What is the primary benefit of implementing a Zero Trust Architecture in a corporate network?
Answer and explanation
Correct answer: B
Zero Trust Architecture focuses on continuous verification of each user and device, ensuring access control is maintained at all times.
Question 2
Infrastructure as Code (IaC) is a critical component in modern DevOps practices. Which of the following is a key advantage of using IaC?
Answer and explanation
Correct answer: B
IaC allows for automated and consistent system configuration, reducing errors and increasing deployment speed.
Question 3
Which of the following describes a primary purpose of Security Information and Event Management (SIEM) systems?
Answer and explanation
Correct answer: B
SIEM systems are used to aggregate and analyze security alerts in real time, helping organizations respond to potential threats quickly.
Question 4
Which type of attack exploits weaknesses in DNS services to redirect users to malicious sites?
Answer and explanation
Correct answer: C
DNS Spoofing is an attack that exploits vulnerabilities in DNS services to redirect users to malicious sites without their knowledge.
Question 5
What is the main objective of implementing Secure Access Service Edge (SASE) in an organization?
Answer and explanation
Correct answer: A
SASE combines network security functions with WAN capabilities to support dynamic secure access needs of modern organizations.
Question 6
Which term describes the process of identifying, assessing, and mitigating risks within an organization?
Answer and explanation
Correct answer: A
Risk Management is the process of identifying, assessing, and mitigating risks to minimize potential negative impacts on an organization.
Question 7
Which of the following best describes the principle of least privilege?
Answer and explanation
Correct answer: B
The principle of least privilege involves providing users with the minimal level of access necessary to perform their job functions, reducing the risk of unauthorized access.
Question 8
Which strategy best describes the use of honeypots in cybersecurity?
Answer and explanation
Correct answer: B
Honeypots are used in cybersecurity to attract attackers to decoy systems, allowing organizations to collect intelligence on their activities.
Question 9
Which of the following is a primary characteristic of a Distributed Denial of Service (DDoS) attack?
Answer and explanation
Correct answer: B
A DDoS attack involves flooding a target with traffic from multiple sources, causing disruption and potential service outages.
Question 10
Which cryptographic method uses a single key for both encryption and decryption?
Answer and explanation
Correct answer: B
Symmetric encryption uses a single key for both encryption and decryption, making it simpler and faster than asymmetric methods.
Question 11
What does the CIA triad stand for in cybersecurity?
Answer and explanation
Correct answer: A
The CIA triad in cybersecurity stands for Confidentiality, Integrity, and Availability, which are the core principles for securing information.
Question 12
Which type of malware is specifically designed to provide unauthorized access to a system?
Answer and explanation
Correct answer: B
A Trojan Horse is a type of malware that disguises itself as legitimate software, providing unauthorized access to a system once executed.
Question 13
Which security principle helps protect data by ensuring that only authorized users can access sensitive information?
Answer and explanation
Correct answer: A
Confidentiality is a security principle that ensures only authorized individuals can access sensitive information, protecting it from unauthorized disclosure.
Question 14
Which of the following is an example of a physical security control?
Answer and explanation
Correct answer: C
A security guard is a physical security control that helps protect facilities and personnel by monitoring access and deterring unauthorized entry.
Question 15
Which method involves hiding data within another file, such as an image or video?
Answer and explanation
Correct answer: B
Steganography is the practice of hiding data within another file, such as an image or video, to conceal its presence.
Question 16
Multiple answers
Which of the following are considered security operations tasks? Select TWO.
Answer and explanation
Correct answers: A, B
Security operations tasks typically include vulnerability scanning and incident response, both of which are essential for maintaining system security.
Question 17
Multiple answers
Which of the following are benefits of using cloud-native security tools? Select TWO.
Answer and explanation
Correct answers: B, C
Cloud-native security tools provide increased flexibility and can often lead to lower costs due to their scalable and efficient nature.
Question 18
Multiple answers
Which practices help ensure secure software development? Select TWO.
Answer and explanation
Correct answers: A, C
Code reviews and penetration testing are critical practices in secure software development, helping to identify and address vulnerabilities.
Question 19
Multiple answers
In cloud computing, which elements are crucial for maintaining data sovereignty? Select ALL that apply.
Answer and explanation
Correct answers: A, B, E
Data encryption, geolocation, and legal compliance are essential elements for maintaining data sovereignty in cloud computing.
Question 20
A SOC analyst is reviewing firewall logs and notices a large volume of inbound DNS query responses from multiple external IP addresses. These responses are significantly larger than the initial outbound queries sent from a single server within the internal network. The target server is now unresponsive. What type of DDoS attack is MOST likely occurring?
graph TD
subgraph Attacker Controlled
A[Attacker] --> R1[Reflector 1]
A --> R2[Reflector 2]
A --> R3[Reflector 3]
end
subgraph Victim Network
S[Internal Server]
V[Victim Server]
end
A -- small spoofed query
(source=V) --> R1
A -- small spoofed query
(source=V) --> R2
A -- small spoofed query
(source=V) --> R3
R1 -- large response --> V
R2 -- large response --> V
R3 -- large response --> V
Answer and explanation
Correct answer: B
This scenario perfectly describes a DNS amplification and reflection attack. The 'reflection' part comes from the attacker spoofing the victim's IP address and sending queries to third-party DNS servers (reflectors). The 'amplification' part comes from crafting a small query that elicits a very large response. The reflectors then send these large responses to the victim, overwhelming its network bandwidth and resources. The key indicators are the use of DNS and the response size being much larger than the query.