Font size
WorksheetsSec+ Extra Study
Total questions: 23
Worksheet time: 29mins
A security analyst is receiving numerous alerts reporting that the response time of an internet-facing application has been degraded. However, the internal network performance was not degraded. Which of the following MOST likely explains this behavior?
DNS poisoning
MAC flooding
DDoS attack
ARP poisoning
Which of the following would BEST provide a systems administrator with the ability to more efficiently identify systems and manage permissions and policies based on location, role, and service level?
Standard naming conventions
Domain services
Baseline configurations
Diagrams
An administrator is experiencing issues when trying to upload a support file to a vendor. A pop-up message reveals that a payment card number was found in the file, and the file upload was mocked. Which of the following controls is most likely causing this issue and should be checked FIRST?
DLP
Firewall rule
Content filter
MDM
Application allow list
During a trial, a judge determined evidence gathered from a hard drive was not admissible. Which of the following BEST explains this reasoning?
The forensic investigator forgot to run a checksum on the disk image after creation.
The chain of custody form did not note time zone offsets between transportation regions.
The computer was turned off. and a RAM image could not be taken at the same time.
The hard drive was not properly kept in an antistatic bag when rt was moved.
A tax organization is working on a solution to validate the online submission of documents. The solution should be carried out on a portable USB device that should be inserted on any computer that is transmitting a transaction securely. Which of the following is the BEST certificate for these requirements?
User certificate
Self-signed certificate
Computer certificate
Root certificate
Which of the following will increase cryptographic security?
High data entropy
Algorithms that require less computing power
Longer key longevity
Hashing
A company needs to validate its updated incident response plan using a real-world scenario that will test decision points and relevant incident response actions without interrupting daily operations. Which of the following would BEST meet the company's requirements?
Red-team exercise
Capture-the-flag exercise
Tabletop exercise
Phishing exercise
A help desk technician receives a phone call from someone claiming to be a part of the organization's cybersecurity modem response team. The caller asks the technician to verify the network's internal firewall IP address. Which of the following is the technician's BEST course of action?
Direct the caller to stop by the help desk in person and hang up declining any further requests from the caller.
Ask for the callers name, verify the person's identity in the email directory and provide the requested information over the phone.
Write down the phone number of the caller if possible, the name of the person requesting the information, hang up. and notify the organization's cybersecurity officer.
Request the caller send an email for identity verification and provide the requested information via email to the caller.
During an incident response, an analyst applied rules to all inbound traffic on the border firewall and implemented ACLs on each critical server. Following an investigation, the company realizes it is still vulnerable because outbound traffic is not restricted and the adversary is able to maintain a presence in the network. In which of the following stages of the Cyber Kill Chain is the adversary currently operating?, and
Reconnaissance
Command and control
Actions on objective
Exploitation
Business partners are working on a security mechanism to validate transactions securely. The requirement is for one company to be responsible for deploying a trusted solution that will register and issue artifacts used to sign, encrypt, and decrypt transaction files. Which of the following is the BEST solution to adopt?
PKI
Blockchain
SAML
OAuth
A systems administrator reports degraded performance on a virtual server. The administrator increases the virtual memory allocation which improves conditions, but performance degrades again after a few days. The administrator runs an analysis tool and sees the following output:
==3214== timeAttend.exe analyzed
==3214== ERROR SUMMARY:
==3214== malloc/free: in use at exit: 4608 bytes in 18 blocks.
==3214== checked 82116 bytes
==3214== definitely lost: 4608 bytes in 18 blocks.
The administrator terminates the timeAttend.exe and observes system performance over the next few days, and notices that the system performance does not degrade. Which of the following issues is MOST likely occurring?
DLL injection
API attack
Buffer overflow
Memory leak
Which of the following describes the exploitation of an interactive process to gain access to restricted areas?
Persistence
Buffer overflow
Privilege escalation
Pharming
A junior security analyst is conducting an analysis after passwords were changed on multiple accounts without users' interaction. The SIEM have multiple login entries with the following text:
Which of the following is the MOST likely attack conducted on the environment?
Malicious script
Privilege escalation
Domain hijacking
DNS poisoning
A security analyst is investigating some users who are being redirected to a fake website that resembles www.comptia.org. The following output was found on the naming server of the organization:
Which of the following attacks has taken place?
Domain reputation
Domain hijacking
Disassociation
DNS poisoning
An organization wants to participate in threat intelligence information sharing with peer groups. Which of the following would MOST likely meet the organization's requirement?
Perform OSINT investigations
Subscribe to threat intelligence feeds
Submit RFCs
Implement a TAXII server
An IT manager is estimating the mobile device budget for the upcoming year. Over the last five years, the number of devices that were replaced due to loss, damage or theft steadily increased by 10%. Which of the following would BEST describe the estimated number of devices to be replaced next year?
ALE
ARO
RPO
SLE
Which of the following uses SAML for authentication?
TOTP
Federation
Kerberos
HOTP
While preparing a software Inventory report, a security analyst discovers an unauthorized program installed on most of the company's servers. The program utilizes the same code signing certificate as an application deployed to only the accounting team. Which of the following mitigations would BEST secure the server environment?
Revoke the code signing certificate used by both programs.
Block all unapproved file hashes from installation.
Add the accounting application file hash to the allowed list.
Update the code signing certificate for the approved application.
Which of the following supplies non-repudiation during a forensics investigation?
Dumping volatile memory contents first
Duplicating a drive with dd
Using a SHA-2 signature of a drive image
Logging everyone in contact with evidence
Encrypting sensitive data
An IT security manager requests a report on company information that is publicly available. The manager's concern is that malicious actors will be able to access the data without engaging in active reconnaissance. Which of the following is the MOST efficient approach to perform the analysis?
Provide a domain parameter to the Harvester tool.
Check public DNS entries using dnsenum.
Perform a vulnerability scan targeting a public company’s IP.
Execute nmap using the options: scan all ports and sneaky mode.
A security auditor is reviewing vulnerability scan data provided by an internal security team. Which of the following BEST indicates that valid credentials were used?
The scan results show open ports, protocols, and services exposed on the target host
The scan enumerated software versions of installed programs
The scan produced a list of vulnerabilities on the target host
The scan identified expired SSL certificates
A company has limited storage available and online presence that cannot for more than four hours. Which of the following backup methodologies should the company implement to allow for the FASTEST database restore time. In the event of a failure, which being mindful of the limited available storage space?
Implement full tape backup every Sunday at 8:00 p.m and perform nightly tape rotations.
Implement different backups every Sunday at 8:00 and nightly incremental backups at 8:00 p.m
Implement nightly full backups every Sunday at 8:00 p.m
Implement full backups every Sunday at 8:00 p.m and nightly differential backups at 8:00 pm
Which of the following will MOST likely adversely impact the operations of unpatched traditional programmable-logic controllers, running a back-end LAMP server and OT systems with human-management interfaces that are accessible over the Internet via a web interface? (Choose two.)
Cross-site scripting
SQL injection
Data exfiltration
Poor system logging
Weak encryption
