Browse all practice questions for the CompTIA Security+ (SY0-601) Certification Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

CompTIA Security+ (SY0-601) Certification Practice Test 2026 – The Complete Guide to Exam Success! course image
More practice questions

These questions are part of the practice quiz. Start practicing

  • What should a security administrator implement to prevent unauthorized program installations by users with administrative access?
  • What is a common practice to ensure the integrity of data during application development?
  • What is the best approach to manage security and customer privacy when a sales department uses mobile devices?
  • In the context of risk management, what does RPO stand for?
  • In a forensics investigation, which type of file is most useful for understanding what was in the memory of a compromised server?
  • What type of penetration testing involves testers only having access to customer documentation?
  • What is the primary purpose of a risk register?
  • What is the primary goal of a disaster recovery plan?
  • Which security standard must a company comply with to accept credit card payments on its e-commerce platform?
  • Which organizational policies are MOST likely to help in detecting fraud conducted by existing employees?
  • What is the MOST likely root cause for stolen corporate credit cards reported by a bank?
  • Which access control scheme allows an object's access policy to be determined by its owner?
  • When selecting a technical solution for identity management, changing from in-house to a third-party SaaS provider exemplifies which risk management strategy?
  • When addressing the presence of unapproved devices on a wireless network, which action should be taken in addition to enabling MAC filtering?
  • What type of testing should be performed to ensure a web application can handle unexpected input without crashing?
  • What type of social-engineering attack is conducted by creating a fake website to trick users into providing personal information?
  • What is the most likely cause of a user experiencing pop-ups and spam after receiving digital promotional materials?
  • What is the primary goal of an incident response plan?
  • What is the best method for mitigating the risk of employees working from high-risk countries while maintaining work flexibility?
  • What control is likely recommended for restricting access to certain network segments using data-link layer security?
  • During an investigation, what should a technician do to maintain the chain of custody for a mobile device?
  • Which of the following is an example of a reconnaissance attack?
  • Which risk management strategy involves using cybersecurity insurance?
  • What type of attack is likely responsible for multiple failed logins before a successful entry occurs?
  • What is the BEST mitigation strategy to prevent an attack detected in web logs?
  • An organization’s RPO is two hours with critical system usage from 9:00 am to 5:00 pm. What is the best backup implementation to meet this requirement?
  • Which method is BEST for creating a detailed diagram of wireless access points and hot-spots?
  • Which method allows for the use of functional test data in new systems while protecting sensitive information?
  • Which type of attack is MOST likely being detected by an Event Viewer message stating, "Special privileges assigned to new login"?
  • Which biometric technology might be used for identifying passengers without any prior enrollment at border checkpoints?
  • Which ISO standard is certified specifically for privacy?
  • For an organization with low tolerance for user inconvenience, which solution is MOST acceptable to protect against data theft on laptop hard drives?
  • What should an IT administrator do FIRST after recovering from a ransomware attack to prevent future incidents?
  • What type of protection can prevent unauthorized information disclosure through encryption?
  • What type of attack is most likely causing a wireless network performance issue at a public location, as inferred from Wireshark output?
  • In response to a data breach, what immediate action should be taken?
  • A security engineer enhances MFA access with a key card and fingerprint scan. What would add another factor of authentication?
  • A Chief Security Officer (CSO) is concerned about the amount of PII stored locally on salespersons' laptops. Which recommendation would BEST address the CSO's concern?
  • In which scenario would a DNS sinkhole be effective in preventing an attack?
  • What preventative measure could have MOST likely stopped a data breach caused by an executive charging a phone in a public area?
  • What must be less than 12 hours to maintain a positive total cost of ownership for manufacturing equipment?
  • After a ransomware attack, a forensics company needs to review a cryptocurrency transaction between the victim and the attacker. What will the company MOST likely review to trace this transaction?
  • What solution should a network administrator implement to improve network security by blocking malicious traffic and stopping network-based attacks?
  • What recommendation would BEST mitigate the impact of a worm infection across the network in the future?
  • What is a crucial step to take when hardening a smart switch installed in a hospital?
  • What do we call a security exploit with no vendor patch readily available?
  • An organization wants to improve its security posture by installing an IDS. What type of control is an IDS categorized as?
  • Some laptops recently went missing from a locked storage area protected by RFID-enabled locks. The employee who unlocked the door was on vacation. What MOST likely occurred?
  • What is the primary purpose of using a mantrap in physical security?
  • Which technology is best for centralizing logs to create a security baseline?
  • What is the primary benefit of using automated threat intelligence tools in a security posture?
  • Which account policy would best prevent unauthorized access shown by logins from vastly different geographical locations?
  • Which protocol should a network administrator use to ensure integrity encryption and authentication for a site-to-site VPN utilizing IPSec?
  • What is a common characteristic of data bias in machine learning?
  • A network administrator notices web pages are experiencing long load times. After confirming it's not a routing issue, which condition is the router MOST likely experiencing?
  • What is the primary goal of a penetration test?
  • A university experiences recurring Internet connectivity outages. This situation is characterized by which types of attacks?
  • To defend against potential API attacks, what is the best strategy for an organization?
  • To comply with PCI DSS, what should a security manager primarily focus on?
  • Which RAID configuration is best suited for high read speeds and fault tolerance, with low risk of multiple drive failures?
  • Which configuration provides the greatest security benefit for devices used internationally by staff who travel extensively?
  • What factors are MOST critical for the live acquisition of data during forensic analysis?
  • What component forwards logs to a central source for analysis in a security strategy?
  • Which solution should a security administrator implement to reduce time spent on common security tasks without increasing staff?
  • What does the process of code-execution testing, black-box testing, and non-functional testing BEST describe?
  • What MDM configuration must an engineer consider when traveling with a corporate-owned mobile device that prohibits personal data?
  • To prevent other devices on the network from accessing a laptop using public WiFi, which two solutions would be most effective?
  • What service would BEST meet the requirement for securely transferring files while authenticating both the IP header and the payload?
  • What is the best solution for a company looking to implement a BYOD policy to protect company information?
  • Why would a server administrator place a document named password.txt on their desktop?
  • A symmetric encryption algorithm is best suited for which purpose?
  • Which approach can be used to enforce security policies on employees’ personal devices accessing corporate networks?
  • Which measure is crucial to preventing data breaches in mobile devices?
  • A security analyst notices a high number of errors in a fingerprint scanner's access logs. What is the MOST likely cause of access issues?
  • What type of plan is an organization likely developing in response to a total loss of critical systems and data?
  • Which solution would BEST communicate to the leadership team the levels of the organization's vulnerabilities?
  • In a cloud environment, what type of technology helps in managing and mitigating data loss across diverse platforms?
  • Which technique uses a fake website to lure users into providing sensitive information?
  • Which two strategies would best enhance resiliency and uptime in a new datacenter?
  • What is the primary purpose of a security policy?
  • Which type of attack involves redirecting users to a fraudulent website?
  • What is an effective method to prevent data leakage in a company using cloud services?
  • Which approach is recommended to educate employees about security threats?
  • Which security practice would have addressed unauthorized access to accounts after an executive departure?
  • Which measure should be implemented to reduce risks for remote users accessing company resources from unauthorized locations?
  • What protocol should be implemented to authenticate the entire packet in a VPN configuration?
  • Which of the following is a recommended practice for ensuring secure password storage?
  • Which network attack is the researcher MOST likely experiencing if they receive a connection issue while using SSH?
  • What is the primary concern of the company when they clean whiteboards and clear desks before a tour?
  • The process of passively gathering information prior to launching a cyberattack is called?
  • What term refers to applications and systems used within an organization without consent or approval?
  • Which type of security tool is known for analyzing network traffic and highlighting anomalies?
  • What is the BEST way for a security analyst to analyze a potentially malicious document without executing it?
  • What is the purpose of employing compensatory controls for less secure devices in a heterogeneous MDM strategy?
  • What principal risk does application whitelisting mitigate in an organization?
  • To quickly check the validity of an SSL certificate, which method provides the fastest results?
  • Which resource would be the best for determining the priority order for upgrading the wireless infrastructure in an office?
  • A network administrator is setting up wireless access points in all the conference rooms and wants to authenticate devices using PKI. Which of the following should the administrator configure?
  • A security analyst notices a particular account attempting to transfer large amounts of money on a web server. Which of the following types of attack is MOST likely being conducted?
  • In risk management, what does the strategy 'risk transference' involve?
  • Which process is BEST described as bringing all code changes from multiple team members into the same development project through automation?
  • Which technology should be used for non-disruptive and user-friendly MFA implementation?
  • A user receives an SMS that asks for bank details. Which social-engineering technique was used?
  • What is the primary purpose of an intrusion detection system (IDS)?
  • Which security framework evaluates risks based on the likelihood of threats targeting vulnerabilities?
  • What is the likely cause of multiple end users downloading files with the .tar.gz extension without consent?
  • When configuring a vulnerability scanner for a global organization, what is the BEST way to mitigate the risk of unauthorized access to service accounts?
  • Which method would help identify potential vulnerabilities on hosted web servers running outdated software?
  • What would most likely help mitigate phishing and spear-phishing attacks within a company?
  • What is the most likely type of attack that occurred when a user entered their credentials into a forged recruiting application website?
  • What is the MOST effective measure to mitigate vulnerabilities in an outdated process control terminal?
  • What is the most effective solution for providing security and visibility into multiple SaaS and IaaS platforms?
  • Which method is the best way to store credit card numbers for easy reordering on an e-commerce website?
  • A company experiences frequent data breaches. Which strategy focuses on proactive identification of vulnerabilities?
  • An administrator needs to capture an exact copy of an employee's hard disk who is suspected of emailing proprietary information. What should the administrator use?
  • What security feature allows organizations to provide single sign-on access while ensuring user password security?
  • A security analyst is reviewing historical logs for specific activities outlined in a security advisory. What is the analyst doing?
  • Which type of attack is indicated by millions of half-open connections to port 443 from various source IPs?
  • Which activity involves identifying and examining unusual network patterns potentially indicating an attack?
  • If a possible breach occurred, what should the network security manager review first?
  • What is the primary goal of a business continuity plan regarding equipment downtime?
  • Which cloud service model provides clients with servers, storage, and networks only?
  • A user reported being prompted for a name and password after connecting to the corporate wireless SSID and is now facing unauthorized transactions. What attack vector was MOST likely used?
  • To prevent a Remote Access Trojan (RAT) from being reinstalled, which recommendation should be prioritized?
  • What method best describes how an attacker compromised a laptop according to SIEM logs?
  • What risk does a company face by allowing users to select mobile devices from multiple vendors?
  • When negotiating with a new vendor, what should be included to address response times to major incidents?
  • Which type of server is most likely to assist in recovering logs that were deleted by a privileged user?
  • Which of the following scenarios BEST describes a risk reduction technique?
  • An attacker has exfiltrated password hashes. Which type of password attack is this?
  • What social-engineering technique is being used if a CFO receives a fraudulent email requesting a money transfer?
  • What is the primary function of Network Intrusion Prevention Systems (NIPS)?
  • What is the most recommended action to prepare for the eradication of compromised accounts and computers?
  • Which of the following best describes a 'brute-force attack'?
  • What represents a threat where professors place unauthorized servers on a university network?
  • What should be performed to securely store a duplicate copy of a CEO's hard drive for forensic processes?
  • What action should a security team take to prevent hackers from invoking command-line interpreters using native administrative tools?
  • After a data breach, what is the best practice to ensure users' credentials remain secure during a reset?
  • What is the primary reason an appliance may remain vulnerable despite previous assessments?
  • During an incident response, which type of attack is best described by a log entry indicating unauthorized script execution on a web page?
  • Which training activity would be most suitable for enhancing the skill levels of a company's developers?
  • Which measure is least effective against physical intrusions?
  • Upon reviewing log files, what indicates that a directory-traversal attack has occurred?
  • A security auditor is reviewing vulnerability scan data. Which of the following BEST indicates that valid credentials were used during the scan?
  • What technology allows for the separation of different network segments to improve security?
  • Which command should a security analyst use to securely forward public keys to remote systems?
  • Which two technologies are being utilized to allow users to access their desktop and information systems across thin clients with smart cards?
  • In which situation is it BEST to use a detective control type for mitigation?
  • What is the most likely source containing data on applications and files open before a user's computer was forcibly shut down?
  • For a company that handles sensitive data, which access control model is BEST to implement for data protection?
  • What can a security analyst conclude if a SIEM alert indicates a login to a test account used for early attack detection?
  • What should the Chief Security Officer implement to enhance resilience against ransomware attacks?
  • An attacker is exploiting a vulnerability that does not have a patch available. What is this type of vulnerability called?
  • What activity is being conducted when a cybersecurity manager holds meetings to discuss hypothetical responses to cyberattacks?
  • A CCTV camera that is not monitored falls into which category of security controls?
  • For a small company looking to improve its security posture, what solution is the best option?
  • In monitoring an industrial system, which mitigation strategy is BEST for alerts while ensuring operational security?
  • In reviewing logs, what type of attack could a security analyst be observing if there are indications of repeated failed authentication attempts?
  • Which method would BEST detect the presence of a rootkit in future incidents?
  • Which of the following is a primary goal of threat containment during an incident response?
  • Which of the following vulnerabilities is MOST likely to adversely impact unpatched programmable-logic controllers and OT systems accessible over the Internet?
  • Which solution is best for providing security and manageability in a multi-cloud environment?
  • In a network assessment, which is a common indicator of a successful brute-force attack?
  • Which of the following provides the BEST protection for sensitive information stored in cloud-based services while allowing data functionality?
  • Which type of attack is characterized by executing unauthorized scripts in the web browser of users?
  • Which environment is most suitable for assessing the impacts of database migrations using the final version of code?
  • Which form of attack involves exploiting vulnerabilities in a user's trust in a trusted source?
  • In a network security design where traffic is routed through a VPN, which element is the WEAKEST in ensuring data protection?
  • Which cloud model would BEST meet an organization's need to move from an on-premises email solution to a cloud-based one?
  • Which tactic would an attacker MOST likely use when company engineers participate in a public Internet forum?
  • Which of the following describes the ability of code to target a hypervisor from inside?
  • Which policy would help identify and mitigate single points of failure in IT operations?
  • What combination of approaches provides the most secure form of two-factor authentication?
  • What is the best way to enhance security on a Linux server after purchasing a new PAM solution?
  • Which of the following will MOST likely cause machine learning and AI-enabled systems to operate with unintended consequences?
  • Which application attack is being tested if the URL shows a session ID after clicking a link?
  • What is a significant reason to use automated tools for code validation in the development process?
  • What type of intelligence source should a security analyst review to understand potential attacks on executives?
  • Who is responsible for applying encryption to a data set on a hard disk?
  • Which job role sponsors data quality and ensures regulatory requirements are met?
  • What is the best approach to securing environmental systems from unauthorized access through a compromised staff WiFi network?
  • What type of agreement is BEST for organizations that want to cooperate without creating binding contractual obligations?
  • What is the most likely cause of wireless connectivity issues occurring near the parking lot of a building?
  • What is a significant characteristic of an evil twin attack?
  • What can security administrators use to assess system configurations against compliance baselines?
  • What does segmentation help achieve in network security?
  • What is the best solution for ensuring always-available connectivity for an online business during outages?
  • What is the BEST document to establish responsibilities and monetary penalties for managing third-party risk?
  • Which of the following is an example of a common method of establishing secure communication over a network?
  • What scan type produces the BEST vulnerability scan report for periodic assessments of production systems?
  • What physical security measure is best to prevent unauthorized entry?
  • If an attacker is using a zero-day exploit, what does this imply?
  • If a company’s username and password database was posted publicly in plain text, which action would best help mitigate future data exfiltration risks?
  • After a security issue with website access, what attack most likely occurred on the original DNS server?
  • What is an important function of a security control matrix?
  • A company moving its operations to the cloud wants to prevent users from downloading company applications for personal use and has visibility into which applications are being used. What solution will BEST meet these requirements?
  • What type of authentication does an administrator provide when they combine a password with a gesture on a touchscreen?
  • What should a CISO read and understand to create a data privacy policy?
  • Which tool will a security administrator MOST likely use to confirm unnecessary services running on a server?
  • What action should a security engineer take to prevent data exfiltration through cracked passwords in the future?
  • Which cloud service model offers software applications over the Internet without direct management by the user?
  • What solution can help ensure availability of point-of-sale systems during peak sales periods?
  • What is a common method to ensure the confidentiality of data within a secure lab environment that is not connected to external networks?
  • Which administrative control would most effectively reduce malware execution occurrences?
  • Which of the following BEST describes the type of attack indicated by the given logs?
  • What is the role of a risk assessment in an organization's security posture?
  • What is a key security implication of using a heterogeneous device approach in mobile device management (MDM)?
  • Which of the following is a fundamental concept of network segmentation?
  • From which source did an alert about PII being sent via email MOST likely originate?
  • Which RAID level should a cybersecurity administrator select to achieve two-drive redundancy for fault tolerance?
  • What is the greatest risk to intellectual property that led to the implementation of conductive metal lockboxes for personal devices?
  • Which of the following, when used at the design stage, improves the efficiency, accuracy, and speed of a database?
  • Which component of network security is responsible for ongoing data protection and management?
  • What is one benefit of implementing containerization in a BYOD environment?
  • Which of the following attacks is likely associated with changes made to a vendor’s IP address during an investigation?
  • What forensic technique should be used to ensure the admissibility of evidence when authorities are collecting evidence for fraud?
  • What technique explains the addition of randomly generated data to passwords for secure storage?
  • Which technical control is best suited for detecting and preventing buffer overflows?
  • A commercial cyber-threat intelligence organization observes IoCs across a variety of customers. What is the organization MOST likely obligated to do before releasing specific threat intelligence?
  • What aspect of security does a VPN primarily enhance?
  • Which of the following algorithms has the smallest key size?
  • Which type of authentication method is considered the most secure?
  • To comply with a corporate mobile device policy, what two controls should be implemented for mobile users?
  • Which logs would MOST likely indicate the original source of malware following an infection on a host system?
  • A network technician is installing a guest wireless network at a coffee shop, providing the password on the customer's receipt. What will provide the highest level of security with the least overhead?
  • What does a man-in-the-middle attack typically aim to accomplish?
  • What type of malicious email usually attempts to steal personal information by claiming the recipient has won a prize?
  • During a security audit, an analyst notices repeated failed attempts to access user accounts. What type of attack would this likely represent?
  • Which technology best balances BYOD culture while protecting company data?
  • What type of analysis helps determine the root cause of security incidents?
  • What type of controls should be applied to mitigate risk when an encryption standard cannot be upgraded in a web application?
  • What is the most effective method for deploying application patches?
  • Which RAID level can handle two simultaneous disk failures and achieve parity?
  • Which solution allows guests at a corporate headquarters to access the Internet while requiring acceptance of an acceptable use policy?
  • Which of the following is MOST likely to outline the roles and responsibilities of data controllers and data processors?
  • In which scenario would steganography most likely be employed?
  • A company wants to rely on another platform for authorization. What is the best approach to implement this?
  • What is the MOST likely goal of an attacker installing malware on a popular website?
  • To validate an incident response plan's thoroughness, which activity will the CSO MOST likely conduct?
  • When implementing centralized event-log management, what is the most significant benefit?
  • A nuclear plant was attacked, and all networks were air gapped. A subsequent investigation revealed a worm as the source of the issue. What is the most likely explanation?
  • Which protective measure should be implemented to guard against malware that spreads unnoticed through network shares?
  • What is the best method to implement secure authentication to third-party websites without using users' passwords?
  • Which tool would be BEST for identifying potential vulnerabilities on web servers?
  • A security engineer is reviewing log files after discovering usernames and passwords for the organization’s accounts. Which type of attack is MOST likely indicated by an IP address change lasting eight hours?
  • A manufacturer creates designs for very high security products required to be protected by government regulations. These designs are not accessible by corporate networks or the Internet. What is the BEST solution to protect these designs?
  • Which type of disaster recovery test requires the least amount of time from the disaster recovery team?
  • Which of the following BEST describes a method to ensure ongoing assessments of security program effectiveness?
  • A remote user recently took a two-week vacation abroad with a corporate-owned laptop. Upon returning, the user has been unable to connect the laptop to the VPN. What is the MOST likely reason for this inability?
  • During what phase of incident response would an organization conduct a full recovery after a threat?
  • An organization in a flood zone is likely to document IT restoration concerns in which plan?
  • A security administrator checks a network switch's table. Which of the following attacks is happening to this switch?
  • To best prevent unauthorized access to a wireless network, which security method should be implemented?
  • Which type of certificate would be best for a company that wants to secure multiple subdomains?
  • What is the primary responsibility of a data owner compared to a data custodian?
  • What does the term 'data breach' refer to in cybersecurity?
  • Based on the output received while investigating alerts from the SIEM, which attack is being executed?
  • What type of attack involves exploiting a user’s web browser by manipulating existing session tokens?
  • An administrator must gesture on a touch screen after entering a username and password. What type of authentication is being demonstrated?
  • During an unauthorized payment investigation, what does the presence of unusual log entries indicating users clicked an unsubscribe link suggest?
  • Which incident response step involves actions to protect critical systems while maintaining business operations?
  • During a forensic investigation, which type of data would likely be discovered in the metadata of images taken by a cellular phone?
  • Which type of malware is specifically designed to remain undetected on a system?
  • What kind of code testing involves executing the code and evaluating its behavior?
  • What type of control is a turnstile classified as?
  • What is the MOST likely recommendation from a CISO to mitigate the risk of a prolonged DDoS attack?
  • Which of the following is a preventive measure against data breaches?
  • A manager decides to acquire cybersecurity insurance for the company. Which of the following risk management strategies is the manager adopting?
  • What approach should be taken to ensure secure remote work for employees?
  • Which resource is MOST likely consulted to validate affected platforms during a vulnerability assessment?
  • Which method would most likely help a company find the cause of sensitive data being shared publicly?
  • What type of attack is described by creating a fake website to exploit users?
  • What did the security assessment identify with the use of DES and 3DES on production servers?
  • A security analyst captures 1GB of inbound network traffic for analysis. Which tool should the analyst use to review the pcap file?
  • How can organizations minimize the risk of insider threats effectively?
  • Which of the following actions should a security engineer take to implement Active Directory authentication on Layer 2 switches and ensure local fallback?
  • Which two elements are essential for maintaining optimal environmental temperature in a data center layout?
  • What solution would meet the requirements for managing administrator/root credentials and service accounts effectively?
  • Which method is used to ensure that data transmission over the network is secure?
  • A global pandemic is forcing a private organization to close some business units. What would be BEST to help executives determine the next course of action?
  • What steps should a network engineer take to troubleshoot intermittent connectivity issues with wireless devices in a warehouse?
  • Which team is dedicated to testing the effectiveness of organizational security programs by emulating attackers' techniques?
  • To generate a server certificate for secure RDP connections, what is the FIRST step the analyst should perform?
  • Which of the following would be the BEST resource for a software developer who is looking to improve secure coding practices for web applications?
  • Which action would MOST improve an incident response process that experienced delays in quarantining an infected host?
  • Which solutions would best allow control over company emails on BYOD devices and limit data exfiltration?
  • Which framework is typically used to assess security controls in an organization?
  • What was the most likely cause of a data compromise after a laptop theft in a cloud-based environment?
  • What method can organizations use to ensure that software updates do not introduce vulnerabilities?
  • Which security measure isolates sensitive technology from external networks?
  • Which technology is crucial for protecting credit card information during online transactions?
  • What is the most likely cause of malware alerts detected on employees' workstations after returning from a trade show?
  • Which method would MOST likely support the integrity of a voting machine?
  • What command would be BEST to use if iptables is dropping all connections and needs to remove existing rules?
  • Under GDPR, who is MOST responsible for the protection of users' privacy and rights on a website?
  • What should a company do to best protect itself from data exfiltration via removable media?
  • Which source would be the best to determine if personal information of a CEO is available for sale?
  • Which control sets should be included in a well-written Business Continuity Plan (BCP)?
  • What is the purpose of network usage rules in a BYOD policy?
  • What would be an effective measure against man-in-the-middle attacks on network communications?
  • What is the purpose of including a CVSS score in a vulnerability assessment report?
  • Which service should a cybersecurity administrator utilize to efficiently manage an on-premises network with a reduced team?
  • To allow PII to be shared securely without compromising security, which action should be taken regarding DLP policies?
  • What biometrics are MOST likely to be used for authentication at country borders without the need for enrollment?
  • What action would best ensure an application is ready for release to production?
  • Which practice in software development ensures that code changes can be merged reliably?
  • What is the most likely cause of a forensic examiner receiving an error while attempting to dump passwords from physical memory?
  • What does the 60-minute expectation for system availability indicate?
  • What is the most likely cause when an analyst cannot open an encrypted email?
  • What should a security administrator do upon discovering unknown devices connected to a company's wireless network?
  • Which of the following targeted the organization involved in a sophisticated cyberattack?
  • Which MFA factors are used when a user enters a password and then an authentication code?
  • During which stage of the incident response process is it appropriate to detail how a security incident occurred and the steps taken for recovery?
  • What is the most likely cause of a data breach on a registration page requiring personal information?
  • What solution should be recommended to monitor data in transit to prevent potential issues in a cloud environment?
  • Which of the following BEST describes the security concerns when hosting web applications in the cloud?
  • What security principle focuses on limiting a user’s access to only what is necessary to perform their job?
  • What is the most likely cause of a computer sending an email address and number to an external IP address?
  • Which backup methodology allows for the fastest database restore time with limited storage available?
  • What does the term 'phishing' specifically refer to in cybersecurity?
  • Which of the following solutions helps ensure secure transmission of sensitive information online?
  • What is the BEST method to prevent the exploitation of the SMB network protocol?
  • Which native tool can a security analyst use to map services running on a server to the server's listening ports?
  • What type of impact is an organization experiencing when customers reduce their orders after a security incident?
  • An organization wants to implement a third factor to an existing multifactor authentication that already utilizes a smart card and password. Which of the following would meet the organization's needs for a third factor?
  • What is the BEST source an analyst could review to understand how an incident occurred due to a lack of patching?
  • To monitor who is accessing files on a Windows server, what command should an analyst use?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy