An employee loses their personal smartphone, which they also use for work-related tasks. They immediately report the loss to the IT department, which then remotely wipes the device. This action is most likely in accordance with which organizational policy?

  • BYOD Policy
  • Data Retention Policy
  • Mobile Device Management (MDM) Policy
  • Privacy Policy
This action is most likely in accordance with the Mobile Device Management (MDM) Policy. MDM policies often include provisions for remote device wiping to protect sensitive company data when a device is lost or stolen. It allows IT departments to remotely erase company data and applications from the device to prevent data breaches.

Which advanced cryptographic protocol allows two parties to securely compute a function over their inputs while keeping those inputs private?

  • DES
  • Diffie-Hellman
  • Homomorphic Encryption
  • RSA
Homomorphic Encryption is an advanced cryptographic technique that allows two parties to perform computations on their encrypted data without revealing the data to each other. This is particularly useful in secure multi-party computation and privacy-preserving data analysis.

In an out-of-band SQL injection attack, data is retrieved using:

  • A separate channel
  • API endpoints
  • HTTP GET requests
  • The same channel with UNION statements
In an out-of-band SQL injection, attackers retrieve data via a separate channel, such as a DNS request, rather than through the same channel as the main application.

Which of the following best describes the primary purpose of a certificate authority (CA) in the SSL/TLS handshake process?

  • Authenticating users
  • Handling encryption keys
  • Issuing digital certificates
  • Providing web hosting
A Certificate Authority (CA) in the SSL/TLS handshake process primarily issues digital certificates. These certificates are used to verify the authenticity of a website, ensuring that the connection is secure and that data is encrypted.

Under GDPR, individuals have the right to access their personal data and the right to _______ it.

  • Alter the Data
  • Correct the Data
  • Delete the Data
  • Share the Data
Under the General Data Protection Regulation (GDPR), individuals have the right to access their personal data held by organizations. This means they can request to correct or update the data if it's inaccurate. This helps individuals maintain the accuracy of their personal information.

Which of the following attacks involves the injection of malicious scripts into web pages viewed by other users?

  • Cross-Site Scripting (XSS)
  • Distributed Denial of Service (DDoS)
  • Phishing
  • SQL Injection
Cross-Site Scripting (XSS) is an attack where an attacker injects malicious scripts into web pages, which are then viewed by other users, potentially leading to data theft or manipulation.

The process of hiding a wireless network by not broadcasting its SSID is known as _______.

  • MAC Filtering
  • Network Masking
  • SSID Concealing
  • SSID Encryption
SSID Concealing, also known as SSID hiding, is a security measure where the network name (SSID) is not broadcast, making it less visible to potential attackers.

Regular _______ sessions are essential to ensure that employees are up-to-date with the latest security policies and practices.

  • Evaluation
  • Maintenance
  • Reporting
  • Training
Regular training sessions are essential to ensure that employees are up-to-date with the latest security policies and practices. Security training helps employees recognize and respond to security threats effectively.

Insider threats can be particularly challenging to detect because they often exploit legitimate _______ rather than external vulnerabilities.

  • Permissions
  • Software Bugs
  • System Flaws
  • Weak Passwords
Insider threats often exploit legitimate "Permissions" granted to them as part of their job. This can make it challenging to distinguish malicious behavior from regular activities, increasing the risk of data breaches.

In penetration testing, what is the significance of a "red team" versus a "blue team"?

  • Red team consists of internal employees, blue team is external
  • Red team defends, blue team simulates attackers
  • Red team simulates attackers, blue team defends
  • Red team tests for software vulnerabilities
In penetration testing, the "red team" simulates attackers, often from an external perspective, while the "blue team" defends, typically from an internal perspective, helping to identify security weaknesses and prepare for real-world threats.