A financial services company is implementing a new data classification policy. The policy defines four levels: Public, Internal, Confidential, and Restricted. A security analyst needs to apply a technical control that prevents files classified as 'Restricted' from being attached to emails sent to external domains. Which security technology is specifically designed to enforce this type of policy-based data handling rule?
Answer and explanation
Correct answer: B
Data Loss Prevention (DLP) systems are specifically designed to enforce policies based on data classification and content analysis. They can inspect data in motion (like email attachments), at rest (on storage), and in use (on endpoints) to prevent unauthorized exfiltration of sensitive information, such as blocking 'Restricted' files from being sent externally.
Question 2
During an incident response tabletop exercise, a team is presented with a scenario where a critical server has been infected with ransomware. The team needs to follow the standard incident response lifecycle. What is the immediate first step that should be taken after detecting and analyzing the incident?
Answer and explanation
Correct answer: C
After detection and analysis, the immediate priority in the incident response lifecycle is containment. This involves isolating the affected system (e.g., disconnecting it from the network) to prevent the ransomware from spreading to other systems. Eradication (removing the malware) and Recovery (restoring from backups) follow the containment phase.
Question 3
A security team is implementing Role-Based Access Control (RBAC) for a large enterprise. They have defined roles such as 'Sales Associate', 'HR Manager', and 'System Administrator'. Which of the following is a primary benefit of using RBAC over Discretionary Access Control (DAC)?
Answer and explanation
Correct answer: B
The primary benefit of RBAC is administrative scalability and simplified management. Instead of assigning permissions directly to hundreds or thousands of individual users, administrators assign permissions to a smaller number of roles. Users are then assigned to these roles, inheriting the associated permissions. This greatly reduces the complexity of managing user access, especially during onboarding, offboarding, and role changes.
Question 4
A threat analyst is investigating a new malware variant that uses a domain generation algorithm (DGA) to create thousands of random domain names for its command-and-control (C2) communication. Which of the following is the MOST effective strategy for a security operations team to detect and block this type of threat?
Answer and explanation
Correct answer: C
DGA malware is designed to evade static blocklists by generating a vast number of potential C2 domains, with only a few being active at any time. The most effective defense is a dynamic one. Modern DNS security solutions use machine learning and statistical analysis to identify the patterns of algorithmically generated domains (e.g., high entropy, unusual character distribution) and block them proactively, without needing to know the specific domains in advance.
Question 5
Multiple answers
A company is conducting a Business Impact Analysis (BIA) to develop its business continuity plan. The analysis determines that the customer relationship management (CRM) system can tolerate a maximum of 4 hours of downtime before causing significant financial loss. It is also determined that losing more than 1 hour of transaction data is unacceptable. How should these two metrics be formally defined? (Select TWO).
Answer and explanation
Correct answers: A, C
The Recovery Time Objective (RTO) defines the maximum acceptable duration of an outage for a system. In this case, the business can tolerate the CRM being down for a maximum of 4 hours, making this the RTO.
The Recovery Point Objective (RPO) defines the maximum acceptable amount of data loss, measured in time. The business has determined that losing more than 1 hour of transaction data is unacceptable, which directly corresponds to an RPO of 1 hour.
Question 6
True or False: In a symmetric encryption system, the key used for encryption is different from the key used for decryption.
Answer and explanation
Correct answer: B
This statement is false. The defining characteristic of symmetric encryption (also known as secret-key or shared-key encryption) is that the same key is used for both the encryption and decryption processes. Asymmetric encryption, in contrast, uses a key pair consisting of a public key for encryption and a different, private key for decryption.
Question 7
Company Background: Global Logistics Inc. (GLI) is a large shipping and logistics company that operates a complex network of warehouses, distribution centers, and transportation fleets. The company relies heavily on its Industrial Control Systems (ICS) and Supervisory Control and Data Acquisition (SCADA) systems to manage automated sorting machinery, climate control in sensitive storage areas, and fleet tracking. Historically, the ICS/SCADA network was completely air-gapped from the corporate IT network.
Current Situation: To improve efficiency and enable predictive maintenance, GLI's management has approved a project to connect the ICS/SCADA network to the corporate IT network. This will allow data from the operational technology (OT) environment to be analyzed by business intelligence platforms in the IT environment. The CISO is concerned because the ICS/SCADA systems are legacy devices, many running on old, unpatched operating systems that cannot be easily upgraded. The OT engineers are resistant to any changes that could introduce latency or cause downtime.
Requirements & Constraints:
Prevent unauthorized traffic from the IT network from reaching the critical ICS/SCADA devices.
Allow specific, approved data flows from the OT network to a data historian server in the IT network.
Ensure that security controls do not interfere with the real-time operational requirements of the OT environment.
The solution must be implemented without replacing the legacy ICS/SCADA equipment.
Which of the following architectural approaches BEST meets GLI's security and operational requirements?
graph TD
subgraph IT_Network [Corporate IT Network]
BI[BI Platform]
Users[Corporate Users]
end
subgraph OT_Network [ICS/SCADA Network]
PLC[PLCs]
HMI[HMIs]
Sensors[Sensors]
end
IT_Network -- "????" -- OT_Network
Answer and explanation
Correct answer: B
This is the best approach based on industry best practices like the Purdue Model for ICS security. A DMZ creates a buffer zone that strictly controls communication between the IT and OT networks. Placing a data historian in the DMZ allows OT systems to send data to a single, controlled point without allowing direct access from the IT network into the OT environment. A proxy adds another layer of security by terminating connections and inspecting traffic, preventing direct protocol communication. This architecture meets all requirements: it prevents unauthorized access, allows specific data flows, and minimizes impact on the real-time OT network.
Question 8
A SOC analyst is reviewing logs from a Security Information and Event Management (SIEM) system and notices a large number of failed login attempts for a single administrator account, originating from multiple international IP addresses within a five-minute window. This is immediately followed by a single successful login from a new, previously unseen international IP address. Which type of attack has MOST likely occurred?
Answer and explanation
Correct answer: D
The pattern described—many failed login attempts against a single account from various sources, culminating in a success—is a classic indicator of a distributed brute-force attack. Attackers use a botnet or multiple compromised machines to try a large number of passwords against one username, eventually guessing the correct one. Password spraying involves trying one or a few common passwords against many different usernames, which would present a different log pattern.
Question 9
Multiple answers
Which of the following are considered administrative security controls? (Select THREE).
Answer and explanation
Correct answers: B, C, E
Security awareness training is an administrative control that aims to influence user behavior and enforce security policies through education.
An acceptable use policy is a document (a policy) that governs how employees can use company assets, making it a classic administrative control.
Conducting background checks is a procedural control (an administrative control) designed to mitigate risks associated with personnel.
Question 10
A software development team uses a CI/CD pipeline to automate builds, testing, and deployments. A security engineer wants to integrate security scanning into this pipeline to identify vulnerabilities early in the development lifecycle. This practice is a core component of which methodology?
Answer and explanation
Correct answer: C
DevSecOps is a methodology that integrates security practices within the DevOps process. A key principle of DevSecOps is 'shifting left,' which means incorporating security considerations and automated testing (like SAST and DAST scans) as early as possible in the development lifecycle, often directly within the CI/CD pipeline. This contrasts with traditional models where security testing is a separate phase at the end of development.