Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

101-120

Total questions: 20

Worksheet time: 24mins

Name
Class
Date
1.

You are security administrator investigating a potential infection on a network.

Click on each host and firewall. Review all logs to determine which host originated the Infecton and

then deny each remaining hosts clean or infected.

a)

b)

.

2.

An engineer needs to find a solution that creates an added layer of security by preventing unauthorized access to internal company resources. Which of the following would be the best solution?

a)

RDP server

b)

Jump server

c)

Proxy server

d)

Hypervisor

3.

An employee receives a text message that appears to have been sent by the payroll department and is asking for credential verification. Which of the following social engineering techniques are being attempted? (Choose two.)

a)

Impersonation

b)

Phishing

c)

Smishing

d)

Vishing

e)

Typosquatting

4.

Which of the following tools can assist with detecting an employee who has accidentally emailed a file containing a customer's PII?

a)

SCAP

b)

Net Flow

c)

Antivirus

d)

DLP

5.

Which of the following involves an attempt to take advantage of database misconfigurations?

a)

Buffer overflow

b)

SQL injection

c)

VM escape

d)

Memory injection

6.

A company's end users are reporting that they are unable to reach external websites. After reviewing the performance data for the DNS severs, the analyst discovers that the CPU, disk, and memory usage are minimal, but the network interface is flooded with inbound traffic. Network logs show only a small number of DNS queries sent to this server. Which of the following best describes what the security analyst is seeing?

a)

Concurrent session usage

b)

Secure DNS cryptographic downgrade

c)

On-path resource consumption

d)

Reflected denial of service

7.

Which of the following roles, according to the shared responsibility model, is responsible for securing the company's database in an IaaS model for a cloud environment?

a)

Client

b)

Third-party vendor

c)

Cloud provider

d)

DBA

8.

Which of the following vulnerabilities is exploited when an attacker overwrites a register with a malicious address?

a)

VM escape

b)

SQL injection

c)

Buffer overflow

d)

Race condition

9.

Which of the following is used to add extra complexity before using a one-way data transformation algorithm?

a)

Key stretching

b)

Data masking

c)

Steganography

d)

Salting

10.

A systems administrator wants to prevent users from being able to access data based on their responsibilities. The administrator also wants to apply the required access structure via a simplified format. Which of the following should the administrator apply to the site recovery resource group?

a)

RBAC

b)

ACL

c)

SAML

d)

GPO

11.

A technician wants to improve the situational and environmental awareness of existing users as they transition from remote to in-office work. Which of the following is the best option?

a)

Send out periodic security reminders

b)

Update the content of new hire documentation

c)

Modify the content of recurring training

d)

Implement a phishing campaign

12.

The management team notices that new accounts that are set up manually do not always have correct access or permissions. Which of the following automation techniques should a systems administrator use to streamline account creation?

a)

Guard rail script

b)

Ticketing workflow

c)

Escalation script

d)

User provisioning script

13.

Malware spread across a company's network after an employee visited a compromised industry blog. Which of the following best describes this type of attack?

a)

Impersonation

b)

Disinformation

c)

Watering-hole

d)

Smishing

14.

A company's web filter is configured to scan the URL for strings and deny access when matches are found. Which of the following search strings should an analyst employ to prohibit access to non-encrypted websites?

a)

encryption=off\

b)

http://

c)

www.*.com

d)

:443

15.

The administrator sees from the security logs that the data was last accessed by a domain user. Which of the following best describes the type of attack that occurred?

a)

Insider threat

b)

Social engineering

c)

Watering-hole

d)

Unauthorized attacker

16.

A company is developing a critical system for the government and storing project information on a fileshare. Which of the following describes how this data will most likely be classified? (Select two).

a)

Operational

b)

Private

c)

Restricted

d)

Confidential

e)

Public

17.

A company needs to provide administrative access to internal resources while minimizing the traffic allowed through the security boundary. Which of the following methods is most secure?

a)

Implementing a bastion host

b)

Deploying a perimeter network

c)

Installing a WAF

d)

Utilizing single sign-on

18.

A systems administrator is creating a script that would save time and prevent human error when performing account creation for a large number of end users. Which of the following would be a good use case for this task?

a)

Off-the-shelf software

b)

Orchestration

c)

Baseline

d)

Policy enforcement

19.

A systems administrator receives the following alert from a file integrity monitoring tool: The hash of the cmd.exe file has changed. The systems administrator checks the OS logs and notices that no patches were applied in the last two months. Which of the following most likely occurred?

a)

The end user changed the file permissions

b)

A cryptographic collision was detected

c)

A snapshot of the file system was taken

d)

A rootkit was deployed

20.

A newly appointed board member with cybersecurity knowledge wants the board of

directors to receive a quarterly report detailing the number of incidents that impacted the

organization. The systems administrator is creating a way to present the data to the board of

directors. Which of the following should the systems administrator use?

a)

Packet captures

b)

Vulnerability scans

c)

Metadata

d)

Dashboard