wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Sec Study Quiz 5

Total questions: 48

Worksheet time: 24mins

Name
Class
Date
1.

Which of the following is NOT a type of attack listed in the network diagram section?

a)

SQL Injection

b)

Cross Site Scripting

c)

XML Injection

d)

Phishing

2.

What is the purpose of the anonymizer in the network diagram?

a)

To protect the web server

b)

To hide the attacker's identity

c)

To filter out malicious traffic

d)

To store application source code

3.

According to the network diagram, where is the application source code repository located?

a)

On the CRM server

b)

On the attacker's tablet

c)

Behind the firewall

d)

Within the web server

4.

What device is directly connected to the internet in the network diagram?

a)

Router

b)

Switch A

c)

Firewall

d)

CRM Server

5.

What is the function of the WAF in the context of the network diagram?

a)

Web Application Firewall to protect against web-based attacks

b)

Wide Area Filesystem for file sharing

c)

Wireless Access Facility for network access

d)

Workstation Application Function for desktop applications

6.

Which type of attack is NOT listed in the 'Select type of attack' section?

a)

SQL Injection

b)

Cross Site Scripting

c)

Phishing

d)

Session Hijacking

7.

What is placed between the Internet and Switch A to protect the network?

a)

Anonymizer

b)

Firewall

c)

Router

d)

Web Server

8.

Which security measure is shown directly connected to the Database in the diagram?

a)

WAF

b)

Input Validation

c)

URL Filtering

d)

Code Review

9.

What is implemented at the Web Server for security as per the diagram?

a)

URL Filtering

b)

Input Validation

c)

Record level access control

d)

Code Review

10.

According to the diagram, what type of control is implemented on the CRM Server?

a)

WAF

b)

Input Validation

c)

Record level access control

d)

URL Filtering

11.

What is the most secure encryption and protocol combination that should be supported by a wireless network for authenticated guest access according to the simulation instructions?

a)

WEP with 802.11b

b)

WPA with 802.11g

c)

WPA2 with 802.11n

d)

802.1X with the most secure encryption available

12.

As per the simulation instructions, what are the credentials provided for the guest AD user?

a)

User: guest01 - Password: guestpass

b)

User: guest - Password: password

c)

User: visitor01 - Password: visitorpass

d)

User: guestuser - Password: guestpassword

13.

Which of the following steps is necessary to configure for authenticated guest access in the simulation?

a)

Configure the DHCP server

b)

Configure the WiFi controller

c)

Configure the web server

d)

Configure the VPN server

14.

What is the purpose of the RADIUS server in the context of the simulation?

a)

To distribute IP addresses to clients

b)

To control the power supply to the network

c)

To authenticate and authorize users for network access

d)

To route traffic between different network segments

15.

What is the IP address of the Controller in the WiFi Controller settings?

a)

192.168.1.20

b)

192.168.1.1

c)

192.168.1.10

d)

192.168.2.1

16.

What is the Shared key for the RADIUS Server?

a)

CORPGUEST

b)

SECRET

c)

PSK

d)

AAA

17.

What is the Server IP address in the RADIUS Server settings?

a)

192.168.1.10

b)

192.168.1.20

c)

192.168.2.20

d)

192.168.2.1

18.

What is the Shared key for the WiFi Controller configuration?

a)

CORPGUEST

b)

SECRET

c)

guestpass

d)

192.168.1.20

19.

What is the PSK for the Wireless Client configuration?

a)

SECRET

b)

guest01

c)

guestpass

d)

CORPGUEST

20.

What is the Authentication type used for the RADIUS Server configuration?

a)

WPA2-PSK

b)

Active Directory

c)

Shared key

d)

PSK

21.

What is the Server IP address for the RADIUS Server configuration?

a)

192.168.1.10

b)

192.168.1.20

c)

192.168.1.1

d)

192.168.1.0

22.

What is the AAA server IP address in the WiFi Controller configuration?

a)

192.168.1.10

b)

192.168.1.20

c)

192.168.1.1

d)

192.168.1.0

23.

Based on the script shown in Command output 1, what type of compromise does it indicate?

a)

RAT

b)

Backdoor

c)

Logic bomb

d)

SQL injection

24.

Based on the script shown in Command output 2, what type of compromise does it indicate?

a)

SQL injection

b)

RAT

c)

Rootkit

d)

Backdoor

25.

What type of compromise is indicated by the script that includes "wget" to download a file from a remote server and informs the user that a virus file has been downloaded?

a)

SQL Injection

b)

RAT

c)

Rootkit

d)

Backdoor

26.

Based on the script shown, which type of compromise involves dropping a database named "production"?

a)

Logic bomb

b)

SQL Injection

c)

RAT

d)

Rootkit

27.

After a recent security incident, a security analyst discovered that unnecessary ports were open on a firewall policy for a web server. Which of the following firewall policies would be MOST secure for a web server?

a)

Allow TCP 53, Allow TCP 80, Allow TCP 443, Allow Any

b)

Deny TCP 53, Allow TCP 80, Allow TCP 445, Allow Any

c)

Deny TCP 80, Allow TCP 443, Allow Any

d)

Allow TCP 80, Allow TCP 443, Deny Any

28.

A large bank with two geographically dispersed data centers is concerned about major power disruptions at both locations. Every day each location experiences very brief outages that last for a few seconds. However, during the summer a high risk of intentional brownouts that last up to an hour exists, particularly at one of the locations near an industrial smelter. Which of the following is the BEST solution to reduce the risk of data loss?

a)

Dual supply

b)

Generator

c)

UPS

d)

POU

e)

Daily backups

29.

Which of the following would be the BEST way to analyze diskless malware that has infected a VDI?

a)

Shut down the VDI and copy off the event logs.

b)

Take a memory snapshot of the running system.

c)

Use NetFlow to identify command-and-control IPs.

d)

Run a full on-demand scan of the root volume.

30.

Users are presented with a banner upon each login to a workstation. The banner mentions that users are not entitled to any reasonable expectation of privacy and access is for authorized personnel only. In order to proceed past that banner, users must click the OK button. Which of the following is this an example of?

a)

AUP

b)

NDA

c)

SLA

d)

MOU

31.

The Chief Information Security Officer is concerned about employees using personal email rather than company email to communicate with clients and sending sensitive business information and PII. Which of the following would be the BEST solution to install on the employees' workstations to prevent information from leaving the company's network?

a)

HIPS

b)

DLP

c)

HIDS

d)

EDR

32.

On the way into a secure building, an unknown individual strikes up a conversation with an employee. The employee scans the required badge at the door while the unknown individual holds the door open, seemingly out of courtesy, for the employee. Which of the following social engineering techniques is being utilized?

a)

Shoulder surfing

b)

Watering-hole attack

c)

Tailgating

d)

Impersonation

33.

Two hospitals merged into a single organization. The privacy officer requested a review of all records to ensure encryption was used during record storage, in compliance with regulations. During the review, the officer discovered that medical diagnosis codes and patient names were left unsecured. Which of the following types of data does this combination BEST represent?

a)

Personal health information

b)

Personally identifiable information

c)

Tokenized data

d)

Proprietary data

34.

A company discovered that terabytes of data have been exfiltrated over the past year after an employee clicked on an email link. The threat continued to evolve and remain undetected until a security analyst noticed an abnormal amount of external connections when the employee was not working. Which of the following is the MOST likely threat actor?

a)

Shadow IT

b)

Script kiddies

c)

APT

d)

Insider threat

35.

Which of the following is the MOST likely reason for an untrusted SSL certificate being discovered during a vulnerability scan, if the certificate is signed properly and is valid on other company servers?

a)

A. The required intermediate certificate is not loaded as part of the certificate chain.

b)

B. The certificate is on the CRL and is no longer valid.

c)

C. The corporate CA has expired on every server, causing the certificate to fail verification.

d)

D. The scanner is incorrectly configured to not trust this certificate when detected on the server.

36.

What should be implemented to allow users to authenticate using their own credentials when logging into a trusted partner website, without issuing separate credentials for the partner website?

a)

A. Directory service

b)

B. AAA server

c)

C. Federation

d)

D. Multifactor authentication

37.

Which of the following should a company implement to assist in an investigation where authorities need to review all emails and ensure data is not deleted?

a)

A. Legal hold

b)

B. Chain of custody

c)

C. Data loss prevention

d)

D. Content filter

38.

Which of the following BEST describes the policy that is being implemented when a user has issues logging in to the corporate network using a VPN over the weekend but can log in successfully on Monday?

a)

Time-based logins

b)

Geofencing

c)

Network location

d)

Password history

39.

Which of the following BEST describes the threat actors who publicly posted stolen internal communications to give an opposition party an advantage?

a)

Semi-authorized hackers

b)

State actors

c)

Script kiddies

d)

Advanced persistent threats

40.

Which of the following BEST explains a risk of continuing to use legacy software to support a critical service?

a)

Default system configuration

b)

Unsecure protocols

c)

Lack of vendor support

d)

Weak encryption

41.

A security analyst has been tasked with ensuring all programs that are deployed into the enterprise have been assessed in a runtime environment. Any critical issues found in the program must be sent back to the developer for verification and remediation. Which of the following BEST describes the type of assessment taking place?

a)

Input validation

b)

Dynamic code analysis

c)

Fuzzing

d)

Manual code review

42.

Which of the following can work as an authentication method and as an alerting mechanism for unauthorized access attempts?

a)

Smart card

b)

Push notifications

c)

Attestation service

d)

HMAC-based

e)

One-time password

43.

A company has a flat network in the cloud. The company needs to implement a solution to segment its production and non-production servers without migrating servers to a new network. Which of the following solutions should the company implement?

a)

Intranet

b)

Screened subnet

c)

VLAN segmentation

d)

Zero Trust

44.

Which of the following policies BEST reduces the risk of malicious activity occurring after a tour of a SOC provided to potential investors?

a)

Password complexity

b)

Acceptable use

c)

Access control

d)

Clean desk

45.

A Chief Information Security Officer has defined resiliency requirements for a new data center architecture. Which of the following are required to BEST meet these objectives? (Choose three.)

a)

NAS

b)

Fiber switching

c)

Redundant power supplies

d)

RAID

e)

IaC

46.

Which of the following is a security best practice that ensures the integrity of aggregated log files within a SIEM?

a)

Set up hashing on the source log file servers that complies with local regulatory requirements.

b)

Back up the aggregated log files at least two times a day or as stated by local regulatory requirements.

c)

Write protect the aggregated log files and move them to an isolated server with limited access.

d)

Back up the source log files and archive them for at least six years or in accordance with local regulatory requirements.

47.

A security analyst is evaluating the risks of authorizing multiple security solutions to collect data from the company's cloud environment. Which of the following is an immediate consequence of these integrations?

a)

Non-compliance with data sovereignty rules

b)

Loss of the vendors interoperability support

c)

Mandatory deployment of a SIEM solution

d)

Increase in the attack surface

48.

Which of the following explains why RTO is included in a BIA?

a)

It identifies the amount of allowable downtime for an application or system.

b)

It prioritizes risks so the organization can allocate resources appropriately.

c)

It monetizes the loss of an asset and determines a break-even point for risk mitigation.

d)

It informs the backup approach so that the organization can recover data to a known time.