WorksheetsCompTIA Security Plus
Total questions: 32
Worksheet time: 16mins
Which of the following would be the most secure way to deploy a legacy application that requires a legacy operating system?
Stress testing
Sandboxing
Placing it on an encrypted drive
Dynamic testing
Which of the following statements are true of input validation?
Requires a login with normal characters as input during testing
Helps to overcome buffer overflow and DoS attack
Includes sending any unexpected or maliciously crafted input to a system
Ensures that different types of input are handled gracefully by an application
Which of the following is more secure and checks the submitted data to ensure its validity?
Browser-side validation
Server-side validation
Client-side validation
Database-side validation
While inspecting your web application, you found that it is vulnerable to a SQL injection attack. Which of the following steps should you immediately take?
Put the web server on DMZ
Add input validation to forms
Install a host-based firewall on the web server
Apply security patch for the operating system on the web server
Which of the following fully implements 802.11i security requirements?
WPA
WPA2
WEP
WPS
What is the process of applying manual changes to a program called?
Patching
Replacement
Hotfix
Service pack
Brena, a security analyst, notices that external users are constantly reporting that a web application is slow and frequently times out when attempting to submit information. Which of the following software development best practices will she implement to prevent the issue?
Input validation
Fuzzing
Stress testing
Regression testing
Gertrude is managing a new software project. The project has very clearly defined requirements that are not likely to change. Which of the following is the most appropriate development model for her?
Scrum
Agile
XP programming
Waterfall
Mary is responsible for website security in her company. She wants to address widely known and documented web application vulnerabilities. Which resource would be most helpful?
OWASP
ISO
NIST
CERT
Which programming model will be appropriate for the situations wherein the requirements are clearly defined well in advance?
Prototyping
Waterfall
Scrum
Agile
An encoded message is sent using public key infrastructure from Roma, a client, to a customer. Roma claims she never sent the message. Which of the following features of PKI best guarantees the identity of the sender?
CRL
Trust model
Non-repudiation
Recovery agent
Mercury Technical Solutions has been using SSL in a business-to-business environment for a number of years. Despite the fact that there have been no compromises in security, the new IT manager wants to use stronger security than SSL can offer. Which of the following protocols is similar to SSL but offers the ability to use additional security protocols?
X.509
TLS
SSH
RSH
Juanita has implemented asymmetric key cryptography for the emails of her company. She is concerned that users may lose their private keys and will not be able to decrypt their messages. Which of the following is the best solution to this problem?
RA
CA
Key escrow
PKI
Due to a breach, a certificate must be permanently revoked, and you don't want it to ever be used again. What is often used to revoke a certificate?
CRA
PKI
CRL
CYA
You are responsible for network and information security at a metropolitan police station. The most important concern is that unauthorized parties are not able to access data. What is this concern called?
Availability
Encryption
Confidentiality
Integrity
Which of the following automatically downloads and displays advertisements in the Web browser without a user's permission?
Backdoor
Adware
Rootkit
Botnet
An attacker has placed an opaque layer over the Request A Catalog button on your web page. This layer tricks visitors into going to a form on a different website and giving their contact information to another party when their intention was to give it to you. What type of attack is this known as?
Man-in-the-middle (MITM)
XSRF
Zero-day
Clickjacking
Which of the following attacks allows an attacker to enter the malicious data into a Website?
Evil twin
Cross-site scripting
Smurf
Denial of service
An attack in which a hacker manipulates database code for retrieving information is a/an:
LDAP injection attack
IP spoofing attack
Birthday attack
SQL injection attack
What kind of virus could attach itself to the boot sector of your disk to avoid detection and report false information about file sizes?
Stealth
Worm
Polymorphic
Trojan
An attacker sends large ICMP packet to overflow the remote host's buffer. This describes which of the following attacks?
Ping of death
Replay
Watering hole
Directory traversal
When a hole is found in a web browser or other software, and attackers begin exploiting it before the developer can respond, what type of attack is it known as?
Xmas
Polymorphic
Zero-day
Malicious insider
Pass-the-hash attacks take advantage of a weak encryption routine associated with which protocols?
NetBEUI and NetBIOS
NTLM and LanMan
Telnet and TFTP
Chargen and DNS
Which of the following types of viruses is described in the statement given below?
"It covers itself with protective code that prevents disassemblers from examining critical elements of it."
Armored
Macro
Companion
Multipartite
Which type of virus attacks antivirus software and destroys virus definition database file?
Macro
Companion
Phage
Retrovirus
The new head of software engineering has demanded that all code be tested to identify the design flow and then modified, as needed, to clean up routines without changing the code's visible behavior. What is this process known as?
Uncluttering
Refactoring
Sanitizing
Straightening
Which of the following involves unauthorized commands coming from a trusted user to the website?
TT3
XSRF
ZDT
HSM
Ann, a network administrator, is worried about the threat of malware on the network. She wants every workstation to install software that will detect worms and Trojan horses. What type of software should she install?
Rootkit
Bot
Adware
Antivirus
Karl from Accounting is in a panic. He is convinced that he has identified malware on the servers—a type of man-in-the-middle attack in which a Trojan horse manipulates calls between the browser and yet still displays back the user's intended transaction. What type of attack could he have stumbled on?
Man-in-the-business
Man-in-the-browser
Man-in-the-castle
Man-in-the-code
Your web server crashes at exactly the point where it reaches 1 million total visits. You discover that the cause of the server crash is a malicious code. Which of the following best fits this description?
Polymorphic virus
Cluster virus
Logic bomb
Worm
Your system has just stopped responding to keyboard commands. You noticed that this occurred when a spreadsheet was open and you connected to the internet. Which kind of attack has probably occurred?
Logic bomb
ACK attack
Virus
Worm
Your system is infected with a virus that can modify signature each time it is executed to fool antivirus software. Which type of virus is this?
Polymorphic
Retrovirus
Stealth
Multipartite
