the established workflow.
Step 2 is Quarantine infected systems.
Immediate containment (e.g., unplugging Ethernet or disabling Wi-Fi) stops lateral movement and unauthorized network communication before pursuing remediation.

Anahtar Kavram

CompTIA 7-Step Malware Remediation Best Practices
Soru 1351Soru

An IT auditor flags unauthorized background network traffic originating from a finance manager's Windows 11 workstation. A technician inspects the system, confirms an active spyware infection, and immediately disconnects the ethernet cable and disables wireless adapters to isolate the device. Next, the technician disables Windows System Restore to prevent infected files from being backed up. According to the CompTIA 7-step malware remediation process, which action should the technician perform next?

Cevabı ve açıklamayı göster

Cevap: Update the anti-malware software definitions using clean media and perform a full scan in Safe Mode.

Cevap

The technician should update the anti-malware software definitions using clean media and perform a full scan in Safe Mode.
Following the standard CompTIA 7-step malware remediation process, after identifying the malware (Step 1), quarantining the system (Step 2), and disabling System Restore (Step 3), the technician must proceed to Step 4: Remediate the infected systems. Because the device is isolated from the network, anti-malware signatures should be updated from clean media, followed by scanning and removing the malware in Safe Mode or another isolated environment.

Adım Adım Çözüm

1
Analyze current progress in the 7-step remediation workflow
The technician has completed Step 1 (Identify malware symptoms), Step 2 (Quarantine the infected system), and Step 3 (Disable System Restore).
Determining completed steps enables identifying the mandatory next stage in the process.
2
Determine the sequential step required next
Step 4 of the CompTIA 7-step process is 'Remediate the infected systems'.
Remediation requires updating anti-malware software signatures (via clean removable media since network connectivity is isolated) and scanning/removing the malware using safe environments like Safe Mode.
3
Match the required action to the correct choice
Updating anti-malware definitions from clean media and scanning in Safe Mode aligns precisely with Step 4.
All other choices correspond to later stages (Step 5: Schedule scans, Step 6: Re-enable System Restore, Step 7: Educate end user).

Anahtar Kavram

CompTIA 7-Step Malware Remediation Process Sequence
Soru 1352Soru

An incident responder is investigating a compromised Windows 11 workstation where a trojan dropper disabled local security services and established persistence in system boot configurations. The machine has already been isolated from the network and quarantined. Following the standard CompTIA malware remediation process, which TWO actions should the responder execute immediately prior to performing the system remediation scan? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Turn off System Protection to prevent malicious files from persisting in restore points.; Deploy updated antivirus definition signatures from a clean external drive.

Cevap

The technician must turn off System Protection to purge infected restore points and deploy updated antivirus definition signatures from a clean external drive.
Disabling System Protection ensures that restore points containing infected files are purged and cannot be accidentally restored later. Updating malware definitions offline ensures the anti-malware engine has the newest threat signatures to detect and clean persistent trojan binaries without reconnecting the compromised host to the network.

Adım Adım Çözüm

1
Verify current stage in the CompTIA 7-Step Malware Remediation Process.
The workstation is already quarantined (Step 2 completed). The next required step before remediation scanning is Step 3.
Step 3 dictates disabling System Restore to ensure infected files are not archived into system recovery points.
2
Identify pre-scan remediation requirements (Step 4 prep).
The anti-malware tools must be updated before executing the scan.
Since the machine is disconnected from the network, signatures must be updated manually via clean external media.

Anahtar Kavram

CompTIA 7-Step Malware Remediation Process - Steps 3 & 4 (Disable System Restore and Update Definitions)
Soru 1353Soru

A network support technician is assisting a user remotely on a Windows 11 Professional workstation. Whenever the user attempts an operation requiring administrative privileges, the technician's remote control software displays a blank black screen instead of showing the User Account Control (UAC) elevation prompt, preventing the technician from typing administrative credentials. Which Local Security Policy setting should be disabled to allow remote viewing of UAC prompts without completely turning off UAC?

Cevabı ve açıklamayı göster

Cevap: User Account Control: Switch to the secure desktop when prompting for elevation

Cevap

Disabling the security policy 'User Account Control: Switch to the secure desktop when prompting for elevation' prevents UAC from switching to an isolated desktop instance that blocks unprivileged remote desktop utilities from capturing the prompt screen.
The option selecting 'User Account Control: Switch to the secure desktop when prompting for elevation' is correct because the secure desktop isolates the screen to prevent software spoofing. Third-party remote tools without specialized service hooks cannot render the secure desktop, resulting in a black screen. Disabling this specific setting forces UAC prompts to appear on the standard desktop where remote software can capture them.

Adım Adım Çözüm

1
Identify the cause of the black screen during remote administration.
The secure desktop feature runs UAC prompts in a isolated system process space (Desktop context) that standard user-mode remote control agents cannot capture or render.
By default, Windows switches to the secure desktop to isolate elevation prompts from malicious software running on the user's interactive desktop.
2
Locate the targeted Local Security Policy rule in secpol.msc under Security Options.
Identify 'User Account Control: Switch to the secure desktop when prompting for elevation'.
This policy explicitly governs whether elevation prompts execute on the secure desktop or the user's interactive desktop.
3
Disable the secure desktop policy setting.
Prompts display on the standard user desktop, making them visible to the remote technician while preserving mandatory UAC credential requests.
This maintains elevation prompt requirements while resolving the remote capture conflict.

Anahtar Kavram

Windows UAC Secure Desktop Configuration and Remote Assistance Compatibility
Soru 1354Soru

A user logged into a Windows workstation with a standard user account attempts to execute a software installer. Before the installation wizard opens, the screen dims and a dialog box pops up asking for an administrator password to proceed. Which Windows security feature is responsible for displaying this credential prompt?

Cevabı ve açıklamayı göster

Cevap: User Account Control (UAC)

Cevap

User Account Control (UAC) is the Windows security feature that intercepts system-level changes and prompts standard users to enter administrator credentials.
User Account Control (UAC) protects Windows operating systems by preventing unauthorized administrative changes. When a standard user attempts to perform an administrative action, UAC dims the secure desktop and requires administrator credentials to elevate permissions.

Adım Adım Çözüm

1
Analyze the observed system behavior in the scenario.
The desktop dims and a dialog box interrupts an installation attempt to request administrative credentials.
This behavior indicates a security boundary check designed to prevent unauthorized application execution or system modifications.
2
Identify the Windows feature responsible for privilege elevation prompts.
User Account Control (UAC) enforces least privilege by forcing applications to run in standard user context until elevated through an explicit admin credential prompt.
UAC protects the operating system from unauthorized changes by requiring authorization before executing administrative actions.

Anahtar Kavram

User Account Control (UAC) Privilege Elevation
Tahmini Süre:45s
Soru 1355Soru

An IT manager hires a third-party disposal service to physically shred decommissioned hard drives containing sensitive company records. Which of the following documents should the manager obtain from the vendor to officially verify compliance with media destruction standards?

Cevabı ve açıklamayı göster

Cevap: Certificate of Destruction

Cevap

Certificate of Destruction
A Certificate of Destruction is a formal document issued by a data sanitization vendor detailing the date, method of destruction, and serial numbers of destroyed devices to prove compliance during security audits.

Adım Adım Çözüm

1
Identify the regulatory requirement
Recognize that organizations require formal, verifiable documentation when outsourcing physical data destruction.
Security compliance audits mandate proof that drives were properly destroyed.
2
Evaluate document types
Identify that a Certificate of Destruction provides serialized tracking and formal confirmation of physical shredding.
Third-party vendors issue this specific legal document upon completing physical disposal.

Anahtar Kavram

Certificate of Destruction for physical media disposal validation
Soru 1356Soru

A systems administrator is preparing to repurpose several Self-Encrypting Drives (SEDs) from a decommissioned database server that previously held highly confidential patient records. The drives must be sanitized in compliance with organizational policy before being redeployed to a non-sensitive testing environment. Which of the following methods should the administrator execute to instantly render all existing data irrecoverable while keeping the drives fully operational?

Cevabı ve açıklamayı göster

Cevap: Perform a Cryptographic Erase (Crypto-Erase) using the drive vendor's management utility to erase the Media Encryption Key.

Cevap

Cryptographic Erase (Crypto-Erase) using the drive vendor's management utility to erase the Media Encryption Key
Performing a Cryptographic Erase (Crypto-Erase) on Self-Encrypting Drives (SEDs) erases or resets the internal Media Encryption Key (MEK). Because all data written to an SED is encrypted at the hardware level, deleting the encryption key makes the existing data instantly and permanently unrecoverable, while resetting the drive to a usable factory state for safe redeployment.

Adım Adım Çözüm

1
Analyze the media type and operational requirements
Identified Self-Encrypting Drives (SEDs) containing confidential data that must be sanitized while preserving hardware functionality for redeployment.
Selection of data disposal methods depends on drive technology (SED/SSD vs. magnetic HDD) and whether the media is destined for reuse or physical destruction.
2
Evaluate sanitization mechanisms compatible with SED reuse
Cryptographic Erase (Crypto-Erase) invalidates or changes the drive's internal Media Encryption Key (MEK).
Without the original encryption key, all stored data blocks become permanent ciphertext (unrecoverable), allowing immediate drive reuse without physical damage.
3
Eliminate inappropriate disposal methods
Degaussing and shredding destroy hardware functionality, while standard OS formatting leaves wear-leveled/over-provisioned blocks intact.
Proper security compliance requires matching sanitization depth with hardware lifecycle goals.

Anahtar Kavram

Cryptographic Erase (Crypto-Erase) on Self-Encrypting Drives (SEDs)
Soru 1357Soru

A technician is connecting a high-performance external NVMe storage array to a workstation to handle raw 8K video editing. The workstation motherboard features a USB Type-C interface marked with a lightning bolt icon. The technician connects the storage array using a standard USB 3.2 Gen 1 (Type-C) passive cable. Although the array functions correctly, data transfer rates peak at 5 Gbps rather than the array's advertised 40 Gbps throughput. Which of the following best explains the reason for this performance limit?

Cevabı ve açıklamayı göster

Cevap: The cable used is rated only for USB 3.2 Gen 1 data rates and lacks the high-speed signaling capability required for Thunderbolt throughput.

Cevap

The cable used is rated only for USB 3.2 Gen 1 data rates and lacks the high-speed signaling capability required for Thunderbolt throughput.
While the physical port on the workstation supports Thunderbolt (indicated by the lightning bolt symbol) and the storage array supports 40 Gbps, the cable inserted is only rated for USB 3.2 Gen 1 (5 Gbps). Data links negotiate parameters based on the lowest-rated component in the connection path; therefore, a standard USB 3.2 Gen 1 cable limits transfer speeds to 5 Gbps.

Adım Adım Çözüm

1
Identify the physical connector and interface capabilities of the host.
The host port is USB Type-C supporting Thunderbolt (indicated by the lightning bolt icon), capable of up to 40 Gbps.
Host capability establishes the maximum potential speed of the interface.
2
Analyze the interconnect cable specs.
The installed cable is a standard USB 3.2 Gen 1 Type-C cable rated for 5 Gbps.
The transmission medium must support the target protocol and frequency to achieve full performance.
3
Determine the bottleneck cause.
The interface negotiates down to the highest common protocol supported by all components in the chain, which is 5 Gbps due to cable limitations.
Physical form factor (USB-C) compatibility does not guarantee underlying protocol speed support without proper cable certification.

Anahtar Kavram

Distinguishing physical USB Type-C connectors from protocol capabilities and cable category throughput ratings.
Tahmini Süre:2m 0s
Soru 1358Soru

Match each workstation security hardening requirement or administrative objective to the most appropriate Windows configuration control or security feature that implements it.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Prevent users from mounting external USB mass storage drives while continuing to allow USB mice and keyboards to function
Mitigate OS-level credential harvesting and memory scraping techniques targeting LSASS secrets
Automatically lock an unattended user workstation when a paired mobile device leaves the immediate physical area
Prevent unauthenticated code execution triggered automatically upon inserting optical or flash media

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

The hardening requirements map directly to their corresponding controls: prohibiting USB mass storage while retaining human interface devices corresponds to configuring Removable Storage Access policies in GPO; protecting LSASS from memory scraping corresponds to enabling Credential Guard with VBS; automatically locking an unattended desktop via Bluetooth proximity corresponds to Dynamic Lock; and disabling automated code launch from inserted media corresponds to disabling AutoPlay and AutoRun policies.
Each security requirement aligns with its specific technical implementation. Denying USB storage access while preserving keyboards/mice relies on GPO Removable Storage Access restrictions. Protecting LSASS memory from administrative privilege abuse requires Credential Guard with VBS. Proximity-based session locking uses Bluetooth Dynamic Lock. Preventing automatic binary launch on volume mount is accomplished by disabling AutoPlay and AutoRun.

Adım Adım Çözüm

1
Analyze USB mass storage blocking requirements vs peripheral functionality
Disabling device driver installation entirely would break mice and keyboards. Removable Storage Access GPOs target specific device classes, denying storage access while leaving HIDs operational.
Granular policy enforcement allows administrators to restrict removable storage without impairing standard USB input peripherals.
2
Analyze LSASS memory protection techniques
Standard access control lists do not stop elevated processes from reading LSASS memory. Credential Guard employs Virtualization-based Security (VBS) to isolate LSASS tokens outside the standard OS kernel.
VBS isolates secrets in a hardware-secured environment, rendering memory scraping tools ineffective even when running with administrative rights.
3
Evaluate automated physical walk-away locking options
Dynamic Lock uses paired Bluetooth device RSSI signal attenuation to detect user absence and trigger a lock command.
This provides defense-in-depth for physical security when users fail to manually lock their desktops.
4
Evaluate automatic media execution controls
Disabling AutoPlay and AutoRun globally stops automatic parsing and launching of scripts or binaries embedded in newly inserted media.
AutoRun and AutoPlay policies directly govern automatic file handler triggers upon drive volume mounting.

Anahtar Kavram

Workstation Hardening and Best Practices
Tahmini Süre:3m 0s
Soru 1359Soru

A human resources administrator receives a targeted email appearing to come from the company's payroll software vendor, requesting an urgent update to employee direct deposit banking details via an attached link. On the same day, an IT technician discovers several unlabelled USB flash drives intentionally left on tables in the employee cafeteria. Which of the following social engineering tactics are demonstrated in these security incidents? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Spear phishing; Baiting

Cevap

The correct tactics are spear phishing and baiting.
Spear phishing describes a targeted digital attack aimed at specific personnel (such as HR administrator) to compromise sensitive corporate data. Baiting describes leaving physical storage media (such as USB drives) in public locations to lure curious individuals into connecting them to network workstations.

Adım Adım Çözüm

1
Analyze the fraudulent email incident directed at the HR administrator.
Determine that sending a targeted email to a specific role to compromise payroll credentials is an example of spear phishing.
Spear phishing targets specific individuals or departments using tailored information rather than generic mass distributions.
2
Analyze the physical USB flash drives discovered in the cafeteria.
Determine that leaving physical media in high-traffic common areas to entice victims into connecting them to company computers is baiting.
Baiting leverages human curiosity or greed by promising a physical or digital reward.

Anahtar Kavram

Identifying Social Engineering Attack Vectors (Spear Phishing and Baiting)
Soru 1360Soru

A field technician is troubleshooting a desktop workstation used for heavy video rendering. The system boots normally into the operating system and performs routine tasks fine. However, several minutes into a full GPU and CPU stress test, the workstation immediately powers off without displaying a crash screen or error code. Pressing the power button immediately after the shutdown yields no response, but waiting approximately 60 seconds allows the machine to power on and boot successfully again. Which of the following is the most likely root cause of this failure?

Cevabı ve açıklamayı göster

Cevap: The power supply unit is exceeding its rated wattage capacity under peak load, triggering internal overload protection circuit thermal reset.

Cevap

The power supply unit is exceeding its rated wattage capacity under peak load, triggering internal overload protection circuit thermal reset.
The correct answer identifies that when a power supply unit experiences demand exceeding its wattage rating under intensive processing loads, built-in protective features (such as Over-Power Protection or Over-Current Protection) trip to prevent physical component damage. This causes an instantaneous total loss of power and prevents immediate rebooting until the PSU protection circuits reset.

Adım Adım Çözüm

1
Analyze symptom pattern during system load
System instantly cuts power without OS error screens or blue screen crash dumps during high CPU/GPU stress.
Sudden hard power loss under heavy load points directly to power delivery failures or thermal safety triggers.
2
Evaluate behavior when trying to power back on immediately
The power button fails to respond right away but works after a 30 to 60-second delay.
This behavior indicates that PSU protective latches (such as Over-Power Protection) or thermal reset switches have tripped and require time to bleed residual energy before allowing restart.
3
Differentiate power supply tripping from motherboard/RAM memory failures
Confirm PSU wattage overload as the primary cause.
RAM errors cause operating system crashes (BSOD) or POST boot failures, whereas immediate power removal with a delayed button response is characteristic of PSU protection features.

Anahtar Kavram

Power Supply Unit (PSU) Protection Features and Load Sizing
Tahmini Süre:1m 30s
ÖncekiSayfa 68 / 178Sonraki
Tüm alıştırma soruları — CompTIA A+ (Core 1 & Core 2) | Examkin