wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Sec+ Quiz - 2

Total questions: 15

Worksheet time: 16mins

Name
Class
Date
1.

An organization has developed an application that needs a patch to fix a critical vulnerability. In which of the following environments should the patch be deployed LAST?

a)

Test

b)

Staging

c)

Development

d)

Production

2.

Which of the following is the MOST effective control against zero-day vulnerabilities?

a)

Network segmentation

b)

Patch management

c)

Intrusion prevention system

d)

Multiple vulnerability scanners

3.

An engineer wants to inspect traffic to a cluster of web servers in a cloud environment. Which of the following solutions should the engineer implement?

a)

Proxy server

b)

WAF

c)

Load balancer

d)

VPN

4.

A Chief Information Security Officer has defined resiliency requirements for a new data center architecture. The requirements are as follows:

• Critical file shares will remain accessible during and after a natural disaster.

• Five percent of hard disks can fail at any given time without impacting the data.

• Systems will be forced to shut down gracefully when battery levels are below 20%.

Which of the following are required to BEST meet these objectives? (Select THREE)

a)

UPS

b)

RAID

c)

Geographic dispersal

d)

Redundant power supplies

e)

Fiber switching

5.

Which of the following actions would be recommended to improve an incident response process?

a)

Train the team to identify the difference between events and incidents

b)

Modify access so the IT team has full access to the compromised assets

c)

Contact the authorities if a cybercrime is suspected

d)

Restrict communication surrounding the response to the IT team

6.

A security proposal was set up to track requests for remote access by creating a baseline of the users' common sign-in properties. When a baseline deviation is detected, an MFA challenge will be triggered. Which of the following should be configured in order to deploy the proposal?

a)

Context-aware authentication

b)

Simultaneous authentication of equals

c)

Extensive authentication protocol EAP

d)

Agentless network access control

7.

An administrator needs to protect user passwords and has been advised to hash the passwords. Which of the following BEST describes what the administrator is being advised to do?

a)

Perform a mathematical operation on the passwords that will convert them into vague strings.

b)

Add extra data to the passwords so their length is increased, making them harder to brute force.

c)

Store all passwords in the system in a rainbow table that has a centralized location.

d)

Enforce the use of one-time passwords that are changed for every login session.

8.

A database administrator wants to grant access to an application that will be reading and writing data to a database. The database is shared by other applications also used by the finance department. Which of the following account types is MOST appropriate for this purpose?

a)

Service

b)

Shared

c)

Generic

d)

Admin

9.

A security analyst is receiving numerous alerts reporting that the response time of an internet-facing application has been degraded. However, the internal network performance was not degraded. Which of the following MOST likely explains this behavior?

a)

DNS poisoning

b)

MAC flooding

c)

DDoS attack

d)

ARP poisoning

10.

The Chief Information Security Officer directed a risk reduction in shadow IT and created a policy requiring all unsanctioned high-risk SaaS applications to be blocked from user access. Which of the following is the BEST security solution to reduce this risk?

a)

CASB

b)

VPN concentrator

c)

MFA

d)

VPC endpoint

11.

An organization discovered files with proprietary financial data have been deleted. The files have been recovered from backup but every time the Chief Financial Officer logs in to the file server, the same files are deleted again. No other users are experiencing this issue. Which of the following types of malware is MOST likely causing this behavior?

a)

Logic bomb

b)

Crypto malware

c)

Spyware

d)

Remote access Trojan

12.

A security analyst is working on a project to implement a solution that monitors network communications and provides alerts when abnormal behavior is detected. Which of the following is the security analyst MOST likely implementing?

a)

Vulnerability scans

b)

User behavior analysis

c)

Security orchestration, automation, and response

d)

Threat hunting

13.

Which of the following would BEST provide a systems administrator with the ability to more efficiently identify systems and manage permissions and policies based on location, role, and service level?

a)

Standard naming conventions

b)

Domain services

c)

Baseline configurations

d)

Diagrams

14.

A security incident has been resolved. Which of the following BEST describes the importance of the final phase of the incident response plan?

a)

It examines and documents how well the team responded discovers what caused the incident, and determines how the incident can be avoided in the future

b)

It returns the affected systems back into production once systems have been fully patched, data restored and vulnerabilities addressed

c)

It identifies the incident and the scope of the breach how it affects the production environment, and the ingress point

d)

It contains the affected systems and disconnects them from the network, preventing further spread of the attack or breach

15.

How is everything going?

a)
b)
c)
d)