Font size
WorksheetsSec+ 601 Final Review Week
Total questions: 52
Worksheet time: 2hrs 47mins
Management within your organization has defined a use case to support the confidentiality of PII stored in a database. Which of the following solutions will BEST meet this need?
Hashing
Digital signature
Encryption
Smart card
Your organization recently implemented two servers that act as a failover device for each other. Which security goal does this policy address?
Confidentiality
Integrity
Obfuscation
Availability
You are tasked with improving the overall security of a database server. Which of the following is a preventive control that will assist with this goal?
Disabling unnecessary services
Identifying the initial baseline configuration
Monitoring logs for trends
Implementing a backup and restoration plan
You suspect that traffic in your network is being rerouted to an unauthorized router within your network. Which of the following command-line tools would help you narrow down the problem?
ping
tracert
ipconfig
netstat
When you log on your online bank account you are also able to access a partner's credit card site, check-ordering services, and a mortgage site without entering your credentials again.
Which of the following does this describe?
SSO
Same sign-on
SAML
Kerberos
You are tasked with configuring a switch so that it separates VoIP and data traffic.
Which of the following provides the BEST solution?
NAC
DMZ
SRTP
VLAN
After Marge turned on her computer, she saw a message indicating that unless she made a payment, her hard drive would be formatted.
What does this indicate?
Keylogger
Ransomware
Backdoor
Trojan
Which of the following is the LOWEST cost solution for fault tolerance?
Load balancing
Round-robin scheduling
RAID
Warm site
Your organization recently suffered a loss from malware that wasn't previously known by any trusted sources.
Which of the following BEST describes this attack?
Phishing
Zero-day
Hoax
Spam
Which of the following terms refers to the concept of virtualization on an application level?
Serverless architecture
Containerization
Virtualization
Emulator
Which programming aspects are critical for secure application development process? (Select 2 answers)
Patch management
Input Validation
Password Protection
Error and Exception handling
Application whitelisting
The process of removing redundant entries from a database is known as:
Normalization
Input Validation
Baselining
Data sanitization
Which of the following is an example of cryptomalware?
Backdoor
Ransomware
Keylogger
Rootkit
Which type of Trojan enables unauthorized remote access to a compromised system?
RAT
MaaS
pcap
pfsense
A collection of software tools used by a hacker to mask intrusion and obtain administrator-level access to a computer or computer network is known as
Rootkit
Spyware
Backdoor
Trojan
Which of the following refers to an undocumented (and often legitimate) way of gaining access to a program, online service, or an entire computer system?
Logic Bomb
Trojan horse
Rootkit
Backdoor
Which password attack takes advantage of a predefined list of words?
Birthday attack
Replay attack
Dictionary attack
Brute-force attack
An attack against encrypted data that relies heavily on computing power to check all possible keys and passwords until the correct one is found is known as:
Replay attack
Brute-force attack
Dictionary attack
Birthday attack
You have been authorized by management to use a vulnerability scanner once every three months. What is this tool?
an application that identifies ports and services that are at risk on a network
an application that identifies ports and services that are at risk on a network
an application that identifies security issues on a network and gives suggestions on how to prevent the issues
an application that detects when network intrusions occur and identifies the appropriate personnel
As part of your company's comprehensive vulnerability scanning policy, you decide to perform a passive vulnerability scan on one of your company's subnetworks. Which statement is true of this scan?
It allows a more in-depth analysis than other scan types.
It is limited to a particular operating system.
It impacts the hosts and network less than other scan types.
It includes the appropriate permissions for the different data types.
What is the goal when you passively test security controls?
Probing for weaknesses
Infiltrating the network
Interfering with business operations
Exploiting weaknesses
Which of these is part of a scan to identify a common misconfiguration?
Packet sniffing
Dictionary attack
Password policy
Router with a default password
Which memory vulnerability is associated with multithreaded applications?
Resource exhaustion
Race condition
DLL injection
Pointer dereferencing
What is often the weakest link in the security chain, and represents the largest vulnerability?
End-of-life systems
Untrained users
Lack of vendor support
Embedded systems
Which type of vulnerability is demonstrated by a SQL injection?
Default configuration
Improper input handling
Misconfiguration/weak configuration
Improper error handling
Management has decided to purchase a new appliance firewall that will be installed between the public and private networks owned by your company. Which type of firewall is also referred to as an appliance firewall?
hardware
application
embedded
software
You are researching the different types of firewalls that you can install to protect your company's network and assets. Which type of firewall is most detrimental to network performance?
circuit-level proxy firewall
packet-filtering firewall
stateful firewall
application-level proxy firewall
What kind of attack can we use with botnets?
ARP poisoning
DOS
Shoulder surfing
DDOS
In which of the following social engineering attack, the attacker threaten the victim to achieve the attack?
Intimidation
Familiarity
Urgency
Social proof
Which of the following terms is used to describe the theft of personal data from a payment card?
Identity theft
Skimming
Phishing
Shoulder surfing
Which of the following protocols is used to secure communications between sender and receiver?
SIP
SNMP
SSL
SMTP
Joe is tuning his organization's firewall rules to prevent IP spoofing. What type of control is Joe implementing?
Operational
Technical
Physical
Managerial
Your company is developing an application in which a private US-based hospital will allow patients to access their medical records online. Regardless of what other data the application handles, what kind of compliance do you already know you need to research?
FISMA
HIPAA
PCI DSS
FERPA
Someone stole thousands of customer records from your organization's database. What aspect of security was primarily attacked?
Portability
Confidentiality
Integrity
Availability
Which of the following is a US government agency charged with developing and supporting standards used by other government organizations?
NIST
W3C
OWASP
ISOC
Which of the following controls primarily protect data availability?
Digital signatures
Patch management
Hashing
Version control
Your company has received an email that contained a virus attached. Later, you have realized that no alarm is raised as the email security solution that your company uses didn't detect the threat. Which of the following has occurred?
False positive
True negative
True positive
False negative
Which of these best describes two-factor authentication?
A printer uses a password and a PIN
The door to a building requires a fingerprint scan
An application requires a TOTP code
A Windows Domain requires a username, password, and a smart card
A manufacturing company would like to track the progress of parts as
they are used on an assembly line. Which of the following technologies
would be the BEST choice for this task?
Quantum computing
Blockchain
Hashing
Asymmetric encryption
A Linux administrator is downloading an updated version of her Linux
distribution. The download site shows a link to the ISO and a SHA256
hash value. Which of these would describe the use of this hash value?
Verifies that the file was not corrupted during the file transfer
Provides a key for decrypting the ISO after download
Authenticates the site as an official ISO distribution site
Confirms that the file does not contain any malware
. Employees of an organization have received an email offering a cash
bonus for completing an internal training course. The link in the email
requires users to login with their Windows Domain credentials, but the
link appears to be located on an external server. Which of the following
would BEST describe this email?
Whaling
Vishing
Smishing
Phishing
Which of the following risk management strategies would include the
purchase and installation of an NGFW?
Transference
Mitigation
Acceptance
Risk-avoidance
A member of the accounting team was out of the office for two weeks,
and an important financial transfer was delayed until they returned.
Which of the following would have prevented this delay?
Split knowledge
Least privilege
Job rotation
Dual control
Which of these protocols use TLS to provide secure communication?
HTTPS
SSH
FTPS
SNMPv2
SRTP
Which of these threat actors would be MOST likely to attack systems for direct financial gain?
Organized crime
Hacktivist
Nation state
Compeititor
UTC 04/05/2018 03:09:15809 AV Gateway Alert
136.127.92.171 80 -> 10.16.10.14 60818
Gateway Anti-Virus Alert: XPACK.A_7854 (Trojan) blocked.
Which of the following can be observed from this log information?
The victim's IP address is 136.127.92.171
A download was blocked from a web server
A botnet DDoS attack was blocked
The Trojan was blocked, but the file was not
Which of the following would be the BEST way to provide a website login using existing credentials from a third-party site?
Federation
802.1X
PEAP
EAP-FAST
The embedded OS in a company’s time clock appliance is configured to reset the file system and reboot when a file system error occurs. On one of the time clocks, this file system error occurs during the startup process and causes the system to constantly reboot. Which of the following BEST describes this issue?
DLL injection
Resource exhaustion
race condition
Weak configuration
Which of the following was initially designed as a stream cipher?
AES
Blowfish
RC4
Twofish
Which of the following is a certificate backed by a stricter identity validation process than the CA’s default?
Domain validation
Extended Validation
Machine authentication
If Alice wishes to digitally sign the message that she is sending to Bob, what key would she use to create the digital signature?
Alice's private key
Alice's public key
Bob's private key
Bob's public key
In which of the following, the server periodically verifies its own certificate status and receives a time-stamped response signed by the CA?
Escrow
Key pinning
Transposition
Stapling
