CompTIA Security+ SY0-701 Security Hardening of Computing Resources Practice Test 2

 

Topic 14 Practice Test 2 covers Security Hardening of Computing Resources for CompTIA Security+ SY0-701 and maps to objective 4.1: Given a scenario, apply common security techniques to computing resources. For broader exam preparation, review the CompTIA Security+ Exam Dumps. Every option includes focused editorial reasoning explaining both the concept and its fit to the scenario.

Question 1

To balance user choice with supportability and security standardization, which security approach should be selected?

  1. Mobile device management (MDM)
  2. Router hardening
  3. Input validation
  4. CYOD

Correct Answer: D

Correct Answer

 

 

Answer D is correct because CYOD means a deployment model in which users choose from a list of organization-approved devices. This is the precise fit for the scenario. Input validation serves the different purpose of checking and constraining application input before it is used.

Incorrect Answers

 

Answer A is incorrect because Mobile device management (MDM) refers to centralized administration of mobile-device configuration, applications, compliance, and remote actions. The question is not asking for this function. It is testing a deployment model in which users choose from a list of organization-approved devices, so CYOD is the stronger fit.

Answer B is incorrect because Router hardening refers to secure configuration of routing devices by limiting management access, disabling unnecessary services, and applying strong authentication. That concept can be valid in another scenario, but this question is testing a deployment model in which users choose from a list of organization-approved devices; CYOD therefore fits the requirement more directly.

Answer C is incorrect because Input validation refers to checking and constraining application input before it is used. That concept can be valid in another scenario, but this question is testing a deployment model in which users choose from a list of organization-approved devices; CYOD therefore fits the requirement more directly.

 

Question 2

Which term describes centralized administration of mobile-device configuration, applications, compliance, and remote actions?

  1. IoT hardening
  2. Cloud-infrastructure hardening
  3. Mobile device management (MDM)
  4. Server hardening

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Mobile device management (MDM) means centralized administration of mobile-device configuration, applications, compliance, and remote actions. This matches the requirement as written. IoT hardening can be valid in another context, but it is used for security of connected embedded devices through credential changes, firmware updates, segmentation, and unnecessary-service reduction.

Incorrect Answers

 

Answer A is incorrect because IoT hardening refers to security of connected embedded devices through credential changes, firmware updates, segmentation, and unnecessary-service reduction. The concept is valid, but it does not match this stem. The required function is centralized administration of mobile-device configuration, applications, compliance, and remote actions, which maps to Mobile device management (MDM).

Answer B is incorrect because Cloud-infrastructure hardening refers to application of least privilege, secure network exposure, logging, encryption, and service-specific security settings in cloud resources. The key mismatch is functional: Mobile device management (MDM) addresses centralized administration of mobile-device configuration, applications, compliance, and remote actions, the need stated by the question.

Answer D is incorrect because Server hardening refers to secure configuration of server operating systems and services using patching, restricted roles, monitoring, and minimized software. The concept is valid, but it does not match this stem. The required function is centralized administration of mobile-device configuration, applications, compliance, and remote actions, which maps to Mobile device management (MDM).

 

Question 3

What is a modern Wi-Fi security standard providing stronger wireless authentication and encryption protections?

  1. Mobile-device hardening
  2. WPA3
  3. Secure cookie
  4. Secure baseline

Correct Answer: B

Correct Answer

 

 

Answer B is correct because WPA3 means a modern Wi-Fi security standard providing stronger wireless authentication and encryption protections. That is the function the question is testing. Secure cookie would instead be used for a web cookie configured with protections such as Secure, HttpOnly, and appropriate SameSite attributes.

Incorrect Answers

 

Answer A is incorrect because Mobile-device hardening refers to security configuration of smartphones and tablets through encryption, screen locking, application control, and management policy. This could be appropriate elsewhere, but the required function is a modern Wi-Fi security standard providing stronger wireless authentication and encryption protections; that makes WPA3 the precise choice.

Answer C is incorrect because Secure cookie refers to a web cookie configured with protections such as Secure, HttpOnly, and appropriate SameSite attributes. This could be appropriate elsewhere, but the required function is a modern Wi-Fi security standard providing stronger wireless authentication and encryption protections; that makes WPA3 the precise choice.

Answer D is incorrect because Secure baseline refers to an approved minimum configuration that establishes required security settings for a class of systems. That concept can be valid in another scenario, but this question is testing a modern Wi-Fi security standard providing stronger wireless authentication and encryption protections; WPA3 therefore fits the requirement more directly.

 

Question 4

To help systems and users trust that code came from an expected source and was not altered, which security approach should be selected?

  1. Cloud-infrastructure hardening
  2. Security monitoring
  3. Code signing
  4. Secure cookie

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Code signing means digital signing of software to verify publisher identity and detect modification. The deciding point is functional fit: this option covers the stated need, while Secure cookie addresses a web cookie configured with protections such as Secure, HttpOnly, and appropriate SameSite attributes.

Incorrect Answers

 

Answer A is incorrect because Cloud-infrastructure hardening refers to application of least privilege, secure network exposure, logging, encryption, and service-specific security settings in cloud resources. The concept is valid, but it does not match this stem. The required function is digital signing of software to verify publisher identity and detect modification, which maps to Code signing.

Answer B is incorrect because Security monitoring refers to collection and review of telemetry from hardened systems. The scenario instead requires digital signing of software to verify publisher identity and detect modification, which is why Code signing is the better answer; this option serves the different function defined above.

Answer D is incorrect because Secure cookie refers to a web cookie configured with protections such as Secure, HttpOnly, and appropriate SameSite attributes. That concept can be valid in another scenario, but this question is testing digital signing of software to verify publisher identity and detect modification; Code signing therefore fits the requirement more directly.

 

Question 5

A security plan created during a computing-resource hardening program must provide secure configuration of end-user computers through patching, least privilege, endpoint protection, and restricted services, secure configuration of routing devices by limiting management access, disabling unnecessary services, and applying strong authentication, and secure configuration of server operating systems and services using patching, restricted roles, monitoring, and minimized software. Which THREE options should be selected? Choose THREE.

  1. CYOD
  2. Router hardening
  3. Server hardening
  4. Workstation hardening
  5. Secure cookie
  6. Mobile-device hardening

Correct Answers: B, C, D

Correct Answers

 

 

Answer B is correct because Router hardening means secure configuration of routing devices by limiting management access, disabling unnecessary services, and applying strong authentication. It belongs in the fixed-count answer set because it covers one of the stated requirements. CYOD instead serves a deployment model in which users choose from a list of organization-approved devices and cannot replace this function.

Answer C is correct because Server hardening means secure configuration of server operating systems and services using patching, restricted roles, monitoring, and minimized software. This selection maps directly to one of the named needs. Secure cookie addresses a web cookie configured with protections such as Secure, HttpOnly, and appropriate SameSite attributes, so it does not satisfy the same slot.

Answer D is correct because Workstation hardening means secure configuration of end-user computers through patching, least privilege, endpoint protection, and restricted services. One required function is exactly what this option provides. Secure cookie may be useful elsewhere, but it is used for a web cookie configured with protections such as Secure, HttpOnly, and appropriate SameSite attributes.

Incorrect Answers

 

Answer A is incorrect because CYOD means a deployment model in which users choose from a list of organization-approved devices. The scenario calls for Workstation hardening, Router hardening, Server hardening. Selecting this option would leave one of those required functions uncovered.

Answer E is incorrect because Secure cookie means a web cookie configured with protections such as Secure, HttpOnly, and appropriate SameSite attributes. The question requires exactly 3 selections: Workstation hardening, Router hardening, Server hardening. This option falls outside that required set.

Answer F is incorrect because Mobile-device hardening means security configuration of smartphones and tablets through encryption, screen locking, application control, and management policy. The required choices are Workstation hardening, Router hardening, Server hardening. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

 

Question 6

To reduce injection and unexpected-input vulnerabilities, which security approach should be selected?

  1. COPE
  2. Input validation
  3. Secure baseline
  4. Security monitoring

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Input validation means checking and constraining application input before it is used. This matches the requirement as written. Security monitoring can be valid in another context, but it is used for collection and review of telemetry from hardened systems.

Incorrect Answers

 

Answer A is incorrect because COPE refers to a deployment model in which the organization owns devices but permits limited personal use. That concept can be valid in another scenario, but this question is testing checking and constraining application input before it is used; Input validation therefore fits the requirement more directly.

Answer C is incorrect because Secure baseline refers to an approved minimum configuration that establishes required security settings for a class of systems. This could be appropriate elsewhere, but the required function is checking and constraining application input before it is used; that makes Input validation the precise choice.

Answer D is incorrect because Security monitoring refers to collection and review of telemetry from hardened systems. The concept is valid, but it does not match this stem. The required function is checking and constraining application input before it is used, which maps to Input validation.

 

Question 7

To detect drift, attacks, and operational problems after controls are deployed, which security approach should be selected?

  1. COPE
  2. Sandboxing
  3. ICS/SCADA hardening
  4. Security monitoring

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Security monitoring means collection and review of telemetry from hardened systems. This matches the requirement as written. Sandboxing can be valid in another context, but it is used for execution of untrusted or risky code in an isolated restricted environment.

Incorrect Answers

 

Answer A is incorrect because COPE refers to a deployment model in which the organization owns devices but permits limited personal use. This could be appropriate elsewhere, but the required function is collection and review of telemetry from hardened systems; that makes Security monitoring the precise choice.

Answer B is incorrect because Sandboxing refers to execution of untrusted or risky code in an isolated restricted environment. That concept can be valid in another scenario, but this question is testing collection and review of telemetry from hardened systems; Security monitoring therefore fits the requirement more directly.

Answer C is incorrect because ICS/SCADA hardening refers to security measures for industrial systems that emphasize safe change control, segmentation, monitoring, and availability. The concept is valid, but it does not match this stem. The required function is collection and review of telemetry from hardened systems, which maps to Security monitoring.

 

Question 8

Which web cookie is configured with protections such as Secure, HttpOnly, and appropriate SameSite attributes?

  1. Secure cookie
  2. RADIUS
  3. Code signing
  4. Workstation hardening

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Secure cookie means a web cookie configured with protections such as Secure, HttpOnly, and appropriate SameSite attributes. The requirement maps directly to this function, whereas Code signing is aimed at digital signing of software to verify publisher identity and detect modification.

Incorrect Answers

 

Answer B is incorrect because RADIUS refers to a centralized AAA protocol commonly used for enterprise network access authentication. The question is not asking for this function. It is testing a web cookie configured with protections such as Secure, HttpOnly, and appropriate SameSite attributes, so Secure cookie is the stronger fit.

Answer C is incorrect because Code signing refers to digital signing of software to verify publisher identity and detect modification. The question is not asking for this function. It is testing a web cookie configured with protections such as Secure, HttpOnly, and appropriate SameSite attributes, so Secure cookie is the stronger fit.

Answer D is incorrect because Workstation hardening refers to secure configuration of end-user computers through patching, least privilege, endpoint protection, and restricted services. The question is not asking for this function. It is testing a web cookie configured with protections such as Secure, HttpOnly, and appropriate SameSite attributes, so Secure cookie is the stronger fit.

 

Question 9

A review during a computing-resource hardening program identifies two gaps. One requires visual representation of wireless signal strength or coverage across a physical area. The other requires checking and constraining application input before it is used. Which TWO options should be included in the remediation plan? Choose TWO.

  1. Sandboxing
  2. Input validation
  3. COPE
  4. Wireless heat map
  5. RADIUS

Correct Answers: B, D

Correct Answers

 

 

Answer B is correct because Input validation means checking and constraining application input before it is used. One required function is exactly what this option provides. RADIUS may be useful elsewhere, but it is used for a centralized AAA protocol commonly used for enterprise network access authentication.

Answer D is correct because Wireless heat map means a visual representation of wireless signal strength or coverage across a physical area. One required function is exactly what this option provides. COPE may be useful elsewhere, but it is used for a deployment model in which the organization owns devices but permits limited personal use.

Incorrect Answers

 

Answer A is incorrect because Sandboxing means execution of untrusted or risky code in an isolated restricted environment. The scenario calls for Wireless heat map, Input validation. Selecting this option would leave one of those required functions uncovered. For example, Wireless heat map is required for a visual representation of wireless signal strength or coverage across a physical area.

Answer C is incorrect because COPE means a deployment model in which the organization owns devices but permits limited personal use. The fixed-count answer set is Wireless heat map, Input validation; this option does not fill one of those named functions.

Answer E is incorrect because RADIUS means a centralized AAA protocol commonly used for enterprise network access authentication. The fixed-count answer set is Wireless heat map, Input validation; this option does not fill one of those named functions. For example, Wireless heat map is required for a visual representation of wireless signal strength or coverage across a physical area.

 

Question 10

What is a deployment model in which the organization owns devices but permits limited personal use?

  1. Cloud-infrastructure hardening
  2. WPA3
  3. COPE
  4. Secure baseline

Correct Answer: C

Correct Answer

 

 

Answer C is correct because COPE means a deployment model in which the organization owns devices but permits limited personal use. This matches the requirement as written. WPA3 can be valid in another context, but it is used for a modern Wi-Fi security standard providing stronger wireless authentication and encryption protections.

Incorrect Answers

 

Answer A is incorrect because Cloud-infrastructure hardening refers to application of least privilege, secure network exposure, logging, encryption, and service-specific security settings in cloud resources. The key mismatch is functional: COPE addresses a deployment model in which the organization owns devices but permits limited personal use, the need stated by the question.

Answer B is incorrect because WPA3 refers to a modern Wi-Fi security standard providing stronger wireless authentication and encryption protections. This could be appropriate elsewhere, but the required function is a deployment model in which the organization owns devices but permits limited personal use; that makes COPE the precise choice.

Answer D is incorrect because Secure baseline refers to an approved minimum configuration that establishes required security settings for a class of systems. This could be appropriate elsewhere, but the required function is a deployment model in which the organization owns devices but permits limited personal use; that makes COPE the precise choice.

 

Question 11

Two requirements remain open in a computing-resource hardening program: security of connected embedded devices through credential changes, firmware updates, segmentation, and unnecessary-service reduction; deployment model in which users choose from a list of organization-approved devices. Which TWO options close those specific gaps? Choose TWO.

  1. ICS/SCADA hardening
  2. COPE
  3. IoT hardening
  4. CYOD
  5. BYOD

Correct Answers: C, D

Correct Answers

 

 

Answer C is correct because IoT hardening means security of connected embedded devices through credential changes, firmware updates, segmentation, and unnecessary-service reduction. One required function is exactly what this option provides. COPE may be useful elsewhere, but it is used for a deployment model in which the organization owns devices but permits limited personal use.

Answer D is correct because CYOD means a deployment model in which users choose from a list of organization-approved devices. The fixed-count item needs this function in the answer set. BYOD covers a deployment model in which users connect personally owned devices to organizational resources, a different requirement.

Incorrect Answers

 

Answer A is incorrect because ICS/SCADA hardening means security measures for industrial systems that emphasize safe change control, segmentation, monitoring, and availability. Every answer slot must map to a stated requirement. The correct set is CYOD, IoT hardening, so this option cannot replace one of those selections.

Answer B is incorrect because COPE means a deployment model in which the organization owns devices but permits limited personal use. The fixed-count answer set is CYOD, IoT hardening; this option does not fill one of those named functions.

Answer E is incorrect because BYOD means a deployment model in which users connect personally owned devices to organizational resources. Every answer slot must map to a stated requirement. The correct set is CYOD, IoT hardening, so this option cannot replace one of those selections.

 

Question 12

Which term describes security of connected embedded devices through credential changes, firmware updates, segmentation, and unnecessary-service reduction?

  1. IoT hardening
  2. Security monitoring
  3. BYOD
  4. Wireless site survey

Correct Answer: A

Correct Answer

 

 

Answer A is correct because IoT hardening means security of connected embedded devices through credential changes, firmware updates, segmentation, and unnecessary-service reduction. That is the function the question is testing. BYOD would instead be used for a deployment model in which users connect personally owned devices to organizational resources.

Incorrect Answers

 

Answer B is incorrect because Security monitoring refers to collection and review of telemetry from hardened systems. This could be appropriate elsewhere, but the required function is security of connected embedded devices through credential changes, firmware updates, segmentation, and unnecessary-service reduction; that makes IoT hardening the precise choice.

Answer C is incorrect because BYOD refers to a deployment model in which users connect personally owned devices to organizational resources. The question is not asking for this function. It is testing security of connected embedded devices through credential changes, firmware updates, segmentation, and unnecessary-service reduction, so IoT hardening is the stronger fit.

Answer D is incorrect because Wireless site survey refers to assessment of radio coverage, interference, channel use, and access-point placement. The scenario instead requires security of connected embedded devices through credential changes, firmware updates, segmentation, and unnecessary-service reduction, which is why IoT hardening is the better answer; this option serves the different function defined above.

 

Question 13

Which term describes secure configuration of routing devices by limiting management access, disabling unnecessary services, and applying strong authentication?

  1. IoT hardening
  2. Router hardening
  3. COPE
  4. ICS/SCADA hardening

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Router hardening means secure configuration of routing devices by limiting management access, disabling unnecessary services, and applying strong authentication. That is the function the question is testing. IoT hardening would instead be used for security of connected embedded devices through credential changes, firmware updates, segmentation, and unnecessary-service reduction.

Incorrect Answers

 

Answer A is incorrect because IoT hardening refers to security of connected embedded devices through credential changes, firmware updates, segmentation, and unnecessary-service reduction. The scenario instead requires secure configuration of routing devices by limiting management access, disabling unnecessary services, and applying strong authentication, which is why Router hardening is the better answer; this option serves the different function defined above.

Answer C is incorrect because COPE refers to a deployment model in which the organization owns devices but permits limited personal use. This could be appropriate elsewhere, but the required function is secure configuration of routing devices by limiting management access, disabling unnecessary services, and applying strong authentication; that makes Router hardening the precise choice.

Answer D is incorrect because ICS/SCADA hardening refers to security measures for industrial systems that emphasize safe change control, segmentation, monitoring, and availability. The question is not asking for this function. It is testing secure configuration of routing devices by limiting management access, disabling unnecessary services, and applying strong authentication, so Router hardening is the stronger fit.

 

Question 14

An architect working on a computing-resource hardening program needs one capability that provides deployment model in which the organization owns devices but permits limited personal use and another that provides deployment model in which users choose from a list of organization-approved devices. Which TWO selections are the best match? Choose TWO.

  1. Sandboxing
  2. RADIUS
  3. CYOD
  4. WPA3
  5. COPE

Correct Answers: C, E

Correct Answers

 

 

Answer C is correct because CYOD means a deployment model in which users choose from a list of organization-approved devices. This selection maps directly to one of the named needs. WPA3 addresses a modern Wi-Fi security standard providing stronger wireless authentication and encryption protections, so it does not satisfy the same slot.

Answer E is correct because COPE means a deployment model in which the organization owns devices but permits limited personal use. This selection maps directly to one of the named needs. RADIUS addresses a centralized AAA protocol commonly used for enterprise network access authentication, so it does not satisfy the same slot.

Incorrect Answers

 

Answer A is incorrect because Sandboxing means execution of untrusted or risky code in an isolated restricted environment. Every answer slot must map to a stated requirement. The correct set is COPE, CYOD, so this option cannot replace one of those selections.

Answer B is incorrect because RADIUS means a centralized AAA protocol commonly used for enterprise network access authentication. The scenario calls for COPE, CYOD. Selecting this option would leave one of those required functions uncovered. For example, CYOD is required for a deployment model in which users choose from a list of organization-approved devices.

Answer D is incorrect because WPA3 means a modern Wi-Fi security standard providing stronger wireless authentication and encryption protections. The fixed-count answer set is COPE, CYOD; this option does not fill one of those named functions. For example, CYOD is required for a deployment model in which users choose from a list of organization-approved devices.

 

Question 15

To authenticate users or devices for wired or wireless access through a central service, which security approach should be selected?

  1. Code signing
  2. RADIUS
  3. Sandboxing
  4. Cloud-infrastructure hardening

Correct Answer: B

Correct Answer

 

 

Answer B is correct because RADIUS means a centralized AAA protocol commonly used for enterprise network access authentication. That is the function the question is testing. Cloud-infrastructure hardening would instead be used for application of least privilege, secure network exposure, logging, encryption, and service-specific security settings in cloud resources.

Incorrect Answers

 

Answer A is incorrect because Code signing refers to digital signing of software to verify publisher identity and detect modification. This could be appropriate elsewhere, but the required function is a centralized AAA protocol commonly used for enterprise network access authentication; that makes RADIUS the precise choice.

Answer C is incorrect because Sandboxing refers to execution of untrusted or risky code in an isolated restricted environment. This could be appropriate elsewhere, but the required function is a centralized AAA protocol commonly used for enterprise network access authentication; that makes RADIUS the precise choice.

Answer D is incorrect because Cloud-infrastructure hardening refers to application of least privilege, secure network exposure, logging, encryption, and service-specific security settings in cloud resources. The scenario instead requires a centralized AAA protocol commonly used for enterprise network access authentication, which is why RADIUS is the better answer; this option serves the different function defined above.

 

Question 16

A review during a computing-resource hardening program identifies two gaps. One requires assessment of radio coverage, interference, channel use, and access-point placement. The other requires deployment model in which users connect personally owned devices to organizational resources. Which TWO options should be included in the remediation plan? Choose TWO.

  1. BYOD
  2. Code signing
  3. Mobile-device hardening
  4. Secure cookie
  5. Wireless site survey

Correct Answers: A, E

Correct Answers

 

 

Answer A is correct because BYOD means a deployment model in which users connect personally owned devices to organizational resources. The fixed-count item needs this function in the answer set. Code signing covers digital signing of software to verify publisher identity and detect modification, a different requirement.

Answer E is correct because Wireless site survey means assessment of radio coverage, interference, channel use, and access-point placement. One required function is exactly what this option provides. Secure cookie may be useful elsewhere, but it is used for a web cookie configured with protections such as Secure, HttpOnly, and appropriate SameSite attributes.

Incorrect Answers

 

Answer B is incorrect because Code signing means digital signing of software to verify publisher identity and detect modification. The fixed-count answer set is BYOD, Wireless site survey; this option does not fill one of those named functions. For example, Wireless site survey is required for assessment of radio coverage, interference, channel use, and access-point placement.

Answer C is incorrect because Mobile-device hardening means security configuration of smartphones and tablets through encryption, screen locking, application control, and management policy. The required choices are BYOD, Wireless site survey. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

Answer D is incorrect because Secure cookie means a web cookie configured with protections such as Secure, HttpOnly, and appropriate SameSite attributes. The required choices are BYOD, Wireless site survey. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

 

Question 17

To manage devices with constrained interfaces and inconsistent patching support, which security approach should be selected?

  1. IoT hardening
  2. Wireless site survey
  3. Input validation
  4. Secure baseline

Correct Answer: A

Correct Answer

 

 

Answer A is correct because IoT hardening means security of connected embedded devices through credential changes, firmware updates, segmentation, and unnecessary-service reduction. That is the function the question is testing. Wireless site survey would instead be used for assessment of radio coverage, interference, channel use, and access-point placement.

Incorrect Answers

 

Answer B is incorrect because Wireless site survey refers to assessment of radio coverage, interference, channel use, and access-point placement. The scenario instead requires security of connected embedded devices through credential changes, firmware updates, segmentation, and unnecessary-service reduction, which is why IoT hardening is the better answer; this option serves the different function defined above. This question specifically tests the requirement represented by IoT hardening.

Answer C is incorrect because Input validation refers to checking and constraining application input before it is used. The concept is valid, but it does not match this stem. The required function is security of connected embedded devices through credential changes, firmware updates, segmentation, and unnecessary-service reduction, which maps to IoT hardening.

Answer D is incorrect because Secure baseline refers to an approved minimum configuration that establishes required security settings for a class of systems. The key mismatch is functional: IoT hardening addresses security of connected embedded devices through credential changes, firmware updates, segmentation, and unnecessary-service reduction, the need stated by the question.

 

Question 18

The control set for a computing-resource hardening program must address both visual representation of wireless signal strength or coverage across a physical area and deployment model in which users connect personally owned devices to organizational resources. Which TWO choices map directly to those needs? Choose TWO.

  1. BYOD
  2. ICS/SCADA hardening
  3. Wireless heat map
  4. Cloud-infrastructure hardening
  5. Security monitoring

Correct Answers: A, C

Correct Answers

 

 

Answer A is correct because BYOD means a deployment model in which users connect personally owned devices to organizational resources. This option satisfies a specific requirement in the stem; Security monitoring serves collection and review of telemetry from hardened systems and therefore is not interchangeable with it.

Answer C is correct because Wireless heat map means a visual representation of wireless signal strength or coverage across a physical area. This selection maps directly to one of the named needs. Security monitoring addresses collection and review of telemetry from hardened systems, so it does not satisfy the same slot.

Incorrect Answers

 

Answer B is incorrect because ICS/SCADA hardening means security measures for industrial systems that emphasize safe change control, segmentation, monitoring, and availability. The question requires exactly 2 selections: Wireless heat map, BYOD. This option falls outside that required set.

Answer D is incorrect because Cloud-infrastructure hardening means application of least privilege, secure network exposure, logging, encryption, and service-specific security settings in cloud resources. The required choices are Wireless heat map, BYOD. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

Answer E is incorrect because Security monitoring means collection and review of telemetry from hardened systems. The required choices are Wireless heat map, BYOD. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

 

Question 19

Which term describes security configuration of smartphones and tablets through encryption, screen locking, application control, and management policy?

  1. Mobile-device hardening
  2. Static code analysis
  3. BYOD
  4. Wireless heat map

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Mobile-device hardening means security configuration of smartphones and tablets through encryption, screen locking, application control, and management policy. The deciding point is functional fit: this option covers the stated need, while Wireless heat map addresses a visual representation of wireless signal strength or coverage across a physical area.

Incorrect Answers

 

Answer B is incorrect because Static code analysis refers to analysis of source code or binaries without executing the application. The question is not asking for this function. It is testing security configuration of smartphones and tablets through encryption, screen locking, application control, and management policy, so Mobile-device hardening is the stronger fit.

Answer C is incorrect because BYOD refers to a deployment model in which users connect personally owned devices to organizational resources. The question is not asking for this function. It is testing security configuration of smartphones and tablets through encryption, screen locking, application control, and management policy, so Mobile-device hardening is the stronger fit.

Answer D is incorrect because Wireless heat map refers to a visual representation of wireless signal strength or coverage across a physical area. This could be appropriate elsewhere, but the required function is security configuration of smartphones and tablets through encryption, screen locking, application control, and management policy; that makes Mobile-device hardening the precise choice.

 

Question 20

Which term describes secure configuration of end-user computers through patching, least privilege, endpoint protection, and restricted services?

  1. Secure baseline
  2. CYOD
  3. Wireless heat map
  4. Workstation hardening

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Workstation hardening means secure configuration of end-user computers through patching, least privilege, endpoint protection, and restricted services. The requirement maps directly to this function, whereas Secure baseline is aimed at an approved minimum configuration that establishes required security settings for a class of systems.

Incorrect Answers

 

Answer A is incorrect because Secure baseline refers to an approved minimum configuration that establishes required security settings for a class of systems. The key mismatch is functional: Workstation hardening addresses secure configuration of end-user computers through patching, least privilege, endpoint protection, and restricted services, the need stated by the question.

Answer B is incorrect because CYOD refers to a deployment model in which users choose from a list of organization-approved devices. The key mismatch is functional: Workstation hardening addresses secure configuration of end-user computers through patching, least privilege, endpoint protection, and restricted services, the need stated by the question.

Answer C is incorrect because Wireless heat map refers to a visual representation of wireless signal strength or coverage across a physical area. The scenario instead requires secure configuration of end-user computers through patching, least privilege, endpoint protection, and restricted services, which is why Workstation hardening is the better answer; this option serves the different function defined above.

Leave a Reply

How It Works

img
Step 1. Choose Exam
on ExamLabs
Download IT Exams Questions & Answers
img
Step 2. Open Exam with
Avanset Exam Simulator
Press here to download VCE Exam Simulator that simulates real exam environment
img
Step 3. Study
& Pass
IT Exams Anywhere, Anytime!