wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

MTA SecFun Review

Total questions: 127

Worksheet time: 1hrs 9mins

Name
Class
Date
1.

A type of malware that is installed on a computer to collect a user’s personal information or details about his or her browsing habits, often without the user’s knowledge.

a)

spyware

b)

virus

c)

worm

d)

rootkit

2.

Junk email that is usually sent unsolicited.

a)

spam

b)

phishing

c)

pharming

d)

Trojan horse

3.

An email validation system designed to prevent email spam that uses source address spoofing. This allows administrators to specify in DNS SPF records in the public DNS which hosts are allowed to send email from a given domain.

a)

Sender Policy Framework (SPF)

b)

Security Compliance Manager 4.0 (SCM 4.0)

c)

Microsoft Active Protection Service (MAPS)

d)

Microsoft Baseline Security Analyzer (MBSA)

4.

A virus that mutates, or changes its code, so that it cannot be as easily detected.

a)

polymorphic virus

b)

worm

c)

rootkit

d)

Trojan horse

5.

The new Microsoft lightweight web browser with a layout engine built around web standards designed to replace Internet Explorer as the default web browser. It integrates with Cortana, annotation tools, Adobe Flash Player, a PDF reader, and a reading mode.

a)

Universal Windows Platform (UWP) app

b)

Microsoft Edge

c)

Microsoft IE 10

d)

Mozilla Firefox

6.

A software tool released by Microsoft to determine the security state of a system by assessing missing security updates and less-secure security settings within Microsoft Windows components such as Internet Explorer, IIS web server, and products such as Microsoft SQL Server and Microsoft Office macro settings.

a)

Microsoft Active Protection Service (MAPS)

b)

Read-Only Domain Controller (RODC)

c)

Microsoft Baseline Security Analyzer (MBSA)

d)

Security Compliance Manager 4.0 (SCM 4.0)

7.

Previously called Windows Live ID, this is a unique account that is the combination of an email address and a password that you use to sign in to services like Outlook.com, MSN.com, Hotmail.com, OneDrive, Windows Phone, or Xbox Live.

a)

Microsoft account

b)

Domain account

c)

Local account

d)

Virtual account

8.

These include apps that are critical to running the company business as well as apps that are unique to the company’s main business.

a)

Line of Business (LOB) app

b)

security template

c)

Universal Windows Platform (UWP) app

d)

security baseline

9.

A piece of text stored by a user’s web browser. This file can be used for a wide range of purposes, including user identification, authentication, and storing site preferences and shopping cart contents.

a)

Bayesian filter

b)

cookie

c)

offline file

d)

pop-up window

10.

Zones used to define and help manage security when visiting sites.

a)

content zone

b)

Microsoft Active Protection Service (MAPS)

c)

Microsoft Baseline Security Analyzer (MBSA)

d)

security baseline

11.

A policy that defines the standards, restrictions, and procedures for end users who have authorized access to company data from their personal devices (tablets, laptops, or smartphones). The policy also includes hardware and related software that is not approved, owned, nor supplied by the company.

a)

Bring Your Own Device (BYOD) policy

b)

Content zone

c)

Microsoft Active Protection Service (MAPS)

d)

Windows Server Update Services (WSUS)

12.

A special algorithm that determines whether email is considered spam.

a)

Bayesian filter

b)

content zone

c)

Sender Policy Framework (SPF)

d)

Security Compliance Manager 4.0 (SCM 4.0)

13.
A list of all users and groups that have access to an object.
a)
access control list (ACL)
b)
confidentiality
c)
personal firewall
d)
public key infrastructure (PKI)
14.
Also known as proxy servers. Works by performing a deep inspection of application data as it traverses the firewall. Rules are set by analyzing client requests and application responses
a)
application level firewall
b)
dictionary attack
c)
removable device
d)
risk assessment
15.

The exposure to theats

a)

attack surface

b)

digital signature

c)

risk acceptance

d)

risk mitigation

16.
Also known as the certification path
a)
certificate chain
b)
effective permissions
c)
Secure Sockets Layer (SSL)
d)
security policy
17.
A logical object that provides a means for authenticating and auditing a computer's access to a Windows network
a)
computer account
b)
encryption
c)
Security Compliance Manager 4.0 (SCM 4.0)
d)
shared folder
18.

isolates and hardens key system and user security information on Windows systems

a)

Credential Guard

b)

flash drive

c)

share permissions

d)

sniffers

19.
An electronic document that contains an identity
a)
digital certificate
b)
host firewall
c)
spoofing
d)
symmetric encryption
20.

A firewall configuration used to secure hosts on a network segment.

a)

DMZ (demilitarized zone)

b)

Berlin Wall

c)

Two Factor

d)

Great Wall

21.

______ occurs when an attacker is able to intercept a DNS request and respond to the request before the DNS server is able to.

a)

DNS spoofing

b)

MITM

c)

Spam

d)

explicit permissions

22.
A collection or list of user accounts or computer accounts.
a)
group
b)
mobile device
c)
personal firewall
d)
intrusion detection systems (IDS)
23.
Permissions granted to a folder (parent object or container) that flows into child objects (subfolders or files) inside that folder.
a)
inherited permission
b)
NTFS
c)
removable device
d)
keylogger
24.
access control model integrated in software used to control subject-to-object access functions through the use of clearance
a)
Mandatory Access Control
b)
polymorphic virus
c)
Secure Sockets Layer (SSL)
d)
nonrepudiation
25.
Permissions that allow you to control which users and groups can gain access to files and folders on an NTFS volume.
a)
NTFS Permission
b)
risk avoidance
c)
smart card
d)
password
26.

The risk that remains after measures have been taken to reduce the likelihood or minimize the effect of a particular event.

a)

residual risk

b)

risk mitigation

c)

Avoided risk

d)

risk

27.

Identifies the risks that might impact your particular environment.

a)

risk assessment

b)

risk mitigation

c)

vulnerability assessment

d)

pentesting

28.

Uses a centrally administrated set of controls to determine how subjects and objects interact. The access control levels can be based upon the necessary operations and tasks a user needs to carry out to fulfill her responsibilities without an organization.

a)

Role-BAC

b)

Rule-BAC

c)

MAC

d)

DAC

29.

A local security database found on most Windows computers.

a)

Security Account Manager (SAM)

b)

Universal Windows Platform (UWP) apps

c)

Trusted Platform Module

d)

smart card

30.
Uses a single key to encrypt and decrypt data.
a)
symmetric encryption
b)
dictionary attack
c)
dictionary attack
d)
user account
31.
An action or occurrence that could result in the breach
a)
threat
b)
digital signature
c)
Discretionary Access Control
d)
Windows Hello
32.

As the Chief Security Officer for a small medical records processing company, you have just finished setting up the physical security for your new office. You have made sure that the parking lot is illuminated, that you have guards at the door as well as doing periodic patrols, and you have badge readers throughout the building at key locations. You also have put biometric access technology on the data center door. And of course, you have cameras in the parking lot, building entrances, and the data center entrances.

This type of implementation is known as: (Choose the best answer)

a)

Access control

b)

Core security principles

c)

Security best practices

d)

Defense in depth

33.

Implementing security measures must always be balanced with what?

a)

Confidentiality

b)

Integrity

c)

Cost

d)

Availability

34.
Access control model where data owner establish guides/ rules that specifies privileges granted
a)
Rule-BAC
b)
Role-BAC
c)
MAC
d)
DAC
35.
Which Internet Explorer zone is the least secure?
a)
Internet zone
b)
local intranet zone
c)
trusted sites zone
d)
restricted sites zone
36.
What do you call multiple Windows updates that have been packaged together as one installation and are well tested?
a)
service packs
b)
cumulative packs
c)
critical update
d)
optional update
37.
What technology allows a user at home to connect to the corporate network?
a)
NAT
b)
VPN
c)
DMZ
d)
PLC
38.
Which type of routing protocol sends the entire routing table to its neighbors?
a)
distance vector
b)
link state
c)
scalable driven
d)
infinity
39.
What port does SSH use?
a)
22
b)
25
c)
443
d)
21
40.
What port is HTTP usually on?
a)
25
b)
22
c)
80
d)
389
41.
What port does LDAP use?
a)
25
b)
443
c)
389
d)
3389
42.
What port does SMTP use?
a)
21
b)
23
c)
25
d)
443
43.
On which OSI layer do routers function?
a)
1
b)
2
c)
3
d)
4
44.
In which OSI layer do TCP and UDP function?
a)
1
b)
2
c)
3
d)
4
45.
What type of attack tries to guess passwords by trying common words?
a)
dictionary attack
b)
brute-force attack
c)
man-in-the-middle attack
d)
smurf attack
46.
What settings are used to keep track of incorrect logon attempts and lock the account if too many attempts are detected within a certain set time?
a)
account lockout
b)
password policy
c)
authentication tracker
d)
user parameters
47.
Which authentication sends the username and password in plain text?
a)
MS-CHAP
b)
CHAP
c)
PAP
d)
SPAP
48.

A junior administrator notices, when looking at a folder's permissions, gray check boxes in the allow column for a group's permissions. What do the gray check boxes represent?

a)

The permissions are conditional

b)

The permissions are inherited

c)

The permissions have bee disable temporarily

d)

The permissions are explicit

49.

Which servers/server apps can be used to push Windows updates to client machines? Choose two answers.

a)

WSUS

b)

WDM

c)

SCCM

d)

MDM

50.

Which of the following statements is TRUE? (There may be more than one right answer)

a)

The tool used to view audit logs is Event Viewer

b)

You can audit logon failures to warn of hacking attacks

c)

You cannot limit the size of audit logs

51.

Which protocols are considered unsecure and should be avoided in a server environment? Choose two answers

a)

PAP

b)

CHAP

c)

SSH

d)

Telnet

e)

SFTP

52.

Which type of VPN will often have a user connect through a web browser?

a)

SSL

b)

TPN

c)

SLS

d)

TTL

53.

Choose which statements are true regarding DELEGATION. There may be more than one correct answer

a)

The Delegation of Control Wizard is found in Active Directory Users and Computers

b)

Users and groups can be delegated to a resource using the Delegation of Control Wizard

c)

Organizational Units can be delegated to a resources using the Delegation of Control Wizard

54.

Choose which statements regarding RADIUS are FALSE. There may be more than one correct answer

a)

RADIUS is Cisco-proprietary

b)

RADIUS performs centralized authentication

c)

RADIUS provides auditing services

55.

Choose which of the following statements regarding VPN's is TRUE. There may be more than one correct answer.

a)

A VPN should use PPTP for tunneling

b)

A VPN connects two entities over a wide area network, like the Internet

c)

A VPN encapsulates and encrypts data to provide a secure connection

56.

A person buying something securely from a website will receive a _________ key to use to encrypt sensitive data. A different ________ key is used to decrypt the data.

a)

public, public

b)

private, private

c)

private, public

d)

public, private

57.

Which of the following are specific types of audits? Choose three answers

a)

File and folder name changes

b)

Directory service access

c)

Desktop background changes

d)

Logins

e)

Policy changes

58.

When enabling Secure Dynamic DNS, who can create records on a DNS server?

a)

Domain admins

b)

DNS admins

c)

Server admins

d)

Members of an Active Directory domain

59.

Which of the following are valid risk responses? (Choose all that apply.)

a)

Mitigation

b)

Transfer

c)

Investment

d)

Avoidance

60.

1. Which of the following technologies could be used to help ensure the confidentiality of proprietary manufacturing techniques for an auto parts manufacturing business? (Choose all that apply.)

a)

Strong encryption

b)

guard patrols

c)

a laptop safe

d)

strong authentication

61.

1. Which type of network traffic originates from outside the network routers and proceeds toward a destination inside the network?

a)

Ingress

b)

Egress

c)

Traverse

d)

Encrypted

62.

If a user is deploying technologies to restrict access to a resource, they are practicing which security principle?

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Access control

63.

What is a method used to gain access to data, systems, or networks, primarily through misrepresentation?

a)

Integrity

b)

Brute Force

c)

Social engineering

d)

Residual risk

64.

What type of malware can copy itself and infect a computer without the user's consent or knowledge?

a)

Virus

b)

Rootkit

c)

Trojan Horse

d)

Backdoor

65.

What is the best way to protect against social engineering?

a)

stronger encryption

b)

stronger authentication

c)

employee awareness

d)

risk mitigation

66.

What is the first line of defense when setting up a network?

a)

physically secure the network

b)

configure authentication

c)

configure encryption

d)

configure an ACL

67.

What is used to identify a person before giving access?

a)

authentication

b)

encryption

c)

access control

d)

auditing

68.

What is used to verify that an administrator is not accessing data that he should not be accessing?

a)

authentication

b)

encryption

c)

access control

d)

auditing

69.

What type of self-replicating program copies to other computers on a network without any user intervention and consumes bandwith and computer resources?

a)

Virus

b)

Trojan Horse

c)

Worm

d)

backdoor

70.

What type of device can be easily lost or stolen or can be used for espionage?

a)

processors

b)

RAM chips

c)

removable devices

d)

servers

71.

To prevent users from copying data to removable media, you should:

a)

Lock the computer cases

b)

Apply a group policy

c)

Disable copy and paste

d)

Store media in a locked room

72.

HOTSPOT: Select TRUE or FALSE for the following statement: Systems administrators should use a standard user account when performing routine functions like reading emails and browsing the internet.

a)

TRUE

b)

FALSE

73.

In Internet Explorer 8, the InPrivate Browsing feature prevents:

a)

Unauthorized private data input.

b)

Unencrypted communication between the client computer and the server.

c)

User credentials from being sent over the Internet.

d)

Any session data from being stored on the computer.

74.

The purpose of a digital certificate is to verify that a:

a)

Public key belongs to a sender.

b)

Private key belongs to a sender.

c)

Computer is virus-free

d)

Digital document is complete.

75.

What authentication type is the default for Active Directory?

a)

NTLM

b)

Kerberos

c)

MS-CHAP

d)

MS-CHAPv2

76.

What directory service is used with Windows domains?

a)

Active Directory

b)

E-Directory

c)

PAM

d)

Kerberos

77.

When you grant access to print to a printer, what are you granting?

a)

right

b)

permission

c)

acccessible

d)

key

78.

What authorizes a user to perform certain actions in Windows such as logging on or performing a backup?

a)

right

b)

permission

c)

acccessible

d)

key

79.

What type of permissions are assigned directly to a file or folder?

a)

explicit

b)

inherited

c)

encompassing

d)

overriding

80.

You create a web server for your school. When users visit your site, they get a certificate error that says your site is not trusted. What should you do to fix this problem?

a)

Install a certificate from a trusted Certificate Authority (CA).

b)

Use a digital signature.

c)

Generate a certificate request.

d)

Enable Public Keys on your website.

81.

The client computers on your network are stable and do not need any new features.

Which is a benefit of applying operating system updates to these clients?

a)

Keep the software licensed

b)

Keep the server ports available

c)

Update the hardware firewall

d)

Close existing vulnerabilities

82.

TRUE OR FALSE: Single sign-on (SSO) allows you to log on once and access multiple related but independent software systems without having to log on again. As you log on with Windows via Active Directory, you are assigned a token, which can then be used to log on to other systems automatically.

a)

TRUE

b)

FALSE

83.

What prevents users from changing a password multiple times so that they can change it to their original password?

a)

minimum password age

b)

maximum password age

c)

password history

d)

account lockout

84.

What Microsoft technology can verify that a client has the newest Windows updates and has an updated antivirus software package before being allowed access to the network?

a)

NAP

b)

IPsec

c)

SCOM

d)

SCCM

85.

Which type of routing protocol sends the entire routing table to its neighbors?

a)

distance vector

b)

link state

c)

scalable driven

d)

infinity

86.

You need to install a domain controller in a branch office. You also need to secure the information on the domain controller. You will be unable to physically secure the server. Which should you implement?

a)

Read-Only Domain Controller

b)

Point-to-Point Tunneling Protocol (PPTP)

c)

Layer 2 Tunneling Protocol (L2TP)

d)

Server Core Domain Controller

87.

The company that you work for wants to set up a secure network, but they do not have any servers. Which three security methods require the use of a server? (Choose three.)

a)

802.1x

b)

WPA2 Personal

c)

WPA2 Enterprise

d)

RADIUS

e)

802.11ac

88.

Your password is 1Vu*cI!8sT. Which attack method is your password vulnerable to?

a)

Rainbow table

b)

Brute force

c)

Spidering

d)

Dictionary

89.

You are an intern and are working remotely.

You need a solution that meets the following requirements:

Allows you to access data on the company network securely gives you the same privileges and access as if you were in the office.

What are two connection methods you could use? (Choose two.)

a)

Forward Proxy

b)

Virtual Private Network (VPN)

c)

Remote Access Service (RAS)

d)

Roaming Profiles

90.

What Windows feature notifies you when something tries to make changes to your computer without your knowledge?

a)

WDS

b)

NDS

c)

Windows Defender

d)

UAC

91.

Which enables you to change the permissions on a folder?

a)

Take ownership

b)

Extended attributes

c)

Auditing

d)

Modify

92.

What are three examples of two-factor authentication? (Choose three.)

a)

A fingerprint and a pattern

b)

A password and a smart card

c)

A username and a password

d)

A password and a pin number

e)

A pin number and a debit card

93.

What does implementing Windows Server Update Services (WSUS) allow a company to manage?

a)

Shared private encryption key updates

b)

Updates to Group Policy Objects

c)

Active Directory server replication

d)

Windows updates for workstations and servers

94.

Before you deploy Network Access Protection (NAP), you must install:

a)

Internet Information Server (IIS)

b)

Network Policy Server (NPS)

c)

Active Directory Federation Services

d)

Windows Update Service

95.

What does NAT do?

a)

It encrypts and authenticates IP packets.

b)

It provides caching and reduces network traffic.

c)

It translates public IP addresses to private addresses and vice versa.

d)

It analyzes incoming and outgoing traffic packets

96.

How does the sender policy framework (SPF) aim to reduce spoofed email?

a)

It provides a list of IP address ranges for particular domains so senders can be verified.

b)

It includes an XML policy file with each email that confirms the validity of the message.

c)

It lists servers that may legitimately forward mail for a particular domain.

d)

It provides an encryption key so that authenticity of an email message can be validated

97.

You create a new file in a folder that has inheritance enabled.

By default, the new file:

a)

Takes the permissions of the parent folder

b)

Does not take any permissions

c)

Takes the permissions of other folders in the same directory

d)

Takes the permissions of other files in the same directory

98.
An IPSec component that provides connectionless integrity and the authentication of data. It also provides protection versus replay attacks.
a)
authentication header (AH)
b)
encapsulating security payload (ESP)
c)
security association (SA)
d)
Internet Protocol Security (IPSec)
99.
A protocol that allows properly configured client computers to obtain IP addresses automatically from a DHCP server.
a)
Dynamic Host Configuration Protocol (DHCP)
b)
domain name system (DNS)
c)
Internet Protocol Security (IPSec)
d)
Remote Desktop Protocol (RDP)
100.

What type of DNS record maps host names to addresses?

a)

Mail Exchanger (MX) DNS record

b)

Service (SRV) DNS record

c)

Host (A) DNS record

d)

Canonical (CNAME) DNS record

101.

Which type of network is most vulnerable to intrusion?

a)

Dial-up

b)

Wireless

c)

Broadband

d)

Leased line

102.

Which wireless authentication method provides the highest level of security?

a)

Wired Equivalency Privacy (WEP)

b)

IEEE 802.lln

c)

WI-FI Protected Access (WPA)

d)

IEEE 802.11a

103.

Which of the following is a Layer 2 WAN protocol?

a)

Point-to-Point Protocol (PPP)

b)

Simple Network Management Protocol (SNMP)

c)

Transmission Control Protocol (TCP)

d)

Internet Protocol (IP)

104.

The protocol that maps IP addresses to a Media Access Control (MAC) address is:

a)

Internet Message Access Protocol (IMAP).

b)

Dynamic Host Configuration Protocol (DHCP).

c)

Routing Information Protocol (RIP).

d)

User Datagram Protocol (UDP).

e)

Address Resolution Protocol (ARP).

105.

A private network that allows members of an organization to exchange data is an:

a)

Extranet

b)

Ethernet

c)

Intranet

d)

Internet

106.

The query protocol used to locate resources on a network is:

a)

User Datagram Protocol (UDP).

b)

Lightweight Directory Access Protocol (LDAP)

c)

Tracert

d)

Telnet

107.

Which of the following is a public IP address?

a)

10.156.89.1

b)

68.24.78.221

c)

172.16.152.48

d)

192.168.25.101

108.

You work at a coffee shop. Your supervisor asks you to help set up a computer network. The network needs to have the following items:

A public facing web server

A Wi-Fi network for customers

A private network for the point of sale terminals

An office PC

A file/print server

A network printer

You need to set up a perimeter network to protect the network. Which two items should you include in the perimeter network? (Choose two.)

a)

Network printer

b)

Web server

c)

File server

d)

Wi-Fi network

e)

Point of sale terminals

109.

Identify the correct port number:

POP

a)

3389

b)

443

c)

110

d)

161

110.

A copy of a network file that is stored on your computer so you can access it when you aren’t connected to the network or when the network folder that contains the file is not connected.

a)

cookie

b)

offline file

c)

content zone

d)

Windows Store

111.

Which type of permission is granted directly to a file or folder?

a)

explicit

b)

shared

c)

effective

112.

BitLocker, when possible, stores the encryption key on a computer's _______________

a)

BitLocker

b)

TPM

c)

BitLocker To Go

d)

EFS

113.

Which three characteristics describe Worms?

a)

Uses system resources like bandwidth, memory, and processor time, which makes the computer run slow

b)

Contained in most music and videos

c)

Typically does not corrupt or modify files

d)

A self-replacing program that copies itself to other computers without user intervention

e)

Only passed by email

114.

Which password policy prohibits reusing the same password?

a)

Lockout policy

b)

History policy

c)

Length policy

d)

Complexity policy

115.

The IEEE 802.11 standard defines the name for a WLAN as the ___________

a)

SSID

b)

WAP

c)

WLAN

d)

WEP

116.

Several users have called the help desk to complain that they are being redirected to websites different from the addresses they entered. Which type of attack is taking place?

a)

IP spoofing

b)

ARP spoofing

c)

DNS spoofing

d)

Man-in-the-middle

117.

Which protocol should be allowed only on email servers used to send email and should be blocked on all other servers and client machines?

a)

POP3

b)

FTP

c)

SMTP

d)

IMAP

118.

Which of the following technologies could be used to help ensure the confidentiality of proprietary manufacturing techniques for an auto parts manufacturing business? (Choose all that apply.)

a)

Strong encryption

b)

Strong authentication

c)

Guard patrols

d)

an alarm system

119.

Joe is an administrator for a small business. The owners want to add wireless tablets for the managers to use. The owner does not want to occur any significant costs in doing so. What are actions can Joe take to meet the onwers requirements?

a)

hide the ssid

b)

use WPA2-PSK

c)

use WPA2-EAP

d)

Use two factor authentication on the tablets.

120.

What is the last step in Threat Modeling?

a)

identify threats

b)

identify assets

c)

Document the threats

d)

Rate the threats

121.

Which of the following is the master time keeper and master for password changes in an Active Directory domain

a)

PDC Emulator

b)

RID

c)

Infrastructure master

d)

Schema Master

122.

John needs to access a file in a shared folder. What must be done in order for this to happen. (select the best two answers)

a)

The permissions on the folder must altered to include John

b)

John must be a member of a group that has rights to the folder

c)

The shared folder must be mapped to John computer

d)

Local security policy must be updates

123.

Which of the following uses an ACL? Select all the apply

a)

NTFS Folder

b)

AD users

c)

Registry Key

d)

Logon Rights

124.

Which technology is used to encrypt an individual file on an NTFS volume?

a)

EFS

b)

Bitlocker

c)

Bitlocker to go

d)

PPTP

125.

Which of the following corresponds with the minimum and maximum password history settings for securing a Windows 10 Pro workstation image?

a)

0,14

b)

1,14

c)

0,24

d)

0,998

126.

Which Administrative Tool should be used to configure password control settings on a new standalone server?

a)

Active Directory Users and Computers

b)

Computer Management

c)

Security Service

d)

Local Security Policy

127.

Which of the following are common uses for a VPN? (Choose all that apply.)

a)

Remote access

b)

Server isolation

c)

Intrusion detection

d)

Extranet connections