WorksheetsSec +
Total questions: 55
Worksheet time: 55mins
What type of social engineering attack usually takes advantage of spammed email being sent out to a specific person or group of unsuspecting recipients?
Vishing
Smishing
Whaling
Spear Phishing
A misleading web address that targets a user incorrectly typing the website’s name directly in the address bar of their browser is referred to this type of attack.
URL hijacking
Phishing
Impersonation
Spamming
This kind of attack can occur when a person is performing sensitive work on a laptop in a public area such as a coffee shop
Piggybacking
Dumpster diving
Shoulder surfing
Smurfing
An evil twin is mostly likely a part of this kind of attack.
Botnet
Phishing
Man-in-the-middle
Zero day
What kind of attack takes advantage of an applications vulnerability of not being patched?
DDoS
Pharming
Smurf
Zero day
This wireless attack sends unsolicited messages to a Bluetooth enabled device.
Bluejacking
Bluesnarfing
Jamming
Bluebugging
Which application attacks directly target the database programs sitting behind the web content servers?
SQL injection
Session hijacking
Cross-site scripting
Command injection
Which application vulnerability can be exploited by providing a series of normal data inputs within a specific sequence and timing?
Injection
Request forgery
Race condition
Buffer overflow
This cryptographic attack has the attacker intercepting data transmissions, usually those with authentication credentials or encryption key exchanges, and then delaying or resending them.
Session replay
Replay
Man-in-the-middle
Session hijacking
What type of attack allows an attacker to interfere with the initial connection setup in order to trick legitimate clients into using weak or no encryption?
Session hijacking
Downgrade
Man-in-the-middle
Brute force
You are working on a new web application for a company that will be hosted in the cloud. Single sign-on capability is required to exchange authentication and authorizatioin data between multiple security domains and they prefer working with XML. What should you use?
PAP
RADIUS
SAML
SecureID
Your assistant is preparing a briefing about TACACS+. He is having trouble remembering the three different packet types used in the authentication process. Which of the following is not used in TACACS+ authentication?
INITIATE
START
CONTINUE
REPLY
You've been tasked to update the authentication protocols for a legacy Windows-based application running on a stand-alone system. It's using LANMAN and running on Windows XP. You would like to keep using something from Microsoft, but your company won't allow an upgrade past Windows7 during this effort. What do you suggest?
TACACS+
NTLM
RADIUS
LDAP
Which of the following protocols uses a key distribution center and can securely pass a symmetric key over an insecure network?
CHAP
PAP
LDAP
Kerberos
During an ovedue server room inventory, you come across a RADIUS accounting server. Your supervisor asks you what RADIUS accounting was mainly used for . What do you tell him?
Source and destination IP addresses of network traffic
Applications used by users
Time billing and security logging
Tracking file acceess
Bob's development team needs an authentication solution that supports authentication across stateless platforms. They want him to explain how other application use Facebook or Google logins for authentication. In his explanation, which of the following concepts would Bob definitely need to mention?
Secure tokens
Secure tickets
XML requests
Request tokens
You are establishing a point-to-point link and need to provide authentication using PPP. Which of the following protocols would you consider?
TCP auth
RADIUS
SAML
CHAP
Which of the following is a service designed to enable single sign-on and federated identity-based authentication and authorization across networks?
PAP
Shibboleth
XAML
OASIS
Which of the following protocols involves a two-way handshake and sends the username and password in clear text?
SAML
LDAP
PAP
NTLM
OpenID Connect allows for which of the following?
A third party can authenticate your users for you using accounts the users already have
Symmetric keys can be shared across unsecured networks
Identity can be confirmed with a single UDP packet.
Trusted IP addresses can be used to mitigate brute force attacks
Stacy's IT department is looking to impliment a new authentication and authorization capability. They need something that can be used to control access to objects as well as handle user authentication and authorization. Which of the following protocols should she suggest?
MSCHAP
TACACS
PPP
LDAP
Which of the following is an open protocol that allows secure, token-based authentication and authorization from web, desktop, and mobile applications and is used by companies such as Google and Microsoft to permit users to share information about their accounts with third-party applications?
Secure DLI
RADIUS
OAuth
SAML
Which statements about TACACS+ is true?
Communication between a TACACS+ client (typically a NAS) and a TACACS+ server are not secure.
Communications between a user (typically a PC) and the TACACS+ client are subject to compromise as communications are usually not encrypted.
TACACS+ is an extension of TACACS and is backward compatible.
TACACS+ uses UDP for its strsnport protocol and PAP for it's backend functionality
This protocol, which is utilized by many directory service systems from multiple vendors, manages distributed directory information services over an IP network.
LEAP
LDAP
ADUC
Kerberos
What system offers network security through a single sign-in method and provides authentication services primarily on local networks and intranets using TCP/UDP 88?
RADIUS
Diameter
SAML
Kerberos
Which protocols listed provide authentication, authorization, and accounting information between a network access server (NAS) that wants to authenticate its links or end users and a shared authentication server? (Choose all that apply)
RADIUS
TACACS+
Diameter
Kerberos
What SSO supported authentication process connects a principal to a service provider in order to request an authentication token from the identity provider?
RADIUS
TACACS+
Diameter
SAML
Which statement about NTLM is true?
It uses an encrypted challenge/response protocol to authenticat a user
It passes user credentials in clear text only.
It is commonly used to integrate UNIX services into a network
It is typically used on stand-alone systems.
What does the "A" in RADIUS stand for?
Authorization
Authentication
Accounting
Auditing
What type of server authenticates users prior to allowing network access?
File server
Active Directory
Domain Controller
RADIUS
Which of the following are examples of RADIUS clients? (Choose two.)
Wireless router
VPN client
802.1x capable switch
Windows 7
You are the network administrator for a UNIX network. You are planning your network security. A secure protocol must be chosen to authenticate all users logging in. Which is a valid authentication protocol?
TCP auth
Kerberos
AES
SSO
You are evaluating the possibility of a Linux client and server operating system encironment. Your main concern is having a central database of user and computer accounts capable of secure authentication. What Linux options should you explore?
NTFSv2
SSH
Samba
LDAP
Which of the following are authentication/authorization frameworks? (Choose all that apply.)
OpenID Connect
Federation
OAuth
Shibboleth
As the network administrator, you've been tasked with configuring a secure VPN for the CEO and his associates. There are a few different options, however, you know you want to protect the conncetions with IPsec. Which of the following options will allow the use of IPsec to secure the VPN traffic?
PPTP
L2TP
IKEv2
CCMP
Regarding data and storage media disposal, which method involves the process of reducing documents or other items to loose fibers?
Incineration
Pulping
Pulverizing
Deqaussing
Degaussers can destroy all data on magnetic media like tapes, hard drives, and optical or flash storage media. (T/F)
True
False
Data should always be classified according to its nature or _________ level.
regulation
permissions
sensitivity
compliance
What type of training is focused on educating users about how to handle data that requires special handling?
Role-based
Rule-based
Discretionary
Ethics
When it comes to managing data, which role ensures that access systems are set up in such a way that clients are able to view their own private information, and not the private information any other entity in the system?
Owner
Custodian
Privacy Officer
User
Which data management role controls user permissions to access data, implement security controls to keep data safe but available, log access, and produce reports for data owners?
Data owner
Data steward
Data user
Data custodian
This term refers to the process of an organization maintaining the existence of and control over certain data in order to comply with business policies and applicable laws and regulations.
Data disposal
Data retention
Data disposition
Data labeling
What might protect users from copying sensitive files to an external media source?
DLP
FDE
HSM
TPM
What does the data label or qualification PHI stand for?
Personally Hidden Information
Personnel Health Information
Protected Human Intervention
Protected Health Information
Which policy is focused on preventing data loss?
AUP
Clean desk policy
Mandatory vacation
Separation of duties
What strategy helps to mitigate organization risk including functions such as courses of action, continuous monitoring, and configuration validation?
Resiliency
Redundancy
Automation
Distributive allocaion
These are master images that are used for hard disks, virtual machines, or servers that are often used in a self-provisioning environment.
Snapshots
Templates
RAID
VMs
In this type of computing environment, if a failure occurs, the information is lost.
Persistent
Non-persistent
Redudant
Automated
This feature is useful when you need to preserve the state of a virtual machine, allowing a restore point when testing software or configuration changes.
Snapchat
Snapshot
Screenshot
Live boot media
The property by which a computing environment is able to gracefully fulfill its ever-increasing resource needs is most closely defining which term?
Scalability
Elasticity
Redundancy
Distributive allocaion
Commonly found in reference to cloud services, this allows a computing environment to dynamically expand or reduce infrastructure resources by independantly adjust to workload changes in order to maximize resources.
Fault tolerance
Redundancy
Scalability
Elasticity
This allows a computing environment to continue providing services at an acceptable level even when one or more components suffer functionality.
Elasticity
Persistent system
Fault tolerance
Distributive allocaion
A system that creates and maintains one or more copies/sets of additional resources, including the primary set, is providing this particular property.
Redundancy
Scalability
Elasticity
Imagery
Which RAID level provides striped data, broken into blocks, without fault tolerance?
Level 0
Level 1
Level 2
Level 3
This RAID level offers 100 percent redundancy because all data is written to both disks (two minimum requirement).
4
3
2
1
