TechNuggets Academy

Security Operations

Free ISC2 Certified in Cybersecurity practice — 6 questions on Security Operations, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Domain 5: Security Operations
A hospital is decommissioning a batch of solid-state drives (SSDs) that stored patient records. The IT security team wants a NIST 800-88 compliant method to ensure the data cannot be recovered, without physically destroying the drives so they can be reused. Which sanitization method is MOST appropriate for SSDs specifically?
SSDs use flash memory and wear-leveling, so traditional overwrite passes may not reach every physical cell, and degaussing (a magnetic process) has no effect on solid-state media. Cryptographic erase — destroying the encryption keys that protect data already stored encrypted on the drive — is the NIST 800-88 recommended purge method for self-encrypting SSDs, rendering data unrecoverable without physical destruction.
Question 2 of 6 · Domain 5: Security Operations
Two organizations need to securely exchange a symmetric session key over an untrusted network before starting a bulk encrypted data transfer, but they have never communicated before and have no pre-shared secret. Which approach BEST solves this key exchange problem?
Asymmetric (public key) cryptography solves the fundamental key distribution problem of symmetric encryption: the sender encrypts the symmetric session key with the recipient's public key, and only the recipient's corresponding private key can decrypt it. This hybrid approach combines asymmetric encryption's secure key exchange with symmetric encryption's speed for bulk data.
Question 3 of 6 · Domain 5: Security Operations
A system administrator is applying a hardening baseline to a newly deployed web server. The baseline requires disabling all services and ports not required for the server's function. This hardening practice is BEST described as an application of which principle?
Least functionality is the security principle that systems should be configured to provide only the essential capabilities required for their intended purpose, disabling unnecessary services, ports, protocols, and functions to reduce the attack surface. This is a core system hardening practice.
Question 4 of 6 · Domain 5: Security Operations
A developer stores user passwords by running each password through SHA-256 once and saving the resulting hash in the database. During a security review, this approach is flagged as a weakness. What is the BEST reason this implementation is considered insecure?
Hashing without a unique, random salt means that any two users with the same password will have identical hash values, allowing attackers to use precomputed rainbow tables to quickly reverse common hashes. Adding a unique salt per password before hashing defeats this attack by ensuring identical passwords produce different stored hashes.
Question 5 of 6 · Domain 5: Security Operations
A company's monthly phishing simulation report shows that 8% of employees clicked a simulated malicious link, and this same small group of individuals has clicked in three consecutive simulations despite completing the standard annual security awareness training. What is the MOST effective NEXT step for the security team?
Security awareness programs are most effective when reinforced and tailored to specific risk groups. Repeat clickers indicate that the general annual training did not address their specific gaps, so targeted, focused follow-up training combined with increased monitoring is the appropriate corrective action, consistent with a continuous-improvement approach to security culture.
Question 6 of 6 · Domain 5: Security Operations
An organization classifies a customer database as 'Confidential' under its data classification policy. According to standard data handling practices for this classification level, which control is MOST appropriate for data stored on a server hard drive?
For data classified as Confidential, encryption at rest (full disk or file-level encryption) is a standard control that protects the data's confidentiality even if physical security is bypassed, such as through drive theft, improper disposal, or insider access to hardware. This directly addresses the data lifecycle's storage and protection phase.
Ready for the real thing?

The full course: two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed explanations.

undefined $34.99 with code SECPREP34 — valid through Oct 11.

Get my $34.99 deal →