wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

security+ (601)

Total questions: 25

Worksheet time: 6hrs 15mins

Name
Class
Date
1.

A security administrator is concerned about data exfiltration resulting from the use of malicious phone charging stations. Which of the following would be the BEST way to protect against this threat?

a)

USB Data Blocker

b)

Personal Firewall

c)

MFA

d)

FDE

2.

A company would like to protect the data stored on laptops used in

the field. Which of the following would be the BEST choice for this

requirement?

a)

MAC

b)

SED

c)

CASB

d)

SOAR

3.

A file server has a full backup performed each Monday at 1 AM.

Incremental backups are performed at 1 AM on Tuesday, Wednesday,

Thursday, and Friday. The system administrator needs to perform a full

recovery of the file server on Thursday afternoon. How many backup sets

would be required to complete the recovery?

a)

1

b)

2

c)

3

d)

4

4.

• All mobile devices must be automatically locked after a predefined

time period.

• Some mobile devices will be used by the remote sales teams, so the

location of each device needs to be traceable.

• All of the user’s information should be completely separated from

company data.

Which of the following would be the BEST way to establish these

security policy rules?

a)

Containerization

b)

Biometrics

c)

COPE

d)

VDI

e)

MDF

5.

A security engineer runs a monthly vulnerability scan. The scan doesn’t

list any vulnerabilities for Windows servers, but a significant vulnerability

was announced last week and none of the servers are patched yet. Which

of the following best describes this result?

a)

Zero-Day

b)

Exploit

c)

Credentialed

d)

False Negative

6.

. A security administrator is adding additional authentication controls to the existing infrastructure. Which of the following should be added by the security administrator?

a)

TOTP

b)

Least Privledge

c)

Role-Based Awareness training

d)

job rotation

e)

Smart Card

7.

A network administrator would like each user to authenticate with their personal username and password when connecting to the company's wireless network. Which of the following should the network administrator configure on the wireless access points?

a)

WPA-PSK

b)

802.1X

c)

WPS

d)

WPA2-AES

8.

. A security administrator needs to identify all references to a Javascript file in the HTML of a web page. Which of the following tools should be used to view the source of the web page and search through the file for a specific filename?

a)

grep

b)

openssl

c)

curl

d)

Nmap

e)

scanless

9.

. A user has assigned individual rights and permissions to a file on their network drive. The user adds three additional individuals to have readonly access to the file. Which of the following would describe this access control model?

a)

DAC

b)

MAC

c)

ABAC

d)

RBAC

10.

A remote user has received a text message requesting login details to the corporate VPN server. Which of the following would BEST describe this message?

a)

Brute force

b)

Prepending

c)

Typosquatting

d)

Smishing

11.

A department store policy requires that a floor manager approves each transaction when a gift certificate is used for payment. The security team has found that some of these transactions have been processed without the approval of a manager. Which of the following would provide a separation of duties to enforce this store policy?

a)

Use a WAF to monitor all gift cerificate transactions

b)

Disable all gift certificate transactions for cashiers

c)

Implement a discretionary access control policy

d)

Require an approval PIN for the cashier and a separate approval for the manager

12.

Which of the following is true of a rainbow table

a)

The rainbow table is built in real-time during the attack

b)

rainbow tables are the most effective online attack type

c)

Rainbow tables require significant CPU cycles at attack time

d)

Different tables are required for different hashing methods

e)

A rainbow table won't be useful if the passwords are salted

13.

A server administrator at a bank has noticed a decrease in the number of visitors to the bank's website. Additional research shows that users are being directed to a different IP address than the bank's web server. Which of the following would MOST likely describe this attack?

a)

Disassociation

b)

DDoS

c)

Buffer Overflow

d)

DNS poisoning

14.

Which of these cloud deployment models would share resources between a private virtualized data center and externally available cloud services?

a)

SaaS

b)

Community

c)

Hybrid

d)

Containerization

15.

A company hires a large number of seasonal employees, and their

system access should normally be disabled when the employee leaves

the company. The security administrator would like to verify that their

systems cannot be accessed by any of the former employees. Which of the

following would be the BEST way to provide this verification?

a)

Confirm that no unauthorized accounts have administrator access

b)

Validate the account lockout policy

c)

Validate the process and procedures for all outgoing employees

d)

Create a report that shows all authentications for a 24-hour period

16.

. A network administrator has installed a new access point, but only a

portion of the wireless devices are able to connect to the network. Other

devices can see the access point, but they are not able to connect even

when using the correct wireless settings. Which of the following security

features was MOST likely enabled?

a)

MAC filtering

b)

SSID broadcast suppression

c)

802.1X authentication

d)

Anti-spoofing

17.

Proto Recv-Q Send-Q Local Address Foreign Address (state)

tcp6 416 0 2601:4c3:4080:82.63976 yv-in-x5e.1e100..https CLOSE_WAIT

tcp6 0 0 2601:4c3:4080:82.63908 atl14s80-in-x0a..https ESTABLISHED

tcp6 0 0 fe80::4de1:1d4:8.36253 fe80::38b0:a2b1:.1025 ESTABLISHED

tcp6 0 0 fe80::4de1:1d4:8.1024 fe80::38b0:a2b1:.1024 ESTABLISHED

Which of the following is being used to create this information?

a)

tracert

b)

netstat

c)

dig

d)

netcat

18.

. An attacker has discovered a way to disable a server by sending specially

crafted packets from many remote devices to the operating system. When

the packet is received, the system crashes and must be rebooted to restore

normal operations. Which of the following would BEST describe this

attack?

a)

Privilege escalation

b)

Spoofing

c)

Replay attack

d)

DDoS

19.

A data breach has occurred in a large insurance company. A security

administrator is building new servers and security systems to get all of

the financial systems back online. Which part of the incident response

process would BEST describe these actions?

a)

Lessons learned

b)

Isolation and containment

c)

Reconstitution

d)

Precursors

20.

A manufacturing company has moved an inventory application from their

internal systems to a PaaS service. Which of the following would be the

BEST way to manage security policies on this new service?

a)

DLP

b)

SIEM

c)

IPS

d)

CASB

21.

An organization has identified a significant vulnerability in a firewall that

was recently installed for Internet connectivity. The firewall company has

stated there are no plans to create a patch for this vulnerability. Which of

the following would BEST describe this issue?

a)

Lack of vendor support

b)

Improper input handling

c)

Improper key management

d)

End-of-life

22.

A company has decided to perform a disaster recovery exercise during an

annual meeting with the IT directors and senior directors. A simulated

disaster will be presented, and the participants will discuss the logistics

and processes required to resolve the disaster. Which of the following

would BEST describe this exercise?

a)

After-action report

b)

Business impact analysis

c)

Alternate business practice

d)

Tabletop exercise

23.

A security administrator needs to identify all computers on the company

network infected with a specific malware variant. Which of the following

would be the BEST way to identify these systems?

a)

Honeynet

b)

Data masking

c)

DNS sinkhole

d)

DLP

24.

A system administrator has been called to a system that is suspected to have a malware infection. The administrator has removed the device from the network and has disconnected all USB flash drives. Which of these incident response steps is the administrator following?

a)

Lesson learned

b)

Containment

c)

Detection

d)

Reconstitution

25.

How can a company ensure that all data on a mobile device is

unrecoverable if the device is lost or stolen?

a)

Containerization

b)

Geofencing

c)

Screen locks

d)

Remote wipe