01. Four administrators maintain a database using one shared account whose password they all know. An unauthorized change is later found in the logs. Which security property has this arrangement defeated?
a) Confidentiality of the data held in the database
b) Availability of the database to the people who depend on it
c) Accountability for the actions recorded against the account
d) Integrity of the log entries written when the change was made
02. An application rejects input containing database syntax, but a comment submitted by one visitor still causes script to run in the browsers of other visitors when the page is displayed. Which additional measure BEST addresses this?
a) Rejecting any comment that contains angle brackets
b) Requiring visitors to sign in before they may comment
c) Serving the page over an encrypted connection
d) Encoding stored content when it is written into the page
03. In a government system, every document carries a sensitivity label, every user holds a clearance, and the system itself decides access by comparing the two. Users cannot share a document with a colleague who lacks the clearance, even if they wrote it. Which access control model is in use?
a) Role-based access control
b) Mandatory access control
c) Discretionary access control
d) Attribute-based access control
04. A retailer sees a surge of sign-in attempts against its customer accounts. Each username is tried once with its own particular password, the usernames are all real customers, and roughly one attempt in a thousand succeeds. Which attack does this pattern BEST indicate?
a) A brute-force attack, trying every possible password in turn
b) A dictionary attack, working through likely passwords against one account
c) Credential stuffing, replaying pairs leaked from a different service
d) A rainbow-table attack, reversing password hashes that have been captured
05. Staff read work email on their own phones. The organization needs to be able to remove company information from a phone when someone leaves, without touching the owner's personal photographs and messages. Which approach meets both requirements?
a) Keep company information in a managed area that can be removed on its own
b) Enroll each phone for full-device management and wipe it when the owner leaves
c) Ask each owner to undertake in writing to delete company information on departure
d) Permit access only from company-owned handsets and withdraw personal phones
06. An organization takes nightly backups and has never had a failure reported by the backup software. During a recovery it discovers that a critical database has been backed up in a form that cannot be restored. Which practice would have revealed this earlier?
a) Encrypting the backups so that the stored copies are protected
b) Storing a second copy of each backup at a different site
c) Increasing how long each backup is retained before it is overwritten
d) Performing periodic test restores from the backups that were taken
07. Servers are built from an approved secure configuration. Over the following year, administrators make individual changes to solve particular problems, and a review finds that few servers still match the approved settings. Which practice BEST addresses this condition?
a) Recording each administrator's changes in a shared log
b) Comparing servers against the approved settings and correcting differences
c) Rebuilding every server from the approved configuration each year
d) Requiring a second administrator to approve each change
08. A data center enforces badge entry at the building door, but the server room inside is left unlocked during working hours and its consoles are signed in. Which principle does this arrangement disregard?
a) Physical access to a system generally defeats its logical controls
b) Detective controls should accompany every preventive control
c) Authentication should be required before authorization is evaluated
d) Controls should be applied consistently across all business hours
09. Attackers wanting access to a defense contractor compromise a small industry news site that engineers at the contractor read daily, and place code there that attacks visitors' browsers. Which technique is this?
a) A man-in-the-middle attack
b) A supply chain attack
c) A denial-of-service attack
d) A watering hole attack
10. An attacker studies a manufacturing company for several weeks and then sends one email to its chief executive alone, referring to a genuine board matter and inviting her to sign in to a document portal to review the papers. Which social-engineering technique does this MOST precisely describe?
a) Spear phishing, in which a researched individual is approached with a message written for them
b) Whaling, in which a senior executive is targeted because the office carries authority
c) Pharming, in which traffic is redirected to a counterfeit site without the user noticing
d) Vishing, in which a voice call is used to pressure the target into an immediate decision