WorksheetsACI Sec+ Midweek
Total questions: 75
Worksheet time: 38mins
Which term does NOT represent a pillar of cybersecurity?
Authentication
Confidentiality
Availability
Integrity
What concept establishes that the parties involved in an action or event cannot deny having been involved?
Authorization
Non-repudiation
Zero Trust
Honeypot
Which access control method is described by resource owners having the authority to grant or deny access to other users?
RBAC
ABAC
MAC
DAC
What physical access control method prevents tailgating by ensuring only one individual at a time can authenticate and be granted physical access through a barrier?
Policy Enforcement Point
Access badge
Access Control Vestibule
Control plane
Which security category focuses on policies, procedures, and overall management of security within an organization?
Managerial
Operational
Technical
Physical
Which security category is exemplified by network security, encryption, authentication mechanisms, IDSs, and firewalls?
Managerial
Physical
Technical
Operational
An organization posts "No Trespassing" signs. What type of security control is this considered?
Deterrent
Detective
Preventive
Corrective
As part of its critical workflow, an organization relies on a Windows-8-based application. The application cannot be moved to a newer OS, and the organization does not have the technical capability to write a new application for a newer OS. What type of security control should the organization consider?
Preventive
Directive
Deterrent
Compensating
What is the most effective way to sanitize an SSD and retain use of it?
Cryptographic erasure
Degaussing
Shredding
Quick format
What data sanitization method involves the use of a magnetic device?
Cryptographic erasure
Quick format
Degaussing
Shredding
When a new employee first gets a network account created for them (and before they log on for the first time), what part of the IAM framework is complete?
Authentication
Accounting
Identification
Authorization
The following statement is an example of what type of access control method: "if request_time == Friday AND current_time >= 6:00 PM THEN deny_access"?
RBAC
ABAC
MAC
DAC
What password policy can prevent users from reusing a specific number of previous passwords?
Password history
Minimum password age
Account lockout
Password length
What is the term used to describe a physical device that generates time-based passwords as an additional layer of security during authentication?
OTP
Push notification
MFA
Hardware token
Which is an authentication factor that relies on geolocation or IP geolocation?
Something you know
Something you have
Something you are
Somewhere you are
What XML-based standard is used to exchange authentication and authorization data between an IdP and an SP?
LDAP
SSO
SAML
OIDC
An organization has taken out a lease for a building that will be used to rebuild their company in the event of a disaster. No work or buildout is being conducted at the newly leased location. What type of site is this considered?
Warm site
Cold site
Hot site
This is not considered any type of site.
An organization conducts asynchronous replication with a backup site that is fully built out, operational, and staffed. What type of backup site is this?
Hot site
Cold Site
Warm site
COOP site
An organization adds more network components (i.e., load balancers, server clusters, or redundant links) to distribute the load and accommodate increased traffic. What is this process called?
Ease of deployment
Horizontal scaling
Vertical scaling
Elasticity
An organization increases the capacity of existing network components by upgrading routers, switches, or server hardware. What is this process called?
Ease of deployment
Horizontal scaling
Vertical scaling
Elasticity
Which of the following is NOT a risk transference strategy?
An MSP
Patch management
Ransomware
Data center co-location
Which of the following is NOT a network segmentation method?
VLAN
Subnetting
Air gapping
Parallels desktop
Select the Type 1 hypervisor.
Oracle VirtualBox
Parallels desktop
VMWare Workstation
Microsoft Hyper-V
You would like to create virtualization at the OS level that shares the host OS kernel but runs as an isolated process. Your virtualization object will only need to conduct one task or function but will require all dependencies. What type of virtualization are you considering?
(a)
As your network has grown in size, you have begun to abstract connections that move data throughout the network as planes so you can manage them more efficiently. What have you implemented?
SDN
Microservices
IaC
Virtualization
You have an SLA with a CSP to provide your web service with six 9s of availability. Over the year, there has only been 1 minute of combined downtime for your web application server. Has the CSP met the terms of the SLA?
Yes, the maximum downtime for six 9s of availability is approximately 30 seconds.
No, the maximum downtime for six 9s of availability is approximately 52 minutes.
No, six 9s of availability ensures zero annual downtime.
Yes, the maximum downtime for six 9s of availability is approximately 52 minutes.
Which deployment concept repeats all manual configurations completely, leading to more consistent deployment and management?
Microservices
Serverless
RTOS
IaC
While coordinating with a CSP, you would like to better understand the division of responsibilities between you and the CSP. What document should be consulted?
BCP
SLA
Responsibility matrix
DRP
Which of the following is NOT an example of a device that uses an embedded system?
A pacemaker
Smart speakers
Automobile infotainment systems
As a sophisticated cyber security organization, you would like to implement a fake but believable production network to detect and analyze malicious attacker techniques. What should you deploy?
Honeynet
Screened subnet
Physical security
Policy enforcement point
You have been tasked with hardening a user workstation. What technique(s) should be applied? (Select all that apply.)
Change default credentials
Enable DES encryption
Open port 21 for secure remote management
Enable logging
A colleague has recommended a tool that can scan and assess systems against predefined secure configuration baselines. What type of tool has been recommended?
SCAP compliant
SNMP
DLP
SOAR
Which Wi-Fi encryption standard utilizes AES-CCMP?
WEP
WPA2
WPA
WPA3
Select the AAA server.
FTPS
SFTP
LDAP
RADIUS
An organization you are joining has offered you a selection of mobile phones to choose from. On your chosen phone, you will have access to the company network and will be able to use it for personal calls and internet browsing. What mobile deployment model is being used?
BYOD
CYOD
COPE
COBO
Which standard outlines security requirements for organizations that handle credit card information?
ISO 27001
NIST SP 800-63
PCI DSS
SOX
As part of contingency planning, you have defined RTOs and RPOs for a plan to complement your BCP. What plan are you developing?
COOP
DRP
IRP
InfoSec Policy
Your organization’s SDLC is too rigid and non-responsive to stakeholder changes. What model could you recommend switching to for better responsiveness to change?
Secure SDLC
Dynamic
Waterfall
Agile
An agreement that discusses permissible and prohibited activities with organizationally owned IT assets. What agreement have you implemented?
SDLC
SLA
AUP
NDA
A former colleague left the company, and subsequently, his remote access credentials were used to access the production network and deploy malware. What process failed to prevent this?
Onboarding
Offboarding
ACL
Principle of least privilege
In order to protect your sensitive data, you have created a secure execution environment. What is the state of the data you are protecting?
Data at rest
Data in use
Data in transit
Proprietary data
By applying Full Disk Encryption with BitLocker, what type of data have you protected?
Proprietary data
Data in use
Data in transit
Data at rest
What refers to the idea that data is bound by the regulations and control policies of the country or jurisdiction in which it is situated or originates?
Data geolocation
Data state
Data sovereignty
Geographic restrictions
In order to send medical data to an analytics company, you would like to remove and replace the PHI in a way that anonymizes it and leaves it in a format that can be restored to its original condition when returned. What is the BEST way to modify this data?
Data masking
Tokenization
Segmenting data
Hashing the data
Select the cryptographic process NOT used for hashing.
MD5
RIPEMD
AES
SHA
Which data role is responsible for enforcing data governance policies to ensure data is collected correctly?
Data stewards
Data processors
Data controllers
Data owners
What security zone is most appropriate for a public web server?
Guest network
Management network
Screened subnet
Internal network
Which type of security device is used to create a screened subnet?
NAC
Layer 3 switch
Firewall
Load balancer
A colleague recommends the assignment of permissions and access rights to ensure that users and systems are provided only the minimum access required to accomplish their tasks. What security principle has been recommended?
SAML
Least privilege
Identity proofing
MFA
A network switch defaults to broadcasting all packets through all of its switch ports when it is overloaded, instead of remaining a unicast device. What type of failure mode is this considered?
Inline failure
Fail open
Fail closed
Connective failure
In a screened subnet, to protect a web server from attacker access, a web server can be configured to only accept administrative connections from which type of server?
Jump server
Proxy server
Choke firewall
SASE
Which type of server can be used to prevent employees from accessing social media from their workstations?
Jump server
Forward proxy
Reverse proxy
Load balancer
Which type of firewall does not retain context or connection state information?
Stateful firewall
NGFW
Stateless firewall
WAF
What type of test access point requires a physical break in the communication link?
Active TAP
Fail-open TAP
Fail-closed TAP
Passive TAP
Which security device must be positioned in-line with network traffic to enable protective action?
IDP
VPN
IPSec
IPS
Which IEEE standard includes EAP authentication protocols?
802.11
802.1Q
802.3
802.5
Which EAP method may be used if both the supplicant and authentication server have been issued a digital certificate?
EAP-FAST
EAP-TLS
MS-CHAP
EAP-TTLS
Which IPSec mode is appropriate for an untrusted network?
Tunnel
Transport
AH
ESP
Which IPsec protocol only ensures data integrity and authenticity but does not encrypt the packet payload?
Tunnel
Transport
AH
ESP
What protocol is used in SFTP to secure the data in transit?
SSL
SSH
TLS
RDP
Which hashing algorithm results in a 128-bit hash value?
SHA-1
SHA-2
SHA-3
MD5
Select the asymmetric encryption algorithm.
AES
Blowfish
3DES
RSA
Select the symmetric encryption algorithm.
RSA
DSA
Twofish
ElGamal
Which encryption algorithm utilizes a public and private key pair?
AES
RSA
SHA-256
MD5
Which encryption algorithm can be configured to operate in a stream or block cipher mode?
RC4
Salsa20
RSA
AES
What level of encryption are FileVault and BitLocker designed to provide?
Database-level
Disk-level
Record-level
File-level
What key is used to sign a digital signature?
Sender's public key
Sender's private key
Recipient's public key
Recipient's private key
Within the Public Key Infrastructure, what entity signs and issues digital certificates?
Client
RA
CA
OCSP
Which authorities sign their own certificates?
Root CA
Intermediate CA
RA
OCSP
Which attribute of the X.509 standard is used to identify subdomains that a certificate may be used with and may include a wildcard character?
DN
CN
SAN
Issuer
What type of obfuscation does the following command apply? "C:> Steghide embed -ef input.txt -cf image.jpg -sf output.jpg"
Data masking
Steganography
Tokenization
Key management
Once a blockchain transaction has been recorded and added to the block, it is virtually impossible to alter or delete. What is this characteristic referred to as?
Smart contract
Cryptographic hashing
Data masking
Immutable ledger
Digital certificates can be revoked for many reasons. What online responder can be used to validate the revocation status of a specific certificate?
CRL
CRM
PKI
OCSP
Once a CSR is submitted to a CA, what process is completed prior to the CA signing the certificate?
Key distribution
Record keeping
Validation
Policy enforcement
What stand-alone security device can be used for cryptographic key generation, backup, and rotation supporting multiple machines?
HSM
TPM
Blockchain
SDN
