Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

CIT26 Practice Final Exam 70Q

Total questions: 91

Worksheet time: 50mins

Name
Class
Date
1.

Users report that a database file on the main server cannot be accessed. A database administrator verifies the issue and notices that the database file is now encrypted. The organization receives a threatening email demanding payment for the decryption of the database file. What type of attack has the organization experienced?

a)
  • DoS attack

b)
  • ransomware

c)
  • man-in-the-middle attack

d)

Trojan horse

2.

What two kinds of personal information can be sold on the dark web by cybercriminals? (Choose two.)

a)
  • city of residence

b)
  • Facebook photos

c)
  • name of a pet

d)
  • street address

e)

name of a bank

3.

Involved in hunting for potential threats and implements threat detection tools

a)

Tier 1 Alert Analyst

b)

Tier 2 Incident Responder

c)

Tier 3 Subject Matter Expert

4.

Involved in deep investigation of incidents

a)

Tier 1 Alert Analyst

b)

Tier 2 Incident Responder

c)

Tier 3 Subject Matter Expert

5.

Monitors incoming alerts and verifies that a true incident has occurred

a)

Tier 1 Alert Analyst

b)

Tier 2 Incident Responder

c)

Tier 3 Subject Matter Expert

6.

How does a security information and event management system (SIEM) in a SOC help the personnel fight against security threats?

a)
  • by analyzing logging data in real time

b)
  • by dynamically implementing firewall rules

c)
  • by combining data from multiple technologies

d)

by integrating all security devices and appliances in an organization

7.

Which statement describes the state of the administrator and guest accounts after a user installs Windows desktop version to a new computer?

a)
  • By default, both the administrator and guest accounts are enabled.

b)
  • By default, both the administrator and guest accounts are disabled.

c)
  • By default, the administrator account is enabled but the guest account is disabled.

d)

By default, the guest account is enabled but the administrator account is disabled.

8.

What is a purpose of entering the nslookup cisco.com command on a Windows PC?

a)
  • to connect to the Cisco server

b)
  • to test if the Cisco server is reachable

c)
  • to check if the DNS service is running

d)

to discover the transmission time needed to reach the Cisco server

9.

Which two actions can be taken when configuring Windows Firewall? (Choose two.)

a)
  • Enable MAC address authentication.

b)
  • Turn on port screening.

c)
  • Manually open ports that are required for specific applications.

d)
  • Allow a different software firewall to control access.

e)

Perform a rollback.

10.

Based on the command output shown, which file permission or permissions have been assigned to the other user group for the data.txt file?

ls –l data.txt
-rwxrw-r-- sales staff 1028 May 28 15:50 data.txt

a)
  • read, write, execute

b)
  • read

c)
  • read, write

d)

full access

11.

What are three benefits of using symbolic links over hard links in Linux? (Choose three.)

a)
  • Symbolic links can be exported.

b)
  • They can be encrypted.

c)

They can link to a file in a different file system.

d)
  • They can link to a directory.

e)
  • They can show the location of the original file.

12.

What is the Internet?

a)
  • It is a network based on Ethernet technology.

b)
  • It provides network access for mobile devices.

c)
  • It provides connections through interconnected global networks.

d)

It is a private network for an organization with LAN and WAN connections.

13.

Which two protocols are associated with the transport layer? (Choose two.)

a)
  • TCP

b)
  • IP

c)
  • UDP

d)
  • PPP

e)

ICMP

14.

At which OSI layer is a source IP address added to a PDU during the encapsulation process?

a)
  • network layer

b)
  • data link layer

c)
  • transport layer

d)
  • application layer

15.

When a connectionless protocol is in use at a lower layer of the OSI model, how is missing data detected and retransmitted if necessary?

a)
  • Connectionless acknowledgements are used to request retransmission.

b)
  • Upper-layer connection-oriented protocols keep track of the data received and can request retransmission from the upper-level protocols on the sending host.

c)
  • Network layer IP protocols manage the communication sessions if connection-oriented transport services are not available.

d)

The best-effort delivery process guarantees that all packets that are sent are received.

16.

What is the prefix length notation for the subnet mask 255.255.255.224?

a)
  • /25

b)
  • /26

c)
  • /27

d)

/28

17.

If the default gateway is configured incorrectly on the host, what is the impact on communications?

a)
  • The host is unable to communicate on the local network.

b)
  • The host can communicate with other hosts on the local network, but is unable to communicate with hosts on remote networks.

c)
  • The host can communicate with other hosts on remote networks, but is unable to communicate with hosts on the local network.

d)

There is no impact on communications.

18.

What are two ICMPv6 messages that are not present in ICMP for IPv4? (Choose two.)

a)
  • Destination Unreachable

b)
  • Neighbor Solicitation

c)
  • Route Redirection

d)
  • Router Advertisement

e)

Time Exceeded

19.

Which protocol is used by the traceroute command to send and receive echo-requests and echo-replies?

a)
  • SNMP

b)
  • ICMP

c)
  • Telnet

d)

TCP

20.

Which two types of messages are used in place of ARP for address resolution in IPv6? (Choose two.)

a)
  • echo reply

b)
  • broadcast

c)
  • neighbor solicitation

d)
  • echo request

e)

neighbor advertisement

21.

What are two problems that can be caused by a large number of ARP request and reply messages? (Choose two.)

a)
  • A large number of ARP request and reply messages may slow down the switching process, leading the switch to make many changes in its MAC table.

b)
  • All ARP request messages must be processed by all nodes on the local network.

c)
  • The ARP request is sent as a broadcast, and will flood the entire subnet.

d)
  • The network may become overloaded because ARP reply messages have a very large payload due to the 48-bit MAC address and 32-bit IP address that they contain.

e)

Switches become overloaded because they concentrate all the traffic from the attached subnets.

22.

Which network monitoring tool saves captured network frames in PCAP files?

a)
  • Wireshark

b)
  • SNMP

c)
  • NetFlow

d)

SIEM

23.

What is the TCP mechanism used in congestion avoidance?

a)
  • three-way handshake

b)
  • socket pair

c)
  • two-way handshake

d)

sliding window

24.

What kind of message is sent by a DHCPv4 client requesting an IP address?

a)
  • DHCPDISCOVER broadcast message

b)
  • DHCPDISCOVER unicast message

c)
  • DHCPOFFER unicast message

d)

DHCPACK unicast message

25.

Why is DHCP preferred for use on large networks?

a)
  • Large networks send more requests for domain to IP address resolution than do smaller networks.

b)
  • DHCP uses a reliable transport layer protocol.

c)
  • It prevents sharing of files that are copyrighted.

d)

t is a more efficient way to manage IP addresses than static address assignment.

e)

Hosts on large networks require more IP addressing configuration settings than hosts on small networks.

26.

What is a characteristic of DNS?

a)
  • DNS relies on a hub-and-spoke topology with centralized servers.

b)
  • DNS servers can cache recent queries to reduce DNS query traffic.

c)
  • All DNS servers must maintain mappings for the entire DNS structure.

d)

DNS servers are programmed to drop requests for name translations that are not within their zone.

27.

Refer to the exhibit. A cybersecurity analyst is viewing captured packets forwarded on switch S1. Which device has the MAC address d8:cb:8a:5c:d5:8a?router

a)
  • DG

b)
  • PC-A

c)
  • router ISP

d)
  • web server

e)

DNS server

28.

R1 replaces the address 192.168.10.10 with a translated inside global address

a)

Step 1

b)

Step 2

c)

Step 3

d)

Step 4

e)

Step 5

29.

R1 checks the NAT configuration to determine if this packet should be translated

a)

Step 1

b)

Step 2

c)

Step 3

d)

Step 4

e)

Step 5

30.

R1 selects an available global address from the dynamic address pool

a)

Step 1

b)

Step 2

c)

Step 3

d)

Step 4

e)

Step 5

31.

The host sends packets that request a connection to the server at the address 209.165.200.254

a)

Step 1

b)

Step 2

c)

Step 3

d)

Step 4

e)

Step 5

32.

If there is no translation entry for this IP address, R1 determines that the source address 192.168.10.10 must be translated.

a)

Step 1

b)

Step 2

c)

Step 3

d)

Step 4

e)

Step 5

33.

A technician is configuring email on a mobile device. The user wants to be able to keep the original email on the server, organize it into folders, and synchronize the folders between the mobile device and the server. Which email protocol should the technician use?

a)
  • POP3

b)
  • IMAP

c)
  • MIME

d)

SMTP

34.

What are two differences between HTTP and HTTP/2? (Choose two.)

a)
  • HTTP/2 uses different status codes than HTTP does to improve performance.

b)
  • HTTP/2 uses a compressed header to reduce bandwidth requirements.

c)
  • HTTP has a different header format than HTTP/2 has.

d)
  • HTTP/2 issues requests using a text format whereas HTTP uses binary commands.

e)

HTTP/2 uses multiplexing to support multiple streams and enhance efficiency.

35.

It encapsulates the Layer 3 packet into a new Layer 2 frame and forwards the frame out the exit interface

a)

Step 1

b)

Step 2

c)

Step 3

36.

It de-encapsulates the Layer 2 frames header and trailer to expose the Layer 3 packet

a)

Step 1

b)

Step 2

c)

Step 3

37.

It examines the destination IP address to find the best path in the routing table

a)

Step 1

b)

Step 2

c)

Step 3

38.

What is the purpose of CSMA/CA?

a)
  • to prevent collisions

b)
  • to prevent loops

c)
  • to filter traffic

d)

to isolate traffic

39.

Which statement describes a typical security policy for a DMZ firewall configuration?

a)
  • Traffic that originates from the outside interface is permitted to traverse the firewall to the inside interface with few or no restrictions.

b)
  • Traffic that originates from the DMZ interface is selectively permitted to the outside interface.

c)
  • Traffic that originates from the inside interface is generally blocked entirely or very selectively permitted to the outside interface.

d)
  • Return traffic from the outside that is associated with traffic originating from the inside is permitted to traverse from the outside interface to the DMZ interface.

e)

Return traffic from the inside that is associated with traffic originating from the outside is permitted to traverse from the inside interface to the outside interface.

40.

What are two shared characteristics of the IDS and the IPS? (Choose two.)

a)
  • Both are deployed as sensors.

b)
  • Both analyze copies of network traffic.

c)
  • Both use signatures to detect malicious traffic.

d)
  • Both have minimal impact on network performance.​

e)

Both rely on an additional network device to respond to malicious traffic.

41.

In an attempt to prevent network attacks, cyber analysts share unique identifiable attributes of known attacks with colleagues. What three types of attributes or indicators of compromise are helpful to share? (Choose three.)

a)
  • features of malware files

b)
  • IP addresses of attack servers

c)
  • system ID of compromised systems

d)
  • BIOS of attacking systems

e)
  • changes made to end system software

42.

Used to determine the possible consequences of successful attacks on the network

a)

Penetration Testing

b)

Network Scanning

c)

Vulnerability

43.

Used to discover available resources on the network

a)

Penetration Testing

b)

Network Scanning

c)

Vulnerability

44.

Used to find weaknesses and misconfiguration on network systems

a)

Penetration Testing

b)

Network Scanning

c)

Vulnerability

45.

Which two statements describe access attacks? (Choose two.)

a)
  • Port redirection attacks use a network adapter card in promiscuous mode to capture all network packets that are sent across a LAN.

b)
  • Password attacks can be implemented by the use of brute-force attack methods, Trojan horses, or packet sniffers.

c)
  • Buffer overflow attacks write data beyond the allocated buffer memory to overwrite valid data or to exploit systems to execute malicious code.

d)
  • To detect listening services, port scanning attacks scan a range of TCP or UDP port numbers on a host.

e)

Trust exploitation attacks often involve the use of a laptop to act as a rogue access point to capture and copy all network traffic in a public location, such as a wireless hotspot.

46.

After complaints from users, a technician identifies that the college web server is running very slowly. A check of the server reveals that there are an unusually large number of TCP requests coming from multiple locations on the Internet. What is the source of the problem?

a)
  • A DDoS attack is in progress.

b)
  • The server is infected with a virus.

c)
  • There is insufficient bandwidth to connect to the server.

d)

There is a replay attack in progress.

47.

What are two monitoring tools that capture network traffic and forward it to network monitoring devices? (Choose two.)

a)
  • SIEM

b)
  • Wireshark

c)
  • SNMP

d)
  • SPAN

e)

network tap

48.

Which network monitoring tool is in the category of network protocol analyzers?

a)
  • SNMP

b)
  • SPAN

c)
  • Wireshark

d)

SIEM

49.

What kind of ICMP message can be used by threat actors to perform network reconnaissance and scanning attacks?

a)
  • ICMP redirects

b)
  • ICMP unreachable

c)
  • ICMP mask reply

d)

ICMP router discovery

50.

A flood of packets with invalid source IP addresses requests a connection on the network. The server busily tries to respond, resulting in valid requests being ignored. What type of attack has occurred?

a)
  • UDP flood

b)
  • TCP session hijacking

c)
  • TCP reset

d)

TCP SYN flood

51.

An attacker is redirecting traffic to a false default gateway in an attempt to intercept the data traffic of a switched network. What type of attack could achieve this?

a)
  • ARP cache poisoning

b)
  • DHCP spoofing

c)
  • DNS tunneling

d)

TCP SYN flood

52.

What is the most common goal of search engine optimization (SEO) poisoning?

a)
  • to trick someone into installing malware or divulging personal information

b)
  • to overwhelm a network device with maliciously formed packets

c)
  • to build a botnet of zombies

d)

to increase web traffic to malicious sites

53.

The likelihood of undesireable consequences

a)

threat

b)

vulnerability

c)

exploit

d)

risk

54.

a mechanism used to compromise an asset

a)

threat

b)

vulnerability

c)

exploit

d)

risk

55.

a weakness in a system

a)

threat

b)

vulnerability

c)

exploit

d)

risk

56.

a potential danger to an asset

a)

threat

b)

vulnerability

c)

exploit

d)

risk

57.

Which section of a security policy is used to specify that only authorized individuals should have access to enterprise data?

a)
  • statement of scope

b)
  • Internet access policy

c)
  • acceptable use policy

d)
  • campus access policy

e)

identification and authentication policy

58.

A network security specialist is tasked to implement a security measure that monitors the status of critical files in the data center and sends an immediate alert if any file is modified. Which aspect of secure communications is addressed by this security measure?

a)
  • data integrity

b)
  • nonrepudiation

c)
  • data confidentiality

d)

origin authentication

59.

A network administrator is configuring an AAA server to manage TACACS+ authentication. What are two attributes of TACACS+ authentication? (Choose two.)

a)
  • encryption for only the password of a user

b)
  • encryption for all communication

c)
  • separate processes for authentication and authorization

d)
  • UDP port 1645

e)
  • single process for authentication and authorization

60.

What three services are offered by FireEye? (Choose three.)

a)
  • blocks attacks across the web

b)
  • identifies and stops email threat vectors

c)
  • creates firewall rules dynamically

d)
  • identifies and stops latent malware on files

e)
  • subjects all traffic to deep packet inspection analysis

61.

Which three algorithms are designed to generate and verify digital signatures? (Choose three.)

a)
  • IKE

b)
  • AES

c)
  • DSA

d)
  • RSA


e)

ECDSA

62.

What are the two important components of a public key infrastructure (PKI) used in network security? (Choose two.)

a)
  • intrusion prevention system

b)
  • certificate authority

c)
  • digital certificates

d)
  • pre-shared key generation

e)

symmetric encryption algorithms

63.

recognizing various characteristics of known malware files

a)

agent-based

b)

behavior-based

c)

signature-based

d)

heuristics-based

64.

analyzing suspicious activities

a)

agent-based

b)

behavior-based

c)

signature-based

d)

heuristics-based

65.

recognizing general features shared by various types of malware

a)

agent-based

b)

behavior-based

c)

signature-based

d)

heuristics-based

66.

Which statement describes the anomaly-based intrusion detection approach?

a)
  • It compares the operations of a host against a well-defined security policy.

b)
  • It compares the signatures of incoming traffic to a known intrusion database.

c)
  • It compares the antivirus definition file to a cloud based repository for latest updates.

d)

It compares the behavior of a host to an established baseline to identify potential intrusions.

67.

A network administrator is creating a network profile to generate a network baseline. What is included in the critical asset address space element?

a)
  • the list of TCP or UDP processes that are available to accept data

b)
  • the IP addresses or the logical location of essential systems or data

c)
  • the time between the establishment of a data flow and its termination

d)

the TCP and UDP daemons and ports that are allowed to be open on the server

68.

What are the three impact metrics contained in the CVSS 3.0 Base Metric Group? (Choose three.)

a)
  • attack vector

b)
  • availability

c)
  • confidentiality

d)
  • exploit

e)
  • integrity

69.

How might corporate IT professionals deal with DNS-based cyber threats?

a)
  • Use IPS/IDS devices to scan internal corporate traffic.

b)
  • Monitor DNS proxy server logs and look for unusual DNS queries.

c)
  • Limit the number of DNS queries permitted within the organization.

d)

Limit the number of simultaneously opened browsers or browser tabs.

70.

How does using HTTPS complicate network security monitoring?

a)
  • HTTPS can be used to infiltrate DNS queries.

b)
  • HTTPS adds complexity to captured packets.

c)
  • Web browser traffic is directed to infected servers.

d)

HTTPS cannot protect visitors to a company-provided web site.

71.

Which three pieces of information are found in session data? (Choose three.)

a)
  • user name

b)
  • source and destination port numbers

c)
  • Layer 4 transport protocol

d)
  • source and destination IP addresses

e)
  • source and destination MAC addresses

72.

What are two elements that form the PRI value in a syslog message? (Choose two.)

a)
  • facility

b)
  • header

c)
  • severity

d)
  • hostname

e)

timestamp

73.

Refer to the exhibit. Which field in the Sguil application window indicates the priority of an event or set of correlated events?

a)
  • CNT

b)
  • ST

c)
  • Pr

d)

AlertID

74.

What is indicated by a true negative security alert classification?

a)
  • An alert is verified to be an actual security incident.

b)
  • Normal traffic is correctly ignored and erroneous alerts are not being issued.

c)
  • An alert is incorrectly issued and does not indicate an actual security incident.

d)

Exploits are not being detected by the security systems that are in place.

75.

Which two types of network traffic are from protocols that generate a lot of routine traffic? (Choose two.)

a)
  • SSL traffic

b)
  • STP traffic

c)
  • IPsec traffic

d)
  • routing updates traffic

e)

Windows security auditing alert traffic

76.

How is the event ID assigned in Sguil?

a)
  • Each event in the series of correlated events is assigned a unique ID.

b)
  • All events in the series of correlated events are assigned the same event ID.

c)
  • All events in the series of correlated events are assigned the same event group ID.

d)

Only the first event in the series of correlated events is assigned a unique ID.

77.

Which type of evidence supports an assertion based on previously obtained evidence?

a)
  • best evidence

b)
  • corroborating evidence

c)
  • direct evidence

d)

indirect evidence

78.

Place the evidence collection priority from most volatile to least volatile as defined by the IETF guidelines.

routing table,ARP cache, process table, kernel statistics, RAM
1.(most volatile) - 7. (least volatile)

a)

1.

b)

2.

c)

3.

d)

4.

e)

5.

79.

Place the evidence collection priority from most volatile to least volatile as defined by the IETF guidelines.

non-volatile media, fixed and removable
1.(most volatile) - 7. (least volatile)

a)

1.

b)

2.

c)

3.

d)

4.

e)

5.

80.

Place the evidence collection priority from most volatile to least volatile as defined by the IETF guidelines.

memory registers, caches
1.(most volatile) - 7. (least volatile)

a)

1.

b)

2.

c)

3.

d)

4.

e)

5.

81.

Place the evidence collection priority from most volatile to least volatile as defined by the IETF guidelines.

temporary file systems
1.(most volatile) - 7. (least volatile)

a)

1.

b)

2.

c)

3.

d)

4.

e)

5.

82.

Place the evidence collection priority from most volatile to least volatile as defined by the IETF guidelines.

remote logging and monitoring data
1.(most volatile) - 7. (least volatile)

a)

1.

b)

2.

c)

3.

d)

4.

e)

5.

83.

Place the evidence collection priority from most volatile to least volatile as defined by the IETF guidelines.

physical interconnections and topologies
1.(most volatile) - 7. (least volatile)

a)

3.

b)

4.

c)

5.

d)

6.

e)

7.

84.

Place the evidence collection priority from most volatile to least volatile as defined by the IETF guidelines.

archival media, tape or backups
1.(most volatile) - 7. (least volatile)

a)

3.

b)

4.

c)

5.

d)

6.

e)

7.

85.

When dealing with a security threat and using the Cyber Kill Chain model, which two approaches can an organization use to help block potential exploitations on a system? (Choose two.)

a)
  • Conduct full malware analysis.

b)
  • Train web developers for securing code.

c)
  • Collect email and web logs for forensic reconstruction.

d)
  • Build detections for the behavior of known weaponizers.

e)

Perform regular vulnerability scanning and penetration testing.

86.

What is the goal of an attack in the installation phase of the Cyber Kill Chain?

a)
  • Break the vulnerability and gain control of the target.

b)
  • Establish command and control (CnC) with the target system.

c)
  • Create a back door in the target system to allow for future access.

d)

Use the information from the reconnaissance phase to develop a weapon against the target.

87.

Which activity is typically performed by a threat actor in the installation phase of the Cyber Kill Chain?

a)
  • Harvest email addresses of user accounts.

b)
  • Obtain an automated tool to deliver the malware payload.

c)
  • Open a two-way communication channel to the CnC infrastructure.

d)

Install a web shell on the target web server for persistent access.

88.

What will a threat actor do to create a back door on a compromised target according to the Cyber Kill Chain model?

a)
  • Collect and exfiltrate data.

b)
  • Add services and autorun keys.

c)
  • Obtain an automated tool to deliver the malware payload.

d)

Open a two-way communications channel to the CnC infrastructure.

89.

What is the responsibility of the human resources department when handling a security incident?

a)
  • Coordinate the incident response with other stakeholders and minimize the damage of the incident.

b)
  • Review the incident policies, plans, and procedures for local or federal guideline violations.

c)
  • Perform actions to minimize the effectiveness of the attack and preserve evidence.

d)

Apply disciplinary measures if an incident is caused by an employee.

90.

Which NIST incident response life cycle phase includes continuous monitoring by the CSIRT to quickly identify and validate an incident?

a)
  • detection and analysis

b)
  • preparation

c)
  • containment, eradication, and recovery

d)

postincident activities

91.

After containment, what is the first step of eradicating an attack?

a)

Patch all vulnerabilities.

b)
  • Change all passwords.

c)
  • Identify all hosts that need remediation.

d)

Hold meetings on lessons learned.