Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

MSSR-PRCT-SC+_A

Total questions: 108

Worksheet time: 57mins

Name
Class
Date
1.

Attacker obtains bank account number

and birth date by calling the victim

a)

Vishing

b)

Spoofing

c)

On-path

d)

DDoS

e)

Hoax

2.

Attacker modifies a legitimate DNS server to resolve

the IP address of a malicious site

a)

Vishing

b)

Spoofing

c)

On-path

d)

DDoS

e)

Hoax

3.

Attacker intercepts all communication between

a client and a web server

a)

Vishing

b)

Spoofing

c)

On-path

d)

DDoS

e)

Hoax

4.

Multiple attackers

overwhelm a web server

a)

Vishing

b)

Spoofing

c)

On-path

d)

DDoS

e)

Hoax

5.

A virus alert appears in your browser from Microsoft

with a phone number to call for support

a)

Vishing

b)

Spoofing

c)

On-path

d)

DDoS

e)

Hoax

6.

The security team at a local public library system is creating a set of

minimum security standards for the various computer systems.

Select the BEST security control for each available placeholder.

Location:

Library

Web Server and

Database Server

Description:

Computer Room

High security

Choose 3.

a)

Locking Cabinets

b)

Environmental Sensors

c)

Video Surveillance

d)

Full-Disk Encryption

e)

Biometric Reader

7.

The security team at a local public library system is creating a set of

minimum security standards for the various computer systems.

Select the BEST security control for each available placeholder.

Location:

Library

Employee

Laptops

Description:

Offsite use

Contains PII

Choose 2.

a)

Locking Cabinets

b)

Environmental Sensors

c)

Video Surveillance

d)

Full-Disk Encryption

e)

Biometric Reader

8.

The security team at a local public library system is creating a set of

minimum security standards for the various computer systems.

Select the BEST security control for each available placeholder.

Location:

Library

Lending

Systems

Description:

Manages the check-in

and check-out process

Choose 1.

a)

Locking Cabinets

b)

Smart Card

c)

Video Surveillance

d)

Full-Disk Encryption

e)

Biometric Reader

9.

The security team at a local public library system is creating a set of

minimum security standards for the various computer systems.

Select the BEST security control for each available placeholder.

Location:

Digital Newspaper

Reading Lab

Description:

Open Area

No supervision

Laptop computers

Choose 1.

a)

Locking Cabinets

b)

Smart Card

c)

Video Surveillance

d)

Full-Disk Encryption

e)

Cable Lock

10.

Choose the BEST secure network protocol

for the description:

Accept customer purchases from your primary website

a)

HTTPS

b)

NTPsec

c)

SRTP

d)

SNMPv3

e)

SSH

11.

Choose the BEST secure network protocol

for the description:

Synchronize the time across all of your devices

a)

HTTPS

b)

NTPsec

c)

SRTP

d)

SNMPv3

e)

SSH

12.

Choose the BEST secure network protocol

for the description:

Access your switch using a CLI terminal screen

a)

HTTPS

b)

NTPsec

c)

SRTP

d)

SNMPv3

e)

SSH

13.

Choose the BEST secure network protocol

for the description:

Talk with customers on scheduled conference calls

a)

HTTPS

b)

NTPsec

c)

SRTP

d)

SNMPv3

e)

SSH

14.

Choose the BEST secure network protocol

for the description:

Gather metrics from routers at remote sites

a)

HTTPS

b)

NTPsec

c)

SRTP

d)

SNMPv3

e)

SSH

15.

Match the appropriate authentication reference (Authentication Factor) to each description.

Each authentication factor or attribute will be used once.

Description:

During the login process, your phone receives a

text message with a one-time passcode

a)

Something you can do

b)

Somewhere you are

c)

Something you have

d)

Something you know

e)

Something you are

16.

Match the appropriate authentication reference (Authentication Factor) to each description.

Each authentication factor or attribute will be used once.

Description:

You enter your PIN to make

a deposit into an ATM

a)

Something you can do

b)

Somewhere you are

c)

Something you have

d)

Something you know

e)

Something you are

17.

Match the appropriate authentication reference (Authentication Factor) to each description.

Each authentication factor or attribute will be used once.

Description:

You must sign a check-in sheet

before entering a controlled area

a)

Something you can do

b)

Somewhere you are

c)

Something you have

d)

Something you know

e)

Something you are

18.

Match the appropriate authentication reference (Authentication Factor) to each description.

Each authentication factor or attribute will be used once.

Description:

You can use your ngerprint to unlock

the door to the data center

a)

Something you can do

b)

Somewhere you are

c)

Something you have

d)

Something you know

e)

Something you are

19.

Match the appropriate authentication reference (Authentication Factor) to each description.

Each authentication factor or attribute will be used once.

Description:

Your login will not work unless you are

connected to the VPN

a)

Something you can do

b)

Somewhere you are

c)

Something you have

d)

Something you know

e)

Something you are

20.

Configure the following stateful firewall rules:

• Allow the Web Server to access the Database Server using LDAP

Choose the correct answer (Source IP/Destination IP/Protocol[TCP/UDP]/Port #/Allow or Block)

a)

Source: 10.1.1.2 / Destination: 10.2.1.20/ Protocol: TCP / Port 389 / Allow

b)

Source: 10.2.1.33 / Destination: 10.1.1.7/ Protocol: TCP / Port 443 / Allow

c)

Source: 10.2.1.47 / Destination: 10.1.1.3/ Protocol: TCP / Port 22 / Allow

21.

Configure the following stateful firewall rules:

• Allow the Storage Server to transfer files to the Video Server

over HTTPS

Choose the correct answer (Source IP/Destination IP/Protocol[TCP/UDP]/Port #/Allow or Block)

a)

Source: 10.1.1.2 / Destination: 10.2.1.20/ Protocol: TCP / Port 389 / Allow

b)

Source: 10.2.1.33 / Destination: 10.1.1.7/ Protocol: TCP / Port 443 / Allow

c)

Source: 10.2.1.47 / Destination: 10.1.1.3/ Protocol: TCP / Port 22 / Allow

22.

Configure the following stateful firewall rules:

• Allow the Management Server to use a secure terminal on the

File Server

Choose the correct answer (Source IP/Destination IP/Protocol[TCP/UDP]/Port #/Allow or Block)

a)

Source: 10.1.1.2 / Destination: 10.2.1.20/ Protocol: TCP / Port 389 / Allow

b)

Source: 10.2.1.33 / Destination: 10.1.1.7/ Protocol: TCP / Port 443 / Allow

c)

Source: 10.2.1.47 / Destination: 10.1.1.3/ Protocol: TCP / Port 22 / Allow

23.

You’ve hired a third-party to gather information about your company’s

servers and data. The third-party will not have direct access to your

internal network but can gather information from any other source.

Which of the following would BEST describe this approach?

a)

Backdoor testing

b)

Passive footprinting

c)

OS fingerprinting

d)

Partially known environment

24.

Which of these protocols use TLS to provide secure communication?

(Select TWO)

a)

HTTPS

b)

SSH

c)

FTPS

d)

SNMPv2

e)

DNSSEC

25.

Which of these threat actors would be MOST likely to attack systems for

direct financial gain?

a)

Organized crime

b)

Hacktivist

c)

Nation state

d)

Competitor

26.

A security incident has occurred on a file server. Which of the following

data sources should be gathered to address file storage volatility?

(Select TWO)

a)

Partition data

b)

Kernel statistics

c)

ROM data

d)

Temporary file systems

e)

Process table

27.

An IPS at your company has found a sharp increase in traffic from

all-in-one printers. After researching, your security team has found a

vulnerability associated with these devices that allows the device to be

remotely controlled by a third-party. Which category would BEST

describe these devices?

a)

IoT

b)

RTOS

c)

MFD

d)

SoC

28.

Which of the following standards provides information on privacy and

managing PII?

a)

ISO 31000

b)

ISO 27002

c)

ISO 27701

d)

ISO 27001

29.

Elizabeth, a security administrator, is concerned about the potential for

data exfiltration using external storage drives. Which of the following

would be the BEST way to prevent this method of data exfiltration?

a)

Create an operating system security policy to prevent

the use of removable media

b)

Monitor removable media usage in host-based firewall logs

c)

Only allow applications that do not use removable media

d)

Define a removable media block rule in the UTM

30.

A CISO (Chief Information Security Officer) would like to decrease

the response time when addressing security incidents. Unfortunately, the

company does not have the budget to hire additional security engineers.

Which of the following would assist the CISO with this requirement?

a)

ISO 27701

b)

PKI

c)

IaaS

d)

SOAR

31.

An insurance company has created a set of policies to handle data

breaches. The security team has been given this set of requirements based

on these policies:

• Access records from all devices must be saved and archived

• Any data access outside of normal working hours

must be immediately reported

• Data access must only occur inside of the country

• Access logs and audit reports must be created from a single database

Which of the following should be implemented by the security team to

meet these requirements? (Select THREE)

a)

Restrict login access by IP address and GPS location

b)

Require government-issued identification

during the onboarding process

c)

Add additional password complexity for accounts that access data

d)

Consolidate all logs on a SIEM

e)

Enable time-of-day restrictions on the authentication server

32.

Rodney, a security engineer, is viewing this record from the firewall logs:

Which of the following can be observed from this log information?

a)

The victim's IP address is 136.127.92.171

b)

A download was blocked from a web server

c)

A botnet DDoS attack was blocked

d)

The Trojan was blocked, but the file was not

33.

A user connects to a third-party website and receives this message:

Which of the following attacks would be the MOST likely reason

for this message?

a)

Brute force

b)

DoS

c)

On-path

d)

Disassociation

34.

Which of the following would be the BEST way to provide a website

login using existing credentials from a third-party site?

a)

Federation

b)

802.1X

c)

PEAP

d)

EAP-FAST

35.

A system administrator, Daniel, is working on a contract that will specify

a minimum required uptime for a set of Internet-facing firewalls. Daniel

needs to know how often the firewall hardware is expected to fail between

repairs. Which of the following would BEST describe this information?

a)

MTBF

b)

RTO

c)

MTTR

d)

MTTF

36.

An attacker calls into a company’s help desk and pretends to be the

director of the company’s manufacturing department. The attacker

states that they have forgotten their password and they need to have the

password reset quickly for an important meeting. What kind of attack

would BEST describe this phone call?

a)

Social engineering

b)

Tailgating

c)

Vishing

d)

On-path

37.

A security administrator has been using EAP-FAST wireless

authentication since the migration from WEP to WPA2. The company’s

network team now needs to support additional authentication protocols

inside of an encrypted tunnel. Which of the following would meet the

network team’s requirements?

a)

EAP-TLS

b)

PEAP

c)

EAP-TTLS

d)

EAP-MSCHAPv2

38.

Which of the following would be commonly provided

by a CASB? (Select TWO)

a)

List of all internal Windows devices that have not installed the

latest security patches

b)

List of applications in use

c)

Centralized log storage facility

d)

List of network outages for the previous month

e)

Verification of encrypted data transfers

39.

The embedded OS in a company’s time clock appliance is configured to

reset the file system and reboot when a file system error occurs. On one

of the time clocks, this file system error occurs during the startup process

and causes the system to constantly reboot. Which of the following

BEST describes this issue?

a)

DLL injection

b)

Resource exhaustion

c)

Race condition

d)

Weak configuration

40.

A recent audit has found that existing password policies do not include

any restrictions on password attempts, and users are not required to

periodically change their passwords. Which of the following would

correct these policy issues? (Select TWO)

a)

Password complexity

b)

Password expiration

c)

Password history

d)

Password lockout

e)

Password recovery

41.

What kind of security control is associated with a login banner?

a)

Preventive

b)

Deterrent

c)

Corrective

d)

Detective

e)

Compensating

42.

A security team has been provided with a non-credentialed vulnerability

scan report created by a third-party. Which of the following would they

expect to see on this report?

a)

A summary of all files with invalid group assignments

b)

A list of all unpatched operating system files

c)

The version of web server software in use

d)

A list of local user accounts

43.

A business manager is documenting a set of steps for processing orders

if the primary Internet connection fails. Which of these would BEST

describe these steps?

a)

Communication plan

b)

Continuity of operations

c)

Stakeholder management

d)

Tabletop exercise

44.

A security administrator is concerned about data exfiltration resulting

from the use of malicious phone charging stations. Which of the

following would be the BEST way to protect against this threat?

a)

USB data blocker

b)

Personal firewall

c)

MFA

d)

FDE

45.

A company would like to protect the data stored on laptops used in

the field. Which of the following would be the BEST choice for this

requirement?

a)

MAC

b)

SED

c)

CASB

d)

SOAR

46.

A file server has a full backup performed each Monday at 1 AM.

Incremental backups are performed at 1 AM on Tuesday, Wednesday,

Thursday, and Friday. The system administrator needs to perform a full

recovery of the file server on Thursday afternoon. How many backup sets

would be required to complete the recovery?

a)

2

b)

3

c)

4

d)

1

47.

A company is creating a security policy that will protect all corporate

mobile devices:

• All mobile devices must be automatically locked after a predefined

time period.

• Some mobile devices will be used by the remote sales teams, so the

location of each device needs to be traceable.

• All of the user’s information should be completely separated from

company data.

Which of the following would be the BEST way to establish these

security policy rules?

a)

Containerization

b)

Biometrics

c)

COPE

d)

VDI

e)

MDM

48.

A security engineer runs a monthly vulnerability scan. The scan doesn’t

list any vulnerabilities for Windows servers, but a significant vulnerability

was announced last week and none of the servers are patched yet. Which

of the following best describes this result?

a)

Exploit

b)

Credentialed

c)

Zero-day attack

d)

False negative

49.

A security administrator is adding additional authentication controls to

the existing infrastructure. Which of the following should be added by

the security administrator? (Select TWO)

a)

TOTP

b)

Least privilege

c)

Role-based awareness training

d)

Separation of duties

e)

Smart Card

50.

A network administrator would like each user to authenticate with

their personal username and password when connecting to the

company's wireless network. Which of the following should the network

administrator configure on the wireless access points?

a)

WPA2-PSK

b)

802.1X

c)

WPS

d)

WPA2-AES

51.

A security administrator needs to identify all references to a Javascript

file in the HTML of a web page. Which of the following tools should be

used to view the source of the web page and search through the file for a

specific filename? (Select TWO)

a)

tail

b)

openssl

c)

scanless

d)

grep

e)

curl

52.

A user has assigned individual rights and permissions to a file on their

network drive. The user adds three additional individuals to have readonly

access to the file. Which of the following would describe this access

control model?

a)

DAC

b)

MAC

c)

ABAC

d)

RBAC

53.

A remote user has received a text message requesting login details to the

corporate VPN server. Which of the following would BEST describe this

message?

a)

Brute force

b)

Prepending

c)

Typosquatting

d)

Smishing

54.

A department store policy requires that a floor manager approves each

transaction when a gift certificate is used for payment. The security team

has found that some of these transactions have been processed without

the approval of a manager. Which of the following would provide a

separation of duties to enforce this store policy?

a)

Use a WAF to monitor all gift certificate transactions

b)

Disable all gift certificate transactions for cashiers

c)

Implement a discretionary access control policy

d)

Require an approval PIN for the cashier and a separate

approval PIN for the manager

55.

Which of the following is true of a rainbow table? (Select TWO)

a)

The rainbow table is built in real-time during the attack

b)

Rainbow tables are the most effective online attack type

c)

Rainbow tables require significant CPU cycles at attack time

d)

Different tables are required for different hashing methods

e)

A rainbow table won’t be useful if the passwords are salted

56.

A server administrator at a bank has noticed a decrease in the number

of visitors to the bank's website. Additional research shows that users are

being directed to a different IP address than the bank's web server. Which

of the following would MOST likely describe this attack?

a)

Disassociation

b)

DDoS

c)

Buffer overflow

d)

DNS poisoning

57.

Which of these cloud deployment models would share resources between

a private virtualized data center and externally available cloud services?

a)

SaaS

b)

Community

c)

Hybrid

d)

Containerization

58.

A company hires a large number of seasonal employees, and their

system access should normally be disabled when the employee leaves

the company. The security administrator would like to verify that their

systems cannot be accessed by any of the former employees. Which of the

following would be the BEST way to provide this verification?

a)

Confirm that no unauthorized accounts have administrator access

b)

Validate the account lockout policy

c)

Validate the processes and procedures for all outgoing employees

d)

Create a report that shows all authentications for a 24-hour period

59.

A network administrator has installed a new access point, but only a

portion of the wireless devices are able to connect to the network. Other

devices can see the access point, but they are not able to connect even

when using the correct wireless settings. Which of the following security

features was MOST likely enabled?

a)

MAC filtering

b)

SSID broadcast suppression

c)

802.1X authentication

d)

Anti-spoofing

60.

A security administrator has gathered this information:

Which of the following is being used to create this information?

a)

tracert

b)

netstat

c)

dig

d)

netcat

61.

An attacker has discovered a way to disable a server by sending specially

crafted packets from many remote devices to the operating system. When

the packet is received, the system crashes and must be rebooted to restore

normal operations. Which of the following would BEST describe this

attack?

a)

Privilege escalation

b)

Spoofing

c)

Replay attack

d)

DDoS

62.

A data breach has occurred in a large insurance company. A security

administrator is building new servers and security systems to get all of

the financial systems back online. Which part of the incident response

process would BEST describe these actions?

a)

. Lessons learned

b)

Isolation and containment

c)

Reconstitution

d)

Precursors

63.

A manufacturing company has moved an inventory application from their

internal systems to a PaaS service. Which of the following would be the

BEST way to manage security policies on this new service?

a)

DLP

b)

SIEM

c)

IPS

d)

CASB

64.

An organization has identified a significant vulnerability in a firewall

used for Internet connectivity. The firewall company has stated there are

no plans to create a patch for this vulnerability. Which of the following

would BEST describe this issue?

a)

Lack of vendor support

b)

Improper input handling

c)

Improper key management

d)

End-of-life

65.

A company has decided to perform a disaster recovery exercise during an

annual meeting with the IT directors and senior directors. A simulated

disaster will be presented, and the participants will discuss the logistics

and processes required to resolve the disaster. Which of the following

would BEST describe this exercise?

a)

After-action report

b)

Business impact analysis

c)

Alternate business practice

d)

Tabletop exercise

66.

A security administrator needs to identify all computers on the company

network infected with a specific malware variant. Which of the following

would be the BEST way to identify these systems?

a)

Honeynet

b)

Data masking

c)

DNS sinkhole

d)

DLP

67.

A system administrator has been called to a system that is suspected to

have a malware infection. The administrator has removed the device from

the network and has disconnected all USB flash drives. Which of these

incident response steps is the administrator following?

a)

Lessons learned

b)

Containment

c)

Detection

d)

Reconstitution

68.

How can a company ensure that all data on a mobile device is

unrecoverable if the device is lost or stolen?

a)

Containerization

b)

Geofencing

c)

Screen locks

d)

Remote wipe

69.

A security administrator is collecting information associated with a

ransomware infection on the company's web servers. Which of the

following log files would provide information regarding the memory

contents of these servers?

a)

Web

b)

Packet

c)

Dump

d)

DNS

70.

Which part of the PC startup process verifies the digital signature of the

OS kernel?

a)

Measured Boot

b)

Trusted Boot

c)

Secure Boot

d)

POST

71.

Which of these best describes two-factor authentication?

a)

A printer uses a password and a PIN

b)

The door to a building requires a fingerprint scan

c)

An application requires a TOTP code

d)

A Windows Domain requires a username, password,

and smart card

72.

A company is deploying a new mobile application to all of its employees

in the field. Some of the problems associated with this rollout include:

• The company does not have a way to manage the mobile devices

in the field

• Company data on mobile devices in the field introduces additional risk

• Team members have many different kinds of mobile devices

Which of the following deployment models would address

these concerns?

a)

Corporate-owned

b)

COPE

c)

VDI

d)

BYOD

73.

An organization is installing a UPS for their new data center. Which of

the following would BEST describe this type of control?

a)

Compensating

b)

Preventive

c)

Administrative

d)

Detective

74.

A manufacturing company would like to track the progress of parts as

they are used on an assembly line. Which of the following technologies

would be the BEST choice for this task?

a)

Quantum computing

b)

Blockchain

c)

Hashing

d)

Asymmetric encryption

75.

A security administrator has been asked to respond to a potential security

breach of the company’s databases, and they need to gather the most

volatile data before powering down the database servers. In which order

should they collect this information?

a)

CPU registers, temporary files, memory, remote monitoring data

b)

Memory, CPU registers, remote monitoring data, temporary files

c)

Memory, CPU registers, temporary files, remote monitoring data

d)

CPU registers, memory, temporary files, remote monitoring data

76.

A Linux administrator is downloading an updated version of her Linux

distribution. The download site shows a link to the ISO and a SHA256

hash value. Which of these would describe the use of this hash value?

a)

Verifies that the file was not corrupted during the file transfer

b)

Provides a key for decrypting the ISO after download

c)

Authenticates the site as an official ISO distribution site

d)

Confirms that the file does not contain any malware

77.

A company's security policy requires that login access should only

be available if a person is physically within the same building as the

server. Which of the following would be the BEST way to provide this

requirement?

a)

TOTP

b)

Biometric scanner

c)

PIN

d)

SMS

78.

Your development team has installed a new application and database to

a cloud service. After running a vulnerability scanner on the application

instance, you find that the database is available for anyone to query

without providing any authentication. Which of these vulnerabilities is

MOST associated with this issue?

a)

Improper error handling

b)

Open permissions

c)

Race condition

d)

Memory leak

79.

Employees of an organization have received an email offering a cash

bonus for completing an internal training course. The link in the email

requires users to login with their Windows Domain credentials, but the

link appears to be located on an external server. Which of the following

would BEST describe this email?

a)

Whaling

b)

Vishing

c)

Smishing

d)

Phishing

80.

Which of the following risk management strategies would include the

purchase and installation of an NGFW?

a)

Transference

b)

Mitigation

c)

Acceptance

d)

Risk-avoidance

81.

Which of the following would be the BEST way to confirm the secure

baseline of a deployed application instance?

a)

Compare the production application to the sandbox

b)

Perform an integrity measurement

c)

Compare the production application to the previous version

d)

Perform QA testing on the application instance

82.

A member of the accounting team was out of the office for two weeks,

and an important financial transfer was delayed until they returned.

Which of the following would have prevented this delay?

a)

Split knowledge

b)

Least privilege

c)

Job rotation

d)

Dual control

83.

A security analyst has identified a number of sessions from a single IP

address with a TTL equal to zero. One of the sessions has a destination of

the Internet firewall, and a session immediately after has a destination of

your DMZ server. Which of the following BEST describes this

log information?.

a)

.Someone is performing a vulnerability scan against the firewall and DMZ server

b)

Users are performing DNS lookups

c)

A remote user is grabbing banners of the firewall and DMZ server

d)

Someone is performing a traceroute to the DMZ server

84.

A security analyst has identified a number of sessions from a single IP

address with a TTL equal to zero. One of the sessions has a destination of

the Internet firewall, and a session immediately after has a destination of

your DMZ server. Which of the following BEST describes this

log information?

a)

Someone is performing a vulnerability scan against the

firewall and DMZ server

b)

Users are performing DNS lookups

c)

A remote user is grabbing banners of the firewall and DMZ server

d)

Someone is performing a traceroute to the DMZ server

85.

An attacker has sent more information than expected in a single API

call, and this has allowed the execution of arbitrary code. Which of the

following would BEST describe this attack?

a)

Buffer overflow

b)

Replay attack

c)

Session hijacking

d)

DDoS

86.

A company encourages users to encrypt all of their confidential materials

on a central server. The organization would like to enable key escrow as a

backup. Which of these keys should the organization place into escrow?

a)

Private

b)

CA

c)

Session

d)

Public

87.

A security administrator is designing an authentication process for a

new remote site deployment. They would like the users to provide their

credentials when they authenticate in the morning, and they do not want

any additional authentication requests to appear during the rest of the

day. Which of the following should be used to meet this requirement?

a)

TACACS+

b)

LDAPS

c)

Kerberos

d)

802.1X

88.

A manufacturing company would like to use an existing router to

separate a corporate network and a manufacturing floor that use the same

physical switch. The company does not want to install any additional

hardware. Which of the following would be the BEST choice for this

segmentation?

a)

Connect the corporate network and the manufacturing floor

with a VPN

b)

Build an air gapped manufacturing floor network

c)

Use personal firewalls on each device

d)

Create separate VLANs for the corporate network and the

manufacturing floor

89.

When a home user connects to the corporate VPN, they are no longer

able to print to their local network printer. Once the user disconnects

from the VPN, the printer works normally. Which of the following would

be the MOST likely reason for this issue?

a)

The VPN uses IPSec instead of SSL

b)

Printer traffic is filtered by the VPN client

c)

The VPN is stateful

d)

The VPN tunnel is configured for full tunnel

90.

A data center manager has built a Faraday cage in the data center, and a

set of application servers have been placed into racks inside the Faraday

cage. Which of the following would be the MOST likely reason for the

data center manager to install this configuration of equipment?

a)

Protect the servers against any unwanted electromagnetic fields

b)

Prevent physical access to the servers without the proper credentials

c)

Provide additional cooling to all devices in the cage

d)

Adds additional fire protection for the application servers

91.

A recent report shows the return of a vulnerability that was previously

patched four months ago. After researching this issue, the security team

has found that a recent patch has reintroduced this vulnerability on

the servers. Which of the following should the security administrator

implement to prevent this issue from occurring in the future?

a)

Templates

b)

Elasticity

c)

Master image

d)

Continuous monitoring

92.

A security manager would like to ensure that unique hashes are used with

an application login process. Which of the following would be the BEST

way to add random data when generating a set of stored password hashes?

a)

Salting

b)

Obfuscation

c)

Key stretching

d)

Digital signature

93.

Which cryptographic method is used to add trust to a digital certificate?

a)

X.509

b)

Hash

c)

Symmetric encryption

d)

Digital signature

94.

An MSP is designing a new server room for a large company. Which of

the following should be included in the design to provide redundancy?

(Select TWO)

a)

SIEM

b)

Temperature monitors

c)

RAID arrays

d)

Dual power supplies

e)

Hot and cold aisles

95.

An organization maintains a large database of customer information for

sales tracking and customer support. Which person in the organization

would be responsible for managing the access rights to this data?

a)

Data processor

b)

Data owner

c)

Privacy officer

d)

Data custodian

96.

An organization’s content management system (CMS) currently labels

files and documents as “Unclassified” and “Restricted.” On a recent

updated to the CMS, a new classification type of “PII” was added. Which

of the following would be the MOST likely reason for this addition?

a)

Healthcare system integration

b)

Simplified categorization

c)

Expanded privacy compliance

d)

Decreased search time

97.

A corporate security team would like to consolidate and protect the

certificates across all of their web servers. Which of these would be the

BEST way to securely store these certificates?

a)

Use an HSM

b)

Implement full disk encryption on the web servers

c)

Use a TPM

d)

Upgrade the web servers to use a UEFI BIOS

98.

Jennifer is reviewing this security log from her IPS:

Which of the following can be determined from this log information?

(Select TWO)

a)

The alert was generated from a malformed User Agent header

b)

The alert was generated from an embedded script

c)

The attacker’s IP address is 222.43.112.74

d)

The attacker’s IP address is 64.235.145.35

e)

The alert was generated due to an invalid client port number

99.

Which of the following describes a monetary loss if one event occurs?

a)

ALE

b)

SLE

c)

RTO

d)

ARO

100.

A user with restricted access has typed this text in a search field of an

internal web-based application:

USER77' OR '1'='1

After submitting this search request, all of the database records are

displayed on the screen. Which of the following would BEST describe

this search?

a)

CSRF

b)

Buffer overflow

c)

SQL injection

d)

SSL stripping

101.

A user has opened a helpdesk ticket complaining of poor system

performance, excessive pop up messages, and the cursor moving

without anyone touching the mouse. This issue began after they opened

a spreadsheet from a vendor containing part numbers and pricing

information. Which of the following is MOST likely the cause of this

user's issues?

a)

On-path

b)

Worm

c)

RAT

d)

Logic bomb

102.

A web-based manufacturing company processes monthly charges to credit

card information saved in the customer's profile. Which of the following

standards would be required to maintain this payment information?

a)

GDPR

b)

ISO 27001

c)

PCI DSS

d)

CSA CCM

103.

A security manager has created a report showing intermittent network

communication from external IP addresses to certain workstations on the

internal network. These traffic patterns occur at random times during the

day. Which of the following would be the MOST likely reason for these

traffic patterns?

a)

ARP poisoning

b)

Backdoor

c)

Polymorphic virus

d)

Trojan horse

104.

The security policies in a manufacturing company prohibit the

transmission of customer information. However, a security administrator

has received an alert that credit card numbers were transmitted as an

email attachment. Which of the following was the MOST likely source

of this alert message?

a)

IPS

b)

DLP

c)

SMTP

d)

IPsec

105.

A security administrator has configured a virtual machine in a screened

subnet with a guest login account and no password. Which of the

following would be the MOST likely reason for this configuration?

a)

The server is a honeypot for attracting potential attackers

b)

The server is a cloud storage service for remote users

c)

The server will be used as a VPN concentrator

d)

The server is a development sandbox for third-party

programming projects

106.

A company's outgoing email server currently uses SMTP with no

encryption. The security administrator would like to implement

encryption between email clients without changing the existing

server-to-server communication. Which of the following would be the

BEST way to implement this requirement?

a)

Implement Secure IMAP

b)

Require the use of S/MIME

c)

Install an SSL certificate on the email server

d)

Use a VPN tunnel between email clients

107.

A company would like to securely deploy applications without the

overhead of installing a virtual machine for each system. Which of the

following would be the BEST way to deploy these applications?

a)

Containerization

b)

IaaS

c)

Proxies

d)

CASB

108.

A company has just purchased a new application server, and the security

director wants to determine if the system is secure. The system is currently

installed in a test environment and will not be available to users until the

rollout to production next week. Which of the following would be the

BEST way to determine if any part of the system can be exploited?

a)

Tabletop exercise

b)

Vulnerability scanner

c)

Password cracker

d)

Penetration test