Font size
Worksheetssecurity+ (601)
Total questions: 25
Worksheet time: 6hrs 15mins
A security administrator is concerned about data exfiltration resulting from the use of malicious phone charging stations. Which of the following would be the BEST way to protect against this threat?
USB Data Blocker
Personal Firewall
MFA
FDE
A company would like to protect the data stored on laptops used in
the field. Which of the following would be the BEST choice for this
requirement?
MAC
SED
CASB
SOAR
A file server has a full backup performed each Monday at 1 AM.
Incremental backups are performed at 1 AM on Tuesday, Wednesday,
Thursday, and Friday. The system administrator needs to perform a full
recovery of the file server on Thursday afternoon. How many backup sets
would be required to complete the recovery?
1
2
3
4
• All mobile devices must be automatically locked after a predefined
time period.
• Some mobile devices will be used by the remote sales teams, so the
location of each device needs to be traceable.
• All of the user’s information should be completely separated from
company data.
Which of the following would be the BEST way to establish these
security policy rules?
Containerization
Biometrics
COPE
VDI
MDF
A security engineer runs a monthly vulnerability scan. The scan doesn’t
list any vulnerabilities for Windows servers, but a significant vulnerability
was announced last week and none of the servers are patched yet. Which
of the following best describes this result?
Zero-Day
Exploit
Credentialed
False Negative
. A security administrator is adding additional authentication controls to the existing infrastructure. Which of the following should be added by the security administrator?
TOTP
Least Privledge
Role-Based Awareness training
job rotation
Smart Card
A network administrator would like each user to authenticate with their personal username and password when connecting to the company's wireless network. Which of the following should the network administrator configure on the wireless access points?
WPA-PSK
802.1X
WPS
WPA2-AES
. A security administrator needs to identify all references to a Javascript file in the HTML of a web page. Which of the following tools should be used to view the source of the web page and search through the file for a specific filename?
grep
openssl
curl
Nmap
scanless
. A user has assigned individual rights and permissions to a file on their network drive. The user adds three additional individuals to have readonly access to the file. Which of the following would describe this access control model?
DAC
MAC
ABAC
RBAC
A remote user has received a text message requesting login details to the corporate VPN server. Which of the following would BEST describe this message?
Brute force
Prepending
Typosquatting
Smishing
A department store policy requires that a floor manager approves each transaction when a gift certificate is used for payment. The security team has found that some of these transactions have been processed without the approval of a manager. Which of the following would provide a separation of duties to enforce this store policy?
Use a WAF to monitor all gift cerificate transactions
Disable all gift certificate transactions for cashiers
Implement a discretionary access control policy
Require an approval PIN for the cashier and a separate approval for the manager
Which of the following is true of a rainbow table
The rainbow table is built in real-time during the attack
rainbow tables are the most effective online attack type
Rainbow tables require significant CPU cycles at attack time
Different tables are required for different hashing methods
A rainbow table won't be useful if the passwords are salted
A server administrator at a bank has noticed a decrease in the number of visitors to the bank's website. Additional research shows that users are being directed to a different IP address than the bank's web server. Which of the following would MOST likely describe this attack?
Disassociation
DDoS
Buffer Overflow
DNS poisoning
Which of these cloud deployment models would share resources between a private virtualized data center and externally available cloud services?
SaaS
Community
Hybrid
Containerization
A company hires a large number of seasonal employees, and their
system access should normally be disabled when the employee leaves
the company. The security administrator would like to verify that their
systems cannot be accessed by any of the former employees. Which of the
following would be the BEST way to provide this verification?
Confirm that no unauthorized accounts have administrator access
Validate the account lockout policy
Validate the process and procedures for all outgoing employees
Create a report that shows all authentications for a 24-hour period
. A network administrator has installed a new access point, but only a
portion of the wireless devices are able to connect to the network. Other
devices can see the access point, but they are not able to connect even
when using the correct wireless settings. Which of the following security
features was MOST likely enabled?
MAC filtering
SSID broadcast suppression
802.1X authentication
Anti-spoofing
Proto Recv-Q Send-Q Local Address Foreign Address (state)
tcp6 416 0 2601:4c3:4080:82.63976 yv-in-x5e.1e100..https CLOSE_WAIT
tcp6 0 0 2601:4c3:4080:82.63908 atl14s80-in-x0a..https ESTABLISHED
tcp6 0 0 fe80::4de1:1d4:8.36253 fe80::38b0:a2b1:.1025 ESTABLISHED
tcp6 0 0 fe80::4de1:1d4:8.1024 fe80::38b0:a2b1:.1024 ESTABLISHED
Which of the following is being used to create this information?
tracert
netstat
dig
netcat
. An attacker has discovered a way to disable a server by sending specially
crafted packets from many remote devices to the operating system. When
the packet is received, the system crashes and must be rebooted to restore
normal operations. Which of the following would BEST describe this
attack?
Privilege escalation
Spoofing
Replay attack
DDoS
A data breach has occurred in a large insurance company. A security
administrator is building new servers and security systems to get all of
the financial systems back online. Which part of the incident response
process would BEST describe these actions?
Lessons learned
Isolation and containment
Reconstitution
Precursors
A manufacturing company has moved an inventory application from their
internal systems to a PaaS service. Which of the following would be the
BEST way to manage security policies on this new service?
DLP
SIEM
IPS
CASB
An organization has identified a significant vulnerability in a firewall that
was recently installed for Internet connectivity. The firewall company has
stated there are no plans to create a patch for this vulnerability. Which of
the following would BEST describe this issue?
Lack of vendor support
Improper input handling
Improper key management
End-of-life
A company has decided to perform a disaster recovery exercise during an
annual meeting with the IT directors and senior directors. A simulated
disaster will be presented, and the participants will discuss the logistics
and processes required to resolve the disaster. Which of the following
would BEST describe this exercise?
After-action report
Business impact analysis
Alternate business practice
Tabletop exercise
A security administrator needs to identify all computers on the company
network infected with a specific malware variant. Which of the following
would be the BEST way to identify these systems?
Honeynet
Data masking
DNS sinkhole
DLP
A system administrator has been called to a system that is suspected to have a malware infection. The administrator has removed the device from the network and has disconnected all USB flash drives. Which of these incident response steps is the administrator following?
Lesson learned
Containment
Detection
Reconstitution
How can a company ensure that all data on a mobile device is
unrecoverable if the device is lost or stolen?
Containerization
Geofencing
Screen locks
Remote wipe
