Worksheets101-120
Total questions: 20
Worksheet time: 24mins
You are security administrator investigating a potential infection on a network.
Click on each host and firewall. Review all logs to determine which host originated the Infecton and
then deny each remaining hosts clean or infected.
.
An engineer needs to find a solution that creates an added layer of security by preventing unauthorized access to internal company resources. Which of the following would be the best solution?
RDP server
Jump server
Proxy server
Hypervisor
An employee receives a text message that appears to have been sent by the payroll department and is asking for credential verification. Which of the following social engineering techniques are being attempted? (Choose two.)
Impersonation
Phishing
Smishing
Vishing
Typosquatting
Which of the following tools can assist with detecting an employee who has accidentally emailed a file containing a customer's PII?
SCAP
Net Flow
Antivirus
DLP
Which of the following involves an attempt to take advantage of database misconfigurations?
Buffer overflow
SQL injection
VM escape
Memory injection
A company's end users are reporting that they are unable to reach external websites. After reviewing the performance data for the DNS severs, the analyst discovers that the CPU, disk, and memory usage are minimal, but the network interface is flooded with inbound traffic. Network logs show only a small number of DNS queries sent to this server. Which of the following best describes what the security analyst is seeing?
Concurrent session usage
Secure DNS cryptographic downgrade
On-path resource consumption
Reflected denial of service
Which of the following roles, according to the shared responsibility model, is responsible for securing the company's database in an IaaS model for a cloud environment?
Client
Third-party vendor
Cloud provider
DBA
Which of the following vulnerabilities is exploited when an attacker overwrites a register with a malicious address?
VM escape
SQL injection
Buffer overflow
Race condition
Which of the following is used to add extra complexity before using a one-way data transformation algorithm?
Key stretching
Data masking
Steganography
Salting
A systems administrator wants to prevent users from being able to access data based on their responsibilities. The administrator also wants to apply the required access structure via a simplified format. Which of the following should the administrator apply to the site recovery resource group?
RBAC
ACL
SAML
GPO
A technician wants to improve the situational and environmental awareness of existing users as they transition from remote to in-office work. Which of the following is the best option?
Send out periodic security reminders
Update the content of new hire documentation
Modify the content of recurring training
Implement a phishing campaign
The management team notices that new accounts that are set up manually do not always have correct access or permissions. Which of the following automation techniques should a systems administrator use to streamline account creation?
Guard rail script
Ticketing workflow
Escalation script
User provisioning script
Malware spread across a company's network after an employee visited a compromised industry blog. Which of the following best describes this type of attack?
Impersonation
Disinformation
Watering-hole
Smishing
A company's web filter is configured to scan the URL for strings and deny access when matches are found. Which of the following search strings should an analyst employ to prohibit access to non-encrypted websites?
encryption=off\
http://
www.*.com
:443
The administrator sees from the security logs that the data was last accessed by a domain user. Which of the following best describes the type of attack that occurred?
Insider threat
Social engineering
Watering-hole
Unauthorized attacker
A company is developing a critical system for the government and storing project information on a fileshare. Which of the following describes how this data will most likely be classified? (Select two).
Operational
Private
Restricted
Confidential
Public
A company needs to provide administrative access to internal resources while minimizing the traffic allowed through the security boundary. Which of the following methods is most secure?
Implementing a bastion host
Deploying a perimeter network
Installing a WAF
Utilizing single sign-on
A systems administrator is creating a script that would save time and prevent human error when performing account creation for a large number of end users. Which of the following would be a good use case for this task?
Off-the-shelf software
Orchestration
Baseline
Policy enforcement
A systems administrator receives the following alert from a file integrity monitoring tool: The hash of the cmd.exe file has changed. The systems administrator checks the OS logs and notices that no patches were applied in the last two months. Which of the following most likely occurred?
The end user changed the file permissions
A cryptographic collision was detected
A snapshot of the file system was taken
A rootkit was deployed
A newly appointed board member with cybersecurity knowledge wants the board of
directors to receive a quarterly report detailing the number of incidents that impacted the
organization. The systems administrator is creating a way to present the data to the board of
directors. Which of the following should the systems administrator use?
Packet captures
Vulnerability scans
Metadata
Dashboard
