WorksheetsSecurity+ Practice
Total questions: 100
Worksheet time: 49mins
Which of the Following authentication services uses a ticket granting system to provide access?
RADIUS
LDAP
TACACS+
Kereberos
SERVER: Port 88 .
Which Authentication services would use this port by default?
Keberos
TACACS+
LDAP
RADIUS
Which of the following was based on previous X.500 specification and allows either unencrypted authentication or encrypted authentication through the use of TLS?
Kerberos
TACACS+
RADIUS
LDAP
A system administrator of configuring UNIX accounts to authenticate against an external server. The configuration file asks for the following information DC+ServerName and DC=COM.
RADIUS
SAML
TACACS+
LDAP
The system administrator is configuring UNIX accounts to authenticate against an external server. The configuration file asks for the following information DC=ServerName and DC=COM.
Which Following authentication services is being used?
RADIUS
SAML
TACACS+
LDAP
Which of the following is an XML based open standard used in the exchange of authentication and......
LDAP
SAML
TACACAS+
Kerbesos
Which of the following is an authentication method that can be secured by using SSL?
RADIUS
LDAP
TACACS+
Kerberos
Which of the following provides a user ID and password together?
Authorization
Auditing
Authentication
The fundamental information security principals include confidentiality, availability and ____________?
The ability to secure data against unauthorized disclosure to external sources
The capacity of a system to resist unauthorized changes to stored information
The confidence with which a system can attest to the identity of a user
Which of the following is the difference between identification and authentication of a user?
Identification tells who the user is and authentication tells whether the user is allowed to logon to a system.
Identification tells who the user is and authentication proves it.
Identification proves who the user is and authentication tells the user what they are allowed to do.
A network administrator has a separate user account with rights to the domain administrator group. However, they cannot remember the password to this account and are not able to login to the server when needed.
Which of the following is MOST accurate in describing the type of issue the administrator is experiencing?
Single sign-on
Authentication
Access Control
Authorization
Ann works at a small company and she is concerned that there is no oversight in the finance department; specifically, that Joe writes, signs and distributes paycheques, as well as other expenditures. Which of the following controls can she implement to address this concern?
Mandatory Vacations
Time of Day Restrictions
Lease Privilege
Seperation of Duties
A security administrator implements access controls based on the security classification of the data and need-to-know information.
Implicit Deny
Role-based Access Control
Mandatory Access Controls
Least Privilege
Which of the following presents the STRONGEST access control?
DAC
MAC
TACACS
RBAC
A user reports being unable to access a file on a network share. The security administrator determines that the file is marked as confidential and that the user does not have the appropriate access level for that file.
AC=Access Control
Which of the following is being implemented?
Mandatory AC
Discretionary AC
Rule Based AC
Role Based AC
Which of the following common access control (AC) models is commonly used on systems to ensure a "need to know" based on classification levels?
Role based AC
Mandatory AC
Discretionary AC
Access Control List
Which of the following access controls enforces permissions based on data labeling at specific levels?
Mandatory AC
Seperation of Duties AC
Discretionary AC
Role based AC
Joe has read and write access to his own home directory. Joe and Ann are collaborating on a project, and Joe would like to give Ann write access to one particular file in this home directory.
Which of the following types of access control would this reflect?
ROLE-BASED AC
RULE-BASED
MANDATORY AC
DISCRETIONARY AC
The IT department has set up a share point site to be used on the intranet. Security has established the groups and permissions on the site. No one may modify the permissions and all requests for access are centrally managed by the security team.
Which of the following control types is this an example of?
RULE-BASED AC
MANDATORY AC
USER ASSIGNED PRIVILAGE
DISCRETIONARY AC
A security technician is working with the network firewall team to implement access controls at the company’s demarc as part of the initiation of configuration management processes. One of the network technicians asks the security technician to explain the access control type found in a firewall.
With which of the following should the security technician respond?
RULE BASED AC
ROLE BASED AC
DISCRETIONARY AC
MANDATORY AC
During the information gathering stage of a deploying role-based access control model, which of the following information is MOST likely required?
Conditional rules under which certain systems may be accessed
Matrix of job titles with required access privileges
Clearance levels of all company personnel
Normal hours of business operation
A company hired Joe, an accountant. The IT administrator will need to create a new account for Joe. The company uses groups for ease of management and administration of user accounts. Joe will need network access to all directories, folders and files within the accounting department.
Which of the following configurations will meet the requirements?
Create two accounts: a user account and an account with full network administration rights.
Create an account with role-based access control for accounting.
Create a user account and assign the user account to the accounting group.
Users require access to a certain server depending on their job function.
Which of the following would be the MOST appropriate strategy for securing the server?
Common Access Card
Role based access control
discretionary access control
The company’s sales team plans to work late to provide the Chief Executive Officer (CEO) with a special report of sales before the quarter ends. After working for several hours, the team finds they cannot save or print the reports.
Which of the following controls is preventing them from completing their work?
Discretionary access control
Role Based Access control
Time of Day access control
D.
Mandatory access control
Which of the following security concepts can prevent a user from logging on from home during the weekends?
Time of day restrictions
Implicit Deny
Common access card
multifactor authentication
A technician is reviewing the logical access control method an organization uses. One of the senior managers requests that the technician prevent staff members from logging on during nonworking days.
Which of the following should the technician implement to meet managements request?
Enforce Kerberos
Deploy smart cards
Time of day restrictions
Ann, the security administrator, wishes to implement multifactor security.
Which of the following should be implemented in order to compliment password usage and smart cards?
Hard tokens
Fingerprint readers
Swipe Badge Readers
Pass-phrases
A network administrator uses an RFID card to enter the datacenter, a key to open the server rack, and a username and password to logon to a server.
Which of the following is these examples of?
Multi-Factor Authentication
Single-Factor Authentication
Seperation of Duties
Identification
Use of a smart card to authenticate remote servers remains MOST susceptible to the following attacks:
Malicious code on the local system
Shoulder Surfing
Brute force certificate cracking
Distributed dictionary attacks
Employee badges are encoded with a private encryption key and specific personal information. The encoding is then used to provide access to the network.
Which of the following describes this access control type?
Smart card
token
discretionary access control
mandatory access control
A Chief Information Security Officer (CISO) wants to implement two-factor authentication within the company.
Which of the following would fulfill the CISO’s requirements?
Username and password
retina scan and fingerprint scan
USB token and PIN
Proximity badge and token
A technician wants to implement a dual factor authentication system that will enable the organization to authorize access to sensitive systems on a need-to-know basis.
Which of the following should be implemented during the authorization stage?
Biometrics
Mandatory access control
Single Sign On
Role-based access control
Which of the following is an example of multifactor authentication?
Credit card and PIN
Username and password
Password and Pin
Finger print and retina scan
Which of the following protocols provides for mutual authentication of the client and server?
Radius
Secure LDAP
Biometrics
A company with a US-based sales force has requested that the VPN system be configured to authenticate the sales team based on their username, password and a client side certificate.
Additionally, the security administrator has restricted the VPN to only allow authentication from the US territory.
How many authentication factors are in use by the VPN system?
1
2
3
4
A company requires that a user’s credentials include providing something they know and something they are in order to gain access to the network.
Which of the following types of authentication is being described?
biometrics
kerberos
token
two factor
One of the most basic ways to protect the confidentiality of data on a laptop in the event the device is physically stolen is to implement the following:
Whole disk encryption with two-factor authentication
BIOS passwords and two-factor authentication
File level encryption with alphanumeric passwords
Speaking a passphrase into a voice print analyzer is an example of the following security concepts:
Two factor authentication
identification and authentication
single sign on
Which of the following BEST describes using a smart card and typing in a PIN to gain access to a system?
Mutlifactor authentication
PKI
Single sign on
All of the above
An organization has introduced token-based authentication to system administrators due to risk of password compromise. The tokens have a set of numbers that automatically change every 30 seconds.
Which of the following type of authentication mechanism is this?
TOTP
SMART CARD
CHAP
HOTP
A security technician has been asked to recommend an authentication mechanism that will allow users to authenticate using a password that will only be valid for a predefined time interval.
Which of the following should the security technician recommend?
chap
totp
hotp
pap
Which of the following is commonly LDAP and Kerberos used for?
To utilize single sign-on capabilities
perform queries on a directory service
sign SSL wildcard certificates for subdomains
After Ann, a user, logs into her banking websites she has access to her financial institution mortgage, credit card, and brokerage websites as well.
Which of the following is being described?
Trusted
Mandatory access control
seperation of duties
Single sign-on
A company wants to ensure that all credentials for various systems are saved within a central database so that users only have to login once for access to all systems.
Which of the following would accomplish this?
Single sign on
Smart card access
Same sign on
A user attempting to log on to a workstation for the first time is prompted for the following information before being granted access: username, password, and a four-digit security pin that was mailed to him during account registration.
Which of the following is this an example of?
Dual factor authentication
multi factor authentication
single factor authentication
biometric authentication
Which of the following allows a network administrator to implement an access control policy based on individual user characteristics and NOT on job function?
attributes based
implicit deny
role based
rule based
Which of the following is the best practice to put at the end of an ACL?
Implicit deny
Time of day restrictions
implicit allow
SNMP STRING
Users report that they are unable to access network printing services. The security technician checks the router access list and sees that web, email, and secure shell are allowed.
Which of the following is blocking network printing?
PORT SECRUTIY
FLOOD GUARDS
IMPLICIT DENY
LOOP PROTECTION
In order for Sara, a client, to logon to her desktop computer, she must provide her username, password, and a four-digit PIN.
Which of the following authentication methods is Sara using?
three factor
single factor
two factor
foul factor
The product requires one user name and password at the time of boot up and also another password after the operating system has finished loading.
Which of the following authentication types is this setup using?
single sign on
single factor authentication
same card
Which of the following is a measure of biometrics performance which rates the ability of a system to correctly authenticate an authorized user?
type ii
mean time to reigister
capacity
Use of group accounts should be minimized to ensure the following:
password security
regular auditing
baseline management
individual accountability
A network inventory discovery application requires non-privileged access to all hosts on a network for inventory of installed applications. A service account is created by the network inventory discovery application for accessing all hosts.
Which of the following is the MOST efficient method for granting the account non-privileged access to the hosts?
Implement Group Policy to add the account to the users group on the hosts
Add the account to the Users group on the hosts
Add the account to the Domain Administrator group
A group policy requires users in an organization to use strong passwords that must be changed every 15 days. Joe and Ann were hired 16 days ago. When Joe logs into the network, he is prompted to change his password; when Ann logs into the network, she is not prompted to change her password.
Which of the following BEST explains why Ann is not required to change her password?
Ann’s user account was not added to the group policy.
Joe’s user account was inadvertently disabled and must be re-created.
B.
Joe’s user account was not added to the group policy.
Ann’s user account has administrator privileges.
The system administrator is tasked with changing the administrator password across all 2000 computers in the organization.
Which of the following should the system administrator implement to accomplish this task?
GROUP POLICY
KEY ESCROW
CERTIFICATE REVOCATION
An auditing team has found that passwords do not meet the best business practices.
Password Complexity and Password history
Password Expiration
Length
History
Which of the following passwords is the LEAST complex?
MyTRAIN!45
Mytr@in!!
MyTr@in12
A security administrator wants to check user password complexity.
Which of the following is the BEST tool to use?
Password history
password logging
password cracker
password hashing
desktop configuration settings have changed. Upon a review of the CCTV logs, it is determined that someone logged into Ann’s workstation.
Which of the following could have prevented this from happening?
Password complexity policy
user reviews
shared acc.
permission policy
After a recent internal audit, the security administrator was tasked to ensure that all credentials must be changed within 90 days, cannot be repeated, and cannot contain any dictionary words or patterns. All credentials will remain enabled regardless of the number of attempts made.
Password Exp and Password Complexity
Lock out
Privelages
An internal auditing team would like to strengthen the password policy to support special characters.
Which of the following types of password controls would achieve this goal?
Add reverse encryption
Password complexity
Allow single sign on
