Skip to content

212-82 Practice Questions

Prepare for 212-82 with more than an answer.

248 questions in the full set20 sample questionsUpdated Jan 26, 2026
Exam fee
$499 USD
Level
Entry-Level
Valid for
3 years
Domains covered on the exam 8
  1. Information Security Threats and Attacks11%
  2. Network Security7%
  3. Network Security Controls23%
  4. Application Security and Cloud Computing9%
  5. Wireless Device Security11%
  6. Data Security10%
  7. Network Monitoring and Analysis16%
  8. Incident and Risk Management13%
  1. 1

    A security technician is configuring a Data Loss Prevention (DLP) solution. The goal is to prevent sensitive customer Personally Identifiable Information (PII) from being sent outside the company via email. Which DLP detection method would be most effective for identifying data like social security numbers or credit card numbers based on their specific structure?

    Show answer details

    Correct answer: C

    Regular expression (regex) pattern matching is the most effective method for this use case. Data like social security numbers (e.g., \d{3}-\d{2}-\d{4}) and credit card numbers have a defined structure and format that can be accurately identified with a regex pattern. Keyword matching is too broad, and data fingerprinting is used for exact or partial matches of specific, registered documents, not for general patterns.

  2. 2

    Which of the following are considered physical security controls that a cybersecurity technician might be responsible for implementing or auditing? (Select THREE).

    Show answer details

    Correct answer: A, C, E

    Perimeter fencing is a classic example of a physical deterrent control designed to prevent unauthorized physical access to a facility.

    CCTV is a physical detective and deterrent control used to monitor physical spaces and record activity.

    Biometric locks are a physical preventive control that uses unique human characteristics to grant or deny physical access to a secured area.

  3. 3

    A security analyst is reviewing logs from a SIEM and discovers that a specific user account has attempted to log in to 15 different servers within a 5-second window, with all attempts failing due to incorrect passwords. This activity triggers a high-priority alert. This scenario is an example of the SIEM performing which function?

    Show answer details

    Correct answer: B

    This is a prime example of event correlation. The SIEM is taking individual, seemingly low-priority events (a single failed login) from multiple sources (different server logs), analyzing them together based on defined rules (e.g., >10 failed logins for one user in <10 seconds), and identifying a significant security event (a likely brute-force or password spray attack). Log aggregation is just the collection of logs; correlation is the intelligence that connects them.

  4. 4

    A cybersecurity technician is tasked with creating a security policy that provides a baseline of security for all systems in the organization. The policy mandates specific configurations, such as disabling unnecessary ports, enforcing strong passwords, and removing default vendor accounts. This type of administrative control is best described as a:

    Show answer details

    Correct answer: C

    This describes a System Hardening Standard. A hardening standard provides mandatory, specific technical configurations required to secure a system and reduce its attack surface. It serves as a checklist or baseline for configuring servers, workstations, and network devices consistently and securely across the organization. An AUP governs user behavior, an IRP details steps for handling incidents, and a BCP outlines how to continue business operations during a disruption.

  5. 5

    A junior network technician is analyzing a Wireshark capture to troubleshoot a failed TLS handshake. They observe the following sequence of packets. Based on this flow, what is the MOST likely cause of the failure?

    sequenceDiagram participant Client participant Server Client->>Server: TCP SYN Server-->>Client: TCP SYN-ACK Client->>Server: TCP ACK Client->>Server: Client Hello Server-->>Client: Server Hello, Certificate, Server Hello Done Server-->>Client: TCP FIN, ACK Client->>Server: TCP ACK

    Show answer details

    Correct answer: B

    The diagram shows the server sends its 'Server Hello' and 'Certificate', but then immediately terminates the connection with a 'TCP FIN' packet. It does not proceed to the 'Server Key Exchange' phase. This behavior is characteristic of a server that cannot find a common cipher suite with the client after reviewing the 'Client Hello'. If the client rejected the certificate, it would typically send a 'TLS Alert' message before closing the connection.

  6. 6

    A cybersecurity technician at a financial services firm is tasked with implementing a technical control to prevent unauthorized devices from connecting to the corporate wired network. The solution must automatically assess the security posture of any device attempting to connect and place non-compliant devices into a quarantined VLAN for remediation. Which of the following technologies is best suited to meet these requirements?

    Show answer details

    Correct answer: B

    Network Access Control (NAC) is the correct solution. NAC systems are designed to enforce security policies on devices seeking to access network resources. They can check for compliance (e.g., updated antivirus, OS patches) and use 802.1X for port-based authentication, automatically quarantining non-compliant devices. An IPS inspects traffic for malicious activity, a proxy server mediates client requests to the internet, and a VPN provides secure remote access.

  7. 7

    A technician is analyzing a packet capture from a host experiencing slow network performance. They observe a large number of TCP packets with the SYN flag set being sent to a single server port, but very few corresponding SYN/ACK replies. The source IP addresses of these packets are varied and appear to be spoofed. What type of network event is most likely occurring?

    Show answer details

    Correct answer: C

    The scenario describes a classic TCP SYN flood, a type of Denial of Service (DoS) attack. The attacker sends a high volume of SYN packets, often with spoofed source IPs, to overwhelm the server's connection table (half-open connections). Since the server never receives the final ACK, it keeps resources allocated, eventually exhausting them and denying service to legitimate users. Port scanning involves probing multiple ports, not flooding one. ARP poisoning manipulates MAC-to-IP mappings locally. A smurf attack uses ICMP echo requests.

  8. 8

    A retail company is upgrading its in-store Wi-Fi network. The security team has mandated the use of the most current and secure wireless encryption protocol available to protect customer data. Which protocol should the network technician implement?

    Show answer details

    Correct answer: D

    WPA3 is the latest and most secure wireless security protocol. It replaces the Pre-Shared Key (PSK) exchange in WPA2 with Simultaneous Authentication of Equals (SAE), making it resistant to offline dictionary attacks. WEP and WPA are deprecated and highly insecure. WPA2 is still common but WPA3 offers superior security features and is the correct choice for a new, secure implementation.

  9. 9

    During a forensic investigation of a compromised web server, a digital forensics specialist creates a bit-for-bit copy of the server's hard drive. To ensure the integrity of this copy, the specialist calculates a unique value for both the original drive and the image file. What is this value called, and which of the following algorithms is commonly used to generate it? (Select TWO).

    Show answer details

    Correct answer: A, C

    The value is a cryptographic hash, which serves as a digital fingerprint to verify data integrity. SHA-256 is a widely used and secure hashing algorithm for this purpose.

    SHA-256 is a standard hashing algorithm used in digital forensics to create a unique hash value for evidence, ensuring its integrity throughout the investigation.

  10. 10

    A software development team is building a new e-commerce application. The security team mandates that all sensitive data, such as credit card numbers, must be protected while stored in the database. The same key will be used for both encrypting and decrypting this data. Which type of cryptography should be implemented?

    Show answer details

    Correct answer: B

    Symmetric encryption uses a single, shared key for both encryption and decryption. It is fast and efficient, making it ideal for encrypting large amounts of data at rest, such as data in a database. Asymmetric encryption uses a key pair (public and private) and is typically used for key exchange and digital signatures. Hashing is a one-way function and cannot be used for decryption. Steganography is the practice of hiding data within other data.

Create an account to continue.