Tüm alıştırma soruları

2232 soru

Soru 1981Soru

A multinational logistics enterprise is restructuring its security operations to satisfy data governance requirements. During an internal security management review, the audit team observes that database administrators (DBAs) are currently determining data sensitivity labels, authorizing access permissions, and establishing data retention schedules for supply chain relational databases. Executive leadership mandates that operational technical management must be separated from business data accountability. Which of the following structural adjustments best aligns with standard data governance role definitions?

Cevabı ve açıklamayı göster

Cevap: Designate business department heads as Data Owners accountable for establishing classification tiers and retention policies, while DBAs act as Data Custodians responsible for implementing technical controls and maintaining data integrity.

Cevap

Designate business department heads as Data Owners accountable for establishing classification tiers and retention policies, while DBAs act as Data Custodians responsible for implementing technical controls and maintaining data integrity.
The correct option properly distinguishes between business accountability and technical execution. The Data Owner is typically a business executive or manager who understands the business value of the data, determines sensitivity labels, defines access constraints, and sets retention requirements. The Data Custodian is a technical role (such as a DBA or system administrator) responsible for implementing technical controls, managing storage systems, maintaining backups, and enforcing the access rules defined by the Data Owner.

Adım Adım Çözüm

1
Analyze the organizational issue described in the scenario.
Database administrators (technical staff) are improperly exercising authority over business-level decision-making, such as classification and retention policy creation.
Effective data governance requires separation of duties between business decision-making and technical execution.
2
Evaluate data governance role definitions according to security management frameworks.
Data Owners hold ultimate business accountability for data classification, privacy requirements, and lifecycle rules. Data Custodians handle technical implementation, system administration, storage, and security control enforcement.
Matching administrative oversight to business leadership and technical implementation to DBAs satisfies standard governance models.
3
Select the option that correctly separates business accountability from technical administration.
Assigning business department heads as Data Owners and DBAs as Data Custodians properly aligns roles.
This structure ensures business aligned control over data sensitivity while leaving hands-on technical management to IT specialists.

Anahtar Kavram

Data Governance Roles (Data Owner vs. Data Custodian)
Soru 1982Soru

An enterprise security manager is defining an updated data governance and privacy enforcement framework to ensure compliance with global regulations. Match each data governance role or privacy mechanism on the left to its corresponding operational responsibility or functional objective on the right.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Data Owner
Data Custodian
Data Protection Officer (DPO)
Data Controller

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Data Owner pairs with defining classification and access requirements. Data Custodian pairs with implementing technical controls, key management, and backups. Data Protection Officer (DPO) pairs with privacy compliance oversight, DPIA evaluation, and supervisory liaison. Data Controller pairs with determining the purpose and legal basis for data processing.
The correct pairings accurately reflect standard governance frameworks. The Data Owner is accountable for data classification and policy setting. The Data Custodian implements technical protection mechanisms and manages daily system operations. The DPO provides regulatory oversight and leads privacy impact assessments. The Data Controller establishes the lawful purpose and parameters for personal data collection and processing.

Adım Adım Çözüm

1
Differentiate governance roles between operational execution, business accountability, legal entity status, and compliance oversight.
Identified that technical database administration tasks belong to the custodian, while policy determination belongs to the owner.
CompTIA Security+ requires clear separation of duties between technical implementation (custodian) and strategic business ownership (owner).
2
Map regulatory compliance and privacy oversight responsibilities.
Linked the Data Protection Officer (DPO) to DPIA reviews and independent regulatory communication.
Under privacy frameworks like GDPR, the DPO serves an advisory and monitoring function rather than executing technical maintenance.
3
Differentiate the Data Controller's legal role from internal data ownership.
Associated Data Controller with defining the legal basis and purpose for processing personal data.
The Data Controller establishes the processing objectives and compliance framework for personal data.

Anahtar Kavram

Data Governance Roles and Responsibilities
Soru 1983Soru

A financial technology enterprise is integrating a third-party analytical platform to evaluate customer payment trends. Legal and privacy compliance requirements state that Primary Account Numbers (PANs) transmitted to the external vendor must be replaced with random surrogate values that maintain no mathematical relationship to the underlying data. Additionally, internal billing microservices must maintain the ability to resolve these surrogate values back to the original PANs using an isolated, highly secure lookup database hosted on-premises. Which of the following privacy-enhancing controls best fulfills these requirements?

Cevabı ve açıklamayı göster

Cevap: Tokenization using a centralized token vault

Cevap

Tokenization using a centralized token vault is the correct privacy-enhancing control.
Tokenization generates random, non-mathematical surrogate characters (tokens) to replace sensitive data like PANs before exporting to third parties. Because the token cannot be derived mathematically from the original value, compromising the external analytics platform does not expose the underlying data. The enterprise retains the mapping in an isolated on-premises token vault, allowing internal microservices to securely re-identify accounts when required.

Adım Adım Çözüm

1
Analyze the technical requirements in the scenario
Identified the need for non-mathematical surrogate values (tokens) and reversible mapping via an isolated lookup database.
The requirement specifies sending non-sensitive placeholder values externally while retaining internal re-identification capability.
2
Evaluate Tokenization against hashing, masking, and anonymization
Tokenization replaces sensitive values with random tokens linked via a secure vault database, matching all requirements.
Unlike encryption or hashing, tokens carry no mathematical link to the payload, minimizing breach exposure on the third-party platform.
3
Differentiate between data governance roles and technical control mechanisms
Confirmed that reassigning ownership roles to third-party vendors is procedurally incorrect and technically ineffective.
The enterprise retains ultimate ownership and accountability for data privacy under governance standards like GDPR/PCI-DSS.

Anahtar Kavram

Tokenization and Data Privacy Enhancing Technologies
Soru 1984Soru

An enterprise organization is updating its data governance framework prior to launching a global customer analytics project. The Chief Risk Officer must formally segregate duties between executive business leads and technical operations staff. Which of the following duties are primary responsibilities of the Data Owner rather than the Data Custodian? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Determining data classification levels and approving user access authorization permissions; Defining data retention policy requirements and legal compliance purpose limitations

Cevap

Determining data classification levels, approving access rights, establishing retention requirements, and defining legal business purpose limitations are the direct responsibilities of the Data Owner. Technical safeguards, such as implementing storage encryption, executing backups, and configuring authentication mechanisms, are carried out by Data Custodians and system administrators.
Data Owners hold ultimate business accountability for data assets. Their duties include establishing sensitivity classification schemas, approving authorization requests, defining retention windows based on business or legal needs, and enforcing usage policy bounds. In contrast, Data Custodians handle technical execution such as implementing backup schedules, managing database storage controls, and maintaining infrastructure.

Adım Adım Çözüm

1
Analyze the core responsibilities of a Data Owner
Identify that Data Owners represent business leadership and are accountable for data classification, access governance, policy enforcement, retention criteria, and regulatory compliance.
Business data owners have organizational authority over data usage and regulatory adherence.
2
Analyze the core responsibilities of a Data Custodian
Identify that Data Custodians are technical personnel responsible for implementing and maintaining technical controls, backup operations, storage encryption, and daily maintenance mandated by Data Owners.
Custodians manage the operational structure and technical safeguards without deciding business policy.
3
Distinguish business ownership tasks from technical execution tasks
Classification tag determination, access authorization approval, retention rule setting, and business purpose definition belong to the Data Owner, while technical database configuration and identity integration belong to technical roles.
Clear segregation of duties prevents business decisions from being delegated to system administrators.

Anahtar Kavram

Data Owner vs. Data Custodian Responsibilities
Tahmini Süre:2m 0s
Soru 1985Soru

An international financial services company is preparing to share historical transaction records with an external research consortium. The privacy officer mandates that the dataset must be modified so that individual data subjects can no longer be identified by any direct or indirect means, even if the records are combined with outside data sources. Once applied, this technical transformation must render the dataset completely exempt from privacy regulation requirements (such as GDPR), permitting long-term retention for analytical study. Which of the following data protection controls should the security team implement to satisfy this mandate?

Cevabı ve açıklamayı göster

Cevap: Data anonymization

Cevap

Data anonymization is the correct control because it irreversibly transforms personal data so that re-identification is impossible, removing the dataset from the scope of privacy regulations.
Data anonymization irreversibly alters personal data so that the individual can no longer be identified directly or indirectly by any means reasonably likely to be used. Because anonymized data is no longer considered personal data, it falls entirely outside the scope of privacy regulations such as GDPR, allowing organizations to retain and process the dataset indefinitely without regulatory restrictions.

Adım Adım Çözüm

1
Analyze the regulatory compliance requirements for the research dataset.
The requirement specifies permanently removing the dataset from the scope of privacy regulations by ensuring re-identification is impossible by any reasonable means.
Regulations like GDPR exempt datasets only when the data can no longer be linked to an identifiable natural person.
2
Evaluate the available privacy-enhancing technologies against the requirement of non-reversibility.
Controls such as pseudonymization, tokenization, and dynamic data masking leave data linkable or reversible via additional information, vault lookups, or underlying storage.
Reversible or display-only obfuscation techniques leave the data subject to privacy regulations.
3
Select the control that achieves permanent, non-reversible identity removal.
Data anonymization irreversibly removes all direct and indirect identifiers, converting personal data into anonymous information.
Anonymized data is completely exempt from privacy laws and can be retained indefinitely without ongoing consent or regulatory burden.

Anahtar Kavram

Data Anonymization vs. Pseudonymization and Privacy Controls
Soru 1986Soru

A regional hospital network is deploying an automated Data Loss Prevention (DLP) system across its Electronic Health Record (EHR) databases. The database administration team has configured technical access controls, automated encrypted backups, and database audit logs. However, during a compliance audit, the team discovers that data sensitivity levels and user authorization baselines for custom health datasets were never formally defined or authorized. Which of the following responsibilities must be assigned to the Data Owner to resolve this compliance deficiency?

Cevabı ve açıklamayı göster

Cevap: Determining the data classification tier and approving business access authorization baselines for the dataset.

Cevap

Determining the data classification tier and approving business access authorization baselines for the dataset.
The Data Owner is a senior manager or executive accountable for the specific information asset. The Data Owner is responsible for determining data sensitivity classifications, establishing rules for data handling, and approving access authorization baselines. In this scenario, defining missing data sensitivity levels and authorizing access policies is the exclusive governance responsibility of the Data Owner.

Adım Adım Çözüm

1
Analyze the operational duties described in the scenario.
Identified technical tasks already completed (configuring access controls, running backups, audit logging) vs missing governance tasks (defining classification tiers, approving business access baselines).
CompTIA Security+ distinguishes between governance accountability (Data Owner) and technical implementation (Data Custodian).
2
Evaluate the specific role requirements of the Data Owner.
The Data Owner is the business executive or manager accountable for determining data classification, defining security requirements, and authorizing access permissions.
Technical custodians execute controls, but business owners hold accountability for dataset policy and classification.
3
Select the option that represents governance and classification authority.
Determining classification tiers and approving business access baselines aligns directly with Data Owner responsibilities.
This resolves the identified audit finding by establishing proper data governance authority.

Anahtar Kavram

Data Governance Roles: Data Owner vs. Data Custodian
Soru 1987Soru

An automotive software enterprise is establishing privacy and governance controls for its connected vehicle telematics platform, which collects driver location history and telemetry data. The Chief Information Security Officer (CISO) designates the Fleet Analytics Product Manager as the Data Owner and the Lead Database Administrator as the Data Custodian. Which of the following operational tasks are the primary responsibility of the Data Custodian? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Configuring role-based access control policies and implementing AES-256 storage encryption across database clusters hosting telemetry logs; Executing routine database backup routines, patch management, and monitoring storage integrity metrics

Cevap

Configuring access controls and storage encryption, along with executing routine database backups and maintenance, are technical tasks assigned to the Data Custodian.
The Data Custodian is responsible for the practical execution of security controls and operational maintenance of datasets. This includes applying technical controls like access policy configurations and storage encryption, as well as preserving data integrity and availability through routine backups and patching.

Adım Adım Çözüm

1
Identify the distinct governance roles defined in the scenario context.
The Product Manager holds ultimate business accountability as Data Owner, while the Database Administrator manages operational safeguards as Data Custodian.
Distinguishing strategic business ownership from technical operational custody is necessary to evaluate task delegation.
2
Evaluate technical implementation tasks against Data Custodian duties.
Tasks enforcing security controls—such as database encryption, role-based access rules, backup execution, and patch management—belong to the Data Custodian.
The Data Custodian is responsible for hands-on technical protection, storage, and maintenance of dataset infrastructure.
3
Evaluate administrative authority tasks against Data Owner duties to identify distractors.
Defining data classification levels and authorizing third-party data sharing permissions are business decision-making duties belonging to the Data Owner.
Data Owners determine data value, assign sensitivity labels, and decide who may access organizational data assets.

Anahtar Kavram

Data Owner vs. Data Custodian Responsibilities
Tahmini Süre:2m 0s
Soru 1988Soru

An e-commerce enterprise is updating its security governance framework to ensure compliance with international data protection regulations. During an internal audit, the security manager discovers that database administrators (DBAs) are currently responsible for setting data sensitivity classification tags, defining retention periods, and approving access permissions for customer profile databases. Which of the following actions should the organization take to align with data governance best practices?

Cevabı ve açıklamayı göster

Cevap: Reassign data classification authority and access approval decisions to business leaders acting as data owners, while retaining DBAs as data custodians responsible for technical controls.

Cevap

The organization should reassign data classification authority and access approval decisions to business leaders acting as data owners, while retaining DBAs as data custodians responsible for technical controls.
In enterprise security governance, data owners are business unit leaders or managers accountable for the data, defining its classification tier, setting retention policies, and approving access permissions. Data custodians (such as database administrators or system engineers) carry out technical implementation tasks, maintaining hardware, configuring database permissions, and running backups in accordance with the data owner's policies. Reassigning classification and authorization authority to business leaders restores proper separation of duties and administrative accountability.

Adım Adım Çözüm

1
Analyze the existing deficiency in the organizational data governance framework.
Identified that DBAs (technical personnel) are performing business governance functions like defining data sensitivity labels and approving access requests.
Technical personnel should manage infrastructure implementation, whereas business leadership understands data value and regulatory context.
2
Differentiate between the roles of Data Owner and Data Custodian.
The Data Owner is accountable for data classification, governance policy, retention rules, and access approval. The Data Custodian is responsible for technical execution (maintaining databases, applying access control lists, running backups).
Separation of duties ensures business accountability drives security policy while technical teams enforce technical safeguards.
3
Select the governance remediation action that aligns responsibilities correctly.
Transfer classification authority to business unit leaders (Data Owners) and maintain DBAs as technical implementers (Data Custodians).
This establishes clear accountability and ensures compliance with standard Security+ data governance frameworks.

Anahtar Kavram

Data Owner vs. Data Custodian Responsibilities
Tahmini Süre:1m 30s
Soru 1989Soru

A security analyst is categorizing corporate IT procedures according to the core components of the AAA framework. Match each operational scenario to the AAA component it primarily demonstrates.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

A remote employee enters a username, password, and a time-based one-time password (TOTP) from an authenticator app to log into the corporate VPN.
The network gateway checks an employee's group membership and grants read-only access to HR records while denying edit rights.
A syslog server records time-stamped entries detailing every database table queried during an administrator's remote database session.

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Matching credential verification to Authentication, permission enforcement to Authorization, and activity logging to Accounting.
Authentication handles proof of identity (passwords, multi-factor tokens). Authorization manages permission policies and resource boundaries (read/write rights based on roles). Accounting captures historical logs, metrics, and audit records of user actions.

Adım Adım Çözüm

1
Identify the purpose of credential verification (username, password, TOTP).
Confirming the user's identity corresponds to Authentication.
Authentication asks 'Who are you?' and validates claims with credentials.
2
Analyze the process of checking access rights and group policies for resource usage.
Restricting access levels based on roles corresponds to Authorization.
Authorization asks 'What are you allowed to do?' and enforces permissions.
3
Examine the function of recording timestamps and user queries into audit logs.
Tracking active usage and generating audit trails corresponds to Accounting.
Accounting asks 'What did you do?' and maintains records for tracking and auditing.

Anahtar Kavram

Core Pillars of Authentication, Authorization, and Accounting (AAA)
Soru 1990Soru

A system administrator is configuring access control for an enterprise network. Before a user is granted permissions to access sensitive network shares, the system must first verify who the user claims to be using a username and password. Which pillar of the Authentication, Authorization, and Accounting (AAA) framework is being performed during this initial identity verification step?

Cevabı ve açıklamayı göster

Cevap: Authentication

Cevap

Authentication
Authentication is the primary pillar of AAA responsible for verifying identity credentials (such as passwords, tokens, or biometrics) to confirm that a user is who they claim to be before granting access.

Adım Adım Çözüm

1
Analyze the scenario task
The system is verifying the user's claimed identity via username and password credentials.
Identifying who a user claims to be is the core purpose of authentication.
2
Map the task to the AAA framework components
Identity verification maps directly to Authentication.
Authorization specifies permissions and Accounting logs activities, whereas Authentication handles initial identity verification.

Anahtar Kavram

Authentication in the AAA Framework
Soru 1991Soru

A security architect for a regional energy utility is reviewing security mechanisms implemented across the smart grid infrastructure. Match each technical security control scenario on the left with the primary CIA Triad pillar or Non-Repudiation objective it satisfies on the right.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Substation operators must authenticate using individual hardware tokens to generate asymmetric digital signatures on remote circuit breaker tripping commands, preventing engineers from claiming an unauthorized shutdown command originated elsewhere.
Smart meter consumption telemetry transmitted over public wireless infrastructure is encrypted with AES-256-GCM to prevent unauthorized third parties from snooping on customer power usage patterns.
Firmware images distributed to remote terminal units (RTUs) incorporate cryptographic hash trees (Merkle trees) to verify that code has not been altered or corrupted prior to installation.
Control center supervisory networks employ redundant network paths, dual power supplies, and automatic failover clustering to ensure continuous operational visibility during hardware faults.

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

The operator authentication control with asymmetric digital signatures matches Non-Repudiation. Encrypting smart meter telemetry with AES-256-GCM matches Confidentiality. Firmware hash tree verification matches Integrity. Redundant paths and failover clustering match Availability.
Each technical scenario corresponds to a foundational security objective: asymmetric signing of commands provides Non-Repudiation by uniquely binding actions to individual operators; payload encryption protects customer usage privacy under Confidentiality; cryptographic hashing verifies unauthorized code modifications under Integrity; and system redundancy maintains uninterrupted operational access under Availability.

Adım Adım Çözüm

1
Analyze the hardware token and asymmetric signature control for tripping commands.
Digital signatures link specific commands to an individual's private key, establishing undeniable proof of origin.
Non-repudiation prevents an entity from denying an action or transaction performed.
2
Analyze the AES-256-GCM encryption of smart meter telemetry.
Encryption shields sensitive customer consumption data from unauthorized eavesdropping across public links.
Confidentiality ensures data is accessible only to authorized entities.
3
Analyze the cryptographic hash tree verification for RTU firmware.
Hashing confirms that the firmware payload remains unaltered from its original authorized state.
Integrity guards against improper data modification or destruction.
4
Analyze the redundant network paths and automatic failover architecture.
High-availability controls prevent single points of failure from causing system downtime.
Availability ensures timely and reliable access to and use of information.

Anahtar Kavram

Core Security Goals (CIA Triad and Non-Repudiation)
Soru 1992Soru

A cloud operations team configures an automated logging mechanism to record high-privilege configuration changes across production servers. The system computes a Hash-based Message Authentication Code (HMAC) for each log entry using a single symmetric key shared among all system administrators. Following an unauthorized system modification, an administrator denies executing the change, claiming that any user with access to the shared key could have forged the log entry. Which of the following security goals failed to be established by this logging design?

Cevabı ve açıklamayı göster

Cevap: Non-repudiation

Cevap

Non-repudiation is the security goal that failed to be established because shared symmetric keys cannot uniquely trace an action to a specific individual.
Non-repudiation provides indisputable proof of the origin and integrity of data such that the sender/creator cannot deny having performed the action. When symmetric keys are shared among multiple users (such as in standard HMAC implementations), any holder of the key can generate valid message authentication codes. As a result, individual attribution is lost, preventing the establishment of non-repudiation. Digital signatures utilizing asymmetric cryptography (where each user holds a unique private key) are required to achieve non-repudiation.

Adım Adım Çözüm

1
Analyze the technical control used in the scenario.
The logging system uses a Hash-based Message Authentication Code (HMAC) with a shared symmetric key.
Symmetric cryptography uses the same key for generation and verification across all authorized parties.
2
Evaluate the security guarantees of the control.
HMAC provides data integrity and proof that someone possessing the secret key created the log, but it cannot identify which specific user signed it.
Because all system administrators possess the identical symmetric key, any administrator could have produced the valid signature.
3
Map the limitation to the corresponding core security principle.
Inability to prove individual accountability means non-repudiation is lost.
To achieve non-repudiation, asymmetric cryptography (such as private key digital signatures) must be used so that only one unique individual could have authored the entry.

Anahtar Kavram

Non-Repudiation vs Integrity in Cryptographic Controls
Soru 1993Soru

An enterprise security architect is mapping operational security controls to primary security principles within a multi-tier datacenter deployment. Match each operational control on the left with the corresponding core CIA Triad or Non-Repudiation goal on the right.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Enforcing AES-256 full disk encryption on database storage volumes holding sensitive client records
Verifying SHA-256 cryptographic checksums of software installation packages prior to deployment
Deploying redundant uninterruptible power supply (UPS) units and automated backup generators
Requiring system administrators to digitally sign security policy updates using individual asymmetric private keys

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Full disk encryption corresponds to Confidentiality. Cryptographic checksum verification corresponds to Integrity. Redundant power systems correspond to Availability. Asymmetric digital signatures on administrative updates correspond to Non-Repudiation.
Each operational control serves a specific primary security pillar: encryption prevents unauthorized viewing (Confidentiality), checksum comparison ensures data remains unaltered (Integrity), redundant power infrastructure maintains continuous service uptime (Availability), and asymmetric key signatures cryptographically tie an operation to a specific actor so they cannot deny performing it (Non-Repudiation).

Adım Adım Çözüm

1
Analyze the primary objective of each listed technical or operational control.
Encryption obscures data from unauthorized eyes; checksums detect unauthorized changes; power redundancy prevents service outage; digital signatures bind actions to a specific identity.
Understanding the security function of each control is necessary before categorizing it within foundational security frameworks.
2
Map each control objective to its foundational security pillar.
Obscuring data maps to Confidentiality; detecting alterations maps to Integrity; preventing outages maps to Availability; binding identity to an immutable action maps to Non-Repudiation.
This completes the precise alignment between implementation mechanisms and security principles.

Anahtar Kavram

CIA Triad and Non-Repudiation
Soru 1994Soru

An energy distribution company is upgrading its remote terminal unit (RTU) fleet across regional sub-stations. The security engineering team must implement a mechanism for over-the-air (OTA) control command execution. The system must guarantee that once a lead control engineer issues a high-voltage switching instruction, the engineer cannot later deny having authorized the command, and the RTUs can verify both origin authenticity and data integrity. Which of the following technical controls best satisfies this security requirement?

Cevabı ve açıklamayı göster

Cevap: Digitally signing the command payload using the lead control engineer's private key

Cevap

Digitally signing the command payload using the lead control engineer's private key
Digitally signing the payload with a private key provides non-repudiation because only the private key owner could have generated the signature. Anyone with the corresponding public key can verify integrity and authenticity, preventing the sender from denying their action.

Adım Adım Çözüm

1
Analyze the core security requirement stated in the scenario.
The requirement asks for origin authenticity, integrity, and non-repudiation (ensuring the author cannot deny issuing the command).
Identifying the required security objective isolates asymmetric digital signatures from simple hashing or symmetric encryption solutions.
2
Evaluate cryptographic mechanisms against the non-repudiation property.
Only asymmetric cryptography (where only the signer holds the private key) provides non-repudiation. Symmetric mechanisms (HMAC/AES) rely on shared keys, allowing either party with the key to produce the payload.
If keys are shared, proof of specific authorship is lost, failing the non-repudiation requirement.

Anahtar Kavram

Non-Repudiation through Asymmetric Digital Signatures
Tahmini Süre:1m 15s
Soru 1995Soru

During a security audit of an enterprise infrastructure, a analyst discovers that network administrators authenticate via a central RADIUS server using multi-factor authentication (MFA). However, once authenticated, any administrator gains full privileged access across all routers and switches, and individual command executions are not recorded in audit logs. The CISO mandates an updated architecture that enforces granular, role-based command execution limits and records every individual command invoked during administrator sessions. Which protocol migration and AAA pillar focus directly fulfills the CISO's mandate?

Cevabı ve açıklamayı göster

Cevap: Migrate from RADIUS to TACACS+ to separate AAA functions, leveraging TACACS+ per-command authorization for granular command restrictions and TACACS+ accounting for individual command auditing.

Cevap

Migrate from RADIUS to TACACS+ to separate AAA functions, leveraging TACACS+ per-command authorization for granular command restrictions and TACACS+ accounting for individual command auditing.
TACACS+ decouples authentication, authorization, and accounting into distinct processes. In administrative device management scenarios, TACACS+ allows every single command entered by an administrator to be sent to the AAA server for authorization before execution, while recording precise per-command accounting logs to satisfy compliance and audit mandates.

Adım Adım Çözüm

1
Analyze the existing deficiency in the AAA architecture
The current RADIUS deployment provides Authentication (verifying identity via MFA) but lacks granular Authorization (restricting specific commands per role) and detailed Accounting (logging individual commands).
RADIUS binds authentication and authorization together and does not support command-by-command evaluation.
2
Evaluate protocol features for administrative device management
TACACS+ separates all three AAA components and operates over TCP (port 49), allowing individual command authorization requests and detailed per-command accounting logs.
TACACS+ is specifically designed for enterprise administrator management of network device shells.
3
Select the control solution that directly fulfills both requirements of the mandate
Transitioning to TACACS+ enables per-command authorization (role-based limits) and per-command accounting (audit recording).
This directly completes the missing Authorization and Accounting pillars required by the scenario.

Anahtar Kavram

Authentication, Authorization, and Accounting (AAA) Protocol Differences (RADIUS vs TACACS+)
Tahmini Süre:2m 0s
Soru 1996Soru

A cloud compliance team is configuring an automated log aggregation vault to collect audit trails from independent third-party SaaS vendors. The organization mandates two primary security requirements for all ingested logs: first, the vault must be able to prove that a log file was not modified after creation; second, the log file must provide non-repudiation, ensuring that an untrusted vault administrator who possesses read access cannot forge a valid log entry on behalf of any vendor. Which of the following cryptographic techniques should each vendor apply to the log files prior to transmission to meet all audit requirements?

Cevabı ve açıklamayı göster

Cevap: Sign the log file using the vendor's private key to generate an asymmetric digital signature appended to the payload.

Cevap

The correct technique is signing the log file using the vendor's private key to generate an asymmetric digital signature.
Generating an asymmetric digital signature by hashing the log file and encrypting the hash digest with the vendor's private key guarantees both integrity and non-repudiation. Anyone can verify the signature using the vendor's public key, but no one—including the untrusted vault administrator—can forge a valid signature without access to the vendor's private key.

Adım Adım Çözüm

1
Analyze the security requirements specified in the scenario
Identified the need for both data integrity (detecting post-creation modifications) and non-repudiation (preventing an untrusted vault administrator with key access from forging log entries).
Non-repudiation requires asymmetric cryptography where only the producing entity possesses the signing key.
2
Evaluate symmetric vs. asymmetric cryptographic primitives for proof of origin
Symmetric primitives (like HMAC with shared keys) allow any key holder to generate valid tags, failing non-repudiation. Asymmetric digital signatures (private key signing, public key verification) ensure only the private key owner can produce valid signatures.
The vault administrator cannot forge signatures without the vendor's private key.
3
Select the option fulfilling both integrity and non-repudiation
Digitally signing the log payload using the vendor's private key fulfills all stated audit and security criteria.
Verification using the vendor's public key confirms both that the file was unchanged and that it originated from that specific vendor.

Anahtar Kavram

Digital Signatures and Non-Repudiation
Soru 1997Soru

An IT security administrator is implementing the Authentication, Authorization, and Accounting (AAA) framework for remote access connections. Which of the following tasks directly represent the Accounting component of AAA? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Logging user session duration and total network data volume transferred; Recording login timestamps and authentication attempt outcomes in an audit repository

Cevap

Logging user session duration and total network data volume transferred, and recording login timestamps and authentication attempt outcomes in an audit repository.
Accounting focuses on tracking user activity, auditing actions, and measuring resource consumption such as connection duration, transferred bytes, and login history logs.

Adım Adım Çözüm

1
Define the primary responsibility of each AAA pillar
Authentication verifies identity, Authorization determines permissions, and Accounting logs actions, session metrics, and audit histories.
Understanding the distinct boundaries of AAA components allows proper classification of administrative tasks.
2
Evaluate each task option against the Accounting definition
Logging resource usage (session length, byte counts) and keeping audit logs (login timestamps) fall under Accounting. Credential verification falls under Authentication, while permission enforcement falls under Authorization.
Accounting is explicitly responsible for telemetry, data tracking, and historical audit trails.

Anahtar Kavram

Authentication, Authorization, and Accounting (AAA) - Accounting Functions
Soru 1998Soru

An enterprise security engineer is auditing a network management infrastructure after migrating remote administrator access to a centralized access control server. Network switches correctly validate administrator credentials against Active Directory and log the total session connection time and byte counts. However, security audits reveal that individual privilege-escalation commands (such as entering configuration modes) executed during active switch sessions are neither restricted based on administrator roles nor recorded in detailed command audit logs. Which of the following best explains why session-level authentication and accounting succeed while command-level authorization and accounting fail?

Cevabı ve açıklamayı göster

Cevap: The deployment relies on RADIUS, which combines authentication and authorization into single transactions and lacks native support for granular per-command authorization and accounting.

Cevap

The deployment relies on RADIUS, which combines authentication and authorization into single transactions and lacks native support for granular per-command authorization and accounting.
The correct answer identifies that RADIUS combines authentication and authorization into a single transaction during initial connection setup. Because RADIUS is designed primarily for network level access (such as 802.1X, VPNs, and wireless connections), it lacks native support for real-time, per-command authorization and individual command accounting logs. TACACS+ would be required to restrict and audit specific command execution on network infrastructure devices.

Adım Adım Çözüm

1
Analyze the scenario symptoms
Initial session authentication succeeds, session duration/volume accounting succeeds, but command-level authorization and individual command logging fail.
Different AAA protocols handle session management and command-level granularity differently.
2
Compare RADIUS and TACACS+ AAA capabilities
RADIUS (UDP 1812/1813) combines authentication and authorization into a single step and is designed primarily for network access control (IP assignment, VLAN tag, session accounting). TACACS+ (TCP 49) separates AAA into discrete processes and allows granular authorization of individual commands as well as auditing of each command entered.
Understanding protocol differences reveals why RADIUS cannot enforce or audit per-command administrative actions.
3
Select the root cause matching the protocol limitation
The organization is using RADIUS for switch administration, which supports initial session authentication and basic session accounting, but cannot enforce command-level authorization.
Migrating switch management requiring command authorization from RADIUS to TACACS+ is necessary to achieve command-level auditing and restriction.

Anahtar Kavram

AAA Protocol Capabilities (RADIUS vs. TACACS+)
Tahmini Süre:2m 0s
Soru 1999Soru

A financial organization is implementing a centralized enterprise API gateway to handle high-value B2B fund transfers with external corporate partners. The security team must ensure that once a corporate partner transmits a payment request, they cannot plausibly claim the request was forged or sent by an unauthorized party. Which of the following technical controls directly support non-repudiation for these payment requests? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Requiring senders to digitally sign payment payloads using their organization's private cryptographic key; Validating sender digital certificates against a mutually trusted Public Key Infrastructure (PKI) Certificate Authority

Cevap

Non-repudiation for payment transactions is directly supported by requiring senders to digitally sign payment payloads using their asymmetric private key and by validating sender certificates against a trusted Public Key Infrastructure (PKI) Certificate Authority.
Non-repudiation ensures that a sender cannot dispute the authenticity of a message or transaction they originated. This security goal requires combining proof of origin with proof of integrity. Digitally signing payloads with an asymmetric private key guarantees that only the key owner could have signed the request. Validating the sender's identity certificate via a trusted Public Key Infrastructure (PKI) binds that key to a verified identity, completing the non-repudiation chain.

Adım Adım Çözüm

1
Identify the core security requirement specified in the scenario.
The requirement calls for preventing a sending organization from denying having originated or authorized a payment request, which defines non-repudiation.
Non-repudiation combines authentication of origin with data integrity to ensure actions cannot be denied.
2
Evaluate mechanisms that provide attribution of identity to a specific sender.
Asymmetric digital signatures created with the sender's private key uniquely identify the sender. PKI certificate validation confirms that the sender's public key maps to a verified organization.
Asymmetric cryptography and PKI trust chains satisfy non-repudiation by linking cryptographically signed content to an verified identity.
3
Distinguish non-repudiation controls from integrity verification and symmetric encryption.
Hashing only proves integrity (data was not altered), not identity. Symmetric encryption uses a shared key known to both receiver and sender, preventing unambiguous proof of who created the message.
Integrity checks and symmetric encryption lack unique origin proof.

Anahtar Kavram

Non-Repudiation and Asymmetric Cryptography
Soru 2000Soru

An organization installs a new physical access control system at the entrance of its data center. When an employee presents a smart card and enters a personal identification number (PIN), the system checks these credentials against the central directory to verify who the employee is before unlocking the door. Which component of the Authentication, Authorization, and Accounting (AAA) framework is being directly performed during credential verification?

Cevabı ve açıklamayı göster

Cevap: Authentication

Cevap

Authentication is the pillar of AAA responsible for verifying a user's or system's claimed identity using credentials like a smart card and PIN.
Verifying user credentials (such as a smart card and PIN) against a directory server confirms the user's identity, which is the exact function of authentication in the AAA security model.

Adım Adım Çözüm

1
Identify the primary action taking place in the scenario.
The system receives a smart card and PIN to confirm that the person attempting entry is indeed who they claim to be.
Verifying claimed identity using authentication factors (something you have + something you know) is the core definition of identity verification.
2
Map the identity verification process to the correct AAA framework pillar.
Confirming identity corresponds directly to Authentication.
Authentication answers the question 'Who are you?', while Authorization answers 'What are you allowed to do?' and Accounting answers 'What did you do?'.

Anahtar Kavram

Authentication in the AAA Framework
ÖncekiSayfa 100 / 112Sonraki
Tüm alıştırma soruları — CompTIA Security+ | Examkin