🔒 OLUMA CERTIFICATION ZONE CCPractice Range 100 original scenarios across the five CC domains — security principles, business continuity, access controls, network security and security operations. ISC2’s entry-level credential, and the perfect first step into cybersecurity. Pick your range and get started. START HERE How do you want us to call you? Enter a name to unlock the practice range — we’ll keep it friendly from here on. 🔒 Practice range locked — enter a name above to begin ✔ You’re in, learner — scroll on when you’re ready About the Certification What is ISC2 CC? Certified in Cybersecurity (CC) is ISC2’s entry-level credential — built from scratch to help newcomers, students, and career changers prove they understand core cybersecurity concepts well enough to be trusted in a real role. It’s the rare certification with no work-experience requirement, and through its “One Million Certified in Cybersecurity” initiative, ISC2 has offered free training and exam vouchers to over a million people. It’s an ideal first certification if you’re breaking into cybersecurity (like much of the Oluma community), moving over from general IT, or building toward larger ISC2 credentials like the SSCP and CISSP down the line. 🖥️SOC Analyst (Tier 1)Monitor alerts and triage security events. 🔎Junior Security AnalystLearn to investigate and support defenses. 🧰IT Support (Security)Bring security into everyday IT work. 🛠️Cybersecurity TechnicianHands-on with the fundamentals of defense. ProviderISC2 Format100–125 items Time120 minutes Passing Score700 / 1000 Exam Objectives The five domains CC covers five entry-level domains. Security Principles is the heavyweight at 26%, with Network Security (24%) and Access Controls (22%) close behind — those three are nearly three-quarters of the exam. These practice questions are grouped by the same five areas. 1 · Security PrinciplesCIA triad, AAA, risk, controls, governance docs and the ISC2 Code of Ethics.26% 2 · BC, DR & Incident ResponseBusiness continuity, disaster recovery, and the incident response lifecycle.10% 3 · Access Controls ConceptsIdentification, authentication factors, access models, and physical access.22% 4 · Network SecurityFirewalls, VPNs, ports, protocols, common attacks and network defenses.24% 5 · Security OperationsData handling, encryption, hardening, patching, and everyday operations.18% Official Resources Go straight to the source Bookmark the official ISC2 pages for authoritative details on the exam, free training, and the full domain blueprint. These open in a new tab. 🎓Official Certification PageOverview, free training & how to register↗ 📋Exam Outline (Oct 2025)The official five-domain blueprint↗ Before You Start Set yourself up to pass CC is entry-level, but it rewards clear fundamentals over memorized trivia. A few habits make it click. 1Weight your studySecurity Principles (26%), Network Security (24%) and Access Controls (22%) are nearly three-quarters of the exam. Start there. 2Learn the CIA triadConfidentiality, Integrity and Availability underpin everything. Know each one and how controls protect it. 3Know your access termsIdentification, authentication, authorization, accountability — plus the three factors (know, have, are). CC leans hard on these. 4Get governance straightPolicy, standard, procedure and guideline — CC asks many short scenarios testing the difference. 5Think in scenariosMost questions describe a situation and ask the BEST answer. Reason from the concept, not a memorized line. 6Don’t fear the CATThe exam is adaptive now — questions adjust to your answers and you can’t go back. Pace steadily, commit, and move on. Security PrinciplesBC / DR / IRAccess ControlsNetwork SecuritySecurity Operations SELECT YOUR RANGE102550100 1/100 Security Principles Keeping sensitive data from being disclosed to unauthorized people protects which part of the CIA triad? AConfidentiality✔ ACCESS GRANTEDThat’s foundation-solid — clean and correct.Confidentiality ensures information is disclosed only to authorized parties. BIntegrity✖ ACCESS DENIEDNo stress — here’s the fix:Confidentiality ensures information is disclosed only to authorized parties. CAvailability✖ ACCESS DENIEDNo stress — here’s the fix:Confidentiality ensures information is disclosed only to authorized parties. DNon-repudiation✖ ACCESS DENIEDNo stress — here’s the fix:Confidentiality ensures information is disclosed only to authorized parties. 2/100 Security Principles Ensuring that data has not been altered or tampered with protects which principle? AConfidentiality✖ THREAT DETECTEDEvery miss is a lesson. Takeaway:Integrity ensures data remains accurate and unaltered. BAvailability✖ THREAT DETECTEDEvery miss is a lesson. Takeaway:Integrity ensures data remains accurate and unaltered. CAuthentication✖ THREAT DETECTEDEvery miss is a lesson. Takeaway:Integrity ensures data remains accurate and unaltered. DIntegrity✔ THREAT NEUTRALIZEDSharp. You’re thinking like a defender.Integrity ensures data remains accurate and unaltered. 3/100 Security Principles A ransomware attack that locks users out of critical files most directly harms which principle? ANon-repudiation✖ ALERT RAISEDReset and lock it in with this:Availability ensures authorized users can access systems and data when they need them. BAccountability✖ ALERT RAISEDReset and lock it in with this:Availability ensures authorized users can access systems and data when they need them. CAvailability✔ IDENTITY VERIFIEDYou’ve got the principle down. Textbook.Availability ensures authorized users can access systems and data when they need them. DConfidentiality✖ ALERT RAISEDReset and lock it in with this:Availability ensures authorized users can access systems and data when they need them. 4/100 Security Principles A user proves who they are by entering a password. This step is: AAuditing✖ CHECK FAILEDPatch your thinking with this:Authentication verifies identity; authorization then decides what that identity may do. BAuthentication✔ CONTROL VALIDATEDLocked in — that’s the CC mindset.Authentication verifies identity; authorization then decides what that identity may do. CAuthorization✖ CHECK FAILEDPatch your thinking with this:Authentication verifies identity; authorization then decides what that identity may do. DAccounting✖ CHECK FAILEDPatch your thinking with this:Authentication verifies identity; authorization then decides what that identity may do. 5/100 Security Principles After logging in, the system checks whether the user is allowed to open a payroll file. This step is: AAuthorization✔ RISK MITIGATEDVerified. Oluma loves to see it.Authorization determines what an authenticated identity is permitted to access or do. BAuthentication✖ FLAGGED FOR REVIEWNo stress — here’s the fix:Authorization determines what an authenticated identity is permitted to access or do. CIdentification✖ FLAGGED FOR REVIEWNo stress — here’s the fix:Authorization determines what an authenticated identity is permitted to access or do. DEncryption✖ FLAGGED FOR REVIEWNo stress — here’s the fix:Authorization determines what an authenticated identity is permitted to access or do. 6/100 Security Principles A digital signature ensures a sender cannot later deny sending a message. This property is: AAvailability✖ ACCESS DENIEDEvery miss is a lesson. Takeaway:Non-repudiation prevents a party from credibly denying an action they took. BConfidentiality✖ ACCESS DENIEDEvery miss is a lesson. Takeaway:Non-repudiation prevents a party from credibly denying an action they took. CRedundancy✖ ACCESS DENIEDEvery miss is a lesson. Takeaway:Non-repudiation prevents a party from credibly denying an action they took. DNon-repudiation✔ POLICY ENFORCEDNicely done — that’s a keeper.Non-repudiation prevents a party from credibly denying an action they took. 7/100 Security Principles An unpatched flaw in software that could be exploited is best described as a: ARisk✖ THREAT DETECTEDReset and lock it in with this:A vulnerability is a weakness; a threat is something that could exploit it. BControl✖ THREAT DETECTEDReset and lock it in with this:A vulnerability is a weakness; a threat is something that could exploit it. CVulnerability✔ INTEGRITY CONFIRMEDThat’s foundation-solid — clean and correct.A vulnerability is a weakness; a threat is something that could exploit it. DThreat✖ THREAT DETECTEDReset and lock it in with this:A vulnerability is a weakness; a threat is something that could exploit it. 8/100 Security Principles A hacker who wants to steal an organization’s data is an example of a: AAsset✖ ALERT RAISEDPatch your thinking with this:A threat is a potential danger or actor that could exploit a vulnerability. BThreat✔ SECUREDSharp. You’re thinking like a defender.A threat is a potential danger or actor that could exploit a vulnerability. CVulnerability✖ ALERT RAISEDPatch your thinking with this:A threat is a potential danger or actor that could exploit a vulnerability. DControl✖ ALERT RAISEDPatch your thinking with this:A threat is a potential danger or actor that could exploit a vulnerability. 9/100 Security Principles Risk is best described as the combination of: AThe likelihood of a threat exploiting a vulnerability and its impact✔ VERIFIEDYou’ve got the principle down. Textbook.Risk combines the likelihood and the impact of a threat exploiting a vulnerability. BThe number of users on a system✖ CHECK FAILEDNo stress — here’s the fix:Risk combines the likelihood and the impact of a threat exploiting a vulnerability. CThe purchase cost of hardware✖ CHECK FAILEDNo stress — here’s the fix:Risk combines the likelihood and the impact of a threat exploiting a vulnerability. DThe age of a software product✖ CHECK FAILEDNo stress — here’s the fix:Risk combines the likelihood and the impact of a threat exploiting a vulnerability. 10/100 Security Principles Management decides a small risk isn’t worth the cost to fix and formally takes no action. This is risk: AAvoidance✖ FLAGGED FOR REVIEWEvery miss is a lesson. Takeaway:Risk acceptance means acknowledging a risk and choosing to take no further action on it. BTransference✖ FLAGGED FOR REVIEWEvery miss is a lesson. Takeaway:Risk acceptance means acknowledging a risk and choosing to take no further action on it. CMitigation✖ FLAGGED FOR REVIEWEvery miss is a lesson. Takeaway:Risk acceptance means acknowledging a risk and choosing to take no further action on it. DAcceptance✔ DEFENSE HELDLocked in — that’s the CC mindset.Risk acceptance means acknowledging a risk and choosing to take no further action on it. CHECKPOINT — 10 DOWN, STAY SHARP 11/100 Security Principles Buying cyber insurance to cover the cost of a possible breach is risk: AAcceptance✖ ACCESS DENIEDReset and lock it in with this:Transference shifts the financial impact of a risk to a third party, such as an insurer. BMitigation✖ ACCESS DENIEDReset and lock it in with this:Transference shifts the financial impact of a risk to a third party, such as an insurer. CTransference✔ ACCESS GRANTEDVerified. Oluma loves to see it.Transference shifts the financial impact of a risk to a third party, such as an insurer. DAvoidance✖ ACCESS DENIEDReset and lock it in with this:Transference shifts the financial impact of a risk to a third party, such as an insurer. 12/100 Security Principles Installing a firewall to reduce the chance an attack succeeds is risk: AAvoidance✖ THREAT DETECTEDPatch your thinking with this:Mitigation reduces the likelihood or impact of a risk by applying controls. BMitigation✔ THREAT NEUTRALIZEDNicely done — that’s a keeper.Mitigation reduces the likelihood or impact of a risk by applying controls. CAcceptance✖ THREAT DETECTEDPatch your thinking with this:Mitigation reduces the likelihood or impact of a risk by applying controls. DTransference✖ THREAT DETECTEDPatch your thinking with this:Mitigation reduces the likelihood or impact of a risk by applying controls. 13/100 Security Principles A company decides not to launch a risky new feature at all, eliminating its risk. This is risk: AAvoidance✔ IDENTITY VERIFIEDThat’s foundation-solid — clean and correct.Avoidance eliminates a risk by choosing not to engage in the activity that creates it. BAcceptance✖ ALERT RAISEDNo stress — here’s the fix:Avoidance eliminates a risk by choosing not to engage in the activity that creates it. CTransference✖ ALERT RAISEDNo stress — here’s the fix:Avoidance eliminates a risk by choosing not to engage in the activity that creates it. DMitigation✖ ALERT RAISEDNo stress — here’s the fix:Avoidance eliminates a risk by choosing not to engage in the activity that creates it. 14/100 Security Principles A locked door and a security guard are examples of which type of control? ATechnical✖ CHECK FAILEDEvery miss is a lesson. Takeaway:Physical controls protect facilities and hardware — locks, guards, fences, and the like. BAdministrative✖ CHECK FAILEDEvery miss is a lesson. Takeaway:Physical controls protect facilities and hardware — locks, guards, fences, and the like. CLogical✖ CHECK FAILEDEvery miss is a lesson. Takeaway:Physical controls protect facilities and hardware — locks, guards, fences, and the like. DPhysical✔ CONTROL VALIDATEDSharp. You’re thinking like a defender.Physical controls protect facilities and hardware — locks, guards, fences, and the like. 15/100 Security Principles A firewall and antivirus software are examples of which type of control? AAdministrative✖ FLAGGED FOR REVIEWReset and lock it in with this:Technical/logical controls are implemented through technology. BManagerial✖ FLAGGED FOR REVIEWReset and lock it in with this:Technical/logical controls are implemented through technology. CTechnical (logical)✔ RISK MITIGATEDYou’ve got the principle down. Textbook.Technical/logical controls are implemented through technology. DPhysical✖ FLAGGED FOR REVIEWReset and lock it in with this:Technical/logical controls are implemented through technology. 16/100 Security Principles A security awareness training requirement written into company policy is which type of control? ACryptographic✖ ACCESS DENIEDPatch your thinking with this:Administrative controls are the policies, procedures, and training that direct behavior. BAdministrative✔ POLICY ENFORCEDLocked in — that’s the CC mindset.Administrative controls are the policies, procedures, and training that direct behavior. CTechnical✖ ACCESS DENIEDPatch your thinking with this:Administrative controls are the policies, procedures, and training that direct behavior. DPhysical✖ ACCESS DENIEDPatch your thinking with this:Administrative controls are the policies, procedures, and training that direct behavior. 17/100 Security Principles Layering multiple security controls so that one failure doesn’t expose everything is called: ADefense in depth✔ INTEGRITY CONFIRMEDVerified. Oluma loves to see it.Defense in depth uses multiple overlapping layers of controls. BLeast privilege✖ THREAT DETECTEDNo stress — here’s the fix:Defense in depth uses multiple overlapping layers of controls. CSingle sign-on✖ THREAT DETECTEDNo stress — here’s the fix:Defense in depth uses multiple overlapping layers of controls. DNon-repudiation✖ THREAT DETECTEDNo stress — here’s the fix:Defense in depth uses multiple overlapping layers of controls. 18/100 Security Principles Giving a user only the access they need to do their job — and no more — is the principle of: ADefense in depth✖ ALERT RAISEDEvery miss is a lesson. Takeaway:Least privilege limits access to the minimum necessary for the role or task. BSeparation of duties✖ ALERT RAISEDEvery miss is a lesson. Takeaway:Least privilege limits access to the minimum necessary for the role or task. CNeed to know✖ ALERT RAISEDEvery miss is a lesson. Takeaway:Least privilege limits access to the minimum necessary for the role or task. DLeast privilege✔ SECUREDNicely done — that’s a keeper.Least privilege limits access to the minimum necessary for the role or task. 19/100 Security Principles As an ISC2 member, the Code of Ethics primarily obligates you to: AProfit personally from insider knowledge✖ CHECK FAILEDReset and lock it in with this:The ISC2 Code of Ethics requires acting honestly and honorably and protecting society, the common good, and the profession. BHide mistakes from your employer✖ CHECK FAILEDReset and lock it in with this:The ISC2 Code of Ethics requires acting honestly and honorably and protecting society, the common good, and the profession. CAct honorably and protect society, the common good, and the profession✔ VERIFIEDThat’s foundation-solid — clean and correct.The ISC2 Code of Ethics requires acting honestly and honorably and protecting society, the common good, and the profession. DIgnore violations to avoid conflict✖ CHECK FAILEDReset and lock it in with this:The ISC2 Code of Ethics requires acting honestly and honorably and protecting society, the common good, and the profession. 20/100 Security Principles A step-by-step set of instructions for resetting a password is best classified as a: AGuideline✖ FLAGGED FOR REVIEWPatch your thinking with this:A procedure gives detailed steps; a policy states intent, a standard sets mandatory rules, and a guideline recommends. BProcedure✔ DEFENSE HELDSharp. You’re thinking like a defender.A procedure gives detailed steps; a policy states intent, a standard sets mandatory rules, and a guideline recommends. CPolicy✖ FLAGGED FOR REVIEWPatch your thinking with this:A procedure gives detailed steps; a policy states intent, a standard sets mandatory rules, and a guideline recommends. DStandard✖ FLAGGED FOR REVIEWPatch your thinking with this:A procedure gives detailed steps; a policy states intent, a standard sets mandatory rules, and a guideline recommends. CHECKPOINT — 20 DOWN, STAY SHARP 21/100 Security Principles A mandatory rule that all company passwords must be at least 12 characters is a: AStandard✔ ACCESS GRANTEDYou’ve got the principle down. Textbook.A standard is a mandatory, specific requirement that supports a policy. BGuideline✖ ACCESS DENIEDNo stress — here’s the fix:A standard is a mandatory, specific requirement that supports a policy. CProcedure✖ ACCESS DENIEDNo stress — here’s the fix:A standard is a mandatory, specific requirement that supports a policy. DLaw✖ ACCESS DENIEDNo stress — here’s the fix:A standard is a mandatory, specific requirement that supports a policy. 22/100 Security Principles A recommended but optional suggestion to use a password manager is a: AStandard✖ THREAT DETECTEDEvery miss is a lesson. Takeaway:A guideline is a recommendation, not a mandatory rule. BPolicy✖ THREAT DETECTEDEvery miss is a lesson. Takeaway:A guideline is a recommendation, not a mandatory rule. CRegulation✖ THREAT DETECTEDEvery miss is a lesson. Takeaway:A guideline is a recommendation, not a mandatory rule. DGuideline✔ THREAT NEUTRALIZEDLocked in — that’s the CC mindset.A guideline is a recommendation, not a mandatory rule. 23/100 Security Principles Requiring both a password and a one-time code from a phone app to log in is an example of: ALeast privilege✖ ALERT RAISEDReset and lock it in with this:MFA combines two or more different types of authentication factors. BEncryption✖ ALERT RAISEDReset and lock it in with this:MFA combines two or more different types of authentication factors. CMulti-factor authentication✔ IDENTITY VERIFIEDVerified. Oluma loves to see it.MFA combines two or more different types of authentication factors. DSingle sign-on✖ ALERT RAISEDReset and lock it in with this:MFA combines two or more different types of authentication factors. 24/100 Security Principles To verify a downloaded file wasn’t altered, you compare its hash to the original’s. Hashing primarily supports: ARedundancy✖ CHECK FAILEDPatch your thinking with this:Hashing detects any change to data, which supports integrity. BIntegrity✔ CONTROL VALIDATEDNicely done — that’s a keeper.Hashing detects any change to data, which supports integrity. CAvailability✖ CHECK FAILEDPatch your thinking with this:Hashing detects any change to data, which supports integrity. DConfidentiality✖ CHECK FAILEDPatch your thinking with this:Hashing detects any change to data, which supports integrity. 25/100 Security Principles A person’s name combined with their Social Security number is an example of: APersonally identifiable information (PII)✔ RISK MITIGATEDThat’s foundation-solid — clean and correct.PII is information that can identify a specific individual. BPublic data✖ FLAGGED FOR REVIEWNo stress — here’s the fix:PII is information that can identify a specific individual. CA security control✖ FLAGGED FOR REVIEWNo stress — here’s the fix:PII is information that can identify a specific individual. DA hash value✖ FLAGGED FOR REVIEWNo stress — here’s the fix:PII is information that can identify a specific individual. 26/100 Security Principles Regularly patching systems and monitoring for threats — doing what a reasonable organization would — demonstrates: ARisk acceptance✖ ACCESS DENIEDEvery miss is a lesson. Takeaway:Due care is taking reasonable steps to protect assets; due diligence is the ongoing effort to ensure they work. BNon-repudiation✖ ACCESS DENIEDEvery miss is a lesson. Takeaway:Due care is taking reasonable steps to protect assets; due diligence is the ongoing effort to ensure they work. CSingle sign-on✖ ACCESS DENIEDEvery miss is a lesson. Takeaway:Due care is taking reasonable steps to protect assets; due diligence is the ongoing effort to ensure they work. DDue care✔ POLICY ENFORCEDSharp. You’re thinking like a defender.Due care is taking reasonable steps to protect assets; due diligence is the ongoing effort to ensure they work. 27/100 BC / DR / IR A plan that keeps critical business functions running during and after a disruption is a: AIncident Response Plan✖ THREAT DETECTEDReset and lock it in with this:A BCP keeps essential business operations running through a disruption. BAcceptable Use Policy✖ THREAT DETECTEDReset and lock it in with this:A BCP keeps essential business operations running through a disruption. CBusiness Continuity Plan (BCP)✔ INTEGRITY CONFIRMEDYou’ve got the principle down. Textbook.A BCP keeps essential business operations running through a disruption. DDisaster Recovery Plan✖ THREAT DETECTEDReset and lock it in with this:A BCP keeps essential business operations running through a disruption. 28/100 BC / DR / IR A plan focused specifically on restoring IT systems and data after a disaster is a: ARisk register✖ ALERT RAISEDPatch your thinking with this:A DRP focuses on recovering IT systems and data after a disaster. BDisaster Recovery Plan (DRP)✔ SECUREDLocked in — that’s the CC mindset.A DRP focuses on recovering IT systems and data after a disaster. CBusiness Continuity Plan✖ ALERT RAISEDPatch your thinking with this:A DRP focuses on recovering IT systems and data after a disaster. DSecurity policy✖ ALERT RAISEDPatch your thinking with this:A DRP focuses on recovering IT systems and data after a disaster. 29/100 BC / DR / IR In incident response, isolating an infected computer from the network to stop the spread is part of which phase? AContainment✔ VERIFIEDVerified. Oluma loves to see it.Containment limits the damage and stops an incident from spreading further. BPreparation✖ CHECK FAILEDNo stress — here’s the fix:Containment limits the damage and stops an incident from spreading further. CRecovery✖ CHECK FAILEDNo stress — here’s the fix:Containment limits the damage and stops an incident from spreading further. DLessons learned✖ CHECK FAILEDNo stress — here’s the fix:Containment limits the damage and stops an incident from spreading further. 30/100 BC / DR / IR A security incident is best described as: AAny routine log entry✖ FLAGGED FOR REVIEWEvery miss is a lesson. Takeaway:An incident actually or potentially harms security; not every event is an incident. BA scheduled nightly backup✖ FLAGGED FOR REVIEWEvery miss is a lesson. Takeaway:An incident actually or potentially harms security; not every event is an incident. CA normal software update✖ FLAGGED FOR REVIEWEvery miss is a lesson. Takeaway:An incident actually or potentially harms security; not every event is an incident. DAn event that actually or potentially harms the security of information or systems✔ DEFENSE HELDNicely done — that’s a keeper.An incident actually or potentially harms security; not every event is an incident. CHECKPOINT — 30 DOWN, STAY SHARP 31/100 BC / DR / IR The maximum acceptable time a system can be down before it seriously hurts the business is the: AMean time between failures✖ ACCESS DENIEDReset and lock it in with this:RTO is the target time to restore a system; RPO is the acceptable amount of data loss. BAnnual loss expectancy✖ ACCESS DENIEDReset and lock it in with this:RTO is the target time to restore a system; RPO is the acceptable amount of data loss. CRecovery Time Objective (RTO)✔ ACCESS GRANTEDThat’s foundation-solid — clean and correct.RTO is the target time to restore a system; RPO is the acceptable amount of data loss. DRecovery Point Objective✖ ACCESS DENIEDReset and lock it in with this:RTO is the target time to restore a system; RPO is the acceptable amount of data loss. 32/100 BC / DR / IR The maximum amount of data, measured in time, that a business can afford to lose sets the: ARisk appetite✖ THREAT DETECTEDPatch your thinking with this:RPO is the acceptable data-loss window, which drives how often backups must run. BRecovery Point Objective (RPO)✔ THREAT NEUTRALIZEDSharp. You’re thinking like a defender.RPO is the acceptable data-loss window, which drives how often backups must run. CRecovery Time Objective✖ THREAT DETECTEDPatch your thinking with this:RPO is the acceptable data-loss window, which drives how often backups must run. DService level agreement✖ THREAT DETECTEDPatch your thinking with this:RPO is the acceptable data-loss window, which drives how often backups must run. 33/100 BC / DR / IR The main reason to keep regular, tested backups of important data is to support: ARecovery and availability after data loss✔ IDENTITY VERIFIEDYou’ve got the principle down. Textbook.Backups enable recovery and availability after loss, corruption, or ransomware. BFaster internet speeds✖ ALERT RAISEDNo stress — here’s the fix:Backups enable recovery and availability after loss, corruption, or ransomware. CStronger passwords✖ ALERT RAISEDNo stress — here’s the fix:Backups enable recovery and availability after loss, corruption, or ransomware. DLower electricity use✖ ALERT RAISEDNo stress — here’s the fix:Backups enable recovery and availability after loss, corruption, or ransomware. 34/100 BC / DR / IR Having a second power supply so a server keeps running if one fails is an example of: ALeast privilege✖ CHECK FAILEDEvery miss is a lesson. Takeaway:Redundancy provides backup components to maintain availability if one fails. BEncryption✖ CHECK FAILEDEvery miss is a lesson. Takeaway:Redundancy provides backup components to maintain availability if one fails. CNon-repudiation✖ CHECK FAILEDEvery miss is a lesson. Takeaway:Redundancy provides backup components to maintain availability if one fails. DRedundancy (high availability)✔ CONTROL VALIDATEDLocked in — that’s the CC mindset.Redundancy provides backup components to maintain availability if one fails. 35/100 BC / DR / IR Writing the incident response plan, training the team, and setting up tools before anything happens is which phase? AEradication✖ FLAGGED FOR REVIEWReset and lock it in with this:Preparation readies the people, plans, and tools before an incident ever occurs. BRecovery✖ FLAGGED FOR REVIEWReset and lock it in with this:Preparation readies the people, plans, and tools before an incident ever occurs. CPreparation✔ RISK MITIGATEDVerified. Oluma loves to see it.Preparation readies the people, plans, and tools before an incident ever occurs. DContainment✖ FLAGGED FOR REVIEWReset and lock it in with this:Preparation readies the people, plans, and tools before an incident ever occurs. 36/100 BC / DR / IR After an incident is resolved, the team meets to review what happened and improve. This is the: APreparation phase✖ ACCESS DENIEDPatch your thinking with this:The lessons-learned phase reviews the incident to strengthen future response. BLessons learned (post-incident) phase✔ POLICY ENFORCEDNicely done — that’s a keeper.The lessons-learned phase reviews the incident to strengthen future response. CDetection phase✖ ACCESS DENIEDPatch your thinking with this:The lessons-learned phase reviews the incident to strengthen future response. DContainment phase✖ ACCESS DENIEDPatch your thinking with this:The lessons-learned phase reviews the incident to strengthen future response. 37/100 Access Controls Typing your username to claim an identity, before proving it, is: AIdentification✔ INTEGRITY CONFIRMEDThat’s foundation-solid — clean and correct.Identification is claiming an identity; authentication then proves it. BAuthentication✖ THREAT DETECTEDNo stress — here’s the fix:Identification is claiming an identity; authentication then proves it. CAuthorization✖ THREAT DETECTEDNo stress — here’s the fix:Identification is claiming an identity; authentication then proves it. DAccounting✖ THREAT DETECTEDNo stress — here’s the fix:Identification is claiming an identity; authentication then proves it. 38/100 Access Controls System logs that tie a specific action back to a specific user provide: AAvailability✖ ALERT RAISEDEvery miss is a lesson. Takeaway:Accountability links actions to identities, usually through logging. BConfidentiality✖ ALERT RAISEDEvery miss is a lesson. Takeaway:Accountability links actions to identities, usually through logging. CRedundancy✖ ALERT RAISEDEvery miss is a lesson. Takeaway:Accountability links actions to identities, usually through logging. DAccountability✔ SECUREDSharp. You’re thinking like a defender.Accountability links actions to identities, usually through logging. 39/100 Access Controls A password or PIN is which type of authentication factor? ASomething you are✖ CHECK FAILEDReset and lock it in with this:‘Something you know’ is knowledge-based, like a password or PIN. BSomewhere you are✖ CHECK FAILEDReset and lock it in with this:‘Something you know’ is knowledge-based, like a password or PIN. CSomething you know✔ VERIFIEDYou’ve got the principle down. Textbook.‘Something you know’ is knowledge-based, like a password or PIN. DSomething you have✖ CHECK FAILEDReset and lock it in with this:‘Something you know’ is knowledge-based, like a password or PIN. 40/100 Access Controls A smart card or hardware token is which authentication factor? ASomething you do✖ FLAGGED FOR REVIEWPatch your thinking with this:‘Something you have’ is possession-based, like a token, smart card, or phone. BSomething you have✔ DEFENSE HELDLocked in — that’s the CC mindset.‘Something you have’ is possession-based, like a token, smart card, or phone. CSomething you know✖ FLAGGED FOR REVIEWPatch your thinking with this:‘Something you have’ is possession-based, like a token, smart card, or phone. DSomething you are✖ FLAGGED FOR REVIEWPatch your thinking with this:‘Something you have’ is possession-based, like a token, smart card, or phone. CHECKPOINT — 40 DOWN, STAY SHARP 41/100 Access Controls A fingerprint or facial scan is which authentication factor? ASomething you are✔ ACCESS GRANTEDVerified. Oluma loves to see it.‘Something you are’ is biometric — fingerprint, face, or iris, for example. BSomething you know✖ ACCESS DENIEDNo stress — here’s the fix:‘Something you are’ is biometric — fingerprint, face, or iris, for example. CSomething you have✖ ACCESS DENIEDNo stress — here’s the fix:‘Something you are’ is biometric — fingerprint, face, or iris, for example. DSomewhere you are✖ ACCESS DENIEDNo stress — here’s the fix:‘Something you are’ is biometric — fingerprint, face, or iris, for example. 42/100 Access Controls Which combination is true multi-factor authentication? AA password and a PIN✖ THREAT DETECTEDEvery miss is a lesson. Takeaway:True MFA combines factors of different types (know + are), not two of the same type. BTwo different passwords✖ THREAT DETECTEDEvery miss is a lesson. Takeaway:True MFA combines factors of different types (know + are), not two of the same type. CA username and a password✖ THREAT DETECTEDEvery miss is a lesson. Takeaway:True MFA combines factors of different types (know + are), not two of the same type. DA password and a fingerprint✔ THREAT NEUTRALIZEDNicely done — that’s a keeper.True MFA combines factors of different types (know + are), not two of the same type. 43/100 Access Controls An access model where the data owner decides who may access their files is: ARole-Based Access Control✖ ALERT RAISEDReset and lock it in with this:In DAC, the owner has discretion to grant or deny access to their resources. BRule-based access✖ ALERT RAISEDReset and lock it in with this:In DAC, the owner has discretion to grant or deny access to their resources. CDiscretionary Access Control (DAC)✔ IDENTITY VERIFIEDThat’s foundation-solid — clean and correct.In DAC, the owner has discretion to grant or deny access to their resources. DMandatory Access Control✖ ALERT RAISEDReset and lock it in with this:In DAC, the owner has discretion to grant or deny access to their resources. 44/100 Access Controls An access model where the system enforces access using classification labels and clearances is: AAttribute-based access✖ CHECK FAILEDPatch your thinking with this:MAC enforces access based on labels and clearances set by the system, not by owners. BMandatory Access Control (MAC)✔ CONTROL VALIDATEDSharp. You’re thinking like a defender.MAC enforces access based on labels and clearances set by the system, not by owners. CDiscretionary Access Control✖ CHECK FAILEDPatch your thinking with this:MAC enforces access based on labels and clearances set by the system, not by owners. DRole-Based Access Control✖ CHECK FAILEDPatch your thinking with this:MAC enforces access based on labels and clearances set by the system, not by owners. 45/100 Access Controls Assigning permissions to job roles, so users gain access based on their role, is: ARole-Based Access Control (RBAC)✔ RISK MITIGATEDYou’ve got the principle down. Textbook.RBAC grants access based on a user’s role within the organization. BDiscretionary Access Control✖ FLAGGED FOR REVIEWNo stress — here’s the fix:RBAC grants access based on a user’s role within the organization. CMandatory Access Control✖ FLAGGED FOR REVIEWNo stress — here’s the fix:RBAC grants access based on a user’s role within the organization. DRule-based access✖ FLAGGED FOR REVIEWNo stress — here’s the fix:RBAC grants access based on a user’s role within the organization. 46/100 Access Controls Even with a Secret clearance, an analyst may only see the specific documents required for their task. This enforces: ADefense in depth✖ ACCESS DENIEDEvery miss is a lesson. Takeaway:Need-to-know limits access to only the information required for a task, even among the cleared. BRedundancy✖ ACCESS DENIEDEvery miss is a lesson. Takeaway:Need-to-know limits access to only the information required for a task, even among the cleared. CNon-repudiation✖ ACCESS DENIEDEvery miss is a lesson. Takeaway:Need-to-know limits access to only the information required for a task, even among the cleared. DNeed to know✔ POLICY ENFORCEDLocked in — that’s the CC mindset.Need-to-know limits access to only the information required for a task, even among the cleared. 47/100 Access Controls Requiring two different people to approve a large payment reduces fraud through: ASingle sign-on✖ THREAT DETECTEDReset and lock it in with this:Separation of duties splits a sensitive task so no single person controls it entirely. BRedundancy✖ THREAT DETECTEDReset and lock it in with this:Separation of duties splits a sensitive task so no single person controls it entirely. CSeparation of duties✔ INTEGRITY CONFIRMEDVerified. Oluma loves to see it.Separation of duties splits a sensitive task so no single person controls it entirely. DLeast privilege✖ THREAT DETECTEDReset and lock it in with this:Separation of duties splits a sensitive task so no single person controls it entirely. 48/100 Access Controls Creating a new employee’s accounts and granting appropriate access on their first day is: AAuditing✖ ALERT RAISEDPatch your thinking with this:Provisioning sets up identities and access when a user joins or changes roles. BProvisioning✔ SECUREDNicely done — that’s a keeper.Provisioning sets up identities and access when a user joins or changes roles. CDeprovisioning✖ ALERT RAISEDPatch your thinking with this:Provisioning sets up identities and access when a user joins or changes roles. DAuthentication✖ ALERT RAISEDPatch your thinking with this:Provisioning sets up identities and access when a user joins or changes roles. 49/100 Access Controls Disabling accounts and removing access the moment an employee is terminated is: ADeprovisioning✔ VERIFIEDThat’s foundation-solid — clean and correct.Deprovisioning promptly removes access when it’s no longer needed, closing a common security gap. BProvisioning✖ CHECK FAILEDNo stress — here’s the fix:Deprovisioning promptly removes access when it’s no longer needed, closing a common security gap. CAuthorization✖ CHECK FAILEDNo stress — here’s the fix:Deprovisioning promptly removes access when it’s no longer needed, closing a common security gap. DEncryption✖ CHECK FAILEDNo stress — here’s the fix:Deprovisioning promptly removes access when it’s no longer needed, closing a common security gap. 50/100 Access Controls An administrator account with broad system rights should be: AShared freely among the team✖ FLAGGED FOR REVIEWEvery miss is a lesson. Takeaway:Privileged accounts are high-value targets and must be limited, monitored, and used sparingly. BLeft logged in at all times✖ FLAGGED FOR REVIEWEvery miss is a lesson. Takeaway:Privileged accounts are high-value targets and must be limited, monitored, and used sparingly. CGiven to every user by default✖ FLAGGED FOR REVIEWEvery miss is a lesson. Takeaway:Privileged accounts are high-value targets and must be limited, monitored, and used sparingly. DTightly controlled, monitored, and used only when needed✔ DEFENSE HELDSharp. You’re thinking like a defender.Privileged accounts are high-value targets and must be limited, monitored, and used sparingly. CHECKPOINT — 50 DOWN, STAY SHARP 51/100 Access Controls A small room with two interlocking doors that lets only one person through at a time is a: ABollard✖ ACCESS DENIEDReset and lock it in with this:A mantrap/access control vestibule prevents tailgating by allowing one person through at a time. BFirewall✖ ACCESS DENIEDReset and lock it in with this:A mantrap/access control vestibule prevents tailgating by allowing one person through at a time. CMantrap (access control vestibule)✔ ACCESS GRANTEDYou’ve got the principle down. Textbook.A mantrap/access control vestibule prevents tailgating by allowing one person through at a time. DTurnstile✖ ACCESS DENIEDReset and lock it in with this:A mantrap/access control vestibule prevents tailgating by allowing one person through at a time. 52/100 Access Controls An employee taps an ID badge to open a secure door. This is a: AAdministrative control✖ THREAT DETECTEDPatch your thinking with this:Badge readers on doors are physical access controls. BPhysical access control✔ THREAT NEUTRALIZEDLocked in — that’s the CC mindset.Badge readers on doors are physical access controls. CLogical access control✖ THREAT DETECTEDPatch your thinking with this:Badge readers on doors are physical access controls. DEncryption control✖ THREAT DETECTEDPatch your thinking with this:Badge readers on doors are physical access controls. 53/100 Access Controls An unauthorized person slips through a secure door right behind an employee. This is: ATailgating (piggybacking)✔ IDENTITY VERIFIEDVerified. Oluma loves to see it.Tailgating is following an authorized person through a controlled entry without authenticating. BPhishing✖ ALERT RAISEDNo stress — here’s the fix:Tailgating is following an authorized person through a controlled entry without authenticating. CSpoofing✖ ALERT RAISEDNo stress — here’s the fix:Tailgating is following an authorized person through a controlled entry without authenticating. DHashing✖ ALERT RAISEDNo stress — here’s the fix:Tailgating is following an authorized person through a controlled entry without authenticating. 54/100 Access Controls The best default when assigning a new user’s permissions is to start with: AFull administrator access✖ CHECK FAILEDEvery miss is a lesson. Takeaway:Least privilege starts minimal and grants more access only as it’s justified. BAll access, then remove some later✖ CHECK FAILEDEvery miss is a lesson. Takeaway:Least privilege starts minimal and grants more access only as it’s justified. CAccess to everything by default✖ CHECK FAILEDEvery miss is a lesson. Takeaway:Least privilege starts minimal and grants more access only as it’s justified. DThe minimum access needed, adding more only as required✔ CONTROL VALIDATEDNicely done — that’s a keeper.Least privilege starts minimal and grants more access only as it’s justified. 55/100 Access Controls A fingerprint reader occasionally admits the wrong person. This error is a: ATrue positive✖ FLAGGED FOR REVIEWReset and lock it in with this:False acceptance wrongly admits an unauthorized user; false rejection wrongly denies a valid one. BCrossover error rate✖ FLAGGED FOR REVIEWReset and lock it in with this:False acceptance wrongly admits an unauthorized user; false rejection wrongly denies a valid one. CFalse acceptance✔ RISK MITIGATEDThat’s foundation-solid — clean and correct.False acceptance wrongly admits an unauthorized user; false rejection wrongly denies a valid one. DFalse rejection✖ FLAGGED FOR REVIEWReset and lock it in with this:False acceptance wrongly admits an unauthorized user; false rejection wrongly denies a valid one. 56/100 Access Controls Logging in once to reach many applications without re-entering credentials is: ALeast privilege✖ ACCESS DENIEDPatch your thinking with this:SSO lets a user authenticate once for access to multiple systems. BSingle sign-on (SSO)✔ POLICY ENFORCEDSharp. You’re thinking like a defender.SSO lets a user authenticate once for access to multiple systems. CMulti-factor authentication✖ ACCESS DENIEDPatch your thinking with this:SSO lets a user authenticate once for access to multiple systems. DSeparation of duties✖ ACCESS DENIEDPatch your thinking with this:SSO lets a user authenticate once for access to multiple systems. 57/100 Access Controls Periodically checking that users still need the access they have, and removing stale rights, is an access: AReview (recertification)✔ INTEGRITY CONFIRMEDYou’ve got the principle down. Textbook.Access reviews/recertification catch excessive or outdated permissions over time. BProvisioning✖ THREAT DETECTEDNo stress — here’s the fix:Access reviews/recertification catch excessive or outdated permissions over time. CEncryption✖ THREAT DETECTEDNo stress — here’s the fix:Access reviews/recertification catch excessive or outdated permissions over time. DBackup✖ THREAT DETECTEDNo stress — here’s the fix:Access reviews/recertification catch excessive or outdated permissions over time. 58/100 Access Controls Security cameras recording a data center entrance primarily serve as a: ACorrective control✖ ALERT RAISEDEvery miss is a lesson. Takeaway:CCTV records activity for later review and deters wrongdoers — detective and deterrent. BEncryption control✖ ALERT RAISEDEvery miss is a lesson. Takeaway:CCTV records activity for later review and deters wrongdoers — detective and deterrent. CAuthentication factor✖ ALERT RAISEDEvery miss is a lesson. Takeaway:CCTV records activity for later review and deters wrongdoers — detective and deterrent. DDetective and deterrent control✔ SECUREDLocked in — that’s the CC mindset.CCTV records activity for later review and deters wrongdoers — detective and deterrent. 59/100 Network Security A device or software that filters network traffic based on rules, allowing or blocking it, is a: ARouter✖ CHECK FAILEDReset and lock it in with this:A firewall enforces rules on what traffic may pass between networks. BModem✖ CHECK FAILEDReset and lock it in with this:A firewall enforces rules on what traffic may pass between networks. CFirewall✔ VERIFIEDVerified. Oluma loves to see it.A firewall enforces rules on what traffic may pass between networks. DSwitch✖ CHECK FAILEDReset and lock it in with this:A firewall enforces rules on what traffic may pass between networks. 60/100 Network Security A system that monitors network traffic and alerts on suspicious activity but does not block it is an: AVPN✖ FLAGGED FOR REVIEWPatch your thinking with this:An IDS detects and alerts; an IPS can also actively block. BIntrusion Detection System (IDS)✔ DEFENSE HELDNicely done — that’s a keeper.An IDS detects and alerts; an IPS can also actively block. CIntrusion Prevention System✖ FLAGGED FOR REVIEWPatch your thinking with this:An IDS detects and alerts; an IPS can also actively block. DFirewall✖ FLAGGED FOR REVIEWPatch your thinking with this:An IDS detects and alerts; an IPS can also actively block. CHECKPOINT — 60 DOWN, STAY SHARP 61/100 Network Security A system that detects malicious traffic and actively blocks it in real time is an: AIntrusion Prevention System (IPS)✔ ACCESS GRANTEDThat’s foundation-solid — clean and correct.An IPS both detects and prevents by blocking malicious traffic inline. BIntrusion Detection System✖ ACCESS DENIEDNo stress — here’s the fix:An IPS both detects and prevents by blocking malicious traffic inline. CDNS server✖ ACCESS DENIEDNo stress — here’s the fix:An IPS both detects and prevents by blocking malicious traffic inline. DProxy server✖ ACCESS DENIEDNo stress — here’s the fix:An IPS both detects and prevents by blocking malicious traffic inline. 62/100 Network Security Remote employees use an encrypted tunnel to connect securely to the office network. This is a: AVirtual LAN✖ THREAT DETECTEDEvery miss is a lesson. Takeaway:A VPN creates an encrypted tunnel over an untrusted network like the internet. BDMZ✖ THREAT DETECTEDEvery miss is a lesson. Takeaway:A VPN creates an encrypted tunnel over an untrusted network like the internet. CDNS server✖ THREAT DETECTEDEvery miss is a lesson. Takeaway:A VPN creates an encrypted tunnel over an untrusted network like the internet. DVirtual Private Network (VPN)✔ THREAT NEUTRALIZEDSharp. You’re thinking like a defender.A VPN creates an encrypted tunnel over an untrusted network like the internet. 63/100 Network Security Splitting a network into separate zones so a breach in one can’t easily reach the others is: ASingle sign-on✖ ALERT RAISEDReset and lock it in with this:Segmentation limits how far an attacker can move within a network. BHashing✖ ALERT RAISEDReset and lock it in with this:Segmentation limits how far an attacker can move within a network. CNetwork segmentation✔ IDENTITY VERIFIEDYou’ve got the principle down. Textbook.Segmentation limits how far an attacker can move within a network. DLoad balancing✖ ALERT RAISEDReset and lock it in with this:Segmentation limits how far an attacker can move within a network. 64/100 Network Security A network zone that hosts public-facing servers, separated from the internal network, is a: AIntranet✖ CHECK FAILEDPatch your thinking with this:A DMZ/screened subnet isolates internet-facing services from the internal network. BDMZ (screened subnet)✔ CONTROL VALIDATEDLocked in — that’s the CC mindset.A DMZ/screened subnet isolates internet-facing services from the internal network. CVPN✖ CHECK FAILEDPatch your thinking with this:A DMZ/screened subnet isolates internet-facing services from the internal network. DVLAN✖ CHECK FAILEDPatch your thinking with this:A DMZ/screened subnet isolates internet-facing services from the internal network. 65/100 Network Security Secure web traffic (HTTPS) uses which well-known port? A443✔ RISK MITIGATEDVerified. Oluma loves to see it.HTTPS uses port 443; unencrypted HTTP uses port 80. B80✖ FLAGGED FOR REVIEWNo stress — here’s the fix:HTTPS uses port 443; unencrypted HTTP uses port 80. C21✖ FLAGGED FOR REVIEWNo stress — here’s the fix:HTTPS uses port 443; unencrypted HTTP uses port 80. D25✖ FLAGGED FOR REVIEWNo stress — here’s the fix:HTTPS uses port 443; unencrypted HTTP uses port 80. 66/100 Network Security Unencrypted web traffic (HTTP) uses which well-known port? A443✖ ACCESS DENIEDEvery miss is a lesson. Takeaway:HTTP uses port 80; the secure version, HTTPS, uses 443. B22✖ ACCESS DENIEDEvery miss is a lesson. Takeaway:HTTP uses port 80; the secure version, HTTPS, uses 443. C53✖ ACCESS DENIEDEvery miss is a lesson. Takeaway:HTTP uses port 80; the secure version, HTTPS, uses 443. D80✔ POLICY ENFORCEDNicely done — that’s a keeper.HTTP uses port 80; the secure version, HTTPS, uses 443. 67/100 Network Security An administrator needs to securely manage a remote server over an encrypted command line. Which protocol? AFTP✖ THREAT DETECTEDReset and lock it in with this:SSH provides encrypted remote administration; Telnet sends everything in cleartext. BHTTP✖ THREAT DETECTEDReset and lock it in with this:SSH provides encrypted remote administration; Telnet sends everything in cleartext. CSSH✔ INTEGRITY CONFIRMEDThat’s foundation-solid — clean and correct.SSH provides encrypted remote administration; Telnet sends everything in cleartext. DTelnet✖ THREAT DETECTEDReset and lock it in with this:SSH provides encrypted remote administration; Telnet sends everything in cleartext. 68/100 Network Security Which service translates a domain name like example.com into an IP address? ANAT✖ ALERT RAISEDPatch your thinking with this:DNS resolves human-friendly names to IP addresses. BDNS✔ SECUREDSharp. You’re thinking like a defender.DNS resolves human-friendly names to IP addresses. CDHCP✖ ALERT RAISEDPatch your thinking with this:DNS resolves human-friendly names to IP addresses. DVPN✖ ALERT RAISEDPatch your thinking with this:DNS resolves human-friendly names to IP addresses. 69/100 Network Security Which service automatically assigns IP addresses to devices joining a network? ADHCP✔ VERIFIEDYou’ve got the principle down. Textbook.DHCP automatically hands out IP configuration to devices. BDNS✖ CHECK FAILEDNo stress — here’s the fix:DHCP automatically hands out IP configuration to devices. CTLS✖ CHECK FAILEDNo stress — here’s the fix:DHCP automatically hands out IP configuration to devices. DARP✖ CHECK FAILEDNo stress — here’s the fix:DHCP automatically hands out IP configuration to devices. 70/100 Network Security An attacker floods a website with traffic until it can’t serve real users. This attack targets: AConfidentiality✖ FLAGGED FOR REVIEWEvery miss is a lesson. Takeaway:A DoS/DDoS attack overwhelms a resource, harming its availability. BIntegrity✖ FLAGGED FOR REVIEWEvery miss is a lesson. Takeaway:A DoS/DDoS attack overwhelms a resource, harming its availability. CNon-repudiation✖ FLAGGED FOR REVIEWEvery miss is a lesson. Takeaway:A DoS/DDoS attack overwhelms a resource, harming its availability. DAvailability (a denial-of-service attack)✔ DEFENSE HELDLocked in — that’s the CC mindset.A DoS/DDoS attack overwhelms a resource, harming its availability. CHECKPOINT — 70 DOWN, STAY SHARP 71/100 Network Security An attacker secretly sits between two parties and intercepts their communication. This is a: ABrute-force attack✖ ACCESS DENIEDReset and lock it in with this:A man-in-the-middle/on-path attacker intercepts or alters traffic between two parties. BSQL injection✖ ACCESS DENIEDReset and lock it in with this:A man-in-the-middle/on-path attacker intercepts or alters traffic between two parties. CMan-in-the-middle (on-path) attack✔ ACCESS GRANTEDVerified. Oluma loves to see it.A man-in-the-middle/on-path attacker intercepts or alters traffic between two parties. DDenial-of-service attack✖ ACCESS DENIEDReset and lock it in with this:A man-in-the-middle/on-path attacker intercepts or alters traffic between two parties. 72/100 Network Security Malicious code that attaches to a file and needs a user to run it in order to spread is a: AFirewall✖ THREAT DETECTEDPatch your thinking with this:A virus needs a host file and user action to execute; a worm spreads on its own. BVirus✔ THREAT NEUTRALIZEDNicely done — that’s a keeper.A virus needs a host file and user action to execute; a worm spreads on its own. CWorm✖ THREAT DETECTEDPatch your thinking with this:A virus needs a host file and user action to execute; a worm spreads on its own. DTrojan✖ THREAT DETECTEDPatch your thinking with this:A virus needs a host file and user action to execute; a worm spreads on its own. 73/100 Network Security Self-replicating malware that spreads across a network on its own, without user action, is a: AWorm✔ IDENTITY VERIFIEDThat’s foundation-solid — clean and correct.A worm self-propagates across networks without needing a host file or user action. BVirus✖ ALERT RAISEDNo stress — here’s the fix:A worm self-propagates across networks without needing a host file or user action. CTrojan✖ ALERT RAISEDNo stress — here’s the fix:A worm self-propagates across networks without needing a host file or user action. DRootkit✖ ALERT RAISEDNo stress — here’s the fix:A worm self-propagates across networks without needing a host file or user action. 74/100 Network Security Malware disguised as a legitimate program to trick a user into installing it is a: AWorm✖ CHECK FAILEDEvery miss is a lesson. Takeaway:A trojan hides malicious functionality inside something that looks legitimate. BFirewall✖ CHECK FAILEDEvery miss is a lesson. Takeaway:A trojan hides malicious functionality inside something that looks legitimate. CSecurity patch✖ CHECK FAILEDEvery miss is a lesson. Takeaway:A trojan hides malicious functionality inside something that looks legitimate. DTrojan✔ CONTROL VALIDATEDSharp. You’re thinking like a defender.A trojan hides malicious functionality inside something that looks legitimate. 75/100 Network Security To secure a home or office Wi-Fi network, you should enable: AWEP, because it is the simplest✖ FLAGGED FOR REVIEWReset and lock it in with this:WPA2/WPA3 provide strong Wi-Fi encryption; WEP is outdated and easily broken. BOnly hiding the SSID✖ FLAGGED FOR REVIEWReset and lock it in with this:WPA2/WPA3 provide strong Wi-Fi encryption; WEP is outdated and easily broken. CWPA2 or WPA3 encryption✔ RISK MITIGATEDYou’ve got the principle down. Textbook.WPA2/WPA3 provide strong Wi-Fi encryption; WEP is outdated and easily broken. DAn open, unencrypted network✖ FLAGGED FOR REVIEWReset and lock it in with this:WPA2/WPA3 provide strong Wi-Fi encryption; WEP is outdated and easily broken. 76/100 Network Security A technique that lets many internal devices share one public IP address is: AIDS✖ ACCESS DENIEDPatch your thinking with this:NAT maps multiple private addresses to public ones, conserving addresses and hiding internal IPs. BNetwork Address Translation (NAT)✔ POLICY ENFORCEDLocked in — that’s the CC mindset.NAT maps multiple private addresses to public ones, conserving addresses and hiding internal IPs. CDNS✖ ACCESS DENIEDPatch your thinking with this:NAT maps multiple private addresses to public ones, conserving addresses and hiding internal IPs. DVPN✖ ACCESS DENIEDPatch your thinking with this:NAT maps multiple private addresses to public ones, conserving addresses and hiding internal IPs. 77/100 Network Security A device that forwards data between different networks, such as your LAN and the internet, is a: ARouter✔ INTEGRITY CONFIRMEDVerified. Oluma loves to see it.A router connects and routes between different networks; a switch connects devices within one. BSwitch✖ THREAT DETECTEDNo stress — here’s the fix:A router connects and routes between different networks; a switch connects devices within one. CHub✖ THREAT DETECTEDNo stress — here’s the fix:A router connects and routes between different networks; a switch connects devices within one. DRepeater✖ THREAT DETECTEDNo stress — here’s the fix:A router connects and routes between different networks; a switch connects devices within one. 78/100 Network Security An attacker probes a server to discover which ports are open and what services are running. This is: AEncrypting✖ ALERT RAISEDEvery miss is a lesson. Takeaway:Port scanning discovers open ports and services as a precursor to an attack. BPatching✖ ALERT RAISEDEvery miss is a lesson. Takeaway:Port scanning discovers open ports and services as a precursor to an attack. CBacking up✖ ALERT RAISEDEvery miss is a lesson. Takeaway:Port scanning discovers open ports and services as a precursor to an attack. DPort scanning✔ SECUREDNicely done — that’s a keeper.Port scanning discovers open ports and services as a precursor to an attack. 79/100 Network Security Which protocol encrypts data in transit for secure websites, email, and more? ATelnet✖ CHECK FAILEDReset and lock it in with this:TLS encrypts data in transit and underpins HTTPS and other secure communications. BPlain SMTP✖ CHECK FAILEDReset and lock it in with this:TLS encrypts data in transit and underpins HTTPS and other secure communications. CTLS✔ VERIFIEDThat’s foundation-solid — clean and correct.TLS encrypts data in transit and underpins HTTPS and other secure communications. DFTP✖ CHECK FAILEDReset and lock it in with this:TLS encrypts data in transit and underpins HTTPS and other secure communications. 80/100 Network Security A model that never automatically trusts a user or device, even inside the network, and verifies every request is: AOpen trust✖ FLAGGED FOR REVIEWPatch your thinking with this:Zero trust assumes no implicit trust and continuously verifies every access request. BZero trust✔ DEFENSE HELDSharp. You’re thinking like a defender.Zero trust assumes no implicit trust and continuously verifies every access request. CDefense in depth✖ FLAGGED FOR REVIEWPatch your thinking with this:Zero trust assumes no implicit trust and continuously verifies every access request. DSingle sign-on✖ FLAGGED FOR REVIEWPatch your thinking with this:Zero trust assumes no implicit trust and continuously verifies every access request. CHECKPOINT — 80 DOWN, STAY SHARP 81/100 Network Security An email pretending to be from your bank asks you to click a link and enter your password. This is: APhishing✔ ACCESS GRANTEDYou’ve got the principle down. Textbook.Phishing uses deceptive messages to trick users into revealing credentials or clicking malicious links. BA firewall alert✖ ACCESS DENIEDNo stress — here’s the fix:Phishing uses deceptive messages to trick users into revealing credentials or clicking malicious links. CA VPN request✖ ACCESS DENIEDNo stress — here’s the fix:Phishing uses deceptive messages to trick users into revealing credentials or clicking malicious links. DA DNS lookup✖ ACCESS DENIEDNo stress — here’s the fix:Phishing uses deceptive messages to trick users into revealing credentials or clicking malicious links. 82/100 Network Security The most secure default rule for a firewall is to: AAllow all traffic except what’s blocked✖ THREAT DETECTEDEvery miss is a lesson. Takeaway:A default-deny (implicit deny) posture blocks everything not explicitly permitted. BAllow everything by default✖ THREAT DETECTEDEvery miss is a lesson. Takeaway:A default-deny (implicit deny) posture blocks everything not explicitly permitted. CBlock only a few known-bad addresses✖ THREAT DETECTEDEvery miss is a lesson. Takeaway:A default-deny (implicit deny) posture blocks everything not explicitly permitted. DDeny all traffic except what is explicitly allowed✔ THREAT NEUTRALIZEDLocked in — that’s the CC mindset.A default-deny (implicit deny) posture blocks everything not explicitly permitted. 83/100 Security Operations Labeling data as Public, Internal, or Confidential so it is handled appropriately is: AData backup✖ ALERT RAISEDReset and lock it in with this:Classification labels data by sensitivity to drive how it is protected and handled. BData mining✖ ALERT RAISEDReset and lock it in with this:Classification labels data by sensitivity to drive how it is protected and handled. CData classification✔ IDENTITY VERIFIEDVerified. Oluma loves to see it.Classification labels data by sensitivity to drive how it is protected and handled. DData encryption✖ ALERT RAISEDReset and lock it in with this:Classification labels data by sensitivity to drive how it is protected and handled. 84/100 Security Operations Encrypting the files stored on a laptop’s hard drive protects data: AIn memory only✖ CHECK FAILEDPatch your thinking with this:Encryption at rest protects stored data; encryption in transit protects data that is moving. BAt rest✔ CONTROL VALIDATEDNicely done — that’s a keeper.Encryption at rest protects stored data; encryption in transit protects data that is moving. CIn transit✖ CHECK FAILEDPatch your thinking with this:Encryption at rest protects stored data; encryption in transit protects data that is moving. DIn use only✖ CHECK FAILEDPatch your thinking with this:Encryption at rest protects stored data; encryption in transit protects data that is moving. 85/100 Security Operations Using HTTPS to protect data as it travels between a browser and a server protects data: AIn transit✔ RISK MITIGATEDThat’s foundation-solid — clean and correct.Encryption in transit protects data while it moves across a network. BAt rest✖ FLAGGED FOR REVIEWNo stress — here’s the fix:Encryption in transit protects data while it moves across a network. CIn storage✖ FLAGGED FOR REVIEWNo stress — here’s the fix:Encryption in transit protects data while it moves across a network. DOn backup tapes✖ FLAGGED FOR REVIEWNo stress — here’s the fix:Encryption in transit protects data while it moves across a network. 86/100 Security Operations Regularly applying vendor updates to fix known vulnerabilities is: AData classification✖ ACCESS DENIEDEvery miss is a lesson. Takeaway:Patch management keeps systems updated to close known security holes. BSocial engineering✖ ACCESS DENIEDEvery miss is a lesson. Takeaway:Patch management keeps systems updated to close known security holes. CLoad balancing✖ ACCESS DENIEDEvery miss is a lesson. Takeaway:Patch management keeps systems updated to close known security holes. DPatch management✔ POLICY ENFORCEDSharp. You’re thinking like a defender.Patch management keeps systems updated to close known security holes. 87/100 Security Operations Removing unnecessary software, closing unused ports, and disabling default accounts on a server is: AProvisioning✖ THREAT DETECTEDReset and lock it in with this:Hardening reduces a system’s attack surface by removing what isn’t needed. BBackup✖ THREAT DETECTEDReset and lock it in with this:Hardening reduces a system’s attack surface by removing what isn’t needed. CSystem hardening✔ INTEGRITY CONFIRMEDYou’ve got the principle down. Textbook.Hardening reduces a system’s attack surface by removing what isn’t needed. DEncryption✖ THREAT DETECTEDReset and lock it in with this:Hardening reduces a system’s attack surface by removing what isn’t needed. 88/100 Security Operations Collecting and reviewing system and security logs to spot suspicious activity supports: ARedundancy✖ ALERT RAISEDPatch your thinking with this:Logging and monitoring provide the visibility needed to detect and investigate incidents. BMonitoring and detection✔ SECUREDLocked in — that’s the CC mindset.Logging and monitoring provide the visibility needed to detect and investigate incidents. CData destruction✖ ALERT RAISEDPatch your thinking with this:Logging and monitoring provide the visibility needed to detect and investigate incidents. DProvisioning✖ ALERT RAISEDPatch your thinking with this:Logging and monitoring provide the visibility needed to detect and investigate incidents. 89/100 Security Operations Teaching employees to recognize phishing and follow good security habits is: ASecurity awareness training✔ VERIFIEDVerified. Oluma loves to see it.Awareness training strengthens the human layer, one of the most common attack targets. BPenetration testing✖ CHECK FAILEDNo stress — here’s the fix:Awareness training strengthens the human layer, one of the most common attack targets. CPatch management✖ CHECK FAILEDNo stress — here’s the fix:Awareness training strengthens the human layer, one of the most common attack targets. DEncryption✖ CHECK FAILEDNo stress — here’s the fix:Awareness training strengthens the human layer, one of the most common attack targets. 90/100 Security Operations A document employees sign describing acceptable use of company systems and the internet is an: AIncident Response Plan✖ FLAGGED FOR REVIEWEvery miss is a lesson. Takeaway:An AUP defines what users may and may not do with company resources. BBusiness Continuity Plan✖ FLAGGED FOR REVIEWEvery miss is a lesson. Takeaway:An AUP defines what users may and may not do with company resources. CService Level Agreement✖ FLAGGED FOR REVIEWEvery miss is a lesson. Takeaway:An AUP defines what users may and may not do with company resources. DAcceptable Use Policy (AUP)✔ DEFENSE HELDNicely done — that’s a keeper.An AUP defines what users may and may not do with company resources. CHECKPOINT — 90 DOWN, STAY SHARP 91/100 Security Operations Reviewing and approving a proposed system change before it’s made, to avoid unintended problems, is: AData classification✖ ACCESS DENIEDReset and lock it in with this:Change management controls how changes are proposed, reviewed, approved, and applied. BProvisioning✖ ACCESS DENIEDReset and lock it in with this:Change management controls how changes are proposed, reviewed, approved, and applied. CChange management✔ ACCESS GRANTEDThat’s foundation-solid — clean and correct.Change management controls how changes are proposed, reviewed, approved, and applied. DIncident response✖ ACCESS DENIEDReset and lock it in with this:Change management controls how changes are proposed, reviewed, approved, and applied. 92/100 Security Operations Before donating old computers, the drives are wiped or destroyed so no data can be recovered. This is: AProvisioning✖ THREAT DETECTEDPatch your thinking with this:Sanitization/secure disposal ensures data cannot be recovered from retired media. BMedia sanitization (secure disposal)✔ THREAT NEUTRALIZEDSharp. You’re thinking like a defender.Sanitization/secure disposal ensures data cannot be recovered from retired media. CEncryption in transit✖ THREAT DETECTEDPatch your thinking with this:Sanitization/secure disposal ensures data cannot be recovered from retired media. DLoad balancing✖ THREAT DETECTEDPatch your thinking with this:Sanitization/secure disposal ensures data cannot be recovered from retired media. 93/100 Security Operations A policy stating how long records must be kept before deletion addresses data: ARetention✔ IDENTITY VERIFIEDYou’ve got the principle down. Textbook.Retention policies define how long data is kept and when it is disposed of. BEncryption✖ ALERT RAISEDNo stress — here’s the fix:Retention policies define how long data is kept and when it is disposed of. CClassification✖ ALERT RAISEDNo stress — here’s the fix:Retention policies define how long data is kept and when it is disposed of. DRedundancy✖ ALERT RAISEDNo stress — here’s the fix:Retention policies define how long data is kept and when it is disposed of. 94/100 Security Operations An attacker phones the help desk pretending to be a locked-out executive to get a password reset. This is: AA brute-force attack✖ CHECK FAILEDEvery miss is a lesson. Takeaway:Social engineering manipulates people, rather than technology, to gain access. BA DDoS attack✖ CHECK FAILEDEvery miss is a lesson. Takeaway:Social engineering manipulates people, rather than technology, to gain access. CPort scanning✖ CHECK FAILEDEvery miss is a lesson. Takeaway:Social engineering manipulates people, rather than technology, to gain access. DSocial engineering✔ CONTROL VALIDATEDLocked in — that’s the CC mindset.Social engineering manipulates people, rather than technology, to gain access. 95/100 Security Operations Requiring strong, unique passwords and enabling MFA is part of good: ALoad balancing✖ FLAGGED FOR REVIEWReset and lock it in with this:Strong password practices and MFA protect accounts from compromise. BNetwork segmentation✖ FLAGGED FOR REVIEWReset and lock it in with this:Strong password practices and MFA protect accounts from compromise. CPassword and credential hygiene✔ RISK MITIGATEDVerified. Oluma loves to see it.Strong password practices and MFA protect accounts from compromise. DData classification✖ FLAGGED FOR REVIEWReset and lock it in with this:Strong password practices and MFA protect accounts from compromise. 96/100 Security Operations An analyst uses a standard account for daily work and a separate admin account only when needed. This applies: ALoad balancing✖ ACCESS DENIEDPatch your thinking with this:Using elevated rights only when required limits the damage if a session is compromised. BLeast privilege✔ POLICY ENFORCEDNicely done — that’s a keeper.Using elevated rights only when required limits the damage if a session is compromised. CRedundancy✖ ACCESS DENIEDPatch your thinking with this:Using elevated rights only when required limits the damage if a session is compromised. DNon-repudiation✖ ACCESS DENIEDPatch your thinking with this:Using elevated rights only when required limits the damage if a session is compromised. 97/100 Security Operations Backups are only truly reliable if the team also: APeriodically tests that they can actually be restored✔ INTEGRITY CONFIRMEDThat’s foundation-solid — clean and correct.Untested backups may fail when needed; restore testing verifies they actually work. BStores them on the same server✖ THREAT DETECTEDNo stress — here’s the fix:Untested backups may fail when needed; restore testing verifies they actually work. CNever encrypts them✖ THREAT DETECTEDNo stress — here’s the fix:Untested backups may fail when needed; restore testing verifies they actually work. DDeletes them every month✖ THREAT DETECTEDNo stress — here’s the fix:Untested backups may fail when needed; restore testing verifies they actually work. 98/100 Security Operations A clean-desk policy requiring sensitive documents to be locked away when unattended supports: AAvailability only✖ ALERT RAISEDEvery miss is a lesson. Takeaway:A clean-desk policy prevents unauthorized viewing of sensitive information, supporting confidentiality. BRedundancy✖ ALERT RAISEDEvery miss is a lesson. Takeaway:A clean-desk policy prevents unauthorized viewing of sensitive information, supporting confidentiality. CLoad balancing✖ ALERT RAISEDEvery miss is a lesson. Takeaway:A clean-desk policy prevents unauthorized viewing of sensitive information, supporting confidentiality. DConfidentiality✔ SECUREDSharp. You’re thinking like a defender.A clean-desk policy prevents unauthorized viewing of sensitive information, supporting confidentiality. 99/100 Security Operations Defining an approved standard configuration for all workstations, so unauthorized changes can be spotted, creates a: ABackup schedule✖ CHECK FAILEDReset and lock it in with this:A configuration baseline is the approved standard build that later changes are measured against. BAccess token✖ CHECK FAILEDReset and lock it in with this:A configuration baseline is the approved standard build that later changes are measured against. CConfiguration baseline✔ VERIFIEDYou’ve got the principle down. Textbook.A configuration baseline is the approved standard build that later changes are measured against. DFirewall rule✖ CHECK FAILEDReset and lock it in with this:A configuration baseline is the approved standard build that later changes are measured against. 100/100 Security Operations You receive an unexpected email attachment from an unknown sender at work. The BEST action is to: AReply to ask who they are✖ FLAGGED FOR REVIEWPatch your thinking with this:Unexpected attachments may be malware; the safe move is to avoid opening it and report it to security. BNot open it and report it to security✔ DEFENSE HELDLocked in — that’s the CC mindset.Unexpected attachments may be malware; the safe move is to avoid opening it and report it to security. COpen it to see what it is✖ FLAGGED FOR REVIEWPatch your thinking with this:Unexpected attachments may be malware; the safe move is to avoid opening it and report it to security. DForward it to coworkers to check✖ FLAGGED FOR REVIEWPatch your thinking with this:Unexpected attachments may be malware; the safe move is to avoid opening it and report it to security. FOUNDATIONS LOCKED IN — WELL DONE Nice work, learner. You just drilled the fundamentals every cybersecurity career is built on — and every rep, right or wrong, is how it sticks. Your live score is on the board below. Whatever the number, you showed up and put in the work today — that’s the part that compounds. Gold means a strong area to lock in; the dashed tag means a domain worth another pass. Keep circling back — you’ve got this, friend. CORRECT ANSWERED These are original practice scenarios written for the Oluma community. CC® and ISC2® are trademarks or registered trademarks of ISC2, Inc. Oluma is not affiliated with or endorsed by ISC2. No official exam content is reproduced here — learn the concepts, not the dumps.