NEW
Font size
WorksheetsSec+ Domain 1.1
Total questions: 12
Worksheet time: 16mins
A company has drafted an insider-threat policy that prohibits the use of external storage devices. Which of the following would BEST protect the company from data exfiltration via removable media?
Blocking removable-media devices and write capabilities using a host-based security tool
Developing mandatory training to educate employees about the removable media policy
Monitoring large data transfer transactions in the firewall logs
Implementing a group policy to block user access to system files
A security analyst is using a recently released security advisory to review historical logs, looking for the specific activity that was outlined in the advisory. Which of the following is the analyst doing?
Threat hunting
A packet capture
Credentialed vulnerability scanning
A user behavior analysis
A company recently experienced an attack in which a malicious actor was able to exfiltrate data by cracking stolen passwords, using a rainbow table of the sensitive data. Which of the following should a security engineer do to prevent such an attack in the future?
Disable password reuse.
Enforce password complexity.
Implement password salting.
Use password hashing.
The IT department at a university is concerned about professors placing servers on the university network in an attempt to bypass security controls. Which of the following BEST represents this type of threat?
Hacktivism
A script kiddie
Shadow IT
White-hat
Which of the following BEST describes a security exploit for which a vendor patch is not readily available?
End of life
Integer overflow
Race condition
Zero-day
The Chief Financial Officer (CFO) of an insurance company received an email from Ann, the company's Chief Executive Officer (CEO), requesting a transfer of $10,000 to an account. The email states Ann is on vacation and has lost her purse, containing cash and credit cards. Which of the following social- engineering techniques is the attacker using?
Pharming
Whaling
Typo squatting
Phishing
Joe, an employee, receives an email stating he won the lottery. The email includes a link that requests a name, mobile phone number, address, and date of birth be provided to confirm Joe's identity before sending him the prize. Which of the following BEST describes this type of email?
Vishing
Phishing
Spear phishing
Whaling
Which of the following refers to applications and systems that are used within an organization without consent or approval?
OSINT
Dark web
Insider threats
Shadow IT
A network administrator has been alerted that web pages are experiencing long load times. After determining it is not a routing or DNS issue, the administrator logs in to the router, runs a command, and receives the following output:
Which of the following is the router experiencing?
Resource exhaustion
Buffer overflow
DDoS attack
Memory leak
A company has just experienced a malware attack affecting a large number of desktop users.
The antivirus solution was not able to block the malware, but the HIDS alerted to C2 calls as
'Troj.Generic'. Once the security team found a solution to remove the malware, they were able to remove the malware files successfully, and the HIDS stopped alerting. The next morning, however, the HIDS once again started alerting on the same desktops, and the security team discovered the files were back. Which of the following BEST describes the type of malware infecting this company's network?
Spyware
Trojan
Rootkit
Botnet
A security administrator has received multiple calls from the help desk about customers who are unable to access the organization's web server. Upon reviewing the log files. The security administrator determines multiple open requests have been made from multiple IP addresses, which is consuming system resources. Which of the following attack types does this BEST describe?
DoS
DDoS
Logic bomb
Zero day
Which of the following would MOST likely be a result of improperly configured user accounts?
Resource exhaustion
Privilege escalation
Buffer overflow
Session hijacking
