212-82 Sample Questions

212-82 Sample Questions & Answers

Administrative, physical, and technical network security controls take the biggest share, next to identifying threats and attacks, securing applications and the cloud, wireless and mobile devices, cryptography, and watching traffic and logs.

Launch the full 212-82 simulator →

Showing 10 of 20 free samples.

  1. Question 1Intermediate

    Application Security and Cloud Computing · Application Security

    A developer is writing code for a web application's login page. To prevent a common web vulnerability, the developer ensures that the application's response to a failed login attempt is identical whether the username is valid or invalid. Which specific attack is this practice designed to mitigate?

    Show answer & explanation

    Correct answer: C

    This practice mitigates username enumeration (or user enumeration). If an application responds differently to an invalid username ('User not found') versus an invalid password ('Incorrect password'), an attacker can use this difference to build a list of valid usernames. By providing a generic error message ('Invalid username or password') in all failure cases, the application prevents attackers from discovering valid user accounts.

  2. Question 2Beginner

    Application Security and Cloud Computing · Virtualization and Cloud Computing

    True or False: In a cloud Infrastructure as a Service (IaaS) model, the cloud provider is responsible for patching the operating systems of the virtual machines deployed by the customer.

    Show answer & explanation

    Correct answer: B

    This statement is false. According to the shared responsibility model for IaaS, the cloud provider is responsible for the security of the cloud (i.e., the physical infrastructure, virtualization layer). The customer is responsible for security in the cloud, which includes securing and patching the guest operating systems, applications, and data they deploy on the infrastructure.

  3. Question 3Advanced

    Network Security Controls · Network Security Assessment Techniques and Tools

    A security analyst is reviewing firewall logs and notices a large volume of inbound traffic from a known malicious IP address has been blocked. The firewall rule that blocked the traffic was automatically created earlier that day. Which security technology MOST likely provided the threat data and instructed the firewall to create the rule?

    Show answer & explanation

    Correct answer: B

    A Threat Intelligence Platform (TIP) aggregates, correlates, and analyzes threat data from multiple sources. Modern TIPs can integrate with other security tools like firewalls and SIEMs to automate defensive actions, such as automatically creating firewall rules to block newly identified malicious IP addresses. A honeypot is a decoy system. A load balancer distributes traffic. A vulnerability scanner identifies potential weaknesses but does not typically automate firewall rule creation in this manner.

  4. Question 4Advanced

    Wireless Device Security · IoT and OT Security

    A hospital is deploying a new network of IoT medical devices (infusion pumps) that must communicate with a central server. These devices have limited processing power and do not support enterprise-grade authentication protocols like 802.1X. The security technician needs to secure the wireless network for these devices while preventing unauthorized connections. Which of the following is the most appropriate security measure in this scenario?

    Show answer & explanation

    Correct answer: C

    Given that the IoT devices do not support enterprise authentication, using WPA2 or WPA3-Personal with a very strong, complex preshared key is the best available encryption option. To add another layer of security, the network should be on a separate, isolated VLAN, and MAC address filtering should be enabled to only allow the specific medical devices to connect. While MAC filtering can be spoofed, it provides a deterrent and is a valid part of a defense-in-depth strategy for limited-capability devices. Disabling SSID broadcast is a weak security measure (security by obscurity). WPA3-Enterprise is not supported by the devices.

  5. Question 5Intermediate

    Incident and Risk Management · Incident Response

    A company's incident response plan is based on the NIST framework. A security analyst has just finished isolating several compromised systems from the network to prevent the spread of a malware infection. According to the NIST incident response lifecycle, what is the IMMEDIATE next phase?

    Show answer & explanation

    Correct answer: C

    The act of isolating compromised systems is part of the Containment phase. According to the NIST incident response lifecycle (Preparation -> Detection & Analysis -> Containment -> Eradication & Recovery -> Post-Incident Activity), the phase immediately following Containment is Eradication & Recovery. This is where the analyst would remove the malware, patch vulnerabilities, and restore the systems to normal operation.

  6. Question 6Intermediate

    Network Security Controls · Network Security Controls - Technical Controls

    A cybersecurity technician needs to configure a system that will sit between the internal corporate network and an untrusted external network. This system should inspect all incoming and outgoing traffic, enforce access control policies, and hide the IP addresses of the internal clients. Which of the following should be implemented?

    Show answer & explanation

    Correct answer: A

    A firewall is the correct answer. It is a network security device that monitors and filters incoming and outgoing network traffic based on an organization's previously established security policies. It acts as a barrier between a trusted internal network and untrusted external networks. Modern firewalls also perform Network Address Translation (NAT) to hide internal IP addresses.

  7. Question 7Beginner

    Information Security Threats and Attacks · Information Security Attacks

    A user reports receiving a suspicious email that appears to be from their bank, asking them to click a link to verify their account details due to a security alert. The user notes that the email contains grammatical errors and the sender's email address is slightly different from the bank's official address. This is an example of which type of attack?

    Show answer & explanation

    Correct answer: B

    This is a classic example of a phishing attack. Phishing is a social engineering attack where attackers send fraudulent communications (typically email) that appear to come from a reputable source to trick individuals into revealing sensitive information, such as login credentials or credit card numbers. Vishing is voice phishing (via phone), smishing is SMS phishing, and whaling is phishing that targets high-profile executives.

  8. Question 8Intermediate

    Network Monitoring and Analysis · Network Troubleshooting

    A technician is troubleshooting an issue where users on a specific subnet cannot access the internet. The technician can ping the default gateway from an affected machine, but cannot ping an external IP address like 8.8.8.8. Pings to internal servers on other subnets are also failing. Which device is MOST likely misconfigured or has failed?

    Show answer & explanation

    Correct answer: C

    The default gateway (which is a router) is responsible for forwarding traffic between different subnets and to external networks like the internet. Since the user can ping the gateway's IP, it means local connectivity (Layer 2) on their subnet is working. The inability to reach anything beyond the local subnet points directly to a problem with the device that handles inter-subnet routing, which is the default gateway.

  9. Question 9Intermediate

    Wireless Device Security · Mobile Device Security

    An organization wants to implement a bring-your-own-device (BYOD) policy securely. The primary goal is to ensure that corporate data on personal devices is isolated and can be selectively wiped without affecting personal data. Which technology should be implemented to achieve this?

    Show answer & explanation

    Correct answer: C

    MDM with containerization is the best solution for BYOD security. Containerization creates a separate, encrypted, and managed 'container' on the device for all corporate apps and data. This allows the organization to enforce security policies (like PIN requirements, encryption) only within the container and perform a 'selective wipe' that removes only the corporate container, leaving personal data untouched. Full-device encryption protects all data but doesn't allow for selective wiping. A VPN secures data in transit but doesn't manage data at rest on the device.

  10. Question 10Intermediate

    Incident and Risk Management · Business Continuity and Disaster Recovery

    A company is defining its disaster recovery strategy. The business has determined that it can tolerate a maximum of 4 hours of downtime for its critical e-commerce application. Additionally, it cannot afford to lose more than 15 minutes of transaction data preceding an outage. How should these requirements be documented in the Business Impact Analysis (BIA)?

    Show answer & explanation

    Correct answer: B

    Recovery Time Objective (RTO) is the maximum tolerable duration of an outage. In this case, the company can tolerate 4 hours of downtime, so the RTO is 4 hours. Recovery Point Objective (RPO) is the maximum amount of data loss that can be tolerated, measured in time. The company cannot lose more than 15 minutes of data, so the RPO is 15 minutes. This dictates that backups must occur at least every 15 minutes.

Ready for the real thing?

The full 212-82 simulator has every exam-style question, timed mode, and instant scoring.

Go to the 212-82 simulator →