Logo Passei Direto
Buscar
Material
páginas com resultados encontrados.
páginas com resultados encontrados.

Prévia do material em texto

Download Valid Microsoft SC-730 PDF Questions with Answers to Study
1 / 6
Exam : SC-730
Title :
https://www.passcert.com/SC-730.html
Cybersecurity Business
Professional (beta)
Download Valid Microsoft SC-730 PDF Questions with Answers to Study
2 / 6
1.Your organization uses Microsoft 365 for daily business operations.
According to the cybersecurity shared responsibility model, which of the following tasks is exclusively the
responsibility of the customer (you and your organization)?
A. Applying security patches to the underlying host operating systems.
B. Managing the physical security of the cloud provider's data centers.
C. Configuring the hypervisor software that isolates virtual machines.
D. Protecting account credentials and correctly classifying sensitive data.
Answer: D
Explanation:
In the shared responsibility model for cloud services (like SaaS), the cloud provider manages the physical
infrastructure, network, and host operating systems. However, the customer is always responsible for
protecting user identities (passwords, MFA) and correctly classifying/handling the data uploaded to the
cloud.
2.Which of the following actions best demonstrates an employee's active participation in their
organization's security awareness initiatives?
A. Completing mandatory training and reporting suspicious emails promptly.
B. Attempting to bypass the corporate firewall to test its overall security.
C. Purchasing and installing unapproved security software on your laptop.
D. Forwarding all internal company newsletters to a personal email address.
Answer: A
Explanation:
As a business professional, you are not expected to perform technical penetration testing (Option B) or
install unapproved IT tools (Option C). Active participation means understanding policies, completing
training, and using correct reporting channels when spotting potential threats like phishing.
3.Company policy strictly prohibits a team of marketing employees from logging into a third-party social
media management tool using a single, shared login credential.
What is the primary reason for this rule?
A. It guarantees that the shared account will be immediately targeted by external actors.
B. It automatically disables the multifactor authentication for the entire corporate network.
C. It prevents the organization from tracing specific actions back to an individual user.
D. It significantly decreases the processing speed of the third-party software platform.
Answer: C
Explanation:
Accountability is a core cybersecurity practice. It ensures that every action taken on a system can be
definitively tied to a specific individual. Shared accounts eliminate accountability, making it impossible to
determine who exactly made a change, leaked data, or made an error.
4.Your team is evaluating a free, public generative AI tool to help write reports.
According to standard organizational data-handling policies, which type of data must NEVER be inputted
into this tool?
A. General industry news articles published on public media websites.
B. Unreleased financial forecasts and proprietary business data.
Download Valid Microsoft SC-730 PDF Questions with Answers to Study
3 / 6
C. A standard template used for out-of-office email auto-replies.
D. Publicly available marketing brochures from your company.
Answer: B
Explanation:
Free and public generative AI models often use user prompts to train their underlying systems. Inputting
sensitive, unreleased, or proprietary business data into these tools can lead to severe data leakage and
confidentiality breaches.
5.The IT department mandates the use of an approved enterprise password manager.
What is the primary security benefit of integrating this tool into your daily workflow?
A. It actively scans the computer's hard drive to detect and remove malicious software.
B. It automatically intercepts and deletes all phishing emails before they reach the inbox.
C. It completely removes the need to use multi-factor authentication across the network.
D. It generates, auto-fills, and securely stores highly complex passwords for every system.
Answer: D
Explanation:
A password manager solves "password fatigue." It prevents the dangerous practice of password reuse by
generating strong, unique passwords for every application and storing them in an encrypted vault. It does
not replace MFA or act as an antivirus.
6.What is the primary security advantage of enabling Multi-Factor Authentication (MFA) on your corporate
email account?
A. It speeds up the login process by completely removing the need to remember a password.
B. It requires a second form of verification, protecting the account even if the password is stolen.
C. It ensures that all documents stored on your local hard drive are permanently encrypted.
D. It automatically blocks unauthorized users from physically accessing the office building.
Answer: B
Explanation:
MFA requires "something you know" (a password) and "something you have" (like a mobile phone app or
hardware key). Even if a threat actor successfully steals or guesses your password, they cannot access
the account without the second factor.
7.If an organization falls victim to a successful ransomware attack, which of the following is the most
immediate and direct business impact?
A. Critical business files become encrypted and inaccessible, causing severe operational downtime.
B. The company's official social media accounts automatically begin posting unauthorized spam.
C. The physical access badges of all employees are temporarily deactivated until the issue is resolved.
D. The internet service provider permanently terminates the organization's external network connection.
Answer: A
Explanation:
Ransomware is a specific type of malware designed to encrypt an organization's files or lock them out of
their systems entirely. This halts normal business operations until the data is restored from backups or a
ransom is paid for the decryption key.
Download Valid Microsoft SC-730 PDF Questions with Answers to Study
4 / 6
8.In cybersecurity terminology, how is a "vulnerability" defined?
A. A malicious software program designed to track user behavior covertly.
B. An individual or group attempting to gain unauthorized system access.
C. A weakness or flaw in a system that can be potentially exploited by an attacker.
D. The process of converting readable data into completely unreadable text.
Answer: C
Explanation:
A vulnerability is a flaw or weakness in software, hardware, or processes. Applying software updates and
security patches is the primary way organizations fix vulnerabilities before threat actors can use an
"exploit" to take advantage of them.
9.You receive a video message from the CEO urgently requesting a wire transfer. However, the CEO's
facial movements look unnatural, and the audio synchronization is slightly off.
What emerging threat does this scenario most likely represent?
A. An advanced persistent threat operating within the internal network infrastructure.
B. A zero-day vulnerability exploit targeting the operating system of your computer.
C. A physical security breach where an unauthorized person enters the executive boardroom.
D. A malicious deepfake video generated by artificial intelligence to impersonate someone.
Answer: D
Explanation:
Deepfakes utilize artificial intelligence to synthesize highly realistic but fabricated video and audio. Threat
actors increasingly use deepfakes of executives to bypass verification processes and authorize fraudulent
payments.
10.Compared to working in a physically controlled corporate office, which of the following is a significant
cybersecurity risk associated with working in a remote home environment?
A. Corporate cloud storage platforms automatically delete files accessed from outside the main office.
B. Home Wi-Fi networks often use weak default passwords and lack enterprise-grade physical security.
C. Remote employees are required to use multifactor authentication significantly more frequently.
D. Remote laptops are physically incapableof receiving mandatory software updates from the IT team.
Answer: B
Explanation:
Remote work environments lack corporate network perimeters. Home routers frequently have weak
default administrator passwords, firmware vulnerabilities, and are shared with other personal devices,
making them easier targets for attackers.
11.You are waiting for a flight and connect your corporate laptop to the airport's free, open public Wi-Fi
without using a Virtual Private Network (VPN).
What is the primary risk of this action?
A. Malicious actors on the same network could intercept your unencrypted data traffic.
B. Your local hard drive will be automatically formatted by the wireless network.
C. Your cloud backups will be permanently deleted without any prior warning.
D. Your multifactor authentication app will be uninstalled automatically by the router.
Answer: A
Download Valid Microsoft SC-730 PDF Questions with Answers to Study
5 / 6
Explanation:
Open public Wi-Fi networks lack encryption. Without a VPN to establish a secure tunnel, attackers
connected to the same network can easily perform "Man-in-the-Middle" attacks to eavesdrop on and
intercept sensitive data transmitted from your device.
12.You receive a phone call from an unknown individual claiming to be an IT support technician. They
fabricate a detailed, believable story about a server crash to manipulate you into providing your password.
Which psychological social engineering technique is this?
A. An attacker leaves a malware-infected USB drive in the parking lot for someone to find.
B. An attacker physically follows an authorized employee through a secure keycard-access door.
C. An attacker fabricates a detailed story and false identity to manipulate you into sharing data.
D. An attacker encrypts your local files and demands a cryptocurrency payment for the key.
Answer: C
Explanation:
This describes "Pretexting." It is a form of social engineering where an attacker creates a fabricated
scenario (a pretext) or assumes a false identity to build trust and trick the victim into disclosing sensitive
information. (Option A is Baiting, Option B is Tailgating, Option D is Ransomware).
13.You receive an email from a trusted vendor stating their bank account has changed, and they request
the next invoice be paid to the new account.
What is the most secure method to verify this digital communication?
A. Update the billing system immediately to avoid late payment penalties and unnecessary fees.
B. Reply directly to the email to ask if the new bank details are absolutely correct and valid.
C. Forward the email to your entire department to see if anyone knows about the sudden change.
D. Call the vendor using a known, verified phone number from a previously signed contract.
Answer: D
Explanation:
This scenario requires "out-of-band verification." Because email accounts can be compromised (Business
Email Compromise), you must verify sensitive financial requests by using a completely separate and
trusted communication channel, such as an official phone number on file.
14.When reviewing security logs, which of the following scenarios is a strong behavioral indicator of a
potential malicious "insider threat"?
A. An employee continuously downloads massive volumes of confidential data at 3:00 AM.
B. An employee accidentally copies the wrong external client on a routine meeting invite.
C. A newly hired employee asks the IT helpdesk to reset their forgotten password twice.
D. An employee uses the company's approved cloud storage platform to share a project file.
Answer: A
Explanation:
Insider threats involve individuals misusing their legitimate access rights. Downloading unusually large
amounts of sensitive data, especially completely outside of normal business hours, is a classic behavioral
indicator of data exfiltration and intellectual property theft.
15.A temporary administrative assistant joins your department for two weeks to perform basic data entry.
Download Valid Microsoft SC-730 PDF Questions with Answers to Study
6 / 6
According to the access control principle of "least privilege," how should their system permissions be
configured?
A. Full administrative access so they can troubleshoot their own computer issues.
B. The absolute minimum access permissions necessary to perform their specific tasks.
C. Read-only access to all confidential company financial records and databases.
D. The exact same access permissions as the senior department manager.
Answer: B
Explanation:
The principle of least privilege ensures that a user is given only the absolute minimum permissions
required to perform their current job functions. This drastically limits the potential "blast radius" if the user
makes a mistake or if their account is compromised.
16.When evaluating digital communications, which of the following characteristics is a classic, highly
reliable indicator that an email is likely a phishing attempt?
A. The email sender is a known colleague casually asking about your lunch plans for tomorrow.
B. The email contains a secure link to an internal SharePoint document you requested yesterday.
C. The email uses a generic greeting and creates a false sense of extreme urgency or panic.
D. The sender's email address exactly matches the company's official corporate domain name.
Answer: C
Explanation:
Phishing emails rely heavily on emotional manipulation. Threat actors frequently use generic greetings
(like "Dear Customer") because they don't know your name, and they manufacture artificial urgency (e.g.,
"Your account will be suspended in 24 hours") to rush you into making a hasty mistake without thinking.
17.You receive an unexpected email containing a suspicious link, but you want to evaluate its actual
destination without clicking on it.
What is the safest technique to perform this verification?
A. Hover your mouse cursor over the link to inspect the actual destination URL on the screen.
B. Copy the link and paste it into a blank Word document to see where the text redirects.
C. Forward the email to your personal email account and open it on your mobile phone.
D. Reply directly to the sender and ask them to confirm where the web link is supposed to lead.
Answer: A
Explanation:
"Hovering" (placing your cursor over the link without clicking) will display the true destination URL in a
small tooltip or at the bottom corner of your browser/email client. This allows you to visually verify if the
link matches the legitimate corporate domain before taking any action.

Mais conteúdos dessa disciplina