TechNuggets Academy

Security Engineering

Free CompTIA SecurityX practice — 6 questions on Security Engineering, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Security Engineering
A financial services firm's API gateway terminates mutual-TLS connections for thousands of clients per second. The security team must verify certificate revocation status while meeting three constraints: no significant per-connection latency, no single point of failure on the CA/OCSP infrastructure, and no leakage of client identity to a third-party OCSP responder. Which approach BEST satisfies all three requirements?
OCSP stapling shifts the revocation query to the server, which periodically fetches and caches a signed OCSP response and attaches ('staples') it to the TLS handshake. This eliminates per-connection latency to an external responder, removes the client-identity leak (the client never contacts the OCSP responder), and a short validity window keeps revocation data fresh without creating a per-request dependency on CA availability.
Question 2 of 6 · Security Engineering
An architect is designing a hybrid TLS 1.3 key exchange configuration to protect current session traffic against 'harvest-now-decrypt-later' attacks by future quantum computers, while retaining compatibility with existing infrastructure. Which key exchange configuration should be implemented?
A hybrid key exchange combines a classical algorithm (X25519) with a NIST-standardized post-quantum KEM (ML-KEM/CRYSTALS-Kyber, FIPS 203). This protects captured traffic against future quantum decryption while the classical component maintains assurance against any near-term weaknesses in the newer PQ algorithm, satisfying the harvest-now-decrypt-later concern.
Question 3 of 6 · Security Engineering
A security team is generating a new root CA private key on an HSM and must ensure that no single custodian can ever reconstruct or use the full key material alone, enforcing dual control during the key ceremony. Which HSM configuration achieves this?
M-of-N quorum authentication (split knowledge and dual control) requires a minimum threshold of independently held authentication factors (e.g., 3 of 5 smartcards) before any HSM key operation can occur, ensuring no individual custodian can unilaterally use or reconstruct the key. This is the standard control used in CA root key ceremonies under FIPS 140-2/3 Level 3 HSMs.
Question 4 of 6 · Security Engineering
A fraud-detection ML model is trained on continuously ingested, third-party labeled datasets. The security architect suspects an adversary may be injecting subtly mislabeled records over time to gradually shift the model's decision boundary (a data poisoning attack). Which control BEST addresses this threat?
Detecting data poisoning requires validating the content and integrity of training data before it influences the model, not just protecting its confidentiality. Statistical anomaly/drift detection combined with data provenance/lineage tracking can flag suspicious or unverified data sources contributing to gradual label skew, allowing remediation before the poisoned data affects model weights.
Question 5 of 6 · Security Engineering
A utility company must send telemetry from an OT SCADA historian to a cloud analytics platform in the IT network, but under no circumstances can control commands or any data flow back into the OT network, even if the IT/cloud side is fully compromised. Which architecture control provides this guarantee?
A hardware-based unidirectional gateway (data diode) physically permits data transmission in only one direction at the electrical/optical layer, making reverse data flow impossible regardless of software misconfiguration or compromise on the IT side. This provides a deterministic, tamper-resistant guarantee appropriate for critical OT/ICS environments.
Question 6 of 6 · Security Engineering
An LLM-powered application retrieves and processes external documents as context (RAG). Which architectural control provides the STRONGEST defense against indirect prompt injection attacks, where malicious instructions are embedded within the retrieved documents?
Effective defense against indirect prompt injection requires layered controls: sanitizing untrusted content, structurally separating it from the trusted system prompt (e.g., using delimiters or distinct role fields so the model treats retrieved text as data, not instructions), and enforcing least privilege on what actions/tools the model is permitted to invoke — limiting the blast radius even if an injection partially succeeds.
Ready for the real thing?

The full course: two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed explanations.

undefined $34.99 with code FREETEST33 — valid through Oct 6.

Get my $34.99 deal →