Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

CompTIA Security Plus

Total questions: 32

Worksheet time: 16mins

Name
Class
Date
1.

Which of the following would be the most secure way to deploy a legacy application that requires a legacy operating system?

a)

Stress testing

b)

Sandboxing

c)

Placing it on an encrypted drive

d)

Dynamic testing

2.

Which of the following statements are true of input validation?

a)

Requires a login with normal characters as input during testing

b)

Helps to overcome buffer overflow and DoS attack

c)

Includes sending any unexpected or maliciously crafted input to a system

d)

Ensures that different types of input are handled gracefully by an application

3.

Which of the following is more secure and checks the submitted data to ensure its validity?

a)

Browser-side validation

b)

Server-side validation

c)

Client-side validation

d)

Database-side validation

4.

While inspecting your web application, you found that it is vulnerable to a SQL injection attack. Which of the following steps should you immediately take?

a)

Put the web server on DMZ

b)

Add input validation to forms

c)

Install a host-based firewall on the web server

d)

Apply security patch for the operating system on the web server

5.

Which of the following fully implements 802.11i security requirements?

a)

WPA

b)

WPA2

c)

WEP

d)

WPS

6.

What is the process of applying manual changes to a program called?

a)

Patching

b)

Replacement

c)

Hotfix

d)

Service pack

7.

Brena, a security analyst, notices that external users are constantly reporting that a web application is slow and frequently times out when attempting to submit information. Which of the following software development best practices will she implement to prevent the issue?

a)

Input validation

b)

Fuzzing

c)

Stress testing

d)

Regression testing

8.

Gertrude is managing a new software project. The project has very clearly defined requirements that are not likely to change. Which of the following is the most appropriate development model for her?

a)

Scrum

b)

Agile

c)

XP programming

d)

Waterfall

9.

Mary is responsible for website security in her company. She wants to address widely known and documented web application vulnerabilities. Which resource would be most helpful?

a)

OWASP

b)

ISO

c)

NIST

d)

CERT

10.

Which programming model will be appropriate for the situations wherein the requirements are clearly defined well in advance?

a)

Prototyping

b)

Waterfall

c)

Scrum

d)

Agile

11.

An encoded message is sent using public key infrastructure from Roma, a client, to a customer. Roma claims she never sent the message. Which of the following features of PKI best guarantees the identity of the sender?

a)

CRL

b)

Trust model

c)

Non-repudiation

d)

Recovery agent

12.

Mercury Technical Solutions has been using SSL in a business-to-business environment for a number of years. Despite the fact that there have been no compromises in security, the new IT manager wants to use stronger security than SSL can offer. Which of the following protocols is similar to SSL but offers the ability to use additional security protocols?

a)

X.509

b)

TLS

c)

SSH

d)

RSH

13.

Juanita has implemented asymmetric key cryptography for the emails of her company. She is concerned that users may lose their private keys and will not be able to decrypt their messages. Which of the following is the best solution to this problem?

a)

RA

b)

CA

c)

Key escrow

d)

PKI

14.

Due to a breach, a certificate must be permanently revoked, and you don't want it to ever be used again. What is often used to revoke a certificate?

a)

CRA

b)

PKI

c)

CRL

d)

CYA

15.

You are responsible for network and information security at a metropolitan police station. The most important concern is that unauthorized parties are not able to access data. What is this concern called?

a)

Availability

b)

Encryption

c)

Confidentiality

d)

Integrity

16.

Which of the following automatically downloads and displays advertisements in the Web browser without a user's permission?

a)

Backdoor

b)

Adware

c)

Rootkit

d)

Botnet

17.

An attacker has placed an opaque layer over the Request A Catalog button on your web page. This layer tricks visitors into going to a form on a different website and giving their contact information to another party when their intention was to give it to you. What type of attack is this known as?

a)

Man-in-the-middle (MITM)

b)

XSRF

c)

Zero-day

d)

Clickjacking

18.

Which of the following attacks allows an attacker to enter the malicious data into a Website?

a)

Evil twin

b)

Cross-site scripting

c)

Smurf

d)

Denial of service

19.

An attack in which a hacker manipulates database code for retrieving information is a/an:

a)

LDAP injection attack

b)

IP spoofing attack

c)

Birthday attack

d)

SQL injection attack

20.

What kind of virus could attach itself to the boot sector of your disk to avoid detection and report false information about file sizes?

a)

Stealth

b)

Worm

c)

Polymorphic

d)

Trojan

21.

An attacker sends large ICMP packet to overflow the remote host's buffer. This describes which of the following attacks?

a)

Ping of death

b)

Replay

c)

Watering hole

d)

Directory traversal

22.

When a hole is found in a web browser or other software, and attackers begin exploiting it before the developer can respond, what type of attack is it known as?

a)

Xmas

b)

Polymorphic

c)

Zero-day

d)

Malicious insider

23.

Pass-the-hash attacks take advantage of a weak encryption routine associated with which protocols?

a)

NetBEUI and NetBIOS

b)

NTLM and LanMan

c)

Telnet and TFTP

d)

Chargen and DNS

24.

Which of the following types of viruses is described in the statement given below?


"It covers itself with protective code that prevents disassemblers from examining critical elements of it."

a)

Armored

b)

Macro

c)

Companion

d)

Multipartite

25.

Which type of virus attacks antivirus software and destroys virus definition database file?

a)

Macro

b)

Companion

c)

Phage

d)

Retrovirus

26.

The new head of software engineering has demanded that all code be tested to identify the design flow and then modified, as needed, to clean up routines without changing the code's visible behavior. What is this process known as?

a)

Uncluttering

b)

Refactoring

c)

Sanitizing

d)

Straightening

27.

Which of the following involves unauthorized commands coming from a trusted user to the website?

a)

TT3

b)

XSRF

c)

ZDT

d)

HSM

28.

Ann, a network administrator, is worried about the threat of malware on the network. She wants every workstation to install software that will detect worms and Trojan horses. What type of software should she install?

a)

Rootkit

b)

Bot

c)

Adware

d)

Antivirus

29.

Karl from Accounting is in a panic. He is convinced that he has identified malware on the servers—a type of man-in-the-middle attack in which a Trojan horse manipulates calls between the browser and yet still displays back the user's intended transaction. What type of attack could he have stumbled on?

a)

Man-in-the-business

b)

Man-in-the-browser

c)

Man-in-the-castle

d)

Man-in-the-code

30.

Your web server crashes at exactly the point where it reaches 1 million total visits. You discover that the cause of the server crash is a malicious code. Which of the following best fits this description?

a)

Polymorphic virus

b)

Cluster virus

c)

Logic bomb

d)

Worm

31.

Your system has just stopped responding to keyboard commands. You noticed that this occurred when a spreadsheet was open and you connected to the internet. Which kind of attack has probably occurred?

a)

Logic bomb

b)

ACK attack

c)

Virus

d)

Worm

32.

Your system is infected with a virus that can modify signature each time it is executed to fool antivirus software. Which type of virus is this?

a)

Polymorphic

b)

Retrovirus

c)

Stealth

d)

Multipartite