wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

CompTIA Security+ 11-20

Total questions: 10

Worksheet time: 6mins

Name
Class
Date
1.

You have been authorized by management to use a vulnerability scanner once every three months. What is this tool?

a)

an application that identifies ports and services that are at risk on a network

b)

an application that identifies ports and services that are at risk on a network

c)

an application that identifies security issues on a network and gives suggestions on how to prevent the issues

d)

an application that detects when network intrusions occur and identifies the appropriate personnel

2.

As part of your company's comprehensive vulnerability scanning policy, you decide to perform a passive vulnerability scan on one of your company's subnetworks. Which statement is true of this scan?

a)

It allows a more in-depth analysis than other scan types.

b)

It is limited to a particular operating system.

c)

It impacts the hosts and network less than other scan types.

d)

It includes the appropriate permissions for the different data types.

3.

What is the goal when you passively test security controls?

a)

Probing for weaknesses

b)

Infiltrating the network

c)

Interfering with business operations

d)

Exploiting weaknesses

4.

Which of these is part of a scan to identify a common misconfiguration?

a)

Packet sniffing

b)

Dictionary attack

c)

Password policy

d)

Router with a default password

5.

Which memory vulnerability is associated with multithreaded applications?

a)

Resource exhaustion

b)

Race condition

c)

DLL injection

d)

Pointer dereferencing

6.

What is often the weakest link in the security chain, and represents the largest vulnerability?

a)

End-of-life systems

b)

Untrained users

c)

Lack of vendor support

d)

Embedded systems

7.

Which type of vulnerability is demonstrated by a SQL injection?

a)

Default configuration

b)

Improper input handling

c)

Misconfiguration/weak configuration

d)

Improper error handling

8.

An IT technician has been assigned to a new embedded firewall. What statement best describes this type of firewall?

a)

a component that is added to a hardware firewall

b)

a firewall that is installed on a server operating system

c)

a firewall that is integrated into a router

d)

a black box device

9.

Management has decided to purchase a new appliance firewall that will be installed between the public and private networks owned by your company. Which type of firewall is also referred to as an appliance firewall?

a)

hardware

b)

application

c)

embedded

d)

software

10.

You are researching the different types of firewalls that you can install to protect your company's network and assets. Which type of firewall is most detrimental to network performance?

a)

circuit-level proxy firewall

b)

packet-filtering firewall

c)

stateful firewall

d)

application-level proxy firewall