All questions
Question 1
In an IT infrastructure audit of a nonprofit organization, the auditor reviews how internal users access payroll and donor management systems hosted in a private data centre. Management wants a centralized service to create, modify, and disable user accounts and group memberships to support access governance and timely deprovisioning. What is the primary role of the component that provides this capability in the IT infrastructure?
- A web application firewall that filters malicious web requests before they reach applications
- A directory service that centrally manages user identities, groups, and authentication policies (correct answer)
- A tape drive that archives monthly reports for long-term storage
- A legacy token-ring network that improves throughput for modern cloud applications
Explanation: This question tests understanding of identity and access management components in IT infrastructure. The scenario requires centralized management of user accounts and group memberships to support access governance and timely deprovisioning across multiple systems. A directory service (B) like Active Directory or LDAP provides this centralized identity management, storing user accounts, groups, and authentication policies in a hierarchical database that multiple systems can query. Web application firewalls (A) filter malicious web traffic but don't manage user identities. Tape drives (C) provide archival storage without identity management capabilities. Token-ring networks (D) are obsolete LAN technologies unrelated to modern cloud applications or identity management. When evaluating access governance requirements, identify components that centralize identity lifecycle management and provide single-source-of-truth for user authentication and authorization across enterprise systems.
Question 2
In an IT infrastructure audit of a public company, the auditor reviews how employee laptops receive IP addresses and network settings when connecting to the corporate network. Management wants a centralized component that automatically assigns IP addresses and reduces configuration errors to align with IT operations standards. What is the primary role of the component that provides this service?
- A dynamic host configuration protocol (DHCP) server that automatically assigns IP addresses and network parameters to devices (correct answer)
- A database server that stores user passwords in plain text for easy retrieval
- A legacy infrared file transfer device that replaces wired networking
- A physical lock on the server room door that prevents network misconfiguration
Explanation: This question tests knowledge of network infrastructure services, specifically automatic IP address management. The scenario requires centralized assignment of IP addresses and network parameters to reduce configuration errors and support IT operations standards. A DHCP server (A) provides this service by automatically assigning IP addresses, subnet masks, default gateways, and DNS servers to devices when they connect to the network, eliminating manual configuration. Database servers storing passwords in plain text (B) represent poor security practice unrelated to IP management. Infrared file transfer devices (C) are obsolete short-range technologies that don't replace networking. Physical locks (D) secure facilities but don't configure network settings. For network administration efficiency, identify DHCP as the standard protocol for automatic network configuration, reducing errors and administrative overhead.
Question 3
A government agency is performing an IT efficiency evaluation and finds that many internal applications are hosted on underutilized physical servers. Management wants to improve hardware utilization and simplify provisioning while maintaining appropriate controls over workloads. How does the key infrastructure component contribute to overall IT efficiency in this scenario?
- Server virtualization that consolidates workloads onto fewer physical servers and enables faster provisioning of new systems (correct answer)
- Manual re-entry of data into multiple systems to reduce integration complexity
- Use of dial-up networking to limit bandwidth and reduce server load
- Disabling system logs to improve performance by eliminating audit trails
Explanation: This question tests understanding of how virtualization technology improves IT efficiency. The scenario describes underutilized physical servers that management wants to consolidate while maintaining workload controls. Server virtualization (A) directly improves efficiency by consolidating multiple workloads onto fewer physical servers, increasing hardware utilization from typical 15-20% to 60-80%, while enabling rapid provisioning through template-based deployment. Manual data re-entry (B) increases errors and labor without improving infrastructure efficiency. Dial-up networking (C) severely limits bandwidth and would decrease efficiency. Disabling system logs (D) eliminates audit trails required for compliance and troubleshooting. When evaluating IT efficiency improvements, recognize server virtualization as a transformative technology that reduces hardware costs, power consumption, and administrative overhead while improving agility.
Question 4
In an IT infrastructure audit at a public company, the auditor evaluates how software updates are distributed to employee endpoints. Management wants a centralized mechanism to deploy approved patches consistently and to report patch compliance, supporting IT governance and security standards. Which component is essential to manage this patch deployment process?
- An endpoint patch management system that deploys approved updates and reports compliance across devices (correct answer)
- A network hub that distributes software updates by broadcasting them to all devices
- A legacy floppy disk distribution process for monthly operating system updates
- A document retention policy that automatically installs patches on endpoints
Explanation: This question assesses knowledge of endpoint management infrastructure components. The scenario requires centralized deployment of approved patches with compliance reporting to support IT governance and security standards. An endpoint patch management system (A) provides these capabilities by maintaining a central repository of approved patches, deploying them according to defined schedules, and generating compliance reports showing patch status across all managed devices. Network hubs (B) broadcast traffic but don't distribute software updates intelligently. Floppy disk distribution (C) is an obsolete, manual, and unreliable method for modern patching. Document retention policies (D) govern information lifecycle but don't install software. For enterprise patch management, identify centralized systems that automate deployment, ensure consistency, and provide visibility into patch compliance across the endpoint population.
Question 5
As part of a system upgrade proposal, a public company evaluates performance issues in its data centre where multiple virtual machines run financial reporting applications on shared physical hosts. Management wants to increase computing capacity without purchasing separate physical servers for each application. Based on the scenario, which IT infrastructure component is the focus of this consolidation approach?
- A virtualization hypervisor that allows multiple virtual machines to run on the same physical server hardware (correct answer)
- A tape rotation schedule that determines how often backup tapes are reused
- A dot-matrix printer that produces multi-part forms for accounts payable
- A personal firewall installed on each user’s smartphone to block all internet access
Explanation: This question evaluates understanding of server virtualization technology in modern IT infrastructure. The scenario describes multiple applications running on shared physical hosts with a need to increase capacity without purchasing separate servers for each application. A virtualization hypervisor (A) enables this consolidation by abstracting physical hardware and allowing multiple virtual machines to share the same physical server resources efficiently. Tape rotation schedules (B) manage backup media lifecycle but don't address server consolidation. Dot-matrix printers (C) are legacy output devices unrelated to server capacity. Personal firewalls on smartphones (D) provide endpoint security but don't consolidate server workloads. When evaluating server infrastructure efficiency, recognize virtualization as the key technology enabling hardware consolidation, resource optimization, and rapid provisioning of new systems.
Question 6
During disaster recovery planning for a private company’s customer billing system, management wants near-real-time copies of critical data at a secondary site to reduce recovery point objectives. The environment includes database servers, storage arrays, and a dedicated network link between sites. Which component is essential to keep data synchronized between the primary and secondary locations?
- Data replication technology that continuously or frequently copies changed data to a secondary site (correct answer)
- A local printer queue that stores print jobs until a printer is available
- A compact cassette tape recorder used for manual data export
- A password rotation policy that copies database records to another site automatically
Explanation: This question evaluates understanding of data replication technologies for disaster recovery. The scenario requires near-real-time data synchronization between primary and secondary sites to minimize recovery point objectives for a billing system. Data replication technology (A) provides this capability through continuous or frequent copying of changed data blocks or database transactions to the secondary site, ensuring minimal data loss if failover is required. Printer queues (B) temporarily store print jobs but don't replicate data between sites. Cassette tape recorders (C) are obsolete manual recording devices unsuitable for automated replication. Password rotation policies (D) enhance security but don't copy data between locations. For disaster recovery with aggressive recovery point objectives, identify real-time or near-real-time replication as essential for maintaining synchronized data copies across sites.
Question 7
A private company performs an IT efficiency evaluation and finds that employees spend significant time searching for the latest versions of policies and procedures stored across shared drives. Management wants a centralized platform with version control and access permissions to improve document management and reduce duplication. Which component is essential to support this improvement?
- A document management system that centralizes files with version control, permissions, and search capabilities (correct answer)
- A network switch that stores document versions in its routing table
- A legacy magnetic tape drive used as the primary location for daily document editing
- A password policy that automatically merges duplicate documents across all folders
Explanation: This question tests understanding of content management infrastructure components. The scenario describes inefficient document management with employees struggling to find current versions across multiple shared drives, requiring centralization with version control and permissions. A document management system (A) provides these capabilities through a centralized repository that maintains version history, enforces access permissions, enables full-text search, and prevents duplication through check-in/check-out workflows. Network switches (B) forward packets but don't store documents or manage versions. Magnetic tape drives (C) provide sequential access unsuitable for daily document editing. Password policies (D) enforce authentication requirements but don't merge documents. For improving document management efficiency, identify dedicated systems that centralize content, automate version control, and provide structured access to organizational knowledge.
Question 8
In a system upgrade proposal for a nonprofit, the IT team reviews aging on-premises servers that host the donor database and internal file shares. The servers are approaching end-of-support, increasing operational risk and limiting the ability to apply security patches in line with governance expectations. Based on the scenario, which IT infrastructure component needs upgrading?
- The server operating system platform on the on-premises servers to ensure vendor support and security patching (correct answer)
- A word processing template used for donor thank-you letters
- A floppy disk inventory used for historical data transfers
- A manual sign-in sheet at reception used to track visitors
Explanation: This question assesses knowledge of IT infrastructure lifecycle management, specifically server operating system components. The scenario describes aging servers approaching end-of-support, which increases operational risk and prevents security patching per governance requirements. The server operating system platform (A) is the component needing upgrade because unsupported operating systems cannot receive critical security updates, exposing the organization to vulnerabilities. Word processing templates (B) support document creation but aren't infrastructure components. Floppy disk inventories (C) track obsolete media unrelated to server support. Manual sign-in sheets (D) provide physical access logs but don't affect server patching. When evaluating infrastructure upgrade needs, prioritize components reaching end-of-support status as they pose significant security and compliance risks.
Question 9
A government agency conducts an IT security assessment and identifies that staff frequently reuse passwords across systems. Management wants to reduce account takeover risk by enforcing additional verification during sign-in and by requiring stronger credential handling. Which IT infrastructure component is most vulnerable to security threats if it is misconfigured or not properly protected, given it stores and validates user credentials for many systems?
- A directory service controller that centralizes authentication and authorization for multiple systems (correct answer)
- A network printer that produces physical copies of reports
- A compact disc (CD) jukebox used for long-term archival storage
- A workstation wallpaper policy that enforces encryption for all user accounts
Explanation: This question assesses understanding of authentication infrastructure vulnerabilities and security risks. The scenario identifies password reuse across systems and asks which component is most vulnerable if misconfigured, given its role in storing and validating credentials for multiple systems. A directory service controller (A) like Active Directory Domain Controller is indeed the most critical component because it centralizes authentication for many systems - if compromised, attackers gain access to all integrated applications. Network printers (B) produce output but don't store authentication credentials. CD jukeboxes (C) provide archival storage without authentication functions. Wallpaper policies (D) standardize desktop appearance but don't enforce encryption or manage accounts. When assessing authentication infrastructure risks, recognize directory service controllers as high-value targets requiring stringent security controls due to their central role in enterprise authentication.
Question 10
As part of an IT security assessment of a public company, the auditor notes that users connect from home to access internal finance applications hosted on the corporate network. Management wants an encrypted tunnel over the internet so remote traffic is protected in transit and access is controlled according to security policies. Which component is essential for providing this secure remote connectivity?
- A virtual private network (VPN) gateway that encrypts remote connections and authenticates users before network access (correct answer)
- A network hub that broadcasts remote traffic to all internal devices
- A fax machine that transmits login credentials securely over phone lines
- A local printer spooler that encrypts all internet traffic by default
Explanation: This question tests understanding of secure remote access technologies in IT infrastructure. The scenario requires encrypted connections for remote users accessing internal applications over the internet with controlled access per security policies. A VPN gateway (A) provides this capability by creating encrypted tunnels between remote devices and the corporate network, authenticating users before granting access and applying security policies. Network hubs (B) broadcast traffic locally without encryption or remote access capabilities. Fax machines (C) transmit documents over phone lines but don't secure network connections. Printer spoolers (D) queue print jobs locally without encrypting internet traffic. When implementing secure remote access, identify VPN technology as the standard solution for creating encrypted connections over untrusted networks while maintaining access controls.
Question 11
As part of a system upgrade proposal, a nonprofit reviews its internet connectivity because video meetings and cloud-based finance applications frequently drop during peak hours. Management wants a more reliable and higher-capacity connection to support business operations and reduce downtime risk. Based on the scenario, which IT infrastructure component needs upgrading?
- The wide area network (WAN) internet circuit bandwidth to support higher volumes of cloud and collaboration traffic (correct answer)
- A local keyboard and mouse set used by the accounting team
- A legacy dial-up connection as the primary method for modern cloud access
- A paper filing cabinet used for storing printed invoices
Explanation: This question tests understanding of network infrastructure capacity planning. The scenario describes insufficient internet bandwidth causing video meetings and cloud applications to drop during peak usage, requiring a more reliable, higher-capacity connection. The WAN internet circuit bandwidth (A) is the component needing upgrade because modern cloud services and video collaboration require significantly more bandwidth than legacy applications, and insufficient capacity directly causes the described service disruptions. Keyboards and mice (B) are local input devices unrelated to network capacity. Dial-up connections (C) provide extremely limited bandwidth unsuitable for cloud access. Paper filing cabinets (D) store physical documents without affecting network performance. When evaluating connectivity upgrades, assess bandwidth requirements for cloud services, video conferencing, and concurrent users to determine appropriate circuit capacity.
Question 12
During an IT efficiency evaluation at a nonprofit, users report frequent delays when accessing an internal web application. The application is hosted on multiple identical web servers, and management wants to distribute incoming requests to improve performance and reduce single points of failure. Which component is essential for distributing this traffic across servers?
- A load balancer that routes incoming application requests across multiple servers based on defined rules (correct answer)
- A tape vaulting service that stores backup media offsite
- A legacy serial port switch that increases internet bandwidth
- A password manager that automatically assigns IP addresses to servers
Explanation: This question evaluates understanding of load balancing technology in IT infrastructure. The scenario describes a web application hosted on multiple servers experiencing performance issues, requiring traffic distribution to improve response times and eliminate single points of failure. A load balancer (A) provides this functionality by intelligently routing incoming requests across available servers based on algorithms like round-robin, least connections, or server health. Tape vaulting services (B) store backup media offsite but don't distribute application traffic. Serial port switches (C) are legacy connectivity devices unrelated to internet bandwidth or load distribution. Password managers (D) store credentials but don't assign IP addresses or route traffic. When designing scalable application architectures, recognize load balancers as essential components for distributing workloads, improving performance, and providing failover capabilities.
Question 13
A private company is performing disaster recovery planning for its on-premises enterprise resource planning (ERP) system hosted on virtual machines. The ERP database must be recoverable to a consistent point in time after an outage, with minimal data loss, in accordance with IT governance requirements. Which component is essential to support point-in-time recovery for the database?
- Database transaction log backups that record changes and enable recovery to a specific point in time (correct answer)
- A domain name system server that resolves hostnames for internal applications
- A network hub that connects multiple devices on the same local network segment
- A screen-saver timeout policy that locks user workstations after inactivity
Explanation: This question evaluates knowledge of database recovery components in disaster recovery planning. The scenario requires point-in-time recovery capability for an ERP database with minimal data loss, which is a fundamental disaster recovery requirement. Database transaction log backups (A) record all database changes sequentially, enabling administrators to restore to any specific point in time by replaying transactions after restoring a full backup. DNS servers (B) resolve network names but don't provide database recovery capabilities. Network hubs (C) are basic connectivity devices without recovery functions. Screen-saver policies (D) provide workstation security but don't support database recovery. For disaster recovery planning, prioritize components that capture incremental changes and enable granular recovery points, particularly transaction logs for database systems requiring consistent state recovery.
Question 14
A government agency is completing disaster recovery planning for a critical case management system. The system must continue operating even if one physical server fails, and the agency wants automatic failover with minimal downtime to meet availability objectives. Which IT infrastructure component is essential to provide this high-availability capability?
- A server cluster that provides redundancy and automatic failover between nodes (correct answer)
- A single external hard drive connected by USB for occasional manual backups
- A legacy coaxial network that reduces the need for redundant servers
- A data classification label that prevents hardware failures through policy enforcement
Explanation: This question evaluates knowledge of high-availability infrastructure components for critical systems. The scenario requires automatic failover capability with minimal downtime when a physical server fails, which is essential for meeting availability objectives. A server cluster (A) provides this redundancy by connecting multiple nodes that monitor each other's health and automatically transfer workloads when failures occur. Single external USB drives (B) provide basic backup storage but no automatic failover. Legacy coaxial networks (C) are outdated cable technologies that don't provide server redundancy. Data classification labels (D) categorize information sensitivity but don't prevent hardware failures. For high-availability requirements, identify clustering technologies that provide active-active or active-passive configurations with automatic failover capabilities to minimize service disruptions.
Question 15
During an IT infrastructure audit of a private company, the auditor evaluates how system changes are tested and deployed to production. Management wants a controlled environment that mirrors production so patches and configuration changes can be validated before release, supporting IT governance and change management practices. Which component is essential for this purpose?
- A non-production test environment that replicates production configurations for validating changes before deployment (correct answer)
- A shared mailbox that stores copies of change requests
- A legacy parallel-port dongle that prevents unauthorized code changes
- A desktop shortcut that automatically approves change tickets
Explanation: This question evaluates understanding of change management infrastructure components. The scenario requires a controlled environment mirroring production for validating patches and changes before deployment, supporting IT governance and change management practices. A non-production test environment (A) provides this capability by replicating production configurations in an isolated setting where changes can be thoroughly tested without affecting live systems. Shared mailboxes (B) store communications but don't provide test environments. Parallel-port dongles (C) are legacy hardware keys unrelated to change testing. Desktop shortcuts (D) provide quick access but don't approve changes. For effective change management, recognize test environments as essential infrastructure components that reduce deployment risks by validating changes in production-like conditions before release.
Question 16
During an IT infrastructure audit of a nonprofit, the auditor observes that application servers and database servers share the same network segment as employee workstations. Management wants to reduce the risk of unauthorized lateral movement by separating systems into distinct network zones while maintaining controlled connectivity. Which infrastructure component is essential for creating these logical network separations?
- Virtual local area networks (VLANs) that logically segment a network into separate broadcast domains (correct answer)
- A screen capture tool that records user activity during training sessions
- A floppy disk drive used to transfer configuration files between servers
- A password complexity policy that automatically encrypts all network traffic
Explanation: This question assesses understanding of network segmentation technologies in IT infrastructure security. The scenario identifies a flat network where servers and workstations share the same segment, creating lateral movement risks that management wants to mitigate through logical separation. Virtual Local Area Networks (VLANs) (A) provide this capability by creating separate broadcast domains at Layer 2, allowing administrators to group devices logically regardless of physical location while controlling inter-VLAN routing. Screen capture tools (B) record user activity but don't segment networks. Floppy disk drives (C) are obsolete storage devices unrelated to network segmentation. Password policies (D) enforce credential strength but don't create network separations or encrypt traffic. When designing secure network architectures, recognize VLANs as the fundamental technology for creating logical network boundaries that limit broadcast domains and enable controlled communication between segments.
Question 17
In an IT security assessment at a public company, the auditor reviews controls over sensitive financial data stored on a shared file server. Management wants to ensure that even if the storage media is removed or stolen, the data remains unreadable without proper authorization. Which component is essential for protecting data in this scenario?
- Full-disk or volume encryption that renders stored data unreadable without the encryption key (correct answer)
- A content delivery network that accelerates website performance for external users
- A hub that repeats network signals to all connected devices
- A printer access log that automatically patches server operating systems
Explanation: This question tests understanding of data-at-rest encryption as a security control in IT infrastructure. The scenario requires protecting sensitive financial data stored on file servers against physical theft or unauthorized access to storage media. Full-disk or volume encryption (A) addresses this requirement by rendering all stored data unreadable without the proper encryption key, providing protection even if drives are physically removed. Content delivery networks (B) optimize web performance but don't encrypt stored data. Network hubs (C) broadcast signals without encryption capabilities. Printer access logs (D) track usage but don't patch systems or encrypt data. When implementing data protection controls, recognize encryption at rest as the primary safeguard against unauthorized access to data on stolen or improperly disposed storage media.
Question 18
In an IT security assessment of a public company’s email environment, management is concerned about malicious attachments and phishing links reaching users. They want a control that scans and filters inbound email content before it is delivered to mailboxes, supporting the organization’s security framework. Which component is essential for this function?
- An email security gateway that filters and scans inbound messages for malware and phishing indicators (correct answer)
- A file compression utility that reduces the size of email attachments
- A legacy pager system that alerts users to new emails
- A network switch that automatically quarantines suspicious emails in user inboxes
Explanation: This question assesses knowledge of email security infrastructure components. The scenario requires filtering malicious attachments and phishing links before they reach user mailboxes, supporting the organization's security framework. An email security gateway (A) provides this functionality by scanning inbound messages for malware signatures, suspicious attachments, and phishing indicators, quarantining or blocking threats before delivery. File compression utilities (B) reduce attachment sizes but don't scan for threats. Pager systems (C) provide notifications but don't filter email content. Network switches (D) forward network traffic but don't analyze email content or quarantine messages. For email security architecture, identify dedicated email security gateways as the primary defense against email-borne threats, positioned between the internet and internal mail servers.
Question 19
A government agency is conducting an IT security assessment of its public-facing permit application portal hosted in a demilitarized zone (DMZ). The agency wants to reduce the risk of internet-based attacks by filtering inbound and outbound traffic based on defined rules and logging blocked connections. Which IT infrastructure component is most directly responsible for this traffic filtering function?
- A firewall that enforces network access rules by allowing or blocking traffic between network zones (correct answer)
- A file server that stores user documents on shared folders
- A fax modem that transmits scanned forms over analog phone lines
- A spreadsheet macro that automates monthly reporting tasks
Explanation: This question assesses knowledge of network security components, specifically perimeter defense mechanisms. The scenario describes a public-facing application in a DMZ requiring protection from internet-based attacks through traffic filtering and logging. A firewall (A) is the primary infrastructure component designed for this purpose, enforcing network access rules by inspecting packets and allowing or blocking traffic based on configured policies while maintaining detailed logs. File servers (B) store documents but don't filter network traffic. Fax modems (C) transmit documents over phone lines without network security functions. Spreadsheet macros (D) automate calculations within applications but don't control network traffic. For network security architecture, recognize that firewalls serve as the fundamental enforcement point for traffic filtering between network zones, particularly at internet boundaries.
Question 20
During disaster recovery planning for a private company, management wants to ensure critical systems can be restored even if the primary data centre is unavailable. They plan to keep copies of backups in a separate geographic location to reduce the impact of a local disaster. Which component is essential to meet this offsite recovery requirement?
- Offsite backup storage (such as a secure cloud repository or secondary site) that holds backup copies outside the primary location (correct answer)
- A local recycle bin on each workstation for deleted files
- A legacy token-based ring network that prevents natural disasters
- A spreadsheet access password that replaces the need for backups
Explanation: This question evaluates knowledge of disaster recovery infrastructure components, specifically offsite backup strategies. The scenario requires backup copies in a separate geographic location to enable recovery if the primary data center is unavailable due to local disaster. Offsite backup storage (A) such as cloud repositories or secondary sites directly addresses this requirement by maintaining backup copies outside the primary location's disaster impact zone. Local recycle bins (B) only store recently deleted files on individual workstations without offsite protection. Token-ring networks (C) are obsolete LAN technologies that cannot prevent disasters. Spreadsheet passwords (D) control file access but don't replace backup requirements. For comprehensive disaster recovery, recognize offsite backup storage as essential for protecting against site-wide disasters and ensuring business continuity.