HomeSecurityX Test PrepQuestions 21–30
SecurityX Test PrepPart 3 of 3

SecurityX Test Prep Exam Questions & Answers 2026 (21–30)

SecurityX Test Prep practice questions and answers 2026. Tap an option to test yourself — you'll see the correct answer and a plain-English explanation for every question. Free, no login.

Practise SecurityX Test Prep questions free, download the PDF, or unlock timed mock exams when you are ready.
Multiple choice — pick the best answer, then reveal it
  1. Q21An online retail company seeks to ensure that external payment processing services can securely and effectively handle customer transactions. This system must define how payment requests will be sent and how confirmations will be received. What type of solution will allow for this?

    • AProxy server
    • BAPI gateway
    • CFirewall
    • DLoad balancer
    Show answer

    ✓ Correct answer: B. API gateway

    Answer: API gateway An Application Programming Interface (API) gateway handles interactions between different types of systems. An API gateway can be used to manage API calls from external sources, such as payment processing services, and securely facilitates the sending of requests and receiving of confirmations. A firewall is a security device that monitors and controls incoming and outgoing network traffic. A load balancer distributes network or application traffic across multiple servers. A proxy server acts as an intermediary for requests from clients seeking resources from other servers.

  2. Q22Where can firewall devices be strategically placed within a corporate network?

    • AAt the network perimeter and at key internal segment points
    • BOnly at the network perimeter, not at internal segments
    • COnly at key internal segment points, not at the network perimeter
    • DAt the network perimeter or internal segments, but not both
    Show answer

    ✓ Correct answer: A. At the network perimeter and at key internal segment points

    Answer: At the network perimeter and at key internal segment points Firewalls are essential for protecting a corporate network. They should be positioned at both the network perimeter to guard against external threats and at key internal segments to monitor and control traffic within the network.

  3. Q23Which of the following is NOT one of the principles of the Zero Trust security model?

    • AVerify explicitly
    • BLeast privilege principle
    • COpen access networks
    • DAssume breach
    Show answer

    ✓ Correct answer: C. Open access networks

    Answer: Open access networks The principles of the Zero Trust security model include assume breach, verify explicitly, and least privilege. Open access networks are not a principle of the Zero Trust security model.

  4. Q24An organization needs to ensure secure communication between their data center and branch offices. What solution should they implement to achieve this?

    • ARemote access VPN
    • BNetwork Access Control (NAC)
    • CNetwork Address Translation (NAT)
    • DSite-to-site VPN
    Show answer

    ✓ Correct answer: D. Site-to-site VPN

    Answer: Site-to-site VPN A site-to-site VPN connects separate networks over the internet to function as a single network. This provides a secure, encrypted connection for data transfer. A remote access VPN is typically used to create a secure tunnel for individual users to connect to an internal network. Network Access Control (NAC) manages authorization of devices before connection, while Network Address Translation (NAT) allows multiple devices on a local network to access external networks using a single public IP address.

  5. Q25How is information about the structure of a file, such as permissions or owner, described in a Linux file system?

    • AMapping data
    • BMetadata
    • CSuperdata
    • DXOR data
    Show answer

    ✓ Correct answer: B. Metadata

    Answer: Metadata. Metadata provides information about the structure and attributes of a file, such as permissions, owner, and timestamps in a Linux file system. Superdata and XOR data are non-existent terms used as distractors.

  6. Q26What is the default port used by SSH?

    • A22
    • B80
    • C21
    • D443
    Show answer

    ✓ Correct answer: A. 22

    Answer: 22. By default, SSH (Secure Shell) uses port 22. Port 80 is used for HTTP, port 21 is used for FTP, and port 443 is used for HTTPS.

  7. Q27Which file transfer protocol is both platform-independent and capable of securely transferring files over a network?

    • ATFTP
    • BHTTP
    • CSFTP
    • DFTP
    Show answer

    ✓ Correct answer: C. SFTP

    Answer: SFTP SFTP (SSH File Transfer Protocol) is a secure and platform-independent method for transferring files over a network, as it leverages SSH (Secure Shell) for encryption. FTP (File Transfer Protocol) lacks inherent security features and generally operates without encryption. TFTP (Trivial File Transfer Protocol) is a simplified version of FTP without authentication and encryption mechanisms. HTTP (HyperText Transfer Protocol) is primarily used for transferring web pages and data over the web but lacks specific focus on secure file transfers.

  8. Q28Your organization is preparing for an annual compliance audit. The compliance officer has requested you to document the current compliance status, identify areas where compliance is not met, and suggest remedies to ensure full compliance before the audit date. Which of the following should you do to meet this objective?

    • AExecute MTBF analysis
    • BExecute MTTR analysis
    • CPerform a compliance gap analysis
    • DConduct a revenue audit based on GAAP
    Show answer

    ✓ Correct answer: C. Perform a compliance gap analysis

    Answer: Perform a compliance gap analysis A compliance gap analysis identifies the current state of compliance, desired compliance state, and necessary steps to achieve full compliance. GAAP (Generally Accepted Accounting Principles) is not directly relevant to the compliance audit preparation. MTBF (Mean Time Between Failures) and MTTR (Mean Time to Repair) analyses are distractors and do not directly address compliance requirements.

  9. Q29BetaTech Ltd. and GammaSolutions Co. are unable to finalize a binding contract for their joint project. Instead, they draft a document, signed by representatives from both companies, outlining the terms and expectations. What is this type of document called?

    • AService level agreement
    • BOperation level agreement
    • CMemorandum of understanding
    • DInterconnection security agreement
    Show answer

    ✓ Correct answer: C. Memorandum of understanding

    Answer: Memorandum of understanding An MOU (memorandum of understanding) is an agreement between multiple parties that is often non-binding, but formally details a shared understanding or agreement. An ISA (interconnection security agreement) is a specific telecommunications contract related to network connections. An OLA (operation level agreement) is an agreement about responsibilities between different support teams. An SLA (service level agreement) is a minimum guaranteed service level a provider commits to. For example, an SLA may specify 99.9% uptime and 1-hour support response times.

  10. Q30In the context of cybersecurity risk management, what does SLE stand for?

    • ASingle Loss Event
    • BSecurity Level Expense
    • CSecurity Loss Estimate
    • DSingle Loss Expectancy
    Show answer

    ✓ Correct answer: D. Single Loss Expectancy

    Answer: Single Loss Expectancy The single loss expectancy (SLE) is a measure of the monetary loss or impact of a single occurrence of a threat. It is often used in risk assessments to estimate the potential financial impact of security incidents.

Free practice here. Timed mocks when you are ready.

Use the free SecurityX Test Prep sample, download the PDF, then unlock web-based timed mock exams for a full exam rehearsal.