Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

ICS Domain 2 Review

Total questions: 20

Worksheet time: 11mins

Name
Class
Date
1.

Sample IDS log entry: "Device with MAC address XX:XX:XX:XX:XX:XX attempted to access the guest wireless network. Access was denied based on MAC address filtering policy."

a)

MAC addresses remain the same, but IP addresses change

b)

IDS can detect host MAC address quicker than the IP address

c)

MAC addresses can not be spoofed, but IP addresses are susceptible to spoofing

d)

MAC addresses are easier to secure because they don't send data across networks

2.

Which of the following is not true about IP addresses?

a)

Any IP address starting with 10 is private

b)

Trusted networks contain all non-routable IP addresses

c)

Any IP address starting with 192 is private

d)

Most trusted networks use private IP addresses

3.

Which of the following is not typically located in a company's DMZ?

a)

Email server

b)

Directory services

c)

Proxy server

d)

Web server

4.

This security technology is used to watch for potential threats, and log suspicious activities.

a)

IDS

b)

IPS

c)

NAT

d)

Proxy server

5.

Which of the following do switches and wireless access points use to control access through a device?

a)

IP address filtering

b)

Port number filtering

c)

MAC address filtering

d)

Session filtering

6.

What type of address is this?

2001:0db8:0000:abcd:0000:0000:0000:7334

a)

IPv6

b)

IPv4

7.

I sit between the internet and the network. I protect the network, by blocking viruses, malware and worms. I can be both hardware and software

a)

Router

b)

Firewall

c)

Ethernet Cable

d)

Modem

8.

Provide an IDS log sample based on the given questions.

a)

It encrypts network traffic

b)

It monitors network traffic for suspicious activity

c)

It blocks all incoming traffic

d)

It manages user access rights

9.

What is the MOST common form of host-based IDS that employs signature or pattern-matching detection methods?

a)

Anti-Virus

software

b)

Motion Detectors

c)

Firewall

d)

Honeypots

10.

This type of attack overwhelms a server by sending more GET requests than the server can handle.

(a)  

11.

IDS Log: Detected ARP spoofing attempt. An attacker is sending frames with the attacker's MAC address associated with the IP address of a legitimate host. What type of attack is this?

(a)  

12.

In this IDS log sample, the attacker overwhelms the server with TCP SYN request to prevent the server from responding to client requests.

a)

ARP spoofing

b)

IP spoofing

c)

HTTP flooding

d)

SYN flooding

13.

What device produces this type of log entry?

2023-10-05T14:48:00Z ALERT: Potential HTTP Flood Detected Source IP: 192.168.1.100 Destination IP: 192.168.1.1 R

a)

Firewall

b)

IDS

c)

IPS

d)

Proxy server

14.

Which device should CITA use to enforce corporate policies on BYOD devices connecting to the network?

a)

VPN

b)

QoS

c)

NAC

d)

IPS

15.

Which type of server performs authentication for 802.1x network access?

a)

LDAP

b)

RADIUS

c)

SNMP

d)

TACACTS+

16.

Which cloud service is used for file storage and backups: SaaS, IaaS, or PaaS?

(a)  

17.

What type of device/service enhances security by hiding their corporate IP address and by acting as a go-between for internal users and the internet?

a)

IDS

b)

proxy server

c)

RADIUS

d)

VPN

18.

A syslog vulnerability is where entries can be tampered with, which questions data integrity.

a)

True

b)

False

19.

Data is encrypted in SNMPv1 and SNMPv2.

a)


True

b)

False

20.

Which remote desktop tool completely takes over a device so the device's activity cannot be seen?

a)

Remote Assistance

b)

Remote Desktop

c)

TeamViewer

d)

VNC