Question 1
What is a security control?
Correct Answer:
Measures used to reduce risks and protect assets
Explanation:
A security control refers to measures that are implemented to reduce risks and to protect assets within an organization. This can encompass a wide array of strategies, tools, protocols, and practices that are designed to mitigate potential threats and vulnerabilities. By defining a security control in this way, it becomes clear that its main purpose is to safeguard information and technology assets from various types of security risks, including unauthorized access, data breaches, and other malicious activities. Controls can be technical (like firewalls and encryption), administrative (like policies and procedures), or physical (like surveillance systems and locks). The other choices do not accurately capture the essence of a security control. Gathering information through software does not inherently relate to risk mitigation or asset protection. Procedures enhancing physical security represent a subset of security controls but do not encompass the broader concept. Lastly, a specific type of malware does not qualify as a security control; rather, it constitutes a threat that security controls would aim to defend against. Thus, the selection that correctly embodies what a security control is, highlights the preventative measures taken to safeguard valuable resources.
Question 2
A threat actor exploits vulnerabilities in a device's wireless protocol to send a malicious file. This describes which networking vector?
Correct Answer:
Bluetooth Network
Explanation:
The scenario describes a situation where a threat actor exploits vulnerabilities within a device’s wireless protocol. Bluetooth networks are characterized by short-range wireless communications and are often susceptible to a variety of attacks, such as unauthorized access or the transmission of malicious files. These vulnerabilities can arise from weaknesses in the Bluetooth protocol itself or flaws in the implementation on devices. Hence, when considering which networking vector is being utilized to send a malicious file through exploitation, Bluetooth is the most fitting answer, as it aligns directly with scenarios involving file transfers and wireless protocol vulnerabilities. In contrast, Wi-Fi typically involves a different set of vulnerabilities and attack vectors, mainly focused on access points and broader range communications. Cellular networks have their own set of protocols and vulnerabilities, emphasizing mobile data transmission security, while VPN networks are designed to secure communications over public networks and primarily protect data rather than serve as a vector for exploiting devices. Thus, the Bluetooth Network is accurately identified as the networking vector involved in this specific malicious activity.
Question 3
What is the primary objective of vulnerability scanning?
Correct Answer:
To identify vulnerabilities in systems and applications before they can be exploited
Explanation:
The primary objective of vulnerability scanning is to identify vulnerabilities in systems and applications before they can be exploited. This process involves using automated tools to scan networks, servers, and applications for known weaknesses, misconfigurations, or outdated software that could be targeted by attackers. By identifying these vulnerabilities early, organizations can take proactive measures to remediate the issues, thereby strengthening their security posture and reducing the risk of potential security breaches. While enhancing user training and awareness, monitoring network traffic, and installing security patches are important components of an overall security strategy, they do not directly represent the primary goal of vulnerability scanning. The focus of vulnerability scanning is specifically on detection and assessment of security weaknesses, making option B the most accurate and relevant choice in this context.
Question 4
A prominent corporation has experienced a spike in unauthorized network traffic aimed at its web servers after a controversial policy decision. Which type of attacker is MOST likely responsible?
Correct Answer:
Hacktivist
Explanation:
The most likely responsible party for the spike in unauthorized network traffic aimed at the corporation's web servers, following a controversial policy decision, is a hacktivist. Hacktivists are individuals or groups that use hacking techniques to promote political agendas or social change. They typically engage in attacks to raise awareness, make a statement, or protest against specific actions or policies that they oppose. In this scenario, the link between the controversial policy decision and the increase in unauthorized traffic suggests that the intent behind the attack is likely to voice dissent or disrupt the operations of the organization in response to that decision. Hacktivists often target organizations they believe are engaging in unethical practices or policies, making them a fitting explanation for the observed activity. Other types of attackers, such as script kiddies, typically perform attacks using pre-written scripts without a nuanced understanding of the implications or motivations. Insider threats involve individuals from within the organization, which does not align with the notion of a widespread spike in network traffic affecting external web servers facing public scrutiny. Competitors may engage in unethical practices to undermine others, but their methods tend to focus on gaining an advantage rather than expressing ideological opposition. Thus, the nature of the attack points strongly toward a hacktivist motive.
Question 5
What is a common reason employees choose to use rooted smartphones?
Correct Answer:
For increased control over their devices
Explanation:
Employees often opt for rooted smartphones primarily to gain increased control over their devices. Rooted smartphones allow users to access the system files and settings that are typically restricted on standard devices. This can enable employees to customize their smartphone experience, install software that is not available through official channels, and adjust settings to their specific needs for better functionality. Such control can lead to greater customization, allowing for personalized app installations, removal of bloatware, and modification of user interfaces. This can ultimately cater to the users' preferences and enhance their overall experience with the device. While other options may seem relevant, the primary motivator for using rooted devices tends to focus more on the autonomy and customization that comes with it rather than on corporate security, compliance, or performance enhancements.
Question 1
Exam overview

About this Exam

The Threats, Vulnerabilities, and Mitigations Assessment (Domain 2.0) is a pivotal assessment designed for cybersecurity professionals seeking to validate their practical knowledge and ability to defend an organization's digital infrastructure. It focuses on the core principles required to proactively identify potential security gaps, analyze the attack surface, and deploy effective countermeasures before exploitation occurs.

This exam is designed for individuals in roles such as IT Security Analysts, Vulnerability Management Specialists, Incident Response Personnel, System Administrators, and any security practitioner tasked with understanding the theoretical foundations of modern threats and the technical implementation of security controls. This certification helps professionals prove they possess the requisite skills to maintain a robust security posture in an increasingly complex threat landscape.

More details

Additional Information

What the Course Entails and Exam Details

This intensive course and assessment delve into a comprehensive curriculum focused on the entire lifecycle of risk management from an operational security perspective. Candidates will master techniques for threat intelligence analysis, learning to decode the methodologies, motivations, and tools used by modern threat actors, ranging from script kiddies to nation-state adversaries.

The syllabus covers rigorous vulnerability assessment processes, including configuring and interpreting results from industry-standard scanning tools, distinguishing between false positives and critical risks, and applying CVSS (Common Vulnerability Scoring System) metrics to prioritize remediation efforts. Crucially, the exam requires candidates to demonstrate hands-on competence in selecting, implementing, and validating effective mitigation strategies, whether through technical controls (like firewall rules, IPS signatures, and endpoint protection), administrative policies, or physical security measures.

 

 

 What to Expect in the Final Exam

The Threats, Vulnerabilities, and Mitigations (Domain 2.0) Final Exam is typically a comprehensive, computer-based assessment. While the exact composition may vary depending on the parent certification provider, it is generally structured to test both theoretical knowledge and practical application under pressure.

Candidates can expect a challenging combination of two main question types:

  • Multiple-Choice Questions: These test your recall and understanding of foundational security concepts, frameworks, and procedures.
  • Performance-Based Questions (PBQs): These are dynamic, immersive scenarios where you must perform tasks in a simulated environment—for example, analyzing a vulnerability scan report to recommend the most efficient patching strategy, configuring a secure network architecture, or modifying access controls to mitigate a specific threat.

You will have a strict time limit, often between 90 to 120 minutes, to complete all questions, making time management a critical factor. The passing score is determined by the certifying body and is calculated on a scaled score, frequently requiring a score of around 700 to 750 on a scale of 100-900. The exam is proctored, either in person or via a secure online testing environment, demanding strict adherence to ID requirements and anti-cheating protocols.

 

How to Study and Exam Centers

Preparation for this rigorous exam requires a blend of structured learning, practical application, and intense practice.

  • Understand the Objectives: Start with the official exam blueprint or objectives list. This is your roadmap, detailing exactly what you need to know.
  • Hands-on Labs are Critical: Don't just read. Set up virtual lab environments to get hands-on experience. Practice running vulnerability scans (using tools like Nessus or OpenVAS), analyze traffic (Wireshark), and configure security controls on both Windows and Linux systems.
  • Utilize Varied Resources: Combine comprehensive study guides with video courses (such as those from reputable providers like ITProTV, Cybrary, or official training partners).
  • Intense Practice Testing: Leverage high-quality practice exams like the ones offered here, featuring flashcards and multiple-choice questions. These are not just for memorization; utilize the detailed explanations and hints to understand the reasoning behind both correct and incorrect answers to solidify your understanding of complex scenarios.

Where to Take the Exam:

You can typically take this exam at an authorized test center or through an online proctored environment. Major certifying bodies partner with global testing vendors like Pearson VUE, which provides access to thousands of physical testing locations worldwide. Alternatively, for greater convenience, you can opt for online proctoring, allowing you to take the test from your home or office using your webcam and microphone, provided you have a stable internet connection and a secure, private room.

 

 

 Job Opportunities from the Course

Successfully completing this domain assessment validates a key skillset in demand across nearly every sector. Cybersecurity professionals who possess specialized knowledge in threats, vulnerabilities, and mitigations are uniquely positioned for critical roles in digital defense.

Completion of this assessment can unlock or accelerate career paths for the following job titles:

  • Cyber Security Analyst / Information Security Analyst
  • Vulnerability Assessment Specialist
  • Vulnerability Management Engineer
  • Incident Responder / SOC (Security Operations Center) Analyst
  • Security Engineer
  • Network Security Administrator
  • Threat Intelligence Analyst
  • Compliance Analyst (focusing on technical controls)
  • Security Architect (as a foundational skill set)
  • Penetration Tester (understanding defense to improve offense)

 

Quiz information

Frequently Asked Questions

The complete question count is available after full access is unlocked.
No fixed duration is currently configured for this quiz.
Question explanations are included where they are available in the quiz content, helping you review the reasoning after answering.
Yes. You can retake the practice test again as you continue studying during your available access period.
After your access is confirmed, you can continue into the complete practice exam from this quiz flow.
Unless explicitly stated otherwise, this page provides independent practice material for study and exam preparation and is not the official examination itself.
Keep studying

Related Questions