ALISON Diploma in Information Technology Support and Security — Questions and Answers
Question 1: What is a 'memory dump' and why is it important in malware forensics?
- A backup of the system's virtual memory swap file
- A capture of the contents of RAM at a point in time, revealing running processes and loaded malware (Correct answer)
- A report generated by antivirus software after a scan
- A log of failed memory allocation errors in system software
Correct answer: A capture of the contents of RAM at a point in time, revealing running processes and loaded malware
Memory dumps capture volatile RAM contents including running processes, network connections, decrypted data, and in-memory malware that leaves no disk artifacts.
Question 2: What term describes a social engineering attack where an attacker calls pretending to be tech support and tricks the victim into installing remote access software?
- Vishing with remote access trojan delivery
- Business email compromise
- Tech support scam (Correct answer)
- Reverse social engineering
Correct answer: Tech support scam
Tech support scams involve fraudsters posing as legitimate support agents to convince victims to grant remote access or pay for fake services.
Question 3: Which concept in cybercrime investigation refers to determining what happened, when, who did it, and how during an incident?
- Threat modeling
- Root cause analysis
- Vulnerability chaining
- Forensic timeline reconstruction (Correct answer)
Correct answer: Forensic timeline reconstruction
Forensic timeline reconstruction correlates timestamps across logs, file system metadata, and artifacts to create a chronological narrative of an incident.
Question 4: What is the recommended approach to staying current in Database Management & Security?
- Relying solely on past experience
- Regular professional development, industry publications, and peer collaboration (Correct answer)
- Waiting for regulatory changes to force updates
- Reviewing initial training materials once per year
Correct answer: Regular professional development, industry publications, and peer collaboration
Staying current in Database Management & Security requires ongoing professional development, reading industry publications, and collaborating with peers to share knowledge and best practices.
Question 5: What common challenge do professionals face when applying Application Security & Development principles?
- Finding the relevant textbook chapter
- Obtaining permission to use the principles
- Balancing theoretical best practices with practical constraints and real-world conditions (Correct answer)
- The principles are too simple to present any challenge
Correct answer: Balancing theoretical best practices with practical constraints and real-world conditions
Professionals commonly face the challenge of adapting theoretical best practices in Application Security & Development to the practical constraints and varying conditions encountered in real-world settings.
Question 6: Which best describes the scope of Vulnerability Assessment & Penetration Testing in professional practice?
- A narrow topic relevant only to entry-level professionals
- An outdated concept no longer relevant to modern practice
- A theoretical framework with no practical applications
- A comprehensive area covering both theoretical foundations and practical applications (Correct answer)
Correct answer: A comprehensive area covering both theoretical foundations and practical applications
Vulnerability Assessment & Penetration Testing encompasses both theoretical foundations and practical applications that are essential to professional practice in this field.
Question 7: How often should compliance procedures be reviewed and updated?
- Once at initial certification and never again
- Regularly, and whenever regulations change or new risks are identified (Correct answer)
- Every ten years regardless of changes
- Only when an audit is scheduled
Correct answer: Regularly, and whenever regulations change or new risks are identified
Compliance procedures should be reviewed regularly and updated whenever regulations change, new risks emerge, or organizational changes occur.
Question 8: What tool is commonly used on Linux/Unix systems to create a forensic bit-stream image of a drive?
- Metasploit
- dd (Correct answer)
- Wireshark
- Nmap
Correct answer: dd
The dd command creates a raw bit-stream copy of a device, making it one of the most fundamental forensic imaging tools on Unix-like systems.
Question 9: What is the principle of least privilege in network security?
- Access permissions should be updated annually
- New users should receive the same access as their managers
- Users should have only the minimum access needed to perform their job functions (Correct answer)
- All users should have administrator access for convenience
Correct answer: Users should have only the minimum access needed to perform their job functions
The principle of least privilege restricts user access to only the resources and permissions necessary for their specific job functions, minimizing potential damage from compromised accounts.
Question 10: What is the first step in the risk management process?
- Risk identification — recognizing potential threats and vulnerabilities (Correct answer)
- Risk acceptance — deciding to live with all risks
- Risk transfer — purchasing insurance immediately
- Risk avoidance — canceling all activities
Correct answer: Risk identification — recognizing potential threats and vulnerabilities
Risk identification is the critical first step in risk management, involving systematic recognition and documentation of potential threats and vulnerabilities.
Question 11: What is 'pretexting' in the context of social engineering?
- Intercepting wireless network traffic
- Sending bulk spam emails
- Installing keyloggers on a target system
- Creating a fabricated scenario to manipulate a victim into revealing information (Correct answer)
Correct answer: Creating a fabricated scenario to manipulate a victim into revealing information
Pretexting involves an attacker inventing a false situation or identity to gain the victim's trust and extract confidential information.
Question 12: What is 'whaling' in the context of social engineering?
- Spear phishing attacks targeting senior executives or high-profile individuals (Correct answer)
- Mass phishing campaigns targeting thousands of users
- Using large botnets to deliver phishing emails
- Attacks against maritime or shipping industry networks
Correct answer: Spear phishing attacks targeting senior executives or high-profile individuals
Whaling targets 'big fish' such as CEOs, CFOs, and other executives, leveraging their authority and access to high-value systems.
Question 13: What is the relationship between Database Management & Security and ethical professional conduct?
- Ethical considerations are integrated into all aspects of professional practice in this area (Correct answer)
- Ethics is relevant only when legal issues arise
- There is no connection between technical knowledge and ethics
- Ethics applies only to separate, unrelated decisions
Correct answer: Ethical considerations are integrated into all aspects of professional practice in this area
Ethical considerations are deeply integrated into Database Management & Security, as professional conduct and integrity underpin all aspects of practice in this field.
Question 14: Which best describes the scope of Cloud Computing & Virtualization in professional practice?
- A narrow topic relevant only to entry-level professionals
- An outdated concept no longer relevant to modern practice
- A theoretical framework with no practical applications
- A comprehensive area covering both theoretical foundations and practical applications (Correct answer)
Correct answer: A comprehensive area covering both theoretical foundations and practical applications
Cloud Computing & Virtualization encompasses both theoretical foundations and practical applications that are essential to professional practice in this field.
Question 15: What is a 'forensic image' in digital forensics?
- A bit-for-bit copy of a storage device including unallocated space (Correct answer)
- A screenshot taken during an investigation
- A photograph of the crime scene equipment
- An encrypted backup of the suspect's files
Correct answer: A bit-for-bit copy of a storage device including unallocated space
A forensic image is an exact sector-by-sector copy of a storage medium that captures all data including deleted files and unallocated space.
Question 16: What is the most important competency assessed in Database Management & Security for professionals in this field?
- Memorization of textbook definitions only
- Academic credentials without practical application
- Years of experience without demonstrated skill
- Applied knowledge and practical problem-solving ability (Correct answer)
Correct answer: Applied knowledge and practical problem-solving ability
Database Management & Security assessment focuses on applied knowledge and practical problem-solving ability, ensuring professionals can effectively perform in real-world situations.
Question 17: What is the relationship between System Administration & Configuration and ethical professional conduct?
- There is no connection between technical knowledge and ethics
- Ethics is relevant only when legal issues arise
- Ethics applies only to separate, unrelated decisions
- Ethical considerations are integrated into all aspects of professional practice in this area (Correct answer)
Correct answer: Ethical considerations are integrated into all aspects of professional practice in this area
Ethical considerations are deeply integrated into System Administration & Configuration, as professional conduct and integrity underpin all aspects of practice in this field.
Question 18: What is the primary purpose of maintaining a 'chain of custody' in digital forensics?
- To share evidence with law enforcement agencies quickly
- To speed up the evidence collection process
- To encrypt all collected evidence files
- To ensure digital evidence remains admissible and unaltered throughout an investigation (Correct answer)
Correct answer: To ensure digital evidence remains admissible and unaltered throughout an investigation
Chain of custody documents every person who handled evidence and every action taken, ensuring its integrity and legal admissibility in court.
Question 19: How does Threat Detection & Incident Response contribute to overall professional effectiveness?
- It applies only to supervisory-level professionals
- It is relevant only during the certification examination
- It provides essential knowledge and skills that directly impact quality of work and outcomes (Correct answer)
- It serves only as a credential requirement with no practical impact
Correct answer: It provides essential knowledge and skills that directly impact quality of work and outcomes
Threat Detection & Incident Response directly contributes to professional effectiveness by providing essential knowledge and skills that improve the quality of work and outcomes across all career levels.
Question 20: What is 'anti-forensics' and what challenge does it present to investigators?
- Encryption tools used to protect forensic images
- Techniques used by attackers to destroy, hide, or alter digital evidence to impede investigations (Correct answer)
- Legal restrictions preventing forensic analysis without a warrant
- Software that speeds up forensic analysis
Correct answer: Techniques used by attackers to destroy, hide, or alter digital evidence to impede investigations
Anti-forensics includes wiping tools, timestamp manipulation, and encryption to make evidence collection harder or impossible for investigators.
Question 21: Which behavior is the best indicator that an employee has been effectively trained against social engineering?
- They disable email on their workstation when away
- They never click on any email links
- They immediately forward suspicious emails to all colleagues
- They verify unexpected requests through an out-of-band communication channel (Correct answer)
Correct answer: They verify unexpected requests through an out-of-band communication channel
Verifying requests via a separate, trusted channel (like calling the requester directly on a known number) defeats most social engineering attempts.
Question 22: How does Access Control & Identity Management contribute to overall professional effectiveness?
- It is relevant only during the certification examination
- It serves only as a credential requirement with no practical impact
- It applies only to supervisory-level professionals
- It provides essential knowledge and skills that directly impact quality of work and outcomes (Correct answer)
Correct answer: It provides essential knowledge and skills that directly impact quality of work and outcomes
Access Control & Identity Management directly contributes to professional effectiveness by providing essential knowledge and skills that improve the quality of work and outcomes across all career levels.
Question 23: Which best describes the scope of Access Control & Identity Management in professional practice?
- An outdated concept no longer relevant to modern practice
- A comprehensive area covering both theoretical foundations and practical applications (Correct answer)
- A narrow topic relevant only to entry-level professionals
- A theoretical framework with no practical applications
Correct answer: A comprehensive area covering both theoretical foundations and practical applications
Access Control & Identity Management encompasses both theoretical foundations and practical applications that are essential to professional practice in this field.
Question 24: What is the relationship between Operating Systems & Platforms and ethical professional conduct?
- Ethics is relevant only when legal issues arise
- There is no connection between technical knowledge and ethics
- Ethical considerations are integrated into all aspects of professional practice in this area (Correct answer)
- Ethics applies only to separate, unrelated decisions
Correct answer: Ethical considerations are integrated into all aspects of professional practice in this area
Ethical considerations are deeply integrated into Operating Systems & Platforms, as professional conduct and integrity underpin all aspects of practice in this field.
Question 25: What is the relationship between Cloud Computing & Virtualization and ethical professional conduct?
- Ethics is relevant only when legal issues arise
- There is no connection between technical knowledge and ethics
- Ethical considerations are integrated into all aspects of professional practice in this area (Correct answer)
- Ethics applies only to separate, unrelated decisions
Correct answer: Ethical considerations are integrated into all aspects of professional practice in this area
Ethical considerations are deeply integrated into Cloud Computing & Virtualization, as professional conduct and integrity underpin all aspects of practice in this field.
Question 26: What is the consequence of non-compliance with mandatory regulations?
- Reduced insurance premiums
- A verbal warning with no further consequences
- Automatic extension of compliance deadline
- Penalties including fines, license revocation, and potential legal action (Correct answer)
Correct answer: Penalties including fines, license revocation, and potential legal action
Non-compliance with mandatory regulations can result in serious consequences including financial penalties, loss of licensure, and legal proceedings.
Question 27: What does a risk matrix assess?
- The probability and impact of identified risks (Correct answer)
- The timeline for risk resolution
- Only the financial cost of risks
- The number of employees affected
Correct answer: The probability and impact of identified risks
A risk matrix evaluates risks based on two dimensions: the probability (likelihood) of occurrence and the potential impact (severity) if the risk materializes.
Question 28: What is 'shoulder surfing' as a social engineering technique?
- Intercepting wireless signals in public areas
- Hijacking a user's active browser session
- Sending fraudulent emails to coworkers
- Observing someone entering passwords or PINs by looking over their shoulder (Correct answer)
Correct answer: Observing someone entering passwords or PINs by looking over their shoulder
Shoulder surfing involves physically observing a target as they input sensitive data such as passwords, PINs, or credit card numbers.
Question 29: How does Operating Systems & Platforms contribute to overall professional effectiveness?
- It provides essential knowledge and skills that directly impact quality of work and outcomes (Correct answer)
- It serves only as a credential requirement with no practical impact
- It applies only to supervisory-level professionals
- It is relevant only during the certification examination
Correct answer: It provides essential knowledge and skills that directly impact quality of work and outcomes
Operating Systems & Platforms directly contributes to professional effectiveness by providing essential knowledge and skills that improve the quality of work and outcomes across all career levels.
Question 30: What is an IMSI catcher (often called a 'Stingray') used for in security contexts?
- A device that impersonates a cellular base station to intercept mobile communications and track device locations (Correct answer)
- Software that detects rogue access points on corporate networks
- A forensic tool for extracting data from locked smartphones
- A tool for analyzing Wi-Fi packet captures in real time
Correct answer: A device that impersonates a cellular base station to intercept mobile communications and track device locations
An IMSI catcher mimics a legitimate cell tower, forcing nearby phones to connect to it, enabling interception of calls, SMS, and location data by capturing the device's IMSI.
Question 31: What common challenge do professionals face when applying Access Control & Identity Management principles?
- The principles are too simple to present any challenge
- Finding the relevant textbook chapter
- Balancing theoretical best practices with practical constraints and real-world conditions (Correct answer)
- Obtaining permission to use the principles
Correct answer: Balancing theoretical best practices with practical constraints and real-world conditions
Professionals commonly face the challenge of adapting theoretical best practices in Access Control & Identity Management to the practical constraints and varying conditions encountered in real-world settings.
Question 32: What is a DMZ (Demilitarized Zone) in network architecture?
- A meeting room for discussing network security
- A backup data center in a remote location
- A network segment between internal and external networks that hosts public-facing services (Correct answer)
- A restricted area where damaged equipment is stored
Correct answer: A network segment between internal and external networks that hosts public-facing services
A DMZ is a network segment that sits between the internal network and external networks, hosting public-facing services while protecting the internal network from direct exposure.
Question 33: What common challenge do professionals face when applying Vulnerability Assessment & Penetration Testing principles?
- Obtaining permission to use the principles
- The principles are too simple to present any challenge
- Finding the relevant textbook chapter
- Balancing theoretical best practices with practical constraints and real-world conditions (Correct answer)
Correct answer: Balancing theoretical best practices with practical constraints and real-world conditions
Professionals commonly face the challenge of adapting theoretical best practices in Vulnerability Assessment & Penetration Testing to the practical constraints and varying conditions encountered in real-world settings.
Question 34: What should be the first action when a new regulation is enacted that affects your practice?
- Delegate review to the newest team member
- Assume existing procedures already comply
- Review the regulation, assess its impact, and develop an implementation plan (Correct answer)
- Wait for enforcement before making changes
Correct answer: Review the regulation, assess its impact, and develop an implementation plan
When new regulations are enacted, professionals should promptly review them, assess their impact on current practices, and develop a structured implementation plan.
Question 35: What is the most important competency assessed in Application Security & Development for professionals in this field?
- Memorization of textbook definitions only
- Applied knowledge and practical problem-solving ability (Correct answer)
- Academic credentials without practical application
- Years of experience without demonstrated skill
Correct answer: Applied knowledge and practical problem-solving ability
Application Security & Development assessment focuses on applied knowledge and practical problem-solving ability, ensuring professionals can effectively perform in real-world situations.
Question 36: How does Cloud Computing & Virtualization contribute to overall professional effectiveness?
- It serves only as a credential requirement with no practical impact
- It applies only to supervisory-level professionals
- It is relevant only during the certification examination
- It provides essential knowledge and skills that directly impact quality of work and outcomes (Correct answer)
Correct answer: It provides essential knowledge and skills that directly impact quality of work and outcomes
Cloud Computing & Virtualization directly contributes to professional effectiveness by providing essential knowledge and skills that improve the quality of work and outcomes across all career levels.
Question 37: What countermeasure best protects against phishing attacks in an organization?
- Disabling all outbound internet traffic
- Using only phone-based communications
- Implementing multi-factor authentication and employee phishing simulations (Correct answer)
- Blocking all email attachments
Correct answer: Implementing multi-factor authentication and employee phishing simulations
Combining MFA (to limit damage if credentials are stolen) with simulated phishing training significantly reduces organizational phishing risk.
Question 38: Which encryption protocol was introduced to replace the vulnerable WEP standard in wireless networks?
- WPA (Wi-Fi Protected Access) (Correct answer)
- IPsec
- SSL/TLS
- AES-256
Correct answer: WPA (Wi-Fi Protected Access)
WPA was specifically designed as an interim replacement for WEP, using TKIP for stronger encryption while maintaining backward compatibility.
Question 39: Which risk response strategy involves reducing the likelihood or impact of a risk?
- Risk transfer
- Risk escalation
- Risk acceptance
- Risk mitigation (Correct answer)
Correct answer: Risk mitigation
Risk mitigation involves taking proactive steps to reduce either the probability of a risk occurring or its potential impact if it does occur.
Question 40: Starting with Android 6.0 (Marshmallow), how were app permissions changed to improve security?
- Dangerous permissions must be requested and granted individually at runtime (Correct answer)
- Permissions were granted at install time in bulk with no granular control
- All permissions were removed and replaced with a single app trust level
- Permissions became device-wide rather than per-application
Correct answer: Dangerous permissions must be requested and granted individually at runtime
Android 6.0 introduced runtime permissions, requiring apps to request dangerous permissions (camera, contacts, location) individually when the feature is used, giving users granular control.
Question 41: What is the recommended approach to staying current in Access Control & Identity Management?
- Waiting for regulatory changes to force updates
- Regular professional development, industry publications, and peer collaboration (Correct answer)
- Relying solely on past experience
- Reviewing initial training materials once per year
Correct answer: Regular professional development, industry publications, and peer collaboration
Staying current in Access Control & Identity Management requires ongoing professional development, reading industry publications, and collaborating with peers to share knowledge and best practices.
Question 42: What primary security risk does a BYOD (Bring Your Own Device) policy introduce in an enterprise environment?
- Mandatory compliance with consumer privacy laws for the employer
- Increased hardware procurement costs for the IT department
- Reduced network bandwidth due to personal device usage
- Loss of organizational control over device security posture and data handling (Correct answer)
Correct answer: Loss of organizational control over device security posture and data handling
BYOD reduces IT control over patching, encryption, and app installation on personal devices, creating risk that corporate data may be stored or transmitted insecurely.
Question 43: Which best describes the scope of Threat Detection & Incident Response in professional practice?
- A comprehensive area covering both theoretical foundations and practical applications (Correct answer)
- A theoretical framework with no practical applications
- A narrow topic relevant only to entry-level professionals
- An outdated concept no longer relevant to modern practice
Correct answer: A comprehensive area covering both theoretical foundations and practical applications
Threat Detection & Incident Response encompasses both theoretical foundations and practical applications that are essential to professional practice in this field.
Question 44: What does TKIP stand for and why was it introduced?
- Transport Key Interchange Protocol — for secure key exchange in VPNs
- Trusted Key Integrity Protocol — to replace RSA in wireless environments
- Temporal Key Integrity Protocol — as a WPA improvement over WEP's static key reuse (Correct answer)
- Two-factor Key Integration Protocol — for multi-factor Wi-Fi authentication
Correct answer: Temporal Key Integrity Protocol — as a WPA improvement over WEP's static key reuse
TKIP (Temporal Key Integrity Protocol) was introduced with WPA to address WEP's fatal flaw of static key reuse by dynamically generating a new encryption key for each packet.
Question 45: How does a 'watering hole' attack incorporate social engineering?
- Attackers intercept data at public water utilities
- Attackers send poisoned water cooler meeting invites via email
- Attackers compromise websites frequently visited by the target group (Correct answer)
- Attackers target employees during lunch breaks in common areas
Correct answer: Attackers compromise websites frequently visited by the target group
In a watering hole attack, adversaries infect websites that a specific target group regularly visits, exploiting trust in familiar sites.
Question 46: What common challenge do professionals face when applying Cloud Computing & Virtualization principles?
- Balancing theoretical best practices with practical constraints and real-world conditions (Correct answer)
- Obtaining permission to use the principles
- The principles are too simple to present any challenge
- Finding the relevant textbook chapter
Correct answer: Balancing theoretical best practices with practical constraints and real-world conditions
Professionals commonly face the challenge of adapting theoretical best practices in Cloud Computing & Virtualization to the practical constraints and varying conditions encountered in real-world settings.
Question 47: Which approach to compliance is considered most effective?
- Focusing compliance efforts only on areas that have been cited previously
- A proactive approach that integrates compliance into daily operations (Correct answer)
- Hiring a consultant once a year for a brief review
- A reactive approach that addresses issues only after violations
Correct answer: A proactive approach that integrates compliance into daily operations
A proactive compliance approach that integrates regulatory requirements into daily operations is most effective at preventing violations and maintaining standards.
Question 48: What is the purpose of intrusion detection systems (IDS)?
- To prevent all unauthorized access automatically
- To manage network IP addresses
- To monitor network traffic for suspicious activity and known threats (Correct answer)
- To speed up network performance
Correct answer: To monitor network traffic for suspicious activity and known threats
IDS monitors network traffic for suspicious activity, known attack patterns, and policy violations, alerting administrators to potential security threats.
Question 49: Why is regular risk reassessment important?
- Because initial assessments are always wrong
- Because it provides work for risk management teams
- Because the risk landscape changes as conditions, activities, and environments evolve (Correct answer)
- Because regulators require it exactly once per year
Correct answer: Because the risk landscape changes as conditions, activities, and environments evolve
Regular risk reassessment is essential because risks are dynamic — new threats emerge, existing risks change in severity, and the effectiveness of controls may vary over time.
Question 50: Which psychological principle is exploited when an attacker impersonates an IT manager demanding immediate password resets?
- Authority (Correct answer)
- Reciprocity
- Liking
- Commitment
Correct answer: Authority
The authority principle makes people more likely to comply with requests from perceived figures of power or authority without questioning them.
Question 51: What is 'steganography' and why is it relevant to digital forensics?
- A method for bypassing file system access controls
- A type of malware that hides in system firmware
- A technique for encrypting network traffic to avoid detection
- Hiding data within ordinary-looking files like images to conceal communications or exfiltrate data (Correct answer)
Correct answer: Hiding data within ordinary-looking files like images to conceal communications or exfiltrate data
Steganography conceals data inside carrier files, and forensic investigators must detect and extract hidden content during investigations.
Question 52: What is the relationship between Access Control & Identity Management and ethical professional conduct?
- Ethical considerations are integrated into all aspects of professional practice in this area (Correct answer)
- There is no connection between technical knowledge and ethics
- Ethics is relevant only when legal issues arise
- Ethics applies only to separate, unrelated decisions
Correct answer: Ethical considerations are integrated into all aspects of professional practice in this area
Ethical considerations are deeply integrated into Access Control & Identity Management, as professional conduct and integrity underpin all aspects of practice in this field.
Question 53: What is 'smishing' in mobile security?
- Phishing attacks delivered via SMS text messages (Correct answer)
- Exploiting vulnerabilities in smartphone browsers
- Installing spyware through malicious QR codes
- Sending malware via Bluetooth to nearby devices
Correct answer: Phishing attacks delivered via SMS text messages
Smishing (SMS phishing) involves sending deceptive text messages that trick recipients into clicking malicious links or providing sensitive information.
Question 54: What common challenge do professionals face when applying Threat Detection & Incident Response principles?
- The principles are too simple to present any challenge
- Finding the relevant textbook chapter
- Balancing theoretical best practices with practical constraints and real-world conditions (Correct answer)
- Obtaining permission to use the principles
Correct answer: Balancing theoretical best practices with practical constraints and real-world conditions
Professionals commonly face the challenge of adapting theoretical best practices in Threat Detection & Incident Response to the practical constraints and varying conditions encountered in real-world settings.
Question 55: What does MDM stand for in the context of enterprise mobile security?
- Mobile Device Management (Correct answer)
- Mobile Data Management
- Managed Device Module
- Multi-Domain Monitoring
Correct answer: Mobile Device Management
MDM (Mobile Device Management) is a solution that allows organizations to remotely manage, monitor, and enforce security policies on employee mobile devices.
Question 56: What is a rogue access point in network security?
- A misconfigured router with outdated firmware
- A public Wi-Fi hotspot with no password
- An unauthorized wireless access point installed on a network without admin approval (Correct answer)
- An access point that uses an outdated encryption protocol
Correct answer: An unauthorized wireless access point installed on a network without admin approval
A rogue access point is an unauthorized AP connected to a network, which attackers or insiders can use to bypass perimeter security and intercept traffic.
Question 57: What is the correct order of volatility in digital evidence collection?
- CPU registers → RAM → Network → Disk (Correct answer)
- Network → Disk → RAM → CPU registers
- Disk → RAM → Network → CPU registers
- RAM → Disk → CPU registers → Network
Correct answer: CPU registers → RAM → Network → Disk
Evidence should be collected from most volatile (CPU registers, cache) to least volatile (disk) to preserve the most transient data first.
Question 58: What is the relationship between Vulnerability Assessment & Penetration Testing and ethical professional conduct?
- Ethics applies only to separate, unrelated decisions
- Ethical considerations are integrated into all aspects of professional practice in this area (Correct answer)
- Ethics is relevant only when legal issues arise
- There is no connection between technical knowledge and ethics
Correct answer: Ethical considerations are integrated into all aspects of professional practice in this area
Ethical considerations are deeply integrated into Vulnerability Assessment & Penetration Testing, as professional conduct and integrity underpin all aspects of practice in this field.
Question 59: What type of file system artifact allows forensic investigators to recover deleted files on NTFS volumes?
- Volume Shadow Copies
- Master File Table ($MFT) (Correct answer)
- Master Boot Record
- Recycle Bin metadata
Correct answer: Master File Table ($MFT)
The NTFS Master File Table ($MFT) retains metadata about deleted files even after deletion, enabling partial or full file recovery.
Question 60: What is network segmentation and why is it important?
- Dividing a network into smaller segments to contain breaches and control access (Correct answer)
- Upgrading all network cables simultaneously
- Increasing the number of network devices
- Removing old network equipment
Correct answer: Dividing a network into smaller segments to contain breaches and control access
Network segmentation divides a network into isolated segments, limiting the spread of security breaches and providing granular access control.
Question 61: Which best describes the scope of Database Management & Security in professional practice?
- A comprehensive area covering both theoretical foundations and practical applications (Correct answer)
- A theoretical framework with no practical applications
- An outdated concept no longer relevant to modern practice
- A narrow topic relevant only to entry-level professionals
Correct answer: A comprehensive area covering both theoretical foundations and practical applications
Database Management & Security encompasses both theoretical foundations and practical applications that are essential to professional practice in this field.
Question 62: What is the primary purpose of industry regulations in this field?
- To create barriers to entry for new professionals
- To protect the public and ensure consistent professional standards (Correct answer)
- To generate revenue for regulatory bodies
- To limit competition in the marketplace
Correct answer: To protect the public and ensure consistent professional standards
Industry regulations are primarily designed to protect the public by ensuring professionals meet consistent standards of competence and conduct.
Question 63: What Bluetooth attack passively captures device information from discoverable Bluetooth devices without owner permission?
- Bluesnarfing (Correct answer)
- Bluetoothing
- Bluebugging
- Bluejacking
Correct answer: Bluesnarfing
Bluesnarfing involves unauthorized access to information on a Bluetooth device (contacts, messages, calendar), exploiting vulnerabilities in the OBEX protocol on discoverable devices.
Question 64: What is the most important competency assessed in Cryptography & Data Protection for professionals in this field?
- Years of experience without demonstrated skill
- Memorization of textbook definitions only
- Applied knowledge and practical problem-solving ability (Correct answer)
- Academic credentials without practical application
Correct answer: Applied knowledge and practical problem-solving ability
Cryptography & Data Protection assessment focuses on applied knowledge and practical problem-solving ability, ensuring professionals can effectively perform in real-world situations.
Question 65: What common challenge do professionals face when applying Operating Systems & Platforms principles?
- Balancing theoretical best practices with practical constraints and real-world conditions (Correct answer)
- Obtaining permission to use the principles
- Finding the relevant textbook chapter
- The principles are too simple to present any challenge
Correct answer: Balancing theoretical best practices with practical constraints and real-world conditions
Professionals commonly face the challenge of adapting theoretical best practices in Operating Systems & Platforms to the practical constraints and varying conditions encountered in real-world settings.
Question 66: What is the most important competency assessed in Cloud Computing & Virtualization for professionals in this field?
- Years of experience without demonstrated skill
- Applied knowledge and practical problem-solving ability (Correct answer)
- Academic credentials without practical application
- Memorization of textbook definitions only
Correct answer: Applied knowledge and practical problem-solving ability
Cloud Computing & Virtualization assessment focuses on applied knowledge and practical problem-solving ability, ensuring professionals can effectively perform in real-world situations.
Question 67: What common challenge do professionals face when applying System Administration & Configuration principles?
- The principles are too simple to present any challenge
- Obtaining permission to use the principles
- Finding the relevant textbook chapter
- Balancing theoretical best practices with practical constraints and real-world conditions (Correct answer)
Correct answer: Balancing theoretical best practices with practical constraints and real-world conditions
Professionals commonly face the challenge of adapting theoretical best practices in System Administration & Configuration to the practical constraints and varying conditions encountered in real-world settings.
Question 68: What is 'baiting' as a social engineering technique?
- Sending threatening emails to cause panic
- Monitoring a target's physical surroundings
- Leaving infected USB drives or media in public places for victims to find (Correct answer)
- Calling victims and pretending to be tech support
Correct answer: Leaving infected USB drives or media in public places for victims to find
Baiting lures victims by leaving malware-laden physical media (like USB drives) where curious individuals will pick them up and insert them into computers.
Question 69: Which social engineering attack involves sending fraudulent emails that appear to come from a trusted source to steal credentials?
- Phishing (Correct answer)
- Tailgating
- Vishing
- Smishing
Correct answer: Phishing
Phishing uses deceptive emails that mimic legitimate organizations to trick recipients into revealing sensitive information.
Question 70: What is the recommended approach to staying current in Operating Systems & Platforms?
- Relying solely on past experience
- Regular professional development, industry publications, and peer collaboration (Correct answer)
- Waiting for regulatory changes to force updates
- Reviewing initial training materials once per year
Correct answer: Regular professional development, industry publications, and peer collaboration
Staying current in Operating Systems & Platforms requires ongoing professional development, reading industry publications, and collaborating with peers to share knowledge and best practices.
Question 71: What is the most important competency assessed in System Administration & Configuration for professionals in this field?
- Memorization of textbook definitions only
- Applied knowledge and practical problem-solving ability (Correct answer)
- Academic credentials without practical application
- Years of experience without demonstrated skill
Correct answer: Applied knowledge and practical problem-solving ability
System Administration & Configuration assessment focuses on applied knowledge and practical problem-solving ability, ensuring professionals can effectively perform in real-world situations.
Question 72: What is the recommended approach to staying current in Application Security & Development?
- Regular professional development, industry publications, and peer collaboration (Correct answer)
- Waiting for regulatory changes to force updates
- Reviewing initial training materials once per year
- Relying solely on past experience
Correct answer: Regular professional development, industry publications, and peer collaboration
Staying current in Application Security & Development requires ongoing professional development, reading industry publications, and collaborating with peers to share knowledge and best practices.
Question 73: Which log file in Linux systems is most useful for tracking user authentication events during a forensic investigation?
- /var/log/syslog
- /var/log/auth.log (Correct answer)
- /var/log/kern.log
- /var/log/dmesg
Correct answer: /var/log/auth.log
The /var/log/auth.log file on Debian/Ubuntu systems records all authentication attempts, sudo usage, SSH logins, and account changes.
Question 74: What is the relationship between Cryptography & Data Protection and ethical professional conduct?
- Ethical considerations are integrated into all aspects of professional practice in this area (Correct answer)
- Ethics applies only to separate, unrelated decisions
- Ethics is relevant only when legal issues arise
- There is no connection between technical knowledge and ethics
Correct answer: Ethical considerations are integrated into all aspects of professional practice in this area
Ethical considerations are deeply integrated into Cryptography & Data Protection, as professional conduct and integrity underpin all aspects of practice in this field.
Question 75: How does System Administration & Configuration contribute to overall professional effectiveness?
- It is relevant only during the certification examination
- It provides essential knowledge and skills that directly impact quality of work and outcomes (Correct answer)
- It applies only to supervisory-level professionals
- It serves only as a credential requirement with no practical impact
Correct answer: It provides essential knowledge and skills that directly impact quality of work and outcomes
System Administration & Configuration directly contributes to professional effectiveness by providing essential knowledge and skills that improve the quality of work and outcomes across all career levels.
Question 76: How does Cryptography & Data Protection contribute to overall professional effectiveness?
- It is relevant only during the certification examination
- It serves only as a credential requirement with no practical impact
- It provides essential knowledge and skills that directly impact quality of work and outcomes (Correct answer)
- It applies only to supervisory-level professionals
Correct answer: It provides essential knowledge and skills that directly impact quality of work and outcomes
Cryptography & Data Protection directly contributes to professional effectiveness by providing essential knowledge and skills that improve the quality of work and outcomes across all career levels.
Question 77: What US law governs the interception of electronic communications and is relevant to digital forensics investigations?
- Electronic Communications Privacy Act (ECPA) (Correct answer)
- Sarbanes-Oxley Act (SOX)
- Computer Fraud and Abuse Act (CFAA)
- Health Insurance Portability and Accountability Act (HIPAA)
Correct answer: Electronic Communications Privacy Act (ECPA)
The ECPA sets legal standards for accessing stored electronic communications and monitoring digital transmissions, directly governing how forensic evidence is collected.
Question 78: What is 'network forensics' focused on?
- Installing monitoring agents on network switches
- Capturing and analyzing network traffic to reconstruct events and identify attackers (Correct answer)
- Forensically imaging routers and firewalls
- Recovering deleted files from network-attached storage
Correct answer: Capturing and analyzing network traffic to reconstruct events and identify attackers
Network forensics involves monitoring and analyzing network packets, flows, and logs to reconstruct attack timelines and identify malicious activity.
Question 79: Which principle in digital forensics states that any contact between two items leaves a trace?
- Locard's Exchange Principle (Correct answer)
- Shannon's Information Theory
- Bell-LaPadula Model
- Occam's Razor
Correct answer: Locard's Exchange Principle
Locard's Exchange Principle states that every contact leaves a trace, which in digital forensics means system interactions leave artifacts like logs and metadata.
Question 80: What is the key difference between WPA2-Personal (PSK) and WPA2-Enterprise in terms of authentication?
- WPA2-Enterprise is only available on 5 GHz bands while WPA2-Personal supports 2.4 GHz
- WPA2-Personal supports 802.11w protected frames while WPA2-Enterprise does not
- WPA2-Personal uses a shared password for all users; WPA2-Enterprise uses individual credentials via a RADIUS server (Correct answer)
- WPA2-Enterprise uses AES encryption while WPA2-Personal uses TKIP
Correct answer: WPA2-Personal uses a shared password for all users; WPA2-Enterprise uses individual credentials via a RADIUS server
WPA2-Personal (PSK) uses a single shared passphrase for all users, while WPA2-Enterprise authenticates each user individually via 802.1X and a RADIUS server, providing per-user accountability.
Question 81: What is the most important competency assessed in Threat Detection & Incident Response for professionals in this field?
- Applied knowledge and practical problem-solving ability (Correct answer)
- Memorization of textbook definitions only
- Academic credentials without practical application
- Years of experience without demonstrated skill
Correct answer: Applied knowledge and practical problem-solving ability
Threat Detection & Incident Response assessment focuses on applied knowledge and practical problem-solving ability, ensuring professionals can effectively perform in real-world situations.
Question 82: Which best describes the scope of Cryptography & Data Protection in professional practice?
- A narrow topic relevant only to entry-level professionals
- An outdated concept no longer relevant to modern practice
- A theoretical framework with no practical applications
- A comprehensive area covering both theoretical foundations and practical applications (Correct answer)
Correct answer: A comprehensive area covering both theoretical foundations and practical applications
Cryptography & Data Protection encompasses both theoretical foundations and practical applications that are essential to professional practice in this field.
Question 83: Which of the following is the most effective organizational defense against social engineering at the human level?
- Purchasing expensive endpoint security software
- Establishing a strong security culture with clear reporting procedures (Correct answer)
- Prohibiting personal devices in the workplace
- Monitoring all employee internet activity
Correct answer: Establishing a strong security culture with clear reporting procedures
A security-aware culture where employees feel empowered to question and report suspicious activity is the strongest human-layer defense.
Question 84: What is 'vishing' in social engineering?
- Phishing via SMS text messages
- Voice-based phishing conducted over phone calls (Correct answer)
- Video-based spear phishing attacks
- Visual phishing using fake websites
Correct answer: Voice-based phishing conducted over phone calls
Vishing (voice phishing) uses phone calls where attackers impersonate trusted entities like banks or government agencies to obtain sensitive data.
Question 85: Which best describes the scope of Application Security & Development in professional practice?
- An outdated concept no longer relevant to modern practice
- A narrow topic relevant only to entry-level professionals
- A comprehensive area covering both theoretical foundations and practical applications (Correct answer)
- A theoretical framework with no practical applications
Correct answer: A comprehensive area covering both theoretical foundations and practical applications
Application Security & Development encompasses both theoretical foundations and practical applications that are essential to professional practice in this field.
Question 86: What is the most important competency assessed in Vulnerability Assessment & Penetration Testing for professionals in this field?
- Memorization of textbook definitions only
- Years of experience without demonstrated skill
- Academic credentials without practical application
- Applied knowledge and practical problem-solving ability (Correct answer)
Correct answer: Applied knowledge and practical problem-solving ability
Vulnerability Assessment & Penetration Testing assessment focuses on applied knowledge and practical problem-solving ability, ensuring professionals can effectively perform in real-world situations.
Question 87: What is the role of documentation in regulatory compliance?
- It serves no practical purpose beyond record-keeping
- It is optional if verbal confirmation is available
- It provides verifiable evidence that standards are being met (Correct answer)
- It is only necessary for international operations
Correct answer: It provides verifiable evidence that standards are being met
Documentation provides verifiable evidence that regulatory requirements are being met and creates an audit trail for compliance verification.
Question 88: What is the purpose of the Windows Registry in a forensic investigation?
- It stores encrypted copies of all user passwords
- It records system configuration, user activity, and installed software that can reveal attacker behavior (Correct answer)
- It contains all email messages sent and received on the system
- It stores temporary internet files and browser cache
Correct answer: It records system configuration, user activity, and installed software that can reveal attacker behavior
The Windows Registry contains keys tracking program execution, USB connections, recently accessed files, and persistence mechanisms used by malware.
Question 89: What is the primary function of a firewall in network security?
- To monitor and control incoming and outgoing network traffic based on security rules (Correct answer)
- To store network data backups
- To increase network speed
- To manage email distribution
Correct answer: To monitor and control incoming and outgoing network traffic based on security rules
A firewall monitors and controls network traffic based on predetermined security rules, acting as a barrier between trusted and untrusted networks.
Question 90: What vulnerability in WPS (Wi-Fi Protected Setup) makes it susceptible to brute-force attacks?
- WPS uses WEP encryption by default when enabled
- WPS requires the SSID to be broadcast, exposing the network to passive scanning
- The 8-digit WPS PIN is validated in two separate 4-digit halves, reducing keyspace from 10^8 to 10^4 + 10^3 (Correct answer)
- WPS disables WPA2 encryption during the setup process
Correct answer: The 8-digit WPS PIN is validated in two separate 4-digit halves, reducing keyspace from 10^8 to 10^4 + 10^3
WPS PIN verification splits the 8-digit PIN into two independently verified halves, reducing the effective keyspace to 11,000 combinations rather than 100 million, making brute-force trivial.
Question 91: What is the recommended approach to staying current in Threat Detection & Incident Response?
- Regular professional development, industry publications, and peer collaboration (Correct answer)
- Waiting for regulatory changes to force updates
- Reviewing initial training materials once per year
- Relying solely on past experience
Correct answer: Regular professional development, industry publications, and peer collaboration
Staying current in Threat Detection & Incident Response requires ongoing professional development, reading industry publications, and collaborating with peers to share knowledge and best practices.
Question 92: Which attack technique involves following an authorized person through a secured door without using credentials?
- Dumpster diving
- Shoulder surfing
- Tailgating (Correct answer)
- Baiting
Correct answer: Tailgating
Tailgating (or piggybacking) is a physical security attack where an unauthorized person follows an authorized individual into a restricted area.
Question 93: What is the recommended approach to staying current in Vulnerability Assessment & Penetration Testing?
- Waiting for regulatory changes to force updates
- Regular professional development, industry publications, and peer collaboration (Correct answer)
- Reviewing initial training materials once per year
- Relying solely on past experience
Correct answer: Regular professional development, industry publications, and peer collaboration
Staying current in Vulnerability Assessment & Penetration Testing requires ongoing professional development, reading industry publications, and collaborating with peers to share knowledge and best practices.
Question 94: Which term describes a highly targeted phishing attack aimed at a specific individual or organization?
- Spear phishing (Correct answer)
- Clone phishing
- Whaling
- Pharming
Correct answer: Spear phishing
Spear phishing targets specific individuals using personalized information to make the attack more convincing than generic phishing campaigns.
Question 95: What is the role of a 'write blocker' in digital forensics?
- To encrypt data written to forensic image files
- To prevent investigators from writing notes about evidence
- To block malicious write operations on a compromised server
- To prevent any writes to the evidence drive during imaging, preserving its original state (Correct answer)
Correct answer: To prevent any writes to the evidence drive during imaging, preserving its original state
A write blocker is a hardware or software device that allows read-only access to storage media, preventing accidental or deliberate modification of evidence.
Question 96: What is the recommended approach to staying current in Cloud Computing & Virtualization?
- Reviewing initial training materials once per year
- Waiting for regulatory changes to force updates
- Regular professional development, industry publications, and peer collaboration (Correct answer)
- Relying solely on past experience
Correct answer: Regular professional development, industry publications, and peer collaboration
Staying current in Cloud Computing & Virtualization requires ongoing professional development, reading industry publications, and collaborating with peers to share knowledge and best practices.
Question 97: What is the recommended approach to staying current in System Administration & Configuration?
- Waiting for regulatory changes to force updates
- Relying solely on past experience
- Reviewing initial training materials once per year
- Regular professional development, industry publications, and peer collaboration (Correct answer)
Correct answer: Regular professional development, industry publications, and peer collaboration
Staying current in System Administration & Configuration requires ongoing professional development, reading industry publications, and collaborating with peers to share knowledge and best practices.
Question 98: What is 'dumpster diving' in information security?
- Recovering deleted files from a hard drive
- Searching through discarded materials to find sensitive information (Correct answer)
- Flooding a system with invalid data packets
- Attacking systems through garbage data inputs
Correct answer: Searching through discarded materials to find sensitive information
Dumpster diving involves sifting through trash to recover documents, printouts, or storage devices containing confidential information.
Question 99: What does 'live forensics' refer to in digital investigations?
- Real-time analysis of network intrusion attempts
- Analysing video footage from live security cameras
- Forensics performed on systems that are currently powered on and running (Correct answer)
- Forensics performed in a live TV broadcast
Correct answer: Forensics performed on systems that are currently powered on and running
Live forensics involves collecting volatile data (RAM, running processes, network connections) from a powered-on system before shutting it down.
Question 100: What is the most important competency assessed in Access Control & Identity Management for professionals in this field?
- Academic credentials without practical application
- Memorization of textbook definitions only
- Years of experience without demonstrated skill
- Applied knowledge and practical problem-solving ability (Correct answer)
Correct answer: Applied knowledge and practical problem-solving ability
Access Control & Identity Management assessment focuses on applied knowledge and practical problem-solving ability, ensuring professionals can effectively perform in real-world situations.
Question 101: What is the recommended approach to staying current in Cryptography & Data Protection?
- Relying solely on past experience
- Waiting for regulatory changes to force updates
- Regular professional development, industry publications, and peer collaboration (Correct answer)
- Reviewing initial training materials once per year
Correct answer: Regular professional development, industry publications, and peer collaboration
Staying current in Cryptography & Data Protection requires ongoing professional development, reading industry publications, and collaborating with peers to share knowledge and best practices.
Question 102: In a wireless evil twin attack, what does the attacker deploy to capture victim credentials?
- A keylogger installed on the target device
- A brute-force tool targeting WPA2 handshakes
- A packet sniffer on the legitimate network
- A malicious access point mimicking a legitimate Wi-Fi network's SSID (Correct answer)
Correct answer: A malicious access point mimicking a legitimate Wi-Fi network's SSID
In an evil twin attack, the attacker creates a fake AP with the same SSID as a legitimate network, luring users to connect and then intercepting their traffic or credentials.
Question 103: Which principle of influence do attackers exploit when they create a sense of urgency in phishing emails?
- Social proof
- Authority
- Reciprocity
- Scarcity (Correct answer)
Correct answer: Scarcity
Scarcity and urgency pressure victims into acting quickly without thinking critically, a common manipulation tactic in social engineering.
Question 104: What is the purpose of a captive portal in wireless networking?
- To encrypt all traffic between clients and the access point
- To require users to authenticate or agree to terms before gaining full network access (Correct answer)
- To isolate wireless clients from each other on the same network segment
- To block access to known malicious websites at the network layer
Correct answer: To require users to authenticate or agree to terms before gaining full network access
A captive portal intercepts client HTTP requests and redirects them to an authentication or terms-of-service page, commonly used in public Wi-Fi hotspots before granting internet access.
Question 105: Which Windows artifact stores recently accessed files and is valuable to forensic investigators?
- Windows Event Logs
- Pagefile.sys
- Link files (LNK files) (Correct answer)
- Registry hive NTUSER.DAT
Correct answer: Link files (LNK files)
Windows LNK (shortcut) files automatically created in Recent Items contain metadata about accessed files including timestamps and original file paths.
Question 106: Which hashing algorithm is most commonly used to verify the integrity of forensic disk images?
- DES
- RSA-2048
- MD5 or SHA-1/SHA-256 (Correct answer)
- AES-256
Correct answer: MD5 or SHA-1/SHA-256
MD5 and SHA-256 hash values are calculated before and after imaging to verify that the forensic copy is identical to the original.
Question 107: What does 'quid pro quo' mean as a social engineering tactic?
- Offering a service or benefit in exchange for information or access (Correct answer)
- Sending fake invoices to financial departments
- Monitoring network traffic for sensitive data
- Impersonating a vendor during a physical visit
Correct answer: Offering a service or benefit in exchange for information or access
In quid pro quo attacks, the attacker offers something valuable (like IT help) in exchange for the victim providing credentials or access.
Question 108: What is the primary purpose of disabling SSID broadcasting on a wireless access point?
- It encrypts the SSID so only known clients can see it
- It enables MAC address filtering automatically
- It provides security through obscurity by hiding the network name from passive scans (Correct answer)
- It prevents all unauthorized devices from connecting
Correct answer: It provides security through obscurity by hiding the network name from passive scans
Disabling SSID broadcast is a security-through-obscurity measure; the network still exists and can be discovered by active scanning tools, so it provides minimal real protection.
Question 109: How does Database Management & Security contribute to overall professional effectiveness?
- It is relevant only during the certification examination
- It serves only as a credential requirement with no practical impact
- It provides essential knowledge and skills that directly impact quality of work and outcomes (Correct answer)
- It applies only to supervisory-level professionals
Correct answer: It provides essential knowledge and skills that directly impact quality of work and outcomes
Database Management & Security directly contributes to professional effectiveness by providing essential knowledge and skills that improve the quality of work and outcomes across all career levels.
Question 110: What is the security purpose of certificate pinning in mobile applications?
- To bind the app license to a specific device's hardware ID
- To encrypt all data stored in the app's local database
- To prevent the app from running on rooted or jailbroken devices
- To ensure the app only trusts specific certificates, preventing MITM attacks via rogue CAs (Correct answer)
Correct answer: To ensure the app only trusts specific certificates, preventing MITM attacks via rogue CAs
Certificate pinning embeds expected certificate fingerprints in the app so it rejects connections that present different certificates, even if signed by a trusted CA, thwarting MITM interception.
Question 111: How does Application Security & Development contribute to overall professional effectiveness?
- It serves only as a credential requirement with no practical impact
- It applies only to supervisory-level professionals
- It is relevant only during the certification examination
- It provides essential knowledge and skills that directly impact quality of work and outcomes (Correct answer)
Correct answer: It provides essential knowledge and skills that directly impact quality of work and outcomes
Application Security & Development directly contributes to professional effectiveness by providing essential knowledge and skills that improve the quality of work and outcomes across all career levels.
Question 112: What is the purpose of a risk register?
- To document, track, and manage all identified risks throughout a project or operation (Correct answer)
- To eliminate all risks before starting work
- To assign blame when problems occur
- To satisfy audit requirements only
Correct answer: To document, track, and manage all identified risks throughout a project or operation
A risk register is a living document that records all identified risks, their assessments, response plans, and status updates throughout the lifecycle of a project or operation.
Question 113: Which IEEE standard defines port-based Network Access Control (NAC) used in enterprise wireless authentication?
- IEEE 802.11n
- IEEE 802.3af
- IEEE 802.15.1
- IEEE 802.1X (Correct answer)
Correct answer: IEEE 802.1X
IEEE 802.1X provides port-based NAC, requiring devices to authenticate (often via RADIUS) before gaining network access, commonly used in WPA2-Enterprise.
Question 114: What is a wireless deauthentication attack and why is it possible?
- A brute-force attack on WPA2 pre-shared keys captured during handshakes
- Jamming the 2.4 GHz band with radio frequency interference to disconnect clients
- Sending spoofed 802.11 deauthentication frames because management frames lacked authentication before 802.11w (Correct answer)
- Flooding an AP with fake association requests to exhaust its connection table
Correct answer: Sending spoofed 802.11 deauthentication frames because management frames lacked authentication before 802.11w
Before 802.11w (Protected Management Frames), deauthentication frames were unauthenticated, allowing attackers to spoof them and forcibly disconnect clients from any AP.
Question 115: What is the relationship between Threat Detection & Incident Response and ethical professional conduct?
- There is no connection between technical knowledge and ethics
- Ethics is relevant only when legal issues arise
- Ethical considerations are integrated into all aspects of professional practice in this area (Correct answer)
- Ethics applies only to separate, unrelated decisions
Correct answer: Ethical considerations are integrated into all aspects of professional practice in this area
Ethical considerations are deeply integrated into Threat Detection & Incident Response, as professional conduct and integrity underpin all aspects of practice in this field.
Question 116: What common challenge do professionals face when applying Database Management & Security principles?
- The principles are too simple to present any challenge
- Balancing theoretical best practices with practical constraints and real-world conditions (Correct answer)
- Finding the relevant textbook chapter
- Obtaining permission to use the principles
Correct answer: Balancing theoretical best practices with practical constraints and real-world conditions
Professionals commonly face the challenge of adapting theoretical best practices in Database Management & Security to the practical constraints and varying conditions encountered in real-world settings.
Question 117: What does a VPN provide in terms of network security?
- Encrypted communication tunnels over public networks (Correct answer)
- Automatic virus removal
- Faster internet connection speeds
- Free internet access worldwide
Correct answer: Encrypted communication tunnels over public networks
A VPN (Virtual Private Network) creates encrypted communication tunnels over public networks, protecting data confidentiality during transmission.
Question 118: What is a SIM swapping attack?
- Installing spyware via a malicious SIM card update
- Cloning a SIM card using RF eavesdropping equipment
- Socially engineering a carrier into transferring a victim's phone number to an attacker-controlled SIM (Correct answer)
- Intercepting SMS messages via a rogue cell tower
Correct answer: Socially engineering a carrier into transferring a victim's phone number to an attacker-controlled SIM
SIM swapping involves deceiving a mobile carrier's support staff into reassigning a victim's phone number to the attacker's SIM, enabling bypass of SMS-based MFA.
ALISON Diploma in Information Technology Support and Security
ALISON's free online Diploma covering IT support and security topics including cloud computing, network security, operating systems, database management, digital forensics, and security compliance through modular assessments on the Alison.com platform.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds