wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

CompTIA Security + : Architecture and Design

Total questions: 64

Worksheet time: 34mins

Name
Class
Date
1.

An organization prepares to deploy specialized medical systems that will remotely collect and monitor health information from each patient's home. The remote systems have limited hardware capabilities, and patients should not be required to purchase additional equipment or perform complex configurations. What should the organization do to ensure that PHI is protected?

a)

Configure a VPN concentrator with remote device accounts

b)

Deploy a NAT gateway and configure restrictive ACLs

c)

Configure tunnel mode IP sec on organization routers

d)

Deploy X.509 certificates on organization web servers

2.

A security administrator is looking for a way to know when people approach any of several secure areas. The method must be active 24-hours a day. They want to keep recurring expenses related to the solution to a minimum.

What should the administrator use?

a)

Proximity readers

b)

A guard dog in each area

c)

Video surveillance

d)

A posted human guard in each are

3.

An administrator sets up a VM for testing different versions of an application. The administrator wants to be able to return to the baseline state as quickly as possible between each test.

What should the administrator do?

a)

Create a snapshot of the VM

b)

Implement automatic change management

c)

Configure a sandbox environment

d)

Run a full backup of the host

4.

An organization prepares to deploy specialized medical systems that will remotely collect and monitor health information from each patient's home. The remote systems have limited hardware capabilities, and patients should not be required to purchase additional equipment or perform complex configurations. What should the organization do to ensure that PHI is protected?

a)

Deploy X.509 certificates on organization web servers.

b)

Deploy a NAT gateway and configure restrictive ACLs.

c)

Configure tunnel mode IPsec on organization routers

d)

Configure a VPN concentrator with remote device accounts.

5.

A security administrator is looking for a way to know when people approach any of several secure areas. The method must be active 24-hours a day. They want to keep recurring expenses related to the solution to a minimum.

What should the administrator use?

a)

A guard dog in each area

b)

A posted human guard in each area

c)

Video surveillance

d)

Proximity readers

6.

An administrator sets up a VM for testing different versions of an application. The administrator wants to be able to return to the baseline state as quickly as possible between each test.

What should the administrator do?

a)

Implement automatic change management

b)

Create a snapshot of the VM

c)

Run a full backup of the host

d)

Configure a sandbox environment

7.

Which server acts as a mirror of the real environment and is used by developers to test and finalize new software prior to rollout?

a)

Staging

b)

Proxy

c)

Production

d)

Development

8.

What are two advantages of implementing a vendor diversity policy? (Choose two.)

a)

Simplified administration requirements

b)

Improved network troubleshooting

c)

Access to the most recent technologies

d)

Reduced equipment costs

e)

Layered defense strategies

9.

A server application produces plain text output. The output needs to be encrypted before being delivered to local and remote client computers. Output varies in length depending on the client request.

The processing requirements and the volume of data sent should be kept to a minimum.

What type of cipher should be used?

a)

Stream cipher

b)

Block cipher

c)

Transport encryption

d)

Hash encryption

10.

An organization deploys web services on a custom, hardened OS. The organization plans to move most of its operations to the cloud. Which of the following models should the organization select?

a)

IaaS

b)

SaaS

c)

PaaS

d)

IDaaS

11.

To reduce management complexity and increase operational security, an organization plans to deploy AAA services. Which of the following platforms or technologies will help the organization meet this goal?

a)

SDN

b)

RADIUS

c)

NIPS

d)

SIEM

12.

An organization plans to contract with a provider for a disaster recovery site that will host server hardware. When the primary data centers fail, data will be restored, and the secondary site will be activated. Costs must be minimized. Which type of disaster recovery site sh0ould the organization deploy?

a)

Hot site

b)

Warm site

c)

Cold site

d)

Mobile site

13.

Which of the following is also known as a Type 1 hypervisor?

a)

Virtual machine

b)

Bare metal

c)

Hosted

d)

Docker container

14.

An organization recently deployed a biometric authentication system. Which of the following should the organization use as its primary tuning metric?

a)

False rejection rate

b)

Crossover error rate

c)

False acceptance rate

d)

True positive rate

15.

Which of the following can be used to prevent external electrical fields from affecting sensitive equipment?

a)

Halon

b)

Hot and cold aisles

c)

Faraday cage

d)

UPS

16.

A company has an office on the fifth floor of a building in a city that is prone to earthquakes. Earthquakes have been identified as the most important risk to mitigate.

Which risk mitigation controls would be most important when ensuring employee safety? (Choose three.)

a)

Access controls

b)

CCTV

c)

Emergency lighting

d)

Escape plans

e)

Drills

17.

Which key is used to encrypt data in an asymmetric encryption system?

a)

The sender's private key

b)

The recipient's public key

c)

The sender's public key

d)

The recipient's private key

18.

Which type of system is MOST susceptible to costly and possibly catastrophic failures caused by operator errors?

a)

FPGA

b)

SCADA

c)

RTOS

d)

SoC

19.

Which process ensures that code vulnerabilities can be patched and updated code placed into production as quickly as possible?

a)

CVCS

b)

Obfuscation

c)

CI/CD

d)

Normalization

20.

A company is designing its disaster recovery plan. The company wants potential down time after a disaster kept to a minimum. Data loss and reposting requirements should also be kept to a minimum. The ability to physically secure the site and prevent any outside entry is a primary concern.

What is the BEST disaster recovery site option?

a)

Cold site

b)

Colocation site

c)

Hot site

d)

Warm site

21.

An organization determines that their working production control is susceptible to attack. What should the organization implement to mitigate the risk of compromised code integrity?

a)

Version control

b)

Elasticity

c)

Normalization

d)

Obfuscation

22.

A company uses an internet of things (IoT) processing solution that uses a distributed architecture with a large number of distributed nodes to support smart buildings. Short-term analytic processing occurs at the local area network (LAN) level, providing quick results and low latency data transfers to gateway devices. Processing can occur when no internet bandwidth is immediately available.

Which computer model does this describe?

a)

Anything as a service (XaaS)

b)

Thin client

c)

Fog computing

d)

Transit gateway

23.

Which of the following statements describes a benefit of implementing stored procedures for a web app?

a)

Protection against data exfiltration

b)

Normalization of data input

c)

Mitigation of injection attacks

d)

Protection against CSRF

24.

A server application is currently under development. It has been discovered that some errors, such as a divide by zero error, can leave the application running in an unstable condition. The application needs to respond more appropriately to errors and generate an error message when they occur.

What should the developers implement? (Choose the BEST answer.)

a)

Input validation

b)

Patch management

c)

Exception handling

d)

Application hardening

25.

A company needs to ensure that, if anyone enters the server room after hours, the doors are locked and cannot be opened from the inside. The company wants to minimize the recurring costs related to the solution.

What should the company install?

a)

Mantrap

b)

Motion detector

c)

Video surveillance

d)

Security guard

26.

Which is NOT a vulnerability associated with embedded systems?

a)

The operating system versions used are unstable and difficult to manage

b)

Embedded systems use older operating systems versions

c)

Embedded systems are susceptible to replicated attacks across multiple devices

d)

Software patches are rarely available and even more rarely applied

27.

A network administrator backs up the server by using an incremental backup strategy. He uses seven tapes, one tape per day, and he performs the backup at the end of each business day. He does a full backup on Friday and Tuesday and an incremental on the other days (Sunday, Monday, Wednesday, Thursday and Saturday).

The server crashes on Sunday morning before the opening of business.

How many tapes will he use to perform the restore on Sunday?

a)

3

b)

4

c)

1

d)

2

28.

A company is designing and developing an automated authentication system based on biometric attributes. One of the goals is to keep the authentication process as transparent and unobtrusive to employees as possible. The company installed CCTV cameras throughout its corporate campus. Images are fed through an artificial intelligence (AI) analysis system for employee identification. Human operators provide feedback to assist with machine learning and improve accuracy.

Which biometric attributes are BEST suited to this application? (Select two.)

a)

Vein

b)

Fingerprint

c)

Gait

d)

Facial

e)

Retina

29.

A security administrator discovers that company confidential information is being encoded into graphics files and sent to a destination outside of the company.

This is an example of which kind of cryptography?

a)

Ephemeral key

b)

Steganography

c)

Hashing

d)

Digital signature

30.

Which are valid examples of multifactor MFA requirements? (Choose two.)

a)

Access token and smart card

b)

Password and PIN

c)

Retina scan and password

d)

Smart card and PIN

e)

Retina scan and voice analysis

31.

A company needs to set up two-factor authentication for a cloud-based application. The authentication should include a one-time use, limited time password that is delivered to the user through the Google Authenticator mobile app. The password should be based on a shared key and the current date and time. What type of authentication should the company use?

a)

PIV

b)

TOTP

c)

CAC

d)

HOTP

32.

An organization has migrated its primary application from a monolithic stack to a microservices architecture. Which of the following is the primary benefit of this migration?

a)

Deployment and operational complexities are reduced.

b)

The application can scale to meet increased demand.

c)

Security controls can focus on a single platform.

d)

Coordination between components is easily managed

33.

What is an advantage of implementing a policy of control diversity in a network?

a)

An attack is less likely to impact multiple devices

b)

Network administrative overhead and training requirements are reduced

c)

Greater fault tolerance in case of device failure

d)

The potential avenues of attack are significantly reduced

34.

A company is concerned about users sending sensitive information to recipients outside of the network. This is a concern due to potential insider threats and the need to meet stringent privacy requirements. What should the company implement to help prevent this?

a)

DLP

b)

SSL/TLS

c)

DNS sinkhole

d)

Hashing

35.

Which statement describes a primary benefit provided by MFA?

a)

Mitigation of phishing attacks

b)

Protection of data in motion

c)

Federated authentication

d)

Required use of biometrics

36.

Which of the following physical controls is the best option for mitigating tailgating attacks?

a)

Air gaps

b)

Mantrap

c)

TEMPEST

d)

Badges

37.

The administrator deploys three web servers, all hosting the same web application and data, on his company's perimeter network. The administrator implements load balancing through the use of a load balancer.

This is BEST described as an example of which resiliency strategy?

a)

Scalability

b)

High availability

c)

Distributive computer

d)

Elasticity

38.

A company is deploying IoT devices on its production network. What are two vulnerabilities that can place the network at greater risk?

a)

Devices cannot be patched or updated

b)

Devices use hard-coded or well-known default passwords

c)

Devices do not have the computing resources to implement advanced security

d)

Devices cannot be detected or monitored by network access controls or intrusion detection devices

e)

Devices introduce non-standard network protocols that interfere with secure protocols

39.

What is the role of OWASP in software development?

a)

OWASP provides free materials to promote and support web application security

b)

OWASP develops structured guidelines for application development methodologies

c)

OWASP offers a publicly available version control system nd code repository

d)

OWASP provides testing services to help identify zero-day and other vulnerabilities

40.

To protect sensitive PHI, an organization plans to substitute random characters for original data, while maintaining the data's format. Which of the following technologies or methods should they use?

a)

Encryption

b)

Tokenization

c)

Masking

d)

Hashing

41.

An organization plans to deploy remote IoT devices that will monitor environmental conditions. Due to processing constraints, the devices do not support PKI, but the organization is concerned that stored secrets might be easily compromised if a device is stolen. Which of the following can be used to mitigate this risk?

a)

VPN

b)

TPM

c)

IPsec

d)

802.1x

42.

A company's internal network has experienced several attempted attacks from the Internet. The Administrator needs to collect as much information about the attackers and their attack methods as possible. The administrator should minimize risk to the internal network.

What should the administrator use?

a)

Honeynet

b)

Extranet

c)

VLAN

d)

DMZ

43.

Which of the following are block cipher modes? (Choose three)

a)

ECB

b)

CBC

c)

SSL

d)

CRC

e)

GCM

44.

A company recently started using an agile development methodology and is making extensive use of automation in testing and in managing the development and deployment process.

The company uses a software engineering practice where development is completed in incremental chunks and held in a staging environment until manually released.

What is this an example of?

a)

Continuous deployment

b)

Continuous validation

c)

Continuous integration

d)

Continuous delivery

45.

A company wants to create a secure tunnel between two sites. Which set of protocols will offer the highest level of security and efficiency? Choose the BEST answer.

a)

DH-1024, AES, and SHA-512

b)

ECDH-384, 3DES, and SHA-1

c)

ECDH-384, AES, and MD5

d)

ECDH-384, AES, and SHA-512

46.

A company has a databases that is used to store product inventory. The cost to the company is very high if the database is not available.

Which two technology controls could be used to improve the database's availability? (Choose two.)

a)

Traffic shaping

b)

Hashing

c)

RAID

d)

Clustering

47.

The company must ensure business continuity through use of an alternate processing location that supports its standard business processes in case of failure at the main site.

a)

Hot site

b)

Cold site

c)

Offsite backup

d)

Warm site

48.

The company must have an alternate location available with the facilities infrastructure to support business operations. Costs must be kept to a minimum.

a)

Hot site

b)

Cold Site

c)

Offsite Backup

d)

Warm site

49.

The company must be able to return to full operations as quickly as possible after a catastrophic failure. The site will maintain copies of all current backups.

a)

Hot site

b)

Cold site

c)

Offsite backup

d)

Warm site

50.

A user arrives at a datacenter and is challenged by three authentication methods as shown in the exhibit. What is the BEST description of the multifactor authentication policy that is in use?

a)

The authentication depends on something he has, something he does, and somewhere he is.

b)

The authentication depends on something he knows, something he is, and somewhere he is.

c)

The authentication depends on something he has, something he is, and somewhere he is.

d)

The authentication depends on something he knows, something he does, and somewhere he is.

51.

Which of the following best describes a digital signature?

a)

A message hash encrypted with the sender's private key

b)

A message hash encrypted with the recipient's public key

c)

A message hash encrypted with the sender's public key

d)

A message hash encrypted with the recipient's private key

52.

Your organization has developed a fault-tolerant design to help ensure business continuity in case of a disaster. The disaster recovery site has mission-critical hardware already installed and connectivity already established. Data backups of critical data are on hand, but they may be up to a week old.

This is an example of which of the following?

a)

Warm site

b)

Off site storage site

c)

Hot site

d)

Cold site

53.

This model supplies an appropriate environment for developing, testing, and deploying applications. The provider is responsible for the operating system, development environment, and other resources.

a)

DaaS

b)

IaaS

c)

PaaS

d)

SaaS

54.

This model gives the user the most direct control over the environment. The subscriber is responsible for maintaining the operating system and other resources.

a)

DaaS

b)

IaaS

c)

PaaS

d)

SaaS

55.

This model offers access to applications on a subscription or pay-as-you-go basis. The provider is responsible for upgrades and all management requirements except user preference settings.

a)

DaaS

b)

IaaS

c)

PaaS

d)

SaaS

56.

What should be used to ensure non-repudiation on outgoing emails?

a)

Digital signature

b)

Cryptographic hash

c)

Ephemeral key

d)

Steganography

57.

An organization deploys a MODBUS based SCADA system to manage production machinery. Which of the following methods should be the organization's first choice for securing the new system?

a)

FDE

b)

NGFW

c)

HIDS

d)

EDR

58.

A subscription to a productivity application allows users in a company to create and share documents. The service is not hosted on a dedicated server.

What two things is this an example of? (Choose two)

a)

Public Cloud

b)

SaaS

c)

Private Cloud

d)

PaaS

e)

IaaS

59.

A security administrator is designing physical security for network servers. The design requirements call for the servers to be kept in a locked room with limited physical access. The administrator wants to ensure that physical access is controlled as tightly as possible and prevent unauthorized access.

What should the security analyst do?

a)

Secure the room with a keyed lock

b)

Secure the room with a biometric-based lock

c)

Secure the room with a combination lock

d)

Secure the room with magnetic key lock requiring a user ID card

60.

A security administrator is looking for a method to manage access to a secure area. They want to allow entry through a locked gate that unlocks automatically and track individuals going into and out of the area. Which method should the administrator use?

a)

Motion Detector

b)

Video Surveillance

c)

Proximity Reader

d)

Access List

61.

A system has six 100 GB hard disks available for data storage. Which RAID configuration will provide the most available storage with fault tolerance?

a)

RAID-1

b)

RAID-10

c)

RAID-5

d)

RAID-0

62.

Which cloud service model provides servers, storage, and network infrastructure, but not operating systems or applications

a)

PaaS

b)

IaaS

c)

SaaS

d)

CaaS

63.

A company deploys a highly advanced HVAC system in a datacenter. Which two security measures should a security specialist recommend for that system? (Choose two.)

a)

Install cameras and alarms

b)

Install a DLP system

c)

Integrate with internal network

d)

Isolate HVAC management devices

e)

Move all systems to the cloud

64.

A security consultant is brought in to test recent changes made to a company's network by its in-house security personnel. The consultant discovered a file named passwd.csv that was located at the disk root on a web server deployed in the company's perimeter network. The web server runs Linux.

What is the MOST likely reason for this file?

a)

The file was placed there as a honeyfile by in-house security

b)

The file is an optional Linux configuration file

c)

The file was left there by an external attacker to help configure persistence

d)

The file is evidence that the web server is a staging point for an active data exfiltration effort