WorksheetsCompTIA Security+ Certification Exam SY0-701 Practice Test 1
Total questions: 25
Worksheet time: 25mins
Which of the following answers can be used to describe technical security controls? (Select 3 answers)
Focused on protecting material assets
Implemented with technology
Executed by computer systems (instead of people)
Also known as administrative controls
Sometimes called logical security controls
Which of the answers listed below refer to examples of technical security controls? (Select 3 answers)
Encryption
Security audits
IDSs
Organizational security policy
Firewalls
Which of the following answers refer to the characteristic features of managerial security controls? (Select 3 answers)
Also known as administrative controls
Focused on reducing the risk of security incidents
Executed by computer systems (instead of people)
Documented in written policies
Sometimes referred to as logical security controls
Examples of managerial security controls include: (Select 3 answers)
Configuration management
Data backups
Organizational security policy
Risk assessments
Security awareness training
Which of the answers listed below can be used to describe operational security controls (Select 3 answers)
Executed by computer systems (instead of people)
Also known as administrative controls
Primarily implemented and executed by people (as opposed to computer systems)
Used to ensure that the equipment continues to work as specified
Focused on the day-to-day procedures of an organization
Which of the following examples fall into the category of operational security controls? (Select 3 answers)
Risk assessments
Configuration management
System backups
Authentication protocols
Patch management
Which of the answers listed below refers to security controls designed to deter, detect, and prevent unauthorized access, theft, damage, or destruction of material assets?
Managerial security controls
Physical security controls
Technical security controls
Operational security controls
Which of the following examples do not fall into the category of physical security controls? (Select 3 answers)
Access control vestibules
Asset management
Firewalls
Lighting
Data backups
What are the examples of preventive security controls? (Select 3 answers)
Encryption
IDS
Sensors
Firewalls
Warning signs
Examples of deterrent security controls include: (Select 3 answers)
Warning signs
Fencing/Bollards
Lighting
Sensors
Video surveillance
Which of the answers listed below refer(s) to detective security control(s)? (Select all that apply)
Vulnerability scanning
IDS
CCTV
Lighting
Log monitoring
Which of the following answers refer(s) to corrective security control(s)? (Select all that apply)
Recovering data from backup copies
Applying software updates and patches to fix vulnerabilities
Developing and implementing IRPs to respond to and recover from security incidents
Regularly reviewing logs for anomalies or patterns indicative of attacks
Activating and executing DRPs to restore operations after a major incident
Which of the answers listed below refer(s) to compensating security control(s)? (Select all that apply)
Backup power systems
Video surveillance
MFA
Application sandboxing
Network segmentation
The term "Directive security controls" refers to the category of security controls that are implemented through policies and procedures.
True
False
Which of the following terms fall into the category of directive security controls? (Select 2 answers)
IRP
AUP
IDS
MFA
IPS
Which of the terms listed below can be used to describe the basic principles of information security?
PKI
AAA
GDPR
CIA
The term "Non-repudiation" describes the inability to deny responsibility for performing a specific action. In the context of data security, non-repudiation ensures data confidentiality, provides proof of data integrity, and proof of data origin.
True
False
Which of the following best applies to the concept of non-repudiation?
Digital certificate
MFA
Hashing
Encryption
Which type of user account violates the concept of non-repudiation?
Standard user account
Shared account
Guest user account
Service account
Which part of the AAA security architecture deals with the verification of the identity of a person or process?
Authentication
Authorization
Accounting
In the AAA security architecture, the process of granting or denying access to resources is known as:
Authentication
Authorization
Accounting
In the AAA security architecture, the process of tracking accessed services as well as the amount of consumed resources is called:
Authentication
Authorization
Accounting
Which of the following solutions provide(s) the AAA functionality? (Select all that apply)
CHAP
TACACS+
PAP
RADIUS
MS-CHAP
In the context of the AAA framework, common methods for authenticating people include: (Select 3 answers)
IP addresses
Usernames and passwords
MAC addresses
Biometrics
MFA
Which of the answers listed below refer to common methods of device authentication used within the AAA framework? (Select 3 answers)
MFA
Usernames and passwords
MAC addresses
IP addresses
Digital certificates
