Font size
WorksheetsSec Plus 1
Total questions: 45
Worksheet time: 2hrs 15mins
You have hired 10 new temporary workers who will be with the company for three months. You want to make sure that the user accounts cannot be used for login after that time period. What should you do?
Configure account lockout in Group Policy.
Configure account policies in Group Policy.
Configure day/time restrictions in the user accounts.
Configure account expiration in the user accounts.
Which type of update should be prioritized even outside of a normal patching window?
Monthly updates
Critical updates
Microsoft updates
Security updates
Prepare to Document means establishing the process you will use to document your network.
Which of the following makes this documentation more useful?
Automate administration as much as possible.
Have a printed hard copy kept in a secure location.
Identify the choke points on the network.
Identify who is responsible for each device.
Documenting procedures and processes are part of which milestone in the NSA's Manageable Network Plan?
Prepare to Document
Control Your Network
Document Your Network
Reach Your Network
In which milestone should you use a network scanner and then confirm the scan manually with a room-by-room walkthrough?
Protect Your Network
Map Your Network
Prepare to Document
Reach Your Network
Windows Server Update Services (WSUS) is used to accomplish which part of a manageable network?
Documentation
Patch management
Device accessibility
User access
You have recently been hired as the new network administrator for a startup company. The company's network was implemented prior to your arrival. One of the first tasks you need to complete in your new position is to develop a manageable network plan for the network.
You have already completed the first and second milestones, in which documentation procedures were identified and the network was mapped. You are now working on the third milestone, which is identifying ways to protect the network.
Which tasks should you complete as a part of this milestone? (Select two.)
Identify and document each user on the network.
Set account expiration dates.
Apply critical patches whenever they are released.
Create an approved application list for each network device.
Physically secure high-value systems.
For Milestone 4 (Reach Your Network), which of the following would be considered a secure protocol to use to reach your network?
Telnet
FTP
SSH
HTTP
As you go through the process of making your network more manageable, you discover that employees in the sales department are on the same network segment as the human resources department.
Which of the following steps can be used to isolate these departments?
Implement the principle of least privilege for the human resources department.
Move the sales department into the DMZ.
Identify the choke points on your network.
Create a separate VLAN for each department.
Which of the following tools can you use on a Windows network to automatically distribute and install software and operating system patches on workstations? (Select two.)
Security Configuration and Analysis
WSUS
Group Policy
Security Templates
What should you consider security baselines?
Dynamic
Static
Unchangeable
Suggestion
By definition, what is the process of reducing security exposure and tightening security controls?
Social engineering
Active scanning
Hardening
Passive reconnaissance
Which of the following is the strongest form of multi-factor authentication?
A password, a biometric scan, and a token device
Two passwords
A password and a biometric scan
Two-factor authentication
Which of the following actions should you take to reduce the attack surface of a server?
Install the latest patches and hotfixes.
Install anti-malware software.
Install a host-based IDS.
Disable unused services.
You have just purchased a new network device and are getting ready to connect it to your network. Which of the following actions should you take to increase its security? (Select two.)
Apply all patches and updates.
Apply all patches and updates.
Conduct privilege escalation.
Implement separation of duties.
Remove any backdoors.
Which of the following is defined as an operating system that comes hardened and validated to a specific security level as defined in the Common Criteria for Information Technology Security Evaluation (CC)?
TOS
OS X
Windows
UNIX
You have placed a File Transfer Protocol (FTP) server in your DMZ behind your firewall. The FTP server is to be used to distribute software updates and demonstration versions of your products. However, users report that they are unable to access the FTP server.
What should you do to enable access?
Define user accounts for all external visitors.
Open ports 20 and 21 for outbound connections.
Install a VPN.
Move the FTP outside of the firewall.
FTPS uses which mechanism to provide security for authentication and data transfer?
Token devices
SSL
IPsec
Multi-factor authentication
You want to close all ports associated with NetBIOS on your network's firewalls to prevent attacks directed against NetBIOS. Which ports should you close?
67, 68
135, 137-139
161, 162
389, 636
To increase security on your company's internal network, the administrator has disabled as many ports as possible. However, now you can browse the internet, but you are unable to perform secure credit card transactions.
Which port needs to be enabled to allow secure transactions?
69
21
443
23
You have a shared folder named Reports. Members of the Managers group have been given Write access to the shared folder.
Mark Mangum is a member of the Managers group. He needs access to the files in the Reports folder, but he should not have any access to the Confidential.xls file.
What should you do?
Remove Mark Mangum from the Managers group.
Add Mark Mangum to the ACL for the Reports directory with Deny permissions.
Add Mark Mangum to the ACL for the Confidential.xls file with Deny permissions.
Configure NTFS permissions for Confidential.xls to allow read-only.
If Mark has a read-write permission to the share \\fileserver\securefiles and a read-only permission to the file coolstuff.docx on the NTFS file system shared by the file share, he is able to perform which action?
Change the contents of the file.
Delete the file.
Rename the file.
Read the file.
You need to increase the security of your Linux system by finding and closing open ports. Which of the following commands should you use to locate open ports?
nslookup
nmap
traceroute
netstat
What does the netstat -a command show?
All listening and non-listening sockets
All connected hosts
All network users
All listening sockets
Where should an organization's web server be placed?
Intranet
Extranet
DMZ
Honeynet
Which of the following is a privately controlled portion of a network that is accessible to some specific external entities?
Intranet
Extranet
Internet
MAN
You want to create a collection of computers on your network that appear to have valuable data but actually store fake data that could entice a potential intruder. Once the intruder connects, you want to be able to observe and gather information about the attacker's methods.
Which feature should you implement?
NIDS
Extranet
NIPS
Honeynet
A honeypot is used for which purpose?
To disable an intruder's system
To entrap intruders
To delay intruders in order to gather auditing data
To prevent sensitive data from being accessed
Which of the following devices can apply quality of service and traffic-shaping rules based on what created the network traffic?
Network access control
Application-aware devices
Proxy server
All-in-one security appliances
You are the office manager of a small financial credit business. Your company handles personal financial information for clients seeking small loans over the internet. You are aware of your obligation to secure clients records, but the budget is an issue for your company.
Which item would provide the BEST security for this situation?
Proxy server with access controls
Network access control system
All-in-one security appliance
Firewall on your gateway server to the internet
You are implementing security at a local high school that is concerned with students accessing inappropriate material on the internet from the library's computers. The students use the computers to search the internet for research paper content. The school budget is limited.
Which content filtering option would you choose?
Allow all content except for the content you have identified as restricted.
Restrict content based on content categories.
Block specific DNS domain names.
Block all content except for content you have identified as permissible.
Which of the following BEST describes a honeyfile?
A default file in the /etc/security directory.
A file used to authenticate.
A file that has been digitally signed.
A single file setup to entice and trap attackers.
Members of the sales team use laptops to connect to the company network. While traveling, they connect their laptops to the internet through airport and hotel networks.
You are concerned that these computers could pick up viruses that could spread to your private network. You would like to implement a solution that prevents the laptops from connecting to your network unless antivirus software and the latest operating system patches are installed.
Which solution should you use?
VLAN
NIDS
NAC
DMZ
A proxy server can be configured to do which of the following?
Act as a unified threat security device or web security gateway.
Block all content except for the content you have identified as permissible.
Restrict users on the inside of a network from getting out to the internet.
Allow all content except for the content you have identified as restricted.
Which of the following terms describes a network device that is exposed to attacks and has been hardened against those attacks?
Circuit proxy
Kernel proxy
Multi-homed
Bastion or sacrificial host
Of the following security zones, which one can serve as a buffer network between a private secured network and the untrusted internet?
DMZ
Padded cell
Extranet
Intranet
Which of the following describes how access control lists can be used to improve network security?
An access control list filters traffic based on the IP header information, such as source or destination IP address, protocol, or socket number.
An access control list filters traffic based on the frame header, such as source or destination MAC address.
An access control list looks for patterns of traffic between multiple packets and takes action to stop detected attacks.
An access control list identifies traffic that must use authentication or encryption.
Jessica needs to set up a firewall to protect her internal network from the internet. Which of the following would be the BEST type of firewall for her to use?
Software
Stateful
Tunneling
Hardware
When designing a firewall, what is the recommended approach for opening and closing ports?
Close all ports.
Close all ports; open only ports required by applications inside the DMZ.
Close all ports; open ports 20, 21, 53, 80, and 443.
Open all ports; close ports that expose common network attacks.
Open all ports; close ports t
You want to connect your small company network to the internet. Your ISP provides you with a single IP address that is to be shared between all hosts on your private network. You do not want external hosts to be able to initiate connection to internal hosts. Which type of Network Address Translation (NAT) should you implement?
Static
Dynamic
Shared
Restricted
Which device is NAT typically implemented on?v
AD server
ISP router
Gateway router
RADIUS server
Which problem does NAT help address?
IPSec not working properly
The shortage of IPv6 addresses
Registering IP addresses with an ISP
The shortage of IPv4 addresses
Which of the following does a NAT router use to associate a port number with a request from a private host?
IPv4
Static NAT
Dynamic NAT
PAT
A network device is given an IP address of 172.16.0.55. Which type of network is this device on?
IPv6 private network
Class A private network
Class C private network
Class B private network
You are the network administrator for a small company that implements NAT to access the internet. However, you recently acquired five servers that must be accessible from outside your network. Your ISP has provided you with five additional registered IP addresses to support these new servers, but you don't want the public to access these servers directly. You want to place these servers behind your firewall on the inside network, yet still allow them to be accessible to the public from the outside.
Which method of NAT translation should you implement for these servers?
Dynamic
Overloading
Restricted
Static
