Cybersecurity-Fundamentals Practice Questions
Prepare for Cybersecurity-Fundamentals with more than an answer.
- Exam fee
- $150 USD
- Level
- Fundamentals
- Valid for
- No expiration
Domains covered on the exam 4
- Information Security Fundamentals27%
- Threat Landscape18%
- Securing Assets35%
- Security Operations and Response20%
- 1
True or False: A zero-day vulnerability is a software flaw that has been publicly disclosed but for which no official patch or update has been released by the vendor.
Show answer details
Correct answer: A
This statement is true. A zero-day vulnerability refers to a security flaw that is known to attackers (and possibly the public) before the software vendor has released a patch to fix it. This creates a critical window of opportunity for attackers to exploit the vulnerability, as there are 'zero days' of protection available for users.
- 2
Company Background:
FinSecure, a rapidly growing fintech startup, provides a mobile banking application to its customers. The company prides itself on innovation and rapid feature deployment, following a DevOps model. The entire infrastructure is hosted in a public cloud environment. The application handles sensitive financial data, including transaction histories and personally identifiable information (PII).Current Situation:
An external audit revealed several security concerns. The development team has been storing database credentials and API keys as plain text variables within their source code repositories. The audit also noted that the company has no formal process for managing user access to its cloud infrastructure, with several developers having broad administrative permissions. Finally, there is no centralized system for monitoring and responding to security events, making it difficult to detect breaches.Requirements & Constraints:
- Eliminate the practice of storing secrets in source code.
- Implement the principle of least privilege for cloud infrastructure access.
- Establish a capability for centralized logging and security event monitoring.
- The solutions must be cloud-native and integrate well with their existing CI/CD pipeline.
Which combination of security controls would be MOST effective in addressing all of the audit findings for FinSecure?
Show answer details
Correct answer: A
This option comprehensively addresses all three audit findings with appropriate, modern solutions. A secrets management tool directly solves the problem of hardcoded credentials. Implementing RBAC via the cloud provider's IAM service is the standard way to enforce the principle of least privilege. Deploying a SIEM provides the necessary centralized logging and monitoring capabilities. These tools are designed to work in cloud environments and integrate with CI/CD pipelines.
- 3
A security analyst needs to assess the security posture of a web application by actively probing it for vulnerabilities like SQL injection and cross-site scripting (XSS) while it is running in a test environment. What type of security testing is being performed?
Show answer details
Correct answer: C
Dynamic Application Security Testing (DAST) analyzes a running application from the outside in, similar to how an attacker would. It sends various malicious and unexpected inputs to the application to identify vulnerabilities like SQL injection, XSS, and other common web flaws without needing access to the source code. This is distinct from SAST, which analyzes the static source code.
- 4
A user receives an email that appears to be from their CEO, urgently requesting the transfer of funds to a new vendor account. The email uses a tone of authority and pressure, and the sender's email address is subtly misspelled (e.g.,
[email protected]instead of[email protected]). This is an example of what type of attack?Show answer details
Correct answer: A
This attack is a specific form of phishing known as whaling (or CEO fraud). Whaling targets high-profile individuals within an organization, such as executives (like the CEO), and often involves social engineering tactics like impersonation and urgency to trick employees into performing actions like transferring funds or revealing sensitive information.
- 5
A network administrator wants to segment a corporate network to isolate the guest wireless network from the internal production network. This would prevent guests from accessing internal servers and resources. Which networking technology is commonly used to create this logical separation on the same physical network hardware?
Show answer details
Correct answer: C
Virtual Local Area Networks (VLANs) are used to logically segment a network. Devices on one VLAN are isolated from devices on another VLAN as if they were on physically separate networks. This is the standard method for creating separate broadcast domains for different purposes (like guest vs. corporate) on the same switches, with a router or Layer 3 switch controlling traffic between them.
- 6
A security team is designing a defense-in-depth strategy for their organization. Which of the following sets of controls BEST represents a multi-layered security architecture? (Select TWO).
graph TD A[Perimeter Firewall] --> B[Internal Segmentation] B --> C[Endpoint Protection] C --> D[Data Encryption]Show answer details
Correct answer: A, C
This option represents multiple layers of technical controls: the firewall at the network perimeter, the IDS for network traffic analysis, and antivirus at the individual host (endpoint) level. If one layer is breached, the others still provide protection.
This option represents multiple layers of administrative controls. Background checks are a pre-employment control, training is an ongoing behavioral control, and data classification is a policy-based control that dictates handling procedures. These work together to reduce risk from the human element.
- 7
The PowerShell command to create a new resource group in Azure is
New-AzResourceGroup -Name 'MyRG' -Location '_____'. Which of the following is a valid value for the-Locationparameter?Show answer details
Correct answer: B
Azure uses specific, non-spaced string identifiers for its regions. 'EastUS' is the correct identifier for the East US region. Other cloud providers use different naming conventions (e.g., 'us-east-1' in AWS), and formats like 'USA-Central-1' are not valid Azure region names.
- 8
A financial services company is implementing a new data classification policy. The policy defines four levels: Public, Internal, Confidential, and Restricted. A security analyst needs to apply a technical control that prevents files classified as 'Restricted' from being attached to emails sent to external domains. Which security technology is specifically designed to enforce this type of policy-based data handling rule?
Show answer details
Correct answer: B
Data Loss Prevention (DLP) systems are specifically designed to enforce policies based on data classification and content analysis. They can inspect data in motion (like email attachments), at rest (on storage), and in use (on endpoints) to prevent unauthorized exfiltration of sensitive information, such as blocking 'Restricted' files from being sent externally.
- 9
During an incident response tabletop exercise, a team is presented with a scenario where a critical server has been infected with ransomware. The team needs to follow the standard incident response lifecycle. What is the immediate first step that should be taken after detecting and analyzing the incident?
Show answer details
Correct answer: C
After detection and analysis, the immediate priority in the incident response lifecycle is containment. This involves isolating the affected system (e.g., disconnecting it from the network) to prevent the ransomware from spreading to other systems. Eradication (removing the malware) and Recovery (restoring from backups) follow the containment phase.
- 10
A security team is implementing Role-Based Access Control (RBAC) for a large enterprise. They have defined roles such as 'Sales Associate', 'HR Manager', and 'System Administrator'. Which of the following is a primary benefit of using RBAC over Discretionary Access Control (DAC)?
Show answer details
Correct answer: B
The primary benefit of RBAC is administrative scalability and simplified management. Instead of assigning permissions directly to hundreds or thousands of individual users, administrators assign permissions to a smaller number of roles. Users are then assigned to these roles, inheriting the associated permissions. This greatly reduces the complexity of managing user access, especially during onboarding, offboarding, and role changes.
