wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Match the following

Total questions: 28

Worksheet time: 17mins

Name
Class
Date
1.

Match the description with the most accurate attack type. Not all attack types will be used.

(a)  

2.

Match the description with the most accurate attack type. Not all attack types will be used.

(a)  

3.

Match the description with the most accurate attack type. Not all attack types will be used.

(a)  

4.

Select the BEST security control for the Library Computer Room from the available options.

a)

Locking Cabinets

b)

Environmental Sensors

c)

Video Surveillance

5.

Select the BEST security control for the Web Server and Database Server described as having high security.

a)

Locking Cabinets

b)

Environmental Sensors

c)

Video Surveillance

6.

Select the BEST security control for the Library Employee Laptops used offsite and containing PII.

a)

Full-Disk Encryption

b)

Biometric Reader

7.

Fill in the blank with the BEST secure network protocol for the description: Accept customer purchases from your primary website.

(a)  

8.

Fill in the blank with the BEST secure network protocol for the description: Synchronize the time across all of your devices.

(a)  

9.

Fill in the blank with the BEST secure network protocol for the description: Access your switch using a CLI terminal screen.

(a)  

10.

Fill in the blank with the BEST secure network protocol for the description: Talk with customers on scheduled conference calls.

(a)  

11.

Fill in the blank with the BEST secure network protocol for the description: Gather metrics from routers at remote sites.

(a)  

12.

During the login process, your phone receives a text message with a one-time passcode. Which authentication factor does this scenario describe?

a)

Something you can do

b)

Somewhere you are

c)

Something you have

d)

Something you know

e)

Something you are

13.

You enter your PIN to make a deposit into an ATM. Which authentication factor does this scenario describe?

a)

Something you can do

b)

Somewhere you are

c)

Something you have

d)

Something you know

e)

Something you are

14.

You must sign a check-in sheet before entering a controlled area. Which authentication factor does this scenario describe?

a)

Something you can do

b)

Somewhere you are

c)

Something you have

d)

Something you know

e)

Something you are

15.

You can use your fingerprint to unlock the door to the data center. Which authentication factor does this scenario describe?

a)

Something you can do

b)

Somewhere you are

c)

Something you have

d)

Something you know

e)

Something you are

16.

Your login will not work unless you are connected to the VPN. Which authentication factor does this scenario describe?

a)

Something you can do

b)

Somewhere you are

c)

Something you have

d)

Something you know

e)

Something you are

17.

Configure the following stateful firewall rules: Allow the Web Server to access the Database Server using LDAP; Allow the Storage Server to transfer files to the Video Server over HTTPS; Allow the Management Server to use a secure terminal on the File Server.

4 lines
18.

You've hired a third-party to gather information about your company's servers and data. The third-party will not have direct access to your internal network but can gather information from any other source. Which of the following would BEST describe this approach?

a)

A. Backdoor testing

b)

B. Passive footprinting

c)

C. OS fingerprinting

d)

D. Partially known environment

19.

Which of these protocols use TLS to provide secure communication? (Select TWO)

a)

SNMPv2

b)

DNSSEC

c)

HTTPS

d)

FTPS

e)

SSH

20.

Which of these threat actors would be MOST likely to attack systems for direct financial gain?

a)

Organized crime

b)

Hacktivist

c)

Nation state

d)

Competitor

21.

A security incident has occurred on a file server. Which of the following data sources should be gathered to address file storage volatility? (Select TWO)

a)

Partition data

b)

Kernel statistics

c)

ROM data

d)

Temporary file systems

e)

Process table

22.

An IPS at your company has found a sharp increase in traffic from all-in-one printers. After researching, your security team has found a vulnerability associated with these devices that allows the device to be remotely controlled by a third-party. Which category would BEST describe these devices?

a)

IoT

b)

RTOS

c)

MFD

d)

SoC

23.

Which of the following standards provides information on privacy and managing PII?

a)

A. ISO 31000

b)

B. ISO 27002

c)

C. ISO 27701

d)

D. ISO 27001

24.

Elizabeth, a security administrator, is concerned about the potential for data exfiltration using external storage drives. Which of the following would be the BEST way to prevent this method of data exfiltration?

a)

Create an operating system security policy to prevent the use of removable media

b)

Monitor removable media usage in host-based firewall logs

c)

Only allow applications that do not use removable media

d)

Define a removable media block rule in the UTM

25.

A CISO (Chief Information Security Officer) would like to decrease the response time when addressing security incidents. Unfortunately, the company does not have the budget to hire additional security engineers. Which of the following would assist the CISO with this requirement?

a)

ISO 27701

b)

PKI

c)

IaaS

d)

SOAR

26.

An insurance company has created a set of policies to handle data breaches. The security team has been given this set of requirements based on these policies: - Access records from all devices must be saved and archived - Any data access outside of normal working hours must be immediately reported - Data access must only occur inside of the country - Access logs and audit reports must be created from a single database Which of the following should be implemented by the security team to meet these requirements? (Select THREE)

a)

Enable time-of-day restrictions on the authentication server

b)

Consolidate all logs on a SIEM

c)

Require government-issued identification during the onboarding process

d)

Restrict login access by IP address and GPS location

e)

Add additional password complexity for accounts that access data

27.

Rodney, a security engineer, is viewing this record from the firewall logs: UTC 04/05/2018 03:09:15809 AV Gateway Alert 136.127.92.171 80 -> 10.16.10.14 60818 Gateway Anti-Virus Alert: XPACK.A_7854 (Trojan) blocked. Which of the following can be observed from this log information?

a)

A. The victim's IP address is 136.127.92.171

b)

B. A download was blocked from a web server

c)

C. A botnet DDoS attack was blocked

d)

D. The Trojan was blocked, but the file was not

28.

A user connects to a third-party website and receives this message: "Your connection is not private. NET::ERR_CERT_INVALID". Which of the following attacks would be the MOST likely reason for this message?

a)

A. Brute force

b)

B. DoS

c)

C. On-path

d)

D. Disassociation