🛡 OLUMA CERTIFICATION ZONE Security+Practice Range 100 original scenarios across security concepts, threats & mitigations, architecture, operations and governance (SY0-701). Pick your range and defend the enterprise. START HERE How do you want us to call you? Enter a name to unlock the practice range โ we’ll keep it friendly from here on. ๐ Practice range locked โ enter a name above to begin โ You’re in, defender โ scroll on when you’re ready About the Certification What is CompTIA Security+? Security+ (exam SY0-701) is the industry-standard, vendor-neutral certification that proves you can assess an organization’s security posture, harden hybrid and cloud environments, respond to incidents, and work within governance, risk and compliance. For most people it’s the first security certification worth earning โ and it’s approved as a U.S. DoD 8140 baseline. It’s a strong fit if you’re moving from IT support or networking into security, you’re a GRC or SOC analyst formalizing your skills, or you’re (like much of the Oluma community) breaking into cybersecurity and want a credential employers actually recognize. ๐ก๏ธSecurity AnalystMonitor, triage, and respond to real security events. ๐จSOC / Incident ResponseDetect, contain, and recover from incidents. ๐GRC AnalystMap controls to risk, policy, and compliance. โ๏ธCloud / Systems AdminSecure hybrid, cloud, mobile and IoT environments. Exam CodeSY0-701 QuestionsUp to 90 Time90 minutes Passing Score750 / 900 Exam Objectives The five domains SY0-701 is organized into five weighted domains. Security Operations is the heavyweight at 28% โ spend your study time proportionally. These practice questions are grouped by the same five areas. 1 ยท General Security ConceptsSecurity controls, core principles, change management & cryptography.12% 2 ยท Threats, Vulnerabilities & MitigationsThreat actors, attack surfaces, vulnerabilities and how to mitigate them.22% 3 ยท Security ArchitectureSecure design, segmentation, zero trust, cloud and data protection.18% 4 ยท Security OperationsMonitoring, incident response, vuln management, IAM and automation.28% 5 ยท Security Program Management & OversightGovernance, risk, compliance, policies and third-party risk.20% Official Resources Go straight to the source Bookmark the official CompTIA pages for authoritative details on the exam, current pricing, and the full objectives blueprint. These open in a new tab. ๐Official Certification PageOverview, pricing & how to registerโ ๐Exam Objectives (SY0-701)The official blueprint PDFโ Before You Start Set yourself up to pass A few habits separate people who pass comfortably from people who retake. Keep these in mind while you drill. 1Weight your studySecurity Operations is 28% and Domains 4+5 are nearly half the exam โ don’t overweight the small buckets. 2Think in scenariosMost questions ask what to do in a situation, not just define a term. Practice choosing the BEST response. 3Handle PBQs firstPerformance-based questions appear at the start and eat time. Flag and return if one stalls you. 4Know your acronymsCIA, AAA, SIEM, SOAR, MFA, PKI, IDS/IPS โ the exam assumes fluency. Drill the acronym list. 5Learn the frameworksZero Trust, shared responsibility, risk concepts and control types are named, testable ideas now. 6Read for qualifiersWatch for “BEST,” “MOST likely,” and “FIRST.” The strongest answer wins, not just a correct one. General Security ConceptsThreats & MitigationsSecurity ArchitectureSecurity OperationsProgram Management SELECT YOUR RANGE102550100 01/100 General Security Concepts A company encrypts customer records so that even if the database is stolen, the data cannot be read. Which part of the CIA triad is this protecting? AConfidentialityโ CONTROL VALIDATEDThat’s analyst-grade thinking โ clean and correct.Encryption protects confidentiality by keeping data unreadable to unauthorized parties. BIntegrityโ ALERT RAISEDFlag it, learn it, move on. Here’s the fix:Encryption protects confidentiality by keeping data unreadable to unauthorized parties. CAvailabilityโ ALERT RAISEDFlag it, learn it, move on. Here’s the fix:Encryption protects confidentiality by keeping data unreadable to unauthorized parties. DNon-repudiationโ ALERT RAISEDFlag it, learn it, move on. Here’s the fix:Encryption protects confidentiality by keeping data unreadable to unauthorized parties. 02/100 General Security Concepts A hashing check confirms a downloaded file was not altered in transit. Which security goal does this support? AConfidentialityโ INTEGRITY CHECK FAILEDEvery alert is a lesson. Takeaway:Hashing verifies integrity โ any change to the file changes its hash value. BIntegrityโ SIGNATURE MATCHEDSharp call. The SOC would want you on shift.Hashing verifies integrity โ any change to the file changes its hash value. CAvailabilityโ INTEGRITY CHECK FAILEDEvery alert is a lesson. Takeaway:Hashing verifies integrity โ any change to the file changes its hash value. DAuthenticationโ INTEGRITY CHECK FAILEDEvery alert is a lesson. Takeaway:Hashing verifies integrity โ any change to the file changes its hash value. 03/100 General Security Concepts A firewall rule that blocks traffic is best described as which type of security control by function? APreventiveโ CONTROL VALIDATEDYou read the risk right. Textbook.Preventive controls stop an incident before it happens; a blocking firewall rule is preventive. BDetectiveโ THREAT DETECTEDReassess and re-secure with this:Preventive controls stop an incident before it happens; a blocking firewall rule is preventive. CCorrectiveโ THREAT DETECTEDReassess and re-secure with this:Preventive controls stop an incident before it happens; a blocking firewall rule is preventive. DCompensatingโ THREAT DETECTEDReassess and re-secure with this:Preventive controls stop an incident before it happens; a blocking firewall rule is preventive. 04/100 General Security Concepts Security cameras that record activity in a data center are which type of control by function? APreventiveโ ALERT RAISEDPatch your thinking with this:Cameras detect and record activity, making them detective controls (with a deterrent effect). BDetectiveโ ALERT RESOLVEDLocked in โ that’s how defenders think.Cameras detect and record activity, making them detective controls (with a deterrent effect). CCorrectiveโ ALERT RAISEDPatch your thinking with this:Cameras detect and record activity, making them detective controls (with a deterrent effect). DDirectiveโ ALERT RAISEDPatch your thinking with this:Cameras detect and record activity, making them detective controls (with a deterrent effect). 05/100 General Security Concepts Because it can’t patch a legacy system, a company isolates it on its own VLAN as an alternative safeguard. What control type is this? ADeterrentโ THREAT DETECTEDEvery alert is a lesson. Takeaway:A compensating control is an alternative safeguard used when the primary control isn’t feasible. BDetectiveโ THREAT DETECTEDEvery alert is a lesson. Takeaway:A compensating control is an alternative safeguard used when the primary control isn’t feasible. CCompensatingโ RISK MITIGATEDVerified. Oluma loves to see it.A compensating control is an alternative safeguard used when the primary control isn’t feasible. DDirectiveโ THREAT DETECTEDEvery alert is a lesson. Takeaway:A compensating control is an alternative safeguard used when the primary control isn’t feasible. 06/100 General Security Concepts A digital signature on an email lets the recipient prove who sent it and that the sender can’t deny it. Which property is this? AAvailabilityโ ACCESS DENIEDReassess and re-secure with this:Non-repudiation ensures a sender cannot deny an action; digital signatures provide it. BNon-repudiationโ IDENTITY VERIFIEDThat’s analyst-grade thinking โ clean and correct.Non-repudiation ensures a sender cannot deny an action; digital signatures provide it. CConfidentialityโ ACCESS DENIEDReassess and re-secure with this:Non-repudiation ensures a sender cannot deny an action; digital signatures provide it. DRedundancyโ ACCESS DENIEDReassess and re-secure with this:Non-repudiation ensures a sender cannot deny an action; digital signatures provide it. 07/100 General Security Concepts In the AAA framework, which step confirms that a user is who they claim to be? AAuthenticationโ IDENTITY VERIFIEDSharp call. The SOC would want you on shift.Authentication proves identity; authorization grants access; accounting logs activity. BAuthorizationโ ACCESS DENIEDPatch your thinking with this:Authentication proves identity; authorization grants access; accounting logs activity. CAccountingโ ACCESS DENIEDPatch your thinking with this:Authentication proves identity; authorization grants access; accounting logs activity. DAuditingโ ACCESS DENIEDPatch your thinking with this:Authentication proves identity; authorization grants access; accounting logs activity. 08/100 General Security Concepts A zero trust architecture is built on which core assumption? AEverything inside the perimeter is trustedโ THREAT DETECTEDReassess and re-secure with this:Zero trust assumes no implicit trust; every request is verified regardless of location. BNever trust, always verifyโ CONTROL VALIDATEDYou read the risk right. Textbook.Zero trust assumes no implicit trust; every request is verified regardless of location. CFirewalls make internal traffic safeโ THREAT DETECTEDReassess and re-secure with this:Zero trust assumes no implicit trust; every request is verified regardless of location. DVPN users need no further checksโ THREAT DETECTEDReassess and re-secure with this:Zero trust assumes no implicit trust; every request is verified regardless of location. 09/100 General Security Concepts A security team plants a fake, monitored server to lure and study attackers. What is this called? AA jump serverโ ALERT RAISEDEvery alert is a lesson. Takeaway:A honeypot is a decoy system used to detect, deflect, and study attacker behavior. BA bastion hostโ ALERT RAISEDEvery alert is a lesson. Takeaway:A honeypot is a decoy system used to detect, deflect, and study attacker behavior. CA honeypotโ THREAT NEUTRALIZEDLocked in โ that’s how defenders think.A honeypot is a decoy system used to detect, deflect, and study attacker behavior. DA proxyโ ALERT RAISEDEvery alert is a lesson. Takeaway:A honeypot is a decoy system used to detect, deflect, and study attacker behavior. 10/100 General Security Concepts Before deploying a configuration change to production, an organization requires review, testing, and a rollback plan. This is an example of: AIncident responseโ ACCESS DENIEDPatch your thinking with this:Change management reduces risk through approval, testing, scheduling, and rollback planning. BChange managementโ POLICY ENFORCEDVerified. Oluma loves to see it.Change management reduces risk through approval, testing, scheduling, and rollback planning. CThreat huntingโ ACCESS DENIEDPatch your thinking with this:Change management reduces risk through approval, testing, scheduling, and rollback planning. DPenetration testingโ ACCESS DENIEDPatch your thinking with this:Change management reduces risk through approval, testing, scheduling, and rollback planning. CHECKPOINT โ 10 DOWN, STAY SHARP 11/100 General Security Concepts Which encryption approach uses the same secret key to both encrypt and decrypt data? ASymmetric encryptionโ CONTROL VALIDATEDThat’s analyst-grade thinking โ clean and correct.Symmetric encryption (e.g., AES) uses one shared key; it’s fast but key distribution is the challenge. BAsymmetric encryptionโ ACCESS DENIEDReassess and re-secure with this:Symmetric encryption (e.g., AES) uses one shared key; it’s fast but key distribution is the challenge. CHashingโ ACCESS DENIEDReassess and re-secure with this:Symmetric encryption (e.g., AES) uses one shared key; it’s fast but key distribution is the challenge. DSteganographyโ ACCESS DENIEDReassess and re-secure with this:Symmetric encryption (e.g., AES) uses one shared key; it’s fast but key distribution is the challenge. 12/100 General Security Concepts To send someone confidential data using asymmetric encryption, which key do you encrypt with? AYour own private keyโ ACCESS DENIEDEvery alert is a lesson. Takeaway:Encrypt with the recipient’s public key; only their matching private key can decrypt it. BYour own public keyโ ACCESS DENIEDEvery alert is a lesson. Takeaway:Encrypt with the recipient’s public key; only their matching private key can decrypt it. CThe recipient’s public keyโ IDENTITY VERIFIEDSharp call. The SOC would want you on shift.Encrypt with the recipient’s public key; only their matching private key can decrypt it. DThe recipient’s private keyโ ACCESS DENIEDEvery alert is a lesson. Takeaway:Encrypt with the recipient’s public key; only their matching private key can decrypt it. 13/100 General Security Concepts Adding a unique random value to each password before hashing it defends against precomputed rainbow tables. What is that value called? AA nonceโ INTEGRITY CHECK FAILEDPatch your thinking with this:A salt is unique random data added before hashing, defeating rainbow-table attacks. BA saltโ CONTROL VALIDATEDYou read the risk right. Textbook.A salt is unique random data added before hashing, defeating rainbow-table attacks. CA cipherโ INTEGRITY CHECK FAILEDPatch your thinking with this:A salt is unique random data added before hashing, defeating rainbow-table attacks. DA tokenโ INTEGRITY CHECK FAILEDPatch your thinking with this:A salt is unique random data added before hashing, defeating rainbow-table attacks. 14/100 General Security Concepts What does a Certificate Authority (CA) do in a public key infrastructure? AEncrypts all network trafficโ ACCESS DENIEDReassess and re-secure with this:A CA issues and digitally signs certificates that bind a public key to a verified identity. BStores user passwordsโ ACCESS DENIEDReassess and re-secure with this:A CA issues and digitally signs certificates that bind a public key to a verified identity. CIssues and signs digital certificatesโ IDENTITY VERIFIEDLocked in โ that’s how defenders think.A CA issues and digitally signs certificates that bind a public key to a verified identity. DBlocks malicious IP addressesโ ACCESS DENIEDReassess and re-secure with this:A CA issues and digitally signs certificates that bind a public key to a verified identity. 15/100 General Security Concepts Which technology stores cryptographic keys in tamper-resistant hardware separate from the main system? ASIEMโ THREAT DETECTEDEvery alert is a lesson. Takeaway:A hardware security module (HSM) generates and stores keys in dedicated tamper-resistant hardware. BHSMโ CONTROL VALIDATEDThat’s analyst-grade thinking โ clean and correct.A hardware security module (HSM) generates and stores keys in dedicated tamper-resistant hardware. CDLPโ THREAT DETECTEDEvery alert is a lesson. Takeaway:A hardware security module (HSM) generates and stores keys in dedicated tamper-resistant hardware. DCASBโ THREAT DETECTEDEvery alert is a lesson. Takeaway:A hardware security module (HSM) generates and stores keys in dedicated tamper-resistant hardware. 16/100 General Security Concepts Replacing sensitive card numbers with a non-sensitive substitute value that maps back only in a secure vault is called: AHashingโ ACCESS DENIEDPatch your thinking with this:Tokenization swaps sensitive data for a token that maps back only inside a protected system. BSaltingโ ACCESS DENIEDPatch your thinking with this:Tokenization swaps sensitive data for a token that maps back only inside a protected system. CTokenizationโ RISK MITIGATEDSharp call. The SOC would want you on shift.Tokenization swaps sensitive data for a token that maps back only inside a protected system. DEncodingโ ACCESS DENIEDPatch your thinking with this:Tokenization swaps sensitive data for a token that maps back only inside a protected system. 17/100 General Security Concepts A sign that reads “Authorized Personnel Only” primarily acts as which type of control? ACorrectiveโ ALERT RAISEDReassess and re-secure with this:A warning sign is a deterrent control โ it discourages a would-be violator by threat of consequence. BDeterrentโ CONTROL VALIDATEDYou read the risk right. Textbook.A warning sign is a deterrent control โ it discourages a would-be violator by threat of consequence. CDetectiveโ ALERT RAISEDReassess and re-secure with this:A warning sign is a deterrent control โ it discourages a would-be violator by threat of consequence. DPreventiveโ ALERT RAISEDReassess and re-secure with this:A warning sign is a deterrent control โ it discourages a would-be violator by threat of consequence. 18/100 General Security Concepts A security policy document that tells employees they must complete annual training is which type of control? ADirectiveโ POLICY ENFORCEDLocked in โ that’s how defenders think.Directive controls instruct or require behavior, such as policies mandating training. BDetectiveโ ACCESS DENIEDEvery alert is a lesson. Takeaway:Directive controls instruct or require behavior, such as policies mandating training. CCompensatingโ ACCESS DENIEDEvery alert is a lesson. Takeaway:Directive controls instruct or require behavior, such as policies mandating training. DCorrectiveโ ACCESS DENIEDEvery alert is a lesson. Takeaway:Directive controls instruct or require behavior, such as policies mandating training. 19/100 General Security Concepts Restoring systems from backup after a ransomware attack is best classified as which control by function? APreventiveโ THREAT DETECTEDPatch your thinking with this:Corrective controls restore systems and reduce impact after an incident has occurred. BDeterrentโ THREAT DETECTEDPatch your thinking with this:Corrective controls restore systems and reduce impact after an incident has occurred. CCorrectiveโ BREACH CONTAINEDVerified. Oluma loves to see it.Corrective controls restore systems and reduce impact after an incident has occurred. DDetectiveโ THREAT DETECTEDPatch your thinking with this:Corrective controls restore systems and reduce impact after an incident has occurred. 20/100 General Security Concepts Which cryptographic concept ensures that a compromised session key does not expose past or future session keys? AKey escrowโ ACCESS DENIEDReassess and re-secure with this:Perfect forward secrecy generates unique ephemeral keys per session, isolating any single compromise. BPerfect forward secrecyโ CONTROL VALIDATEDThat’s analyst-grade thinking โ clean and correct.Perfect forward secrecy generates unique ephemeral keys per session, isolating any single compromise. CKey stretchingโ ACCESS DENIEDReassess and re-secure with this:Perfect forward secrecy generates unique ephemeral keys per session, isolating any single compromise. DKey escrow recoveryโ ACCESS DENIEDReassess and re-secure with this:Perfect forward secrecy generates unique ephemeral keys per session, isolating any single compromise. CHECKPOINT โ 20 DOWN, STAY SHARP 21/100 Threats & Mitigations A well-funded, highly skilled attacker backed by a government targets critical infrastructure over many months. Which threat actor is this? ANation-state (APT)โ THREAT NEUTRALIZEDThat’s analyst-grade thinking โ clean and correct.Nation-state actors are highly resourced and persistent, often labeled advanced persistent threats. BScript kiddieโ THREAT DETECTEDReassess and re-secure with this:Nation-state actors are highly resourced and persistent, often labeled advanced persistent threats. CHacktivistโ THREAT DETECTEDReassess and re-secure with this:Nation-state actors are highly resourced and persistent, often labeled advanced persistent threats. DInsider threatโ THREAT DETECTEDReassess and re-secure with this:Nation-state actors are highly resourced and persistent, often labeled advanced persistent threats. 22/100 Threats & Mitigations An attacker calls an employee pretending to be IT support and asks for their password. Which attack is this? ASmishingโ ACCESS DENIEDEvery alert is a lesson. Takeaway:Vishing is voice-based social engineering, using a phone call and a pretext to extract information. BVishingโ THREAT NEUTRALIZEDSharp call. The SOC would want you on shift.Vishing is voice-based social engineering, using a phone call and a pretext to extract information. CTailgatingโ ACCESS DENIEDEvery alert is a lesson. Takeaway:Vishing is voice-based social engineering, using a phone call and a pretext to extract information. DWatering holeโ ACCESS DENIEDEvery alert is a lesson. Takeaway:Vishing is voice-based social engineering, using a phone call and a pretext to extract information. 23/100 Threats & Mitigations Malware that encrypts a victim’s files and demands payment for the decryption key is: AA rootkitโ THREAT DETECTEDPatch your thinking with this:Ransomware encrypts data and extorts the victim for the key or to prevent leaks. BSpywareโ THREAT DETECTEDPatch your thinking with this:Ransomware encrypts data and extorts the victim for the key or to prevent leaks. CRansomwareโ THREAT NEUTRALIZEDYou read the risk right. Textbook.Ransomware encrypts data and extorts the victim for the key or to prevent leaks. DAdwareโ THREAT DETECTEDPatch your thinking with this:Ransomware encrypts data and extorts the victim for the key or to prevent leaks. 24/100 Threats & Mitigations Malicious code that lies dormant until a specific date or condition triggers it is called: AA wormโ ALERT RAISEDReassess and re-secure with this:A logic bomb executes its payload when a set condition or time is met. BA trojanโ ALERT RAISEDReassess and re-secure with this:A logic bomb executes its payload when a set condition or time is met. CA keyloggerโ ALERT RAISEDReassess and re-secure with this:A logic bomb executes its payload when a set condition or time is met. DA logic bombโ THREAT NEUTRALIZEDLocked in โ that’s how defenders think.A logic bomb executes its payload when a set condition or time is met. 25/100 Threats & Mitigations A web form lets an attacker enter ‘ OR ‘1’=’1 to bypass a login. Which attack is this? ASQL injectionโ BREACH CONTAINEDThat’s analyst-grade thinking โ clean and correct.SQL injection inserts crafted input into a query; parameterized queries and input validation mitigate it. BCross-site scriptingโ THREAT DETECTEDEvery alert is a lesson. Takeaway:SQL injection inserts crafted input into a query; parameterized queries and input validation mitigate it. CBuffer overflowโ THREAT DETECTEDEvery alert is a lesson. Takeaway:SQL injection inserts crafted input into a query; parameterized queries and input validation mitigate it. DCSRFโ THREAT DETECTEDEvery alert is a lesson. Takeaway:SQL injection inserts crafted input into a query; parameterized queries and input validation mitigate it. 26/100 Threats & Mitigations An attacker injects a malicious script into a website that then runs in other visitors’ browsers. This is: ASQL injectionโ ACCESS DENIEDPatch your thinking with this:Cross-site scripting (XSS) injects scripts that execute in other users’ browsers; output encoding mitigates it. BCross-site scripting (XSS)โ BREACH CONTAINEDSharp call. The SOC would want you on shift.Cross-site scripting (XSS) injects scripts that execute in other users’ browsers; output encoding mitigates it. CPrivilege escalationโ ACCESS DENIEDPatch your thinking with this:Cross-site scripting (XSS) injects scripts that execute in other users’ browsers; output encoding mitigates it. DReplay attackโ ACCESS DENIEDPatch your thinking with this:Cross-site scripting (XSS) injects scripts that execute in other users’ browsers; output encoding mitigates it. 27/100 Threats & Mitigations An attacker tries a handful of very common passwords against many different accounts to avoid lockouts. This is: ABrute force of one accountโ THREAT DETECTEDReassess and re-secure with this:Password spraying tries a few common passwords across many accounts to avoid triggering lockouts. BPassword sprayingโ THREAT NEUTRALIZEDYou read the risk right. Textbook.Password spraying tries a few common passwords across many accounts to avoid triggering lockouts. CRainbow tableโ THREAT DETECTEDReassess and re-secure with this:Password spraying tries a few common passwords across many accounts to avoid triggering lockouts. DPass-the-hashโ THREAT DETECTEDReassess and re-secure with this:Password spraying tries a few common passwords across many accounts to avoid triggering lockouts. 28/100 Threats & Mitigations A newly discovered flaw with no vendor patch available yet is known as a: AMisconfigurationโ ALERT RAISEDEvery alert is a lesson. Takeaway:A zero-day is a vulnerability unknown to the vendor, with no patch available when exploited. BLegacy vulnerabilityโ ALERT RAISEDEvery alert is a lesson. Takeaway:A zero-day is a vulnerability unknown to the vendor, with no patch available when exploited. CZero-dayโ THREAT NEUTRALIZEDLocked in โ that’s how defenders think.A zero-day is a vulnerability unknown to the vendor, with no patch available when exploited. DRace conditionโ ALERT RAISEDEvery alert is a lesson. Takeaway:A zero-day is a vulnerability unknown to the vendor, with no patch available when exploited. 29/100 Threats & Mitigations A finance employee gets an urgent email that appears to come from the CEO asking for a wire transfer. Which attack is this? ATyposquattingโ ACCESS DENIEDPatch your thinking with this:Business email compromise (a spear-phishing/whaling technique) impersonates an executive to authorize fraud. BBusiness email compromiseโ THREAT NEUTRALIZEDThat’s analyst-grade thinking โ clean and correct.Business email compromise (a spear-phishing/whaling technique) impersonates an executive to authorize fraud. CShoulder surfingโ ACCESS DENIEDPatch your thinking with this:Business email compromise (a spear-phishing/whaling technique) impersonates an executive to authorize fraud. DDumpster divingโ ACCESS DENIEDPatch your thinking with this:Business email compromise (a spear-phishing/whaling technique) impersonates an executive to authorize fraud. 30/100 Threats & Mitigations Which mitigation most directly limits the damage an attacker can do after compromising a single user account? ADisabling loggingโ THREAT DETECTEDReassess and re-secure with this:Least privilege limits each account to only what it needs, containing the blast radius of a compromise. BSharing admin accountsโ THREAT DETECTEDReassess and re-secure with this:Least privilege limits each account to only what it needs, containing the blast radius of a compromise. CPrinciple of least privilegeโ RISK MITIGATEDVerified. Oluma loves to see it.Least privilege limits each account to only what it needs, containing the blast radius of a compromise. DUsing default passwordsโ THREAT DETECTEDReassess and re-secure with this:Least privilege limits each account to only what it needs, containing the blast radius of a compromise. CHECKPOINT โ 30 DOWN, STAY SHARP 31/100 Threats & Mitigations An attacker positions themselves between two communicating hosts to intercept and alter traffic. This is a(n): AOn-path (man-in-the-middle) attackโ BREACH CONTAINEDThat’s analyst-grade thinking โ clean and correct.An on-path attacker intercepts traffic between two parties; encryption and integrity checks defend against it. BDenial-of-service attackโ THREAT DETECTEDEvery alert is a lesson. Takeaway:An on-path attacker intercepts traffic between two parties; encryption and integrity checks defend against it. CBrute-force attackโ THREAT DETECTEDEvery alert is a lesson. Takeaway:An on-path attacker intercepts traffic between two parties; encryption and integrity checks defend against it. DPhishing attackโ THREAT DETECTEDEvery alert is a lesson. Takeaway:An on-path attacker intercepts traffic between two parties; encryption and integrity checks defend against it. 32/100 Threats & Mitigations Malware disguised as a legitimate program that the user installs willingly is a: AWormโ ACCESS DENIEDPatch your thinking with this:A trojan masquerades as legitimate software to trick the user into running it. BTrojanโ THREAT NEUTRALIZEDSharp call. The SOC would want you on shift.A trojan masquerades as legitimate software to trick the user into running it. CRootkitโ ACCESS DENIEDPatch your thinking with this:A trojan masquerades as legitimate software to trick the user into running it. DBotโ ACCESS DENIEDPatch your thinking with this:A trojan masquerades as legitimate software to trick the user into running it. 33/100 Threats & Mitigations An employee downloads free software that secretly installs a compromised update, infecting the whole company. This is an example of a: AInsider threatโ THREAT DETECTEDReassess and re-secure with this:Supply chain attacks compromise trusted software or vendors to reach downstream victims. BSupply chain attackโ THREAT NEUTRALIZEDYou read the risk right. Textbook.Supply chain attacks compromise trusted software or vendors to reach downstream victims. CBrute-force attackโ THREAT DETECTEDReassess and re-secure with this:Supply chain attacks compromise trusted software or vendors to reach downstream victims. DReplay attackโ THREAT DETECTEDReassess and re-secure with this:Supply chain attacks compromise trusted software or vendors to reach downstream victims. 34/100 Threats & Mitigations Unusual outbound traffic to an unknown host at 3 a.m. is best described as a(n): ASecurity controlโ ALERT RAISEDPatch your thinking with this:An indicator of compromise (IoC) is evidence, like anomalous traffic, that a breach may have occurred. BThreat vectorโ ALERT RAISEDPatch your thinking with this:An indicator of compromise (IoC) is evidence, like anomalous traffic, that a breach may have occurred. CIndicator of compromise (IoC)โ THREAT DETECTEDLocked in โ that’s how defenders think.An indicator of compromise (IoC) is evidence, like anomalous traffic, that a breach may have occurred. DRisk appetiteโ ALERT RAISEDPatch your thinking with this:An indicator of compromise (IoC) is evidence, like anomalous traffic, that a breach may have occurred. 35/100 Threats & Mitigations An unauthorized wireless access point secretly plugged into the corporate LAN is a: AEvil twinโ THREAT DETECTEDEvery alert is a lesson. Takeaway:A rogue access point is an unauthorized AP added to a network, creating an unmanaged entry point. BRogue access pointโ THREAT NEUTRALIZEDThat’s analyst-grade thinking โ clean and correct.A rogue access point is an unauthorized AP added to a network, creating an unmanaged entry point. CHoneypotโ THREAT DETECTEDEvery alert is a lesson. Takeaway:A rogue access point is an unauthorized AP added to a network, creating an unmanaged entry point. DJump boxโ THREAT DETECTEDEvery alert is a lesson. Takeaway:A rogue access point is an unauthorized AP added to a network, creating an unmanaged entry point. 36/100 Threats & Mitigations Which mitigation ensures only explicitly approved applications can run on a workstation? AA block listโ ACCESS DENIEDReassess and re-secure with this:Application allow listing permits only approved software to execute, blocking everything else by default. BAntivirus signaturesโ ACCESS DENIEDReassess and re-secure with this:Application allow listing permits only approved software to execute, blocking everything else by default. CApplication allow listingโ CONTROL VALIDATEDSharp call. The SOC would want you on shift.Application allow listing permits only approved software to execute, blocking everything else by default. DPort forwardingโ ACCESS DENIEDReassess and re-secure with this:Application allow listing permits only approved software to execute, blocking everything else by default. 37/100 Threats & Mitigations A disgruntled employee with legitimate access copies confidential files before resigning. This is a(n): ANation-state attackโ THREAT DETECTEDPatch your thinking with this:An insider threat comes from someone with authorized access who misuses it. BInsider threatโ THREAT NEUTRALIZEDYou read the risk right. Textbook.An insider threat comes from someone with authorized access who misuses it. CScript kiddieโ THREAT DETECTEDPatch your thinking with this:An insider threat comes from someone with authorized access who misuses it. DHacktivistโ THREAT DETECTEDPatch your thinking with this:An insider threat comes from someone with authorized access who misuses it. 38/100 Threats & Mitigations Which single mitigation most effectively closes known software vulnerabilities? ATimely patch managementโ VULN PATCHEDThat’s analyst-grade thinking โ clean and correct.Applying vendor patches promptly removes known vulnerabilities before they can be exploited. BLonger passwordsโ ALERT RAISEDEvery alert is a lesson. Takeaway:Applying vendor patches promptly removes known vulnerabilities before they can be exploited. CMore firewallsโ ALERT RAISEDEvery alert is a lesson. Takeaway:Applying vendor patches promptly removes known vulnerabilities before they can be exploited. DDisabling MFAโ ALERT RAISEDEvery alert is a lesson. Takeaway:Applying vendor patches promptly removes known vulnerabilities before they can be exploited. 39/100 Threats & Mitigations An attacker floods a server with traffic from a botnet of thousands of devices to take it offline. This is a: APrivilege escalationโ THREAT DETECTEDReassess and re-secure with this:A distributed denial-of-service (DDoS) attack overwhelms a target from many sources at once. BSQL injectionโ THREAT DETECTEDReassess and re-secure with this:A distributed denial-of-service (DDoS) attack overwhelms a target from many sources at once. CDDoS attackโ THREAT NEUTRALIZEDLocked in โ that’s how defenders think.A distributed denial-of-service (DDoS) attack overwhelms a target from many sources at once. DWatering holeโ THREAT DETECTEDReassess and re-secure with this:A distributed denial-of-service (DDoS) attack overwhelms a target from many sources at once. 40/100 Threats & Mitigations An attacker exploits a flaw to gain higher permissions than their account should have. This is: AData exfiltrationโ ACCESS DENIEDEvery alert is a lesson. Takeaway:Privilege escalation obtains rights beyond those originally granted, often to reach sensitive resources. BPrivilege escalationโ BREACH CONTAINEDVerified. Oluma loves to see it.Privilege escalation obtains rights beyond those originally granted, often to reach sensitive resources. CSocial engineeringโ ACCESS DENIEDEvery alert is a lesson. Takeaway:Privilege escalation obtains rights beyond those originally granted, often to reach sensitive resources. DTailgatingโ ACCESS DENIEDEvery alert is a lesson. Takeaway:Privilege escalation obtains rights beyond those originally granted, often to reach sensitive resources. CHECKPOINT โ 40 DOWN, STAY SHARP 41/100 Security Architecture Placing public-facing web servers in an isolated network segment separated from the internal LAN is called a: AScreened subnet (DMZ)โ CONTROL VALIDATEDThat’s analyst-grade thinking โ clean and correct.A screened subnet isolates internet-facing services so a compromise there can’t directly reach the LAN. BVPN concentratorโ ACCESS DENIEDReassess and re-secure with this:A screened subnet isolates internet-facing services so a compromise there can’t directly reach the LAN. CBroadcast domainโ ACCESS DENIEDReassess and re-secure with this:A screened subnet isolates internet-facing services so a compromise there can’t directly reach the LAN. DTrust zoneโ ACCESS DENIEDReassess and re-secure with this:A screened subnet isolates internet-facing services so a compromise there can’t directly reach the LAN. 42/100 Security Architecture Which device specifically inspects and filters HTTP/HTTPS traffic to protect web applications from attacks like injection? AA routerโ THREAT DETECTEDPatch your thinking with this:A web application firewall (WAF) inspects application-layer web traffic to block attacks like XSS and SQLi. BA web application firewall (WAF)โ CONTROL VALIDATEDSharp call. The SOC would want you on shift.A web application firewall (WAF) inspects application-layer web traffic to block attacks like XSS and SQLi. CA load balancerโ THREAT DETECTEDPatch your thinking with this:A web application firewall (WAF) inspects application-layer web traffic to block attacks like XSS and SQLi. DA switchโ THREAT DETECTEDPatch your thinking with this:A web application firewall (WAF) inspects application-layer web traffic to block attacks like XSS and SQLi. 43/100 Security Architecture In a cloud IaaS model, who is responsible for securing the customer’s operating system and applications? AThe cloud provider aloneโ ACCESS DENIEDEvery alert is a lesson. Takeaway:Under the shared responsibility model for IaaS, the customer secures the OS, apps, and data. BThe customerโ CONTROL VALIDATEDYou read the risk right. Textbook.Under the shared responsibility model for IaaS, the customer secures the OS, apps, and data. CNo oneโ ACCESS DENIEDEvery alert is a lesson. Takeaway:Under the shared responsibility model for IaaS, the customer secures the OS, apps, and data. DThe ISPโ ACCESS DENIEDEvery alert is a lesson. Takeaway:Under the shared responsibility model for IaaS, the customer secures the OS, apps, and data. 44/100 Security Architecture Which solution monitors and enforces security policy for cloud application usage, sitting between users and cloud services? AHSMโ ACCESS DENIEDReassess and re-secure with this:A cloud access security broker (CASB) enforces policy between users and cloud services. BIDSโ ACCESS DENIEDReassess and re-secure with this:A cloud access security broker (CASB) enforces policy between users and cloud services. CCASBโ POLICY ENFORCEDLocked in โ that’s how defenders think.A cloud access security broker (CASB) enforces policy between users and cloud services. DNATโ ACCESS DENIEDReassess and re-secure with this:A cloud access security broker (CASB) enforces policy between users and cloud services. 45/100 Security Architecture Which protocol should replace Telnet to provide encrypted remote administration? ASSHโ CONTROL VALIDATEDThat’s analyst-grade thinking โ clean and correct.SSH encrypts remote administration; Telnet sends everything, including credentials, in cleartext. BFTPโ ACCESS DENIEDEvery alert is a lesson. Takeaway:SSH encrypts remote administration; Telnet sends everything, including credentials, in cleartext. CHTTPโ ACCESS DENIEDEvery alert is a lesson. Takeaway:SSH encrypts remote administration; Telnet sends everything, including credentials, in cleartext. DSNMPv1โ ACCESS DENIEDEvery alert is a lesson. Takeaway:SSH encrypts remote administration; Telnet sends everything, including credentials, in cleartext. 46/100 Security Architecture Which control is designed to detect and block sensitive data (like SSNs) from leaving the organization? ASIEMโ THREAT DETECTEDPatch your thinking with this:Data loss prevention (DLP) inspects data in use, in motion, and at rest to stop unauthorized exfiltration. BDLPโ RISK MITIGATEDSharp call. The SOC would want you on shift.Data loss prevention (DLP) inspects data in use, in motion, and at rest to stop unauthorized exfiltration. CVPNโ THREAT DETECTEDPatch your thinking with this:Data loss prevention (DLP) inspects data in use, in motion, and at rest to stop unauthorized exfiltration. DNACโ THREAT DETECTEDPatch your thinking with this:Data loss prevention (DLP) inspects data in use, in motion, and at rest to stop unauthorized exfiltration. 47/100 Security Architecture Protecting data as it travels across a network is referred to as protecting data: AAt restโ ACCESS DENIEDReassess and re-secure with this:Data in transit is protected with transport encryption such as TLS as it moves across networks. BIn transitโ CONTROL VALIDATEDYou read the risk right. Textbook.Data in transit is protected with transport encryption such as TLS as it moves across networks. CIn useโ ACCESS DENIEDReassess and re-secure with this:Data in transit is protected with transport encryption such as TLS as it moves across networks. DIn escrowโ ACCESS DENIEDReassess and re-secure with this:Data in transit is protected with transport encryption such as TLS as it moves across networks. 48/100 Security Architecture Distributing incoming requests across multiple servers to improve availability and performance is done by a: AProxyโ ALERT RAISEDEvery alert is a lesson. Takeaway:A load balancer spreads traffic across servers, improving availability and resilience. BFirewallโ ALERT RAISEDEvery alert is a lesson. Takeaway:A load balancer spreads traffic across servers, improving availability and resilience. CLoad balancerโ CONTROL VALIDATEDLocked in โ that’s how defenders think.A load balancer spreads traffic across servers, improving availability and resilience. DHoneypotโ ALERT RAISEDEvery alert is a lesson. Takeaway:A load balancer spreads traffic across servers, improving availability and resilience. 49/100 Security Architecture A recovery site that is fully equipped and running, ready to take over almost immediately, is a: AHot siteโ CONTROL VALIDATEDThat’s analyst-grade thinking โ clean and correct.A hot site is fully operational and can take over with minimal downtime; cold sites need setup. BCold siteโ ACCESS DENIEDReassess and re-secure with this:A hot site is fully operational and can take over with minimal downtime; cold sites need setup. CWarm siteโ ACCESS DENIEDReassess and re-secure with this:A hot site is fully operational and can take over with minimal downtime; cold sites need setup. DMobile siteโ ACCESS DENIEDReassess and re-secure with this:A hot site is fully operational and can take over with minimal downtime; cold sites need setup. 50/100 Security Architecture In a zero trust model, the component that decides whether to grant an access request is the: APolicy enforcement pointโ ACCESS DENIEDEvery alert is a lesson. Takeaway:The policy engine makes the access decision; the enforcement point carries it out. BPolicy engineโ CONTROL VALIDATEDSharp call. The SOC would want you on shift.The policy engine makes the access decision; the enforcement point carries it out. CLoad balancerโ ACCESS DENIEDEvery alert is a lesson. Takeaway:The policy engine makes the access decision; the enforcement point carries it out. DTrust anchorโ ACCESS DENIEDEvery alert is a lesson. Takeaway:The policy engine makes the access decision; the enforcement point carries it out. CHECKPOINT โ 50 DOWN, STAY SHARP 51/100 Security Architecture Which technology creates an encrypted tunnel so remote workers can securely access the corporate network over the internet? AVLANโ ACCESS DENIEDReassess and re-secure with this:A VPN builds an encrypted tunnel across untrusted networks for secure remote access. BVPNโ CONTROL VALIDATEDThat’s analyst-grade thinking โ clean and correct.A VPN builds an encrypted tunnel across untrusted networks for secure remote access. CNATโ ACCESS DENIEDReassess and re-secure with this:A VPN builds an encrypted tunnel across untrusted networks for secure remote access. DDNSโ ACCESS DENIEDReassess and re-secure with this:A VPN builds an encrypted tunnel across untrusted networks for secure remote access. 52/100 Security Architecture Dividing a flat network into smaller zones so a breach in one area can’t spread freely is called: APort forwardingโ THREAT DETECTEDPatch your thinking with this:Network segmentation limits lateral movement by separating systems into isolated zones. BSegmentationโ RISK MITIGATEDSharp call. The SOC would want you on shift.Network segmentation limits lateral movement by separating systems into isolated zones. CLoad balancingโ THREAT DETECTEDPatch your thinking with this:Network segmentation limits lateral movement by separating systems into isolated zones. DTunnelingโ THREAT DETECTEDPatch your thinking with this:Network segmentation limits lateral movement by separating systems into isolated zones. 53/100 Security Architecture Which RAID level provides redundancy by mirroring all data across two drives? ARAID 0โ ALERT RAISEDEvery alert is a lesson. Takeaway:RAID 1 mirrors data across drives for redundancy; RAID 0 stripes with no fault tolerance. BRAID 1โ CONTROL VALIDATEDYou read the risk right. Textbook.RAID 1 mirrors data across drives for redundancy; RAID 0 stripes with no fault tolerance. CRAID 0 with no parityโ ALERT RAISEDEvery alert is a lesson. Takeaway:RAID 1 mirrors data across drives for redundancy; RAID 0 stripes with no fault tolerance. DJBODโ ALERT RAISEDEvery alert is a lesson. Takeaway:RAID 1 mirrors data across drives for redundancy; RAID 0 stripes with no fault tolerance. 54/100 Security Architecture Replacing part of a value so only the last four digits of a card number show is an example of data: AEncryptionโ ACCESS DENIEDPatch your thinking with this:Data masking obscures portions of data (e.g., showing only the last four digits) while keeping it usable. BMaskingโ RISK MITIGATEDLocked in โ that’s how defenders think.Data masking obscures portions of data (e.g., showing only the last four digits) while keeping it usable. CHashingโ ACCESS DENIEDPatch your thinking with this:Data masking obscures portions of data (e.g., showing only the last four digits) while keeping it usable. DCompressionโ ACCESS DENIEDPatch your thinking with this:Data masking obscures portions of data (e.g., showing only the last four digits) while keeping it usable. 55/100 Security Architecture Labeling data as Public, Internal, Confidential, or Restricted is the practice of data: AClassificationโ CONTROL VALIDATEDThat’s analyst-grade thinking โ clean and correct.Data classification assigns sensitivity levels so appropriate handling and controls can be applied. BSanitizationโ ACCESS DENIEDEvery alert is a lesson. Takeaway:Data classification assigns sensitivity levels so appropriate handling and controls can be applied. CDeduplicationโ ACCESS DENIEDEvery alert is a lesson. Takeaway:Data classification assigns sensitivity levels so appropriate handling and controls can be applied. DNormalizationโ ACCESS DENIEDEvery alert is a lesson. Takeaway:Data classification assigns sensitivity levels so appropriate handling and controls can be applied. 56/100 Security Architecture Which secure protocol should be used to encrypt file transfers instead of plain FTP? ATFTPโ ACCESS DENIEDReassess and re-secure with this:SFTP (over SSH) or FTPS encrypts file transfers, unlike plaintext FTP or TFTP. BHTTPโ ACCESS DENIEDReassess and re-secure with this:SFTP (over SSH) or FTPS encrypts file transfers, unlike plaintext FTP or TFTP. CSFTPโ CONTROL VALIDATEDSharp call. The SOC would want you on shift.SFTP (over SSH) or FTPS encrypts file transfers, unlike plaintext FTP or TFTP. DTelnetโ ACCESS DENIEDReassess and re-secure with this:SFTP (over SSH) or FTPS encrypts file transfers, unlike plaintext FTP or TFTP. 57/100 Security Architecture Applying a documented, hardened configuration to every new server before deployment establishes a secure: AHoneypotโ ALERT RAISEDEvery alert is a lesson. Takeaway:A secure baseline is a standardized hardened configuration applied consistently across systems. BBaselineโ CONTROL VALIDATEDYou read the risk right. Textbook.A secure baseline is a standardized hardened configuration applied consistently across systems. CSandboxโ ALERT RAISEDEvery alert is a lesson. Takeaway:A secure baseline is a standardized hardened configuration applied consistently across systems. DSnapshotโ ALERT RAISEDEvery alert is a lesson. Takeaway:A secure baseline is a standardized hardened configuration applied consistently across systems. 58/100 Security Architecture Industrial control systems that manage physical processes in utilities and manufacturing are commonly known as: ACDNโ ACCESS DENIEDPatch your thinking with this:ICS/SCADA systems monitor and control physical processes and require specialized security. BCRMโ ACCESS DENIEDPatch your thinking with this:ICS/SCADA systems monitor and control physical processes and require specialized security. CICS/SCADAโ CONTROL VALIDATEDLocked in โ that’s how defenders think.ICS/SCADA systems monitor and control physical processes and require specialized security. DERPโ ACCESS DENIEDPatch your thinking with this:ICS/SCADA systems monitor and control physical processes and require specialized security. 59/100 Security Architecture Which backup strategy captures only the data changed since the last full backup, requiring the full plus the latest one to restore? ADifferentialโ CONTROL VALIDATEDThat’s analyst-grade thinking โ clean and correct.A differential backup stores changes since the last full backup; restore needs the full plus latest differential. BIncrementalโ ACCESS DENIEDEvery alert is a lesson. Takeaway:A differential backup stores changes since the last full backup; restore needs the full plus latest differential. CSnapshot onlyโ ACCESS DENIEDEvery alert is a lesson. Takeaway:A differential backup stores changes since the last full backup; restore needs the full plus latest differential. DFull every timeโ ACCESS DENIEDEvery alert is a lesson. Takeaway:A differential backup stores changes since the last full backup; restore needs the full plus latest differential. 60/100 Security Architecture Running an untrusted file in an isolated environment to observe its behavior safely is called: ATunnelingโ THREAT DETECTEDReassess and re-secure with this:Sandboxing isolates code so it can be analyzed or contained without risking the host or network. BLoad balancingโ THREAT DETECTEDReassess and re-secure with this:Sandboxing isolates code so it can be analyzed or contained without risking the host or network. CClusteringโ THREAT DETECTEDReassess and re-secure with this:Sandboxing isolates code so it can be analyzed or contained without risking the host or network. DSandboxingโ THREAT NEUTRALIZEDVerified. Oluma loves to see it.Sandboxing isolates code so it can be analyzed or contained without risking the host or network. CHECKPOINT โ 60 DOWN, STAY SHARP 61/100 Security Operations Which system aggregates and correlates log data from across the enterprise to detect and alert on security events? ASIEMโ ALERT RESOLVEDThat’s analyst-grade thinking โ clean and correct.A SIEM centralizes log collection, correlation, and alerting for security monitoring. BDHCPโ ALERT RAISEDEvery alert is a lesson. Takeaway:A SIEM centralizes log collection, correlation, and alerting for security monitoring. CVPNโ ALERT RAISEDEvery alert is a lesson. Takeaway:A SIEM centralizes log collection, correlation, and alerting for security monitoring. DNATโ ALERT RAISEDEvery alert is a lesson. Takeaway:A SIEM centralizes log collection, correlation, and alerting for security monitoring. 62/100 Security Operations Which technology automates repetitive response actions by running predefined playbooks across security tools? ADLPโ ACCESS DENIEDReassess and re-secure with this:SOAR orchestrates and automates response workflows via playbooks to speed up operations. BSOARโ ALERT RESOLVEDSharp call. The SOC would want you on shift.SOAR orchestrates and automates response workflows via playbooks to speed up operations. CCASBโ ACCESS DENIEDReassess and re-secure with this:SOAR orchestrates and automates response workflows via playbooks to speed up operations. DPKIโ ACCESS DENIEDReassess and re-secure with this:SOAR orchestrates and automates response workflows via playbooks to speed up operations. 63/100 Security Operations What is the correct order of the first three phases of the incident response lifecycle? APreparation โ Detection โ Containmentโ BREACH CONTAINEDThat’s analyst-grade thinking โ clean and correct.IR flows: preparation, detection/identification, containment, eradication, recovery, lessons learned. BRecovery โ Detection โ Preparationโ ALERT RAISEDEvery alert is a lesson. Takeaway:IR flows: preparation, detection/identification, containment, eradication, recovery, lessons learned. CContainment โ Preparation โ Recoveryโ ALERT RAISEDEvery alert is a lesson. Takeaway:IR flows: preparation, detection/identification, containment, eradication, recovery, lessons learned. DEradication โ Recovery โ Detectionโ ALERT RAISEDEvery alert is a lesson. Takeaway:IR flows: preparation, detection/identification, containment, eradication, recovery, lessons learned. 64/100 Security Operations Requiring a password plus a code from an authenticator app is an example of: ASingle sign-onโ ACCESS DENIEDPatch your thinking with this:MFA combines factors from different categories โ here something you know plus something you have. BMultifactor authenticationโ IDENTITY VERIFIEDLocked in โ that’s how defenders think.MFA combines factors from different categories โ here something you know plus something you have. CFederationโ ACCESS DENIEDPatch your thinking with this:MFA combines factors from different categories โ here something you know plus something you have. DAccountingโ ACCESS DENIEDPatch your thinking with this:MFA combines factors from different categories โ here something you know plus something you have. 65/100 Security Operations A fingerprint scan represents which authentication factor? ASomething you knowโ ACCESS DENIEDEvery alert is a lesson. Takeaway:Biometrics like a fingerprint are “something you are.” Passwords are “something you know.” BSomething you haveโ ACCESS DENIEDEvery alert is a lesson. Takeaway:Biometrics like a fingerprint are “something you are.” Passwords are “something you know.” CSomething you areโ IDENTITY VERIFIEDThat’s analyst-grade thinking โ clean and correct.Biometrics like a fingerprint are “something you are.” Passwords are “something you know.” DSomewhere you areโ ACCESS DENIEDEvery alert is a lesson. Takeaway:Biometrics like a fingerprint are “something you are.” Passwords are “something you know.” 66/100 Security Operations Which approach grants users permissions based on their job function rather than assigning them individually? ADiscretionary access controlโ ACCESS DENIEDReassess and re-secure with this:Role-based access control (RBAC) assigns permissions to roles that map to job functions. BRole-based access controlโ POLICY ENFORCEDSharp call. The SOC would want you on shift.Role-based access control (RBAC) assigns permissions to roles that map to job functions. COpen accessโ ACCESS DENIEDReassess and re-secure with this:Role-based access control (RBAC) assigns permissions to roles that map to job functions. DRule-of-thumb accessโ ACCESS DENIEDReassess and re-secure with this:Role-based access control (RBAC) assigns permissions to roles that map to job functions. 67/100 Security Operations A vulnerability scan flags a critical issue, but investigation shows the system is actually patched. This result is a: ATrue positiveโ INTEGRITY CHECK FAILEDPatch your thinking with this:A false positive is an alert for a condition that isn’t actually present. BFalse positiveโ ALERT RESOLVEDYou read the risk right. Textbook.A false positive is an alert for a condition that isn’t actually present. CFalse negativeโ INTEGRITY CHECK FAILEDPatch your thinking with this:A false positive is an alert for a condition that isn’t actually present. DTrue negativeโ INTEGRITY CHECK FAILEDPatch your thinking with this:A false positive is an alert for a condition that isn’t actually present. 68/100 Security Operations Which framework provides a standardized numeric severity score (0โ10) for a vulnerability? AMITRE ATT&CKโ ACCESS DENIEDEvery alert is a lesson. Takeaway:CVSS produces a 0โ10 severity score to help prioritize vulnerability remediation. BOWASPโ ACCESS DENIEDEvery alert is a lesson. Takeaway:CVSS produces a 0โ10 severity score to help prioritize vulnerability remediation. CCVSSโ CONTROL VALIDATEDLocked in โ that’s how defenders think.CVSS produces a 0โ10 severity score to help prioritize vulnerability remediation. DSTIXโ ACCESS DENIEDEvery alert is a lesson. Takeaway:CVSS produces a 0โ10 severity score to help prioritize vulnerability remediation. 69/100 Security Operations In digital forensics, the documentation proving who handled evidence and when is the: AChain of custodyโ INTEGRITY CHECK PASSEDThat’s analyst-grade thinking โ clean and correct.Chain of custody documents evidence handling to preserve its integrity and admissibility. BOrder of volatilityโ INTEGRITY CHECK FAILEDReassess and re-secure with this:Chain of custody documents evidence handling to preserve its integrity and admissibility. CLegal holdโ INTEGRITY CHECK FAILEDReassess and re-secure with this:Chain of custody documents evidence handling to preserve its integrity and admissibility. DData retentionโ INTEGRITY CHECK FAILEDReassess and re-secure with this:Chain of custody documents evidence handling to preserve its integrity and admissibility. 70/100 Security Operations When collecting forensic evidence, which data should be captured first according to the order of volatility? AData on a backup tapeโ ACCESS DENIEDEvery alert is a lesson. Takeaway:Order of volatility says capture the most fleeting data first โ CPU registers and RAM before disk. BContents of RAMโ INTEGRITY CHECK PASSEDSharp call. The SOC would want you on shift.Order of volatility says capture the most fleeting data first โ CPU registers and RAM before disk. CFiles on a hard driveโ ACCESS DENIEDEvery alert is a lesson. Takeaway:Order of volatility says capture the most fleeting data first โ CPU registers and RAM before disk. DArchived logsโ ACCESS DENIEDEvery alert is a lesson. Takeaway:Order of volatility says capture the most fleeting data first โ CPU registers and RAM before disk. CHECKPOINT โ 70 DOWN, STAY SHARP 71/100 Security Operations Which solution continuously monitors endpoints for suspicious behavior and can isolate or roll back a compromised host? ARouter ACLโ THREAT DETECTEDReassess and re-secure with this:EDR provides continuous endpoint monitoring, detection, and response actions like host isolation. BEDRโ THREAT NEUTRALIZEDThat’s analyst-grade thinking โ clean and correct.EDR provides continuous endpoint monitoring, detection, and response actions like host isolation. CDHCPโ THREAT DETECTEDReassess and re-secure with this:EDR provides continuous endpoint monitoring, detection, and response actions like host isolation. DSMTP relayโ THREAT DETECTEDReassess and re-secure with this:EDR provides continuous endpoint monitoring, detection, and response actions like host isolation. 72/100 Security Operations Which control checks a device’s compliance (patched, AV running) before allowing it onto the corporate network? ANACโ ACCESS GRANTEDSharp call. The SOC would want you on shift.Network access control (NAC) assesses device posture and permits or denies network access accordingly. BDLPโ ACCESS DENIEDEvery alert is a lesson. Takeaway:Network access control (NAC) assesses device posture and permits or denies network access accordingly. CSIEMโ ACCESS DENIEDEvery alert is a lesson. Takeaway:Network access control (NAC) assesses device posture and permits or denies network access accordingly. DPKIโ ACCESS DENIEDEvery alert is a lesson. Takeaway:Network access control (NAC) assesses device posture and permits or denies network access accordingly. 73/100 Security Operations Which practice tightly controls, monitors, and time-limits the use of privileged administrator accounts? ASSOโ ACCESS DENIEDReassess and re-secure with this:Privileged access management (PAM) secures, monitors, and limits the use of admin accounts. BFederationโ ACCESS DENIEDReassess and re-secure with this:Privileged access management (PAM) secures, monitors, and limits the use of admin accounts. CPAMโ CONTROL VALIDATEDYou read the risk right. Textbook.Privileged access management (PAM) secures, monitors, and limits the use of admin accounts. DCASBโ ACCESS DENIEDReassess and re-secure with this:Privileged access management (PAM) secures, monitors, and limits the use of admin accounts. 74/100 Security Operations Letting a user log in once and access multiple applications without re-entering credentials is: APAMโ ACCESS DENIEDEvery alert is a lesson. Takeaway:Single sign-on (SSO) lets one authentication grant access to multiple trusted applications. BSingle sign-on (SSO)โ ACCESS GRANTEDLocked in โ that’s how defenders think.Single sign-on (SSO) lets one authentication grant access to multiple trusted applications. CNACโ ACCESS DENIEDEvery alert is a lesson. Takeaway:Single sign-on (SSO) lets one authentication grant access to multiple trusted applications. DDLPโ ACCESS DENIEDEvery alert is a lesson. Takeaway:Single sign-on (SSO) lets one authentication grant access to multiple trusted applications. 75/100 Security Operations Immediately disabling accounts and revoking access the moment an employee is terminated is part of: AOnboardingโ ACCESS DENIEDPatch your thinking with this:Deprovisioning promptly removes access when a user leaves, closing a common security gap. BDeprovisioning (offboarding)โ ACCESS DENIED โ BY DESIGNThat’s analyst-grade thinking โ clean and correct.Deprovisioning promptly removes access when a user leaves, closing a common security gap. CFederationโ ACCESS DENIEDPatch your thinking with this:Deprovisioning promptly removes access when a user leaves, closing a common security gap. DAccountingโ ACCESS DENIEDPatch your thinking with this:Deprovisioning promptly removes access when a user leaves, closing a common security gap. 76/100 Security Operations Which scan type logs into the target with credentials to see vulnerabilities a remote attacker couldn’t, producing deeper results? ACredentialed scanโ CONTROL VALIDATEDSharp call. The SOC would want you on shift.A credentialed scan authenticates to the host, revealing missing patches and config issues in depth. BNon-credentialed scanโ ALERT RAISEDEvery alert is a lesson. Takeaway:A credentialed scan authenticates to the host, revealing missing patches and config issues in depth. CPassive scanโ ALERT RAISEDEvery alert is a lesson. Takeaway:A credentialed scan authenticates to the host, revealing missing patches and config issues in depth. DPort scanโ ALERT RAISEDEvery alert is a lesson. Takeaway:A credentialed scan authenticates to the host, revealing missing patches and config issues in depth. 77/100 Security Operations A tester is given no prior knowledge of the target environment and must discover everything as an outside attacker would. This is a: AWhite-box testโ ACCESS DENIEDReassess and re-secure with this:An unknown-environment (black-box) test gives the tester no inside information, simulating an external attacker. BBlack-box (unknown environment) testโ THREAT NEUTRALIZEDYou read the risk right. Textbook.An unknown-environment (black-box) test gives the tester no inside information, simulating an external attacker. CCredentialed scanโ ACCESS DENIEDReassess and re-secure with this:An unknown-environment (black-box) test gives the tester no inside information, simulating an external attacker. DCompliance auditโ ACCESS DENIEDReassess and re-secure with this:An unknown-environment (black-box) test gives the tester no inside information, simulating an external attacker. 78/100 Security Operations Proactively searching networks and endpoints for undetected threats, rather than waiting for alerts, is called: APatch managementโ THREAT DETECTEDEvery alert is a lesson. Takeaway:Threat hunting proactively looks for adversaries that evaded existing detections. BChange managementโ THREAT DETECTEDEvery alert is a lesson. Takeaway:Threat hunting proactively looks for adversaries that evaded existing detections. CThreat huntingโ THREAT NEUTRALIZEDLocked in โ that’s how defenders think.Threat hunting proactively looks for adversaries that evaded existing detections. DProvisioningโ THREAT DETECTEDEvery alert is a lesson. Takeaway:Threat hunting proactively looks for adversaries that evaded existing detections. 79/100 Security Operations What is a primary security benefit of automating routine operational tasks with scripts and orchestration? AConsistent, repeatable execution that reduces human errorโ CONTROL VALIDATEDThat’s analyst-grade thinking โ clean and correct.Automation enforces consistency and speed, cutting the human errors that create security gaps. BIt removes the need for any loggingโ ALERT RAISEDEvery alert is a lesson. Takeaway:Automation enforces consistency and speed, cutting the human errors that create security gaps. CIt guarantees zero vulnerabilitiesโ ALERT RAISEDEvery alert is a lesson. Takeaway:Automation enforces consistency and speed, cutting the human errors that create security gaps. DIt eliminates the need for MFAโ ALERT RAISEDEvery alert is a lesson. Takeaway:Automation enforces consistency and speed, cutting the human errors that create security gaps. 80/100 Security Operations During an active incident, disconnecting an infected host from the network to stop the spread is part of which phase? APreparationโ ALERT RAISEDReassess and re-secure with this:Containment limits the damage and stops the spread, such as isolating an infected host. BLessons learnedโ ALERT RAISEDReassess and re-secure with this:Containment limits the damage and stops the spread, such as isolating an infected host. CContainmentโ BREACH CONTAINEDVerified. Oluma loves to see it.Containment limits the damage and stops the spread, such as isolating an infected host. DRecoveryโ ALERT RAISEDReassess and re-secure with this:Containment limits the damage and stops the spread, such as isolating an infected host. CHECKPOINT โ 80 DOWN, STAY SHARP 81/100 Program Management A GRC analyst maintains a central document that lists each identified risk with its likelihood, impact, assigned owner, and treatment status. What is this document called? AA risk registerโ RISK MITIGATEDYou read the risk right. Textbook.A risk register is the living record of identified risks, their scoring, ownership, and treatment status. BAn incident reportโ ALERT RAISEDFlag it, learn it, move on. Here’s the fix:A risk register is the living record of identified risks, their scoring, ownership, and treatment status. CA business impact analysisโ ALERT RAISEDFlag it, learn it, move on. Here’s the fix:A risk register is the living record of identified risks, their scoring, ownership, and treatment status. DAn acceptable use policyโ ALERT RAISEDFlag it, learn it, move on. Here’s the fix:A risk register is the living record of identified risks, their scoring, ownership, and treatment status. 82/100 Program Management An organization’s board sets the broad amount of risk it is willing to pursue in order to meet its objectives. Which term describes this? ARisk toleranceโ THREAT DETECTEDEvery alert is a lesson. Takeaway:Risk appetite is the overall level of risk an organization is willing to accept; tolerance is the acceptable variation around a specific risk. BRisk appetiteโ POLICY ENFORCEDLocked in โ that’s how defenders think.Risk appetite is the overall level of risk an organization is willing to accept; tolerance is the acceptable variation around a specific risk. CResidual riskโ THREAT DETECTEDEvery alert is a lesson. Takeaway:Risk appetite is the overall level of risk an organization is willing to accept; tolerance is the acceptable variation around a specific risk. DInherent riskโ THREAT DETECTEDEvery alert is a lesson. Takeaway:Risk appetite is the overall level of risk an organization is willing to accept; tolerance is the acceptable variation around a specific risk. 83/100 Program Management To handle the financial impact of a potential ransomware event, a company purchases a cyber-insurance policy. Which risk treatment strategy is this? ARisk avoidanceโ ACCESS DENIEDReassess and re-secure with this:Buying insurance shifts the financial impact to a third party โ that is risk transference. BRisk acceptanceโ ACCESS DENIEDReassess and re-secure with this:Buying insurance shifts the financial impact to a third party โ that is risk transference. CRisk transferenceโ RISK MITIGATEDSharp call. The SOC would want you on shift.Buying insurance shifts the financial impact to a third party โ that is risk transference. DRisk mitigationโ ACCESS DENIEDReassess and re-secure with this:Buying insurance shifts the financial impact to a third party โ that is risk transference. 84/100 Program Management After analysis, management decides a low-impact risk would cost more to fix than it could ever cause in damage, and formally chooses to take no action. This is an example of: ARisk acceptanceโ CONTROL VALIDATEDVerified. Oluma loves to see it.When the cost of a control exceeds the potential loss, formally accepting the risk is a valid treatment. BRisk avoidanceโ ALERT RAISEDPatch your thinking with this:When the cost of a control exceeds the potential loss, formally accepting the risk is a valid treatment. CRisk transferenceโ ALERT RAISEDPatch your thinking with this:When the cost of a control exceeds the potential loss, formally accepting the risk is a valid treatment. DRisk mitigationโ ALERT RAISEDPatch your thinking with this:When the cost of a control exceeds the potential loss, formally accepting the risk is a valid treatment. 85/100 Program Management A single flood could cause $40,000 in damage to a data center, and floods are expected once every 10 years. What is the annualized loss expectancy (ALE)? A$400,000โ INTEGRITY CHECK FAILEDFlag it, learn it, move on. Here’s the fix:ALE = SLE x ARO. Here $40,000 x 0.1 = $4,000 expected loss per year. B$40,000โ INTEGRITY CHECK FAILEDFlag it, learn it, move on. Here’s the fix:ALE = SLE x ARO. Here $40,000 x 0.1 = $4,000 expected loss per year. C$4,000โ SIGNATURE MATCHEDThat’s analyst-grade thinking โ clean and correct.ALE = SLE x ARO. Here $40,000 x 0.1 = $4,000 expected loss per year. D$400โ INTEGRITY CHECK FAILEDFlag it, learn it, move on. Here’s the fix:ALE = SLE x ARO. Here $40,000 x 0.1 = $4,000 expected loss per year. 86/100 Program Management A risk assessment rates risks as ‘high,’ ‘medium,’ or ‘low’ using expert judgment rather than dollar figures. Which type of assessment is this? AQuantitativeโ ALERT RAISEDEvery alert is a lesson. Takeaway:Qualitative assessments use descriptive ratings and judgment; quantitative assessments use numeric or monetary values. BQualitativeโ CONTROL VALIDATEDYou read the risk right. Textbook.Qualitative assessments use descriptive ratings and judgment; quantitative assessments use numeric or monetary values. CActuarialโ ALERT RAISEDEvery alert is a lesson. Takeaway:Qualitative assessments use descriptive ratings and judgment; quantitative assessments use numeric or monetary values. DProbabilisticโ ALERT RAISEDEvery alert is a lesson. Takeaway:Qualitative assessments use descriptive ratings and judgment; quantitative assessments use numeric or monetary values. 87/100 Program Management Business continuity planners define the maximum acceptable length of time a critical system can be down before the impact becomes unacceptable. Which metric is this? ARecovery point objective (RPO)โ THREAT DETECTEDReassess and re-secure with this:RTO is the target time to restore a system after an outage; RPO is the acceptable amount of data loss measured in time. BMean time between failures (MTBF)โ THREAT DETECTEDReassess and re-secure with this:RTO is the target time to restore a system after an outage; RPO is the acceptable amount of data loss measured in time. CRecovery time objective (RTO)โ ALERT RESOLVEDLocked in โ that’s how defenders think.RTO is the target time to restore a system after an outage; RPO is the acceptable amount of data loss measured in time. DMean time to repair (MTTR)โ THREAT DETECTEDReassess and re-secure with this:RTO is the target time to restore a system after an outage; RPO is the acceptable amount of data loss measured in time. 88/100 Program Management A team decides they can tolerate losing at most 15 minutes of data if a database fails, which sets how often backups must run. Which metric does this define? ARecovery point objective (RPO)โ RISK MITIGATEDControl validated โ nicely done.RPO is the maximum acceptable data loss expressed as a point in time, which drives backup frequency. BRecovery time objective (RTO)โ ALERT RAISEDPatch your thinking with this:RPO is the maximum acceptable data loss expressed as a point in time, which drives backup frequency. CMean time to detect (MTTD)โ ALERT RAISEDPatch your thinking with this:RPO is the maximum acceptable data loss expressed as a point in time, which drives backup frequency. DService level agreement (SLA)โ ALERT RAISEDPatch your thinking with this:RPO is the maximum acceptable data loss expressed as a point in time, which drives backup frequency. 89/100 Program Management A metric tracks the average time it takes to restore a failed component to normal operation after a fault. Which metric is this? AMean time between failures (MTBF)โ INTEGRITY CHECK FAILEDFlag it, learn it, move on. Here’s the fix:MTTR measures the average time to repair and restore a failed system; MTBF measures the average time between failures. BMean time to repair (MTTR)โ ALERT RESOLVEDSharp call. The SOC would want you on shift.MTTR measures the average time to repair and restore a failed system; MTBF measures the average time between failures. CRecovery point objective (RPO)โ INTEGRITY CHECK FAILEDFlag it, learn it, move on. Here’s the fix:MTTR measures the average time to repair and restore a failed system; MTBF measures the average time between failures. DAnnualized rate of occurrence (ARO)โ INTEGRITY CHECK FAILEDFlag it, learn it, move on. Here’s the fix:MTTR measures the average time to repair and restore a failed system; MTBF measures the average time between failures. 90/100 Program Management Before writing a disaster recovery plan, an organization identifies its critical processes and the impact of their loss over time to prioritize recovery. Which activity is this? APenetration testโ ALERT RAISEDEvery alert is a lesson. Takeaway:A BIA identifies critical functions and the impact of disruption, driving recovery priorities and metrics like RTO and RPO. BBusiness impact analysis (BIA)โ CONTROL VALIDATEDVerified. Oluma loves to see it.A BIA identifies critical functions and the impact of disruption, driving recovery priorities and metrics like RTO and RPO. CVulnerability scanโ ALERT RAISEDEvery alert is a lesson. Takeaway:A BIA identifies critical functions and the impact of disruption, driving recovery priorities and metrics like RTO and RPO. DThreat huntโ ALERT RAISEDEvery alert is a lesson. Takeaway:A BIA identifies critical functions and the impact of disruption, driving recovery priorities and metrics like RTO and RPO. CHECKPOINT โ 90 DOWN, STAY SHARP 91/100 Program Management A document gives step-by-step instructions for exactly how to revoke a departing employee’s access. Within governance documentation, this is best classified as a: APolicyโ ACCESS DENIEDReassess and re-secure with this:A procedure is a detailed, step-by-step set of instructions; policies state intent, standards set mandatory rules, and guidelines are recommendations. BStandardโ ACCESS DENIEDReassess and re-secure with this:A procedure is a detailed, step-by-step set of instructions; policies state intent, standards set mandatory rules, and guidelines are recommendations. CProcedureโ POLICY ENFORCEDThat’s analyst-grade thinking โ clean and correct.A procedure is a detailed, step-by-step set of instructions; policies state intent, standards set mandatory rules, and guidelines are recommendations. DGuidelineโ ACCESS DENIEDReassess and re-secure with this:A procedure is a detailed, step-by-step set of instructions; policies state intent, standards set mandatory rules, and guidelines are recommendations. 92/100 Program Management New employees must sign a document defining what they may and may not do with company laptops, email, and internet access. Which document is this? AAcceptable use policy (AUP)โ POLICY ENFORCEDLocked in โ that’s how defenders think.An AUP defines acceptable behavior and permitted use of an organization’s systems and resources. BBusiness partner agreement (BPA)โ ALERT RAISEDPatch your thinking with this:An AUP defines acceptable behavior and permitted use of an organization’s systems and resources. CMemorandum of understanding (MOU)โ ALERT RAISEDPatch your thinking with this:An AUP defines acceptable behavior and permitted use of an organization’s systems and resources. DService level agreement (SLA)โ ALERT RAISEDPatch your thinking with this:An AUP defines acceptable behavior and permitted use of an organization’s systems and resources. 93/100 Program Management A contract with a cloud provider guarantees 99.9% uptime and defines penalties if that target is missed. Which agreement specifies these measurable service commitments? ANon-disclosure agreement (NDA)โ THREAT DETECTEDFlag it, learn it, move on. Here’s the fix:An SLA defines the measurable level of service, such as uptime, a provider commits to, and often the penalties for falling short. BService level agreement (SLA)โ CONTROL VALIDATEDYou read the risk right. Textbook.An SLA defines the measurable level of service, such as uptime, a provider commits to, and often the penalties for falling short. CMemorandum of understanding (MOU)โ THREAT DETECTEDFlag it, learn it, move on. Here’s the fix:An SLA defines the measurable level of service, such as uptime, a provider commits to, and often the penalties for falling short. DAcceptable use policy (AUP)โ THREAT DETECTEDFlag it, learn it, move on. Here’s the fix:An SLA defines the measurable level of service, such as uptime, a provider commits to, and often the penalties for falling short. 94/100 Program Management Two departments document a broad, non-binding understanding of how they intend to cooperate on a project, without strict legal obligations. Which document fits best? AService level agreement (SLA)โ ALERT RAISEDEvery alert is a lesson. Takeaway:An MOU expresses a mutual, generally non-binding intent to cooperate; it is less formal than a contract like an MSA or SLA. BMaster service agreement (MSA)โ ALERT RAISEDEvery alert is a lesson. Takeaway:An MOU expresses a mutual, generally non-binding intent to cooperate; it is less formal than a contract like an MSA or SLA. CMemorandum of understanding (MOU)โ IDENTITY VERIFIEDControl validated โ nicely done.An MOU expresses a mutual, generally non-binding intent to cooperate; it is less formal than a contract like an MSA or SLA. DNon-disclosure agreement (NDA)โ ALERT RAISEDEvery alert is a lesson. Takeaway:An MOU expresses a mutual, generally non-binding intent to cooperate; it is less formal than a contract like an MSA or SLA. 95/100 Program Management Before sharing confidential architecture details with a contractor, a company requires them to sign an agreement that legally binds them to keep the information secret. Which agreement is this? ANon-disclosure agreement (NDA)โ POLICY ENFORCEDSharp call. The SOC would want you on shift.An NDA legally obligates the parties to protect and not disclose shared confidential information. BAcceptable use policy (AUP)โ ACCESS DENIEDReassess and re-secure with this:An NDA legally obligates the parties to protect and not disclose shared confidential information. CService level agreement (SLA)โ ACCESS DENIEDReassess and re-secure with this:An NDA legally obligates the parties to protect and not disclose shared confidential information. DBusiness impact analysis (BIA)โ ACCESS DENIEDReassess and re-secure with this:An NDA legally obligates the parties to protect and not disclose shared confidential information. 96/100 Program Management Before onboarding a SaaS vendor that will process customer data, a security team reviews the vendor’s certifications, security questionnaires, and past breach history. This process is best described as: APenetration testingโ ALERT RAISEDPatch your thinking with this:Due diligence is the up-front investigation of a third party’s security posture and risk before entering a relationship. BVendor due diligenceโ RISK MITIGATEDVerified. Oluma loves to see it.Due diligence is the up-front investigation of a third party’s security posture and risk before entering a relationship. CThreat modelingโ ALERT RAISEDPatch your thinking with this:Due diligence is the up-front investigation of a third party’s security posture and risk before entering a relationship. DChange managementโ ALERT RAISEDPatch your thinking with this:Due diligence is the up-front investigation of a third party’s security posture and risk before entering a relationship. 97/100 Program Management In a data governance model, who is the senior individual accountable for classifying a data set and deciding who may access it, as opposed to the team that maintains it day to day? AData custodianโ INTEGRITY CHECK FAILEDFlag it, learn it, move on. Here’s the fix:The data owner is accountable for classification and access decisions; the custodian handles day-to-day storage, backup, and technical protection. BData processorโ INTEGRITY CHECK FAILEDFlag it, learn it, move on. Here’s the fix:The data owner is accountable for classification and access decisions; the custodian handles day-to-day storage, backup, and technical protection. CData ownerโ IDENTITY VERIFIEDThat’s analyst-grade thinking โ clean and correct.The data owner is accountable for classification and access decisions; the custodian handles day-to-day storage, backup, and technical protection. DData subjectโ INTEGRITY CHECK FAILEDFlag it, learn it, move on. Here’s the fix:The data owner is accountable for classification and access decisions; the custodian handles day-to-day storage, backup, and technical protection. 98/100 Program Management Under privacy regulations such as GDPR, the entity that determines the purposes and means of processing personal data is the: AData processorโ ALERT RAISEDEvery alert is a lesson. Takeaway:The controller decides why and how personal data is processed; the processor acts on the controller’s instructions. BData controllerโ IDENTITY VERIFIEDYou read the risk right. Textbook.The controller decides why and how personal data is processed; the processor acts on the controller’s instructions. CData custodianโ ALERT RAISEDEvery alert is a lesson. Takeaway:The controller decides why and how personal data is processed; the processor acts on the controller’s instructions. DData subjectโ ALERT RAISEDEvery alert is a lesson. Takeaway:The controller decides why and how personal data is processed; the processor acts on the controller’s instructions. 99/100 Program Management An online retailer must meet a specific set of security requirements because it stores and processes payment card data. Which compliance standard applies most directly? AHIPAAโ THREAT DETECTEDReassess and re-secure with this:PCI DSS is the standard governing the protection of cardholder and payment card data. BGDPRโ THREAT DETECTEDReassess and re-secure with this:PCI DSS is the standard governing the protection of cardholder and payment card data. CPCI DSSโ POLICY ENFORCEDLocked in โ that’s how defenders think.PCI DSS is the standard governing the protection of cardholder and payment card data. DSOXโ THREAT DETECTEDReassess and re-secure with this:PCI DSS is the standard governing the protection of cardholder and payment card data. 100/100 Program Management After several staff fell for a phishing simulation, the security team rolls out recurring training and simulated phishing to change day-to-day behavior. Which control category does this best represent? AA technical controlโ ALERT RAISEDPatch your thinking with this:Security awareness training is an administrative control that targets human behavior, often the most-exploited attack surface. BA physical controlโ ALERT RAISEDPatch your thinking with this:Security awareness training is an administrative control that targets human behavior, often the most-exploited attack surface. CAn administrative control aimed at the human layerโ ACCESS GRANTEDVerified. Oluma loves to see it.Security awareness training is an administrative control that targets human behavior, often the most-exploited attack surface. DA cryptographic controlโ ALERT RAISEDPatch your thinking with this:Security awareness training is an administrative control that targets human behavior, often the most-exploited attack surface. ALL CLEAR — ENTERPRISE SECURED Nice work, defender. You just worked a full shift of scenarios — and every rep, right or wrong, is how real security judgment gets built. Your live score is on the board below. Whatever the number, you showed up and put in the work today — that’s the part that compounds. Gold means a strong area to lock in; the dashed tag means a domain worth another pass. Keep circling back — you’ve got this, friend. SECURED REVIEWED These are original practice scenarios written for the Oluma community. CompTIA® and Security+® are registered trademarks of CompTIA, Inc. Oluma is not affiliated with or endorsed by CompTIA. No official exam content is reproduced here — learn the concepts, not the dumps.