A systems administrator is attempting to recover from a catastrophic failure in the datacenter. To recover the domain controller, the systems administrator needs to provide the domain administrator credentials.
Which of the following account types is the systems administrator using?

A.    Guest account
B.    Service account
C.    User account

Answer: C

A penetration tester is crawling a target website that is available to the public. Which of the following represents the actions the penetration tester is performing?

A.    URL hijacking
B.    Reconnaissance
C.    White box testing
D.    Escalation of privilege

Answer: B

When systems, hardware, or software are not supported by the original vendor, it is a vulnerability known as:

A.    system sprawl.
B.    end-of-life systems
C.    resource exhaustion
D.    a default configuration

Answer: C

An organization’s internal auditor discovers that large sums of money have recently been paid to a vendor that management does not recognize. The IT security department is asked to investigate the organization’s ERP system to determine how the accounts payable module has been used to make these vendor payments.

The IT security department finds the following security configuration for the accounts payable module:


Which of the following changes to the security configuration of the accounts payable module would BEST mitigate this risk?

A.     1242
B.     1243
C.     1244
D.     1245

Answer: D

As part of a new industry regulation, companies are required to utilize secure, standardized OS settings. A technician must ensure the OS settings are hardened. Which of the following is the BEST way to do this?

A.    Use a vulnerability scanner.
B.    Use a configuration compliance scanner.
C.    Use a passive, in-line scanner.
D.    Use a protocol analyzer.

Answer: A

Joe, an employee, wants to show his colleagues how much he knows about smartphones. Joe demonstrates a free movie application that he installed from a third party on his corporate smartphone. Joe’s colleagues were unable to find the application in the app stores. Which of the following allowed Joe to install the application? (Select TWO).

A.    Near-field communication
B.    Rooting/jailbreaking
C.    Ad-hoc connections
D.    Tethering
E.    Sideloading

Answer: AB

A company’s user lockout policy is enabled after five unsuccessful login attempts. The help desk notices a user is repeatedly locked out over the course of a workweek. Upon contacting the user, the help desk discovers the user is on vacation and does not have network access. Which of the following types of attacks are MOST likely occurring? (Select TWO)

A.    Replay
B.    Rainbow tables
C.    Brute force
D.    Pass the hash
E.    Dictionary

Answer: DE

A user has attempted to access data at a higher classification level than the user’s account is currency authorized to access. Which of the following access control models has been applied to this user’s account?

A.    MAC
B.    DAC
C.    RBAC
D.    ABAC

Answer: D

A company determines that it is prohibitively expensive to become compliant with new credit card regulations. Instead, the company decides to purchase insurance to cover the cost of any potential loss. Which of the following is the company doing?

A.    Transferring the risk
B.    Accepting the risk
C.    Avoiding the risk
D.    Mitigating the risk

Answer: A

An organization has determined it can tolerate a maximum of three hours of downtime.
Which of the following has been specified?

A.    RTO
B.    RPO
C.    MTBF
D.    MTTR

Answer: B

