Skip to content

156-110 Practice Questions

Prepare for 156-110 with more than an answer.

100 questions in the full set12 sample questionsUpdated Jan 24, 2026
Level
Associate
  1. 1

    Why should the number of services on a server be limited to required services?

    Show answer details

    Correct answer: A

    Every open service on a server represents a potential vulnerability because each service provides an attack vector that could be exploited by malicious actors, expanding the attack surface and increasing security risks. Following the security principle of minimal exposure, servers should only run services essential for their intended function to reduce the number of potential entry points for attackers. The incorrect options present false information: closed systems don't require special connectivity services, extra services decrease rather than increase efficiency due to resource consumption, services are not inherently secure and require proper configuration and maintenance, and additional services definitely do not improve security.

  2. 2

    ABC Corporation's network is configured such that a user must log in individually at each server and access control. Which type of authentication is in use?

    Show answer details

    Correct answer: E

    Mandatory sign-on describes the authentication approach where users must log in individually at each server and access control point, requiring separate authentication for each system without credential sharing or centralized authentication mechanisms. This represents a decentralized authentication model that provides isolated security but increases administrative overhead and user inconvenience. Role-based access control manages permissions not authentication methods, three-factor authentication refers to the number of authentication factors used, single sign-on allows one login for multiple systems (the opposite of this scenario), and hybrid access control describes permission models rather than authentication approaches.

  3. 3

    The items listed below are examples of __________ controls

    *Smart cards
    *Access control lists
    *Authentication servers
    *Auditing

    Show answer details

    Correct answer: C

    Smart cards, access control lists, authentication servers, and auditing represent technical controls that use technology-based mechanisms to enforce security policies and protect information assets. Technical controls are implemented through hardware, software, and firmware solutions to automate security functions and provide consistent enforcement. Administrative controls involve policies and procedures, physical controls protect against physical threats, role-based and mandatory controls describe access control models rather than control categories.

  4. 4

    When should procedures be evaluated?

    Show answer details

    Correct answer: D

    Procedures should be evaluated whenever business processes are modified because changes in business operations can impact security requirements, introduce new risks, or make existing procedures obsolete or inadequate. Process modifications often require procedural updates to maintain security effectiveness and operational alignment. New user onboarding, anniversaries, regular usage, and exploit discoveries may trigger procedure reviews but don't represent the systematic evaluation trigger that ensures procedures remain relevant to actual business operations.

  5. 5

    Which of the following best describes an external intrusion attempt on a local-area network (LAN)?

    Show answer details

    Correct answer: B

    External intrusion attempts are attacks originating from outside the organization's network perimeter, where unauthorized external entities attempt to gain access to internal resources without proper permissions or rights. This represents the classic security threat model where attackers from the internet or other external sources try to breach network defenses. The other options incorrectly describe internal threats (insider attacks), confused definitions mixing external users with legitimate public access, nonsensical vulnerability exploitation for access removal, or internal misuse of authorized access.

  6. 6

    Maintenance of the Business Continuity Plan (BCP) must be integrated with __________ an organization’s process.

    Show answer details

    Correct answer: A

    Business Continuity Plans must be integrated with change-control processes because any organizational changes (infrastructure, personnel, procedures, technology) can impact business continuity requirements and recovery capabilities. Change control ensures BCP updates are evaluated and implemented systematically when organizational changes occur. Disaster recovery is a component of BCP, not the integration point; inventory maintenance, discretionary budgets, and compensation reviews are operational processes that don't directly govern BCP maintenance cycles.

Create an account to continue.