WorksheetsSEC+ Mod 6 Part 4
Total questions: 86
Worksheet time: 43mins
What is privilege escalation?
Gaining control of the target system with the privileges of the compromised process.
Increasing the memory capacity of a system.
Enhancing the speed of a network.
Upgrading the operating system to a newer version.
Which programming languages offer memory safety features to help prevent buffer overflows?
Python, Java, and C#
HTML, CSS, and JavaScript
PHP, Ruby, and Perl
SQL, NoSQL, and MongoDB
Which of the following is NOT a security practice to mitigate buffer overflow vulnerabilities?
Input validation
Boundary checks
Using unsafe functions like strcpy in C/C++
Avoiding the use of unsafe functions
What is the purpose of Data Execution Prevention (DEP) and Address Space Layout Randomization (ASLR)?
To enhance the difficulty for attackers attempting to exploit buffer overflows.
To increase the speed of data processing.
To improve the graphical user interface of the operating system.
To reduce the power consumption of the system.
Which of the following is NOT an endpoint hardening technique?
Changing default passwords
Host-based firewalls
Host-based IPSs
Increasing the screen resolution
What do host-based enterprise hardening techniques focus on?
Securing individual endpoints or hosts within an organization's network.
Enhancing the visual appearance of the user interface.
Increasing the storage capacity of servers.
Reducing the number of software applications installed.
Which of the following is a fundamental security measure to prevent unauthorized access by changing default settings?
Removing unnecessary software
Disabling unused ports and protocols
Changing default passwords
Implementing host-based firewalls
What is the primary benefit of removing unnecessary software from a system?
It increases the attack surface
It minimizes potential security risks
It enhances device-level security
It allows for better network traffic management
Which of the following practices helps in reducing the potential for unauthorized access by disabling unused ports and protocols?
Implementing host-based firewalls
Changing default passwords
Removing unnecessary software
Disabling unused ports and protocols
What is the role of a host-based firewall in a security system?
To monitor and protect individual hosts from various forms of malicious activity
To manage inbound and outbound network traffic and enforce access policies
To disable unused ports and protocols
To change default passwords
Which security measure is designed to monitor and protect individual hosts from various forms of malicious activity and intrusion attempts?
Host-based firewall
Disabling unused ports and protocols
Host-based Intrusion Prevention System (HIPS)
Removing unnecessary software
What is the primary purpose of endpoint protection solutions?
To enhance the speed of individual devices
To safeguard individual devices and endpoints from malware and other security threats
To improve the graphical interface of software applications
To increase the storage capacity of devices
Which of the following is NOT a feature of endpoint protection suites?
Host-based firewall to control network traffic
Managing and enforcing policies related to external devices
Increasing the processing power of devices
Providing a centralized console for managing security
What does Full-Disk Encryption (FDE) secure?
Only user files
Only applications
The entire storage drive of a device
Only the operating system
Which of the following is a built-in FDE tool for Windows operating systems?
FileVault
VeraCrypt
LUKS
BitLocker
What is the macOS equivalent of BitLocker?
VeraCrypt
FileVault
LUKS
Symantec Endpoint Encryption
Which encryption software is compatible with Windows, macOS, and Linux operating systems?
BitLocker
FileVault
VeraCrypt
LUKS
What does file-level encryption allow you to do?
Encrypt the entire storage drive of a device
Encrypt specific files or folders on a host
Encrypt only the operating system
Encrypt only user files
Which of the following tools is a built-in file-level encryption feature for Windows operating systems?
AxCrypt
Encrypto (Mac)
Microsoft EFS (Encrypting File System)
Boxcryptor
Which encryption tool is specifically designed for Mac and simplifies the process of encrypting individual files?
GNU Privacy Guard (GPG)
Encrypto (Mac)
Boxcryptor
AxCrypt
What is the primary purpose of Transport Layer Security (TLS)?
To secure data at rest
To secure data in transit over a network
To encrypt individual files
To provide drag-and-drop encryption
Which of the following is an open-source file-level encryption tool available for Windows?
Boxcryptor
Microsoft EFS (Encrypting File System)
AxCrypt
Encrypto (Mac)
What does Public Key Infrastructure (PKI) use to secure communications?
Symmetric key cryptography
Digital signatures and encryption of data
File-level encryption
Drag-and-drop encryption
Which encryption tool integrates with cloud storage services like Dropbox, Google Drive, and OneDrive?
AxCrypt
Boxcryptor
GNU Privacy Guard (GPG)
Encrypto (Mac)
Which of the following practices involves applying software updates, patches, and security fixes to eliminate known vulnerabilities in operating systems, applications, and software components?
Decommissioning
Configuration enforcement
Patching
Monitoring
What is the primary goal of decommissioning in the context of security practices?
Applying updates to eliminate vulnerabilities
Safe retirement of hardware and software
Ongoing surveillance of system activities
Maintaining safe configurations
Which security practice is essential for maintaining the security and integrity of an organization's IT infrastructure by addressing identified vulnerabilities in software?
Monitoring
Configuration enforcement
Decommissioning
Patching
What is one of the benefits of applying patches to software systems?
Increasing the number of vulnerabilities
Improving the overall performance and stability of software and systems
Decreasing system reboots and downtime
Reducing the need for change management
Which security practice involves ongoing surveillance of system activities?
Patching
Decommissioning
Configuration enforcement
Monitoring
What challenge might organizations face when applying patches in an enterprise network?
Ensuring patches are compatible with existing software and configurations
Reducing the number of vulnerabilities
Increasing system performance
Decreasing the need for change management
What can organizations use to automate the identification and application of patches across their systems?
Manual patching processes
Patch management tools
System reboots
Downtime management tools
What is the primary purpose of decommissioning in cybersecurity?
To increase the number of assets in use
To enhance the performance of outdated systems
To mitigate security risks associated with aging or unused assets
To reduce the cost of new hardware acquisition
Which of the following is a benefit of decommissioning obsolete systems or software?
Increased operational expenses
Enhanced security monitoring
Increased number of vulnerabilities
Reduced compliance with regulations
What role does data management play in the decommissioning process?
It increases the number of assets
It guarantees secure erasure, safe migration, or compliant archiving of sensitive information
It reduces the need for cybersecurity measures
It increases the lifecycle of hardware
What is the primary purpose of configuration enforcement in cybersecurity?
To increase the number of configurations
To prevent misconfigurations and security weaknesses
To reduce the number of security tools
To enhance the performance of outdated systems
Which standard is used for configuring and assessing security settings on computer systems?
ISO 9001
SCAP
PCI DSS
GDPR
What is the primary purpose of security monitoring in an organization's cybersecurity strategy?
To increase the number of security events
To identify and respond to signs of suspicious or unauthorized activities
To reduce the number of security tools
To enhance the performance of outdated systems
Which of the following tools collects and correlates data from various sources such as firewalls, intrusion detection systems, and log files for real-time monitoring, analysis, and reporting of security events?
Intrusion Detection Systems (IDS)
Endpoint Detection and Response (EDR)
Security Information and Event Management (SIEM)
Vulnerability Scanners
What is the primary function of Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS)?
To store and analyze log data
To detect and respond to suspicious network traffic or behavior
To monitor and respond to threats at the endpoint level
To use machine learning and behavior analysis to detect abnormal activities
Which security tool focuses on monitoring and responding to threats at the endpoint level?
Log management systems
User and Entity Behavior Analytics (UEBA)
Endpoint Detection and Response (EDR)
Firewalls and next-generation firewalls
What is the role of log management systems in security monitoring?
To detect and respond to suspicious network traffic
To collect and correlate data from various sources
To store, analyze, and manage log data from multiple systems and applications
To use machine learning to detect abnormal user activities
Which tool uses machine learning and behavior analysis to help identify insider threats or new threats that endpoint detection systems have not characterized?
Vulnerability Scanners
User and Entity Behavior Analytics (UEBA)
Security Information and Event Management (SIEM)
Firewalls and next-generation firewalls
What is the primary purpose of firewalls and next-generation firewalls in security monitoring?
To detect and respond to suspicious network traffic
To monitor and control network traffic
To store and analyze log data
To use machine learning to detect abnormal user activities
What is the primary purpose of access control in an organization?
To grant users unlimited access to all resources
To manage and regulate who can access specific resources or systems
To eliminate the need for authentication
To allow unrestricted network traffic
Which of the following is NOT a component of access control mechanisms?
Usernames and passwords
Multi-factor authentication
Role-Based Access Control (RBAC)
Unrestricted access permissions
What is the principle of least privilege?
Granting users the minimal level of access necessary
Allowing users to access all systems and data
Providing maximum access to all employees
Eliminating the need for access control
What should be done before implementing ACLs on firewalls?
Allow all traffic by default
Identify security objectives and determine traffic rules
Disable all security protocols
Ignore continuous monitoring
What is the role of segmentation in network security?
To grant users unlimited access
To split the network into smaller zones
To eliminate the need for firewalls
To allow unrestricted data flow
What is the purpose of configuring folder ACLs in Windows or Linux systems?
To manage access based on the principle of least privilege
To provide unrestricted access to all users
To disable file and directory permissions
To allow all users to modify system files
What is the benefit of continuous monitoring in access control?
To ensure that access control rules are never updated
To adapt to changing security requirements
To eliminate the need for firewalls
To allow unrestricted network traffic
Which mode in Linux uses letters and symbols to represent file permissions?
Octal mode
Symbolic mode
Numeric mode
Absolute mode
In symbolic mode, what does the letter 'u' stand for?
User/Owner
Group
Others
All
What does the '+' operator represent in symbolic mode?
To remove permissions
To add permissions
To set permissions explicitly
To view permissions
Which of the following represents the 'execute' permission in symbolic mode?
r
w
x
e
What does the 'a' stand for in symbolic mode?
User/Owner
Group
Others
All (equivalent to ugo)
What does the numeric value 4 represent in the octal mode for file permissions?
Write (w)
Execute (x)
Read (r)
No permissions
Which command would you use to give the user read and write permissions and remove execute permission for a file?
chmod u+rwx filename
chmod u+rw-x filename
chmod g+rx filename
chmod o-wx filename
What does the numeric value 7 represent in the octal mode for file permissions?
Read and write
Read, write, and execute
Write and execute
Read only
What is the principle of least privilege?
Granting users the maximum level of access required to perform their tasks.
Granting users the minimum level of access required to perform their tasks.
Granting users no access to perform their tasks.
Granting users full administrative access.
What does the command "chmod 755 [filename]" do?
Grants the owner read, write, and execute permissions; the group and others no permissions.
Grants the owner read and write permissions; the group and others read and execute permissions.
Grants the owner read, write, and execute permissions; the group and others read and execute permissions.
Grants the owner read and execute permissions; the group and others write and execute permissions.
What is the primary focus of an application allow list in an organization's IT environment?
Blocking known malicious software
Permitting only approved and trusted applications to run
Allowing all applications to run
Blocking all applications
How does network segmentation enhance security within an IT environment?
By allowing all network segments to communicate freely
By splitting a network into smaller, isolated segments or zones
By combining all network segments into one large network
By removing all firewalls and access control policies
What is the primary objective of network isolation?
To allow free movement of data across all network segments
To establish highly segregated and self-contained network environments
To combine all network segments into one large network
To remove all security measures such as firewalls and access controls
Which of the following is NOT a benefit of using application allow lists?
Mitigating the risk of malware infections
Allowing only pre-vetted applications to run
Blocking all applications from running
Maintaining the integrity and reliability of critical systems and data
What is a key element in maintaining a robust security posture and compliance with regulatory requirements?
Allowing all network segments to communicate freely
Combining all network segments into one large network
Network segmentation
Removing all firewalls and access control policies
What is the first step in hardening a network router?
Update firmware
Enable strong authentication
Change default credentials
Enable encryption
Why is it important to update the router's firmware regularly?
To improve the router's speed
To ensure known vulnerabilities are patched
To increase the router's range
To reduce power consumption
What does enabling strong authentication on a router typically involve?
Using a single password
Implementing multi-factor authentication (MFA)
Disabling unused services
Updating the router's firmware
What is the purpose of disabling unused services and ports on a router?
To increase the router's speed
To reduce the attack surface
To improve the router's range
To save energy
What is the role of Access Control Lists (ACLs) in network security?
To control which devices or IP addresses are allowed to access the router
To increase the router's speed
To update the router's firmware
To enable strong encryption
Which of the following is a method to secure communication with the router?
Using HTTP
Using FTP
Using SSH or HTTPS
Using Telnet
Why is it important to log and monitor router activity?
To increase the router's speed
To identify and respond to potential threats
To improve the router's range
To reduce power consumption
Which of the following is a method to isolate various sections of a network to prevent lateral movement during a security breach?
MAC address filtering
Network segmentation
Backup configuration settings
Physically secure the router
What is the purpose of disabling Wi-Fi Protected Setup (WPS) on a router?
To allow more devices to connect
To enhance the speed of the network
To mitigate susceptibility to brute-force attacks
To improve the range of the Wi-Fi signal
Which security measure involves using MAC address filtering?
To control which devices are allowed to connect to the network
To back up the router's configuration settings
To physically secure the router
To disable WPS on the router
Why is it important to regularly back up the router's configuration settings?
To increase the speed of the network
To ensure a known good configuration in case of a security incident
To allow more devices to connect
To improve the range of the Wi-Fi signal
What is the primary goal of physically securing the router?
To prevent unauthorized physical access to the device
To increase the speed of the network
To allow more devices to connect
To improve the range of the Wi-Fi signal
What type of attack targets the control systems and devices responsible for managing the infrastructure of an organization?
True
False
Which type of attack involves compromising the security and integrity of physical systems and infrastructure?
Environmental attack
Brute force attack
RFID cloning
Phishing attack
What does RFID cloning exploit?
The open access of RFID databases.
The visibility of RFID signals to unauthorized devices.
The vulnerability in the secure communication of RFID devices.
The encryption algorithms of RFID technology.
What are "indicators of compromise" (IOCs) and "indicators of attack" (IOAs) used for?
To monitor environmental changes
To provide insights into potential security threats
To manage network traffic
To control physical access to buildings
Which of the following is an example of a physical attack with environmental implications?
Phishing attack
Water treatment system compromise
Social engineering
Password cracking
What was the consequence of the cyber/ransomware attack on Colonial Pipeline in May 2021?
Unauthorized access to personal data
Disruption of one of the nation's largest fuel pipeline operators
Manipulation of air quality data
Shutdown of a water treatment plant
What can attacks on the power grid's control systems result in?
Leaks and spills
Unauthorized access to personal data
Outages or overloads
Manipulation of water quality parameters
What is a potential consequence of environmental monitoring system manipulation?
Disruption of fuel supply
Inaccurate data on air quality
Unauthorized access to network systems
Physical damage to buildings
What can environmental attacks on dam control systems lead to?
Unauthorized access to personal data
Downstream flooding and environmental damage
Disruption of fuel supply
Manipulation of air quality data
