wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Security+ Practice

Total questions: 100

Worksheet time: 49mins

Name
Class
Date
1.
MMC
a)
MICROSOFT MANAGEMENT CONSOLE
b)
MICRO MANAGEMENT CONSOLATION
c)
MICRO MANAGEMENT CONSOLE
d)
MICROSOFT MANAGING CONSOLE
2.
MIMO
a)
MULTIPLE INPUT MULTIPLE OUTPUT
b)
MANY INPUT MANY OUTPUT
c)
MULTITUDE INPUT MULTITUDE OUTPUT
d)
MASSIVE INPUT MASSIVE OUTPUT
3.
MIME
a)
MULTIPURPOSE INTERNET MAIL EXTENDED
b)
MULTIPURPOSE INTERNET MAIL EXTENSION
c)
MULTIPURPOSE INTERNET MAP EXTENDED
d)
MULTIPURPOSE INTERNET MAP EXTENSION
4.
MFD
a)
Multi-Functioning Disc
b)
Multi-Functioning Disc Drive
c)
Multi-Functioning Device
d)
Multi-Functioning DVD
5.
MBSA
a)
Microsoft Baseline Security Analyzer
b)
Megabyte Serial Attachment
c)
Maps Business Security Attachment
d)
Makers Bits Seeing Association
6.
MBR
a)
Master Boot Recrd
b)
Master Boot Record
c)
Master Boots Rec
d)
Master Boot Rem
7.
AGP
a)
Acclimated Graphics Port
b)
LASER
c)
Accelerated Gliffy Port
d)
Accelerated Graphics Port
8.
DHCP
a)
Dead Host Configuration Protocol
b)
Dynamic Home Configuration Protocol
c)
Dynamic Host Configuration Protocol
d)
Dynamic Host Central Protocl
9.
DNS
a)
Domain Name Service
b)
Double Name Service
c)
Domain Nominal Service
d)
Double Name Server
10.
IDE
a)
Integrated Drive Electronics
b)
Internet Drive Electronics
c)
Integrated Digital Electronics
d)
Infrared Drive Electronics
11.
WPA
a)
Wireless Protected Access
b)
Wireless Port Access
12.
ftp
a)
20/21
b)
445
c)
67/68
d)
427
13.
ssh
a)
22
b)
137/138/139
c)
443
d)
445
14.
telnet
a)
23
b)
20/21
c)
137/138/139
d)
443
15.
smtp
a)
25
b)
67/68
c)
20/21
d)
53
16.
dns
a)
53
b)
548
c)
25
d)
20/21
17.
http
a)
80
b)
53
c)
23
d)
143
18.
pop3
a)
110
b)
3389
c)
427
d)
23
19.
https
a)
443
b)
80
c)
110
d)
137/138/139
20.
rdp
a)
3389
b)
443
c)
548
d)
389
21.
netbios
a)
137/138/139
b)
143
c)
80
d)
3389
22.
slp
a)
427
b)
25
c)
143
d)
67/68
23.
smb
a)
445
b)
389
c)
53
d)
110
24.
afp
a)
548
b)
427
c)
22
d)
25
25.
dhcp
a)
67/68
b)
23
c)
445
d)
22
26.
ldap
a)
389
b)
22
c)
3389
d)
548
27.

Which of the Following authentication services uses a ticket granting system to provide access?

a)

RADIUS

b)

LDAP

c)

TACACS+

d)

Kereberos

28.

SERVER: Port 88 .

Which Authentication services would use this port by default?

a)

Keberos

b)

TACACS+

c)

LDAP

d)

RADIUS

29.

Which of the following was based on previous X.500 specification and allows either unencrypted authentication or encrypted authentication through the use of TLS?

a)

Kerberos

b)

TACACS+

c)

RADIUS

d)

LDAP

30.

A system administrator of configuring UNIX accounts to authenticate against an external server. The configuration file asks for the following information DC+ServerName and DC=COM.

a)

RADIUS

b)

SAML

c)

TACACS+

d)

LDAP

31.

The system administrator is configuring UNIX accounts to authenticate against an external server. The configuration file asks for the following information DC=ServerName and DC=COM.


Which Following authentication services is being used?

a)

RADIUS

b)

SAML

c)

TACACS+

d)

LDAP

32.

Which of the following is an XML based open standard used in the exchange of authentication and......

a)

LDAP

b)

SAML

c)

TACACAS+

d)

Kerbesos

33.

Which of the following is an authentication method that can be secured by using SSL?

a)

RADIUS

b)

LDAP

c)

TACACS+

d)

Kerberos

34.

Which of the following provides a user ID and password together?

a)

Authorization

b)

Auditing

c)

Authentication

35.

The fundamental information security principals include confidentiality, availability and ____________?

a)

The ability to secure data against unauthorized disclosure to external sources

b)

The capacity of a system to resist unauthorized changes to stored information

c)

The confidence with which a system can attest to the identity of a user

36.

Which of the following is the difference between identification and authentication of a user?

a)

Identification tells who the user is and authentication tells whether the user is allowed to logon to a system.

b)

Identification tells who the user is and authentication proves it.

c)

Identification proves who the user is and authentication tells the user what they are allowed to do.

37.

A network administrator has a separate user account with rights to the domain administrator group. However, they cannot remember the password to this account and are not able to login to the server when needed.


Which of the following is MOST accurate in describing the type of issue the administrator is experiencing?

a)

Single sign-on

b)

Authentication

c)

Access Control

d)

Authorization

38.

Ann works at a small company and she is concerned that there is no oversight in the finance department; specifically, that Joe writes, signs and distributes paycheques, as well as other expenditures. Which of the following controls can she implement to address this concern?

a)

Mandatory Vacations

b)

Time of Day Restrictions

c)

Lease Privilege

d)

Seperation of Duties

39.

A security administrator implements access controls based on the security classification of the data and need-to-know information.

a)

Implicit Deny

b)

Role-based Access Control

c)

Mandatory Access Controls

d)

Least Privilege

40.

Which of the following presents the STRONGEST access control?

a)

DAC

b)

MAC

c)

TACACS

d)

RBAC

41.

A user reports being unable to access a file on a network share. The security administrator determines that the file is marked as confidential and that the user does not have the appropriate access level for that file.


AC=Access Control


Which of the following is being implemented?

a)

Mandatory AC

b)

Discretionary AC

c)

Rule Based AC

d)

Role Based AC

42.

Which of the following common access control (AC) models is commonly used on systems to ensure a "need to know" based on classification levels?

a)

Role based AC

b)

Mandatory AC

c)

Discretionary AC

d)

Access Control List

43.

Which of the following access controls enforces permissions based on data labeling at specific levels?

a)

Mandatory AC

b)

Seperation of Duties AC

c)

Discretionary AC

d)

Role based AC

44.

Joe has read and write access to his own home directory. Joe and Ann are collaborating on a project, and Joe would like to give Ann write access to one particular file in this home directory.

Which of the following types of access control would this reflect?

a)

ROLE-BASED AC

b)

RULE-BASED

c)

MANDATORY AC

d)

DISCRETIONARY AC

45.

The IT department has set up a share point site to be used on the intranet. Security has established the groups and permissions on the site. No one may modify the permissions and all requests for access are centrally managed by the security team.


Which of the following control types is this an example of?

a)

RULE-BASED AC

b)

MANDATORY AC

c)

USER ASSIGNED PRIVILAGE

d)

DISCRETIONARY AC

46.

A security technician is working with the network firewall team to implement access controls at the company’s demarc as part of the initiation of configuration management processes. One of the network technicians asks the security technician to explain the access control type found in a firewall.

With which of the following should the security technician respond?

a)

RULE BASED AC

b)

ROLE BASED AC

c)

DISCRETIONARY AC

d)

MANDATORY AC

47.

During the information gathering stage of a deploying role-based access control model, which of the following information is MOST likely required?

a)

Conditional rules under which certain systems may be accessed

b)

Matrix of job titles with required access privileges

c)

Clearance levels of all company personnel

d)

Normal hours of business operation

48.

A company hired Joe, an accountant. The IT administrator will need to create a new account for Joe. The company uses groups for ease of management and administration of user accounts. Joe will need network access to all directories, folders and files within the accounting department.

Which of the following configurations will meet the requirements?

a)

Create two accounts: a user account and an account with full network administration rights.

b)

Create an account with role-based access control for accounting.

c)

Create a user account and assign the user account to the accounting group.

49.

Users require access to a certain server depending on their job function.


Which of the following would be the MOST appropriate strategy for securing the server?

a)

Common Access Card

b)

Role based access control

c)

discretionary access control

50.

The company’s sales team plans to work late to provide the Chief Executive Officer (CEO) with a special report of sales before the quarter ends. After working for several hours, the team finds they cannot save or print the reports.

Which of the following controls is preventing them from completing their work?

a)

Discretionary access control

b)

Role Based Access control

c)

Time of Day access control

d)

D.

Mandatory access control

51.

Which of the following security concepts can prevent a user from logging on from home during the weekends?

a)

Time of day restrictions

b)

Implicit Deny

c)

Common access card

d)

multifactor authentication

52.

A technician is reviewing the logical access control method an organization uses. One of the senior managers requests that the technician prevent staff members from logging on during nonworking days.

Which of the following should the technician implement to meet managements request?

a)

Enforce Kerberos

b)

Deploy smart cards

c)

Time of day restrictions

53.

Ann, the security administrator, wishes to implement multifactor security.

Which of the following should be implemented in order to compliment password usage and smart cards?

a)

Hard tokens

b)

Fingerprint readers

c)

Swipe Badge Readers

d)

Pass-phrases

54.

A network administrator uses an RFID card to enter the datacenter, a key to open the server rack, and a username and password to logon to a server.


Which of the following is these examples of?

a)

Multi-Factor Authentication

b)

Single-Factor Authentication

c)

Seperation of Duties

d)

Identification

55.

Use of a smart card to authenticate remote servers remains MOST susceptible to the following attacks:

a)

Malicious code on the local system

b)

Shoulder Surfing

c)

Brute force certificate cracking

d)

Distributed dictionary attacks

56.

Employee badges are encoded with a private encryption key and specific personal information. The encoding is then used to provide access to the network.

Which of the following describes this access control type?

a)

Smart card

b)

token

c)

discretionary access control

d)

mandatory access control

57.

A Chief Information Security Officer (CISO) wants to implement two-factor authentication within the company.

Which of the following would fulfill the CISO’s requirements?

a)

Username and password

b)

retina scan and fingerprint scan

c)

USB token and PIN

d)

Proximity badge and token

58.

A technician wants to implement a dual factor authentication system that will enable the organization to authorize access to sensitive systems on a need-to-know basis.

Which of the following should be implemented during the authorization stage?

a)

Biometrics

b)

Mandatory access control

c)

Single Sign On

d)

Role-based access control

59.

Which of the following is an example of multifactor authentication?

a)

Credit card and PIN

b)

Username and password

c)

Password and Pin

d)

Finger print and retina scan

60.

Which of the following protocols provides for mutual authentication of the client and server?

a)

Radius

b)

Secure LDAP

c)

Biometrics

61.

A company with a US-based sales force has requested that the VPN system be configured to authenticate the sales team based on their username, password and a client side certificate.

Additionally, the security administrator has restricted the VPN to only allow authentication from the US territory.

How many authentication factors are in use by the VPN system?

a)

1

b)

2

c)

3

d)

4

62.

A company requires that a user’s credentials include providing something they know and something they are in order to gain access to the network.

Which of the following types of authentication is being described?

a)

biometrics

b)

kerberos

c)

token

d)

two factor

63.

One of the most basic ways to protect the confidentiality of data on a laptop in the event the device is physically stolen is to implement the following:

a)

Whole disk encryption with two-factor authentication

b)

BIOS passwords and two-factor authentication

c)

File level encryption with alphanumeric passwords

64.

Speaking a passphrase into a voice print analyzer is an example of the following security concepts:

a)

Two factor authentication

b)

identification and authentication

c)

single sign on

65.

Which of the following BEST describes using a smart card and typing in a PIN to gain access to a system?

a)

Mutlifactor authentication

b)

PKI

c)

Single sign on

d)

All of the above

66.

An organization has introduced token-based authentication to system administrators due to risk of password compromise. The tokens have a set of numbers that automatically change every 30 seconds.

Which of the following type of authentication mechanism is this?

a)

TOTP

b)

SMART CARD

c)

CHAP

d)

HOTP

67.

A security technician has been asked to recommend an authentication mechanism that will allow users to authenticate using a password that will only be valid for a predefined time interval.

Which of the following should the security technician recommend?

a)

chap

b)

totp

c)

hotp

d)

pap

68.

Which of the following is commonly LDAP and Kerberos used for?

a)

To utilize single sign-on capabilities

b)

perform queries on a directory service

c)

sign SSL wildcard certificates for subdomains

69.

After Ann, a user, logs into her banking websites she has access to her financial institution mortgage, credit card, and brokerage websites as well.

Which of the following is being described?

a)

Trusted

b)

Mandatory access control

c)

seperation of duties

d)

Single sign-on

70.

A company wants to ensure that all credentials for various systems are saved within a central database so that users only have to login once for access to all systems.

Which of the following would accomplish this?

a)

Single sign on

b)

Smart card access

c)

Same sign on

71.

A user attempting to log on to a workstation for the first time is prompted for the following information before being granted access: username, password, and a four-digit security pin that was mailed to him during account registration.

Which of the following is this an example of?

a)

Dual factor authentication

b)

multi factor authentication

c)

single factor authentication

d)

biometric authentication

72.

Which of the following allows a network administrator to implement an access control policy based on individual user characteristics and NOT on job function?

a)

attributes based

b)

implicit deny

c)

role based

d)

rule based

73.

Which of the following is the best practice to put at the end of an ACL?

a)

Implicit deny

b)

Time of day restrictions

c)

implicit allow

d)

SNMP STRING

74.

Users report that they are unable to access network printing services. The security technician checks the router access list and sees that web, email, and secure shell are allowed.

Which of the following is blocking network printing?

a)

PORT SECRUTIY

b)

FLOOD GUARDS

c)

IMPLICIT DENY

d)

LOOP PROTECTION

75.

In order for Sara, a client, to logon to her desktop computer, she must provide her username, password, and a four-digit PIN.

Which of the following authentication methods is Sara using?

a)

three factor

b)

single factor

c)

two factor

d)

foul factor

76.

The product requires one user name and password at the time of boot up and also another password after the operating system has finished loading.

Which of the following authentication types is this setup using?

a)

single sign on

b)

single factor authentication

c)

same card

77.

Which of the following is a measure of biometrics performance which rates the ability of a system to correctly authenticate an authorized user?

a)

type ii

b)

mean time to reigister

c)

capacity

78.

Use of group accounts should be minimized to ensure the following:

a)

password security

b)

regular auditing

c)

baseline management

d)

individual accountability

79.

A network inventory discovery application requires non-privileged access to all hosts on a network for inventory of installed applications. A service account is created by the network inventory discovery application for accessing all hosts.

Which of the following is the MOST efficient method for granting the account non-privileged access to the hosts?

a)

Implement Group Policy to add the account to the users group on the hosts

b)

Add the account to the Users group on the hosts

c)

Add the account to the Domain Administrator group

80.

A group policy requires users in an organization to use strong passwords that must be changed every 15 days. Joe and Ann were hired 16 days ago. When Joe logs into the network, he is prompted to change his password; when Ann logs into the network, she is not prompted to change her password.

Which of the following BEST explains why Ann is not required to change her password?

a)

Ann’s user account was not added to the group policy.

b)

Joe’s user account was inadvertently disabled and must be re-created.

c)

B.

Joe’s user account was not added to the group policy.

d)

Ann’s user account has administrator privileges.

81.

The system administrator is tasked with changing the administrator password across all 2000 computers in the organization.

Which of the following should the system administrator implement to accomplish this task?

a)

GROUP POLICY

b)

KEY ESCROW

c)

CERTIFICATE REVOCATION

82.

An auditing team has found that passwords do not meet the best business practices.

a)

Password Complexity and Password history

b)

Password Expiration

c)

Length

d)

History

83.

Which of the following passwords is the LEAST complex?

a)

MyTRAIN!45

b)

Mytr@in!!

c)

MyTr@in12

84.

A security administrator wants to check user password complexity.

Which of the following is the BEST tool to use?

a)

Password history

b)

password logging

c)

password cracker

d)

password hashing

85.

desktop configuration settings have changed. Upon a review of the CCTV logs, it is determined that someone logged into Ann’s workstation.

Which of the following could have prevented this from happening?

a)

Password complexity policy

b)

user reviews

c)

shared acc.

d)

permission policy

86.

After a recent internal audit, the security administrator was tasked to ensure that all credentials must be changed within 90 days, cannot be repeated, and cannot contain any dictionary words or patterns. All credentials will remain enabled regardless of the number of attempts made.

a)

Password Exp and Password Complexity

b)

Lock out

c)

Privelages

87.

An internal auditing team would like to strengthen the password policy to support special characters.

Which of the following types of password controls would achieve this goal?

a)

Add reverse encryption

b)

Password complexity

c)

Allow single sign on

88.
Which of the following is an example of active eavesdropping?
a)
Phishing
b)
DDoS
c)
Xmas attack
d)
MITM
89.
Switch spoofing and double tagging are two primary methods of attacking networked resources on:
a)
WLAN
b)
VPN
c)
VLAN
d)
PAN
90.
Harmful programs used to disrupt computer operation, gather sensitive information, or gain access to private computer systems are commonly referred to as:
a)
Adware
b)
Malware
c)
Computer viruses
d)
Spyware
91.
Zero-day attack exploits:
a)
New accounts
b)
Patched software
c)
Vulnerability that is present in already released software but unknown to the software developer
d)
Well known vulnerability
92.
A hacker has captured network traffic with cleartext commands sent from the client to the server console. Which of the following ports is being used by the network admin for the client-server communication?
a)
49
b)
 23 
c)
68
d)
22
93.
Which of the following answers refers to a preferred replacement for the SLIP protocol?
a)
PoE
b)
PPP
c)
CHAP
d)
PAP 
94.
Which of the following protocols does not provide authentication?
a)
FTP 
b)
 TFTP
c)
SCP
d)
SFTP
95.
Which of the following answers refers to a cryptographic network protocol for secure data communication, remote command-line login, remote command execution, and other secure network services between two networked computers?
a)
Telnet
b)
SSH
c)
Bcrypt
d)
TFTP
96.
Which of the protocols listed below was designed as a secure replacement for Telnet?
a)
CHAP
b)
FTP
c)
SSH 
d)
LDAP
97.
The SCP protocol is used for:
a)
 Directory access
b)
Secure file transfer
c)
Network addressing
d)
Sending emails
98.
Which of the IPsec modes provides entire packet encryption?
a)
Tunnel
b)
Payload
c)
Transport
d)
Default
99.
 Which of the following solutions provides a shielded environment that protects against unintentional signal leakage and eavesdropping?
a)
SCADA
b)
TEMPEST
c)
HVAC
d)
 RADIUS
100.
Data files containing detection and/or remediation code that antivirus or antispyware products use to identify malicious code are known as:
a)
Repositories
b)
Signature files
c)
Macros
d)
Security logs