wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Sec+ Quiz - 1

Total questions: 15

Worksheet time: 15mins

Name
Class
Date
1.

An organization is migrating several SaaS applications that support SSO. The security manager wants to ensure the migration is completed securely. Which of the following should the organization consider before implementation? (Select TWO).

a)

The hashing method

b)

The encryption method

c)

The registration authority

d)

The certificate authority

e)

The back-end directory source

2.

A user is attempting to navigate to a website from inside the company network using a desktop. When the user types in the URL. https://www.site.com, the user is presented with a certificate mismatch warning from the browser. The user does not receive a warning when visiting http://www.anothersite.com. Which of the following describes this attack?

a)

On-path

b)

Domain hijacking

c)

DNS poisoning

d)

Evil twin

3.

A systems administrator is troubleshooting a server's connection to an internal web server. The administrator needs to determine the correct ports to use. Which of the following tools BEST shows which ports on the web server are in a listening state?

a)

Netstat

b)

Ping

c)

ssh

d)

Ipconfig

4.

The Chief Information Security Officer (CISO) requested a report on potential areas of improvement following a security incident. Which of the following incident response processes is the CISO requesting?

a)

Lessons learned

b)

Preparation

c)

Detection

d)

Containment

e)

Root cause analysis

5.

A security analyst was called to investigate a file received directly from a hardware manufacturer. The analyst is trying to determine whether it is modified in transit before installation on the user's computer. Which of the following can be used to safely assess the file?

a)

Check the hash of the installation file

b)

Match the file names

c)

Verify the URL download location

d)

Verify the code-signing certificate

6.

An employee received a word processing file that was delivered as an email attachment. The subject line and email content enticed the employee to open the attachment. Which of the following attack vectors BEST matches this malware?

a)

Embedded Python code

b)

Macro-enabled file

c)

Bash scripting

d)

Credential-harvesting website

7.

A security forensics analyst is examining a virtual server. The analyst wants to preserve the present state of the virtual server, including memory contents. Which of the following backup types should be used?

a)

Snapshot

b)

Differential

c)

Cloud

d)

Full

e)

Incremental

8.

Two organizations plan to collaborate on the evaluation of new SIEM solutions for their respective companies. A combined effort from both organizations' SOC teams would speed up the effort. Which of the following can be written to document this agreement?

a)

MOU

b)

ISA

c)

SLA

d)

NDA

9.

A cloud service provider has created an environment where customers can connect existing local networks to the cloud for additional computing resources and block internal HR applications from reaching the cloud. Which of the following cloud models is being used?

a)

Public

b)

Community

c)

Hybrid

d)

Private

10.

A social media company based in North America is looking to expand into new global markets and needs to maintain compliance with international standards. With which of the following is the company's data protection officer MOST likely concerned?

a)

NIST Framework

b)

ISO 27001

c)

GDPR

d)

PCI-DSS

11.

A company recently experienced a significant data loss when proprietary Information was leaked to a competitor. The company took special precautions by using proper labels; however, email filter logs do not have any record of the incident. An Investigation confirmed the corporate network was not breached, but documents were downloaded from an employee's COPE tablet and passed to the competitor via cloud storage. Which of the following is the BEST mitigation strategy to prevent this from happening in the future?

a)

User training

b)

CASB

c)

MDM

d)

DLP

12.

A company is implementing a DLP solution on the file server. The file server has PII. financial information, and health information stored on it. Depending on what type of data that is hosted on the file server, the company wants different DLP rules assigned to the data. Which of the following should the company do to help accomplish this goal?

a)

Classify the data

b)

Mask the data

c)

Assign an application owner

d)

Perform a risk analysis

13.

Which of the following control types is focused primarily on reducing risk before an incident occurs?

a)

Preventive

b)

Deterrent

c)

Corrective

d)

Detective

14.

A routine audit of medical billing claims revealed that several claims were submitted without the subscriber's knowledge. A review of the audit logs for the medical billing company's system indicated a company employee downloaded customer records and adjusted the direct deposit information to a personal bank account. Which of the following does this action describe?

a)

Insider threat

b)

Social engineering

c)

Third-party risk

d)

Data breach

15.

After a recent security breach a security analyst reports that several administrative usernames and passwords are being sent via cleartext across the network to access network devices over port 23. Which of the following should be implemented so all credentials sent over the network are encrypted when remotely accessing and configuring network devices?

a)

SSH

b)

SNMPv3

c)

FTP

d)

Telnet

e)

SFTP