Topic 02 Practice Test 1 covers Fundamental Security Concepts for CompTIA Security+ SY0-701 and maps to objective 1.2: Summarize fundamental security concepts. For broader exam preparation, review the CompTIA Security+ Exam Dumps. Every option includes focused editorial reasoning explaining both the concept and its fit to the scenario.
Question 1
During a zero-trust and foundational-security design review, the team has two independent requirements: (1) security objective of preventing unauthorized or undetected modification of data and systems; and (2) decoy system or service intended to attract and observe malicious activity. Which TWO choices best satisfy those requirements? Choose TWO.
- Honeypot
- Integrity
- Non-repudiation
- Policy enforcement point
- Honeytoken
Correct Answers: A, B
Correct Answers
Answer A is correct because Honeypot means a decoy system or service intended to attract and observe malicious activity. This selection maps directly to one of the named needs. Non-repudiation addresses assurance that a party cannot credibly deny having performed a specific action or sent a specific message, so it does not satisfy the same slot.
Answer B is correct because Integrity means the security objective of preventing unauthorized or undetected modification of data and systems. This selection maps directly to one of the named needs. Honeytoken addresses a fake credential, record, API key, or other data element that has no legitimate use and can reveal unauthorized access when touched, so it does not satisfy the same slot.
Incorrect Answers
Answer C is incorrect because Non-repudiation means assurance that a party cannot credibly deny having performed a specific action or sent a specific message. Every answer slot must map to a stated requirement. The correct set is Integrity, Honeypot, so this option cannot replace one of those selections.
Answer D is incorrect because Policy enforcement point means the component that actually allows, blocks, or terminates traffic according to policy decisions. The question requires exactly 2 selections: Integrity, Honeypot. This option falls outside that required set. For example, Integrity is required for the security objective of preventing unauthorized or undetected modification of data and systems.
Answer E is incorrect because Honeytoken means a fake credential, record, API key, or other data element that has no legitimate use and can reveal unauthorized access when touched. The question requires exactly 2 selections: Integrity, Honeypot. This option falls outside that required set.
Question 2
To keep sensitive information available only to authorized subjects, which security approach should be selected?
- Authentication
- Access control vestibule
- Confidentiality
- Authorization
Correct Answer: C
Correct Answer
Answer C is correct because Confidentiality means the security objective of preventing unauthorized disclosure of information. The deciding point is functional fit: this option covers the stated need, while Access control vestibule addresses a physical entry design that uses two controlled doors so only one is open at a time.
Incorrect Answers
Answer A is incorrect because Authentication refers to the process of verifying the identity of a user, device, or other entity. The key mismatch is functional: Confidentiality addresses the security objective of preventing unauthorized disclosure of information, the need stated by the question.
Answer B is incorrect because Access control vestibule refers to a physical entry design that uses two controlled doors so only one is open at a time. The scenario instead requires the security objective of preventing unauthorized disclosure of information, which is why Confidentiality is the better answer; this option serves the different function defined above.
Answer D is incorrect because Authorization refers to the process of determining what an authenticated identity is allowed to do. The key mismatch is functional: Confidentiality addresses the security objective of preventing unauthorized disclosure of information, the need stated by the question.
Question 3
What is the security objective of preventing unauthorized disclosure of information?
- Confidentiality
- Honeypot
- Non-repudiation
- Bollard
Correct Answer: A
Correct Answer
Answer A is correct because Confidentiality means the security objective of preventing unauthorized disclosure of information. That makes it the best answer here; Honeypot addresses a decoy system or service intended to attract and observe malicious activity, not the function requested in the stem.
Incorrect Answers
Answer B is incorrect because Honeypot refers to a decoy system or service intended to attract and observe malicious activity. That concept can be valid in another scenario, but this question is testing the security objective of preventing unauthorized disclosure of information; Confidentiality therefore fits the requirement more directly.
Answer C is incorrect because Non-repudiation refers to assurance that a party cannot credibly deny having performed a specific action or sent a specific message. That concept can be valid in another scenario, but this question is testing the security objective of preventing unauthorized disclosure of information; Confidentiality therefore fits the requirement more directly.
Answer D is incorrect because Bollard refers to a sturdy physical barrier positioned to prevent vehicles from reaching protected areas. That concept can be valid in another scenario, but this question is testing the security objective of preventing unauthorized disclosure of information; Confidentiality therefore fits the requirement more directly.
Question 4
What is the security objective of preventing unauthorized or undetected modification of data and systems?
- Authorization
- Bollard
- Integrity
- Honeytoken
Correct Answer: C
Correct Answer
Answer C is correct because Integrity means the security objective of preventing unauthorized or undetected modification of data and systems. This is the precise fit for the scenario. Authorization serves the different purpose of the process of determining what an authenticated identity is allowed to do.
Incorrect Answers
Answer A is incorrect because Authorization refers to the process of determining what an authenticated identity is allowed to do. The question is not asking for this function. It is testing the security objective of preventing unauthorized or undetected modification of data and systems, so Integrity is the stronger fit.
Answer B is incorrect because Bollard refers to a sturdy physical barrier positioned to prevent vehicles from reaching protected areas. The key mismatch is functional: Integrity addresses the security objective of preventing unauthorized or undetected modification of data and systems, the need stated by the question.
Answer D is incorrect because Honeytoken refers to a fake credential, record, API key, or other data element that has no legitimate use and can reveal unauthorized access when touched. The concept is valid, but it does not match this stem. The required function is the security objective of preventing unauthorized or undetected modification of data and systems, which maps to Integrity.
Question 5
To ensure information remains accurate, complete, and trustworthy, which security approach should be selected?
- Integrity
- Gap analysis
- Bollard
- Policy enforcement point
Correct Answer: A
Correct Answer
Answer A is correct because Integrity means the security objective of preventing unauthorized or undetected modification of data and systems. The deciding point is functional fit: this option covers the stated need, while Bollard addresses a sturdy physical barrier positioned to prevent vehicles from reaching protected areas.
Incorrect Answers
Answer B is incorrect because Gap analysis refers to a comparison of the current security state with a required or desired target state. The key mismatch is functional: Integrity addresses the security objective of preventing unauthorized or undetected modification of data and systems, the need stated by the question.
Answer C is incorrect because Bollard refers to a sturdy physical barrier positioned to prevent vehicles from reaching protected areas. The concept is valid, but it does not match this stem. The required function is the security objective of preventing unauthorized or undetected modification of data and systems, which maps to Integrity.
Answer D is incorrect because Policy enforcement point refers to the component that actually allows, blocks, or terminates traffic according to policy decisions. The scenario instead requires the security objective of preventing unauthorized or undetected modification of data and systems, which is why Integrity is the better answer; this option serves the different function defined above.
Question 6
An architect working on a zero-trust and foundational-security design review needs one capability that provides security objective of preventing unauthorized disclosure of information and another that provides physical or electronic credential used to identify and permit authorized personnel into a facility. Which TWO selections are the best match? Choose TWO.
- Integrity
- Access badge
- Confidentiality
- Authorization
- Policy administrator
Correct Answers: B, C
Correct Answers
Answer B is correct because Access badge means a physical or electronic credential used to identify and permit authorized personnel into a facility. It belongs in the fixed-count answer set because it covers one of the stated requirements. Policy administrator instead serves the Zero Trust component that establishes or terminates the communication path after receiving the policy decision and cannot replace this function.
Answer C is correct because Confidentiality means the security objective of preventing unauthorized disclosure of information. One required function is exactly what this option provides. Policy administrator may be useful elsewhere, but it is used for the Zero Trust component that establishes or terminates the communication path after receiving the policy decision.
Incorrect Answers
Answer A is incorrect because Integrity means the security objective of preventing unauthorized or undetected modification of data and systems. The scenario calls for Confidentiality, Access badge. Selecting this option would leave one of those required functions uncovered. For example, Confidentiality is required for the security objective of preventing unauthorized disclosure of information.
Answer D is incorrect because Authorization means the process of determining what an authenticated identity is allowed to do. Every answer slot must map to a stated requirement. The correct set is Confidentiality, Access badge, so this option cannot replace one of those selections.
Answer E is incorrect because Policy administrator means the Zero Trust component that establishes or terminates the communication path after receiving the policy decision. The scenario calls for Confidentiality, Access badge. Selecting this option would leave one of those required functions uncovered.
Question 7
During a zero-trust and foundational-security design review, three requirements must be addressed: (1) assurance that a party cannot credibly deny having performed a specific action or sent a specific message; (2) Zero Trust decision component that evaluates policy and contextual signals to determine whether access should be allowed; and (3) fake credential, record, API key, or other data element that has no legitimate use and can reveal unauthorized access when touched. Which THREE choices best satisfy them? Choose THREE.
- Non-repudiation
- Zero Trust
- Honeypot
- Bollard
- Honeytoken
- Policy engine
Correct Answers: A, E, F
Correct Answers
Answer A is correct because Non-repudiation means assurance that a party cannot credibly deny having performed a specific action or sent a specific message. This option satisfies a specific requirement in the stem; Honeypot serves a decoy system or service intended to attract and observe malicious activity and therefore is not interchangeable with it.
Answer E is correct because Honeytoken means a fake credential, record, API key, or other data element that has no legitimate use and can reveal unauthorized access when touched. This option satisfies a specific requirement in the stem; Honeypot serves a decoy system or service intended to attract and observe malicious activity and therefore is not interchangeable with it.
Answer F is correct because Policy engine means the Zero Trust decision component that evaluates policy and contextual signals to determine whether access should be allowed. This selection maps directly to one of the named needs. Zero Trust addresses a security approach that avoids implicit trust and continuously evaluates identity, device, context, and policy before allowing access, so it does not satisfy the same slot.
Incorrect Answers
Answer B is incorrect because Zero Trust means a security approach that avoids implicit trust and continuously evaluates identity, device, context, and policy before allowing access. The required choices are Policy engine, Non-repudiation, Honeytoken. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Answer C is incorrect because Honeypot means a decoy system or service intended to attract and observe malicious activity. Every answer slot must map to a stated requirement. The correct set is Policy engine, Non-repudiation, Honeytoken, so this option cannot replace one of those selections.
Answer D is incorrect because Bollard means a sturdy physical barrier positioned to prevent vehicles from reaching protected areas. The required choices are Policy engine, Non-repudiation, Honeytoken. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Question 8
An architect working on a zero-trust and foundational-security design review needs one capability that provides security objective of keeping systems and information accessible to authorized users when needed and another that provides physical or electronic credential used to identify and permit authorized personnel into a facility. Which TWO selections are the best match? Choose TWO.
- Accounting
- Availability
- Access badge
- Integrity
- Gap analysis
Correct Answers: B, C
Correct Answers
Answer B is correct because Availability means the security objective of keeping systems and information accessible to authorized users when needed. The fixed-count item needs this function in the answer set. Integrity covers the security objective of preventing unauthorized or undetected modification of data and systems, a different requirement.
Answer C is correct because Access badge means a physical or electronic credential used to identify and permit authorized personnel into a facility. This option satisfies a specific requirement in the stem; Integrity serves the security objective of preventing unauthorized or undetected modification of data and systems and therefore is not interchangeable with it.
Incorrect Answers
Answer A is incorrect because Accounting means the recording and tracking of security-relevant actions for auditing and accountability. The fixed-count answer set is Availability, Access badge; this option does not fill one of those named functions. For example, Access badge is required for a physical or electronic credential used to identify and permit authorized personnel into a facility.
Answer D is incorrect because Integrity means the security objective of preventing unauthorized or undetected modification of data and systems. The fixed-count answer set is Availability, Access badge; this option does not fill one of those named functions. For example, Availability is required for the security objective of keeping systems and information accessible to authorized users when needed.
Answer E is incorrect because Gap analysis means a comparison of the current security state with a required or desired target state. The question requires exactly 2 selections: Availability, Access badge. This option falls outside that required set. For example, Availability is required for the security objective of keeping systems and information accessible to authorized users when needed.
Question 9
What is the recording and tracking of security-relevant actions for auditing and accountability?
- Honeytoken
- Authentication
- Policy enforcement point
- Accounting
Correct Answer: D
Correct Answer
Answer D is correct because Accounting means the recording and tracking of security-relevant actions for auditing and accountability. This matches the requirement as written. Authentication can be valid in another context, but it is used for the process of verifying the identity of a user, device, or other entity.
Incorrect Answers
Answer A is incorrect because Honeytoken refers to a fake credential, record, API key, or other data element that has no legitimate use and can reveal unauthorized access when touched. This could be appropriate elsewhere, but the required function is the recording and tracking of security-relevant actions for auditing and accountability; that makes Accounting the precise choice.
Answer B is incorrect because Authentication refers to the process of verifying the identity of a user, device, or other entity. This could be appropriate elsewhere, but the required function is the recording and tracking of security-relevant actions for auditing and accountability; that makes Accounting the precise choice.
Answer C is incorrect because Policy enforcement point refers to the component that actually allows, blocks, or terminates traffic according to policy decisions. That concept can be valid in another scenario, but this question is testing the recording and tracking of security-relevant actions for auditing and accountability; Accounting therefore fits the requirement more directly.
Question 10
Two requirements remain open in a zero-trust and foundational-security design review: assurance that a party cannot credibly deny having performed a specific action or sent a specific message; sturdy physical barrier positioned to prevent vehicles from reaching protected areas. Which TWO options close those specific gaps? Choose TWO.
- Honeypot
- Policy administrator
- Accounting
- Non-repudiation
- Bollard
Correct Answers: D, E
Correct Answers
Answer D is correct because Non-repudiation means assurance that a party cannot credibly deny having performed a specific action or sent a specific message. This selection maps directly to one of the named needs. Policy administrator addresses the Zero Trust component that establishes or terminates the communication path after receiving the policy decision, so it does not satisfy the same slot.
Answer E is correct because Bollard means a sturdy physical barrier positioned to prevent vehicles from reaching protected areas. One required function is exactly what this option provides. Accounting may be useful elsewhere, but it is used for the recording and tracking of security-relevant actions for auditing and accountability.
Incorrect Answers
Answer A is incorrect because Honeypot means a decoy system or service intended to attract and observe malicious activity. Every answer slot must map to a stated requirement. The correct set is Bollard, Non-repudiation, so this option cannot replace one of those selections.
Answer B is incorrect because Policy administrator means the Zero Trust component that establishes or terminates the communication path after receiving the policy decision. The required choices are Bollard, Non-repudiation. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Answer C is incorrect because Accounting means the recording and tracking of security-relevant actions for auditing and accountability. The fixed-count answer set is Bollard, Non-repudiation; this option does not fill one of those named functions. For example, Non-repudiation is required for assurance that a party cannot credibly deny having performed a specific action or sent a specific message.
Question 11
What is the process of determining what an authenticated identity is allowed to do?
- Honeynet
- Authorization
- Confidentiality
- Policy engine
Correct Answer: B
Correct Answer
Answer B is correct because Authorization means the process of determining what an authenticated identity is allowed to do. The deciding point is functional fit: this option covers the stated need, while Confidentiality addresses the security objective of preventing unauthorized disclosure of information.
Incorrect Answers
Answer A is incorrect because Honeynet refers to a network of decoy systems designed to provide a broader deception environment. The concept is valid, but it does not match this stem. The required function is the process of determining what an authenticated identity is allowed to do, which maps to Authorization.
Answer C is incorrect because Confidentiality refers to the security objective of preventing unauthorized disclosure of information. The scenario instead requires the process of determining what an authenticated identity is allowed to do, which is why Authorization is the better answer; this option serves the different function defined above.
Answer D is incorrect because Policy engine refers to the Zero Trust decision component that evaluates policy and contextual signals to determine whether access should be allowed. That concept can be valid in another scenario, but this question is testing the process of determining what an authenticated identity is allowed to do; Authorization therefore fits the requirement more directly.
Question 12
Which decoy system or service is intended to attract and observe malicious activity?
- Honeypot
- Access badge
- Honeynet
- Integrity
Correct Answer: A
Correct Answer
Answer A is correct because Honeypot means a decoy system or service intended to attract and observe malicious activity. This matches the requirement as written. Access badge can be valid in another context, but it is used for a physical or electronic credential used to identify and permit authorized personnel into a facility.
Incorrect Answers
Answer B is incorrect because Access badge refers to a physical or electronic credential used to identify and permit authorized personnel into a facility. This could be appropriate elsewhere, but the required function is a decoy system or service intended to attract and observe malicious activity; that makes Honeypot the precise choice.
Answer C is incorrect because Honeynet refers to a network of decoy systems designed to provide a broader deception environment. The concept is valid, but it does not match this stem. The required function is a decoy system or service intended to attract and observe malicious activity, which maps to Honeypot.
Answer D is incorrect because Integrity refers to the security objective of preventing unauthorized or undetected modification of data and systems. The question is not asking for this function. It is testing a decoy system or service intended to attract and observe malicious activity, so Honeypot is the stronger fit.
Question 13
What is the security objective of keeping systems and information accessible to authorized users when needed?
- Availability
- Honeynet
- Policy engine
- Policy administrator
Correct Answer: A
Correct Answer
Answer A is correct because Availability means the security objective of keeping systems and information accessible to authorized users when needed. The deciding point is functional fit: this option covers the stated need, while Policy engine addresses the Zero Trust decision component that evaluates policy and contextual signals to determine whether access should be allowed.
Incorrect Answers
Answer B is incorrect because Honeynet refers to a network of decoy systems designed to provide a broader deception environment. That concept can be valid in another scenario, but this question is testing the security objective of keeping systems and information accessible to authorized users when needed; Availability therefore fits the requirement more directly.
Answer C is incorrect because Policy engine refers to the Zero Trust decision component that evaluates policy and contextual signals to determine whether access should be allowed. The key mismatch is functional: Availability addresses the security objective of keeping systems and information accessible to authorized users when needed, the need stated by the question.
Answer D is incorrect because Policy administrator refers to the Zero Trust component that establishes or terminates the communication path after receiving the policy decision. The key mismatch is functional: Availability addresses the security objective of keeping systems and information accessible to authorized users when needed, the need stated by the question.
Question 14
To control and record entry to restricted locations, which security approach should be selected?
- Policy administrator
- Access badge
- Bollard
- Authentication
Correct Answer: B
Correct Answer
Answer B is correct because Access badge means a physical or electronic credential used to identify and permit authorized personnel into a facility. The deciding point is functional fit: this option covers the stated need, while Policy administrator addresses the Zero Trust component that establishes or terminates the communication path after receiving the policy decision.
Incorrect Answers
Answer A is incorrect because Policy administrator refers to the Zero Trust component that establishes or terminates the communication path after receiving the policy decision. The key mismatch is functional: Access badge addresses a physical or electronic credential used to identify and permit authorized personnel into a facility, the need stated by the question.
Answer C is incorrect because Bollard refers to a sturdy physical barrier positioned to prevent vehicles from reaching protected areas. The scenario instead requires a physical or electronic credential used to identify and permit authorized personnel into a facility, which is why Access badge is the better answer; this option serves the different function defined above.
Answer D is incorrect because Authentication refers to the process of verifying the identity of a user, device, or other entity. The scenario instead requires a physical or electronic credential used to identify and permit authorized personnel into a facility, which is why Access badge is the better answer; this option serves the different function defined above.
Question 15
Which component actually allows, blocks, or terminates traffic according to policy decisions?
- Access control vestibule
- Non-repudiation
- Policy enforcement point
- Integrity
Correct Answer: C
Correct Answer
Answer C is correct because Policy enforcement point means the component that actually allows, blocks, or terminates traffic according to policy decisions. That makes it the best answer here; Access control vestibule addresses a physical entry design that uses two controlled doors so only one is open at a time, not the function requested in the stem.
Incorrect Answers
Answer A is incorrect because Access control vestibule refers to a physical entry design that uses two controlled doors so only one is open at a time. The key mismatch is functional: Policy enforcement point addresses the component that actually allows, blocks, or terminates traffic according to policy decisions, the need stated by the question.
Answer B is incorrect because Non-repudiation refers to assurance that a party cannot credibly deny having performed a specific action or sent a specific message. The concept is valid, but it does not match this stem. The required function is the component that actually allows, blocks, or terminates traffic according to policy decisions, which maps to Policy enforcement point.
Answer D is incorrect because Integrity refers to the security objective of preventing unauthorized or undetected modification of data and systems. The concept is valid, but it does not match this stem. The required function is the component that actually allows, blocks, or terminates traffic according to policy decisions, which maps to Policy enforcement point.
Question 16
The control set for a zero-trust and foundational-security design review must address both process of verifying the identity of a user, device, or other entity and component that actually allows, blocks, or terminates traffic according to policy decisions. Which TWO choices map directly to those needs? Choose TWO.
- Authorization
- Authentication
- Gap analysis
- Honeypot
- Policy enforcement point
Correct Answers: B, E
Correct Answers
Answer B is correct because Authentication means the process of verifying the identity of a user, device, or other entity. One required function is exactly what this option provides. Honeypot may be useful elsewhere, but it is used for a decoy system or service intended to attract and observe malicious activity.
Answer E is correct because Policy enforcement point means the component that actually allows, blocks, or terminates traffic according to policy decisions. One required function is exactly what this option provides. Gap analysis may be useful elsewhere, but it is used for a comparison of the current security state with a required or desired target state.
Incorrect Answers
Answer A is incorrect because Authorization means the process of determining what an authenticated identity is allowed to do. The question requires exactly 2 selections: Policy enforcement point, Authentication. This option falls outside that required set. For example, Authentication is required for the process of verifying the identity of a user, device, or other entity.
Answer C is incorrect because Gap analysis means a comparison of the current security state with a required or desired target state. The scenario calls for Policy enforcement point, Authentication. Selecting this option would leave one of those required functions uncovered.
Answer D is incorrect because Honeypot means a decoy system or service intended to attract and observe malicious activity. The question requires exactly 2 selections: Policy enforcement point, Authentication. This option falls outside that required set. For example, Authentication is required for the process of verifying the identity of a user, device, or other entity.
Question 17
To grant or deny permissions after identity has been established, which security approach should be selected?
- Honeytoken
- Policy engine
- Access control vestibule
- Authorization
Correct Answer: D
Correct Answer
Answer D is correct because Authorization means the process of determining what an authenticated identity is allowed to do. The requirement maps directly to this function, whereas Honeytoken is aimed at a fake credential, record, API key, or other data element that has no legitimate use and can reveal unauthorized access when touched.
Incorrect Answers
Answer A is incorrect because Honeytoken refers to a fake credential, record, API key, or other data element that has no legitimate use and can reveal unauthorized access when touched. The scenario instead requires the process of determining what an authenticated identity is allowed to do, which is why Authorization is the better answer; this option serves the different function defined above.
Answer B is incorrect because Policy engine refers to the Zero Trust decision component that evaluates policy and contextual signals to determine whether access should be allowed. The concept is valid, but it does not match this stem. The required function is the process of determining what an authenticated identity is allowed to do, which maps to Authorization.
Answer C is incorrect because Access control vestibule refers to a physical entry design that uses two controlled doors so only one is open at a time. The key mismatch is functional: Authorization addresses the process of determining what an authenticated identity is allowed to do, the need stated by the question.
Question 18
Which fake credential, record, API key, or other data element has no legitimate use and can reveal unauthorized access when touched?
- Access badge
- Availability
- Policy engine
- Honeytoken
Correct Answer: D
Correct Answer
Answer D is correct because Honeytoken means a fake credential, record, API key, or other data element that has no legitimate use and can reveal unauthorized access when touched. This matches the requirement as written. Policy engine can be valid in another context, but it is used for the Zero Trust decision component that evaluates policy and contextual signals to determine whether access should be allowed.
Incorrect Answers
Answer A is incorrect because Access badge refers to a physical or electronic credential used to identify and permit authorized personnel into a facility. That concept can be valid in another scenario, but this question is testing a fake credential, record, API key, or other data element that has no legitimate use and can reveal unauthorized access when touched; Honeytoken therefore fits the requirement more directly.
Answer B is incorrect because Availability refers to the security objective of keeping systems and information accessible to authorized users when needed. That concept can be valid in another scenario, but this question is testing a fake credential, record, API key, or other data element that has no legitimate use and can reveal unauthorized access when touched; Honeytoken therefore fits the requirement more directly.
Answer C is incorrect because Policy engine refers to the Zero Trust decision component that evaluates policy and contextual signals to determine whether access should be allowed. The question is not asking for this function. It is testing a fake credential, record, API key, or other data element that has no legitimate use and can reveal unauthorized access when touched, so Honeytoken is the stronger fit.
Question 19
To provide strong evidence linking an action or transaction to its originator, which security approach should be selected?
- Authorization
- Non-repudiation
- Zero Trust
- Policy administrator
Correct Answer: B
Correct Answer
Answer B is correct because Non-repudiation means assurance that a party cannot credibly deny having performed a specific action or sent a specific message. That is the function the question is testing. Zero Trust would instead be used for a security approach that avoids implicit trust and continuously evaluates identity, device, context, and policy before allowing access.
Incorrect Answers
Answer A is incorrect because Authorization refers to the process of determining what an authenticated identity is allowed to do. The key mismatch is functional: Non-repudiation addresses assurance that a party cannot credibly deny having performed a specific action or sent a specific message, the need stated by the question.
Answer C is incorrect because Zero Trust refers to a security approach that avoids implicit trust and continuously evaluates identity, device, context, and policy before allowing access. The key mismatch is functional: Non-repudiation addresses assurance that a party cannot credibly deny having performed a specific action or sent a specific message, the need stated by the question.
Answer D is incorrect because Policy administrator refers to the Zero Trust component that establishes or terminates the communication path after receiving the policy decision. The key mismatch is functional: Non-repudiation addresses assurance that a party cannot credibly deny having performed a specific action or sent a specific message, the need stated by the question.
Question 20
To maintain evidence of who did what, when, and from where, which security approach should be selected?
- Honeynet
- Honeytoken
- Authorization
- Accounting
Correct Answer: D
Correct Answer
Answer D is correct because Accounting means the recording and tracking of security-relevant actions for auditing and accountability. That makes it the best answer here; Authorization addresses the process of determining what an authenticated identity is allowed to do, not the function requested in the stem.
Incorrect Answers
Answer A is incorrect because Honeynet refers to a network of decoy systems designed to provide a broader deception environment. This could be appropriate elsewhere, but the required function is the recording and tracking of security-relevant actions for auditing and accountability; that makes Accounting the precise choice.
Answer B is incorrect because Honeytoken refers to a fake credential, record, API key, or other data element that has no legitimate use and can reveal unauthorized access when touched. The question is not asking for this function. It is testing the recording and tracking of security-relevant actions for auditing and accountability, so Accounting is the stronger fit.
Answer C is incorrect because Authorization refers to the process of determining what an authenticated identity is allowed to do. The key mismatch is functional: Accounting addresses the recording and tracking of security-relevant actions for auditing and accountability, the need stated by the question.