Security

442 soru

Soru 21Soru

A network administrator is deploying new high-density servers into a shared multi-tenant colocation facility. Facility personnel provide outer perimeter security and entry logging, but technicians from other companies frequently work in the same server room. To protect the company's hardware from unauthorized direct console access and physical tampering at the device level, which physical security control should the administrator implement?

Cevabı ve açıklamayı göster

Cevap: Locked server rack enclosures

Cevap

Implementing locked server rack enclosures is the correct physical security control.
Locked server rack enclosures provide physical containment at the individual cabinet level, preventing unauthorized personnel who have general access to a shared colocation floor from opening the server chassis, plugging in rogue USB devices, or accessing local console ports.

Adım Adım Çözüm

1
Analyze the physical security scope requirement
The requirement focuses on securing hardware equipment at the individual device level inside a shared room.
Outer perimeter controls are already managed by the facility provider, but internal multi-tenant access poses a risk to specific racks.
2
Evaluate candidate physical security controls against internal unauthorized tampering
Locked rack cabinets restrict physical access to servers, power units, and local ports exclusively to authorized personnel possessing keys or rack-level biometric credentials.
Other room-level controls permit authorized room visitors to walk up to unshielded equipment.

Anahtar Kavram

Physical Hardware Isolation and Device Security Controls
Tahmini Süre:1m 0s
Soru 22Soru

A network security administrator is tasked with designing physical access controls for an enterprise server vault containing sensitive financial data. The audit requirements demand a solution that physically restricts access to one authenticated individual at a time using an interlocking dual-door entry system, while strictly preventing employees from scanning their access credential and immediately passing it back to an unauthenticated colleague to enter behind them. Which of the following physical security implementations best addresses all of these requirements?

Cevabı ve açıklamayı göster

Cevap: An access control vestibule configured with anti-passback enforcement

Cevap

An access control vestibule configured with anti-passback enforcement is the optimal physical control.
An access control vestibule (also known as a mantrap) consists of a specialized space between two interlocking doors where the first door must close and lock before the second door unlocks, physically restricting access to one person at a time and preventing tailgating. Anti-passback is a logical access control feature implemented on card readers that prevents a badge from being scanned for entrance twice in succession without an intervening exit scan, directly stopping authorized users from passing their credentials back to unauthorized individuals.

Adım Adım Çözüm

1
Analyze the entry restriction requirement
Identified the need for a physical barrier restricting entry to one individual at a time using interlocking doors (access control vestibule / mantrap).
An access control vestibule prevents unauthorized individuals from physically tailgating authorized personnel through dual interlocking doors.
2
Analyze the credential reuse requirement
Identified the requirement to block badge sharing or passing back credentials at the entryway.
Anti-passback rules require an exit badge scan before a credential can be scanned for entry again, preventing badge sharing.
3
Synthesize and select the combined physical control
Selected the option combining an access control vestibule with anti-passback enforcement.
This combination satisfies both the structural interlocking door requirement and the badge reuse control policy.

Anahtar Kavram

Physical Access Control Mechanisms (Access Control Vestibules & Anti-Passback)
Soru 23Soru

A network administrator needs to enhance the physical security of a network closet. Specifically, the administrator must prevent unauthorized users from plugging unauthorized Ethernet cables into open wall jacks and prevent physical theft of sensitive magnetic backup tapes stored in the room. Which of the following physical security controls should be implemented to meet these two goals? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: RJ45 port locks; Locking media safe

Cevap

The correct physical security controls to implement are RJ45 port locks and a locking media safe.
RJ45 port locks directly prevent unauthorized physical connections into open network jacks, and a locking media safe prevents unauthorized individuals from taking physical backup tapes.

Adım Adım Çözüm

1
Identify the control needed to secure open network wall jacks
RJ45 port locks insert into unused Ethernet jacks and require a special key to remove, physically blocking unauthorized connections.
Prevents unauthorized network access via physical cabling.
2
Identify the control needed to protect physical backup tapes against theft
A locking media safe provides a dedicated, locked enclosure for physical backup tapes.
Prevents physical removal and theft of data storage media.

Anahtar Kavram

Selecting appropriate physical security controls for port protection and data media storage.
Soru 24Soru

A cybersecurity technician is designing a physical security baseline for an enterprise datacenter facility and employee workstations. Match each physical security control to the specific threat or unauthorized physical security risk it is engineered to prevent.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Faraday cage
Mantrap
Privacy filter
Cable lock

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Faraday cage pairs with blocking electromagnetic field emissions; Mantrap pairs with eliminating tailgating via interlocking doors; Privacy filter pairs with mitigating shoulder surfing by narrowing screen viewing angles; Cable lock pairs with preventing physical hardware theft by anchoring devices.
Each control directly mitigates its paired physical vulnerability: Faraday cages suppress electromagnetic waves, mantraps control physical human access cadence to prevent piggybacking, privacy filters restrict screen viewing line-of-sight against observation, and cable locks mechanically bind equipment against unauthorized removal.

Adım Adım Çözüm

1
Analyze each physical security control's operational mechanism.
Identified the primary defense domain for each control (RF shielding, access control, visual privacy, physical theft prevention).
Understanding the physical property targeted by each control allows proper alignment with corresponding threat mitigations.
2
Map Faraday cage to wireless/electromagnetic threat mitigation.
Faraday cage matches the prevention of electromagnetic field signal eavesdropping.
Conductive enclosures restrict ingress and egress of RF signals.
3
Map Mantrap to physical entry control.
Mantrap matches eliminating tailgating using interlocking access doors.
Two-stage access control requires individual verification before allowing access into secured areas.
4
Map Privacy filter to visual threat protection.
Privacy filter matches mitigating shoulder surfing.
Polarized films limit monitor visibility exclusively to direct viewing positions.
5
Map Cable lock to equipment theft prevention.
Cable lock matches preventing opportunistic device theft by anchoring to fixed objects.
Physical cables mechanically tether hardware components to solid structures.

Anahtar Kavram

Physical Security Controls and Threat Mitigation
Soru 25Soru

A helpdesk technician receives a call from an individual claiming to be an executive support specialist who urgently needs a user's network password to resolve a critical server outage. Which type of social engineering attack is being attempted?

Cevabı ve açıklamayı göster

Cevap: Vishing

Cevap

The attack being attempted is vishing (voice phishing).
Vishing is a social engineering attack performed over the telephone where an attacker impersonates a trusted authority to extract sensitive data or login credentials.

Adım Adım Çözüm

1
Identify the communication vector used in the scenario.
The attacker is contacting the target via a direct telephone call.
Social engineering attack types are distinguished by their delivery mechanisms.
2
Analyze the attacker's method and purpose.
The attacker uses voice communication and impersonation to trick the technician into disclosing network passwords.
Phishing conducted specifically through voice telephone calls is defined as vishing.

Anahtar Kavram

Vishing (Voice Phishing)
Soru 26Soru

Match each enterprise physical security control to the specific threat vector or physical security risk it is designed to mitigate.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Faraday Cage
Physical Port Lock
Kensington Cable Lock
Security Bollard

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Each physical security control maps to its corresponding defense mechanism: Faraday Cage blocks RF emissions; Physical Port Lock blocks unauthorized interface connections; Kensington Cable Lock physically anchors devices to prevent theft; Security Bollard protects perimeters against vehicle ramming attacks.
Each physical security control addresses a distinct domain of security: Faraday cages block electromagnetic and wireless signal interception; physical port locks block hardware interface manipulation; Kensington cable locks prevent physical device theft; security bollards protect against vehicle impact.

Adım Adım Çözüm

1
Analyze electromagnetic and wireless isolation mechanisms.
Identified that enclosure technologies shielding against RF/signals correspond to the Faraday Cage control.
Faraday cages prevent external signal interception and internal RF leakage.
2
Examine device port protection controls.
Matched physical port locks with blocking unused hardware interfaces against unauthorized media connection.
Unsecured USB ports are primary vectors for physical data exfiltration and badUSB attacks.
3
Evaluate endpoint anti-theft anchoring mechanisms.
Paired Kensington cable locks with mechanical anchoring to fixed office furniture.
Cable locks increase the time and effort required to steal portable computer hardware.
4
Identify perimeter vehicle protection controls.
Associated bollards with anti-ramming structural protection at entry points.
Bollards absorb kinetic impact from vehicles attempting to breach building perimeters.

Anahtar Kavram

Physical Security Controls and Threat Mitigation Functions
Soru 27Soru

Match each physical security control to the specialized security risk or intrusion vector it is primarily designed to mitigate.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Faraday cage enclosure
Access control vestibule with anti-passback
Heavyweight steel bollards
Protected Distribution System (PDS)

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

The Faraday cage enclosure matches RF eavesdropping mitigation; the Access control vestibule with anti-passback matches tailgating and credential-sharing prevention; Heavyweight steel bollards match vehicle ramming attack prevention; and the Protected Distribution System (PDS) matches physical cable wiretapping protection.
Each physical security control addresses a distinct attack vector: Faraday cages protect against RF eavesdropping; access control vestibules with anti-passback eliminate tailgating and badge-sharing; bollards defeat vehicle ramming attacks; and Protected Distribution Systems secure cabling runs against physical wiretapping.

Adım Adım Çözüm

1
Identify the primary defensive characteristic of a Faraday cage.
Recognize that continuous conductive shielding blocks electromagnetic induction and radio frequency transmission.
Faraday cages prevent signals from entering or escaping shielded environments, mitigating RF eavesdropping.
2
Evaluate an access control vestibule enforcing anti-passback rules.
Determine that interlocking doors regulate physical movement while anti-passback prevents a single credential from being passed back to admit a secondary individual.
This combination directly stops tailgating/piggybacking and badge reuse.
3
Analyze the structural role of steel bollards.
Understand that bollards serve as reinforced physical barriers situated outside facility entrances.
Their primary function is to prevent vehicles from breaching building perimeters through ramming.
4
Determine the protective scope of a Protected Distribution System (PDS).
Identify that PDS encapsulates telecommunications cabling in secure conduits or alarm-monitored raceways.
PDS prevents unauthorized physical access and wiretapping along vulnerable cable pathways.

Anahtar Kavram

Physical Security Controls & Threat Alignment
Soru 28Soru

A facility manager notices that unauthorized visitors are entering a secure office building by closely following authorized employees through the main entrance door before it closes. Which physical security control should be implemented to specifically prevent this practice?

Cevabı ve açıklamayı göster

Cevap: An access control vestibule

Cevap

An access control vestibule
An access control vestibule consists of a small space with two interlocking doors. When an authorized person passes through the first door, it must close completely before the second door unlocks and opens. This physical barrier ensures that only one person can enter per authentication event, directly stopping tailgaters.

Adım Adım Çözüm

1
Identify the physical security threat described in the scenario.
The issue is tailgating (or piggybacking), where an unauthorized individual closely follows an authorized person through a secure doorway.
Selecting the correct physical security measure requires identifying the specific access control vulnerability.
2
Evaluate the available security mechanisms to determine which one restricts entryway throughput to one authenticated person at a time.
An access control vestibule creates an enclosed double-door checkpoint that isolates individuals during access attempts.
The interlocking mechanism ensures the outer door shuts completely before allowing entry through the inner door, neutralizing tailgating attempts.

Anahtar Kavram

Physical Access Controls and Tailgating Prevention
Soru 29Soru

Match each social engineering threat type on the left to its correct characteristic description on the right.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Spear Phishing
Pretexting
Tailgating
Whaling

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Spear Phishing matches targeted email messages; Pretexting matches creating a fabricated narrative; Tailgating matches physically following an authorized person into a facility; Whaling matches phishing attacks targeting senior executives.
Spear phishing targets specific individuals with tailored communications. Pretexting creates a false story to convince a target to reveal sensitive details. Tailgating is a physical intrusion technique of closely following authorized personnel into secure areas. Whaling is an executive-level phishing attack aimed at high-value targets such as CEOs or CFOs.

Adım Adım Çözüm

1
Identify digital targeted attack types
Recognize Spear Phishing as customized emails to specific users, and Whaling as spear phishing specifically directed at high-level executives.
Both vectors use targeted messaging, but Whaling focuses exclusively on high-profile corporate targets.
2
Identify psychological and physical attack vectors
Associate Pretexting with scenario creation/impersonation and Tailgating with physical access intrusion.
Pretexting establishes a false context to gain trust, while tailgating exploits physical proximity to bypass access controls.

Anahtar Kavram

Social Engineering Threat Classifications
Tahmini Süre:1m 0s
Soru 30Soru

An IT technician is setting up desktop workstations at a customer-facing service counter where staff members frequently leave their desks unattended to assist clients in the lobby. The facility manager requires a physical security control specifically designed to prevent unauthorized individuals from quickly stealing and carrying away the desktop hardware. Which of the following physical security controls should the technician implement?

Cevabı ve açıklamayı göster

Cevap: Cable locks attached to a heavy, stationary desk fixture

Cevap

Cable locks attached to a heavy, stationary desk fixture provide the necessary physical security to prevent hardware theft at open service counters.
Cable locks physically anchor desktop computers and hardware to rigid, heavy fixtures, directly mitigating the risk of quick equipment theft in open or unattended areas.

Adım Adım Çözüm

1
Analyze the threat context described in the scenario
The workstations are located in an open, customer-facing area where equipment can be physically stolen while staff are away.
Identifying the specific physical threat (hardware theft in an open area) determines the required physical control.
2
Evaluate candidate physical security mechanisms against hardware theft
Cable locks physically secure device chassis and peripherals to immovable furniture, making quick theft impractical.
Cable locks specifically address device theft in open or semi-public environments without restricting room access.

Anahtar Kavram

Selecting appropriate physical security controls based on specific environmental threats and assets.
Soru 31Soru

A corporate security technician is upgrading physical security access controls for an enterprise data hall housing sensitive financial records. Recent internal audits identified that unauthorized personnel have repeatedly gained entry into the secure hallway by closely following authorized staff through open door swings (tailgating). The security team requires a solution that physically enforces single-person entry per valid credential scan without requiring continuous physical monitoring by security guards. Which of the following physical security controls best meets these requirements?

Cevabı ve açıklamayı göster

Cevap: An access control vestibule equipped with interlocking doors and presence sensors

Cevap

An access control vestibule equipped with interlocking doors and presence sensors
An access control vestibule (mantrap) provides automated physical enforcement against tailgating. It functions by locking an individual inside a small chamber between two interlocking doors until single-occupancy identity verification occurs, ensuring that only one person enters per valid authentication attempt without needing round-the-clock security personnel.

Adım Adım Çözüm

1
Identify the primary threat vector in the scenario
The threat vector is physical tailgating (piggybacking), where unauthorized individuals closely follow authorized employees through unlocked access doors.
Understanding the threat vector determines whether detective, deterrent, or physical preventive controls are required.
2
Analyze operational constraints and enforcement criteria
The required control must physically restrict access to one person per authentication event automatically, eliminating reliance on human security guards.
Detective controls like CCTV only record events after entry, failing the automated physical prevention requirement.
3
Select the appropriate preventive physical security mechanism
An access control vestibule (mantrap) utilizes two interlocking doors with integrated weight or presence sensors, preventing the inner door from unlocking until only one authenticated person is inside the chamber.
Interlocking access control vestibules are specifically designed to eliminate tailgating through physical containment.

Anahtar Kavram

Access Control Vestibules (Mantraps)
Tahmini Süre:1m 30s
Soru 32Soru

Match each physical security control to its primary protective function.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Biometric reader
Privacy filter
Cable lock
Faraday bag

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Biometric reader pairs with authenticating identity using unique physical characteristics; Privacy filter pairs with preventing visual eavesdropping; Cable lock pairs with securing portable hardware to immovable fixtures; Faraday bag pairs with blocking external wireless signals.
Biometric readers authenticate physical traits, privacy filters block side-angle screen visibility, cable locks physically anchor equipment to prevent theft, and Faraday bags block electromagnetic signal transmission.

Adım Adım Çözüm

1
Analyze each security control's operational role.
Biometrics relate to physical authentication, privacy filters address screen visibility, cable locks prevent physical device theft, and Faraday bags block radio signals.
Matching each physical control directly to its operational target ensures standard physical security principles are applied.

Anahtar Kavram

Physical Security Controls and Features
Soru 33Soru

A technician reviews security camera footage after an unauthorized rogue device was found connected to a network switch inside a restricted server room. The footage reveals an unbadged visitor carrying a large box who closely followed an authorized administrator through a keycard-secured door before it latched closed. Which of the following social engineering threat types best describes this physical security breach?

Cevabı ve açıklamayı göster

Cevap: Tailgating

Cevap

Tailgating
Tailgating (or piggybacking) describes an unauthorized person physically gaining entry to a locked or restricted area by closely trailing an authorized individual who opens the door.

Adım Adım Çözüm

1
Analyze the physical scenario indicators
The intruder physically entered a keycard-secured room by closely following an authorized employee while carrying an item to blend in or exploit courtesy.
Identifying the medium and method of intrusion distinguishes physical social engineering attacks from digital or phone-based attacks.
2
Match the observed behavior to defined threat types
Following an authorized user through a physical access barrier before it closes is explicitly classified as tailgating.
Tailgating specifically targets physical access controls by exploiting employee courtesy or lack of awareness.

Anahtar Kavram

Tailgating (Piggybacking) Physical Social Engineering Attack
Soru 34Soru

An incident response technician has confiscated a powered mobile device suspected of containing unencrypted corporate data relevant to an ongoing investigation. To preserve forensic integrity, the technician must prevent the device from receiving remote signals—such as a remote wipe or locking command via cellular networks, Wi-Fi, or Bluetooth—while transporting it to the digital forensics laboratory. Which physical security control is most effective for this scenario?

Cevabı ve açıklamayı göster

Cevap: Enclosing the device in a Faraday bag

Cevap

Enclosing the device in a Faraday bag is the most effective physical control to prevent wireless signals from reaching the device during transit.
Enclosing the device in a Faraday bag blocks electromagnetic signals (radio frequency shielding), preventing cellular, Wi-Fi, and Bluetooth signals from connecting to the device and triggering a remote wipe or lock command.

Adım Adım Çözüm

1
Identify the primary threat in the scenario
The main risk is remote command transmission (such as a remote wipe) via cellular, Wi-Fi, or Bluetooth signals.
Incident response requires preserving evidence in its state at seizure without allowing network connectivity to modify or erase data.
2
Evaluate physical security controls designed to block radio frequency (RF) signals
A Faraday bag/enclosure blocks external electromagnetic fields and radio frequencies.
By absorbing or reflecting incoming and outgoing signals, the device remains powered without connecting to any external network.
3
Differentiate Faraday shielding from standard physical anti-theft or access controls
Controls like cable locks, privacy screens, or unshielded lockboxes address physical theft or shoulder surfing, not RF communication.
Only RF shielding prevents remote data alteration during transport.

Anahtar Kavram

RF Shielding / Faraday Enclosures for Physical Security
Soru 35Soru

A network security technician is hardening the physical security measures for a newly established satellite datacenter. The facility manager specifies two primary security goals: first, preventing unauthorized individuals from gaining entry by closely following authorized staff through outer access points, and second, ensuring that server hardware cannot be removed from equipment enclosures if room perimeter security is compromised. Which of the following physical security controls should the technician implement to meet these specific requirements? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: An access control vestibule equipped with anti-passback authentication controls; Locking rack enclosures securely bolted to the facility floor

Cevap

The technician should implement an access control vestibule equipped with anti-passback controls to prevent tailgating, along with locking rack enclosures bolted to the floor to prevent physical hardware theft.
An access control vestibule (mantrap) using anti-passback authentication prevents unauthorized users from tailgating authorized staff through entryways. Locking rack enclosures bolted to the building floor provide targeted hardware security, preventing server units from being physically disconnected and carried away.

Adım Adım Çözüm

1
Analyze the physical security threats described in the scenario
Two distinct physical risks are identified: unauthorized entry via tailgating/piggybacking and physical theft of server hardware.
Choosing effective physical controls requires mapping specific mechanisms directly to the identified physical security threat vectors.
2
Select the physical control for tailgating prevention
An access control vestibule (mantrap) with anti-passback authentication ensures that only one credentialed person passes through at a time.
Interlocking doors prevent second individuals from following authorized personnel without validating their own credentials.
3
Select the physical control for equipment theft prevention
Locking rack enclosures anchored directly to the floor secure individual host systems and hardware units.
Securing rack doors and anchoring the frame ensures servers cannot be removed or stolen even if room-level access control fails.

Anahtar Kavram

Physical Access Controls and Asset Protection
Tahmini Süre:1m 30s
Soru 36Soru

A facilities security team is planning physical enhancements for an enterprise data center building located near a heavy traffic intersection. To prevent vehicles from ramming through the main building entrance or damaging structural perimeter walls, which of the following physical security controls should be installed?

Cevabı ve açıklamayı göster

Cevap: Bollards

Cevap

Bollards are the physical security control designed specifically to prevent vehicle ramming and perimeter breaches by motor vehicles.
Bollards are heavy-duty vertical posts placed along perimeters, sidewalks, and building entrances specifically to block vehicles from driving into structures or secure grounds.

Adım Adım Çözüm

1
Analyze the threat identified in the scenario
The primary threat is vehicle impact or ramming into the building perimeter and main entrance.
Security measures must match the specific threat vector, which in this case is a vehicular collision.
2
Evaluate the function of physical security barriers
Bollards act as physical vehicle barriers capable of stopping or decelerating heavy motor vehicles.
Installing impact-resistant posts along building perimeters mitigates vehicle-borne entry or damage.

Anahtar Kavram

Physical Security Barriers and Vehicle Impact Protection
Tahmini Süre:45s
Soru 37Soru

A datacenter administrator is designing physical security controls for a ground-floor server room located immediately adjacent to a public parking lot. Compliance regulations mandate that the facility implement measures to prevent physical perimeter breaches caused by vehicle impacts, while also preventing unauthorized interception of high-frequency electromagnetic RF emissions originating from wireless testing hardware inside the facility. Which TWO of the following physical security controls should the administrator implement to satisfy these requirements? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Reinforced exterior steel bollards installed along the building perimeter line; A grounded Faraday cage enclosure integrated into the room's wall structure

Cevap

The administrator should implement reinforced exterior steel bollards along the perimeter to mitigate vehicle impacts and integrate a grounded Faraday cage enclosure into the wall structure to prevent electromagnetic RF signal leakage.
Implementing steel bollards along the exterior perimeter line creates a physical barrier capable of stopping moving vehicles from breaching the building wall. Installing a grounded Faraday cage within the room envelope creates an electromagnetic shield that attenuates and blocks radio frequency (RF) signals, preventing eavesdropping on wireless hardware emissions.

Adım Adım Çözüm

1
Identify the specific physical security threats defined in the scenario.
The scenario requires protection against two specific threat vectors: vehicular impact against ground-floor walls and electromagnetic RF signal interception.
Selecting appropriate physical security controls requires matching each control directly to the specific threat vector.
2
Evaluate physical barriers for kinetic impact defense.
Bollards are heavy vertical posts installed outside a facility designed specifically to stop vehicle ramming attacks.
Neither access control vestibules, cable locks, nor privacy screens offer structural kinetic protection against moving vehicles.
3
Evaluate signal containment controls for RF eavesdropping.
A Faraday cage utilizes grounded conductive enclosure materials to block electromagnetic emissions from escaping the server room.
Standard walls, privacy filters, and door access vestibules do not block or attenuate electromagnetic RF signal leakage.

Anahtar Kavram

Physical Security Controls (Bollards and Faraday Cages)
Tahmini Süre:2m 0s
Soru 38Soru

An IT security team must update physical security controls at a satellite office based on a recent vulnerability audit. The report mandates deploying controls to specifically address two vulnerabilities: preventing the physical theft of unattended desktop computers located in open work areas, and physically blocking unauthorized media insertion into unused Ethernet and USB ports on network switches. Which of the following physical security controls should the IT team deploy to fulfill these requirements? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Cable locks; Port locks

Cevap

Cable locks and port locks should be deployed to satisfy the audit requirements.
Cable locks physically tether workstation computers to stationary objects to mitigate theft in accessible work environments. Port locks are physical plugs inserted into empty USB or Ethernet ports that require a proprietary key to remove, preventing unauthorized physical access to network infrastructure.

Adım Adım Çözüm

1
Analyze the first requirement: preventing physical theft of unattended desktop computers in open areas.
Identify that cable locks (such as Kensington locks) tether the desktop chassis directly to desks or structural fixtures, preventing hardware theft.
Cable locks provide a direct physical restraint against unauthorized equipment removal.
2
Analyze the second requirement: physically blocking unauthorized media/connections into unused Ethernet and USB ports on network switches.
Identify that port locks plug into unused RJ-45 and USB sockets and require a specialized key to remove, blocking unauthorized physical connections.
Port locks secure open interface ports from unauthorized physical flash drive insertion or rogue device attachment.
3
Evaluate the non-selected options to confirm they do not satisfy either requirement.
Privacy filters address visual security, asset tags address tracking, and Faraday bags address RF shielding.
None of the alternative options physically anchor hardware or lock down network ports.

Anahtar Kavram

Physical Security Controls for Device Anchoring and Interface Locking
Tahmini Süre:2m 0s
Soru 39Soru

An executive assistant in the finance department receives an urgent email claiming to be from the company's Chief Executive Officer (CEO). The email states that the CEO is in an emergency board meeting and requires an immediate wire transfer to secure an acquisition, directing the assistant to enter corporate banking credentials into a provided link. A technician inspects the email header and notices the sender's domain uses a subtle typosquatting variation of the legitimate company domain. Which of the following social engineering threat types best describes this attack?

Cevabı ve açıklamayı göster

Cevap: Whaling

Cevap

Whaling
Whaling is a specialized spear phishing attack directed at high-level corporate executives or leveraging top executive impersonation to deceive employees into performing financial transactions or disclosing confidential information.

Adım Adım Çözüm

1
Analyze the attack vector and target.
The attack uses a fraudulent email impersonating a high-level executive (CEO) to target financial credentials and initiate wire transfers.
Identifying the target profile and delivery mechanism distinguishes general phishing from specialized targeted attacks.
2
Evaluate the social engineering classification.
Targeted phishing campaigns focused on executive roles or leveraging executive authority for financial gain are classified as whaling.
Whaling specifically describes spear phishing directed at or mimicking top corporate executives.

Anahtar Kavram

Whaling and Spear Phishing Attack Vectors
Soru 40Soru

An executive assistant receives an urgent email appearing to come directly from the Chief Executive Officer (CEO) requesting an immediate transfer of funds to a new vendor. Simultaneously, a system administrator discovers that employee web traffic intended for the corporate banking portal is being secretly redirected to a fake login page through altered local host files. Which of the following threat types are demonstrated in this scenario? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Whaling; Pharming

Cevap

Whaling and Pharming are the correct threat types.
Whaling accurately describes spoofing high-level executives to coerce employees into transferring funds. Pharming accurately describes corrupting host files or DNS settings to misdirect web traffic to spoofed websites.

Adım Adım Çözüm

1
Analyze the email attack vector targeting executive authorization.
Identify that impersonating executive leadership for fraudulent wire transfers is whaling.
Whaling targets or spoofs high-level executive positions to achieve high-impact malicious goals.
2
Analyze the network redirection method affecting web browsing.
Identify that modifying host files to secretly send users to a fraudulent banking site is pharming.
Pharming manipulates domain name resolution to hijack traffic without the user's explicit interaction with a malicious link.

Anahtar Kavram

Identifying executive-targeted phishing (whaling) and DNS/host-file web traffic misdirection (pharming).
ÖncekiSayfa 2 / 23Sonraki
Security Alıştırma Soruları — CompTIA A+ (Core 1 & Core 2) — Sayfa 2 | Examkin