wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

CompTIA Sec+ Chapter 3, 2nd Attempt Missed

Total questions: 23

Worksheet time: 23mins

Name
Class
Date
1.

Chris is preparing to implement an 802.1X-enabled wireless infrastructure. He knows that he wants to use an Extensible Authentication Protocol (EAP)-based protocol that does not require client-side certificates. Which of the following options should he choose?

a)

EAP-MD5

b)

PEAP

c)

LEAP

d)

EAP-TLS

2.

Mark is responsible for managing his company's load balancer and wants to use a load-balancing scheduling technique that will take into account the current server load and active sessions. Which of the following techniques should he choose?

a)

Source IP hashing

b)

Weighted response time

c)

Least connection

d)

Round robin

3.

Which design concept limits access to systems from outside users while protecting users and systems inside the LAN?

a)

DMZ

b)

VLAN

c)

Router

d)

Guest network

4.

Which of the following is the equivalent of a VLAN from a physical security perspective?

a)

Perimeter security

b)

Partitioning

c)

Security zones

d)

Firewall

5.

Which type of firewall examines the content and context of each packet it encounters?

a)

Packet filtering firewall

b)

Stateful packet filtering firewall

c)

Application layer firewall

d)

Gateway firewall

6.

You're designing a new network infrastructure so that your company can allow unauthenticated users connecting from the Internet to access certain areas. Your goal is to protect the internal network while providing access to those areas. You decide to put the web server on a separate subnet open to public contact. What is this subnet called?

a)

Guest network

b)

DMZ

c)

Intranet

d)

VLAN

7.

Hans is a security administrator for a large company. Users on his network visit a wide range of websites. He is concerned they might get malware from one of these many websites. Which of the following would be his best approach to mitigate this threat?

a)

Implement host-based antivirus.

b)

Blacklist known infected sites.

c)

Set browsers to allow only signed components.

d)

Set browsers to block all active content (ActiveX, JavaScript, etc.).

8.

You work at a large company. You are concerned about ensuring that all workstations have a common configuration, that no rogue software is installed, and that all patches are kept up to date. Which of the following would be the most effective for accomplishing this?

a)

Use VDI.

b)

Implement restrictive policies.

c)

Use an image for all workstations.

d)

Implement strong patch management.

9.

Edward is responsible for web application security at a large insurance company. One of the applications that he is particularly concerned about is used by insurance adjusters in the field. He wants to have strong authentication methods to mitigate misuse of the application. What would be his best choice?

a)

Authenticate the client with a digital certificate.

b)

Implement a very strong password policy.

c)

Secure application communication with Transport Layer Security (TLS).

d)

Implement a web application firewall (WAF).

10.

Samantha has used ssh-keygen to generate new SSH keys. Which SSH key should she place on the server she wants to access, and where is it typically stored on a Linux system?

a)

Her public SSH key, /etc/

b)

Her private SSH key, /etc/

c)

Her public SSH key, ~/.ssh/

d)

Her private SSH key, ~/.ssh/

11.

What type of topology does an ad hoc wireless network use?

a)

Point-to-multipoint

b)

Star

c)

Point-to-point

d)

Bus

12.

Matt has enabled port security on the network switches in his building. What does port security do?

a)

Filters by MAC address

b)

Prevents routing protocol updates from being sent from protected ports

c)

Establishes private VLANs

d)

Prevents duplicate MAC addresses from connecting to the network

13.

Amanda wants to allow users from other organizations to log in to her wireless network. What technology would allow her to do this using their own home organization's credentials?

a)

Pre-shared keys

b)

802.11q

c)

RADIUS federation

d)

OpenID Connect

14.

You work for a social media website. You wish to integrate your users' accounts with other web resources. To do so, you need to allow authentication to be used across different domains, without exposing your users' passwords to these other services. Which of the following would be most helpful in accomplishing this goal?

a)

Kerberos

b)

SAML

c)

OAuth

d)

OpenID

15.

Amelia is looking for a network authentication method that can use digital certificates and does not require end users to remember passwords. Which of the following would best fit her requirements?

a)

OAuth

b)

Tokens

c)

OpenID

d)

RBAC

16.

Patrick has been asked to identify a UTM appliance for his organization. Which of the following capabilities is not a common feature for a UTM device?

a)

IDS and or IPS

b)

Antivirus

c)

MDM

d)

DLP

17.

Gary is designing his cloud infrastructure and needs to provide a firewall-like capability for the virtual systems he is running. Which of the following cloud capabilities acts like a virtual firewall?

a)

Security groups

b)

Dynamic resource allocation

c)

VPC endpoints

d)

Instance awareness

18.

In which of the following scenarios would using a shared account pose the least security risk?

a)

For a group of tech support personnel

b)

For guest Wi-Fi access

c)

For students logging in at a university

d)

For accounts with few privileges

19.

Mike's manager has asked him to verify that the certificate chain for their production website is valid. What has she asked Mike to validate?

a)

That the certificate has not been revoked

b)

That users who visit the website can verify that the site and the CAs in the chain are all trustworthy

c)

That the encryption used to create the certificate is strong and has not been cracked

d)

That the certificate was issued properly and that prior certificates issued for the same system have also been issued properly

20.

Magnus is concerned about someone using a password cracker on computers in his company. He is concerned that crackers will attempt common passwords in order to log in to a system. Which of the following would be best for mitigating this threat?

a)

Password age restrictions

b)

Password minimum length requirements

c)

Account lockout policies

d)

Account usage auditing

21.

Susan has configured a virtual private network (VPN) so that traffic destined for systems on her corporate network is routed over the VPN but traffic sent to other destinations is sent out via the VPN user's local network. What is this configuration called?

a)

Half-pipe

b)

Full-tunnel

c)

Split-tunnel

d)

Split horizon

22.

Ben is preparing to implement a firewall for his network and is considering whether to implement an open source firewall or a proprietary commercial firewall. Which of the following is not an advantage of an open source firewall?

a)

Lower cost

b)

Community code validation

c)

Maintenance and support

d)

Speed of acquisition

23.

Which of the following is not a common way to validate control over a domain for a domain-validated X.509 certificate?

a)

Changing the DNS TXT record

b)

Responding to an email sent to a contact in the domain’s WHOIS information

c)

Publishing a nonce provided by the certificate authority as part of the domain information

d)

Changing the IP addresses associated with the domain