1. A financial institution is implementing a new customer data platform. To comply with various industry regulations (e.g., PCI DSS, GDPR) and internal security standards, the development team is required to follow strict guidelines for data handling, access control, and encryption. These guidelines are formally documented and communicated across all relevant departments. Which security concept do these guidelines primarily represent?
Security Concepts
A.Security Reporting
B.Security Audits
C.Security Metrics
D.Security Policies
Show answerAnswer
D. Security Policies
Formal, documented guidelines for data handling, access control, and encryption, especially when driven by regulations and internal standards, are core components of security policies.
2. A security architect is evaluating different cloud deployment models for a new application that will process highly sensitive intellectual property. The primary concern is maintaining maximum control over the underlying infrastructure and ensuring complete data isolation, while still benefiting from some aspects of cloud elasticity. Which cloud deployment model would best meet these requirements?
Cloud Security
A.Public Cloud
B.Community Cloud
C.Hybrid Cloud
D.Private Cloud
Show answerAnswer
D. Private Cloud
A private cloud provides a dedicated environment for a single organization, offering maximum control over infrastructure, enhanced security, and complete data isolation, while still allowing for internal elasticity.
3. A security analyst is conducting a post-incident review after a successful ransomware attack. The review reveals that several critical servers were not included in the regular patching schedule, and their operating systems were severely outdated. Furthermore, there was no comprehensive inventory of all IT assets, making it difficult to quickly identify affected systems and their owners during the incident. Which security best practice, if properly implemented, could have significantly mitigated the impact of this incident?
Security Concepts
A.Security Reporting
B.Asset Management
C.Security Awareness Training
D.Threat Intelligence
Show answerAnswer
B. Asset Management
The lack of patching and a comprehensive inventory directly points to deficiencies in asset management. Proper asset management includes tracking assets, their configuration, patch status, and ownership, which would have addressed the issues described.
4. A global enterprise is migrating its sensitive customer data to a public cloud provider. Due to regulatory compliance requirements (e.g., GDPR), the company must ensure that encryption keys for this data are generated and managed in a hardware-secured environment and remain under the company's sole control. Which cloud security service best addresses this specific requirement?
Cloud Security
A.Key Management Service (KMS)
B.Identity and Access Management (IAM)
C.Cloud Hardware Security Module (HSM)
D.Cloud Storage Gateway
Show answerAnswer
C. Cloud Hardware Security Module (HSM)
Cloud HSMs provide dedicated, single-tenant hardware security modules that allow customers to generate and manage their own encryption keys in a FIPS 140-2 Level 3 compliant environment, ensuring exclusive control and meeting stringent compliance needs.
5. A global organization is implementing a cloud security strategy that prioritizes the ability to automatically enforce security policies and respond to threats across its multi-cloud environment without human intervention. This includes automated patching, configuration drift detection, and incident response workflows. Which security automation and orchestration concept is being applied here?
Cloud Security
A.Cloud Security Posture Management (CSPM)
B.Security Information and Event Management (SIEM)
C.Security Orchestration, Automation, and Response (SOAR)
D.Cloud Access Security Broker (CASB)
Show answerAnswer
C. Security Orchestration, Automation, and Response (SOAR)
SOAR platforms integrate security tools and automate repetitive security tasks, orchestrating complex workflows for incident response, threat hunting, and security operations, directly aligning with the need for automated policy enforcement and threat response across a multi-cloud environment.
6. A security auditor is reviewing an organization's endpoint security posture. The auditor identifies that while traditional antivirus is deployed, there is no mechanism to detect advanced persistent threats (APTs) that bypass signature-based detection or to provide visibility into endpoint activities post-compromise. The organization needs a solution that can identify stealthy attacks, provide deep forensic capabilities, and enable rapid containment. Which endpoint security technology should the auditor recommend?
Endpoint Security and Secure Network Access
A.Endpoint Detection and Response (EDR)
B.Data Loss Prevention (DLP)
C.Security Information and Event Management (SIEM)
D.Network Intrusion Detection System (NIDS)
Show answerAnswer
A. Endpoint Detection and Response (EDR)
Endpoint Detection and Response (EDR) systems are designed to continuously monitor endpoint activities, collect detailed data, detect advanced threats (including APTs that bypass traditional AV), provide deep forensic capabilities, and enable rapid response actions like isolating compromised devices. NIDS is network-centric, SIEM aggregates logs, and DLP prevents data exfiltration, none of which provide the necessary endpoint visibility and response for APTs.
7. A global technology company is expanding its operations into new countries, each with unique data residency and privacy laws. The company's security team must ensure that their data handling practices comply with all applicable regulations worldwide. Which aspect of security governance is most critical in this scenario?
Security Concepts
A.Security metrics reporting
B.Legal and regulatory compliance
C.Incident response plan maturity
D.Security awareness training effectiveness
Show answerAnswer
B. Legal and regulatory compliance
The scenario explicitly states the need to comply with 'unique data residency and privacy laws' and 'all applicable regulations worldwide'. This directly falls under legal and regulatory compliance, a key aspect of security governance.
8. A global enterprise is deploying a new application across multiple cloud regions to improve latency and resilience. Due to strict data residency regulations, certain types of sensitive customer data must remain within specific geographic boundaries. Which cloud security architecture principle is most relevant for ensuring compliance in this scenario?
Cloud Security
A.Continuous security monitoring
B.Decentralized identity management
C.Automated security orchestration
D.Data locality and sovereignty
Show answerAnswer
D. Data locality and sovereignty
Data locality and sovereignty directly address the requirement for data to reside and be governed by the laws of a specific geographic region, which is critical for meeting data residency regulations.
9. A security engineer is tasked with securing a serverless application deployed on AWS Lambda. The application processes user requests and interacts with an Amazon S3 bucket. Which security control is paramount to limit the S3 bucket's exposure only to the specific Lambda function and prevent unauthorized access?
Cloud Security
A.Applying an S3 bucket policy with IAM conditions
B.Enabling S3 bucket versioning
C.Implementing a Web Application Firewall (WAF) in front of S3
D.Configuring S3 Transfer Acceleration
Show answerAnswer
A. Applying an S3 bucket policy with IAM conditions
An S3 bucket policy, combined with IAM conditions, allows granular control over who (specifically the Lambda's IAM role) can access the bucket and what actions they can perform, thus limiting exposure precisely.
10. A security engineer is designing a secure network access solution for a campus network. The design requires that all endpoints, including corporate laptops, personal mobile devices, and IoT sensors, are authenticated and authorized before gaining access to network resources. Which network access control (NAC) component is primarily responsible for evaluating the endpoint's compliance with security policies and assigning appropriate network access privileges?
Endpoint Security and Secure Network Access
A.Authenticator
B.Supplicant
C.Policy Enforcement Point (PEP)
D.Policy Decision Point (PDP)
Show answerAnswer
D. Policy Decision Point (PDP)
The Policy Decision Point (PDP) is the component within a NAC architecture that evaluates the security policies against the supplicant's attributes and makes the decision on whether to grant or deny access, and what level of access to provide.
11. A security analyst is investigating a potential breach where an unauthorized device gained access to the internal network. The network uses 802.1X authentication. Upon initial investigation, it was discovered that the attacker bypassed 802.1X by connecting their malicious device to an already authenticated IP phone, leveraging the phone's authenticated port. What 802.1X feature should have been enabled on the switch port to prevent this specific attack vector?
Endpoint Security and Secure Network Access
A.MAC Address Bypass (MAB)
B.Guest VLAN
C.Multi-domain authentication
D.Port security
Show answerAnswer
C. Multi-domain authentication
Multi-domain authentication (MDA) allows an IP phone and a PC connected to the phone's data port to authenticate independently on the same switch port. This ensures that even if the phone is authenticated, the connected PC still needs its own successful authentication, preventing an attacker from piggybacking on the phone's access. Port security limits MAC addresses but doesn't handle the multi-device authentication scenario as elegantly as MDA.
12. A security architect is designing an endpoint security architecture that must protect against fileless malware and ransomware, provide deep visibility into endpoint processes, and offer rapid response capabilities across a hybrid environment. The solution must integrate seamlessly with existing security operations tools. Which modern endpoint security solution best meets these requirements?
Endpoint Security and Secure Network Access
A.Data Loss Prevention (DLP)
B.Endpoint Detection and Response (EDR)
C.Traditional Signature-Based Antivirus
D.Host-based Intrusion Prevention System (HIPS)
Show answerAnswer
B. Endpoint Detection and Response (EDR)
EDR solutions are specifically designed to detect and respond to advanced threats like fileless malware and ransomware by providing deep visibility into endpoint activities, continuous monitoring, and robust response capabilities, making them superior to traditional AV or HIPS for these modern challenges.
13. A security engineer is implementing a new wireless network that must support a mix of corporate devices (laptops, phones) and guest devices. Corporate devices must use strong, certificate-based authentication, while guest devices require a simple, web-based authentication method. Both types of devices need to be placed in separate, isolated network segments with different access policies. Which combination of 802.1X and network access control features would best achieve these requirements?
Endpoint Security and Secure Network Access
A.EAP-TLS for corporate and a Captive Portal with Guest VLAN for guests.
B.WPA2-Enterprise with EAP-FAST for corporate and an open network with a disclaimer for guests.
C.WPA3-Personal for corporate and a pre-shared key (PSK) for guests.
D.PSK authentication for corporate and MAC filtering for guests.
Show answerAnswer
A. EAP-TLS for corporate and a Captive Portal with Guest VLAN for guests.
EAP-TLS provides strong, certificate-based authentication required for corporate devices. A Captive Portal with a Guest VLAN offers a simple web-based authentication for guests and places them into an isolated segment, fulfilling all requirements. PSK and MAC filtering are less secure. EAP-FAST is certificate-less but still robust, while an open network is insecure. WPA3-Personal and PSK are not suitable for enterprise certificate-based corporate access or simple guest web authentication with isolation.
14. A security analyst is investigating a recent breach where an unauthorized external party gained access to the company's internal network. The attacker exploited a known vulnerability in an unpatched web server and exfiltrated sensitive customer data. Which security principle was primarily compromised in this scenario?
Security Concepts
A.Availability
B.Confidentiality
C.Integrity
D.Non-repudiation
Show answerAnswer
B. Confidentiality
The exfiltration of sensitive customer data directly compromises confidentiality, as unauthorized access to information occurred. The attacker gained access to information they were not authorized to see.
15. A security auditor is reviewing an organization's endpoint security posture. The auditor discovers that several critical servers are running outdated operating systems and lack current security patches, making them vulnerable to known exploits. However, these servers cannot be immediately upgraded due to application compatibility issues. Which endpoint security design principle should be prioritized to mitigate the risk posed by these vulnerable servers without directly upgrading them?
Endpoint Security and Secure Network Access
A.Regular Vulnerability Scanning
B.Endpoint Hardening
C.Patch Management
D.Network Segmentation and Micro-segmentation
Show answerAnswer
D. Network Segmentation and Micro-segmentation
Network segmentation and micro-segmentation can isolate vulnerable systems, limiting their exposure and preventing potential exploits from spreading to other parts of the network. While not a direct fix for the vulnerability, it's the best immediate mitigation strategy when patching is not an option.
16. An organization is deploying a new containerized application using Kubernetes in a public cloud. The security team needs to ensure that containers are scanned for vulnerabilities before deployment and that only approved images from a trusted registry are used. Which cloud security tool or practice is most effective for achieving this goal?
Cloud Security
A.Implementing a Cloud Native Application Protection Platform (CNAPP)
B.Utilizing a Cloud Access Security Broker (CASB)
C.Configuring a Security Information and Event Management (SIEM) system
D.Deploying a Web Application Firewall (WAF) at the ingress
Show answerAnswer
A. Implementing a Cloud Native Application Protection Platform (CNAPP)
A CNAPP integrates various security capabilities, including container image scanning, supply chain security, and continuous posture management, making it highly effective for securing containerized applications and enforcing approved image usage.
17. During an incident response, a security analyst discovers that a threat actor has modified critical system files to maintain persistence and hide their activities. The analyst needs to restore the system to a known good state. Which core security principle has been directly compromised by the file modifications?
Security Concepts
A.Integrity
B.Confidentiality
C.Availability
D.Accountability
Show answerAnswer
A. Integrity
Integrity ensures that data and systems remain accurate, complete, and untampered. The modification of critical system files by a threat actor directly violates this principle, as the system's state is no longer trustworthy or as intended.
18. A cloud architect is designing a highly available and resilient multi-region application in a public cloud. The application's database tier needs to ensure data consistency across regions while remaining accessible even if an entire region becomes unavailable. Which database deployment strategy is most suitable for meeting both high availability and strong consistency requirements in a multi-region cloud environment?
Cloud Security
A.Multi-region read replicas with eventual consistency
B.Active-passive database replication with asynchronous updates
C.Multi-region active-active database with synchronous replication
D.Single-region database instance with daily backups
Show answerAnswer
C. Multi-region active-active database with synchronous replication
A multi-region active-active database with synchronous replication ensures that all database instances in different regions are kept up-to-date simultaneously. This provides both high availability (if one region fails, others are active) and strong data consistency across all regions.
19. A security architect is integrating an on-premises Active Directory with a cloud-based Software as a Service (SaaS) application to provide single sign-on (SSO) capabilities. The goal is to allow users to authenticate once using their existing corporate credentials and access the SaaS application without re-entering them. Which protocol is commonly used to facilitate this federated identity management in cloud environments?
Cloud Security
A.SMTP
B.SSH
C.SNMP
D.SAML
Show answerAnswer
D. SAML
SAML (Security Assertion Markup Language) is an XML-based open standard for exchanging authentication and authorization data between an identity provider (like Active Directory) and a service provider (like a SaaS application). It is widely used for federated single sign-on.
20. A security operations center (SOC) team is struggling to keep up with the volume of security alerts generated by their cloud environment. They need a solution that can automatically collect security data from various cloud services, correlate events, and execute predefined incident response playbooks without human intervention for common, low-risk incidents. Which cloud security technology would best integrate these capabilities?
Cloud Security
A.Cloud Security Posture Management (CSPM)
B.Security Orchestration, Automation, and Response (SOAR)
C.Security Information and Event Management (SIEM)
D.Cloud Access Security Broker (CASB)
Show answerAnswer
B. Security Orchestration, Automation, and Response (SOAR)
SOAR platforms are designed to integrate security tools, automate incident response workflows (playbooks), and orchestrate complex tasks, directly addressing the need to handle a high volume of alerts with automated responses.
21. A security auditor is reviewing an organization's endpoint security posture. The auditor notes that while traditional antivirus is deployed, there's a lack of visibility into post-compromise activity, such as lateral movement, privilege escalation, and data exfiltration attempts. The organization needs a solution that can retrospectively analyze endpoint data to identify hidden threats and provide detailed forensic information for incident response. Which technology is specifically designed to address these gaps?
Endpoint Security and Secure Network Access
A.Unified Threat Management (UTM)
B.Security Information and Event Management (SIEM)
C.Endpoint Detection and Response (EDR)
D.Next-Generation Firewall (NGFW)
Show answerAnswer
C. Endpoint Detection and Response (EDR)
Endpoint Detection and Response (EDR) is specifically designed to fill the visibility gap left by traditional antivirus. It continuously monitors endpoint activity, collects telemetry data, and provides capabilities for detecting post-compromise behaviors, threat hunting, and retrospective analysis to uncover hidden threats and support detailed forensic investigations during incident response.
22. A company is integrating its Cisco Secure Web Appliance (WSA) with its existing identity management system (Cisco ISE) to implement user-based web access policies. The goal is to ensure that different user groups (e.g., 'Developers', 'Marketing') have varying levels of internet access and content filtering, and that these policies follow users regardless of which device they use or where they connect from within the corporate network. Which integration method is most effective for achieving this user-aware content security?
Content Security
A.WSA relying solely on IP address-based access control lists (ACLs).
B.WSA integrated with Active Directory via NTLM for authentication.
C.WSA configured with local user accounts and groups.
D.WSA integrated with Cisco ISE for user and group identity context.
Show answerAnswer
D. WSA integrated with Cisco ISE for user and group identity context.
Integrating the Cisco WSA with Cisco ISE provides the most robust and flexible solution for user-based web access policies. ISE acts as a central identity management system, providing the WSA with real-time user and group context, enabling policies that follow users regardless of their device or location.
23. A network security administrator is configuring 802.1X authentication on a Cisco Catalyst switch. The goal is to allow endpoints to connect only after successful authentication against a RADIUS server. Which command sequence would correctly enable 802.1X port-based authentication on a specific interface and specify the authentication method list?
Endpoint Security and Secure Network Access
A.interface GigabitEthernet0/1
authentication port-control auto
dot1x pae authenticator
dot1x timeout tx-period 10
aaa authentication dot1x default group radius
B.interface GigabitEthernet0/1
dot1x port-control auto
dot1x pae authenticator
authentication pre-authenticate
aaa authentication dot1x default group radius
C.interface GigabitEthernet0/1
authentication host-mode multi-auth
dot1x pae authenticator
dot1x port-control auto
aaa authentication dot1x default group radius
D.interface GigabitEthernet0/1
authentication port-control auto
dot1x pae authenticator
aaa authentication dot1x default group radius
dot1x host-mode multi-domain
Show answerAnswer
A. interface GigabitEthernet0/1
authentication port-control auto
dot1x pae authenticator
dot1x timeout tx-period 10
aaa authentication dot1x default group radius
The command `authentication port-control auto` enables 802.1X on the interface, `dot1x pae authenticator` sets the switch as the authenticator, and `aaa authentication dot1x default group radius` specifies the RADIUS server for authentication. The `dot1x timeout tx-period` is a common configuration for 802.1X.
24. A network security architect is designing a content security solution for a large enterprise. The design must ensure that all HTTP/HTTPS traffic is inspected for malware and sensitive data, even if the traffic is encrypted. The solution needs to integrate with existing Active Directory for user-based policies and provide granular reporting on web usage. Where should SSL decryption be performed in the content inspection flow to maximize effectiveness and minimize performance impact?
Content Security
A.On the endpoint device via a proxy agent.
B.On a dedicated content security gateway after initial firewall filtering.
C.Within the core network router after routing decisions.
D.At the perimeter firewall before content inspection.
Show answerAnswer
B. On a dedicated content security gateway after initial firewall filtering.
Performing SSL decryption on a dedicated content security gateway after initial firewall filtering allows the firewall to handle basic access control and high-volume traffic, offloading resource-intensive decryption and deep content inspection to a specialized device. This optimizes performance and ensures comprehensive inspection of encrypted traffic.
25. An organization is deploying a Cisco Firepower Threat Defense (FTD) appliance and needs to define custom application signatures to accurately identify and control a proprietary internal application that uses a unique protocol header. Which configuration element within Firepower Management Center (FMC) allows for the creation of these custom application identities?
Content Security
A.Network Analysis Policy (NAP)
B.Intrusion Policy
C.Security Intelligence Feed
D.Application Detector
Show answerAnswer
D. Application Detector
The Application Detector within Firepower Management Center (FMC) is the component used to create and manage custom application identifiers. This allows FTD to recognize proprietary applications based on unique characteristics like protocol headers, enabling granular control in access policies.
The systematic process of identifying, tracking, categorizing, and maintaining all organizational assets, including hardware, software, and data, to ensure their security.
Crucial for vulnerability management and incident response.
Includes maintaining inventory, configurations, and patch levels.
Helps understand the scope and impact of security incidents.
Security Orchestration, Automation, and Response (SOAR)
Flip card
A category of security software that enables organizations to collect security alerts, standardize incident response, and automate various security tasks and workflows.
Endpoint Detection and Response (EDR) is an endpoint security solution that continuously monitors endpoints to detect advanced persistent threats (APTs) and stealthy attacks, providing deep forensic visibility and enabling rapid incident response.
Detects threats beyond signature-based AV.
Provides deep endpoint visibility and forensic data.
Enables rapid containment and response to advanced attacks.
The process of ensuring that an organization adheres to all relevant laws, regulations, and industry standards pertaining to information security and data privacy.
Non-compliance can lead to significant fines, legal penalties, and reputational damage.
Requires continuous monitoring and adaptation to evolving legal landscapes.
Principles that dictate where data must be stored (locality) and which legal jurisdiction's laws apply to that data (sovereignty), often driven by regulatory requirements.
Ensures compliance with data residency laws.
Impacts cloud region selection and data architecture.
Crucial for global businesses handling sensitive data.
A component in a Network Access Control (NAC) system responsible for evaluating security policies and making access decisions for connecting endpoints.
Evaluates endpoint attributes against defined policies.
Determines the appropriate level of network access.
Communicates decisions to the Policy Enforcement Point (PEP).
An 802.1X feature that enables independent authentication for different types of devices (e.g., voice and data) connected to the same switch port, preventing unauthorized devices from leveraging an already authenticated device's access.
A wireless network design that uses different authentication methods for different user groups (e.g., EAP-TLS for corporate devices requiring strong certificate-based security, and a Captive Portal for guests needing simple web-based access with segmentation).
A unified security platform that provides a broad set of security capabilities for cloud-native applications across the entire lifecycle, from development to runtime.
Multi-region Active-Active Database with Synchronous Replication
Flip card
A database deployment strategy where multiple active instances of a database are deployed across different cloud regions, and all writes are synchronously replicated to ensure strong consistency across all instances.
Provides highest levels of availability and disaster recovery.
Ensures strong data consistency across all regions.
Writes are committed to all active regions before acknowledgment, incurring higher latency.
Integrating Cisco Secure Web Appliance (WSA) with Cisco Identity Services Engine (ISE) to leverage centralized identity management for applying granular, user- and group-based web access and content filtering policies.
ISE provides user and group context to WSA.
Enables dynamic policies that follow users across devices and locations.
Enhances visibility and control over web usage based on identity.
Strategic placement of SSL decryption capabilities within the network to enable deep inspection of encrypted traffic for security threats or policy enforcement while minimizing performance impact on critical infrastructure.
Decryption is resource-intensive and requires dedicated hardware/software.
Best placed on specialized content security gateways (e.g., web proxy, NGFW with advanced capabilities).
Typically occurs after basic firewalling but before deep content inspection.
The ability within Cisco Firepower Threat Defense (FTD) to define unique signatures for proprietary or unrecognized applications, enabling granular control.
Uses the Application Detector in FMC.
Identifies applications independent of port.
Crucial for controlling internal or niche applications.
An architectural pattern where an application runs simultaneously across two or more distinct cloud providers, with traffic distributed between them, enabling high availability, disaster recovery, and resilience.
Workloads are active in multiple cloud environments concurrently.
Provides immediate failover capabilities between providers.
Requires consistent security policies and configurations across all active clouds.
Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.