Font size
S
M
L
XL
WorksheetsMCyber_Chap12N13
Total questions: 25
Worksheet time: 24mins
Name
Class
Date
1.
A user has created a new program and wants to distribute it to everyone in the company. The user wants to ensure that when the program is downloaded that the program is not changed while in transit. What can the user do to ensure that the program is not changed when downloaded?
a)
Create a hash of the program file that can be used to verify the integrity of the file after it is downloaded.
b)
Turn off antivirus on all the computers.
c)
Distribute the program on a thumb drive.
d)
Encrypt the program and require a password after it is downloaded.
e)
Install the program on individual computers.
2.
A user is running a routine audit of the server hardware in the company data center. Several servers are using single drives to host operating systems and multiple types of attached storage solutions for storing data. The user wants to offer a better solution to provide fault tolerance during a drive failure. Which solution is best?
a)
Offsite backup
b)
RAID
c)
UPS
d)
Tape backup
3.
A user was hired by a company to provide a highly available network infrastructure. The user wants to build redundancy into the network in case of a switch failure, but wants to prevent Layer 2 looping. What would the user implement in the network?
a)
VRRP
b)
GLBP
c)
HSRP
d)
Spanning Tree Protocol
4.
Why is WPA2 better than WPA?
a)
Reduced processing time
b)
Supports TKIP
c)
Mandatory use of AES algorithms
d)
Reduced keyspace
5.
An administrator of a small data center wants a flexible, secure method of remotely connecting to servers.Which protocol would be best to use?
a)
Remote Desktop
b)
Telnet
c)
Secure Copy
d)
Secure Shell
6.
Which service will resolve a specific web address into an IP address of the destination web server?
a)
DHCP
b)
ICMP
c)
DNS
d)
NTP
7.
A company wants to implement biometric access to its data center. The company is concerned with people being able to circumvent the system by being falsely accepted as legitimate users. What type of error is false acceptance?
a)
Type I
b)
Type II
c)
False Rejection
d)
CER
8.
Mutual authentication can prevent which type of attack?
a)
Wireless IP spoofing
b)
Wireless sniffing
c)
Man-in-the-middle
d)
Wireless poisoning
9.
Which utility uses the Internet Control Messaging Protocol (ICMP)?
a)
RIP
b)
DNS
c)
Ping
d)
NTP
10.
Which technology can be used to protect VoIP against eavesdropping?
a)
ARP
b)
Encrypted voice messages
c)
Strong authentication
d)
SSH
11.
What is the purpose of a DMZ?
a)
It analyzes traffic for intrusion attempts and sends reports to management stations.
b)
It provides secure connectivity for clients that connect to the internal network through a wireless LAN.
c)
It allows external hosts to access specific company servers while maintaining the security restrictions for the internal network.
d)
It creates an encrypted and authenticated tunnel for remote hosts to access the internal network.
12.
What two steps should be taken before connecting any IoT device to a home or business network? (Choose 2.)
a)
Update the device firmware with all relevant security patches
b)
Reset all IoT device settings to their defaults before connecting to a live network.
c)
Record the administrative credentials on the login plate in case you forget them.
d)
Change all default administrator credentials.
e)
Ensure all IoT devices are isolated to a single broadcast domain.
13.
Which three processes are examples of logical access controls? (Choose three.)
a)
Intrusion detection system (IDS) to watch for suspicious network activity
b)
Firewalls to monitor traffic
c)
Guards to monitor security screens
d)
Swipe cards to allow access to a restricted area
e)
Biometrics to validate physical characteristics
14.
An organization plans to implement security training to educate employees about security policies. What type of access control is the organization trying to implement?
a)
Administrative
b)
Technological
c)
Phyiscal
d)
Logical
15.
When a security audit is performed at a company, the auditor reports that new users have access to network resources beyond their normal job roles. Additionally, users who move to different positions retain their prior permissions. What kind of violation is occurring?
a)
Password
b)
Network policy
c)
Least privilege
d)
Audit
16.
Which access control model assigns security privileges based on the position, responsibilities, or job classification of an individual or group within an organization?
a)
Rule-based
b)
Discretionary
c)
Role-based
d)
Mandatory
17.
Which type of access control applies the strictest access control and is commonly used in military or mission critical applications?
a)
Non-discretionary access control
b)
Discretionary access control (DAC)
c)
Attribute-based access control (ABAC)
d)
Mandatory access control (MAC)
18.
Which component is a pillar of the zero trust security approach that focuses on the secure access of devices, such as servers, printers, and other endpoints, including devices attached to IoT?
a)
Workforce
b)
Workplace
c)
Workloads
d)
Workflows
19.
A user has been asked to implement IPsec for inbound external connections. The user plans to use SHA-1 as part of the implementation. The user wants to ensure the integrity and authenticity of the connection. What security tool can the user use?
a)
HMAC
b)
SHA256
c)
ISAKMP
d)
MD5
20.
After a security audit for an organization, multiple accounts were found to have privileged access to systems and devices. Which three best practices for securing privileged accounts should be included in the audit report? (Choose three.)
a)
Secure password storage.
b)
Enforce the principle of least privilege.
c)
Only the CIO should have privileged access.
d)
No one should have privileged access
e)
Reduce the number of privileged accounts.
21.
What Windows utility should be used to configure password rules and account lockout policies on a system that is not part of a domain?
a)
Active Directory Security tool
b)
Event Viewer security log
c)
Computer Management
d)
Local Security Policy tool
22.
What is the purpose of the network security accounting function?
a)
To require users to prove who they are
b)
To determine which resources a user can access
c)
To provide challenge and response questions
d)
To keep track of the actions of a user
23.
Because of implemented security controls, a user can only access a server with FTP. Which AAA component accomplishes this?
a)
Auditing
b)
Accessibility
c)
Authorization
d)
Accounting
e)
Authentication
24.
What is used to scan a BYOD device to verify that it is compliant with company security policies before the device is permitted to access the network?
a)
ACL
b)
NAC
c)
Reconnaissance
d)
Proxy server
e)
IDS
25.
Which AAA component can be established using token cards?
a)
Authentication
b)
Auditing
c)
Authorization
d)
Accounting
Reset
