wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Security+ SY0 601 Questions 42-82

Total questions: 42

Worksheet time: 22mins

Name
Class
Date
1.

An organization is tuning SIEM rules based off of threat intelligence

reports. Which of the following phases of the incident response process

does this scenario represent?

a)

Eradication

b)

Lessons Learned

c)

Preparation

d)

Recovery

2.

A network manager is concerned that business may be negatively

impacted if the firewall in its datacenter goes offline. The manager would

like to implement a high availability pair to:

a)

decrease the mean time between failures

b)

remove the single point of failure.

c)

cut dawn the mean time to repair.

d)

reduce the recovery time objective.

3.

A host was infected with malware. During the incident response, Joe, a

user, reported that he did not receive any emails with links, but he had

been browsing the Internet all day.

Which of the following would MOST likely show where the malware

originated?

a)

The DNS logs

b)

The web server logs

c)

The SIP traffic logs

d)

The SNMPlogs

4.

Which of the following would MOST likely be identified by a

Points

credentialed scan but would be missed by an uncredentialed scan?

a)

Vulnerabilities with a CVSS score greater than 6.9.

b)

Critical infrastructure vulnerabilities on non-lP protocols.

c)

CVEs related to nan-Microsoft systems such as printers and switches.

d)

Missing patches far third-party software an Windows workstations and

servers.

5.

A recent phishing campaign resulted in several compromised user

accounts. The security incident response team has been tasked with

reducing the manual labor ot filtering through all the phishing emails as

they arrive and blocking the sender's email address, along with other

time-consuming mitigation actions.

Which of the following can be configured to streamline those tasks?

a)

SOAR playbook

b)

MOM policy

c)

Firewall rules

d)

URLfilter

e)

SIEM data collection

6.

Which of the following is a reason to publish files' hashes?

a)

To validate the integrity af the files

b)

To verify if the software was digitally signed

c)

To use the hash as a software activation key

d)

To use the hash as a decryption passphrase

7.

A security analyst is tasked with classifying data to be stored on company

servers.

Which of the following should be classified as proprietary?

a)

CustomerS dates af birth

b)

CustomerS email addresses

c)

Marketing strategies

d)

Employee salaries

8.

Which of the following are requirements that must be configured for PCI

OSS compliance? (Choose two.)

a)

Testing security systems and processes regularly

b)

Installing and maintaining a web proxy to protect cardholder data

c)

Assigning a unique 10 to each person with computer access

d)

Encrypting transmission of cardholder data across private networks

e)

Benchmarking security awareness training far contractors

9.

Which of the following can be used by a monitoring tool to compare

values and detect password leaks without providing the actual

credentials?

a)

Hashing

b)

Tokenization

c)

Masking

d)

Encryption

10.

An organization would like to give remote workers the ability to use

applications hosted inside the corporate network. Users will be allowed to

use their personal computers, or they will be provided organization

assets. Either way, no data or applications will be installed locally on any

user systems.

Which of the following mobile solutions would accomplish these

goals?

a)

VDI

b)

MDM

c)

COPE

d)

UTM

11.

Which of the following explains why RTO is included in a BlA?

a)

It identifies the amount of allowable downtime for an application or system.

b)

It prioritizes risks so the organization can allocate resources appropriately.

c)

It monetizes the loss of an asset and determines a break-even point for risk

mitigation.

d)

It informs the backup approach so that the organization can recover data ta

a known time.

12.

Against the recommendation ot the IT security analyst, a company set all

user passwords on a server as F@55w0rD. upon review of the

/etc/passwd file, an attacker found the following:

a)

Perfect forward secrecy

b)

Key stretching

c)

Salting

d)

Hashing

13.

Which of the following would be the BEST way to analyze diskless

malware that has infected a VDI?

a)

Run a full on-demand scan of the root volume.

b)

Shut down the VOI and copy off the event logs.

c)

Take a memory snapshot of the running system.

d)

Use NetFlow to identify command-and-control IPs.

14.

An attacker browses a company's online job board attempting to find any

relevant information regarding the technologies the company uses.

Which of the following BEST describes this social engineering

technique?

a)

Hoax

b)

Reconnaissance

c)

Impersonation

d)

Pretexting

15.

An organization is building backup server rooms in geographically diverse

locations. The Chief Information Security Officer implemented a

requirement on the project that states the new hardware cannot be

susceptible to the same vulnerabilities in the existing server room.

Which of the following should the systems engineer consider?

a)

Purchasing hardware from different vendors

b)

Migrating workloads to public cloud infrastructure

c)

Implementing a robust patch management solution

d)

Designing new detective security controls

16.

While investigating a recent security incident, a security analyst decided

to view all network connections on a paäicular server.

Which of the following would provide the desired information?

a)

nslookup

b)

netstat

c)

nmap

d)

arp

17.

A Chief Information Security Officer (CISO) has defined resiliency

requirements for a new data center architecture The requirements are as

follows:

• Critical fileshares will remain accessible during and after a natural

disaster

• Five percent of hard disks can fail at any given time without impacting

the data.

• Systems will be forced to shut down gracefully when battery levels are

below 20%.

Which of the following are required to BEST meet these objectives? (Select THREE)

a)

RAID

b)

High Availability

c)

NAS

d)

UPS

e)

Redundant power supplies

18.

While investigating a recent security incident, a security analyst decided

to view all network connections on a particular server.


Which of the following would provide the desired information?

a)

nslookup

b)

arp

c)

netstat

d)

nmap

19.

A security analyst is reviewing the following command-line output:

a)

ICMP spoofing

b)

URL redirection

c)

MAC address cloning

d)

DNS poisoning

20.

A company is required to continue using legacy software to support a

critical service.

Which of the following BEST explains a risk of this practice?

a)

Default system configuration

b)

Unsecure protocols

c)

Lack of vendor support

d)

Weak encryption

21.

A major political pay experienced a server breach. The hacker then

publicly posted stolen internal communications concerning campaign

strategies to give the opposition party an advantage.

Which of the following BEST describes these threat actors?

a)

Semi-authorized hackers

b)

State actors

c)

Script kiddies

d)

Advanced persistent threats

22.

While reviewing the wireless router, a systems administrator of a small

business determines someone is spoofing the MAC address of an

authorized device. Given the table ABOVE

Which of the following should be the administrators NEXT step to detect if

there is a rogue system without impacting availability?

a)

Conduct a ping sweep

b)

Physically check each system.

c)

Deny Internet access to the "UNKNOWN" hostname.

d)

Apply MAC filtering

23.

A forensics investigator is examining a number ot unauthorized payments

that were reported on the company's website. Some unusual log entries

show users received an email for an unwanted mailing attempt to

unsubscribe. One of the users reported the email to the phishing team,

and the forwarded email revealed the link to be:

<a href="https://www.company.com/payto.do?routing=00001111&acct=22223334&amount=250">Click here to unsubscribe</a>

Which of the following will the forensics investigator MOST likely determine has occurred?

a)

SQL Injection

b)

Broken authentication

c)

XSS

d)

XSRF

24.

Which of the following is a risk that is specifically associated with hosting

applications in the public cloud?

a)

Unsecured root accounts

b)

Zero-day

c)

Shared tenancy

d)

Insider threat

25.

While checking logs, a security engineer notices a number of end users

suddenly downloading files with the .tar.gz extension. Closer examination

of the files reveals they are PE32 files. The end users state they did not

initiate any of the downloads. Fuäher investigation reveals the end users

all clicked on an external email containing an infected MHT file with an

href link a week prion

Which of the following is MOST likely occurring?

a)

A RATwas installed and is transferring additional exploit tools.

b)

The workstations are beaconing to a command-and-control server.

c)

A logic bomb was executed and is responsible for the data transfers.

d)

Afireless virus is spreading in the local network environment.

26.

A worldwide manufacturing company has been experiencing email

account compromises. In one incident, a user logged in from the

corporate office in France, but then seconds later, the same user account

attempted a login from Brazil.

Which of the following account policies would BEST prevent this type of

attack?

a)

Network location

b)

Impossible travel time

c)

Geolocation

d)

Geofencing

27.

After segmenting the network, the network manager wants to control the

traffic between the segments.

Which of the following should the manager use to control the

network traffic?

a)

A DMZ

b)

A VPN

c)

A VLAN

d)

An ACL

28.

Which of the following uses SAML for authentication?

a)

HOTP

b)

Federation

c)

TOTP

d)

Kerberos

29.

While reviewing pcap data, a netv,ork security analyst is able to locate

plaintext usernames and passwords being sent from workstations to

network switches.

Which of the following is the security analyst MOST likely observing?

a)

SNMP traps

b)

A Telnet session

c)

An SSH connection

d)

SFTP traffic

30.

The manager who is responsible for a data set has asked a security

engineer to apply encryption to the data on a hard disk. The security

engineer is an example of a:

a)

data controller.

b)

data owner

c)

data custodian

d)

data processor

31.

A cybersecurity analyst reviews the log files trom a web server and sees a

series of files that indicate a directory-traversal attack has occurred.

Which of the following is the analyst MOST likely seeing?

32.

Under GOPR, which of the following is MOST responsible for the

protection of privacy and website user rights?

a)

The data protection officer

b)

The data processor

c)

The data owner

d)

The data controller

33.

A security administrator is analyzing the corporate wireless network. The

network only has two access points running on channels 1 and 11. While

using airodump-ng. the administrator notices other access points are

running with the same corporate ESSID on all available channels and with

the same 3SSlO of one of the legitirnate access points.

Which of the following attacks is happening on the corporate network?

a)

Man in the middle

b)

Evil twill

c)

Jamming

d)

Rogue access point

e)

Disassociation

34.

The IT depaäment's on-site developer has been WI•th the team for many

years. Each time an application is released, the security team is able to

identify multiple vulnerabilities.

Which of the following would BEST help the team ensure the application

is ready to be released to production?

a)

Limit the use of third-pady libraries

b)

Prevent data exposure queries.

c)

Obfuscate the source code

d)

Submit the application to

before releasing it

35.

A user received an SMS on a mobile phone that asked for bank details.

Which of the following social-engineering techniques was used in this

case?

a)

SPIM

b)

Vishing

c)

Spear phishing

d)

Smishing

36.

A company recently experienced a data breach and the source was

determined to be an executive who was charging a phone in a public

area.

Which of the following would MOST likely have prevented this breach?

a)

A firewall

b)

A device pin

c)

A

data blocker

d)

Biometrics

37.

A company is adopting a BYOD policy and is looking for a comprehensive

solution to protect company information on user devices.

Which of the following solutions would BEST support the policy?

a)

Mobile device management

b)

Full-device encryption

c)

Remote wipe

d)

Biometrics

38.

A security analyst is investigating multiple hosts that are communicating

to external IP addresses during the hours of 2.00 mm - 4:00 am. The

malware has evaded detection by traditional antivirus software.

Which of the following types of malware is MOST likely infecting the

hosts?

a)

Ransomware

b)

A worm

c)

Plymorphic

d)

A RAT

39.

A security analyst is investigating multiple hosts that are communicating

to external IP addresses between the hours of 2.00 a.m. and 4:00 a.m.

The malware has evaded detection by traditional antivirus somware.

Which of the following types of malware is MOST likely infecting the

hosts?

a)

RAT

b)

Ransomeware

c)

Logic Bomb

d)

Worm

40.

A security administrator suspects there may be unnecessary services

running on a server. Which of the following tools will the administrator

MOST likely use to confirm the suspicions?

a)

Nmap

b)

Wireshark

c)

Autopsy

d)

DNSEnum

41.

An organization is concerned about hackers potentially entering a facility

and plugging in a remotely accessible Kali Linux box.

Which of the following should be the first lines of defense against

such an attack? (Choose two.)

a)

MAC filtering

b)

Network access control

c)

Zero Trust segmentation

d)

Access control vestibules

e)

Guards

42.

Ann, a customer, received a notification from her mortgage company

stating her PII may be shared with partners, affiliates, and associates to

maintain day-to-day business operations.

Which of the following documents did Ann receive?

a)

An annual privacy n06ce

b)

Anon-disclosure agreement

c)

A privNeged•user agreement

d)

memorandum of understandng