wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Sec+ 601 Final Review Week

Total questions: 52

Worksheet time: 2hrs 47mins

Name
Class
Date
1.

Management within your organization has defined a use case to support the confidentiality of PII stored in a database. Which of the following solutions will BEST meet this need?

a)

Hashing

b)

Digital signature

c)

Encryption

d)

Smart card

2.

Your organization recently implemented two servers that act as a failover device for each other. Which security goal does this policy address?

a)

Confidentiality

b)

Integrity

c)

Obfuscation

d)

Availability

3.

You are tasked with improving the overall security of a database server. Which of the following is a preventive control that will assist with this goal?

a)

Disabling unnecessary services

b)

Identifying the initial baseline configuration

c)

Monitoring logs for trends

d)

Implementing a backup and restoration plan

4.

You suspect that traffic in your network is being rerouted to an unauthorized router within your network. Which of the following command-line tools would help you narrow down the problem?

a)

ping

b)

tracert

c)

ipconfig

d)

netstat

5.

When you log on your online bank account you are also able to access a partner's credit card site, check-ordering services, and a mortgage site without entering your credentials again.


Which of the following does this describe?

a)

SSO

b)

Same sign-on

c)

SAML

d)

Kerberos

6.

You are tasked with configuring a switch so that it separates VoIP and data traffic.


Which of the following provides the BEST solution?

a)

NAC

b)

DMZ

c)

SRTP

d)

VLAN

7.

After Marge turned on her computer, she saw a message indicating that unless she made a payment, her hard drive would be formatted.


What does this indicate?

a)

Keylogger

b)

Ransomware

c)

Backdoor

d)

Trojan

8.

Which of the following is the LOWEST cost solution for fault tolerance?

a)

Load balancing

b)

Round-robin scheduling

c)

RAID

d)

Warm site

9.

Your organization recently suffered a loss from malware that wasn't previously known by any trusted sources.


Which of the following BEST describes this attack?

a)

Phishing

b)

Zero-day

c)

Hoax

d)

Spam

10.

Which of the following terms refers to the concept of virtualization on an application level?

a)

Serverless architecture

b)

Containerization

c)

Virtualization

d)

Emulator

11.

Which programming aspects are critical for secure application development process? (Select 2 answers)

a)

Patch management

b)

Input Validation

c)

Password Protection

d)

Error and Exception handling

e)

Application whitelisting

12.

The process of removing redundant entries from a database is known as:

a)

Normalization

b)

Input Validation

c)

Baselining

d)

Data sanitization

13.

Which of the following is an example of cryptomalware?

a)

Backdoor

b)

Ransomware

c)

Keylogger

d)

Rootkit

14.

Which type of Trojan enables unauthorized remote access to a compromised system?

a)

RAT

b)

MaaS

c)

pcap

d)

pfsense

15.

A collection of software tools used by a hacker to mask intrusion and obtain administrator-level access to a computer or computer network is known as

a)

Rootkit

b)

Spyware

c)

Backdoor

d)

Trojan

16.

Which of the following refers to an undocumented (and often legitimate) way of gaining access to a program, online service, or an entire computer system?

a)

Logic Bomb

b)

Trojan horse

c)

Rootkit

d)

Backdoor

17.

Which password attack takes advantage of a predefined list of words?

a)

Birthday attack

b)

Replay attack

c)

Dictionary attack

d)

Brute-force attack

18.

An attack against encrypted data that relies heavily on computing power to check all possible keys and passwords until the correct one is found is known as:

a)

Replay attack

b)

Brute-force attack

c)

Dictionary attack

d)

Birthday attack

19.

You have been authorized by management to use a vulnerability scanner once every three months. What is this tool?

a)

an application that identifies ports and services that are at risk on a network

b)

an application that identifies ports and services that are at risk on a network

c)

an application that identifies security issues on a network and gives suggestions on how to prevent the issues

d)

an application that detects when network intrusions occur and identifies the appropriate personnel

20.

As part of your company's comprehensive vulnerability scanning policy, you decide to perform a passive vulnerability scan on one of your company's subnetworks. Which statement is true of this scan?

a)

It allows a more in-depth analysis than other scan types.

b)

It is limited to a particular operating system.

c)

It impacts the hosts and network less than other scan types.

d)

It includes the appropriate permissions for the different data types.

21.

What is the goal when you passively test security controls?

a)

Probing for weaknesses

b)

Infiltrating the network

c)

Interfering with business operations

d)

Exploiting weaknesses

22.

Which of these is part of a scan to identify a common misconfiguration?

a)

Packet sniffing

b)

Dictionary attack

c)

Password policy

d)

Router with a default password

23.

Which memory vulnerability is associated with multithreaded applications?

a)

Resource exhaustion

b)

Race condition

c)

DLL injection

d)

Pointer dereferencing

24.

What is often the weakest link in the security chain, and represents the largest vulnerability?

a)

End-of-life systems

b)

Untrained users

c)

Lack of vendor support

d)

Embedded systems

25.

Which type of vulnerability is demonstrated by a SQL injection?

a)

Default configuration

b)

Improper input handling

c)

Misconfiguration/weak configuration

d)

Improper error handling

26.

Management has decided to purchase a new appliance firewall that will be installed between the public and private networks owned by your company. Which type of firewall is also referred to as an appliance firewall?

a)

hardware

b)

application

c)

embedded

d)

software

27.

You are researching the different types of firewalls that you can install to protect your company's network and assets. Which type of firewall is most detrimental to network performance?

a)

circuit-level proxy firewall

b)

packet-filtering firewall

c)

stateful firewall

d)

application-level proxy firewall

28.

What kind of attack can we use with botnets?

a)

ARP poisoning

b)

DOS

c)

Shoulder surfing

d)

DDOS

29.

In which of the following social engineering attack, the attacker threaten the victim to achieve the attack?

a)

Intimidation

b)

Familiarity

c)

Urgency

d)

Social proof

30.

Which of the following terms is used to describe the theft of personal data from a payment card?

a)

Identity theft

b)

Skimming

c)

Phishing

d)

Shoulder surfing

31.

Which of the following protocols is used to secure communications between sender and receiver?

a)

SIP

b)

SNMP

c)

SSL

d)

SMTP

32.

Joe is tuning his organization's firewall rules to prevent IP spoofing. What type of control is Joe implementing?

a)

Operational

b)

Technical

c)

Physical

d)

Managerial

33.

Your company is developing an application in which a private US-based hospital will allow patients to access their medical records online. Regardless of what other data the application handles, what kind of compliance do you already know you need to research?

a)

FISMA

b)

HIPAA

c)

PCI DSS

d)

FERPA

34.

Someone stole thousands of customer records from your organization's database. What aspect of security was primarily attacked?

a)

Portability

b)

Confidentiality

c)

Integrity

d)

Availability

35.

Which of the following is a US government agency charged with developing and supporting standards used by other government organizations?

a)

NIST

b)

W3C

c)

OWASP

d)

ISOC

36.

Which of the following controls primarily protect data availability?

a)

Digital signatures

b)

Patch management

c)

Hashing

d)

Version control

37.

Your company has received an email that contained a virus attached. Later, you have realized that no alarm is raised as the email security solution that your company uses didn't detect the threat. Which of the following has occurred?

a)

False positive

b)

True negative

c)

True positive

d)

False negative

38.

Which of these best describes two-factor authentication?

a)

A printer uses a password and a PIN

b)

The door to a building requires a fingerprint scan

c)

An application requires a TOTP code

d)

A Windows Domain requires a username, password, and a smart card

39.

A manufacturing company would like to track the progress of parts as

they are used on an assembly line. Which of the following technologies

would be the BEST choice for this task?

a)

Quantum computing

b)

Blockchain

c)

Hashing

d)

Asymmetric encryption

40.

A Linux administrator is downloading an updated version of her Linux

distribution. The download site shows a link to the ISO and a SHA256

hash value. Which of these would describe the use of this hash value?

a)

Verifies that the file was not corrupted during the file transfer

b)

Provides a key for decrypting the ISO after download

c)

Authenticates the site as an official ISO distribution site

d)

Confirms that the file does not contain any malware

41.

. Employees of an organization have received an email offering a cash

bonus for completing an internal training course. The link in the email

requires users to login with their Windows Domain credentials, but the

link appears to be located on an external server. Which of the following

would BEST describe this email?

a)

Whaling

b)

Vishing

c)

Smishing

d)

Phishing

42.

Which of the following risk management strategies would include the

purchase and installation of an NGFW?

a)

Transference

b)

Mitigation

c)

Acceptance

d)

Risk-avoidance

43.

A member of the accounting team was out of the office for two weeks,

and an important financial transfer was delayed until they returned.

Which of the following would have prevented this delay?

a)

Split knowledge

b)

Least privilege

c)

Job rotation

d)

Dual control

44.

Which of these protocols use TLS to provide secure communication?

a)

HTTPS

b)

SSH

c)

FTPS

d)

SNMPv2

e)

SRTP

45.

Which of these threat actors would be MOST likely to attack systems for direct financial gain?

a)

Organized crime

b)

Hacktivist

c)

Nation state

d)

Compeititor

46.

UTC 04/05/2018 03:09:15809 AV Gateway Alert

136.127.92.171 80 -> 10.16.10.14 60818

Gateway Anti-Virus Alert: XPACK.A_7854 (Trojan) blocked.


Which of the following can be observed from this log information?

a)

The victim's IP address is 136.127.92.171

b)

A download was blocked from a web server

c)

A botnet DDoS attack was blocked

d)

The Trojan was blocked, but the file was not

47.

Which of the following would be the BEST way to provide a website login using existing credentials from a third-party site?

a)

Federation

b)

802.1X

c)

PEAP

d)

EAP-FAST

48.

The embedded OS in a company’s time clock appliance is configured to reset the file system and reboot when a file system error occurs. On one of the time clocks, this file system error occurs during the startup process and causes the system to constantly reboot. Which of the following BEST describes this issue?

a)

DLL injection

b)

Resource exhaustion

c)

race condition

d)

Weak configuration

49.

Which of the following was initially designed as a stream cipher?

a)

AES

b)

Blowfish

c)

RC4

d)

Twofish

50.

Which of the following is a certificate backed by a stricter identity validation process than the CA’s default?

a)

Domain validation

b)

Email

c)

Extended Validation

d)

Machine authentication

51.

If Alice wishes to digitally sign the message that she is sending to Bob, what key would she use to create the digital signature?

a)

Alice's private key

b)

Alice's public key

c)

Bob's private key

d)

Bob's public key

52.

In which of the following, the server periodically verifies its own certificate status and receives a time-stamped response signed by the CA?

a)

Escrow

b)

Key pinning

c)

Transposition

d)

Stapling