WorksheetsESS Full EOC Review
Total questions: 200
Worksheet time: 2hrs 13mins
The exposure a system has to possible hacker
The part of the AAA process that includes identifying an individual
Authorization
Auditiing
Assessment
athenication
Auditing
Administration
authorization
authentication
adminstration
RADIUS
PIN
Kerberos
Bitlocker
Windows Hello
PGP
A type of attack that tries as many possible combinations of characters as time and money permits
Money attack
Hacker Attack
BLuesnarfing
Adminstration
Everyone
Remote Users
A list of certificates that are no longer considered safe
ACL
Expired Cert List
Certificate Path
admin account
RADIUS
inherited permission
A Windows feature that isolates and hardens key system and user security information.
Windows Hello
NTLM
Stenography
Plain Text
encryption
Security Token
ID Card
Mandatory Access Control
Rule_BAC
NTFS
A multiple firewall configuration used to secure hosts on a network segment.
Bastion Host
Single Honed Host
Chinese Wall
Router
Unified Threat Management Device
authentication server
Organizational Unit Server
RADIUS
A Microsoft system used to measure and rank the threats risk level.
Inherited Permissions
Explicit Permissions
ingress traffic
Email traffic
HTTPS traffic
inherited permissions
effective permissions
NTFS
Unified Threat Management Device
router
ACL
Domain Controller
NTFS
Stateless Firewall
IPSEC
HIDS
explicit permissions
effective permissions
A cytological method used to ensure integrity
hash
symmetric
non-repudiation
AES
intrusion prevention system
Windows HELLO
stateless firewall
Digital Certificate
RADIUS
TELNET
NTLM
RADIUS
Asymmetric
Computer Account
Admin
Guest
the physical or hardware address burned into each NIC
Digital Cert
IP address
IP6Address
access control model integrated in software used to control subject-to-object access functions through the use of clearance labels
Discretionary Access Control
Label Access Control
Physical Access Control
Kerberos Authentication
A Microsoft solution that allows administrators a more powerful way to control access to network resources. It's controls are based on the client computer's identity and whether that computer complies with the configured network governance policies.
RADIUS
Domain Controller
Secure Boot
host firewall
Remote Access Protocol
symmetric encryption
Permissions that allow you to control which users and groups can gain access to files and folders on a MS Windows system.
Effective Permissions
Inherited permissions
FAT32
APFS
ext3
Group Policy Object
Groups
group
Honey Net
Acceptable Use Policy
Digital Certificate
PIN
right
inherited permissions
Snort
NID
NIPS
Personal
password
A type of virus that changes to protect itself
macro virus
fileless virus
root virus
A security discipline that requires that a particular user only has access to what they need to do the job
separation of duty
risk
risk assessment
risk taking
permission
risk mitigation
risk matrix
residual risk
risk acceptance
residual risk
risk mitigation
risk acceptance
risk mitigation
risk transfer
risk acceptance
residual risk
risk avoidance
risk acceptance
risk avoidance
risk mitigation
A Flaw or weakness that allows a threat agent to bypass security
Vulnerabiliy
risk
risk acceptance
____ Access Control - uses a centrally administrated set of controls to determine how subjects and objects interact. The access control levels can be based upon the necessary operations and tasks a user needs to carry out to fulfill her responsibilities without an organization.
Role-Based
Mandatory
Rule
Discertionary
Firewall
Digital Certificate
User
AES
Digital Certificate
Windows Defender
Firewall
Acceptable Use Policy
Group Policy Object
RADIUS
Phone
USB drive
NTFS Permission
Group Policy Object
inherited permissions
VPN
Router
Web Server
Kerberos
symmetric encryption
Domain Controller
USB
mobile device
PIN
rubber ducky
packer squirel
malware
A method used to gain access to data by tricking people
rubber ducky
sniffing
DNS
In addition to examining the header information of the packets traversing the network this firewall verifies the state of the session.
stateless
packet filtering
personal
attack surface
risk mitigation
residual risk
risk
asset
vulnerability
UDP
TCP
SFTP
IMAP
password
Technology that securely links two computers through a wide-area network such as the Internet.
web server
telnet
MS Windows product designed to protect your computer against viruses
MS Excel
Windows Advanced Firewall
Windows Mobile
Windows Defender
Windows Clipart
ransomware
UDP flood
worm
A block cipher works on a single character at a time, and is faster than a stream cipher.
True
False
The process of converting plaintext to ciphertext.
cryptography
cyphertext
decryption
encryption
A method of encryption and decryption in which each letter in the alphabet is replaced by another.
encryption
decryption
substitution cypher
plaintext
A alogrithm that takes a varible string or block of data and converts it to a fixed length, unqiue data string is called
a hash
symmetric encryption
block encryption
Bit locker
Symmetric encryption supports what element(s) of information security? Select all that apply
Confidentiality
Non-Repudiation
Integrity
Availability
What are the disadvantages to using symmetric encryption? Select all that apply
Speed
Key Distribution
Scalability
Key Size
Which is NOT a symmetric encryption algorithm?
AES
DES
Blowfish
MD5
A chip on a computer’s motherboard that provides cryptographic services is called
TPM
Firmware
RAM
CryptoChip
Which IPsec protocol provides integrity protection for packet data but does not encrypt the IP header information?
AH
ESP
IKE
LDAP
In a modern network environment where there are multiple wireless access points within a building, which of the four types of tunneling protocols used with a VPN server/RAS server would be best to use?
PPTP
L2TP
SSTP
IKEv2
Which of the following protects against unauthorized access to confidential information via encryption and works at the network layer?
IPSEC
L2TP
Firewall
NAT
Which of the following is a US Federal government algorithm created to generate a hash
DES
3DES
AES
SHA
What must be trusted for the Public key Infrastructure (PKI) to work.
The CIO
The Certificate Authority
The Sender
The KDC
The most common digital certificate categories are: Select ALL
Personal digital certificates
Server digital certificates
Software publisher digital certificates
Internet digital certificates
When DoctorWho is encrypted to be Torchwood, this is an example of
transposition
substitution
stenography
AES
The use a of a Digital Signature supports what principle(s) of information security?
Non-repudiation
Confidentiality
Integrity
Availability
You have been tasked to setup a VPN with with a Windows 2016 Server. You plan to use kerbroes and smart cards. What authentication protocol will you need to use?
CHAP
PAP
MS-CHAP v2
EAP
How many different keys are used in encrypting and decrypting a file using EFS?
1
2
3
4
When using SSL/TLS to secure a HTTP session, is it the client or the sever that creates the symmetric key?
client
server
Ricardo wants to send secret messages to a competitor company. To secure these messages, he uses a technique of hiding a secret message within an ordinary message. The technique provides ‘security through obscurity’. What technique is Ricardo using?
Public-key cryptography
RSA algorithm
Steganography
Encryption
The network administrator for a company is setting up a website with e-commerce capabilities. Packet sniffing is a concern because credit card information will be sent electronically over the Internet. Customers visiting the site will need to encrypt the data. What can be added to protect the data?
Asymmetric Encryption
Confidential
Label to all data
Symmetric Encryption
Digital Certificate
You create a web server for the school. When users visit the site, they get a certificate error saying the site is not trusted. What is the best way to solve this problem?
Install a certificate on the web server from trusted Certificate Authority
Use a digital signature
Generate a self signed certificate and install it
Enable Public Keys on the website
A person approaches a network administrator and wants advice on how to send encrypted email from home. The end user does not want to have to pay for any license fees or manage server services. Which of the following is the most secure encryption protocol that the network administrator should recommend?
IP Security (IPSEC)
Multipurpose Internet Mail Extensions (MIME)
Pretty Good Privacy (PGP)
Hyper Text Transfer Protocol with Secure Socket Layer (HTTPS)
For messages sent through an insecure channel, a properly implemented digital signature gives the receiver reason to believe the message was sent by the claimed sender. While using a digital signature, the message digest is encrypted with which key?
Sender’s public key
Receiver’s private key
Receiver’s public key
Sender’s private key
Which specific element of security testing is being assured by using hash?
Authentication
Integrity
Confidentiality
Availability
How can rainbow tables be defeated?
Password salting
Lockout accounts under brute force password cracking attempts
All uppercase character passwords
Use of non-dictionary words
Which of the following is a symmetric cryptographic standard?
DSA
PKI
RSA
AES
A security professional that only hacks computers and networks when they have permission of the owner.
White Hat Hacker
Grey Hat Hacker
Black Hat Hacker
Purple Hat Hacker
You are volunteering at an organization that gets a brand new web server. To make the server more secure, you should _______ .
add a second administrator account
