Topic 14 Practice Test 3 covers Security Hardening of Computing Resources for CompTIA Security+ SY0-701 and maps to objective 4.1: Given a scenario, apply common security techniques to computing resources. For broader exam preparation, review the CompTIA Security+ Exam Dumps. Every option includes focused editorial reasoning explaining both the concept and its fit to the scenario.
Question 1
As part of a computing-resource hardening program, reviewers identify a need for execution of untrusted or risky code in an isolated restricted environment. Which option should they select?
- Server hardening
- Wireless site survey
- Security monitoring
- Sandboxing
Correct Answer: D
Correct Answer
Answer D is correct because Sandboxing means execution of untrusted or risky code in an isolated restricted environment. That is the function the question is testing. Server hardening would instead be used for secure configuration of server operating systems and services using patching, restricted roles, monitoring, and minimized software.
Incorrect Answers
Answer A is incorrect because Server hardening means secure configuration of server operating systems and services using patching, restricted roles, monitoring, and minimized software. The scenario instead requires execution of untrusted or risky code in an isolated restricted environment, which is why Sandboxing is the better answer; this option serves the different function defined above.
Answer B is incorrect because Wireless site survey means assessment of radio coverage, interference, channel use, and access-point placement. The scenario instead requires execution of untrusted or risky code in an isolated restricted environment, which is why Sandboxing is the better answer; this option serves the different function defined above.
Answer C is incorrect because Security monitoring means collection and review of telemetry from hardened systems. The concept is valid, but it does not match this stem. The required function is execution of untrusted or risky code in an isolated restricted environment, which maps to Sandboxing.
Question 2
An architect working on a computing-resource hardening program needs one capability that provides secure configuration of server operating systems and services using patching, restricted roles, monitoring, and minimized software and another that provides assessment of radio coverage, interference, channel use, and access-point placement. Which TWO selections are the best match? Choose TWO.
- CYOD
- Wireless site survey
- Cloud-infrastructure hardening
- Security monitoring
- Server hardening
Correct Answers: B, E
Correct Answers
Answer B is correct because Wireless site survey means assessment of radio coverage, interference, channel use, and access-point placement. This selection maps directly to one of the named needs. Cloud-infrastructure hardening addresses application of least privilege, secure network exposure, logging, encryption, and service-specific security settings in cloud resources, so it does not satisfy the same slot.
Answer E is correct because Server hardening means secure configuration of server operating systems and services using patching, restricted roles, monitoring, and minimized software. This option satisfies a specific requirement in the stem; Security monitoring serves collection and review of telemetry from hardened systems and therefore is not interchangeable with it.
Incorrect Answers
Answer A is incorrect because CYOD means a deployment model in which users choose from a list of organization-approved devices. The fixed-count answer set is Wireless site survey, Server hardening; this option does not fill one of those named functions.
Answer C is incorrect because Cloud-infrastructure hardening means application of least privilege, secure network exposure, logging, encryption, and service-specific security settings in cloud resources. The fixed-count answer set is Wireless site survey, Server hardening; this option does not fill one of those named functions.
Answer D is incorrect because Security monitoring means collection and review of telemetry from hardened systems. The question requires exactly 2 selections: Wireless site survey, Server hardening. This option falls outside that required set. For example, Server hardening is required for secure configuration of server operating systems and services using patching, restricted roles, monitoring, and minimized software.
Question 3
To identify weak, excessive, or overlapping coverage zones, which security approach should be selected?
- Static code analysis
- WPA3
- Wireless heat map
- ICS/SCADA hardening
Correct Answer: C
Correct Answer
Answer C is correct because Wireless heat map means a visual representation of wireless signal strength or coverage across a physical area. The deciding point is functional fit: this option covers the stated need, while WPA3 addresses a modern Wi-Fi security standard providing stronger wireless authentication and encryption protections.
Incorrect Answers
Answer A is incorrect because Static code analysis refers to analysis of source code or binaries without executing the application. This could be appropriate elsewhere, but the required function is a visual representation of wireless signal strength or coverage across a physical area; that makes Wireless heat map the precise choice.
Answer B is incorrect because WPA3 refers to a modern Wi-Fi security standard providing stronger wireless authentication and encryption protections. This could be appropriate elsewhere, but the required function is a visual representation of wireless signal strength or coverage across a physical area; that makes Wireless heat map the precise choice.
Answer D is incorrect because ICS/SCADA hardening refers to security measures for industrial systems that emphasize safe change control, segmentation, monitoring, and availability. The question is not asking for this function. It is testing a visual representation of wireless signal strength or coverage across a physical area, so Wireless heat map is the stronger fit.
Question 4
An architect working on a computing-resource hardening program needs one capability that provides application of least privilege, secure network exposure, logging, encryption, and service-specific security settings in cloud resources and another that provides deployment model in which the organization owns devices but permits limited personal use. Which TWO selections are the best match? Choose TWO.
- Cloud-infrastructure hardening
- Code signing
- Secure baseline
- COPE
- Server hardening
Correct Answers: A, D
Correct Answers
Answer A is correct because Cloud-infrastructure hardening means application of least privilege, secure network exposure, logging, encryption, and service-specific security settings in cloud resources. One required function is exactly what this option provides. Code signing may be useful elsewhere, but it is used for digital signing of software to verify publisher identity and detect modification.
Answer D is correct because COPE means a deployment model in which the organization owns devices but permits limited personal use. It belongs in the fixed-count answer set because it covers one of the stated requirements. Server hardening instead serves secure configuration of server operating systems and services using patching, restricted roles, monitoring, and minimized software and cannot replace this function.
Incorrect Answers
Answer B is incorrect because Code signing means digital signing of software to verify publisher identity and detect modification. The fixed-count answer set is COPE, Cloud-infrastructure hardening; this option does not fill one of those named functions. For example, Cloud-infrastructure hardening is required for application of least privilege, secure network exposure, logging, encryption, and service-specific security settings in cloud resources.
Answer C is incorrect because Secure baseline means an approved minimum configuration that establishes required security settings for a class of systems. The required choices are COPE, Cloud-infrastructure hardening. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Answer E is incorrect because Server hardening means secure configuration of server operating systems and services using patching, restricted roles, monitoring, and minimized software. Every answer slot must map to a stated requirement. The correct set is COPE, Cloud-infrastructure hardening, so this option cannot replace one of those selections.
Question 5
To enforce mobile security policy at scale, which security approach should be selected?
- Mobile device management (MDM)
- Router hardening
- Workstation hardening
- Static code analysis
Correct Answer: A
Correct Answer
Answer A is correct because Mobile device management (MDM) means centralized administration of mobile-device configuration, applications, compliance, and remote actions. This is the precise fit for the scenario. Router hardening serves the different purpose of secure configuration of routing devices by limiting management access, disabling unnecessary services, and applying strong authentication.
Incorrect Answers
Answer B is incorrect because Router hardening refers to secure configuration of routing devices by limiting management access, disabling unnecessary services, and applying strong authentication. The key mismatch is functional: Mobile device management (MDM) addresses centralized administration of mobile-device configuration, applications, compliance, and remote actions, the need stated by the question.
Answer C is incorrect because Workstation hardening refers to secure configuration of end-user computers through patching, least privilege, endpoint protection, and restricted services. The scenario instead requires centralized administration of mobile-device configuration, applications, compliance, and remote actions, which is why Mobile device management (MDM) is the better answer; this option serves the different function defined above.
Answer D is incorrect because Static code analysis refers to analysis of source code or binaries without executing the application. The concept is valid, but it does not match this stem. The required function is centralized administration of mobile-device configuration, applications, compliance, and remote actions, which maps to Mobile device management (MDM).
Question 6
To protect control-plane and administrative functions on routers, which security approach should be selected?
- Secure cookie
- Secure baseline
- Router hardening
- COPE
Correct Answer: C
Correct Answer
Answer C is correct because Router hardening means secure configuration of routing devices by limiting management access, disabling unnecessary services, and applying strong authentication. The deciding point is functional fit: this option covers the stated need, while Secure cookie addresses a web cookie configured with protections such as Secure, HttpOnly, and appropriate SameSite attributes.
Incorrect Answers
Answer A is incorrect because Secure cookie refers to a web cookie configured with protections such as Secure, HttpOnly, and appropriate SameSite attributes. The key mismatch is functional: Router hardening addresses secure configuration of routing devices by limiting management access, disabling unnecessary services, and applying strong authentication, the need stated by the question.
Answer B is incorrect because Secure baseline refers to an approved minimum configuration that establishes required security settings for a class of systems. That concept can be valid in another scenario, but this question is testing secure configuration of routing devices by limiting management access, disabling unnecessary services, and applying strong authentication; Router hardening therefore fits the requirement more directly.
Answer D is incorrect because COPE refers to a deployment model in which the organization owns devices but permits limited personal use. That concept can be valid in another scenario, but this question is testing secure configuration of routing devices by limiting management access, disabling unnecessary services, and applying strong authentication; Router hardening therefore fits the requirement more directly.
Question 7
Which centralized AAA protocol commonly is used for enterprise network access authentication?
- Static code analysis
- RADIUS
- Router hardening
- BYOD
Correct Answer: B
Correct Answer
Answer B is correct because RADIUS means a centralized AAA protocol commonly used for enterprise network access authentication. That makes it the best answer here; Static code analysis addresses analysis of source code or binaries without executing the application, not the function requested in the stem.
Incorrect Answers
Answer A is incorrect because Static code analysis refers to analysis of source code or binaries without executing the application. This could be appropriate elsewhere, but the required function is a centralized AAA protocol commonly used for enterprise network access authentication; that makes RADIUS the precise choice.
Answer C is incorrect because Router hardening refers to secure configuration of routing devices by limiting management access, disabling unnecessary services, and applying strong authentication. This could be appropriate elsewhere, but the required function is a centralized AAA protocol commonly used for enterprise network access authentication; that makes RADIUS the precise choice.
Answer D is incorrect because BYOD refers to a deployment model in which users connect personally owned devices to organizational resources. That concept can be valid in another scenario, but this question is testing a centralized AAA protocol commonly used for enterprise network access authentication; RADIUS therefore fits the requirement more directly.
Question 8
To reduce compromise risk on portable endpoints, which security approach should be selected?
- Wireless heat map
- Wireless site survey
- Mobile-device hardening
- Cloud-infrastructure hardening
Correct Answer: C
Correct Answer
Answer C is correct because Mobile-device hardening means security configuration of smartphones and tablets through encryption, screen locking, application control, and management policy. The deciding point is functional fit: this option covers the stated need, while Wireless site survey addresses assessment of radio coverage, interference, channel use, and access-point placement.
Incorrect Answers
Answer A is incorrect because Wireless heat map refers to a visual representation of wireless signal strength or coverage across a physical area. The question is not asking for this function. It is testing security configuration of smartphones and tablets through encryption, screen locking, application control, and management policy, so Mobile-device hardening is the stronger fit.
Answer B is incorrect because Wireless site survey refers to assessment of radio coverage, interference, channel use, and access-point placement. The concept is valid, but it does not match this stem. The required function is security configuration of smartphones and tablets through encryption, screen locking, application control, and management policy, which maps to Mobile-device hardening.
Answer D is incorrect because Cloud-infrastructure hardening refers to application of least privilege, secure network exposure, logging, encryption, and service-specific security settings in cloud resources. The question is not asking for this function. It is testing security configuration of smartphones and tablets through encryption, screen locking, application control, and management policy, so Mobile-device hardening is the stronger fit.
Question 9
Which approved minimum configuration establishes required security settings for a class of systems?
- ICS/SCADA hardening
- Secure cookie
- Secure baseline
- Code signing
Correct Answer: C
Correct Answer
Answer C is correct because Secure baseline means an approved minimum configuration that establishes required security settings for a class of systems. That is the function the question is testing. Secure cookie would instead be used for a web cookie configured with protections such as Secure, HttpOnly, and appropriate SameSite attributes.
Incorrect Answers
Answer A is incorrect because ICS/SCADA hardening refers to security measures for industrial systems that emphasize safe change control, segmentation, monitoring, and availability. The key mismatch is functional: Secure baseline addresses an approved minimum configuration that establishes required security settings for a class of systems, the need stated by the question.
Answer B is incorrect because Secure cookie refers to a web cookie configured with protections such as Secure, HttpOnly, and appropriate SameSite attributes. The question is not asking for this function. It is testing an approved minimum configuration that establishes required security settings for a class of systems, so Secure baseline is the stronger fit.
Answer D is incorrect because Code signing refers to digital signing of software to verify publisher identity and detect modification. The concept is valid, but it does not match this stem. The required function is an approved minimum configuration that establishes required security settings for a class of systems, which maps to Secure baseline.
Question 10
A review during a computing-resource hardening program identifies two gaps. One requires centralized administration of mobile-device configuration, applications, compliance, and remote actions. The other requires web cookie configured with protections such as Secure, HttpOnly, and appropriate SameSite attributes. Which TWO options should be included in the remediation plan? Choose TWO.
- Secure cookie
- CYOD
- BYOD
- Cloud-infrastructure hardening
- Mobile device management (MDM)
Correct Answers: A, E
Correct Answers
Answer A is correct because Secure cookie means a web cookie configured with protections such as Secure, HttpOnly, and appropriate SameSite attributes. It belongs in the fixed-count answer set because it covers one of the stated requirements. CYOD instead serves a deployment model in which users choose from a list of organization-approved devices and cannot replace this function.
Answer E is correct because Mobile device management (MDM) means centralized administration of mobile-device configuration, applications, compliance, and remote actions. This option satisfies a specific requirement in the stem; CYOD serves a deployment model in which users choose from a list of organization-approved devices and therefore is not interchangeable with it.
Incorrect Answers
Answer B is incorrect because CYOD means a deployment model in which users choose from a list of organization-approved devices. The required choices are Secure cookie, Mobile device management (MDM). Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Answer C is incorrect because BYOD means a deployment model in which users connect personally owned devices to organizational resources. The question requires exactly 2 selections: Secure cookie, Mobile device management (MDM). This option falls outside that required set.
Answer D is incorrect because Cloud-infrastructure hardening means application of least privilege, secure network exposure, logging, encryption, and service-specific security settings in cloud resources. The fixed-count answer set is Secure cookie, Mobile device management (MDM); this option does not fill one of those named functions.
Question 11
Which term describes application of least privilege, secure network exposure, logging, encryption, and service-specific security settings in cloud resources?
- ICS/SCADA hardening
- Router hardening
- IoT hardening
- Cloud-infrastructure hardening
Correct Answer: D
Correct Answer
Answer D is correct because Cloud-infrastructure hardening means application of least privilege, secure network exposure, logging, encryption, and service-specific security settings in cloud resources. The deciding point is functional fit: this option covers the stated need, while Router hardening addresses secure configuration of routing devices by limiting management access, disabling unnecessary services, and applying strong authentication.
Incorrect Answers
Answer A is incorrect because ICS/SCADA hardening refers to security measures for industrial systems that emphasize safe change control, segmentation, monitoring, and availability. That concept can be valid in another scenario, but this question is testing application of least privilege, secure network exposure, logging, encryption, and service-specific security settings in cloud resources; Cloud-infrastructure hardening therefore fits the requirement more directly.
Answer B is incorrect because Router hardening refers to secure configuration of routing devices by limiting management access, disabling unnecessary services, and applying strong authentication. This could be appropriate elsewhere, but the required function is application of least privilege, secure network exposure, logging, encryption, and service-specific security settings in cloud resources; that makes Cloud-infrastructure hardening the precise choice.
Answer C is incorrect because IoT hardening refers to security of connected embedded devices through credential changes, firmware updates, segmentation, and unnecessary-service reduction. The concept is valid, but it does not match this stem. The required function is application of least privilege, secure network exposure, logging, encryption, and service-specific security settings in cloud resources, which maps to Cloud-infrastructure hardening.
Question 12
During a computing-resource hardening program, the team needs approved minimum configuration that establishes required security settings for a class of systems. Which option best meets this requirement?
- Secure baseline
- Server hardening
- COPE
- Code signing
Correct Answer: A
Correct Answer
Answer A is correct because Secure baseline means an approved minimum configuration that establishes required security settings for a class of systems. That makes it the best answer here; COPE addresses a deployment model in which the organization owns devices but permits limited personal use, not the function requested in the stem.
Incorrect Answers
Answer B is incorrect because Server hardening means secure configuration of server operating systems and services using patching, restricted roles, monitoring, and minimized software. The scenario instead requires an approved minimum configuration that establishes required security settings for a class of systems, which is why Secure baseline is the better answer; this option serves the different function defined above.
Answer C is incorrect because COPE means a deployment model in which the organization owns devices but permits limited personal use. The question is not asking for this function. It is testing an approved minimum configuration that establishes required security settings for a class of systems, so Secure baseline is the stronger fit.
Answer D is incorrect because Code signing means digital signing of software to verify publisher identity and detect modification. The key mismatch is functional: Secure baseline addresses an approved minimum configuration that establishes required security settings for a class of systems, the need stated by the question.
Question 13
During a computing-resource hardening program, the team has two independent requirements: (1) security measures for industrial systems that emphasize safe change control, segmentation, monitoring, and availability; and (2) collection and review of telemetry from hardened systems. Which TWO choices best satisfy those requirements? Choose TWO.
- WPA3
- ICS/SCADA hardening
- Router hardening
- Secure cookie
- Security monitoring
Correct Answers: B, E
Correct Answers
Answer B is correct because ICS/SCADA hardening means security measures for industrial systems that emphasize safe change control, segmentation, monitoring, and availability. This option satisfies a specific requirement in the stem; Router hardening serves secure configuration of routing devices by limiting management access, disabling unnecessary services, and applying strong authentication and therefore is not interchangeable with it.
Answer E is correct because Security monitoring means collection and review of telemetry from hardened systems. The fixed-count item needs this function in the answer set. Secure cookie covers a web cookie configured with protections such as Secure, HttpOnly, and appropriate SameSite attributes, a different requirement.
Incorrect Answers
Answer A is incorrect because WPA3 means a modern Wi-Fi security standard providing stronger wireless authentication and encryption protections. The scenario calls for ICS/SCADA hardening, Security monitoring. Selecting this option would leave one of those required functions uncovered.
Answer C is incorrect because Router hardening means secure configuration of routing devices by limiting management access, disabling unnecessary services, and applying strong authentication. The scenario calls for ICS/SCADA hardening, Security monitoring. Selecting this option would leave one of those required functions uncovered.
Answer D is incorrect because Secure cookie means a web cookie configured with protections such as Secure, HttpOnly, and appropriate SameSite attributes. Every answer slot must map to a stated requirement. The correct set is ICS/SCADA hardening, Security monitoring, so this option cannot replace one of those selections.
Question 14
What is a deployment model in which users connect personally owned devices to organizational resources?
- BYOD
- Workstation hardening
- Server hardening
- Input validation
Correct Answer: A
Correct Answer
Answer A is correct because BYOD means a deployment model in which users connect personally owned devices to organizational resources. The deciding point is functional fit: this option covers the stated need, while Input validation addresses checking and constraining application input before it is used.
Incorrect Answers
Answer B is incorrect because Workstation hardening refers to secure configuration of end-user computers through patching, least privilege, endpoint protection, and restricted services. The scenario instead requires a deployment model in which users connect personally owned devices to organizational resources, which is why BYOD is the better answer; this option serves the different function defined above.
Answer C is incorrect because Server hardening refers to secure configuration of server operating systems and services using patching, restricted roles, monitoring, and minimized software. The question is not asking for this function. It is testing a deployment model in which users connect personally owned devices to organizational resources, so BYOD is the stronger fit.
Answer D is incorrect because Input validation refers to checking and constraining application input before it is used. The scenario instead requires a deployment model in which users connect personally owned devices to organizational resources, which is why BYOD is the better answer; this option serves the different function defined above.
Question 15
Which term describes analysis of source code or binaries without executing the application?
- COPE
- Static code analysis
- Sandboxing
- BYOD
Correct Answer: B
Correct Answer
Answer B is correct because Static code analysis means analysis of source code or binaries without executing the application. This matches the requirement as written. BYOD can be valid in another context, but it is used for a deployment model in which users connect personally owned devices to organizational resources.
Incorrect Answers
Answer A is incorrect because COPE refers to a deployment model in which the organization owns devices but permits limited personal use. The question is not asking for this function. It is testing analysis of source code or binaries without executing the application, so Static code analysis is the stronger fit.
Answer C is incorrect because Sandboxing refers to execution of untrusted or risky code in an isolated restricted environment. The scenario instead requires analysis of source code or binaries without executing the application, which is why Static code analysis is the better answer; this option serves the different function defined above.
Answer D is incorrect because BYOD refers to a deployment model in which users connect personally owned devices to organizational resources. The key mismatch is functional: Static code analysis addresses analysis of source code or binaries without executing the application, the need stated by the question.
Question 16
Reviewers working through a computing-resource hardening program identify three separate needs: application of least privilege, secure network exposure, logging, encryption, and service-specific security settings in cloud resources; secure configuration of server operating systems and services using patching, restricted roles, monitoring, and minimized software; analysis of source code or binaries without executing the application. Which THREE choices map to those needs? Choose THREE.
- Static code analysis
- IoT hardening
- Cloud-infrastructure hardening
- Workstation hardening
- Server hardening
- Wireless heat map
Correct Answers: A, C, E
Correct Answers
Answer A is correct because Static code analysis means analysis of source code or binaries without executing the application. This selection maps directly to one of the named needs. Workstation hardening addresses secure configuration of end-user computers through patching, least privilege, endpoint protection, and restricted services, so it does not satisfy the same slot.
Answer C is correct because Cloud-infrastructure hardening means application of least privilege, secure network exposure, logging, encryption, and service-specific security settings in cloud resources. One required function is exactly what this option provides. Workstation hardening may be useful elsewhere, but it is used for secure configuration of end-user computers through patching, least privilege, endpoint protection, and restricted services.
Answer E is correct because Server hardening means secure configuration of server operating systems and services using patching, restricted roles, monitoring, and minimized software. The fixed-count item needs this function in the answer set. Workstation hardening covers secure configuration of end-user computers through patching, least privilege, endpoint protection, and restricted services, a different requirement.
Incorrect Answers
Answer B is incorrect because IoT hardening means security of connected embedded devices through credential changes, firmware updates, segmentation, and unnecessary-service reduction. The scenario calls for Server hardening, Cloud-infrastructure hardening, Static code analysis. Selecting this option would leave one of those required functions uncovered.
Answer D is incorrect because Workstation hardening means secure configuration of end-user computers through patching, least privilege, endpoint protection, and restricted services. The scenario calls for Server hardening, Cloud-infrastructure hardening, Static code analysis. Selecting this option would leave one of those required functions uncovered.
Answer F is incorrect because Wireless heat map means a visual representation of wireless signal strength or coverage across a physical area. The question requires exactly 3 selections: Server hardening, Cloud-infrastructure hardening, Static code analysis. This option falls outside that required set.
Question 17
Two requirements remain open in a computing-resource hardening program: application of least privilege, secure network exposure, logging, encryption, and service-specific security settings in cloud resources; web cookie configured with protections such as Secure, HttpOnly, and appropriate SameSite attributes. Which TWO options close those specific gaps? Choose TWO.
- Secure baseline
- Secure cookie
- Mobile-device hardening
- Cloud-infrastructure hardening
- Wireless heat map
Correct Answers: B, D
Correct Answers
Answer B is correct because Secure cookie means a web cookie configured with protections such as Secure, HttpOnly, and appropriate SameSite attributes. This selection maps directly to one of the named needs. Secure baseline addresses an approved minimum configuration that establishes required security settings for a class of systems, so it does not satisfy the same slot.
Answer D is correct because Cloud-infrastructure hardening means application of least privilege, secure network exposure, logging, encryption, and service-specific security settings in cloud resources. One required function is exactly what this option provides. Wireless heat map may be useful elsewhere, but it is used for a visual representation of wireless signal strength or coverage across a physical area.
Incorrect Answers
Answer A is incorrect because Secure baseline means an approved minimum configuration that establishes required security settings for a class of systems. Every answer slot must map to a stated requirement. The correct set is Cloud-infrastructure hardening, Secure cookie, so this option cannot replace one of those selections.
Answer C is incorrect because Mobile-device hardening means security configuration of smartphones and tablets through encryption, screen locking, application control, and management policy. The question requires exactly 2 selections: Cloud-infrastructure hardening, Secure cookie. This option falls outside that required set.
Answer E is incorrect because Wireless heat map means a visual representation of wireless signal strength or coverage across a physical area. The required choices are Cloud-infrastructure hardening, Secure cookie. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Question 18
To deploy consistent hardened settings and detect configuration drift, which security approach should be selected?
- Mobile device management (MDM)
- Secure baseline
- Static code analysis
- CYOD
Correct Answer: B
Correct Answer
Answer B is correct because Secure baseline means an approved minimum configuration that establishes required security settings for a class of systems. The requirement maps directly to this function, whereas Static code analysis is aimed at analysis of source code or binaries without executing the application.
Incorrect Answers
Answer A is incorrect because Mobile device management (MDM) refers to centralized administration of mobile-device configuration, applications, compliance, and remote actions. The key mismatch is functional: Secure baseline addresses an approved minimum configuration that establishes required security settings for a class of systems, the need stated by the question.
Answer C is incorrect because Static code analysis refers to analysis of source code or binaries without executing the application. This could be appropriate elsewhere, but the required function is an approved minimum configuration that establishes required security settings for a class of systems; that makes Secure baseline the precise choice.
Answer D is incorrect because CYOD refers to a deployment model in which users choose from a list of organization-approved devices. That concept can be valid in another scenario, but this question is testing an approved minimum configuration that establishes required security settings for a class of systems; Secure baseline therefore fits the requirement more directly.
Question 19
Which term describes security measures for industrial systems that emphasize safe change control, segmentation, monitoring, and availability?
- Server hardening
- ICS/SCADA hardening
- IoT hardening
- Wireless heat map
Correct Answer: B
Correct Answer
Answer B is correct because ICS/SCADA hardening means security measures for industrial systems that emphasize safe change control, segmentation, monitoring, and availability. This matches the requirement as written. Server hardening can be valid in another context, but it is used for secure configuration of server operating systems and services using patching, restricted roles, monitoring, and minimized software.
Incorrect Answers
Answer A is incorrect because Server hardening refers to secure configuration of server operating systems and services using patching, restricted roles, monitoring, and minimized software. The scenario instead requires security measures for industrial systems that emphasize safe change control, segmentation, monitoring, and availability, which is why ICS/SCADA hardening is the better answer; this option serves the different function defined above.
Answer C is incorrect because IoT hardening refers to security of connected embedded devices through credential changes, firmware updates, segmentation, and unnecessary-service reduction. The concept is valid, but it does not match this stem. The required function is security measures for industrial systems that emphasize safe change control, segmentation, monitoring, and availability, which maps to ICS/SCADA hardening.
Answer D is incorrect because Wireless heat map refers to a visual representation of wireless signal strength or coverage across a physical area. This could be appropriate elsewhere, but the required function is security measures for industrial systems that emphasize safe change control, segmentation, monitoring, and availability; that makes ICS/SCADA hardening the precise choice.
Question 20
What is a visual representation of wireless signal strength or coverage across a physical area?
- Wireless site survey
- Secure baseline
- Workstation hardening
- Wireless heat map
Correct Answer: D
Correct Answer
Answer D is correct because Wireless heat map means a visual representation of wireless signal strength or coverage across a physical area. This is the precise fit for the scenario. Workstation hardening serves the different purpose of secure configuration of end-user computers through patching, least privilege, endpoint protection, and restricted services.
Incorrect Answers
Answer A is incorrect because Wireless site survey refers to assessment of radio coverage, interference, channel use, and access-point placement. This could be appropriate elsewhere, but the required function is a visual representation of wireless signal strength or coverage across a physical area; that makes Wireless heat map the precise choice.
Answer B is incorrect because Secure baseline refers to an approved minimum configuration that establishes required security settings for a class of systems. The question is not asking for this function. It is testing a visual representation of wireless signal strength or coverage across a physical area, so Wireless heat map is the stronger fit.
Answer C is incorrect because Workstation hardening refers to secure configuration of end-user computers through patching, least privilege, endpoint protection, and restricted services. The concept is valid, but it does not match this stem. The required function is a visual representation of wireless signal strength or coverage across a physical area, which maps to Wireless heat map.