A company plans to secure its systems by:\n• Preventing users from sending sensitive data over corporate email\n• Restricting access to potentially harmful websites\nWhich of the following features should the company set up? (Select 2 Answers)
Data Loss Prevention (DLP) software inspects outgoing emails in real time to identify and block any sensitive information from leaving the network. DNS filtering complements this by preventing users from reaching known malicious or unauthorized websites, thereby enforcing web-use policies. Together, these controls create a layered defense that addresses both data exfiltration and web-based threats.
Which of the following exercises should an organization use to improve its incident response process?
A tabletop exercise is a discussion-based simulation of an incident response scenario. It allows the organization to test its incident response plan, identify gaps, and train its team in a controlled environment without affecting production systems.
Which of the following describes effective change management procedures?
Effective change management always includes a backout or rollback plan to restore systems if an update causes issues. This plan is predefined before implementation. It minimizes downtime and ensures quick recovery from failed changes.
Which of the following is the most likely reason a security analyst would review SIEM logs?
SIEM platforms aggregate and correlate events from many devices, making it possible to spot patterns that span across hosts. Analysts review these logs to detect multi-stage attacks or lateral movements.
An organization is implementing a COPE mobile device management policy. Which of the following should the organization include in the COPE policy? (Select two).
COPE policies typically involve encrypting data on the device and allowing remote wipe to protect organizational data in case of loss or theft.
Which of the following data states applies to data that is being actively processed by a database server?
Data in use refers to data actively being processed, such as by a database server.
A company is concerned about theft of client data from decommissioned laptops. Which of the following is the most cost-effective method to decrease this risk?
Wiping is the most cost-effective method to erase all data from decommissioned laptops, preventing data theft.
Which testing method is performed on a deployed application during runtime?
Dynamic analysis evaluates an application while it is running to detect vulnerabilities.
A security analyst regularly receives emails from users who are concerned that attached files may be malicious. Which of the following should the analyst use to evaluate the suspicious files and report back as to whether or not files are a threat?
A sandbox environment executes attachments in isolation so the analyst can observe any malicious behavior without risking production systems. After testing, the analyst can confidently report whether the file poses a threat.
Which of the following is the MOST secure way to dispose of sensitive paper documents?
Cross-cut shredding makes document reconstruction extremely difficult, providing a secure and practical method for disposing of sensitive documents.
A company is implementing a policy to allow employees to use their personal equipment for work. However, the company wants to ensure that only company-approved applications can be installed. Which of the following addresses this concern?
MDM (Mobile Device Management) ensures that only approved applications are installed on personal devices used for work.
A company wants to track modifications to the code that is used to build new virtual servers. Which of the following will the company most likely deploy?
A version control tool helps track changes to code and allows for rollback and collaboration in software development.
A security analyst needs to securely remove all sensitive data from a decommissioned hard drive before disposal. Which of the following methods would be the most effective?
Performing a secure wipe ensures that all sensitive data is permanently removed from the hard drive and cannot be recovered.
Which of the following is most likely to be used as a just-in-time reference document within a security operations center?
Playbooks contain concise, step-by-step procedures for responding to specific incidents, enabling SOC analysts to act quickly and consistently. They serve as real-time guides during active investigations.
A recent review of logs indicate many attempts to join an internal wireless network from external devices. The connections appear to be originating from surrounding buildings. Which of the following would best help minimize the visibility of the wireless network?
Heat maps visualize wireless signal strength and coverage areas. By analyzing these maps, administrators can adjust transmit power and antenna placement to limit signal leakage. This reduces unauthorized attempts from outside the intended coverage zone.
Quiz Complete!
Domain 4: Security Operations