wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

ESS Full EOC Review

Total questions: 200

Worksheet time: 2hrs 13mins

Name
Class
Date
1.
describes the constraints and practices that users must agree to in order to access the corporate network
a)
acceptable use policy
b)
computer account
c)
permission
d)
principle of least privilege
2.
A list of all users and groups that have access to an object.
a)
access control list (ACL)
b)
confidentiality
c)
personal firewall
d)
public key infrastructure (PKI)
3.
The process of restricting access to a resource to only permitted users
a)
access control
b)
cracked password
c)
personal identification number (PIN)
d)
registry
4.
Refers to the number of incorrect logon attempts permitted before a system locks an account. Each bad logon attempt is tracked by the bad logon counter
a)
account lockout
b)
Credential Guard
c)
polymorphic virus
d)
removable device
5.
Also known as auditing
a)
accounting
b)
decryption
c)
principle of least privilege
d)
residual risk
6.
Active Directory is a directory service technology created by Microsoft that provides a variety of network services
a)
Active Directory
b)
defense in depth
c)
public key infrastructure (PKI)
d)
right
7.
A shared folder typically used for administrative purposes.
a)
administrative share
b)
Device Guard
c)
registry
d)
risk acceptance
8.
Also known as proxy servers. Works by performing a deep inspection of application data as it traverses the firewall. Rules are set by analyzing client requests and application responses
a)
application level firewall
b)
dictionary attack
c)
removable device
d)
risk assessment
9.
enables you to control how users access and use programs and files and extends the functionality originally provided by the Software Windows 10 only. located in the Local Group Policy Editor
a)
AppLocker
b)
dictionary attack
c)
residual risk
d)
risk avoidance
10.
Also known as public key cryptography
a)
asymmetric encryption
b)
digital certificate
c)
right
d)
risk management
11.

The exposure a system has to possible hacker

a)
attack surface
b)
digital signature
c)
risk acceptance
d)
risk mitigation
12.
Also known as accounting
a)
auditing
b)
Discretionary Access Control
c)
risk assessment
d)
risk transfer
13.

The part of the AAA process that includes identifying an individual

a)
authentication
b)

Authorization

c)

Auditiing

d)

Assessment

14.
The process of giving individuals access to system objects based on their identity.
a)
authorization
b)

athenication

c)

Auditing

d)

Administration

15.
Describes a resource being accessible to a user
a)
availability
b)

authorization

c)

authentication

d)

adminstration

16.
An authentication method that identifies and recognizes people based on physical traits
a)
biometrics
b)

RADIUS

c)

PIN

d)

Kerberos

17.
A new feature in Windows 7 that enables users to encrypt removable USB devices
a)
BitLocker To Go
b)

Bitlocker

c)

Windows Hello

d)

PGP

18.

A type of attack that tries as many possible combinations of characters as time and money permits

a)
brute force attack
b)

Money attack

c)

Hacker Attack

d)

BLuesnarfing

19.
The default groups that are included within Windows or Active Directory.
a)
built in groups
b)

Adminstration

c)

Everyone

d)

Remote Users

20.
Also known as the certification path
a)
certificate chain
b)
effective permissions
c)
Secure Sockets Layer (SSL)
d)
security policy
21.

A list of certificates that are no longer considered safe

a)
certificate revocation list (CRL)
b)

ACL

c)

Expired Cert List

d)

Certificate Path

22.
Typically considered second-generation firewall technology. They work in a similar fashion to packet-filtering firewalls
a)
circuit level firewall
b)
email bomb
c)
security baseline
d)
share permissions
23.
A logical object that provides a means for authenticating and auditing a computer's access to a Windows network
a)
computer account
b)

admin account

c)

RADIUS

d)
shared folder
24.
The characteristic of a resource ensuring access is restricted to only permitted users
a)
confidentiality
b)
explicit permission
c)

inherited permission

d)
single sign on (SSO)
25.

A Windows feature that isolates and hardens key system and user security information.

a)
Credential Guard
b)

Windows Hello

c)

NTLM

d)
sniffers
26.
The process of converting data from encrypted format back to its original format.
a)
decryption
b)

Stenography

c)

Plain Text

d)

encryption

27.
Using multiple layers of security to defend your assets.
a)
defense in depth
b)
group
c)
single sign on (SSO)
d)
spoofing
28.
helps harden a computer system against malware by running only trusted applications
a)
Device Guard
b)
hash function
c)
smart card
d)
stateful inspection
29.
An attack that uses a dictionary containing an extensive list of potential passwords that the attacker then tries in conjunction with a user ID in an attempt to guess the appropriate password.
a)
dictionary attack
b)
Honeypot
c)
social engineering
d)
strong password
30.
An electronic document that contains an identity
a)
digital certificate
b)

Security Token

c)

ID Card

d)
symmetric encryption
31.
A mathematical scheme that is used to demonstrate the authenticity of a digital message or document. It is also used to prove that the message or document has not been modified.
a)
digital signature
b)
ingress traffic
c)
stateful inspection
d)
Syslog
32.
enables the owner of the resource to specify which subjects can access specific resources.
a)
Discretionary Access Control
b)

Mandatory Access Control

c)

Rule_BAC

d)

NTFS

33.

A multiple firewall configuration used to secure hosts on a network segment.

a)
DMZ (demilitarized zone)
b)

Bastion Host

c)

Single Honed Host

d)

Chinese Wall

34.
An attack against the cached information on your DNS server.
a)
DNS poisoning
b)
intrusion detection systems (IDS)
c)
symmetric encryption
d)
Trusted Platform Module (TPM) chip
35.
Adds security provisions to DNS so that computers can verify they have been directed to proper servers.
a)
DNS Security Extensions (DNSsec)
b)
intrusion prevention systems (IPS)
c)

Router

d)

Unified Threat Management Device

36.
A Windows server that stores a replica of the account and security information of a domain and defines the domain boundaries.
a)
domain controller
b)

authentication server

c)

Organizational Unit Server

d)

RADIUS

37.

A Microsoft system used to measure and rank the threats risk level.

a)
DREAD
b)
keylogger
c)
UDP Flood
d)
Group Policy Object (GPO)
38.
Actual permissions when logging in and accessing a file or folder. They consist of explicit permissions plus any inherited permissions.
a)
effective permissions
b)

Inherited Permissions

c)
Unified Threat Management (UTM)
d)

Explicit Permissions

39.
is network traffic that begins inside of a network and proceeds through its routers to its destination somewhere outside of the network
a)
egress traffic
b)

ingress traffic

c)

Email traffic

d)

HTTPS traffic

40.
Sends so many emails to a user or domain
a)
email bomb
b)
local user account
c)
user account
d)
Honey net
41.
Permissions granted directly to a file or folder.
a)
explicit permission
b)

inherited permissions

c)

effective permissions

d)

NTFS

42.
A system that is designed to protect a computer or a computer network from network-based attacks. Can be implemented by hardware or software and does this by filtering the data packets that are traversing the network.
a)
firewall
b)
member server
c)

Unified Threat Management Device

d)

router

43.
A set of rules that allow an administrator granular control over the configuration of objects in Active Directory (AD)
a)
Group Policy Object (GPO)
b)

ACL

c)

Domain Controller

d)

NTFS

44.
A collection of honeypots used to present an attacker with an even more realistic attack environment.
a)
Honey net
b)
Network Access Protection (NAP)
c)
polymorphic virus
d)
IP Security (IPsec)
45.
A trap for hackers.
a)
Honeypot
b)
network firewall
c)
principle of least privilege
d)
Kerberos
46.
A type of software firewall installed on a host and used to protect the host from network-based attacks.
a)
host firewall
b)

Stateless Firewall

c)

IPSEC

d)

HIDS

47.
Permissions granted to a folder (parent object or container) that flows into child objects (subfolders or files) inside that folder.
a)
inherited permission
b)
NTFS
c)

explicit permissions

d)

effective permissions

48.

A cytological method used to ensure integrity

a)

hash

b)

symmetric

c)

non-repudiation

d)

AES

49.
A solution designed to detect unauthorized user activities
a)
intrusion detection systems (IDS)
b)

intrusion prevention system

c)

Windows HELLO

d)

stateless firewall

50.
A suite of protocols that provides a mechanism for data integrity
a)
IP Security (IPsec)
b)

Digital Certificate

c)

RADIUS

d)

TELNET

51.
The default domain computer network authentication protocol
a)
Kerberos
b)

NTLM

c)

RADIUS

d)

Asymmetric

52.
A software or hardware device that that captures passwords and other critical data directly from the keyboard.
a)
keylogger
b)
password
c)
risk transfer
d)
mobile device
53.
include apps that are critical to running the company business as well as apps that are unique to the company's main business
a)
Line of Business (LOB) apps
b)
permission
c)
risk
d)
multifactor authentication
54.
A user account that is stored in the Security Account Manager (SAM) database on the local computer.
a)
local user account
b)

Computer Account

c)

Admin

d)

Guest

55.

the physical or hardware address burned into each NIC

a)
MAC address
b)

Digital Cert

c)

IP address

d)

IP6Address

56.

access control model integrated in software used to control subject-to-object access functions through the use of clearance labels

a)
Mandatory Access Control
b)

Discretionary Access Control

c)

Label Access Control

d)

Physical Access Control

57.
A server that is not running as a domain controller.
a)
member server
b)
principle of least privilege
c)
Security Account Manager (SAM)
d)
NTFS Permission
58.
is a two-factor authentication that consists of an enrolled device (such as a smartphone) and a Windows Hello (biometric) or PIN
a)
Microsoft Passport
b)
registry
c)

Kerberos Authentication

d)
NTLM
59.
Small devices that are used to process information
a)
mobile device
b)
removable device
c)
security policy
d)
Open Systems Interconnect (OSI)
60.
When two or more authentication methods are used to authenticate someone.
a)
multifactor authentication
b)
residual risk
c)
security token
d)
organizational units (OU)
61.

A Microsoft solution that allows administrators a more powerful way to control access to network resources. It's controls are based on the client computer's identity and whether that computer complies with the configured network governance policies.

a)
Network Access Protection (NAP)
b)

RADIUS

c)

Domain Controller

d)

Secure Boot

62.
A category of software firewall consists of applications that are installed on servers used to protect network segments from other network segments.
a)
network firewall
b)

host firewall

c)
shared folder
d)

Remote Access Protocol

63.
Prevents one party from denying the actions it has carried out.
a)
nonrepudiation
b)
risk assessment
c)
single sign on (SSO)
d)

symmetric encryption

64.

Permissions that allow you to control which users and groups can gain access to files and folders on a MS Windows system.

a)
NTFS Permission
b)

Effective Permissions

c)

Inherited permissions

d)
password
65.
The preferred file system for today's Windows operating system.
a)
NTFS
b)

FAT32

c)

APFS

d)

ext3

66.
A container used in Active Directory to help organize objects within a domain and minimize the number of domains.
a)
organizational units (OU)
b)

Group Policy Object

c)

Groups

d)
personal identification number (PIN)
67.
A identity that controls an object including what permissions are set on the object and to whom permissions are granted.
a)
owner
b)
Role
c)
STRIDE
d)

group

68.
A system that waits for an IDS to detect an attacker and then transfers the attacker to a special host where he or she cannot do any damage to the production environment.
a)
padded cell
b)

Honey Net

c)
strong password
d)
principle of least privilege
69.
dictates the length and complexity requirements for passwords and how often a password should be changed
a)
password policy
b)

Acceptable Use Policy

c)
symmetric encryption
d)
public key infrastructure (PKI)
70.
A secret series of characters that enables a user to access a particular file
a)
password
b)

Digital Certificate

c)

PIN

d)
registry
71.
Defines the type of access that is granted to an object (an object can be identified with a security identifier) or object attribute.
a)
permission
b)

right

c)
threat
d)

inherited permissions

72.
A type of software firewall installed on a host and used to protect the host from network-based attacks.
a)

Snort

b)

NID

c)

NIPS

d)

Personal

73.
A secret numeric password shared between a user and a system that can be used to authenticate the user to the system.
a)
personal identification number (PIN)
b)
security token
c)

password

d)
risk acceptance
74.

A type of virus that changes to protect itself

a)
polymorphic virus
b)

macro virus

c)

fileless virus

d)

root virus

75.

A security discipline that requires that a particular user only has access to what they need to do the job

a)
principle of least privilege
b)

separation of duty

c)
Universal Windows Platform (UWP) apps
d)
risk avoidance
76.
The risk that remains after measures have been taken to reduce the likelihood or minimize the effect of a particular event.
a)
residual risk
b)

risk

c)

risk assessment

d)

risk taking

77.
Authorizes a user to perform certain actions on a computer
a)
right
b)

permission

c)
zero day attacks
d)
Role
78.
The act of identifying and then making an informed decision to accept the likelihood and impact of a specific risk.
a)
risk acceptance
b)

risk mitigation

c)

risk matrix

d)

residual risk

79.
Identifies the risks that might impact your particular environment.
a)
risk assessment
b)

risk acceptance

c)

residual risk

d)

risk mitigation

80.
The process of eliminating a risk by choosing not to engage in an action or activity.
a)
risk avoidance
b)

risk acceptance

c)

risk mitigation

d)

risk transfer

81.
Taking steps to reduce the likelihood or impact of a risk.
a)
risk mitigation
b)

risk acceptance

c)

residual risk

d)

risk avoidance

82.
The act of taking steps to move responsibility for a risk to a third party through insurance or outsourcing.
a)
risk transfer
b)

risk acceptance

c)

risk avoidance

d)

risk mitigation

83.

A Flaw or weakness that allows a threat agent to bypass security

a)

Vulnerabiliy

b)
threat
c)

risk

d)

risk acceptance

84.

____ Access Control - uses a centrally administrated set of controls to determine how subjects and objects interact. The access control levels can be based upon the necessary operations and tasks a user needs to carry out to fulfill her responsibilities without an organization.

a)

Role-Based

b)

Mandatory

c)

Rule

d)

Discertionary

85.
Software protection against spyware
a)
Secure Content Management (SCM)
b)

Firewall

c)

Digital Certificate

d)

User

86.
A cryptographic system that uses two keys to encrypt data
a)
Secure Sockets Layer (SSL)
b)

AES

c)

Digital Certificate

d)
single sign on (SSO)
87.
A local security database found on most Windows computers.
a)
Security Account Manager (SAM)
b)
Universal Windows Platform (UWP) apps
c)

Windows Defender

d)

Firewall

88.
is a collection of security settings. should include Microsoft's recommended for configuring those settings
a)
security baseline
b)

Acceptable Use Policy

c)

Group Policy Object

d)

RADIUS

89.
is a written document that describes how a system
a)
security policy
b)
Windows Defender
c)
built in groups
d)
spoofing
90.
A physical device that an authorized computer services user is given to ease authentication.
a)
security token
b)

Phone

c)
certificate chain
d)

USB drive

91.
permissions assigned to shared folders or drives.
a)
share permissions
b)

NTFS Permission

c)

Group Policy Object

d)

inherited permissions

92.
Technology that allows access of data files over the network.
a)
shared folder
b)

VPN

c)

Router

d)

Web Server

93.
Technology that allows you to log on once and access multiple related but independent software systems without having to log in again.
a)
single sign on (SSO)
b)

Kerberos

c)

symmetric encryption

d)

Domain Controller

94.
A pocket-sized card with embedded integrated circuits consisting of nonvolatile memory storage components and perhaps dedicated security logic.
a)
smart card
b)

USB

c)

mobile device

d)

PIN

95.
A specially designed software (and in some cases hardware) applications that capture network packets as they traverse a network
a)
sniffers
b)

rubber ducky

c)

packer squirel

d)

malware

96.

A method used to gain access to data by tricking people

a)
social engineering
b)
cracked password
c)
Credential Guard
d)
threat
97.
The misuse of a network protocol to perpetrate a hoax on a host or a network device.
a)
spoofing
b)

rubber ducky

c)

sniffing

d)

DNS

98.

In addition to examining the header information of the packets traversing the network this firewall verifies the state of the session.

a)
stateful inspection
b)

stateless

c)

packet filtering

d)

personal

99.
A password that is hard to guess because it is long and has a mix of different types of characters. It also has random enough where it could not be easily guessed.
a)
strong password
b)
Device Guard
c)
dictionary attack
d)
Universal Windows Platform (UWP) apps
100.
Uses a single key to encrypt and decrypt data.
a)
symmetric encryption
b)
dictionary attack
c)
dictionary attack
d)
user account
101.
A standard for logging program messages that can be accessed by devices that would not otherwise have a method for communications.
a)
Syslog
b)
dictionary attack
c)
digital certificate
d)
virtual private network (VPN)
102.
is a procedure for optimizing network security by identifying vulnerabilities
a)
threat modelling
b)

attack surface

c)

risk mitigation

d)

residual risk

103.
An action or occurrence that could result in the breach
a)
threat
b)

risk

c)

asset

d)

vulnerability

104.
an international standard for a secure cryptoprocessor—to protect the private keys. Is used to encrypt the information
a)
Trusted Platform Module (TPM) chip
b)
Discretionary Access Control
c)
DMZ (demilitarized zone)
d)
zero day attacks
105.
is a sessionless networking protocol
a)

UDP

b)

TCP

c)

SFTP

d)

IMAP

106.
A comprehensive security product that includes protection against multiple threats. A UTM product typically includes a firewall
a)
Unified Threat Management (UTM)
b)
DNS poisoning
c)
DNS Security Extensions (DNSsec)
d)
Secure Sockets Layer (SSL)
107.
A logical object that enables a user to log on to a computer and domain.
a)
user account
b)

password

c)
domain controller
d)
security baseline
108.

Technology that securely links two computers through a wide-area network such as the Internet.

a)
virtual private network (VPN)
b)
domain controller
c)

web server

d)

telnet

109.

MS Windows product designed to protect your computer against viruses

a)
Windows Defender
b)

MS Excel

c)

Windows Advanced Firewall

d)
security policy
110.
is a Windows 10 biometric authentication system that uses a user's face
a)
Windows Hello
b)

Windows Mobile

c)

Windows Defender

d)

Windows Clipart

111.
These attacks are based on using unknown or recently announced vulnerabilities.
a)
zero day attacks
b)

ransomware

c)

UDP flood

d)

worm

112.
What is the best way to protect against social engineering?
a)
stronger encryption
b)
stronger authentication
c)
employee awareness
d)
risk mitigation
113.
What is the first line of defense when setting up a network?
a)
physically secure the network
b)
configure authentication
c)
configure encryption
d)
configure an ACL
114.
Which concept determines what resources users can access after they log on?
a)
authentication
b)
auditing
c)
access control
d)
defense in depth
115.
What is used to provide protection when one line of defense is breached?
a)
defense in depth
b)
attack surface
c)
principle of least privilege
d)
risk mitigation
116.
What is used to verify that an administrator is not accessing data that he should not be accessing?
a)
authentication
b)
encryption
c)
access control
d)
auditing
117.
What do you call the process in which a user is identified via a username and password?
a)
authentication
b)
authorization
c)
accounting
d)
auditing
118.
What is the process of giving individual access to a system or resource?
a)
authentication
b)
authorization
c)
accounting
d)
auditing
119.
What process prevents someone from denying that she accessed a resource?
a)
accounting
b)
authorization
c)
sniffing
d)
nonrepudiation
120.
What type of electronic document contains a public key?
a)
digital certificate
b)
biometrics
c)
PIN
d)
PAN
121.
What directory service is used with Windows domains?
a)
Active Directory
b)
E-Directory
c)
PAM
d)
Kerberos
122.
What type of server runs Active Directory?
a)
member server
b)
file server
c)
domain controller
d)
NTLAN server
123.
When you create a local user on a computer running in Windows 7, where is the user account stored?
a)
Active Directory
b)
SAM
c)
PAM
d)
SQL database
124.
Which type of group can be granted rights and permissions?
a)
security
b)
distribution
c)
authorizing
d)
SAM
125.
What authorizes a user to perform certain actions in Windows such as logging on or performing a backup?
a)
right
b)
permission
c)
accessible
d)
key
126.
When you grant access to print to a printer, what are you granting?
a)
right
b)
permission
c)
accessible
d)
key
127.
Where are users and permissions stored for an NTFS folder?
a)
access log
b)
access file
c)
registry
d)
ACL
128.
What type of permissions are assigned directly to a file or folder?
a)
explicit
b)
inherited
c)
encompassing
d)
overriding
129.
Which authentication sends the username and password in plain text?
a)
MS-CHAP
b)
CHAP
c)
PAP
d)
SPAP
130.
What is the most common form of authenication
a)
password
b)
PIN
c)
digital certificates
d)
smart cards
131.
What do you call a password that is at least seven characters long and uses three of the following categories (uppercase, lowercase, numbers, and special characters)?
a)
healthy password
b)
migrating password
c)
standard password
d)
complex password
132.
Which of the following is not a complex password?
a)
Platter*SAN
b)
John!Taylor
c)
Password01
d)
ThereisTimetoLive&Die
133.
What settings are used to keep track of incorrect logon attempts and lock the account if too many attempts are detected within a certain set time?
a)
account lockout
b)
password policy
c)
authentication tracker
d)
user parameters
134.
What setting is used to prevent users from reusing the same password over and over?
a)
minimum password age
b)
maximum password age
c)
password history
d)
account lockout
135.
What prevents users from changing a password multiple times so that they can change it to their original password?
a)
minimum password age
b)
maximum password age
c)
password history
d)
account lockout
136.
What malicious software captures every keystroke and sends it to a hacker?
a)
dictionary software
b)
password leaker
c)
keylogger
d)
sniffer
137.
What are the only passwords that should not expire?
a)
administrator accounts
b)
power users
c)
service accounts
d)
standard user
138.
On which OSI layer do routers function?
a)
1
b)
2
c)
3
d)
4
139.
In which OSI layer do TCP and UDP function?
a)
1
b)
2
c)
3
d)
4
140.
What OSI layer do switches and bridges use?
a)
1
b)
2
c)
3
d)
4
141.
On which OSI layer would you find FTP?
a)
3
b)
7
c)
5
d)
1
142.
What port does SMTP use?
a)
21
b)
23
c)
25
d)
443
143.
What port is HTTP usually on?
a)
25
b)
22
c)
80
d)
389
144.
What port does SSH use?
a)
22
b)
25
c)
443
d)
21
145.
What type of firewall is also known as a proxy server?
a)
packet-filtering
b)
circuit-filtering
c)
application-level
d)
stateful
146.
What technology can you use to isolate a network of servers so that they cannot interact with other servers?
a)
bridge
b)
switch
c)
router
d)
VLAN
147.
Which type of routing protocol sends the entire routing table to its neighbors?
a)
distance vector
b)
link state
c)
scalable driven
d)
infinity
148.
What special area serves as a buffer area between the Internet and the internal network and can be used to hold web servers that are accessed from the Internet?
a)
DMZ
b)
NAT
c)
VLAN
d)
PLC
149.
How many firewalls would you use to create a sandwich DMZ?
a)
1
b)
2
c)
3
d)
4
150.
You have several Internet web servers that need to communicate with a SQL server. Where would you place the SQL server?
a)
internal network
b)
DMZ
c)
Internet
d)
isolated VLAN
151.
Which IPsec protocol provides integrity protection for packet headers, data, and user authentication but does not encrypt the data load?
a)
AH
b)
ESP
c)
IKE
d)
LDAP
152.
Which type of malware can copy itself and infect a computer without the user's consent or knowledge?
a)
virus
b)
Trojan horse
c)
rootkit
d)
backdoor
153.
What type of self-replicating program copies itself to other computers on a network without any user intervention and consumes bandwidth and computer resources?
a)
virus
b)
Trojan horse
c)
worm
d)
backdoor
154.
What malware looks like a useful or desired executable program but is in reality program that is supposed to cause harm to your computer or steal information from your computer?
a)
virus
b)
Trojan horse
c)
worm
d)
backdoor
155.
What malware collects a user's personal information or details about your browsing habits without your knowledge?
a)
virus
b)
Trojan horse
c)
worm
d)
spyware
156.
What malware gives administrator-level control over a computer system?
a)
rootkit
b)
Trojan horse
c)
worm
d)
spyware
157.
What do you call a message warning you to delete an essential Windows file?
a)
virus hoax
b)
keylogger
c)
backdoor
d)
worm
158.
What Windows feature notifies you when something tries to make changes to your computer without your knowledge?
a)
WDS
b)
NAT
c)
Windows Defender
d)
UAC
159.
What do you call unsolicited junk email?
a)
spam
b)
j-mail
c)
junkettes
d)
Infected mail
160.
What email validation system is designed to stop spam that uses source address spoofing?
a)
Foremost Relay System
b)
Sender Policy Framework
c)
Spam Checking Networking
d)
Spoof Checker
161.
Which tab in Internet Explorer settings would you use to delete history and cookies?
a)
General
b)
Privacy
c)
Security
d)
Advanced
162.
Which Internet Explorer zone is the least secure?
a)
Internet zone
b)
local intranet zone
c)
trusted sites zone
d)
restricted sites zone
163.
What technique is used to send you to a fake, but realistic-looking, website to verify your account information?
a)
spoofing
b)
smurfing
c)
man-in-the-middle
d)
phishing
164.

A block cipher works on a single character at a time, and is faster than a stream cipher.

a)

True

b)

False

165.
What type of key is not shared and computers cannot decrypt a message without it?
a)
Free key
b)
Private key
c)
Public key
d)
Personal key
166.
Asymmetric encryption uses only 1 key.
a)
True
b)
False
167.

The process of converting plaintext to ciphertext.

a)

cryptography

b)

cyphertext

c)

decryption

d)

encryption

168.

A method of encryption and decryption in which each letter in the alphabet is replaced by another.

a)

encryption

b)

decryption

c)

substitution cypher

d)

plaintext

169.
What type of key can be freely shared with anyone so that they can encrypt a message?
a)
Personal key
b)
Private key
c)
Free key
d)
Public key
170.

A alogrithm that takes a varible string or block of data and converts it to a fixed length, unqiue data string is called

a)

a hash

b)

symmetric encryption

c)

block encryption

d)

Bit locker

171.

Symmetric encryption supports what element(s) of information security? Select all that apply

a)

Confidentiality

b)

Non-Repudiation

c)

Integrity

d)

Availability

172.

What are the disadvantages to using symmetric encryption? Select all that apply

a)

Speed

b)

Key Distribution

c)

Scalability

d)

Key Size

173.

Which is NOT a symmetric encryption algorithm?

a)

AES

b)

DES

c)

Blowfish

d)

MD5

174.

A chip on a computer’s motherboard that provides cryptographic services is called

a)

TPM

b)

Firmware

c)

RAM

d)

CryptoChip

175.

Which IPsec protocol provides integrity protection for packet data but does not encrypt the IP header information?

a)

AH

b)

ESP

c)

IKE

d)

LDAP

176.

In a modern network environment where there are multiple wireless access points within a building, which of the four types of tunneling protocols used with a VPN server/RAS server would be best to use?

a)

PPTP

b)

L2TP

c)

SSTP

d)

IKEv2

177.

Which of the following protects against unauthorized access to confidential information via encryption and works at the network layer?

a)

IPSEC

b)

L2TP

c)

Firewall

d)

NAT

178.

Which of the following is a US Federal government algorithm created to generate a hash

a)

DES

b)

3DES

c)

AES

d)

SHA

179.
Which of the following features are used in Bitlocker, but not  BitLocker-To-Go?
a)
Encryption
b)
TPM Chip
c)
Password requirement
d)
Safe Mode
180.
The main purpose of Bitlocker is to _____?
a)
Find your device when it is lost.
b)
Backup your data when it is corrupted.
c)
To prevent PC from being stolen.
d)
To encrypt volumes data on a drive
181.

What must be trusted for the Public key Infrastructure (PKI) to work.

a)

The CIO

b)

The Certificate Authority

c)

The Sender

d)

The KDC

182.

The most common digital certificate categories are: Select ALL

a)

Personal digital certificates

b)

Server digital certificates

c)

Software publisher digital certificates

d)

Internet digital certificates

183.

When DoctorWho is encrypted to be Torchwood, this is an example of

a)

transposition

b)

substitution

c)

stenography

d)

AES

184.

The use a of a Digital Signature supports what principle(s) of information security?

a)

Non-repudiation

b)

Confidentiality

c)

Integrity

d)

Availability

185.

You have been tasked to setup a VPN with with a Windows 2016 Server. You plan to use kerbroes and smart cards. What authentication protocol will you need to use?

a)

CHAP

b)

PAP

c)

MS-CHAP v2

d)

EAP

186.

How many different keys are used in encrypting and decrypting a file using EFS?

a)

1

b)

2

c)

3

d)

4

187.

When using SSL/TLS to secure a HTTP session, is it the client or the sever that creates the symmetric key?

a)

client

b)

server

188.

Ricardo wants to send secret messages to a competitor company. To secure these messages, he uses a technique of hiding a secret message within an ordinary message. The technique provides ‘security through obscurity’. What technique is Ricardo using?

a)

Public-key cryptography

b)

RSA algorithm

c)

Steganography

d)

Encryption

189.

The network administrator for a company is setting up a website with e-commerce capabilities. Packet sniffing is a concern because credit card information will be sent electronically over the Internet. Customers visiting the site will need to encrypt the data. What can be added to protect the data?

a)

Asymmetric Encryption

b)

Confidential

Label to all data

c)

Symmetric Encryption

d)

Digital Certificate

190.

You create a web server for the school. When users visit the site, they get a certificate error saying the site is not trusted. What is the best way to solve this problem?

a)

Install a certificate on the web server from trusted Certificate Authority

b)

Use a digital signature

c)

Generate a self signed certificate and install it

d)

Enable Public Keys on the website

191.

A person approaches a network administrator and wants advice on how to send encrypted email from home. The end user does not want to have to pay for any license fees or manage server services. Which of the following is the most secure encryption protocol that the network administrator should recommend?

a)

IP Security (IPSEC)

b)

Multipurpose Internet Mail Extensions (MIME)

c)

Pretty Good Privacy (PGP)

d)

Hyper Text Transfer Protocol with Secure Socket Layer (HTTPS)

192.

For messages sent through an insecure channel, a properly implemented digital signature gives the receiver reason to believe the message was sent by the claimed sender. While using a digital signature, the message digest is encrypted with which key?

a)

Sender’s public key

b)

Receiver’s private key

c)

Receiver’s public key

d)

Sender’s private key

193.

Which specific element of security testing is being assured by using hash?

a)

Authentication

b)

Integrity

c)

Confidentiality

d)

Availability

194.

How can rainbow tables be defeated?

a)

Password salting

b)

Lockout accounts under brute force password cracking attempts

c)

All uppercase character passwords

d)

Use of non-dictionary words

195.

Which of the following is a symmetric cryptographic standard?

a)

DSA

b)

PKI

c)

RSA

d)

AES

196.
describes the constraints and practices that users must agree to in order to access the corporate network
a)
acceptable use policy
b)
computer account
c)
permission
d)
principle of least privilege
197.
A collection or list of user accounts or computer accounts.
a)
group
b)
mobile device
c)
personal firewall
d)
intrusion detection systems (IDS)
198.
The risk that remains after measures have been taken to reduce the likelihood or minimize the effect of a particular event.
a)
residual risk
b)
social engineering
c)
Windows Hello
d)
risk
199.

A security professional that only hacks computers and networks when they have permission of the owner.

a)

White Hat Hacker

b)

Grey Hat Hacker

c)

Black Hat Hacker

d)

Purple Hat Hacker

200.

You are volunteering at an organization that gets a brand new web server. To make the server more secure, you should _______ .

a)
Disable unused services
b)
Enable LM authentication
c)
Enable NTLM authentication
d)

add a second administrator account