wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Security + Exam Questions

Total questions: 98

Worksheet time: 49mins

Name
Class
Date
1.

You have recently been hired as a network administrator. The CIO informs you that their wireless networks are protected using firewalls. He has asked that you implement MAC filtering on all access points. What is the purpose of using this technology?

a)

to provide port authentication for a wireless network

b)

to restrict the clients that can access a wireless network

c)

to ensure that unused ports are not accessible by clients

d)

to restrict the clients that can access a Web site

2.

When considering automation in security operations, which term refers to the long-term risks of choosing an expedient but limited solution instead of investing time and funds in a more comprehensive one?

a)

Complexity

b)

Cost

c)

Ongoing supportability

d)

Technical debt

3.

Audits are regarded as a tool for current-state risk assessments mainly because:

a)

They identify IT and business risk scenarios and establish suitable risk responses for each.

b)

They perform rigorous testing of current controls in place and rely strongly on evidence provided by process owners.

c)

They provide recommendations for process improvements.

d)

They include listings of controls and the respective control owners.

4.

Your organization has recently undergone a hacker attack. You have been tasked with preserving the data evidence. You must follow the appropriate eDiscovery process. You are currently engaged in the Preservation and Collection process. Which of the following guidelines should you follow?(Choose 3)

a)

The data acquisition should be from a live system to include volatile data when possible.

b)

The data acquisition should include both bit-stream imaging and logical backups.

c)

The chain of custody should be preserved from the data acquisition phase to the presentation phase.

d)

Hashing of acquired data should occur only when the data is acquired and when the data is modified.

5.

You are incorporating a perimeter network into a network redesign and are adding several new devices to enhance security. Which of these would NOT be best placed in the new perimeter network?

a)

DDoS mitigation

b)

VPN concentrators

c)

Authentication servers

d)

Proxies

6.

When calculating risks by using the quantitative method, what is the result of multiplying the asset values by the exposure factor (EF)?

a)

ARO(Annualized Rate of Occurrence)

b)

SLE(Single Loss Expectancy)

c)

Risk elimination

d)

ALE(Annualized Loss Expectancy)

7.

What is the purpose of quantitative risk analysis?

a)

To generate an action plan for each identified risk

b)

To generate a prioritized list of risks that might adversely affect the organization

c)

To estimate the overall impact that a specific risk poses to the organization

d)

To analyze a potential risk in such a way as to give it a numerical rating or value

8.

What is the process of identifying IoT and other devices that are not part of the core infrastructure so that hackers cannot use them to compromise an organization's core network?

a)

Security controls testing

b)

Penetration testing and adversary emulation

c)

Passive discovery

d)

Edge cleansing

9.

Which type of test relies heavily on automated scanning tools and reporting?

a)

Known environment test

b)

Unknown environment test

c)

Vulnerability test

d)

Penetration test

10.

What is vishing?

a)

an attack that looks for open ports

b)

a special type of phishing that appears to come from a trusted individual

c)

a special type of phishing that uses Voice over IP (VoIP)

d)

a special type of phishing that targets a single power user

11.

Which of the following are accomplished through identity validation?(Choose 2)

a)

Gap analysis

b)

Authorization models

c)

Authorizing people

d)

Authenticating systems

12.

You are tasked with choosing a mail gateway for your organization. Which of the following is a consideration for this deployment?

a)

DLP

b)

Encryption

c)

All of these options

d)

Spam filter

13.

The business continuity team is interviewing users to gather information about business units and their functions. Which part of the business continuity plan includes this analysis?

a)

Business impact analysis

b)

Disaster recovery plan

c)

Occupant emergency plan

d)

Contingency plan

14.

Your company really needs to enhance email security to prevent spoofing. What should you implement?

a)

Gateway filter

b)

DKIM (DomainKeys Identified Mail)

c)

SPF (Sender Policy Framework)

d)

DMARC (Domain-based Message Authentication, Reporting, and Conformance)

e)

DNS filtering (Domain Name System (DNS) filtering)

15.

What is the primary goal of buffer overflow attacks?

a)

Cross-site scripting

b)

Arbitrary injection

c)

SQL injection

d)

Malicious update

16.

Which of these options simulates a disaster and allows you to check the thoroughness of your disaster recovery plan?

a)

Business continuity plans

b)

Tabletop exercises

c)

Critical business functions

d)

After-action reports

17.

Which of the following are key phases in implementing security awareness practices?

a)

Execution

b)

Anomalous behavior recognition

c)

Phishing

d)

Development

18.

While performing a penetration test, you encounter several issues that you plan to document in the final report. However, you need to ensure that management is immediately notified of any IoCs documented in the communication escalation path. Which of the following is MOST likely to result in the need for immediate communication to management?

a)

A finding was discovered regarding an out-of-scope system.

b)

Encrypted personally identifiable information (PII) was discovered on several systems.

c)

A network compromise has previously occurred about which management knows nothing.

d)

Unpatched applications exist on a system marked for retirement.

19.

Recently, while reviewing log data, you discover that a hacker has used a design flaw in an application to obtain unauthorized access to the application. Which type of attack has occurred?

a)

maintenance hook

b)

backdoor

c)

buffer overflow

d)

privilege escalation

20.

Which of the following activities is associated with tracking the lifecycle of technology assets within the organization?

a)

Assignment/accounting

b)

Information asset tracking

c)

Disposal/decommissioning

d)

Acquisition/procurement process

21.

Which of the following network architecture concepts consists of a policy engine, a policy administrator, and a policy enforcement point?

a)

Cloud

b)

Hybrid

c)

Secure Access Service Edge

d)

Zero Trust

22.

Company management has discovered that systems administrators have made critical changes to operational policies and procedures without management’s consent or knowledge. To keep this from happening again, which change management component should be implemented?

a)

Ownership

b)

Test results

c)

Stakeholders

d)

Approval process

23.

Your organization needs to implement a system that logs changes to files. What category of solution should you research?

a)

Host-based firewall

b)

Antivirus

c)

File integrity checks

d)

HIDS/HIPS (Host-based Intrusion Detection Systems, Host-based Intrusion prevention systems)

24.

Which two options are threat vectors used against vulnerable software?

a)

Untrusted

b)

Unsupported systems and applications

c)

Signatures

d)

Default credentials

25.

A large corporation wants to implement a solution to block access to malicious websites and prevent employees from accessing inappropriate content while browsing the internet. Which capability of agent-based web filters would be most appropriate?

a)

Centralized proxy

b)

Block rules

c)

Content categorization

d)

Universal Resource Locator (URL) scanning

26.

Recently there was a DoS attack on one of the servers, which succeeded in taking the server down for three hours. You would like to deploy a solution that would allow you to detect a huge rush of traffic to a specific device and route it somewhere away from the device. What technique could you use?

a)

Network segmentation

b)

System isolation

c)

Sinkholing

d)

Endpoint security

27.

Which vendor selection concern consists of thoroughly researching and investigating potential vendors to ensure they meet the security and compliance requirements you have established?

a)

Regulatory compliance

b)

Service-level agreements

c)

Due diligence

d)

Conflict of interest

28.

Which of the following types of guidance and training focuses on educating users about recognizing and responding to potential security threats in their environment?

a)

Situational awareness

b)

Insider threat

c)

Password management

d)

Policy/handbooks

29.

Which component of effective security compliance involves regularly assessing and verifying adherence to security policies and regulations to identify and address gaps or deficiencies?

a)

Compliance reporting

b)

Compliance monitoring

c)

Privacy

d)

Consequences of non-compliance

30.

You need to incorporate SAML and SSO into a web application. Which of the following would you use?

a)

Shibboleth

b)

id_token

c)

OAuth

d)

OpenID Connect

31.

As your organization's security administrator, you are reviewing the audit results to assess if your organization's security baselines are maintained. In which phase of the security management life cycle are you engaged?

a)

Implement

b)

Operate and Maintain

c)

Monitor and Evaluate

d)

Plan and Organize

32.

Which message-based attack vector is the platform responsible for launching over 90% of all attacks?

a)

SMS

b)

Email

c)

Typo-squatting

d)

IM

33.

You have asked your assistant to configure a firewall with the following access control list (ACL). access list outbound deny ip 0.0.0.0 0.0.0.0/0 port 23 access list outbound permit ip 192.168.5.6/32 0.0.0.0/0 port 23 access list outbound permit ip 0.0.0.0 0.0.0.0/0 Which of the following statements is true about the firewall configuration?

a)

All outbound traffic is denied

b)

Only traffic from 192.168.5.6 to port 23 is permitted, all other port 23 traffic is denied

c)

All outbound traffic except port 23 is permitted

d)

All outbound traffic is permitted except port 23 from 192.168.5.6

34.

What will be the effect of these commands?

a)

No devices will be able to send outbound Telnet requests.

b)

No devices will be able to send outbound DNS requests.

c)

Only the device at 192.168.5.6 will be able to send outbound Telnet requests.

d)

Only the device at 192.168.5.6 will be able to send outbound DNS requests.

35.

Which process allows you to deploy, configure, and manage data centers through scripts?

a)

Waterfall

b)

Immutable systems

c)

Agile

d)

Baselining

e)

IaC (Infrastructure as code)

36.

Using the NetFlow/IPFIX protocol, which of the following fields define a unique network flow?(Choose 2)

a)

Source/Destination Ports

b)

Source/Destination Encodings

c)

Source/Destination MAC Addresses

d)

Source/Destination IP Addresses

37.

An accounting job role requires separation of duties to reduce the risk of fraud, with tasks spread across two employees. Due to a staffing shortage, you only have one person available to perform all of the tasks. You ask your business’s bank to start sending you weekly statements instead of monthly, and to create an automated email that will alert you if a withdrawal above a certain threshold is made. Which type or category of control did you implement? Choose the BEST answer.

a)

Operational category

b)

Managerial category

c)

Compensating type

d)

Preventative type

e)

Deterrent type

38.

Which of the following supply chain elements are threat vectors?(Choose all that apply)

a)

Managed service provider

b)

Third-party software dependencies

c)

Hardware suppliers

d)

Software suppliers

39.

Which of the following would most likely be the primary motivation for attacks conducted by organized crime?

a)

Disruption and chaos

b)

Financial gain

c)

Wartime agendas

d)

Revenge

40.

Which of the following is an independent third party which provides validation services to assure that a digital certificate is genuine?

a)

OCSP (Online Certificate Status Protocol)

b)

Certificate signing request

c)

Root of trust

d)

Certificate authority

41.

Data may be subject to the laws and regulations of the nation in which it is collected, not necessarily where it is stored. Which principle is being described?

a)

Legal hold

b)

Incident response plan

c)

Data sovereignty

d)

Chain of custody

42.

Which of the following would determine if safeguards that have been installed were properly implemented, performing as expected and producing the appropriate results?

a)

Security controls testing

b)

Bug bounty

c)

Penetration testing and adversary emulation

d)

Attack surface reduction

43.

Which of the following is based on impersonating an executive in an organization, with the intent of convincing an employee to do something they shouldn’t?

a)

Brand impersonation

b)

Typo-squatting

c)

Business email compromise

d)

Misinformation

44.

Which statement is FALSE with respect to access control lists (ACLs)?

a)

Every rule is examined before a traffic decision is made.

b)

The order of the rules is important.

c)

There is an implicit deny all at the end of each rule set.

d)

The first rule match is applied to traffic.

e)

The rules in the list are examined from top to bottom. grok model

45.

Your organization has decided to outsource its e-mail service. The company chosen for this purpose has provided a document that details the e-mail functions that will be provided for a specified period, along with guaranteed performance metrics. What is this document called?

a)

SLA (service level agreement)

b)

MOU (memorandum of understanding)

c)

ISA (interconnection security agreement)

d)

BPA (business partner agreement)

46.

You need data to validate what you believe to be the issue in your network investigation. Which of the following data sources would be the most beneficial in analyzing network traffic and identification of security incidents?

a)

OS-specific logs

b)

Firewall logs

c)

Endpoint logs

d)

Application logs

47.

Which role and associated responsibility involves managing and overseeing the use of systems and data, ensuring compliance with security policies and regulations?

a)

Custodians and stewards

b)

Owners

c)

Processors

d)

Controllers

48.

You are building a public-access Wi-Fi system for a new hotel. You want to require the users to accept a fair use policy before connecting to the Internet. Which of the following should you implement?

a)

802.1X

b)

RADIUS federation

c)

Captive portal

d)

WPS

49.

Recently, an attacker tricked a user into believing he was selecting a button to direct him to a legitimate web site, but that button actually took him to another site. Which type of attack occurred?

a)

Clickjacking

b)

Amplification

c)

Pass the hash

d)

Driver manipulation

50.

Which stage of incident response includes actions aimed at preventing further spread or damage of a security incident within the organization's network environment?

a)

Analysis

b)

Containment

c)

Preparation

d)

Detection

51.

You need to provide your company with a report regarding potential security-related software flaws. You need to use standardized names so that a security analyst contractor can understand the report. Which SCAP component should you use?

a)

CVE (Common Vulnerabilities and Exposures)

b)

CVSS (Common Vulnerability Scoring System)

c)

CPE (Common Platform Enumeration)

d)

CCE (Common Configuration Enumeration)

52.

You want to implement additional protection for your e-commerce server by installing a specific type of firewall. This firewall will sit between the web server and clients and will be placed in a screened subnet or perimeter network. Its primary purpose will be to protect the e-commerce apps running on the server. Which type of firewall should you choose?

a)

SD-WAN (software-defined wide area network)

b)

Layer 4 firewall (Transport layer)

c)

Layer 7 firewall (Application layer)

d)

NGFW (next generation firewall)

53.

Which of the following data protection concepts focuses on determining the physical location of a user or device prior to granting access to sensitive information?

a)

Geolocation

b)

Data masking

c)

Data encryption

d)

Digital signatures

54.

Your company has deployed a firewall that includes two network interfaces. Which firewall architecture has been deployed?

a)

screened subnet

b)

bastion host

c)

dual-homed firewall

d)

screened host

55.

Which term refers to the capability of automation and scripting to effectively streamline tasks and processes, allowing security teams to accomplish more with existing resources?

a)

Reaction time

b)

Scaling in a secure manner

c)

Workforce multiplier

d)

Employee retention

56.

Your company underwent an attack that involved an attacker injecting a command to access the underlying file system. Which type of attack occurred?

a)

DLP (data loss prevention)

b)

privilege escalation

c)

directory traversal

d)

resource exhaustion

57.

Your company-provided Android devices are all under the control of a mobile device management (MDM) console. You want to use this console to prevent users from rooting their devices. How does this support security?

a)

On an unrooted device, the user cannot intentionally or unintentionally download malicious apps from unauthorized sources.

b)

On an unrooted device, the user cannot allow apps to escape the isolated virtual sandbox they run in.

c)

On an unrooted device, the user cannot remotely wipe their device.

d)

On an unrooted device, the user cannot upgrade to a new, untested version of the Android operating system.

58.

What is a physical barrier that acts as the first line of defense against an intruder?

a)

a lock

b)

a fence

c)

an access control vestibule

d)

a turnstile

e)

a bollard

59.

Smart devices and Internet of Things (IoT) are growing rapidly. Which of these include embedded systems that are security risks?
(Choose all that apply)

a)

Medical devices

b)

Printers

c)

Home automation devices

d)

Wearable technology

60.

Provisioning requests for the IT department have been backlogged for months. You are concerned that employees are using unauthorized cloud services to deploy VMs and store company data. Which of the following services can be used to bring this shadow IT back under the corporate security policy?

a)

CASB (cloud access security broker)

b)

SWG (secure web gateway)

c)

SLA (service level agreement)

d)

VPN (virtual private network)

61.

Which of the following security zones is sometimes known as a demilitarized zone (DMZ)?

a)

SCADA (DMZ)

b)

Intranet

c)

Extranet

d)

Screened subnet

62.

You have discovered that data was injected into your database, thereby causing security issues. Which injection attack most likely occurred?

a)

XML injection

b)

SQL injection

c)

command injection

d)

LDAP injection

63.

What are some disadvantages to using a cold site?(Choose all that apply)

a)

administration time

b)

expense

c)

testing availability

d)

recovery time

64.

Which concepts are associated with the Zero Trust control plane?(Choose 2)

a)

Threat scope reduction

b)

Policy enforcement point

c)

Adaptive identity

d)

Implicit trust zones

65.

You received a security bulletin stating that an accounting application widely used in your organization has a known vulnerability. The risk score for the vulnerability is low. What should you do?

a)

Purchase insurance to protect your assets

b)

Use compensating controls until a fix is found

c)

Create an exemption for the application's users until a more secure application can be found

d)

Check for patches

e)

Segment the network to reduce the attack surface

66.

Which of the following is not a cryptographic attack?

a)

Downgrade

b)

Spraying

c)

Collision

d)

Birthday

67.

Which network architecture concept allows for dynamic reconfiguration of a network as a reaction to changes in volume, types of traffic, and security incidents?

a)

Secure Access Service Edge

b)

On-premises

c)

Software-defined networking

d)

Hybrid

68.

Your company decides to implement a RAID-5 array on several file servers. Which feature is provided by this deployment?

a)

Scalability

b)

Distributed allocation

c)

High availability

d)

Elasticity

69.

Which process allows you to deploy, configure, and manage data centers through scripts?

a)

Waterfall

b)

IaC (Infrastructure as code)

c)

Immutable systems

d)

Baselining

70.

As a security professional, you have been asked to advise an organization on which access control model to use. You decide that role-based access control (RBAC) is the best option for the organization. What are two advantages of implementing this access control model?(Choose 2)

a)

discretionary in nature

b)

highly secure environment

c)

low security cost

d)

easier to implement

e)

user friendly

71.

Where is steganography typically used?

a)

In executable file-based attacks

b)

In an image-based attack

c)

As a removable device exploitation

d)

In voice calls

72.

Which of the following mitigation techniques would include establishing, deploying, and then maintaining a standard configuration, such as an image?

a)

Configuration enforcement

b)

Installation of endpoint protection

c)

Removal of unnecessary software

d)

Decommissioning

73.

Which of the following tools or activities is primarily used for automating security compliance checks and vulnerability assessments across an organization's IT infrastructure?

a)

Configuration enforcement

b)

Installation of endpoint protection

c)

Removal of unnecessary software

d)

Decommissioning

74.

Which of the following is a protocol used for automating vulnerability management, measurement, and policy compliance evaluation?

a)

Archiving

b)

SCAP (Security Content Automation Protocol)

c)

Benchmarks

d)

Alert tuning

75.

Which type of reporting and monitoring is typically conducted on a regular basis to detect and respond to security incidents as part of an organization's ongoing security operations?

a)

Initial

b)

Operational

c)

Compliance

d)

Recurring

76.

Which governance structure provides the highest level of autonomy with regard to decision-making authority in a large organization?

a)

Decentralized

b)

Boards

c)

Centralized

d)

Committee

e)

Government entities

77.

Which of the following encryption tools is also known as a trusted execution environment (TEE)?

a)

Secure enclave

b)

TPM (Trusted Platform Model)

c)

Key management system

d)

HSM (hardware security module)

78.

Which of the following network attacks has the goal of capturing a user's login information to use in a subsequent attack?

a)

On-path

b)

Credential replay

c)

Reflected

d)

Amplified

79.

A user notifies you that a software application displays advertisements while the application is executing. Of which security threat is this an example?

a)

Adware

b)

Ransomware

c)

Spyware

d)

Rootkit

80.

Which of the following is an example of adware?

a)

worm

b)

spyware

c)

adware

d)

virus

81.

Which of the following security control types includes acceptable use policies, handbooks, and posted warning signs?

a)

Detective controls

b)

Compensating controls

c)

Preventive controls

d)

Directive controls

82.

Your organization has asked the security team to add terrorist attacks to the organization's business continuity plan. Which type of threat does this most likely represent?

a)

Supply system threat

b)

Internal threat

c)

Natural environmental threat

d)

Politically motivated threat

83.

Which of the following is most likely the primary motivation for a threat actor who wants to gain notoriety by claiming responsibility for an event?

a)

War

b)

Disruption and chaos

c)

Service disruption

d)

Revenge

84.

You implement network segmentation, airgaps, multiple firewalls, and virtualization on your company's network. Of what are these examples?

a)

None of the above

b)

Defense-in-depth

c)

Control diversity

d)

Vendor diversity

85.

Your organization has decided to outsource its e-mail service. The company chosen for this purpose has provided a document that details the e-mail functions that will be provided for a specified period, along with guaranteed performance metrics. What is this document called?

a)

SLA (service level agreement)

b)

MOU (memorandum of understanding)

c)

BPA (business partner agreement)

d)

ISA (interconnection security agreement)

86.

In a security investigation, which of the following would provide you with the best data source for detailed information about network transmissions?

a)

IPS/IDS logs

b)

Dashboards

c)

Application logs

d)

Packet captures

87.

Which type of internal audit focuses on evaluating the adherence to industry regulations, standards, and internal policies?

a)

Self-assessments

b)

Process improvement

c)

Audit committee

d)

Compliance

88.

Which of the following encryption levels offers the most granular control?

a)

Database

b)

Volume

c)

Partition

d)

Record

89.

A user supplies the proper credentials and logins in to a remote system from an offsite location in New York. Moments later, the same proper credentials are used to login from a different offsite location, this time from Tokyo. What type of Indicator of Compromise does this represent?

a)

Concurrent session

b)

Blocked content

c)

Resource consumption

d)

Impossible travel

90.

Now that security requirements have been defined, the software development team is ready to start the security testing phase. They want to analyze the code without the code executing and plan to repeat this testing throughout the entire application development life cycle. What type of testing are they planning?

a)

Static code analysis

b)

Use interception proxy to crawl application

c)

Web application vulnerability scanning

d)

Fuzzing

91.

Which of the following threat actor motivations is also known as a competition attack?

a)

Ethical hacking

b)

Revenge

c)

Philosophical beliefs

d)

Espionage

92.

Your organization has decided to implement an encryption algorithm to protect data. One IT staff member suggests that the organization use IDEA (International Data Encryption Algorithm). Which strength encryption key is used in this encryption algorithm?

a)

56-bit

b)

256-bit

c)

128-bit

d)

64-bit

93.

As part of your monthly report, you must classify specific vulnerabilities into a broad range of vulnerability types. Which type of vulnerability is demonstrated by an SQL injection?

a)

Improper error handling

b)

Misconfiguration/weak configuration

c)

Improper input handling

d)

Default configuration

94.

Which external factor influences effective security governance by dictating rules and compliance standards by which organizations must abide?

a)

Industry standards

b)

Regulations

c)

Laws

d)

Local/Regional governance

95.

Which of the following architecture models is characterized by a design where administrative control and decision-making are distributed among various autonomous entities?

a)

Centralized architecture model

b)

Decentralized architecture model

c)

Client-server architecture model

d)

Monolithic architecture model

96.

Which policy outlines the procedures and protocols for managing and responding to a security breach?

a)

Disaster recovery policy

b)

Change management policy

c)

Incident response policy

d)

SDLC (Software Development Lifecycle)

97.

Which of the following data sources would provide you with information about potential weaknesses and security flaws within a network or system?

a)

Vulnerability scans

b)

Network logs

c)

IDS/IPS logs

d)

Automated reports

98.

Your company has recently started adopting formal security policies to comply with several state regulations. One of the security policies states that certain hardware is vital to the organization. As part of this security policy, you must ensure that you have the required number of components plus one extra to plug into any system in case of failure. Which strategy is this policy demonstrating?

a)

server redundancy

b)

clustering

c)

cold site

d)

fault tolerance