Skip to content
Oluma Cyber Security Awareness
🛡
OLUMA CERTIFICATION ZONE

Security+Practice Range

100 original scenarios across security concepts, threats & mitigations, architecture, operations and governance (SY0-701). Pick your range and defend the enterprise.

START HERE
How do you want us to call you?
Enter a name to unlock the practice range โ€” we’ll keep it friendly from here on.
๐Ÿ”’ Practice range locked โ€” enter a name above to begin
โœ” You’re in, defender โ€” scroll on when you’re ready
About the Certification

What is CompTIA Security+?

Security+ (exam SY0-701) is the industry-standard, vendor-neutral certification that proves you can assess an organization’s security posture, harden hybrid and cloud environments, respond to incidents, and work within governance, risk and compliance. For most people it’s the first security certification worth earning โ€” and it’s approved as a U.S. DoD 8140 baseline.

It’s a strong fit if you’re moving from IT support or networking into security, you’re a GRC or SOC analyst formalizing your skills, or you’re (like much of the Oluma community) breaking into cybersecurity and want a credential employers actually recognize.

๐Ÿ›ก๏ธSecurity AnalystMonitor, triage, and respond to real security events.
๐ŸšจSOC / Incident ResponseDetect, contain, and recover from incidents.
๐Ÿ“‹GRC AnalystMap controls to risk, policy, and compliance.
โ˜๏ธCloud / Systems AdminSecure hybrid, cloud, mobile and IoT environments.
Exam CodeSY0-701
QuestionsUp to 90
Time90 minutes
Passing Score750 / 900
Exam Objectives

The five domains

SY0-701 is organized into five weighted domains. Security Operations is the heavyweight at 28% โ€” spend your study time proportionally. These practice questions are grouped by the same five areas.

1 ยท General Security Concepts
Security controls, core principles, change management & cryptography.
12%
2 ยท Threats, Vulnerabilities & Mitigations
Threat actors, attack surfaces, vulnerabilities and how to mitigate them.
22%
3 ยท Security Architecture
Secure design, segmentation, zero trust, cloud and data protection.
18%
4 ยท Security Operations
Monitoring, incident response, vuln management, IAM and automation.
28%
5 ยท Security Program Management & Oversight
Governance, risk, compliance, policies and third-party risk.
20%
Official Resources

Go straight to the source

Bookmark the official CompTIA pages for authoritative details on the exam, current pricing, and the full objectives blueprint. These open in a new tab.

Before You Start

Set yourself up to pass

A few habits separate people who pass comfortably from people who retake. Keep these in mind while you drill.

1Weight your study

Security Operations is 28% and Domains 4+5 are nearly half the exam โ€” don’t overweight the small buckets.

2Think in scenarios

Most questions ask what to do in a situation, not just define a term. Practice choosing the BEST response.

3Handle PBQs first

Performance-based questions appear at the start and eat time. Flag and return if one stalls you.

4Know your acronyms

CIA, AAA, SIEM, SOAR, MFA, PKI, IDS/IPS โ€” the exam assumes fluency. Drill the acronym list.

5Learn the frameworks

Zero Trust, shared responsibility, risk concepts and control types are named, testable ideas now.

6Read for qualifiers

Watch for “BEST,” “MOST likely,” and “FIRST.” The strongest answer wins, not just a correct one.

General Security ConceptsThreats & MitigationsSecurity ArchitectureSecurity OperationsProgram Management
SELECT YOUR RANGE
01/100 General Security Concepts

A company encrypts customer records so that even if the database is stolen, the data cannot be read. Which part of the CIA triad is this protecting?

โœ” CONTROL VALIDATED

That’s analyst-grade thinking โ€” clean and correct.

Encryption protects confidentiality by keeping data unreadable to unauthorized parties.

โœ– ALERT RAISED

Flag it, learn it, move on. Here’s the fix:

Encryption protects confidentiality by keeping data unreadable to unauthorized parties.

โœ– ALERT RAISED

Flag it, learn it, move on. Here’s the fix:

Encryption protects confidentiality by keeping data unreadable to unauthorized parties.

โœ– ALERT RAISED

Flag it, learn it, move on. Here’s the fix:

Encryption protects confidentiality by keeping data unreadable to unauthorized parties.

02/100 General Security Concepts

A hashing check confirms a downloaded file was not altered in transit. Which security goal does this support?

โœ– INTEGRITY CHECK FAILED

Every alert is a lesson. Takeaway:

Hashing verifies integrity โ€” any change to the file changes its hash value.

โœ” SIGNATURE MATCHED

Sharp call. The SOC would want you on shift.

Hashing verifies integrity โ€” any change to the file changes its hash value.

โœ– INTEGRITY CHECK FAILED

Every alert is a lesson. Takeaway:

Hashing verifies integrity โ€” any change to the file changes its hash value.

โœ– INTEGRITY CHECK FAILED

Every alert is a lesson. Takeaway:

Hashing verifies integrity โ€” any change to the file changes its hash value.

03/100 General Security Concepts

A firewall rule that blocks traffic is best described as which type of security control by function?

โœ” CONTROL VALIDATED

You read the risk right. Textbook.

Preventive controls stop an incident before it happens; a blocking firewall rule is preventive.

โœ– THREAT DETECTED

Reassess and re-secure with this:

Preventive controls stop an incident before it happens; a blocking firewall rule is preventive.

โœ– THREAT DETECTED

Reassess and re-secure with this:

Preventive controls stop an incident before it happens; a blocking firewall rule is preventive.

โœ– THREAT DETECTED

Reassess and re-secure with this:

Preventive controls stop an incident before it happens; a blocking firewall rule is preventive.

04/100 General Security Concepts

Security cameras that record activity in a data center are which type of control by function?

โœ– ALERT RAISED

Patch your thinking with this:

Cameras detect and record activity, making them detective controls (with a deterrent effect).

โœ” ALERT RESOLVED

Locked in โ€” that’s how defenders think.

Cameras detect and record activity, making them detective controls (with a deterrent effect).

โœ– ALERT RAISED

Patch your thinking with this:

Cameras detect and record activity, making them detective controls (with a deterrent effect).

โœ– ALERT RAISED

Patch your thinking with this:

Cameras detect and record activity, making them detective controls (with a deterrent effect).

05/100 General Security Concepts

Because it can’t patch a legacy system, a company isolates it on its own VLAN as an alternative safeguard. What control type is this?

โœ– THREAT DETECTED

Every alert is a lesson. Takeaway:

A compensating control is an alternative safeguard used when the primary control isn’t feasible.

โœ– THREAT DETECTED

Every alert is a lesson. Takeaway:

A compensating control is an alternative safeguard used when the primary control isn’t feasible.

โœ” RISK MITIGATED

Verified. Oluma loves to see it.

A compensating control is an alternative safeguard used when the primary control isn’t feasible.

โœ– THREAT DETECTED

Every alert is a lesson. Takeaway:

A compensating control is an alternative safeguard used when the primary control isn’t feasible.

06/100 General Security Concepts

A digital signature on an email lets the recipient prove who sent it and that the sender can’t deny it. Which property is this?

โœ– ACCESS DENIED

Reassess and re-secure with this:

Non-repudiation ensures a sender cannot deny an action; digital signatures provide it.

โœ” IDENTITY VERIFIED

That’s analyst-grade thinking โ€” clean and correct.

Non-repudiation ensures a sender cannot deny an action; digital signatures provide it.

โœ– ACCESS DENIED

Reassess and re-secure with this:

Non-repudiation ensures a sender cannot deny an action; digital signatures provide it.

โœ– ACCESS DENIED

Reassess and re-secure with this:

Non-repudiation ensures a sender cannot deny an action; digital signatures provide it.

07/100 General Security Concepts

In the AAA framework, which step confirms that a user is who they claim to be?

โœ” IDENTITY VERIFIED

Sharp call. The SOC would want you on shift.

Authentication proves identity; authorization grants access; accounting logs activity.

โœ– ACCESS DENIED

Patch your thinking with this:

Authentication proves identity; authorization grants access; accounting logs activity.

โœ– ACCESS DENIED

Patch your thinking with this:

Authentication proves identity; authorization grants access; accounting logs activity.

โœ– ACCESS DENIED

Patch your thinking with this:

Authentication proves identity; authorization grants access; accounting logs activity.

08/100 General Security Concepts

A zero trust architecture is built on which core assumption?

โœ– THREAT DETECTED

Reassess and re-secure with this:

Zero trust assumes no implicit trust; every request is verified regardless of location.

โœ” CONTROL VALIDATED

You read the risk right. Textbook.

Zero trust assumes no implicit trust; every request is verified regardless of location.

โœ– THREAT DETECTED

Reassess and re-secure with this:

Zero trust assumes no implicit trust; every request is verified regardless of location.

โœ– THREAT DETECTED

Reassess and re-secure with this:

Zero trust assumes no implicit trust; every request is verified regardless of location.

09/100 General Security Concepts

A security team plants a fake, monitored server to lure and study attackers. What is this called?

โœ– ALERT RAISED

Every alert is a lesson. Takeaway:

A honeypot is a decoy system used to detect, deflect, and study attacker behavior.

โœ– ALERT RAISED

Every alert is a lesson. Takeaway:

A honeypot is a decoy system used to detect, deflect, and study attacker behavior.

โœ” THREAT NEUTRALIZED

Locked in โ€” that’s how defenders think.

A honeypot is a decoy system used to detect, deflect, and study attacker behavior.

โœ– ALERT RAISED

Every alert is a lesson. Takeaway:

A honeypot is a decoy system used to detect, deflect, and study attacker behavior.

10/100 General Security Concepts

Before deploying a configuration change to production, an organization requires review, testing, and a rollback plan. This is an example of:

โœ– ACCESS DENIED

Patch your thinking with this:

Change management reduces risk through approval, testing, scheduling, and rollback planning.

โœ” POLICY ENFORCED

Verified. Oluma loves to see it.

Change management reduces risk through approval, testing, scheduling, and rollback planning.

โœ– ACCESS DENIED

Patch your thinking with this:

Change management reduces risk through approval, testing, scheduling, and rollback planning.

โœ– ACCESS DENIED

Patch your thinking with this:

Change management reduces risk through approval, testing, scheduling, and rollback planning.

CHECKPOINT โ€” 10 DOWN, STAY SHARP
11/100 General Security Concepts

Which encryption approach uses the same secret key to both encrypt and decrypt data?

โœ” CONTROL VALIDATED

That’s analyst-grade thinking โ€” clean and correct.

Symmetric encryption (e.g., AES) uses one shared key; it’s fast but key distribution is the challenge.

โœ– ACCESS DENIED

Reassess and re-secure with this:

Symmetric encryption (e.g., AES) uses one shared key; it’s fast but key distribution is the challenge.

โœ– ACCESS DENIED

Reassess and re-secure with this:

Symmetric encryption (e.g., AES) uses one shared key; it’s fast but key distribution is the challenge.

โœ– ACCESS DENIED

Reassess and re-secure with this:

Symmetric encryption (e.g., AES) uses one shared key; it’s fast but key distribution is the challenge.

12/100 General Security Concepts

To send someone confidential data using asymmetric encryption, which key do you encrypt with?

โœ– ACCESS DENIED

Every alert is a lesson. Takeaway:

Encrypt with the recipient’s public key; only their matching private key can decrypt it.

โœ– ACCESS DENIED

Every alert is a lesson. Takeaway:

Encrypt with the recipient’s public key; only their matching private key can decrypt it.

โœ” IDENTITY VERIFIED

Sharp call. The SOC would want you on shift.

Encrypt with the recipient’s public key; only their matching private key can decrypt it.

โœ– ACCESS DENIED

Every alert is a lesson. Takeaway:

Encrypt with the recipient’s public key; only their matching private key can decrypt it.

13/100 General Security Concepts

Adding a unique random value to each password before hashing it defends against precomputed rainbow tables. What is that value called?

โœ– INTEGRITY CHECK FAILED

Patch your thinking with this:

A salt is unique random data added before hashing, defeating rainbow-table attacks.

โœ” CONTROL VALIDATED

You read the risk right. Textbook.

A salt is unique random data added before hashing, defeating rainbow-table attacks.

โœ– INTEGRITY CHECK FAILED

Patch your thinking with this:

A salt is unique random data added before hashing, defeating rainbow-table attacks.

โœ– INTEGRITY CHECK FAILED

Patch your thinking with this:

A salt is unique random data added before hashing, defeating rainbow-table attacks.

14/100 General Security Concepts

What does a Certificate Authority (CA) do in a public key infrastructure?

โœ– ACCESS DENIED

Reassess and re-secure with this:

A CA issues and digitally signs certificates that bind a public key to a verified identity.

โœ– ACCESS DENIED

Reassess and re-secure with this:

A CA issues and digitally signs certificates that bind a public key to a verified identity.

โœ” IDENTITY VERIFIED

Locked in โ€” that’s how defenders think.

A CA issues and digitally signs certificates that bind a public key to a verified identity.

โœ– ACCESS DENIED

Reassess and re-secure with this:

A CA issues and digitally signs certificates that bind a public key to a verified identity.

15/100 General Security Concepts

Which technology stores cryptographic keys in tamper-resistant hardware separate from the main system?

โœ– THREAT DETECTED

Every alert is a lesson. Takeaway:

A hardware security module (HSM) generates and stores keys in dedicated tamper-resistant hardware.

โœ” CONTROL VALIDATED

That’s analyst-grade thinking โ€” clean and correct.

A hardware security module (HSM) generates and stores keys in dedicated tamper-resistant hardware.

โœ– THREAT DETECTED

Every alert is a lesson. Takeaway:

A hardware security module (HSM) generates and stores keys in dedicated tamper-resistant hardware.

โœ– THREAT DETECTED

Every alert is a lesson. Takeaway:

A hardware security module (HSM) generates and stores keys in dedicated tamper-resistant hardware.

16/100 General Security Concepts

Replacing sensitive card numbers with a non-sensitive substitute value that maps back only in a secure vault is called:

โœ– ACCESS DENIED

Patch your thinking with this:

Tokenization swaps sensitive data for a token that maps back only inside a protected system.

โœ– ACCESS DENIED

Patch your thinking with this:

Tokenization swaps sensitive data for a token that maps back only inside a protected system.

โœ” RISK MITIGATED

Sharp call. The SOC would want you on shift.

Tokenization swaps sensitive data for a token that maps back only inside a protected system.

โœ– ACCESS DENIED

Patch your thinking with this:

Tokenization swaps sensitive data for a token that maps back only inside a protected system.

17/100 General Security Concepts

A sign that reads “Authorized Personnel Only” primarily acts as which type of control?

โœ– ALERT RAISED

Reassess and re-secure with this:

A warning sign is a deterrent control โ€” it discourages a would-be violator by threat of consequence.

โœ” CONTROL VALIDATED

You read the risk right. Textbook.

A warning sign is a deterrent control โ€” it discourages a would-be violator by threat of consequence.

โœ– ALERT RAISED

Reassess and re-secure with this:

A warning sign is a deterrent control โ€” it discourages a would-be violator by threat of consequence.

โœ– ALERT RAISED

Reassess and re-secure with this:

A warning sign is a deterrent control โ€” it discourages a would-be violator by threat of consequence.

18/100 General Security Concepts

A security policy document that tells employees they must complete annual training is which type of control?

โœ” POLICY ENFORCED

Locked in โ€” that’s how defenders think.

Directive controls instruct or require behavior, such as policies mandating training.

โœ– ACCESS DENIED

Every alert is a lesson. Takeaway:

Directive controls instruct or require behavior, such as policies mandating training.

โœ– ACCESS DENIED

Every alert is a lesson. Takeaway:

Directive controls instruct or require behavior, such as policies mandating training.

โœ– ACCESS DENIED

Every alert is a lesson. Takeaway:

Directive controls instruct or require behavior, such as policies mandating training.

19/100 General Security Concepts

Restoring systems from backup after a ransomware attack is best classified as which control by function?

โœ– THREAT DETECTED

Patch your thinking with this:

Corrective controls restore systems and reduce impact after an incident has occurred.

โœ– THREAT DETECTED

Patch your thinking with this:

Corrective controls restore systems and reduce impact after an incident has occurred.

โœ” BREACH CONTAINED

Verified. Oluma loves to see it.

Corrective controls restore systems and reduce impact after an incident has occurred.

โœ– THREAT DETECTED

Patch your thinking with this:

Corrective controls restore systems and reduce impact after an incident has occurred.

20/100 General Security Concepts

Which cryptographic concept ensures that a compromised session key does not expose past or future session keys?

โœ– ACCESS DENIED

Reassess and re-secure with this:

Perfect forward secrecy generates unique ephemeral keys per session, isolating any single compromise.

โœ” CONTROL VALIDATED

That’s analyst-grade thinking โ€” clean and correct.

Perfect forward secrecy generates unique ephemeral keys per session, isolating any single compromise.

โœ– ACCESS DENIED

Reassess and re-secure with this:

Perfect forward secrecy generates unique ephemeral keys per session, isolating any single compromise.

โœ– ACCESS DENIED

Reassess and re-secure with this:

Perfect forward secrecy generates unique ephemeral keys per session, isolating any single compromise.

CHECKPOINT โ€” 20 DOWN, STAY SHARP
21/100 Threats & Mitigations

A well-funded, highly skilled attacker backed by a government targets critical infrastructure over many months. Which threat actor is this?

โœ” THREAT NEUTRALIZED

That’s analyst-grade thinking โ€” clean and correct.

Nation-state actors are highly resourced and persistent, often labeled advanced persistent threats.

โœ– THREAT DETECTED

Reassess and re-secure with this:

Nation-state actors are highly resourced and persistent, often labeled advanced persistent threats.

โœ– THREAT DETECTED

Reassess and re-secure with this:

Nation-state actors are highly resourced and persistent, often labeled advanced persistent threats.

โœ– THREAT DETECTED

Reassess and re-secure with this:

Nation-state actors are highly resourced and persistent, often labeled advanced persistent threats.

22/100 Threats & Mitigations

An attacker calls an employee pretending to be IT support and asks for their password. Which attack is this?

โœ– ACCESS DENIED

Every alert is a lesson. Takeaway:

Vishing is voice-based social engineering, using a phone call and a pretext to extract information.

โœ” THREAT NEUTRALIZED

Sharp call. The SOC would want you on shift.

Vishing is voice-based social engineering, using a phone call and a pretext to extract information.

โœ– ACCESS DENIED

Every alert is a lesson. Takeaway:

Vishing is voice-based social engineering, using a phone call and a pretext to extract information.

โœ– ACCESS DENIED

Every alert is a lesson. Takeaway:

Vishing is voice-based social engineering, using a phone call and a pretext to extract information.

23/100 Threats & Mitigations

Malware that encrypts a victim’s files and demands payment for the decryption key is:

โœ– THREAT DETECTED

Patch your thinking with this:

Ransomware encrypts data and extorts the victim for the key or to prevent leaks.

โœ– THREAT DETECTED

Patch your thinking with this:

Ransomware encrypts data and extorts the victim for the key or to prevent leaks.

โœ” THREAT NEUTRALIZED

You read the risk right. Textbook.

Ransomware encrypts data and extorts the victim for the key or to prevent leaks.

โœ– THREAT DETECTED

Patch your thinking with this:

Ransomware encrypts data and extorts the victim for the key or to prevent leaks.

24/100 Threats & Mitigations

Malicious code that lies dormant until a specific date or condition triggers it is called:

โœ– ALERT RAISED

Reassess and re-secure with this:

A logic bomb executes its payload when a set condition or time is met.

โœ– ALERT RAISED

Reassess and re-secure with this:

A logic bomb executes its payload when a set condition or time is met.

โœ– ALERT RAISED

Reassess and re-secure with this:

A logic bomb executes its payload when a set condition or time is met.

โœ” THREAT NEUTRALIZED

Locked in โ€” that’s how defenders think.

A logic bomb executes its payload when a set condition or time is met.

25/100 Threats & Mitigations

A web form lets an attacker enter ‘ OR ‘1’=’1 to bypass a login. Which attack is this?

โœ” BREACH CONTAINED

That’s analyst-grade thinking โ€” clean and correct.

SQL injection inserts crafted input into a query; parameterized queries and input validation mitigate it.

โœ– THREAT DETECTED

Every alert is a lesson. Takeaway:

SQL injection inserts crafted input into a query; parameterized queries and input validation mitigate it.

โœ– THREAT DETECTED

Every alert is a lesson. Takeaway:

SQL injection inserts crafted input into a query; parameterized queries and input validation mitigate it.

โœ– THREAT DETECTED

Every alert is a lesson. Takeaway:

SQL injection inserts crafted input into a query; parameterized queries and input validation mitigate it.

26/100 Threats & Mitigations

An attacker injects a malicious script into a website that then runs in other visitors’ browsers. This is:

โœ– ACCESS DENIED

Patch your thinking with this:

Cross-site scripting (XSS) injects scripts that execute in other users’ browsers; output encoding mitigates it.

โœ” BREACH CONTAINED

Sharp call. The SOC would want you on shift.

Cross-site scripting (XSS) injects scripts that execute in other users’ browsers; output encoding mitigates it.

โœ– ACCESS DENIED

Patch your thinking with this:

Cross-site scripting (XSS) injects scripts that execute in other users’ browsers; output encoding mitigates it.

โœ– ACCESS DENIED

Patch your thinking with this:

Cross-site scripting (XSS) injects scripts that execute in other users’ browsers; output encoding mitigates it.

27/100 Threats & Mitigations

An attacker tries a handful of very common passwords against many different accounts to avoid lockouts. This is:

โœ– THREAT DETECTED

Reassess and re-secure with this:

Password spraying tries a few common passwords across many accounts to avoid triggering lockouts.

โœ” THREAT NEUTRALIZED

You read the risk right. Textbook.

Password spraying tries a few common passwords across many accounts to avoid triggering lockouts.

โœ– THREAT DETECTED

Reassess and re-secure with this:

Password spraying tries a few common passwords across many accounts to avoid triggering lockouts.

โœ– THREAT DETECTED

Reassess and re-secure with this:

Password spraying tries a few common passwords across many accounts to avoid triggering lockouts.

28/100 Threats & Mitigations

A newly discovered flaw with no vendor patch available yet is known as a:

โœ– ALERT RAISED

Every alert is a lesson. Takeaway:

A zero-day is a vulnerability unknown to the vendor, with no patch available when exploited.

โœ– ALERT RAISED

Every alert is a lesson. Takeaway:

A zero-day is a vulnerability unknown to the vendor, with no patch available when exploited.

โœ” THREAT NEUTRALIZED

Locked in โ€” that’s how defenders think.

A zero-day is a vulnerability unknown to the vendor, with no patch available when exploited.

โœ– ALERT RAISED

Every alert is a lesson. Takeaway:

A zero-day is a vulnerability unknown to the vendor, with no patch available when exploited.

29/100 Threats & Mitigations

A finance employee gets an urgent email that appears to come from the CEO asking for a wire transfer. Which attack is this?

โœ– ACCESS DENIED

Patch your thinking with this:

Business email compromise (a spear-phishing/whaling technique) impersonates an executive to authorize fraud.

โœ” THREAT NEUTRALIZED

That’s analyst-grade thinking โ€” clean and correct.

Business email compromise (a spear-phishing/whaling technique) impersonates an executive to authorize fraud.

โœ– ACCESS DENIED

Patch your thinking with this:

Business email compromise (a spear-phishing/whaling technique) impersonates an executive to authorize fraud.

โœ– ACCESS DENIED

Patch your thinking with this:

Business email compromise (a spear-phishing/whaling technique) impersonates an executive to authorize fraud.

30/100 Threats & Mitigations

Which mitigation most directly limits the damage an attacker can do after compromising a single user account?

โœ– THREAT DETECTED

Reassess and re-secure with this:

Least privilege limits each account to only what it needs, containing the blast radius of a compromise.

โœ– THREAT DETECTED

Reassess and re-secure with this:

Least privilege limits each account to only what it needs, containing the blast radius of a compromise.

โœ” RISK MITIGATED

Verified. Oluma loves to see it.

Least privilege limits each account to only what it needs, containing the blast radius of a compromise.

โœ– THREAT DETECTED

Reassess and re-secure with this:

Least privilege limits each account to only what it needs, containing the blast radius of a compromise.

CHECKPOINT โ€” 30 DOWN, STAY SHARP
31/100 Threats & Mitigations

An attacker positions themselves between two communicating hosts to intercept and alter traffic. This is a(n):

โœ” BREACH CONTAINED

That’s analyst-grade thinking โ€” clean and correct.

An on-path attacker intercepts traffic between two parties; encryption and integrity checks defend against it.

โœ– THREAT DETECTED

Every alert is a lesson. Takeaway:

An on-path attacker intercepts traffic between two parties; encryption and integrity checks defend against it.

โœ– THREAT DETECTED

Every alert is a lesson. Takeaway:

An on-path attacker intercepts traffic between two parties; encryption and integrity checks defend against it.

โœ– THREAT DETECTED

Every alert is a lesson. Takeaway:

An on-path attacker intercepts traffic between two parties; encryption and integrity checks defend against it.

32/100 Threats & Mitigations

Malware disguised as a legitimate program that the user installs willingly is a:

โœ– ACCESS DENIED

Patch your thinking with this:

A trojan masquerades as legitimate software to trick the user into running it.

โœ” THREAT NEUTRALIZED

Sharp call. The SOC would want you on shift.

A trojan masquerades as legitimate software to trick the user into running it.

โœ– ACCESS DENIED

Patch your thinking with this:

A trojan masquerades as legitimate software to trick the user into running it.

โœ– ACCESS DENIED

Patch your thinking with this:

A trojan masquerades as legitimate software to trick the user into running it.

33/100 Threats & Mitigations

An employee downloads free software that secretly installs a compromised update, infecting the whole company. This is an example of a:

โœ– THREAT DETECTED

Reassess and re-secure with this:

Supply chain attacks compromise trusted software or vendors to reach downstream victims.

โœ” THREAT NEUTRALIZED

You read the risk right. Textbook.

Supply chain attacks compromise trusted software or vendors to reach downstream victims.

โœ– THREAT DETECTED

Reassess and re-secure with this:

Supply chain attacks compromise trusted software or vendors to reach downstream victims.

โœ– THREAT DETECTED

Reassess and re-secure with this:

Supply chain attacks compromise trusted software or vendors to reach downstream victims.

34/100 Threats & Mitigations

Unusual outbound traffic to an unknown host at 3 a.m. is best described as a(n):

โœ– ALERT RAISED

Patch your thinking with this:

An indicator of compromise (IoC) is evidence, like anomalous traffic, that a breach may have occurred.

โœ– ALERT RAISED

Patch your thinking with this:

An indicator of compromise (IoC) is evidence, like anomalous traffic, that a breach may have occurred.

โœ” THREAT DETECTED

Locked in โ€” that’s how defenders think.

An indicator of compromise (IoC) is evidence, like anomalous traffic, that a breach may have occurred.

โœ– ALERT RAISED

Patch your thinking with this:

An indicator of compromise (IoC) is evidence, like anomalous traffic, that a breach may have occurred.

35/100 Threats & Mitigations

An unauthorized wireless access point secretly plugged into the corporate LAN is a:

โœ– THREAT DETECTED

Every alert is a lesson. Takeaway:

A rogue access point is an unauthorized AP added to a network, creating an unmanaged entry point.

โœ” THREAT NEUTRALIZED

That’s analyst-grade thinking โ€” clean and correct.

A rogue access point is an unauthorized AP added to a network, creating an unmanaged entry point.

โœ– THREAT DETECTED

Every alert is a lesson. Takeaway:

A rogue access point is an unauthorized AP added to a network, creating an unmanaged entry point.

โœ– THREAT DETECTED

Every alert is a lesson. Takeaway:

A rogue access point is an unauthorized AP added to a network, creating an unmanaged entry point.

36/100 Threats & Mitigations

Which mitigation ensures only explicitly approved applications can run on a workstation?

โœ– ACCESS DENIED

Reassess and re-secure with this:

Application allow listing permits only approved software to execute, blocking everything else by default.

โœ– ACCESS DENIED

Reassess and re-secure with this:

Application allow listing permits only approved software to execute, blocking everything else by default.

โœ” CONTROL VALIDATED

Sharp call. The SOC would want you on shift.

Application allow listing permits only approved software to execute, blocking everything else by default.

โœ– ACCESS DENIED

Reassess and re-secure with this:

Application allow listing permits only approved software to execute, blocking everything else by default.

37/100 Threats & Mitigations

A disgruntled employee with legitimate access copies confidential files before resigning. This is a(n):

โœ– THREAT DETECTED

Patch your thinking with this:

An insider threat comes from someone with authorized access who misuses it.

โœ” THREAT NEUTRALIZED

You read the risk right. Textbook.

An insider threat comes from someone with authorized access who misuses it.

โœ– THREAT DETECTED

Patch your thinking with this:

An insider threat comes from someone with authorized access who misuses it.

โœ– THREAT DETECTED

Patch your thinking with this:

An insider threat comes from someone with authorized access who misuses it.

38/100 Threats & Mitigations

Which single mitigation most effectively closes known software vulnerabilities?

โœ” VULN PATCHED

That’s analyst-grade thinking โ€” clean and correct.

Applying vendor patches promptly removes known vulnerabilities before they can be exploited.

โœ– ALERT RAISED

Every alert is a lesson. Takeaway:

Applying vendor patches promptly removes known vulnerabilities before they can be exploited.

โœ– ALERT RAISED

Every alert is a lesson. Takeaway:

Applying vendor patches promptly removes known vulnerabilities before they can be exploited.

โœ– ALERT RAISED

Every alert is a lesson. Takeaway:

Applying vendor patches promptly removes known vulnerabilities before they can be exploited.

39/100 Threats & Mitigations

An attacker floods a server with traffic from a botnet of thousands of devices to take it offline. This is a:

โœ– THREAT DETECTED

Reassess and re-secure with this:

A distributed denial-of-service (DDoS) attack overwhelms a target from many sources at once.

โœ– THREAT DETECTED

Reassess and re-secure with this:

A distributed denial-of-service (DDoS) attack overwhelms a target from many sources at once.

โœ” THREAT NEUTRALIZED

Locked in โ€” that’s how defenders think.

A distributed denial-of-service (DDoS) attack overwhelms a target from many sources at once.

โœ– THREAT DETECTED

Reassess and re-secure with this:

A distributed denial-of-service (DDoS) attack overwhelms a target from many sources at once.

40/100 Threats & Mitigations

An attacker exploits a flaw to gain higher permissions than their account should have. This is:

โœ– ACCESS DENIED

Every alert is a lesson. Takeaway:

Privilege escalation obtains rights beyond those originally granted, often to reach sensitive resources.

โœ” BREACH CONTAINED

Verified. Oluma loves to see it.

Privilege escalation obtains rights beyond those originally granted, often to reach sensitive resources.

โœ– ACCESS DENIED

Every alert is a lesson. Takeaway:

Privilege escalation obtains rights beyond those originally granted, often to reach sensitive resources.

โœ– ACCESS DENIED

Every alert is a lesson. Takeaway:

Privilege escalation obtains rights beyond those originally granted, often to reach sensitive resources.

CHECKPOINT โ€” 40 DOWN, STAY SHARP
41/100 Security Architecture

Placing public-facing web servers in an isolated network segment separated from the internal LAN is called a:

โœ” CONTROL VALIDATED

That’s analyst-grade thinking โ€” clean and correct.

A screened subnet isolates internet-facing services so a compromise there can’t directly reach the LAN.

โœ– ACCESS DENIED

Reassess and re-secure with this:

A screened subnet isolates internet-facing services so a compromise there can’t directly reach the LAN.

โœ– ACCESS DENIED

Reassess and re-secure with this:

A screened subnet isolates internet-facing services so a compromise there can’t directly reach the LAN.

โœ– ACCESS DENIED

Reassess and re-secure with this:

A screened subnet isolates internet-facing services so a compromise there can’t directly reach the LAN.

42/100 Security Architecture

Which device specifically inspects and filters HTTP/HTTPS traffic to protect web applications from attacks like injection?

โœ– THREAT DETECTED

Patch your thinking with this:

A web application firewall (WAF) inspects application-layer web traffic to block attacks like XSS and SQLi.

โœ” CONTROL VALIDATED

Sharp call. The SOC would want you on shift.

A web application firewall (WAF) inspects application-layer web traffic to block attacks like XSS and SQLi.

โœ– THREAT DETECTED

Patch your thinking with this:

A web application firewall (WAF) inspects application-layer web traffic to block attacks like XSS and SQLi.

โœ– THREAT DETECTED

Patch your thinking with this:

A web application firewall (WAF) inspects application-layer web traffic to block attacks like XSS and SQLi.

43/100 Security Architecture

In a cloud IaaS model, who is responsible for securing the customer’s operating system and applications?

โœ– ACCESS DENIED

Every alert is a lesson. Takeaway:

Under the shared responsibility model for IaaS, the customer secures the OS, apps, and data.

โœ” CONTROL VALIDATED

You read the risk right. Textbook.

Under the shared responsibility model for IaaS, the customer secures the OS, apps, and data.

โœ– ACCESS DENIED

Every alert is a lesson. Takeaway:

Under the shared responsibility model for IaaS, the customer secures the OS, apps, and data.

โœ– ACCESS DENIED

Every alert is a lesson. Takeaway:

Under the shared responsibility model for IaaS, the customer secures the OS, apps, and data.

44/100 Security Architecture

Which solution monitors and enforces security policy for cloud application usage, sitting between users and cloud services?

โœ– ACCESS DENIED

Reassess and re-secure with this:

A cloud access security broker (CASB) enforces policy between users and cloud services.

โœ– ACCESS DENIED

Reassess and re-secure with this:

A cloud access security broker (CASB) enforces policy between users and cloud services.

โœ” POLICY ENFORCED

Locked in โ€” that’s how defenders think.

A cloud access security broker (CASB) enforces policy between users and cloud services.

โœ– ACCESS DENIED

Reassess and re-secure with this:

A cloud access security broker (CASB) enforces policy between users and cloud services.

45/100 Security Architecture

Which protocol should replace Telnet to provide encrypted remote administration?

โœ” CONTROL VALIDATED

That’s analyst-grade thinking โ€” clean and correct.

SSH encrypts remote administration; Telnet sends everything, including credentials, in cleartext.

โœ– ACCESS DENIED

Every alert is a lesson. Takeaway:

SSH encrypts remote administration; Telnet sends everything, including credentials, in cleartext.

โœ– ACCESS DENIED

Every alert is a lesson. Takeaway:

SSH encrypts remote administration; Telnet sends everything, including credentials, in cleartext.

โœ– ACCESS DENIED

Every alert is a lesson. Takeaway:

SSH encrypts remote administration; Telnet sends everything, including credentials, in cleartext.

46/100 Security Architecture

Which control is designed to detect and block sensitive data (like SSNs) from leaving the organization?

โœ– THREAT DETECTED

Patch your thinking with this:

Data loss prevention (DLP) inspects data in use, in motion, and at rest to stop unauthorized exfiltration.

โœ” RISK MITIGATED

Sharp call. The SOC would want you on shift.

Data loss prevention (DLP) inspects data in use, in motion, and at rest to stop unauthorized exfiltration.

โœ– THREAT DETECTED

Patch your thinking with this:

Data loss prevention (DLP) inspects data in use, in motion, and at rest to stop unauthorized exfiltration.

โœ– THREAT DETECTED

Patch your thinking with this:

Data loss prevention (DLP) inspects data in use, in motion, and at rest to stop unauthorized exfiltration.

47/100 Security Architecture

Protecting data as it travels across a network is referred to as protecting data:

โœ– ACCESS DENIED

Reassess and re-secure with this:

Data in transit is protected with transport encryption such as TLS as it moves across networks.

โœ” CONTROL VALIDATED

You read the risk right. Textbook.

Data in transit is protected with transport encryption such as TLS as it moves across networks.

โœ– ACCESS DENIED

Reassess and re-secure with this:

Data in transit is protected with transport encryption such as TLS as it moves across networks.

โœ– ACCESS DENIED

Reassess and re-secure with this:

Data in transit is protected with transport encryption such as TLS as it moves across networks.

48/100 Security Architecture

Distributing incoming requests across multiple servers to improve availability and performance is done by a:

โœ– ALERT RAISED

Every alert is a lesson. Takeaway:

A load balancer spreads traffic across servers, improving availability and resilience.

โœ– ALERT RAISED

Every alert is a lesson. Takeaway:

A load balancer spreads traffic across servers, improving availability and resilience.

โœ” CONTROL VALIDATED

Locked in โ€” that’s how defenders think.

A load balancer spreads traffic across servers, improving availability and resilience.

โœ– ALERT RAISED

Every alert is a lesson. Takeaway:

A load balancer spreads traffic across servers, improving availability and resilience.

49/100 Security Architecture

A recovery site that is fully equipped and running, ready to take over almost immediately, is a:

โœ” CONTROL VALIDATED

That’s analyst-grade thinking โ€” clean and correct.

A hot site is fully operational and can take over with minimal downtime; cold sites need setup.

โœ– ACCESS DENIED

Reassess and re-secure with this:

A hot site is fully operational and can take over with minimal downtime; cold sites need setup.

โœ– ACCESS DENIED

Reassess and re-secure with this:

A hot site is fully operational and can take over with minimal downtime; cold sites need setup.

โœ– ACCESS DENIED

Reassess and re-secure with this:

A hot site is fully operational and can take over with minimal downtime; cold sites need setup.

50/100 Security Architecture

In a zero trust model, the component that decides whether to grant an access request is the:

โœ– ACCESS DENIED

Every alert is a lesson. Takeaway:

The policy engine makes the access decision; the enforcement point carries it out.

โœ” CONTROL VALIDATED

Sharp call. The SOC would want you on shift.

The policy engine makes the access decision; the enforcement point carries it out.

โœ– ACCESS DENIED

Every alert is a lesson. Takeaway:

The policy engine makes the access decision; the enforcement point carries it out.

โœ– ACCESS DENIED

Every alert is a lesson. Takeaway:

The policy engine makes the access decision; the enforcement point carries it out.

CHECKPOINT โ€” 50 DOWN, STAY SHARP
51/100 Security Architecture

Which technology creates an encrypted tunnel so remote workers can securely access the corporate network over the internet?

โœ– ACCESS DENIED

Reassess and re-secure with this:

A VPN builds an encrypted tunnel across untrusted networks for secure remote access.

โœ” CONTROL VALIDATED

That’s analyst-grade thinking โ€” clean and correct.

A VPN builds an encrypted tunnel across untrusted networks for secure remote access.

โœ– ACCESS DENIED

Reassess and re-secure with this:

A VPN builds an encrypted tunnel across untrusted networks for secure remote access.

โœ– ACCESS DENIED

Reassess and re-secure with this:

A VPN builds an encrypted tunnel across untrusted networks for secure remote access.

52/100 Security Architecture

Dividing a flat network into smaller zones so a breach in one area can’t spread freely is called:

โœ– THREAT DETECTED

Patch your thinking with this:

Network segmentation limits lateral movement by separating systems into isolated zones.

โœ” RISK MITIGATED

Sharp call. The SOC would want you on shift.

Network segmentation limits lateral movement by separating systems into isolated zones.

โœ– THREAT DETECTED

Patch your thinking with this:

Network segmentation limits lateral movement by separating systems into isolated zones.

โœ– THREAT DETECTED

Patch your thinking with this:

Network segmentation limits lateral movement by separating systems into isolated zones.

53/100 Security Architecture

Which RAID level provides redundancy by mirroring all data across two drives?

โœ– ALERT RAISED

Every alert is a lesson. Takeaway:

RAID 1 mirrors data across drives for redundancy; RAID 0 stripes with no fault tolerance.

โœ” CONTROL VALIDATED

You read the risk right. Textbook.

RAID 1 mirrors data across drives for redundancy; RAID 0 stripes with no fault tolerance.

โœ– ALERT RAISED

Every alert is a lesson. Takeaway:

RAID 1 mirrors data across drives for redundancy; RAID 0 stripes with no fault tolerance.

โœ– ALERT RAISED

Every alert is a lesson. Takeaway:

RAID 1 mirrors data across drives for redundancy; RAID 0 stripes with no fault tolerance.

54/100 Security Architecture

Replacing part of a value so only the last four digits of a card number show is an example of data:

โœ– ACCESS DENIED

Patch your thinking with this:

Data masking obscures portions of data (e.g., showing only the last four digits) while keeping it usable.

โœ” RISK MITIGATED

Locked in โ€” that’s how defenders think.

Data masking obscures portions of data (e.g., showing only the last four digits) while keeping it usable.

โœ– ACCESS DENIED

Patch your thinking with this:

Data masking obscures portions of data (e.g., showing only the last four digits) while keeping it usable.

โœ– ACCESS DENIED

Patch your thinking with this:

Data masking obscures portions of data (e.g., showing only the last four digits) while keeping it usable.

55/100 Security Architecture

Labeling data as Public, Internal, Confidential, or Restricted is the practice of data:

โœ” CONTROL VALIDATED

That’s analyst-grade thinking โ€” clean and correct.

Data classification assigns sensitivity levels so appropriate handling and controls can be applied.

โœ– ACCESS DENIED

Every alert is a lesson. Takeaway:

Data classification assigns sensitivity levels so appropriate handling and controls can be applied.

โœ– ACCESS DENIED

Every alert is a lesson. Takeaway:

Data classification assigns sensitivity levels so appropriate handling and controls can be applied.

โœ– ACCESS DENIED

Every alert is a lesson. Takeaway:

Data classification assigns sensitivity levels so appropriate handling and controls can be applied.

56/100 Security Architecture

Which secure protocol should be used to encrypt file transfers instead of plain FTP?

โœ– ACCESS DENIED

Reassess and re-secure with this:

SFTP (over SSH) or FTPS encrypts file transfers, unlike plaintext FTP or TFTP.

โœ– ACCESS DENIED

Reassess and re-secure with this:

SFTP (over SSH) or FTPS encrypts file transfers, unlike plaintext FTP or TFTP.

โœ” CONTROL VALIDATED

Sharp call. The SOC would want you on shift.

SFTP (over SSH) or FTPS encrypts file transfers, unlike plaintext FTP or TFTP.

โœ– ACCESS DENIED

Reassess and re-secure with this:

SFTP (over SSH) or FTPS encrypts file transfers, unlike plaintext FTP or TFTP.

57/100 Security Architecture

Applying a documented, hardened configuration to every new server before deployment establishes a secure:

โœ– ALERT RAISED

Every alert is a lesson. Takeaway:

A secure baseline is a standardized hardened configuration applied consistently across systems.

โœ” CONTROL VALIDATED

You read the risk right. Textbook.

A secure baseline is a standardized hardened configuration applied consistently across systems.

โœ– ALERT RAISED

Every alert is a lesson. Takeaway:

A secure baseline is a standardized hardened configuration applied consistently across systems.

โœ– ALERT RAISED

Every alert is a lesson. Takeaway:

A secure baseline is a standardized hardened configuration applied consistently across systems.

58/100 Security Architecture

Industrial control systems that manage physical processes in utilities and manufacturing are commonly known as:

โœ– ACCESS DENIED

Patch your thinking with this:

ICS/SCADA systems monitor and control physical processes and require specialized security.

โœ– ACCESS DENIED

Patch your thinking with this:

ICS/SCADA systems monitor and control physical processes and require specialized security.

โœ” CONTROL VALIDATED

Locked in โ€” that’s how defenders think.

ICS/SCADA systems monitor and control physical processes and require specialized security.

โœ– ACCESS DENIED

Patch your thinking with this:

ICS/SCADA systems monitor and control physical processes and require specialized security.

59/100 Security Architecture

Which backup strategy captures only the data changed since the last full backup, requiring the full plus the latest one to restore?

โœ” CONTROL VALIDATED

That’s analyst-grade thinking โ€” clean and correct.

A differential backup stores changes since the last full backup; restore needs the full plus latest differential.

โœ– ACCESS DENIED

Every alert is a lesson. Takeaway:

A differential backup stores changes since the last full backup; restore needs the full plus latest differential.

โœ– ACCESS DENIED

Every alert is a lesson. Takeaway:

A differential backup stores changes since the last full backup; restore needs the full plus latest differential.

โœ– ACCESS DENIED

Every alert is a lesson. Takeaway:

A differential backup stores changes since the last full backup; restore needs the full plus latest differential.

60/100 Security Architecture

Running an untrusted file in an isolated environment to observe its behavior safely is called:

โœ– THREAT DETECTED

Reassess and re-secure with this:

Sandboxing isolates code so it can be analyzed or contained without risking the host or network.

โœ– THREAT DETECTED

Reassess and re-secure with this:

Sandboxing isolates code so it can be analyzed or contained without risking the host or network.

โœ– THREAT DETECTED

Reassess and re-secure with this:

Sandboxing isolates code so it can be analyzed or contained without risking the host or network.

โœ” THREAT NEUTRALIZED

Verified. Oluma loves to see it.

Sandboxing isolates code so it can be analyzed or contained without risking the host or network.

CHECKPOINT โ€” 60 DOWN, STAY SHARP
61/100 Security Operations

Which system aggregates and correlates log data from across the enterprise to detect and alert on security events?

โœ” ALERT RESOLVED

That’s analyst-grade thinking โ€” clean and correct.

A SIEM centralizes log collection, correlation, and alerting for security monitoring.

โœ– ALERT RAISED

Every alert is a lesson. Takeaway:

A SIEM centralizes log collection, correlation, and alerting for security monitoring.

โœ– ALERT RAISED

Every alert is a lesson. Takeaway:

A SIEM centralizes log collection, correlation, and alerting for security monitoring.

โœ– ALERT RAISED

Every alert is a lesson. Takeaway:

A SIEM centralizes log collection, correlation, and alerting for security monitoring.

62/100 Security Operations

Which technology automates repetitive response actions by running predefined playbooks across security tools?

โœ– ACCESS DENIED

Reassess and re-secure with this:

SOAR orchestrates and automates response workflows via playbooks to speed up operations.

โœ” ALERT RESOLVED

Sharp call. The SOC would want you on shift.

SOAR orchestrates and automates response workflows via playbooks to speed up operations.

โœ– ACCESS DENIED

Reassess and re-secure with this:

SOAR orchestrates and automates response workflows via playbooks to speed up operations.

โœ– ACCESS DENIED

Reassess and re-secure with this:

SOAR orchestrates and automates response workflows via playbooks to speed up operations.

63/100 Security Operations

What is the correct order of the first three phases of the incident response lifecycle?

โœ” BREACH CONTAINED

That’s analyst-grade thinking โ€” clean and correct.

IR flows: preparation, detection/identification, containment, eradication, recovery, lessons learned.

โœ– ALERT RAISED

Every alert is a lesson. Takeaway:

IR flows: preparation, detection/identification, containment, eradication, recovery, lessons learned.

โœ– ALERT RAISED

Every alert is a lesson. Takeaway:

IR flows: preparation, detection/identification, containment, eradication, recovery, lessons learned.

โœ– ALERT RAISED

Every alert is a lesson. Takeaway:

IR flows: preparation, detection/identification, containment, eradication, recovery, lessons learned.

64/100 Security Operations

Requiring a password plus a code from an authenticator app is an example of:

โœ– ACCESS DENIED

Patch your thinking with this:

MFA combines factors from different categories โ€” here something you know plus something you have.

โœ” IDENTITY VERIFIED

Locked in โ€” that’s how defenders think.

MFA combines factors from different categories โ€” here something you know plus something you have.

โœ– ACCESS DENIED

Patch your thinking with this:

MFA combines factors from different categories โ€” here something you know plus something you have.

โœ– ACCESS DENIED

Patch your thinking with this:

MFA combines factors from different categories โ€” here something you know plus something you have.

65/100 Security Operations

A fingerprint scan represents which authentication factor?

โœ– ACCESS DENIED

Every alert is a lesson. Takeaway:

Biometrics like a fingerprint are “something you are.” Passwords are “something you know.”

โœ– ACCESS DENIED

Every alert is a lesson. Takeaway:

Biometrics like a fingerprint are “something you are.” Passwords are “something you know.”

โœ” IDENTITY VERIFIED

That’s analyst-grade thinking โ€” clean and correct.

Biometrics like a fingerprint are “something you are.” Passwords are “something you know.”

โœ– ACCESS DENIED

Every alert is a lesson. Takeaway:

Biometrics like a fingerprint are “something you are.” Passwords are “something you know.”

66/100 Security Operations

Which approach grants users permissions based on their job function rather than assigning them individually?

โœ– ACCESS DENIED

Reassess and re-secure with this:

Role-based access control (RBAC) assigns permissions to roles that map to job functions.

โœ” POLICY ENFORCED

Sharp call. The SOC would want you on shift.

Role-based access control (RBAC) assigns permissions to roles that map to job functions.

โœ– ACCESS DENIED

Reassess and re-secure with this:

Role-based access control (RBAC) assigns permissions to roles that map to job functions.

โœ– ACCESS DENIED

Reassess and re-secure with this:

Role-based access control (RBAC) assigns permissions to roles that map to job functions.

67/100 Security Operations

A vulnerability scan flags a critical issue, but investigation shows the system is actually patched. This result is a:

โœ– INTEGRITY CHECK FAILED

Patch your thinking with this:

A false positive is an alert for a condition that isn’t actually present.

โœ” ALERT RESOLVED

You read the risk right. Textbook.

A false positive is an alert for a condition that isn’t actually present.

โœ– INTEGRITY CHECK FAILED

Patch your thinking with this:

A false positive is an alert for a condition that isn’t actually present.

โœ– INTEGRITY CHECK FAILED

Patch your thinking with this:

A false positive is an alert for a condition that isn’t actually present.

68/100 Security Operations

Which framework provides a standardized numeric severity score (0โ€“10) for a vulnerability?

โœ– ACCESS DENIED

Every alert is a lesson. Takeaway:

CVSS produces a 0โ€“10 severity score to help prioritize vulnerability remediation.

โœ– ACCESS DENIED

Every alert is a lesson. Takeaway:

CVSS produces a 0โ€“10 severity score to help prioritize vulnerability remediation.

โœ” CONTROL VALIDATED

Locked in โ€” that’s how defenders think.

CVSS produces a 0โ€“10 severity score to help prioritize vulnerability remediation.

โœ– ACCESS DENIED

Every alert is a lesson. Takeaway:

CVSS produces a 0โ€“10 severity score to help prioritize vulnerability remediation.

69/100 Security Operations

In digital forensics, the documentation proving who handled evidence and when is the:

โœ” INTEGRITY CHECK PASSED

That’s analyst-grade thinking โ€” clean and correct.

Chain of custody documents evidence handling to preserve its integrity and admissibility.

โœ– INTEGRITY CHECK FAILED

Reassess and re-secure with this:

Chain of custody documents evidence handling to preserve its integrity and admissibility.

โœ– INTEGRITY CHECK FAILED

Reassess and re-secure with this:

Chain of custody documents evidence handling to preserve its integrity and admissibility.

โœ– INTEGRITY CHECK FAILED

Reassess and re-secure with this:

Chain of custody documents evidence handling to preserve its integrity and admissibility.

70/100 Security Operations

When collecting forensic evidence, which data should be captured first according to the order of volatility?

โœ– ACCESS DENIED

Every alert is a lesson. Takeaway:

Order of volatility says capture the most fleeting data first โ€” CPU registers and RAM before disk.

โœ” INTEGRITY CHECK PASSED

Sharp call. The SOC would want you on shift.

Order of volatility says capture the most fleeting data first โ€” CPU registers and RAM before disk.

โœ– ACCESS DENIED

Every alert is a lesson. Takeaway:

Order of volatility says capture the most fleeting data first โ€” CPU registers and RAM before disk.

โœ– ACCESS DENIED

Every alert is a lesson. Takeaway:

Order of volatility says capture the most fleeting data first โ€” CPU registers and RAM before disk.

CHECKPOINT โ€” 70 DOWN, STAY SHARP
71/100 Security Operations

Which solution continuously monitors endpoints for suspicious behavior and can isolate or roll back a compromised host?

โœ– THREAT DETECTED

Reassess and re-secure with this:

EDR provides continuous endpoint monitoring, detection, and response actions like host isolation.

โœ” THREAT NEUTRALIZED

That’s analyst-grade thinking โ€” clean and correct.

EDR provides continuous endpoint monitoring, detection, and response actions like host isolation.

โœ– THREAT DETECTED

Reassess and re-secure with this:

EDR provides continuous endpoint monitoring, detection, and response actions like host isolation.

โœ– THREAT DETECTED

Reassess and re-secure with this:

EDR provides continuous endpoint monitoring, detection, and response actions like host isolation.

72/100 Security Operations

Which control checks a device’s compliance (patched, AV running) before allowing it onto the corporate network?

โœ” ACCESS GRANTED

Sharp call. The SOC would want you on shift.

Network access control (NAC) assesses device posture and permits or denies network access accordingly.

โœ– ACCESS DENIED

Every alert is a lesson. Takeaway:

Network access control (NAC) assesses device posture and permits or denies network access accordingly.

โœ– ACCESS DENIED

Every alert is a lesson. Takeaway:

Network access control (NAC) assesses device posture and permits or denies network access accordingly.

โœ– ACCESS DENIED

Every alert is a lesson. Takeaway:

Network access control (NAC) assesses device posture and permits or denies network access accordingly.

73/100 Security Operations

Which practice tightly controls, monitors, and time-limits the use of privileged administrator accounts?

โœ– ACCESS DENIED

Reassess and re-secure with this:

Privileged access management (PAM) secures, monitors, and limits the use of admin accounts.

โœ– ACCESS DENIED

Reassess and re-secure with this:

Privileged access management (PAM) secures, monitors, and limits the use of admin accounts.

โœ” CONTROL VALIDATED

You read the risk right. Textbook.

Privileged access management (PAM) secures, monitors, and limits the use of admin accounts.

โœ– ACCESS DENIED

Reassess and re-secure with this:

Privileged access management (PAM) secures, monitors, and limits the use of admin accounts.

74/100 Security Operations

Letting a user log in once and access multiple applications without re-entering credentials is:

โœ– ACCESS DENIED

Every alert is a lesson. Takeaway:

Single sign-on (SSO) lets one authentication grant access to multiple trusted applications.

โœ” ACCESS GRANTED

Locked in โ€” that’s how defenders think.

Single sign-on (SSO) lets one authentication grant access to multiple trusted applications.

โœ– ACCESS DENIED

Every alert is a lesson. Takeaway:

Single sign-on (SSO) lets one authentication grant access to multiple trusted applications.

โœ– ACCESS DENIED

Every alert is a lesson. Takeaway:

Single sign-on (SSO) lets one authentication grant access to multiple trusted applications.

75/100 Security Operations

Immediately disabling accounts and revoking access the moment an employee is terminated is part of:

โœ– ACCESS DENIED

Patch your thinking with this:

Deprovisioning promptly removes access when a user leaves, closing a common security gap.

โœ” ACCESS DENIED โ€” BY DESIGN

That’s analyst-grade thinking โ€” clean and correct.

Deprovisioning promptly removes access when a user leaves, closing a common security gap.

โœ– ACCESS DENIED

Patch your thinking with this:

Deprovisioning promptly removes access when a user leaves, closing a common security gap.

โœ– ACCESS DENIED

Patch your thinking with this:

Deprovisioning promptly removes access when a user leaves, closing a common security gap.

76/100 Security Operations

Which scan type logs into the target with credentials to see vulnerabilities a remote attacker couldn’t, producing deeper results?

โœ” CONTROL VALIDATED

Sharp call. The SOC would want you on shift.

A credentialed scan authenticates to the host, revealing missing patches and config issues in depth.

โœ– ALERT RAISED

Every alert is a lesson. Takeaway:

A credentialed scan authenticates to the host, revealing missing patches and config issues in depth.

โœ– ALERT RAISED

Every alert is a lesson. Takeaway:

A credentialed scan authenticates to the host, revealing missing patches and config issues in depth.

โœ– ALERT RAISED

Every alert is a lesson. Takeaway:

A credentialed scan authenticates to the host, revealing missing patches and config issues in depth.

77/100 Security Operations

A tester is given no prior knowledge of the target environment and must discover everything as an outside attacker would. This is a:

โœ– ACCESS DENIED

Reassess and re-secure with this:

An unknown-environment (black-box) test gives the tester no inside information, simulating an external attacker.

โœ” THREAT NEUTRALIZED

You read the risk right. Textbook.

An unknown-environment (black-box) test gives the tester no inside information, simulating an external attacker.

โœ– ACCESS DENIED

Reassess and re-secure with this:

An unknown-environment (black-box) test gives the tester no inside information, simulating an external attacker.

โœ– ACCESS DENIED

Reassess and re-secure with this:

An unknown-environment (black-box) test gives the tester no inside information, simulating an external attacker.

78/100 Security Operations

Proactively searching networks and endpoints for undetected threats, rather than waiting for alerts, is called:

โœ– THREAT DETECTED

Every alert is a lesson. Takeaway:

Threat hunting proactively looks for adversaries that evaded existing detections.

โœ– THREAT DETECTED

Every alert is a lesson. Takeaway:

Threat hunting proactively looks for adversaries that evaded existing detections.

โœ” THREAT NEUTRALIZED

Locked in โ€” that’s how defenders think.

Threat hunting proactively looks for adversaries that evaded existing detections.

โœ– THREAT DETECTED

Every alert is a lesson. Takeaway:

Threat hunting proactively looks for adversaries that evaded existing detections.

79/100 Security Operations

What is a primary security benefit of automating routine operational tasks with scripts and orchestration?

โœ” CONTROL VALIDATED

That’s analyst-grade thinking โ€” clean and correct.

Automation enforces consistency and speed, cutting the human errors that create security gaps.

โœ– ALERT RAISED

Every alert is a lesson. Takeaway:

Automation enforces consistency and speed, cutting the human errors that create security gaps.

โœ– ALERT RAISED

Every alert is a lesson. Takeaway:

Automation enforces consistency and speed, cutting the human errors that create security gaps.

โœ– ALERT RAISED

Every alert is a lesson. Takeaway:

Automation enforces consistency and speed, cutting the human errors that create security gaps.

80/100 Security Operations

During an active incident, disconnecting an infected host from the network to stop the spread is part of which phase?

โœ– ALERT RAISED

Reassess and re-secure with this:

Containment limits the damage and stops the spread, such as isolating an infected host.

โœ– ALERT RAISED

Reassess and re-secure with this:

Containment limits the damage and stops the spread, such as isolating an infected host.

โœ” BREACH CONTAINED

Verified. Oluma loves to see it.

Containment limits the damage and stops the spread, such as isolating an infected host.

โœ– ALERT RAISED

Reassess and re-secure with this:

Containment limits the damage and stops the spread, such as isolating an infected host.

CHECKPOINT โ€” 80 DOWN, STAY SHARP
81/100 Program Management

A GRC analyst maintains a central document that lists each identified risk with its likelihood, impact, assigned owner, and treatment status. What is this document called?

โœ” RISK MITIGATED

You read the risk right. Textbook.

A risk register is the living record of identified risks, their scoring, ownership, and treatment status.

โœ– ALERT RAISED

Flag it, learn it, move on. Here’s the fix:

A risk register is the living record of identified risks, their scoring, ownership, and treatment status.

โœ– ALERT RAISED

Flag it, learn it, move on. Here’s the fix:

A risk register is the living record of identified risks, their scoring, ownership, and treatment status.

โœ– ALERT RAISED

Flag it, learn it, move on. Here’s the fix:

A risk register is the living record of identified risks, their scoring, ownership, and treatment status.

82/100 Program Management

An organization’s board sets the broad amount of risk it is willing to pursue in order to meet its objectives. Which term describes this?

โœ– THREAT DETECTED

Every alert is a lesson. Takeaway:

Risk appetite is the overall level of risk an organization is willing to accept; tolerance is the acceptable variation around a specific risk.

โœ” POLICY ENFORCED

Locked in โ€” that’s how defenders think.

Risk appetite is the overall level of risk an organization is willing to accept; tolerance is the acceptable variation around a specific risk.

โœ– THREAT DETECTED

Every alert is a lesson. Takeaway:

Risk appetite is the overall level of risk an organization is willing to accept; tolerance is the acceptable variation around a specific risk.

โœ– THREAT DETECTED

Every alert is a lesson. Takeaway:

Risk appetite is the overall level of risk an organization is willing to accept; tolerance is the acceptable variation around a specific risk.

83/100 Program Management

To handle the financial impact of a potential ransomware event, a company purchases a cyber-insurance policy. Which risk treatment strategy is this?

โœ– ACCESS DENIED

Reassess and re-secure with this:

Buying insurance shifts the financial impact to a third party โ€” that is risk transference.

โœ– ACCESS DENIED

Reassess and re-secure with this:

Buying insurance shifts the financial impact to a third party โ€” that is risk transference.

โœ” RISK MITIGATED

Sharp call. The SOC would want you on shift.

Buying insurance shifts the financial impact to a third party โ€” that is risk transference.

โœ– ACCESS DENIED

Reassess and re-secure with this:

Buying insurance shifts the financial impact to a third party โ€” that is risk transference.

84/100 Program Management

After analysis, management decides a low-impact risk would cost more to fix than it could ever cause in damage, and formally chooses to take no action. This is an example of:

โœ” CONTROL VALIDATED

Verified. Oluma loves to see it.

When the cost of a control exceeds the potential loss, formally accepting the risk is a valid treatment.

โœ– ALERT RAISED

Patch your thinking with this:

When the cost of a control exceeds the potential loss, formally accepting the risk is a valid treatment.

โœ– ALERT RAISED

Patch your thinking with this:

When the cost of a control exceeds the potential loss, formally accepting the risk is a valid treatment.

โœ– ALERT RAISED

Patch your thinking with this:

When the cost of a control exceeds the potential loss, formally accepting the risk is a valid treatment.

85/100 Program Management

A single flood could cause $40,000 in damage to a data center, and floods are expected once every 10 years. What is the annualized loss expectancy (ALE)?

โœ– INTEGRITY CHECK FAILED

Flag it, learn it, move on. Here’s the fix:

ALE = SLE x ARO. Here $40,000 x 0.1 = $4,000 expected loss per year.

โœ– INTEGRITY CHECK FAILED

Flag it, learn it, move on. Here’s the fix:

ALE = SLE x ARO. Here $40,000 x 0.1 = $4,000 expected loss per year.

โœ” SIGNATURE MATCHED

That’s analyst-grade thinking โ€” clean and correct.

ALE = SLE x ARO. Here $40,000 x 0.1 = $4,000 expected loss per year.

โœ– INTEGRITY CHECK FAILED

Flag it, learn it, move on. Here’s the fix:

ALE = SLE x ARO. Here $40,000 x 0.1 = $4,000 expected loss per year.

86/100 Program Management

A risk assessment rates risks as ‘high,’ ‘medium,’ or ‘low’ using expert judgment rather than dollar figures. Which type of assessment is this?

โœ– ALERT RAISED

Every alert is a lesson. Takeaway:

Qualitative assessments use descriptive ratings and judgment; quantitative assessments use numeric or monetary values.

โœ” CONTROL VALIDATED

You read the risk right. Textbook.

Qualitative assessments use descriptive ratings and judgment; quantitative assessments use numeric or monetary values.

โœ– ALERT RAISED

Every alert is a lesson. Takeaway:

Qualitative assessments use descriptive ratings and judgment; quantitative assessments use numeric or monetary values.

โœ– ALERT RAISED

Every alert is a lesson. Takeaway:

Qualitative assessments use descriptive ratings and judgment; quantitative assessments use numeric or monetary values.

87/100 Program Management

Business continuity planners define the maximum acceptable length of time a critical system can be down before the impact becomes unacceptable. Which metric is this?

โœ– THREAT DETECTED

Reassess and re-secure with this:

RTO is the target time to restore a system after an outage; RPO is the acceptable amount of data loss measured in time.

โœ– THREAT DETECTED

Reassess and re-secure with this:

RTO is the target time to restore a system after an outage; RPO is the acceptable amount of data loss measured in time.

โœ” ALERT RESOLVED

Locked in โ€” that’s how defenders think.

RTO is the target time to restore a system after an outage; RPO is the acceptable amount of data loss measured in time.

โœ– THREAT DETECTED

Reassess and re-secure with this:

RTO is the target time to restore a system after an outage; RPO is the acceptable amount of data loss measured in time.

88/100 Program Management

A team decides they can tolerate losing at most 15 minutes of data if a database fails, which sets how often backups must run. Which metric does this define?

โœ” RISK MITIGATED

Control validated โ€” nicely done.

RPO is the maximum acceptable data loss expressed as a point in time, which drives backup frequency.

โœ– ALERT RAISED

Patch your thinking with this:

RPO is the maximum acceptable data loss expressed as a point in time, which drives backup frequency.

โœ– ALERT RAISED

Patch your thinking with this:

RPO is the maximum acceptable data loss expressed as a point in time, which drives backup frequency.

โœ– ALERT RAISED

Patch your thinking with this:

RPO is the maximum acceptable data loss expressed as a point in time, which drives backup frequency.

89/100 Program Management

A metric tracks the average time it takes to restore a failed component to normal operation after a fault. Which metric is this?

โœ– INTEGRITY CHECK FAILED

Flag it, learn it, move on. Here’s the fix:

MTTR measures the average time to repair and restore a failed system; MTBF measures the average time between failures.

โœ” ALERT RESOLVED

Sharp call. The SOC would want you on shift.

MTTR measures the average time to repair and restore a failed system; MTBF measures the average time between failures.

โœ– INTEGRITY CHECK FAILED

Flag it, learn it, move on. Here’s the fix:

MTTR measures the average time to repair and restore a failed system; MTBF measures the average time between failures.

โœ– INTEGRITY CHECK FAILED

Flag it, learn it, move on. Here’s the fix:

MTTR measures the average time to repair and restore a failed system; MTBF measures the average time between failures.

90/100 Program Management

Before writing a disaster recovery plan, an organization identifies its critical processes and the impact of their loss over time to prioritize recovery. Which activity is this?

โœ– ALERT RAISED

Every alert is a lesson. Takeaway:

A BIA identifies critical functions and the impact of disruption, driving recovery priorities and metrics like RTO and RPO.

โœ” CONTROL VALIDATED

Verified. Oluma loves to see it.

A BIA identifies critical functions and the impact of disruption, driving recovery priorities and metrics like RTO and RPO.

โœ– ALERT RAISED

Every alert is a lesson. Takeaway:

A BIA identifies critical functions and the impact of disruption, driving recovery priorities and metrics like RTO and RPO.

โœ– ALERT RAISED

Every alert is a lesson. Takeaway:

A BIA identifies critical functions and the impact of disruption, driving recovery priorities and metrics like RTO and RPO.

CHECKPOINT โ€” 90 DOWN, STAY SHARP
91/100 Program Management

A document gives step-by-step instructions for exactly how to revoke a departing employee’s access. Within governance documentation, this is best classified as a:

โœ– ACCESS DENIED

Reassess and re-secure with this:

A procedure is a detailed, step-by-step set of instructions; policies state intent, standards set mandatory rules, and guidelines are recommendations.

โœ– ACCESS DENIED

Reassess and re-secure with this:

A procedure is a detailed, step-by-step set of instructions; policies state intent, standards set mandatory rules, and guidelines are recommendations.

โœ” POLICY ENFORCED

That’s analyst-grade thinking โ€” clean and correct.

A procedure is a detailed, step-by-step set of instructions; policies state intent, standards set mandatory rules, and guidelines are recommendations.

โœ– ACCESS DENIED

Reassess and re-secure with this:

A procedure is a detailed, step-by-step set of instructions; policies state intent, standards set mandatory rules, and guidelines are recommendations.

92/100 Program Management

New employees must sign a document defining what they may and may not do with company laptops, email, and internet access. Which document is this?

โœ” POLICY ENFORCED

Locked in โ€” that’s how defenders think.

An AUP defines acceptable behavior and permitted use of an organization’s systems and resources.

โœ– ALERT RAISED

Patch your thinking with this:

An AUP defines acceptable behavior and permitted use of an organization’s systems and resources.

โœ– ALERT RAISED

Patch your thinking with this:

An AUP defines acceptable behavior and permitted use of an organization’s systems and resources.

โœ– ALERT RAISED

Patch your thinking with this:

An AUP defines acceptable behavior and permitted use of an organization’s systems and resources.

93/100 Program Management

A contract with a cloud provider guarantees 99.9% uptime and defines penalties if that target is missed. Which agreement specifies these measurable service commitments?

โœ– THREAT DETECTED

Flag it, learn it, move on. Here’s the fix:

An SLA defines the measurable level of service, such as uptime, a provider commits to, and often the penalties for falling short.

โœ” CONTROL VALIDATED

You read the risk right. Textbook.

An SLA defines the measurable level of service, such as uptime, a provider commits to, and often the penalties for falling short.

โœ– THREAT DETECTED

Flag it, learn it, move on. Here’s the fix:

An SLA defines the measurable level of service, such as uptime, a provider commits to, and often the penalties for falling short.

โœ– THREAT DETECTED

Flag it, learn it, move on. Here’s the fix:

An SLA defines the measurable level of service, such as uptime, a provider commits to, and often the penalties for falling short.

94/100 Program Management

Two departments document a broad, non-binding understanding of how they intend to cooperate on a project, without strict legal obligations. Which document fits best?

โœ– ALERT RAISED

Every alert is a lesson. Takeaway:

An MOU expresses a mutual, generally non-binding intent to cooperate; it is less formal than a contract like an MSA or SLA.

โœ– ALERT RAISED

Every alert is a lesson. Takeaway:

An MOU expresses a mutual, generally non-binding intent to cooperate; it is less formal than a contract like an MSA or SLA.

โœ” IDENTITY VERIFIED

Control validated โ€” nicely done.

An MOU expresses a mutual, generally non-binding intent to cooperate; it is less formal than a contract like an MSA or SLA.

โœ– ALERT RAISED

Every alert is a lesson. Takeaway:

An MOU expresses a mutual, generally non-binding intent to cooperate; it is less formal than a contract like an MSA or SLA.

95/100 Program Management

Before sharing confidential architecture details with a contractor, a company requires them to sign an agreement that legally binds them to keep the information secret. Which agreement is this?

โœ” POLICY ENFORCED

Sharp call. The SOC would want you on shift.

An NDA legally obligates the parties to protect and not disclose shared confidential information.

โœ– ACCESS DENIED

Reassess and re-secure with this:

An NDA legally obligates the parties to protect and not disclose shared confidential information.

โœ– ACCESS DENIED

Reassess and re-secure with this:

An NDA legally obligates the parties to protect and not disclose shared confidential information.

โœ– ACCESS DENIED

Reassess and re-secure with this:

An NDA legally obligates the parties to protect and not disclose shared confidential information.

96/100 Program Management

Before onboarding a SaaS vendor that will process customer data, a security team reviews the vendor’s certifications, security questionnaires, and past breach history. This process is best described as:

โœ– ALERT RAISED

Patch your thinking with this:

Due diligence is the up-front investigation of a third party’s security posture and risk before entering a relationship.

โœ” RISK MITIGATED

Verified. Oluma loves to see it.

Due diligence is the up-front investigation of a third party’s security posture and risk before entering a relationship.

โœ– ALERT RAISED

Patch your thinking with this:

Due diligence is the up-front investigation of a third party’s security posture and risk before entering a relationship.

โœ– ALERT RAISED

Patch your thinking with this:

Due diligence is the up-front investigation of a third party’s security posture and risk before entering a relationship.

97/100 Program Management

In a data governance model, who is the senior individual accountable for classifying a data set and deciding who may access it, as opposed to the team that maintains it day to day?

โœ– INTEGRITY CHECK FAILED

Flag it, learn it, move on. Here’s the fix:

The data owner is accountable for classification and access decisions; the custodian handles day-to-day storage, backup, and technical protection.

โœ– INTEGRITY CHECK FAILED

Flag it, learn it, move on. Here’s the fix:

The data owner is accountable for classification and access decisions; the custodian handles day-to-day storage, backup, and technical protection.

โœ” IDENTITY VERIFIED

That’s analyst-grade thinking โ€” clean and correct.

The data owner is accountable for classification and access decisions; the custodian handles day-to-day storage, backup, and technical protection.

โœ– INTEGRITY CHECK FAILED

Flag it, learn it, move on. Here’s the fix:

The data owner is accountable for classification and access decisions; the custodian handles day-to-day storage, backup, and technical protection.

98/100 Program Management

Under privacy regulations such as GDPR, the entity that determines the purposes and means of processing personal data is the:

โœ– ALERT RAISED

Every alert is a lesson. Takeaway:

The controller decides why and how personal data is processed; the processor acts on the controller’s instructions.

โœ” IDENTITY VERIFIED

You read the risk right. Textbook.

The controller decides why and how personal data is processed; the processor acts on the controller’s instructions.

โœ– ALERT RAISED

Every alert is a lesson. Takeaway:

The controller decides why and how personal data is processed; the processor acts on the controller’s instructions.

โœ– ALERT RAISED

Every alert is a lesson. Takeaway:

The controller decides why and how personal data is processed; the processor acts on the controller’s instructions.

99/100 Program Management

An online retailer must meet a specific set of security requirements because it stores and processes payment card data. Which compliance standard applies most directly?

โœ– THREAT DETECTED

Reassess and re-secure with this:

PCI DSS is the standard governing the protection of cardholder and payment card data.

โœ– THREAT DETECTED

Reassess and re-secure with this:

PCI DSS is the standard governing the protection of cardholder and payment card data.

โœ” POLICY ENFORCED

Locked in โ€” that’s how defenders think.

PCI DSS is the standard governing the protection of cardholder and payment card data.

โœ– THREAT DETECTED

Reassess and re-secure with this:

PCI DSS is the standard governing the protection of cardholder and payment card data.

100/100 Program Management

After several staff fell for a phishing simulation, the security team rolls out recurring training and simulated phishing to change day-to-day behavior. Which control category does this best represent?

โœ– ALERT RAISED

Patch your thinking with this:

Security awareness training is an administrative control that targets human behavior, often the most-exploited attack surface.

โœ– ALERT RAISED

Patch your thinking with this:

Security awareness training is an administrative control that targets human behavior, often the most-exploited attack surface.

โœ” ACCESS GRANTED

Verified. Oluma loves to see it.

Security awareness training is an administrative control that targets human behavior, often the most-exploited attack surface.

โœ– ALERT RAISED

Patch your thinking with this:

Security awareness training is an administrative control that targets human behavior, often the most-exploited attack surface.

ALL CLEAR — ENTERPRISE SECURED

Nice work, defender. You just worked a full shift of scenarios — and every rep, right or wrong, is how real security judgment gets built.

Your live score is on the board below. Whatever the number, you showed up and put in the work today — that’s the part that compounds.

Gold means a strong area to lock in; the dashed tag means a domain worth another pass. Keep circling back — you’ve got this, friend.

SECURED REVIEWED

These are original practice scenarios written for the Oluma community. CompTIA® and Security+® are registered trademarks of CompTIA, Inc. Oluma is not affiliated with or endorsed by CompTIA. No official exam content is reproduced here — learn the concepts, not the dumps.