100-160 Exam Questions
59 real 100-160 exam questions with expert-verified answers and explanations. Page 1 of 2.
- Question #1Endpoint Security Concepts
Why is it necessary to update firmware to the latest version?
firmware updatespatch managementendpoint hardeningvulnerability mitigation - Question #2Threats and Vulnerabilities
How do threat actors launch ransomware attacks on organizations?
ransomwaremalwarethreat actorsdata extortion - Question #3Network Security Concepts
You are planning to work from home. Your company requires that you connect to the company network through a VPN. Which three critical functions do VPNs provide to remote workers? (...
VPNconfidentialityintegrityauthentication - Question #4Threats and Vulnerabilities
A threat actor sets up a rogue access point (AP) at a local cafe. The rogue AP captures traffic and then forwards the traffic to the cafe AP. Which type of attack does this scenari...
man-in-the-middle attackrogue access pointwireless securitytraffic interception - Question #5Cybersecurity Incident Response
What is the main purpose of a disaster recovery plan as compared to a business continuity plan?
disaster recovery planbusiness continuityIT infrastructure recoveryincident response - Question #6Network Security Concepts
A restaurant installs a second wireless router that only employees can use. Which statement describes how to securely configure the new router?
wireless securitySSID broadcastnetwork configurationaccess control - Question #7Network Security Concepts
You need to transfer configuration files to a router across an unsecured network. Which protocol should you use to encrypt the files in transit?
SSHsecure file transferencryption in transitprotocol selection - Question #8Cybersecurity Best Practices
Your company is creating a BYOD policy to allow employees to join their personal smartphones to the company network. Which three requirements are commonly included in a BYOD policy...
BYOD policymobile securitydata encryptionpassword policy - Question #9Threats and Vulnerabilities
You notice that a new CVE has been shared to an email group that you belong to. What should you do first with the CVE?
CVEvulnerability triagethreat intelligencepatch prioritization - Question #10Network Security Concepts
Which encryption type is commonly used to secure WiFi networks?
WiFi securityAESWPA2wireless encryption - Question #11Endpoint Security Concepts
How does sandboxing help with the analysis of malware?
sandboxingmalware analysisthreat isolationdynamic analysis - Question #12Network Security Concepts
Which network security technology passively monitors network traffic and compares the captured packet stream with known malicious signatures?
IDSintrusion detectionsignature-based detectionpassive monitoring - Question #13Threats and Vulnerabilities
Your supervisor tells you that you will participate in a CVSS assessment. What will you be doing?
CVSSvulnerability scoringsecurity assessmentvulnerability management - Question #14Network Security Concepts
The company web server collects information through a form. The form is accessed by using port 80. The form content is transferred to an encrypted database for storage. You are inv...
HTTP vs HTTPSunencrypted protocolweb securitydata in transit - Question #15Security Laws and Regulations
You work for a hospital that stores electronic protected health information (ePHI) in an online portal. Authorized employees can use their mobile devices to access patient ePHI. Yo...
HIPAAePHImobile device policyhealthcare compliance - Question #16Cybersecurity Best Practices
You need to design your company's password policy to adhere to the National Institute of Standards and Technology (NIST) guidelines for user password security. What is the minimum...
NIST guidelinespassword policyminimum password lengthsecurity standards - Question #17Cybersecurity Incident Response
You need a software solution that performs the following tasks: - Compiles network data - Logs information from many sources - Provides orchestration in the form of case management...
SOARsecurity orchestrationincident response automationcase management - Question #18Cybersecurity Incident Response
You are collecting data after a suspected intrusion on the local LAN. You need to capture incoming IP packets to a file for an investigator to analyze. Which two tools should you u...
Wiresharktcpdumppacket capturenetwork forensics - Question #19Cybersecurity Incident Response
What should an incident response team do immediately after detecting an incident?
incident responsenotificationfirst responsestakeholder management - Question #20Threats and Vulnerabilities
Which vulnerabilities can a risk assessment reveal? (Choose two)
Risk assessmentVulnerabilitiesSoftware patchingAccess controls - Question #21Security Principles
What are components of a comprehensive risk management process? (Choose two)
Risk ManagementRisk AssessmentRisk MitigationRisk Process - Question #22Threats and Vulnerabilities
Which metric is used in risk assessment to evaluate the severity of a vulnerability?
CVSSVulnerability ScoringRisk AssessmentSeverity Metrics - Question #23Endpoint Security Concepts
What is the main role of a Host-Based Intrusion Prevention System (HIPS)?
HIPSEndpoint SecurityIntrusion PreventionThreat Prevention - Question #24Network Security Concepts
Which of the following are examples of secure network protocols? (Choose two)
Network ProtocolsEncryptionSecure CommunicationProtocol Security - Question #25Threats and Vulnerabilities
What tools can help identify network vulnerabilities? (Choose two)
Vulnerability Assessment ToolsNetwork ScannersNetwork VulnerabilitiesVulnerability Identification - Question #26Network Security Concepts
Which protocol is commonly used for secure data transmission over the internet?
HTTPSTLS/SSLSecure ProtocolsEncryption - Question #28Security Principles
Drag and Drop Question Move each definition from the list on the left to the correct CIA Triad term on the right. Note: You will receive partial credit for each correct answer. Ans...
CIA triadconfidentialityintegrityavailability - Question #29Cybersecurity Incident Response
Drag and Drop Question Move each NIST Incident Response Lifecycle phase from the list on the left to the correct description on the right. Note: You will receive partial credit for...
NIST incident responseIR lifecyclepreparationcontainment - Question #30Threats and Vulnerabilities
Drag and Drop Question Move each worm mitigation step from the list on the left to the correct description on the right. Note: You will receive partial credit for each correct answ...
worm mitigationmalware containmentnetwork threatsincident handling - Question #31Cybersecurity Incident Response
Drag and Drop Question You need to diagram an intrusion event by using the Diamond Model. Move each event detail from the list on the left to the correct location in the diagram on...
Diamond Modelintrusion analysisthreat modelingadversary attribution - Question #32Security Principles
Drag and Drop Question You need to manage security risks at your company. In which order should you complete the actions? Move all the actions to the answer area and place them in...
risk managementrisk assessmentsecurity governancerisk treatment - Question #33Security Principles
Drag and Drop Question Move each framework from the list on the left to the correct purpose on the right. Note: You will receive partial credit for each correct answer. Answer:
security frameworksNISTcompliance frameworksframework purpose - Question #34Threats and Vulnerabilities
Drag and Drop Question Move each scenario from the list on the left to the correct type of attacker on the right. Note: You will receive partial credit for each correct answer. Ans...
threat actorsattacker typesinsider threatnation-state - Question #35Network Security Concepts
How does a honeypot enhance network security?
honeypotnetwork deceptionthreat diversiondecoy systems - Question #36Basic Security Concepts
Which data type is protected through hard disk encryption?
data at restdisk encryptiondata statesencryption - Question #37Endpoint Security Concepts
Your supervisor suspects that someone is attempting to gain access to a Windows computer by guessing user account IDs and passwords. The supervisor asks you to use the Windows Even...
Windows Event Vieweraudit policyaccount logon failureaccount lockout - Question #38Threats and Vulnerabilities
You are going to perform a penetration test on a company LAN. As part of your preparation, you access the company's websites, view webpage source code, and run internet searches to...
passive reconnaissanceOSINTinformation gatheringpenetration testing - Question #39Threats and Vulnerabilities
Your manager asks you to review the output of some vulnerability scans and report anything that may require escalation. Which two findings should you report for further investigati...
vulnerability scanningopen portsfirewall configurationsecurity assessment - Question #40Network Security Concepts
A client cannot connect to the corporate web server. You discover a large number of half-open TCP connections to the server. What should you do?
SYN floodDoS attackTCP three-way handshakehalf-open connections - Question #41Threats and Vulnerabilities
Which two basic metrics should be taken into consideration when assigning a severity to a vulnerability during an assessment? (Choose two.)
vulnerability severityCVSSexploit likelihoodimpact assessment - Question #42Endpoint Security Concepts
Which Windows app is a command-line interface that includes a sophisticated scripting language used to automate Windows tasks?
PowerShellWindows CLIscriptingtask automation - Question #43Endpoint Security Concepts
You are reviewing the Application log on a Windows computer. You see an event with an error- level message as shown. What can you determine about the application that generated the...
Windows Event Viewerapplication logserror eventslog analysis - Question #44Network Security Concepts
Which security measure can prevent unauthorized devices from automatically connecting to a corporate network through unused switch ports?
port securityswitch hardeningnetwork access controlunauthorized devices - Question #45Endpoint Security Concepts
An administrator wants to ensure that any files downloaded from the internet are automatically scanned for malicious code before execution. Which security control should be impleme...
anti-malwarereal-time protectionendpoint securitymalicious code scanning - Question #46Cybersecurity Best Practices
Which step should be performed immediately after identifying a critical vulnerability affecting internet-facing systems?
patch managementvulnerability remediationinternet-facing systemsvulnerability management - Question #47Cybersecurity Incident Response
A SOC analyst notices repeated failed login attempts from a foreign IP address followed by a successful login to a privileged account. What is the most appropriate next step?
brute force attackprivileged account compromiseSOC analysisincident triage - Question #48Network Security Concepts
Which wireless security protocol provides the strongest protection for a home or small business network?
WPA3wireless securityencryption protocolsnetwork authentication - Question #49Cybersecurity Incident Response
During an incident response, the security team needs to isolate a compromised server from the rest of the network but still allow forensic analysis. Which action should they take?
server isolationforensic analysisincident containmentcompromised host - Question #50Cybersecurity Incident Response
What activities should occur during the preparation phase of incident handling? (Choose two)
Incident Response PhasesPreparation PhaseIncident Response PlanningTeam Training - Question #51Threats and Vulnerabilities
Which type of attack exploits human vulnerabilities to gain unauthorized access?
PhishingSocial EngineeringAttack TypesHuman Vulnerabilities