Font size
WorksheetsDomain 1 - Network Security
Total questions: 46
Worksheet time: 23mins
Which aspects of core security fall under the purview of confidentiality? Choose three (3) answers.
Controlling accessibility
Encryption
Tracking data
Strong authentication
Strict control of permissions
Which of the following are examples of levels of confidentiality utilized by organizations? Choose three answers.
Nonconfidential
Internal use only
Top secret
Public
Privileged
Match each of the following terms to their proper definitions.
AVAILABILITY: keeps data secure from unauthorized access
INTEGRITY: keeps data accurate and valid.
CONFIDENTIALITY: keeps data accessible to those who need it.
CONFIDENTIALITY: keeps data secure from unauthorized access
INTEGRITY: keeps data accurate and valid.
AVAILABILITY: keeps data accessible to those who need it.
AVAILABILITY: keeps data secure from unauthorized access
CONFIDENTIALITY: keeps data accurate and valid.
INTEGRITY: keeps data accessible to those who need it.
Which methods can ensure the integrity of information, such as the contents of an email? Choose two answers.
Labels
A digital signature
A redundancy
MFA
Encryption
The availability part of the CIA triangle ensures that data is protected from which circumstances? Choose three answers.
Natural disaster
Malware
Equipment failure
Theft
Corporate mismanagement
A RISK is the possibility of data being compromised. What word should replace RISK in order for the sentence to correct?
Vulnerability
Mitigation
The word is correct in the sentence
Threat
What is a weakness in the CIA of data known as?
Threat
Risk
Vulnerability
Acceptance
What does mitigating a risk mean?
Lessening the impact of a risk
Do nothing about it but acknowledge the risk.
Sharing the risk burden
Do nothing about it
(BLANK) and (BLANK) should be used to control permissions.
Passwords; verification
Logins; accounts
Groups; roles
Users; management
Increasing the amount of privileges for a given user (BLANK) a system’s attack surface.
Exposes
Protects
Limits
Increases
Look at the following statement and choose whether the phrase, “Threat modeling” is correct or needs to be replaced: Threat modeling is the process of identifying threats and vulnerabilities and then defining preventative countermeasures.
Threat analysis
Attack modeling
The statement is correct as it
Attack analysis
Which security concept involves applying multiple layers of security?
Sandboxing
Firewalls
Preclusive defense
Defense in depth
Securing fences and gates with guards and using security cameras help secure which area of access control?
Separation barrier
External perimeter
Virtual private network
Internal perimeter
Which security mechanism sits just inside the entry point of building?
Zone of control
Mantrap
Trap door
Entrapment zone
For thumb drives and external drives, encryption through (BLANK) should be used to encrypt the drive
Ciphertext
MetaFrame
OpenPGP
BitLocker
The idea of restricting both physical and file/server access to only those who need it is known as (BLANK)
Access control
Site security
Social engineering
Principle of least privilege
Which are methods for securing smartphones? Choose three answers.
Mobile device management software
Tethering
Biometrics
Password/PIN protection
Mobile hotspots
Attackers use a (BLANK) to intercept and record what people type.
Pastebin
Keylogger
Transient cookie
Rootkit
Which statements are true of mantraps? Choose two (2) answers.
Mantraps employ physical controls such as barricades and bollards to prevent illegal entry.
Mantraps protect against social engineering techniques such as phishing, vishing, and whaling.
Mantraps are considered physical, psychological, and social deterrents from confidential areas within a building
Mantraps are physicals controls that serve as a gateway from an unsecure part of a building to a secure part of a building
Persons caught in a mantrap are often questioned by security guards of similar individuals
Which social engineering technique do mantraps defend against?
Whaling
Spear phishing
Tailgating
Dumpster diving
Impersonation
Which of the following are examples of technical controls? Choose two (2) answers.
Documentation
Cmdlets
Hashing algorithms
Firewalls
Inclusion detection systems
A buffer overflow attack occurs when one attempts to fill a(n) (BLANK) field with a number outside the (BLANK) range.
Integer, number
Buffer, integer
Integer, integer
Buffer, number
(BLANK) are self-replicating malicious code blocks that are capable of running without a carrier.
Trojan horses
Viruses
Zero day attacks
Worms
A user calls a help desk and states that an antivirus program downloaded is not actually an antivirus program. What does the user have?
Trojan horse
Zero day attack
Worm
Virus
Which of these describe common types of ransomware? Choose two (2) answers.
Crackware
Lockscreen
Encryption
Scareware
Registry lock
A user complains that newly installed software is displaying advertisements at the top of the screen. Which of the following has most likely been installed?
Worm
Virus
Adware
Spyware
A rootkit is used to gain which kind of access to a computer without being detected?
Executive
Global
Administrative
Guest
Which of the following describes a class of malware that creates hidden openings in the OS?
Backdoor
Trojan horse
OpenPGP
Directory traversal
Which of the following malware types causes security breaches that have not yet been identified by credible sources?
Zero day attack
Polymorphica
I’ma Hoax
Logic bomb
A (BLANK) network attack utilizes multiple machines to disrupt a network to the point where it can no longer function.
DoS
Botnet
Zombie
DDoS
Which common attack method injects a fraudulent destination for an IP address?
Replay attack
DNS poisoning
Cross-site scripting
SQL injection attack
Which type of attack method is used to intercept data while it is being transferred?
Back door attack
Replay attack
Email bombing
Man-in-the middle
Which password policies help mitigate brute force attacks? Choose two (2) answers.
Passwords expire after a set time
Passwords are changed regularly
Passwords are stored in secure browsers
Passwords are complex
Passwords are longer than 16 characters
Which three (3) scenarios are examples of MITB attacks?
An attacker changes the browser settings on a device
An attacker redirects data being sent from a browser to a device of their choosing
An attacker uses a script to obtain the cookies and certificates stored on a browser
An attacker changes the browser settings on a device
An attacker runs SQL statements to infiltrate and change the data in a webpage
An attacker redirects data being sent from a browser to a device of their choosing
An attacker redirects data being sent from a browser to a device of their choosing
An attacker records a user’s keystrokes and uses the captured password to hack into the user’s browser
An attacker uses a script to obtain the cookies and certificates stored on a browser
An attacker changes the browser settings on a device
An attacker redirects data being sent from a browser to a device of their choosing
An attacker uses a script to obtain the cookies and certificates stored on a browser
What method do attackers use to inject malicious activity by targeting client-side scripts?
SQL injection
Cross-site scripting
Man-in-the-middle attack
Brute force attack
Man-in-the-browser attack
How do attackers manipulate information on servers by running SQL statements?
Man-in-the-middle attack
Brute force attack
Cross-site scripting
SQL injection
Man-in-the-browser attack
What type of attack involves attackers attempting to guess the password of an account?
Brute force attack
Man-in-the-browser attack
SQL injection
Man-in-the-middle attack
Cross-site scripting
How do attackers intercept data transmission between two devices?
Man-in-the-browser attack
SQL injection
Man-in-the-middle attack
Cross-site scripting
Brute force attack
By sending a script to a website and obtaining privileges to modify webpages, attackers are conducting which type of attack?
Man-in-the-middle attack
Cross-site scripting
Man-in-the-browser attack
SQL injection
Brute force attack
Which 3 (three) are examples of social engineering?
Phone calls asking for info
Student job shadowing
Emails asking for info
Phishing websites
Phone calls asking for information
Emails asking for information
Phishing websites
IRS office audit
Phone calls asking for information
Phishing websites
IRS office audit
Emails asking for information
IRS office audit
Student job shadowing
Emails asking for information
Which three (3) statements are true of keylogging?
While keylogging is often malicious, some users utilize keyloggers legitimately
The use of a keylogger is illegal and ownership of one can result in monetary fines
A keylogger is typically used to capture user credentials
Keyloggers include hardware and software tools that capture keystrokes
While keylogging is often malicious, some users utilize keyloggers legitimately
A keylogger is typically used to capture user credentials
Keyloggers include hardware and software tools that capture keystrokes
Surveillance techniques such as shoulder surfing are examples of keylogging
While keylogging is often malicious, some users utilize keyloggers legitimately
Keyloggers include hardware and software tools that capture keystrokes
Surveillance techniques such as shoulder surfing are examples of keylogging
While keylogging is often malicious, some users utilize keyloggers legitimately
The use of a
Keyloggers include hardware and software tools that capture keystrokes
Surveillance techniques such as shoulder surfing are examples of keylogging
The use of a keylogger is illegal and ownership of one can result in monetary fines
Which three (3) scenarios are examples of the correct usage of a logic bomb?
An attacker sets a logic bomb to detonate in a power grid on the Western coast
An attacker sets a logic bomb to detonate on May 5, 2005 at 5 PM
An attacker sets a logic bomb to detonate on Christmas Eve
An attacker sets a logic bomb to detonate in a power grid on the Western coast
An attacker sets a logic bomb to detonate on May 5, 2005 at 5 PM
An attacker sets a logic bomb to detonate one month after they were fired from a company
An attacker sets a logic bomb to detonate randomly across several machines
An attacker sets a logic bomb to detonate one month after they were fired from a company
An attacker sets a logic bomb to detonate on Christmas Eve
An attacker sets a logic bomb to detonate randomly across several machines
An attacker sets a logic bomb to detonate in a power grid on the Western coast
An attacker sets a logic bomb to detonate on May 5, 2005 at 5 PM
An attacker sets a logic bomb to detonate on May 5, 2005 at 5 PM
An attacker sets a logic bomb to detonate one month after they were fired from a company
An attacker sets a logic bomb to detonate on Christmas Eve
Which two (2) statements are true of setting up a full backup?
Full backups are typically not performed every day
Full backups are set to occur automatically by default
Full backups are typically not performed every day
Full backups connected to an external hard drive are less secure than those saved to a local drive)
Full backups should not interfere with day-to-day operations
Full backups are set to occur automatically by default
Full backups are typically not performed every day
Full backups should not interfere with day-to-day operations
Full backups are typically performed every day
Full backups are set to occur automatically by default
Under which two (2) circumstances do differential backups typically occur?
Before an incremental backup
After an incremental backup
Before an incremental backup
At the same time as a full backup
After a full backup
After an incremental backup
At the same time as a full backup
After a full backup
Before a full backup
After an incremental backup
As more backups take place from the last full or incremental backup, the size of the differential backup file (BLANK)
decreases
halves
increases
doubles
A full restore of data that uses differential backups requires restoring the last full backup, as well as (BLANK) backup(s).
The last differential
All incrementals
All differentials
The first differential
