Study. uk . com
  1. Home
  2. All questions

All 611 questions — CompTIA Security+

Every question in the free CompTIA Security+ study material, one page each: the question, its options, the answer, the reasoning and a public source. Pick one of 10 topics or read them in order.

Challenge yourself → Study as cards

Topics

Every question

  1. 1. A security team rates a finding as high risk purely because the potential loss would be severe, without considering how plausible the event is. Which part of the standard definition of risk have they left out?
  2. 2. Which two of the following are risk factors in the NIST risk model? Choose two.
  3. 3. A power supply fails and takes a database offline. Under the standard definition, how should this be classified?
  4. 4. Which two of the following are recognised categories of threat source? Choose two.
  5. 5. An analyst argues that because a provisioning server outage was traced to an administrator's mistake, denial of service can be removed from the risk register for that server. Why is this reasoning wrong?
  6. 6. After an organisation deploys strong controls on its public web tier, attackers begin targeting a smaller partner instead. What is this behaviour called?
  7. 7. An assessment notes that the organisation has no central asset inventory, which makes many threat events more likely to succeed. In risk-model terms, what has been described?
  8. 8. At which tier of the risk management hierarchy are decisions about the organisation-wide risk management strategy made?
  9. 9. Before running its first formal risk assessment, an organisation documents its assumptions, constraints, priorities and tolerance. Which activity is this?
  10. 10. A manager decides, during a finding review, how much risk the organisation is willing to accept. What is wrong with deciding it at that point?
  11. 11. A threat report describes how a group gains access, moves laterally and exfiltrates data, without naming any specific tool. What is being described?
  12. 12. Which sequence correctly lists the steps of the Risk Management Framework?
  13. 13. Which RMF step determines which control baseline the system will start from?
  14. 14. Who makes the decision to accept a system's residual risk and issue an authorisation to operate?
  15. 15. An organisation wants to move from three-yearly reauthorisation to ongoing authorisation. Which capability makes that possible?
  16. 16. Agency B accepts Agency A's existing assessment evidence for a shared service instead of repeating the assessment. What is this practice called?
  17. 17. A data centre's physical security controls are implemented once and relied on by every system hosted there. What are these called, and who is accountable for them?
  18. 18. A team draws a system's authorisation boundary very narrowly to reduce assessment effort. What is the main consequence?
  19. 19. An executive asks why the Cybersecurity Framework does not tell them which products to buy. What is the correct explanation?
  20. 20. Which two concerns were raised to first-class prominence in version 2.0 of the Cybersecurity Framework? Choose two.
  21. 21. How is the Cybersecurity Framework Core structured?
  22. 22. An organisation builds a current Profile and a target Profile using the Cybersecurity Framework. What does comparing them produce?
  23. 23. A consultant reports that the organisation "is at Tier 2" as a single maturity score for its whole security programme. Why is this a misuse of Tiers?
  24. 24. Why does the Cybersecurity Framework encourage managing cybersecurity risk alongside financial, privacy, supply chain and reputational risk?
  25. 25. An asset is worth $200,000. A fire would destroy half of it, and fires of that kind are expected once every ten years. What is the annualised loss expectancy?
  26. 26. Which two values are multiplied to produce a single loss expectancy?
  27. 27. An organisation has no reliable loss data for a new class of risk and needs a ranking quickly. Which approach fits, and what is its main limitation?
  28. 28. A vendor will not patch a flaw in a product the organisation uses. Which two of the following are recognised risk responses in this situation? Choose two.
  29. 29. After buying cyber insurance, a director states that the breach risk now belongs to the insurer. What is wrong with this claim?
  30. 30. Which quantity does an authorising official actually accept when granting an authorisation to operate?
  31. 31. What does a risk register record beyond the description of each risk?
  32. 32. How do risk appetite and risk tolerance differ?
  33. 33. Which analysis determines what a disruption would cost over time and which processes must be recovered first?
  34. 34. A service may be unavailable for at most four hours, and at most fifteen minutes of transactions may be lost. Which objectives do these two statements set?
  35. 35. A business states that beyond 48 hours of downtime the company would not survive. The recovery time objective is then set at 48 hours. What is wrong?
  36. 36. Which three problems does cybersecurity supply chain risk management address in products and services an organisation acquires?
  37. 37. An organisation wants to impose security requirements on a SaaS provider. When does it have the most leverage to do so?
  38. 38. After a supplier incident, an organisation asks to review the supplier's security evidence and is refused. What should have been in place?
  39. 39. Which agreement states the availability a provider commits to and the remedy if it is missed?
  40. 40. An organisation signs many small engagements with one consultancy and wants to avoid renegotiating liability and security terms each time. Which instrument achieves this?
  41. 41. Which two items must the rules of engagement for a penetration test establish? Choose two.
  42. 42. An assessor reviews configuration files, policies and logs without sending any traffic to the system. Which activity is this?
  43. 43. A manager reports to the board that a vulnerability scan "proved the systems can be breached". Why is that claim unsupported?
  44. 44. A customer requires assurance that carries weight with its own regulator. Which type of audit best meets that need?
  45. 45. An organisation passes its regulatory audit and is breached three months later. Which statement best explains how both can be true?
  46. 46. How do due diligence and due care differ?
  47. 47. A document states "all servers must use disk encryption approved by the security team" and lists the approved algorithms. Which governance artefact is this?
  48. 48. Which governance artefact offers recommended practice that staff are not obliged to follow?
  49. 49. An employee is dismissed for misusing company systems and challenges the decision. Which document most directly supports the organisation's position?
  50. 50. Who decides a data set's classification and who may access it?
  51. 51. A security team wants to know whether awareness training has changed behaviour rather than recall. Which measure fits best?
  52. 52. Why do developers and system administrators receive different security training from general staff?
  53. 53. A user who clicked a phishing link waits two days before telling anyone, fearing discipline. Which change most directly reduces this delay?
  54. 54. A team uses a vulnerability's CVSS score directly as its risk rating. Which factor does CVSS deliberately exclude that they must add themselves?
  55. 55. A vulnerability's base score is taken straight from a public feed and used to rank remediation. What assumption is being carried in unexamined?
  56. 56. A report labels a score CVSS-BTE. What does the label tell the reader?
  57. 57. Two flaws both score 8.8. One appears in the Known Exploited Vulnerabilities catalog. Which should be remediated first and why?
  58. 58. Which two conditions must be met before a vulnerability is added to the Known Exploited Vulnerabilities catalog? Choose two.
  59. 59. Why does the Known Exploited Vulnerabilities catalog read more like a directive than an advisory list?
  60. 60. Which set correctly lists the four Traffic Light Protocol labels?
  61. 61. An analyst receives a report marked TLP:AMBER. Who may they share it with?
  62. 62. Which TLP label means the information may go no further than the individuals who received it?
  63. 63. A team proposes replacing its data classification scheme with TLP labels. Why is that a mistake?
  64. 64. An analyst needs to share TLP:GREEN information with a public blog audience. What must they do?
  65. 65. A researcher finds a flaw in a company's product and cannot locate any way to report it. Which control would have prevented this situation?
  66. 66. Which element of a vulnerability disclosure policy most directly encourages a good-faith researcher to report rather than stay silent?
  67. 67. A company with a two-person security team launches a public bug bounty. What is the most likely outcome?
  68. 68. Which two backup properties most directly determine whether an organisation can recover from ransomware without paying? Choose two.
  69. 69. An executive proposes paying a ransom because it will be faster than restoring. Which point should the security lead make?
  70. 70. An organisation restores cleanly from backup after a ransomware attack, yet still faces a serious problem. What is it?
  71. 71. Which parties should an incident response plan identify before an incident occurs?
  72. 72. Why must the exact time an incident was detected be recorded precisely?
  73. 73. A company hires a payroll bureau that processes employee data strictly on the company's written instructions. Under privacy regulation, what are their roles?
  74. 74. A team chooses a cloud region purely on latency. Which consideration have they overlooked?
  75. 75. Which measure reduces breach impact before any technical control is applied?
  76. 76. Why is an over-long records retention period a security problem as well as a storage cost?
  77. 77. A service will only let users register if they also consent to their data being used for unrelated marketing analysis. What is wrong with this?
  78. 78. An identity proofing system wrongly rejects a legitimate applicant. What must the provider offer?
  79. 79. Which artefact does an authorising official read to understand a system's control effectiveness before making the authorisation decision?
  80. 80. A weakness is found that will not be remediated for nine months. Where should it be recorded so it stays visible and owned?
  81. 81. A team applies a NIST control baseline exactly as published with no changes. What have they misunderstood?
  82. 82. Several similar healthcare systems each need the same tailored control set. Which construct avoids each of them tailoring the baseline separately?
  83. 83. A supplier passed its assessment two years ago and has not been reviewed since. What risk does this create?
  84. 84. An organisation's SaaS provider depends on a third-party payment processor that the organisation has never assessed. What is this exposure called?
  85. 85. A batch of network cards turns out to be counterfeit, though no malicious code is present. Why is this still a supply chain security issue?
  86. 86. A critical flaw is announced in a widely used logging library. Which artefact turns finding affected products from a research project into a lookup?
  87. 87. Which two elements must a change management process require before an authorised change is applied? Choose two.
  88. 88. An engineer applies an emergency fix at 3am without raising a ticket, arguing the outage justified it. What is the correct position?
  89. 89. What does keeping infrastructure configuration under version control give a change management process?
  90. 90. An organisation adopts a security framework and needs to know what work to budget for. Which activity produces that list?
  91. 91. A client asks for a test that begins with no inside information about the environment. Which engagement type is this?
  92. 92. During a test, an assessor gathers information about the target using only public records and search engines. What is the main advantage of this approach?
  93. 93. Mid-engagement, a tester discovers they can reach a system that was not listed in the agreed scope. What should they do?
  94. 94. A penetration test report is filed after review and no findings are tracked. What is the consequence?
  95. 95. A team wants to test decision-making and plan clarity for a ransomware scenario at the lowest cost. Which exercise type fits?
  96. 96. After a successful tabletop exercise, a manager states the recovery capability is now proven. Why is that overstating the result?
  97. 97. A continuity plan written three years ago has never been exercised. What is the most likely problem with it now?
  98. 98. Why do redundant power and environmental monitoring belong in a contingency plan rather than only in daily operations?
  99. 99. Why do perimeter controls contribute little against an insider threat?
  100. 100. A department signs up for an unapproved file-sharing service. What is the primary security concern?
  101. 101. Why is asset management treated as a security control rather than an IT housekeeping task?
  102. 102. At which stage of the asset lifecycle does data most often escape the organisation's control?
  103. 103. A board asks why it cannot act on the security team's quarterly report. The report lists control gaps by identifier. What is the underlying problem?
  104. 104. Which statement correctly describes the relationship between cybersecurity risk and privacy risk?
  105. 105. A system cannot meet a mandated control. Which response keeps this within governance rather than making it an audit finding?
  106. 106. A flaw the organisation has been carrying quietly for months is published in a security advisory. What changes about the risk?
  107. 107. Which response to a software vulnerability removes it outright without also removing functionality?
  108. 108. An unused reporting service on a server has an unpatched critical flaw. The business confirms nobody uses it. Which response is avoidance?
  109. 109. A critical flaw is found in an application whose vendor ended support two years ago. Why is this different from a normal unpatched finding?
  110. 110. A hospital's imaging system vendor requires that updates be applied only on its certified schedule. An engineer wants to patch immediately. What is the risk of doing so?
  111. 111. An upgrade would fix a vulnerability, but the new version's cryptographic modules are not yet FIPS-validated and the organisation must use validated modules. What does this illustrate?
  112. 112. Where does the vulnerability management lifecycle begin?
  113. 113. A team installs a patch and immediately closes the finding. Which lifecycle step have they skipped?
  114. 114. Which two activities belong to the prepare phase of executing a patch response? Choose two.
  115. 115. An organisation treats every patch cycle as an emergency and never plans capacity for it. Which framing does NIST recommend instead?
  116. 116. An enterprise patch strategy currently covers only servers and workstations. Which two asset classes must also be included? Choose two.
  117. 117. A legacy control system cannot be patched and cannot be replaced this year. What does NIST expect the organisation to produce for it?
  118. 118. A flaw is being exploited in the wild and no patch exists yet. According to NIST's patch planning guidance, how should the organisation treat this?
  119. 119. Which two of the following are metric groups in CVSS v4.0? Choose two.
  120. 120. Which CVSS metric group changes as proof-of-concept exploit code becomes publicly available?
  121. 121. Which CVSS Attack Vector value produces the highest severity contribution?
  122. 122. A flaw can only be triggered by a device on the same Wi-Fi network or local IP subnet. Which CVSS Attack Vector value applies?
  123. 123. An attacker recovers disk encryption keys from memory after gaining brief physical possession of a laptop. Which CVSS Attack Vector value describes this?
  124. 124. An exploit succeeds repeatably against any instance of a product with no target-specific work. What Attack Complexity value should it receive?
  125. 125. Exploiting a flaw requires the attacker to win a race condition. In CVSS v4.0, which metric captures this?
  126. 126. A device ships with the same default administrator password across every unit, and it is rarely changed. How should Privileges Required be scored?
  127. 127. A stored cross-site scripting flaw fires when the victim simply views a page. Which CVSS v4.0 User Interaction value fits?
  128. 128. What did CVSS v4.0 replace the older Scope metric with?
  129. 129. An analyst wants to lower a base score because the flaw was found through a difficult internal audit rather than being publicly known. Why is this wrong?
  130. 130. An organisation has a custom firewall rule that blocks the only path to a vulnerable service. Where should that be reflected in CVSS?
  131. 131. Who is best placed to supply the Environmental metric values for a vulnerability?
  132. 132. Why does FIRST require a CVSS vector string to be published alongside the numeric score?
  133. 133. A report references both CWE-89 and CVE-2024-XXXX for the same finding. What is the difference between the two identifiers?
  134. 134. A patch compliance report built from unauthenticated scans shows far fewer missing patches than the software inventory suggests. What is the likely cause?
  135. 135. Which scan type best measures what an outside attacker would see of an organisation's internet-facing estate?
  136. 136. A team must assess a fragile industrial network without risking an outage. Which technique fits?
  137. 137. An organisation scans only the hosts in its asset inventory. What kind of exposure does this method structurally miss?
  138. 138. Which activity separates a scanner finding from a confirmed vulnerability?
  139. 139. What is the underlying cause common to every injection flaw?
  140. 140. Which technique is the primary defence against SQL injection, and why does it work?
  141. 141. A team moves all queries into stored procedures and declares SQL injection solved. Under what condition is that claim wrong?
  142. 142. A report lets the user choose which column to sort by, and the column name goes into the query. Parameters cannot bind an identifier. What is the correct defence?
  143. 143. An application's database account is granted read access only to the two tables it needs. What does this achieve against SQL injection?
  144. 144. Which validation strategy does OWASP recommend, and why?
  145. 145. A developer removes server-side validation because the form already validates in the browser. What is the flaw in this reasoning?
  146. 146. Why should input be canonicalised before it is validated?
  147. 147. A team validates all input strictly and concludes that output encoding is unnecessary. Why is that wrong?
  148. 148. Which two controls should be applied to a user file upload feature? Choose two.
  149. 149. Why does a single encoding function not prevent all cross-site scripting?
  150. 150. A developer wants to insert a user-supplied value directly inside a script block, encoded carefully. What is OWASP's guidance?
  151. 151. What role does a Content Security Policy play in defending against cross-site scripting?
  152. 152. An application built on a modern framework has a stored cross-site scripting flaw. What is the most likely cause?
  153. 153. Why can a server not distinguish a cross-site request forgery from a legitimate request using cookies alone?
  154. 154. Why does a synchroniser token defeat cross-site request forgery?
  155. 155. A team sets SameSite on its session cookie and removes its CSRF tokens. What is OWASP's position on this?
  156. 156. An unauthenticated endpoint runs an expensive report generation on every call. What is the risk?
  157. 157. Which two application controls most directly limit denial-of-service exposure? Choose two.
  158. 158. An administrator raises the password hashing work factor until each login takes three seconds. What new risk has been introduced?
  159. 159. Which two findings fall under security misconfiguration? Choose two.
  160. 160. A production application returns full stack traces including framework versions when an error occurs. Beyond untidiness, what does this give an attacker?
  161. 161. Why do vulnerable and outdated components form a category distinct from the rest of the OWASP Top Ten?
  162. 162. An application fetches a URL supplied by the user to generate a link preview. Why is this dangerous?
  163. 163. An application turns attacker-controlled data directly into live objects. Which flaw class is this, and what is the worst case?
  164. 164. Which two defences remove the buffer overflow class rather than mitigating individual instances?
  165. 165. A program checks that a file is owned by the user, then opens it. An attacker replaces the file between the two steps. Which flaw is this?
  166. 166. Which virtualisation weakness would affect every tenant sharing a host?
  167. 167. Which two weaknesses account for most cloud security incidents? Choose two.
  168. 168. A user installs an application from outside the vetted app store onto a corporate phone. What is the primary weakness this creates?
  169. 169. Which two are hardware or firmware weaknesses rather than software ones? Choose two.
  170. 170. Why do supply chain vulnerabilities defeat controls aimed at untrusted input?
  171. 171. What does hardening a system primarily achieve?
  172. 172. Systems are built to a hardened baseline but drift out of compliance within weeks. Which control addresses this?
  173. 173. A critical flaw is disclosed and the vendor patch is two weeks away. The team deploys a rule at the application gateway that blocks the exploit pattern. What is this called?
  174. 174. Which step confirms that a deployed patch actually removed the vulnerability?
  175. 175. A patching programme reports the number of patches installed each month. Why is this a weak enterprise-level metric?
  176. 176. How does an organisation learn that a library it depends on has become vulnerable?
  177. 177. Why are logging and monitoring failures serious even though they rarely cause the breach?
  178. 178. A flaw is found that no amount of correct implementation would have prevented. Which category does it fall into, and what practice addresses it?
  179. 179. A team patches every critical-severity finding first, regardless of whether the affected service is reachable. What is the problem with this policy?
  180. 180. The same coding flaw exists in two code paths, one reachable from the internet and one that is dead code. Why do they carry different risk?
  181. 181. How does NIST define media sanitisation?
  182. 182. A drive will be reissued to another employee in the same department. Which sanitisation category is normally sufficient?
  183. 183. What standard must a Purge operation meet that Clear does not?
  184. 184. An organisation chooses Destroy for a batch of drives. What does this imply?
  185. 185. A self-encrypting drive must be sanitised in minutes rather than hours. Which technique achieves this?
  186. 186. Why is a multi-pass overwrite an unreliable way to sanitise a solid-state drive?
  187. 187. A team cuts each decommissioned drive in half and records it as Destroyed. What should be verified?
  188. 188. When should sanitisation requirements first be considered for a new system?
  189. 189. Why is sanitisation not only an end-of-life activity?
  190. 190. What does data classification allow an organisation to do?
  191. 191. Which protection applies to data in use, as distinct from data at rest or in transit?
  192. 192. A payments team replaces card numbers throughout its systems with surrogate values that have no mathematical relationship to the original. What is this?
  193. 193. A support screen shows only the last four digits of an account number, while the full value remains in the database. Which control is in use, and what does it not protect against?
  194. 194. Which technique removes the link to an individual irreversibly?
  195. 195. A data loss prevention deployment generates constant false positives and misses real exfiltration. What most likely needs fixing first?
  196. 196. How are controls organised in the NIST control catalogue?
  197. 197. What is a control enhancement?
  198. 198. A security guard at a reception desk is classified by category as which type of control?
  199. 199. A prominent sign warning that the site is under video surveillance is best described as which control function?
  200. 200. A required control cannot be implemented on a legacy platform, so an alternative providing comparable protection is deployed and documented. What is this?
  201. 201. Why is a policy document on its own a weak control?
  202. 202. Which property ensures a sender cannot credibly deny having sent a message?
  203. 203. A system records which administrator changed a firewall rule and when. Which of the three AAA functions does this serve?
  204. 204. Why does an alert from a honeypot carry unusually high confidence?
  205. 205. A fake set of credentials is planted in a document share. It is later used to attempt a login. What has this proved?
  206. 206. Which four questions structure a threat modelling exercise?
  207. 207. Why is threat modelling most valuable during design rather than after implementation?
  208. 208. What makes a data flow diagram useful for threat modelling?
  209. 209. A threat model was produced two years ago and the architecture has since changed substantially. What is its current value?
  210. 210. In the STRIDE prompt list, which threat category does a digital signature most directly address?
  211. 211. An architecture layers a firewall, an intrusion prevention system and endpoint protection, all from one vendor sharing one signature feed. What weakens the defence in depth?
  212. 212. An electronically controlled fire door loses power. Which design choice should govern its behaviour, and why?
  213. 213. Why do secure defaults matter more than good documentation of how to harden a product?
  214. 214. A rarely used feature carries repeated vulnerabilities. Which approach reduces risk most durably?
  215. 215. An organisation's hardening standard was written for an operating system version no longer deployed. What has happened to it?
  216. 216. Which control requires that a system provide only the capabilities it needs, with unnecessary ports, protocols and services disabled?
  217. 217. An API key was accidentally committed to a Git repository and the commit was reverted an hour later. What must still be done?
  218. 218. Which two reasons argue against holding a production secret in an environment variable? Choose two.
  219. 219. What distinguishes a hardware security module from software key storage?
  220. 220. Which component anchors full-disk encryption and boot integrity to one specific machine?
  221. 221. How does secure boot differ from measured boot?
  222. 222. An email gateway opens attachments in an isolated environment before delivery. Which control is this?
  223. 223. Which control stops previously unseen malware from executing without needing a signature for it?
  224. 224. What is the structural weakness of a deny-listing approach to software control?
  225. 225. What does code signing let an organisation verify, and what does it enable operationally?
  226. 226. A signed vendor update is later found to contain malicious code. What does this show about signature verification?
  227. 227. Which testing approach reads source code without executing it?
  228. 228. A parser crashes on malformed input in production despite passing code review. Which technique was most likely to have found this earlier?
  229. 229. Why are development, test and production environments kept separate?
  230. 230. A team copies a production database into a test environment to reproduce a bug. What must happen first?
  231. 231. What security benefit does defining infrastructure as code provide?
  232. 232. Under an immutable infrastructure model, how is a compromised host handled?
  233. 233. A monitoring team asks for an alert on repeated failed logins in an internal application, but the application emits no such event. What does this illustrate?
  234. 234. Which two attributes should an application security log entry carry to support correlation? Choose two.
  235. 235. Why must passwords and session tokens never be written to application logs?
  236. 236. An attacker submits input containing newline characters that appear in the log as separate, forged entries. What is the defence?
  237. 237. A two-node cluster is described as highly available, but both nodes attach to one storage array. What is the flaw?
  238. 238. An organisation runs every web server on the same operating system and vendor stack. Which resilience principle is missing?
  239. 239. A data centre has an uninterruptible power supply but no generator. Which outage is it unable to survive?
  240. 240. Why do cooling and fire suppression belong in a contingency plan alongside data backups?
  241. 241. In the deter, delay and detect model of physical security, which layer does a reinforced door belong to?
  242. 242. A site relies on cameras as its primary control against theft from a storeroom. What gap does this leave?
  243. 243. An air-gapped network has no connectivity to any other network. Where does its risk concentrate?
  244. 244. What does privacy by design mean in practice?
  245. 245. A relying party needs to know only whether a user is over eighteen. Which approach best satisfies privacy expectations?
  246. 246. What does configuration management provide that makes unauthorised change detectable?
  247. 247. A team encrypts every secret in its vault at rest. What problem does this leave unsolved?
  248. 248. Why does NIST suggest storing a verifier's secret key in a hardware-protected area such as a TPM or trusted execution environment?
  249. 249. Which factors should drive the choice between Clear, Purge and Destroy?
  250. 250. An organisation uses a third-party disposal vendor. What evidence should it retain?
  251. 251. A developer replaces sensitive identifiers with a reversible transformation and calls the data protected. What is the correct assessment?
  252. 252. Why does a control catalogue matter more than a list of security intentions?
  253. 253. A service proofs users at a high level but allows single-factor login. Which NIST assurance components describe these two choices?
  254. 254. Which authenticator arrangement satisfies AAL3?
  255. 255. An application is being assessed at AAL2. What must its verifier offer users?
  256. 256. A vendor claims their fingerprint-only login is multi-factor authentication. What is wrong with that claim?
  257. 257. Which biometric arrangement does NIST prefer, and why?
  258. 258. Under the current NIST digital identity guidelines, what is the minimum length for a password used as the only authentication factor?
  259. 259. A policy requires every password to contain an uppercase letter, a digit and a symbol. What is NIST's current guidance?
  260. 260. Under current NIST guidance, when must a verifier force a password change?
  261. 261. When checking a new password against a blocklist, what must be compared?
  262. 262. A team proposes expanding its password blocklist to a billion entries. Why does NIST consider this of little additional benefit?
  263. 263. How must a verifier store passwords so they resist offline attack?
  264. 264. What is the minimum salt length NIST specifies for stored passwords, and what does the salt achieve?
  265. 265. NIST suggests an additional keyed operation over the stored password hash. Where should that secret key live?
  266. 266. Which two authenticator types are classed as not phishing-resistant? Choose two.
  267. 267. An attacker repeatedly requests a new out-of-band code hoping to reset the failed-attempt counter. What does NIST require?
  268. 268. Before sending an authentication code over the telephone network, which two risk indicators should a verifier consider? Choose two.
  269. 269. A service offers only SMS codes as its second factor. Beyond the interception risk, what NIST requirement does this miss?
  270. 270. An organisation wants to use cloud-synced passkeys to meet AAL3. Why will this fail?
  271. 271. What does the AAL3 requirement to demonstrate authentication intent mean in practice?
  272. 272. At AAL2, what does NIST recommend for the overall session timeout and the inactivity timeout?
  273. 273. How does an inactivity timeout differ from an overall session timeout?
  274. 274. A login arrives from an unexpected country, so the system prompts for an extra check. Does the geolocation signal count as an authentication factor?
  275. 275. A service uses strong multi-factor authentication but never learns the user's real name. Is this consistent with NIST guidance?
  276. 276. At IAL1, how should attributes the subscriber supplies be treated?
  277. 277. A user changes the phone number that receives their authentication codes. How should the system treat this operation?
  278. 278. What does the AAL2 requirement for replay resistance prevent?
  279. 279. Which combination represents two genuinely distinct authentication factors?
  280. 280. Why does adding a security question to a password login not meaningfully improve resistance to credential stuffing?
  281. 281. Why is a FIDO2 security key resistant to a convincing look-alike login page?
  282. 282. An attacker with a valid password triggers repeated push approvals until the user taps accept. Which control most directly counters this?
  283. 283. A login form replies "no such user" for unknown addresses and "incorrect password" for known ones. What does this enable?
  284. 284. Besides the login form, which two flows commonly leak whether an address is registered? Choose two.
  285. 285. At which moment must an application regenerate the session identifier to prevent session fixation?
  286. 286. Which two cookie attributes protect a session identifier, and what does each achieve? Choose two.
  287. 287. Which property must a session identifier have?
  288. 288. A logout function deletes the session cookie in the browser but leaves the server-side session valid. What is the risk?
  289. 289. Why should a session identifier never be carried in the URL?
  290. 290. What does single sign-on actually change about how applications authenticate users?
  291. 291. Which two security benefits does federation give a relying party? Choose two.
  292. 292. What does the Federation Assurance Level describe?
  293. 293. An attacker captures a valid assertion from one relying party and presents it to a second. Which assertion property prevents this from working?
  294. 294. Which two assertion properties let a relying party reject a stale or already-used assertion? Choose two.
  295. 295. Which protocol carries identity assertions as signed XML and is the long-standing choice for enterprise web single sign-on?
  296. 296. A developer uses the presence of a valid OAuth 2.0 access token as proof of the user's identity. Why is this a mistake?
  297. 297. Domain logons begin failing after a server's clock drifts by several minutes. Which authentication protocol explains this symptom?
  298. 298. Which protocol is preferred for administering network devices because it separates authentication, authorisation and accounting and encrypts the whole payload?
  299. 299. Which server usually sits behind 802.1X port-based network access control?
  300. 300. An employee leaves and their accounts remain active for six weeks. Which process failed?
  301. 301. Why does driving account provisioning from an authoritative HR source reduce risk?
  302. 302. Which activity is designed to discover privilege creep?
  303. 303. A service account cannot use an interactive multi-factor prompt. What should it rely on instead?
  304. 304. What property of a secrets manager most reduces the value of a leaked credential?
  305. 305. Which user behaviour does a password manager most directly eliminate?
  306. 306. Which two properties must a password reset link have? Choose two.
  307. 307. Why does certificate-based authentication resist network capture better than a password?
  308. 308. A smart card requires a PIN before it will sign an authentication challenge. How many factors does this represent?
  309. 309. Which biometric measure describes the rate at which impostors are wrongly accepted?
  310. 310. Users complain that a fingerprint reader rejects them too often, so the sensitivity is lowered. What is the security consequence?
  311. 311. An application creates a local account the first time the identity provider asserts a user. What is this called, and what problem does it solve?
  312. 312. Why must AAL3 authenticators use public-key cryptography to protect the authentication secret?
  313. 313. Which reauthentication limits does NIST associate with AAL3?
  314. 314. A federal service will display personal information to signed-in users. What minimum assurance level applies?
  315. 315. At every assurance level, what does NIST require of the channel between the claimant and the verifier?
  316. 316. What are the minimum requirements for an out-of-band authentication secret?
  317. 317. A one-time password is truncated to six digits. What obligation does that place on the verifier?
  318. 318. Which single control does OWASP identify as the most valuable defence for user accounts?
  319. 319. Why are hard-coded credentials in a container image particularly dangerous?
  320. 320. What distinguishes attribute-based access control from a permission list?
  321. 321. NIST describes access control lists and role-based access control as narrow cases of the attribute model. Which attribute does each key off?
  322. 322. A new contractor needs access to project records the moment they join, without an administrator granting it. Which model supports this directly?
  323. 323. Which two inputs, besides the rules and the subject's attributes, does an ABAC mechanism weigh on each request? Choose two.
  324. 324. An access requirement changes and the team struggles to find every place it was implemented. Which models does NIST warn about for this reason?
  325. 325. Two ABAC policies produce contradictory verdicts for the same request. What must the design have addressed?
  326. 326. An employee moves from finance to procurement. Under role-based access control, how is their access changed?
  327. 327. On a file share, the creator of a document can grant anyone else access to it. Which access control model is in use, and what is its weakness?
  328. 328. In a classified environment, no user may reclassify a document to a lower level, and access is decided by comparing clearance with label. Which model is this?
  329. 329. An administrator configures that no account may access the finance system outside 07:00 to 19:00, regardless of role. Which model does this illustrate?
  330. 330. What does applying least privilege achieve when an account is compromised?
  331. 331. A payments process is split so that one person raises a payment and another approves it. Which control is this, and what does it force an attacker to do?
  332. 332. Why are job rotation and mandatory vacation classed as detective rather than preventive controls?
  333. 333. What does a privileged access management platform change about how administrators work?
  334. 334. An engineer holds an administrator role only for the duration of an approved task, after which it is removed automatically. What is this called?
  335. 335. Which two controls should surround an emergency break-glass account? Choose two.
  336. 336. Which control closes the gap left when an offboarding notification never reaches the IT team?
  337. 337. What is the principal security problem with a shared administrator account used by four engineers?
  338. 338. Which control protects an unattended workstation without ending the user's work?
  339. 339. What does limiting the number of concurrent sessions per account achieve?
  340. 340. Which two requirements does NIST place on remote access? Choose two.
  341. 341. Which control governs where data may travel between systems and domains, as distinct from whether a subject may read an object?
  342. 342. What does zero trust replace as the basis for granting access?
  343. 343. In a zero trust architecture, which component sits in the data path and applies the verdict?
  344. 344. A user is granted access to the finance application under zero trust. What does this imply about the reporting database next door?
  345. 345. Why is "we have implemented zero trust" a poor summary of an organisation's position under the CISA maturity model?
  346. 346. An attacker compromises a workstation in the marketing VLAN. Which control most directly limits how far they can reach?
  347. 347. Two application servers sit on the same subnet but cannot communicate unless policy permits it. Which technique is in use?
  348. 348. An application hides the delete button from non-administrators but the delete endpoint performs no check. What is wrong?
  349. 349. Changing the invoice number in a URL shows another customer's invoice. What is this flaw called?
  350. 350. A standard user reads another standard user's records. How is this escalation classified?
  351. 351. An authorisation layer is deployed with a deny-by-default posture. What happens when a new endpoint is added and no rule is written for it?
  352. 352. In an 802.1X deployment, which role does the switch or wireless access point play?
  353. 353. A laptop fails a posture check because its endpoint agent is disabled. What should network access control do?
  354. 354. Which physical control defeats tailgating through a badge-controlled door?
  355. 355. A user's device falls out of compliance halfway through an authenticated session. Under zero trust, what should happen?
  356. 356. A relying party requests the full user profile when it only needs a department name. What principle does this violate?
  357. 357. Why does the order of entries in a firewall access list matter?
  358. 358. Which control corrects privilege creep, and why does the joiner process not?
  359. 359. An organisation grants access through security groups rather than per-user entitlements. What problem does this introduce over time?
  360. 360. An ABAC deployment produces wrong decisions even though its rules are correct. What should be examined first?
  361. 361. Which external inputs may a zero trust policy engine consult when scoring a request?
  362. 362. What is the purpose of a jump server for administrative access?
  363. 363. With credential vaulting and automatic rotation, why can an administrator not reuse the password they just used?
  364. 364. Which capability does a secrets platform give that a shared static password cannot?
  365. 365. An organisation enables split tunnelling on its VPN to reduce bandwidth. What is the security trade-off?
  366. 366. Why should authorisation be checked on every request rather than cached for the session?
  367. 367. Which requirement can attribute-based rules express that roles cannot?
  368. 368. What should be set when a contractor account is created?
  369. 369. Which description of zero trust's effect on the perimeter is most accurate?
  370. 370. Why does MITRE list privileged account management as a mitigation in its own right?
  371. 371. NIST's Access Control family treats access enforcement, account management, least privilege and separation of duties as separate controls. Why does that matter?
  372. 372. A request arrives from a server inside the corporate data centre. Under zero trust, how should it be treated?
  373. 373. Under zero trust's first tenet, which of the following counts as a resource?
  374. 374. Which two inputs feed a dynamic zero trust access decision? Choose two.
  375. 375. NIST divides the zero trust policy decision point into two logical components. Which pair?
  376. 376. Which two are recognised approaches to implementing a zero trust architecture? Choose two.
  377. 377. A zero trust enforcement point adds several seconds to every request. Why is this a design failure and not merely a performance issue?
  378. 378. Why does patching an industrial control system follow different rules from patching an office server?
  379. 379. Which two properties make Internet-of-Things devices difficult to secure? Choose two.
  380. 380. Under the cloud shared responsibility model, who is responsible for configuring identity permissions on a storage service?
  381. 381. How does the customer's responsibility change moving from infrastructure as a service to software as a service?
  382. 382. Why is isolation between containers weaker than between virtual machines?
  383. 383. An organisation places its public web servers between an external and an internal filtering layer. What is this design called, and what does it achieve?
  384. 384. What can a stateful firewall do that a stateless packet filter cannot without broad permissive rules?
  385. 385. An application tunnels its traffic over port 443 to avoid filtering. Which control identifies it anyway?
  386. 386. Which device can block a SQL injection attempt inside an otherwise permitted HTTPS session?
  387. 387. What risk does an intrusion prevention system carry that an intrusion detection system does not?
  388. 388. A team wants detection that can catch previously unseen attack behaviour and accepts more investigation effort. Which approach fits?
  389. 389. How does DNS filtering interrupt an intrusion before any connection is made?
  390. 390. Which device protects and load-balances inbound traffic to servers, as opposed to controlling outbound user traffic?
  391. 391. An organisation terminates TLS at its load balancer. What is the security trade-off?
  392. 392. Why is out-of-band management valuable during an incident?
  393. 393. Why does every TLS 1.3 handshake provide forward secrecy?
  394. 394. Which two features were removed in TLS 1.3? Choose two.
  395. 395. An API adopts TLS 1.3 zero-round-trip resumption for speed. Which request must not be sent as early data?
  396. 396. A site serves its login page over HTTPS and the rest over HTTP. Why is this insufficient?
  397. 397. Which mechanism closes the window opened by a user typing a bare hostname and being redirected from HTTP to HTTPS?
  398. 398. A phishing site presents a valid domain-validated certificate. What does this certificate actually prove?
  399. 399. What risk does a wildcard certificate concentrate?
  400. 400. What does a certificate signing request contain?
  401. 401. A browser warns about a self-signed certificate on an internal site. What is actually missing?
  402. 402. What does the three-two-one backup guidance require?
  403. 403. A team needs the fastest possible restore and accepts a long backup window. Which scheme fits?
  404. 404. Restoring from a differential backup scheme requires which media?
  405. 405. Why is a storage snapshot not a substitute for a backup?
  406. 406. An organisation relies on synchronous replication to a second site as its ransomware defence. What is the flaw?
  407. 407. An organisation needs to resume operations within an hour of a site loss and can fund it. Which alternate site type fits?
  408. 408. What is the tension in choosing the location of an alternate processing site?
  409. 409. Two data centres are twenty kilometres apart on the same power grid and flood plain. Which resilience property is not actually achieved?
  410. 410. A team selects a hot site before running the business impact analysis. What is the problem with that order?
  411. 411. A failover to an untested standby fails. Which two causes are most typical? Choose two.
  412. 412. What is the main security difference between wireless personal mode and enterprise mode?
  413. 413. Which weakness of WPA2 personal did WPA3 address by replacing the handshake?
  414. 414. An administrator disables broadcast of the wireless network name as a security measure. Why is this ineffective?
  415. 415. A team wants visibility into traffic without any chance of disrupting it. Which deployment fits?
  416. 416. An inline security appliance fails. Which design choice preserves control rather than availability?
  417. 417. A new storage medium has no vendor-supported sanitisation command. What follows for the organisation?
  418. 418. A patch programme covers operating systems and applications but not firmware. What is the consequence?
  419. 419. In MITRE ATT&CK, what is the difference between a tactic and a technique?
  420. 420. An adversary registers domains and builds infrastructure before any contact with the target. Which ATT&CK tactic is this?
  421. 421. Which ATT&CK tactic most directly enables an attacker to move from one compromised host to the rest of the estate?
  422. 422. An adversary encrypts a victim's file servers to disrupt operations. Which ATT&CK tactic does this fall under?
  423. 423. Why does analysing outbound traffic often reveal an intrusion the perimeter missed?
  424. 424. Why does MITRE catalogue Valid Accounts as a technique in its own right?
  425. 425. An organisation focuses its defences entirely on user awareness training. Which initial-access technique does this leave unaddressed?
  426. 426. What do ATT&CK data sources tell a detection team?
  427. 427. A team publishes an ATT&CK coverage map with no version recorded. Why is this a problem?
  428. 428. What most distinguishes a nation-state actor from other threat actors?
  429. 429. Why do campaigns by unskilled attackers tend to appear soon after a vulnerability is disclosed?
  430. 430. Which outcome is most characteristic of hacktivist activity?
  431. 431. Why does the ATT&CK Initial Access tactic have limited relevance to an insider threat?
  432. 432. Which two are recognised threat vectors on the exam? Choose two.
  433. 433. An organisation filters email thoroughly but has no controls on SMS or instant messaging. Why does the vector distinction matter?
  434. 434. Why does generic awareness messaging fail against spear phishing?
  435. 435. A finance clerk receives a convincing instruction to change a supplier's bank details and complies. No malware was involved. What is this attack called?
  436. 436. An attacker compromises an industry news site frequently read by employees of one company. Which technique is this?
  437. 437. An attacker registers a domain differing from a bank's by one transposed letter. What is this technique, and what does it exploit?
  438. 438. An attacker calls the help desk posing as a travelling executive locked out before a board meeting. Which social engineering element is central?
  439. 439. Which two psychological levers do social engineers most commonly use, and why? Choose two.
  440. 440. According to CISA, which two are common ransomware initial access routes? Choose two.
  441. 441. Which control does CISA recommend for remote desktop services that must remain available?
  442. 442. On discovering ransomware, an administrator wants to wipe and rebuild the affected servers immediately. What should happen first?
  443. 443. A board asks for threat intelligence to inform next year's security budget. Which tier is appropriate?
  444. 444. An assessor builds a target profile from company registrations, job adverts and public code repositories. What is this activity?
  445. 445. How does an indicator of attack differ from an indicator of compromise?
  446. 446. Why does behaviour-based detection built on ATT&CK techniques outlast an indicator feed?
  447. 447. A retailer subscribes to a threat feed aimed at industrial control operators. What is the likely result?
  448. 448. What distinguishes threat hunting from alert triage?
  449. 449. Which measure best characterises an advanced persistent threat?
  450. 450. Why is an untrusted wireless network a threat vector even when both endpoints are patched?
  451. 451. How does malware most commonly reach an air-gapped network?
  452. 452. Why is a malicious update through a legitimate vendor channel especially hard to stop?
  453. 453. Beyond a remediation list, what does the Known Exploited Vulnerabilities catalog tell a defender?
  454. 454. An analyst joins a sector information sharing community. Which notation tells them how widely each item may be redistributed?
  455. 455. Why does attachment sandboxing sit alongside link filtering rather than replacing it?
  456. 456. An attacker tries the password "Autumn2026!" against several thousand accounts, one attempt each. Which attack is this, and why does it work?
  457. 457. Which user behaviour makes credential stuffing effective?
  458. 458. An attacker steals a password hash file. Why does the login endpoint's rate limiting no longer help?
  459. 459. Which defence makes rainbow tables useless against a stolen password database?
  460. 460. Why is SHA-256 unsuitable for storing passwords even when salted?
  461. 461. A team pre-hashes passwords with plain SHA-512 before passing them to bcrypt. Which attack does this enable?
  462. 462. An attacker captures an authentication exchange on the network and replays it later to log in. Which property would have prevented this?
  463. 463. How does session hijacking differ from credential theft?
  464. 464. What does cross-site scripting give the attacker access to?
  465. 465. Which variant of cross-site scripting affects every user who views a page, without any of them clicking a crafted link?
  466. 466. A security review of server responses finds no injected script, yet cross-site scripting still occurs. Which variant is most likely?
  467. 467. What is the most serious outcome of SQL injection when the database account is over-privileged?
  468. 468. An application returns identical responses regardless of the injected condition, but responses take longer when the condition is true. What does this indicate?
  469. 469. A request for a report filename returns the contents of a system configuration file elsewhere on disk. Which attack is this?
  470. 470. An application passes user input into a shell command. What is the most reliable fix?
  471. 471. An XML parser resolves an external entity supplied by the user and returns a local file's contents. Which configuration change prevents this?
  472. 472. Why does process injection frustrate detection tools that judge activity by process name?
  473. 473. An adversary creates a scheduled task that runs their payload at every boot. Which ATT&CK tactic does this serve?
  474. 474. Malicious code lies dormant in an application until a specific date, then deletes records. What is this called?
  475. 475. Why should a suspected rootkit infection not be investigated using tools running on the affected host?
  476. 476. Why does a trojan need no software vulnerability to succeed?
  477. 477. Which malware property makes patching internet-facing services more urgent than patching desktops?
  478. 478. Why does fileless malware evade a product that scans files on disk?
  479. 479. A keylogger is installed on a user's workstation. Which control most directly limits the damage?
  480. 480. Why does blocking by source address fail against a distributed denial-of-service attack?
  481. 481. An attacker sends small spoofed requests to a service that replies with much larger responses aimed at the victim. What is this technique?
  482. 482. A user reaches an attacker's server while the address bar still shows the expected domain name. Which manipulation explains this?
  483. 483. How does an attacker take an on-path position inside a local network segment?
  484. 484. An attacker sets up an access point broadcasting the same network name as the corporate wireless. Why is this effective?
  485. 485. What are the two uses of a wireless deauthentication attack?
  486. 486. Why is disabling old TLS versions on the server necessary rather than merely deprioritising them?
  487. 487. Which property of a hash function does a birthday attack exploit?
  488. 488. A collision is found in the hash function underlying a signature scheme. What has been broken, even though no key was compromised?
  489. 489. An attacker recovers a key by measuring how long cryptographic operations take. What class of attack is this?
  490. 490. An attacker abuses a legitimate elevation mechanism rather than exploiting a software flaw. How does MITRE classify this?
  491. 491. After gaining access, an adversary adds an SSH key and a group membership to the compromised account. Which technique is this, and what does it achieve?
  492. 492. During an incident, defenders find their own administrative accounts have been disabled. Which ATT&CK tactic does this serve?
  493. 493. A flaw is being exploited and no patch exists. What is the appropriate response posture?
  494. 494. Which sequence lists the four phases of the NIST incident response lifecycle?
  495. 495. Which incident response phase most determines how well the other three go?
  496. 496. An engineer wants to reimage an infected server immediately to remove the malware. Why does NIST place containment before eradication?
  497. 497. Which two considerations does a containment strategy have to trade off? Choose two.
  498. 498. After eradication and recovery, what does NIST expect the team to do?
  499. 499. An organisation handles a major incident well but never holds a review afterwards. What has it lost?
  500. 500. Which dependency is most likely to delay an incident response if it was not settled in advance?
  501. 501. A responder spends hours attributing the attacking IP address during an active intrusion. What is NIST's guidance on this?
  502. 502. Three incidents are open at once. How should they be prioritised?
  503. 503. Which sequence describes the forensic process?
  504. 504. A responder is about to power down a compromised server for imaging. What should be captured first?
  505. 505. Why does the forensic process separate examination from analysis?
  506. 506. Why is forensic examination performed on a copy rather than the original media?
  507. 507. What does recomputing a hash of an evidence image months after acquisition demonstrate?
  508. 508. What does chain of custody add that a verified hash does not?
  509. 509. Litigation is anticipated and the retention schedule is about to delete relevant mailboxes. What must be issued?
  510. 510. An attacker wiped the endpoint's logs before leaving. Which evidence source may still show what was taken?
  511. 511. NIST expects log management duties to be assigned at two levels. Which two?
  512. 512. What is the principal security weakness of base syslog for centralised logging?
  513. 513. Why is log normalisation necessary before correlation?
  514. 514. An investigation cannot establish the order of events across three systems. Which prerequisite was most likely missing?
  515. 515. Why should logs be forwarded off the host promptly?
  516. 516. Why should log retention be planned against investigation needs rather than storage cost alone?
  517. 517. What does a security information and event management system add beyond centralised log storage?
  518. 518. A monitoring team is drowning in alerts nobody can act on. What is the underlying failure?
  519. 519. Which two capabilities does endpoint detection and response give an incident responder? Choose two.
  520. 520. What does extended detection and response add over endpoint detection and response?
  521. 521. What is the primary security benefit of orchestrating a response action rather than performing it manually?
  522. 522. A team scripts a repetitive hardening task. What new risk does this introduce?
  523. 523. Why do the credentials held by an automation platform deserve particular protection?
  524. 524. Which capability lets an organisation retain control of data on a device it does not own?
  525. 525. Under a bring-your-own-device policy, which approach separates corporate data from the owner's personal data?
  526. 526. Which monitoring approach continues to work when the network path to a host is down?
  527. 527. Which control alerts when a file that should never change is modified?
  528. 528. Which sequence describes the vulnerability management cycle the exam expects?
  529. 529. What question does root cause analysis ask that an incident timeline does not?
  530. 530. How do the questions asked by an incident responder and a forensic examiner differ?
  531. 531. Why is hashing rather than encryption the right tool for storing passwords?
  532. 532. How does a pepper differ from a salt?
  533. 533. A pepper is compromised. Why can it not simply be rotated?
  534. 534. Which password hashing algorithm does OWASP recommend first, and why?
  535. 535. An organisation must use FIPS-140 validated implementations. Which password hashing algorithm should it choose?
  536. 536. An application uses bcrypt and accepts passwords of any length. What must it also enforce?
  537. 537. When is the usual moment to re-hash a user's password with an increased work factor?
  538. 538. A team refuses to document which password hashing algorithm it uses, calling it sensitive. What is the correct position?
  539. 539. What determines the appropriate cryptoperiod for a key?
  540. 540. Why does a signing key's usage period end well before the period during which its signatures must still verify?
  541. 541. Why should the same key not be used both to sign and to encrypt?
  542. 542. An implementation seeds its key generation from the system clock. What is the consequence?
  543. 543. An organisation wants to rotate its encryption key without re-encrypting terabytes of stored data. Which technique achieves this?
  544. 544. What is the trade-off of escrowing an encryption key?
  545. 545. Why do protocols such as TLS use asymmetric cryptography only to establish a symmetric session key?
  546. 546. An adversary records encrypted sessions today and obtains the server's long-term private key next year. Which property prevents them decrypting the recordings?
  547. 547. Which two properties does a digital signature provide that an HMAC does not? Choose two.
  548. 548. What problem does a public key infrastructure solve?
  549. 549. In a public key infrastructure, which component verifies the requester's identity?
  550. 550. A mobile application pins the certificate of its backend. What does this prevent, and what does it complicate?
  551. 551. What security property does a blockchain provide?
  552. 552. A laptop with full-disk encryption is stolen while running and unlocked. What protection remains?
  553. 553. How does steganography differ from encryption?
  554. 554. What does key stretching achieve against an offline attacker?
  555. 555. What is the difference between using an approved algorithm and using a FIPS 140 validated module?
  556. 556. Why does NIST apply stricter FIPS 140 requirements to verifiers than to authenticators?
  557. 557. Why can a protocol using only static long-term keys not provide forward secrecy?
  558. 558. Why does SHA-1 still appear in some systems despite being unsuitable for new designs?
  559. 559. An attacker obtains valid query access to a database whose files are encrypted at rest. What still protects individual sensitive fields?
  560. 560. An attacker steals a table of salted password hashes. What can they do with it directly?
  561. 561. Beyond choosing an algorithm, which two concerns does key management cover? Choose two.
  562. 562. Which step was added to the Risk Management Framework in Revision 2, and what does it establish?
  563. 563. What does the risk executive function provide that individual system authorisations cannot?
  564. 564. Why are Cybersecurity Framework outcomes written to be sector-, country- and technology-neutral?
  565. 565. How does NIST expect supply chain cybersecurity to be handled?
  566. 566. Why can a medium-severity vulnerability legitimately outrank a high-severity one in a remediation queue?
  567. 567. An analyst wants to post a TLP:GREEN advisory on the company's public blog. Is that permitted?
  568. 568. A team translates an advisory into Spanish, including translating the TLP label. What is wrong?
  569. 569. Which artefact gives a security researcher a documented route to report a finding?
  570. 570. How does coordinated disclosure differ from full disclosure?
  571. 571. An organisation confirms backups complete successfully every night. What does CISA say this does not establish?
  572. 572. What makes ongoing authorisation less costly than a periodic full reassessment?
  573. 573. What changed about the structure of the NIST control catalogue in Revision 5?
  574. 574. A supplier ships a product with serious flaws caused by weak development practices, with no adversary involved. Which control addresses this?
  575. 575. A risk assessment is commissioned to inform a decision about a single application's deployment. At which tier should it be run?
  576. 576. An organisation has taken no explicit decision about a vulnerability it does not yet know exists. Which risk response is it implicitly taking?
  577. 577. What is the range of a CVSS score, and which metric group produces it before any refinement?
  578. 578. A flaw is exploitable only when a non-default option is enabled. How should the Base metrics be scored?
  579. 579. A scanner is tuned aggressively to reduce noise and now misses several real weaknesses. Which measure has worsened?
  580. 580. What does port and service identification contribute to a vulnerability assessment?
  581. 581. Where does escaping input sit among OWASP's SQL injection defences?
  582. 582. A team adds CSRF tokens to every endpoint, including read-only ones. What is the effect?
  583. 583. Which two of the following does the exam list among its mitigation techniques? Choose two.
  584. 584. What must a remediation report state beyond the list of findings?
  585. 585. A device cannot follow the standard patching plan. What keeps it visible and owned?
  586. 586. Why does OWASP treat storing unnecessary sensitive data as a vulnerability in itself?
  587. 587. Which two are identification and authentication failures? Choose two.
  588. 588. An application loads a plugin from an unverified source at runtime. Which OWASP category does this fall under?
  589. 589. An adversary sends a malicious attachment that establishes a foothold on a workstation. Which ATT&CK tactic has been achieved?
  590. 590. An attacker enumerates domain accounts, shares and running services on a compromised host. Which tactic is this?
  591. 591. A team looks for a one-to-one mapping between ATT&CK mitigations and products to buy. Why does this not work?
  592. 592. Which two motivations does the exam name for threat actors? Choose two.
  593. 593. Why do ransomware operations run affiliate programmes, negotiation teams and leak sites?
  594. 594. Why are voice phishing and SMS phishing treated as separate vectors from email phishing?
  595. 595. How does reducing the attack surface differ from hardening what remains?
  596. 596. Why does NIST advise building detection and analysis capability across the organisation rather than only in the security team?
  597. 597. Why does the forensic collection stage begin with identifying possible data sources?
  598. 598. Which two events should an application always log? Choose two.
  599. 599. Why do logs need their own access control and integrity protection?
  600. 600. What does the reporting step of the vulnerability management cycle achieve?
  601. 601. Which step of the secure baseline process do most programmes skip, and what is the result?
  602. 602. What must a defined account management lifecycle specify?
  603. 603. Which two ATT&CK mitigations limit what an adversary can run or elevate to? Choose two.
  604. 604. Why are badge readers and visitor logs treated as part of access management rather than facilities work?
  605. 605. Why should a secret be scoped to the smallest set of workloads that need it?
  606. 606. Under zero trust, when is trust in a requester evaluated and with what privilege granted?
  607. 607. Which two are architecture models the exam expects to be compared? Choose two.
  608. 608. Besides forward secrecy, what did TLS 1.3 improve about the handshake?
  609. 609. An organisation's backup server is domain-joined and reachable with production administrator credentials. Why does this defeat the backup's purpose?
  610. 610. How does continuity of operations planning differ from information system contingency planning?
  611. 611. Which two systems fall under the definition of operational technology? Choose two.