A company's IT staff is given the task of securely disposing of 100 server HDDs. The security team informs the IT staff that the data must not be accessible by a third party after disposal. Which of the following is the MOST time-efficient method to achieve this goal?
A. Use a degausser to sanitize the drives.
B. Remove the platters from the HDDs and shred them.
C. Use software to zero fill all of the hard drives.
D. Perform a quick format of the HDD drives.
正解:A
質問 2:
A user contacts the help desk about getting a newly installed application to work When searching the logging servers for the user's IP address the help desk analyst finds the following output from the host-based firewall:

Which of the following is MOST likely occurring?
A. The PC is infected with C2
B. The application needs host firewall rules
C. The host cc abc com is scanning the PC
D. WINDOWS-ABCXYZ is an unknown host
正解:A
質問 3:
A security analyst received an after-hours alert indicating that a large number of accounts with the suffix "admin'' were locked out. The accounts were all locked out after five unsuccessful login attempts, and no other accounts on the network triggered the same alert. Which of the following is the BEST explanation for these alerts?
A. The administrator accounts do not have rigid password complexity rules, and this made them easier to crack.
B. The standard naming convention makes administrator accounts easy to identify, and they were targeted for an attack.
C. The company has implemented time-of-day restrictions, and this triggered a false positive alert when the administrators tried to log in.
D. The threshold for locking out administrator accounts is too high, and it should be changed from five to three to prevent unauthorized access attempts.
正解:B
質問 4:
A security administrator is investigating a possible account compromise. The administrator logs onto a desktop computer, executes the command notepad.exe c:\Temp\qkakforlkgfkja.1og, and reviews the following:
Lee,\rI have completed the task that was assigned to me\rrespectfully\rJohn\r
https://www.portal.com\rjohnuser\rilovemycat2
Given the above output, which of the following is the MOST likely cause of this compromise?
A. Rootkit
B. Keylogger
C. Virus
D. Worm
正解:B
質問 5:
A manager makes an unannounced visit to the marketing department and performs a walk-through of the office. The manager observes unclaimed documents on printers. A closer look at these documents reveals employee names, addresses, ages, birth dates, marital/dependent statuses, and favorite ice cream flavors. The manager brings this to the attention of the marketing department head. The manager believes this information to be PII, but the marketing head does not agree. Having reached a stalemate, which of the following is the MOST appropriate action to take NEXT?
A. find the privacy officer in the organization and let the officer act as the arbiter.
B. To maintain a working relationship with marketing, quietly record the incident in the risk register.
C. Notify employees whose names are on these files that their personal information is being compromised.
D. Elevate to the Chief Executive Officer (CEO) for redress; change from the top down usually succeeds.
正解:A
質問 6:
An employee on the Internet-facing part of a company's website submits a 20-character phrase in a small textbox on a web form. The website returns a message back to the browser stating Error: Table 'advprofile' entry into column 'lname' has exceeded number of allowed characters. Error saving database information.
Of which of the following is this an example?
A. Improper error handling
B. Improperly configured account
C. Resource exhaustion
D. Buffer overflow
正解:A
質問 7:
Which of the following are examples of two-factor authentication? (Select THREE)
A. Voice recognition and fingerprint
B. Proximity reader and password
C. Password and TOTP
D. Smart card and ID badge
E. Smart card and PIN
F. User ID and password
正解:B,C,E
質問 8:
A penetration tester is testing passively for vulnerabilities on a company's network. Which of the following tools should the penetration tester use? (Select TWO).
A. tcpdump
B. Wireshark
C. Nmap
D. Snort
E. Zenmap
F. Nikto
正解:B,C
質問 9:
Which of the following security controls BEST mitigates social engineering attacks?
A. Mandatory vacation
B. User awareness training
C. Least privilege
D. Separation of duties
正解:B
クリック」


0 お客様のコメント