CompTIA Security+ SY0-701 Security Hardening of Computing Resources Practice Test 1

 

Topic 14 Practice Test 1 covers Security Hardening of Computing Resources for CompTIA Security+ SY0-701 and maps to objective 4.1: Given a scenario, apply common security techniques to computing resources. For broader exam preparation, review the CompTIA Security+ Exam Dumps. Every option includes focused editorial reasoning explaining both the concept and its fit to the scenario.

Question 1

The control set for a computing-resource hardening program must address both deployment model in which users choose from a list of organization-approved devices and collection and review of telemetry from hardened systems. Which TWO choices map directly to those needs? Choose TWO.

  1. Secure baseline
  2. Security monitoring
  3. CYOD
  4. Wireless site survey
  5. Input validation

Correct Answers: B, C

Correct Answers

 

 

Answer B is correct because Security monitoring means collection and review of telemetry from hardened systems. It belongs in the fixed-count answer set because it covers one of the stated requirements. Input validation instead serves checking and constraining application input before it is used and cannot replace this function.

Answer C is correct because CYOD means a deployment model in which users choose from a list of organization-approved devices. This option satisfies a specific requirement in the stem; Input validation serves checking and constraining application input before it is used and therefore is not interchangeable with it.

Incorrect Answers

 

Answer A is incorrect because Secure baseline means an approved minimum configuration that establishes required security settings for a class of systems. The required choices are CYOD, Security monitoring. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

Answer D is incorrect because Wireless site survey means assessment of radio coverage, interference, channel use, and access-point placement. The required choices are CYOD, Security monitoring. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

Answer E is incorrect because Input validation means checking and constraining application input before it is used. The question requires exactly 2 selections: CYOD, Security monitoring. This option falls outside that required set. For example, Security monitoring is required for collection and review of telemetry from hardened systems.

 

Question 2

Which term describes assessment of radio coverage, interference, channel use, and access-point placement?

  1. Code signing
  2. Static code analysis
  3. Wireless site survey
  4. Server hardening

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Wireless site survey means assessment of radio coverage, interference, channel use, and access-point placement. That is the function the question is testing. Server hardening would instead be used for secure configuration of server operating systems and services using patching, restricted roles, monitoring, and minimized software.

Incorrect Answers

 

Answer A is incorrect because Code signing refers to digital signing of software to verify publisher identity and detect modification. This could be appropriate elsewhere, but the required function is assessment of radio coverage, interference, channel use, and access-point placement; that makes Wireless site survey the precise choice.

Answer B is incorrect because Static code analysis refers to analysis of source code or binaries without executing the application. The key mismatch is functional: Wireless site survey addresses assessment of radio coverage, interference, channel use, and access-point placement, the need stated by the question.

Answer D is incorrect because Server hardening refers to secure configuration of server operating systems and services using patching, restricted roles, monitoring, and minimized software. The scenario instead requires assessment of radio coverage, interference, channel use, and access-point placement, which is why Wireless site survey is the better answer; this option serves the different function defined above.

 

Question 3

The control set for a computing-resource hardening program must address both secure configuration of routing devices by limiting management access, disabling unnecessary services, and applying strong authentication and checking and constraining application input before it is used. Which TWO choices map directly to those needs? Choose TWO.

  1. Router hardening
  2. BYOD
  3. Input validation
  4. Security monitoring
  5. Cloud-infrastructure hardening

Correct Answers: A, C

Correct Answers

 

 

Answer A is correct because Router hardening means secure configuration of routing devices by limiting management access, disabling unnecessary services, and applying strong authentication. The fixed-count item needs this function in the answer set. Cloud-infrastructure hardening covers application of least privilege, secure network exposure, logging, encryption, and service-specific security settings in cloud resources, a different requirement.

Answer C is correct because Input validation means checking and constraining application input before it is used. This option satisfies a specific requirement in the stem; Cloud-infrastructure hardening serves application of least privilege, secure network exposure, logging, encryption, and service-specific security settings in cloud resources and therefore is not interchangeable with it.

Incorrect Answers

 

Answer B is incorrect because BYOD means a deployment model in which users connect personally owned devices to organizational resources. The scenario calls for Input validation, Router hardening. Selecting this option would leave one of those required functions uncovered.

Answer D is incorrect because Security monitoring means collection and review of telemetry from hardened systems. The scenario calls for Input validation, Router hardening. Selecting this option would leave one of those required functions uncovered. For example, Router hardening is required for secure configuration of routing devices by limiting management access, disabling unnecessary services, and applying strong authentication.

Answer E is incorrect because Cloud-infrastructure hardening means application of least privilege, secure network exposure, logging, encryption, and service-specific security settings in cloud resources. The scenario calls for Input validation, Router hardening. Selecting this option would leave one of those required functions uncovered.

 

Question 4

To design wireless networks with adequate coverage and reduced unintended signal exposure, which security approach should be selected?

  1. Sandboxing
  2. WPA3
  3. Wireless site survey
  4. Input validation

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Wireless site survey means assessment of radio coverage, interference, channel use, and access-point placement. This matches the requirement as written. Input validation can be valid in another context, but it is used for checking and constraining application input before it is used.

Incorrect Answers

 

Answer A is incorrect because Sandboxing refers to execution of untrusted or risky code in an isolated restricted environment. The scenario instead requires assessment of radio coverage, interference, channel use, and access-point placement, which is why Wireless site survey is the better answer; this option serves the different function defined above.

Answer B is incorrect because WPA3 refers to a modern Wi-Fi security standard providing stronger wireless authentication and encryption protections. The concept is valid, but it does not match this stem. The required function is assessment of radio coverage, interference, channel use, and access-point placement, which maps to Wireless site survey.

Answer D is incorrect because Input validation refers to checking and constraining application input before it is used. This could be appropriate elsewhere, but the required function is assessment of radio coverage, interference, channel use, and access-point placement; that makes Wireless site survey the precise choice.

 

Question 5

To retain enterprise control while allowing some user flexibility, which security approach should be selected?

  1. Input validation
  2. Sandboxing
  3. Mobile device management (MDM)
  4. COPE

Correct Answer: D

Correct Answer

 

 

Answer D is correct because COPE means a deployment model in which the organization owns devices but permits limited personal use. This is the precise fit for the scenario. Mobile device management (MDM) serves the different purpose of centralized administration of mobile-device configuration, applications, compliance, and remote actions.

Incorrect Answers

 

Answer A is incorrect because Input validation refers to checking and constraining application input before it is used. This could be appropriate elsewhere, but the required function is a deployment model in which the organization owns devices but permits limited personal use; that makes COPE the precise choice.

Answer B is incorrect because Sandboxing refers to execution of untrusted or risky code in an isolated restricted environment. This could be appropriate elsewhere, but the required function is a deployment model in which the organization owns devices but permits limited personal use; that makes COPE the precise choice.

Answer C is incorrect because Mobile device management (MDM) refers to centralized administration of mobile-device configuration, applications, compliance, and remote actions. That concept can be valid in another scenario, but this question is testing a deployment model in which the organization owns devices but permits limited personal use; COPE therefore fits the requirement more directly.

 

Question 6

To support user-owned devices while applying policy and data protection controls, which security approach should be selected?

  1. ICS/SCADA hardening
  2. BYOD
  3. Wireless site survey
  4. Input validation

Correct Answer: B

Correct Answer

 

 

Answer B is correct because BYOD means a deployment model in which users connect personally owned devices to organizational resources. The deciding point is functional fit: this option covers the stated need, while Wireless site survey addresses assessment of radio coverage, interference, channel use, and access-point placement.

Incorrect Answers

 

Answer A is incorrect because ICS/SCADA hardening refers to security measures for industrial systems that emphasize safe change control, segmentation, monitoring, and availability. The concept is valid, but it does not match this stem. The required function is a deployment model in which users connect personally owned devices to organizational resources, which maps to BYOD.

Answer C is incorrect because Wireless site survey refers to assessment of radio coverage, interference, channel use, and access-point placement. The scenario instead requires a deployment model in which users connect personally owned devices to organizational resources, which is why BYOD is the better answer; this option serves the different function defined above.

Answer D is incorrect because Input validation refers to checking and constraining application input before it is used. The key mismatch is functional: BYOD addresses a deployment model in which users connect personally owned devices to organizational resources, the need stated by the question.

 

Question 7

During a computing-resource hardening program, the team has two independent requirements: (1) secure configuration of end-user computers through patching, least privilege, endpoint protection, and restricted services; and (2) modern Wi-Fi security standard providing stronger wireless authentication and encryption protections. Which TWO choices best satisfy those requirements? Choose TWO.

  1. Workstation hardening
  2. Wireless heat map
  3. Secure baseline
  4. WPA3
  5. Mobile device management (MDM)

Correct Answers: A, D

Correct Answers

 

 

Answer A is correct because Workstation hardening means secure configuration of end-user computers through patching, least privilege, endpoint protection, and restricted services. It belongs in the fixed-count answer set because it covers one of the stated requirements. Wireless heat map instead serves a visual representation of wireless signal strength or coverage across a physical area and cannot replace this function.

Answer D is correct because WPA3 means a modern Wi-Fi security standard providing stronger wireless authentication and encryption protections. One required function is exactly what this option provides. Secure baseline may be useful elsewhere, but it is used for an approved minimum configuration that establishes required security settings for a class of systems.

Incorrect Answers

 

Answer B is incorrect because Wireless heat map means a visual representation of wireless signal strength or coverage across a physical area. Every answer slot must map to a stated requirement. The correct set is Workstation hardening, WPA3, so this option cannot replace one of those selections.

Answer C is incorrect because Secure baseline means an approved minimum configuration that establishes required security settings for a class of systems. The fixed-count answer set is Workstation hardening, WPA3; this option does not fill one of those named functions.

Answer E is incorrect because Mobile device management (MDM) means centralized administration of mobile-device configuration, applications, compliance, and remote actions. The scenario calls for Workstation hardening, WPA3. Selecting this option would leave one of those required functions uncovered. For example, Workstation hardening is required for secure configuration of end-user computers through patching, least privilege, endpoint protection, and restricted services.

 

Question 8

To reduce theft or misuse of session-related browser data, which security approach should be selected?

  1. Secure cookie
  2. BYOD
  3. WPA3
  4. Wireless site survey

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Secure cookie means a web cookie configured with protections such as Secure, HttpOnly, and appropriate SameSite attributes. The requirement maps directly to this function, whereas WPA3 is aimed at a modern Wi-Fi security standard providing stronger wireless authentication and encryption protections.

Incorrect Answers

 

Answer B is incorrect because BYOD refers to a deployment model in which users connect personally owned devices to organizational resources. The key mismatch is functional: Secure cookie addresses a web cookie configured with protections such as Secure, HttpOnly, and appropriate SameSite attributes, the need stated by the question.

Answer C is incorrect because WPA3 refers to a modern Wi-Fi security standard providing stronger wireless authentication and encryption protections. This could be appropriate elsewhere, but the required function is a web cookie configured with protections such as Secure, HttpOnly, and appropriate SameSite attributes; that makes Secure cookie the precise choice.

Answer D is incorrect because Wireless site survey refers to assessment of radio coverage, interference, channel use, and access-point placement. The question is not asking for this function. It is testing a web cookie configured with protections such as Secure, HttpOnly, and appropriate SameSite attributes, so Secure cookie is the stronger fit.

 

Question 9

To protect operational technology without causing unsafe disruption, which security approach should be selected?

  1. ICS/SCADA hardening
  2. Wireless heat map
  3. Code signing
  4. BYOD

Correct Answer: A

Correct Answer

 

 

Answer A is correct because ICS/SCADA hardening means security measures for industrial systems that emphasize safe change control, segmentation, monitoring, and availability. This is the precise fit for the scenario. Wireless heat map serves the different purpose of a visual representation of wireless signal strength or coverage across a physical area.

Incorrect Answers

 

Answer B is incorrect because Wireless heat map refers to a visual representation of wireless signal strength or coverage across a physical area. The key mismatch is functional: ICS/SCADA hardening addresses security measures for industrial systems that emphasize safe change control, segmentation, monitoring, and availability, the need stated by the question.

Answer C is incorrect because Code signing refers to digital signing of software to verify publisher identity and detect modification. The scenario instead requires security measures for industrial systems that emphasize safe change control, segmentation, monitoring, and availability, which is why ICS/SCADA hardening is the better answer; this option serves the different function defined above.

Answer D is incorrect because BYOD refers to a deployment model in which users connect personally owned devices to organizational resources. The concept is valid, but it does not match this stem. The required function is security measures for industrial systems that emphasize safe change control, segmentation, monitoring, and availability, which maps to ICS/SCADA hardening.

 

Question 10

The control set for a computing-resource hardening program must address both secure configuration of end-user computers through patching, least privilege, endpoint protection, and restricted services and web cookie configured with protections such as Secure, HttpOnly, and appropriate SameSite attributes. Which TWO choices map directly to those needs? Choose TWO.

  1. Workstation hardening
  2. Secure cookie
  3. Router hardening
  4. RADIUS
  5. Server hardening

Correct Answers: A, B

Correct Answers

 

 

Answer A is correct because Workstation hardening means secure configuration of end-user computers through patching, least privilege, endpoint protection, and restricted services. One required function is exactly what this option provides. Router hardening may be useful elsewhere, but it is used for secure configuration of routing devices by limiting management access, disabling unnecessary services, and applying strong authentication.

Answer B is correct because Secure cookie means a web cookie configured with protections such as Secure, HttpOnly, and appropriate SameSite attributes. The fixed-count item needs this function in the answer set. RADIUS covers a centralized AAA protocol commonly used for enterprise network access authentication, a different requirement.

Incorrect Answers

 

Answer C is incorrect because Router hardening means secure configuration of routing devices by limiting management access, disabling unnecessary services, and applying strong authentication. The fixed-count answer set is Workstation hardening, Secure cookie; this option does not fill one of those named functions.

Answer D is incorrect because RADIUS means a centralized AAA protocol commonly used for enterprise network access authentication. The question requires exactly 2 selections: Workstation hardening, Secure cookie. This option falls outside that required set. For example, Secure cookie is required for a web cookie configured with protections such as Secure, HttpOnly, and appropriate SameSite attributes.

Answer E is incorrect because Server hardening means secure configuration of server operating systems and services using patching, restricted roles, monitoring, and minimized software. The question requires exactly 2 selections: Workstation hardening, Secure cookie. This option falls outside that required set.

 

Question 11

To reduce desktop attack surface and user-driven compromise, which security approach should be selected?

  1. IoT hardening
  2. Input validation
  3. Workstation hardening
  4. Mobile device management (MDM)

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Workstation hardening means secure configuration of end-user computers through patching, least privilege, endpoint protection, and restricted services. That makes it the best answer here; Input validation addresses checking and constraining application input before it is used, not the function requested in the stem.

Incorrect Answers

 

Answer A is incorrect because IoT hardening refers to security of connected embedded devices through credential changes, firmware updates, segmentation, and unnecessary-service reduction. That concept can be valid in another scenario, but this question is testing secure configuration of end-user computers through patching, least privilege, endpoint protection, and restricted services; Workstation hardening therefore fits the requirement more directly.

Answer B is incorrect because Input validation refers to checking and constraining application input before it is used. That concept can be valid in another scenario, but this question is testing secure configuration of end-user computers through patching, least privilege, endpoint protection, and restricted services; Workstation hardening therefore fits the requirement more directly.

Answer D is incorrect because Mobile device management (MDM) refers to centralized administration of mobile-device configuration, applications, compliance, and remote actions. The question is not asking for this function. It is testing secure configuration of end-user computers through patching, least privilege, endpoint protection, and restricted services, so Workstation hardening is the stronger fit.

 

Question 12

During a computing-resource hardening program, three requirements must be addressed: (1) security of connected embedded devices through credential changes, firmware updates, segmentation, and unnecessary-service reduction; (2) checking and constraining application input before it is used; and (3) collection and review of telemetry from hardened systems. Which THREE choices best satisfy them? Choose THREE.

  1. WPA3
  2. IoT hardening
  3. Input validation
  4. Sandboxing
  5. Security monitoring
  6. ICS/SCADA hardening

Correct Answers: B, C, E

Correct Answers

 

 

Answer B is correct because IoT hardening means security of connected embedded devices through credential changes, firmware updates, segmentation, and unnecessary-service reduction. The fixed-count item needs this function in the answer set. Sandboxing covers execution of untrusted or risky code in an isolated restricted environment, a different requirement.

Answer C is correct because Input validation means checking and constraining application input before it is used. This option satisfies a specific requirement in the stem; Sandboxing serves execution of untrusted or risky code in an isolated restricted environment and therefore is not interchangeable with it.

Answer E is correct because Security monitoring means collection and review of telemetry from hardened systems. The fixed-count item needs this function in the answer set. WPA3 covers a modern Wi-Fi security standard providing stronger wireless authentication and encryption protections, a different requirement.

Incorrect Answers

 

Answer A is incorrect because WPA3 means a modern Wi-Fi security standard providing stronger wireless authentication and encryption protections. The scenario calls for Input validation, IoT hardening, Security monitoring. Selecting this option would leave one of those required functions uncovered.

Answer D is incorrect because Sandboxing means execution of untrusted or risky code in an isolated restricted environment. The fixed-count answer set is Input validation, IoT hardening, Security monitoring; this option does not fill one of those named functions.

Answer F is incorrect because ICS/SCADA hardening means security measures for industrial systems that emphasize safe change control, segmentation, monitoring, and availability. The scenario calls for Input validation, IoT hardening, Security monitoring. Selecting this option would leave one of those required functions uncovered.

 

Question 13

To reduce risk from cloud misconfiguration and excessive permissions, which security approach should be selected?

  1. Cloud-infrastructure hardening
  2. CYOD
  3. Workstation hardening
  4. Secure baseline

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Cloud-infrastructure hardening means application of least privilege, secure network exposure, logging, encryption, and service-specific security settings in cloud resources. The deciding point is functional fit: this option covers the stated need, while Workstation hardening addresses secure configuration of end-user computers through patching, least privilege, endpoint protection, and restricted services.

Incorrect Answers

 

Answer B is incorrect because CYOD refers to a deployment model in which users choose from a list of organization-approved devices. The concept is valid, but it does not match this stem. The required function is application of least privilege, secure network exposure, logging, encryption, and service-specific security settings in cloud resources, which maps to Cloud-infrastructure hardening.

Answer C is incorrect because Workstation hardening refers to secure configuration of end-user computers through patching, least privilege, endpoint protection, and restricted services. This could be appropriate elsewhere, but the required function is application of least privilege, secure network exposure, logging, encryption, and service-specific security settings in cloud resources; that makes Cloud-infrastructure hardening the precise choice.

Answer D is incorrect because Secure baseline refers to an approved minimum configuration that establishes required security settings for a class of systems. The key mismatch is functional: Cloud-infrastructure hardening addresses application of least privilege, secure network exposure, logging, encryption, and service-specific security settings in cloud resources, the need stated by the question.

 

Question 14

What is a deployment model in which users choose from a list of organization-approved devices?

  1. WPA3
  2. CYOD
  3. BYOD
  4. COPE

Correct Answer: B

Correct Answer

 

 

Answer B is correct because CYOD means a deployment model in which users choose from a list of organization-approved devices. That makes it the best answer here; WPA3 addresses a modern Wi-Fi security standard providing stronger wireless authentication and encryption protections, not the function requested in the stem.

Incorrect Answers

 

Answer A is incorrect because WPA3 refers to a modern Wi-Fi security standard providing stronger wireless authentication and encryption protections. That concept can be valid in another scenario, but this question is testing a deployment model in which users choose from a list of organization-approved devices; CYOD therefore fits the requirement more directly.

Answer C is incorrect because BYOD refers to a deployment model in which users connect personally owned devices to organizational resources. The question is not asking for this function. It is testing a deployment model in which users choose from a list of organization-approved devices, so CYOD is the stronger fit.

Answer D is incorrect because COPE refers to a deployment model in which the organization owns devices but permits limited personal use. That concept can be valid in another scenario, but this question is testing a deployment model in which users choose from a list of organization-approved devices; CYOD therefore fits the requirement more directly.

 

Question 15

Which term describes checking and constraining application input before it is used?

  1. Wireless site survey
  2. Sandboxing
  3. Secure cookie
  4. Input validation

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Input validation means checking and constraining application input before it is used. The requirement maps directly to this function, whereas Secure cookie is aimed at a web cookie configured with protections such as Secure, HttpOnly, and appropriate SameSite attributes.

Incorrect Answers

 

Answer A is incorrect because Wireless site survey refers to assessment of radio coverage, interference, channel use, and access-point placement. This could be appropriate elsewhere, but the required function is checking and constraining application input before it is used; that makes Input validation the precise choice.

Answer B is incorrect because Sandboxing refers to execution of untrusted or risky code in an isolated restricted environment. The question is not asking for this function. It is testing checking and constraining application input before it is used, so Input validation is the stronger fit.

Answer C is incorrect because Secure cookie refers to a web cookie configured with protections such as Secure, HttpOnly, and appropriate SameSite attributes. This could be appropriate elsewhere, but the required function is checking and constraining application input before it is used; that makes Input validation the precise choice.

 

Question 16

Which term describes secure configuration of server operating systems and services using patching, restricted roles, monitoring, and minimized software?

  1. Secure baseline
  2. WPA3
  3. RADIUS
  4. Server hardening

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Server hardening means secure configuration of server operating systems and services using patching, restricted roles, monitoring, and minimized software. The deciding point is functional fit: this option covers the stated need, while RADIUS addresses a centralized AAA protocol commonly used for enterprise network access authentication.

Incorrect Answers

 

Answer A is incorrect because Secure baseline refers to an approved minimum configuration that establishes required security settings for a class of systems. That concept can be valid in another scenario, but this question is testing secure configuration of server operating systems and services using patching, restricted roles, monitoring, and minimized software; Server hardening therefore fits the requirement more directly.

Answer B is incorrect because WPA3 refers to a modern Wi-Fi security standard providing stronger wireless authentication and encryption protections. The scenario instead requires secure configuration of server operating systems and services using patching, restricted roles, monitoring, and minimized software, which is why Server hardening is the better answer; this option serves the different function defined above.

Answer C is incorrect because RADIUS refers to a centralized AAA protocol commonly used for enterprise network access authentication. The concept is valid, but it does not match this stem. The required function is secure configuration of server operating systems and services using patching, restricted roles, monitoring, and minimized software, which maps to Server hardening.

 

Question 17

To reduce attack surface on high-value service hosts, which security approach should be selected?

  1. CYOD
  2. Router hardening
  3. Secure baseline
  4. Server hardening

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Server hardening means secure configuration of server operating systems and services using patching, restricted roles, monitoring, and minimized software. The requirement maps directly to this function, whereas CYOD is aimed at a deployment model in which users choose from a list of organization-approved devices.

Incorrect Answers

 

Answer A is incorrect because CYOD refers to a deployment model in which users choose from a list of organization-approved devices. This could be appropriate elsewhere, but the required function is secure configuration of server operating systems and services using patching, restricted roles, monitoring, and minimized software; that makes Server hardening the precise choice.

Answer B is incorrect because Router hardening refers to secure configuration of routing devices by limiting management access, disabling unnecessary services, and applying strong authentication. The concept is valid, but it does not match this stem. The required function is secure configuration of server operating systems and services using patching, restricted roles, monitoring, and minimized software, which maps to Server hardening.

Answer C is incorrect because Secure baseline refers to an approved minimum configuration that establishes required security settings for a class of systems. This could be appropriate elsewhere, but the required function is secure configuration of server operating systems and services using patching, restricted roles, monitoring, and minimized software; that makes Server hardening the precise choice.

 

Question 18

To secure supported wireless networks against weaknesses in older Wi-Fi security methods, which security approach should be selected?

  1. WPA3
  2. Router hardening
  3. RADIUS
  4. Code signing

Correct Answer: A

Correct Answer

 

 

Answer A is correct because WPA3 means a modern Wi-Fi security standard providing stronger wireless authentication and encryption protections. The requirement maps directly to this function, whereas Router hardening is aimed at secure configuration of routing devices by limiting management access, disabling unnecessary services, and applying strong authentication.

Incorrect Answers

 

Answer B is incorrect because Router hardening refers to secure configuration of routing devices by limiting management access, disabling unnecessary services, and applying strong authentication. The question is not asking for this function. It is testing a modern Wi-Fi security standard providing stronger wireless authentication and encryption protections, so WPA3 is the stronger fit.

Answer C is incorrect because RADIUS refers to a centralized AAA protocol commonly used for enterprise network access authentication. The key mismatch is functional: WPA3 addresses a modern Wi-Fi security standard providing stronger wireless authentication and encryption protections, the need stated by the question.

Answer D is incorrect because Code signing refers to digital signing of software to verify publisher identity and detect modification. The concept is valid, but it does not match this stem. The required function is a modern Wi-Fi security standard providing stronger wireless authentication and encryption protections, which maps to WPA3.

 

Question 19

The control set for a computing-resource hardening program must address both approved minimum configuration that establishes required security settings for a class of systems and security measures for industrial systems that emphasize safe change control, segmentation, monitoring, and availability. Which TWO choices map directly to those needs? Choose TWO.

  1. COPE
  2. Wireless site survey
  3. ICS/SCADA hardening
  4. Workstation hardening
  5. Secure baseline

Correct Answers: C, E

Correct Answers

 

 

Answer C is correct because ICS/SCADA hardening means security measures for industrial systems that emphasize safe change control, segmentation, monitoring, and availability. This option satisfies a specific requirement in the stem; Wireless site survey serves assessment of radio coverage, interference, channel use, and access-point placement and therefore is not interchangeable with it.

Answer E is correct because Secure baseline means an approved minimum configuration that establishes required security settings for a class of systems. One required function is exactly what this option provides. Wireless site survey may be useful elsewhere, but it is used for assessment of radio coverage, interference, channel use, and access-point placement.

Incorrect Answers

 

Answer A is incorrect because COPE means a deployment model in which the organization owns devices but permits limited personal use. Every answer slot must map to a stated requirement. The correct set is Secure baseline, ICS/SCADA hardening, so this option cannot replace one of those selections.

Answer B is incorrect because Wireless site survey means assessment of radio coverage, interference, channel use, and access-point placement. Every answer slot must map to a stated requirement. The correct set is Secure baseline, ICS/SCADA hardening, so this option cannot replace one of those selections.

Answer D is incorrect because Workstation hardening means secure configuration of end-user computers through patching, least privilege, endpoint protection, and restricted services. The fixed-count answer set is Secure baseline, ICS/SCADA hardening; this option does not fill one of those named functions.

 

Question 20

Which term describes execution of untrusted or risky code in an isolated restricted environment?

  1. CYOD
  2. Sandboxing
  3. WPA3
  4. Security monitoring

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Sandboxing means execution of untrusted or risky code in an isolated restricted environment. That is the function the question is testing. Security monitoring would instead be used for collection and review of telemetry from hardened systems.

Incorrect Answers

 

Answer A is incorrect because CYOD refers to a deployment model in which users choose from a list of organization-approved devices. That concept can be valid in another scenario, but this question is testing execution of untrusted or risky code in an isolated restricted environment; Sandboxing therefore fits the requirement more directly.

Answer C is incorrect because WPA3 refers to a modern Wi-Fi security standard providing stronger wireless authentication and encryption protections. This could be appropriate elsewhere, but the required function is execution of untrusted or risky code in an isolated restricted environment; that makes Sandboxing the precise choice.

Answer D is incorrect because Security monitoring refers to collection and review of telemetry from hardened systems. The concept is valid, but it does not match this stem. The required function is execution of untrusted or risky code in an isolated restricted environment, which maps to Sandboxing.

Leave a Reply

How It Works

img
Step 1. Choose Exam
on ExamLabs
Download IT Exams Questions & Answers
img
Step 2. Open Exam with
Avanset Exam Simulator
Press here to download VCE Exam Simulator that simulates real exam environment
img
Step 3. Study
& Pass
IT Exams Anywhere, Anytime!