Font size
WorksheetsSecurity+
Total questions: 15
Worksheet time: 17mins
An organization has implemented a policy requiring the use of conductive metal lockboxes for personal electronic devices outside of a secure research lab. Which of the following did the organization determine to be the GREATEST risk to intellectual property when creating this policy?
The theft of portable electronic devices
Geotagging in the metadata of images
Bluesnarfing of mobile devices
Data exfiltration over a mobile hotspot
A company recently set up an e-commerce portal to sell its product online. The company wants to start accepting credit cards for payment, which requires compliance with a security standard. Which of the following standards must the company comply with before accepting credit cards on its e-commerce platform?
PCI DSS
ISO 22301
ISO 27001
NIST CSF
The Chief Financial Officer (CFO) of an insurance company received an email from Ann, the company's Chief Executive Officer (CEO), requesting a transfer of
$10,000 to an account. The email states Ann is on vacation and has lost her purse, containing cash and credit cards. Which of the following social-engineering techniques is the attacker using?
Phishing
Whaling
Typo squatting
Pharming
An organization wants to implement a third factor to an existing multifactor authentication. The organization already uses a smart card and password. Which of the following would meet the organization's needs for a third factor?
Date of birth
Fingerprints
PIN
TPM
An employee has been charged with fraud and is suspected of using corporate assets. As authorities collect evidence, and to preserve the admissibility of the evidence, which of the following forensic techniques should be used?
Order of volatility
Data recovery
Chain of custody
Non-repudiation
A company wants to deploy PKI on its Internet-facing website. The applications that are currently deployed are:
✑ www.company.com (main website)
✑ contactus.company.com (for locating a nearby location)
✑ quotes.company.com (for requesting a price quote)
The company wants to purchase one SSL certificate that will work for all the existing applications and any future applications that follow the same naming conventions, such as store.company.com. Which of the following certificate types would BEST meet the requirements?
SAN
Wildcard
Extended validation
Self-signed
A user contacts the help desk to report the following:
✑ Two days ago, a pop-up browser window prompted the user for a name and password after connecting to the corporate wireless SSID. This had never happened before, but the user entered the information as requested.
✑ The user was able to access the Internet but had trouble accessing the department share until the next day.
✑ The user is now getting notifications from the bank about unauthorized transactions.
Which of the following attack vectors was MOST likely used in this scenario?
Rogue access point
Evil twin
DNS poisoning
ARP poisoning
Joe, an employee, receives an email stating he won the lottery. The email includes a link that requests a name, mobile phone number, address, and date of birth be provided to confirm Joe's identity before sending him the prize. Which of the following BEST describes this type of email?
Spear phishing
Whaling
Phishing
Vishing
A company processes highly sensitive data and senior management wants to protect the sensitive data by utilizing classification labels. Which of the following access control schemes would be BEST for the company to implement?
Discretionary
Rule-based
Role-based
Mandatory
Which of the following policies would help an organization identify and mitigate potential single points of failure in the company's IT/security operations?
Least privilege
Awareness training
Separation of duties
Mandatory vacation
A user enters a password to log in to a workstation and is then prompted to enter an authentication code. Which of the following MFA factors or attributes are being utilized in the authentication process? (Choose two.)
Something you know
Something you have
Somewhere you are
Someone you know
Something you are
A company recently experienced a data breach and the source was determined to be an executive who was charging a phone in a public area. Which of the following would MOST likely have prevented this breach?
A firewall
A device pin
A USB data blocker
Biometrics
A smart switch has the ability to monitor electrical levels and shut off power to a building in the event of power surge of power surge or other fault situation. The switch was installed on a wired network in a hospital and is monitored by the facilities department via a cloud application. The security administrator isolated the switch on a separate VLAN and set up a patching routine. Which of the following steps should also be taken to
harden the smart switch?
Set up an air gap for the switch.
Change the default password for the switch.
Place the switch in a Faraday cage.
Install a cable lock on the switch.
A security assessment determines DES and 3DES are still being used on recently deployed production servers. Which of the following did the assessment identify?
Unsecure protocols
Default settings
Open permissions
Weak encryption
Which of the following describes the BEST approach for deploying application patches?
Apply the patches to systems in a testing environment, then to systems in a staging environment, and finally to production systems.
Test the patches in a staging environment, develop against them in the development environment, and then apply them to the production
systems.
Test the patches in a test environment, apply them to the production systems, and then apply them to a staging environment.
Apply the patches to the production systems, apply them in a staging environment, and then test all of them in a testing environment.
