Font size
WorksheetsMTA SecFun Review
Total questions: 127
Worksheet time: 1hrs 9mins
A type of malware that is installed on a computer to collect a user’s personal information or details about his or her browsing habits, often without the user’s knowledge.
spyware
virus
worm
rootkit
Junk email that is usually sent unsolicited.
spam
phishing
pharming
Trojan horse
An email validation system designed to prevent email spam that uses source address spoofing. This allows administrators to specify in DNS SPF records in the public DNS which hosts are allowed to send email from a given domain.
Sender Policy Framework (SPF)
Security Compliance Manager 4.0 (SCM 4.0)
Microsoft Active Protection Service (MAPS)
Microsoft Baseline Security Analyzer (MBSA)
A virus that mutates, or changes its code, so that it cannot be as easily detected.
polymorphic virus
worm
rootkit
Trojan horse
The new Microsoft lightweight web browser with a layout engine built around web standards designed to replace Internet Explorer as the default web browser. It integrates with Cortana, annotation tools, Adobe Flash Player, a PDF reader, and a reading mode.
Universal Windows Platform (UWP) app
Microsoft Edge
Microsoft IE 10
Mozilla Firefox
A software tool released by Microsoft to determine the security state of a system by assessing missing security updates and less-secure security settings within Microsoft Windows components such as Internet Explorer, IIS web server, and products such as Microsoft SQL Server and Microsoft Office macro settings.
Microsoft Active Protection Service (MAPS)
Read-Only Domain Controller (RODC)
Microsoft Baseline Security Analyzer (MBSA)
Security Compliance Manager 4.0 (SCM 4.0)
Previously called Windows Live ID, this is a unique account that is the combination of an email address and a password that you use to sign in to services like Outlook.com, MSN.com, Hotmail.com, OneDrive, Windows Phone, or Xbox Live.
Microsoft account
Domain account
Local account
Virtual account
These include apps that are critical to running the company business as well as apps that are unique to the company’s main business.
Line of Business (LOB) app
security template
Universal Windows Platform (UWP) app
security baseline
A piece of text stored by a user’s web browser. This file can be used for a wide range of purposes, including user identification, authentication, and storing site preferences and shopping cart contents.
Bayesian filter
cookie
offline file
pop-up window
Zones used to define and help manage security when visiting sites.
content zone
Microsoft Active Protection Service (MAPS)
Microsoft Baseline Security Analyzer (MBSA)
security baseline
A policy that defines the standards, restrictions, and procedures for end users who have authorized access to company data from their personal devices (tablets, laptops, or smartphones). The policy also includes hardware and related software that is not approved, owned, nor supplied by the company.
Bring Your Own Device (BYOD) policy
Content zone
Microsoft Active Protection Service (MAPS)
Windows Server Update Services (WSUS)
A special algorithm that determines whether email is considered spam.
Bayesian filter
content zone
Sender Policy Framework (SPF)
Security Compliance Manager 4.0 (SCM 4.0)
The exposure to theats
attack surface
digital signature
risk acceptance
risk mitigation
isolates and hardens key system and user security information on Windows systems
Credential Guard
flash drive
share permissions
sniffers
A firewall configuration used to secure hosts on a network segment.
DMZ (demilitarized zone)
Berlin Wall
Two Factor
Great Wall
______ occurs when an attacker is able to intercept a DNS request and respond to the request before the DNS server is able to.
DNS spoofing
MITM
Spam
explicit permissions
The risk that remains after measures have been taken to reduce the likelihood or minimize the effect of a particular event.
residual risk
risk mitigation
Avoided risk
risk
Identifies the risks that might impact your particular environment.
risk assessment
risk mitigation
vulnerability assessment
pentesting
Uses a centrally administrated set of controls to determine how subjects and objects interact. The access control levels can be based upon the necessary operations and tasks a user needs to carry out to fulfill her responsibilities without an organization.
Role-BAC
Rule-BAC
MAC
DAC
A local security database found on most Windows computers.
Security Account Manager (SAM)
Universal Windows Platform (UWP) apps
Trusted Platform Module
smart card
As the Chief Security Officer for a small medical records processing company, you have just finished setting up the physical security for your new office. You have made sure that the parking lot is illuminated, that you have guards at the door as well as doing periodic patrols, and you have badge readers throughout the building at key locations. You also have put biometric access technology on the data center door. And of course, you have cameras in the parking lot, building entrances, and the data center entrances.
This type of implementation is known as: (Choose the best answer)
Access control
Core security principles
Security best practices
Defense in depth
Implementing security measures must always be balanced with what?
Confidentiality
Integrity
Cost
Availability
A junior administrator notices, when looking at a folder's permissions, gray check boxes in the allow column for a group's permissions. What do the gray check boxes represent?
The permissions are conditional
The permissions are inherited
The permissions have bee disable temporarily
The permissions are explicit
Which servers/server apps can be used to push Windows updates to client machines? Choose two answers.
WSUS
WDM
SCCM
MDM
Which of the following statements is TRUE? (There may be more than one right answer)
The tool used to view audit logs is Event Viewer
You can audit logon failures to warn of hacking attacks
You cannot limit the size of audit logs
Which protocols are considered unsecure and should be avoided in a server environment? Choose two answers
PAP
CHAP
SSH
Telnet
SFTP
Which type of VPN will often have a user connect through a web browser?
SSL
TPN
SLS
TTL
Choose which statements are true regarding DELEGATION. There may be more than one correct answer
The Delegation of Control Wizard is found in Active Directory Users and Computers
Users and groups can be delegated to a resource using the Delegation of Control Wizard
Organizational Units can be delegated to a resources using the Delegation of Control Wizard
Choose which statements regarding RADIUS are FALSE. There may be more than one correct answer
RADIUS is Cisco-proprietary
RADIUS performs centralized authentication
RADIUS provides auditing services
Choose which of the following statements regarding VPN's is TRUE. There may be more than one correct answer.
A VPN should use PPTP for tunneling
A VPN connects two entities over a wide area network, like the Internet
A VPN encapsulates and encrypts data to provide a secure connection
A person buying something securely from a website will receive a _________ key to use to encrypt sensitive data. A different ________ key is used to decrypt the data.
public, public
private, private
private, public
public, private
Which of the following are specific types of audits? Choose three answers
File and folder name changes
Directory service access
Desktop background changes
Logins
Policy changes
When enabling Secure Dynamic DNS, who can create records on a DNS server?
Domain admins
DNS admins
Server admins
Members of an Active Directory domain
Which of the following are valid risk responses? (Choose all that apply.)
Mitigation
Transfer
Investment
Avoidance
1. Which of the following technologies could be used to help ensure the confidentiality of proprietary manufacturing techniques for an auto parts manufacturing business? (Choose all that apply.)
Strong encryption
guard patrols
a laptop safe
strong authentication
1. Which type of network traffic originates from outside the network routers and proceeds toward a destination inside the network?
Ingress
Egress
Traverse
Encrypted
If a user is deploying technologies to restrict access to a resource, they are practicing which security principle?
Confidentiality
Integrity
Availability
Access control
What is a method used to gain access to data, systems, or networks, primarily through misrepresentation?
Integrity
Brute Force
Social engineering
Residual risk
What type of malware can copy itself and infect a computer without the user's consent or knowledge?
Virus
Rootkit
Trojan Horse
Backdoor
What is the best way to protect against social engineering?
stronger encryption
stronger authentication
employee awareness
risk mitigation
What is the first line of defense when setting up a network?
physically secure the network
configure authentication
configure encryption
configure an ACL
What is used to identify a person before giving access?
authentication
encryption
access control
auditing
What is used to verify that an administrator is not accessing data that he should not be accessing?
authentication
encryption
access control
auditing
What type of self-replicating program copies to other computers on a network without any user intervention and consumes bandwith and computer resources?
Virus
Trojan Horse
Worm
backdoor
What type of device can be easily lost or stolen or can be used for espionage?
processors
RAM chips
removable devices
servers
To prevent users from copying data to removable media, you should:
Lock the computer cases
Apply a group policy
Disable copy and paste
Store media in a locked room
HOTSPOT: Select TRUE or FALSE for the following statement: Systems administrators should use a standard user account when performing routine functions like reading emails and browsing the internet.
TRUE
FALSE
In Internet Explorer 8, the InPrivate Browsing feature prevents:
Unauthorized private data input.
Unencrypted communication between the client computer and the server.
User credentials from being sent over the Internet.
Any session data from being stored on the computer.
The purpose of a digital certificate is to verify that a:
Public key belongs to a sender.
Private key belongs to a sender.
Computer is virus-free
Digital document is complete.
What authentication type is the default for Active Directory?
NTLM
Kerberos
MS-CHAP
MS-CHAPv2
What directory service is used with Windows domains?
Active Directory
E-Directory
PAM
Kerberos
When you grant access to print to a printer, what are you granting?
right
permission
acccessible
key
What authorizes a user to perform certain actions in Windows such as logging on or performing a backup?
right
permission
acccessible
key
What type of permissions are assigned directly to a file or folder?
explicit
inherited
encompassing
overriding
You create a web server for your school. When users visit your site, they get a certificate error that says your site is not trusted. What should you do to fix this problem?
Install a certificate from a trusted Certificate Authority (CA).
Use a digital signature.
Generate a certificate request.
Enable Public Keys on your website.
The client computers on your network are stable and do not need any new features.
Which is a benefit of applying operating system updates to these clients?
Keep the software licensed
Keep the server ports available
Update the hardware firewall
Close existing vulnerabilities
TRUE OR FALSE: Single sign-on (SSO) allows you to log on once and access multiple related but independent software systems without having to log on again. As you log on with Windows via Active Directory, you are assigned a token, which can then be used to log on to other systems automatically.
TRUE
FALSE
What prevents users from changing a password multiple times so that they can change it to their original password?
minimum password age
maximum password age
password history
account lockout
What Microsoft technology can verify that a client has the newest Windows updates and has an updated antivirus software package before being allowed access to the network?
NAP
IPsec
SCOM
SCCM
Which type of routing protocol sends the entire routing table to its neighbors?
distance vector
link state
scalable driven
infinity
You need to install a domain controller in a branch office. You also need to secure the information on the domain controller. You will be unable to physically secure the server. Which should you implement?
Read-Only Domain Controller
Point-to-Point Tunneling Protocol (PPTP)
Layer 2 Tunneling Protocol (L2TP)
Server Core Domain Controller
The company that you work for wants to set up a secure network, but they do not have any servers. Which three security methods require the use of a server? (Choose three.)
802.1x
WPA2 Personal
WPA2 Enterprise
RADIUS
802.11ac
Your password is 1Vu*cI!8sT. Which attack method is your password vulnerable to?
Rainbow table
Brute force
Spidering
Dictionary
You are an intern and are working remotely.
You need a solution that meets the following requirements:
Allows you to access data on the company network securely gives you the same privileges and access as if you were in the office.
What are two connection methods you could use? (Choose two.)
Forward Proxy
Virtual Private Network (VPN)
Remote Access Service (RAS)
Roaming Profiles
What Windows feature notifies you when something tries to make changes to your computer without your knowledge?
WDS
NDS
Windows Defender
UAC
Which enables you to change the permissions on a folder?
Take ownership
Extended attributes
Auditing
Modify
What are three examples of two-factor authentication? (Choose three.)
A fingerprint and a pattern
A password and a smart card
A username and a password
A password and a pin number
A pin number and a debit card
What does implementing Windows Server Update Services (WSUS) allow a company to manage?
Shared private encryption key updates
Updates to Group Policy Objects
Active Directory server replication
Windows updates for workstations and servers
Before you deploy Network Access Protection (NAP), you must install:
Internet Information Server (IIS)
Network Policy Server (NPS)
Active Directory Federation Services
Windows Update Service
What does NAT do?
It encrypts and authenticates IP packets.
It provides caching and reduces network traffic.
It translates public IP addresses to private addresses and vice versa.
It analyzes incoming and outgoing traffic packets
How does the sender policy framework (SPF) aim to reduce spoofed email?
It provides a list of IP address ranges for particular domains so senders can be verified.
It includes an XML policy file with each email that confirms the validity of the message.
It lists servers that may legitimately forward mail for a particular domain.
It provides an encryption key so that authenticity of an email message can be validated
You create a new file in a folder that has inheritance enabled.
By default, the new file:
Takes the permissions of the parent folder
Does not take any permissions
Takes the permissions of other folders in the same directory
Takes the permissions of other files in the same directory
What type of DNS record maps host names to addresses?
Mail Exchanger (MX) DNS record
Service (SRV) DNS record
Host (A) DNS record
Canonical (CNAME) DNS record
Which type of network is most vulnerable to intrusion?
Dial-up
Wireless
Broadband
Leased line
Which wireless authentication method provides the highest level of security?
Wired Equivalency Privacy (WEP)
IEEE 802.lln
WI-FI Protected Access (WPA)
IEEE 802.11a
Which of the following is a Layer 2 WAN protocol?
Point-to-Point Protocol (PPP)
Simple Network Management Protocol (SNMP)
Transmission Control Protocol (TCP)
Internet Protocol (IP)
The protocol that maps IP addresses to a Media Access Control (MAC) address is:
Internet Message Access Protocol (IMAP).
Dynamic Host Configuration Protocol (DHCP).
Routing Information Protocol (RIP).
User Datagram Protocol (UDP).
Address Resolution Protocol (ARP).
A private network that allows members of an organization to exchange data is an:
Extranet
Ethernet
Intranet
Internet
The query protocol used to locate resources on a network is:
User Datagram Protocol (UDP).
Lightweight Directory Access Protocol (LDAP)
Tracert
Telnet
Which of the following is a public IP address?
10.156.89.1
68.24.78.221
172.16.152.48
192.168.25.101
You work at a coffee shop. Your supervisor asks you to help set up a computer network. The network needs to have the following items:
A public facing web server
A Wi-Fi network for customers
A private network for the point of sale terminals
An office PC
A file/print server
A network printer
You need to set up a perimeter network to protect the network. Which two items should you include in the perimeter network? (Choose two.)
Network printer
Web server
File server
Wi-Fi network
Point of sale terminals
Identify the correct port number:
POP
3389
443
110
161
A copy of a network file that is stored on your computer so you can access it when you aren’t connected to the network or when the network folder that contains the file is not connected.
cookie
offline file
content zone
Windows Store
Which type of permission is granted directly to a file or folder?
explicit
shared
effective
BitLocker, when possible, stores the encryption key on a computer's _______________
BitLocker
TPM
BitLocker To Go
EFS
Which three characteristics describe Worms?
Uses system resources like bandwidth, memory, and processor time, which makes the computer run slow
Contained in most music and videos
Typically does not corrupt or modify files
A self-replacing program that copies itself to other computers without user intervention
Only passed by email
Which password policy prohibits reusing the same password?
Lockout policy
History policy
Length policy
Complexity policy
The IEEE 802.11 standard defines the name for a WLAN as the ___________
SSID
WAP
WLAN
WEP
Several users have called the help desk to complain that they are being redirected to websites different from the addresses they entered. Which type of attack is taking place?
IP spoofing
ARP spoofing
DNS spoofing
Man-in-the-middle
Which protocol should be allowed only on email servers used to send email and should be blocked on all other servers and client machines?
POP3
FTP
SMTP
IMAP
Which of the following technologies could be used to help ensure the confidentiality of proprietary manufacturing techniques for an auto parts manufacturing business? (Choose all that apply.)
Strong encryption
Strong authentication
Guard patrols
an alarm system
Joe is an administrator for a small business. The owners want to add wireless tablets for the managers to use. The owner does not want to occur any significant costs in doing so. What are actions can Joe take to meet the onwers requirements?
hide the ssid
use WPA2-PSK
use WPA2-EAP
Use two factor authentication on the tablets.
What is the last step in Threat Modeling?
identify threats
identify assets
Document the threats
Rate the threats
Which of the following is the master time keeper and master for password changes in an Active Directory domain
PDC Emulator
RID
Infrastructure master
Schema Master
John needs to access a file in a shared folder. What must be done in order for this to happen. (select the best two answers)
The permissions on the folder must altered to include John
John must be a member of a group that has rights to the folder
The shared folder must be mapped to John computer
Local security policy must be updates
Which of the following uses an ACL? Select all the apply
NTFS Folder
AD users
Registry Key
Logon Rights
Which technology is used to encrypt an individual file on an NTFS volume?
EFS
Bitlocker
Bitlocker to go
PPTP
Which of the following corresponds with the minimum and maximum password history settings for securing a Windows 10 Pro workstation image?
0,14
1,14
0,24
0,998
Which Administrative Tool should be used to configure password control settings on a new standalone server?
Active Directory Users and Computers
Computer Management
Security Service
Local Security Policy
Which of the following are common uses for a VPN? (Choose all that apply.)
Remote access
Server isolation
Intrusion detection
Extranet connections
