WorksheetsSecurity + Exam Questions
Total questions: 98
Worksheet time: 49mins
You have recently been hired as a network administrator. The CIO informs you that their wireless networks are protected using firewalls. He has asked that you implement MAC filtering on all access points. What is the purpose of using this technology?
to provide port authentication for a wireless network
to restrict the clients that can access a wireless network
to ensure that unused ports are not accessible by clients
to restrict the clients that can access a Web site
When considering automation in security operations, which term refers to the long-term risks of choosing an expedient but limited solution instead of investing time and funds in a more comprehensive one?
Complexity
Cost
Ongoing supportability
Technical debt
Audits are regarded as a tool for current-state risk assessments mainly because:
They identify IT and business risk scenarios and establish suitable risk responses for each.
They perform rigorous testing of current controls in place and rely strongly on evidence provided by process owners.
They provide recommendations for process improvements.
They include listings of controls and the respective control owners.
Your organization has recently undergone a hacker attack. You have been tasked with preserving the data evidence. You must follow the appropriate eDiscovery process. You are currently engaged in the Preservation and Collection process. Which of the following guidelines should you follow?(Choose 3)
The data acquisition should be from a live system to include volatile data when possible.
The data acquisition should include both bit-stream imaging and logical backups.
The chain of custody should be preserved from the data acquisition phase to the presentation phase.
Hashing of acquired data should occur only when the data is acquired and when the data is modified.
You are incorporating a perimeter network into a network redesign and are adding several new devices to enhance security. Which of these would NOT be best placed in the new perimeter network?
DDoS mitigation
VPN concentrators
Authentication servers
Proxies
When calculating risks by using the quantitative method, what is the result of multiplying the asset values by the exposure factor (EF)?
ARO(Annualized Rate of Occurrence)
SLE(Single Loss Expectancy)
Risk elimination
ALE(Annualized Loss Expectancy)
What is the purpose of quantitative risk analysis?
To generate an action plan for each identified risk
To generate a prioritized list of risks that might adversely affect the organization
To estimate the overall impact that a specific risk poses to the organization
To analyze a potential risk in such a way as to give it a numerical rating or value
What is the process of identifying IoT and other devices that are not part of the core infrastructure so that hackers cannot use them to compromise an organization's core network?
Security controls testing
Penetration testing and adversary emulation
Passive discovery
Edge cleansing
Which type of test relies heavily on automated scanning tools and reporting?
Known environment test
Unknown environment test
Vulnerability test
Penetration test
What is vishing?
an attack that looks for open ports
a special type of phishing that appears to come from a trusted individual
a special type of phishing that uses Voice over IP (VoIP)
a special type of phishing that targets a single power user
Which of the following are accomplished through identity validation?(Choose 2)
Gap analysis
Authorization models
Authorizing people
Authenticating systems
You are tasked with choosing a mail gateway for your organization. Which of the following is a consideration for this deployment?
DLP
Encryption
All of these options
Spam filter
The business continuity team is interviewing users to gather information about business units and their functions. Which part of the business continuity plan includes this analysis?
Business impact analysis
Disaster recovery plan
Occupant emergency plan
Contingency plan
Your company really needs to enhance email security to prevent spoofing. What should you implement?
Gateway filter
DKIM (DomainKeys Identified Mail)
SPF (Sender Policy Framework)
DMARC (Domain-based Message Authentication, Reporting, and Conformance)
DNS filtering (Domain Name System (DNS) filtering)
What is the primary goal of buffer overflow attacks?
Cross-site scripting
Arbitrary injection
SQL injection
Malicious update
Which of these options simulates a disaster and allows you to check the thoroughness of your disaster recovery plan?
Business continuity plans
Tabletop exercises
Critical business functions
After-action reports
Which of the following are key phases in implementing security awareness practices?
Execution
Anomalous behavior recognition
Phishing
Development
While performing a penetration test, you encounter several issues that you plan to document in the final report. However, you need to ensure that management is immediately notified of any IoCs documented in the communication escalation path. Which of the following is MOST likely to result in the need for immediate communication to management?
A finding was discovered regarding an out-of-scope system.
Encrypted personally identifiable information (PII) was discovered on several systems.
A network compromise has previously occurred about which management knows nothing.
Unpatched applications exist on a system marked for retirement.
Recently, while reviewing log data, you discover that a hacker has used a design flaw in an application to obtain unauthorized access to the application. Which type of attack has occurred?
maintenance hook
backdoor
buffer overflow
privilege escalation
Which of the following activities is associated with tracking the lifecycle of technology assets within the organization?
Assignment/accounting
Information asset tracking
Disposal/decommissioning
Acquisition/procurement process
Which of the following network architecture concepts consists of a policy engine, a policy administrator, and a policy enforcement point?
Cloud
Hybrid
Secure Access Service Edge
Zero Trust
Company management has discovered that systems administrators have made critical changes to operational policies and procedures without management’s consent or knowledge. To keep this from happening again, which change management component should be implemented?
Ownership
Test results
Stakeholders
Approval process
Your organization needs to implement a system that logs changes to files. What category of solution should you research?
Host-based firewall
Antivirus
File integrity checks
HIDS/HIPS (Host-based Intrusion Detection Systems, Host-based Intrusion prevention systems)
Which two options are threat vectors used against vulnerable software?
Untrusted
Unsupported systems and applications
Signatures
Default credentials
A large corporation wants to implement a solution to block access to malicious websites and prevent employees from accessing inappropriate content while browsing the internet. Which capability of agent-based web filters would be most appropriate?
Centralized proxy
Block rules
Content categorization
Universal Resource Locator (URL) scanning
Recently there was a DoS attack on one of the servers, which succeeded in taking the server down for three hours. You would like to deploy a solution that would allow you to detect a huge rush of traffic to a specific device and route it somewhere away from the device. What technique could you use?
Network segmentation
System isolation
Sinkholing
Endpoint security
Which vendor selection concern consists of thoroughly researching and investigating potential vendors to ensure they meet the security and compliance requirements you have established?
Regulatory compliance
Service-level agreements
Due diligence
Conflict of interest
Which of the following types of guidance and training focuses on educating users about recognizing and responding to potential security threats in their environment?
Situational awareness
Insider threat
Password management
Policy/handbooks
Which component of effective security compliance involves regularly assessing and verifying adherence to security policies and regulations to identify and address gaps or deficiencies?
Compliance reporting
Compliance monitoring
Privacy
Consequences of non-compliance
You need to incorporate SAML and SSO into a web application. Which of the following would you use?
Shibboleth
id_token
OAuth
OpenID Connect
As your organization's security administrator, you are reviewing the audit results to assess if your organization's security baselines are maintained. In which phase of the security management life cycle are you engaged?
Implement
Operate and Maintain
Monitor and Evaluate
Plan and Organize
Which message-based attack vector is the platform responsible for launching over 90% of all attacks?
SMS
Typo-squatting
IM
You have asked your assistant to configure a firewall with the following access control list (ACL). access list outbound deny ip 0.0.0.0 0.0.0.0/0 port 23 access list outbound permit ip 192.168.5.6/32 0.0.0.0/0 port 23 access list outbound permit ip 0.0.0.0 0.0.0.0/0 Which of the following statements is true about the firewall configuration?
All outbound traffic is denied
Only traffic from 192.168.5.6 to port 23 is permitted, all other port 23 traffic is denied
All outbound traffic except port 23 is permitted
All outbound traffic is permitted except port 23 from 192.168.5.6
What will be the effect of these commands?
No devices will be able to send outbound Telnet requests.
No devices will be able to send outbound DNS requests.
Only the device at 192.168.5.6 will be able to send outbound Telnet requests.
Only the device at 192.168.5.6 will be able to send outbound DNS requests.
Which process allows you to deploy, configure, and manage data centers through scripts?
Waterfall
Immutable systems
Agile
Baselining
IaC (Infrastructure as code)
Using the NetFlow/IPFIX protocol, which of the following fields define a unique network flow?(Choose 2)
Source/Destination Ports
Source/Destination Encodings
Source/Destination MAC Addresses
Source/Destination IP Addresses
An accounting job role requires separation of duties to reduce the risk of fraud, with tasks spread across two employees. Due to a staffing shortage, you only have one person available to perform all of the tasks. You ask your business’s bank to start sending you weekly statements instead of monthly, and to create an automated email that will alert you if a withdrawal above a certain threshold is made. Which type or category of control did you implement? Choose the BEST answer.
Operational category
Managerial category
Compensating type
Preventative type
Deterrent type
Which of the following supply chain elements are threat vectors?(Choose all that apply)
Managed service provider
Third-party software dependencies
Hardware suppliers
Software suppliers
Which of the following would most likely be the primary motivation for attacks conducted by organized crime?
Disruption and chaos
Financial gain
Wartime agendas
Revenge
Which of the following is an independent third party which provides validation services to assure that a digital certificate is genuine?
OCSP (Online Certificate Status Protocol)
Certificate signing request
Root of trust
Certificate authority
Data may be subject to the laws and regulations of the nation in which it is collected, not necessarily where it is stored. Which principle is being described?
Legal hold
Incident response plan
Data sovereignty
Chain of custody
Which of the following would determine if safeguards that have been installed were properly implemented, performing as expected and producing the appropriate results?
Security controls testing
Bug bounty
Penetration testing and adversary emulation
Attack surface reduction
Which of the following is based on impersonating an executive in an organization, with the intent of convincing an employee to do something they shouldn’t?
Brand impersonation
Typo-squatting
Business email compromise
Misinformation
Which statement is FALSE with respect to access control lists (ACLs)?
Every rule is examined before a traffic decision is made.
The order of the rules is important.
There is an implicit deny all at the end of each rule set.
The first rule match is applied to traffic.
The rules in the list are examined from top to bottom. grok model
Your organization has decided to outsource its e-mail service. The company chosen for this purpose has provided a document that details the e-mail functions that will be provided for a specified period, along with guaranteed performance metrics. What is this document called?
SLA (service level agreement)
MOU (memorandum of understanding)
ISA (interconnection security agreement)
BPA (business partner agreement)
You need data to validate what you believe to be the issue in your network investigation. Which of the following data sources would be the most beneficial in analyzing network traffic and identification of security incidents?
OS-specific logs
Firewall logs
Endpoint logs
Application logs
Which role and associated responsibility involves managing and overseeing the use of systems and data, ensuring compliance with security policies and regulations?
Custodians and stewards
Owners
Processors
Controllers
You are building a public-access Wi-Fi system for a new hotel. You want to require the users to accept a fair use policy before connecting to the Internet. Which of the following should you implement?
802.1X
RADIUS federation
Captive portal
WPS
Recently, an attacker tricked a user into believing he was selecting a button to direct him to a legitimate web site, but that button actually took him to another site. Which type of attack occurred?
Clickjacking
Amplification
Pass the hash
Driver manipulation
Which stage of incident response includes actions aimed at preventing further spread or damage of a security incident within the organization's network environment?
Analysis
Containment
Preparation
Detection
You need to provide your company with a report regarding potential security-related software flaws. You need to use standardized names so that a security analyst contractor can understand the report. Which SCAP component should you use?
CVE (Common Vulnerabilities and Exposures)
CVSS (Common Vulnerability Scoring System)
CPE (Common Platform Enumeration)
CCE (Common Configuration Enumeration)
You want to implement additional protection for your e-commerce server by installing a specific type of firewall. This firewall will sit between the web server and clients and will be placed in a screened subnet or perimeter network. Its primary purpose will be to protect the e-commerce apps running on the server. Which type of firewall should you choose?
SD-WAN (software-defined wide area network)
Layer 4 firewall (Transport layer)
Layer 7 firewall (Application layer)
NGFW (next generation firewall)
Which of the following data protection concepts focuses on determining the physical location of a user or device prior to granting access to sensitive information?
Geolocation
Data masking
Data encryption
Digital signatures
Your company has deployed a firewall that includes two network interfaces. Which firewall architecture has been deployed?
screened subnet
bastion host
dual-homed firewall
screened host
Which term refers to the capability of automation and scripting to effectively streamline tasks and processes, allowing security teams to accomplish more with existing resources?
Reaction time
Scaling in a secure manner
Workforce multiplier
Employee retention
Your company underwent an attack that involved an attacker injecting a command to access the underlying file system. Which type of attack occurred?
DLP (data loss prevention)
privilege escalation
directory traversal
resource exhaustion
Your company-provided Android devices are all under the control of a mobile device management (MDM) console. You want to use this console to prevent users from rooting their devices. How does this support security?
On an unrooted device, the user cannot intentionally or unintentionally download malicious apps from unauthorized sources.
On an unrooted device, the user cannot allow apps to escape the isolated virtual sandbox they run in.
On an unrooted device, the user cannot remotely wipe their device.
On an unrooted device, the user cannot upgrade to a new, untested version of the Android operating system.
What is a physical barrier that acts as the first line of defense against an intruder?
a lock
a fence
an access control vestibule
a turnstile
a bollard
Smart devices and Internet of Things (IoT) are growing rapidly. Which of these include embedded systems that are security risks?
(Choose all that apply)
Medical devices
Printers
Home automation devices
Wearable technology
Provisioning requests for the IT department have been backlogged for months. You are concerned that employees are using unauthorized cloud services to deploy VMs and store company data. Which of the following services can be used to bring this shadow IT back under the corporate security policy?
CASB (cloud access security broker)
SWG (secure web gateway)
SLA (service level agreement)
VPN (virtual private network)
Which of the following security zones is sometimes known as a demilitarized zone (DMZ)?
SCADA (DMZ)
Intranet
Extranet
Screened subnet
You have discovered that data was injected into your database, thereby causing security issues. Which injection attack most likely occurred?
XML injection
SQL injection
command injection
LDAP injection
What are some disadvantages to using a cold site?(Choose all that apply)
administration time
expense
testing availability
recovery time
Which concepts are associated with the Zero Trust control plane?(Choose 2)
Threat scope reduction
Policy enforcement point
Adaptive identity
Implicit trust zones
You received a security bulletin stating that an accounting application widely used in your organization has a known vulnerability. The risk score for the vulnerability is low. What should you do?
Purchase insurance to protect your assets
Use compensating controls until a fix is found
Create an exemption for the application's users until a more secure application can be found
Check for patches
Segment the network to reduce the attack surface
Which of the following is not a cryptographic attack?
Downgrade
Spraying
Collision
Birthday
Which network architecture concept allows for dynamic reconfiguration of a network as a reaction to changes in volume, types of traffic, and security incidents?
Secure Access Service Edge
On-premises
Software-defined networking
Hybrid
Your company decides to implement a RAID-5 array on several file servers. Which feature is provided by this deployment?
Scalability
Distributed allocation
High availability
Elasticity
Which process allows you to deploy, configure, and manage data centers through scripts?
Waterfall
IaC (Infrastructure as code)
Immutable systems
Baselining
As a security professional, you have been asked to advise an organization on which access control model to use. You decide that role-based access control (RBAC) is the best option for the organization. What are two advantages of implementing this access control model?(Choose 2)
discretionary in nature
highly secure environment
low security cost
easier to implement
user friendly
Where is steganography typically used?
In executable file-based attacks
In an image-based attack
As a removable device exploitation
In voice calls
Which of the following mitigation techniques would include establishing, deploying, and then maintaining a standard configuration, such as an image?
Configuration enforcement
Installation of endpoint protection
Removal of unnecessary software
Decommissioning
Which of the following tools or activities is primarily used for automating security compliance checks and vulnerability assessments across an organization's IT infrastructure?
Configuration enforcement
Installation of endpoint protection
Removal of unnecessary software
Decommissioning
Which of the following is a protocol used for automating vulnerability management, measurement, and policy compliance evaluation?
Archiving
SCAP (Security Content Automation Protocol)
Benchmarks
Alert tuning
Which type of reporting and monitoring is typically conducted on a regular basis to detect and respond to security incidents as part of an organization's ongoing security operations?
Initial
Operational
Compliance
Recurring
Which governance structure provides the highest level of autonomy with regard to decision-making authority in a large organization?
Decentralized
Boards
Centralized
Committee
Government entities
Which of the following encryption tools is also known as a trusted execution environment (TEE)?
Secure enclave
TPM (Trusted Platform Model)
Key management system
HSM (hardware security module)
Which of the following network attacks has the goal of capturing a user's login information to use in a subsequent attack?
On-path
Credential replay
Reflected
Amplified
A user notifies you that a software application displays advertisements while the application is executing. Of which security threat is this an example?
Adware
Ransomware
Spyware
Rootkit
Which of the following is an example of adware?
worm
spyware
adware
virus
Which of the following security control types includes acceptable use policies, handbooks, and posted warning signs?
Detective controls
Compensating controls
Preventive controls
Directive controls
Your organization has asked the security team to add terrorist attacks to the organization's business continuity plan. Which type of threat does this most likely represent?
Supply system threat
Internal threat
Natural environmental threat
Politically motivated threat
Which of the following is most likely the primary motivation for a threat actor who wants to gain notoriety by claiming responsibility for an event?
War
Disruption and chaos
Service disruption
Revenge
You implement network segmentation, airgaps, multiple firewalls, and virtualization on your company's network. Of what are these examples?
None of the above
Defense-in-depth
Control diversity
Vendor diversity
Your organization has decided to outsource its e-mail service. The company chosen for this purpose has provided a document that details the e-mail functions that will be provided for a specified period, along with guaranteed performance metrics. What is this document called?
SLA (service level agreement)
MOU (memorandum of understanding)
BPA (business partner agreement)
ISA (interconnection security agreement)
In a security investigation, which of the following would provide you with the best data source for detailed information about network transmissions?
IPS/IDS logs
Dashboards
Application logs
Packet captures
Which type of internal audit focuses on evaluating the adherence to industry regulations, standards, and internal policies?
Self-assessments
Process improvement
Audit committee
Compliance
Which of the following encryption levels offers the most granular control?
Database
Volume
Partition
Record
A user supplies the proper credentials and logins in to a remote system from an offsite location in New York. Moments later, the same proper credentials are used to login from a different offsite location, this time from Tokyo. What type of Indicator of Compromise does this represent?
Concurrent session
Blocked content
Resource consumption
Impossible travel
Now that security requirements have been defined, the software development team is ready to start the security testing phase. They want to analyze the code without the code executing and plan to repeat this testing throughout the entire application development life cycle. What type of testing are they planning?
Static code analysis
Use interception proxy to crawl application
Web application vulnerability scanning
Fuzzing
Which of the following threat actor motivations is also known as a competition attack?
Ethical hacking
Revenge
Philosophical beliefs
Espionage
Your organization has decided to implement an encryption algorithm to protect data. One IT staff member suggests that the organization use IDEA (International Data Encryption Algorithm). Which strength encryption key is used in this encryption algorithm?
56-bit
256-bit
128-bit
64-bit
As part of your monthly report, you must classify specific vulnerabilities into a broad range of vulnerability types. Which type of vulnerability is demonstrated by an SQL injection?
Improper error handling
Misconfiguration/weak configuration
Improper input handling
Default configuration
Which external factor influences effective security governance by dictating rules and compliance standards by which organizations must abide?
Industry standards
Regulations
Laws
Local/Regional governance
Which of the following architecture models is characterized by a design where administrative control and decision-making are distributed among various autonomous entities?
Centralized architecture model
Decentralized architecture model
Client-server architecture model
Monolithic architecture model
Which policy outlines the procedures and protocols for managing and responding to a security breach?
Disaster recovery policy
Change management policy
Incident response policy
SDLC (Software Development Lifecycle)
Which of the following data sources would provide you with information about potential weaknesses and security flaws within a network or system?
Vulnerability scans
Network logs
IDS/IPS logs
Automated reports
Your company has recently started adopting formal security policies to comply with several state regulations. One of the security policies states that certain hardware is vital to the organization. As part of this security policy, you must ensure that you have the required number of components plus one extra to plug into any system in case of failure. Which strategy is this policy demonstrating?
server redundancy
clustering
cold site
fault tolerance
