Search Header Logo

Sec+ Domain 1.1

Authored by Isabella S

Instructional Technology

Professional Development

Used 22+ times

Sec+ Domain 1.1
AI

AI Actions

Add similar questions

Adjust reading levels

Convert to real-world scenario

Translate activity

More...

    Content View

    Student View

12 questions

Show all answers

1.

MULTIPLE CHOICE QUESTION

2 mins • 1 pt

A company has drafted an insider-threat policy that prohibits the use of external storage devices. Which of the following would BEST protect the company from data exfiltration via removable media?

Blocking removable-media devices and write capabilities using a host-based security tool

Developing mandatory training to educate employees about the removable media policy

Monitoring large data transfer transactions in the firewall logs

Implementing a group policy to block user access to system files

2.

MULTIPLE CHOICE QUESTION

1 min • 1 pt

A security analyst is using a recently released security advisory to review historical logs, looking for the specific activity that was outlined in the advisory. Which of the following is the analyst doing?

Threat hunting

A packet capture

Credentialed vulnerability scanning

A user behavior analysis

3.

MULTIPLE CHOICE QUESTION

1 min • 1 pt

A company recently experienced an attack in which a malicious actor was able to exfiltrate data by cracking stolen passwords, using a rainbow table of the sensitive data. Which of the following should a security engineer do to prevent such an attack in the future?

Disable password reuse.

Enforce password complexity.

Implement password salting.

Use password hashing.

4.

MULTIPLE CHOICE QUESTION

1 min • 1 pt

The IT department at a university is concerned about professors placing servers on the university network in an attempt to bypass security controls. Which of the following BEST represents this type of threat?

Hacktivism

A script kiddie

Shadow IT

White-hat

5.

MULTIPLE CHOICE QUESTION

45 sec • 1 pt

Which of the following BEST describes a security exploit for which a vendor patch is not readily available?

End of life

Integer overflow

Race condition

Zero-day

6.

MULTIPLE CHOICE QUESTION

1 min • 1 pt

The Chief Financial Officer (CFO) of an insurance company received an email from Ann, the company's Chief Executive Officer (CEO), requesting a transfer of $10,000 to an account. The email states Ann is on vacation and has lost her purse, containing cash and credit cards. Which of the following social- engineering techniques is the attacker using?

Pharming

Whaling

Typo squatting

Phishing

7.

MULTIPLE CHOICE QUESTION

1 min • 1 pt

Joe, an employee, receives an email stating he won the lottery. The email includes a link that requests a name, mobile phone number, address, and date of birth be provided to confirm Joe's identity before sending him the prize. Which of the following BEST describes this type of email?

Vishing

Phishing

  Spear phishing

Whaling

Access all questions and much more by creating a free account

Create resources

Host any resource

Get auto-graded reports

Google

Continue with Google

Email

Continue with Email

Classlink

Continue with Classlink

Clever

Continue with Clever

or continue with

Microsoft

Microsoft

Apple

Apple

Others

Others

Already have an account?