wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

CompTIA Security+ Access

Total questions: 24

Worksheet time: 12mins

Name
Class
Date
1.

During an airline flight, a laptop user makes last-minute changes to a presentation that contains sensitive company information. Which of the following would make it difficult for other passengers to view this information on the laptop display?

a)

Cable lock

b)

Privacy filter

c)

Smart card

d)

Mantrap

2.

A technician assists Joe, an employee in the sales department who needs access to the client database, by granting him administrator privileges. Later, Joe discovers he has access to the salaries in the payroll database Which of the following security practices was violated?

a)

Strong password policy

b)

Multifactor authentication

c)

Entry control roster

d)

Principle of least privilege

3.

Bob calls and complains that he has suddenly started getting a lot of unwanted email. Which of the following is the BEST type of software to install to help solve Bob's problem?

a)

Anti-virus

b)

Anti-malware

c)

Anti-spam

d)

Anti-plagiarism

4.

Which of the following security practices are the BEST example of the principle of least privilege?

a)

All users on a Windows workstation are limited users except for one user, who is responsible for maintaining the system.

b)

Autorun has been disabled on a Windows workstation.

c)

All users on a Windows workstation have been assigned strong passwords

d)

The Guest user account on a Windows workstation has been disabled

5.

Which are examples of a strong password? (Select TWO)

a)

NewYork

b)

il0ve2EatIceCr3am

c)

skippy

d)

Morganstern

e)

TuxP3nguinsRn0v3l

6.

A security incident is currently occurring on the company network. You discover that the attack involves a computer system that is attached to the network. You're unsure what kind of damage is being done to the network systems or data. Which of the following actions should you take FIRST?

a)

Stop the attack and contain the damage by disconnecting the system from the network

b)

Examine the active computer system to analyze the live network connection, memory contents, and running programs.

c)

Determine whether you have the expertise to conduct an investigation, or whether you need to call in additional help

d)

Document and photograph the entire scene of the crime including the current state of the attached computer system

7.

The chain of custody is used for what purposes?

a)

Retaining evidence integrity by identifying people coming into contact with evidence

b)

Detailing the timeline between creation and discovery of evidence

c)

Identifying the owner of evidence

d)

Maintaining compliance with federal privacy laws

8.

A security technician is conducting a forensic analysis. Which of the following actions is MOST likely to destroy critical evidence?

a)

Disconnecting the system from the network

b)

Shutting down the system

c)

Copying the contents of memory to removable media

d)

Restricting physical access to the system

9.

A public library has purchased a new laptop computer to replace their older desktop computers and is concerned that they are vulnerable to theft. Which of the following laptop features should be used to physically secure the laptop?

a)

A cable lock

b)

Biometric authentication

c)

A multi-factor password policy

d)

An external encryption device

10.

You have a set of DVD-RW discs that have been used to archive files for your latest development project. You need to dispose of the discs. Which of the following methods should you use to BEST prevent extracting data from the discs?

a)

Degaussing

b)

Shredding

c)

Delete the data on the discs

d)

Write junk data over the discs 7 times

11.

You have purchased new computers and will be disposing of your old computers. These computers were previously used for storing highly-sensitive customer order information, including credit card numbers.

To properly protect the accidental discovery of the company's sensitive information, which of the following steps MUST be completed prior to getting rid of the computers?

a)

Physically destroy the hard drives with a hammer

b)

Repartition the hard drives.

c)

Reformat the hard drives

d)

Delete user data and applications from the hard

drives

e)

Reinstall a fresh copy of Windows on the drives

12.

While reviewing video files from your organization's security cameras, you notice a suspicious person using piggy-backing to gain access to your building. The individual in question did not have a security badge.

Which of the following would you MOST likely implement to keep this from happening in the future

a)

Mantraps

b)

Cable locks

c)

Door locks with card readers

d)

Lo-jack recovery service

13.

An unauthorized person gains access to a secured area by following an authorized person through a door controlled by a badge reader. Which of the following security threats does this sentence describe?

a)

Tailgating

b)

Shoulder surfing

c)

Brute forcing

d)

Phishing

14.

Joe, an executive, receives an email that appears to be from the financial institution that provides his company credit card. The text of the email includes Joe's name and the company name and states that there is a problem with Joe's credit card. The email provides a link to verify the credit card, but when Joe hovers over the link, he thinks the web address seems strange.

Which of the following BEST describes this type of attack?

a)

Social engineering

b)

Zero-day attack

c)

Brute forcing

d)

Man-in-the-middle attack

15.

Which of the following are common forms of social engineering attacks?

a)

Sending hoax virus information emails

b)

Using a sniffer to capture network traffic

c)

Stealing the key card of an employee and using that to enter a secured building

d)

Distributing false information about your organization's financial status

16.

Which of the following is an example of social engineering?

a)

Brute force password cracking

b)

Port scanning

c)

Dumpster diving

d)

War dialing

17.

What is the best countermeasure against social engineering?

a)

Acceptable use policy

b)

User awareness training

c)

Strong passwords

d)

Access auditing

18.

You want to configure your computer so that a password is required before the operating system will load. What should you do?

a)

Configure a user password in the BIOS/UEFI.

b)

Configure an administrator password in the BIOS/UEFI

c)

Configure chassis instruction detect

d)

Require complex passwords in the local security policy

19.

ou have purchased a used computer from a computer liquidator. When you boot the computer, you find that there has been a password set on the BIOS. You need to clear the password so that you can edit the CMOS settings.

What should you do?

a)

Remove the motherboard battery for a few seconds.

b)

Flash the BIOS.

c)

Press F2 while booting the computer.

d)

Press Ctrl + Alt + Del while booting the computer.

20.

A large number of compromised computers are infected with malware that allows an attacker (herder) to control them to spread email spam and launch denial-of-service attacks. Which of the following does this security threat describe?

a)

Zombie/botnet

b)

Phishing

c)

Spoofing

d)

Man-in-the-middle

21.

What is a program that appears to be a legitimate application, utility, game, or screensaver, but performs malicious firewall port exposures?

a)

Ransomware

b)

Worm

c)

Scareware

d)

Trojan

22.

What is a cookie?

a)

A file saved on your hard drive that tracks website preferences and use.

b)

A malicious program that runs when you read an email attachment

c)

A malicious program that disguises itself as a useful program.

d)

An executable file that runs in the background and tracks internet use.

23.

While browsing the internet, you notice that your browser displays pop-ups containing advertisements that are related to recent keyword searches you have performed.

What is this an example of?

a)

Adware

b)

Worm

c)

Grayware

d)

Trojan

24.

What is the common name for a program that has no useful purpose, but attempts to spread itself to other systems and often damages resources on the systems where it is found?

a)

Virus

b)

Trojan

c)

Buffer overflow

d)

Password attack