wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

C1 - NetSec

Total questions: 24

Worksheet time: 22mins

Name
Class
Date
1.
A security service company is conducting an audit in several risk areas within a major corporation. What statement describes the risk of access to cloud storage devices?
a)
the retrieval of confidential or personal information from a lost or stolen device that was not configured to use encryption software
b)
the unauthorized transfer of data containing valuable corporate information to a USB drive
c)
sensitive data lost through access to the cloud that has been compromised due to weak security settings
d)
intercepted emails that reveal confidential corporate or personal information
2.
A security service company is conducting an audit in several risk areas within a major corporation. What statement describes the risk of using social networking?
a)
sensitive data lost through access to the cloud that has been compromised due to weak security settings
b)
gaining illegal access to corporate data by stealing passwords or cracking weak passwords
c)
data loss through access to personal or corporate instant messaging and social media sites
d)
the retrieval of confidential or personal information from a lost or stolen device that was not configured to use encryption software
3.
A security service company is conducting an audit in several risk areas within a major corporation. What statement describes an attack vector?
a)
the potential of causing great damage because of direct access to the building and its infrastructure devices
b)
the unauthorized transfer of data containing valuable corporate information to a USB drive
c)
the path by which a threat actor can gain access to a server, host, or network
d)
the retrieval of confidential or personal information from a lost or stolen device that was not configured to use encryption software
4.
A security service company is conducting an audit in several risk areas within a major corporation. What statement describes the risk of access to removable media?
a)
the potential of causing great damage because of direct access to the building and its infrastructure devices
b)
intercepted emails that reveal confidential corporate or personal information
c)
the unauthorized transfer of data containing valuable corporate information to a USB drive
d)
data loss through access to personal or corporate instant messaging and social media sites
5.
A security service company is conducting an audit in several risk areas within a major corporation. What statement describes an internal threat?
a)
the path by which a threat actor can gain access to a server, host, or network
b)
intercepted emails that reveal confidential corporate or personal information
c)
the potential of causing great damage because of direct access to the building and its infrastructure devices
d)
gaining valuable information through the retrieval of discarded unshredded reports
6.
Which condition describes the potential threat created by Instant On in a data center?
a)
when the primary IPS appliance is malfunctioning
b)
when the primary firewall in the data center crashes
c)
when a VM that may have outdated security policies is brought online after a long period of inactivity
d)
when an attacker hijacks a VM hypervisor and then launches attacks against other devices in the data center
7.
Which security feature or device would more likely be used within a CAN than a SOHO or data center?
a)
ESA/WSA
b)
wireless router
c)
exit sensors
d)
security trap
e)
virtual security gateway
8.
A company has several sales offices distributed within a city. Each sales office has a SOHO network. What are two security features that are commonly found in such a network configuration? (Choose two.)
a)
Cisco ASA firewall
b)
port security on user facing ports
c)
WPA2
d)
biometric verifications
e)
Virtual Security Gateway within Cisco Nexus switches
9.
What are two data protection functions provided by MDM? (Choose two.)
a)
quarantine
b)
inoculation
c)
PIN locking
d)
physical security
e)
remote wiping
10.
What is the motivation of a white hat attacker?
a)
taking advantage of any vulnerability for illegal personal gain
b)
fine tuning network devices to improve their performance and efficiency
c)
studying operating systems of various platforms to develop a new system
d)
discovering weaknesses of networks and systems to improve the security level of these systems
11.
Which attack involves threat actors positioning themselves between a source and destination with the intent of transparently monitoring, capturing, and controlling the communication?
a)
DoS attack
b)
ICMP attack
c)
SYN flood attack
d)
man-in-the-middle attack
12.
A user is curious about how someone might know a computer has been infected with malware. What are two common malware behaviors? (Choose two.)
a)
The computer beeps once during the boot process.
b)
The computer emits a hissing sound every time the pencil sharpener is used.
c)
The computer gets increasingly slower to respond. No sound emits when an audio CD is played.
d)
The computer freezes and requires reboots.
e)

No sound emits when an audio CD is played.

13.
What is the purpose of a reconnaissance attack on a computer network?
a)
to steal data from the network servers
b)
to redirect data traffic so that it can be monitored
c)
to prevent users from accessing network resources
d)
to gather information about the target network and system
14.
What are two evasion methods used by hackers? (Choose two.)
a)
encryption
b)
phishing
c)
access attack
d)
resource exhaustion
e)
scanning
15.
What is the purpose of mobile device management (MDM) software?
a)
It is used to create a security policy.
b)
It is used by threat actors to penetrate the system.
c)
It is used to identify potential mobile device vulnerabilities
d)
It is used to implement security policies, setting, and software configurations on mobile devices.
16.
Which security measure is best used to limit the success of a reconnaissance attack from within a campus area network?
a)
Implement access lists on the border router.
b)
Implement encryption for sensitive traffic.
c)
Implement a firewall at the edge of the network.
d)

Implement restrictions on the use of ICMP echo-reply messages.

17.
What functional area of the Cisco Network Foundation Protection framework is responsible for device-generated packets required for network operation, such as ARP message exchanges and routing advertisements?
a)
control plane
b)
management plane
c)
data plane
d)
forwarding plane
18.
Which security implementation will provide management plane protection for a network device?
a)
routing protocol authentication
b)
access control lists
c)
role-based access control
d)
antispoofing
19.
Which two practices are associated with securing the features and performance of router operating systems? (Choose two.)
a)
Install a UPS.
b)
Keep a secure copy of router operating system images.
c)
Disable default router services that are not necessary.
d)
Reduce the number of ports that can be used to access the router.
e)
Configure the router with the maximum amount of memory possible.
20.
On which two interfaces or ports can security be improved by configuring executive timeouts? (Choose two.)
a)
Fast Ethernet interfaces
b)
console ports
c)
serial interfaces
d)
vty ports
e)
loopback interfaces
21.
A network administrator enters the service password-encryption command into the configuration mode of a router. What does this command accomplish?
a)
This command encrypts passwords as they are transmitted across serial WAN links.
b)
This command prevents someone from viewing the running configuration passwords.
c)
This command enables a strong encryption algorithm for the enable secret password command.
d)
This command automatically encrypts passwords in configuration files that are currently stored in NVRAM.
e)
This command provides an exclusive encrypted password for external service personnel who are required to do router maintenance.
22.
Which command will block login attempts on RouterA for a period of 30 seconds if there are 2 failed login attempts within 10 seconds?
a)
RouterA(config)# login block-for 10 attempts 2 within 30
b)
RouterA(config)# login block-for 30 attempts 2 within 10
c)
RouterA(config)# login block-for 2 attempts 30 within 10
d)
RouterA(config)# login block-for 30 attempts 10 within 2
23.

Passwords can be used to restrict access to all or parts of the Cisco IOS. Select the modes and interfaces that can be protected with passwords. (Choose three.)

a)

VTY interface

b)

console interface

c)

Ethernet interface

d)

boot IOS mode

e)

privileged EXEC mode

24.

An administrator defined a local user account with a secret password on router R1 for use with SSH. Which three additional steps are required to configure R1 to accept only encrypted SSH connections? (Choose three.)

a)

Configure the IP domain name on the router.

b)

Enable inbound vty Telnet sessions.

c)

Generate crypto keys.

d)

Configure DNS on the router.

e)

Configure a host name other than "Router".