Font size
Worksheets1-30 Quiz
Total questions: 30
Worksheet time: 3600secs
NO.1 The process of passively gathering information prior to launching a cyberattack is called:
(A). tailgating
(B). reconnaissance
(C). pharming
(D). prepending
NO.2 A Chief Security Office's (CSO's) key priorities are to improve preparation, response, and
recovery practices to minimize system downtime and enhance organizational resilience to
ransomware attacks. Which of the following would BEST meet the CSO's objectives?
(A). Use email-filtering software and centralized account management, patch high-risk systems, and
restrict administration privileges on fileshares.
(B). Purchase cyber insurance from a reputable provider to reduce expenses during an incident.
(C). Invest in end-user awareness training to change the long-term culture and behavior of staff and
executives, reducing the organization's susceptibility to phishing attacks.
(D). Implement application whitelisting and centralized event-log management, and perform regular
testing and validation of full backups.
NO.3 A new plug-and-play storage device was installed on a PC in the corporate environment. Which
of the following safeguards will BEST help to protect the PC from malicious files on the storage
device?
(A). Change the default settings on the PC.
(B). Define the PC firewall rules to limit access.
(C). Encrypt the disk on the storage device.
(D). Plug the storage device in to the UPS
NO.4 An organization is concerned about hackers potentially entering a facility and plugging in a
remotely accessible Kali Linux box. Which of the following should be the first lines of defense against
such an attack? (Select Two)
(A). MAC filtering
(B). Zero Trust segmentation
(C). Network access control
(D) Access control vestibules
(E) Guards
NO.5 The following is an administrative control that would be MOST effective to reduce the
occurrence of malware execution?
(A). Security awareness training
(B). Frequency of NIDS updates
(C). Change control procedures
(D). EDR reporting cycle
NO.6 A security analyst is investigation an incident that was first reported as an issue connecting to
network shares and the internet, While reviewing logs and tool output, the analyst sees the
following:
Which of the following attacks has occurred?
(A). IP conflict
(B). Pass-the-hash
(C). MAC flooding
(D). Directory traversal
(E). ARP poisoning
NO.7 Which of the following technical controls is BEST suited for the detection and prevention of
buffer overflows on hosts?
(A). DLP
(B). HIDS
(C). EDR
(D). NIPS
NO.8 A nuclear plant was the victim of a recent attack, and all the networks were air gapped. A
subsequent investigation revealed a worm as the source of the issue. Which of the following BEST
explains what happened?
(A). A malicious USB was introduced by an unsuspecting employee.
(B). The ICS firmware was outdated
(C). A local machine has a RAT installed.
(D). The HVAC was connected to the maintenance vendor.
NO.9 Which of the following ISO standards is certified for privacy?
(A). ISO 9001
(B). ISO 27002
(C). ISO 27701
(D). ISO 31000
NO.10 An incident, which is affecting dozens of systems, involves malware that reaches out to an
Internet service for rules and updates. The IP addresses for the Internet host appear to be different in
each case. The organization would like to determine a common IoC to support response and recovery
actions. Which of the following sources of information would BEST support this solution?
(A). Web log files
(B). Browser cache
(C). DNS query logs
(D). Antivirus
NO.11 Which of the following incident response steps involves actions to protect critical systems
while maintaining business operations?
(A). Investigation
(B). Containment
(C). Recovery
(D). Lessons learned
NO.12 A Chief Executive Officer (CEO) is dissatisfied with the level of service from the company's
new service provider. The service provider is preventing the CEO from sending email from a work
account to a personal account. Which of the following types of service providers is being used?
(A). Telecommunications service provider
(B). Cloud service provider
(C). Master managed service provider
(D) Managed security service provider
NO.13 A researcher has been analyzing large data sets for the last ten months. The researcher works
with colleagues from other institutions and typically connects via SSH to retrieve additional data.
Historically, this setup has worked without issue, but the researcher recently started getting the
following message:
Which of the following network attacks is the researcher MOST likely experiencing?
(A). MAC cloning
(B). Evil twin
(C). Man-in-the-middle
(D). ARP poisoning
NO.14 A smart retail business has a local store and a newly established and growing online
storefront. A recent storm caused a power outage to the business and the local ISP, resulting in
several hours of lost sales and delayed order processing. The business owner now needs to ensure
two things:
* Protection from power outages
* Always-available connectivity In case of an outage
The owner has decided to implement battery backups for the computer equipment Which of the
following would BEST fulfill the owner's second need?
(A). Lease a point-to-point circuit to provide dedicated access.
(B). Connect the business router to its own dedicated UPS.
(C). Purchase services from a cloud provider for high availability
D Replace the business's wired network with a wireless network.
NO.15 A company Is concerned about is security after a red-team exercise. The report shows the
team was able to reach the critical servers due to the SMB being exposed to the Internet and running
NTLMV1,
Which of the following BEST explains the findings?
(A). Default settings on the servers
(B). Unsecured administrator accounts
(C). Open ports and services
(D). Weak Data encryption
NO.16 A company is setting up a web server on the Internet that will utilize both encrypted and
unencrypted web-browsing protocols. A security engineer runs a port scan against the server from
the Internet and sees the following output:
Which of the following steps would be best for the security engineer to take NEXT?
(A). Allow DNS access from the internet.
(B). Block SMTP access from the Internet
(C). Block HTTPS access from the Internet
(D). Block SSH access from the Internet.
NO.17 An attacked is attempting to exploit users by creating a fake website with the URL
The attacker's intent is to imitate the look and feel of a legitimate website to obtain personal
information from unsuspecting users. Which of the following social-engineering attacks does this
describe?
(A). Information elicitation
(B) Typo squatting
(C). Impersonation
(D). Watering-hole attack
NO.18 A company is implementing MFA for all applications that store sensitive data. The IT manager
wants MFA to be non-disruptive and user friendly. Which of the following technologies should the IT
manager use when implementing MFA?
(A). One-time passwords
(B). Email tokens
(C). Push notifications
(D). Hardware authentication
NO.19 A financial organization has adopted a new secure, encrypted document-sharing application
to help with its customer loan process. Some important PII needs to be shared across this new
platform, but it is getting blocked by the DLP systems. Which of the following actions will BEST allow
the PII to be shared with the secure application without compromising the organization's security
posture?
(A). Configure the DLP policies to allow all PII
(B). Configure the firewall to allow all ports that are used by this application
(C). Configure the antivirus software to allow the application
(D). Configure the DLP policies to whitelist this application with the specific PII
(E). Configure the application to encrypt the PII
NO.20 An organization's Chief Security Officer (CSO) wants to validate the business's involvement in
the incident response plan to ensure its validity and thoroughness. Which of the following will the
CSO MOST likely use?
(A). An external security assessment
(B). A bug bounty program
(C). A tabletop exercise
(D). A red-team engagement
NO.21 A small business just recovered from a ransomware attack against its file servers by
purchasing the decryption keys from the attackers. The issue was triggered by a phishing email and
the IT administrator wants to ensure it does not happen again. Which of the following should the IT
administrator do FIRST after recovery?
(A). Scan the NAS for residual or dormant malware and take new daily backups that are tested on a
frequent basis
(B). Restrict administrative privileges and patch ail systems and applications.
(C). Rebuild all workstations and install new antivirus software
(D). Implement application whitelisting and perform user application hardening
NO.22 Name: Wikipedia.org
Address: 208.80.154.224
Which of the following attacks MOST likely occurred on the user's internal network?
(A). DNS poisoning
(B). URL redirection
(C). ARP poisoning
(D). /etc/hosts poisoning
NO.23 A SOC is implementing an in sider-threat-detection program. The primary concern is that
users may be accessing confidential data without authorization. Which of the following should be
deployed to detect a potential insider threat?
(A). A honeyfile
(B). A DMZ
(C). DLP
(D). File integrity monitoring
NO.24 A SECURITY ANALYST NEEDS TO FIND REAL-TIME DATA ON THE LATEST MALWARE AND loCs
WHICH OF THE FOLLOWING BEST DESCRIBE THE SOLUTION THE ANALYST SHOULD PERSUE?
(A). ADVISORIES AND BULLETINS
(B). THREAT FEEDS
(C). SECURITY NEWS ARTICLES
(D). PEER-REVIEWED CONTENT
NO.26 An attacker is attempting, to harvest user credentials on a client's website. A security analyst
notices multiple attempts of random usernames and passwords. When the analyst types in a random
username and password.
the logon screen displays the following message:
Which of the following should the analyst recommend be enabled?
(A). Input validation
(B). Obfuscation
(C). Error handling
(D). Username lockout
NO.27 Security analysts are conducting an investigation of an attack that occurred inside the
organization's network.
An attacker was able to connect network traffic between workstation throughout the network. The
analysts review the following logs:
The layer 2 address table has hundred of entries similar to the ones above. Which of the following
attacks has MOST likely occurred?
(A). SQL injection
(B). DNS spoofing
(C). MAC flooding
(D). ARP poisoning
NO.28 An organization hired a consultant to assist with an active attack, and the consultant was able
to identify the compromised accounts and computers. Which of the following is the consultant MOST
likely to recommend to prepare for eradication?
(A). Quarantining the compromised accounts and computers, only providing them with network
access
(B). Segmenting the compromised accounts and computers into a honeynet so as to not alert the
attackers.
(C) Isolating the compromised accounts and computers, cutting off all network and internet access.
(D). Logging off and deleting the compromised accounts and computers to eliminate attacker access.
NO.29 Which of the following provides the BEST protection for sensitive information and data stored
in cloud-based services but still allows for full functionality and searchability of data within the cloudbased
services?
(A). Data encryption
(B). Data masking
(C). Anonymization
(D). Tokenization
NO.30 A major political party experienced a server breach. The hacker then publicly posted stolen
internal communications concerning campaign strategies to give the opposition party an advantage.
Which of the following BEST describes these threat actors?
(A). Semi-authorized hackers
(B). State actors
(C). Script kiddies
(D). Advanced persistent threats
NO.25 Leveraging the information supplied below, complete the CSR (Cetificate Signing Request) for the server to set up TLS
(HTTPS)
Hostname : ws01
Domain : comptia.org
IPv4 : 10.1.9.50
IPV4 : 10.2.10.50
Root : home.aspx*
DNS CNAME : homesite.
