wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Exam CNSA

Total questions: 35

Worksheet time: 18mins

Name
Class
Date
1.

Which is the most important reason for the removal of unused, unnecessary, or unneeded protocols, services, and applications?

a)

Increased security

b)

Increased performance

c)

Less need for administration

d)

Less machine resource use

2.

Why is network security important for organizations?

a)

It increases network speed

b)

It protects sensitive information

c)

It reduces electricity usage

d)

It simplifies network configurations

3.

Which of the following best describes 'encryption'?

a)

Speeding up data transmission

b)

Compressing data for storage

c)

Creating user-friendly software

d)

Converting data into a secure code

4.

The act of attempting to appear to be someone you're not in order to gain access to a system is known as which of the following?

a)

Spoofing

b)

DDoS

c)

Replay

d)

Sniffing

5.

Which term refers to the protection of networked systems from misuse or unauthorized access?

a)

Network Optimization

b)

Network Monitoring

c)

Network Security

d)

Network Analysis

6.

Which of the following is an example of a social engineering attack?

a)

Firewall breach

b)

Phishing

c)

SQL Injection

d)

Man-in-the-Middle attack

7.

Which of the following is considered an attack vector?

a)

USB drive

b)

Monitor

c)

Keyboard

d)

Printer

8.

Which of the following is most likely to make systems vulnerable to MITM attacks?

a)

Weak passwords

b)

Weak TCP sequence numbers

c)

Authentication misconfiguration on routers

d)

Use of the wrong operating systems

9.

Which of the following is the best way to protect your organization from revealing sensitive information through dumpster diving?

a)

Establish a policy requiring employees to change passwords every 30 to 60 days

b)

Add a new firewall to the network

c)

Teach employees the value of not disclosing restricted information over the telephone to unknown parties

d)

Shred all sensitive documentation

10.

What type of threat involves exploiting software flaws to gain unauthorized access?

a)

Phishing

b)

Malware

c)

Vulnerability Exploit

d)

Social Engineering

11.

Which encryption type uses the same key for both encryption and decryption?

a)

Symmetric encryption

b)

Asymmetric encryption

c)

Hash functions

d)

Digital signatures

12.

Which of the following is a best practice for network security procedures?

a)

Using outdated software

b)

Regularly updating and patching systems

c)

Ignoring security alerts

d)

Sharing passwords

13.

What is the main principle of cryptography?

a)

To speed up data transmission

b)

To secure information through encoding

c)

To compress data for storage

d)

To enhance user interfaces

14.

Which of the following is an essential component of security procedures?

a)

Regular system backups

b)

Increasing network speed

c)

Reducing software costs

d)

Enhancing user interfaces

15.

What is the primary purpose of developing security policies?

a)

To increase network speed

b)

To enhance network graphics

c)

To establish rules and guidelines for network security

d)

To reduce software costs

16.

PDAs, cell phones, and certain network cards have the ability to use _____________ networks. Choose the BEST answer.

a)

Wired

b)

Private

c)

Wireless

d)

Antique

17.

The PKI identification process is based upon the use of unique identifiers, known as _____

a)

Licences

b)

Fingerprints

c)

Keys

d)

Locks

18.

Your supervisor has charged you with determining which 802.11 authentication method to use when deploying the new wireless network. Given your knowledge of the 802.11 specification, which of the following is the most secure 802.11 authentication method?

a)

Shared-key

b)

EAP-TLS

c)

EAP-MD5

d)

Open

19.

What are the two WEP key sizes available in 802.11 networks?

a)

64-bit and 128-bit

b)

40-bit and 104-bit

c)

24-bit and 64-bit

d)

24-bit and 104-bit

20.

Which of the following is a weakness in WEP related to the IV?

a)

The IV is a static value, which makes it relatively easy for an attacker to brute force the WEP key from captured traffic

b)

The IV is transmitted in plaintext and can be easily seen in captured traffic.

c)

There is no weakness in WEP related to the IV.

d)

The IV is only 24 bits in size, which makes it possible that two or more data frames will be transmitted with the same IV, thereby resulting in an IV collision that an attacker can use to determine information about the network.

21.

When you use Java, the JVM isolates the Java applet to a sandbox when it executes. What does this do to provide additional security?

a)

This prevents the Java applet from accessing data on the client's hard drive

b)

This prevents the Java applet from failing in such a way that the Java applet is unable to execute.

c)

This prevents the Java applet from communicating to servers other than the one from which it was downloaded.

d)

This prevents the Java applet from failing in such a way that it affects another application

22.

To allow its employees remote access to the corporate network, a company has implemented a hardware VPN solution. Why is this considered a secure remote access solution?

a)

Because only the company's employees will know the address to connect to in order to use the VPN.

b)

Because VPNs use the Internet to transfer data.

c)

Because a VPN uses encryption to make its data secure

d)

Because a VPN uses compression to make its data secure.

23.

What types of computers might you expect to find located on an intranet?

a)

Publicly accessible DNS servers and Public Web servers

b)

SQL 2000 servers and User workstations

c)

Public Web servers and SQL 2000 servers

d)

User workstations and Publicly accessible DNS servers

24.

Which of the following protocols can be used to secure a VPN connection?

a)

DNS

b)

MPPE

c)

Apple Talk

d)

TCP/IP

25.

Josh has asked for a clarification of what a firmware update is. How could you briefly describe for him the purpose of firmware updates?

a)

Firmware updates are control software- or BIOS-type updates that are installed to improve the functionality or extend the life of the device involved.

b)

Firmware updates are device-specific command sets that must be upgraded to continue operation.

c)

Firmware updates update the mechanical function of the device.

d)

Firmware updates are minor fixes, and are not usually necessary

26.

Your FTP server was just compromised. When you examine the settings, you find that the server allows Anonymous access. However, you know that this is a default condition in most FTP servers, and must dig further for the problem. Where else might you check?

a)

All of them are correct

b)

ACL settings for server access

c)

Effective permissions for the anonymous access

d)

Access permissions on server's file structure

27.

You have downloaded a CD ISO image and want to verify its integrity. What should you do?

a)

Compare the file sizes

b)

Burn the image and see if it works

c)

Create an MD4 sum and compare it to the MD4 sum listed where the image was downloaded.

d)

Create an MD5 sum and compare it to the MD5 sum listed where the image was downloaded

28.

Which of the following algorithms are available for commercial use without a licensing fee?

a)

RSA, DES, and IDEA

b)

DES, IDEA, and AES

c)

RSA, DES, and AES

d)

IDEA, AES, and RSA

29.

Public Key Cryptography is a system that uses a mix of symmetric and ___________ algorithms for the encryption of a secret key.

a)

Public

b)

Asymmetric

c)

Private

d)

Certificate

30.

When a company uses ____________, it is keeping copies of the private key in two separate secured locations where only authorized persons are allowed to access them.

a)

Key destruction

b)

Key escrow

c)

Key generetion

d)

Key rings

31.

You are the first person to arrive at a crime scene. An investigator and crime scene technician arrive afterwards to take over the investigation. Which of the following tasks will the crime scene technician be responsible for performing?

a)

Tag, bag, and inventory evidence.

b)

Establish a chain of command

c)

Reestablish a perimeter as new evidence presents itself

d)

Ensure that any documentation and evidence they possessed is handed over to the investigator.

32.

You are manager of the IT department and have designed a new security policy that addresses the IT staff's responsibilities to users, equipment, and data. The policy only affects the IT staff. It deals with such issues as routine backups of data, network security changes, and audits of data on servers. Now that the new policy is written, which of the following should you do next?

a)

Publish the policy and make it available for all users to read.

b)

Obtain authorization from other members of the IT staff.

c)

Obtain authorization from senior management.

d)

Provide a copy of the policy to legal counsel, and have them review its content and wording.

33.

You have been asked to develop an audit plan for your company. You have been told that there have been constant deletions of files that are being worked on by a team, and that they have had to redo the work a number of times. What type of auditing would you implement to track the access to this resource?

a)

Logon/logoff success

b)

Object/file access success

c)

Object/file access failure

d)

Logon/logoff failure

34.

You want to implement access control that will allow users to control who has access to the data they have ownership over. Which of the following would you use?

a)

MAC

b)

DAC

c)

RBAC

d)

BAC

35.

Sally has come to you for advice and guidance. She is trying to configure a network device to block attempts to connect on certain ports, but when she finishes the configuration, it works for a period of time but then changes back to the original configuration. She cannot understand why the settings continue to change back. When you examine the configuration, you find that the __________ are incorrect, and are allowing Bob to change the configuration, although he is not supposed to operate or configure this device. Since he did not know about Sally, he kept changing the configuration back.

a)

MAC settings

b)

DAC settings

c)

ACL settings

d)

Permission