01. Ransomware has taken an insurer's claims intake system offline. The response team has contained the infection and technical restoration is under way, but the claims department still has to accept and record new claims from customers while the system is down.
Which plan governs how the department keeps accepting claims during the outage?
a) The incident response plan, which directs the containment and eradication of the infection
b) The disaster recovery plan, which restores the affected systems to service
c) The crisis communication plan, which notifies customers and regulators
d) The business continuity plan, which keeps the process running by other means
02. Contractor laptops connect to an office network. The organization wants each laptop checked for current anti-malware and patch levels at the moment it connects, and wants a laptop that fails the check kept away from production systems. Which control provides this?
a) Network access control that evaluates device posture and quarantines a device that fails
b) A virtual private network gateway that encrypts the contractor's traffic
c) A web application firewall that inspects the requests users send to the published order portal
d) Mobile device management that enforces configuration on enrolled handsets
03. Users at an enterprise type the correct name of their banking portal into their browsers and are delivered to a site under an attacker's control. The name shown in the address bar is the one they typed. Which attack BEST explains what happened?
a) Capture of the user's session token after a valid login
b) Poisoning of the resolver's cached name-resolution records
c) Substitution of the attacker's certificate during the encrypted handshake
d) Registration of a look-alike domain near the real one
04. An auditor examines logs pulled from a firewall, a directory server, and an application server for a single intrusion. Each system recorded the same connection, but the three entries carry timestamps minutes apart, and no common time source is configured anywhere in the environment.
What is the most significant consequence for the investigation?
a) The order of events across the three systems cannot be established reliably
b) Individual entries can no longer be attributed to the account that produced them
c) Entries from the systems will be recorded in different formats
d) The integrity of each log file can no longer be demonstrated
05. The discovery of known dangerous artifacts on a network, such as IP addresses or domain names, helps to identify which of the following?
a) System vulnerabilities
b) A data breach
c) Indicator of compromise
d) Unauthorized access
06. An organization already allows staff to authenticate once and reach several internal applications without signing in again. It now wants partner staff, employed by a different company, to reach one of those applications using credentials their own employer issued.
What does federation add to single sign-on?
a) A second authentication factor applied to every sign-on event inside the organization
b) Trust in an authentication carried out by another organization
c) A requirement for each application to hold its own copy of every user's password
d) Removal of the authentication server, with credentials stored on each user's own device
07. Why are security frameworks an important part of a cybersecurity strategy?
a) They are required for regulatory compliance.
b) They provide protection to the organization.
c) They contain the necessary policies and standards.
d) They serve to integrate and guide activities.
08. Most alerts produced by one detection rule turn out to be benign activity, and analysts have started closing that rule's alerts without opening them. Genuine detections from the same rule are now going unread. Which response addresses the underlying problem?
a) Refine the rule's logic to match the activity it targets
b) Raise the rule's threshold until the number of alerts becomes manageable
c) Move the rule's alerts into a low priority queue that is reviewed later
d) Assign more analysts to the queue for each shift
09. A healthcare organization recently acquired another firm that outsources its patient information processing to a third-party Software as a Service (SaaS) provider. From a regulatory perspective, which of the following is MOST important for the healthcare organization to determine?
a) Cybersecurity risk assessment methodology
b) Encryption algorithms used to encrypt the data
c) Physical location of the data
d) Incident escalation procedures
10. The private key belonging to an enterprise's public web server certificate has been exposed. The certificate itself remains well inside its stated validity period. What should the enterprise do FIRST about that certificate?
a) Ask the certificate authority to reissue the certificate for the same key pair already deployed
b) Have the certificate authority revoke it and publish the revocation to relying parties
c) Shorten the validity period requested for subsequent certificates on this production server
d) Request a replacement certificate from the certificate authority once the present one has expired