wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Sec+ CH.2 Review Test

Total questions: 15

Worksheet time: 8mins

Name
Class
Date
1.

Your organization wants to identify biometric methods used for

identification. The requirements are:

1) Collect the data passively.

2) Bypass a formal enrollment process.

3) Avoid obvious methods that let the subject know data is being

collected.

Which of the following biometric methods BEST meet these requirements?

(Select TWO.)

a)

Fingerprint

b)

Retina

c)

Iris

d)

Facial

e)

Gait analysis

2.

Your organization recently updated an online application that employees

use to log on when working from home. Employees enter their username

and password into the application from their smartphone and the application

logs their location using GPS. Which type of authentication is being used?

a)

One-factor

b)

Dual-factor

c)

Something you are

d)

Something you have

3.

Management within your organization wants to add 2FA security for

users working from home. Additionally, management wants to ensure that

2FA passwords expire after 30 seconds. Which of the following choices

BEST meets this requirement?

a)

HOTP

b)

TOTP

c)

SMS

d)

Kerberos

4.

Management within your organization has decided to implement a

biometric solution for authentication into the data center. They have stated

that the biometric system needs to be highly accurate. Which of the

following provides the BEST indication of accuracy with a biometric

system?

a)

The lowest possible FRR

b)

The highest possible FAR

c)

The lowest possible CER

d)

The highest possible CER

5.

The Marvin Monroe Memorial Hospital was recently sued after removing

a kidney from the wrong patient. Hospital executives want to implement a

method that will reduce medical errors related to misidentifying patients.

They want to ensure medical personnel can identify a patient even if the

patient is unconscious. Which of the following would be the BEST

solution?

a)

Gait analysis

b)

Vein scans

c)

Retina scan

d)

Voice recognition

6.

Users regularly log on with a username and password. However,

management wants to add a second authentication factor for any users who

launch the gcga application. The method needs to be user-friendly and non-

disruptive. Which of the following will BEST meet these requirements?

a)

An authentication application

b)

TPM

c)

HSM

d)

Push notifications

7.

Your organization hires students during the summer for temporary help.

They need access to network resources, but only during working hours.

Management has stressed that it is critically important to safeguard trade

secrets and other confidential information. Which of the following account

management concepts would be MOST important to meet these goals?

a)

Account expiration

b)

Account lockout

c)

Time-of-day restrictions

d)

Password recovery

e)

Password history

8.

You need to provide a junior administrator with appropriate credentials to

rebuild a domain controller after it suffers a catastrophic failure. Of the

following choices, what type of account would BEST meet this need?

a)

User account

b)

Generic account

c)

Guest account

d)

Service account

9.

Lisa is reviewing an organization’s account management processes. She

wants to ensure that security log entries accurately report the identity of

personnel taking specific actions. Which of the following steps would

BEST meet this requirement?

a)

Implement generic accounts.

b)

Implement role-based privileges.

c)

Use an SSO solution.

d)

Remove all shared accounts.

10.

A recent security audit discovered several apparently dormant user

accounts. Although users could log on to the accounts, no one had logged

on to them for more than 60 days. You later discovered that these accounts

are for contractors who work approximately one week every quarter. Which

of the following is the BEST response to this situation?

a)

Remove the account expiration from the accounts.

b)

Delete the accounts.

c)

Reset the accounts.

d)

Disable the accounts.

11.

An administrator is implementing a network from scratch for a medical

office. The owners want to have strong authentication and authorization to

protect the privacy of data on all internal systems. They also want regular

employees to use only a single username and password for all network

access. Which of the following is the BEST choice to meet these needs?

a)

OpenID

b)

SAML

c)

Kerberos

d)

RADIUS

12.

Web developers in your organization are creating a web application that

will interact with other applications running on the Internet. They want their

application to receive user credentials from an app running on a trusted

partner’s web domain. Which of the following is the BEST choice to meet

this need?

a)

SSO 2

b)

SAML 2

c)

Kerberos 2

d)

RADIUS 4

13.

Artie has been working at Ziffcorp as an accountant. However, after a

disagreement with his boss, he decides to leave the company and gives a

two-week notice. He has a user account allowing him to access network

resources. Which of the following is the MOST appropriate step to take?

a)

Ensure his account is disabled when he announces that he will be

leaving the company.

b)

Immediately terminate his employment.

c)

Force him to take a mandatory vacation.

d)

Ensure his account is disabled during his exit interview.

14.

You administer access control for users in your organization. Some

departments have a high employee turnover, so you want to simplify

account administration. Which of the following is the BEST choice?

a)

User-assigned privileges

b)

Group-based privileges

c)

Domain-assigned privileges

d)

Network-assigned privileges

15.

An administrator needs to grant users access to different shares on file

servers based on their job functions. Which of the following access control

schemes would BEST meet this need?

a)

Discretionary access control

b)

Mandatory access control

c)

Role-based access control

d)

Rule-based access control