{"id":11809,"date":"2026-09-14T12:15:05","date_gmt":"2026-09-14T12:15:05","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=11809"},"modified":"2026-09-14T12:15:05","modified_gmt":"2026-09-14T12:15:05","slug":"microsoft-az-104-practice-test-questions-and-exam-dumps-part-19-q361-380","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-az-104-practice-test-questions-and-exam-dumps-part-19-q361-380\/","title":{"rendered":"Microsoft AZ-104 Practice Test Questions and Exam Dumps Part 19 (Q361\u2013380)"},"content":{"rendered":"<h2><b>View Full\u00a0<a href=\"https:\/\/www.examlabs.com\/az-104-exam-dumps\">Microsoft AZ-104 Exam Dumps<\/a>\u00a0and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 361<\/b><\/h3>\n<p><b>Which security control is used to verify that a user&#8217;s identity is valid before granting access to a system?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Authorization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Accounting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Auditing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Authentication is the process of verifying the identity of a user, device, or system before access is granted. Common authentication methods include passwords, security tokens, smart cards, certificates, and biometric characteristics. Strong authentication helps ensure that only legitimate users can access protected resources. Multifactor authentication strengthens this process by requiring multiple authentication factors. Authentication is different from authorization because authentication confirms who the user is, while authorization determines what that authenticated user is allowed to access or perform within the system.<\/span><\/p>\n<h3><b>Question 362<\/b><\/h3>\n<p><b>Which type of attack attempts to gain access by trying a small number of commonly used passwords against many accounts?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Brute-force attack<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password spraying<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Credential stuffing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Pass-the-hash<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Password spraying is an attack in which an attacker tries a small number of commonly used passwords against many different user accounts. Instead of repeatedly attacking one account, the attacker distributes login attempts across multiple accounts to avoid triggering account lockout policies. Commonly attempted passwords may include seasonal passwords, simple patterns, or passwords based on an organization&#8217;s name. Multifactor authentication, strong password policies, monitoring failed login attempts, and detecting unusual authentication patterns can help organizations identify and prevent password spraying attacks.<\/span><\/p>\n<h3><b>Question 363<\/b><\/h3>\n<p><b>Which technology provides secure communication by encrypting data transmitted between a web browser and a web server?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Telnet<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HTTPS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HTTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">HTTPS uses HTTP over a secure TLS connection to protect communication between a client and a web server. It provides encryption that helps prevent attackers from easily reading information transmitted across the network. HTTPS also supports server authentication through digital certificates and helps protect the integrity of transmitted data. It is commonly used for websites that handle passwords, payment information, personal information, and other sensitive data. Organizations should properly configure TLS and keep certificates valid to maintain secure web communications.<\/span><\/p>\n<h3><b>Question 364<\/b><\/h3>\n<p><b>Which type of attack attempts to overwhelm a service by sending a large number of requests from a single source?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DDoS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Phishing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Replay<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DoS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A denial-of-service (DoS) attack attempts to make a system or service unavailable by overwhelming it with excessive traffic, requests, or resource consumption. A traditional DoS attack may originate from a single system, while a distributed denial-of-service attack uses multiple systems. The attacker may target network bandwidth, server processing power, memory, or application resources. Organizations can reduce DoS risks through traffic filtering, rate limiting, redundant infrastructure, load balancing, and specialized protection services. Monitoring can also help identify unusual traffic patterns early.<\/span><\/p>\n<h3><b>Question 365<\/b><\/h3>\n<p><b>Which security control provides a centralized location for administrators to securely access multiple servers?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Honeypot<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Jump server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Proxy server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancer<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A jump server, also known as a jump box, provides a controlled and centralized access point for administrators who need to manage systems in a protected network. Instead of allowing administrators to connect directly to many sensitive servers, organizations can require administrative access through the jump server. This reduces the number of systems exposed to direct administrative connections and makes monitoring easier. Access to the jump server should be strongly authenticated and logged. Organizations can also apply strict security controls and limit which systems can be accessed through it.<\/span><\/p>\n<h3><b>Question 366<\/b><\/h3>\n<p><b>Which security technique hides information inside another file, such as an image or audio file?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tokenization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hashing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Steganography<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Encryption<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Steganography is a technique used to conceal information inside another type of file, such as an image, audio recording, or video. Unlike encryption, which makes information unreadable without the correct key, steganography attempts to hide the existence of the information itself. Attackers may use steganography to conceal malicious code or stolen information. Security teams can use specialized analysis tools to identify suspicious files and unusual data patterns. File integrity monitoring, endpoint security, and content inspection can also help detect suspicious use of concealed information.<\/span><\/p>\n<h3><b>Question 367<\/b><\/h3>\n<p><b>Which security control verifies that a device meets organizational security requirements before allowing it to connect to the network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DLP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SIEM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">WAF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAC<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network access control (NAC) evaluates devices before or while they connect to an organization&#8217;s network and can enforce security requirements. NAC may check whether a device has current patches, approved security software, appropriate configurations, or valid authentication credentials. Noncompliant devices can be denied access or placed into a restricted network segment. NAC helps prevent insecure or unauthorized devices from gaining normal network access. It is especially useful in environments with many employee devices, guest systems, and managed endpoints that must meet organizational security policies.<\/span><\/p>\n<h3><b>Question 368<\/b><\/h3>\n<p><b>Which type of malware can replicate itself across networks without requiring a user to manually execute it on every system?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Worm<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Trojan<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Spyware<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Adware<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A worm is a type of malware that can self-replicate and spread from one system to another, often by exploiting network vulnerabilities or weaknesses in services. Unlike many traditional viruses, worms do not necessarily require a user to execute an infected file to spread. Rapidly spreading worms can consume network resources and compromise large numbers of systems. Organizations can reduce worm activity through timely patching, network segmentation, firewalls, endpoint protection, and disabling unnecessary services. Monitoring network traffic can also help identify unusual propagation patterns.<\/span><\/p>\n<h3><b>Question 369<\/b><\/h3>\n<p><b>Which type of malware disguises itself as legitimate software to trick a user into installing it?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Worm<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Rootkit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Trojan<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ransomware<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Trojan is malware that disguises itself as legitimate or useful software to convince users to install or execute it. Unlike a worm, a Trojan generally relies on the victim to initiate its execution. Once installed, it may provide unauthorized access, steal information, download additional malware, or perform other malicious activities. Users should download software only from trusted sources and verify unexpected applications before installation. Endpoint protection, application allowlisting, security awareness training, and least privilege can also reduce the impact of Trojan malware.<\/span><\/p>\n<h3><b>Question 370<\/b><\/h3>\n<p><b>Which security control helps prevent unauthorized devices from connecting to switch ports?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS filtering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data masking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Port security is a network switch feature that can restrict which devices are allowed to connect through specific physical switch ports. Administrators can configure allowed MAC addresses or limit the number of devices that can use a port. If an unauthorized device attempts to connect, the switch can block the connection or take another configured security action. Port security helps reduce unauthorized physical network access and can prevent some forms of device spoofing. It is most effective when combined with other network access and authentication controls.<\/span><\/p>\n<h3><b>Question 371<\/b><\/h3>\n<p><b>Which security concept ensures that two people cannot independently complete all stages of a sensitive transaction?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Separation of duties<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Single sign-on<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Federation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Job enlargement<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Separation of duties divides important responsibilities among multiple people so that one individual cannot independently complete an entire sensitive process. For example, one employee might create a financial payment while another employee approves it. This reduces opportunities for fraud, unauthorized changes, and abuse of privileges. Separation of duties is especially important for financial systems, administrative functions, security changes, and other high-risk activities. Organizations should carefully design roles so that responsibilities are divided appropriately without creating unnecessary operational delays.<\/span><\/p>\n<h3><b>Question 372<\/b><\/h3>\n<p><b>Which security technology is designed to detect malicious activity on an individual endpoint and provide investigation and response capabilities?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">WAF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">EDR<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Endpoint detection and response (EDR) solutions monitor endpoint activity such as processes, files, network connections, and system changes to identify suspicious behavior. EDR platforms provide security teams with detailed information that can be used to investigate potential incidents and determine how an attack occurred. Many EDR solutions also support response actions, such as isolating compromised endpoints, terminating malicious processes, or quarantining suspicious files. EDR improves visibility into endpoint activity and can help organizations detect threats that traditional antivirus software may miss.<\/span><\/p>\n<h3><b>Question 373<\/b><\/h3>\n<p><b>Which attack attempts to obtain sensitive information by observing a person entering a password or PIN?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tailgating<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Pretexting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shoulder surfing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dumpster diving<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Shoulder surfing occurs when an attacker observes someone entering sensitive information, such as a password, PIN, or security code. The attacker may physically watch the victim or use cameras and other observation methods. This attack is particularly relevant in public areas such as airports, offices, banks, and crowded locations. Users can reduce the risk by shielding keyboards and screens, avoiding entering sensitive information where others can easily observe it, and using privacy filters when appropriate. Multifactor authentication can also limit the value of stolen passwords.<\/span><\/p>\n<h3><b>Question 374<\/b><\/h3>\n<p><b>Which type of social engineering involves following an authorized person through a secured entrance without authorization?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Phishing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tailgating<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vishing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Pretexting<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Tailgating occurs when an unauthorized individual follows an authorized person into a restricted physical area without using their own credentials. Attackers may take advantage of courtesy, distraction, or busy entrances to bypass access controls. Organizations can reduce tailgating through security awareness training, access badges, mantraps, security guards, cameras, and policies requiring employees to challenge unknown individuals. Employees should avoid holding secured doors open for people they do not recognize or allowing others to enter using their credentials.<\/span><\/p>\n<h3><b>Question 375<\/b><\/h3>\n<p><b>Which type of social engineering attack uses voice communication to deceive a victim?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Smishing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Phishing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Pharming<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vishing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Vishing, or voice phishing, uses telephone calls or other voice communication to manipulate victims into revealing sensitive information or performing an unauthorized action. Attackers may impersonate bank representatives, technical support staff, government employees, or company executives. They often create urgency or fear to pressure victims into responding quickly. Organizations can reduce vishing risks through security awareness training, verification procedures, and policies that prohibit sharing passwords or authentication codes over unexpected calls. Employees should independently verify suspicious requests using trusted contact information.<\/span><\/p>\n<h3><b>Question 376<\/b><\/h3>\n<p><b>Which type of vulnerability occurs when an application allows data to exceed the memory space allocated for it?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Buffer overflow<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SQL injection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Directory traversal<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cross-site scripting<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A buffer overflow occurs when a program writes more data into a memory buffer than the allocated space can safely contain. Excess data may overwrite adjacent memory areas, potentially causing crashes or enabling an attacker to execute malicious code. Buffer overflows are commonly associated with software written in languages that provide limited automatic memory protection. Developers can reduce these risks through secure coding practices, memory-safe languages, bounds checking, input validation, compiler protections, and regular vulnerability testing. Keeping software patched also helps address known buffer overflow vulnerabilities.<\/span><\/p>\n<h3><b>Question 377<\/b><\/h3>\n<p><b>Which security control is designed to identify vulnerabilities in systems before attackers exploit them?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data destruction<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vulnerability scanning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network translation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Vulnerability scanning uses automated tools to examine systems and identify known weaknesses such as missing security patches, outdated software, insecure configurations, and exposed services. Regular scanning gives organizations visibility into their security posture and helps security teams prioritize remediation. Scans can be performed against internal networks, external-facing systems, applications, and cloud resources. However, scanning results should be reviewed because tools can produce false positives or fail to identify complex vulnerabilities. Vulnerability scanning is an important part of proactive security management.<\/span><\/p>\n<h3><b>Question 378<\/b><\/h3>\n<p><b>Which security mechanism protects data by converting readable information into an unreadable format using a cryptographic key?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hashing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tokenization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Encoding<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Encryption converts readable plaintext into ciphertext using a cryptographic algorithm and key. The encrypted information can then be decrypted by an authorized party with the appropriate key. Encryption protects data from unauthorized disclosure when it is stored or transmitted. Examples include full-disk encryption, database encryption, encrypted backups, and TLS for network communications. Strong encryption depends not only on the algorithm but also on proper key management. If encryption keys are stolen, lost, or poorly protected, the security of the encrypted information can be seriously affected.<\/span><\/p>\n<h3><b>Question 379<\/b><\/h3>\n<p><b>Which disaster recovery metric defines how quickly a system must be restored after an outage?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RPO<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MTBF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SLA<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RTO<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The recovery time objective (RTO) defines the maximum acceptable amount of time that a system or service can remain unavailable after an incident. For example, an organization with an RTO of two hours should aim to restore the affected service within approximately two hours. RTO helps determine disaster recovery requirements, including backup methods, redundancy, failover systems, and recovery procedures. RTO differs from RPO because RPO focuses on acceptable data loss, while RTO focuses on the acceptable duration of service downtime.<\/span><\/p>\n<h3><b>Question 380<\/b><\/h3>\n<p><b>Which security process examines an incident after it has been resolved to identify improvements for future incidents?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Containment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Eradication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Lessons learned<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Identification<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The lessons-learned phase occurs after an incident has been handled and focuses on identifying what worked well, what failed, and what should be improved. Security teams may review the timeline, detection methods, response actions, communication procedures, and technical controls used during the incident. The organization can then update policies, security configurations, training, monitoring rules, and incident response plans. Conducting lessons learned helps prevent similar incidents from having the same impact in the future and supports continuous improvement of the overall security program.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full\u00a0Microsoft AZ-104 Exam Dumps\u00a0and Practice Test Dumps. &nbsp; Question 361 Which security control is used to verify that a user&#8217;s identity is valid before granting access to a system? Authentication Authorization Accounting Auditing Correct Answer: 1 Explanation Authentication is the process of verifying the identity of a user, device, or system before access is [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/11809"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=11809"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/11809\/revisions"}],"predecessor-version":[{"id":11810,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/11809\/revisions\/11810"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=11809"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=11809"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=11809"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}