wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

L3: Understanding Security Policies

Total questions: 21

Worksheet time: 4hrs 3mins

Name
Class
Date
1.
The default password length for a Windows Server domain controller is:
a)
0
b)
5
c)
7
d)
14
2.
A network sniffer is software or hardware that:
a)
Records user activity and transmits it to the server
b)
Captures and analyzes network communication
c)
Protects workstations from intrusions
d)
Catalogs network data to create a secure index
3.
Your password is 1Vu*cI!8sT.
Which attack method is your password vulnerable to?
a)
Rainbow table
b)
Brute force
c)
Spidering
d)
Dictionary
4.

Roblox requires a user name and password. How should Karl secure this password?

a)

Save them to a text file

b)

Enable session caching

c)

Configure the browser to save passwords

d)

Save it to an encrypted file

5.

Which two characteristics would you recommend for Cames Joncannon's* Roblox password?

*Names, characters, businesses, places, events, locales, and incidents are either the products of the author's imagination or used in a fictitious manner. Any resemblance to actual persons, living or dead, or actual events is purely coincidental.

a)

Hard to guess + Easy to remember

b)

Includes Unicode characters + Easy to increment

c)

Hard to guess + Unicode

d)

Easy to remember + easy to increment

6.
Account lockout policies are used to prevent which type of security attack?
a)
Brute force attacks
b)
Users sharing passwords
c)
Social engineering
d)
Passwords being reused immediately
7.
What is a common method for password collection?
a)
Email attachments
b)
Back door intrusions
c)
SQL Injection
d)
Network sniffers
8.
Basic security questions used to reset a password are susceptible to:
a)
Hashing
b)
Social engineering
c)
Network sniffing
d)
Trojan horses
9.
Password history policies are used to prevent:
a)
Brute force attacks
b)
Users from sharing passwords
c)
Social engineering
d)
Passwords from being reused immediately
10.

3.14 signed up for an online bank account. Every 6 months, the bank requires 3.14 to change the password. 3.14 has changed the password 5 times in the past. Instead of coming up with a new password, 3.14 decides to use one of their past passwords, but the bank's password history prevents 3.14 from doing so.

a)

Minimum password age

b)

Maximum password duration

c)

Password complexity

d)

No change is needed.

11.
A brute force attack:
a)
Uses response filtering
b)
Tries all possible password variations
c)
Uses the strongest possible algorithms
d)
Targets all the ports
12.

Passwords that contain recognizable words are vulnerable to a:

a)

Denial of Service attack

b)

Hashing attack

c)

Dictionary attack

d)

James attack

13.
What are three examples of two-factor authentication?
a)
A fingerprint and a pattern
A password and a smart card
A pin number and a debit card
b)
A password and a smart card
A username and a password
A pin number and a debit card
14.
Setting a minimum password age restricts when users can:
a)
Request a password reset
b)
Change their passwords
c)
Log on by using their passwords
d)
Set their own password expiration
15.

You are an intern at Roblox, Inc. Your manager asks you to make password guess attempts harder by limiting login attempts on company computers.

What should you do?

a)

Enforce password sniffing.

b)

Enforce password history.

c)

Make password complexity requirements higher.

d)

Implement account lockout policy

16.
Humongous Insurance is an online healthcare insurance company. During an annual security audit a security firm tests the strength of the company's password policy and suggests that Humongous Insurance implement password history policy. What is the likely reason that the security firm suggests this?
a)
Past passwords were easily cracked by the brute force method.
b)
Past passwords of users contained dictionary words.
c)
Previous password breaches involved use of past passwords.
d)
Past passwords lacked complexity and special characters.
17.
Keyloggers are specially designed software or hardware applications that capture network packets as they traverse a network, displaying them for the attacker.
a)
No change is needed
b)
Sniffers
c)
Key Generators
d)
Crack files
18.

Which of the following are not valid password controls? (Choose all that apply (I would pick two, but that is just me. You do whatever you want.))

a)

Minimum Password Age

b)

Maximum Password Age

c)

Maximum Password Length

d)

Account Lockout Threshold

19.

2. Which of the following would be an acceptable password on a Windows 7 Professional system with Password Complexity enabled and Minimum Password Length set to eight? (Choose all that apply. (ahem *coughpick3cough*))

a)

Summer2010

b)

$$Thx17i

c)

^^RGood4U

d)

Password

e)

St@rTr3k

20.

You are setting up your first secure Windows 7 Professional workstation and you are setting the password history. What are the minimum and maximum settings you can use?

a)

0, 14

b)

1, 14

c)

0, 24

d)

1, 24

e)

0, 998

21.

Three of these are configuration settings for account lockout. Which one is NOT?

a)

Account password age

b)

Account lockout duration

c)

Account lockout threshold

d)

Reset Account lockout counter after