wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Security+ Part 3 Implementation

Total questions: 90

Worksheet time: 2hrs 30mins

Name
Class
Date
1.

A user reports to the help desk that he is getting "cannot resolve address" error messages from his browser. Which port is likely a problem on his firewall?

a)

22

b)

53

c)

161

d)

162

2.

What is a weakness of the DNS protocol?

a)

Requests and replies are sent in plaintext

b)

It doesn't provide billing standardization in cloud infrastructures

c)

TCP can be used for large transfers such as zone transfers

d)

Its encryption capabilities are slow

3.

Which of the following is a benefit of DNSSEC?

a)

Scalability

b)

Lower expenditures from operations capital (OpsCap) expenditures

c)

Enables origin authentication, authenticated denial of existence, and data integrity

d)

Availability and confidentiality

4.

What is the Secure Shell (SSH) protocol?

a)

It is an encrypted remote terminal connection program used for remote connections to a server

b)

It provides dynamic network address translation

c)

It provides Software as a Service (SaaS)

d)

It provides snapshots of physical machines at a point in time.

5.

What is the purpose of the Secure/Multipurpose Internet Mail Extensions (S/MIME) protocol?

a)

It is used in audio encryption

b)

It optimizes the use of ports 80 and 443

c)

It encrypts HTTP traffic

d)

It provides cryptographic protections to emails

6.

What is the purpose of Lightweight Directory Access Protocol Secure (LDAPS)?

a)

It leverages encryption protections of SSH to secure FTP transfers

b)

It uses an SSL/TLS tunnel to connect LDAP services

c)

It digitally signs DNS records

d)

It provides both symmetric and asymmetric encryption

7.

Which port does FTPS use?

a)

53

b)

83

c)

990

d)

991

8.

You are a security admin for XYZ company. You suspect that company emails using the default POP and IMAP email protocols and ports are getting intercepted while in transit. Which of the following ports should you consider using?

a)

Ports 995 and 993

b)

Ports 53 and 22

c)

Ports 110 and 143

d)

Ports 161 and 16240

9.

What is the purpose of the Simple Network Management Protocol version 3 (SNMPv3)?

a)

It provides asymmetric encryption values

b)

It achieves specific communication goals

c)

It provides a common language for developers

d)

It is used to securely manage devices on IP-based networks

10.

What is the purpose of HTTPS?

a)

To allow enumeration and monitoring of network resources

b)

To use SSL or TLS to encrypt a channel over which HTTP traffic is transmitted

c)

To implement Single Sign-On

d)

To enhance communication protocols

11.

Fuzz testing works best in which of the following testing environments?

a)

Known environment testing

b)

Partially known environment testing

c)

Unknown environment testing

d)

Fuzz testing works equally well in all of the above

12.

Which code analysis method is performed while the software is executed, either on a target system or an emulated system?

a)

Static analysis

b)

Runtime analysis

c)

Sandbox analysis

d)

Dynamic analysis

13.

Which of the following are associated with endpoint protection? (Choose all that apply)

a)

EDR

b)

TPM

c)

DLP

d)

HTTP headers

14.

You have a series of web servers that you wish to harden. Which of the following is the best solution for this case?

a)

A block list/deny list

b)

An allow list

c)

Secure cookies

d)

Code signing

15.

You are examining the server infrastructure and wish to harden the machines in your server farm. Which is thee first task you should perform across all your servers?

a)

Apply a block list/deny list

b)

Apply an allow list

c)

Block open ports and disable unused services

d)

Employ disk encryption

16.

Databases can use which of the following for security? (Choose all that apply)

a)

Tokenization

b)

Salting

c)

Code signing

d)

Secure cookies

17.

When you're creating a website, which of the following will provide protection against user attacks against your site? (Choose all that apply)

a)

Tokenization

b)

HTTP headers

c)

Code signing

d)

Fuzzing

18.

Your firm has 200 desktops in three sites, split among a dozen business departments. Which of the following would be the first that you should ensure is working correctly to reduce risk?

a)

Application security

b)

Secure Boot

c)

Patch management

d)

Secure cookies

19.

You have a database full of very sensitive data. Salespeople need to access some of this sensitive data when onsite with a customer. The best method to prevent leakage of critical data during these access sessions would be to employ which of the following?

a)

Salting

b)

Hashing

c)

Block list

d)

Tokenization

20.

Which of the following elements is not part of the Root of Trust?

a)

Registry

b)

UEFI

c)

TPM PCR

d)

Digital signatures

21.

A network-based intrusion prevention system (NIPS) relies on what other technology at its core?

a)

VPN

b)

IDS

c)

NAT

d)

ACL

22.

You have been asked to prepare a report on network-based intrusion detection systems that compares the NIDS solutions from two potential vendors your company is considering. One solution is signature based and one is behavior based. Which of the following lists what your report will identify as the key advantage of each?

a)

Behavioral: low false-negative rate;

Signature: ability to detect zero-day attacks

b)

Behavioral: ability to detect zero-day attacks;

Signature: low false-positive rates

c)

Behavioral: high false-positive rate;

Signature: high speed of detection

d)

Behavioral: low false-positive rate;

Signature: high false-positive rate

23.

How can proxy servers improve security?

a)

They use TLS-based encryption to access all sites

b)

They can control which sites and content employees access, lessening the chance of malware exposure

c)

They enforce appropriate use of company resources

d)

They prevent access to phishing sites

24.

What technology can check the client's health before allowing access to the network?

a)

DLP

b)

Reverse proxy

c)

NIDS/NIPS

d)

NAC

25.

What kind of device provides tamper protection for encryption keys?

a)

HSM

b)

IPSec

c)

Jump Server

d)

HTML5

26.

What is the purpose of the DNS protocol?

a)

It provides a function for charging SaaS on a per-use basis

b)

It supports the networking infrastructure

c)

It translates names into IP addresses

d)

It defines tenants in a public cloud

27.

A user reports to the help desk that he is getting "cannot resolve address" error messages from his browser. Which port is likely a problem on his firewall?

a)

22

b)

553

c)

440

d)

53

28.

What is the primary purpose of a screened subnet?

a)

To prevent direct access to secure servers from the Internet

b)

To provide a place for corporate servers to reside so they can access the Internet

c)

To create a safe computing environment next to the Internet

d)

To slow down traffic coming and going to the network

29.

What is the best tool to ensure network traffic priorities for video conferencing are maintained?

a)

QoS

b)

VLAN

c)

Network segmentation

d)

Next-generation firewall

30.

If you wish to monitor 100 percent of the transmissions from your customer service representatives to the Internet and other internal services, which is the best tool to use?

a)

SPAN port

b)

TAP

c)

Mirror port

d)

Aggregator switches

31.

The use of an eight-digit PIN to set up a wireless connection is part of which of the following?

a)

WPA

b)

SAE

c)

WPA3

d)

WPS

32.

What is the role of EAP in wireless connections?

a)

It is a framework for establishing connectivity

b)

It is a framework for passing authentication information

c)

It is a framework to secure the authentication process

d)

It is an actual encryption method used during authentication

33.

What is the primary difference between WPA2-Personal and WPA2-Enterprise?

a)

The use of a pre-shared secret

b)

The number of concurrent supported users

c)

Licensing costs on a per-user basis

d)

The use of SAE for connections

34.

You are setting up a Wi-Fi hotspot for guest visitors. What is the best method of establishing connections?

a)

Open access

b)

A posted password visually available on site

c)

Use of a PSK solution

d)

Captive portal

35.

What is the most secure means of establishing connectivity to a Wi-Fi access point?

a)

CCMP

b)

SAE protocol

c)

WPA2

d)

IEEE 802.1X

36.

A site survey will reveal all of the following except which one?

a)

Optimal access point placement

b)

Captive portal location

c)

Channel allocations

d)

Link speeds across the site

37.

Forward secrecy exists for which of the following protocols?

a)

WPS

b)

WPA2

c)

WPA3

d)

All of the above

38.

Your boss has asked you to set up wireless connectivity at a new company location. However, she is concerned about planning, coverage, and security regarding AP placement. She wants you to ensure coverage and address security concerns. Which of the following should you consider using while setting up this new location? (Select three)

a)

RADIUS federation

b)

Site survey

c)

Wi-Fi analyzer

d)

Heat map

39.

You are using EAP-TTLS, which includes what unique aspect?

a)

It cannot be used in WPA3

b)

It requires client-side certificates

c)

It cannot be used with CHAP

d)

It is easier to set up than other EAP schemes

40.

Which protocol allows the passing of legacy authentication protocols such as PAP, CHAP, and MS-CHAP?

a)

EAP-TTLS

b)

EAP-TLS

c)

SAE

d)

CCMP

41.

Which of the following is a weakness of cellular technology?

a)

Multiple vendors in a nationwide network

b)

Less availability in rural areas

c)

Multiple cell towers in close proximity in urban areas

d)

Strong signals in areas of reasonable population

42.

What frequency spectrum does Bluetooth use?

a)

1.7 GHz

b)

2.4 GHz

c)

5 GHz

d)

6.4 GHz

43.

You need to use cryptographic keys between several devices. Which of the following can manage this task?

a)

MAM solutions

b)

Firmware OTA updates

c)

USB OTG

d)

MicroSD HSM

44.

Which of the following are the three modes supported by Bluetooth 4.0?

a)

Classic, Low Speed, High Energy

b)

Enhanced Data Rate, Backward Compatible, High Energy

c)

Classic, High Speed, Low Energy

d)

Synchronous, High Speed, Low Energy

45.

What is the primary use of near field communication (NFC)?

a)

Establishing radio communications over a short proximity

b)

Communication in sparsely populated areas

c)

Long-distance connectivity

d)

Communication in noisy industrial environments

46.

You need to manage a whole host of different endpoints in the enterprise, including mobile devices, iPads, printers, PCs and phones. Which of the following is the most comprehensive solution?

a)

COPE-based solutions

b)

MAM solutions

c)

MDM solutions

d)

UEM solutions

47.

What is the disadvantage of infrared (IR) technology?

a)

It has a high data rate

b)

It cannot penetrate solid objects

c)

It can penetrate walls

d)

It uses a slow encryption technology

48.

What is the main security concern with Universal Serial Bus (USB) technology?

a)

It connects to cell phones for easy charging

b)

It uses proprietary encryption

c)

It automounts and acts like a hard drive attached to the computer

d)

It uses older encryption technology

49.

Why is it important to establish policies governing remote wiping of mobile devices?

a)

Mobile devices typically do not mix personal and business data

b)

Mobile devices are more easily secured

c)

Thieves cannot decrypt mobile devices

d)

They are more susceptible to loss than other devices

50.

What is the purpose of geofencing?

a)

It can be used to remotely wipe a lost device

b)

It makes securing the mobile device simpler

c)

It enables devices to be recognized by location and have actions taken

d)

It can enforce device locking with a strong password

51.

The policies and procedures employed to connect the IAM systems of the enterprise and the cloud to enable communication with the data are referred to as what?

a)

API inspection and integration

b)

Secrets management

c)

Dynamic resource allocation

d)

Container security

52.

Which of the following terms is not related to storage security in the cloud?

a)

Permissions

b)

High availability

c)

Segmentation

d)

Encryption

53.

Resource policies involve all the following except?

a)

Permissions

b)

IAM

c)

Cost

d)

Access

54.

Virtual networking in a cloud environment can include all the following except?

a)

VPC endpoint

b)

Public subnets

c)

Private subnets

d)

Network function virtualization

55.

What structure is used to manage users in cloud environments?

a)

Permissions

b)

Incident awareness

c)

Dynamic resource allocations

d)

Security groups

56.

Which of the following is a security policy enforcement point placed between cloud service consumers and cloud service providers to manage enterprise security policies as cloud-based resources are accessed?

a)

SWG

b)

VPC endpoint

c)

CASB

d)

Resource policies

57.

Secure web gateways operate by inspecting at what point in the communication channel?

a)

Security group membership

b)

Application layer

c)

Instance awareness

d)

API inspection

58.

Which of the following are critical in cloud security? (Choose all that apply)

a)

Firewalls

b)

Integration and auditing

c)

Secrets management

d)

Encryption

59.

High availability is dependent on which of the following?

a)

Secrets management

b)

Dynamic resource allocation

c)

Container security

d)

CASB

60.

Which is the most critical element in understanding your current cloud security posture?

a)

Cloud service agreement

b)

Networking security controls

c)

Encryption

d)

Application security

61.

A friend of yours who works in the IT department of a bank tells you that tellers are allowed to log in to their terminals only from 9am to 5pm Monday through Saturday. What is this restriction an example of?

a)

User auditing

b)

Least privlege

c)

Time-of-day restrictions

d)

Account verification

62.

Your organization is revamping its account management policies and you've been asked to clarify the difference between account disablement and account lockout. Which of the following statements best describes that difference?

a)

Account disablement removes the user and all their data files; account lockout does not.

b)

Account lockout typically only affects the ability to log in; account disablement removes all privileges

c)

Account lockout is permanent; account disablement is easily reversible

d)

Account disablement requires administrative privileges to execute; account lockout can be performed by any user.

63.

Password policies are needed for all of the following except?

a)

Password complexity

b)

Password history

c)

Password reuse

d)

Password language

64.

Which of the following is used to identify when a device is within a specified distance of a location?

a)

Geofencing

b)

Geoproximity

c)

Geodistance

d)

Geotagging

65.

Account audits are used for all of the following except?

a)

Testing password strength

b)

Verification of user training

c)

Verification of use employment/authorization

d)

Testing for password policy enforcement

66.

Which of the following represents the greatest risk when used?

a)

Service accounts

b)

Users accounts

c)

Guest accounts

d)

Shared accounts

67.

When a new login request comes from a geographically distant location, for a user with a history of recent local logins, what policy can best help address legitimacy?

a)

Impossible travel time

b)

Geolocation

c)

Network location

d)

Time-of-day restrictions

68.

You wish to tokenize account credentials so people can carry their passwords with them and not have to remember or type in long passwords. The best solution would involve which of the following?

a)

Identity providers (IdP's)

b)

SSH keys

c)

Smart card

d)

Password managers

69.

On a web-facing interface, where your employees can gain access to the network, you wish to employ security against brute force attacks. One of the most cost-effective tools is to enforce which of the following?

a)

Geofencing policy

b)

Password complexity policy

c)

Account lockout policy

d)

Certificates

70.

Which type of policy sets the direction for the security team to manage who can access what resources in a system?

a)

Account permissions policy

b)

Time-based login policies

c)

Password policies

d)

Time-of-day restriction policies

71.

Your organization needs a system for restricting access to files based on the sensitivity of the information in those files. You might suggest which of the following access control systems?

a)

Discretionary access control

b)

Mandatory access control

c)

Confidential access control

d)

File-based access ccontrol

72.

Which of the following describes a major difference between NTFS and FAT32 file systems?

a)

NTFS supports user-level access differentiation

b)

FAT32 supports group-level access differentiation

c)

FAT32 natively encrypts files and directories

d)

NTFS logs all file access using secure tokens

73.

Your organization has grown too large to support assigning permissions to users individually. Within your organization, you have large groups of users who perform the same duties and need the same type and level of access to the same files. Rather than assigning individual permissions, your organization may wish to consider using which of the following access control methods?

a)

Group-based access control

b)

Shift-based access control

c)

Role-based access control

d)

File-based access control

74.

A ticket-granting server is an important element in which of the following authentication models?

a)

802.1X

b)

RADIUS

c)

TACACS+

d)

Kerberos

75.

Which of the following is an open standard that uses security tokens and assertions and allows you to access multiple websites with one set of credentials?

a)

PAP

b)

CHAP

c)

SSO

d)

SAML

76.

What protocol is used for RADIUS?

a)

UDP

b)

NetBIOS

c)

TCP

d)

Proprietary

77.

What are accounts with greater than "normal" user access called?

a)

Privileged accounts

b)

System accounts

c)

Superuser accounts

d)

Audit accounts

78.

You have to implement an OpenID solution. What is the typical relationship with existing systems?

a)

OpenID is used for authentication, OAuth is used for authorization

b)

OpenID is used for authorization, OAuth is used for authentication

c)

OpenID is not compatible with OAuth

d)

OpenID only works with Kerberos

79.

You wish to create an access control scheme that enables the CFO to access financial data from his machine, but not from the machine in the reception area of the lobby. Which access control model is best suited for this?

a)

Role-based access control

b)

Conditional access control

c)

Mandatory access control

d)

Discretionary access control

80.

You need to design an authentication system where users who have never connected to the system can be identified and authenticated in a single process. Which is the best solution?

a)

RADIUS

b)

Password vault-based authentication

c)

TPM-based authentication

d)

Knowledge-based authentication

81.

You are asked by the senior system administrator to refresh the SSL certificates on the web servers. The process is to generate a certificate signing request (CSR), send it to a third party to be signed, and then apply the return information to the CSR. What is this an example of?

a)

Pinning

b)

Borrowed authority

c)

Third-party trust model

d)

Stapling

82.

A certificate authority consists of which of the following?

a)

Hardware and software

b)

Policies and procedures

c)

People who manage certificates

d)

All of the above

83.

Your manager wants you to review the company's internal PKI system's CPS for applicability and verification and to ensure that it meets current needs. What are you most likely to focus on?

a)

Revocations

b)

Trust level provided to users

c)

Key entropy

d)

How the keys are stored

84.

You are preparing an email to send to a colleague at work, and because the message information is sensitive, you decide you should encrypt it. When you attempt to apply the certificate that you have for the colleague, the encryption fails. The certificate was listed as still valid for another year, and the certificate authority is still trusted and working. What happened to this user's key?

a)

It was using the wrong algorithm

b)

You are querying the incorrect certificate authority

c)

It was revoked

d)

The third-party trust model failed

85.

Which of the following is a requirement for a CRL?

a)

It must have the email addresses of all the certificate owners

b)

It must contain a list of all expired certificates

c)

It must contain information about all the subdomains covered by the CA

d)

It must be posted to a public directory

86.

What does OCSP do?

a)

It reviews the CRL for the client and provides a status about the certificate being validated

b)

It outlines the details of a certificate authority, including how identities are verified, the steps the CA follows to generate certificates, and why the CA can be trusted

c)

It provides for a set of values to be attached to the certificate

d)

It provides encryption for digital signatures

87.

The X.509 standard applies to which of the following?

a)

SSL providers

b)

Digital certificates

c)

Certificate revocation lists

d)

Public key infrastructure

88.

You are browsing a website when your browser provides you with the following warning message: "There is a problem with this website's security certificate." When you examine the certificate, it indicates that the root CA is not trusted. What most likely happened to cause this error?

a)

The certificate was revoked

b)

The certificate does not have enough bit length for the TLS protocol

c)

The server's CSR was not signed by a trusted CA

d)

The certificate has expired

89.

You are issued a certificate from a CA, delivered by email, but the file does not have an extension. The email notes that the root CA, the intermediate CAs, and your certificate are all attached in the file. What format is your certificate likely in?

a)

DER

b)

CER

c)

PEM

d)

PFX

90.

Why is pinning more important on mobile devices?

a)

It uses elliptic curve cryptography

b)

it uses less power for pinned certificate requests

c)

It reduces network bandwidth usage by combining multiple CA requests into one

d)

It allows caching of a known good certificate when roaming to low-trust networks