wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Chapter 5 (PART I) Securing Hosts and Data

Total questions: 47

Worksheet time: 47mins

Name
Class
Date
1.

Question #3: A technician needs to prevent data loss in a laboratory. The laboratory is not connected to any external networks.

Which of the following methods would BEST prevent the exfiltration of data? (Select TWO)

a)

A. VPN

b)

B. Drive encryption

c)

C. Network firewall

D. File level encryption

d)

E. USB blocker

e)

F. MFA

2.

Question #4: The Chief Executive Officer (CEO) of an organization would like staff members to have the flexibility to work from home anytime during business hours, incident during a pandemic or crisis. However, the CEO is concerned that some staff members may take advantage of the flexibility and work from high-risk countries while on holidays work to a third-party organization in another country. The Chief information Officer (CIO) believes the company can implement some basic to mitigate the majority of the risk.

Which of the following would be BEST to mitigate the CEO's concern? (Select TWO)

a)

A. Geolocation

b)

B. Time-of-day restrictions

c)

D. Certificates

d)

E. Tokens

F. Geotagging

e)

G. Role-based access controls

3.

Question #6: A security engineer needs to implement an MDM solution that complies with the corporate mobile device policy. The policy states that in order for mobile users to access corporate resources on their devices the following requirements must be met:

Mobile device OSs must be patched up to the latest release A screen lock must be enabled (passcode or biometric) Corporate data must be removed if the device is reported lost or stolen

Which of the following controls should the security engineer configure? (Select TWO)

a)

A. Containerization

b)

B. Storage segmentation

c)

C. Posturing

d)

D. Remote wipe

e)

E. Full-device encryption

G. Geofencing

4.

Question #7: A startup company is using multiple SaaS and IaaS platforms to stand up a corporate infrastructure and build out a customer - facing web application. Which of the following solutions would be BEST to provide security, manageability, and visibility into the platforms?

a)

SIEM

b)

DLP

c)

CASB

d)

SWG

5.

Question #8: An enterprise needs to keep cryptographic keys in a safe manner.

Which of the following network appliances can achieve this goal?

a)

HSM

b)

CASB

c)

TPM

d)

DLP

6.

Question #9: A company recently transitioned to a strictly BYOD culture due to the cost of replacing lost or damaged corporate-owned mobile devices. Which of the following technologies would be BEST to balance the BYOD culture while also protecting the company’s data?

a)

Containerization

b)

Geofencing

c)

Full-disk encryption

d)

Remote wipe

7.

Question #10: Which of the following distributes data among nodes, making it more difficult to manipulate the data while also minimizing downtime?

a)

MSSP

b)

Public cloud

c)

Hybrid cloud

d)

Fog computing

8.

Question #11: A security audit has revealed that a process control terminal is vulnerable to malicious users installing and executing software on the system. The terminal is beyond end-of-life support and cannot be upgraded, so it is placed on a projected network segment. Which of the following would be MOST effective to implement to further mitigate the reported vulnerability?

a)

DNS sinkholding

b)

DLP rules on the terminal

c)

An IP blacklist

d)

Application whitelisting

9.

Question #12: A nationwide company is experiencing unauthorized logins at all hours of the day. The logins appear to originate from countries in which the company has no employees. Which of the following controls should the company consider using as part of its IAM strategy? (Select TWO)

a)

A. A complex password policy

b)

B. Geolocation

c)

C. An impossible travel policy

d)

D. Self-service password reset

e)

E. Geofencing

F. Time-based logins

10.

Question #13: A company is adopting a BYOD policy and is looking for a comprehensive solution to protect company information on user devices. Which of the following solutions would BEST support the policy?

a)

Mobile device management

b)

Full-device encryption

c)

Remote wipe

d)

Biometrics

11.

Question #14: A company provides mobile devices to its users to permit access to email and enterprise applications. The company recently started allowing users to select from several different vendors and device models. When configuring the MDM, which of the following is a key security implication of this heterogeneous device approach?

a)

The most common set of MDM configurations will become the effective set of enterprise mobile security controls.

b)

All devices will need to support SCEP-based enrollment; therefore, the heterogeneity of the chosen architecture may unnecessarily expose private keys to adversaries.

c)

Certain devices are inherently less secure than others, so compensatory controls will be needed to address the delta between device vendors.

d)

MDMs typically will not support heterogeneous deployment environments, so multiple MDMs will need to be installed and configured.

12.

Question #15: A major clothing company recently lost a large amount of proprietary information. The security officer must find a solution to ensure this never happens again. Which of the following is the BEST technical implementation to prevent this from happening again?

a)

Configure DLP solutions

b)

Disable peer-to-peer sharing.

c)

Enable role-based access controls

d)

Mandate job rotation.

e)

Implement content filters

13.

Question #16: A company is implementing MFA for all applications that store sensitive data. The IT manager wants MFA to be non-disruptive and user friendly. Which of the following technologies should the IT manager use when implementing MFA?

a)

One-time passwords

b)

Email tokens

c)

Push notifications

d)

Hardware authentication

14.

Question #17: Which of the following would BEST identify and remediate a data-loss event in an enterprise using third-party, web-based services and filesharing platforms?

a)

SIEM

b)

CASB

c)

UTM

d)

DLP

15.

Question #18: To secure an application after a large data breach, an e-commerce site will be resetting all users’ credentials. Which of the following will BEST ensure the site’s users are not compromised after the reset?

a)

A password reuse policy

b)

Account lockout after three failed attempts

c)

Encrypted credentials in transit

d)

A geofencing policy based on login history

16.

Question #19: An organization recently recovered from a data breach. During the root cause analysis, the organization determined the source of the breach to be a personal cell phone that had been reported lost. Which of the following solutions should the organization implement to reduce the likelihood of future data breaches?

a)

MDM

b)

MAM

c)

VDI

d)

DLP

17.

Question #20: The lessons-learned analysis from a recent incident reveals that an administrative office worker received a call from someone claiming to be from technical support. The caller convinced the office worker to visit a website, and then download and install a program masquerading as an antivirus package. The program was actually a backdoor that an attacker could later use to remote control the worker's PC. Which of the following would be BEST to help prevent this type of attack in the future?

a)

Data loss prevention

b)

Segmentation

c)

Application whitelisting

d)

Quarantine

18.

Question #21: An organization has decided to host its web application and database in the cloud. Which of the following BEST describes the security concerns for this decision?

a)

Access to the organization's servers could be exposed to other cloudprovider clients

b)

The cloud vendor is a new attack vector within the supply chain

c)

Outsourcing the code development adds risk to the cloud provider

d)

Vendor support will cease when the hosting platforms reach EOL.

19.

Question #22: A company has drafted an insider- threat policy that prohibits the use of external storage devices. Which of the following would BEST protect the company from data exfiltration via removable media?

a)

Monitoring large data transfer transactions in the firewall logs

b)

Developing mandatory training to educate employees about the removable media policy

c)

Implementing a group policy to block user access to system files

d)

Blocking removable-media devices and write capabilities using a hostbased security tool

20.

Question #23: Which of the following is a risk that is specifically associated with hosting applications in the public cloud?

a)

Unsecured root accounts

b)

Zero day

c)

Shared tenancy

d)

Insider threat

21.

Question #24: Which of the following cloud models provides clients with servers, storage, and networks but nothing else?

a)

SaaS

b)

PaaS

c)

IaaS

d)

DaaS

22.

Question #26: A company has decided to move its operations to the cloud. It wants to utilize technology that will prevent users from downloading company applications for personal use, restrict data that is uploaded, and have visibility into which applications are being used across the company. Which of the following solutions will BEST meet these requirements?

a)

An NGFW

b)

A CASB

c)

Application whitelisting

d)

An NG-SWG

23.

Question #27: A Chief Executive Officer (CEO) is dissatisfied with the level of service from the company's new service provider. The service provider is preventing the CEO from sending email from a work account to a personal account. Which of the following types of service providers is being used?

a)

Telecommunications service provider

b)

Cloud service provider

c)

Master managed service provider

d)

Managed security service provider

24.

Question #28: After installing a Windows server, a cybersecurity administrator needs to harden it, following security best practices. Which of the following will achieve the administrator's goal?

(Select TWO)

a)

Disabling guest accounts

b)

Disabling service accounts

c)

Enabling network sharing

d)

Disabling NetBIOS over TCP/IP

e)

Storing LAN manager hash values

Enabling NTLM

25.

Question #29: A security analyst needs to implement security features across smartphones, laptops, and tablets. Which of the following would be the MOST effective across heterogeneous platforms?

a)

Enforcing encryption

b)

Deploying GPOs

c)

Removing administrative permissions

d)

Applying MDM software

26.

Question #30: A company just implemented a new telework policy that allows employees to use personal devices for official email and file sharing while working from home. Some of the requirements are:

Employees must provide an alternate work location (i.e., a home address)

Employees must install software on the device that will prevent the loss of proprietary data but will not restrict any other software from being installed.

Which of the following BEST describes the MDM options the company is using?

a)

Geofencing, content management, remote wipe, containerization, and storage segmentation

b)

Content management, remote wipe, geolocation, context-aware authentication, and containerization

c)

Application management, remote wipe, geofencing, context-aware authentication, and containerization

d)

Remote wipe, geolocation, screen locks, storage segmentation, and full-device encryption

27.

Question #31: Which of the following describes the ability of code to target a hypervisor from inside?

a)

Fog computing

b)

VM escape

c)

Software-defined networking

d)

Image forgery

e)

Container breakout

28.

Question #32: A Chief Security Officer (CSO) was notified that a customer was able to access confidential internal company files on a commonly used file-sharing service. The file-sharing service is the same one used by company staff as one of its approved third-party applications. After further investigation, the security team determines the sharing of confidential files was accidental and not malicious. However, the CSO wants to implement changes to minimize this type of incident from reoccurring but does not want to impact existing business processes. Which of the following would BEST meet the CSO's objectives?

a)

DLP

b)

SWG

c)

CASB

d)

Virtual network segmentation

e)

Container security

29.

Question #33: A user wanted to catch up on some work over the weekend but had issues logging in to the corporate network using a VPN. On Monday, the user opened a ticket for this issue but was able to log in successfully. Which of the following BEST describes the policy that is being implemented?

a)

Time-based logins

b)

Geofencing

c)

Network location

d)

Password history

30.

Question #34: An engineer is setting up a VDI environment for a factory location, and the business wants to deploy a low- cost solution to enable users on the shop floor to log in to the VDI environment directly. Which of the following should the engineer select to meet these requirements?

a)

Laptops

b)

Containers

c)

Thin clients

d)

Workstations

31.

Question #35: An organization has a growing workforce that is mostly driven by additions to the sales department. Each newly hired salesperson relies on a mobile device to conduct business. The Chief Information Officer (CIO) is wondering if the organization may need to scale down just as quickly as it scaled up. The ClO is also concerned about the organization's security and customer privacy. Which of the following would be BEST to address the ClO’s concerns?

a)

Disallow new hires from using mobile devices for six months

b)

Select four devices for the sales department to use in a CYOD model

c)

Implement BYOD for the sales department while leveraging the MDM

d)

Deploy mobile devices using the COPE methodology

32.

Question #36: A cybersecurity administrator has a reduced team and needs to operate an on-premises network and security infrastructure efficiently. To help with the situation, the administrator decides to hire a service provider. Which of the following should the administrator use?

a)

SDP

b)

AAA

c)

IaaS

d)

MSSP

e)

Microservices

33.

Question #37: A Chief Security Officer (CSO) is concerned about the amount of PII that is stored locally on each salesperson’s laptop. The sales department has a higher-than-average rate of lost equipment. Which of the following recommendations would BEST address the CSO’s concern?

a)

Deploy an MDM solution

b)

Implement managed FDE

c)

Replace all hard drives with SEDs

d)

Install DLP agents on each laptop

34.

Question #38: An organization has implemented a policy requiring the use of conductive metal lockboxes for personal electronic devices outside of a secure research lab. Which of the following did the organization determine to be the GREATEST risk to intellectual property when creating this policy?

a)

The theft of portable electronic devices

b)

Geotagging in the metadata of images

c)

Bluesnarfing of mobile devices

d)

Data exfiltration over a mobile hotspot

35.

Question #43: A company recently experienced a data breach and the source was determined to be an executive who was charging a phone in a public area. Which of the following would MOST likely have prevented this breach?

a)

A firewall

b)

A device pin

c)

A USB data blocker

d)

Biometrics

36.

Question #44: A startup company is using multiple SaaS and IaaS platforms to stand up a corporate infrastructure and build out a customer - facing web application. Which of the following solutions would be BEST to provide security, manageability, and visibility into the platforms?

a)

SIEM

b)

DLP

c)

CASB

d)

SWG

37.

Question #45: Which of the following technical controls is BEST suited for the detection and prevention of buffer overflows on hosts?

a)

DLP

b)

HIDS

c)

EDR

d)

NIPS

38.

Question #46: During a security assessment, a security finds a file with overly permissive permissions. Which of the following tools will allow the analyst to reduce the permission for the existing users and groups and remove the set-user-ID from the file?

a)

1a

b)

chflags

c)

chmod

d)

leof

e)

setuid

39.

Question #47: A network administrator is concerned about users being exposed to malicious content when accessing company cloud applications. The administrator wants to be able to block access to sites based on the AUP. The users must also be protected because many of them work from home or at remote locations, providing on-site customer support. Which of the following should the administrator employ to meet these criteria?

a)

Implement NAC

b)

Implement an SWG

c)

Implement a URL filter

d)

Implement an MDM

40.

Question #48: A RAT that was used to compromise an organization’s banking credentials was found on a user’s computer. The RAT evaded antivirus detection. It was installed by a user who has local administrator rights to the system as part of a remote management tool set. Which of the following recommendations would BEST prevent this from reoccurring?

a)

Create a new acceptable use policy.

b)

Segment the network into trusted and untrusted zones.

c)

Enforce application whitelisting.

d)

Implement DLP at the network boundary.

41.

Question #49: A security administrator needs to inspect in-transit files on the enterprise network to search for PII, credit card data, and classification words. Which of the following would be the BEST to use?

a)

IDS solution

b)

EDR solution

c)

HIPS software solution

d)

Network DLP solution

42.

Question #50: To reduce costs and overhead, an organization wants to move from an on -premises email solution to a cloud-based email solution. At this time, no other services will be moving. Which of the following cloud models would BEST meet the needs of the organization?

a)

MaaS

b)

laaS

c)

SaaS

d)

PaaS

43.

Question #51: A pharmaceutical sales representative logs on to a laptop and connects to the public WiFi to check emails and update reports. Which of the following would be BEST to prevent other devices on the network from directly accessing the laptop? (Choose two)

a)

A. Trusted Platform Module

b)

B. A host-based firewall

c)

C. A DLP solution

D. Full disk encryption

d)

E. A VPN

e)

F. Antivirus software

44.

Question #52: An organization with a low tolerance for user inconvenience wants to protect laptop hard drives against loss or data theft. Which of the following would be the MOST acceptable?

a)

SED

b)

HSM

c)

DLP

d)

TPM

45.

Question #53: A desktop support technician recently installed a new document-scanning software program on a computer. However, when the end user tried to launch the program, it did not respond. Which of the following is MOST likely the cause?

a)

A new firewall rule is needed to access the application.

b)

The system was quarantined for missing software updates

c)

The software was not added to the application whitelist.

d)

The system was isolated from the network due to infected software.

46.

Question #54: A security analyst has received an alert about PII being sent via email. The analyst’s Chief information Security Officer (CISO) has made it clear that PII must be handled with extreme care from which of the following did the alert MOST likely originate?

a)

S/MIME

b)

DLP

c)

IMAP

d)

HIDS

47.

Question #55: Users have been issued smart cards that provide physical access to a building. The cards also contain tokens that can be used to access information systems. Users can login to any thin client located throughout the building and see the same desktop each time. Which of the following technologies are being utilized to provide these capabilities? (Select TWO)

a)

A. COPE

b)

B. VDI

c)

C. GPS

D. TOTP

d)

E. RFID

e)

F. BYOD