Font size
WorksheetsCousera Final Exam 201-300
Total questions: 100
Worksheet time: 56mins
201. Which shortcut will switch between running applications?
* WinS
Ctrl-S
• Win-Tab
• Alt-Tab
202. Where does Windows 10 store 32-bit applications?
• \Program Files (x86)
• \System32
• \Program Files
\System
203. What is the shortcut to open the Task Manager
Ctrl+Alt+Del
Ctrl+Shift+Esc
• Ctrl+T
• Ctrl+Shift+
204. Which three (3) statements about Linux are True?
Linux is licensed under the General Public License (GNU).
Linux is an opensource operating system.
Linux was developed and is now owned by Red Hat.
Linux guarantees end users freedom to run, study, share, and modify the software.
205. Executable files such as ping, grep and cp are stored in which directory?
• /root
• /etc
• /sbin
• /bin
206. The Linux “kill” command does which of the following?
Permanently delete a file.
Permanently delete a system directory
Stop an executing process.
Performs an emergency system down.
207. What permissions can be set on a file in Linux?
read, write, execute
read, edit, run
view, modify, remove
read, edit, delete
08. Which basic Linux command deletes an empty directory?
Less
Rm
mv
rmdir
209. Which is not a group that can own a file?
· everybody
• group
• user
• anybody
210. Which three (3) groups can “own” a file in Linux?
user, group, everybody
user, team, world
self, other, all
system, user, group
211. What can be known about a file with permissions set to “-rwxr-x-r–”?
• The file is a directory and the rwx indicators apply to all files within that directory.
The user can read, write and execute the file; the group cannot modify the file, and others not in the group an read it only. You cannot tell the file/directory type from this string.
The file is not a directory; the user can read, write and execute the file; the group cannot modify the file, and others not in the group an read it only.
.
• The file is a directory, the user can read, write and execute the file; others can read and execute the file, and the group can execute it only.
212. A person using Linux would normally interact directly with which?
• The API.
• The shell.
• The HCL.
• The kerne
213. In the Linux file system, what is the highest level in the directory structure?
• bin
• root
• kernel
• home
214. In Linux, a directory is a special type of ____.
file
text
htm
document
215. What does the nano command do?
nano displays the first 10 lines of any text file.
nano deletes all empty files and directories.
nano is a file compression utility.
nano is a basic text file editor
216. Application configuration files are usually stored in which directory?
• /sbin
• /root
• /etc
• /bin
217. When configuring a new application, in which directory should you have it save log files?
• /bin
• /var
• /log
• In the same directory where the application is located
218. The Linux “cat” command does which of the following?
Creates a catalog of all files in the file system.
Puts the file system catalog into edit mode for rapid deletion or insertion of files and directories.
Concatenates 2 or more files together.
Copies file properties.
219. What application can you use to see all the active running applications and processes on mac OS?
• Activity Monitor
• Console
• Disk Utility
• System information
220. What feature in macOS prevents unauthorized applications from being installed?
Apple Watch
• Gatekeeper
• FileVault
• Firewall
221. Which three (3) utilities are found when booting macOS to the recovery partition? (Select 3)
Safari
• Disk Utility
• Keychain Access
• Time Machine
222. Where does the hypervisor sit in a virtual architecture?
Between the hardware and the operating system(s).
Between the operating system and the applications.
Between the applications and the user.
Remotely to coordinate tasks between different physical computers.
223. Which are the first two steps to perform in a cloud deployment?
• Automate and Manage
• Integrate and Optimize
• Consolidate and Virtualize
224. Which are the three (3) most common forms of Cloud computing?
Public Cloud
• Universal Cloud
• Private Cloud
• Hybrid Cloud
225. Which type of cloud is the best choice for a start-up company with no existing IT infrastructure and limited funds?
• Public Cloud
• Private Cloud
• Hybrid Cloud
• All of the above.
226. Which three (3) are the primary benefits of cloud computing?
Efficiency
• Flexibility
• Strategic Value
• Security
227. Which is a primary security consideration in a cloud environment?
Disaster Recovery and Business Continuity Plan
Governance Plan
Compliance
All of the above.
228. Virtualization allows you to create multiple simulated environments or dedicated resources from how many physical hardware systems?
1
2
3
Unlimited
229. What relays requests from the VM to the actual hardware?
• Hypervisor
HyperX
SpaceX
VisorHyper
230. Which two steps of a cloud deployment are performed after you move your applications to the cloud?
• Consolidate and Virtualize
• Integrate and Optimize
• Automate and Manage
231. Which type of cloud is the best choice for a company with a robust existing IT infrastructure and very serious data privacy concerns?
• Public Cloud
• Private Cloud
• Hybrid Cloud
• All of the above.
232. Which is a primary security consideration in a cloud environment?
Availability
• Data Security
• Identity and Access Management
• All of the above.
233. Which of the bad guys are described as "They are "in" an organization but are human and make mistakes"?
Inadvertent Actor
• Malicious Insiders
• Outsiders
• Employees
234. Which is NOT one of the security controls?
• Operational
• Technical
• Testing
• Physical
235. What year did the GDPR come into effect?
2018
• 2017
• 2016
2014
236. Which three (3) of these obligations are part of the 5 key GDPR obligations? Check all that apply
Security of Public Data
Accountability of Compliance
Consent
• Rights of EU Data Subject
237. Which is the foundational principle that everyone will get during a SOC audit?
Security
Confidentiality
• Availability
• Privacy
238. The HIPAA security rule requires covered entites to maintain which two (2) reasonable safeguards for protecting e-PHI?
• Informational
• Operational
• Technical
• Physical
239. HIPAA Administrative safeguards include which two (2) of the following?
• Workforce Training and Management
Integrity Controls
• Access Controls
• Security Personnel
240. PCI includes 264 requirements grouped under how many main requirements?
5
10
12
20
241. If you are a mature organization which IS Controls Implementation Group would you use?
Do not need a controls implementation group due to maturity of my organization
Implementation Group 3
Implementation Group 1
Implementation Group 2
242. A security attack is defined as which of the following?
An event that has been identified by correlation and analytics tools as a malicious activity.
Establish scope, readiness assessment, gap remediation, testing/auditing, management reporting
243. Which order does a typical compliance process follow?
Establish scope, readiness assessment, gap remediation, testing/auditing, management reporting
An event that has been identified by correlation and analytics tools as a malicious activity.
244. Under GDPR who determines the purpose and means of processing of personal data?
Controller
Switch
Router
SLACC
245. Under the International Organization for Standardization (ISO) which standard focuses on Privacy?
• ISO 27018
CR 777
MCM 2001
osi 2875
246. Which SOC report is closest to an ISO report?
type1
type 2
type 3
type 4
247. What is an auditor looking for when they test control the control for implementation over an entire offering with no gaps?
• Completeness
Accomplishment
Award
Complete
278. The HIPAA Security Rule requires covered entities to maintain which three (3) reasonable safeguards for protecting e-PHI?
• physical
• technical
• administrative
virtual
249. HIPAA Administrative safeguards include which two (2) of the following?
• Workforce training and management
• Security Personnel
Physical trainning
250. Who is the governing entity for HIPAA?
US Department of Health and Human Services Office of Civil Rights
Fantazya Biiti Anas
251. HIPAA Physical safeguards include which two (2) of the following?
Workstation and Device Security
Facility Access and Control
Access Point
252. PCI uses which three (3) of the following Card Holder Data Environment categories to determine scope?
Technology
• Processes
• People
Other
253. One PCI Requirement is using an approved scanning vendor to scan at what frequency?
• Quarterly
Diidicult
All the above
pepsi
254. In which CIS control category will you find Incident Response and Management?
Organizational
Special
Full
All the above
255. Which is NOT an example of a client?
• Cellphone
• Laptop
• Personal Computer
• e-mail Serve
256. Which three (3) threat key factors should be considered when looking at an Endpoint Security Solution?
• basic operations
• threat hunting
• user education
• detection response
257. A patch is a set of changes to a computer program or its data designed for which three (3) functions?
delete
• update
• improve
• fix
258. Which two types of updates do most organizations patch as soon as possible after testing?
Critical and Software
Security and Service Packs
Security and Critical
Critical and Service Packs
259. Which three (3) are common Endpoint attack types?
Whale hunting
• Ad Network
• SQL Injection
• Spear Phishing
260. Endpoint detection and response includes which three (3) of these key technologies?
Automatic policy creation for endpoints.
Continuous monitoring.
One-Time patching process.
Zero-day OS updates.
261. Which common endpoint attack is targeted at supply chain infiltration?
Island Hopping
Water Hole
Ransomware
Spear Phishing
262. What two windows security updates do most organizations always patch?
critical and important
important and moderate
high and important
critical and high
263. How frequent will most organizations distribute patches?
• Monthly
• Weekly
• Annually
•
As soon as patches are released
264. Which three (3) objects are typically managed by active directory?
• Network User
• Volumes
• Local Accounts
• Services
265. Which type of group within Active Directory is used to assign permissions to shared resources?
• Security groups
• Data groups
• Service groups
Distribution groups
266. Kerberos Authentication provides several benefits including which three (3) of the following?
• single sign on
• delegated authentication
• interoperability
• distributed authentification
267. Which of the nine different kinds of Windows events that can be audited is used to see when someone has shutdown or restarted the computer or when a program tries to do something it does not have permission to do?
• Policy change
• System events
• Privilege Use
• Process tracking
268. True or False: Internal commands are built into the shell program and are shell dependent?
TRUE
FALSE
269. Which Linux Run Level shuts down all services when the system is being rebooted?
RunLevel 0: Halt
Run Level 1: Single User
Run Level 5: Graphical
Run Level 6: Reboot
270. Which Windows directory folder stores per-user application data and settings?
\AppData
DataBase
271. Which is NOT an example of a default Windows local user account?
Network Service
Network Security
272. Which feature allows Active Directory to be shared by multiple servers?
• A replication services
Sperate administator
Disable
Create dedicated
273. Which three (3) of the following steps can be taken to help protect sensitive Windows domain accounts? (Select 3)
Separate administrator accounts from user accounts.
Disable the account delegation rights for administrator accounts.
• Create dedicated workstation hosts without Internet and email access.
Disappointed
274. What tool can an administrator use to manage servers on private networks that are not connected to the Internet?
Windows Admin Center
Mac os
Linux OS
275. Which of the nine different kind of Windows events that can be audited is used to see each instance of a user logging on to and logging off from another computer?
• Account logon
Login
Password
276. Which of these commands does not shutdown the Linux operating system?
• reboot
• * itit6
shutdown -r
GGG
277. Which Linux commands are totally shell-independent and usually found in any Linux distribution?
External commands
Common Commands
SAT
278. Which three (3) of the following are common choices of Shell?
tcsh
• Bash
• sh
dt
279. Which of the cryptography basics ensures authentication, non-repudiation and integrity?
Digital Signatures
• Public key encryption
• Symmetric key encryption
• Hashing
280. Complete the following statement.
Data can be encrypted_____
at rest only.
in use only.
in transit only.
at rest, in use, and in transit.
281. Which is NOT a pitfall of encryption?
Using hardcoded/predictable weak keys
Implementing a reliable and proven cryptography
Relying on algorithms being secret
Missing encryption of data and communications
282. True or False: Internal commands are built into the shell program and are shell dependent.
True
False
283. True or False: A whole branch of hacking - Reverse Engineering - is devoted to discovering hidden algorithms and data.
True
False
284. Which is not a key takeaway of best practices of cryptography?
Do rely on your own encryption algorithms.
Not correct
Do rely other encrryption
All the above
285. Which three (3) are true of digital signatures?
Ensures authentication, non-reputiation, and integrity
Keys , Maps
Thread, Clean
286. What is the recommendation to avoid the encrypting data at rest pitfall "Using hardcoded/easily guessed keys"?
• Select cryptographically-random keys, do not reuse keys for different installs.
Hashing provides
the destinanion
Maps data
287. Which two (2) statements are true of the Hash function?
Hashing provides integrity.
Maps data of arbitrary size to data of a fixed size.
The soures Ip
Service
288. Which four (4) factors does a stateless firewall look at to determine if a packet should be allowed pass?
the destination port
if the packet belongs to an open session
the source IP address
the service or protocol used
the destination IP address
289. Can a single firewall conduct both a stateless and stateful inspection?
• Yes, but not on the same packet. A decision is made which type of inspection will be most effective on a packet-by-packet bases.
• No, the latency created by a double inspection is too great to be practical.
• Yes, the stateless inspection is conducted first and then a stateful inspection is done.
No, stateless and stateful firewalls are distinctly different and used for different purposes.
290. True or False: An Intrusion Prevention System (IPS) is generally a passive device that listens to network traffic and alerts an administrator when a potential problem is detected?
True
False
291. Network Address Translation (NAT) typically conducts which of the following translations?
An IP address to a physical address and vice versa.
A MAC address to an IP address and vice versa.
An IP address to a domain name and vice versa
A private network IP address to a public network IP address and vice versa.
292. Which type of NAT routing allows one-to-one mapping between local and global addresses?
Static
• Kinetic
• Dynamic
• Overload
293. Which network layer do IP addresses belong to?
The Physical Layer
The Network Layer
The Data Layer
The Application Layer
294. Which address assures a packet is delivered to a computer on a different network segment from the sender?
The MAC Address
The IP Address
The DNS Address
The DHCP Address
295. A network device that is capable of sending and receiving data at the same time is referred to as which of the following?
•
Full duplex
Half uplex
Monoplex
Unidirectional
296. True or False: Collision avoidance protocols are critical to the smooth operation of modern networks.
TRUE
FALSE
297. Comparing bridges with switches, which are three (3) characteristics specific to a bridge?
End-user devices share bandwidth on each port.
Virtual LANs are not possible.
Half-duplex transmission.
Virtual LANs are possible
End-user devices share bandwidth on each port.
298. True or False: Switches solved the problem of network loops and improved performance of multicast/broadcast traffic.
False
True
299. If a network server has four (4) network interface cards, how many MAC addresses will be associated with that server?
4
2
1
3
300. True or False: When you connect your laptop to a new network, a new IP address will be assigned.
True
False
