ALISON Diploma in Information Technology Support and Security — Questions and Answers
Question 1: What is a wireless deauthentication attack and why is it possible?
- A brute-force attack on WPA2 pre-shared keys captured during handshakes
- Jamming the 2.4 GHz band with radio frequency interference to disconnect clients
- Flooding an AP with fake association requests to exhaust its connection table
- Sending spoofed 802.11 deauthentication frames because management frames lacked authentication before 802.11w (Correct answer)
Correct answer: Sending spoofed 802.11 deauthentication frames because management frames lacked authentication before 802.11w
Before 802.11w (Protected Management Frames), deauthentication frames were unauthenticated, allowing attackers to spoof them and forcibly disconnect clients from any AP.
Question 2: What is the recommended approach to staying current in Vulnerability Assessment & Penetration Testing?
- Regular professional development, industry publications, and peer collaboration (Correct answer)
- Waiting for regulatory changes to force updates
- Relying solely on past experience
- Reviewing initial training materials once per year
Correct answer: Regular professional development, industry publications, and peer collaboration
Staying current in Vulnerability Assessment & Penetration Testing requires ongoing professional development, reading industry publications, and collaborating with peers to share knowledge and best practices.
Question 3: What is 'anti-forensics' and what challenge does it present to investigators?
- Encryption tools used to protect forensic images
- Legal restrictions preventing forensic analysis without a warrant
- Techniques used by attackers to destroy, hide, or alter digital evidence to impede investigations (Correct answer)
- Software that speeds up forensic analysis
Correct answer: Techniques used by attackers to destroy, hide, or alter digital evidence to impede investigations
Anti-forensics includes wiping tools, timestamp manipulation, and encryption to make evidence collection harder or impossible for investigators.
Question 4: What type of file system artifact allows forensic investigators to recover deleted files on NTFS volumes?
- Recycle Bin metadata
- Master File Table ($MFT) (Correct answer)
- Volume Shadow Copies
- Master Boot Record
Correct answer: Master File Table ($MFT)
The NTFS Master File Table ($MFT) retains metadata about deleted files even after deletion, enabling partial or full file recovery.
Question 5: Which IEEE standard defines port-based Network Access Control (NAC) used in enterprise wireless authentication?
- IEEE 802.1X (Correct answer)
- IEEE 802.15.1
- IEEE 802.11n
- IEEE 802.3af
Correct answer: IEEE 802.1X
IEEE 802.1X provides port-based NAC, requiring devices to authenticate (often via RADIUS) before gaining network access, commonly used in WPA2-Enterprise.
Question 6: What distinguishes inherent risk from residual risk?
- Inherent risk exists before controls; residual risk remains after controls are applied (Correct answer)
- Inherent risk is financial; residual risk is operational
- There is no meaningful difference between them
- Inherent risk is internal; residual risk is external
Correct answer: Inherent risk exists before controls; residual risk remains after controls are applied
Inherent risk is the level of risk present before any controls are implemented, while residual risk is the level that remains after controls and mitigations are applied.
Question 7: What is a DMZ (Demilitarized Zone) in network architecture?
- A network segment between internal and external networks that hosts public-facing services (Correct answer)
- A meeting room for discussing network security
- A restricted area where damaged equipment is stored
- A backup data center in a remote location
Correct answer: A network segment between internal and external networks that hosts public-facing services
A DMZ is a network segment that sits between the internal network and external networks, hosting public-facing services while protecting the internal network from direct exposure.
Question 8: Which log file in Linux systems is most useful for tracking user authentication events during a forensic investigation?
- /var/log/syslog
- /var/log/auth.log (Correct answer)
- /var/log/dmesg
- /var/log/kern.log
Correct answer: /var/log/auth.log
The /var/log/auth.log file on Debian/Ubuntu systems records all authentication attempts, sudo usage, SSH logins, and account changes.
Question 9: What common challenge do professionals face when applying Cloud Computing & Virtualization principles?
- Finding the relevant textbook chapter
- Balancing theoretical best practices with practical constraints and real-world conditions (Correct answer)
- Obtaining permission to use the principles
- The principles are too simple to present any challenge
Correct answer: Balancing theoretical best practices with practical constraints and real-world conditions
Professionals commonly face the challenge of adapting theoretical best practices in Cloud Computing & Virtualization to the practical constraints and varying conditions encountered in real-world settings.
Question 10: What is the most important competency assessed in Operating Systems & Platforms for professionals in this field?
- Applied knowledge and practical problem-solving ability (Correct answer)
- Years of experience without demonstrated skill
- Memorization of textbook definitions only
- Academic credentials without practical application
Correct answer: Applied knowledge and practical problem-solving ability
Operating Systems & Platforms assessment focuses on applied knowledge and practical problem-solving ability, ensuring professionals can effectively perform in real-world situations.
Question 11: Which risk response strategy involves reducing the likelihood or impact of a risk?
- Risk mitigation (Correct answer)
- Risk transfer
- Risk acceptance
- Risk escalation
Correct answer: Risk mitigation
Risk mitigation involves taking proactive steps to reduce either the probability of a risk occurring or its potential impact if it does occur.
Question 12: What is the role of documentation in regulatory compliance?
- It provides verifiable evidence that standards are being met (Correct answer)
- It is optional if verbal confirmation is available
- It serves no practical purpose beyond record-keeping
- It is only necessary for international operations
Correct answer: It provides verifiable evidence that standards are being met
Documentation provides verifiable evidence that regulatory requirements are being met and creates an audit trail for compliance verification.
Question 13: What is an IMSI catcher (often called a 'Stingray') used for in security contexts?
- A tool for analyzing Wi-Fi packet captures in real time
- A forensic tool for extracting data from locked smartphones
- A device that impersonates a cellular base station to intercept mobile communications and track device locations (Correct answer)
- Software that detects rogue access points on corporate networks
Correct answer: A device that impersonates a cellular base station to intercept mobile communications and track device locations
An IMSI catcher mimics a legitimate cell tower, forcing nearby phones to connect to it, enabling interception of calls, SMS, and location data by capturing the device's IMSI.
Question 14: Which best describes the scope of Cryptography & Data Protection in professional practice?
- A comprehensive area covering both theoretical foundations and practical applications (Correct answer)
- An outdated concept no longer relevant to modern practice
- A theoretical framework with no practical applications
- A narrow topic relevant only to entry-level professionals
Correct answer: A comprehensive area covering both theoretical foundations and practical applications
Cryptography & Data Protection encompasses both theoretical foundations and practical applications that are essential to professional practice in this field.
Question 15: What is a 'forensic image' in digital forensics?
- A photograph of the crime scene equipment
- An encrypted backup of the suspect's files
- A screenshot taken during an investigation
- A bit-for-bit copy of a storage device including unallocated space (Correct answer)
Correct answer: A bit-for-bit copy of a storage device including unallocated space
A forensic image is an exact sector-by-sector copy of a storage medium that captures all data including deleted files and unallocated space.
Question 16: What vulnerability in WPS (Wi-Fi Protected Setup) makes it susceptible to brute-force attacks?
- WPS uses WEP encryption by default when enabled
- WPS disables WPA2 encryption during the setup process
- WPS requires the SSID to be broadcast, exposing the network to passive scanning
- The 8-digit WPS PIN is validated in two separate 4-digit halves, reducing keyspace from 10^8 to 10^4 + 10^3 (Correct answer)
Correct answer: The 8-digit WPS PIN is validated in two separate 4-digit halves, reducing keyspace from 10^8 to 10^4 + 10^3
WPS PIN verification splits the 8-digit PIN into two independently verified halves, reducing the effective keyspace to 11,000 combinations rather than 100 million, making brute-force trivial.
Question 17: Which social engineering attack involves sending fraudulent emails that appear to come from a trusted source to steal credentials?
- Vishing
- Tailgating
- Phishing (Correct answer)
- Smishing
Correct answer: Phishing
Phishing uses deceptive emails that mimic legitimate organizations to trick recipients into revealing sensitive information.
Question 18: How does System Administration & Configuration contribute to overall professional effectiveness?
- It provides essential knowledge and skills that directly impact quality of work and outcomes (Correct answer)
- It is relevant only during the certification examination
- It applies only to supervisory-level professionals
- It serves only as a credential requirement with no practical impact
Correct answer: It provides essential knowledge and skills that directly impact quality of work and outcomes
System Administration & Configuration directly contributes to professional effectiveness by providing essential knowledge and skills that improve the quality of work and outcomes across all career levels.
Question 19: How does Threat Detection & Incident Response contribute to overall professional effectiveness?
- It applies only to supervisory-level professionals
- It serves only as a credential requirement with no practical impact
- It is relevant only during the certification examination
- It provides essential knowledge and skills that directly impact quality of work and outcomes (Correct answer)
Correct answer: It provides essential knowledge and skills that directly impact quality of work and outcomes
Threat Detection & Incident Response directly contributes to professional effectiveness by providing essential knowledge and skills that improve the quality of work and outcomes across all career levels.
Question 20: What is the relationship between Application Security & Development and ethical professional conduct?
- Ethics is relevant only when legal issues arise
- Ethics applies only to separate, unrelated decisions
- Ethical considerations are integrated into all aspects of professional practice in this area (Correct answer)
- There is no connection between technical knowledge and ethics
Correct answer: Ethical considerations are integrated into all aspects of professional practice in this area
Ethical considerations are deeply integrated into Application Security & Development, as professional conduct and integrity underpin all aspects of practice in this field.
Question 21: Which best describes the scope of System Administration & Configuration in professional practice?
- A theoretical framework with no practical applications
- A narrow topic relevant only to entry-level professionals
- An outdated concept no longer relevant to modern practice
- A comprehensive area covering both theoretical foundations and practical applications (Correct answer)
Correct answer: A comprehensive area covering both theoretical foundations and practical applications
System Administration & Configuration encompasses both theoretical foundations and practical applications that are essential to professional practice in this field.
Question 22: What is 'steganography' and why is it relevant to digital forensics?
- Hiding data within ordinary-looking files like images to conceal communications or exfiltrate data (Correct answer)
- A technique for encrypting network traffic to avoid detection
- A type of malware that hides in system firmware
- A method for bypassing file system access controls
Correct answer: Hiding data within ordinary-looking files like images to conceal communications or exfiltrate data
Steganography conceals data inside carrier files, and forensic investigators must detect and extract hidden content during investigations.
Question 23: What does MDM stand for in the context of enterprise mobile security?
- Managed Device Module
- Multi-Domain Monitoring
- Mobile Device Management (Correct answer)
- Mobile Data Management
Correct answer: Mobile Device Management
MDM (Mobile Device Management) is a solution that allows organizations to remotely manage, monitor, and enforce security policies on employee mobile devices.
Question 24: What is the purpose of a risk register?
- To document, track, and manage all identified risks throughout a project or operation (Correct answer)
- To eliminate all risks before starting work
- To assign blame when problems occur
- To satisfy audit requirements only
Correct answer: To document, track, and manage all identified risks throughout a project or operation
A risk register is a living document that records all identified risks, their assessments, response plans, and status updates throughout the lifecycle of a project or operation.
Question 25: Which of the following is the most effective organizational defense against social engineering at the human level?
- Prohibiting personal devices in the workplace
- Establishing a strong security culture with clear reporting procedures (Correct answer)
- Monitoring all employee internet activity
- Purchasing expensive endpoint security software
Correct answer: Establishing a strong security culture with clear reporting procedures
A security-aware culture where employees feel empowered to question and report suspicious activity is the strongest human-layer defense.
Question 26: What is 'baiting' as a social engineering technique?
- Leaving infected USB drives or media in public places for victims to find (Correct answer)
- Monitoring a target's physical surroundings
- Sending threatening emails to cause panic
- Calling victims and pretending to be tech support
Correct answer: Leaving infected USB drives or media in public places for victims to find
Baiting lures victims by leaving malware-laden physical media (like USB drives) where curious individuals will pick them up and insert them into computers.
Question 27: What does a VPN provide in terms of network security?
- Free internet access worldwide
- Faster internet connection speeds
- Encrypted communication tunnels over public networks (Correct answer)
- Automatic virus removal
Correct answer: Encrypted communication tunnels over public networks
A VPN (Virtual Private Network) creates encrypted communication tunnels over public networks, protecting data confidentiality during transmission.
Question 28: Which best describes the scope of Operating Systems & Platforms in professional practice?
- A theoretical framework with no practical applications
- An outdated concept no longer relevant to modern practice
- A narrow topic relevant only to entry-level professionals
- A comprehensive area covering both theoretical foundations and practical applications (Correct answer)
Correct answer: A comprehensive area covering both theoretical foundations and practical applications
Operating Systems & Platforms encompasses both theoretical foundations and practical applications that are essential to professional practice in this field.
Question 29: What encryption algorithm does WPA2 use to secure wireless communications?
- AES with CCMP (Correct answer)
- DES
- 3DES
- RC4
Correct answer: AES with CCMP
WPA2 uses AES (Advanced Encryption Standard) with CCMP (Counter Mode CBC-MAC Protocol), providing much stronger security than WEP's RC4.
Question 30: Which best describes the scope of Vulnerability Assessment & Penetration Testing in professional practice?
- A comprehensive area covering both theoretical foundations and practical applications (Correct answer)
- An outdated concept no longer relevant to modern practice
- A narrow topic relevant only to entry-level professionals
- A theoretical framework with no practical applications
Correct answer: A comprehensive area covering both theoretical foundations and practical applications
Vulnerability Assessment & Penetration Testing encompasses both theoretical foundations and practical applications that are essential to professional practice in this field.
Question 31: What should be the first action when a new regulation is enacted that affects your practice?
- Delegate review to the newest team member
- Assume existing procedures already comply
- Wait for enforcement before making changes
- Review the regulation, assess its impact, and develop an implementation plan (Correct answer)
Correct answer: Review the regulation, assess its impact, and develop an implementation plan
When new regulations are enacted, professionals should promptly review them, assess their impact on current practices, and develop a structured implementation plan.
Question 32: What is the first step in the risk management process?
- Risk identification — recognizing potential threats and vulnerabilities (Correct answer)
- Risk acceptance — deciding to live with all risks
- Risk avoidance — canceling all activities
- Risk transfer — purchasing insurance immediately
Correct answer: Risk identification — recognizing potential threats and vulnerabilities
Risk identification is the critical first step in risk management, involving systematic recognition and documentation of potential threats and vulnerabilities.
Question 33: What is the most important competency assessed in Access Control & Identity Management for professionals in this field?
- Memorization of textbook definitions only
- Applied knowledge and practical problem-solving ability (Correct answer)
- Years of experience without demonstrated skill
- Academic credentials without practical application
Correct answer: Applied knowledge and practical problem-solving ability
Access Control & Identity Management assessment focuses on applied knowledge and practical problem-solving ability, ensuring professionals can effectively perform in real-world situations.
Question 34: What is 'shoulder surfing' as a social engineering technique?
- Sending fraudulent emails to coworkers
- Intercepting wireless signals in public areas
- Hijacking a user's active browser session
- Observing someone entering passwords or PINs by looking over their shoulder (Correct answer)
Correct answer: Observing someone entering passwords or PINs by looking over their shoulder
Shoulder surfing involves physically observing a target as they input sensitive data such as passwords, PINs, or credit card numbers.
Question 35: What is 'smishing' in mobile security?
- Exploiting vulnerabilities in smartphone browsers
- Sending malware via Bluetooth to nearby devices
- Installing spyware through malicious QR codes
- Phishing attacks delivered via SMS text messages (Correct answer)
Correct answer: Phishing attacks delivered via SMS text messages
Smishing (SMS phishing) involves sending deceptive text messages that trick recipients into clicking malicious links or providing sensitive information.
Question 36: What common challenge do professionals face when applying Operating Systems & Platforms principles?
- Balancing theoretical best practices with practical constraints and real-world conditions (Correct answer)
- The principles are too simple to present any challenge
- Obtaining permission to use the principles
- Finding the relevant textbook chapter
Correct answer: Balancing theoretical best practices with practical constraints and real-world conditions
Professionals commonly face the challenge of adapting theoretical best practices in Operating Systems & Platforms to the practical constraints and varying conditions encountered in real-world settings.
Question 37: What is the recommended approach to staying current in Cryptography & Data Protection?
- Relying solely on past experience
- Regular professional development, industry publications, and peer collaboration (Correct answer)
- Reviewing initial training materials once per year
- Waiting for regulatory changes to force updates
Correct answer: Regular professional development, industry publications, and peer collaboration
Staying current in Cryptography & Data Protection requires ongoing professional development, reading industry publications, and collaborating with peers to share knowledge and best practices.
Question 38: What is the principle of least privilege in network security?
- New users should receive the same access as their managers
- All users should have administrator access for convenience
- Access permissions should be updated annually
- Users should have only the minimum access needed to perform their job functions (Correct answer)
Correct answer: Users should have only the minimum access needed to perform their job functions
The principle of least privilege restricts user access to only the resources and permissions necessary for their specific job functions, minimizing potential damage from compromised accounts.
Question 39: Which best describes the scope of Threat Detection & Incident Response in professional practice?
- A comprehensive area covering both theoretical foundations and practical applications (Correct answer)
- A theoretical framework with no practical applications
- An outdated concept no longer relevant to modern practice
- A narrow topic relevant only to entry-level professionals
Correct answer: A comprehensive area covering both theoretical foundations and practical applications
Threat Detection & Incident Response encompasses both theoretical foundations and practical applications that are essential to professional practice in this field.
Question 40: What does a risk matrix assess?
- The number of employees affected
- Only the financial cost of risks
- The probability and impact of identified risks (Correct answer)
- The timeline for risk resolution
Correct answer: The probability and impact of identified risks
A risk matrix evaluates risks based on two dimensions: the probability (likelihood) of occurrence and the potential impact (severity) if the risk materializes.
Question 41: How does Application Security & Development contribute to overall professional effectiveness?
- It is relevant only during the certification examination
- It serves only as a credential requirement with no practical impact
- It provides essential knowledge and skills that directly impact quality of work and outcomes (Correct answer)
- It applies only to supervisory-level professionals
Correct answer: It provides essential knowledge and skills that directly impact quality of work and outcomes
Application Security & Development directly contributes to professional effectiveness by providing essential knowledge and skills that improve the quality of work and outcomes across all career levels.
Question 42: What is the recommended approach to staying current in Threat Detection & Incident Response?
- Relying solely on past experience
- Regular professional development, industry publications, and peer collaboration (Correct answer)
- Reviewing initial training materials once per year
- Waiting for regulatory changes to force updates
Correct answer: Regular professional development, industry publications, and peer collaboration
Staying current in Threat Detection & Incident Response requires ongoing professional development, reading industry publications, and collaborating with peers to share knowledge and best practices.
Question 43: What is a rogue access point in network security?
- A public Wi-Fi hotspot with no password
- A misconfigured router with outdated firmware
- An access point that uses an outdated encryption protocol
- An unauthorized wireless access point installed on a network without admin approval (Correct answer)
Correct answer: An unauthorized wireless access point installed on a network without admin approval
A rogue access point is an unauthorized AP connected to a network, which attackers or insiders can use to bypass perimeter security and intercept traffic.
Question 44: Which best describes the scope of Cloud Computing & Virtualization in professional practice?
- A comprehensive area covering both theoretical foundations and practical applications (Correct answer)
- An outdated concept no longer relevant to modern practice
- A theoretical framework with no practical applications
- A narrow topic relevant only to entry-level professionals
Correct answer: A comprehensive area covering both theoretical foundations and practical applications
Cloud Computing & Virtualization encompasses both theoretical foundations and practical applications that are essential to professional practice in this field.
Question 45: What is the recommended approach to staying current in Access Control & Identity Management?
- Waiting for regulatory changes to force updates
- Relying solely on past experience
- Reviewing initial training materials once per year
- Regular professional development, industry publications, and peer collaboration (Correct answer)
Correct answer: Regular professional development, industry publications, and peer collaboration
Staying current in Access Control & Identity Management requires ongoing professional development, reading industry publications, and collaborating with peers to share knowledge and best practices.
Question 46: What is the recommended approach to staying current in System Administration & Configuration?
- Relying solely on past experience
- Reviewing initial training materials once per year
- Regular professional development, industry publications, and peer collaboration (Correct answer)
- Waiting for regulatory changes to force updates
Correct answer: Regular professional development, industry publications, and peer collaboration
Staying current in System Administration & Configuration requires ongoing professional development, reading industry publications, and collaborating with peers to share knowledge and best practices.
Question 47: What does SSID stand for in the context of wireless networking?
- Service Set Identifier (Correct answer)
- Subnet Specific Interface Descriptor
- System Security ID Data
- Secure Session Identification Directive
Correct answer: Service Set Identifier
SSID stands for Service Set Identifier, which is the name that identifies a specific wireless network and is broadcast in beacon frames.
Question 48: What is the most important competency assessed in Application Security & Development for professionals in this field?
- Academic credentials without practical application
- Applied knowledge and practical problem-solving ability (Correct answer)
- Memorization of textbook definitions only
- Years of experience without demonstrated skill
Correct answer: Applied knowledge and practical problem-solving ability
Application Security & Development assessment focuses on applied knowledge and practical problem-solving ability, ensuring professionals can effectively perform in real-world situations.
Question 49: Which Windows artifact stores recently accessed files and is valuable to forensic investigators?
- Registry hive NTUSER.DAT
- Windows Event Logs
- Link files (LNK files) (Correct answer)
- Pagefile.sys
Correct answer: Link files (LNK files)
Windows LNK (shortcut) files automatically created in Recent Items contain metadata about accessed files including timestamps and original file paths.
Question 50: What primary security risk does a BYOD (Bring Your Own Device) policy introduce in an enterprise environment?
- Reduced network bandwidth due to personal device usage
- Mandatory compliance with consumer privacy laws for the employer
- Increased hardware procurement costs for the IT department
- Loss of organizational control over device security posture and data handling (Correct answer)
Correct answer: Loss of organizational control over device security posture and data handling
BYOD reduces IT control over patching, encryption, and app installation on personal devices, creating risk that corporate data may be stored or transmitted insecurely.
Question 51: What is the primary purpose of maintaining a 'chain of custody' in digital forensics?
- To encrypt all collected evidence files
- To ensure digital evidence remains admissible and unaltered throughout an investigation (Correct answer)
- To share evidence with law enforcement agencies quickly
- To speed up the evidence collection process
Correct answer: To ensure digital evidence remains admissible and unaltered throughout an investigation
Chain of custody documents every person who handled evidence and every action taken, ensuring its integrity and legal admissibility in court.
Question 52: How often should compliance procedures be reviewed and updated?
- Every ten years regardless of changes
- Regularly, and whenever regulations change or new risks are identified (Correct answer)
- Only when an audit is scheduled
- Once at initial certification and never again
Correct answer: Regularly, and whenever regulations change or new risks are identified
Compliance procedures should be reviewed regularly and updated whenever regulations change, new risks emerge, or organizational changes occur.
Question 53: What is the relationship between Cloud Computing & Virtualization and ethical professional conduct?
- Ethical considerations are integrated into all aspects of professional practice in this area (Correct answer)
- There is no connection between technical knowledge and ethics
- Ethics applies only to separate, unrelated decisions
- Ethics is relevant only when legal issues arise
Correct answer: Ethical considerations are integrated into all aspects of professional practice in this area
Ethical considerations are deeply integrated into Cloud Computing & Virtualization, as professional conduct and integrity underpin all aspects of practice in this field.
Question 54: Which hashing algorithm is most commonly used to verify the integrity of forensic disk images?
- MD5 or SHA-1/SHA-256 (Correct answer)
- RSA-2048
- DES
- AES-256
Correct answer: MD5 or SHA-1/SHA-256
MD5 and SHA-256 hash values are calculated before and after imaging to verify that the forensic copy is identical to the original.
Question 55: What common challenge do professionals face when applying Database Management & Security principles?
- Obtaining permission to use the principles
- The principles are too simple to present any challenge
- Balancing theoretical best practices with practical constraints and real-world conditions (Correct answer)
- Finding the relevant textbook chapter
Correct answer: Balancing theoretical best practices with practical constraints and real-world conditions
Professionals commonly face the challenge of adapting theoretical best practices in Database Management & Security to the practical constraints and varying conditions encountered in real-world settings.
Question 56: What is the correct order of volatility in digital evidence collection?
- Disk → RAM → Network → CPU registers
- Network → Disk → RAM → CPU registers
- RAM → Disk → CPU registers → Network
- CPU registers → RAM → Network → Disk (Correct answer)
Correct answer: CPU registers → RAM → Network → Disk
Evidence should be collected from most volatile (CPU registers, cache) to least volatile (disk) to preserve the most transient data first.
Question 57: What term describes a social engineering attack where an attacker calls pretending to be tech support and tricks the victim into installing remote access software?
- Business email compromise
- Reverse social engineering
- Vishing with remote access trojan delivery
- Tech support scam (Correct answer)
Correct answer: Tech support scam
Tech support scams involve fraudsters posing as legitimate support agents to convince victims to grant remote access or pay for fake services.
Question 58: What is a SIM swapping attack?
- Socially engineering a carrier into transferring a victim's phone number to an attacker-controlled SIM (Correct answer)
- Cloning a SIM card using RF eavesdropping equipment
- Installing spyware via a malicious SIM card update
- Intercepting SMS messages via a rogue cell tower
Correct answer: Socially engineering a carrier into transferring a victim's phone number to an attacker-controlled SIM
SIM swapping involves deceiving a mobile carrier's support staff into reassigning a victim's phone number to the attacker's SIM, enabling bypass of SMS-based MFA.
Question 59: What is the most important competency assessed in Cryptography & Data Protection for professionals in this field?
- Applied knowledge and practical problem-solving ability (Correct answer)
- Academic credentials without practical application
- Years of experience without demonstrated skill
- Memorization of textbook definitions only
Correct answer: Applied knowledge and practical problem-solving ability
Cryptography & Data Protection assessment focuses on applied knowledge and practical problem-solving ability, ensuring professionals can effectively perform in real-world situations.
Question 60: What is the recommended approach to staying current in Operating Systems & Platforms?
- Relying solely on past experience
- Regular professional development, industry publications, and peer collaboration (Correct answer)
- Reviewing initial training materials once per year
- Waiting for regulatory changes to force updates
Correct answer: Regular professional development, industry publications, and peer collaboration
Staying current in Operating Systems & Platforms requires ongoing professional development, reading industry publications, and collaborating with peers to share knowledge and best practices.
Question 61: How does Vulnerability Assessment & Penetration Testing contribute to overall professional effectiveness?
- It provides essential knowledge and skills that directly impact quality of work and outcomes (Correct answer)
- It is relevant only during the certification examination
- It serves only as a credential requirement with no practical impact
- It applies only to supervisory-level professionals
Correct answer: It provides essential knowledge and skills that directly impact quality of work and outcomes
Vulnerability Assessment & Penetration Testing directly contributes to professional effectiveness by providing essential knowledge and skills that improve the quality of work and outcomes across all career levels.
Question 62: What is the relationship between Cryptography & Data Protection and ethical professional conduct?
- There is no connection between technical knowledge and ethics
- Ethics is relevant only when legal issues arise
- Ethics applies only to separate, unrelated decisions
- Ethical considerations are integrated into all aspects of professional practice in this area (Correct answer)
Correct answer: Ethical considerations are integrated into all aspects of professional practice in this area
Ethical considerations are deeply integrated into Cryptography & Data Protection, as professional conduct and integrity underpin all aspects of practice in this field.
Question 63: Which attack technique involves following an authorized person through a secured door without using credentials?
- Tailgating (Correct answer)
- Dumpster diving
- Shoulder surfing
- Baiting
Correct answer: Tailgating
Tailgating (or piggybacking) is a physical security attack where an unauthorized person follows an authorized individual into a restricted area.
Question 64: What is the recommended approach to staying current in Cloud Computing & Virtualization?
- Relying solely on past experience
- Regular professional development, industry publications, and peer collaboration (Correct answer)
- Reviewing initial training materials once per year
- Waiting for regulatory changes to force updates
Correct answer: Regular professional development, industry publications, and peer collaboration
Staying current in Cloud Computing & Virtualization requires ongoing professional development, reading industry publications, and collaborating with peers to share knowledge and best practices.
Question 65: What is 'dumpster diving' in information security?
- Attacking systems through garbage data inputs
- Recovering deleted files from a hard drive
- Flooding a system with invalid data packets
- Searching through discarded materials to find sensitive information (Correct answer)
Correct answer: Searching through discarded materials to find sensitive information
Dumpster diving involves sifting through trash to recover documents, printouts, or storage devices containing confidential information.
Question 66: What common challenge do professionals face when applying Vulnerability Assessment & Penetration Testing principles?
- Finding the relevant textbook chapter
- Balancing theoretical best practices with practical constraints and real-world conditions (Correct answer)
- Obtaining permission to use the principles
- The principles are too simple to present any challenge
Correct answer: Balancing theoretical best practices with practical constraints and real-world conditions
Professionals commonly face the challenge of adapting theoretical best practices in Vulnerability Assessment & Penetration Testing to the practical constraints and varying conditions encountered in real-world settings.
Question 67: What is the most important competency assessed in Database Management & Security for professionals in this field?
- Academic credentials without practical application
- Years of experience without demonstrated skill
- Memorization of textbook definitions only
- Applied knowledge and practical problem-solving ability (Correct answer)
Correct answer: Applied knowledge and practical problem-solving ability
Database Management & Security assessment focuses on applied knowledge and practical problem-solving ability, ensuring professionals can effectively perform in real-world situations.
Question 68: What is the purpose of intrusion detection systems (IDS)?
- To monitor network traffic for suspicious activity and known threats (Correct answer)
- To prevent all unauthorized access automatically
- To speed up network performance
- To manage network IP addresses
Correct answer: To monitor network traffic for suspicious activity and known threats
IDS monitors network traffic for suspicious activity, known attack patterns, and policy violations, alerting administrators to potential security threats.
Question 69: What is the relationship between Threat Detection & Incident Response and ethical professional conduct?
- Ethical considerations are integrated into all aspects of professional practice in this area (Correct answer)
- There is no connection between technical knowledge and ethics
- Ethics applies only to separate, unrelated decisions
- Ethics is relevant only when legal issues arise
Correct answer: Ethical considerations are integrated into all aspects of professional practice in this area
Ethical considerations are deeply integrated into Threat Detection & Incident Response, as professional conduct and integrity underpin all aspects of practice in this field.
Question 70: What is the primary purpose of industry regulations in this field?
- To protect the public and ensure consistent professional standards (Correct answer)
- To generate revenue for regulatory bodies
- To create barriers to entry for new professionals
- To limit competition in the marketplace
Correct answer: To protect the public and ensure consistent professional standards
Industry regulations are primarily designed to protect the public by ensuring professionals meet consistent standards of competence and conduct.
Question 71: What is the relationship between Access Control & Identity Management and ethical professional conduct?
- Ethics applies only to separate, unrelated decisions
- There is no connection between technical knowledge and ethics
- Ethical considerations are integrated into all aspects of professional practice in this area (Correct answer)
- Ethics is relevant only when legal issues arise
Correct answer: Ethical considerations are integrated into all aspects of professional practice in this area
Ethical considerations are deeply integrated into Access Control & Identity Management, as professional conduct and integrity underpin all aspects of practice in this field.
Question 72: In a wireless evil twin attack, what does the attacker deploy to capture victim credentials?
- A malicious access point mimicking a legitimate Wi-Fi network's SSID (Correct answer)
- A keylogger installed on the target device
- A brute-force tool targeting WPA2 handshakes
- A packet sniffer on the legitimate network
Correct answer: A malicious access point mimicking a legitimate Wi-Fi network's SSID
In an evil twin attack, the attacker creates a fake AP with the same SSID as a legitimate network, luring users to connect and then intercepting their traffic or credentials.
Question 73: How does Cloud Computing & Virtualization contribute to overall professional effectiveness?
- It is relevant only during the certification examination
- It applies only to supervisory-level professionals
- It provides essential knowledge and skills that directly impact quality of work and outcomes (Correct answer)
- It serves only as a credential requirement with no practical impact
Correct answer: It provides essential knowledge and skills that directly impact quality of work and outcomes
Cloud Computing & Virtualization directly contributes to professional effectiveness by providing essential knowledge and skills that improve the quality of work and outcomes across all career levels.
Question 74: What is the recommended approach to staying current in Database Management & Security?
- Relying solely on past experience
- Regular professional development, industry publications, and peer collaboration (Correct answer)
- Waiting for regulatory changes to force updates
- Reviewing initial training materials once per year
Correct answer: Regular professional development, industry publications, and peer collaboration
Staying current in Database Management & Security requires ongoing professional development, reading industry publications, and collaborating with peers to share knowledge and best practices.
Question 75: What is the relationship between Vulnerability Assessment & Penetration Testing and ethical professional conduct?
- Ethics applies only to separate, unrelated decisions
- There is no connection between technical knowledge and ethics
- Ethical considerations are integrated into all aspects of professional practice in this area (Correct answer)
- Ethics is relevant only when legal issues arise
Correct answer: Ethical considerations are integrated into all aspects of professional practice in this area
Ethical considerations are deeply integrated into Vulnerability Assessment & Penetration Testing, as professional conduct and integrity underpin all aspects of practice in this field.
Question 76: Which best describes the scope of Database Management & Security in professional practice?
- An outdated concept no longer relevant to modern practice
- A theoretical framework with no practical applications
- A narrow topic relevant only to entry-level professionals
- A comprehensive area covering both theoretical foundations and practical applications (Correct answer)
Correct answer: A comprehensive area covering both theoretical foundations and practical applications
Database Management & Security encompasses both theoretical foundations and practical applications that are essential to professional practice in this field.
Question 77: What is 'jailbreaking' a mobile device?
- Resetting a device to factory settings to remove malware
- Unlocking a carrier-locked phone to use any SIM
- Exploiting OS vulnerabilities to remove manufacturer/carrier restrictions and gain root access (Correct answer)
- Encrypting device storage to protect data at rest
Correct answer: Exploiting OS vulnerabilities to remove manufacturer/carrier restrictions and gain root access
Jailbreaking (iOS) or rooting (Android) involves exploiting OS vulnerabilities to gain privileged root access, bypassing built-in security controls and vetting mechanisms.
Question 78: Which approach to compliance is considered most effective?
- Focusing compliance efforts only on areas that have been cited previously
- Hiring a consultant once a year for a brief review
- A proactive approach that integrates compliance into daily operations (Correct answer)
- A reactive approach that addresses issues only after violations
Correct answer: A proactive approach that integrates compliance into daily operations
A proactive compliance approach that integrates regulatory requirements into daily operations is most effective at preventing violations and maintaining standards.
Question 79: Which best describes the scope of Access Control & Identity Management in professional practice?
- A narrow topic relevant only to entry-level professionals
- An outdated concept no longer relevant to modern practice
- A theoretical framework with no practical applications
- A comprehensive area covering both theoretical foundations and practical applications (Correct answer)
Correct answer: A comprehensive area covering both theoretical foundations and practical applications
Access Control & Identity Management encompasses both theoretical foundations and practical applications that are essential to professional practice in this field.
Question 80: What is a 'memory dump' and why is it important in malware forensics?
- A capture of the contents of RAM at a point in time, revealing running processes and loaded malware (Correct answer)
- A backup of the system's virtual memory swap file
- A report generated by antivirus software after a scan
- A log of failed memory allocation errors in system software
Correct answer: A capture of the contents of RAM at a point in time, revealing running processes and loaded malware
Memory dumps capture volatile RAM contents including running processes, network connections, decrypted data, and in-memory malware that leaves no disk artifacts.
Question 81: What is the primary goal of security awareness training in an organization?
- To configure firewalls and IDS systems
- To install antivirus software
- To perform penetration testing on systems
- To teach employees to recognize and respond to social engineering attacks (Correct answer)
Correct answer: To teach employees to recognize and respond to social engineering attacks
Security awareness training educates employees on identifying threats like phishing, pretexting, and other manipulation tactics.
Question 82: How does a 'watering hole' attack incorporate social engineering?
- Attackers send poisoned water cooler meeting invites via email
- Attackers intercept data at public water utilities
- Attackers target employees during lunch breaks in common areas
- Attackers compromise websites frequently visited by the target group (Correct answer)
Correct answer: Attackers compromise websites frequently visited by the target group
In a watering hole attack, adversaries infect websites that a specific target group regularly visits, exploiting trust in familiar sites.
Question 83: What is the primary purpose of disabling SSID broadcasting on a wireless access point?
- It provides security through obscurity by hiding the network name from passive scans (Correct answer)
- It encrypts the SSID so only known clients can see it
- It prevents all unauthorized devices from connecting
- It enables MAC address filtering automatically
Correct answer: It provides security through obscurity by hiding the network name from passive scans
Disabling SSID broadcast is a security-through-obscurity measure; the network still exists and can be discovered by active scanning tools, so it provides minimal real protection.
Question 84: What is the relationship between Operating Systems & Platforms and ethical professional conduct?
- Ethics applies only to separate, unrelated decisions
- There is no connection between technical knowledge and ethics
- Ethics is relevant only when legal issues arise
- Ethical considerations are integrated into all aspects of professional practice in this area (Correct answer)
Correct answer: Ethical considerations are integrated into all aspects of professional practice in this area
Ethical considerations are deeply integrated into Operating Systems & Platforms, as professional conduct and integrity underpin all aspects of practice in this field.
Question 85: What is the relationship between System Administration & Configuration and ethical professional conduct?
- Ethics is relevant only when legal issues arise
- There is no connection between technical knowledge and ethics
- Ethical considerations are integrated into all aspects of professional practice in this area (Correct answer)
- Ethics applies only to separate, unrelated decisions
Correct answer: Ethical considerations are integrated into all aspects of professional practice in this area
Ethical considerations are deeply integrated into System Administration & Configuration, as professional conduct and integrity underpin all aspects of practice in this field.
Question 86: What is the role of a 'write blocker' in digital forensics?
- To prevent any writes to the evidence drive during imaging, preserving its original state (Correct answer)
- To block malicious write operations on a compromised server
- To encrypt data written to forensic image files
- To prevent investigators from writing notes about evidence
Correct answer: To prevent any writes to the evidence drive during imaging, preserving its original state
A write blocker is a hardware or software device that allows read-only access to storage media, preventing accidental or deliberate modification of evidence.
Question 87: What countermeasure best protects against phishing attacks in an organization?
- Blocking all email attachments
- Disabling all outbound internet traffic
- Using only phone-based communications
- Implementing multi-factor authentication and employee phishing simulations (Correct answer)
Correct answer: Implementing multi-factor authentication and employee phishing simulations
Combining MFA (to limit damage if credentials are stolen) with simulated phishing training significantly reduces organizational phishing risk.
Question 88: Why is regular risk reassessment important?
- Because initial assessments are always wrong
- Because it provides work for risk management teams
- Because regulators require it exactly once per year
- Because the risk landscape changes as conditions, activities, and environments evolve (Correct answer)
Correct answer: Because the risk landscape changes as conditions, activities, and environments evolve
Regular risk reassessment is essential because risks are dynamic — new threats emerge, existing risks change in severity, and the effectiveness of controls may vary over time.
Question 89: What is the most important competency assessed in Threat Detection & Incident Response for professionals in this field?
- Memorization of textbook definitions only
- Applied knowledge and practical problem-solving ability (Correct answer)
- Years of experience without demonstrated skill
- Academic credentials without practical application
Correct answer: Applied knowledge and practical problem-solving ability
Threat Detection & Incident Response assessment focuses on applied knowledge and practical problem-solving ability, ensuring professionals can effectively perform in real-world situations.
Question 90: Which best describes the scope of Application Security & Development in professional practice?
- An outdated concept no longer relevant to modern practice
- A comprehensive area covering both theoretical foundations and practical applications (Correct answer)
- A narrow topic relevant only to entry-level professionals
- A theoretical framework with no practical applications
Correct answer: A comprehensive area covering both theoretical foundations and practical applications
Application Security & Development encompasses both theoretical foundations and practical applications that are essential to professional practice in this field.
Question 91: What US law governs the interception of electronic communications and is relevant to digital forensics investigations?
- Health Insurance Portability and Accountability Act (HIPAA)
- Computer Fraud and Abuse Act (CFAA)
- Electronic Communications Privacy Act (ECPA) (Correct answer)
- Sarbanes-Oxley Act (SOX)
Correct answer: Electronic Communications Privacy Act (ECPA)
The ECPA sets legal standards for accessing stored electronic communications and monitoring digital transmissions, directly governing how forensic evidence is collected.
Question 92: What is the consequence of non-compliance with mandatory regulations?
- Reduced insurance premiums
- A verbal warning with no further consequences
- Automatic extension of compliance deadline
- Penalties including fines, license revocation, and potential legal action (Correct answer)
Correct answer: Penalties including fines, license revocation, and potential legal action
Non-compliance with mandatory regulations can result in serious consequences including financial penalties, loss of licensure, and legal proceedings.
Question 93: Which principle in digital forensics states that any contact between two items leaves a trace?
- Bell-LaPadula Model
- Locard's Exchange Principle (Correct answer)
- Occam's Razor
- Shannon's Information Theory
Correct answer: Locard's Exchange Principle
Locard's Exchange Principle states that every contact leaves a trace, which in digital forensics means system interactions leave artifacts like logs and metadata.
Question 94: What is 'pretexting' in the context of social engineering?
- Creating a fabricated scenario to manipulate a victim into revealing information (Correct answer)
- Installing keyloggers on a target system
- Intercepting wireless network traffic
- Sending bulk spam emails
Correct answer: Creating a fabricated scenario to manipulate a victim into revealing information
Pretexting involves an attacker inventing a false situation or identity to gain the victim's trust and extract confidential information.
Question 95: Which psychological principle is exploited when an attacker impersonates an IT manager demanding immediate password resets?
- Liking
- Commitment
- Reciprocity
- Authority (Correct answer)
Correct answer: Authority
The authority principle makes people more likely to comply with requests from perceived figures of power or authority without questioning them.
Question 96: What does 'live forensics' refer to in digital investigations?
- Analysing video footage from live security cameras
- Forensics performed in a live TV broadcast
- Forensics performed on systems that are currently powered on and running (Correct answer)
- Real-time analysis of network intrusion attempts
Correct answer: Forensics performed on systems that are currently powered on and running
Live forensics involves collecting volatile data (RAM, running processes, network connections) from a powered-on system before shutting it down.
Question 97: What Bluetooth attack passively captures device information from discoverable Bluetooth devices without owner permission?
- Bluetoothing
- Bluebugging
- Bluejacking
- Bluesnarfing (Correct answer)
Correct answer: Bluesnarfing
Bluesnarfing involves unauthorized access to information on a Bluetooth device (contacts, messages, calendar), exploiting vulnerabilities in the OBEX protocol on discoverable devices.
Question 98: What does 'quid pro quo' mean as a social engineering tactic?
- Offering a service or benefit in exchange for information or access (Correct answer)
- Monitoring network traffic for sensitive data
- Impersonating a vendor during a physical visit
- Sending fake invoices to financial departments
Correct answer: Offering a service or benefit in exchange for information or access
In quid pro quo attacks, the attacker offers something valuable (like IT help) in exchange for the victim providing credentials or access.
Question 99: What is 'vishing' in social engineering?
- Visual phishing using fake websites
- Voice-based phishing conducted over phone calls (Correct answer)
- Phishing via SMS text messages
- Video-based spear phishing attacks
Correct answer: Voice-based phishing conducted over phone calls
Vishing (voice phishing) uses phone calls where attackers impersonate trusted entities like banks or government agencies to obtain sensitive data.
Question 100: What does TKIP stand for and why was it introduced?
- Two-factor Key Integration Protocol — for multi-factor Wi-Fi authentication
- Trusted Key Integrity Protocol — to replace RSA in wireless environments
- Transport Key Interchange Protocol — for secure key exchange in VPNs
- Temporal Key Integrity Protocol — as a WPA improvement over WEP's static key reuse (Correct answer)
Correct answer: Temporal Key Integrity Protocol — as a WPA improvement over WEP's static key reuse
TKIP (Temporal Key Integrity Protocol) was introduced with WPA to address WEP's fatal flaw of static key reuse by dynamically generating a new encryption key for each packet.
Question 101: What is the relationship between Database Management & Security and ethical professional conduct?
- There is no connection between technical knowledge and ethics
- Ethics applies only to separate, unrelated decisions
- Ethical considerations are integrated into all aspects of professional practice in this area (Correct answer)
- Ethics is relevant only when legal issues arise
Correct answer: Ethical considerations are integrated into all aspects of professional practice in this area
Ethical considerations are deeply integrated into Database Management & Security, as professional conduct and integrity underpin all aspects of practice in this field.
Question 102: What is 'network forensics' focused on?
- Forensically imaging routers and firewalls
- Installing monitoring agents on network switches
- Capturing and analyzing network traffic to reconstruct events and identify attackers (Correct answer)
- Recovering deleted files from network-attached storage
Correct answer: Capturing and analyzing network traffic to reconstruct events and identify attackers
Network forensics involves monitoring and analyzing network packets, flows, and logs to reconstruct attack timelines and identify malicious activity.
Question 103: Which principle of influence do attackers exploit when they create a sense of urgency in phishing emails?
- Reciprocity
- Scarcity (Correct answer)
- Authority
- Social proof
Correct answer: Scarcity
Scarcity and urgency pressure victims into acting quickly without thinking critically, a common manipulation tactic in social engineering.
Question 104: How does Database Management & Security contribute to overall professional effectiveness?
- It provides essential knowledge and skills that directly impact quality of work and outcomes (Correct answer)
- It applies only to supervisory-level professionals
- It is relevant only during the certification examination
- It serves only as a credential requirement with no practical impact
Correct answer: It provides essential knowledge and skills that directly impact quality of work and outcomes
Database Management & Security directly contributes to professional effectiveness by providing essential knowledge and skills that improve the quality of work and outcomes across all career levels.
Question 105: What is the primary function of a firewall in network security?
- To store network data backups
- To monitor and control incoming and outgoing network traffic based on security rules (Correct answer)
- To manage email distribution
- To increase network speed
Correct answer: To monitor and control incoming and outgoing network traffic based on security rules
A firewall monitors and controls network traffic based on predetermined security rules, acting as a barrier between trusted and untrusted networks.
Question 106: What common challenge do professionals face when applying Cryptography & Data Protection principles?
- Obtaining permission to use the principles
- The principles are too simple to present any challenge
- Balancing theoretical best practices with practical constraints and real-world conditions (Correct answer)
- Finding the relevant textbook chapter
Correct answer: Balancing theoretical best practices with practical constraints and real-world conditions
Professionals commonly face the challenge of adapting theoretical best practices in Cryptography & Data Protection to the practical constraints and varying conditions encountered in real-world settings.
Question 107: What is network segmentation and why is it important?
- Removing old network equipment
- Dividing a network into smaller segments to contain breaches and control access (Correct answer)
- Increasing the number of network devices
- Upgrading all network cables simultaneously
Correct answer: Dividing a network into smaller segments to contain breaches and control access
Network segmentation divides a network into isolated segments, limiting the spread of security breaches and providing granular access control.
Question 108: What is the most important competency assessed in System Administration & Configuration for professionals in this field?
- Academic credentials without practical application
- Years of experience without demonstrated skill
- Applied knowledge and practical problem-solving ability (Correct answer)
- Memorization of textbook definitions only
Correct answer: Applied knowledge and practical problem-solving ability
System Administration & Configuration assessment focuses on applied knowledge and practical problem-solving ability, ensuring professionals can effectively perform in real-world situations.
Question 109: What is the purpose of the Windows Registry in a forensic investigation?
- It contains all email messages sent and received on the system
- It stores encrypted copies of all user passwords
- It stores temporary internet files and browser cache
- It records system configuration, user activity, and installed software that can reveal attacker behavior (Correct answer)
Correct answer: It records system configuration, user activity, and installed software that can reveal attacker behavior
The Windows Registry contains keys tracking program execution, USB connections, recently accessed files, and persistence mechanisms used by malware.
Question 110: What is the purpose of a captive portal in wireless networking?
- To require users to authenticate or agree to terms before gaining full network access (Correct answer)
- To isolate wireless clients from each other on the same network segment
- To encrypt all traffic between clients and the access point
- To block access to known malicious websites at the network layer
Correct answer: To require users to authenticate or agree to terms before gaining full network access
A captive portal intercepts client HTTP requests and redirects them to an authentication or terms-of-service page, commonly used in public Wi-Fi hotspots before granting internet access.
Question 111: What is the most important competency assessed in Cloud Computing & Virtualization for professionals in this field?
- Years of experience without demonstrated skill
- Academic credentials without practical application
- Memorization of textbook definitions only
- Applied knowledge and practical problem-solving ability (Correct answer)
Correct answer: Applied knowledge and practical problem-solving ability
Cloud Computing & Virtualization assessment focuses on applied knowledge and practical problem-solving ability, ensuring professionals can effectively perform in real-world situations.
Question 112: What is the most important competency assessed in Vulnerability Assessment & Penetration Testing for professionals in this field?
- Years of experience without demonstrated skill
- Academic credentials without practical application
- Memorization of textbook definitions only
- Applied knowledge and practical problem-solving ability (Correct answer)
Correct answer: Applied knowledge and practical problem-solving ability
Vulnerability Assessment & Penetration Testing assessment focuses on applied knowledge and practical problem-solving ability, ensuring professionals can effectively perform in real-world situations.
Question 113: How does Operating Systems & Platforms contribute to overall professional effectiveness?
- It provides essential knowledge and skills that directly impact quality of work and outcomes (Correct answer)
- It is relevant only during the certification examination
- It applies only to supervisory-level professionals
- It serves only as a credential requirement with no practical impact
Correct answer: It provides essential knowledge and skills that directly impact quality of work and outcomes
Operating Systems & Platforms directly contributes to professional effectiveness by providing essential knowledge and skills that improve the quality of work and outcomes across all career levels.
Question 114: What common challenge do professionals face when applying Access Control & Identity Management principles?
- Obtaining permission to use the principles
- Balancing theoretical best practices with practical constraints and real-world conditions (Correct answer)
- The principles are too simple to present any challenge
- Finding the relevant textbook chapter
Correct answer: Balancing theoretical best practices with practical constraints and real-world conditions
Professionals commonly face the challenge of adapting theoretical best practices in Access Control & Identity Management to the practical constraints and varying conditions encountered in real-world settings.
Question 115: What tool is commonly used on Linux/Unix systems to create a forensic bit-stream image of a drive?
- Nmap
- dd (Correct answer)
- Metasploit
- Wireshark
Correct answer: dd
The dd command creates a raw bit-stream copy of a device, making it one of the most fundamental forensic imaging tools on Unix-like systems.
Question 116: How does Access Control & Identity Management contribute to overall professional effectiveness?
- It applies only to supervisory-level professionals
- It is relevant only during the certification examination
- It serves only as a credential requirement with no practical impact
- It provides essential knowledge and skills that directly impact quality of work and outcomes (Correct answer)
Correct answer: It provides essential knowledge and skills that directly impact quality of work and outcomes
Access Control & Identity Management directly contributes to professional effectiveness by providing essential knowledge and skills that improve the quality of work and outcomes across all career levels.
Question 117: What is 'whaling' in the context of social engineering?
- Spear phishing attacks targeting senior executives or high-profile individuals (Correct answer)
- Attacks against maritime or shipping industry networks
- Mass phishing campaigns targeting thousands of users
- Using large botnets to deliver phishing emails
Correct answer: Spear phishing attacks targeting senior executives or high-profile individuals
Whaling targets 'big fish' such as CEOs, CFOs, and other executives, leveraging their authority and access to high-value systems.
Question 118: Which concept in cybercrime investigation refers to determining what happened, when, who did it, and how during an incident?
- Vulnerability chaining
- Root cause analysis
- Forensic timeline reconstruction (Correct answer)
- Threat modeling
Correct answer: Forensic timeline reconstruction
Forensic timeline reconstruction correlates timestamps across logs, file system metadata, and artifacts to create a chronological narrative of an incident.
ALISON Diploma in Information Technology Support and Security
ALISON's free online Diploma covering IT support and security topics including cloud computing, network security, operating systems, database management, digital forensics, and security compliance through modular assessments on the Alison.com platform.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds