WorksheetsMock Exam 3 (Sec + 701)
Total questions: 60
Worksheet time: 43mins
A hacker uses a program to flood a network with packets, causing it to become unavailable to users. Which type of attack is this?
Phishing
DDoS
SQL Injection
Cross-site scripting
What is a common security risk associated with SQL injection attacks?
Unauthorized access to databases
Execution of malicious scripts in web browsers
Theft of user authentication credentials
Disclosure of sensitive information via email
Scenario: A user receives an email with a link prompting them to update their online banking credentials. Upon clicking the link, they are directed to a website that looks identical to their bank's website but is hosted on a different domain. What type of attack is this?
Man-in-the-middle
Spoofing
Phishing
Spear phishing
What is the primary goal of a buffer overflow attack?
To disrupt the normal operations of a web server
To execute arbitrary code on the target system by overwriting memory
To execute an arithmetic operation that exceeds the maximum size of the integer type used to store it
To insert comments in a log file
Scenario: An attacker sends a specially crafted packet to a network device, causing it to crash or become unresponsive. What type of attack is this?
Buffer overflow
SQL injection
Denial of Service (DoS)
Cross-site scripting
What is the purpose of using VLANs (Virtual Local Area Networks)?
To improve network performance
To segment broadcast domains
To increase the speed of data transmission
To prevent unauthorized access to network devices
Scenario: An organization is designing a new network infrastructure and wants to ensure that users can securely access resources remotely. Which technology should be implemented to provide secure remote access?
SSL VPN
WPA2-Enterprise
MAC filtering
NAT (Network Address Translation)
Which cryptographic algorithm is commonly used for digital signatures and key exchange?
DES (Data Encryption Standard)
RSA (Rivest-Shamir-Adleman)
AES (Advanced Encryption Standard)
MD5 (Message Digest Algorithm 5)
Scenario: An organization is implementing a network security control that inspects and filters incoming and outgoing network traffic based on predetermined security rules. Which type of security control is this?
Firewall
IDS (Intrusion Detection System)
IPS (Intrusion Prevention System)
VPN (Virtual Private Network)
What is the purpose of using hashing algorithms in cryptography?
To encrypt data for secure transmission
To compress data for efficient storage
To verify the integrity of data
To authenticate users during login processes
Scenario: An organization is implementing a BYOD (Bring Your Own Device) policy to allow employees to use their personal devices for work purposes. What security measure should be implemented to protect corporate data on personal devices?
Containerization
MAC filtering
VLAN segmentation
Intrusion Detection System (IDS)
Which of the following is a best practice for securing wireless networks?
Disabling encryption to improve performance
Broadcasting SSID (Service Set Identifier) to facilitate connections
Enabling WPA2-Enterprise encryption with strong authentication
Using default admin credentials for easy access management
Scenario: An organization is deploying a web application that handles sensitive customer information. What security measure should be implemented to protect the confidentiality of data transmitted between the web server and clients?
Implementing CAPTCHA on all forms
Using strong, unique passwords for user accounts
Encrypting data in transit with SSL/TLS
Regularly updating the web server's software
What is the primary purpose of deploying host-based intrusion detection systems (HIDS)?
To monitor network traffic for suspicious activities
To detect and prevent unauthorized access to network devices
To monitor system logs and file integrity on individual hosts
To authenticate users before granting access to network resources
Which security control is commonly used to protect against malware infections on endpoints?
Patch management
VLAN segregation
MAC filtering
NAT (Network Address Translation)
Scenario: An organization has experienced a security breach resulting in unauthorized access to sensitive customer data. What is the first step the incident response team should take?
Notify law enforcement agencies
Contain the breach to prevent further damage
Restore affected systems from backups
Conduct a post-incident review
What is the primary purpose of performing a vulnerability scan?
To identify and mitigate security vulnerabilities
To recover data after a security incident
To test the effectiveness of security controls
To investigate the root cause of security breaches
Scenario: An organization has detected unusual network activity indicating a potential security incident. What action should be taken to investigate the incident further?
Review network logs and traffic patterns
Restore affected systems from backups
Notify senior management immediately
Ignore the incident as it may be a false positive
What is the role of a Security Operations Center (SOC) in an organization?
To provide technical support to end-users
To monitor and respond to security incidents
To develop security policies and procedures
To conduct vulnerability assessments
Scenario: An organization has experienced a data breach resulting in the exposure of sensitive customer information. What action should be taken to notify affected individuals and regulatory authorities?
Send an email notification to affected individuals
Post a notice on the company website
File a report with the appropriate regulatory authorities
Ignore the breach and hope it goes unnoticed
Which of the following regulations sets requirements for protecting sensitive information related to credit card transactions?
HIPAA (Health Insurance Portability and Accountability Act)
GDPR (General Data Protection Regulation)
PCI DSS (Payment Card Industry Data Security Standard)
FERPA (Family Educational Rights and Privacy Act)
Scenario: An organization is developing a security policy to define acceptable use of company-owned devices. What should be included in the policy?
Guidelines for securing personal devices
Procedures for reporting security incidents
Requirements for updating antivirus software
Recommendations for securing home networks
What is the purpose of a security risk assessment?
To identify and mitigate security vulnerabilities
To recover data after a security incident
To enforce compliance with regulatory requirements
To provide evidence of security controls
Scenario: An organization is planning to implement a new cloud-based storage solution for storing sensitive company data. What should be included in the cloud security policy?
Guidelines for sharing account credentials with third-party vendors
Procedures for encrypting data before uploading it to the cloud
Requirements for storing sensitive data in plain text format
Recommendations for disabling multi-factor authentication
What is the primary purpose of conducting security awareness training for employees?
To eliminate the need for technical controls
To prevent all security incidents
To educate employees about security risks and best practices
To increase network performance
Scenario: An organization has identified a critical security vulnerability in a third-party software application used for processing customer payments. What action should be taken to mitigate the risk posed by the vulnerability?
Ignore the vulnerability as it might not be exploited
Inform the software provider and wait for a patch
Immediately disconnect the application from the network
Apply a temporary workaround until a patch is available
Scenario: An organization is planning to decommission several legacy servers that are no longer in use. What is the recommended approach for securely decommissioning the servers?
Delete all data from the servers and repurpose them for other use
Physically destroy the servers to prevent data leakage
Conduct a data wipe to ensure all sensitive information is removed
Transfer ownership of the servers to a third-party vendor
Scenario: An organization is experiencing a high volume of spam emails containing malicious attachments. What security measure should be implemented to mitigate the risk posed by these emails?
Implement email encryption to protect sensitive information
Deploy email filtering and anti-malware software
Disable email forwarding to prevent unauthorized access
Train employees to recognize and report suspicious emails
Scenario: An organization has detected unauthorized access to its network resources from an unknown IP address. What action should be taken to respond to the incident?
Block the IP address at the firewall to prevent further access
Notify law enforcement agencies to investigate the incident
Ignore the incident as it may be a false positive
Conduct a vulnerability scan to identify other potential vulnerabilities
Scenario: An organization has discovered that an employee's laptop containing sensitive company information has been stolen. What immediate step should the organization take to secure the data?
Report the theft to the police and wait for their investigation
Remotely wipe the laptop to remove all sensitive data
Inform the company's legal team to prepare for potential lawsuits
Conduct a company-wide meeting to discuss data security policies
Which of the following is an example of a technical control?
Security policy
Security awareness training
Intrusion Detection System (IDS)
Disaster recovery plan
What is the purpose of a security baseline?
To monitor network traffic
To establish a minimum level of security for systems
To provide evidence of compliance
To eliminate the need for security controls
Which of the following is a security control designed to prevent phishing attacks?
SSL/TLS encryption
Penetration testing
Security awareness training
Intrusion Detection System (IDS)
What is the primary goal of an audit trail?
Providing evidence of compliance
Detecting and responding to security breaches
Preventing all security incidents
Increasing network performance
Which of the following is a security control designed to prevent unauthorized access to physical facilities?
Firewall
Biometric authentication
Antivirus software
Encryption
What is the purpose of a vulnerability assessment?
Identifying potential security threats
Identifying security vulnerabilities
Documenting security incidents
Increasing network performance
Which of the following is an example of a security control designed to protect against social engineering attacks?
Security awareness training
Encryption
Firewall
Intrusion Detection System (IDS)
What is the primary goal of incident response planning?
Minimizing the impact of security incidents
Identifying potential security threats
Preventing all security incidents
Increasing network performance
Which of the following is a security control designed to prevent unauthorized access to a network?
Firewall
Intrusion Detection System (IDS)
Security awareness training
Password complexity requirements
What is the purpose of a security incident response plan?
Documenting security incidents
Identifying potential security threats
Providing guidance on how to respond to security breaches
Increasing network performance
Scenario: An organization is implementing a new web application to facilitate online transactions. What security measure should be implemented to protect customer data transmitted over the internet?
SSL/TLS encryption
MAC filtering
Port security
Network segmentation
Scenario: An organization is planning to implement a disaster recovery plan to ensure business continuity in the event of a natural disaster. What component should be included in the plan to mitigate the risk of data loss?
Regular data backups
Redundant power supplies
Uninterruptible power sources (UPS)
Geographically dispersed data centers
Scenario: An organization has detected unauthorized access attempts to its network resources from multiple IP addresses. What security measure should be implemented to prevent further unauthorized access?
Implement multi-factor authentication
Disable unused network ports
Enable MAC filtering on network devices
Conduct a security audit of network configurations
Scenario: An organization is planning to migrate its email infrastructure to a cloud-based platform. What security measure should be implemented to protect email communications from unauthorized access?
Enable email encryption
Use strong password policies
Implement email filtering and anti-malware software
Disable email forwarding
Scenario: An organization has experienced a security incident resulting in the loss of sensitive customer information. What action should be taken to notify affected individuals and regulatory authorities?
File a report with the appropriate regulatory authorities
Send an email notification to affected individuals
Ignore the incident as it may be a false positive
Offer credit monitoring services to affected individuals
Which of the following is a security control designed to prevent malware infections?
Patch management
Security awareness training
Encryption
Intrusion Detection System (IDS)
What is the purpose of a vulnerability assessment?
Identifying potential security threats
Identifying security vulnerabilities
Documenting security incidents
Increasing network performance
Which of the following is a security control designed to protect against social engineering attacks?
Firewalls
Antivirus software
User awareness training
Data encryption
What is the primary goal of an audit trail?
Providing evidence of compliance
Detecting and responding to security breaches
Preventing all security incidents
Increasing network performance
Which of the following is an example of a security control designed to prevent unauthorized access to physical facilities?
Biometric authentication
Security awareness training
Firewall
Intrusion Detection System (IDS)
Scenario: An organization is planning to deploy a new wireless network to provide internet access to employees and guests. What security measure should be implemented to prevent unauthorized access to the wireless network?
Implement WEP encryption
Enable MAC filtering
Broadcast SSID (Service Set Identifier)
Use default admin credentials
Scenario: An organization is developing a security policy to enforce password complexity requirements for user accounts. What should be included in the policy?
Requiring users to change their passwords every six months
Allowing users to reuse their previous passwords
Enforcing a minimum password length and requiring the use of special characters
Scenario: An organization is planning to implement a data backup strategy to protect critical business data. What should be included in the backup strategy?
Backing up data to a single location
Encrypting backup data to improve security
Testing backup and recovery procedures regularly
Storing backup data on the same server as the original data
Scenario: An organization is experiencing a high volume of spam emails containing malicious attachments. What security measure should be implemented to mitigate the risk posed by these emails?
Implement email encryption to protect sensitive information
Deploy email filtering and anti-malware software
Disable email forwarding to prevent unauthorized access
Train employees to recognize and report suspicious emails
Scenario: An organization has detected unauthorized access to its network resources from an unknown IP address. What action should be taken to respond to the incident?
Block the IP address at the firewall to prevent further access
Notify law enforcement agencies to investigate the incident
Ignore the incident as it may be a false positive
Conduct a vulnerability scan to identify other potential vulnerabilities
Which of the following is an example of a technical control?
Security policy
Background checks
Firewall
Security awareness training
Which of the following is a key component of a disaster recovery plan?
Annual company retreats
Data backup and recovery
Employee performance reviews
Customer loyalty programs
Which of the following is an example of a security control designed to prevent data leakage?
Security policy enforcement
Intrusion Detection System (IDS)
Security awareness training
Encryption
What is the purpose of a vulnerability assessment?
Identifying security vulnerabilities
Implementing security controls
Auditing network configurations
Developing security policies
Which of the following is a security control designed to prevent unauthorized access to a wireless network?
IDS/IPS
MAC filtering
VLAN segregation
Port security
