wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

security+ (601)

Total questions: 15

Worksheet time: 4hrs 45mins

Name
Class
Date
1.

A security administrator is collecting information associated with a ransomware infection on the company's web servers. Which of the following log files would provide information regarding the memory contents of these servers?

a)

Web

b)

Packet

c)

Dump

d)

DNS

2.

Which part of the PC startup process verifies the digital signature of the

OS kernel?

a)

Measured Boot

b)

Trusted Boot

c)

Secure Boot

d)

POST

3.

Which of these best describes two-factor authentication?

a)

A printer uses a password and a PIN

b)

The door to a building requires a fingerprint scan

c)

An application requires a TOTP code

d)

A Windows Domain requires a username, password, and a smart card

4.

• The company does not have a way to manage the mobile devices

in the field

• Company data on mobile devices in the field introduces additional risk

• Team members have many different kinds of mobile devices

Which of the following deployment models would address

these concerns?

a)

Corporate-owned

b)

COPE

c)

VDI

d)

BYOD

5.

An organization is installing a UPS for their new data center. Which of

the following would BEST describe this type of control?

a)

Compensation

b)

Preventive

c)

Administrative

d)

Detective

6.

A manufacturing company would like to track the progress of parts as

they are used on an assembly line. Which of the following technologies

would be the BEST choice for this task?

a)

Quantum computing

b)

Blockchain

c)

Hashing

d)

Asymmetric encryption

7.

A security administrator has been asked to respond to a potential security

breach of the company’s databases, and they need to gather the most

volatile data before powering down the database servers. In which order

should they collect this information?

a)

CPU registers, temporary files, memory, remote monitoring data

b)

Memory, CPU registers, remote monitoring data, temporary files

c)

Memory, CPU registers, remote monitoring data, remote monitoring data

d)

CPU registers, memory, temporary file, remote monitoring data

8.

A Linux administrator is downloading an updated version of her Linux

distribution. The download site shows a link to the ISO and a SHA256

hash value. Which of these would describe the use of this hash value?

a)

Verifies that the file was not corrupted during the file transfer

b)

Provides a key for decrypting the ISO after download

c)

Authenticates the site as an official ISO distribution site

d)

Confirms that the file does not contain any malware

9.

A company's security policy requires that login access should only

be available if a person is physically within the same building as the

server. Which of the following would be the BEST way to provide this

requirement?

a)

TOTP

b)

Biometric scanner

c)

PIN

d)

SMS

10.

Your development team has installed a new application and database to

a cloud service. After running a vulnerability scanner on the application

instance, you find that the database is available for anyone to query

without providing any authentication. Which of these vulnerabilities is

MOST associated with this issue?

a)

Improper error handling

b)

Open permissions

c)

Race condition

d)

Memory leak

11.

. Employees of an organization have received an email offering a cash

bonus for completing an internal training course. The link in the email

requires users to login with their Windows Domain credentials, but the

link appears to be located on an external server. Which of the following

would BEST describe this email?

a)

Whaling

b)

Vishing

c)

Smishing

d)

Phishing

12.

Which of the following risk management strategies would include the

purchase and installation of an NGFW?

a)

Transference

b)

Mitigation

c)

Acceptance

d)

Risk-avoidance

13.

Which of the following would be the BEST way to confirm the secure

baseline of a deployed application instance?

a)

Compare the production application to the sandbox

b)

Perform an integrity measurement

c)

Compare the production application to the previous version

d)

Perform QA testing on application instance

14.

A member of the accounting team was out of the office for two weeks,

and an important financial transfer was delayed until they returned.

Which of the following would have prevented this delay?

a)

Split knowledge

b)

Least privilege

c)

Job rotation

d)

Dual control

15.

A security analyst has identified a number of sessions from a single IP

address with a TTL equal to zero. One of the sessions has a destination of

the Internet firewall, and a session immediately after has a destination of

your DMZ server. Which of the following BEST describes this

log information?

a)

Someone is performing a vulnerability scan against the firewall and DMZ server

b)

Users are performing DNS lookups

c)

A remote user is grabbing banners of the firewall and DMZ server

d)

Someone is performing a traceroute to the DMZ server