WorksheetsExam CNSA
Total questions: 35
Worksheet time: 18mins
Which is the most important reason for the removal of unused, unnecessary, or unneeded protocols, services, and applications?
Increased security
Increased performance
Less need for administration
Less machine resource use
Why is network security important for organizations?
It increases network speed
It protects sensitive information
It reduces electricity usage
It simplifies network configurations
Which of the following best describes 'encryption'?
Speeding up data transmission
Compressing data for storage
Creating user-friendly software
Converting data into a secure code
The act of attempting to appear to be someone you're not in order to gain access to a system is known as which of the following?
Spoofing
DDoS
Replay
Sniffing
Which term refers to the protection of networked systems from misuse or unauthorized access?
Network Optimization
Network Monitoring
Network Security
Network Analysis
Which of the following is an example of a social engineering attack?
Firewall breach
Phishing
SQL Injection
Man-in-the-Middle attack
Which of the following is considered an attack vector?
USB drive
Monitor
Keyboard
Printer
Which of the following is most likely to make systems vulnerable to MITM attacks?
Weak passwords
Weak TCP sequence numbers
Authentication misconfiguration on routers
Use of the wrong operating systems
Which of the following is the best way to protect your organization from revealing sensitive information through dumpster diving?
Establish a policy requiring employees to change passwords every 30 to 60 days
Add a new firewall to the network
Teach employees the value of not disclosing restricted information over the telephone to unknown parties
Shred all sensitive documentation
What type of threat involves exploiting software flaws to gain unauthorized access?
Phishing
Malware
Vulnerability Exploit
Social Engineering
Which encryption type uses the same key for both encryption and decryption?
Symmetric encryption
Asymmetric encryption
Hash functions
Digital signatures
Which of the following is a best practice for network security procedures?
Using outdated software
Regularly updating and patching systems
Ignoring security alerts
Sharing passwords
What is the main principle of cryptography?
To speed up data transmission
To secure information through encoding
To compress data for storage
To enhance user interfaces
Which of the following is an essential component of security procedures?
Regular system backups
Increasing network speed
Reducing software costs
Enhancing user interfaces
What is the primary purpose of developing security policies?
To increase network speed
To enhance network graphics
To establish rules and guidelines for network security
To reduce software costs
PDAs, cell phones, and certain network cards have the ability to use _____________ networks. Choose the BEST answer.
Wired
Private
Wireless
Antique
The PKI identification process is based upon the use of unique identifiers, known as _____
Licences
Fingerprints
Keys
Locks
Your supervisor has charged you with determining which 802.11 authentication method to use when deploying the new wireless network. Given your knowledge of the 802.11 specification, which of the following is the most secure 802.11 authentication method?
Shared-key
EAP-TLS
EAP-MD5
Open
What are the two WEP key sizes available in 802.11 networks?
64-bit and 128-bit
40-bit and 104-bit
24-bit and 64-bit
24-bit and 104-bit
Which of the following is a weakness in WEP related to the IV?
The IV is a static value, which makes it relatively easy for an attacker to brute force the WEP key from captured traffic
The IV is transmitted in plaintext and can be easily seen in captured traffic.
There is no weakness in WEP related to the IV.
The IV is only 24 bits in size, which makes it possible that two or more data frames will be transmitted with the same IV, thereby resulting in an IV collision that an attacker can use to determine information about the network.
When you use Java, the JVM isolates the Java applet to a sandbox when it executes. What does this do to provide additional security?
This prevents the Java applet from accessing data on the client's hard drive
This prevents the Java applet from failing in such a way that the Java applet is unable to execute.
This prevents the Java applet from communicating to servers other than the one from which it was downloaded.
This prevents the Java applet from failing in such a way that it affects another application
To allow its employees remote access to the corporate network, a company has implemented a hardware VPN solution. Why is this considered a secure remote access solution?
Because only the company's employees will know the address to connect to in order to use the VPN.
Because VPNs use the Internet to transfer data.
Because a VPN uses encryption to make its data secure
Because a VPN uses compression to make its data secure.
What types of computers might you expect to find located on an intranet?
Publicly accessible DNS servers and Public Web servers
SQL 2000 servers and User workstations
Public Web servers and SQL 2000 servers
User workstations and Publicly accessible DNS servers
Which of the following protocols can be used to secure a VPN connection?
DNS
MPPE
Apple Talk
TCP/IP
Josh has asked for a clarification of what a firmware update is. How could you briefly describe for him the purpose of firmware updates?
Firmware updates are control software- or BIOS-type updates that are installed to improve the functionality or extend the life of the device involved.
Firmware updates are device-specific command sets that must be upgraded to continue operation.
Firmware updates update the mechanical function of the device.
Firmware updates are minor fixes, and are not usually necessary
Your FTP server was just compromised. When you examine the settings, you find that the server allows Anonymous access. However, you know that this is a default condition in most FTP servers, and must dig further for the problem. Where else might you check?
All of them are correct
ACL settings for server access
Effective permissions for the anonymous access
Access permissions on server's file structure
You have downloaded a CD ISO image and want to verify its integrity. What should you do?
Compare the file sizes
Burn the image and see if it works
Create an MD4 sum and compare it to the MD4 sum listed where the image was downloaded.
Create an MD5 sum and compare it to the MD5 sum listed where the image was downloaded
Which of the following algorithms are available for commercial use without a licensing fee?
RSA, DES, and IDEA
DES, IDEA, and AES
RSA, DES, and AES
IDEA, AES, and RSA
Public Key Cryptography is a system that uses a mix of symmetric and ___________ algorithms for the encryption of a secret key.
Public
Asymmetric
Private
Certificate
When a company uses ____________, it is keeping copies of the private key in two separate secured locations where only authorized persons are allowed to access them.
Key destruction
Key escrow
Key generetion
Key rings
You are the first person to arrive at a crime scene. An investigator and crime scene technician arrive afterwards to take over the investigation. Which of the following tasks will the crime scene technician be responsible for performing?
Tag, bag, and inventory evidence.
Establish a chain of command
Reestablish a perimeter as new evidence presents itself
Ensure that any documentation and evidence they possessed is handed over to the investigator.
You are manager of the IT department and have designed a new security policy that addresses the IT staff's responsibilities to users, equipment, and data. The policy only affects the IT staff. It deals with such issues as routine backups of data, network security changes, and audits of data on servers. Now that the new policy is written, which of the following should you do next?
Publish the policy and make it available for all users to read.
Obtain authorization from other members of the IT staff.
Obtain authorization from senior management.
Provide a copy of the policy to legal counsel, and have them review its content and wording.
You have been asked to develop an audit plan for your company. You have been told that there have been constant deletions of files that are being worked on by a team, and that they have had to redo the work a number of times. What type of auditing would you implement to track the access to this resource?
Logon/logoff success
Object/file access success
Object/file access failure
Logon/logoff failure
You want to implement access control that will allow users to control who has access to the data they have ownership over. Which of the following would you use?
MAC
DAC
RBAC
BAC
Sally has come to you for advice and guidance. She is trying to configure a network device to block attempts to connect on certain ports, but when she finishes the configuration, it works for a period of time but then changes back to the original configuration. She cannot understand why the settings continue to change back. When you examine the configuration, you find that the __________ are incorrect, and are allowing Bob to change the configuration, although he is not supposed to operate or configure this device. Since he did not know about Sally, he kept changing the configuration back.
MAC settings
DAC settings
ACL settings
Permission
