{"id":11805,"date":"2026-09-14T12:13:55","date_gmt":"2026-09-14T12:13:55","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=11805"},"modified":"2026-09-14T12:13:55","modified_gmt":"2026-09-14T12:13:55","slug":"microsoft-az-104-practice-test-questions-and-exam-dumps-part-17-q321-340","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-az-104-practice-test-questions-and-exam-dumps-part-17-q321-340\/","title":{"rendered":"Microsoft AZ-104 Practice Test Questions and Exam Dumps Part 17 (Q321\u2013340)"},"content":{"rendered":"<h2><b>View Full\u00a0<a href=\"https:\/\/www.examlabs.com\/az-104-exam-dumps\">Microsoft AZ-104 Exam Dumps<\/a>\u00a0and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 321<\/b><\/h3>\n<p><b>Which security solution collects and analyzes log data from multiple sources to identify potential security threats?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SIEM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VPN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HSM<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A security information and event management (SIEM) solution collects logs and security events from multiple systems, applications, servers, endpoints, and network devices. It then analyzes and correlates these events to identify suspicious patterns that may indicate an attack. Security teams can use SIEM platforms for real-time monitoring, alerting, investigation, and incident response. SIEM can also support compliance requirements by maintaining searchable security records. Proper configuration is important because excessive or poorly tuned logging can generate large numbers of false positives and make important security events harder to identify.<\/span><\/p>\n<h3><b>Question 322<\/b><\/h3>\n<p><b>Which attack repeatedly attempts different password combinations until the correct password is discovered?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Brute-force attack<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Phishing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DDoS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Man-in-the-middle<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A brute-force attack attempts to discover a password by systematically trying many possible combinations until the correct one is found. Attackers can automate this process using specialized tools and large password lists. The effectiveness of brute-force attacks depends on password complexity, authentication controls, and the number of attempts allowed. Organizations can reduce this risk through strong passwords, multifactor authentication, account lockout policies, rate limiting, and monitoring for repeated failed login attempts. Longer and more unique passwords make brute-force attacks significantly more difficult.<\/span><\/p>\n<h3><b>Question 323<\/b><\/h3>\n<p><b>Which security process determines what resources an authenticated user is permitted to access?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Authorization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Accounting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Identification<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Authorization determines which resources and actions an authenticated user is allowed to access. Authentication first verifies the identity of the user, while authorization determines what that user can do after their identity has been confirmed. For example, an employee may successfully authenticate but only have authorization to access specific files or applications. Authorization can be managed using roles, access control lists, permissions, and policies. Proper authorization supports least privilege by ensuring that users receive only the access required to perform their assigned responsibilities.<\/span><\/p>\n<h3><b>Question 324<\/b><\/h3>\n<p><b>Which part of AAA records and tracks what an authenticated user does on a system?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Authorization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Accounting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Availability<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Accounting is the third component of the AAA security framework and is responsible for recording user activities. It can track information such as login times, accessed resources, commands executed, data transfers, and administrative actions. These records help organizations investigate security incidents and determine who performed specific actions. Accounting also supports auditing, compliance, and accountability. Authentication verifies identity, while authorization determines permissions. Accounting completes the process by maintaining records of activities performed after a user has been authenticated and granted access.<\/span><\/p>\n<h3><b>Question 325<\/b><\/h3>\n<p><b>Which type of social engineering attack uses fraudulent text messages to trick users into revealing information or clicking malicious links?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vishing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Smishing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Pharming<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tailgating<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Smishing is a social engineering attack that uses SMS or other text messaging services to deceive victims. Attackers may impersonate banks, delivery companies, government agencies, employers, or other trusted organizations. The message may contain a malicious link, request account credentials, or ask the victim to provide financial information. Because mobile users may quickly respond to urgent messages, smishing can be highly effective. Users should independently verify unexpected requests and avoid clicking suspicious links. Multifactor authentication can also reduce the damage caused by stolen credentials.<\/span><\/p>\n<h3><b>Question 326<\/b><\/h3>\n<p><b>Which security technology monitors critical files and alerts administrators when unauthorized changes occur?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File integrity monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network load balancing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data masking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port forwarding<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">File integrity monitoring (FIM) tracks important files and system configurations and detects changes that may indicate unauthorized activity. It can identify modifications, deletions, or additions to files and compare them against an approved baseline. FIM is useful for detecting malware, unauthorized administrative activity, and configuration changes. When a monitored file changes unexpectedly, an alert can be generated for investigation. FIM is particularly valuable for servers containing sensitive information or critical applications because unauthorized file changes may indicate that a system has been compromised.<\/span><\/p>\n<h3><b>Question 327<\/b><\/h3>\n<p><b>Which type of malware is designed to hide its presence by modifying low-level system components?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Rootkit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Worm<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Adware<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Spyware<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A rootkit is malware designed to conceal its presence and maintain unauthorized access to a system. Rootkits can operate at different levels, including the operating system kernel, applications, or firmware. Because they are designed to remain hidden, detecting them can be difficult using traditional security tools. Attackers may use rootkits to hide malicious processes, files, network connections, or other activities. Organizations can reduce the risk through secure boot mechanisms, endpoint security, system integrity monitoring, patch management, and maintaining trusted system images for recovery.<\/span><\/p>\n<h3><b>Question 328<\/b><\/h3>\n<p><b>Which network security technique separates a network into smaller isolated sections to limit unauthorized access and lateral movement?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port mirroring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network segmentation divides a larger network into smaller isolated sections with controlled communication between them. Organizations can use segmentation to separate sensitive systems, user devices, servers, guest networks, and critical infrastructure. If an attacker compromises one segment, segmentation can make it more difficult to move laterally into other areas. Firewalls, VLANs, access control lists, and other technologies can enforce segmentation policies. Proper segmentation reduces the attack surface and limits the potential impact of a compromised account, endpoint, or application.<\/span><\/p>\n<h3><b>Question 329<\/b><\/h3>\n<p><b>Which type of cryptography uses separate public and private keys?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Symmetric encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Asymmetric encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hashing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Steganography<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Asymmetric encryption uses a pair of mathematically related keys: a public key and a private key. The public key can be distributed to other users, while the private key must remain protected. Asymmetric cryptography is commonly used for secure key exchange, digital signatures, and certificate-based authentication. It is generally slower than symmetric encryption, so secure communication systems often use asymmetric cryptography to establish a secure session and then use faster symmetric encryption for bulk data. Protecting private keys is essential to maintaining security.<\/span><\/p>\n<h3><b>Question 330<\/b><\/h3>\n<p><b>Which application security control allows only approved software to execute on an endpoint?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application allowlisting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">URL filtering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data retention<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Application allowlisting restricts software execution to applications that have been explicitly approved by an organization. When an unknown or unauthorized application attempts to run, the security control can prevent its execution. This helps protect endpoints against malware, unauthorized utilities, and potentially dangerous software. Allowlisting can be particularly useful on systems with predictable workloads, such as servers or specialized workstations. Administrators must maintain the approved list carefully so that legitimate applications and updates are not unnecessarily blocked while unauthorized software remains restricted.<\/span><\/p>\n<h3><b>Question 331<\/b><\/h3>\n<p><b>Which social engineering technique involves creating a fabricated scenario to persuade a victim to provide sensitive information?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Pretexting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shoulder surfing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dumpster diving<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tailgating<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Pretexting is a social engineering technique in which an attacker creates a believable story or scenario to manipulate a victim into providing information or performing an action. For example, an attacker may pretend to be a technical support employee and request a user&#8217;s password or verification code. The success of pretexting depends heavily on trust and psychological manipulation rather than technical exploitation. Security awareness training, identity verification procedures, and policies requiring employees to independently confirm unusual requests can help reduce the effectiveness of pretexting attacks.<\/span><\/p>\n<h3><b>Question 332<\/b><\/h3>\n<p><b>Which security device is specifically designed to protect web applications from application-layer attacks?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">WAF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Router<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Switch<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VPN concentrator<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A web application firewall (WAF) protects web applications by inspecting HTTP and HTTPS requests and blocking traffic that matches malicious patterns. It can help defend against attacks such as SQL injection, cross-site scripting, malicious requests, and certain application-layer exploits. A WAF can apply rules based on URLs, parameters, headers, request methods, and other web traffic characteristics. Although it provides an important defensive layer, it should be used alongside secure coding practices, vulnerability management, authentication controls, and application security testing.<\/span><\/p>\n<h3><b>Question 333<\/b><\/h3>\n<p><b>Which access control principle gives users only the permissions required to perform their jobs?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least privilege<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mandatory access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Federation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Least privilege means providing users, applications, and systems with only the permissions necessary to perform their authorized tasks. This principle reduces the potential impact of compromised accounts and limits accidental or intentional misuse of sensitive resources. For example, a user who only needs to read a document should not receive permission to modify or delete it. Organizations should regularly review permissions because users may change roles or responsibilities. Combining least privilege with role-based access control and strong authentication can significantly improve overall access security.<\/span><\/p>\n<h3><b>Question 334<\/b><\/h3>\n<p><b>Which attack inserts malicious SQL commands into an application&#8217;s input to manipulate a database?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SQL injection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Directory traversal<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cross-site request forgery<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Buffer overflow<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">SQL injection occurs when an attacker places malicious SQL statements into application input that is improperly handled by the backend database system. Successful exploitation may allow attackers to retrieve sensitive records, modify information, bypass authentication, or delete database contents. Developers can reduce SQL injection risk by using parameterized queries and prepared statements instead of dynamically constructing SQL commands from user input. Input validation, least-privilege database accounts, secure coding practices, and regular application testing provide additional layers of protection against database manipulation attacks.<\/span><\/p>\n<h3><b>Question 335<\/b><\/h3>\n<p><b>Which security technique executes potentially dangerous code in an isolated environment to prevent it from affecting production systems?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Sandboxing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tokenization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hashing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network address translation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Sandboxing places potentially dangerous or untrusted code inside an isolated environment where its actions can be restricted and monitored. This prevents the code from directly interacting with sensitive production systems or resources. Security teams can use sandboxes to analyze suspicious files, test applications, examine malware behavior, or safely execute untrusted content. If malicious activity occurs inside the sandbox, the impact can be contained. Sandboxing is especially useful for malware analysis and application testing, although it should not replace endpoint security or other protective controls.<\/span><\/p>\n<h3><b>Question 336<\/b><\/h3>\n<p><b>Which physical security control is designed to prevent vehicles from entering a restricted area?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Bollard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mantrap<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Motion sensor<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Badge reader<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A bollard is a physical security barrier designed to prevent or restrict vehicles from entering protected areas. Bollards can be installed around building entrances, pedestrian areas, parking facilities, and other locations where vehicle-based threats or unauthorized access are concerns. Some bollards are fixed, while others can be retractable or automatically controlled. They are a form of physical preventive control and can complement other security measures such as gates, barriers, surveillance cameras, and access control systems to protect facilities and personnel.<\/span><\/p>\n<h3><b>Question 337<\/b><\/h3>\n<p><b>Which solution provides centralized management and monitoring of privileged accounts?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">PAM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IDS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DLP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Proxy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Privileged access management (PAM) provides centralized control over accounts that have elevated permissions. PAM solutions can securely store administrator credentials, enforce approval workflows, rotate passwords, restrict privileged sessions, and record administrative activities. These capabilities reduce the risk of attackers abusing compromised administrator accounts. PAM can also help organizations implement least privilege by providing temporary or just-in-time access rather than permanent administrative rights. Monitoring privileged activity is particularly important because administrative accounts can often access sensitive systems, databases, configurations, and security controls.<\/span><\/p>\n<h3><b>Question 338<\/b><\/h3>\n<p><b>Which backup method stores only data that has changed since the previous backup?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Full backup<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Differential backup<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Incremental backup<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Synthetic backup<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An incremental backup saves only the data that has changed since the previous backup, regardless of whether that previous backup was full or incremental. This approach usually requires less storage space and takes less time than performing full backups repeatedly. However, restoration can be more complicated because the original full backup and all required incremental backups may be needed. Organizations should regularly test their restoration procedures to ensure backups are usable. Incremental backups are commonly used when organizations need frequent backups while controlling storage and backup-window requirements.<\/span><\/p>\n<h3><b>Question 339<\/b><\/h3>\n<p><b>Which security strategy limits communication between different network zones to reduce lateral movement?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Compression<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Multiplexing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Fragmentation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network segmentation separates systems and users into different security zones and restricts communication between those zones. This limits an attacker&#8217;s ability to move laterally after compromising one system. For example, an organization may place public web servers, employee workstations, database servers, and sensitive administrative systems in separate network segments. Firewalls and access control policies can regulate traffic between these areas. Segmentation reduces the potential blast radius of an incident and provides security teams with greater control over which systems are allowed to communicate.<\/span><\/p>\n<h3><b>Question 340<\/b><\/h3>\n<p><b>During which incident response phase are malicious files, compromised accounts, and attacker persistence mechanisms removed from affected systems?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Identification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Containment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Eradication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Recovery<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Eradication is the incident response phase in which the root cause and malicious components of an incident are removed from affected systems. Security teams may delete malware, remove unauthorized accounts, eliminate persistence mechanisms, patch exploited vulnerabilities, and correct compromised configurations. Eradication normally follows containment, which focuses on limiting the spread and impact of the incident. After eradication is complete, systems can move toward recovery and normal operation. Proper eradication is important because simply restoring a system without removing the attacker&#8217;s access or persistence could allow the compromise to return.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full\u00a0Microsoft AZ-104 Exam Dumps\u00a0and Practice Test Dumps. &nbsp; Question 321 Which security solution collects and analyzes log data from multiple sources to identify potential security threats? SIEM VPN NAC HSM Correct Answer: 1 Explanation A security information and event management (SIEM) solution collects logs and security events from multiple systems, applications, servers, endpoints, and [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/11805"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=11805"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/11805\/revisions"}],"predecessor-version":[{"id":11806,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/11805\/revisions\/11806"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=11805"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=11805"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=11805"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}