WorksheetsSec Study Quiz 5
Total questions: 48
Worksheet time: 24mins
Which of the following is NOT a type of attack listed in the network diagram section?
SQL Injection
Cross Site Scripting
XML Injection
Phishing
What is the purpose of the anonymizer in the network diagram?
To protect the web server
To hide the attacker's identity
To filter out malicious traffic
To store application source code
According to the network diagram, where is the application source code repository located?
On the CRM server
On the attacker's tablet
Behind the firewall
Within the web server
What device is directly connected to the internet in the network diagram?
Router
Switch A
Firewall
CRM Server
What is the function of the WAF in the context of the network diagram?
Web Application Firewall to protect against web-based attacks
Wide Area Filesystem for file sharing
Wireless Access Facility for network access
Workstation Application Function for desktop applications
Which type of attack is NOT listed in the 'Select type of attack' section?
SQL Injection
Cross Site Scripting
Phishing
Session Hijacking
What is placed between the Internet and Switch A to protect the network?
Anonymizer
Firewall
Router
Web Server
Which security measure is shown directly connected to the Database in the diagram?
WAF
Input Validation
URL Filtering
Code Review
What is implemented at the Web Server for security as per the diagram?
URL Filtering
Input Validation
Record level access control
Code Review
According to the diagram, what type of control is implemented on the CRM Server?
WAF
Input Validation
Record level access control
URL Filtering
What is the most secure encryption and protocol combination that should be supported by a wireless network for authenticated guest access according to the simulation instructions?
WEP with 802.11b
WPA with 802.11g
WPA2 with 802.11n
802.1X with the most secure encryption available
As per the simulation instructions, what are the credentials provided for the guest AD user?
User: guest01 - Password: guestpass
User: guest - Password: password
User: visitor01 - Password: visitorpass
User: guestuser - Password: guestpassword
Which of the following steps is necessary to configure for authenticated guest access in the simulation?
Configure the DHCP server
Configure the WiFi controller
Configure the web server
Configure the VPN server
What is the purpose of the RADIUS server in the context of the simulation?
To distribute IP addresses to clients
To control the power supply to the network
To authenticate and authorize users for network access
To route traffic between different network segments
What is the IP address of the Controller in the WiFi Controller settings?
192.168.1.20
192.168.1.1
192.168.1.10
192.168.2.1
What is the Shared key for the RADIUS Server?
CORPGUEST
SECRET
PSK
AAA
What is the Server IP address in the RADIUS Server settings?
192.168.1.10
192.168.1.20
192.168.2.20
192.168.2.1
What is the Shared key for the WiFi Controller configuration?
CORPGUEST
SECRET
guestpass
192.168.1.20
What is the PSK for the Wireless Client configuration?
SECRET
guest01
guestpass
CORPGUEST
What is the Authentication type used for the RADIUS Server configuration?
WPA2-PSK
Active Directory
Shared key
PSK
What is the Server IP address for the RADIUS Server configuration?
192.168.1.10
192.168.1.20
192.168.1.1
192.168.1.0
What is the AAA server IP address in the WiFi Controller configuration?
192.168.1.10
192.168.1.20
192.168.1.1
192.168.1.0
Based on the script shown in Command output 1, what type of compromise does it indicate?
RAT
Backdoor
Logic bomb
SQL injection
Based on the script shown in Command output 2, what type of compromise does it indicate?
SQL injection
RAT
Rootkit
Backdoor
What type of compromise is indicated by the script that includes "wget" to download a file from a remote server and informs the user that a virus file has been downloaded?
SQL Injection
RAT
Rootkit
Backdoor
Based on the script shown, which type of compromise involves dropping a database named "production"?
Logic bomb
SQL Injection
RAT
Rootkit
After a recent security incident, a security analyst discovered that unnecessary ports were open on a firewall policy for a web server. Which of the following firewall policies would be MOST secure for a web server?
Allow TCP 53, Allow TCP 80, Allow TCP 443, Allow Any
Deny TCP 53, Allow TCP 80, Allow TCP 445, Allow Any
Deny TCP 80, Allow TCP 443, Allow Any
Allow TCP 80, Allow TCP 443, Deny Any
A large bank with two geographically dispersed data centers is concerned about major power disruptions at both locations. Every day each location experiences very brief outages that last for a few seconds. However, during the summer a high risk of intentional brownouts that last up to an hour exists, particularly at one of the locations near an industrial smelter. Which of the following is the BEST solution to reduce the risk of data loss?
Dual supply
Generator
UPS
POU
Daily backups
Which of the following would be the BEST way to analyze diskless malware that has infected a VDI?
Shut down the VDI and copy off the event logs.
Take a memory snapshot of the running system.
Use NetFlow to identify command-and-control IPs.
Run a full on-demand scan of the root volume.
Users are presented with a banner upon each login to a workstation. The banner mentions that users are not entitled to any reasonable expectation of privacy and access is for authorized personnel only. In order to proceed past that banner, users must click the OK button. Which of the following is this an example of?
AUP
NDA
SLA
MOU
The Chief Information Security Officer is concerned about employees using personal email rather than company email to communicate with clients and sending sensitive business information and PII. Which of the following would be the BEST solution to install on the employees' workstations to prevent information from leaving the company's network?
HIPS
DLP
HIDS
EDR
On the way into a secure building, an unknown individual strikes up a conversation with an employee. The employee scans the required badge at the door while the unknown individual holds the door open, seemingly out of courtesy, for the employee. Which of the following social engineering techniques is being utilized?
Shoulder surfing
Watering-hole attack
Tailgating
Impersonation
Two hospitals merged into a single organization. The privacy officer requested a review of all records to ensure encryption was used during record storage, in compliance with regulations. During the review, the officer discovered that medical diagnosis codes and patient names were left unsecured. Which of the following types of data does this combination BEST represent?
Personal health information
Personally identifiable information
Tokenized data
Proprietary data
A company discovered that terabytes of data have been exfiltrated over the past year after an employee clicked on an email link. The threat continued to evolve and remain undetected until a security analyst noticed an abnormal amount of external connections when the employee was not working. Which of the following is the MOST likely threat actor?
Shadow IT
Script kiddies
APT
Insider threat
Which of the following is the MOST likely reason for an untrusted SSL certificate being discovered during a vulnerability scan, if the certificate is signed properly and is valid on other company servers?
A. The required intermediate certificate is not loaded as part of the certificate chain.
B. The certificate is on the CRL and is no longer valid.
C. The corporate CA has expired on every server, causing the certificate to fail verification.
D. The scanner is incorrectly configured to not trust this certificate when detected on the server.
What should be implemented to allow users to authenticate using their own credentials when logging into a trusted partner website, without issuing separate credentials for the partner website?
A. Directory service
B. AAA server
C. Federation
D. Multifactor authentication
Which of the following should a company implement to assist in an investigation where authorities need to review all emails and ensure data is not deleted?
A. Legal hold
B. Chain of custody
C. Data loss prevention
D. Content filter
Which of the following BEST describes the policy that is being implemented when a user has issues logging in to the corporate network using a VPN over the weekend but can log in successfully on Monday?
Time-based logins
Geofencing
Network location
Password history
Which of the following BEST describes the threat actors who publicly posted stolen internal communications to give an opposition party an advantage?
Semi-authorized hackers
State actors
Script kiddies
Advanced persistent threats
Which of the following BEST explains a risk of continuing to use legacy software to support a critical service?
Default system configuration
Unsecure protocols
Lack of vendor support
Weak encryption
A security analyst has been tasked with ensuring all programs that are deployed into the enterprise have been assessed in a runtime environment. Any critical issues found in the program must be sent back to the developer for verification and remediation. Which of the following BEST describes the type of assessment taking place?
Input validation
Dynamic code analysis
Fuzzing
Manual code review
Which of the following can work as an authentication method and as an alerting mechanism for unauthorized access attempts?
Smart card
Push notifications
Attestation service
HMAC-based
One-time password
A company has a flat network in the cloud. The company needs to implement a solution to segment its production and non-production servers without migrating servers to a new network. Which of the following solutions should the company implement?
Intranet
Screened subnet
VLAN segmentation
Zero Trust
Which of the following policies BEST reduces the risk of malicious activity occurring after a tour of a SOC provided to potential investors?
Password complexity
Acceptable use
Access control
Clean desk
A Chief Information Security Officer has defined resiliency requirements for a new data center architecture. Which of the following are required to BEST meet these objectives? (Choose three.)
NAS
Fiber switching
Redundant power supplies
RAID
IaC
Which of the following is a security best practice that ensures the integrity of aggregated log files within a SIEM?
Set up hashing on the source log file servers that complies with local regulatory requirements.
Back up the aggregated log files at least two times a day or as stated by local regulatory requirements.
Write protect the aggregated log files and move them to an isolated server with limited access.
Back up the source log files and archive them for at least six years or in accordance with local regulatory requirements.
A security analyst is evaluating the risks of authorizing multiple security solutions to collect data from the company's cloud environment. Which of the following is an immediate consequence of these integrations?
Non-compliance with data sovereignty rules
Loss of the vendors interoperability support
Mandatory deployment of a SIEM solution
Increase in the attack surface
Which of the following explains why RTO is included in a BIA?
It identifies the amount of allowable downtime for an application or system.
It prioritizes risks so the organization can allocate resources appropriately.
It monetizes the loss of an asset and determines a break-even point for risk mitigation.
It informs the backup approach so that the organization can recover data to a known time.
