wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Security+ Phase 4

Total questions: 64

Worksheet time: 2hrs 8mins

Name
Class
Date
1.

Which authentication protocol is used by Microsoft Active Directory Domain Services?

a)

802.1x

b)

Kerberos

c)

RADIUS

d)

OAuth

2.

Your organization requires a method for desktop computers to verify that the machine boots only with trusted operating systems. Which firmware components must be present to meet this requirement? (Choose two.)

a)

EAP

b)

HSM

c)

UEFI

d)

TPM

3.

Which configuration option enhances the user authentication process?

a)

TPM

b)

HSM

c)

SSO

d)

MFA

4.

Which term best embodies a centralized network database containing user account information?

a)

SSO

b)

OpenID

c)

SAML

d)

Directory service

5.

Which authentication example is considered multifactor authentication?

a)

Username, password

b)

Smartcard, key fob

c)

Username, password, fingerprint scan

d)

Username, password, security question

6.

When authenticating to your cloud account, you must supply a username, password, and a unique numeric code supplied from a smartphone app that changes every 30 seconds. Which term is used to describe the changing numeric code?

a)

SMS

b)

TOTP

c)

Virtual smartcard

d)

Push notification

7.

Which authentication protocol transmits user sign-in credentials in plain text over the network?

a)

CHAP

b)

TACACS+

c)

PAP

d)

Kerberos

8.

Your organization is creating a web application that generates animated video from story text. Instead of requiring users to create an account with your organization before using the app, you want to enable users to sign in using their existing Google or Facebook accounts. What type of authentication is this?

a)

Attested

b)

Token key

c)

Federated

d)

Kerberos

9.

Which security hardware can be used for multifactor authentication?

a)

Token key

b)

TPM

c)

HSM

d)

Password vault

10.

Which term best describes a user authenticating to a service and receiving a unique authentication code via a phone call?

a)

Token key

b)

Out-of-band authentication

c)

Federation

d)

SAML

11.

Which type of authentication method measures the motion patterns of a person’s body movement?

a)

SAML

b)

Biometric

c)

Gait analysis

d)

TOTP

12.

A user complains that her new laptop occasionally does not allow fingerprint authentication. Which term best describes this situation?

a)

Crossover error rate

b)

False acceptance

c)

False rejection

d)

Efficacy rate

13.

A travelling employee is unable to authenticate to a corporate custom web application that is normally accessible when he’s at home. What type of authentication is in place or the custom web application?

a)

Biometric

b)

Federated

c)

Geolocation

d)

Attested

14.

Which of the following represents the correct sequence in which AAA occurs?

a)

All AAA items occur simultaneously

b)

Authorization, authentication, accounting

c)

Authentication, authorization, accounting

d)

Accounting, authentication, authorization

15.

You have configured your smartphone authentication such that, using your finger, you connect points on a picture. Which type of authentication category does this apply to?

a)

Something you are

b)

Somewhere you are

c)

Something you know

d)

Something you do

16.

You have forgotten your login credentials for a secure web site. The forgotten password mechanism on the site prompts you to enter your PIN before selecting a help desk user that will supply you with a reset code. Which type of forgotten password authentication mechanism is at work here?

a)

Something you are

b)

Somewhere you are

c)

Something you exhibit

d)

Someone you know

17.

Cloud technicians in your organization have linked your on-premises Microsoft Active Directory domain to a cloud-based directory service. What benefit is derived from this configuration?

a)

Multifactor authentication can be enabled.

b)

User authentication will occur faster.

c)

Users can authenticate to cloud apps using their on-premises credentials.

d)

User authorization will occur faster.

18.

Which type of authentication environment is depicted in Figure 10-1?

a)

SSO

b)

Federated

c)

Kerberos

d)

Multifactor

19.

Which type of authentication is depicted in Figure 10-2?

a)

Biometric

b)

Geolocation

c)

SSO

d)

TOTP

20.

Which type of authentication is depicted in Figure 10-3?

a)

Biometric

b)

Gesture-based

c)

Location-based

d)

TOTP

21.

Which of the following is an example of authentication?

a)

Accessing a secured part of a web site

b)

Writing a log entry when users access sensitive files

c)

Verifying that files have not been modified by unauthorized users

d)

Supplying a username and password

22.

Users complain that they cannot use different usernames and passwords for all of the web applications they use because there are too many to remember, so they use the same username and password for all of the web apps. You need to ensure that users maintain unique usernames and complex passwords for all web apps while minimizing user frustration. What should you deploy for users?

a)

HSM

b)

TPM

c)

Token key

d)

Password vault

23.

A malicious user has removed an encrypted drive from a TPM-enabled system and connected it to his own TPM-enabled computer. What will the outcome be?

a)

The malicious user will have full access to the drive contents.

b)

The malicious user will be unable to access the drive contents.

c)

The drive contents will be erased automatically.

d)

The drive contents will be accessible in read-only mode.

24.

Which fact is specific to the Challenge Handshake Authentication Protocol (CHAP)?

a)

Passwords are sent over the network in encrypted form.

b)

Passwords are sent over the network in plaint text.

c)

Passwords are never sent over the network.

d)

Passwords are combined with a one-time password to complete authentication.

25.

How does OAuth determine whether a user is permitted to access a resource?

a)

Username, password

b)

PKI certificate

c)

One-time password

d)

Access token

26.

Which term is the most closely associated with Figure 10-4?

a)

OAuth

b)

MFA

c)

OTP

d)

TPM

27.

After successful authentication, which method can be used to transmit authorization details to a resource provider to grant resource access?

a)

Kerberos

b)

SAML

c)

MFA

d)

OTP

28.

Which statements regarding OAuth are correct? (Choose two.)

a)

OAuth passes encrypted user credentials to a resource provider.

b)

OAuth tokens are issued by a resource provider.

c)

OAuth tokens are consumed by a resource provider.

d)

OAuth does not handle authentication.

29.

You need to configure VPN authentication methods that use PKI certificates. Which VPN configuration option should you choose?

a)

PAP

b)

CHAP

c)

OAuth

d)

EAP

30.

To secure VPN access, you need a solution that will first authenticate devices before allowing network access. Which authentication standard does this apply to?

a)

OAuth

b)

MFA

c)

IEEE 802.1x

d)

SSO

31.

You do not want authentication handled by wireless access points in your network. What should you configure?

a)

RADIUS server

b)

OAuth

c)

SSO

d)

Identity federation

32.

Which authentication standard is directly related to identity federation?

a)

Kerberos

b)

CHAP

c)

OpenID

d)

IEEE 802.1x

33.

Which identity federation component authenticates users?

a)

Identity provider

b)

Resource provider

c)

OAuth

d)

SAML

34.

After successful authentication, which SAML component contains claim information?

a)

Resource provider

b)

Security token service

c)

PKI certificate

d)

Token

35.

You are configuring file system security such that Microsoft Active Directory user accounts with a specific manager configured in their user account properties are granted file system access. What type of access control configuration is this?

a)

Role-based

b)

Discretionary

c)

Attribute-based

d)

Time-based

36.

Which of the following constitutes multifactor authentication?

a)

Username, password

b)

Username, PIN

c)

Smartcard, PIN

d)

Smartcard, key fob

37.

You are configuring SSH public key authentication for a Linux host. Which statements about this configuration are correct? (Choose two.)

a)

The public key is stored with the user.

b)

The private key is stored with the user.

c)

The public key is stored with the Linux host.

d)

The private key is stored with the Linux host.

38.

After configuring SSH public key authentication for a Linux host, users complain that they are prompted for a passphrase when using SSH to connect to the host. Why is this happening?

a)

SSH is configured incorrectly on the Linux host.

b)

SSH is configured incorrectly on the client device.

c)

A passphrase has been configured to protect the private key.

d)

A passphrase has been configured to protect the public key.

39.

Which configuration limits the use of a mobile device to a specific area?

a)

Geotagging

b)

Geolocation

c)

GPS

d)

Geofencing

40.

While scrolling through social media posts, you come across a friend’s post stating that he had recently boarded a flight from Las Vegas en route to Toronto. What is this an example of?

a)

Geotagging

b)

Geolocation

c)

GPS

d)

Geofencing

41.

Which user password setting will prevent the reuse of old passwords?

a)

Password complexity

b)

Account lockout

c)

Password history

d)

Time-based login

42.

You have configured user workstations so that upon a user’s login, a message states that the system may be used only to conduct business in accordance with organizational security policies, and that noncompliance could result in disciplinary action. Which type of security control is this?

a)

Detective

b)

Corrective

c)

Deterrent

d)

Compensating

43.

Which type of access control model uses a hardened specialized operating system with resource labeling and security clearance levels to control resources access?

a)

Discretionary access control

b)

Role-based access control

c)

Attribute-based access control

d)

Mandatory access control

44.

Your cloud-based virtual machine runs a custom application workload that requires access to resources running within on-premises virtual machines. What should you do to enable secure connectivity between the virtual machines? (Choose two.)

a)

Configure HTTP connectivity between the virtual machines.

b)

Configure a guest account for the application.

c)

Configure a service account for the application.

d)

Configure a VPN tunnel between the virtual machines.

45.

Which term is the most closely related to the “impossible travel time” security feature?

a)

Chain of trust

b)

Security token

c)

Geofencing

d)

Anomaly detection

46.

You are configuring file servers in the enterprise to allow read-only access to files labeled as “PII” for users accessing files from the corporate network if they have been assigned to a project named “ProjectA.” Which type of access control mechanism is being used?

a)

Discretionary

b)

Conditional

c)

Mandatory

d)

Role-based

47.

The IT department has been tasked with conducting a risk assessment related to the migration of a line-of-business app to the public cloud. To which security control category does this apply?

a)

Operational

b)

Managerial

c)

Technical

d)

Physical

48.

You have been tasked with the weekly tape backup rotation for backing up on-premises database servers. To which security control category does this apply?

a)

Operational

b)

Managerial

c)

Technical

d)

Physical

49.

Organizational security policies require that customers’ personal information be encrypted when stored. To which security control category does this apply?

a)

Operational

b)

Managerial

c)

Technical

d)

Physical

50.

You are configuring a hardware firewall to allow traffic only from a jump box in the DMZ to internal Linux hosts. Which type of security control is this?

a)

Physical

b)

Compensating

c)

Preventative

d)

Detective

51.

To achieve regulatory compliance, your organization must encrypt all fixed disks to protect data at rest on each station. Your company plans on using the Microsoft Windows BitLocker drive encryption feature. None of your computers has a TPM chip, so you have configured Group Policy such that decryption keys can be stored on a removable USB thumb drive. Which type of security control is this?

a)

Physical

b)

Compensating

c)

Detective

d)

Corrective

52.

You have configured a network-based intrusion prevention system (NIPS) hardware appliance to block traffic from IP addresses that send excessive traffic to your network. Which type of security control is this?

a)

Physical

b)

Compensating

c)

Deterrent

d)

Corrective

53.

You are a consultant helping a retail client with app geofencing. Which type of tracking mechanisms can you use to enable geofencing for customers with the retail app installed on their smartphones?

a)

GPS, Wi-Fi

b)

Wi-Fi, NFC

c)

GPS, NAC

d)

NAC, Bluetooth

54.

Your identity federation configuration creates digitally signed tokens for authenticated users that contain the user date of birth and security clearance level. Which term is used to describe this extra data added to the token?

a)

PKI certificate

b)

Cookie

c)

SAML

d)

Claim

55.

Why is the SSH authentication error in Figure 11-1 occurring?

a)

The incorrect public key is being used.

b)

The incorrect private key is being used.

c)

The username is incorrect.

d)

The password is incorrect.

56.

You are viewing the contents of the Linux authorized_keys file. Which type of key is stored here?

a)

Public

b)

Private

c)

Secret

d)

Symmetric

57.

You need to assess whether Linux servers in the screened subnet need to be hardened. The servers are currently configured with SSH public key authentication. What should you check that should be in place? (Choose two.)

a)

Password protection for the public key

b)

Private key password protection

c)

Default SSH port number TCP 22 has been changed to an unreserved port number

d)

Default SSH port number TCP 25 has been changed to an unreserved port number

58.

Which statements regarding SSH public key authentication are correct? (Choose two.)

a)

A user password is not required.

b)

A user password is required.

c)

A public and private key pair is required.

d)

A symmetric key is required.

59.

You are an IT technician for FakeCorp1. You have configured your on-premises Microsoft Active Directory domain controller server, Dc1, as a federated identity provider during the acquisition phase of a competitor, FakeCorp2. The IT team at FakeCorp2 must configure web app servers to trust tokens issued by FakeCorp1. What should you provide to the technicians?

a)

The private key for DC1

b)

The administrative username for DC1

c)

The public key for DC1

d)

The administrative password for DC1

60.

What is normally required when using smartcard authentication? (Choose two.)

a)

Smartcard reader

b)

PIN

c)

TPM

d)

HSM

61.

Where are virtual smartcards stored?

a)

Windows registry

b)

RADIUS server

c)

Identity provider

d)

TPM

62.

Your organization plans on issuing smartcards to users for the purposes of digitally signing and decrypting e-mail messages. What must be deployed to the smartcards?

a)

Server public key

b)

User public key

c)

Server private key

d)

User private key

63.

What is one disadvantage of using a virtual smartcard in a Microsoft Windows environment?

a)

It is available only on a single Android smartphone at a time.

b)

It cannot be used for remote management.

c)

It requires a virtual smartcard reader.

d)

It is available only on a host with TPM.

64.

A user account lockout configuration helps mitigate which type of attack?

a)

Denial of service

b)

Ransomware

c)

Phishing

d)

Brute-force password attacks