Font size
Worksheetssecurity+ (601)
Total questions: 20
Worksheet time: 5hrs 0mins
You’ve hired a third-party to gather information about your company’s servers and data. The third-party will not have direct access to your internal network but can gather information from any other source. Which of the following would BEST describe this approach?
Backdoor testing
Passive footprinting
OS fingerprinting
Partially known enviroment
Which of these protocols use TLS to provide secure communication?
HTTPS
SSH
FTPS
SNMPv2
SRTP
Which of these threat actors would be MOST likely to attack systems for direct financial gain?
Organized crime
Hacktivist
Nation state
Compeititor
. A security incident has occurred on a file server. Which of the following data sources should be gathered to address file storage volatility?
Partition data
Kernel statistics
ROM data
Temporary file systems
Process table
An IPS at your company has found a sharp increase in traffic from all-in-one printers. After researching, your security team has found a vulnerability associated with these devices that allows the device to be remotely controlled by a third-party. Which category would BEST describe these devices?
IoT
RTOS
MFD
SoC
. Which of the following standards provides information on privacy and managing PII?
ISO 31000
ISO 27002
ISO 27701
ISO 27001
Elizabeth, a security administrator, is concerned about the potential for data exfiltration using external storage drives. Which of the following would be the BEST way to prevent this method of data exfiltration?
Create an operating system security policy to prevent the use of removable media
Monitor removable media usage in host-based firewall logs
Only allow applications that do not use removable media
Define a removable media block rule in the UTM
A CISO (Chief Information Security Officer) would like to decrease the response time when addressing security incidents. Unfortunately, the company does not have the budget to hire additional security engineers. Which of the following would assist the CISO with this requirement?
ISO 27701
PKI
IaaS
SOAR
• Access records from all devices must be saved and archived • Any data access outside of normal working hours must be immediately reported • Data access must only occur inside of the country • Access logs and audit reports must be created from a single database Which of the following should be implemented by the security team to meet these requirements?
Restrict login access by IP address and GPS location
Consolidate all logs on a SIEM
Add additional password complexity for accounts that access data
Conduct monthly permission auditing
Enable time-of-day restrictions on the authentication server
UTC 04/05/2018 03:09:15809 AV Gateway Alert
136.127.92.171 80 -> 10.16.10.14 60818
Gateway Anti-Virus Alert: XPACK.A_7854 (Trojan) blocked.
Which of the following can be observed from this log information?
The victim's IP address is 136.127.92.171
A download was blocked from a web server
A botnet DDoS attack was blocked
The Trojan was blocked, but the file was not
Your connection is not private.
NET::ERR_CERT_INVALID
Which of the following attacks would be the MOST likely reason for this message?
Brute force
Dos
On-path
Dissassociation
Which of the following would be the BEST way to provide a website login using existing credentials from a third-party site?
Federation
802.1X
PEAP
EAP-FAST
A system administrator, Daniel, is working on a contract that will specify a minimum required uptime for a set of Internet-facing firewalls. Daniel needs to know how often the firewall hardware is expected to fail between repairs. Which of the following would BEST describe this information?
MTBF
RTO
MTTR
MTTF
An attacker calls into a company’s help desk and pretends to be the director of the company’s manufacturing department. The attacker states that they have forgotten their password and they need to have the password reset quickly for an important meeting. What kind of attack would BEST describe this phone call?
Social engineering
Tailgating
Vishing
On-path
A security administrator has been using EAP-FAST wireless authentication since the migration from WEP to WPA2. The company’s network team now needs to support additional authentication protocols inside of an encrypted tunnel. Which of the following would meet the network team’s requirements?
EAP-TLS
PEAP
EAP-TTLS
EAP-MSCHAPv2
Which of the following would be commonly provided by a CASB?
List of all internal Windows devices that have not installed the latest security patches
List of applications in use
Centralized log storage facility
. Verification of encrypted data transfers
The embedded OS in a company’s time clock appliance is configured to reset the file system and reboot when a file system error occurs. On one of the time clocks, this file system error occurs during the startup process and causes the system to constantly reboot. Which of the following BEST describes this issue?
DLL injection
Resource exhaustion
race condition
Weak configuration
A recent audit has found that existing password policies do not include any restrictions on password attempts, and users are not required to periodically change their passwords. Which of the following would correct these policy issues?
Password complexity
Password expiration
Password history
Password lockout
Password recovery
What kind of security control is associated with a login banner?
Preventive
Deterrent
Corrective
Detective
Physical
A security team has been provided with a noncredentialed vulnerability scan report created by a thirdparty. Which of the following would they expect to see on this report?
A summary of all files with invalid group assignments
A list of all unpatched operating system files
The version of web server software in use
A list of local user accounts
