wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

SEC+ 001-025

Total questions: 25

Worksheet time: 13mins

Name
Class
Date
1.

Question #:1

A security administrator needs a method to secure data in an environment that includes some form of checks so that the administrator can track any changes. Which of the following should the administrator set up to achieve this goal?

a)

A

SPF

b)

B

GPO

c)

C

NAC

d)

D

FIM

2.

Question #:2

The local administrator account for a company's VPN appliance was unexpectedly used to log in to the remote management interface. Which of the following would have most likely prevented this from happening'?

a)

A

Using least privilege

b)

B

Changing the default password

c)

C

Assigning individual user IDs

d)

D

Reviewing logs more frequently

3.

Question #:3

A Chief Information Security Officer (CISO) wants to explicitly raise awareness about the increase of ransomware-as-a-service in a report to the management team. Which of the following best describes the threat actor in the CISO's report?

a)

A

Insider threat

b)

B

Hacktivist

c)

C

Nation-state

d)

D

Organized crime

4.

Question #:4

A security consultant needs secure, remote access to a client environment. Which of the following should the

security consultant most likely use to gain access?

a)

A

EAP

b)

B

DHCP

c)

C

IPSec

d)

D

NAT

5.

Question #:5

A systems administrator set up a perimeter firewall but continues to notice suspicious connections between internal endpoints. Which of the following should be set up in order to mitigate the threat posed by the suspicious activity?

a)

A

Host-based firewall

b)

B

Web application firewall

c)

C

Access control list

d)

D

Application allow list

6.

Question #:6

An administrator assists the legal and compliance team with ensuring information about customer transactions is archived for the proper time period. Which of the following data policies is the administrator carrying out?

a)

A

Compromise

b)

B

Retention

c)

C

Analysis

d)

D

Transfer

e)

E

Inventory

7.

Question #:7

Which of the following is a hardware-specific vulnerability?

a)

A

Firmware version

b)

B

Buffer overflow

c)

C

SQL injection

d)

D

Cross-site scripting

8.

Question #:8

After an audit, an administrator discovers all users have access to confidential data on a file server. Which of the following should the administrator use to restrict access to the data quickly?

a)

A

Group Policy

b)

B

Content filtering

c)

C

Data loss prevention

d)

D

Access control lists

9.

Question #:9

Which of the following scenarios describes a possible business email compromise attack?

a)

An employee receives a gift card request in an email that has an executive's name in the display field of the email.

b)

Employees who open an email attachment receive messages demanding payment in order to access files.

c)

A service desk employee receives an email from the HR director asking for log-in credentials to a cloud administrator account.

d)

An employee receives an email with a link to a phishing site that is designed to look like the company's email portal.

10.

Question #:10

An enterprise has been experiencing attacks focused on exploiting vulnerabilities in older browser versions with well-known exploits. Which of the following security solutions should be configured to best provide the ability to monitor and block these known signature-based attacks?

a)

A

ACL

b)

B

DLP

c)

C

IDS

d)

D

IPS

11.

Question #:11

A user is attempting to patch a critical system, but the patch fails to transfer. Which of the following access

controls is most likely inhibiting the transfer?

a)

A

Attribute-based

b)

B

Time of day

c)

C

Role-based

d)

D

Least privilege

12.

Question #:12

A company is planning to set up a SIEM system and assign an analyst to review the logs on a weekly basis. Which of the following types of controls is the company setting up?

a)

A

Corrective

b)

B

Preventive

c)

C

Detective

d)

D

Deterrent

13.

Question #:13

A company is expanding its threat surface program and allowing individuals to security test the company’s internet-facing application. The company will compensate researchers based on the vulnerabilities discovered. Which of the following best describes the program the company is setting up?

a)

A

Open-source intelligence

b)

B

Bug bounty

c)

C

Red team

d)

D

Penetration testing

14.

Question #:14

An organization’s internet-facing website was compromised when an attacker exploited a buffer overflow. Which of the following should the organization deploy to best protect against similar attacks in the future?

a)

A

NGFW

b)

B

WAF

c)

C

TLS

d)

D

SD-WAN

15.

Question #:15

Which of the following describes the maximum allowance of accepted risk?

a)

A

Risk indicator

b)

B

Risk level

c)

C

Risk score

d)

D

Risk threshold

16.

Question #:16

A systems administrator is working on a solution with the following requirements:

• Provide a secure zone.

• Enforce a company-wide access control policy.

• Reduce the scope of threats.

Which of the following is the systems administrator setting up?

a)

A

Zero Trust

b)

B

AAA

c)

C

Non-repudiation

d)

D

CIA

17.

Question #:17

A security engineer is implementing FDE for all laptops in an organization. Which of the following are the most important for the engineer to consider as part of the planning process? (Select two).

a)

A

Key escrow

b)

B

TPM presence

c)

C

Digital signatures

d)

D

Data tokenization

e)

E

Public key management

F

Certificate authority linking

18.

Question #:18

Which of the following is used to add extra complexity before using a one-way data transformation algorithm?

a)

A

Key stretching

b)

B

Data masking

c)

C

Steganography

d)

D

Salting

19.

Question #:19

The management team notices that new accounts that are set up manually do not always have correct access or permissions.

Which of the following automation techniques should a systems administrator use to streamline account creation?

a)

A

Guard rail script

b)

B

Ticketing workflow

c)

C

Escalation script

d)

D

User provisioning script

20.

Question #:20

Which of the following would be most useful in determining whether the long-term cost to transfer a risk is less than the impact of the risk?

a)

A

ARO

b)

B

RTO

c)

C

RPO

d)

D

ALE

e)

E

SLE

21.

Question #:21

A company wants to verify that the software the company is deploying came from the vendor the company purchased the software from. Which of the following is the best way for the company to confirm this information?

a)

A

Validate the code signature

b)

B

Execute the code in a sandbox

c)

C

Search the executable for ASCII strings

d)

D

Generate a hash of the files

22.

Question #:22

Simulation Questions check SQ+edited.pdf

a)

A

Simulation Questions check SQ+edited.pdf

b)

B

c)

C

d)

D

23.

Question #:23

Which of the following must be considered when designing a high-availability network? (Choose two).

a)

A

Ease of recovery

b)

B

Ability to patch

c)

C

Physical isolation

D

Responsiveness

d)

E

Attack surface

e)

F

Extensible authentication

24.

Question #:24

Which of the following involves an attempt to take advantage of database misconfigurations?

a)

A

Buffer overflow

b)

B

SQL injection

c)

C

VM escape

d)

D

Memory injection

25.

Question #:25

A bank insists all of its vendors must prevent data loss on stolen laptops. Which of the following strategies is the bank requiring?

a)

A

Encryption at rest

b)

B

Masking

c)

C

Data classification

d)

D

Permission restrictions