Browse all practice questions for the Information Security Principles and Frameworks Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

Information Security Principles and Frameworks Practice Test course image
All questions

These questions are part of the practice quiz. Start practicing

  • In risk calculation, which term represents the percentage of an asset's value that would be lost during a security incident or disaster?
  • What is a hardened server that provides access to other hosts called?
  • Which term describes the group primarily responsible for monitoring and protecting assets in real time?
  • Which feature allows enrollment into a wireless network through an eight-digit PIN?
  • Which term describes firewall technology that includes application awareness, user-based filtering, and intrusion prevention, with cloud inspection capabilities?
  • What term describes the collection of entries that determine which subjects are allowed or denied access to a resource?
  • Which multifactor authentication scheme uses ownership and biometric factors, but not knowledge factors?
  • CIA stands for?
  • A type of IDS that monitors a computer system for unexpected behavior or drastic changes to the system's state.
  • Which term represents the granularity levels used for encrypting data at rest, from file-level to database-level?
  • Which term describes the impersonation attack in which an attacker uses a compromised employee's account to convince others to perform fraudulent actions?
  • Identification and authentication information presented in the X.509 format and issued by a certificate authority as evidence that a key pair belongs to a particular subject is a
  • What security control enforces a virtual boundary based on real-world geography?
  • In wireless security, PSK stands for what?
  • Which term describes a directory service across a network, commonly used to hold identity information?
  • Which term refers to intelligence activities focused on emerging threats and threat sources?
  • Which specification provides secure hardware-based storage of encryption keys, hashed passwords, and other user- and platform-identification information?
  • Which term refers to a security solution designed to manage and control cloud service usage across users and devices?
  • A threat actor with a malicious purpose is described as an?
  • What is hashing in cryptography?
  • What type of certificate matches multiple subdomains under a parent domain?
  • Which architecture distributes data processing and storage across multiple locations or devices?
  • Which term describes a decoy system used to lure attackers and study attack methods?
  • Which vulnerability assessment method uses login credentials to perform a deeper, more informative audit of a network?
  • A technology or procedure put in place to mitigate vulnerabilities and risk and to ensure the CIA of information.
  • An impersonation attack in which an attacker gains control of an employee's account and uses it to convince other employees to perform fraudulent actions.
  • Information present in the volatile memory of a host, such as system memory or cache, is called?
  • Which term describes software-defined networking, the decoupling of control logic from forwarding hardware to enable programmable networks?
  • The science and practice of altering data to make it unintelligible to unauthorized parties.
  • What term describes a disk drive where the controller automatically encrypts data written to it?
  • Which file does an entity send to a certificate authority to request a certificate?
  • Which open source NIDS requires a subscription to obtain up-to-date rulesets, with community-authored rules available to non-subscribers?
  • What term refers to configuration guides, benchmarks, and best practices for deploying and maintaining a network device or application server in a secure state for its given role?
  • What term refers to weaknesses in software that could be triggered accidentally or exploited by an attacker to perform unauthorized actions?
  • What term refers to disguising the nature and purpose of buildings or parts of buildings?
  • Which port is commonly used by SSH by default?
  • Which model uses administrator-managed ACLs to provide user permissions based on job functions?
  • What term describes serverless computing offloading infrastructure management to the cloud provider, such as configuring storage without building and deploying a file server?
  • Which statement best describes private keys in asymmetric cryptography?
  • In a federated network, which entity holds the user account and performs authentication?
  • A person or entity responsible for an event identified as a security incident or as a risk is called what?
  • Which framework provides a standardized approach to exchanging vulnerability management information and automating checks?
  • Which term describes a threat actor that is supported by the resources of its host country's military and security services?
  • Which cryptographic technique provides secure key exchange?
  • The science of creating machines with the ability to develop problem-solving and analysis strategies without significant human direction or intervention.
  • Which attack involves injecting a database query into input data directed at a server, allowing unintended access or manipulation of data?
  • What is the process called when an account, host, or application is removed from the production environment, including revocation of privileged access?
  • Which term describes a strategy that ensures processing redundancy to support workflow during disruptions?
  • Which method secures devices against theft using cable locks?
  • What term denotes the unique identifier assigned to a Windows account by the operating system?
  • The process of investigating, collecting, analyzing, and disseminating information about emerging threats and threat sources.
  • Resources on the Internet that are distributed across anonymized nodes and protected by layered encryption and routing describe which area?
  • Which term refers to sending an unsolicited message or picture via a Bluetooth connection?
  • An impersonation attack in which a request for a website, typically an e-commerce site, is redirected to a similar-looking, but fake, website.
  • Which term describes the social engineering attack where the attacker pretends to be someone else?
  • Which term refers to an asset disposal method that relies on a third party and provides documentary evidence of completion?
  • Which term describes an area of the network where security configuration is uniform for all hosts within it?
  • What is the term for the set of policies, procedures, and software designed to manage accounts and credentials with administrative permissions?
  • Security settings that control access to objects including file system items and network resources are known as which term?
  • Which term refers to data that has been encrypted and is unreadable without the key?
  • Which term describes copying ingress and/or egress communications from one or more switch ports to another port to monitor communications passing over the switch?
  • Which term describes a security strategy that positions layers of diverse security control categories and functions instead of relying solely on perimeter controls?
  • Which term describes the processes and tools used to detect deviations from configuration baselines and to track asset states over time?
  • Which control discourages intrusion attempts?
  • Which term refers to a framework of certificate authorities, digital certificates, software, services, and other cryptographic components used to validate subject identities?
  • Which term is defined as the ability of a system to process a task within an acceptable amount of time?
  • What term refers to information about sessions between hosts that is gathered by a stateful firewall?
  • Data that has been enciphered and cannot be read without the cipher key.
  • Which component in zero trust architecture is responsible for defining policy and making access decisions?
  • A cloud service model that provisions fully developed application services to users.
  • Which term best matches the social engineering tactic involving pretending to be a trusted entity?
  • Which cryptographic function produces a 128-bit output?
  • Which term refers to the concept of standards for implementing device encryption on storage devices?
  • Which term describes the IPsec component that provides authentication for origin and integrity and protection against replay attacks?
  • Which legacy mechanism is used to encrypt data over a wireless connection?
  • Classifying the ownership and management of a cloud as public, private, community, or hybrid describes what concept?
  • Which architecture emphasizes independently deployable services with lightweight interfaces?
  • Which application protocol supports secure tunneling, remote terminal emulation, and file copy and runs over TCP port 22?
  • Which process involves provisioning an account, host, or application to production, including identity verification and credential issuance?
  • Which biometric metric measures the number of valid subjects who are denied access?
  • Which mechanism redirects malicious DNS queries to a controlled address for analysis?
  • Which term describes the considerations for positioning security controls to protect network zones and individual hosts to implement a defense in depth strategy and meet overall security goals?
  • Social engineering tactic where a team will communicate, whether directly or indirectly, a lie or half-truth in order to get someone to believe a falsehood.
  • Which term describes a hacker engaged in authorized penetration testing or security consultancy?
  • In a Wi-Fi site survey, what diagram shows signal strength and channel utilization at different locations?
  • The likelihood and impact (consequence) of a threat actor exercising a vulnerability is called?
  • What component identifies unauthorized entry via infrared, ultrasonic, microwave, or pressure-based detection of movement?
  • Which term refers to the capability and methods a threat actor employs and the complexity of the attack campaigns they can mount?
  • Publicly available information plus the tools used to search and aggregate it is known as which intelligence discipline?
  • Which scheme for identifying vulnerabilities was developed by MITRE and adopted by NIST?
  • A concept in which an expanding list of transactional records listed in a public ledger is secured using cryptography is known as what?
  • Which proxy redirects requests and responses without the client being explicitly configured to use it, also called a forced or intercepting proxy?
  • Which practice validates redundancy by executing primary and backup systems in parallel?
  • A weakness that could be triggered accidentally or exploited intentionally to cause a security breach is called a?
  • Which Kerberos component authenticates users and issues tickets (tokens)?
  • Which software aggregates and catalogs data from multiple sources within an industrial control environment for analysis and reporting?
  • Social engineering attack where an attacker pretends to be someone they are not.
  • Which term refers to a security control that is used when a primary control fails to meet security requirements?
  • Which term describes CPU extensions that protect data stored in system memory so that an untrusted process cannot read it?
  • Which credential stores authentication information such as a private key on a card-like device with an embedded processor, used for authentication?
  • Which password concept is valid for a single session and becomes invalid after that session ends?
  • An authentication scheme that requires the user to present at least two different factors; for example, something you know, something you have, something you are, something you do, and somewhere you are. Specifying two factors is known as "2FA."
  • Which mechanism was used in the first version of WPA to improve security over WEP?
  • Which security appliance combines detection capabilities with functions that can actively block attacks?
  • Falsifying records, such as an internal fraud that involves tampering with accounts, describes which term?
  • The product life cycle phase where mainstream vendor support ends, leaving systems without official updates.
  • Which term describes encryption applied to data in motion (examples include WPA, IPsec, TLS)?
  • Backup that writes job data to media that is stored in the same physical location as the production system.
  • What computing environment allows multiple independent operating systems to be installed on one hardware platform and run simultaneously?
  • Distributed public record of transactions that underpins the integrity of blockchains is called what?
  • Which technique used in firewalls analyzes packets down to the application layer to enforce tighter security?
  • Developed by Cisco and Microsoft to support VPNs over PPP and TCP/IP. PPTP is highly vulnerable to password cracking attacks and considered obsolete.
  • Which term describes a measure of randomness that strengthens resistance to brute-force attacks?
  • Which protocol provides authenticated encryption with associated data (AEAD) in high-performance symmetric encryption?
  • Which set of standards promotes the use of public key infrastructure?
  • What is the term for the estimation of the physical location of a device such as a radar source or internet-connected device?
  • Which organization develops computer security standards used by US federal agencies and publishes best practice guides and research?
  • Which term describes Near-field communication (NFC), a standard for very short-range wireless communications used for contactless payments and similar technologies?
  • Which policy type restricts user access based on the time of day?
  • Which term describes an enumeration, vulnerability, or incident detection scan that analyzes only intercepted network traffic rather than sending probes to a target?
  • Which proxy type protects backend servers by shielding them from direct contact with client requests?
  • Which biometric metric measures the number of unauthorized users who are mistakenly granted access?
  • Which acronym is introduced with WPA3 as a more secure authentication method compared to WPA-PSK?
  • Which solution uses digital certificates to identify hosts and establish secure tunnels for network traffic?
  • Which security measure involves inspecting traffic to locate and block viruses?
  • Which concept ensures that access events are recorded and can be audited?
  • Which standard enables the exchange of authentication assertions in web single sign-on scenarios?
  • Which term describes placement and configuration of a network security control so that it becomes part of the cable path?
  • What is a logical network segment created by assigning VLAN IDs to ports on a managed switch?
  • What term describes a segment isolated from the private network by firewalls that accepts Internet connections on designated ports?
  • A set of rules governing user security information, such as password expiration and uniqueness, which can be set globally.
  • Which file format uses attribute-value pairs in a human- and machine-readable structure to define configurations?
  • Which term is used to quantify the severity of vulnerabilities on a standard scale to prioritize remediation?
  • Which type of programming languages are designed to enforce strict type-checking and prevent memory-related vulnerabilities?
  • Which protocol provides addressing and routing at the Internet layer in the TCP/IP suite?
  • Which term describes a group that commits cybercrime for profit?
  • Which describes the role of a compensating control when a primary control fails?
  • Which term refers to a load balancing setup where a group of servers work together as a unit to provide network services?
  • Which term describes a detection method that uses feature comparisons and likenesses rather than signature matching to identify malicious activity?
  • In a federated network, the service that holds the user account and performs authentication is called what?
  • Which statement best describes the purpose of a certificate signing request (CSR)?
  • Which term describes software that remains owned by the developer and is accessible only under license terms that restrict usage?
  • Which asset disposal technique ensures that data remnants are rendered physically inaccessible and irrevocable, through degaussing, shredding, or incineration?
  • Which term describes disguising or hiding code to make reverse engineering more difficult?
  • What protocol is used to access directory databases that store information about users and their privileges?
  • AAA stands for?
  • Which provisioning approach uses machine-readable configuration to manage resources on cloud providers?
  • Which term describes the practice of hiding code to prevent unauthorized reading?
  • Which term refers to a synchronizable list of data and scripts used to check for vulnerabilities and is also known as plug-ins or network vulnerability tests (NVTs)?
  • Which term refers to a security control configuration that treats a failure as a green light, allowing access?
  • A digital certificate contains the subject's identity and their public key.
  • Standards for authenticating and encrypting access to Wi-Fi networks are collectively known as which protocol?
  • An attack type that entices a victim into using or opening a removable device, document, image, or program that conceals malware is called?
  • What is the self-signed certificate that serves as the trust anchor in a PKI hierarchy called?
  • Which term describes a firewall that examines content at the application layer, enforcing rules based on protocols such as HTTP or SMTP?
  • Which term describes Bluetooth, a short-range wireless technology used to connect devices like phones and headsets?
  • What term describes an authentication scheme requiring two or more factors?
  • Which IPSec sub-protocol provides encryption and authentication of the header and payload of a data packet?
  • Which term refers to hardware or software used on a private network without the owner's knowledge?
  • What term describes the process of detecting patterns within data over time to predict future events or understand past events?
  • A proxy that redirects requests and responses for clients configured with the proxy address and port is best described as a
  • Which architectural style features independent, single-function modules with lightweight interfaces to enable rapid deployment of complex applications?
  • Which concept uses a chain of blocks to securely record transactions and maintain integrity through cryptography?
  • Which access control technique evaluates a set of attributes that each subject possesses to determine if access should be granted?
  • A cloud that is deployed for use by a single entity.
  • A nondiscretionary access control technique based on a set of operational rules or restrictions to enforce a least privileges policy is known as which?
  • Which term describes an alternate processing location that is prepared for rapid conversion to an operating site but normally performs noncritical functions?
  • Which term describes installing an app on a mobile device from outside the official app store?
  • Techniques and tools designed to mitigate risks from application vulnerabilities in third-party code, such as libraries and dependencies.
  • Which authentication technology enables a user to authenticate once and receive authorizations for multiple services?
  • Which AAA protocol is used to manage remote and wireless authentication infrastructures?
  • A security control category implemented as a system (hardware, software, or firmware) such as firewalls, antivirus, OS access controls?
  • What is the secure entry system with two gateways, only one of which is open at any one time?
  • Which feature allows enrollment in a wireless network using an eight-digit PIN?
  • A threat actor that causes a vulnerability or exposes an attack vector without malicious intent is described as?
  • Which file format uses attribute-value pairs to define configurations in a readable structure?
  • Which proxy type sits in front of backend servers to handle client requests and shield internal systems?
  • What is the term for a method of generating random values by sampling physical phenomena with high entropy?
  • The process by which a user account and credentials are issued to the correct person is called what?
  • Which officer is primarily responsible for management of information technology assets and procedures?
  • AAA stands for?
  • Which term describes a threat actor who causes a vulnerability or exposes an attack vector without malicious intent?
  • Which is a stateful inspection firewall that can filter traffic based on specific application protocol headers and data, such as web or email?
  • A predetermined alternate location where a network can be rebuilt after a disaster is known as which site?
  • Which framework negotiates authentication methods that enable hardware-based identifiers and establishes secure tunnels for credential submission?
  • In wireless security, which mode uses a passphrase-based mechanism to derive an encryption key?
  • What device provides a connection between wireless devices and a wired network in an infrastructure-mode WLAN?
  • Which server mediates communications between a client and another server, can filter and often modify communications as well as provide caching services to improve performance?
  • What is the term for a host, network, file, or credential set up to lure attackers away from assets of actual value?
  • Which type of algorithm uses public and private keys?
  • A security countermeasure that mitigates the impact of precomputed hash table attacks by adding a random value to plaintext input is called what?
  • IPsec protocol that provides authentication for the origin of transmitted data as well as integrity and protection against replay attacks is the?
  • Which token is generated by a cryptoprocessor on a dedicated hardware device, and its value is never transmitted directly?
  • A type of email-based social engineering attack, in which the attacker sends email from a supposedly reputable source, such as a bank, to try to elicit private information from the victim.
  • Which area refers to parts of the internet intended to be accessed via special networks and with user anonymity protection, often requiring specific access methods?
  • A technology or procedure to mitigate vulnerabilities and risk to ensure CIA of information is called?
  • In zero trust architecture, which component defines policy and makes access decisions?
  • What property of transport encryption ensures the compromise of a key in one session does not allow plaintext data from other sessions to be recovered?
  • Which electronic system is designed to perform a specific, dedicated function, such as a microcontroller in medical equipment?
  • Which term describes an attack where an attacker compromises websites frequented by a target group to deliver malware?
  • De-identification method where a unique token is substituted for real data.
  • Which term denotes an insider who unintentionally creates vulnerability due to careless actions?
  • Demanding payment to prevent or halt some type of attack describes which term?
  • Which security approach defines a virtual perimeter around a geographic area and triggers actions when devices cross it?
  • Which NIST framework outlines accepted practices for automating vulnerability scanning?
  • Which term refers to a browser-based attack where a malicious script is delivered via a trusted site to compromise the client?
  • Under PKI, the entity that guarantees certificate validity is called a
  • Which term refers to a hardware device dedicated to firewall functionality that is typically a standalone unit?
  • Protection against system failure by providing extra (redundant) capacity is the goal of which approach?
  • Which protocol enables remote graphical desktop connections to a host and typically uses port 3389?
  • Which security measure uses a temporary DNS record to route malicious traffic to a controlled IP?
  • What type of digital certificate is signed by the entity that issued it rather than by a certificate authority?
  • The ability of threat actors to draw upon funding to acquire personnel, tools, and to develop novel attack types is referred to as what?
  • Which device distributes client requests among multiple resources to provide fault tolerance and improved throughput?
  • A formal classification of the resources and expertise available to a threat actor is known as what?
  • Which personal authentication method was introduced with WPA3 to address vulnerabilities in WPA-PSK?
  • Which credential is a password valid for one session and expires afterward?
  • Which provisioning model restricts personal use on corporate-owned devices?
  • Which term encompasses the financial resources that enable attackers to hire personnel, buy tools, and fund development of new attack techniques?
  • Which concept is the browser interface that exposes a page's structure to client-side scripts and can be manipulated by them?
  • Which method assigns a non-reversible token to data, mapping to the original through a secure lookup?
  • Which term describes a firewall that primarily inspects traffic at the transport layer, tracking TCP/UDP connections?
  • Blacklists of known threat sources, such as malware signatures, IP address ranges, and DNS domains.
  • Which approach uses behavior analytics to detect unusual patterns across users and devices?
  • What term describes the standards for data access over cellular networks across 2G through 5G?
  • Which term describes the process of selecting the type and placement of security controls to ensure the goals of the CIA triad and compliance with any framework requirements?
  • Which architectural style is standardized and stateless, commonly used for web service communication?
  • Which architectural style is described as stateless and uses standard operations for web services?
  • What term describes a measure of disorder that affects the strength of cryptographic systems?
  • Which device serves as an appliance for generating and storing cryptographic keys, and may be less susceptible to tampering than software-based storage?
  • Which term describes a cloud arrangement that uses more than one public cloud service?
  • A fully configured alternate processing site that can be brought online either instantly or very quickly after a disaster is called what?
  • An access control model where each resource is protected by an access control list (ACL) managed by the resource's owner is best described as which model?
  • What term refers to a software update that has been altered by an attacker to introduce malicious code into a package supply chain?
  • What Linux framework provides a pluggable approach to authentication providers?
  • Which security activity involves formal, wide-scope auditing of systems that includes governance, configurations, monitoring, and cybersecurity controls?
  • Which term describes the field of enabling machines to learn and solve problems with minimal human direction?
  • Which security appliance or software analyzes data from a packet sniffer to identify traffic that violates policies or rules?
  • Which term defines historical analysis of cyber attacks and the actions of adversaries?
  • Which term refers to a hardware-assisted area that keeps sensitive data isolated from untrusted software?
  • An alternate processing location that is dormant or performs noncritical functions under normal conditions, but can be rapidly converted to a key operations site if needed is which type of site?
  • Which term refers to a short-range wireless radio transmission medium used to connect two personal devices, such as a mobile phone and a wireless headset?
  • In authentication design, different technologies for implementing authentication, such as knowledge, ownership/token, and biometric/inherence. These are characterized as something you know/have/are.
  • Which encryption method describes the encryption of all data on a disk, including system files, temporary files, and the pagefile, which can be implemented by the OS, third-party software, or at the disk controller level?
  • What is the term for the string that identifies a particular wireless LAN (WLAN)?
  • Which metric defines how closely systems approach 100% data availability while maintaining performance?
  • Which device has the primary function of a router but includes firewall functionality embedded into its firmware?
  • A security configuration where access is generally permitted to a software process, IP/domain, or other subject unless it is listed as explicitly prohibited.
  • What type of operating system prioritizes deterministic execution of operations to ensure a predictable response for time-critical tasks?
  • Which practice applies consistent names and labels to assets and digital resources within a configuration management system?
  • What is encryption?
  • A cloud that is deployed for shared use by cooperating tenants.
  • Which mechanism ensures data availability by copying data to a secondary location, either synchronously or asynchronously?
  • What is the collection of attributes that defines a unique identifier for a resource within an X.500-like directory?
  • An impersonation attack in which the attacker registers a domain name with a common misspelling of an existing domain to mislead users.
  • What testing technique replicates the conditions of a real-world disaster scenario or security incident?
  • What reward scheme do software and web services vendors offer to researchers who report vulnerabilities?
  • Which physical security feature ensures adequate lighting for safety and surveillance effectiveness?
  • A security configuration where access is denied to any entity unless the entity appears on a whitelist.
  • Which de-identification method preserves structure while removing sensitive content by replacing with placeholders?
  • Which term denotes the percentage of asset value likely to be lost in a security incident?
  • Which architecture describes data processing and storage in a single location?
  • Which security device resembles a credit card and stores authentication information, such as a private key, on an embedded processor?
  • Which term describes computer hardware, software, or services used on a private network without authorization from the system owner?
  • The potential vulnerability that occurs when there is a change between when an app checks a resource and when the app uses the resource is known as?
  • Which wireless authentication mode uses the access point as a pass-through for credentials verified by an AAA server?
  • Which term refers to data that is readable and not encrypted?
  • Which term names an authentication mechanism that uses biometric scans and stores physical characteristics as a digital template for user verification?
  • A group account is a collection of user accounts used to grant the same level of access to multiple users. What is this concept called?
  • Which component provides the plug-in interface for different authentication methods in Linux systems?
  • What process provides a shared login capability across multiple systems and enterprises, connecting identity management services?
  • Which term is used to describe the practice that embeds security into software development and operations?
  • What device is described as an advanced strip socket that provides filtered output voltage and can be remotely administered?
  • What term describes the practice of maintaining and enforcing configuration settings for server roles across deployments?
  • Which officer is primarily responsible for making effective use of new and emerging computing platforms and innovations?
  • What is a key?
  • Infrastructure, protocols, and software that allow a host to join a local network from a remote location, or that allow a session on a host to be established over a network is called?
  • In a port-based access control setup, which device passes a supplicant's authentication data to the central authentication server?
  • Which vulnerability arises when software checks a resource and uses it later, potentially after changes?
  • Which XML-based data format is used to exchange authentication information between a client and a service?
  • In PKI, the public CA that issues certificates for multiple domains and is widely trusted as a root trust by operating systems and browsers is called
  • Which identifier is used as a unique security token for Windows accounts and is used by access control mechanisms?
  • Which term describes an attack where data exceeds the destination buffer and corrupts adjacent memory, potentially allowing code execution?
  • Which component centralizes generation and storage of cryptographic keys in PKI?
  • What is the term for a message digest encrypted with the sender's private key and appended to a message to authenticate the sender and prove message integrity?
  • In configuration management, applying consistent names and labels to assets and digital resources is called what?
  • Which principle is primarily concerned with ensuring that data remains accurate and protected from unauthorized changes?
  • Which security solution mediates access to cloud services for users across devices, helping enforce policies and visibility?
  • Which transport security protocol is commonly used to provide encryption for data in transit on the Internet?
  • Which technique strengthens potentially weak input for cryptographic key generation, such as passwords or passphrases created by people, against brute force attacks?
  • Which cloud deployment is designed for a specific community of users with shared concerns?
  • Which control is primarily concerned with compliance and governance, enforcing rules via policy or contract?
  • What term describes a fundamental cryptographic building block used within a larger system?
  • What term describes a private network segment allocated to a single cloud customer within a public cloud?
  • A network protocol suite used to secure data through authentication and encryption as the data travels across the network or the Internet is?
  • Which standby power source uses diesel or propane and provides transitionary power during outages?
  • Which type of system manages large-scale, geographically dispersed devices from a central host computer?
  • Overprovisioning resources at the component, host, and/or site level so that there is failover to a working instance in the event of a problem is known as which concept?
  • What term refers to network topology enforced by switches, routers, and firewalls that prevents hosts on different segments from communicating?
  • Which network monitoring approach uses a predefined set of rules to identify unacceptable events?
  • Which term refers to the collection of cryptographic algorithms that can be negotiated to secure a connection?
  • The process of encapsulating data from one protocol for safe transfer over another network is called what?
  • Which concept involves placing a backup cryptographic key with a trusted third party?
  • Which term refers to the processing, memory, storage, and networking resources that allow a host or network appliance to handle a given workload?
  • In asymmetric cryptography, what cannot be derived from the public key?
  • Which security component consists of sturdy vertical posts designed to control traffic and deter ram-raiding?
  • Automatically copying data between two processing systems either synchronously or asynchronously is known as what?
  • A list of detailed information about the software components and dependencies used in an application or system.
  • Which type of security control acts after an incident to eliminate or minimize its impact?
  • Which term describes a documented set of baseline configurations for securely deploying a device or service?
  • Which term describes a means of determining a receiver's position on Earth using information from orbiting satellites?
  • De-identification method where generic placeholders are substituted for real data while preserving structure.
  • Which term best describes the concept where security responsibilities are shared between customer and cloud service provider?
  • What term describes the integration of software development, security operations, and systems operations into a single discipline?
  • Which term is used for a threat actor group that is often state-sponsored for espionage?
  • What term describes the science, art, and practice of breaking codes and ciphers?
  • Tracking authorized use of a resource or alerting when unauthorized use is detected or attempted is known as?
  • Unencrypted data that is meant to be encrypted before it is transmitted, or the result of decryption of encrypted data.
  • An attack in which an attacker targets specific groups or organizations, discovers which websites they frequent, and injects malicious code into those sites.
  • Which physical security control uses cameras and recording devices to monitor activity in an area?
  • Software testing that examines code behavior during runtime.
  • Which term describes a type of wireless network where connected devices communicate directly with each other instead of over an established medium?
  • An audit with a broad scope that includes supply chain, configuration, support, monitoring, and cybersecurity factors is known as what?
  • Target for data-at-rest encryption, ranging from more granular (file or row/record) to less granular (volume/partition/disk or database), is known as?
  • Which process generates numbers that approximate randomness but are not truly random?
  • What is the method that verifies both the integrity and authenticity of a message by combining a cryptographic hash with a secret key?
  • Which term describes isolating a broadcast domain within a single switch using VLANs?
  • An analysis that measures the difference between the current and desired states to help assess the scope of work in a project.
  • Endpoint protection that can detect and prevent malicious activity via signature and heuristic pattern matching.
  • What is the commonly used acronym for the three core information security goals?
  • What is the primary design goal regarding collisions in cryptographic hashing?
  • The concept that most IT requirements can be deployed as a cloud service model.
  • Which device reads data from RFID or NFC tags when in range?
  • Which term describes the policies for removing devices from production networks and disposing of them via sale, donation, or waste?
  • Removes the protective seal and any OS-specific restrictions to give users greater control over the device is called?
  • Classifying the provision of cloud services and the limit of the cloud service provider's responsibility as software, platform, infrastructure, and so on.
  • Which term is a threat actor motivated by a social issue or political cause?
  • Which security control continuously monitors a host to detect changes to critical system files?
  • Which term refers to the firewall-protected segment that accepts Internet connections on designated ports?
  • Which option best describes a vulnerability scan that intentionally uses credentials to access more information and find deeper issues?
  • Which option is the protocol suite used to secure data through authentication and encryption as it travels across networks?
  • Which device provides battery-powered AC power for equipment during power loss?
  • Which fundamental security goal ensures information is accurate and free from unauthorized modifications?
  • Which term best describes an authentication factor based on possession of a physical object like a card?
  • Which term describes the process of implementing changes to software configurations as part of a broader configuration management strategy?
  • Which term describes someone who breaks into computer systems or spreads viruses, often seen as an expert by ethical hackers?
  • Which term refers to the component that stores session information for a stateful firewall to track active connections?
  • Which term describes computing that isolates applications at the OS level, enabling portable and scalable deployment?
  • A number used with authentication devices such as smart cards; the PIN should be known only to the user, loss of the smart card should not present a security risk.
  • What is a standalone hardware device that performs only firewall functions and is embedded in the appliance's firmware?
  • Which term refers to a network scope that uses close-range wireless technologies to establish communications between personal devices such as smartphones and printers?
  • Which term refers to APIs and compatible hardware/virtual appliances enabling programmable network appliances and systems?
  • Which team is responsible for incident response and must have cross-domain expertise across IT, HR, legal, and marketing?
  • Which biometric performance metric is characterized by a lower value indicating better accuracy?
  • What process determines what rights and privileges an entity has?
  • Which term is the catalog of publicly disclosed cybersecurity vulnerabilities and exposures used as a common reference?
  • A security control category implemented by people?
  • Which term best fits the description: a plan ensuring essential services continue during disruptions by maintaining processing redundancy?
  • Which standard governs authenticating and encrypting access to Wi‑Fi networks?
  • Which term denotes a monitor that sniffs data from frames as they traverse network media?
  • A potential for an entity to exercise a vulnerability (that is, to breach security) is termed a?
  • What is the term for accessing the administrative interface of a network appliance using a separate network from the usual data network?
  • In security scanning, which term describes a finding that is not reported when it should be?
  • Which term refers to a power solution that uses batteries to provide uninterrupted power and allows time for safe shutdown?
  • Which security feature uses sturdy vertical posts to prevent vehicle intrusion along perimeters?
  • What is the main goal of patch management?
  • What term describes a strategic assessment of what level of residual risk is tolerable for an organization?
  • Which term is defined as lists of cryptographic algorithms that a server and client can use to negotiate a secure connection?
  • Which architecture converges security services with networking to provide secure access to cloud apps?
  • Which cloud deployment model uses multiple public cloud services?
  • What type of security control enforces a rule of behavior through a policy or contract?
  • Which term describes the practice of combining software development and systems operations to shorten the development lifecycle?
  • Which is a stateful inspection firewall that can monitor TCP sessions and UDP traffic?
  • Which open-source network intrusion detection system is described as requiring a subscription for up-to-date rulesets, with community rules available for non-subscribers?
  • Which term describes a security monitoring concept combining network behavior and anomaly detection?
  • Which certificate field allows a host to be identified by multiple host names or subdomains?
  • Which type of attack falsifies an information resource that is normally trusted by others?
  • What is the term for the user-facing interface that allows operators to configure and monitor an industrial process from a PLC-based system?
  • In IPSec, what does a Security Association (SA) establish between two hosts?
  • Which term describes an attack targeting the availability of a service or process, potentially causing downtime?
  • Which term describes a process that enables cross-organization authentication by connecting identity management services?
  • Which governance practice ensures each asset has a clearly identified owner and is properly tagged within the inventory?
  • Which statement about key length is accurate?
  • Which security paradigm requires continuous authentication for every inter-service request, regardless of network location?
  • In key management, the storage of a backup key with a third party is known as what?
  • Which term describes an inexperienced, unskilled attacker who typically uses tools created by others?
  • Which term refers to the points where a network or application receives external connections or inputs that could be exploited by attackers?
  • Which term best describes a weakness that can be exploited to breach security?
  • Signatures and pattern-matching rules supplied to analysis platforms as an automated feed.
  • What is a primary purpose of encryption?
  • Which term is used for a tool that scans systems to identify known weaknesses and exploitable conditions?
  • Which cloud deployment model uses shared infrastructure across multiple tenants and is widely described as multi-tenant?
  • What term describes a type of network isolation that physically separates a host from other networks?
  • Which architectural style is standardized and stateless, used for web application communication and integration?
  • Installing an app to a mobile device without using an app store is known as?
  • Which provisioning model offers employees a selection of corporate devices for work and, optionally, private use?
  • Which mobility policy enables the use of personally owned devices to access corporate networks and data?
  • In a load-balanced setup, the option that lets a client maintain a connection with a load-balanced server for the duration of the session is known as?
  • Which term describes a wireless attack where an attacker gains access to unauthorized information on a device using a Bluetooth connection?
  • Which process enables researchers and reviewers to disclose vulnerabilities to a software developer in a safe manner?
  • Which product life cycle phase has mainstream vendor support no longer available?
  • Which term best describes a person who conducts authorized security testing to identify vulnerabilities?
  • What is the security principle stating that access is denied unless explicitly granted?
  • What provisioning approach involves deploying virtual network appliances like switches and firewalls via VMs or containers?
  • Which term describes the set of practices used to manage risks and protect the confidentiality, integrity, and availability of information, guided by CSF?
  • Which term describes a digital certificate that has not been signed by a trusted certificate authority but is signed by the entity that created it?
  • Which software delivery model streams code that runs on a server and is delivered to a client?
  • What challenge-response authentication protocol was developed by Microsoft for use in its products?
  • Which metric expresses the point at which FAR and FRR intersect, with a lower value indicating better performance?
  • Which process secures a host or application by reducing its attack surface through running only necessary services, installing monitoring software, and establishing a maintenance schedule to apply patches?
  • Which term refers to encryption of all data on a disk, including system and temporary files, across OS, software, or hardware implementations?
  • Gaining superuser-level access over an Android-based mobile device is called?
  • In PKI, a root certificate is a self-signed certificate that serves as the trust anchor and can issue certificates to intermediate CAs in a hierarchy. The term for this authority is
  • Which protocol would you use to query a directory service to retrieve user attributes?
  • Which term refers to a hacker operating with malicious intent?
  • What term describes a network that manages embedded devices in industrial environments?
  • Which backup type stores data in a separate location from production systems?
  • What document describes optimal locations for wireless antennas and access points to ensure adequate coverage and identify interference sources?
  • Which term refers to identifying, testing, and deploying OS and application updates?
  • Which term best describes the process by which an organization's information systems components are kept in a controlled state that meets security and compliance requirements?
  • Which term best describes the act of transferring sensitive data from a protected environment to an external destination without authorization?
  • Which type of security control acts during an incident to identify or record that the incident is happening?
  • The process of reviewing uncompiled source code either manually or using automated tools.
  • Which term denotes the hardware standard designed for secure storage of encryption keys and identity information?
  • What term denotes a hardware device inserted into a cable path to copy frames for analysis?
  • Which type of vulnerability scan is performed with no credentials, often focusing on missing patches and misconfigurations?
  • An access control model where resources are protected by inflexible, system-defined rules and resources and users are allocated a clearance level is called which?
  • An access control model where resources are protected by ACLs that are managed by administrators and that provide user permissions based on job functions is known as which?
  • Which fundamental security goal is defined as keeping information private and protected from unauthorized access?
  • What does key length refer to in cryptography?
  • Blacklists of known threat sources, such as malware signatures, IP address ranges, and DNS domains.
  • Standards, best practices, and guidelines for effective security risk management; some general and some industry-specific.
  • Which monitoring system detects changes in normal data sequences and identifies abnormal sequences?
  • Which term is a technique that ensures a redundant component can quickly take over the functionality after failure?
  • What term describes browser-based, clientless remote desktop/VPN connections implemented with HTML5 features?
  • Information that is primarily stored on specific media, rather than moving from one medium to another, is called?
  • Which term describes a vulnerability testing tool designed to identify issues with application code and platform configuration, including web servers and web applications?
  • Which provisioning concept involves deploying network functions as software on commodity hardware to enable flexible networking?
  • In storage encryption, the private key used to encrypt the symmetric bulk MEK is the Key Encryption Key (KEK). Which option best describes its role?
  • Which authentication mechanism uses a smart card to operate an entry system?
  • Which term describes a monitor that records (or "sniffs") data from frames as they pass over network media, using methods such as a mirror port or TAP device?
  • Which processes ensure asset enumeration and inventory, verifying compliance with configuration baselines and detecting tampering?
  • Which term describes a resiliency mechanism where processing and data storage resources are replicated between physically distant sites?
  • Which term identifies how business processes should deal with disruptions by ensuring that there is processing redundancy supporting the workflow?
  • Which technology uses software-defined mechanisms to create virtual tunnels and overlay networks across multiple transport types?
  • Which standard is used for port-based authentication controlling access to LANs and WLANs?
  • Which risk management approach quantifies vulnerability data and accounts for different levels of risk across systems or information?
  • What is a software agent that collects system data and logs for threat analysis?
  • Which principle requires allocating the minimum privileges necessary to perform a role?
  • Which mechanism restricts network access to devices with approved MAC addresses by applying an access control list on a switch or access point?
  • Which security measure provides risk mitigation when a primary control fails or cannot fully meet expectations?
  • What security model requires authentication for every request, regardless of network location?
  • Which Windows feature centralizes the configuration and deployment of user and computer settings across a domain?
  • Which security control is designed to identify security events as they occur?
  • What term means removing or severely restricting communications paths to a particular device or system?
  • What term refers to settings for services and policy configuration for a network appliance or server operating in a particular application role (such as web server, mail server, or file/print server)?
  • A cloud deployed for shared use by multiple independent tenants is described as which?
  • Which service model gives developers a platform to create and run their own applications, while the provider handles the underlying middleware and runtime?
  • Which architecture distributes processing and storage across multiple locations to improve resilience?
  • Information being transmitted between two hosts, such as over a private network or the Internet, is called?
  • The operation to recover system functionality and/or data integrity using backup media.
  • The AAA framework serves which function in access management?
  • Linux command for managing file permissions.
  • The process by which an attacker takes data stored inside of a private network and moves it to an external network is called what?
  • Which architecture is most susceptible to single points of failure due to centralization?
  • Which term best describes a distributed public record of transactions that underpins blockchains?
  • Which term describes a private network facility owned and operated by an organization for its employees?
  • Which term describes the degree to which a threat actor has access privileges before an attack, distinguishing between actors with no standing privileges and those with some access?
  • Which term describes an OTP-like code delivered to a registered number or email, or generated by an authenticator app, as a means of two-step verification?
  • What term describes validating an entity's or individual's unique credentials?
  • Which property describes a computing environment's ability to gracefully fulfill ever-increasing resource needs?
  • Which fundamental security goal ensures that systems operate continuously and data is accessible as needed?
  • What is the primary purpose of a security control?
  • Which term denotes a token that represents the ownership factor in a multifactor authentication scheme, generated by a hardware device?
  • NBAD is an acronym used in network security monitoring. What does it stand for?
  • Which option describes a browser-based remote access solution that requires no client software and relies on HTML5 features?
  • A system that provides automated identification of suspicious activity by user accounts and computer hosts.
  • Which term refers to the framework that negotiates authentication methods and establishes secure credential submission tunnels?
  • Which concept describes streaming application code from a server to a client to run remotely, reducing client-side requirements?
  • Which protection mechanism is described as a firewall designed to protect web applications from code injection and DoS attacks?
  • In EAP architecture, which entity is the device requesting access to the network?
  • An operating system virtualization deployment containing everything required to run a service, application, or microservice describes what concept?
  • Which term describes restricting access to a network based on hardware MAC addresses?
  • A cloud deployment that uses both private and public elements.
  • What process and supporting technologies are used to track, control, and secure the organization's mobile infrastructure?
  • What is the primary role of a certificate authority in PKI?
  • What term refers to all-in-one security appliances that combine firewall, malware scanner, intrusion detection, vulnerability scanning, data-loss prevention, and content filtering?
  • Rules to govern secure selection and maintenance of knowledge factor authentication secrets, such as length, complexity, age, and reuse.
  • Which firewall technology operates at Layer 3 by comparing packet headers to ACLs to determine which traffic to accept?
  • Which term refers to using the cellular data plan of a mobile device to provide Internet access to a laptop or PC, with the PC connected via USB, Bluetooth, or Wi-Fi?
  • Which term represents the likelihood and impact of a threat exploiting a vulnerability?
  • Which resilience tools and techniques aim to increase the cost of attack planning for threat actors?
  • Which vulnerability allows an attacker to execute code within the context of the vulnerable process, potentially gaining its privileges?
  • In storage encryption, the private key used to encrypt the symmetric bulk MEK (Media Encryption Key) is called what?
  • What term describes a set of methods exposed by software to allow other programs to access its functions?
  • Which practice removes device restrictions to gain greater control over the operating system?
  • Which term describes the process of making password-based keys more resistant to brute-force attacks by applying iterations of a hashing function?
  • Which not-for-profit entity is set up to share sector-specific threat intelligence and security best practices among its members?
  • Which device reads RFID or NFC tags at close range and is commonly used at entry points?
  • Which term refers to the end-to-end process of supplying, manufacturing, distributing, and releasing goods and services to a customer?
  • Which practice involves estimating the personnel, storage, computer hardware, software, and connection infrastructure resources required over some future period of time?
  • What is the purpose of a preventive security control?
  • Which term refers to a framework that provides a structured approach to cybersecurity risk management and is widely adopted across industries?
  • Which statement best describes the SHA family?
  • Which remote access protocol is the basis of macOS screen sharing?
  • Which term describes the process of assigning ownership and governance to assets within an inventory?
  • Using persuasion, manipulation, or intimidation to make the victim violate a security policy. The goal of social engineering might be to gain access to an account, gain access to physical premises, or gather information.
  • Which policy area governs the secure procurement of assets and services, ensuring purchases come from authorized suppliers?
  • Which item is issued by a certificate authority to guarantee that a key pair is valid for a particular subject?
  • What mechanism prevents a device attached to a switch port from communicating unless its MAC address matches a protection profile?
  • Which testing approach involves running primary and backup systems in parallel to validate backup functionality without disrupting normal operations?
  • Which standardized, stateless architectural style is used by web applications for communication and integration?
  • A virtual private networking solution that uses digital certificates to identify and host and establish secure tunnels for network traffic is a?
  • A method of validating a certificate by tracing each CA that signs the certificate up through the hierarchy to the root CA is known as
  • A software vulnerability where the outcome depends on the order and timing of events, and those events fail to execute in the intended order is called?
  • Which device resembles a credit card and stores authentication information on an embedded processor for authentication?
  • What is the facility where security professionals monitor and protect critical information assets?
  • Which concept identifies how business processes should deal with both minor and disaster-level disruption by ensuring that there is processing redundancy supporting the workflow?
  • What describes groups that systematically exchange data about emerging cybersecurity threats and vulnerabilities?
  • What describes the ability of a system to recover quickly from failure events with minimal manual intervention?
  • Which term describes a malicious script designed to run in a user's browser by exploiting trusted sites, often delivered via a link or on a compromised site?
  • What is the term for any method by which cryptographic keys are transferred among users?
  • What term describes the standards for data access over cellular networks across 2G to 5G?
  • Which indoor positioning technology is used to determine a device's location indoors?
  • A firewall designed to protect web applications and their back-end databases from code injection and DoS attacks is a?
  • Which access-control approach grants general access unless an explicit prohibition is in place?
  • What term refers to a disk drive whose controller can automatically encrypt data as it is written to the disk?
  • Which form of phishing uses SMS text messages to trick a victim into revealing information?
  • Which of the following terms best describes a secure method of connecting remote users to a network by creating an encrypted tunnel over the Internet?
  • Which term describes the path a threat actor uses to execute a data exfiltration, service disruption, or disinformation attack?
  • What PKI element centralizes generation and storage of cryptographic keys?
  • In asset management, the policies and procedures that govern the removal of devices and software from production networks, and their subsequent disposal through sale, donation, or waste.
  • Which standard enables federated identity management by allowing resource servers to rely on an external identity provider?
  • What provisioning architecture uses declarative configuration files and code to automate deployment of resources?
  • The process through which changes to the configuration of information systems are implemented as part of the organization's overall configuration management efforts?
  • What indoor location technology triangulates proximity to Bluetooth beacons or Wi-Fi access points to determine position?
  • Which standard specifies device-level encryption for storage devices?
  • Which term describes a human-based attack where the attacker extracts information while speaking over the phone or leveraging IP-based voice messaging services (VoIP)?
  • Which term describes a threat actor who is assigned privileges on the system that cause an intentional or unintentional incident?
  • Which term describes the capability of an authenticator or other cryptographic module to prove that it is a root of trust and can provide reliable reporting to prove that a device or computer is a trustworthy platform?
  • Which standard enables federated identity management by allowing resource servers to rely on an external identity provider?
  • Which IPSec framework is used for creating a Security Association?
  • The degree of access a threat actor possesses before initiating an attack is described as what?
  • A secure tunnel created between two endpoints connected via an unsecure transport network (typically the Internet) is a?
  • Which protocol provides addressing and routing at the Internet layer in the TCP/IP suite?
  • Which PNAC mechanism allows the use of EAP authentication when a host connects to an Ethernet switch?
  • Who typically holds the job title of the person with overall responsibility for information assurance and systems security?
  • Which domain-impersonation tactic involves registering a domain name visually similar to a legitimate domain to deceive users?
  • Which security control configuration ensures continued access to a resource in the event of a failure?
  • Which term is associated with the team responsible for incident response readiness and coordination across the organization?
  • Which exercise is described as a discussion of simulated emergency situations and security incidents?
  • Which term describes an email-based social engineering attack in which the attacker appears to be a legitimate institution to elicit private information?
  • Which port is commonly used by the Remote Desktop Protocol?
  • What type of attack compromises the availability of an asset or business process?
  • Which term captures the idea that IT requirements can be delivered as cloud services spanning software, platforms, and infrastructure?
  • Which device activates EAPoL and forwards the supplicant's authentication data to an authenticating server such as a RADIUS server?
  • Which cloud service model provisions virtual machines and network infrastructure?
  • Which term describes a configuration that exposes a large attack surface due to open ports, weak authentication, default credentials, or lack of secure communications?
  • Which legacy encryption standard for wireless networks is considered insecure and should be avoided?
  • The AIC triad is the reverse order of the CIA triad and includes which three goals?
  • Which term best describes an appliance dedicated to generating and securely storing cryptographic keys?
  • Which term describes a threat actor who uses hacking and computer fraud for commercial gain?
  • What term describes a networking and security architecture that provides secure access to cloud applications while reducing complexity, combining services like SD-WAN with security?
  • Which protocol enables clients to query the revocation status of a certificate in real time?
  • Which term describes a hardware device inserted into a cable run to copy frames for analysis?
  • Which term is specifically associated with organizations that coordinate sector-specific threat intelligence sharing among members?
  • The security concept that ensures the party that created or sent data cannot deny having sent it.
  • A security process that provides identification, authentication, and authorization for users, computers, and other entities in systems.
  • In cryptography, a key that is used within the context of a single session only is called what?
  • Which X500 attribute is commonly used as the host or user identifier in a digital certificate's subject?
  • Which term describes a device that provides remotely managed, filtered power output to connected equipment?
  • A security assessment method that uses active tools to simulate an attack, verify existence of threats, bypass controls, and exploit vulnerabilities is called what?
  • Which term refers to a snapshot or image-like backup used to restore a device to a specific state?
  • PKCS stands for
  • What basic principle of security states that something should be allocated the minimum necessary rights to perform its role?
  • Controls like alarms, gateways, locks, lighting, and security cameras that deter and detect physical access to premises belong to which category?
  • Which network service stores identity data for all objects within a network, including users and devices?
  • Which XML-based web services protocol is used to exchange messages?
  • Which model is nondiscretionary and relies on a predefined set of rules or restrictions to grant access in a nondiscretionary manner?
  • Which term refers to a security protocol that uses certificates to authenticate and encrypt web communications?
  • A vulnerability that a threat actor can exploit to run malicious code with the same privilege level as the vulnerable process is called?
  • Which term describes the process of identifying, authenticating, and authorizing users, computers, and other entities in systems?
  • Which defense on a host uses both signatures and heuristic detection to stop threats in real time?
  • Which term denotes a wireless network where devices connect directly to each other without an established infrastructure?
  • Which term describes a portable hardware security module with a computer interface (USB or NFC) used for multifactor authentication?
  • Which type of security control acts before an incident to reduce the likelihood that an attack can succeed?
  • Which term describes the process of thoroughly and completely removing data from a storage medium so that file remnants cannot be recovered?
  • Used to create the entire architectural instance/copy of an application, disk, or system. It is used in backup processes to restore the system or disk of a particular device at a specific time. A snapshot backup can also be referred to as image backup.
  • Which term describes an organization that provides infrastructure, application, and/or storage services through an "as a service" subscription-based offering?
  • Control giving oversight of the information system, such as risk identification or evaluation and selection of security controls?
  • A security copy of production data made to removable media, typically according to a regular schedule.
  • Which configuration exposes a large attack surface, such as through unnecessary open service ports, weak or no authentication, use of default credentials, or lack of secure communications/encryption?
  • In security scanning, which term describes a finding reported when it should not be?
  • What device distributes client requests among multiple resources to provide fault tolerance and improve throughput?
  • A software that reviews system files to ensure that they have not been tampered with.
  • Which default Linux security module provides context-based permissions for CentOS and Red Hat Enterprise Linux?
  • Which technique hides a message by embedding it in an innocuous medium such as an image or audio file?
  • Backup that writes job data to media that is stored in a separate physical location to the production system.
  • Which proxy-related component stores copies of frequently accessed web pages to improve performance?
  • In a Windows domain, which construct is used to distribute per-user and per-computer security settings such as password policies and firewall status?
  • What is the general term for the policies, protocols, and hardware that authenticate and authorize access to a network at the device level?
  • Which cloud deployment is intended for exclusive use by a single organization?
  • Which term describes the capability of an authenticator to prove it is a root of trust and provide reliable reporting to prove platform trustworthiness?
  • In Kerberos, what token is issued to an authenticated account to allow access to authorized application servers?
  • Which algorithm is a classic example of asymmetric cryptography?
  • Which concept refers to the patterns of adversary behavior including tactics, techniques, and procedures (TTPs)?
  • Which feature of proxy servers enables the retention of a copy of frequently requested web pages to speed up subsequent requests?
  • What type of firewall runs on a single host and protects only that host?
  • Which mobility model provides organization-owned devices with some personal usage while maintaining control?
  • A method used by file systems to record changes not yet made to the file system in an object called a journal.
  • Which term describes a guided, non-live exercise used to discuss response to events?
  • Which certificate feature allows identification by multiple hostnames?
  • The process of deploying an account, host, or application to a target production environment, including proving identity and issuing credentials and access permissions, is called what?
  • A technique for obscuring the presence of a message by embedding information within a file or entity.
  • In vulnerability assessment, which term refers to factors or metrics due to local network or host configuration that increase or decrease the base risk level?
  • Which category of devices can report state data and be managed remotely over IP networks?
  • A structured list detailing components and dependencies used in software.
  • A cloud service model that provisions application and database services as a platform for development of apps.
  • Which term represents the security strategy of distributing security controls across multiple layers rather than depending on a single perimeter?
  • Which backup type stores data in the same location as production systems?
  • Which attack involves injecting a database query via user-supplied input to a server?
  • Which term describes copying traffic from switch ports to monitor communications by using a dedicated monitoring port?
  • Which term describes the ability of a system to scale with increasing demand?
  • Which asset disposal technique relies on a third party to perform data remnant removal and provides documentary evidence that the process is complete and successful?
  • What describes a software application or gateway that filters client requests for various types of Internet content (web, FTP, IM, etc.)?
  • Tools designed to assist with identification of third-party and open-source code during software development and deployment.
  • Which term is a standard for two-way radio communications over very short distances, facilitating contactless payments and similar technologies?
  • Which term denotes a security protocol that uses certificates for authentication and encryption to protect web communications and other application protocols?
  • Which term describes detective and preventive security controls that use an agent or network configuration to monitor hosts, allowing for more accurate credentialed scanning, but consumes some host resources and is detectable by threat actors?
  • Which policy allows employees to choose from a set of corporate devices for work?
  • Which authentication service is based on a time-sensitive, ticket-granting system and provides single sign-on across services?
  • A vulnerability in software that is unpatched by the developer or an attack that exploits such a vulnerability is called?
  • Which term refers to detective and preventive security controls that can perform both detection and prevention, often requiring software agents on hosts?
  • Which term describes programming languages that enforce strict type-checking at compile time to prevent certain classes of memory errors?
  • Which term describes a broad set of tools and techniques designed to mislead attackers and increase the effort required to breach defenses?
  • Demanding payment to prevent the release of information describes which term?
  • Which list contains certificates that were revoked before their expiration date?
  • Which detection method is described as identifying threats by deviations from established baselines in network behavior?
  • In asymmetric encryption, which key is publicly distributed?
  • What is a small unit of supplemental code to address a security problem or functionality flaw in software?
  • Software that can suggest and store site and app passwords to reduce risks from poor user choices and behavior. Most browsers have a built-in password manager.
  • What does SSID stand for?
  • Which security control configuration blocks access to a resource in the event of a failure?
  • Which standard encapsulates EAP communications over a LAN or WLAN to implement port-based authentication?
  • Computing architecture with metered, on-demand resources and high availability, billed by usage.
  • Signatures and pattern-matching rules supplied to analysis platforms as an automated feed.
  • Which proxy is also referred to as forced or intercepting because it redirects without client configuration?
  • The scheduling approach used by load balancers to route traffic to devices that have already established connections with the client is called?
  • Which monitoring approach analyzes network packets for known attack signatures?
  • Which technique ensures message authentication without requiring public-key cryptography by using a secret key and a hash function?
  • Which Kerberos token is used to obtain access to application servers after initial authentication?
  • The process by which the need for change is recorded and approved?
  • Which role is responsible for implementing security policies, frameworks, and controls in an organization?
  • Which provisioning model allows organization-owned devices with some personal use, such as private email?
  • Which deception strategy returns spoofed data in response to network probes?
  • What best describes Symmetric Encryption?
  • Operations that transform a plaintext into a ciphertext with cryptographic properties, also called a cipher. There are symmetric, asymmetric, and hash cipher types.
  • Which term best describes distributing processing and data storage across multiple, geographically separated sites to enhance resilience?
  • Which term best describes a practice of using publicly available sources like social media, news, and official reports to gather security intelligence?
  • Which resilience strategy increases attack costs by provisioning multiple controls, technologies, vendors, and crypto implementations?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy