wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Sec+ Domain 1.1

Total questions: 12

Worksheet time: 16mins

Name
Class
Date
1.

A company has drafted an insider-threat policy that prohibits the use of external storage devices. Which of the following would BEST protect the company from data exfiltration via removable media?

a)

Blocking removable-media devices and write capabilities using a host-based security tool

b)

Developing mandatory training to educate employees about the removable media policy

c)

Monitoring large data transfer transactions in the firewall logs

d)

Implementing a group policy to block user access to system files

2.

A security analyst is using a recently released security advisory to review historical logs, looking for the specific activity that was outlined in the advisory. Which of the following is the analyst doing?

a)

Threat hunting

b)

A packet capture

c)

Credentialed vulnerability scanning

d)

A user behavior analysis

3.

A company recently experienced an attack in which a malicious actor was able to exfiltrate data by cracking stolen passwords, using a rainbow table of the sensitive data. Which of the following should a security engineer do to prevent such an attack in the future?

a)

Disable password reuse.

b)

Enforce password complexity.

c)

Implement password salting.

d)

Use password hashing.

4.

The IT department at a university is concerned about professors placing servers on the university network in an attempt to bypass security controls. Which of the following BEST represents this type of threat?

a)

Hacktivism

b)

A script kiddie

c)

Shadow IT

d)

White-hat

5.

Which of the following BEST describes a security exploit for which a vendor patch is not readily available?

a)

End of life

b)

Integer overflow

c)

Race condition

d)

Zero-day

6.

The Chief Financial Officer (CFO) of an insurance company received an email from Ann, the company's Chief Executive Officer (CEO), requesting a transfer of $10,000 to an account. The email states Ann is on vacation and has lost her purse, containing cash and credit cards. Which of the following social- engineering techniques is the attacker using?

a)

Pharming

b)

Whaling

c)

Typo squatting

d)

Phishing

7.

Joe, an employee, receives an email stating he won the lottery. The email includes a link that requests a name, mobile phone number, address, and date of birth be provided to confirm Joe's identity before sending him the prize. Which of the following BEST describes this type of email?

a)

Vishing

b)

Phishing

c)

  Spear phishing

d)

Whaling

8.

Which of the following refers to applications and systems that are used within an organization without consent or approval?

a)

OSINT

b)

  Dark web

c)

  Insider threats

d)

  Shadow IT

9.

A network administrator has been alerted that web pages are experiencing long load times. After determining it is not a routing or DNS issue, the administrator logs in to the router, runs a command, and receives the following output:

Which of the following is the router experiencing?

a)

Resource exhaustion

b)

Buffer overflow

c)

DDoS attack

d)

Memory leak

10.

A company has just experienced a malware attack affecting a large number of desktop users.

The antivirus solution was not able to block the malware, but the HIDS alerted to C2 calls as

'Troj.Generic'. Once the security team found a solution to remove the malware, they were able to remove the malware files successfully, and the HIDS stopped alerting. The next morning, however, the HIDS once again started alerting on the same desktops, and the security team discovered the files were back. Which of the following BEST describes the type of malware infecting this company's network?

a)

Spyware

b)

Trojan

c)

Rootkit

d)

Botnet

11.

A security administrator has received multiple calls from the help desk about customers who are unable to access the organization's web server. Upon reviewing the log files. The security administrator determines multiple open requests have been made from multiple IP addresses, which is consuming system resources. Which of the following attack types does this BEST describe?

a)

DoS

b)

DDoS

c)

Logic bomb

d)

Zero day

12.

Which of the following would MOST likely be a result of improperly configured user accounts?

a)

Resource exhaustion

b)

Privilege escalation

c)

Buffer overflow

d)

Session hijacking