01. An analyst confirms that personal records held by the organization have been read by someone outside it, and breach-notification law applies in that jurisdiction.
What does the organization then have to do?
a) Tell the people affected and the relevant authority that their records were reached
b) Publish the technical detail of the weakness and the fix so that others can defend themselves
c) Recover the records from the person who read them before saying anything
d) Keep the finding confidential until the vulnerability has been closed
02. Connected devices such as cameras, thermostats and industrial controllers often stay in service for a decade or more.
Why does that long service life create a security problem?
a) Configuration drift accumulates until nobody can say what settings the device holds
b) Aging hardware fails more often, so the device is offline at the moment it is needed
c) Old devices exhaust the pool of network addresses that was set aside for the estate
d) Weaknesses discovered beyond the support window have no fix to apply
03. Staff reach a company's cloud services from home networks, hotels and mobile connections, so there is no single network edge to defend.
Which control becomes the primary boundary in that arrangement?
a) Placement of the services behind the head office firewall and its gateway
b) Encryption of stored data using keys held by the provider
c) Verification of user and device identity at each incoming request
d) Restriction of access to a fixed list of approved home network addresses
04. A team compares running an application on cloud infrastructure it manages itself against subscribing to a finished cloud application.
What changes about the customer's security work as it moves from infrastructure as a service to software as a service?
a) Operating system and runtime upkeep pass to the provider, while data protection stays with the customer
b) The customer keeps operating system patching under both models, so the workload is unchanged
c) Responsibility for user accounts and their permissions passes to the provider, while server patching stays with the customer
d) Security responsibility passes wholly to the provider, leaving the customer a purely commercial relationship
05. Requests from many thousands of compromised machines arrive at once at a company's public website, until the site stops answering legitimate visitors.
Which term names this attack?
a) A denial of service attack from a single source
b) A privilege escalation attack against the web server
c) A distributed denial of service attack
d) A brute force attack against the site's logon page
06. Files across a company's shared drives are encrypted and a payment demand appears, weeks after the intruder first obtained access.
Which description of ransomware does this sequence support?
a) It is how access is kept alive across a restart, since encrypted files are hard to clean up
b) It is how information is gathered quietly, since encrypting files shows what a company holds
c) It is how the intruder got in, since the encryption is what opened the drives
d) It is how an intrusion is acted on and made visible, rather than how the intruder got in
07. A finance clerk takes a telephone call from someone claiming to be a supplier, who persuades the clerk to change the bank details held for that supplier.
Why do technical controls alone leave this risk open?
a) The call arrived on a line the network monitoring tools do not inspect
b) The change was made outside the hours when logging is switched on
c) The clerk was authorized to make the change
d) The supplier record is held in a system the security team does not administer
08. Two organizations are compromised by the same technique. One finds the intrusion the next day; the other finds it four months later. Both blocked a similar number of attacks over the same year.
What does the difference between them mainly reveal?
a) Their recovery planning differs, and the slower organization would take longer to restore service once the intrusion was understood
b) Their risk appetite differs, and the slower organization accepted an exposure that the other would have treated as unacceptable
c) Their preventive controls differ, and the slower organization must have been running fewer of them when the compromise happened
d) Their detection capability differs, and a count of blocked attacks says nothing about how quickly a successful one is found
09. Six months after an awareness program starts, the number of suspicious messages reported by staff to the security team has tripled.
What is the most reasonable reading of that increase?
a) The organization is under more attack than before and the program has not helped
b) Staff are reporting ordinary messages out of anxiety, so the figure should be discounted
c) Staff are noticing suspicious messages and telling someone, which is what the program set out to do
d) The email filtering has degraded, so more unwanted messages and alerts reach staff
10. Having compromised a workstation, an intruder arranges to regain entry automatically whenever the machine is restarted.
Which goal does this arrangement serve?
a) Privilege escalation, so the account gains a higher level of rights
b) Lateral movement, so a second machine comes under the intruder's control
c) Exfiltration, so the gathered files leave the network
d) Persistence, so the foothold outlives a reboot of the machine