wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

311-350

Total questions: 40

Worksheet time: 40mins

Name
Class
Date
1.

A new security engineer has started hardening systems. One of the hardening techniques the engineer is using involves disabling remote logins to the NAS. Users are now reporting the inability to use SCP to transfer files to the NAS, even though the data is still viewable from the users PCs. Which of the following is the MOST likely cause of this issue?

a)

(A). TFTP was disabled on the local hosts

b)

(B). SSH was turned off instead of modifying the configuration file

c)

(C). Remote login was disabled in the networkd.config instead of using the sshd.conf

d)

(D). Network services are no longer running on the NAS

2.

A small business just recovered from a ransomware attack against its file servers by

purchasing the decryption keys from the attackers. The issue was triggered by a phishing email and

the IT administrator wants to ensure it does not happen again. Which of the following should the IT

administrator do FIRST after recovery?

a)

(A). Scan the NAS for residual or dormant malware and take new daily backups that are tested on a

frequent basis

b)

(B). Restrict administrative privileges and patch ail systems and applications.

c)

(C). Rebuild all workstations and install new antivirus software

d)

(D). Implement application whitelisting and perform user application hardening

3.

An analyst is trying to identify insecure services that are running on the internal network. After performing a port scan the analyst identifies that a server has some insecure services enabled on default ports. Which of the following BEST describes the services that are currently running and the secure alternatives for replacing them' (Select THREE)

a)

(A). SFTP FTPS

b)

(B). SNMPv2 SNMPv3

c)

(C). HTTP, HTTPS

d)

(D). TFTP FTP

e)

(F). Telnet SSH

4.

A user enters a password to log in to a workstation and is then prompted to enter an authentication code. Which of the following MFA factors or attributes are being utilized in the authentication process? (Select TWO).

a)

(A). Something you know

b)

(B). Something you have

c)

(C). Somewhere you are

d)

(D). Someone you are

e)

(E). Something you are

5.

As part of the lessons-learned phase, the SOC is tasked with building methods to detect if a previous incident is happening again. Which of the following would allow the security analyst to alert the SOC if an event is reoccurring?

a)

(A). Creating a playbook within the SOAR

b)

(B). Implementing rules in the NGFW

c)

(C). Updating the DLP hash database

d)

(D). Publishing a new CRL with revoked certificates

6.

A security engineer is installing a WAF to protect the company's website from malicious web requests over SSL. Which of the following is needed to meet the objective?

a)

(A). A reverse proxy

b)

(B). A decryption certificate

c)

(C). A split-tunnel VPN

d)

(D). Load-balanced serv

7.

A security analyst needs to generate a server certificate to be used for 802.1X and secure RDP connections. The analyst is unsure what is required to perform the task and solicits help from a senior colleague. Which of the following is the FIRST step the senior colleague will most likely tell the analyst to perform to accomplish this task?

a)

(A). Create an OCSP

b)

(B). Generate a CSR

c)

(C). Create a CRL

d)

(D). Generate a .pfx file

8.

An organization wants to host an externally accessible web server that will not contain sensitive user information. Any sensitive information will be hosted on file servers. Which of the following is the BEST architecture configuration for this organization?

a)

(A). Host the web server in a DMZ and the file servers behind a firewall

b)

(B). Host the web server and the file servers in a DMZ

c)

(C). Host the web server behind a firewall and the file servers in a DMZ

d)

(D). Host both the web server and file servers behind a firewall

9.

Which of the following should be monitored by threat intelligence researchers who search for leaked credentials?

a)

Common Weakness Enumeration

b)

OSİNT

c)

Dark Web

d)

Vulnerability Databases

10.

A customer service representative reported an unusual text message that was sent to the help desk. The message contained an unrecognized invoice number with a large balance due and a link to click for more details. Which of the following BEST describes this technique?

a)

(A). Vishing

b)

(B). Whaling

c)

(C). Phishing

d)

(D). Smishing

11.

A security analyst has received an alert about being sent via email. The analyst's Chief information Security Officer (CISO) has made it clear that PII must be handle with extreme care From which of the following did the alert MOST likely originate?

a)

(A). S/MIME

b)

(B). DLP

c)

(C). IMAP

d)

(D). HIDS

12.

Which of the following would be MOST effective to contain a rapidly attack that is affecting a large number of organizations?

a)

(A). Machine learning

b)

(B). DNS sinkhole

c)

(C). Blocklist

d)

(D). Honeypot

13.

A company has determined that if its computer-based manufacturing is not functioning for 12 consecutive hours, it will lose more money that it costs to maintain the equipment. Which of the following must be less than 12 hours to maintain a positive total cost of ownership?

a)

(A). MTBF

b)

(B). RPO

c)

(C). RTO

d)

(D). MTTR

14.

After segmenting the network, the network manager wants to control the traffic between the segments. Which of the following should the manager use to control the network traffic?

a)

(A). A DMZ

b)

(B). A VPN

c)

(C). A VLAN

d)

(D). An ACL

15.

A company has discovered unauthorized devices are using its WiFi network, and it wants to harden the access point to improve security. Which of the following configuration should an analyst enable to improve security? (Select Two)

a)

(A). RADIUS

b)

(B). PEAP

c)

(C). WPS

d)

(D). WEP-TKIP

e)

(E). WPA2-PSK

16.

An employee has been charged with fraud and is suspected of using corporate assets. As authorities collect evidence, and to preserve the admissibility of the evidence, which of the following forensic techniques should be used?

a)

(A). Order of volatility

b)

(B). Data recovery

c)

(C). Chain of custody

d)

(D). Non-repudiation

17.

An organization has decided to host its web application and database in the cloud.

Which of the following BEST describes the security concerns for this decision?

a)

(A). Access to the organization's servers could be exposed to other cloud-provider clients

b)

(B). The cloud vendor is a new attack vector within the supply chain

c)

(C). Outsourcing the code development adds risk to the cloud provider

d)

(D). Vendor support will cease when the hosting platforms reach EOL.

18.

Which of the following BEST explains the difference between a data owner and a data custodian?

a)

(A). The data owner is responsible for adhering to the rules for using the data, while the data

custodian is responsible for determining the corporate governance regarding the data

b)

(B). The data owner is responsible for determining how the data may be used, while the data

custodian is responsible for implementing the protection to the data

c)

(C). The data owner is responsible for controlling the data, while the data custodian is responsible for

maintaining the chain of custody when handling the data

d)

(D). The data owner grants the technical permissions for data access, while the data custodian

maintains the database access controls to the data

19.

A security administrator is analyzing the corporate wireless network The network only has two access points running on channels 1 and 11. While using airodump-ng. the administrator notices other access points are running with the same corporate ESSID on all available channels and with the same BSSID of one of the legitimate access ports Which erf the following attacks in happening on the corporate network?

a)

(A). Man in the middle

b)

(B). Evil twin

c)

(C). Jamming

d)

(D). Rogue access point

e)

(E). Disassociation

20.

An organization has expanded its operations by opening a remote office. The new office is fully furnished with office resources to support up to 50 employees working on any given day. Which of the following VPN solutions would BEST support the new office?

a)

(A). Always On

b)

(B). Remote access

c)

(C). Site-to-site

d)

(D). Full tunnel

21.

A junior systems administrator noticed that one of two hard drives in a server room had a red error notification. The administrator removed the hard drive to replace it but was unaware that the server was configured in an array. Which of the following configurations would ensure no data is lost?

a)

(A). RAID 0

b)

(B). RAID 1

c)

(C). RAID 2

d)

(D). RAID 3

22.

A website developer who is concerned about theft cf the company's user database warns to protect weak passwords from offline brute-force attacks. Which of the following be the BEST solution?

a)

(A). Lock accounts after five failed logons

b)

(B). Precompute passwords with rainbow tables

c)

(C). Use a key-stretching technique

d)

(D). Hash passwords with the MD5 algorithm

23.

An organization suffered an outage and a critical system took 90 minutes to come back online. Though there was no data loss during the outage, the expectation was that the critical system would be available again within 60 minutes. Which of the following is the 60- minute expectation an example of:

a)

(A). MTBF

b)

(B). RPO

c)

(C). MTTR

d)

(D). RTO

24.

Which of the following will MOST likely cause machine learning and Al-enabled systems to operate with unintended consequences?

a)

(A). Stored procedures

b)

(B). Buffer overflows

c)

(C). Data bias

d)

(D). Code reuse

25.

A company labeled some documents with the public sensitivity classification. This means the documents can be accessed by?

a)

(A). employees of other companies press

b)

(B). all members of the department that created the documents

c)

(C). only the company's employees and those listed in the document

d)

(D). only the individuals listed in the documents

26.

A company recently experienced an attack in which a malicious actor was able to exfiltrate data by cracking stolen passwords, using a rainbow table the sensitive data. Which of the following should a security engineer do to prevent such an attack in the future?

a)

(A). Use password hashing.

b)

(B). Enforce password complexity.

c)

(C). Implement password salting.

d)

(D). Disable password reuse.

27.

Which of the following environments would MOST likely be used to assess the execution of component parts of a system at both the hardware and software levels and to measure performance characteristics?

a)

Test

b)

Staging

c)

Development

d)

Production

28.

Which of the following is the correct order of volatility from MOST to LEAST volatile?

a)

(A). Memory, temporary filesystems, routing tables, disk, network storage

b)

(B). Cache, memory, temporary filesystems, disk, archival media

c)

(C). Memory, disk, temporary filesystems, cache, archival media

d)

(D). Cache, disk, temporary filesystems, network storage, archival media

29.

Some laptops recently went missing from a locked storage area that is protected by keyless

RFID-enabled locks. There is no obvious damage to the physical space. The security manager

identifies who unlocked the door, however, human resources confirms the employee was on

vacation at the time of the incident. Which of the following describes what MOST likely occurred?

a)

(A). The employee's physical access card was cloned.

b)

(B). The employee is colluding with human resources

c)

(C). The employee's biometrics were harvested

d)

(D). A criminal used lock picking tools to open the door.

30.

A small company that does not have security staff wants to improve its security posture. Which of the following would BEST assist the company?

a)

(A). MSSP

b)

(B). SOAR

c)

(C). IaaS

d)

(D). PaaS

31.

An organization routes all of its traffic through a VPN Most users are remote and connect into a corporate datacenter that houses confidential information There is a firewall at the Internet border followed by a DIP appliance, the VPN server and the datacenter itself. Which of the following is the WEAKEST design element?

a)

(A). The DLP appliance should be integrated into a NGFW.

b)

(B). Split-tunnel connections can negatively impact the DLP appliance's performance

c)

(C). Encrypted VPN traffic will not be inspected when entering or leaving the network

d)

(D). Adding two hops in the VPN tunnel may slow down remote connections

32.

A retail company that is launching a new website to showcase the company's product line

and other information for online shoppers registered the following URLs:

* www.companysite.com

* shop.companysite.com

* about-us.companysite.com

* contact-us.companysite.com

* secure-logon.companysite.com

Which of the following should the company use to secure its website if the company is concerned with convenience and cost?

a)

(A). A self-signed certificate

b)

(B). A root certificate

c)

(C). A code-signing certificate

d)

(D). A wildcard certificate

e)

(E). An extended validation certificate

33.

A Chief Information Officer receives an email stating a database will be encrypted within 24 hours unless a payment of $20,000 is credited to the account mentioned In the email. This BEST describes a scenario related to:

a)

(A). whaling.

b)

(B). smishing.

c)

(C). spear phishing

d)

(D). vishing

34.

After a phishing scam for a user's credentials, the red team was able to craft a payload to deploy on a server. The attack allowed the installation of malicious software that initiates a new remote session. Which of the following types of attacks has occurred?

a)

(A). Privilege escalation

b)

(B). Session replay

c)

(C). Application programming interface

d)

(D). Directory traversal

35.

The Chief Executive Officer (CEO) of an organization would like staff members to have the

flexibility to work from home anytime during business hours, incident during a pandemic or crisis,

However, the CEO is concerned that some staff members may take advantage of the of the flexibility

and work from high-risk countries while on holidays work to a third-party organization in another

country. The Chief information Officer (CIO) believes the company can implement some basic to

mitigate the majority of the risk. Which of the following would be BEST to mitigate CEO's concern? (Select TWO).

a)

(A). Geolocation

b)

(B). Time-of-day restrictions

c)

(C). Certificates

d)

(D). Tokens

e)

(E). Geotagging

36.

A company wants to restrict emailing of PHI documents. The company is implementing a DLP solution. In order to restrict PHI documents, which of the following should be performed FIRST?

a)

Retention

b)

Governance

c)

Classification

d)

Change Management

37.

A security administrator is trying to determine whether a server is vulnerable to a range of attacks. After using a tool, the administrator obtains the following output:

Which of the following attacks was successfully implemented based on the output?

a)

(A). Memory leak

b)

(B). Race conditions

c)

(C). SQL injection

d)

(D). Directory traversal

38.

An employee opens a web browser and types a URL into the address bar. Instead of reaching the requested site, the browser opens a completely different site. Which of the following types of attacks have MOST likely occurred? (Select TWO).

a)

(A). DNS hijacking

b)

(B). Cross-site scripting

c)

(C). Domain hijacking

d)

(D). Man-in-the-browser

e)

(E). Session hijacking

39.

An organization's Chief Information Security Officer is creating a position that will be responsible for implementing technical controls to protect data, including ensuring backups are properly maintained. Which of the following roles would MOST likely include these responsibilities?

a)

(A). Data protection officer

b)

(B). Data owner

c)

(C). Backup administrator

d)

(D). Data custodian

e)

(E). Internal auditor

40.

A Chief Security Officer (CSO) is concerned about the amount of PII that is stored locally on each salesperson's laptop. The sales department has a higher-than-average rate of lost equipment. Which of the following recommendations would BEST address the CSO's concern?

a)

(A). Deploy an MDM solution.

b)

(B). Implement managed FDE.

c)

(C). Replace all hard drives with SEDs.

d)

(D). Install DLP agents on each laptop.