Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

ACI Sec+ Midweek

Total questions: 75

Worksheet time: 38mins

Name
Class
Date
1.

Which term does NOT represent a pillar of cybersecurity?

a)

Authentication

b)

Confidentiality

c)

Availability

d)

Integrity

2.

What concept establishes that the parties involved in an action or event cannot deny having been involved?

a)

Authorization

b)

Non-repudiation

c)

Zero Trust

d)

Honeypot

3.

Which access control method is described by resource owners having the authority to grant or deny access to other users?

a)

RBAC

b)

ABAC

c)

MAC

d)

DAC

4.

What physical access control method prevents tailgating by ensuring only one individual at a time can authenticate and be granted physical access through a barrier?

a)

Policy Enforcement Point

b)

Access badge

c)

Access Control Vestibule

d)

Control plane

5.

Which security category focuses on policies, procedures, and overall management of security within an organization?

a)

Managerial

b)

Operational

c)

Technical

d)

Physical

6.

Which security category is exemplified by network security, encryption, authentication mechanisms, IDSs, and firewalls?

a)

Managerial

b)

Physical

c)

Technical

d)

Operational

7.

An organization posts "No Trespassing" signs. What type of security control is this considered?

a)

Deterrent

b)

Detective

c)

Preventive

d)

Corrective

8.

As part of its critical workflow, an organization relies on a Windows-8-based application. The application cannot be moved to a newer OS, and the organization does not have the technical capability to write a new application for a newer OS. What type of security control should the organization consider?

a)

Preventive

b)

Directive

c)

Deterrent

d)

Compensating

9.

What is the most effective way to sanitize an SSD and retain use of it?

a)

Cryptographic erasure

b)

Degaussing

c)

Shredding

d)

Quick format

10.

What data sanitization method involves the use of a magnetic device?

a)

Cryptographic erasure

b)

Quick format

c)

Degaussing

d)

Shredding

11.

When a new employee first gets a network account created for them (and before they log on for the first time), what part of the IAM framework is complete?

a)

Authentication

b)

Accounting

c)

Identification

d)

Authorization

12.

The following statement is an example of what type of access control method: "if request_time == Friday AND current_time >= 6:00 PM THEN deny_access"?

a)

RBAC

b)

ABAC

c)

MAC

d)

DAC

13.

What password policy can prevent users from reusing a specific number of previous passwords?

a)

Password history

b)

Minimum password age

c)

Account lockout

d)

Password length

14.

What is the term used to describe a physical device that generates time-based passwords as an additional layer of security during authentication?

a)

OTP

b)

Push notification

c)

MFA

d)

Hardware token

15.

Which is an authentication factor that relies on geolocation or IP geolocation?

a)

Something you know

b)

Something you have

c)

Something you are

d)

Somewhere you are

16.

What XML-based standard is used to exchange authentication and authorization data between an IdP and an SP?

a)

LDAP

b)

SSO

c)

SAML

d)

OIDC

17.

An organization has taken out a lease for a building that will be used to rebuild their company in the event of a disaster. No work or buildout is being conducted at the newly leased location. What type of site is this considered?

a)

Warm site

b)

Cold site

c)

Hot site

d)

This is not considered any type of site.

18.

An organization conducts asynchronous replication with a backup site that is fully built out, operational, and staffed. What type of backup site is this?

a)

Hot site

b)

Cold Site

c)

Warm site

d)

COOP site

19.

An organization adds more network components (i.e., load balancers, server clusters, or redundant links) to distribute the load and accommodate increased traffic. What is this process called?

a)

Ease of deployment

b)

Horizontal scaling

c)

Vertical scaling

d)

Elasticity

20.

An organization increases the capacity of existing network components by upgrading routers, switches, or server hardware. What is this process called?

a)

Ease of deployment

b)

Horizontal scaling

c)

Vertical scaling

d)

Elasticity

21.

Which of the following is NOT a risk transference strategy?

a)

An MSP

b)

Patch management

c)

Ransomware

d)

Data center co-location

22.

Which of the following is NOT a network segmentation method?

a)

VLAN

b)

Subnetting

c)

Air gapping

d)

Parallels desktop

23.

Select the Type 1 hypervisor.

a)

Oracle VirtualBox

b)

Parallels desktop

c)

VMWare Workstation

d)

Microsoft Hyper-V

24.

You would like to create virtualization at the OS level that shares the host OS kernel but runs as an isolated process. Your virtualization object will only need to conduct one task or function but will require all dependencies. What type of virtualization are you considering?

(a)  

25.

As your network has grown in size, you have begun to abstract connections that move data throughout the network as planes so you can manage them more efficiently. What have you implemented?

a)

SDN

b)

Microservices

c)

IaC

d)

Virtualization

26.

You have an SLA with a CSP to provide your web service with six 9s of availability. Over the year, there has only been 1 minute of combined downtime for your web application server. Has the CSP met the terms of the SLA?

a)

Yes, the maximum downtime for six 9s of availability is approximately 30 seconds.

b)

No, the maximum downtime for six 9s of availability is approximately 52 minutes.

c)

No, six 9s of availability ensures zero annual downtime.

d)

Yes, the maximum downtime for six 9s of availability is approximately 52 minutes.

27.

Which deployment concept repeats all manual configurations completely, leading to more consistent deployment and management?

a)

Microservices

b)

Serverless

c)

RTOS

d)

IaC

28.

While coordinating with a CSP, you would like to better understand the division of responsibilities between you and the CSP. What document should be consulted?

a)

BCP

b)

SLA

c)

Responsibility matrix

d)

DRP

29.

Which of the following is NOT an example of a device that uses an embedded system?

a)

A pacemaker

b)

Smart speakers

c)

Automobile infotainment systems

30.

As a sophisticated cyber security organization, you would like to implement a fake but believable production network to detect and analyze malicious attacker techniques. What should you deploy?

a)

Honeynet

b)

Screened subnet

c)

Physical security

d)

Policy enforcement point

31.

You have been tasked with hardening a user workstation. What technique(s) should be applied? (Select all that apply.)

a)

Change default credentials

b)

Enable DES encryption

c)

Open port 21 for secure remote management

d)

Enable logging

32.

A colleague has recommended a tool that can scan and assess systems against predefined secure configuration baselines. What type of tool has been recommended?

a)

SCAP compliant

b)

SNMP

c)

DLP

d)

SOAR

33.

Which Wi-Fi encryption standard utilizes AES-CCMP?

a)

WEP

b)

WPA2

c)

WPA

d)

WPA3

34.

Select the AAA server.

a)

FTPS

b)

SFTP

c)

LDAP

d)

RADIUS

35.

An organization you are joining has offered you a selection of mobile phones to choose from. On your chosen phone, you will have access to the company network and will be able to use it for personal calls and internet browsing. What mobile deployment model is being used?

a)

BYOD

b)

CYOD

c)

COPE

d)

COBO

36.

Which standard outlines security requirements for organizations that handle credit card information?

a)

ISO 27001

b)

NIST SP 800-63

c)

PCI DSS

d)

SOX

37.

As part of contingency planning, you have defined RTOs and RPOs for a plan to complement your BCP. What plan are you developing?

a)

COOP

b)

DRP

c)

IRP

d)

InfoSec Policy

38.

Your organization’s SDLC is too rigid and non-responsive to stakeholder changes. What model could you recommend switching to for better responsiveness to change?

a)

Secure SDLC

b)

Dynamic

c)

Waterfall

d)

Agile

39.

An agreement that discusses permissible and prohibited activities with organizationally owned IT assets. What agreement have you implemented?

a)

SDLC

b)

SLA

c)

AUP

d)

NDA

40.

A former colleague left the company, and subsequently, his remote access credentials were used to access the production network and deploy malware. What process failed to prevent this?

a)

Onboarding

b)

Offboarding

c)

ACL

d)

Principle of least privilege

41.

In order to protect your sensitive data, you have created a secure execution environment. What is the state of the data you are protecting?

a)

Data at rest

b)

Data in use

c)

Data in transit

d)

Proprietary data

42.

By applying Full Disk Encryption with BitLocker, what type of data have you protected?

a)

Proprietary data

b)

Data in use

c)

Data in transit

d)

Data at rest

43.

What refers to the idea that data is bound by the regulations and control policies of the country or jurisdiction in which it is situated or originates?

a)

Data geolocation

b)

Data state

c)

Data sovereignty

d)

Geographic restrictions

44.

In order to send medical data to an analytics company, you would like to remove and replace the PHI in a way that anonymizes it and leaves it in a format that can be restored to its original condition when returned. What is the BEST way to modify this data?

a)

Data masking

b)

Tokenization

c)

Segmenting data

d)

Hashing the data

45.

Select the cryptographic process NOT used for hashing.

a)

MD5

b)

RIPEMD

c)

AES

d)

SHA

46.

Which data role is responsible for enforcing data governance policies to ensure data is collected correctly?

a)

Data stewards

b)

Data processors

c)

Data controllers

d)

Data owners

47.

What security zone is most appropriate for a public web server?

a)

Guest network

b)

Management network

c)

Screened subnet

d)

Internal network

48.

Which type of security device is used to create a screened subnet?

a)

NAC

b)

Layer 3 switch

c)

Firewall

d)

Load balancer

49.

A colleague recommends the assignment of permissions and access rights to ensure that users and systems are provided only the minimum access required to accomplish their tasks. What security principle has been recommended?

a)

SAML

b)

Least privilege

c)

Identity proofing

d)

MFA

50.

A network switch defaults to broadcasting all packets through all of its switch ports when it is overloaded, instead of remaining a unicast device. What type of failure mode is this considered?

a)

Inline failure

b)

Fail open

c)

Fail closed

d)

Connective failure

51.

In a screened subnet, to protect a web server from attacker access, a web server can be configured to only accept administrative connections from which type of server?

a)

Jump server

b)

Proxy server

c)

Choke firewall

d)

SASE

52.

Which type of server can be used to prevent employees from accessing social media from their workstations?

a)

Jump server

b)

Forward proxy

c)

Reverse proxy

d)

Load balancer

53.

Which type of firewall does not retain context or connection state information?

a)

Stateful firewall

b)

NGFW

c)

Stateless firewall

d)

WAF

54.

What type of test access point requires a physical break in the communication link?

a)

Active TAP

b)

Fail-open TAP

c)

Fail-closed TAP

d)

Passive TAP

55.

Which security device must be positioned in-line with network traffic to enable protective action?

a)

IDP

b)

VPN

c)

IPSec

d)

IPS

56.

Which IEEE standard includes EAP authentication protocols?

a)

802.11

b)

802.1Q

c)

802.3

d)

802.5

57.

Which EAP method may be used if both the supplicant and authentication server have been issued a digital certificate?

a)

EAP-FAST

b)

EAP-TLS

c)

MS-CHAP

d)

EAP-TTLS

58.

Which IPSec mode is appropriate for an untrusted network?

a)

Tunnel

b)

Transport

c)

AH

d)

ESP

59.

Which IPsec protocol only ensures data integrity and authenticity but does not encrypt the packet payload?

a)

Tunnel

b)

Transport

c)

AH

d)

ESP

60.

What protocol is used in SFTP to secure the data in transit?

a)

SSL

b)

SSH

c)

TLS

d)

RDP

61.

Which hashing algorithm results in a 128-bit hash value?

a)

SHA-1

b)

SHA-2

c)

SHA-3

d)

MD5

62.

Select the asymmetric encryption algorithm.

a)

AES

b)

Blowfish

c)

3DES

d)

RSA

63.

Select the symmetric encryption algorithm.

a)

RSA

b)

DSA

c)

Twofish

d)

ElGamal

64.

Which encryption algorithm utilizes a public and private key pair?

a)

AES

b)

RSA

c)

SHA-256

d)

MD5

65.

Which encryption algorithm can be configured to operate in a stream or block cipher mode?

a)

RC4

b)

Salsa20

c)

RSA

d)

AES

66.

What level of encryption are FileVault and BitLocker designed to provide?

a)

Database-level

b)

Disk-level

c)

Record-level

d)

File-level

67.

What key is used to sign a digital signature?

a)

Sender's public key

b)

Sender's private key

c)

Recipient's public key

d)

Recipient's private key

68.

Within the Public Key Infrastructure, what entity signs and issues digital certificates?

a)

Client

b)

RA

c)

CA

d)

OCSP

69.

Which authorities sign their own certificates?

a)

Root CA

b)

Intermediate CA

c)

RA

d)

OCSP

70.

Which attribute of the X.509 standard is used to identify subdomains that a certificate may be used with and may include a wildcard character?

a)

DN

b)

CN

c)

SAN

d)

Issuer

71.

What type of obfuscation does the following command apply? "C:> Steghide embed -ef input.txt -cf image.jpg -sf output.jpg"

a)

Data masking

b)

Steganography

c)

Tokenization

d)

Key management

72.

Once a blockchain transaction has been recorded and added to the block, it is virtually impossible to alter or delete. What is this characteristic referred to as?

a)

Smart contract

b)

Cryptographic hashing

c)

Data masking

d)

Immutable ledger

73.

Digital certificates can be revoked for many reasons. What online responder can be used to validate the revocation status of a specific certificate?

a)

CRL

b)

CRM

c)

PKI

d)

OCSP

74.

Once a CSR is submitted to a CA, what process is completed prior to the CA signing the certificate?

a)

Key distribution

b)

Record keeping

c)

Validation

d)

Policy enforcement

75.

What stand-alone security device can be used for cryptographic key generation, backup, and rotation supporting multiple machines?

a)

HSM

b)

TPM

c)

Blockchain

d)

SDN