wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Network Security - Practice Test #1

Total questions: 62

Worksheet time: 31mins

Name
Class
Date
1.

Which controls are looked at as technical controls? (Choose two)

a)

IDS

b)

Training manual

c)

Firewall

d)

AUP

2.

Which type of injection attack uses keywords such as SELECT and UPDATE to manipulate data through a web form?

a)

LDAP injection

b)

SQL injection

c)

XML injection

d)

HTML injection

3.

An end user calls the help desk complaining about a web page not loading the most current data for the page unless the user refreshes the page. What should the help desk agent have the user do first?

a)

Restart the browser

b)

Clear out the cookies

c)

Clear out the history

d)

Clear out the cache

4.

When one suspects a device has been affected by malware, what is the first step that should be taken to remediate the device?

a)

Disconnect the device from the network

b)

Run a system scan on the device

c)

Update the antimalware app to use for remediation

d)

Update the signature files on the antimalware app to use for remediation

5.

A good Audit Plan may collect both successful and failed events. (T/F)

a)

True

b)

False

6.

Audit events take up computer resources and personnel time, so you should be selective about the events to audit. (T/F)

a)

True

b)

False

7.

You should always audit log-on successes. (T/F)

a)

True

b)

False

8.

Review the underlined text. If the statement is correct, select "No change is needed." If the statement is incorrect, select the answer that best fits in the statement: Spoofing redirects internet traffic from one website to an identical-looking website in order to trick you into entering your username and password into their database.

a)

No change is needed

b)

Spamming

c)

Pharming

d)

Phishing

9.

What must take place for someone trying to enter a physical area of a building before access control takes place?

a)

Authentication

b)

Authorization

c)

Accounting

d)

Auditing

10.

MAC Filtering is best suited for large wireless networks. (T/F)

a)

True

b)

False

11.

WEP is the strongest form of encryption for a wireless network. (T/F)

a)

True

b)

False

12.

WPA/WPA2 can require an authentication server. (T/F)

a)

True

b)

False

13.

One of the layers of defense in the anti-phishing and malware protection strategies developed by Microsoft is:

a)

SmartScreen Filter

b)

Malware Detector

c)

Home Defense

d)

SureBlock

14.

Review the underlined text. If the statement is correct, select "No change is needed." If the statement is incorrect, select the answer that best fits in the statement: One of the ways you can protect your computer from hackers and malicious software is to use Windows Firewall.

a)

Spam filtering

b)

No change is needed

c)

Email filtering

d)

Windows Security Essentials

15.

What is considered the minimum length of a good password?

a)
Eight characters
b)

Five characters

c)

Thirty-two characters

d)

Twenty characters

16.

Static Routing allows multiple computers on an internal network to share one public IP address. Review the underlined text. If the statement is correct, select "No change is needed." If the statement is incorrect, select the answer that best fits in the statement.

a)

NAT

b)

VLAN

c)

No change is needed

d)

IPsec

17.

Which type of VPN will often have a user connect through a web browser?

a)

TLS

b)

SSL

c)

SSH

d)

UDP

18.

Which type of VPN connection usually connects two business entities?

a)

Site-to-host

b)
Site-to-site
c)

Host-to-host

19.

What email filtering technique uses a list of verified DNS domains to verify that an email is coming from a trusted IP address?

a)

Dedicated Perimeter Firewall

b)

Network Address Translation (NAT)

c)

SMTP Callback Verification

d)

Sender Policy Framework (SPF)

20.

Application-level firewalls can provide content filtering and virus protection. (T/F)

a)

True

b)

False

21.

Application-level firewalls support caching. (T/F)

a)

True

b)

False

22.

Application-level firewalls tend to be less resource intensive than that of a traditional firewall. (T/F)

a)

True

b)

False

23.

Which of the following are NTFS permissions? (Choose three)

a)

Read

b)

Write

c)

View

d)

Modify

e)

Administrator

24.

Which protocols are considered unsecure and should be avoided in a server environment? (Choose two)

a)

PAP

b)

SSH

c)

CHAP

d)

Telnet

e)

SFTP

25.

Which type of DNS record contains an IP address that is then used to look up an associated host or domain name?

a)

PTR

b)

MX

c)

A

d)

SPF

26.

IPSec encrypts data packets using AH. (T/F)

a)

True

b)

False

27.

IPSec is a set of protocols that protects data transmission between hosts by providing authentication and privacy. (T/F)

a)

True

b)

False

28.

IPSec is used to create a secure tunnel between two computing devices. (T/F)

a)

True

b)

False

29.

IPSec uses digital signatures to create a chain of authority. (T/F)

a)

True

b)

False

30.

Which of the following would be considered to be the strongest password?

a)

j0hn$m1T

b)

P@ssw0rd

c)

johnny

d)

password

31.

Your IT department is getting a barrage of calls from users saying their pop-up blockers are not blocking ads for huge discounts on software. Upon further research you discover that you current malware signature files are not sufficiently removing this nuisance from your systems. Which type of attack is taking place?

a)

Ransomeware

b)

Spyware

c)

Adware

32.

Your IT department is getting a barrage of calls from users saying their pop-up blockers are not blocking ads for huge discounts on software. Upon further research you discover that you current malware signature files are not sufficiently removing this nuisance from your systems. Which characteristic of the attack indicates that it is not being eradicated by antimalware programs?

a)

Zero-day

b)

Rootkit

c)

Stealth

33.

A certificate authority provides keys used in digital certificates for authentication. (T/F)

a)

Yes

b)

No

34.

In a Public Key Infrastructure, the public key encrypts data, and a corresponding public key decrypts it. (T/F)

a)

True

b)

False

35.

In Digital Signatures, the sender uses a secret key to create a unique electronic number that can be read by anyone possessing the corresponding public key, which verifies that the message is from the sender. (T/F)

a)

True

b)

False

36.

Forging a fake sender address within an email message is an example of malware. Review the underlined text. If the statement is correct, select "No change is needed." If the statement is incorrect, select the answer that best fits in the statement.

a)

No change is needed

b)

Phishing

c)

Spam

d)

Spoofing

37.

Where do most computers obtain a Media Access Control (MAC) address?

a)

DNS Server

b)

Network Interface

c)

Hub or Layer-2 Switch

d)

IP Address

38.

The tool used to view audit logs is Event Viewer. (T/F)

a)

True

b)

False

39.

You can audit logon failures to warn of hacking attacks. (T/F)

a)

True

b)

False

40.

You cannot limit the size of audit logs. (T/F)

a)

True

b)

False

41.

Ensuring the Sales department can access a document is an example of:

a)

Availability

b)

Confidentiality

c)

Integrity

42.

Encrypting a document as it travels across network is an example of:

a)

Availability

b)

Confidentiality

c)

Integrity

43.

Verifying the sender of a document is an example of:

a)

Availability

b)

Confidentiality

c)

Integrity

44.

Which backup does this describe? Backs up all files and resets the archive bit

a)

Incremental

b)

Differential

c)

Full

45.

Which backup does this describe? Backs up all changed files since the last full backup

a)

Incremental

b)

Differential

c)

Full

46.

Which backup does this describe? Backs up all changed files since the last full or Incremental backup

a)

Incremental

b)

Differential

c)

Full

47.

Which protocol should be allowed only on email servers used to send email and should be blocked on all other servers and client machines?

a)

SMTP

b)

POP3

c)

FTP

d)

IMAP

48.

How can a wireless network best be set up to allow only specific devices onto the network?

a)

Device type filtering

b)

MAC address filtering

c)

SSID filtering

d)

IP address filtering

49.

A Network Sniffer can easily obtain:

a)
Communication via HTTPS
b)

Unencrypted passwords

c)

Servers without security

d)

Digital Certificates

50.

Which Windows app is used to help protect a device against malware?

a)

Forefront Gateway

b)

Unified Threat Manager

c)

Windows Defender

d)

Malicious Software Removal Tool

51.

Which of the following are advanced permissions in NTFS? (Choose two)

a)

Change Permissions

b)

Full Control

c)

Take Ownership

d)

List Folder Contents

52.

BitLocker, when possible, stores the encryption key on a computer's EFS. Review the underlined text. If the statement is correct, select "No change is needed." If the statement is incorrect, select the answer that best fits in the statement.

a)

BitLocker To Go

b)

TPM

c)

BitLocker

d)

No change is needed

53.

RADIUS is an authentication method that identifies individuals based on physical characteristics such as fingerprints, facial recognition, retina scans, or voice patterns. Review the underlined text. If the statement is correct, select "No change is needed." If the statement is incorrect, select the answer that best fits in the statement.

a)

Dictionary Attack

b)

Brute Force Attack

c)

Biometrics

d)

No change is needed

54.

A junior administrator asks you what it means to harden a server. Which two statements fit the description of hardening a server?

a)

Place the server in a secure location

b)

Minimize crosstalk

c)

Uninstall unnecessary features

d)

Disable unnecessary services

55.

To best protect servers, which of the following options is considered a best practice on how services are used on servers?

a)

Run all services on one server

b)

Spread out the services among servers

c)

Run all services on the domain controller

d)

Run all services on two servers

56.

Malware that steals and encrypts data and demands money for the return of the data is known as what type of malware?

a)

Ransomware

b)

Cookie

c)

Spyware

d)

Adware

57.

Which three characteristics describe worms? (Choose three)

a)

Typically does not corrupt or modify files

b)

A self-replicating program that copies itself to other computers without user intervention

c)

Only passed by email

d)

Uses system resources like bandwidth, memory, and processor time, which makes the computer run slow

e)

Contained in most music and videos

58.

Which Password policy prohibits reusing the same password?

a)
History policy
b)

Lockout policy

c)

Length policy

d)

Complexity policy

59.

Which protocols are used to encrypt emails? (Choose two)

a)

S/MIME

b)

SSL

c)

PGP

d)

TLS

60.

The process of eliminating a risk by choosing not to participate in an action or activity describes which of the following?

a)

Risk acceptance

b)

Residual risk

c)

Risk avoidance

d)

Risk mitigation

61.

A junior administrator notices, when looking at a folder's permissions, gray checkboxes in the Allow column for a group's permissions. What do the gray checkboxes represent?

a)

The permissions are explicit.

b)

The permissions are inherited.

c)

The permissions are conditional.

d)

The permissions have been disabled temporarily.

62.

Where are password policies established for an Active Directory domain?

a)

Group Policy

b)

Active Directory Users and Computers

c)

Local Security Policy

d)

Active Directory Administrative Center