Font size
WorksheetsCybersecurity Midterm
Total questions: 93
Worksheet time: 47mins
You have hired 10 new temporary workers who will be with the company for three months. You want to make sure that the user accounts cannot be used for login after that time period. What should you do?
Configure account lockout in Group Policy.
Configure account policies in Group Policy.
Configure account expiration in the user accounts.
Configure day/time restrictions in the user accounts.
Which Microsoft tool can be used to review a system's security configuration against recommended settings?
Microsoft Security Compliance Toolkit
Registry Editor
Microsoft Internet Explorer
Windows Defender
Which type of update should be prioritized even outside of a normal patching window?
Microsoft updates
Security updates
Critical updates
Monthly updates
Which of the following makes this documentation more useful? (select 3)
Have a printed hard copy kept in a secure location.
Identify the choke points on the network.
Automate administration as much as possible.
Identify who is responsible for each device.
Which of the following tools can you use on a Windows network to automatically distribute and install software and operating system patches on workstations? (Select two.)
WSUS
Security Templates
Group Policy
Security Configuration and Analysis
Which of the following describes a configuration baseline?
A list of common security settings that a group or all devices share
A collection of security settings that can be automatically applied to a device
A set of performance statistics that identifies normal operating performance
The minimum services required for a server to function
By definition, what is the process of reducing security exposure and tightening security controls?
Hardening
Passive reconnaissance
Social engineering
Active scanning
Which of the following is the strongest form of multi-factor authentication?
A password, a biometric scan, and a token device
Two-factor authentication
A password and a biometric scan
Two passwords
You have placed a File Transfer Protocol (FTP) server in your DMZ behind your firewall. The FTP server is to be used to distribute software updates and demonstration versions of your products. However, users report that they are unable to access the FTP server. What should you do to enable access?
Move the FTP outside of the firewall.
Install a VPN.
Open ports 20 and 21 for outbound connections.
Define user accounts for all external visitors.
FTPS uses which mechanism to provide security for authentication and data transfer?
Multi-factor authentication
SSL
IPsec
Token devices
To transfer files to your company's internal network from home, you use FTP. The administrator has recently implemented a firewall at the network perimeter and disabled as many ports as possible. You can no longer make the FTP connection. You suspect the firewall is causing the issue. Which ports need to remain open so you can still transfer the files? (Select two.)
21
443
23
80
20
You want to close all ports associated with NetBIOS on your network's firewall to prevent attacks directed against NetBIOS. Which ports should you close?
67, 68
135, 137-139
161, 162
389, 636
Which of the following file transfer protocols use SSH to provide confidentiality during the transfer? (Select two.)
HTTPS
SCP
FTPS
FTP
SFTP
You need to increase the security of your Linux system by finding and closing open ports. Which of the following commands should you use to locate open ports?
traceroute
nslookup
nmap
Netstat
Which action would you use in a rule to disallow a connection silently?
Accept
Drop
Reject
Forward
In which of the iptables default chains would you configure a rule to allow an external device to access the HTTPS port on the Linux server?
Forward
Input
Accept
Output
Which type of packet would the sender receive if they sent a connection request to TCP port 25 on a server with the following command applied: sudo iptables -A OUTPUT -p tcp --dport 25 -j REJECT
ICMP Unreachable Port
SYN
RST
ACK
You have configured the following rules. What is the effect? sudo iptables -A INPUT -p tcp --dport 25 -m conntrack --ctstate NEW,ESTABLISHED -j ACCEPT sudo iptables -A OUTPUT -p tcp --sport 25 -m conntrack --ctstate ESTABLISHED -j ACCEPT
Allow SMTP traffic
Block SMTP traffic
Block SSH traffic
Allow SSH traffic
Which command would you use to list all of the currently defined iptables rules?
sudo /sbin/iptables-save
sudo iptables -F
sudo iptables -A INPUT -j DROP
sudo iptables -L
When a cryptographic system is used to protect data confidentiality, what actually takes place? (select 2)
Encrypted data transmission is prohibited.
Data is protected from corruption or change.
Unauthorized users are prevented from viewing or accessing the resource.
Data is available for access whenever authorized users need it.
An SSL client has determined that the certificate authority (CA) issuing a server's certificate is on its list of trusted CAs. What is the next step in verifying the server's identity?
The CA's public key must validate the CA's digital signature on the server certificate.
The master secret is generated from common keycode.
The domain on the server certificate must match the CA's domain name.
The post-master secret must initiate subsequent communication.
Which of the following would require that a certificate be placed on the CRL?
The private key is compromised.
The encryption key algorithm is revealed.
The certificate validity period is exceeded.
The signature key size is revealed.
Which technology was developed to help improve the efficiency and reliability of checking the validity status of certificates in large, complex environments?
Online Certificate Status Protocol
Certificate Revocation List
Private key recovery
Key escrow
A PKI is an implementation for managing which type of encryption?
Hashing
Asymmetric
Symmetric
Steganography
A remote access user needs to gain access to resources on the server. Which of the following processes are performed by the remote access server to control access to resources?
Identity proofing and authentication
Authorization and accounting
Identity proofing and authorization
Authentication and authorization
Authentication and accounting
Audit trails produced by auditing activities are which type of security control?
Detective
Deterrent
Directive
Preventative
Which of the following is used for identification? (select 3)
Cognitive question
Password
PIN
Username
Which of the following are examples of Something You Have authentication controls? (Select two.)
PIN
Handwriting analysis
Smartcard
Voicerecognition
Photo ID
Which of the following identification and authentication factors are often well known or easily discovered by others on the same network or system? (select 2)
PGP secret key
Password
Biometric reference profile
Username
Which of the following is a password that relates to things that people know, such as a mother's maiden name or a pet's name?
Dynamic
Passphrase
One-time
Cognitive
What is the process of controlling access to resources such as computers, files, or printers called?
Conditional access
Mandatory access control
Authentication
Authorization
Which of the following objects identifies a set of users with similar access needs?
Group
SACL
DACL
Permissions
Which of the following account types is a cloud-based identity and access management service that provides access to both internal and external resources?
Microsoft
Domain
AzureAD
Administrator
Which of the following account types uses a single sign-on system that lets you access Windows, Office 365, Xbox Live, and more?
Administrator
AzureAD
Microsoft
Domain
What should you do to a user account if the user goes on an extended vacation?
Remove all rights from the account
Disable the account
Monitor the account more closely
Delete the account
You are teaching new users about security and passwords. Which of the following is the BEST example of a secure password?
8181952
T1a73gZ9!
Stiles_2031
JoHnSmITh
Where should an organization's web server be placed?
DMZ
Extranet
Honeynet
Intranet
Which of the following is a privately controlled portion of a network that is accessible to some specific external entities?
Internet
MAN
Extranet
Intranet
You want to create a collection of computers on your network that appear to have valuable data but actually store fake data that could entice a potential intruder. Once the intruder connects, you want to be able to observe and gather information about the attacker's methods. Which features should you implement?
NIPS
Extranet
Honeynet
NIDS
Which of the following devices can apply quality of service and traffic-shaping rules based on what created the network traffic?
Application-aware devices
Proxy server
Network access control
All-in-one security appliances
Which item would provide the BEST security for this situation?
Firewall on your gateway server to the internet
All-in-one security appliance
Proxy server with access controls
Network access control system
All of the above
Which of the following terms describes a network device that is exposed to attacks and has been hardened against those attacks?
Circuit proxy
Bastion or sacrificial host
Multi-homed
Kernel proxy
Of the following security zones, which one can serve as a buffer network between a private secured network and the untrusted internet?
Intranet
Padded cell
DMZ
Extranet
Which of the following is the MOST likely to happen if the firewall managing traffic into the DMZ fails?
Only the servers in the DMZ are compromised, but the LAN will stay protected.
All devices in the DMZ and LAN will be compromised.
Nothing will happen - all devices will stay protected.
The LAN is compromised, but the DMZ stays protected.
What needs to be configured on a firewall to allow traffic directed to the public resource in the DMZ?
Subnet
VPN
Packet filters
FTP
Which of the following are features of an application-level gateway? (select 2)
Allows only valid packets within approved sessions
Reassembles entire messages
Verifies that packets are properly sequenced
Stops each packet at the firewall for inspection
Uses access control lists
You want to install a firewall that can reject packets that are not part of an active session. Which type of firewall should you use?
Application-level gateway
Circuit-level gateway
VPN concentrator
Packet-filtering firewall
Jessica needs to set up a firewall to protect her internal network from the internet. Which of the following would be the BEST type of firewall for her to use?
Hardware
Stateful
Software
Tunneling
You want to protect the laptop from internet-based attacks. Which solution should you use?
VPN concentrator
Network-based firewall
Host-based firewall
Proxy server
You want to connect your small company network to the internet. Your ISP provides you with a single IP address that is to be shared between all hosts on your private network. You do not want external hosts to be able to initiate connection to internal hosts. Which type of Network Address Translation (NAT) should you implement?
Restricted
Dynamic
Static
Shared
Which device is NAT typically implemented on?
RADIUS server
AD server
Gateway router
ISP router
At which layer of the OSI model do NAT routers operate?
Layer 3 (Network layer)
Layer 5 (Session layer)
Layer 1 (Physical layer)
Layer 7 (Application layer)
A VPN is primarily used for which of the following purposes?
Support secured communications over an untrusted network
Allow remote systems to save on long-distance charges
Support the distribution of public web documents
Allow the use of network-attached printers
Which VPN implementation uses routers on the edge of each site?
Always-on VPN
Host-to-host VPN
Remote access VPN
Site-to-site VPN
Which VPN tunnel style routes only certain types of traffic?
Split
Full
Site-to-site
Host-to-host
Which IPSec subprotocol provides data encryption?
AH
AES
ESP
SSL
You are investigating the use of website and URL content filtering to prevent users from visiting certain websites. Which benefits are the result of implementing this technology in your organization? (select 2)
Prevention of emails containing threats
Enforcement of the organization's internet usage policy
An increase in bandwidth availability
Identification and disposal of infected content
Prevention of phishing attempts
Travis is sending a highly confidential email to Craig that contains sensitive data. Which of the following should Travis implement to ensure that only Craig is able to read the email?
Encryption
Anti-phishing software
Virus scanner
Spam filter
Which of the following types of proxies would you use to remain anonymous when surfing the internet?
Reverse
Content filter
VPN
Forward
As the security analyst for your organization, you have noticed an increase in emails that attempt to trick users into revealing confidential information. Which web threat solutions should you implement to protect against these threats? (select 3)
Encryption
Proxies
Data loss prevention
Anti-phishing software
Which of the following NAC agent types would be used for IoT devices?
Dissolvable
Zero-trust
Permanent
Agentless
Which of the steps in the Network Access Control (NAC) implementation process occur once the policies have been defined?
Plan
Apply
Review
Test
Which of the following defines all the prerequisites a device must meet in order to access a network?
Identity Services Engine (ISE)
Authentication
Zero-trust security
Authorization
Which of the following applies the appropriate policies in order to provide a device with the access it's defined to receive?
Authentication
Identity Services Engine
Authorization
Zero-trust security
Which of the following NAC agent types creates a temporary connection?
Zero-trust
Dissolvable
Agentless
Permanent
You are the security analyst for your organization and have discovered evidence that someone is attempting to brute-force the root password on the web server. Which classification of attack type is this?
Inside
External
Passive
Active
An attacker sets up 100 drone computers that flood a DNS server with invalid requests. This is an example of which kind of attack?
Backdoor
Replay
DDoS
Spamming
In which of the following zones would a web server most likely be placed? (select 2)
High-trust zone
Medium-trust zone
No-trust zone
Low-trust zone
Which area of focus helps to identify weak network architecture or design?
Network baseline
Entry points
Inherent vulnerabilities
Documentation
Which classification of attack type does packet sniffing fall under?
Inside
External
Active
Passive
An attacker was able to gain unauthorized access to a mobile phone and install a Trojan horse so that he or she could bypass security controls and reconnect later. Which type of attack is this an example of?
Backdoor
Social engineering
Privilege escalation
Replay
In an effort to increase the security of your organization, programmers have been informed they can no longer bypass security during development. Which vulnerability are you attempting to prevent?
Replay
Social engineering
Privilege escalation
Backdoor
An attacker has gained access to the administrator's login credentials. Which type of attack has most likely occurred?
Buffer overflow
Privilege escalation
Password cracking
Backdoor
When setting up a new wireless access point, what is the first configuration change that should be made?
Default login
Encryption protocol
MAC filtering
SSID
Which common design feature among instant messaging clients make them less secure than other means of communicating over the internet?
Peer-to-peer networking
Real-time communication
Transfer of text and files
Freely available for use
Which type of application allows users to share and access content without using a centralized server?
Peer-to-peer software
Group Policy
Real-time communication
Instant messaging
Which of the following methods did Microsoft introduce in Windows 10 to help distribute OS updates?
File Transfer Protocol
Server download
Peer-to-peer software
Group Policy
Which of the following is a benefit of P2P applications?
Low-upload bandwidth
Strong security
Real-time communication
Shared resources
What do application control solutions use to identify specific applications?
Packet inspection
Flags
Application signatures
Whitelists
Which feature prevents switching loops and ensures there is only a single active path between any two switches?
Trunking
Spanning Tree Protocol
802.1x
Bonding
When configuring VLANs on a switch, which type of switch ports are members of all VLANs defined on the switch?
Uplink ports
Gigabit and higher Ethernet ports
Any port not assigned to a VLAN
Trunk ports
Which of the following switch attacks associates the attacker's MAC address with the IP address of the victim's devices?
DNS poisoning
Cross-site scripting (XSS)
ARP spoofing/poisoning
MAC spoofing
Which of the following attacks, if successful, causes a switch to function like a hub?
Replay attack
ARP poisoning
MAC flooding
MAC spoofing
You are adding switches to your network to support additional VLANs. Unfortunately, the new switches are from a different vendor than the current switches. Which standard do you need to ensure that the switches are supported?
802.3
802.1Q
802.1x
802.11
When configuring VLANs on a switch, what is used to identify which VLAN a device belongs to? (select 2)
MAC address
Switchport
Hostname
IP address
Which 802.1Q priority is IP phone traffic on a voice VLAN tagged with by default?
3
5
8
1
A virtual LAN can be created using which of the following?
Gateway
Router
Hub
Switch
You are creating a VLAN for voice over IP (VoIP). Which command should you use?
switchport vlan voice [number]
switchport voip vlan [number]
switchport voice vlan [number]
switchport vlan voip [number]
Which of the following should be configured on the router to filter traffic at the router level?
Telnet
Anti-spoofing rules
Access control list
SSH
Which of the following happens by default when you create and apply a new ACL on a router?
All traffic is blocked.
The ACL is ignored until applied.
All traffic is permitted.
ACLs are not created on a router.
Which type of ACL should be placed as close to the source as possible?
Basic
Standard
Extended
Advanced
You are deploying a brand new router. What is one of the first things you should do?
Secure the configuration file.
Update the firmware.
Configure anti-spoofing rules.
Configure SSH to access the router configuration.
Which of the following can make passwords use less on a router? (select 2)
Storing the router configuration file in a secure location
Using the MD5 hashing algorithm to encrypt the password
Using SSH to remotely connect to a router
Not controlling physical access to the router
