wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

SEC+ set 1

Total questions: 26

Worksheet time: 27mins

Name
Class
Date
1.

A security engineer is installing a WAF to protect the company's website from malicious web requests over SSL. Which of the following is needed to meet the objective?

a)

A reverse proxy

b)

A decryption certificate

c)

A spill-tunnel VPN

d)

Load-balanced servers

2.

A security analyst is running a vulnerability scan to check for missing patches during a suspected security rodent During

which of the following phases of the response process is this activity MOST likely occurring?

a)

Containment

b)

Preparation

c)

Recovery

d)

Identification

3.

A security engineer needs to create a network segment that can be used for servers that require connections from

untrusted networks. Which of the following should the engineer implement?

a)

An air gap

b)

A screened subnet

c)

A VLAN

d)

A hot site

4.

A systems engineer is building a new system for production. Which of the following is the FINAL step to be performed prior to promotion to production?

a)

Disable unneeded services.

b)

Install the latest security patches.

c)

Run a vulnerability scan.

d)

Encrypt all disks.

5.

A major clothing company recently lost a large amount of proprietary information. The security officer must find a solution to ensure this never happens again. Which of the following is the BEST technical implementation to prevent this from happening again?

a)

Configure DLP solutions

b)

Disable peer-to-peer sharing

c)

Enable role-based

d)

Mandate job rotation

e)

Implement content filters

6.

Which of the following would be BEST for a technician to review to determine the total risk an organization can bear

when assessing a "cloud-first" adoption strategy?

a)

Risk matrix

b)

Risk tolerance

c)

Risk register

d)

Risk appetite

7.

Ann, a customer, received a notification from her mortgage company stating her PII may be shared with partners,

affiliates, and associates to maintain day-to-day business operations.

Which of the following documents did Ann receive?

a)

An annual privacy notice

b)

A non-disclosure agreement

c)

A privileged-user agreement

d)

A memorandum of understanding

8.

The help desk has received calls from users in multiple locations who are unable to access core network services. The

network team has identified and turned off the network switches using remote commands. Which of the following

actions should the network team take NEXT?

a)

Disconnect all external network connections from the firewall

b)

Send response teams to the network switch locations to perform updates

c)

Turn on all the network switches by using the centralized management software

d)

Initiate the organization's incident response plan.

9.

A company would like to set up a secure way to transfer data between users via their mobile phones. The company's top

priority is utilizing technology that requires users to be in as close proximity as possible to each other. Which of the

following connection methods would BEST fulfill this need?

a)

Cellular

b)

NFC

c)

Wi-Fi

d)

Bluetooth

10.

A security analyst has been tasked with creating a new WiFi network for the company. The requirements received by

the analyst are as follows:

•Must be able to differentiate between users connected to WiFi

•The encryption keys need to change routinely without interrupting the users or forcing reauthentication

•Must be able to integrate with RADIUS

•Must not have any open SSIDs

Which of the following options BEST accommodates these requirements?

a)

WPA2-Enterprise

b)

WPS

c)

802.11n

d)

WPA3-PSK

11.

Which of the following describes a maintenance metric that measures the average time required to troubleshoot and

restore failed equipment?

a)

RTO

b)

MTTR

c)

MTBF

d)

RPO

12.

A company recently experienced an attack during which its main website was directed to the attacker's web server,

allowing the attacker to harvest credentials from unsuspecting customers. Which of the following should the company

implement to prevent this type of attack from occurring in the future?

a)

IPsec

b)

SSL/TLS

c)

DNSSEC

d)

S/MIME

13.

Which of the following are the MOST likely vectors for the unauthorized inclusion of vulnerable code in a software

company’s final software releases? (Select TWO.)

a)

Unsecure protocols

b)

Included third-party libraries

c)

Outdated anti-malware software

d)

Weak passwords

e)

E. Vendors/supply chain

14.

A backdoor was detected in the containerized application environment. The investigation detected that a zero-day

vulnerability was introduced when the latest container image version was downloaded from a public registry. Which of

the following is the BEST solution to prevent this type of incident from occurring again?

a)

Enforce the use of a controlled trusted source of container images

b)

Deploy an IPS solution capable of detecting signatures of attacks targeting containers

c)

Define a vulnerability scan to assess container images before being introduced on the environment

d)

Create a dedicated VPC for the containerized environment

15.

A company wants to modify its current backup strategy to minimize the number of backups that would need to be

restored in case of data loss. Which of the following would be the BEST backup strategy

a)

Incremental backups followed by differential backups

b)

Full backup followed by incremental backups

c)

Delta backups followed by differential backups

d)

Incremental backups followed by delta backups

e)

Full backup followed by differential backups

16.

Which of the following roles would MOST likely have direct access to the senior management team?

a)

Data custodian

b)

Data owner

c)

Data protection officer

d)

Data controller

17.

Which of the following incident response steps occurs before containment?

a)

Eradication

b)

Recovery

c)

Lessons learned

d)

Identification

18.

A dynamic application vulnerability scan identified code injection could be performed using a web form.

Which of the following will be BEST remediation to prevent this vulnerability?

a)

Implement input validations

b)

Deploy MFA

c)

Utilize a WAF

d)

Configure HIPS

19.

A network engineer and a security engineer are discussing ways to monitor network operations. Which of the following

is the BEST method?

a)

Disable Telnet and force SSH.

b)

Establish a continuous ping.

c)

Utilize an agentless monitor

d)

Enable SNMPv3 With passwords.

20.

Which of the following involves the inclusion of code in the main codebase as soon as it is written?

a)

Continuous monitoring

b)

Continuous deployment

c)

Continuous validation

d)

Continuous integration

21.

During a forensic investigation, a security analyst discovered that the following command was run on a compromised

host:

crackmapexec smb 192.168.10.232 -u localadmin -H 0A3CE8D07A46E5C51070F03593E0A5E6

Which of the following attacks occurred?

a)

Buffer overflow

b)

Pass the hash

c)

SQL injection

d)

Replay attack

22.

An attacker replaces a digitally signed document with another version that goes unnoticed. Upon reviewing the

document’s contents, the author notices some additional verbiage that was not originally in the document but can’t

validate an integrity issue. Which of the following attacks was used?

a)

Cryptomalware

b)

Hash substitution

c)

Collision

d)

Phishing

23.

A security analyst notices several attacks are being blocked by the NIPS but does not see anything on the boundary

firewall logs. The attack seems to have been thwarted. Which of the following resiliency techniques was applied to the

network to prevent this attack?

a)

NIC Teaming

b)

Port mirroring

c)

Defense in depth

d)

High availability

e)

Geographic dispersal

24.

During an incident, a company’s CSIRT determines it is necessary to observe the continued network-based transactions

between a callback domain and the malware running on an enterprise PC. Which of the following techniques would be

BEST to enable this activity while reducing the risk of lateral spread and the risk that the adversary would notice any

changes?

a)

Physically move the PC to a separate internet point of presence

b)

Create and apply micro segmentation rules.

c)

Emulate the malware in a heavily monitored DMZ segment.

d)

Apply network blacklisting rules for the adversary domain

25.

If a current private key is compromised, which of the following would ensure it cannot be used to decrypt any

historical data?

a)

Perfect forward secrecy

b)

Elliptic-curve cryptography

c)

Key stretching

d)

Homomorphic encryption

26.

A security analyst is responding to an alert from the SIEM. The alert states that malware was discovered on a host and

was not automatically deleted. Which of the following would be BEST for the analyst to perform?

a)

Add a deny-all rule to that host in the network ACL

b)

Implement a network-wide scan for other instances of the malware.

c)

Quarantine the host from other parts of the network

d)

Revoke the client's network access certificates