Free Cybersecurity-Fundamentals sample questions
Real questions from the ISA/IEC 62443 Cybersecurity Fundamentals Specialist practice bank, with the correct answer and an explanation for each one. No junk, no filler.
Try them in the simulator Same questions, with study, timed and flashcard modes.
Showing 10 of 20 free sample questions.
During an incident response tabletop exercise, a team is presented with a scenario where a critical server has been infected with ransomware. The team needs to follow the standard incident response lifecycle. What is the immediate first step that should be taken after detecting and analyzing the incident?
A security team is implementing Role-Based Access Control (RBAC) for a large enterprise. They have defined roles such as 'Sales Associate', 'HR Manager', and 'System Administrator'. Which of the following is a primary benefit of using RBAC over Discretionary Access Control (DAC)?
A threat analyst is investigating a new malware variant that uses a domain generation algorithm (DGA) to create thousands of random domain names for its command-and-control (C2) communication. Which of the following is the MOST effective strategy for a security operations team to detect and block this type of threat?
A company is conducting a Business Impact Analysis (BIA) to develop its business continuity plan. The analysis determines that the customer relationship management (CRM) system can tolerate a maximum of 4 hours of downtime before causing significant financial loss. It is also determined that losing more than 1 hour of transaction data is unacceptable. How should these two metrics be formally defined? (Select TWO).
True or False: In a symmetric encryption system, the key used for encryption is different from the key used for decryption.
**Company Background:** Global Logistics Inc. (GLI) is a large shipping and logistics company that operates a complex network of warehouses, distribution centers, and transportation fleets. The company relies heavily on its Industrial Control Systems (ICS) and Supervisory Control and Data Acquisition (SCADA) systems to manage automated sorting machinery, climate control in sensitive storage areas, and fleet tracking. Historically, the ICS/SCADA network was completely air-gapped from the corporate IT network. **Current Situation:** To improve efficiency and enable predictive maintenance, GLI's management has approved a project to connect the ICS/SCADA network to the corporate IT network. This will allow data from the operational technology (OT) environment to be analyzed by business intelligence platforms in the IT environment. The CISO is concerned because the ICS/SCADA systems are legacy devices, many running on old, unpatched operating systems that cannot be easily upgraded. The OT engineers are resistant to any changes that could introduce latency or cause downtime. **Requirements & Constraints:** - Prevent unauthorized traffic from the IT network from reaching the critical ICS/SCADA devices. - Allow specific, approved data flows from the OT network to a data historian server in the IT network. - Ensure that security controls do not interfere with the real-time operational requirements of the OT environment. - The solution must be implemented without replacing the legacy ICS/SCADA equipment. Which of the following architectural approaches BEST meets GLI's security and operational requirements? graph TD subgraph IT_Network [Corporate IT Network] BI[BI Platform] Users[Corporate Users] end subgraph OT_Network [ICS/SCADA Network] PLC[PLCs] HMI[HMIs] Sensors[Sensors] end IT_Network -- "????" -- OT_Network
A SOC analyst is reviewing logs from a Security Information and Event Management (SIEM) system and notices a large number of failed login attempts for a single administrator account, originating from multiple international IP addresses within a five-minute window. This is immediately followed by a single successful login from a new, previously unseen international IP address. Which type of attack has MOST likely occurred?
Which of the following are considered administrative security controls? (Select THREE).
A software development team uses a CI/CD pipeline to automate builds, testing, and deployments. A security engineer wants to integrate security scanning into this pipeline to identify vulnerabilities early in the development lifecycle. This practice is a core component of which methodology?
10 more free samples are waiting
Create a free account to unlock the whole Cybersecurity-Fundamentals sample bank, or get full access to all 203 practice questions in the simulator.