wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Sec+ Extra Study

Total questions: 23

Worksheet time: 29mins

Name
Class
Date
1.

A security analyst is receiving numerous alerts reporting that the response time of an internet-facing application has been degraded. However, the internal network performance was not degraded. Which of the following MOST likely explains this behavior?

a)

DNS poisoning

b)

MAC flooding

c)

DDoS attack

d)

ARP poisoning

2.

Which of the following would BEST provide a systems administrator with the ability to more efficiently identify systems and manage permissions and policies based on location, role, and service level?

a)

Standard naming conventions

b)

Domain services

c)

Baseline configurations

d)

Diagrams

3.

An administrator is experiencing issues when trying to upload a support file to a vendor. A pop-up message reveals that a payment card number was found in the file, and the file upload was mocked. Which of the following controls is most likely causing this issue and should be checked FIRST?

a)

DLP

b)

Firewall rule

c)

Content filter

d)

MDM

e)

Application allow list

4.

During a trial, a judge determined evidence gathered from a hard drive was not admissible. Which of the following BEST explains this reasoning?

a)

The forensic investigator forgot to run a checksum on the disk image after creation.

b)

The chain of custody form did not note time zone offsets between transportation regions.

c)

The computer was turned off. and a RAM image could not be taken at the same time.

d)

The hard drive was not properly kept in an antistatic bag when rt was moved.

5.

A tax organization is working on a solution to validate the online submission of documents. The solution should be carried out on a portable USB device that should be inserted on any computer that is transmitting a transaction securely. Which of the following is the BEST certificate for these requirements?

a)

User certificate

b)

Self-signed certificate

c)

Computer certificate

d)

Root certificate

6.

Which of the following will increase cryptographic security?

a)

High data entropy

b)

Algorithms that require less computing power

c)

Longer key longevity

d)

Hashing

7.

A company needs to validate its updated incident response plan using a real-world scenario that will test decision points and relevant incident response actions without interrupting daily operations. Which of the following would BEST meet the company's requirements?

a)

Red-team exercise

b)

Capture-the-flag exercise

c)

Tabletop exercise

d)

Phishing exercise

8.

A help desk technician receives a phone call from someone claiming to be a part of the organization's cybersecurity modem response team. The caller asks the technician to verify the network's internal firewall IP address. Which of the following is the technician's BEST course of action?

a)

Direct the caller to stop by the help desk in person and hang up declining any further requests from the caller.

b)

Ask for the callers name, verify the person's identity in the email directory and provide the requested information over the phone.

c)

Write down the phone number of the caller if possible, the name of the person requesting the information, hang up. and notify the organization's cybersecurity officer.

d)

Request the caller send an email for identity verification and provide the requested information via email to the caller.

9.

During an incident response, an analyst applied rules to all inbound traffic on the border firewall and implemented ACLs on each critical server. Following an investigation, the company realizes it is still vulnerable because outbound traffic is not restricted and the adversary is able to maintain a presence in the network. In which of the following stages of the Cyber Kill Chain is the adversary currently operating?, and

a)

Reconnaissance

b)

Command and control

c)

Actions on objective

d)

Exploitation

10.

Business partners are working on a security mechanism to validate transactions securely. The requirement is for one company to be responsible for deploying a trusted solution that will register and issue artifacts used to sign, encrypt, and decrypt transaction files. Which of the following is the BEST solution to adopt?

a)

PKI

b)

Blockchain

c)

SAML

d)

OAuth

11.

A systems administrator reports degraded performance on a virtual server. The administrator increases the virtual memory allocation which improves conditions, but performance degrades again after a few days. The administrator runs an analysis tool and sees the following output:

==3214== timeAttend.exe analyzed

==3214== ERROR SUMMARY:

==3214== malloc/free: in use at exit: 4608 bytes in 18 blocks.

==3214== checked 82116 bytes

==3214== definitely lost: 4608 bytes in 18 blocks.

The administrator terminates the timeAttend.exe and observes system performance over the next few days, and notices that the system performance does not degrade. Which of the following issues is MOST likely occurring?

a)

DLL injection

b)

API attack

c)

Buffer overflow

d)

Memory leak

12.

Which of the following describes the exploitation of an interactive process to gain access to restricted areas?

a)

Persistence

b)

Buffer overflow

c)

Privilege escalation

d)

Pharming

13.

A junior security analyst is conducting an analysis after passwords were changed on multiple accounts without users' interaction. The SIEM have multiple login entries with the following text:

Which of the following is the MOST likely attack conducted on the environment?

a)

Malicious script

b)

Privilege escalation

c)

Domain hijacking

d)

DNS poisoning

14.

A security analyst is investigating some users who are being redirected to a fake website that resembles www.comptia.org. The following output was found on the naming server of the organization:

Which of the following attacks has taken place?

a)

Domain reputation

b)

Domain hijacking

c)

Disassociation

d)

DNS poisoning

15.

An organization wants to participate in threat intelligence information sharing with peer groups. Which of the following would MOST likely meet the organization's requirement?

a)

Perform OSINT investigations

b)

Subscribe to threat intelligence feeds

c)

Submit RFCs

d)

Implement a TAXII server

16.

An IT manager is estimating the mobile device budget for the upcoming year. Over the last five years, the number of devices that were replaced due to loss, damage or theft steadily increased by 10%. Which of the following would BEST describe the estimated number of devices to be replaced next year?

a)

ALE

b)

ARO

c)

RPO

d)

SLE

17.

Which of the following uses SAML for authentication?

a)

TOTP

b)

Federation

c)

Kerberos

d)

HOTP

18.

While preparing a software Inventory report, a security analyst discovers an unauthorized program installed on most of the company's servers. The program utilizes the same code signing certificate as an application deployed to only the accounting team. Which of the following mitigations would BEST secure the server environment?

a)

Revoke the code signing certificate used by both programs.

b)

Block all unapproved file hashes from installation.

c)

Add the accounting application file hash to the allowed list.

d)

Update the code signing certificate for the approved application.

19.

Which of the following supplies non-repudiation during a forensics investigation?

a)

Dumping volatile memory contents first

b)

Duplicating a drive with dd

c)

Using a SHA-2 signature of a drive image

d)

Logging everyone in contact with evidence

e)

Encrypting sensitive data

20.

An IT security manager requests a report on company information that is publicly available. The manager's concern is that malicious actors will be able to access the data without engaging in active reconnaissance. Which of the following is the MOST efficient approach to perform the analysis?

a)

Provide a domain parameter to the Harvester tool.

b)

Check public DNS entries using dnsenum.

c)

Perform a vulnerability scan targeting a public company’s IP.

d)

Execute nmap using the options: scan all ports and sneaky mode.

21.

A security auditor is reviewing vulnerability scan data provided by an internal security team. Which of the following BEST indicates that valid credentials were used?

a)

The scan results show open ports, protocols, and services exposed on the target host

b)

The scan enumerated software versions of installed programs

c)

The scan produced a list of vulnerabilities on the target host

d)

The scan identified expired SSL certificates

22.

A company has limited storage available and online presence that cannot for more than four hours. Which of the following backup methodologies should the company implement to allow for the FASTEST database restore time. In the event of a failure, which being mindful of the limited available storage space?

a)

Implement full tape backup every Sunday at 8:00 p.m and perform nightly tape rotations.

b)

Implement different backups every Sunday at 8:00 and nightly incremental backups at 8:00 p.m

c)

Implement nightly full backups every Sunday at 8:00 p.m

d)

Implement full backups every Sunday at 8:00 p.m and nightly differential backups at 8:00 pm

23.

Which of the following will MOST likely adversely impact the operations of unpatched traditional programmable-logic controllers, running a back-end LAMP server and OT systems with human-management interfaces that are accessible over the Internet via a web interface? (Choose two.)

a)

Cross-site scripting

b)

SQL injection

c)

Data exfiltration

d)

Poor system logging

e)

Weak encryption