Font size
WorksheetsCompTIA Security + : Architecture and Design
Total questions: 64
Worksheet time: 34mins
An organization prepares to deploy specialized medical systems that will remotely collect and monitor health information from each patient's home. The remote systems have limited hardware capabilities, and patients should not be required to purchase additional equipment or perform complex configurations. What should the organization do to ensure that PHI is protected?
Configure a VPN concentrator with remote device accounts
Deploy a NAT gateway and configure restrictive ACLs
Configure tunnel mode IP sec on organization routers
Deploy X.509 certificates on organization web servers
A security administrator is looking for a way to know when people approach any of several secure areas. The method must be active 24-hours a day. They want to keep recurring expenses related to the solution to a minimum.
What should the administrator use?
Proximity readers
A guard dog in each area
Video surveillance
A posted human guard in each are
An administrator sets up a VM for testing different versions of an application. The administrator wants to be able to return to the baseline state as quickly as possible between each test.
What should the administrator do?
Create a snapshot of the VM
Implement automatic change management
Configure a sandbox environment
Run a full backup of the host
An organization prepares to deploy specialized medical systems that will remotely collect and monitor health information from each patient's home. The remote systems have limited hardware capabilities, and patients should not be required to purchase additional equipment or perform complex configurations. What should the organization do to ensure that PHI is protected?
Deploy X.509 certificates on organization web servers.
Deploy a NAT gateway and configure restrictive ACLs.
Configure tunnel mode IPsec on organization routers
Configure a VPN concentrator with remote device accounts.
A security administrator is looking for a way to know when people approach any of several secure areas. The method must be active 24-hours a day. They want to keep recurring expenses related to the solution to a minimum.
What should the administrator use?
A guard dog in each area
A posted human guard in each area
Video surveillance
Proximity readers
An administrator sets up a VM for testing different versions of an application. The administrator wants to be able to return to the baseline state as quickly as possible between each test.
What should the administrator do?
Implement automatic change management
Create a snapshot of the VM
Run a full backup of the host
Configure a sandbox environment
Which server acts as a mirror of the real environment and is used by developers to test and finalize new software prior to rollout?
Staging
Proxy
Production
Development
What are two advantages of implementing a vendor diversity policy? (Choose two.)
Simplified administration requirements
Improved network troubleshooting
Access to the most recent technologies
Reduced equipment costs
Layered defense strategies
A server application produces plain text output. The output needs to be encrypted before being delivered to local and remote client computers. Output varies in length depending on the client request.
The processing requirements and the volume of data sent should be kept to a minimum.
What type of cipher should be used?
Stream cipher
Block cipher
Transport encryption
Hash encryption
An organization deploys web services on a custom, hardened OS. The organization plans to move most of its operations to the cloud. Which of the following models should the organization select?
IaaS
SaaS
PaaS
IDaaS
To reduce management complexity and increase operational security, an organization plans to deploy AAA services. Which of the following platforms or technologies will help the organization meet this goal?
SDN
RADIUS
NIPS
SIEM
An organization plans to contract with a provider for a disaster recovery site that will host server hardware. When the primary data centers fail, data will be restored, and the secondary site will be activated. Costs must be minimized. Which type of disaster recovery site sh0ould the organization deploy?
Hot site
Warm site
Cold site
Mobile site
Which of the following is also known as a Type 1 hypervisor?
Virtual machine
Bare metal
Hosted
Docker container
An organization recently deployed a biometric authentication system. Which of the following should the organization use as its primary tuning metric?
False rejection rate
Crossover error rate
False acceptance rate
True positive rate
Which of the following can be used to prevent external electrical fields from affecting sensitive equipment?
Halon
Hot and cold aisles
Faraday cage
UPS
A company has an office on the fifth floor of a building in a city that is prone to earthquakes. Earthquakes have been identified as the most important risk to mitigate.
Which risk mitigation controls would be most important when ensuring employee safety? (Choose three.)
Access controls
CCTV
Emergency lighting
Escape plans
Drills
Which key is used to encrypt data in an asymmetric encryption system?
The sender's private key
The recipient's public key
The sender's public key
The recipient's private key
Which type of system is MOST susceptible to costly and possibly catastrophic failures caused by operator errors?
FPGA
SCADA
RTOS
SoC
Which process ensures that code vulnerabilities can be patched and updated code placed into production as quickly as possible?
CVCS
Obfuscation
CI/CD
Normalization
A company is designing its disaster recovery plan. The company wants potential down time after a disaster kept to a minimum. Data loss and reposting requirements should also be kept to a minimum. The ability to physically secure the site and prevent any outside entry is a primary concern.
What is the BEST disaster recovery site option?
Cold site
Colocation site
Hot site
Warm site
An organization determines that their working production control is susceptible to attack. What should the organization implement to mitigate the risk of compromised code integrity?
Version control
Elasticity
Normalization
Obfuscation
A company uses an internet of things (IoT) processing solution that uses a distributed architecture with a large number of distributed nodes to support smart buildings. Short-term analytic processing occurs at the local area network (LAN) level, providing quick results and low latency data transfers to gateway devices. Processing can occur when no internet bandwidth is immediately available.
Which computer model does this describe?
Anything as a service (XaaS)
Thin client
Fog computing
Transit gateway
Which of the following statements describes a benefit of implementing stored procedures for a web app?
Protection against data exfiltration
Normalization of data input
Mitigation of injection attacks
Protection against CSRF
A server application is currently under development. It has been discovered that some errors, such as a divide by zero error, can leave the application running in an unstable condition. The application needs to respond more appropriately to errors and generate an error message when they occur.
What should the developers implement? (Choose the BEST answer.)
Input validation
Patch management
Exception handling
Application hardening
A company needs to ensure that, if anyone enters the server room after hours, the doors are locked and cannot be opened from the inside. The company wants to minimize the recurring costs related to the solution.
What should the company install?
Mantrap
Motion detector
Video surveillance
Security guard
Which is NOT a vulnerability associated with embedded systems?
The operating system versions used are unstable and difficult to manage
Embedded systems use older operating systems versions
Embedded systems are susceptible to replicated attacks across multiple devices
Software patches are rarely available and even more rarely applied
A network administrator backs up the server by using an incremental backup strategy. He uses seven tapes, one tape per day, and he performs the backup at the end of each business day. He does a full backup on Friday and Tuesday and an incremental on the other days (Sunday, Monday, Wednesday, Thursday and Saturday).
The server crashes on Sunday morning before the opening of business.
How many tapes will he use to perform the restore on Sunday?
3
4
1
2
A company is designing and developing an automated authentication system based on biometric attributes. One of the goals is to keep the authentication process as transparent and unobtrusive to employees as possible. The company installed CCTV cameras throughout its corporate campus. Images are fed through an artificial intelligence (AI) analysis system for employee identification. Human operators provide feedback to assist with machine learning and improve accuracy.
Which biometric attributes are BEST suited to this application? (Select two.)
Vein
Fingerprint
Gait
Facial
Retina
A security administrator discovers that company confidential information is being encoded into graphics files and sent to a destination outside of the company.
This is an example of which kind of cryptography?
Ephemeral key
Steganography
Hashing
Digital signature
Which are valid examples of multifactor MFA requirements? (Choose two.)
Access token and smart card
Password and PIN
Retina scan and password
Smart card and PIN
Retina scan and voice analysis
A company needs to set up two-factor authentication for a cloud-based application. The authentication should include a one-time use, limited time password that is delivered to the user through the Google Authenticator mobile app. The password should be based on a shared key and the current date and time. What type of authentication should the company use?
PIV
TOTP
CAC
HOTP
An organization has migrated its primary application from a monolithic stack to a microservices architecture. Which of the following is the primary benefit of this migration?
Deployment and operational complexities are reduced.
The application can scale to meet increased demand.
Security controls can focus on a single platform.
Coordination between components is easily managed
What is an advantage of implementing a policy of control diversity in a network?
An attack is less likely to impact multiple devices
Network administrative overhead and training requirements are reduced
Greater fault tolerance in case of device failure
The potential avenues of attack are significantly reduced
A company is concerned about users sending sensitive information to recipients outside of the network. This is a concern due to potential insider threats and the need to meet stringent privacy requirements. What should the company implement to help prevent this?
DLP
SSL/TLS
DNS sinkhole
Hashing
Which statement describes a primary benefit provided by MFA?
Mitigation of phishing attacks
Protection of data in motion
Federated authentication
Required use of biometrics
Which of the following physical controls is the best option for mitigating tailgating attacks?
Air gaps
Mantrap
TEMPEST
Badges
The administrator deploys three web servers, all hosting the same web application and data, on his company's perimeter network. The administrator implements load balancing through the use of a load balancer.
This is BEST described as an example of which resiliency strategy?
Scalability
High availability
Distributive computer
Elasticity
A company is deploying IoT devices on its production network. What are two vulnerabilities that can place the network at greater risk?
Devices cannot be patched or updated
Devices use hard-coded or well-known default passwords
Devices do not have the computing resources to implement advanced security
Devices cannot be detected or monitored by network access controls or intrusion detection devices
Devices introduce non-standard network protocols that interfere with secure protocols
What is the role of OWASP in software development?
OWASP provides free materials to promote and support web application security
OWASP develops structured guidelines for application development methodologies
OWASP offers a publicly available version control system nd code repository
OWASP provides testing services to help identify zero-day and other vulnerabilities
To protect sensitive PHI, an organization plans to substitute random characters for original data, while maintaining the data's format. Which of the following technologies or methods should they use?
Encryption
Tokenization
Masking
Hashing
An organization plans to deploy remote IoT devices that will monitor environmental conditions. Due to processing constraints, the devices do not support PKI, but the organization is concerned that stored secrets might be easily compromised if a device is stolen. Which of the following can be used to mitigate this risk?
VPN
TPM
IPsec
802.1x
A company's internal network has experienced several attempted attacks from the Internet. The Administrator needs to collect as much information about the attackers and their attack methods as possible. The administrator should minimize risk to the internal network.
What should the administrator use?
Honeynet
Extranet
VLAN
DMZ
Which of the following are block cipher modes? (Choose three)
ECB
CBC
SSL
CRC
GCM
A company recently started using an agile development methodology and is making extensive use of automation in testing and in managing the development and deployment process.
The company uses a software engineering practice where development is completed in incremental chunks and held in a staging environment until manually released.
What is this an example of?
Continuous deployment
Continuous validation
Continuous integration
Continuous delivery
A company wants to create a secure tunnel between two sites. Which set of protocols will offer the highest level of security and efficiency? Choose the BEST answer.
DH-1024, AES, and SHA-512
ECDH-384, 3DES, and SHA-1
ECDH-384, AES, and MD5
ECDH-384, AES, and SHA-512
A company has a databases that is used to store product inventory. The cost to the company is very high if the database is not available.
Which two technology controls could be used to improve the database's availability? (Choose two.)
Traffic shaping
Hashing
RAID
Clustering
The company must ensure business continuity through use of an alternate processing location that supports its standard business processes in case of failure at the main site.
Hot site
Cold site
Offsite backup
Warm site
The company must have an alternate location available with the facilities infrastructure to support business operations. Costs must be kept to a minimum.
Hot site
Cold Site
Offsite Backup
Warm site
The company must be able to return to full operations as quickly as possible after a catastrophic failure. The site will maintain copies of all current backups.
Hot site
Cold site
Offsite backup
Warm site
A user arrives at a datacenter and is challenged by three authentication methods as shown in the exhibit. What is the BEST description of the multifactor authentication policy that is in use?
The authentication depends on something he has, something he does, and somewhere he is.
The authentication depends on something he knows, something he is, and somewhere he is.
The authentication depends on something he has, something he is, and somewhere he is.
The authentication depends on something he knows, something he does, and somewhere he is.
Which of the following best describes a digital signature?
A message hash encrypted with the sender's private key
A message hash encrypted with the recipient's public key
A message hash encrypted with the sender's public key
A message hash encrypted with the recipient's private key
Your organization has developed a fault-tolerant design to help ensure business continuity in case of a disaster. The disaster recovery site has mission-critical hardware already installed and connectivity already established. Data backups of critical data are on hand, but they may be up to a week old.
This is an example of which of the following?
Warm site
Off site storage site
Hot site
Cold site
This model supplies an appropriate environment for developing, testing, and deploying applications. The provider is responsible for the operating system, development environment, and other resources.
DaaS
IaaS
PaaS
SaaS
This model gives the user the most direct control over the environment. The subscriber is responsible for maintaining the operating system and other resources.
DaaS
IaaS
PaaS
SaaS
This model offers access to applications on a subscription or pay-as-you-go basis. The provider is responsible for upgrades and all management requirements except user preference settings.
DaaS
IaaS
PaaS
SaaS
What should be used to ensure non-repudiation on outgoing emails?
Digital signature
Cryptographic hash
Ephemeral key
Steganography
An organization deploys a MODBUS based SCADA system to manage production machinery. Which of the following methods should be the organization's first choice for securing the new system?
FDE
NGFW
HIDS
EDR
A subscription to a productivity application allows users in a company to create and share documents. The service is not hosted on a dedicated server.
What two things is this an example of? (Choose two)
Public Cloud
SaaS
Private Cloud
PaaS
IaaS
A security administrator is designing physical security for network servers. The design requirements call for the servers to be kept in a locked room with limited physical access. The administrator wants to ensure that physical access is controlled as tightly as possible and prevent unauthorized access.
What should the security analyst do?
Secure the room with a keyed lock
Secure the room with a biometric-based lock
Secure the room with a combination lock
Secure the room with magnetic key lock requiring a user ID card
A security administrator is looking for a method to manage access to a secure area. They want to allow entry through a locked gate that unlocks automatically and track individuals going into and out of the area. Which method should the administrator use?
Motion Detector
Video Surveillance
Proximity Reader
Access List
A system has six 100 GB hard disks available for data storage. Which RAID configuration will provide the most available storage with fault tolerance?
RAID-1
RAID-10
RAID-5
RAID-0
Which cloud service model provides servers, storage, and network infrastructure, but not operating systems or applications
PaaS
IaaS
SaaS
CaaS
A company deploys a highly advanced HVAC system in a datacenter. Which two security measures should a security specialist recommend for that system? (Choose two.)
Install cameras and alarms
Install a DLP system
Integrate with internal network
Isolate HVAC management devices
Move all systems to the cloud
A security consultant is brought in to test recent changes made to a company's network by its in-house security personnel. The consultant discovered a file named passwd.csv that was located at the disk root on a web server deployed in the company's perimeter network. The web server runs Linux.
What is the MOST likely reason for this file?
The file was placed there as a honeyfile by in-house security
The file is an optional Linux configuration file
The file was left there by an external attacker to help configure persistence
The file is evidence that the web server is a staging point for an active data exfiltration effort
