NEW
Font size
WorksheetsCompTIA Sec+ Chapter 3, 2nd Attempt Missed
Total questions: 23
Worksheet time: 23mins
Chris is preparing to implement an 802.1X-enabled wireless infrastructure. He knows that he wants to use an Extensible Authentication Protocol (EAP)-based protocol that does not require client-side certificates. Which of the following options should he choose?
EAP-MD5
PEAP
LEAP
EAP-TLS
Mark is responsible for managing his company's load balancer and wants to use a load-balancing scheduling technique that will take into account the current server load and active sessions. Which of the following techniques should he choose?
Source IP hashing
Weighted response time
Least connection
Round robin
Which design concept limits access to systems from outside users while protecting users and systems inside the LAN?
DMZ
VLAN
Router
Guest network
Which of the following is the equivalent of a VLAN from a physical security perspective?
Perimeter security
Partitioning
Security zones
Firewall
Which type of firewall examines the content and context of each packet it encounters?
Packet filtering firewall
Stateful packet filtering firewall
Application layer firewall
Gateway firewall
You're designing a new network infrastructure so that your company can allow unauthenticated users connecting from the Internet to access certain areas. Your goal is to protect the internal network while providing access to those areas. You decide to put the web server on a separate subnet open to public contact. What is this subnet called?
Guest network
DMZ
Intranet
VLAN
Hans is a security administrator for a large company. Users on his network visit a wide range of websites. He is concerned they might get malware from one of these many websites. Which of the following would be his best approach to mitigate this threat?
Implement host-based antivirus.
Blacklist known infected sites.
Set browsers to allow only signed components.
Set browsers to block all active content (ActiveX, JavaScript, etc.).
You work at a large company. You are concerned about ensuring that all workstations have a common configuration, that no rogue software is installed, and that all patches are kept up to date. Which of the following would be the most effective for accomplishing this?
Use VDI.
Implement restrictive policies.
Use an image for all workstations.
Implement strong patch management.
Edward is responsible for web application security at a large insurance company. One of the applications that he is particularly concerned about is used by insurance adjusters in the field. He wants to have strong authentication methods to mitigate misuse of the application. What would be his best choice?
Authenticate the client with a digital certificate.
Implement a very strong password policy.
Secure application communication with Transport Layer Security (TLS).
Implement a web application firewall (WAF).
Samantha has used ssh-keygen to generate new SSH keys. Which SSH key should she place on the server she wants to access, and where is it typically stored on a Linux system?
Her public SSH key, /etc/
Her private SSH key, /etc/
Her public SSH key, ~/.ssh/
Her private SSH key, ~/.ssh/
What type of topology does an ad hoc wireless network use?
Point-to-multipoint
Star
Point-to-point
Bus
Matt has enabled port security on the network switches in his building. What does port security do?
Filters by MAC address
Prevents routing protocol updates from being sent from protected ports
Establishes private VLANs
Prevents duplicate MAC addresses from connecting to the network
Amanda wants to allow users from other organizations to log in to her wireless network. What technology would allow her to do this using their own home organization's credentials?
Pre-shared keys
802.11q
RADIUS federation
OpenID Connect
You work for a social media website. You wish to integrate your users' accounts with other web resources. To do so, you need to allow authentication to be used across different domains, without exposing your users' passwords to these other services. Which of the following would be most helpful in accomplishing this goal?
Kerberos
SAML
OAuth
OpenID
Amelia is looking for a network authentication method that can use digital certificates and does not require end users to remember passwords. Which of the following would best fit her requirements?
OAuth
Tokens
OpenID
RBAC
Patrick has been asked to identify a UTM appliance for his organization. Which of the following capabilities is not a common feature for a UTM device?
IDS and or IPS
Antivirus
MDM
DLP
Gary is designing his cloud infrastructure and needs to provide a firewall-like capability for the virtual systems he is running. Which of the following cloud capabilities acts like a virtual firewall?
Security groups
Dynamic resource allocation
VPC endpoints
Instance awareness
In which of the following scenarios would using a shared account pose the least security risk?
For a group of tech support personnel
For guest Wi-Fi access
For students logging in at a university
For accounts with few privileges
Mike's manager has asked him to verify that the certificate chain for their production website is valid. What has she asked Mike to validate?
That the certificate has not been revoked
That users who visit the website can verify that the site and the CAs in the chain are all trustworthy
That the encryption used to create the certificate is strong and has not been cracked
That the certificate was issued properly and that prior certificates issued for the same system have also been issued properly
Magnus is concerned about someone using a password cracker on computers in his company. He is concerned that crackers will attempt common passwords in order to log in to a system. Which of the following would be best for mitigating this threat?
Password age restrictions
Password minimum length requirements
Account lockout policies
Account usage auditing
Susan has configured a virtual private network (VPN) so that traffic destined for systems on her corporate network is routed over the VPN but traffic sent to other destinations is sent out via the VPN user's local network. What is this configuration called?
Half-pipe
Full-tunnel
Split-tunnel
Split horizon
Ben is preparing to implement a firewall for his network and is considering whether to implement an open source firewall or a proprietary commercial firewall. Which of the following is not an advantage of an open source firewall?
Lower cost
Community code validation
Maintenance and support
Speed of acquisition
Which of the following is not a common way to validate control over a domain for a domain-validated X.509 certificate?
Changing the DNS TXT record
Responding to an email sent to a contact in the domain’s WHOIS information
Publishing a nonce provided by the certificate authority as part of the domain information
Changing the IP addresses associated with the domain
