An enterprise is trying to limit outbound DNS traffic originating from its internal network. Outbound DNS requests will only be allowed from one device with the IP address 10.50.10.25. Which of the following firewall ACLs will accomplish this goal?
The correct ACL allows DNS traffic only from the IP address 10.50.10.25 and denies it from all other devices.
Which of the following solutions provides a single, centralized source for reviewing events?
Log aggregation collects logs from multiple devices and applications into a central repository for unified analysis. This enables correlation of events across systems and quicker incident detection. It also simplifies compliance reporting by providing one source of truth.
A security engineer needs to configure an NGFW to minimize the impact of the increasing number of various traffic types during attacks. Which of the following types of rules is the engineer the most likely to configure?
Behavioral-based rules analyze network traffic patterns to detect and block malicious activity. This is effective for mitigating the impact of various traffic types during attacks, as it focuses on identifying anomalies and deviations from normal behavior rather than relying on specific signatures or URLs.
An organization needs to monitor its users' activities in order to prevent insider threats. Which of the following solutions would help the organization achieve this goal?
Behavioral analytics helps monitor user activities and detect anomalous behavior that could indicate insider threats.
Which of the following best describes the concept of information being stored outside of its country of origin while still being subject to the laws and requirements of the country of origin?
Data sovereignty refers to the principle that data stored in another country remains subject to the originating country's laws. This is a common concern in cloud computing.
A company wants to ensure secure communication between two remote offices over the internet. Which of the following technologies should the company implement to achieve this?
A Virtual Private Network (VPN) is the best solution for securely connecting remote offices over the internet by creating a private and encrypted connection.
A security analyst is reviewing logs to identify the destination of command-and-control traffic originating from a compromised device within the on-premises network. Which of the following is the best log to review?
Firewall logs are the best choice to review as they will contain information about network traffic, including command-and-control communication.
Which of the following would be the best way to test resiliency in the event of a primary power failure?
A production failover simulates an actual switch to backup power and systems to test resiliency in real-world conditions.
The company only data center has undervoltage issues. What is the best way to mitigate this type of event?
A UPS (Uninterruptible Power Supply) provides backup power during undervoltage events and ensures that the equipment in the data center continues to function without interruption. It also helps to prevent damage to sensitive electronics from power fluctuations.
The security team notices that the Always On VPN solution sometimes fails to connect. This leaves remote users unprotected because they cannot connect to the on-premises web proxy. Which of the following changes will best provide web protection in this scenario?
When a VPN connection fails, remote users lose access to the on-premises proxy and become unprotected. Installing a host-based content filtering solution ensures that security policies continue to be enforced locally on the device, regardless of VPN availability.
A company would like to provide employees with computers that do not have access to the internet in order to prevent information from being leaked to an online forum. Which of the following would be best for the systems administrator to implement?
Air gapping involves physically isolating a system or network from any external connections. This is the most effective way to prevent information leakage to the internet, as the computers would be completely disconnected from any online access.
A security team is setting up a new environment for hosting the company's web servers as a cloud-based service. Which of the following should the team ensure is in place in order for the company to follow security best practices?
Virtualization and isolation of resources are fundamental for ensuring security in a cloud environment by preventing unauthorized access and reducing risks to other systems.
Which of the following is the best physical security control to prevent damage from a vehicle?
Bollards are physical barriers, often concrete or steel posts, that prevent vehicles from ramming into buildings or critical infrastructure. Unlike guards or lighting, bollards provide a direct physical defense against vehicle-based threats.
An administrator is creating a server that cannot be shared with any other organizations. The administrator also wants to ensure that the company retains control over the infrastructure. Which of the following cloud deployment models should the administrator choose?
A private cloud is solely dedicated to a single organization, providing isolation and control over the infrastructure. This meets the administrator's requirements for non-sharing and maintaining control over resources.
A security team is addressing a risk associated with the attack surface of the organization's web application over port 443. Currently, no advanced network security capabilities are in place. Which of the following would be best to set up? (Select two).
Setting up a WAF and NIDS would help protect the web application by blocking malicious traffic and detecting potential threats.
Quiz Complete!
Domain 3: Security Architecture