wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

WSDip CSF - SSM

Total questions: 76

Worksheet time: 2hrs 51mins

Name
Class
Date
1.

Which of the following is the correct representation of the AAA of Security Framework? (Choose 1 or more answers)

a)

Accounting

b)

Authentication

c)

Authorization

d)

Accessibility

2.

Multi-Factor Authentication (MFA) is a security system where more than ONE method of authentication is used to verify a USER's Identity. Which of the following is a valid independent credential? (Choose 1 or more answers)

a)

What the User knows (Password)

b)

What the User has (Security Token)

c)

What the User is (Biometric Verification)

d)

Where the User is (Location Verification)

3.

Policy Settings in Account Policies are implemented at Domain Level and generally affect all accounts. Which of the following policy can be configured for a particular user or group?

a)

Fine - grained Password Policy

b)

Refined Password Policy

c)

User Password Policy

d)

Group Password Policy

4.

Which of the following policy is part of the Policy Settings in Account Policy? (Choose 1 or more answers)

a)

Account Lockout Policy

b)

Password Policy

c)

Kerberos Policy

d)

Domain Policy

5.

Which of the following action is to be taken to ensure an locked account can only be manually unlocked by an Administrator?

a)

Set Lockout Threshold to 0

b)

Set Reset Account Lockout Counter to 0

c)

Set Lockout Duration to 0

d)

Use the Intruder Lockout Settings

6.

Which of the following setting is valid to ensure Users can attempt to login after 10 mins if their account is locked out due to wrong password?

a)

Lockout Duration = 10

b)

Lockout Threshold = 10

c)

Reset Account Lockout Counter = 10

d)

Maximum Password Age = 10

7.

Any user who enters 3 incorrect password in succession in a 5 minutes period will have their account locked out until manually unlocked by an Administrator.

Which of the following Account Policy setting is valid for the above scenario?

a)

Lockout Duration = 3

b)

Lockout Duration = 5

c)

Lockout Duration = 0

d)

Lockout Duration = 8

8.

Any user who enters 3 incorrect password in succession in a 5 minutes period will have their account locked out until manually unlocked by an Administrator.

Which of the following Account Policy setting is valid for the above scenario?

a)

Lockout Threshold = 3

b)

Lockout Threshold = 5

c)

Lockout Threshold = 0

d)

Lockout Threshold = 8

9.

Any user who enters 3 incorrect password in succession in a 5 minutes period will have their account locked out until manually unlocked by an Administrator.

Which of the following Account Policy setting is valid for the above scenario?

a)

Reset Account Lockout Counter = 3

b)

Reset Account Lockout Counter = 5

c)

Reset Account Lockout Counter = 0

d)

Reset Account Lockout Counter = 8

10.

A user password must be

1) At least 8 characters;

2) Must be different from last 10 passwords used;

3) Must be changed every 30 days;

4) Password can be changed anytime;

5) Difficult to Crack

Which of the following Account Policy setting is valid for the above scenario? (Choose 1 or more answers)

a)

Minimum Password Length = 8

b)

Minimum Password Age = 8

c)

Maximum Password Age = 8

d)

Enforce Password History = 8

e)

Password must meet complexity requirements

11.

A user password must be

1) At least 8 characters;

2) Must be different from last 10 passwords used;

3) Must be changed every 30 days;

4) Password can be changed anytime;

5) Difficult to Crack

Which of the following Account Policy setting is valid for the above scenario? (Choose 1 or more answers)

a)

Minimum Password Length = 10

b)

Minimum Password Age = 10

c)

Maximum Password Age = 10

d)

Enforce Password History = 10

e)

Password must meet complexity requirements

12.

A user password must be

1) At least 8 characters;

2) Must be different from last 10 passwords used;

3) Must be changed every 30 days;

4) Password can be changed anytime;

5) Difficult to Crack

Which of the following Account Policy setting is valid for the above scenario? (Choose 1 or more answers)

a)

Minimum Password Length = 30

b)

Minimum Password Age = 30

c)

Maximum Password Age = 30

d)

Enforce Password History = 30

e)

Password must meet complexity requirements

13.

A user password must be

1) At least 8 characters;

2) Must be different from last 10 passwords used;

3) Must be changed every 30 days;

4) Password can be changed anytime;

5) Difficult to Crack

Which of the following Account Policy setting is valid for the above scenario? (Choose 1 or more answers)

a)

Minimum Password Length = 0

b)

Minimum Password Age = 0

c)

Maximum Password Age = 0

d)

Enforce Password History = 0

e)

Password must meet complexity requirements

14.

Which is NOT a Common Type of Attacks?

a)

Trojan horse

b)

Network scanner

c)

People engineering

d)

Denial of service attacks

15.

Which is NOT a valid Reasons for Network Attacks?

a)

Profit

b)

Revenge

c)

Patching

d)

Personal Satisfaction

16.

Which is NOT a Common Network Vulnerabilities?

a)

User rights

b)

Sudo command

c)

Audit settings

d)

Account passwords

17.

Which is NOT a valid layer in Defense-in-depth?

a)

Data

b)

Storage

c)

Networks

d)

Perimeter

18.

Which is NOT a best practise to increase system security in Server Hardening?

a)

Close unneeded ports

b)

Maximise software installations

c)

Keep security patches up to date

d)

Stop and/or uninstall unneeded services

19.

Which is NOT an area where security settings can be applied using Security Templates?

a)

BIOS: Firmware settings for system hardware

b)

File System : Permissions for folders and files

c)

Event Log : App, system, and security event log settings

d)

System Services: Startup and permissions for system services

20.

Which is NOT a valid method to configure Windows Firewall?

a)

Group Policy

b)

Network Adapter Properties

c)

Windows Firewall with Advanced Security

d)

Basic Firewall configuration in Control Panel

21.

Which is NOT a main criteria used in firewall rules?

a)

IP addresses

b)

Port numbers

c)

MAC addresses

d)

Protocol numbers

22.

AAA of Security Framework for User Accounts DOES NOT include which of the following?

a)

Accounting

b)

Assessment

c)

Authorization

d)

Authentication

23.

Windows Account Policy consists of the following types EXCEPT one of the following.

a)

Radius policy

b)

Password policy

c)

Kerberos policy

d)

Account lockout policy

24.

Which of the following is NOT a correct data security goal?

a)

Validity

b)

Integrity

c)

Availability

d)

Confidentiality

25.

Which of the following is NOT correct about Audit Policies?

a)

Logs are captured in security log

b)

Enabled based on success or failure

c)

Used to track events by activity category

d)

Capture events about system and application failures

26.

Which of the following is NOT a valid Audit Event Category?

a)

Audit account management

b)

Audit account logon events

c)

Audit directory service access

d)

Audit incoming TCP network connections

27.

Which of the following is a common type of cyber attack? (Choose 1 or more answers)

a)

Network Scanner

b)

Trojan Horse

c)

Social Engineering

d)

Denial of Service Attacks

e)

Vulnerabilities

28.

Which of the following is a common Network Vulnerability? (Choose 1 or more answers)

a)

Account Password

b)

Audit Settings

c)

User Rights

d)

Services

29.

Which of the following is a Key Security Principles? (Choose 1 or more answers)

a)

Defense - In - Depth

b)

Least Privilege

c)

Minimized Attack Surface

d)

Maximized Tracking

30.

Which of the following will help in server hardening? (Choose 1 or more answers)

a)

Disable Automatic Updates

b)

Update Security Patches to the latest

c)

Stop Un-needed Services

d)

Close Un-needed Ports

e)

Minimize Software Installations

31.

Which of the following will help in server hardening? (Choose 1 or more answers)

a)

Enable Plug and Play

b)

Use Anti-Malware Software

c)

Un-install Un-needed Services

d)

Run Vulnerability Scans

e)

Disable Un-needed Hardware

32.

Which of the following tool can be used to highlight common administrative vulnerabilities and missing security updates?

a)

Security Configuration Wizard

b)

Microsoft Baseline Security Analyzer

c)

Windows Firewall

d)

Windows Defender

33.

Which of the following is the criteria used in Firewall rules? (Choose 1 or more answers)

a)

IP Addresses

b)

Protocol Numbers

c)

Port Numbers

d)

Packet Sequences

34.

Which of the following is the default rule for Windows Firewall? (Choose 1 or more answers)

a)

On

b)

Allow All Incoming Traffic

c)

Allow All Outgoing Traffic

d)

Block All Incoming Traffic

e)

Block All Outgoing Traffic

35.

Which of the following is NOT an advantage of virtualization?

a)

Underutilizes resources.

b)

Offers flexible infrastructure at low cost.

c)

Makes OS and applications hardware independent.

d)

Runs multiple OS per physical machine concurrently.

36.

Which of the following is a benefit of virtualization?

a)

Decrease hardware utilization.

b)

Improve business continuity.

c)

Establish a decentralized desktop strategy.

d)

Decrease efficiency in development and test activities.

37.

Which of the following is NOT a server virtualization product?

a)

Vmware – Vsphere.

b)

Microsoft - Hyper-V.

c)

Veritas Infoscale Availability 7.0.

d)

Amazon Web Services - Elastic Compute Cloud (EC2).

38.

Which of the following is NOT a characteristic of Type I Virtualization (Native or Bare Metal)?

a)

Host operating system required.

b)

Parent partition creates and manages the child partitions.

c)

Individual virtual machines have their own OS and accesses hardware through the hypervisor.

d)

Hypervisor layer interacts directly with the computer’s physical hardware for better performance.

39.

Which of the following is NOT a characteristic of Type II Virtualization (Hosted)?

a)

Requires a Host operating system.

b)

Does not provide the same performance as separate physical computers.

c)

A virtual hardware environment is shared by all VMs with OS installed.

d)

The host OS shares access to the computer’s processor with the hypervisor.

40.

Which of the following is NOT a valid virtual disk type?

a)

Differencing.

b)

Variable size.

c)

Dynamically expanding.

d)

Physical (or pass through disk).

41.

Which of the following is NOT the purpose of event logs?

a)

It provides an audit trail to understand the activities on the system.

b)

It provides historical information so you can track down system and security problems.

c)

Provide GUI to for command-level intreface

d)

Help to diagnose problems.

42.

Which of the following is NOT a type of Windows event log?

a)

Application

b)

Firewall

c)

Security

d)

Setup

43.

Which of the following is NOT a type of event in a Windows log?

a)

Warnings

b)

Errors

c)

System

d)

Information

44.

Which of the following actions is NOT a valid action taken by the Event Tracker when a log file reaches its maximum file size by default?

a)

It will stop recording

b)

It will delete the logfile

c)

It will overwrite the logfile

d)

It will archive the log file

45.

Which of the following actions will enable you to collect logs from remote servers automatically?

a)

Configure event subscription

b)

Creating a custom view

c)

Configure Log filtering

d)

Change the location of all logfiles.

46.

Which of the following is NOT a type of Windows Updates?

a)

Security Updates

b)

Service Packs

c)

Server Packs

d)

Critical Updates

47.

Which of the following can be used to automate and centrally manage updates?

a)

WSUS

b)

WDS

c)

NAP

d)

Automatic Updates

48.

With WSUS, windows clients do not need to have internet access to download updates.

a)

False

b)

True

49.

Which of the following 3 types are used to categorize Updates on a WSUS server? (Choose 1 or more answers)

a)

Upload

b)

Declined

c)

Removed

d)

Approved

50.

WSUS Administration console is used for the following EXCEPT:

a)

Configure WSUS settings and options

b)

View performance report

c)

View computer status

d)

Manage updates

51.

Which one of the followings is the correct definition of baselining?

a)

A baseline is the level of system activities that you decide is acceptable.

b)

A baseline is the level of system utilizations that you decide is acceptable.

c)

A baseline is the level of system performance that you decide is acceptable.

d)

A baseline is the level of system bottlenecks that you decide is acceptable.

52.

You can view a system’s current performance by using _________.

a)

Performance Alert

b)

Task Scheduler

c)

Task Manager

d)

Data Collector's Set

53.

Identify all the tools you can use to help identify the process which is hogging the system memory? (Choose 1 or more answers)

a)

Reliability Monitor

b)

Performance Monitor

c)

Resource Monitor

d)

Task Manager

54.

Select 2 tools or methods which could be used to view historical data.

a)

Performance Monitor

b)

Event Viewer

c)

Performance log

d)

Task Manager

55.

Which of the following is a Symmetric Encryption Algorithm?

a)

ECC

b)

AES

c)

RSA

d)

MD5

56.

In Windows Encrypting File System, where are the Encryption keys stored?

a)

Registry

b)

User Profile

c)

Digital Certificate

d)

Organisational Unit

57.

Which of the following will NOT help to improve data security

a)

Audit Policy

b)

Bitlocker

c)

Encrypting File System (EFS)

d)

System Restore

58.

Which of the following can recover Encrypted File System (EFS) files other than the user?

a)

Data Recovery Agent

b)

Domain Admins

c)

Enterprise Admins

d)

Administrators

59.

Which of the following is required to recover Encrypted File System (EFS) files?

a)

Data Recovery Key

b)

File

c)

Encryption Key

d)

Operating System

60.

Which of the following log is used to store Audit Events in Windows Operating System (OS)?

a)

Application Log

b)

Security Log

c)

Setup Log

d)

System Log

61.

Which of the following can access a file encrypted using Encrypted File System (EFS)? (Choose 1 or more answers)

a)

User who encrypt the File

b)

Data Recovery Agent

c)

User who is given access to the File

d)

Administrators

62.

Which of the following audit policy need to be enabled to monitor who has been accessing the files on the server?

a)

Logon Events

b)

Object Access

c)

Directory Service Access

d)

System Events

63.

Which of the following action must be taken to track users accessing folders on a server? (Choose 1 or more answers)

a)

Enable Audit Policy (Object Access)

b)

Apply Audit Policy on Files / Folders

c)

Apply NTFS Permissions on Files / Folders

d)

Enable Audit Policy (System Events)

64.

Which of the following settings can help to prevent brute - force attacks?

(Choose 1 or more answers)

a)

Password Age

b)

Password History

c)

Password Length

d)

Password Complexity

65.

Which of the following measures will help to secure records in a Storage Area Network (SAN)?

(Choose 1 or more answers)

a)

Disk Encryption

b)

File Encryption

c)

Database Records Encryption

d)

Data & User Access Controls

66.

Which of the following measures will help secure Internet data traffic between clients' and servers' endpoints?

(Choose 1 or more answers)

a)

Secure Socket Layer

b)

Transport Layer Security

c)

Field Level Encryption

d)

Hypertext Transfer Protocol Secure

67.

Which of the following is NOT a recommended practice to prevent malware infections?

a)

Regularly update antivirus software

b)

Click on suspicious email links

c)

Avoid downloading files from unknown sources

d)

Use a firewall

68.

Which of the following is NOT a valid step to protect sensitive data on a computer?

a)

Encrypt the data

b)

Store passwords in a text file

c)

Use strong passwords

d)

Enable file and folder permissions

69.

Fail2ban is an Intrusion Prevention System (IPS) that can protect systems from brute - force attacks. Which of the following is NOT a characteristic of Fail2ban?

a)

Scan Log Files to Detect Patterns that Indicates Break-In Attempts

b)

Takes Predefined Actions to Block Hosts by Adding Entries in IPtables

c)

Block Hosts & IP Addresses for Specified Periods

d)

Alerts and Takes No Action when Break-In Attempts are Detected

70.

Which of the following group of domain users will be assigned with Hypervisor administrative role?

(Choose 1 or more answers)

a)

ESX Admins

b)

ESXi Admins

c)

Hyper-V Administrators

d)

Administrators

71.

How many virtual hosts can be support by ONE vCenter Service instance?

a)

1000

b)

500

c)

1500

d)

2000

72.

Which of the following is a component of vCenter Server Architecture?

(Choose 1 or more answers)

a)

Core Services

b)

Database Server

c)

Active Directory

d)

User Access Control

73.

Which of the following is a component of vCenter Server Architecture?

(Choose 1 or more answers)

a)

vSphere API

b)

Distributed Services

c)

ESX / ESXi Management

d)

User Access Control

74.

Which of the following is a phase in a malware incident life - cycle?

(Choose 1 or more answers)

a)

Preparation

b)

Detection & Analysis

c)

Containment, Eradication & Recovery

d)

Post - Incident Activities

75.

Which of the following measures will protect the ESXi Host(s) from unauthorised intrusion & misuse?

(Choose 1 or more answers)

a)

Limit User Access

b)

Limit Shell Access

c)

Limit Services Run

d)

Limit Network Connections

76.

Which of the following measures will protect the ESXi Host(s) from unauthorised intrusion & misuse?

(Choose 1 or more answers)

a)

Limit User Access

b)

Limit Shell Access

c)

Patch Host(s) with latest Security Updates

d)

Use Secure Network Connections