Security
442 soru
A company needs to prevent unauthorized individuals from following authorized employees into a highly secure server room, a practice known as tailgating. Which of the following physical security controls is specifically designed to enforce single-person entry at an access point?
A helpdesk technician needs to adjust the User Account Control (UAC) notification level on a Windows 10 workstation using the standard Control Panel interface. In what sequence should the technician perform the following steps to access and apply the new UAC settings?
Öğeleri doğru sıraya koymak için sürükleyin
A systems administrator is configuring Windows 11 Pro workstations used for automated nightly batch tasks. An administrative script assigned to run under a local administrator account fails to complete because User Account Control (UAC) pauses execution while waiting for interactive consent on the Secure Desktop. To allow automated background execution for administrative accounts while maintaining UAC protections for standard users, which Local Security Policy setting should be modified?
A desktop technician has finished scanning and removing a spyware infection from a Windows workstation, updated the operating system and anti-malware signature files, and configured scheduled recurring scans. According to the CompTIA 7-step malware remediation process, which of the following actions should the technician perform NEXT?
A security technician at a defense contractor is investigating a multi-stage security incident reported across the corporate facility. Physical access logs and security footage show an unknown individual wearing a fake delivery uniform closely following an authorized employee through a badge-restricted turnstile without scanning an access card. Later that day, several senior lead engineers received customized emails containing authentic project reference numbers and names of their team members, requesting that they click an external link to verify their corporate credentials. Which of the following social engineering threat types were directly executed during this incident? (Select TWO.)
Geçerli olan tümünü seçin
An IT support specialist is responding to a reported malware infection on a company workstation. Arrange the following actions in the correct sequence according to the standard CompTIA malware removal process, starting with the earliest step and ending with the final step.
Öğeleri doğru sıraya koymak için sürükleyin
A system administrator is configuring security baselines on standalone Windows 11 Pro workstations located in a shared laboratory environment. To enforce strict access controls and prevent standard domain users from triggering administrative privilege requests or running unauthorized installers, the administrator opens the Local Security Policy snap-in (secpol.msc). Which TWO User Account Control (UAC) policy settings should the administrator configure under Security Options? Select TWO.
Geçerli olan tümünü seçin
An IT security technician is finalizing a data destruction workflow for a decommissioned enterprise storage array that contains both magnetic Hard Disk Drives (HDDs) and Solid-State Drives (SSDs). The technician plans to pass all drives through a powerful magnetic degausser as the primary sanitization step before sending the hardware off-site for physical shredding. Which of the following identifies the most critical security flaw in this proposed workflow?
A systems administrator is configuring remote support capabilities on standalone Windows 11 Pro workstations. During remote management sessions, the helpdesk technician notices that whenever an action requires elevated administrative privileges, the remote screen turns black and becomes non-responsive, preventing the technician from seeing or interacting with the elevation prompt. Local security policy mandates that User Account Control (UAC) elevation prompts must remain active for all administrative tasks. Which of the following Local Security Policy settings should the administrator modify to resolve the remote screen blackout issue while maintaining elevation prompts?
An enterprise systems administrator is decommissioning a high-security server room containing legacy magnetic hard disk drives (HDDs) holding regulated customer financial records. Company policy mandates a strict sanitization and disposal workflow adhering to NIST SP 800-88 guidelines and complete chain-of-custody preservation. Place the technician's disposition actions in the correct chronological order from start to finish.
Öğeleri doğru sıraya koymak için sürükleyin
A system administrator is hardening domain-joined Windows 11 Pro workstations to adhere to a strict corporate security baseline. Under this baseline, standard domain users must be completely prevented from initiating elevation attempts—if an unprivileged account triggers a process requiring administrative credentials, the operating system must immediately reject the request without presenting a credential prompt. Furthermore, administrators logged in under Admin Approval Mode must explicitly re-enter their domain credentials on the Secure Desktop whenever an application requests elevated privileges. Which combination of Local Security Policy (secpol.msc) settings under User Account Control will correctly enforce this baseline?
A security administrator is hardening standalone Windows 11 Professional workstations deployed in a public testing center. To adhere to compliance guidelines, standard user accounts must be strictly prohibited from triggering administrator credential prompts upon attempting elevated tasks, and any executable requesting administrative privileges must be verified against a valid digital signature infrastructure before elevation is permitted. Which TWO settings in Local Security Policy (secpol.msc) under Security Options should the administrator configure to meet these requirements? (Select TWO.)
Geçerli olan tümünü seçin
A systems administrator is establishing a comprehensive security baseline across enterprise endpoints. Match each workstation hardening control on the left with the specific threat or vulnerability it directly mitigates on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An IT specialist is configuring several Windows 11 workstations deployed in a shared corporate training center. The systems must allow external guest speakers to plug in USB presentation remotes and keyboards, but security policy strictly prohibits executable files from automatically launching when USB flash drives are inserted. Which of the following is the most effective workstation hardening practice to satisfy this requirement without disabling essential USB input devices?
A technician is setting up a Wi-Fi network for a small home office. The client requires a wireless security mode that allows all devices to connect using a single, shared passphrase without requiring an external authentication server. Which of the following wireless security modes should the technician configure?
A financial analyst working in a public airport lounge notices an unfamiliar individual sitting nearby who is repeatedly looking at their laptop screen while they type sensitive user credentials and view confidential company budget files. Which of the following social engineering threat types is actively occurring in this scenario?
A security technician is categorizing various physical and digital security incidents reported across an enterprise environment. Match each social engineering or threat type on the left with its corresponding attack description on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A system administrator needs to secure individual server chassis inside a shared colocation facility so that unauthorized personnel cannot physically remove hard drives or tamper with hardware components. Which of the following physical security controls should be implemented to directly achieve this requirement?
Match each physical security control to its primary protective function.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A security technician is securing a dedicated equipment cabinet within a third-party colocation data center. The organization's security baseline requires preventing physical access to server hardware ports to block unauthorized hardware keyloggers, as well as containing electromagnetic emissions from critical cryptographic servers to prevent signal interception. Which combination of physical security controls directly addresses both of these specific requirements?