Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Sec +

Total questions: 55

Worksheet time: 55mins

Name
Class
Date
1.

What type of social engineering attack usually takes advantage of spammed email being sent out to a specific person or group of unsuspecting recipients?

a)

Vishing

b)

Smishing

c)

Whaling

d)

Spear Phishing

2.

A misleading web address that targets a user incorrectly typing the website’s name directly in the address bar of their browser is referred to this type of attack.

a)

URL hijacking

b)

Phishing

c)

Impersonation

d)

Spamming

3.

This kind of attack can occur when a person is performing sensitive work on a laptop in a public area such as a coffee shop

a)

Piggybacking

b)

Dumpster diving

c)

Shoulder surfing

d)

Smurfing

4.

An evil twin is mostly likely a part of this kind of attack.

a)

Botnet

b)

Phishing

c)

Man-in-the-middle

d)

Zero day

5.

What kind of attack takes advantage of an applications vulnerability of not being patched?

a)

DDoS

b)

Pharming

c)

Smurf

d)

Zero day

6.

This wireless attack sends unsolicited messages to a Bluetooth enabled device.

a)

Bluejacking

b)

Bluesnarfing

c)

Jamming

d)

Bluebugging

7.

Which application attacks directly target the database programs sitting behind the web content servers?

a)

SQL injection

b)

Session hijacking

c)

Cross-site scripting

d)

Command injection

8.

Which application vulnerability can be exploited by providing a series of normal data inputs within a specific sequence and timing?

a)

Injection

b)

Request forgery

c)

Race condition

d)

Buffer overflow

9.

This cryptographic attack has the attacker intercepting data transmissions, usually those with authentication credentials or encryption key exchanges, and then delaying or resending them.

a)

Session replay

b)

Replay

c)

Man-in-the-middle

d)

Session hijacking

10.

What type of attack allows an attacker to interfere with the initial connection setup in order to trick legitimate clients into using weak or no encryption?

a)

Session hijacking

b)

Downgrade

c)

Man-in-the-middle

d)

Brute force

11.

You are working on a new web application for a company that will be hosted in the cloud. Single sign-on capability is required to exchange authentication and authorizatioin data between multiple security domains and they prefer working with XML. What should you use?

a)

PAP

b)

RADIUS

c)

SAML

d)

SecureID

12.

Your assistant is preparing a briefing about TACACS+. He is having trouble remembering the three different packet types used in the authentication process. Which of the following is not used in TACACS+ authentication?

a)

INITIATE

b)

START

c)

CONTINUE

d)

REPLY

13.

You've been tasked to update the authentication protocols for a legacy Windows-based application running on a stand-alone system. It's using LANMAN and running on Windows XP. You would like to keep using something from Microsoft, but your company won't allow an upgrade past Windows7 during this effort. What do you suggest?

a)

TACACS+

b)

NTLM

c)

RADIUS

d)

LDAP

14.

Which of the following protocols uses a key distribution center and can securely pass a symmetric key over an insecure network?

a)

CHAP

b)

PAP

c)

LDAP

d)

Kerberos

15.

During an ovedue server room inventory, you come across a RADIUS accounting server. Your supervisor asks you what RADIUS accounting was mainly used for . What do you tell him?

a)

Source and destination IP addresses of network traffic

b)

Applications used by users

c)

Time billing and security logging

d)

Tracking file acceess

16.

Bob's development team needs an authentication solution that supports authentication across stateless platforms. They want him to explain how other application use Facebook or Google logins for authentication. In his explanation, which of the following concepts would Bob definitely need to mention?

a)

Secure tokens

b)

Secure tickets

c)

XML requests

d)

Request tokens

17.

You are establishing a point-to-point link and need to provide authentication using PPP. Which of the following protocols would you consider?

a)

TCP auth

b)

RADIUS

c)

SAML

d)

CHAP

18.

Which of the following is a service designed to enable single sign-on and federated identity-based authentication and authorization across networks?

a)

PAP

b)

Shibboleth

c)

XAML

d)

OASIS

19.

Which of the following protocols involves a two-way handshake and sends the username and password in clear text?

a)

SAML

b)

LDAP

c)

PAP

d)

NTLM

20.

OpenID Connect allows for which of the following?

a)

A third party can authenticate your users for you using accounts the users already have

b)

Symmetric keys can be shared across unsecured networks

c)

Identity can be confirmed with a single UDP packet.

d)

Trusted IP addresses can be used to mitigate brute force attacks

21.

Stacy's IT department is looking to impliment a new authentication and authorization capability. They need something that can be used to control access to objects as well as handle user authentication and authorization. Which of the following protocols should she suggest?

a)

MSCHAP

b)

TACACS

c)

PPP

d)

LDAP

22.

Which of the following is an open protocol that allows secure, token-based authentication and authorization from web, desktop, and mobile applications and is used by companies such as Google and Microsoft to permit users to share information about their accounts with third-party applications?

a)

Secure DLI

b)

RADIUS

c)

OAuth

d)

SAML

23.

Which statements about TACACS+ is true?

a)

Communication between a TACACS+ client (typically a NAS) and a TACACS+ server are not secure.

b)

Communications between a user (typically a PC) and the TACACS+ client are subject to compromise as communications are usually not encrypted.

c)

TACACS+ is an extension of TACACS and is backward compatible.

d)

TACACS+ uses UDP for its strsnport protocol and PAP for it's backend functionality

24.

This protocol, which is utilized by many directory service systems from multiple vendors, manages distributed directory information services over an IP network.

a)

LEAP

b)

LDAP

c)

ADUC

d)

Kerberos

25.

What system offers network security through a single sign-in method and provides authentication services primarily on local networks and intranets using TCP/UDP 88?

a)

RADIUS

b)

Diameter

c)

SAML

d)

Kerberos

26.

Which protocols listed provide authentication, authorization, and accounting information between a network access server (NAS) that wants to authenticate its links or end users and a shared authentication server? (Choose all that apply)

a)

RADIUS

b)

TACACS+

c)

Diameter

d)

Kerberos

27.

What SSO supported authentication process connects a principal to a service provider in order to request an authentication token from the identity provider?

a)

RADIUS

b)

TACACS+

c)

Diameter

d)

SAML

28.

Which statement about NTLM is true?

a)

It uses an encrypted challenge/response protocol to authenticat a user

b)

It passes user credentials in clear text only.

c)

It is commonly used to integrate UNIX services into a network

d)

It is typically used on stand-alone systems.

29.

What does the "A" in RADIUS stand for?

a)

Authorization

b)

Authentication

c)

Accounting

d)

Auditing

30.

What type of server authenticates users prior to allowing network access?

a)

File server

b)

Active Directory

c)

Domain Controller

d)

RADIUS

31.

Which of the following are examples of RADIUS clients? (Choose two.)

a)

Wireless router

b)

VPN client

c)

802.1x capable switch

d)

Windows 7

32.

You are the network administrator for a UNIX network. You are planning your network security. A secure protocol must be chosen to authenticate all users logging in. Which is a valid authentication protocol?

a)

TCP auth

b)

Kerberos

c)

AES

d)

SSO

33.

You are evaluating the possibility of a Linux client and server operating system encironment. Your main concern is having a central database of user and computer accounts capable of secure authentication. What Linux options should you explore?

a)

NTFSv2

b)

SSH

c)

Samba

d)

LDAP

34.

Which of the following are authentication/authorization frameworks? (Choose all that apply.)

a)

OpenID Connect

b)

Federation

c)

OAuth

d)

Shibboleth

35.

As the network administrator, you've been tasked with configuring a secure VPN for the CEO and his associates. There are a few different options, however, you know you want to protect the conncetions with IPsec. Which of the following options will allow the use of IPsec to secure the VPN traffic?

a)

PPTP

b)

L2TP

c)

IKEv2

d)

CCMP

36.

Regarding data and storage media disposal, which method involves the process of reducing documents or other items to loose fibers?

a)

Incineration

b)

Pulping

c)

Pulverizing

d)

Deqaussing

37.

Degaussers can destroy all data on magnetic media like tapes, hard drives, and optical or flash storage media. (T/F)

a)

True

b)

False

38.

Data should always be classified according to its nature or _________ level.

a)

regulation

b)

permissions

c)

sensitivity

d)

compliance

39.

What type of training is focused on educating users about how to handle data that requires special handling?

a)

Role-based

b)

Rule-based

c)

Discretionary

d)

Ethics

40.

When it comes to managing data, which role ensures that access systems are set up in such a way that clients are able to view their own private information, and not the private information any other entity in the system?

a)

Owner

b)

Custodian

c)

Privacy Officer

d)

User

41.

Which data management role controls user permissions to access data, implement security controls to keep data safe but available, log access, and produce reports for data owners?

a)

Data owner

b)

Data steward

c)

Data user

d)

Data custodian

42.

This term refers to the process of an organization maintaining the existence of and control over certain data in order to comply with business policies and applicable laws and regulations.

a)

Data disposal

b)

Data retention

c)

Data disposition

d)

Data labeling

43.

What might protect users from copying sensitive files to an external media source?

a)

DLP

b)

FDE

c)

HSM

d)

TPM

44.

What does the data label or qualification PHI stand for?

a)

Personally Hidden Information

b)

Personnel Health Information

c)

Protected Human Intervention

d)

Protected Health Information

45.

Which policy is focused on preventing data loss?

a)

AUP

b)

Clean desk policy

c)

Mandatory vacation

d)

Separation of duties

46.

What strategy helps to mitigate organization risk including functions such as courses of action, continuous monitoring, and configuration validation?

a)

Resiliency

b)

Redundancy

c)

Automation

d)

Distributive allocaion

47.

These are master images that are used for hard disks, virtual machines, or servers that are often used in a self-provisioning environment.

a)

Snapshots

b)

Templates

c)

RAID

d)

VMs

48.

In this type of computing environment, if a failure occurs, the information is lost.

a)

Persistent

b)

Non-persistent

c)

Redudant

d)

Automated

49.

This feature is useful when you need to preserve the state of a virtual machine, allowing a restore point when testing software or configuration changes.

a)

Snapchat

b)

Snapshot

c)

Screenshot

d)

Live boot media

50.

The property by which a computing environment is able to gracefully fulfill its ever-increasing resource needs is most closely defining which term?

a)

Scalability

b)

Elasticity

c)

Redundancy

d)

Distributive allocaion

51.

Commonly found in reference to cloud services, this allows a computing environment to dynamically expand or reduce infrastructure resources by independantly adjust to workload changes in order to maximize resources.

a)

Fault tolerance

b)

Redundancy

c)

Scalability

d)

Elasticity

52.

This allows a computing environment to continue providing services at an acceptable level even when one or more components suffer functionality.

a)

Elasticity

b)

Persistent system

c)

Fault tolerance

d)

Distributive allocaion

53.

A system that creates and maintains one or more copies/sets of additional resources, including the primary set, is providing this particular property.

a)

Redundancy

b)

Scalability

c)

Elasticity

d)

Imagery

54.

Which RAID level provides striped data, broken into blocks, without fault tolerance?

a)

Level 0

b)

Level 1

c)

Level 2

d)

Level 3

55.

This RAID level offers 100 percent redundancy because all data is written to both disks (two minimum requirement).

a)

4

b)

3

c)

2

d)

1