wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

zubeyirr

Total questions: 30

Worksheet time: 15mins

Name
Class
Date
1.

A security administrator needs to create a RAID configuration that is focused on high read/write speeds and fault tolerance. It is unlikely that multiple drives will fail simultaneously. Which of the following RAID configurations should the administrator use?

a)
  • RAID 0

b)
  • RAID 1

c)
  • RAID 5

d)
  • RAID 10

2.

A certificate vendor notified a company that recently invalidated certificates may need to be updated. Which of the following mechanisms should a security administrator use to determine whether the certificates installed on the company's machines need to be updated?

a)
  • CRL

b)
  • CSR

c)
  • OCSP

d)
  • SCEP

3.

A company wants to build a new website to sell products online. The website will host a storefront application that will allow visitors to add products to a shopping cart and pay for the products using a credit card. Which of the following protocols would be the MOST secure to implement?

a)

SSL

b)

SFTP

c)

SNMP

d)

TLS

4.

In a rush to meet an end-of-year business goal, the IT department was told to implement a new business application. The security engineer reviews the attributes of the application and decides the time needed to perform due diligence is insufficient from a cybersecurity perspective. Which of the following BEST describes the security engineer's response?

a)
  • Risk appetite

b)
  • Risk importance

c)
  • Risk acceptance

d)
  • Risk tolerance

5.

While assessing the security of a web application, a security analyst was able to introduce unsecure strings through the application input fields by bypassing client-side controls. Which of the following solutions should the analyst recommend?

a)
  • Server-side validation

b)
  • Secure cookies

c)
  • Host-based intrusion detection system

d)
  • Code signing

6.

The local administrator account for a company’s VPN appliance was unexpectedly used to log in to the remote management interface. Which of the following would have prevented this from happening?

a)
  • Implementing multifactor authentication

b)
  • Assigning individual user IDs

c)
  • Changing the default password

d)
  • Using least privilege

7.

Which of the following should a security administrator adhere to when setting up a new set of firewall rules?

a)
  • Business continuity plan

b)
  • Change management procedure

c)
  • cident response procedure

d)
  • Disaster recovery plan

8.

A root cause analysis reveals that a web application outage was caused by one of the company's developers uploading a newer version of the third-party libraries that were shared among several applications. Which of the following implementations would be BEST to prevent this issue from reoccurring?

a)

CASB

b)

SWG

c)

Containerization

d)

Automated failover

9.

Which of the following techniques eliminates the use of rainbow tables for password cracking?

a)

Hashing

b)

Tokenization

c)

Asymmetric encryption

d)

Salting

10.

Which of the following is MOST likely to outline the roles and responsibilities of data controllers and data processors?

a)
  • ISO 31000

b)
  • GDPR

c)
  •  PCI DSS

d)
  • SSAE SOC 2

11.

An upcoming project focuses on secure communications and trust between external parties. Which of the following security components will need to be considered to ensure a chosen trust provider IS used and the selected option is highly scalable?

a)

Domain validation

b)

Public key Infrastructure

c)

Self-signed certificate

d)

Certificate attributes

12.

A security administrator performs weekly vulnerability scans on all cloud assets and provides a detailed report. Which of the following describes the administrator’s activities?

a)

Data processor

b)

Data owners

c)

Continuous integration

d)

Continuous deployment

13.

A security administrator performs weekly vulnerability scans on all cloud assets and provides a detailed report. Which of the following describes the administrator's activities?

a)

Continuous integration

b)

Continuous validation

c)

Continuous monitoring

d)

Continuous deployment

14.

Which of the following best describes the situation where a successfully onboarded employee who is using a fingerprint reader is denied access at the company's mam gate?

a)

Crossover error rate

b)

False positive

c)

False rejection

d)

False match raw

15.

During an incident a company CIRT determine it is necessary to observe the continued network-based transaction between a callback domain and the malware running on an enterprise PC. Which of the following techniques would be BEST to enable this activity while reducing the risk of lateral spread and the risk that the adversary would notice any changes?

a)

Apply network blacklisting rules for the adversary domain

b)

Emulate the malware in a heavily monitored DMZ segment.

c)

Create and apply micro segmentation rules.

d)

Physical move the PC to a separate internet pint of presence

16.

A company has discovered unauthorized devices are using its WiFi network, and it wants to harden the access point to improve security. Which of the following configurations should an analyst enable to improve security? (Choose two.)

a)

SSL

b)

WPA-TKIP

c)

WPA2-PSK

d)

RADIUS

e)

EAP-PEAP

17.

A corporate security team needs to secure the wireless perimeter of its physical facilities to ensure only authorized users can access corporate resources. Which of the following should the security team do?

a)

Create heat maps.

b)

Check for channel overlaps.

c)

Identify rogue access points.

d)

Implement domain hijacking.

18.

A new security engineer has started hardening systems. One o( the hardening techniques the engineer is using involves disabling remote logins to the NAS. Users are now reporting the inability lo use SCP to transfer files to the NAS, even though the data is still viewable from the users' PCs. Which of the following is the MOST likely cause of this issue?

a)

Network services are no longer running on the NAS

b)

Remote login was disabled in the networkd.conf instead of using the sshd. conf.

D.

c)

TFTP was disabled on the local hosts.

d)

SSH was turned off instead of modifying the configuration file.

19.

An organization’s Chief Information Security Officer is creating a position that will be responsible for implementing technical controls to protect data, including ensuring backups are properly maintained. Which of the following roles would MOST likely include these responsibilities?

a)
  • Internal auditor

b)
  • Data custodian

c)
  • Backup administrator

d)
  • Data protection officer

e)
  • Data owner

20.

Which of the following allow access to remote computing resources, a operating system. and centrdized configuration and data

a)

Edge computing

b)

Infrastructure as a service

c)

Containers

d)

Thin client

21.

Stakeholders at an organization must be kept aware of any incidents and receive updates on status changes as they occur. Which of the following plans would fulfill this requirement?

a)

Communication plan

b)

Disaster recovery plan

c)

Business continuity plan

d)

Risk plan

22.

Which of the following should an organization consider implementing in the event executives need to speak to the media after a publicized data breach?

a)

Communication plan

b)

Business continuity plan

c)

Incident response plan

d)

Disaster recovery pl

23.

A company wants the ability to restrict web access and monitor the websites that employees visit. Which of the following would best meet these requirements?

a)

Firewall

b)

VPN

c)

WAF

d)
  • Internet proxy

24.

A security operations center wants to implement a solution that can execute files to test for malicious activity. The solution should provide a report of the files' activity against known threats.

Which of the following should the security operations center implement?

a)

Sn1per

b)

Cuckoo

c)

theHarvester

d)

Nessus

25.

A recent vulnerability scan revealed multiple servers have non-standard ports open for applications that are no longer in use. The security team is working to ensure all devices are patched and hardened. Which of the following would the security team perform to ensure the task is completed with minimal impact to production?

a)
  • Enable HIDS on all servers and endpoints.

b)
  • Ensure the antivirus is up to date.

c)
  • Configure the deny list appropriately on the NGFW

d)
  • Disable unnecessary services.

26.

A company is launching a website in a different country in order to capture user information that a marketing business can use. The company itself will not be using the information. Which of the following roles is the company assuming?

a)
  • Data collector

b)
  • Data steward

c)
  • Data processor

d)
  • Data owner

27.

Stakeholders at an organization must be kept aware of any incidents and receive updates on status changes as they occur. Which of the following plans would fulfill this requirement?

a)
  • Risk plan

b)
  • Disaster recovery plan

c)
  • Communication plan

d)
  • Business continuity plan

28.

A network architect wants a server to have the ability to retain network availability even if one of the network switches it is connected to goes down. Which of the following should the architect implement on the server to achieve this goal?

a)

Load balancing

b)

NIC teaming

c)

RAID

d)

UPS

29.

A company is under investigation for possible fraud. As part of the investigation, the authorities need to review all emails and ensure data is not deleted. Which of the following should the company implement to assist in the investigation?

a)
  • Content filter

b)
  • Data loss prevention

c)
  • Legal hold

30.

A user wanted to catch up on some work over the weekend but had issues logging in to the corporate network using a VPN. On Monday, the user opened a ticket for this issue but was able to log in successfully. Which of the following BEST describes the policy that is being implemented?

a)
  • Network location

b)
  • Password history

c)
  • Geofencing

d)
  • Time-based logins