All questions

CompTIA SecurityX Practice Test

Browse all practice questions for the CompTIA SecurityX Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

CompTIA SecurityX Practice Test course image
All questions

These questions are part of the practice quiz. Start practicing

  • What metric represents the average amount of time it would take to repair an asset or component after a disaster?
  • Which term describes employees who can pose a threat to data security due to their position or disposition?
  • Connects to a separate and isolated network not accessible from the internet or the rest of the LAN.
  • Which feature permanently alters the state of a transistor on a chip if the bootloader is modified?
  • Which peripheral is able to connect using the USB or Lightning port on a mobile device?
  • Which term describes testing recovery capabilities by executing real business transactions?
  • Which term is used to recover a device after an attack?
  • Which description best defines Policy Template?
  • Which KPI represents the percentage of time that the infrastructure, system, or solution is operational under normal circumstances?
  • Which term describes data organized as tables and lists, such as in a spreadsheet?
  • Which term describes a client-based solution that streams an application directly to a user's PC?
  • Which term refers specifically to failures of power, heating and cooling systems, and other similar problems?
  • Which term describes a Perl framework that automates manual release processes?
  • Which device detects attempts to cause a denial of service on a wireless network?
  • Which term provides sufficient support for multilevel security to meet government requirements?
  • Which metric describes the percentage of time a system remains operational under normal conditions?
  • RAID stands for Redundant Array of Independent/Inexpensive Disks. Which property does RAID provide?
  • What does RFI stand for?
  • Which term is often used to integrate other services?
  • Which term is described as a generic term that refers to the deletion or making data inaccessible?
  • In the context of data loss prevention, EDM is defined as?
  • Which term describes the overall process from concept through retirement of a system?
  • What is the function of a hypervisor?
  • When two people each have half of the knowledge for how to do something.
  • Which term describes the liability that arises when a subcontractor fails to meet security requirements?
  • Which term describes the set of plans focusing on disaster response and maintaining operations?
  • Which term refers to the entire period of time that data exists within your systems?
  • Which term defines the levels of assurance, with 1 the lowest and 7 the highest?
  • Which statement best defines 3D Printing?
  • Which level is described as valuable and must be protected by several restrictions on viewing?
  • Which technology is similar to RDP but fully cross-platform and open-source?
  • Virtualization is defined as which of the following?
  • Which provides services with a single purpose or function?
  • The ease with which a security solution or device can be used and how well it suits organization needs is referred to as:
  • Which technology is commonly used for contactless payments and access control due to its very short-range interaction?
  • Which control is used to discourage violations of security policies?
  • Carries the traffic that provides the signals to or from a router. Decides how to move data.
  • Trusted Third Party (Bridge) is best described as which concept?
  • Which firmware interface enhances boot security and provides a graphical interface and 64-bit support?
  • Which concept is focused on ensuring that code updates are tested and can be released at any time?
  • Which term suggests that every organization has its own rules for conducting the information technology portion of its business?
  • Which term serves as a single source of truth within the organization?
  • Which term refers to the protection of information from being accessed by unauthorized individuals or systems?
  • Which term refers to a variant that combines traditional protocols and SDN strategies?
  • What term refers to the competency of the threat actor?
  • Which term refers to the memory structure used by switches to map MAC addresses to physical ports for efficient forwarding?
  • Creates a GRE tunnel over an IP network to connect the network analyzer to the network device.
  • Which term refers to a comprehensive test that shuts down primary site operations and validates recovery capabilities?
  • What term describes having extra components used to support a system in case of component failure?
  • Which term describes deploying private networks in the cloud or extending on-premise network into the cloud?
  • Which data protection technique preserves data format while hiding actual values by substituting placeholders?
  • Which term describes the process of tracking changes to a standard reference point?
  • Which term describes data that is not actively used?
  • Used to reinforce users with the importance of their help in securing the organization's valuable resources.
  • The probability that a threat will be realized and a continual balancing act of a vulnerability against a threat.
  • Which control approach enforces policies based on conditions or rules without considering individual user identity?
  • Fully controlled and managed by the cloud service provider?
  • A federal law that prohibits unlicensed export of certain commodities or information.
  • Which concept allows dictating where data will be stored by geographical regions in cloud services?
  • Which concept considers an OEM's supply chain management and security reputation?
  • Which term is defined as copying data to an environment for storage in case it will be needed in an active production environment again later?
  • Quantum Cryptography is defined as
  • Which standard set defines a framework for evaluating IT product security using Evaluation Assurance Levels (EALs)?
  • Which authentication method relies on a password-based authentication and key agreement that provides forward secrecy?
  • OpenID is described as which in the context of authentication protocols?
  • Which term serves as a single source of truth within the organization?
  • What does ALE stand for in risk management?
  • Which term is set in the processor to designate memory areas that cannot execute code at all?
  • Which concept is primarily concerned with protecting an individual's sensitive information, including personally identifiable information, from exposure?
  • Which term describes data that has been sanitized to remove personal identifiers before sharing?
  • Which component enables automation in assembly lines, autonomous field operations, robotics, and other applications?
  • Which preventive administrative control should be considered when drafting authentication and authorization policies to prevent fraud by breaking high-risk functions into smaller parts?
  • Which concept encapsulates computer programs from the underlying OS on which they are executed?
  • In resource metrics, saturation refers to which of the following?
  • What is the purpose of Data Loss Prevention (DLP) in a network?
  • Which term is focused on the quality of the data and the associated metadata?
  • How is Data format defined?
  • Which is a type of network isolation that physically separates a network from all other networks?
  • Which concept is flexible in nature, allowing exceptions and allowances when a unique situation occurs?
  • Which sector focuses on patient health devices, medical equipment, supply management, and building management in hospital and other care facilities?
  • Which device gives endpoints without public IP addresses access to the Internet without exposing those resources to incoming Internet connections?
  • Which protocol creates a secure and encrypted tunnel between two devices? (Port 500)
  • Which agreement is designed to simplify future negotiations by outlining a framework for ongoing work?
  • Which term makes traffic switching decisions based on the MAC address of the sending and receiving devices through transparent bridging?
  • Which sector focuses on the movement of materials and goods using embedded technology to control automated transport and lift systems, as well as embedded sensors for tracking cargo containers?
  • Watermarking is described as which of the following?
  • Which term is used for a centralized system that collects, analyzes, and correlates security events from multiple sources?
  • Which term is a centralized repository of organizational information?
  • Which term is designed to collect and consolidate data from across the organization to support planning and operations?
  • Which technology provides buffer overflow prevention by making it difficult to guess the location of executable files stored in RAM?
  • Which organization is known for creating a series of international standards across multiple industries?
  • Which term refers to a system that stores and provides access to directory-based authentication data across a network?
  • Which model is described as risk-focused and iterative, with repeated cycles called spirals?
  • Which description best defines the Web of Trust?
  • Architecture is similar to a dual-homed architecture except it uses more than two interfaces.
  • Which component provides necessary network services to end users?
  • Which concept refers to discovery conducted in electronic format during legal proceedings?
  • What is the purpose of a Requirements Definition?
  • Which term best describes data that is stored or transmitted in a readable, unprotected format?
  • Which term describes the level of risk an organization is willing to accept?
  • Which term describes the action of creating a formalized process and incident report form for your vendor to utilize?
  • Which term is used to describe a set of tools that enables various forms of communication within an organization?
  • Which solution monitors traffic based on the configuration of the interface's access control list?
  • What is the purpose of a Data Tag?
  • Which term is used as a basic training event for team members?
  • Which protocol is widely used for network management and defaults to port 161?
  • Which term is focused on the mitigations put into place to lower the risk that was just assessed?
  • Which term refers to preserving information for legal actions across formats?
  • Which protocol is typically used for centralized AAA in mixed vendor environments and uses UDP?
  • Which term uses separate virtual networks to allow security professionals to test suspicious or malicious files?
  • Which practice places development, QA, and operations into one team to improve collaboration and reduce deployment time?
  • What distributes the computational workload across multiple hardware products?
  • Used to state the role of security in an organization and establishes the desired end-state of the security program.
  • Which bidding document invites suppliers to bid on specific products or services and often aligns with an invitation for bid?
  • Which API creates and manages data containers using an application programming interface?
  • Which device provides content caching, traffic scrubbing, IP masking, and load balancing for inbound traffic?
  • Which term describes a representation of data with a shared purpose, need, and user?
  • Which role provides threat intelligence and overall context during incident response?
  • Which document is used to gather information about suppliers' capabilities before an RFP or RFQ?
  • What concept allows customers to share computing resources in a public or private cloud?
  • Which term describes a one-way function that reduces a message to a hash value used to verify message integrity?
  • Which technique collects expert opinions asynchronously via written responses to forecast future events?
  • Which device uses specific rule sets to prevent common web application attacks such as cross-site scripting and SQL injection?
  • Which term refers to a digital currency that operates without a central authority?
  • Which technology detects and stops adware, spyware, viruses, worms, and other destructive types of software?
  • Implemented through hardware or software and used to prevent or restrict access to a system is best described as which control?
  • Which term addresses the security needs of a specific technology, application, network, or computer system?
  • What term describes a network boundary element used to monitor and regulate traffic at the edge?
  • Shuts down operations at the primary site and shift operations to the recovery or backup site. They are great, but expensive.
  • Which term describes the senior executive role primarily responsible for maintaining the confidentiality, integrity, and availability of an information asset?
  • Which term covers discovering electronic information in legal cases?
  • Which statement best describes the Ex-Frame-Options header?
  • Which term is used for identifying the person responsible for the confidentiality, integrity, availability, and privacy of information assets?
  • What is the primary purpose of a Content Delivery Network (CDN)?
  • What does Deidentification refer to?
  • Which term determines a qualitative or quantitative estimate of risk related to a well-defined situation and a recognized threat?
  • Which recovery site option provides more time to recover and is cheaper than a warm site, typically described in weeks?
  • Which vulnerability allows the attacker to gain complete control over a device without even being connected to the target device?
  • Forensic Watermark refers to what?
  • Which term describes the process when data you have created, used, shared, stored, and archived is no longer valuable?
  • Which process involves comparing the current security posture to the desired state to identify gaps?
  • Which term occurs whenever there is a disclosure or modification of data?
  • Which category involves the creation of components and assembling them into finished products?
  • What term defines the maximum downtime a business can tolerate for an asset or component?
  • Which classification indicates information with no restrictions and no risk if disclosed to the public?
  • What is the term for a one-way function that produces a hash value to determine message integrity when compared between sender and receiver?
  • Refers what they are achieving through their attack on our organization.
  • Which approach enables an administrator to implement security policies across all users based on predefined rules?
  • Which term allows or blocks data movement based on its associated classification level?
  • What is the term for the process organizations use to preserve all forms of potentially relevant information when litigation is pending?
  • Which concept gathers secure metrics to validate the boot process in an attestation report?
  • What does OLA stand for?
  • Which term describes locating the correct host on the local network and delivering frames using its MAC address?
  • Which term describes a set of practices that combines development, security, and operations to improve delivery?
  • Which term is a measure of the probability that a particular risk will be realized and impact the organization?
  • Which description matches a DaaS deployment where the provider maintains the infrastructure and delivers desktops as a service?
  • Which agreements are binding and used to govern ongoing operations between partners?
  • What concept describes the method in place for users to authenticate and access training resources?
  • Which component holds the list of MAC addresses learned by the switch for each port?
  • Which package bundles multiple security patches released over time into one installation?
  • Which term refers to a spreadsheet-like report that documents the security requirements that a new asset must meet?
  • Which act imposes requirements on website owners and online services directed to children under 13?
  • Which technique provides sender authentication and message integrity by encrypting the hash with the sender's private key?
  • Which term describes the action of enabling a switch to send a copy of all traffic to a monitoring device by configuring a mirror port?
  • Which technology provides memory address randomization to prevent buffer overflow exploits?
  • The actual costs that an organization must pay to procure and replace hardware and software, as well as to any repair companies for their labor.
  • Which term describes relying on software rather than hardware to perform the load balancing functions?
  • What term refers to the input and output controls on a PLC that allow a user to configure and monitor the system?
  • Which IPv6 transition technology is designed to provide IPv6 connectivity for hosts behind NAT without requiring native IPv6?
  • Which role recovers key artifacts and evidence from the network and uses them to build a timeline of events to understand what happened?
  • Which agreement sets the security controls for data exchange between two partner organizations?
  • When merging two networks, what factor concerns data processing levels and regulatory issues?
  • Baselines affect which groups?
  • Which term is a role that is responsible for the oversight of any kind of privacy-related data?
  • Enterprise Mobility Management (EMM) enables
  • Which term stores all of the data relating to the organization's customers?
  • Diameter is a peer-to-peer protocol created as a next-generation version of RADIUS. Which port does it use?
  • Which policy controls how many unique passwords a user must create before reusing a previous one?
  • PHI is included in which data category?
  • Which term ensures hardware is procured tamper-free from trustworthy suppliers?
  • Which architecture allows for the full integration of storage, network, and servers without hardware changes?
  • Which concept refers to the process of confirming a user's identity through additional verification steps beyond basic credentials?
  • Which technology maintains confidentiality of data in transit from the user's system to the server? (Port 443)
  • Which term prevents copying and pasting between the remote client PC connected over RDP and their host?
  • Not concealed; not secret refers to which term?
  • What is OWASP?
  • Which term describes a host-level entity used to provide data about the device to a management system?
  • Which concept is designed to support multilevel security to meet government requirements?
  • Which testing approach performs security tests while the application is running and in use?
  • Which method enables two parties to jointly evaluate a private function without revealing inputs?
  • Which policy focuses on managing how credentials and passwords are created and used across an organization?
  • Involve registering all the content considered sensitive. Which DLP concept involves registering all sensitive content?
  • Which term describes failures of power and environmental infrastructure like HVAC systems?
  • Which facility type is not fully equipped like a hot site and is typically described in terms of days?
  • Which act focuses on government information security and mandates an agency-wide information systems security program?
  • DHCP Snooping increases ARP inspection efficiency and prevents DHCP-related spoofing on a LAN.
  • Which term describes an information security governance component that describes how policies will be implemented within an organization?
  • Which patch management action is typically applied immediately after testing in a lab environment?
  • What is the programming language entered into the system through the creation of a graphical diagram used in the PLCs?
  • Which description best characterizes Quantum Computing?
  • Which term best describes a policy that governs mandatory standards and laws affecting the organization?
  • What term describes a storage network that connects storage devices using a high-speed private network interconnected by storage-specific switches?
  • Which process identifies and manages privacy risks arising from new projects, initiatives, systems, processes, strategies, policies, business relationships, and other risk events?
  • Which term represents a formal policy baseline that defines how governance policies should be implemented across the organization?
  • Which term describes a microprocessor manufacturing utility that is part of a validated supply chain?
  • Which term applies confidentiality and privacy labels to a piece of information?
  • What is the single point of contact for Microsoft security incidents within your organization called?
  • Which term involves copying data to an environment where it is stored for potential future use in an active production environment again later?
  • Which design pattern provides a more secure layout for the storage of data in a web application?
  • Which EAP method utilizes simple passwords and the challenge-handshake authentication process to provide remote access authentication?
  • Which term describes a security framework that dictates the security obligations of a cloud computing provider and its clients to ensure accountability?
  • What is the publicly accessible registry documenting the security and privacy controls provided by popular cloud computing offerings?
  • Which term describes the organization of information into preset structures or specifications?
  • PHI stands for what?
  • Which concept is described as managing personnel and assets through security policies, standards, procedures, guidelines, and baselines?
  • Which action blocks the ability to print to a printer?
  • Which technology protects the contents of the storage device when the operating system is not running?
  • What describes having extra components not strictly necessary to function, but used in case of a failure in another component?
  • Which practice involves depositing the software's source code with a third-party escrow agent?
  • Which term describes the risk that remains after applying mitigations and security controls?
  • Occurs when a partner or outsource provider fails to fulfill organizational requirements.
  • Which term corresponds to What causes someone to act?
  • Which term is used to describe a NAC category when enforcing access policies on devices attempting to connect to the network?
  • Which security testing method analyzes source code to identify vulnerabilities that could expose an application to attack?
  • Connects a monitoring device to a local port and receives a copy of every piece of traffic going into or out of the network device.
  • Which term describes the act of complying with orders, rules, or requests?
  • Which term corresponds to the description: a term by how often the youngest media sets are overwritten?
  • Which concept has been developed through a community effort for major programming languages?
  • Which term captures the same information as a baseline but at a different point in time?
  • Defined as having investigated all reasonable measures to address a given risk.
  • Which solution provides visibility over endpoints to detect and respond to threats?
  • Which solution acts as a reverse proxy to accept all API calls and aggregates the required services to fulfill such requests?
  • Which component stores usernames, passwords, or encryption keys?
  • Confidentiality (Cryptography) protects against unintentional, unlawful or unauthorized access, disclosure, or theft of any sensitive information.
  • Which term describes the event when a user makes the data available to someone outside the organization?
  • Which framework is associated with evaluating IT products using EALs?
  • Which technique connects a network analyzer to a device by creating a GRE tunnel for traffic monitoring?
  • Which concept indicates the history of a software base, recording changes over time?
  • Which process generalizes data to protect individuals in a dataset by grouping or suppressing details?
  • Which technique retrieves an item from a service without revealing which item is retrieved?
  • Which practice isolates risky code changes from production to prevent affecting users?
  • Which term describes evaluating a known function without revealing the parties' inputs when the function is public?
  • Which term refers to data that is stored, transmitted, or processed in an unprotected format that anyone can view?
  • Which authentication approach requires two or more independent factors to verify a user's identity?
  • Which term describes systems and users interacting with devices on public networks such as the internet and other clouds?
  • Which term protects the VDI-hosted image when being used by end users?
  • Which term describes the concept that data may be governed by the laws of the location where it is stored, regardless of where it was collected?
  • Which term is used as a reference point to compare current performance against past measurements?
  • Which term encompasses identifying assets and their value, identifying threats and vulnerabilities, and determining risk as a combination of likelihood and impact?
  • Which term acts as a middleman and consolidates all of the different cloud security services into one suite of tools for an organization?
  • In a virtualization stack, which component manages the distribution of physical resources to virtual machines?
  • What term identifies any single software or hardware flaw that can bring down a system if it fails?
  • Isolated location within data center regions where public cloud services originate and operate.
  • An Artificial Neural Network (ANN) is best described as?
  • Which term describes the process of reviewing and validating password policy settings to ensure compliance?
  • Which act affects publicly traded corporations by requiring certain accounting methods and financial reporting?
  • Which concept is about restricting access to the minimum level required for each user?
  • What component contains the keys used for cryptographic functions and enables a secure boot process?
  • Which policy model indicates corporate ownership of devices used by employees for work-related purposes only?
  • What analysis is conducted to determine the impact of a disruption on business operations as part of continuity planning?
  • In a Data Loss Prevention policy, what does the Alert action do?
  • Which term describes scanning the network for vulnerabilities and ensuring systems are updated with patches?
  • What term describes a technology's ability to perform under an increased or expanding use case?
  • Describes the technologies standards and use cases that enable portability of identity information across autonomous security domains.
  • Hash Digest is a unique digital identifies or fingerprint that represents the data received as an input to the function.
  • Which term is used to isolate and protect zones within data centers or cloud environments, securing them individually?
  • Which feature prevents unwanted processes from executing during the boot operation?
  • Employee threats, such as disgruntled, untrained, or uncaring employees, fall under which category?
  • Which term ensures a selected vendor will be around for the long-term?
  • Which component provides modifications to the Linux kernel to ensure higher levels of security?
  • What does NDA stand for?
  • Which model focuses on processes and behaviors used during software development and assigns maturity levels from 1 to 5?
  • Which security concept involves digitally signing executables and scripts to confirm the software author and guarantee code has not been altered?
  • Which term describes enforcing access policies based on the device's location within defined geographic boundaries?
  • Which term refers to the use of electronics and computer-controlled devices to take control of processes?
  • Lightweight EAP (LEAP) is best described as which of the following?
  • Which data classification includes blueprints for weapons or similar information that could gravely damage national security if disclosed?
  • The technology term for the efficiency with which a system can accommodate workload growth while preserving performance and availability.
  • Which term denotes growing the capacity by adding more resources to support load, rather than increasing individual resource power?
  • OpenID is best described as which?
  • Which term describes a file on the share drive replaced by a message stating a policy violation has occurred?
  • Caching is described as which of the following?
  • Which system provides the mechanisms for workflow and process automation by using embedded devices?
  • What phase is described as data being put to work to achieve a purpose within your organization?
  • Where can the Statement of Applicability (SOA) be configured to control the flow of traffic?
  • Which term is most closely associated with privacy governance and data protection within an organization?
  • It considers the cost of the money spent today against the savings that we might see tomorrow.
  • Which term describes a contract-like framework that defines what personally identifiable information can be shared, with whom, how it is transmitted securely, and opt-out options?
  • Which technology creates a personal area network over 2.4 GHz to enable wireless connectivity?
  • Which protocol authenticates and authorizes users to services and accounts for their usage, typically using UDP ports 1812/1813?
  • Which term describes a protocol that enables BACnet to run over IP networks?
  • Which term describes the process that occurs whenever a system is no longer needed by an organization?
  • Which term collects and consolidates data from across the organization?
  • Which plan documents standard procedures for communications during disruption?
  • Which term describes the process of reducing a device's attack surface by disabling unused features, services, or ports?
  • Which recovery option uses independent and portable units to provide restoration capabilities?
  • Which testing method is performed while the app is running and users interact with the application's functionality?
  • Which policy indicates devices provided by the company may be used for both business and personal activities?
  • Which term is a checklist of actions to detect and respond to a specific type of incident?
  • Document Matching is best defined as what?
  • Which firewall sits between internal and external connections and can make connections on behalf of endpoints (circuit-level at Layer 5, application-level at Layer 7)?
  • Under which policy must an employee take a vacation during the year for review?
  • Which classification level is described as highly-sensitive data restricted to approved persons under NDA?
  • Which term identifies a piece of data under a subcategory of a classification?
  • Which practice ensures a device has had unnecessary applications, services or ports disabled or removed from the host?
  • Which cloud model involves using both private and public cloud resources in combination?
  • Which control reduces impact after an undesirable event or attack?
  • During an outage, if the system is required to receive payments and provide services, which loss occurs?
  • Which term indicates that an external organization has conducted an independent audit to verify compliance with requirements?
  • Which term is the measure used to describe the cost of owning a product or service over its lifetime?
  • Which term is designed to educate users about security best practices?
  • Which authentication allows login without a password?
  • A collection of activities that work together for a specific outcome or goal?
  • Which attack does the Ex-Frame-Options header help prevent?
  • Which sector focuses on site and building management systems, including the operation of HVAC systems, lighting systems, and security systems?
  • Establishes a requirement for the information and data exchange between two organizations.
  • Which document lists recovery strategies to restore IT after a disruption?
  • Which artifact is used to systematically identify and document potential risks in a system?
  • Measure by the number of requests a system or application can effectively support simultaneously.
  • Which term corresponds to providing the proper data classification for the information security professionals?
  • Which term bundles several released security patches into a single package?
  • Which concept describes the creation of virtual boundaries based on geographical locations and coordinates to trigger access controls?
  • Cross-Certification is best described as which concept?
  • Which approach involves reviewing code artifacts to identify security flaws without running the application?
  • Which concept allows multiple parties to jointly compute a function over their inputs while keeping those inputs private?
  • Which term refers to the fixed-size output produced by a hash operation?
  • Natural Language Processing enables computers to do what?
  • Creates a trust relationship between networks and their AD services to allow authentication.
  • Which term facilitates incident response, threat hunting, and security configurations without any human assistance?
  • Which term would you use to verify that the software's distribution is authentic by attaching a digital certificate?
  • The shortest period of time in which an asset or component should be fixed to prevent any negative consequences to the business is called what?
  • What term is defined as a site that is up and running continuously?
  • Which statement best describes the recommended ordering of SOA rules?
  • Which term describes employing traditional and SDN protocols to operate?
  • Which term describes the ongoing process of identifying, assessing, and treating risk across its lifecycle?
  • Which protocol gives control servers and the SCADA host the ability to query and change configurations of each PLC over a network?
  • Which device monitors network traffic across a network rather than a single host?
  • Which Bluetooth attack makes unauthorized access to a device via Bluetooth?
  • Which statement defines replication?
  • Involves creating fully automated workflows.
  • Which authentication type relies on an identity signal from the same system requesting authentication?
  • Can be released to the public under the Freedom of Information Act.
  • Which term refers to preventing mass data exfiltration using an external device?
  • Which term keeps track of every asset in the organization?
  • Which term is associated with detecting and reacting to component failures and is sometimes linked with RAID arrays?
  • Which NAC deployment installs the scanning engine on the domain controller instead of the end point device?
  • Which security control is designed to prevent unauthorized data exfiltration from endpoints?
  • Which EAP method uses public key infrastructure with a digital certificate installed on both client and server?
  • Which metric is used to gauge ongoing risk levels to trigger mitigation before incidents occur?
  • Which system returns an industrial process to a safe state after a predetermined condition was detected?
  • Which feature shares a cellular data Internet connection from a smartphone to multiple other devices?
  • Identity Proofing relies on a person providing additional proof of who they are.
  • Defined as having taken all reasonable actions to prevent security issues or mitigate a breach.
  • Which act affects publicly traded U.S. corporations by requiring certain accounting methods and financial reporting?
  • Which term describes downtime that reduces productivity leading to productivity loss?
  • What term best describes an ongoing process that evaluates the system or its users?
  • Which control includes installing devices like firewalls, IDS, IPS, authentication schemes, encryption, auditing or monitoring software, and more?
  • Which term describes data lost after power loss?
  • Wi-Fi Protected Access 3 (WPA3) is
  • What term describes the process of converting readable data into unreadable characters to prevent unauthorized access?
  • Which standard governs protection of credit card data during storage, processing, and transmission?
  • Which term describes replacing sensitive data with non-sensitive substitutes that maintain format and structure?
  • Which term corresponds to the description: a step further than data removal that makes an effort to destroy the underlying data?
  • Which security system scans network traffic for malicious activity and can stop it?
  • The area or region covered by an official power.
  • Which solution monitors and prevents data leakage?
  • Which classification level is described as data restricted to authorized persons or under NDA?
  • Which term refers to requiring diverse character types (lowercase, uppercase, numbers, and symbols) in passwords?
  • Which term refers to a standard set of security controls applied across resources?
  • Which concept stores data in blocks chained chronologically and immutable?
  • A specialized type of DMZ created for partner organizations to access over a wide area network is called what?
  • Which term allows a network administrator to associate specific MAC addresses from devices to specific interfaces?
  • Which term refers to a type of nonrelational database that uses a simple key-value method to store data?
  • What term means the process of downgrading of a classified piece of data or information to the unclassified level?
  • Which term corresponds to the description: data read into memory or currently inside the processor and being worked on or manipulated?
  • Which classification level could cause grave danger if disclosed?
  • Which technology reduces end-user latency by caching data closer to users?
  • Which term describes anything that could cause harm, loss, damage, or compromise to information technology systems?
  • Which device distributes incoming requests across multiple servers to optimize resource use?
  • Which term denotes something that is openly accessible and not hidden?
  • Which concept extends SELinux-style security into the Android environment?
  • Which publication defines standards for security categorization of federal information systems, requiring assessment in the CIA categories (Confidentiality, Integrity, and Availability)?
  • Which term describes a strategy that involves stopping a risky activity or choosing a less risky alternative?
  • What does Endpoint Detection and Response (EDR) provide?
  • Which policy allows employees to use company-procured devices for work-related and/or personal use?
  • Which term describes maintaining essential functions during disruption?
  • Which tool is used to centrally manage Windows policies and security groups across a domain?
  • Which term is the outcome document that analyzes an incident to improve future responses?
  • Which term describes data creation when existing data produced outside the system is imported into the system?
  • Which concept eliminates handoffs and delays that traditional development methods used?
  • Which term covers any process or procedure that might affect one of the three tenets of information security?
  • Which term is taught to perform an employee's job securely?
  • Which concept enables authentication across security domains, supporting resource access across domains?
  • The great size or importance of something is called what?
  • Occurs when a part of a company is 'spun off' to form its own company.
  • What provides a platform for companies that develop applications without the need for infrastructure?
  • What involves having a system imitate another system?
  • What does an Update provide?
  • Which process achieves group agreement without a centralized unit?
  • Which term best describes the layer handling user data traffic in networks?
  • Which non-binding agreement is used for mutual backups in disaster recovery scenarios?
  • Which category includes intangible creations such as copyrights, patents, trademarks, and trade secret designation?
  • Which term means identify issues and indicate possible security issues?
  • Which process enables computers to understand human language?
  • Which process verifies if an application meets an organization's security requirements?
  • Which concept is focused on ensuring business operations can continue with minimal downtime after a disruption?
  • Which document prioritizes the restoration of services after a disruption, including IT?
  • Which technology monitors the traffic coming in and out of a network?
  • Which bidding document details a commodity, service, or asset that an organization wants to purchase?
  • Which term refers to information kept for a specific purpose beyond standard retention policies?
  • Transitive Trust refers to which type of relationship in Microsoft Active Directory?
  • DHCP Snooping prevents poisoning attacks on the DHCP database and increases the efficiency of ARP inspection.
  • Non-Repudiation assures that sender of the message cannot deny the validity of the message sent.
  • Which cryptographic mechanism provides sender authentication and message integrity by encrypting a hash with the sender's private key?
  • Which term describes failures of physical security measures such as gates, fences, and closed circuit TVs?
  • Which term describes a decentralized security model for identity authentication?
  • Which concept creates zones in data center and cloud environments to isolate workloads from one another and secure them individually?
  • Digital Rights Management (DRM) primarily serves to?
  • Which component provides controlled access to publicly available servers hosted within the organization's network?
  • Which term refers to the act of a data disclosure or modification?
  • Which device makes routing decisions based on IP addresses?
  • Protected EAP (PEAP) is best described as which of the following?
  • What process compares current security posture to the desired posture?
  • What term describes the step beyond data destruction that verifies data has been wiped and is no longer accessible?
  • Which concept is primarily involved in ensuring safety in automated industrial processes by responding to predefined conditions?
  • Which term is used to categorize events caused by natural forces such as floods and earthquakes?
  • Which term is a software architecture style organized as a collection of loosely coupled services?
  • Occurs whenever there is a security incident?
  • Which term refers to any software that makes itself available over the Internet that uses a standardized XML messaging system?
  • Which indicator increases security by identifying activity patterns within IT services?
  • Which metric measures the ease with which a system can be maintained?
  • Which term is associated with monitoring traffic conditions and network status?
  • Which term describes removing identifying information before distribution?
  • Which term describes the process of planning and coordinating actions during an incident using pre-defined rules and priorities?
  • Which agreement covers the ability to support and respond to problems within a defined timeframe and with an agreed level of service?
  • BCP stands for Business Continuity Plan, which covers plans and processes used during a disruptive event.
  • Which objective defines the minimum downtime acceptable before critical operations suffer unacceptable impact?
  • Which term is a checklist of actions to detect and respond to a specific type of incident?
  • Which term is associated with enforcing mandatory access control in Unix-like systems and is not Android-specific?
  • RAID is a disk technology described as data written across multiple disks to tolerate a disk failure. Which option best describes RAID?
  • Which term protects data against improper modification or alteration?
  • Which term can perform sequential operations from a dedicated instruction set?
  • Which organization provides over 1300 standards and includes a Cybersecurity Framework known as the CSF?
  • By utilizing its measures, such as redundant hardware, power sources, and network connections, we can increase resiliency across the entire system. Which concept is demonstrated?
  • Contains information such as personnel records, salary information, and other data used only within the organization.
  • Which term describes combining deidentified data sets with other data sources to reveal identities?
  • Which component centralizes time-stamped event data from the control loop for trend analysis and reporting?
  • Which component stores and protects both symmetric and asymmetric encryption keys, hashes, and digital certificates?
  • Which term enables communication between applications and protocols?
  • Which term describes the set of controls that administer an organization's assets and personnel, including policies, procedures, standards, baselines, and guidelines established by management?
  • Availability is the principle that deals with ensuring data is accessible when and where it is needed.
  • Which non-binding agreement is typically used in disaster recovery scenarios to back up data with another party?
  • What tool is used in risk management to identify vulnerabilities and threats, assess impact, and determine controls?
  • The threat exists as an individual, team, organization, or even a nation state or government. Which term describes this?
  • Which term refers to the interconnection of two separate networks to exchange traffic between their users?
  • Which term is designed to prevent copying and pasting between a remote session and the host over RDP?
  • Kerberos relies on which component to conduct authentication and authorization functions, using symmetric encryption?
  • Which environment isolates untested code changes and experimentation from the production repository?
  • Provides the ability to conduct numerous security functions within a single device or network appliance.
  • Which process allows enterprise security personnel to determine if a change to the baseline has been made?
  • Which term represents data like trade secrets and intellectual property that would seriously impact the business if disclosed?
  • Which term is a financial measure that compares annual loss to savings from controls?
  • Which data category comprises intangible creations such as copyrights, patents, trademarks, and trade secret designation?
  • Which tool is used to identify potential risks in a system or organization?
  • What term describes a device such as a router, switch, firewall, printer, or workstation?
  • Which component provides filtering and access controls that focus on XML-formatted inbound data to an API?
  • Which term describes ensuring data remains unchanged during transfer by preventing modifications?
  • Which is the act of impersonating someone to bypass a biometric-based passwordless system?
  • Which term provides the digital evidence when investigating anomalous issues on a network?
  • Which architecture uses more than two interfaces to connect networks with multiple boundaries?
  • In risk assessment, which term identifies the value of an asset to the organization?
  • Which term describes automating the coordination of tasks across multiple systems?
  • The individual accountable for managing threats and vulnerabilities related to a risk, and for reassessing the residual risk, is known as
  • What term describes protection of the VDI-hosted image when used by end users?
  • Which act focuses on the use of encryption in healthcare data?
  • What does Sideloading mean?
  • Which term denotes the last date that a manufacturer will support a given product?
  • Which concept describes the ongoing removal of the network perimeter and reliance on controls across the environment?
  • Which term denotes controls that are the sole responsibility of the customer?
  • What exercise type is a structured, scenario-based discussion that tests team roles and response without changing production systems?
  • Which Android capability enables a user to obtain root privileges, sideload apps, change or add carriers, and customize the interface of an Android device?
  • Which term describes data retained after power loss?
  • Which term ensures privacy by not revealing which data item is retrieved from a service?
  • Which policy blocks the ability to print to a networked or USB-connected printer?
  • Which term describes any smart device worn on or implanted in the body?
  • Which statement accurately contrasts VDI and DaaS?
  • Which act is primarily associated with corporate governance and financial reporting obligations for publicly traded companies?
  • Which scenario describes a client losing access to data because the cloud provider ceased operation?
  • Which type encapsulates computer programs from the underlying OS on which they are executed?
  • What is the probability that a failed solution can be restored to normal operations within a given time period?
  • Which data classification includes health-related information such as PHI?
  • What describes systems that are up and available?
  • Which policy defines the minimum number of days before a user can reset their password after a prior change?
  • Which project describes the HTTP response headers your application can use to increase security?
  • Which term describes The percent value or functionality of an asset that will be lost when a threat event occurs?
  • What does Artificial Intelligence describe?
  • Which analysis compares the costs of deploying a solution to the benefits gained?
  • Which term contains common functions and objects used by a programming language to allow reuse?
  • An information security governance component which ensures that security issues do not progress beyond a configured level is called:
  • Which term describes a storage approach that imposes a hierarchical file and folder structure on data?
  • Which component coordinates and centralizes SNMP communications between devices and agents?
  • Which term describes a mode that terminates noncritical processes when a failure occurs to try to keep operations going?
  • Which term describes a weakness in the system design or implementation?
  • Which term describes the group responsible for providing proper data classification for the information security professionals?
  • Which concept represents a virtualized mobile operating system delivered similarly to desktop VDI?
  • Which term is responsible for handling the management of the system where data assets are stored?
  • An administrative control that is focused on what to do when hiring and firing employees.
  • Which concept involves reducing vulnerabilities by integrating security early in development?
  • Which site type uses portable units and is intended for rapid recovery?
  • Which term denotes a device exposed to untrusted networks, potentially performing firewall duties but primarily serving as a hardened gateway?
  • A formal document that defines the security program's scope, responsibilities, and objectives.
  • Teredo provides full IPv6 connectivity for hosts even if they do not have a native IPv6 network.
  • One interface is connected to the internal or trusted network, while the other interface is connected to the external or untrusted network describes which architecture?
  • Which agreement requires organizations that collect, store, or process credit card information to abide by?
  • Which concept focuses on keeping systems operational with no single failure point by having multiple paths or components?
  • Which mechanism acts as a reverse proxy to receive API calls and route them to appropriate services?
  • Which concept describes the risk present before mitigations — the risk level before any mitigating actions?
  • Which one-time password method uses a shared secret and a counter to generate codes instead of time?
  • What best describes Exact Data Match (EDM) in data security contexts?
  • Which protocol is commonly used to securely access and administer network devices via a command-line interface on port 22?
  • Ensuring virtual machine formats are supported by multiple cloud vendors mitigates which risk?
  • Which indicator is used to gauge and measure different things within your organization and helps manage an IT service?
  • Which act affects both healthcare and educational organizations by increasing some of the security measures to further protect healthcare information?
  • What is a Host-Based Intrusion Detection System (HIDS) and what does it do?
  • The security categorization framework described in FIPS 199 uses ratings in which three categories?
  • Which standard enables line-of-sight communication using infrared light?
  • Which term aims to establish a strategic risk management framework that is supported by key stakeholders at the top tier of the organization?
  • What indicates the type of information and dictates its importance among other pieces of information?
  • Which term describes an organization's own employees who use the company's information systems for their jobs?
  • Which term is the automated version of a playbook that leaves clearly defined interaction points for human analysis?
  • Which term refers to separating network traffic into logical segments to improve security and manageability?
  • Which risk analysis approach uses numeric values and monetary values for all parts of the analysis?
  • Which NAC deployment installs the scanning engine on the domain controller rather than the endpoint it protects?
  • Which term describes a technology's ability to fulfill its intended purpose or the efficiency with which it fulfills it?
  • Which device is the primary automation controller in many OT environments, often programmed with ladder logic?
  • Which term is the process of classifying something according to shared qualities or characteristics?
  • What term describes an independent audit by a separate organization to validate compliance with requirements?
  • Which data category would seriously affect the business if disclosed?
  • Which standard is used for port-based authorization on both wired and wireless networks?
  • Which term describes monitoring of applications and servers and automatically adjusting capacity to maintain performance at the lowest cost?
  • Which term means Hidden; Undercover?
  • Which testing category includes unit tests and vulnerability assessments?
  • What does Host-Based Firewall do?
  • To free up resources back to the host server.
  • Which DLP approach uses exact matching of sensitive content rather than guessing?
  • Which term describes records that indicate the priority or importance of other information within a data collection?
  • Which device allows inbound connections to be initiated from the Internet and relays or proxies them to internal resources?
  • Occurs whenever a business function or process is provided by a third-party outside of the organization.
  • Which term describes the capability that allows direct connection between two devices without routing traffic through a central hub?
  • Which term describes wearable devices intentionally used for work or health monitoring?
  • Forensic Watermark is best described as which option?
  • Which term describes the busyness or load on system components?
  • Which set of standards allows users to specify security functional and assurance requirements in a system, including Evaluation Assurance Levels (EALs)?
  • Which drive type includes an encryption circuit built into the hardware?
  • Which category focuses on power generation and distribution?
  • Which term describes a system that provides data interoperability and quality of service in distributed networks?
  • Which term encompasses groups such as competitors, hackers, activists, vandals, terrorists, nation-state cyber attackers, data miners, criminals, and others who target systems?
  • What term describes downtime or repair time when a system is unavailable or undergoing maintenance?
  • Which term is associated with enabling scalable, real-time data exchange with timing guarantees in industrial networks?
  • Which EAP method requires a digital certificate on the server and a password on the client as part of its authentication?
  • Open Authorization (OAuth) is best described as which?
  • Which term defines the standards of behavior for activities and dictates how to conduct cybersecurity within an organization?
  • Which topology involves cooperation among nodes to maintain connectivity by relaying data?
  • Which term is an open-source variant of software defined networking?
  • Which term describes the processor setting that creates separate memory areas and prevents code execution in those areas?
  • Which data category covers unclassified information that should be protected from public disclosure?
  • Which term describes sending unsolicited messages to a Bluetooth device?
  • Which system monitors traffic, reports on it, and blocks or responds to suspicious activity?
  • Which control type provides guidance for acceptable activities?
  • Which practice involves keeping a copy of the software's source code with a trusted third party as a safeguard?
  • Which term considers all types of risks or uncertainties that may impact achieving objectives?
  • Which term describes technology designed to implement an industrial control system rather than business IT networks?
  • Which data type is exemplified by a PowerPoint slide, an email, a text file, or a chat log?
  • Which metric is displayed as a percentage of computing power needed during a disaster?
  • What operation digitally signs the file being distributed by a software developer or distributor?
  • Which statement correctly defines MTTR?
  • Which term allows two parties to jointly evaluate a private function without revealing inputs?
  • Which term is designed to take an input, perform processing, and produce an output?
  • Which statement best describes CSIRT composition?
  • Which feature permanently alters the state of a transistor on a computer chip if the bootloader is modified or altered?
  • Which term is described as public key cryptography based on elliptic curves over finite fields?
  • Which term is the process of hiding a message inside another object, such as a picture or document?
  • Which detection method analyzes traffic and compares it to a normal baseline to identify threats?
  • Which component collects, stores, and signals the presence of data on a device?
  • What is API Management primarily about?
  • What provides a platform for developers to build and deploy applications without worrying about infrastructure?
  • Which term refers to enterprise mobile device management across an organization?
  • Which access control model assigns permissions based on the roles assigned to users, simplifying access management?
  • Which practice involves training multiple employees to perform the same critical job to reduce risk?
  • Which term means to free up resources back to the host server?
  • What term refers to a value calculated from data to detect errors or tampering?
  • Adding additional resources to help handle the extra load being experienced.
  • Which term is most closely associated with preventing unauthorized distribution of digital media?
  • In the data lifecycle, which term describes keeping data in a non-active state for potential future retrieval?
  • Collaboration effort where infrastructure is shared between several organizations from a specific community with common concerns. (Noncompetitive)
  • Which role provides threat intelligence and overall context during your incident response?
  • Which term describes the automatic switch to a backup system when the primary system cannot continue to operate?
  • To set a certain amount of resources in order to provide an established service.
  • Software that operates in the middle between applications and the OS is called:
  • Which cloud model enables multiple tenants to share computing resources while keeping data isolated?
  • Which term describes software that connects computers and devices to other applications and networks?
  • Which category includes the mining and refinement of raw materials, including hazardous high heat and pressure processes, presses, centrifuges, and pumps?
  • Which concept promotes strong passwords by imposing acceptable password specifications?
  • Which indicator is used to measure risk, instead of system performance?
  • Contains items like trade secrets, intellectual property data, source code, and other data that would seriously affect the business if disclosed.
  • Which term runs functions within virtualized runtime containers in a cloud?
  • Which process involves reviewing the password policy to ensure proper settings?
  • Which term refers to a security mechanism that uses digital certificates and asymmetric keys to secure transactions?
  • Which mechanism focuses on securing accounts with elevated privileges and monitoring their activity?
  • Which Cisco-proprietary protocol provides separate authentication, authorization, and accounting services?
  • What characterizes the Hosted Model/Desktop as a Service (DaaS)?
  • Which term describes a strategy that passes the risk to a third party, most commonly an insurance company?
  • Which concept describes the limited set of functions that must be continued during or resume rapidly after a disruption?
  • A list of items that are required, a list of things to be done, or a list of points to be considered.
  • Which enforces standard operating environments in a Windows domain?
  • Which technology protects the contents of the storage device when the operating system is not running?
  • Refers to whether the threat actor cares if they get caught.
  • Which cloud concept focuses on running code in a managed environment with event-driven execution and without server management by the developer?
  • Which term refers to embedding a unique marker into a file to prove ownership of a digital asset?
  • Which protocol is used to translate hostnames to IP addresses for network applications?
  • Which term denotes the class of controls used to restrict access, including software or hardware components?
  • Network Traffic Analysis is primarily concerned with?
  • A financial estimate intended to help buyers and owners determine the direct and indirect costs of a product or service. Consider not just the sticker price but also the other parts of the cost of ownership to support the countermeasure.
  • Which option allows communication of traffic between two VPCs as if they were on the same network?
  • Which development approach requires continuous feedback and cross-functional teamwork, prioritizing customer satisfaction?
  • Which NAC deployment involves software installed on the endpoint requesting access?
  • Which technology is used to carry IPv6 packets over IPv4 by encapsulating inside GRE?
  • Which term refers to an entity that carries out a threat?
  • A piece of software installed on a device requesting access to the network.
  • Which term refers to the cost associated with the realization of each individual threat that occurs?
  • Which boot attestation concept gathers secure metrics for boot validation?
  • Which term corresponds to the description: data stored in memory, a hard drive, or a storage device?
  • Which policy type is explicitly designed to govern a specific security concern, such as email privacy?
  • Which method allows two parties to jointly evaluate a publicly known function without revealing inputs?
  • Which technology looks at suspicious network traffic going to or from a single host or endpoint?
  • Which term covers protecting data from unauthorized modifications or data corruption and ensures data is not changed during transfer?
  • Which action describes removing restrictions on an iOS device to gain root access?
  • Which policy addresses mandatory standards and laws that affect the organization?
  • Firmware Updates (Mobile Devices) refer to
  • What describes a way of delivering applications remotely over the internet instead of locally on machines?
  • If a system blocks data movement based on classification levels, which feature is being used?
  • Which statement best describes the purpose of a checksum?
  • Dual Stack allows devices to support both IPv4 and IPv6 routing simultaneously.
  • Which term stands for Supervisory Control and Data Acquisition, a type of OT system that monitors and controls geographically distributed assets from a central host?
  • What KPI measures the probability that a system will meet certain performance standards and yield the correct output for a specific time?
  • Refers to how the threat operates.
  • What does a System Design Document describe?
  • Which device policy lets employees select a device from an approved list of vendors or devices?
  • Double Tagging adds two VLAN tags, an outer and inner tag, to traffic going to a switch as part of a Q-in-Q attack.
  • What does the OWASP Secure Headers Project describe?
  • Which practice involves combining deidentified data with other data sources to re-link with individuals?
  • Which term describes exposing a hard drive to a powerful magnetic field to wipe data?
  • Which term describes the costs to replace hardware and software and pay for repair labor after an incident?
  • What does BIGOT stand for in this context?
  • Which storage type stores data as distinct units called objects?
  • Which technology is a form of radio frequency transmission modified for use in authentication systems?
  • Hash Function maps arbitrary sized-data to a fixed-size value.
  • Which term is used for data actively in use or processing to comply with business policies and applicable laws?
  • Which term is used to denote establishing a strategic risk management framework supported by top-level stakeholders?
  • Which term refers to a risk that is created due to an exemption being granted or failure to comply with corporate policy?
  • Which virtualization model replaces the operating system on the physical server?
  • What describes a flaw that can bring down a system if it fails?
  • Which role is primarily responsible for aligning security cost assessments with organizational budgets?
  • Which statement best describes ISO/IEC 27034?
  • Which term refers to an organized and structured format for storage?
  • Which feature provides CPU hardware-level isolation and memory encryption on every endpoint?
  • Which term describes the long-term viability of a vendor?
  • Which document provides insight into the incident and how to improve response processes in the future?
  • Which term describes a network of appliances and personal devices equipped with sensors, software, and network connectivity?
  • Which control uses application allow/block lists to regulate what can be installed on devices?
  • Which protocol maintains confidentiality of the data in transit from the user's system to the server on port 443?
  • Which virtualization model relies on a common host operating system as the base for containers?
  • Which organization is credited with creating international standards across multiple industries?
  • Which statement best defines Virtual Reality?
  • Which technique involves gathering data and generalizing it to protect individuals' identities?
  • Which term describes a scenario where a single component's failure can cause a complete outage due to lack of redundancy?
  • Which act addresses economic espionage involving trade secrets and criminal use of encryption?
  • What term describes the interconnection of two separate networks to exchange traffic between their users?
  • Which technology is used for asset tracking and authentication and uses radio frequency transmission?
  • Which endpoint security capability detects and logs security events on the host?
  • Which term is the method of concealing a message within another object?
  • Which security principle defines the minimum information or access required for a given job or function?
  • Rely on keywords, regular expressions, metadata tags, Bayesian analysis and statistical analysis to guess what files should be protected under the DLP program. Which method is this?
  • Which model relies on a set of characteristics of an object to make access control decisions?
  • Which term refers to a facility that manufactures microprocessors under a validated supply chain to prevent tampering?
  • Which term describes the intended end state an attacker aims to achieve?
  • Which document requires organizations to specify the technical requirements for IT system interconnection?
  • Which term refers to a software or hardware component used to restrict access?
  • Which term describes the culture within the organization?
  • Which term stores information about the MAC addresses available on any given port of the switch?
  • What term describes the process where a baseline is created and all changes to that baseline are tracked and assessed?
  • Which interface provides a graphical interface for operators to monitor PLCs and adjust parameters?
  • Which control is described as regulating the flow of traffic into or out of a network segment, with the most specific rules at the top and a deny all rule at the end?
  • Advisory Policies describe the expected annual cost of a realized threat and use the formula SLE x ARO.
  • Which term describes a document listing items to be considered during incident response?
  • Which term describes the busyness of systems and their components?
  • Which term corresponds to the description: maintains and controls certain data in order to comply with business policies and applicable laws and regulations?
  • What device physically copies packets for analysis and can be placed on a network before the analyzer?
  • Which are application-aware and can integrate with several other security products?
  • Which technology creates machines that solve problems without human direction?
  • Which device makes connections on behalf of endpoints (circuit-level at Layer 5, application-level at Layer 7)?
  • Which capability lets an organization inspect TLS/SSL traffic by acting as a MitM?
  • Which term refers to the organization of information into present structures or specification?
  • Which term provides security for organizations that do not have the necessary security skills?
  • What is a Self-Encrypting Drive (SED)?
  • Which security analysis approach helps to find vulnerabilities in web applications while they are running in production?
  • Provides for outsourcing of the infrastructure of the server and desktops to a service provider.
  • Which decision-making technique involves group members responding in writing to questions posed by the group leader without meeting face-to-face, to estimate the likelihood and outcome of future events?
  • Which term causes a MAC address overflow to occur in the CAM table by flooding the switch with random MAC addresses?
  • Which practice is a method of formal or informal review of the programming instructions?
  • Which term describes the role that oversees and prioritizes actions during the detection, analysis, and containment of an incident?
  • Which term represents the process of downgrading a classification level?
  • What term describes the team made up of a manager, cyber security personnel, a representative from legal counsel, and possibly someone from public relations or human resources, depending on the type and severity of the incident?
  • Which technology provides additional security to payment card transactions over HTTPS?
  • Which term refers to mirroring all inbound and outbound traffic to cloud-based servers' interfaces?
  • Which regulation requires consent for processing personal data and protects EU citizens' privacy?
  • Which concept is described as a centralized repository of organizational information used to manage content?
  • What is a Hot Fix?
  • Forwards route advertisements received from the external BGP router throughout the internal network.
  • In identity management, what does federation refer to?
  • What is a Host-Based Intrusion Prevention System (HIPS) and what does it do?
  • Which act governs the protection of personal identifiable information in financial contexts and prohibits sharing with third parties?
  • Dynamic ARP Inspection (DAI) inspects ARP traffic to prevent ARP spoofing.
  • Which concept informs how to decide on the legitimacy of a digital certificate?
  • Which process verifies that a device's software has not been altered from its approved baseline?
  • Tracks all the activities of a user or system in the network is known as what?
  • Which term refers to finding ways to minimize the likelihood of a specified outcome and continually examining risks, vulnerabilities, and mitigations?
  • Which element provides the memory and processing functions between devices and the agents?
  • Which term covers phenomena like floods, fires, tornados, and earthquakes?
  • Which data category relates to the financial health of a business, including profitability and liquidity?
  • Which term describes the process of verifying hardware provenance to ensure it originates from trusted sources?
  • Which feature allows a smartphone to share its cellular data connection with multiple devices?
  • Which term describes taking CI/CD further with automated production deployment?
  • Which data category is used only within the organization and includes personnel records?
  • Which term describes a ratio that considers how long it would take to make up for the expense, or investment, by preventing the risk from occurring. It determines the expected fiscal gains for improvements and balances that against the cost of implementing the changes.
  • The amount of risk an organization is willing to accept in pursuit of its objectives is called
  • What device acts as a centralized appliance or software package to monitor, manage, and control wireless access points?
  • Which term provides a quantitative view of risk and performance in a network?
  • Provide a quantitative look at risk and performance in the network.
  • Which act requires federal agencies to develop, document, and implement an agency-wide information security program?
  • Which term is used to denote the software development practice that covers planning, building, testing, and deployment?
  • What device creates a network connection between an end user's client machine and a remote resource such as a web server?
  • Caching is best described as which concept?
  • Which concept is designed to detect and prevent sensitive information from being stored or transmitted over unauthorized networks?
  • Which concept permits performing computations on encrypted data?
  • Asset Value (AV) identifies the value of an asset and can be a monetary value or a subjective value.
  • Which term corresponds to the description: a generic term that refers to any process that deletes or makes some form of data inaccessible?
  • Which document would most likely govern the security requirements for a cross-organizational IT connection?
  • Which concept is a plan listing and prioritizing essential services to resume after disruption?
  • Configures the router or switch to make a copy of every packet that the device processes.
  • Which term refers to the electronic mechanism that collects data and processes signals within a network?
  • Which role works with experts within the organization to determine the security costs necessary for the organization's information systems?
  • Developing human capital to support multiple cloud offerings describes which risk?
  • Which control category is used to recover a device after an attack?
  • Which term denotes a one-time evaluation of a security posture?
  • What principle requires giving users the minimum level of access necessary?
  • Transitive Trust is described as which concept?
  • 6to4 provides IPv6 connectivity over IPv4 networks without explicit tunnels.
  • Which component aggregates and catalogs data from multiple sources within an ICS by collecting all events generated from the control loop?
  • Which term refers to computing on encrypted data without decrypting it?
  • Which term enables communication between applications and supports various protocols?
  • What concept describes the removal of a network boundary and the ongoing changes to that boundary?
  • Occurs when we calculate the risk after applying our mitigations and security controls.
  • Which process removes or modifies personal identifiable information from a data set to protect privacy?
  • Testing in live environments should be done in stages and during low periods of activity. Which term best describes this concept?
  • Which system enforces SELinux-type security inside the Android operating system?
  • Which term is used to force compliance with the security policy and practices within the organization?
  • Which network security model eliminates implicit trust by requiring verification for every access request?
  • Security Assertion Markup Language (SAML) is best described as which?
  • Which service model provides a complete platform for developing and deploying applications with control over the runtime environment but without managing hardware?
  • Which term refers to the settings you should be aware of on your endpoint devices?
  • Which of the following is one of the six steps of incident response?
  • Which act reforming health care and education funding is referenced as affecting accounting for corporations?
  • Which practice evaluates an application's behavior in a running environment to detect security issues?
  • What does ARO represent in risk assessment?
  • Which term describes a financial estimate to help buyers and owners determine direct and indirect costs of a product or service, including ownership costs?
  • Which term sets the standards of behaviors for cybersecurity within an organization?
  • Which concept describes computing that combines physics, mathematics and quantum mechanics to exploit quantum states?
  • Which infrared-based standard enables data transfer between devices using line-of-sight communication?
  • Which term refers to a Building Automation and Control Network that includes an application, network, and media access layer and can run over other Layer 2 protocols?
  • What is the term for data that could identify a specific individual?
  • Which term describes selecting data storage locations by geographic region in cloud environments?
  • A framework that determines data locality in multi-cloud deployments, aligning with regional storage choices.
  • Which contract type defines the conditions of the relationship between two business partners?
  • The heart of the operating system is:
  • Which concept generates inputs from scratch?
  • Which document focuses on the plans and processes used during a disaster?
  • Which act protects the privacy of personal identifiable information and sets guidelines for securing that financial information?
  • Which term refers to controlling access to sensitive materials?
  • Which term provides a framework for building software by exposing services with a single purpose?
  • Top Secret Data (Military/Government) includes PHI, which covers what types of information?
  • The delay that occurs during data processing on a network is called what?
  • Which concept describes changing existing input values?
  • Which term determines the expected fiscal gains for improvements and balances that against the cost of implementing the changes?
  • Which term corresponds to the description: information that's kept for a specific purpose outside of an organization's data retention policy?
  • Which technology monitors file integrity by generating a hash digest for files to detect changes?
  • Which term is an automated version of a playbook with clearly defined interaction points for human analysis?
  • Trusted Solaris is best described as:
  • PHI stands for which term?
  • Which service helps network clients find a website using human readable hostnames?
  • Which document would describe the architecture of an application?
  • Which term describes adding a layer of security over an existing app on the device?
  • Which statement correctly describes 3D Printing (Additive Manufacturing)?
  • Which approach integrates security into every phase of the development lifecycle?
  • Which term describes a firewall that is application-aware and can integrate with several security products?
  • Which concept uses a virtualized mobile OS delivered to devices, enabling a centralized management model?
  • What describes a virtualization type applied by a host OS to provide an isolated execution environment for an application?
  • What technique substitutes a unique token for the real data, making the actual data inaccessible while preserving referential integrity?
  • Which term is specifically used to keep track of every asset and its configuration in the IT environment?
  • Which role helps filter out false positives by configuring intrusion detection and protection systems, as well as performing ongoing monitoring and analysis?
  • What term describes a technology's ability to perform a solution?
  • What does SLA stand for?
  • Which attack involves sending malicious ARP packets to the default gateway on the network to alter the IP-MAC bindings in its ARP table?
  • Which term determines the integrity of a TPM chip?
  • Who is responsible for managing the threats and vulnerabilities that might exploit a risk, and for reassessing the risk to determine the residual level?
  • Which act defines hacking of what is referred to as 'protected computers'?
  • Which term refers to a negative event that impacts an organization's security or operations?
  • Which practice safeguards accounts that contain special access or capabilities beyond a regular user?
  • Which tool provides granular control to allow or disallow inheritance of a policy from one group or container to another?
  • What does PII stand for?
  • Which term denotes the loss amount expected per single loss event?
  • Which term describes controls that are shared between the cloud provider and the client?
  • Which risk focuses on the strategic viability of the vendor being considered?
  • JSON Web Token (JWT) is best described as which?
  • Privacy protects sensitive information about someone's personally identifiable information.
  • Which term describes preventing attempts of copying and pasting files into another file type that may not be protected by the DLP system?
  • Which term describes the location of data within a processing system?
  • Which statement best differentiates standard Watermarking from Forensic Watermark?
  • Which field concerns the manipulation of matter on an atomic, molecular, and supramolecular scale for industrial purposes?
  • Remote Virtual Desktop Model is best described by which of the following?
  • Dynamic ARP Inspection (DAI) is a security feature that examines ARP requests and responses and validates them against a trusted MAC-IP binding table.
  • Shibboleth is best described as which?
  • Which term refers to a virtualization approach where an application runs in isolated user space on the host OS?
  • Basic Input Output System (BIOS) initializes hardware for boot.
  • What term describes a single session of information that shares certain characteristics between two devices?
  • Enables monitoring of network traffic passing in or out of a network.
  • Which control is used to detect an attack while it is occurring and to notify proper personnel?
  • Which term describes Binary Large Object storage, a collection of binary data stored as a single entity?
  • What is the term for distributing workload across multiple computing resources?
  • Residual risk is the risk that remains after which step of the risk treatment process?
  • Which document would describe a non-binding intention of two organizations to act together?
  • Which term creates virtual connections between different endpoints to provide additional security benefits?
  • What best describes Virtual Desktop Infrastructure (VDI)?
  • Which term describes the centralization of control logic separate from the data forwarding hardware?
  • What describes using multiple pieces of physical hardware?
  • Which registry documents the security and privacy controls of cloud offerings under the Cloud Security Alliance?
  • Which term describes allowing employees to use personal devices at work and connect to the corporate network?
  • Which term describes a virtualization approach where containers share the host OS kernel but remain isolated?
  • Which term means you have met the requirements and are compliant?
  • What process involves systematically tracking and evaluating the performance of risk mitigation actions against established metrics throughout the lifecycle of an identified risk?
  • Which term describes the model for how data is stored in a cloud infrastructure?
  • Which statement best describes Machine Learning?
  • Which access control model allows the resource owner to specify which users can access each resource?
  • Which term refers to threats arising from people, including insiders and outsiders?
  • Which term corresponds to the description: data moving from one computer or system to another over the network or within the same computer?
  • Which port is commonly associated with the Remote Desktop Protocol?
  • Which technology creates an encrypted tunnel to securely connect to the enterprise network from a remote location?
  • What describes the risk that exists before mitigation actions are applied?
  • Maintains the confidentiality of data is referred to as what?
  • Which approach explicitly integrates security into every phase of the development lifecycle?
  • Which design pattern aims to eliminate the accidental insertion of vulnerabilities into code and mitigate their consequences?
  • Which security device is designed to prevent cross-site scripting and SQL injection by inspecting and filtering HTTP traffic?
  • Which security concept involves validating the device's bootloader before the operating system loads?
  • Which system is a host-based intrusion detection system that creates a hash digest for every monitored file and is required for PCI-DSS, SOX, FISMA, HIPAA and CIS controls?
  • Which risk concerns ongoing dependence on a vendor's services, leading to costly switching?
  • Which act requires organizations to obtain consent for collecting, using, or disclosing personal information and to publish clear policies?
  • Which term refers to the general direction and goals provided by an organization, forming a framework for security efforts?
  • Which security concept involves device bootloader validation before the device boots?
  • What does User and Entity Behavior Analytics (UEBA) provide?
  • Which document focuses on disaster-related communications protocols?
  • Which concept involves segmenting corporate-owned data and resources from personally-enabled mobile devices?
  • Which EAP method is described as using public key infrastructure with certificates installed on both the client and the server?
  • NIST SP 800-39 is associated with which area of information security?
  • Which term refers to a Perl framework that takes manual release processes and makes them automated?
  • Assigns a particular resource to a single organization.
  • Which term addresses a specific security issue such as email privacy or employee termination procedures?
  • Which calculation is used to determine the Annual Loss Expectancy (ALE) from the Single Loss Expectancy (SLE) and the Annualized Rate of Occurrence (ARO)?
  • Which term refers to adding location metadata to files or devices?
  • Which term refers to a process that includes a set of activities working toward a goal in security management?
  • Which organization focuses on sharing sector-specific threat intelligence and security best practices among its members?
  • Which mechanism is commonly used in multi-factor authentication to provide a second factor via a time-based code?
  • Which virtualization type replaces the OS on the physical server?
  • Which lifecycle model is described as an incremental approach with sequential steps?
  • Which agreement is typically non-binding and describes an intended common course of action?
  • Which term refers to detailed step-by-step instructions designed to ensure personnel can perform a given action?
  • Terminal Services refers to what type of solution?
  • What activity evaluates the effectiveness of risk response measures and identifies changes that could affect how risk is managed?
  • Which VLAN type is used to manage inter-switch traffic and provide an extra security boundary?
  • Which term describes a discussion-based session where team members discuss their roles and what they would do in response to a given scenario?
  • Which concept focuses on secure coding standards developed through a community effort across major languages?
  • Which term describes a governance artifact that defines how policies are implemented across the organization?
  • Which term describes the concept of increasing the power of the existing resources in the working environment?
  • Which access control model uses security labels to determine which users are authorized to access a resource?
  • Which EAP method uses a protected access credential to establish mutual authentication between devices?
  • Opportunistic Wireless Encryption (OWE) is
  • What term describes a person who uses the same tools and techniques as a hacker but aims to disrupt services to protest a political or social cause?
  • Single Sign-On (SSO) enables users to authenticate once and receive authorizations for multiple services across the network. What does SSO enable?
  • Which of the following best describes Web Services Security (WSS)?
  • Which pattern is concerned with ensuring a secure storage layout within a web application?
  • Which term describes a technology's ability to perform under an expanded set of use cases?
  • Places devices at the boundaries of the security zone to control the ingress and egress of data is called what?
  • Which hardware device is a reprogrammable digital logic device whose configuration is set after manufacturing?
  • Which risk focuses on developing staff capabilities to support multiple cloud platforms?
  • What is the term for a signed agreement that defines what data must remain confidential and cannot be shared outside the relationship?
  • What type of ICS manages large-scale, multi-site devices and equipment spread over a geographic region from a host computer?
  • Which term is the sole responsibility of the client?
  • Which term describes a device that can be managed remotely and supports SNMP operations?
  • What does Build Security In (BSI) provide?
  • Which term refers to the end state the threat actor is trying to accomplish?
  • Which term describes the method used by a cloud computing infrastructure to store data?
  • What term describes the network component that carries signaling information and makes routing decisions?
  • Which term corresponds to a concept describing data in transit between components (i.e., data in motion)?
  • What protocol provides a graphical interface to connect to another computer over a network connection (port 3389)?
  • Which network topology has nodes that cooperate to relay data to ensure connectivity among all nodes?
  • Which term refers to the final result of an attack as observed?
  • To ensure an application can be deployed across Azure, AWS, and Google Cloud, which risk is addressed?
  • What is the measure of how often the solution must be updated, upgraded, or fixed?
  • Which solution provides numerous security functions within a single device, simplifying management?
  • A cloud design approach that creates micro-perimeters around workloads to limit lateral movement.
  • Which term describes preventing copy-paste into non-protected file types?
  • What term refers to activities that increase expertise and improve management of security programs within an organization?
  • What does the Block action do in a Data Loss Prevention policy?
  • Which authentication uses a separate communication channel to deliver the OTP or PIN?
  • Nanotechnology involves...
  • Which term means Secret, Concealed; Underhanded?
  • Which term involves grouping team members to run through a simulated disaster to verify the effectiveness of emergency response plans?
  • Which term enables an interface to dynamically associate the first MAC address that it connected to as an authorized address?
  • Which concept ensures applications meet an acceptable level of security for the functions they are designed to provide?
  • Automation/Orchestration refers to which of the following?
  • Reduce the background traffic and allows the network to grow while still providing different security protections to different parts of the network. Which concept fits this description?
  • Which principle describes the idea that countries may impose data handling requirements on data stored within their jurisdiction?
  • Which term describes the foundational hardware element that contains cryptographic keys used during secure boot and trust establishment?
  • Which term refers to the act of copying or reproducing data?
  • Which term refers to controls implemented to administer an organization's assets and personnel, including policies, procedures, standards, baselines, and guidelines established by management?
  • Which term is defined as the last date a manufacturer will support a given product?
  • Which element comprises essential items to discuss in the security policy?
  • Which statement correctly distinguishes In-Band from Out-of-Band authentication?
  • Which firewall tracks the state of all connections and requests going into and out of the network?
  • Which device inspects and controls traffic trying to enter or leave a network boundary?
  • Which term refers to linking electronic identities and attributes across multiple distinct identity management systems?
  • An organization's willingness to take and accept various types of risk.
  • Which option is the open standard for exchanging authentication data used in SSO across domains?
  • Which event is used primarily for basic training of team members?
  • Which term protects data against improper modification or alteration?
  • Deep Packet Inspection focuses on which aspect of network traffic?
  • Which term refers to amending or removing data in a database to minimize exposure?
  • Which term contains all the components of a computer system on a single chip?
  • Used as a reference point to compare against a future metric.
  • Minimal impact if released and includes data like organizational financial data.
  • Which term describes data moved to archive storage to prevent overwriting?
  • Which term describes a collection of binary data stored as a single entity?
  • Which firewall has minimal performance impact while still performing full packet inspection at every layer?
  • Which form of public key cryptography is based on the algebraic structure of elliptic curves over finite fields?
  • Which term provides confidentiality and privacy labels to information?
  • Which component generates and stores cryptographic keys and is less susceptible to tampering and insider threats?
  • Which device is typically placed at the network edge to route traffic between internal networks and the Internet, including handling translations?
  • To provide remote access, which option represents the encrypted connectivity commonly used to reach the enterprise network?
  • Which term describes the phase that focuses on the mitigations implemented to lower risk after assessment?
  • Which protocol is designed to allow communications between embedded programmable logic controllers?
  • What type of control seeks to prevent or stop an attack from occurring?
  • Which term describes a system of best practices, techniques, procedures, and rules used by professionals in a field?
  • ARP Broadcast locates the correct host on the local network and passes traffic to the host using its MAC address.
  • Which connectivity type supports large-scale data integration and easy management by linking cloud resources with on-premises systems?
  • Which term corresponds to the description: any data that's moved to an archive storage to prevent being overwritten?
  • Which sector includes site and building management systems, including operating HVAC, lighting, and security systems?
  • Which concept focuses on a certain topic and is designed to be educational in nature?
  • Which mechanism does Web Services Security (WSS) use to provide confidentiality?
  • Which protocol encrypts DNS requests by tunneling through TLS via HTTPS?
  • Which term describes a system that detects and responds to component failures, such as in data storage or hardware redundancy?
  • The LDAP protocol by default operates on which network port?
  • Which term is used to describe resources that are not essential and may be deprioritized in recovery planning?
  • JSON Web Token is best described as which in the context of authentication protocols?
  • A calculation that simply compares the Annual Loss Expectancy against the expected savings from implementing a given control.
  • Combination of private and public clouds.
  • Which virtualization type is installed after an OS is placed on the server?
  • What term describes the technique of encapsulating IPv6 packets inside GRE IPv4 packets to traverse an IPv4 network?
  • Which attack exploits the Dynamic Trunking Protocol (DTP) to negotiate a trunk link with a switch?
  • Which term is described as creating and managing data containers via an API?
  • What does the acronym RTO stand for?
  • Increasing the power of the existing resources in the working environment.
  • Which concept involves dynamically learning and then persisting the first MAC address seen on a switch port to authorize future devices?
  • The average amount of time an asset or component will operate before failing is what?
  • Any device directly exposed to the internet or another untrusted network which may or may not be a firewall is known as what?
  • Which organization focuses on sharing sector-specific threat intelligence and security best practices among its members?
  • Which term describes a positive or negative change in the state of security or operations?
  • Which role plays detective on the affected network in order to determine what happened?
  • Which technology links different programmable logic controllers together?
  • Which term refers to security operations that automate incident response and threat hunting without human input?
  • Which protocol is used for internal propagation of BGP routes within an enterprise?
  • Statistical or Lexicon approaches in document analysis rely primarily on what?
  • Focused on maintaining business continuity for critical services, applications, and data.
  • What term describes a hardened server that provides access to other hosts in a DMZ?
  • What term defines a set of data that describes information about other data?
  • In software development, which component provides reusable building blocks such as common functions and objects?
  • Which control is intended to enforce adherence to security policies across an organization?
  • Which agreement defines the legal terms for two partners to work together and share IT assets?
  • Which term is like a microcontroller but its structure is not fully set at the time of manufacture?
  • Which term defines software development where code updates are tested and committed to a development environment?
  • Which term denotes the average time between failures of an asset?
  • Which data classification includes data such as military deployment plans and defensive postures?
  • The privacy risk process identification is best described by which term?
  • What does Attestation signify in compliance contexts?
  • Which risk analysis approach uses intuition, experience, and other best practices to assign nonnumeric values to risk, using methods such as brainstorming sessions, focus groups, surveys, and interviews?
  • Which technique injects invalid or unexpected inputs into an application to determine its reaction?
  • Which principle ensures the system only provides access to essential capabilities?
  • Which technology prevents unauthorized users or devices from accessing a private network?
  • Which concept describes being dependent on a vendor's products or services with high switching costs?
  • Extensible Authentication Protocol (EAP) is known for allowing multiple different authentication mechanisms. Which statement best reflects this?
  • Which term describes an asset that is of value to an organization, including personnel, facilities, and devices?
  • Which term describes a formal agreement that governs information exchange between two organizations?
  • Which term means Secret, Concealed; Underhanded?
  • Which protocol is a cross-platform protocol that centralizes information about clients and objects on the network?
  • Which term creates a flood of traffic across the network and causes switches to become non-responsive, creating a self-imposed denial of service attack?
  • Which term represents data that would not impact the organization if released?
  • Which term describes recovery systems built and tested to perform actual business transactions to support key processes?
  • Which term describes the consumers or beneficiaries of IT services within an organization?
  • Which wireless technology creates a personal area network and operates around 2.4 GHz?
  • Which processor setting prevents code execution in memory regions?
  • Which term applies to both the infrastructure layer and the customer layers?
  • Which term provides network interoperability and facilitates the required scalability, performance, and QoS features?
  • Which storage type stores data as distinct units called objects?
  • Which term describes the component that carries user traffic and actually moves the data?
  • Which act is a follow-on legislation to HIPAA focusing on the use of encryption?
  • Which concept creates and manages strong passwords with only one master password to remember?
  • Which firewall type inspects only the header of the packet to permit or deny traffic based on IP addresses and port numbers?
  • Which component is specifically designed to handle inbound XML data for APIs?
  • Which appliance is usually positioned at the edge of a corporate network and regulates outbound traffic according to organizational policies?
  • What is the highest level in the Evaluation Assurance Level scale?
  • Which term allows support for Internet Protocol and routing over traditional business networks?
  • No impact to the company if released and is often posted in an open-source environment such as their website.
  • Which term is a strategy that seeks to minimize the risk to an acceptable level which an organization can accept?
  • Which term provides security as a service to organizations lacking security skills?
  • Which term describes a policy that blocks the user from copying the file and then revokes read or open access?
  • Which protocol provides secure remote command-line access to network devices and typically uses port 22?
  • Which term best describes the science of applying quantum mechanical properties to perform cryptographic functions and tasks?
  • Which field-network protocol enables data exchange between PLCs across a network, facilitating control operations?
  • What do Test Plans describe?
  • Which model describes systems and users only having access with other devices inside the same private cloud or system?
  • In risk management, what term refers to any object that is of value to the organization, including personnel, facilities, devices, and more?
  • Which components often have firmware that contains code to perform their specific functions?
  • What is a trust model in the context of digital certificates?
  • Which system consolidates log files from various systems into a centralized database?
  • Which protocol uses a Key Distribution Center to manage authentication and authorization functions?
  • Which term indicates the end of sales for a product by the manufacturer?
  • Which term describes a technology that allows encrypted tunnels to connect to an enterprise network?
  • Which term refers to taking appropriate responses to risks to reduce impact?
  • OAuth is best described as which in the context of authentication protocols?
  • What is Deepfake?
  • The ability of a system to handle the increase in demand without impacting the application's performance or availability is known as:
  • Which option best defines a vulnerability?
  • Which process enables a user to obtain root privileges, sideload apps, and customize an iOS device?
  • The physical separation of the network control plane from the forwarding plane, and where a control plane controls several devices.
  • Which sector focuses on the movement of materials and goods using embedded technology to control the automated transport and lift systems, as well as embedded sensors for tracking of cargo containers?
  • Which term describes the policy set that provides general direction, a framework to meet business goals, and defines roles and terms?
  • Which device is typically used to passively monitor traffic by copying packets without altering them?
  • Which term describes large or complex data sets that traditional data processing applications cannot sufficiently handle?
  • Financial risk assessment in vendor selection is typically based on what?
  • Which internal agreement describes how different departments coordinate to support business functions?
  • Which term describes software development where the application and platform requirements are frequently tested and validated for immediate availability?
  • Loss of trust and reputation after a security incident.
  • Conducting unit level, performance, robustness, and vulnerability testing is categorized as which type of testing?
  • Which metric tells us how much time remains after our Recovery Time Objective but before negative effects are experienced?
  • Which lifecycle model is iterative and emphasizes risk analysis during each phase?
  • Which risk occurs when a cloud customer cannot access data because the provider ceases operation?
  • Which term is the value used to represent the portion of asset value lost due to a threat?
  • Which term relies on a system of digital certificates and asymmetric keys?
  • Which term functions as a medium of exchange in digital form?
  • Which term refers to both non-malicious and malicious insiders and outsiders, including spies, adversaries, terrorists, and others?
  • What term refers to the rest of the industry, including peers and competitors?
  • Which term covers failures of hardware or software, including malware that inflicts harm?
  • Which act governs the privacy of government records and personal data?
  • Which storage type is similar to object storage but comes with a hierarchical file and folder structure imposed on the data?
  • Which data classification includes blueprints for weapons or other information that could gravely damage national security if disclosed?
  • A strategy that seeks to accept the current level of risk and the costs associated with it.
  • Which term acts as a set of patterns that should be matched by the system?
  • Which term describes data entry when information is manually typed into the system by personnel?
  • Used in place of a primary access control measure in order to mitigate a given risk.
  • Which term is primarily concerned with data quality and metadata management?
  • Passes inter-switch traffic which provides a layer of security. Which VLAN is described?
  • Which term refers to groups that may include criminals and nation-state attackers seeking to compromise systems?
  • What is the primary benefit of Single Sign-On (SSO) for users within a network?
  • Used to teach the organization's personnel the skills that they need to perform their job in a more secure manner.
  • An established point in time to which the disrupted asset or component should be restored is called what?
  • Unified Extensible Firmware Interface (UEFI) provides support for 64-bit CPU operations, a full GUI and mouse operations, and better boot security.
  • Which act protects the privacy of student education records?
  • Double Tagging is the attack that adds two VLAN tags to frames (outer and inner) to perform what type of attack?
  • A segment designed to host publicly accessible services while isolating them from the internal network is known as what?
  • Which term describes general best practices that are commonly employed across industries?
  • Which description best defines Time-Based One-Time Password (TOTP)?
  • Which deployment type restricts access to devices within the same private cloud or system?
  • Which term refers to a subset of a system's development focused on the creation of software to support a given solution?
  • Which approach to intrusion detection relies on a database of known attack signatures?
  • Which practice aims to decrease time to deployment by integrating development, QA, and operations into one team?
  • What term refers to stateless filtering rules applied at the subnet level and apply to every resource deployed to the subnet within the VPC or VNE?
  • Network Traffic Decryption is the process of?
  • Which term denotes a comprehensive assessment of risk by identifying assets, threats, vulnerabilities, and impacts?
  • Provides a math-based methodological process for historical data and provides a baseline and possibly a future projection of risk.
  • What term describes a device that contains both the needed hardware and software to perform a dedicated function?
  • Which model hosts all desktop instances on a single server or server farm?
  • Which access control model centralizes permissions by assigning users to roles with corresponding access rights?
  • Which model would be most appropriate when access decisions rely on multiple attributes of the user and the resource?
  • Which term is an advanced cloud computing model that supports service-oriented application development and microservice-based deployment?
  • Which component ensures that only authorized users can access sensitive resources?
  • Which capability uses a device's location detection to determine whether to grant access to a resource?
  • Which term represents the date when a manufacturer will no longer sell a given product?
  • What do Application Controls help manage on workstations and servers?
  • Which technology uses radio frequency to send transaction data over a short distance?
  • Which term describes data that is generated by a device used within the organization?
  • Which one-time password method uses a shared secret and the current time to generate codes?
  • Which protocol is described as a peer-to-peer protocol created as a next-generation version of RADIUS?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy