NEW
Font size
Worksheetssecurity+ (601)
Total questions: 15
Worksheet time: 4hrs 45mins
A security administrator is collecting information associated with a ransomware infection on the company's web servers. Which of the following log files would provide information regarding the memory contents of these servers?
Web
Packet
Dump
DNS
Which part of the PC startup process verifies the digital signature of the
OS kernel?
Measured Boot
Trusted Boot
Secure Boot
POST
Which of these best describes two-factor authentication?
A printer uses a password and a PIN
The door to a building requires a fingerprint scan
An application requires a TOTP code
A Windows Domain requires a username, password, and a smart card
• The company does not have a way to manage the mobile devices
in the field
• Company data on mobile devices in the field introduces additional risk
• Team members have many different kinds of mobile devices
Which of the following deployment models would address
these concerns?
Corporate-owned
COPE
VDI
BYOD
An organization is installing a UPS for their new data center. Which of
the following would BEST describe this type of control?
Compensation
Preventive
Administrative
Detective
A manufacturing company would like to track the progress of parts as
they are used on an assembly line. Which of the following technologies
would be the BEST choice for this task?
Quantum computing
Blockchain
Hashing
Asymmetric encryption
A security administrator has been asked to respond to a potential security
breach of the company’s databases, and they need to gather the most
volatile data before powering down the database servers. In which order
should they collect this information?
CPU registers, temporary files, memory, remote monitoring data
Memory, CPU registers, remote monitoring data, temporary files
Memory, CPU registers, remote monitoring data, remote monitoring data
CPU registers, memory, temporary file, remote monitoring data
A Linux administrator is downloading an updated version of her Linux
distribution. The download site shows a link to the ISO and a SHA256
hash value. Which of these would describe the use of this hash value?
Verifies that the file was not corrupted during the file transfer
Provides a key for decrypting the ISO after download
Authenticates the site as an official ISO distribution site
Confirms that the file does not contain any malware
A company's security policy requires that login access should only
be available if a person is physically within the same building as the
server. Which of the following would be the BEST way to provide this
requirement?
TOTP
Biometric scanner
PIN
SMS
Your development team has installed a new application and database to
a cloud service. After running a vulnerability scanner on the application
instance, you find that the database is available for anyone to query
without providing any authentication. Which of these vulnerabilities is
MOST associated with this issue?
Improper error handling
Open permissions
Race condition
Memory leak
. Employees of an organization have received an email offering a cash
bonus for completing an internal training course. The link in the email
requires users to login with their Windows Domain credentials, but the
link appears to be located on an external server. Which of the following
would BEST describe this email?
Whaling
Vishing
Smishing
Phishing
Which of the following risk management strategies would include the
purchase and installation of an NGFW?
Transference
Mitigation
Acceptance
Risk-avoidance
Which of the following would be the BEST way to confirm the secure
baseline of a deployed application instance?
Compare the production application to the sandbox
Perform an integrity measurement
Compare the production application to the previous version
Perform QA testing on application instance
A member of the accounting team was out of the office for two weeks,
and an important financial transfer was delayed until they returned.
Which of the following would have prevented this delay?
Split knowledge
Least privilege
Job rotation
Dual control
A security analyst has identified a number of sessions from a single IP
address with a TTL equal to zero. One of the sessions has a destination of
the Internet firewall, and a session immediately after has a destination of
your DMZ server. Which of the following BEST describes this
log information?
Someone is performing a vulnerability scan against the firewall and DMZ server
Users are performing DNS lookups
A remote user is grabbing banners of the firewall and DMZ server
Someone is performing a traceroute to the DMZ server
