wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Security+ Study Guide-04 Securing Your Network

Total questions: 15

Worksheet time: 10mins

Name
Class
Date
1.

A HIDS reported a vulnerability on a system based on a known attack. After researching the alert from the HIDS, you identify the recommended solution and begin applying it.

What type of HIDS is in use?

a)

Network-based

b)

Signature-based

c)

Heuristic-based

d)

Anomaly-based

2.

You are preparing to deploy a heuristic-based detection system to monitor activity. Which of the following would you create first?

a)

BPDU guard

b)

Signatures

c)

Baseline

d)

Honeypot

3.

Lenny noticed a significant number of logon failures for administrator accounts on the organization's public website. After investigating it further, he notices that most of these attempts are from IP addresses assigned to foreign countries. He wants to implement a solution that will detect and prevent similar attacks.

Which of the following is the BEST choice?

a)

Implement a passive NIDS

b)

Block all traffic from foreign countries

c)

Implement an inline NIPS

d)

Disable the administrator accounts

4.

Lisa created a document called password.txt and put the usernames of two accounts with elevated privileges. She then placed the file on her administrator account desktop on several servers.

Which of the following BEST explains her actions?

a)

She can use this file to retrieve the passwords if she forgets them

b)

This file will divert attackers from the live network

c)

The document is a honeyfile

d)

The file is needed by an application to run when the system starts

5.

Your organization is planning to upgrade the wireless network used by employees. It will provide encrypted authentication of wireless users over TLS.

Which of the following protocols are the MOST likely implementing?

a)

EAP

b)

PEAP

c)

WPA2

d)

WPA3

6.

Lisa is creating a detailed diagram of wireless access points and hotspots within your organization. What is another name for this?

a)

Remote access VPN

b)

Wireless footprinting

c)

Channel overlap map

d)

Architectural diagram

7.

You are assisting a small business owner in setting up a public wireless for her customers. She wants to allow customers to access the hotspot without entering a password. Which of the following is the MOST appropriate for this hotspot?

a)

Use Open mode

b)

Use a PSK

c)

A Raspberry Pi device

d)

Rogue AP

e)

APT

8.

A network administrator routinely test the network looking for vulnerabilities. He recently discover a new access point set to open. After connecting to it, he found he was able to access network resources.

What is the BEST explanation for this device?

a)

Evil twin

b)

A Raspberry Pi device

c)

Rogue AP

d)

APT

9.

You are an administrator at a small organization. Homer contacted you today and reported the following:

* He logged on normally on Monday morning and accessed network shares.

* Later, when he tried to access the Internet, a pop-up window with the organization's wireless SSID prompted him to log on.

* After doing so, he could access the Internet but no longer had access to the network shares.

* Three days later, his bank notified him of suspicious activity on his account.

Which of the following indicates the MOST likely explanation for this activity?

a)

An evil twin

b)

A rogue access point

c)

A DDoS attack

d)

A captive portal

10.

Mobile users in your network report that they frequently lose connectivity with the wireless network on some days, but they don't have any problems on other days. You suspect this is due to an attack. Which of the following attacks is MOST likely to cause these symptoms?

a)

Wireless jamming attack

b)

IV attack

c)

Replay attack

d)

Bluesnarfing attack

11.

An attacker can access email contact lists on your smartphone.

What type of attack is this?

a)

Bluesnarfing

b)

Bluejacking

c)

Captive portal

d)

WPS

12.

Your organization plans to implement a connection between the main site and a remote office giving remote employees on-demand access to resources at headquarters. The chief information officer (CIO) wants to use the Internet for this connection.

Which of the following solutions will BEST support this requirement?

a)

Remote access VPN

b)

Site-to-site VPN

c)

Always-on VPN

d)

Full-tunnel VPN

e)

Split-tunnel VPN

13.

Your organization is allowing more employees to work from home, and they want to upgrade their VPN. Management wants to ensure that after a VPN client connects to the VPN server, all traffic from the VPN client is encrypted.

Which of the following would BEST meet this goal?

a)

Split tunnel

b)

Full tunnel

c)

IPsec using Tunnel mode

d)

IPsec using Transport mode

14.

An organization is hosting a VPN that employees are using while working from home. Management wants to ensure that all VPN clients are using up-to-date operating systems and antivirus software.

Which of the following would BEST meet this need?

a)

NAT

b)

NAC

c)

VLAN

d)

DMZ

15.

Your organization recently implemented a BYOD policy. However, management want to ensure that mobile devices meet minimum standards for security before they can access any network resources.

Which of the following would the NAC MOST likely use?

a)

Permanent

b)

Health

c)

RADIUS

d)

Agentless