{"id":11811,"date":"2026-09-14T12:15:39","date_gmt":"2026-09-14T12:15:39","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=11811"},"modified":"2026-09-14T12:15:39","modified_gmt":"2026-09-14T12:15:39","slug":"microsoft-az-104-practice-test-questions-and-exam-dumps-part-20-q381-400","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-az-104-practice-test-questions-and-exam-dumps-part-20-q381-400\/","title":{"rendered":"Microsoft AZ-104 Practice Test Questions and Exam Dumps Part 20 (Q381\u2013400)"},"content":{"rendered":"<h2><b>View Full\u00a0<a href=\"https:\/\/www.examlabs.com\/az-104-exam-dumps\">Microsoft AZ-104 Exam Dumps<\/a>\u00a0and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 381<\/b><\/h3>\n<p><b>Which security control is designed to prevent unauthorized users from accessing a restricted physical area?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Badge reader<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Proxy server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SIEM<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A badge reader is a physical access control that verifies an individual&#8217;s authorized credential before allowing entry into a restricted area. Employees may use access cards, smart cards, or other identification badges to authenticate themselves at secured doors. Organizations can configure badge readers to allow access only during approved hours or to specific areas based on job responsibilities. Badge systems also create access records that can support security investigations. They are often combined with cameras, security guards, locks, and biometric systems to provide layered physical protection.<\/span><\/p>\n<h3><b>Question 382<\/b><\/h3>\n<p><b>Which security principle ensures that systems and data remain accessible to authorized users when required?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Confidentiality<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Integrity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Availability<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Authentication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Availability ensures that authorized users can access systems, applications, and information when they need them. Various events can affect availability, including hardware failures, cyberattacks, power outages, natural disasters, and software problems. Organizations can improve availability through redundancy, backups, failover systems, load balancing, disaster recovery plans, and resilient infrastructure. Availability is one of the three components of the CIA triad. A system can maintain confidentiality and integrity while still failing to meet security requirements if legitimate users cannot access the information or services they need.<\/span><\/p>\n<h3><b>Question 383<\/b><\/h3>\n<p><b>Which type of attack attempts to manipulate users into revealing confidential information by pretending to be a trusted person or organization?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Social engineering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port scanning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data masking<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Social engineering involves manipulating people into performing actions or revealing information that benefits an attacker. Rather than relying entirely on technical vulnerabilities, attackers exploit human psychology such as trust, fear, urgency, curiosity, or authority. Common social engineering techniques include phishing, pretexting, baiting, vishing, smishing, and tailgating. Security awareness training is one of the most important defenses because users need to recognize suspicious requests and verify unusual instructions. Strong technical controls such as multifactor authentication can also reduce the consequences of successful social engineering.<\/span><\/p>\n<h3><b>Question 384<\/b><\/h3>\n<p><b>Which security technology provides encrypted remote access to an organization&#8217;s internal resources over an untrusted network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hub<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Repeater<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Bridge<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VPN<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A virtual private network (VPN) creates an encrypted connection between a remote user and an organization&#8217;s network across an untrusted network such as the public internet. VPNs help protect sensitive information from interception while it travels between the user&#8217;s device and the organization&#8217;s infrastructure. Remote-access VPNs are commonly used by employees working outside the office, while site-to-site VPNs can securely connect different organizational networks. Strong authentication, secure VPN protocols, updated software, and appropriate access controls are important for maintaining secure remote connectivity.<\/span><\/p>\n<h3><b>Question 385<\/b><\/h3>\n<p><b>Which type of security control is intended to stop an unwanted event before it occurs?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Preventive control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Detective control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Corrective control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Recovery control<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Preventive controls are designed to stop or reduce the likelihood of a security incident before it occurs. Examples include firewalls, access controls, authentication mechanisms, security policies, encryption, and application allowlisting. These controls create barriers that make unauthorized activity more difficult. Preventive controls are an important part of defense in depth, but no single control can prevent every possible attack. Organizations should combine preventive controls with detective and corrective measures so that incidents can still be identified and handled if prevention fails.<\/span><\/p>\n<h3><b>Question 386<\/b><\/h3>\n<p><b>Which security control identifies suspicious activity and generates an alert for investigation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Preventive control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Detective control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Deterrent control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Compensating control<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Detective controls are designed to identify security events or suspicious activity after or while an event is occurring. Examples include intrusion detection systems, security cameras, log monitoring, SIEM alerts, and file integrity monitoring. These controls provide visibility into potential threats and allow security teams to investigate unusual activity. Detective controls do not necessarily stop an attack by themselves. Instead, they help organizations recognize incidents quickly so that appropriate containment and response actions can be taken before the impact becomes more severe.<\/span><\/p>\n<h3><b>Question 387<\/b><\/h3>\n<p><b>Which type of access control is based on centrally defined security labels and classifications?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Discretionary access control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mandatory access control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Role-based access control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Rule-based access control<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Mandatory access control (MAC) uses centrally defined security classifications and labels to determine access to resources. Users generally cannot change these permissions themselves because access decisions are controlled by the security policy. MAC is commonly associated with environments requiring strict control over sensitive information, such as military or government systems. A user may have access only when their clearance level and the resource classification meet the required rules. This model provides strong centralized control but can be more complex to administer.<\/span><\/p>\n<h3><b>Question 388<\/b><\/h3>\n<p><b>Which access control model allows resource owners to determine who can access their resources?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mandatory access control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Role-based access control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Discretionary access control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Attribute-based access control<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Discretionary access control (DAC) allows the owner of a resource to determine who can access it and what permissions they receive. For example, the owner of a shared file may grant another user read or write permissions. DAC provides flexibility because resource owners can manage access without requiring a central administrator for every decision. However, this flexibility can also create security risks if users grant excessive permissions. Organizations should combine DAC with appropriate policies and regular access reviews to prevent unnecessary exposure of sensitive information.<\/span><\/p>\n<h3><b>Question 389<\/b><\/h3>\n<p><b>Which access control model assigns permissions based on attributes such as department, location, device type, or time?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Discretionary access control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mandatory access control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Attribute-based access control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Rule-based routing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Attribute-based access control (ABAC) makes access decisions using characteristics or attributes associated with users, resources, devices, and environmental conditions. For example, a policy might allow an employee to access a sensitive application only when the employee belongs to the finance department, uses a managed device, and connects during approved hours. ABAC can provide highly flexible and detailed access decisions. However, designing and maintaining complex attribute-based policies requires careful planning. Organizations must ensure that attributes are accurate, current, and properly protected.<\/span><\/p>\n<h3><b>Question 390<\/b><\/h3>\n<p><b>Which attack exploits weaknesses in an application&#8217;s handling of user-supplied file paths?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SQL injection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Directory traversal<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password spraying<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DDoS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Directory traversal occurs when an attacker manipulates file path information to access files or directories outside the application&#8217;s intended location. If successful, an attacker may retrieve sensitive configuration files, credentials, source code, or other information stored on the server. Secure applications should validate user input and avoid allowing users to directly control sensitive file paths. Developers can also use secure file APIs, restrict application permissions, and apply proper operating system access controls. Regular security testing can help identify directory traversal vulnerabilities before attackers exploit them.<\/span><\/p>\n<h3><b>Question 391<\/b><\/h3>\n<p><b>Which security mechanism is commonly used to verify the integrity and authenticity of a digitally signed message?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MAC address<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Token<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Digital signature<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A digital signature provides a way to verify the authenticity and integrity of digital information. The sender uses a private key to create the signature, and the recipient can use the corresponding public key to verify it. If the content changes after signing, the verification process can detect the modification. Digital signatures also provide evidence that the message or document was associated with the holder of the private key. They are commonly used in secure email, software distribution, certificates, and electronic documents requiring trust and accountability.<\/span><\/p>\n<h3><b>Question 392<\/b><\/h3>\n<p><b>Which security method protects stored data if a laptop is lost or stolen?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Full-disk encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS filtering<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Full-disk encryption protects data stored on a device by encrypting the contents of the storage drive. If a laptop is lost or stolen, an unauthorized person who removes the drive or attempts to access its contents may be unable to read the encrypted information without the appropriate authentication or encryption key. Full-disk encryption is especially important for mobile devices that may contain sensitive business or personal information. Organizations should combine encryption with strong authentication, secure key management, device management, and remote-wipe capabilities.<\/span><\/p>\n<h3><b>Question 393<\/b><\/h3>\n<p><b>Which security control helps protect against unauthorized changes to operating system and application files?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File integrity monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network address translation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">File integrity monitoring (FIM) establishes a trusted baseline for important files and detects changes that may indicate unauthorized activity. It can monitor system files, application files, configuration files, and other critical resources. If a file is modified, deleted, or replaced unexpectedly, the system can generate an alert for investigation. FIM can help identify malware infections, unauthorized administrative changes, and other integrity issues. It is particularly valuable on servers and systems where unexpected modifications could indicate compromise or create serious operational problems.<\/span><\/p>\n<h3><b>Question 394<\/b><\/h3>\n<p><b>Which security technique separates sensitive systems from less trusted systems by using isolated network zones?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password synchronization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data compression<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tokenization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network segmentation divides an organization&#8217;s infrastructure into separate network zones and controls communication between those zones. Sensitive systems such as databases, payment systems, and administrative servers can be isolated from ordinary user devices and public-facing services. If an attacker compromises a less trusted system, segmentation can limit the attacker&#8217;s ability to reach sensitive resources. Firewalls, VLANs, access control lists, and other technologies can enforce segmentation policies. Effective segmentation reduces the potential impact of a breach and supports stronger access control.<\/span><\/p>\n<h3><b>Question 395<\/b><\/h3>\n<p><b>Which type of malware secretly records a user&#8217;s activities and may collect passwords or personal information?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Worm<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Spyware<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Rootkit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ransomware<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Spyware is malware designed to monitor a user&#8217;s activities and collect information without proper authorization. Depending on the type, spyware may capture browsing activity, credentials, keystrokes, personal information, or other sensitive data. Attackers can use stolen information for identity theft, financial fraud, espionage, or further compromise. Organizations can reduce spyware risks through endpoint protection, application allowlisting, secure software practices, patch management, and user awareness training. Users should also avoid installing unknown applications or clicking suspicious links that could deliver spyware.<\/span><\/p>\n<h3><b>Question 396<\/b><\/h3>\n<p><b>Which security control allows an organization to identify who accessed a system and what actions they performed?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tokenization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Audit logs<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Audit logs record security-relevant activities performed by users, applications, and systems. They can contain information such as login attempts, account changes, file access, administrative commands, and configuration modifications. Security teams use audit logs to investigate incidents, establish accountability, identify suspicious behavior, and meet compliance requirements. Logs should be protected against unauthorized modification and retained according to organizational policies. Centralized logging and SIEM solutions can make it easier to correlate events from multiple systems and identify patterns that may indicate a security incident.<\/span><\/p>\n<h3><b>Question 397<\/b><\/h3>\n<p><b>Which disaster recovery strategy maintains a fully operational duplicate environment that can quickly take over if the primary site fails?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hot site<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cold site<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Backup tape<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Archive site<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A hot site is a secondary facility that is fully equipped and ready to take over operations when the primary environment becomes unavailable. It typically contains hardware, software, networking, and other infrastructure needed to support critical services. Because it is already operational or can become operational very quickly, a hot site generally provides a faster recovery time than a cold site. However, maintaining a hot site can be expensive. Organizations choose between hot, warm, and cold recovery facilities based on business requirements, risk, and recovery objectives.<\/span><\/p>\n<h3><b>Question 398<\/b><\/h3>\n<p><b>Which disaster recovery site has equipment and infrastructure available but generally requires additional preparation before operations can resume?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hot site<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Warm site<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cold site<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Offline site<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A warm site is a disaster recovery facility that has some equipment, connectivity, and infrastructure already available but may require additional configuration or data restoration before normal operations can resume. It provides a balance between the rapid recovery of a hot site and the lower cost of a cold site. Organizations may use warm sites when they need reasonably fast recovery but cannot justify the expense of maintaining a fully operational duplicate environment. The appropriate recovery site depends on business continuity requirements, budget, and acceptable downtime.<\/span><\/p>\n<h3><b>Question 399<\/b><\/h3>\n<p><b>Which incident response activity focuses on removing malware and closing the vulnerability that allowed an attacker to enter?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Identification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Containment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Eradication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Preparation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Eradication is the incident response activity focused on completely removing the cause and remaining elements of a security incident. Security teams may remove malware, delete unauthorized accounts, terminate attacker persistence, patch exploited vulnerabilities, and correct compromised configurations. Simply isolating an infected system does not guarantee that the threat has been removed. Organizations must identify and eliminate the mechanisms that allowed the attacker to maintain access. After eradication is complete, affected systems can proceed toward recovery, validation, and a return to normal operations.<\/span><\/p>\n<h3><b>Question 400<\/b><\/h3>\n<p><b>Which security principle ensures that data has not been altered by unauthorized individuals or processes?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Confidentiality<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Integrity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Availability<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Authentication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Integrity ensures that information remains accurate, complete, and protected against unauthorized modification or destruction. Organizations can maintain data integrity through access controls, hashing, digital signatures, file integrity monitoring, backups, and change-management procedures. For example, a digital signature can help verify that a document has not been changed after it was signed. Integrity is one of the three fundamental principles of the CIA triad, along with confidentiality and availability. Protecting integrity is essential for financial records, system configurations, databases, applications, and other critical information.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full\u00a0Microsoft AZ-104 Exam Dumps\u00a0and Practice Test Dumps. &nbsp; Question 381 Which security control is designed to prevent unauthorized users from accessing a restricted physical area? Badge reader Load balancer Proxy server SIEM Correct Answer: 1 Explanation A badge reader is a physical access control that verifies an individual&#8217;s authorized credential before allowing entry into [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/11811"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=11811"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/11811\/revisions"}],"predecessor-version":[{"id":11812,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/11811\/revisions\/11812"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=11811"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=11811"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=11811"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}