wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Comp_Sec_241-270

Total questions: 30

Worksheet time: 3hrs 30mins

Name
Class
Date
1.

NO.241 Several employees have noticed other bystanders can clearly observe a terminal where

passcodes are being entered. Which of the following can be eliminated with the use of a privacy

screen?

a)

Shoulder surfing

b)

Spear phishing

c)

Impersonation attack

d)

Card cloning

2.

NO.242 A security analyst needs to complete an assessment.

The analyst is logged into a server and

must use native tools to map services running on it to the server's listening ports.

Which of the

following tools can BEST accomplish this talk?

a)

Netcat

b)

Netstat

c)

Nmap

d)

Nessus

3.

NO.243 A workwide manufacturing company has been experiencing email account compromised.

In one incident, a user logged in from the corporate office in France, but then seconds later, the same user account attempted a login from Brazil.

Which of the following account policies would BEST prevent this type of attack?

a)

Network location

b)

Impossible travel time

c)

Geolocation

d)

Geofencing

4.

NO.244 A user recently attended an exposition and received some digital promotional materials.

The user later noticed blue boxes popping up and disappearing on the computer,

and reported receiving several spam emails, which the user did not open.

Which of the following is MOST likely the cause of the reported issue?

a)

There was a drive-by download of malware

b)

The user installed a cryptominer

c)

The OS was corrupted

d)

There was malicious code on the USB drive

5.

NO.245 An organization is concerned about intellectual property theft by

employee who leave the organization.

Which of the following will be organization MOST likely implement?

a)

CBT

b)

NDA

c)

MOU

d)

AUP

6.

NO.246 An end user reports a computer has been acting slower than normal for a few weeks. During an investigation, an analyst determines the system is sending the user's email address and a ten-digit number to an IP address once a day.

The only recent log entry regarding the user's computer is the following:

Which of the following is the MOST likely cause of the issue?

a)

The end user purchased and installed a PUP from a web browser

b)

A bot on the computer is brute forcing passwords against a website

c)

A hacker is attempting to exfiltrate sensitive data

d)

Ransomware is communicating with a command-and-control server

7.

NO.247 An organization would like to remediate the risk associated with its cloud service provider not meeting its advertised 99.999% availability metrics.

Which of the following should the

organization consult for the exact requirements for the cloud provider?

a)

SLA

b)

BPA

c)

NDA

d)

MOU

8.

No. 248 Which of the following will provide the BEST physical security countermeasures to stop intruders? (Choose two)

a)

Alarms

&

Signage

b)

Lighting

c)

Sensors

d)

Mantraps

e)

Fencing

9.

NO.249 An incident response technician collected a mobile device during an investigation.

Which of the following should the technician do to maintain chain of custody?

a)

Document the collection and require a sign-off when possession changes.

b)

Lock the device in a safe or other secure location to prevent theft or alteration.

c)

Place the device in a Faraday cage to prevent corruption of the data.

d)

Record the collection in a blockchain-protected public ledger.

10.

NO.250 Administrators have allowed employee to access their company email from personal

computers.

However, the administrators are concerned that these computes are another attach

surface and can result in user accounts being breached by foreign actors.

Which of the following actions would provide the MOST secure solution?

a)

Enable an option in the administration center so accounts can be locked if they are accessed from

different geographical areas

b)

Implement a 16-character minimum length and 30-day expiration password policy

c)

Set up a global mail rule to disallow the forwarding of any company email to email addresses

outside the organization

d)

Enforce a policy that allows employees to be able to access their email only while they are

connected to the internet via VPN

11.

NO.251 A security analyst is performing a forensic investigation compromised account credentials.

Using the Event Viewer, the analyst able to detect the following message, ''Special privileges assigned to new login.''

Several of these messages did not have a valid logon associated with the user before these privileges were assigned.

Which of the following attacks is MOST likely being detected?

a)

Pass-the-hash

b)

Buffer overflow

c)

Cross-site scripting

d)

Session replay

12.

No.252 Which of the following environments would MOST likely be used to assess the execution of component parts of a system at both the hardware and software levels and to measure performance of characteristics?

a)

Test

b)

Staging

c)

Development

d)

Production

13.

NO.253 A security administrator suspects there may be unnecessary services running on a server.

Which of the following tools will the administrator MOST likely use to confirm the suspicions?

a)

Nmap

b)

Wireshark

c)

Autopsy

d)

DNSEnum

14.

NO.254 A technician needs to prevent data loss in a laboratory. The laboratory is not connected to any external networks.

Which of the following methods would BEST prevent data? (Select TWO)

a)

VPN

b)

Drive encryption

c)

Network firewall

d)

MFA

&

File-level encryption

e)

USB blocker

15.

NO.255 The security team received a report of copyright infringement from the IP space of lire

corporate network. The report provided a precise time stamp for the incident as well as the name of

the copyrighted le. The analyst has been tasked with determining the infringing source machine and

instructed to implement measures to prevent such incidents from occurring again.

Which of the following is MOST capable of accomplishing both tasks?

a)

HIDS

b)

Allow list

c)

TPM

d)

NGFW

16.

NO.256 An organization's corporate offices were destroyed due to a natural disaster, so the organization is now setting up offices in a temporary work space.

Which of the following will the organization MOST likely consult?

a)

The business continuity plan

b)

The disaster recovery plan

c)

The communications plan

d)

The incident response plan

17.

No. 257 Which of the following describes the ability of code to target a hypervisor from inside a guest OS?

a)

Fog computing

b)

VM escape

c)

Software-defined networking

d)

Image forgery

e)

Container breakout

18.

NO.258 An information security policy states that separation of duties is required for all highly sensitive database changes that involve customers' financial data. Which of the following will this be BEST to prevent?

a)

Least privilege

b)

An insider threat

c)

A data breach

d)

A change control violation

19.

NO.259 A user recent an SMS on a mobile phone that asked for bank delays.

Which of the following social-engineering techniques was used in this case?

a)

SPIM

b)

Vishing

c)

Spear phishing

d)

Smishing

20.

NO. 260 A company wants to deploy PKI on its Internet-facing website.

The applications that are currently deployed are:

www.company.com (main website)

contactus.company.com (for locating a nearby location)

quotes.company.com (for requesting a price quote)

The company wants to purchase one SSL certificate that will work for all the existing applications and any future applications that follow the same naming conventions, such as store.company.com.

Which of the following certificate types would BEST meet the requirements?

a)

SAN

b)

Wildcard

c)

Extended validation

d)

Self-signed

21.

NO.261 An attack relies on an end user visiting a website the end user would typically visit, however, the site is compromised and uses vulnerabilities in the end users browser to deploy malicious software.

Which of the blowing types of attack does this describe?

a)

Smishing

b)

Whaling

c)

Watering hole

d)

Phishing

22.

NO.262 Which of the following will MOST likely adversely impact the operations of unpatched traditional programmable-logic controllers, running a back-end LAMP server and OT systems with human-management interfaces that are accessible over the Internet via a web interface?

a)

SQL injection &

Cross-site scripting

b)

Data exfiltration

c)

Poor system logging

d)

Weak encryption

e)

Server-side request forgery

23.

NO.263 A systems analyst is responsible for generating a new digital forensics chain-of-custody form.

Which of the following should the analyst include in this documentation? (Select TWO).

a)

The order of volatility

b)

A checksum

&

A warning banner

c)

The location of the artifacts

d)

The vendor's name

e)

The date and time

24.

NO.264 The Chief Financial Officer (CFO) of an insurance company received an email from Ann, the company's Chief Executive Officer (CEO), requesting a transfer of $10,000 to an account. The email states Ann is on vacation and has lost her purse, containing cash and credit cards.

Which of the

following social-engineering techniques is the attacker using?

a)

Phishing

b)

Whaling

c)

Typo squatting

d)

Pharming

25.

NO.265 A software developer needs to perform code-execution testing, black-box testing, and non-functional testing on a new product before its general release.

Which of the following BEST describes the tasks the developer is conducting?

a)

Verification

b)

Validation

c)

Normalization

d)

Staging

26.

A security analyst sees the following log output while reviewing web logs:

Which of the following mitigation strategies would be BEST to prevent this attack from being successful?

a)

Secure cookies

b)

Input validation

c)

Code signing

d)

Stored procedures

27.

NO.267 On which of the following is the live acquisition of data

for forensic analysis MOST dependent?

a)

Data accessibility

&

Value and volatility of data

b)

Legal hold

c)

Cryptographic or hash algorithm

d)

Data retention legislation

e)

Right-to-audit clauses

28.

NO.268 The human resources department of a large online retailer has received multiple customer

complaints about the rudeness of the automated chatbots. It uses to interface and assist online

shoppers.

The system, which continuously learns and adapts, was working fine when it was installed

a few months ago.

Which of the following BEST describes the method being used to exploit the

system?

a)

Baseline modification

b)

A fileless virus

c)

Tainted training data

d)

Cryptographic manipulation

29.

NO.269 A company is upgrading its wireless infrastructure to WPA2-Enterprise using EAP-TLS. Which

of the following must be part of the security architecture to achieve AAA?

a)

DNSSEC

b)

Reverse proxy

c)

VPN concentrator

d)

PKI

e)

Active Directory

& RADIUS

30.

NO.270 An organization has various applications that contain sensitive data hosted in the cloud.

The company's leaders are concerned about lateral movement across applications of different trust

levels.

Which of the following solutions should the organization implement to address the concern?

a)

ISFW

b)

UTM

c)

SWG

d)

CASB

( cloud

access security broker)