Font size
S
M
L
XL
WorksheetsMCyber_Chap17N19
Total questions: 25
Worksheet time: 25mins
Name
Class
Date
1.
What are the two classes of encryption algorithms? (Choose two.)
a)
Open
b)
Symmetric
c)
Asymmetric
d)
Classic
e)
Advanced
2.
What term is used to describe the phenomenon of more VMs than can be managed effectively?
a)
VM Scaling
b)
VM Exhaustion
c)
VM Escape
d)
VM Sprawl
3.
Which cloud security domain covers the challenges of delivering, measuring, and communicating compliances when organizations migrate from traditional data centers to the cloud?
a)
Infrastructure Security
b)
Management Plane and Business Continuity
c)
Information Governance
d)
Compliance and Audit Management
4.
A company is deploying a product ordering system on a public cloud. The company IT specialist is working on security measures to protect the cloud resources. What are two possible negative impacts that should be considered when deploying a virtual firewall and an IPS appliance? (Choose two.)
a)
Compatibility with VM operating systems
b)
Routing issues associated with virtual security appliances
c)
Traffic bottleneck
d)
Possible VM escape attacks
e)
Processor overloading
5.
What should be deployed to protect traffic confidentiality between a public cloud and a private cloud?
a)
Proxy device
b)
IPS
c)
VPN
d)
Firewall
6.
In which type of environment would a developer run software to verify that required security settings are met prior to production deployment?
a)
Sandbox environment
b)
Development environment
c)
Production environment
d)
Staging environment
7.
Which state of data refers to data moving between the CPU and the hard drive of a server?
a)
Data in storage
b)
Data in process
c)
Data in transit
d)
Data at rest
8.
Which technology is used to verify the integrity of files to ensure they were not modified in transit?
a)
Asymmetric encryption
b)
Checksum
c)
Secure cookies
d)
Normalization
9.
Which threat type describes the case when cloud computing resources are set up incorrectly?
a)
Inside threat
b)
Cloud misconfiguration
c)
Data breaches
d)
Poor cloud security architecture strategy
10.
What term is used to refer to readable data in the context of the data encryption process?
a)
Ciphertext
b)
Cleantext
c)
Opentext
d)
Plaintext
11.
Which key component of virtualization allows for running multiple independent operating systems on one physical computing system?
a)
VDI
b)
Hypervisor
c)
VM
d)
Container
12.
How do cybercriminals make use of a malicious iFrame?
a)
The iFrame allows multiple DNS subdomains to be used.
b)
The attacker embeds malicious content in business appropriate files.
c)
The iFrame allows the browser to load a web page from another source.
d)
The attacker redirects traffic to an incorrect DNS server.
13.
In which way does the use of HTTPS increase the security monitoring challenges within enterprise networks?
a)
HTTPS traffic can carry a much larger data payload than HTTP can carry.
b)
HTTPS traffic is much faster than HTTP traffic.
c)
HTTPS traffic does not require authentication.
d)
HTTPS traffic enables end-to-end encryption.
14.
Which network service synchronizes the time across all devices on the network?
a)
NetFlow
b)
Syslog
c)
NTP
d)
SNMP
15.
Which type of server daemon accepts messages sent by network devices to create a collection of log entries?
a)
SSH
b)
NTP
c)
Syslog
d)
AAA
16.
What port number would be used if a threat actor was using NTP to direct DDoS attacks?
a)
443
b)
25
c)
69
d)
123
17.
Which protocol is used to send e-mail messages between two servers that are in different e-mail domains?
a)
POP3
b)
SMTP
c)
HTTPS traffic does not require authentication.
d)
IMAP4
18.
What type of server can threat actors use DNS to communicate with?
a)
CnC
b)
Database
c)
NTP
d)
Web
19.
Which type of server would support the SMTP, POP, and IMAP protocols?
a)
DHCP
b)
Email
c)
Proxy
d)
Syslog
20.
What method allows VPN traffic to remain confidential?
a)
Verification
b)
Authentication
c)
Encryption
d)
Encapsulation
21.
To facilitate the troubleshooting process, which inbound ICMP message should be permitted on an outside interface?
a)
Echo request
b)
Time-stamp request
c)
Echo reply
d)
Time-stamp reply
e)
Router advertisement
22.
Which statement describes the function provided by the Tor network?
a)
It distributes user packets through load balancing.
b)
It allows users to browse the Internet anonymously.
c)
It conceals packet contents by establishing end-to-end tunnels.
d)
It manipulates packets by mapping IP addresses between two networks.
23.
How can NAT/PAT complicate network security monitoring if NetFlow is being used?
a)
It changes the source and destination MAC addresses.
b)
It conceals the contents of a packet by encrypting the data payload.
c)
It disguises the application initiated by a user by manipulating port numbers.
d)
It hides internal IP addresses by allowing them to share one or a few outside IP addresses.
24.
A cyberanalyst is reviewing an entry-point ACL. What three types of ICMP traffic should be allowed to access an internal network from the internet? (Choose three.)
a)
Destination unreachable
b)
Time exceeded
c)
Ping
d)
Reply
e)
Squelch
25.
A company decides to purchase a device capable of managing load balancing so that traffic will be distributed between their servers. What could be a potential problem using the new device on the network?
a)
It will cause extra traffic going to a server resource that is not available.
b)
It will require the purchase of more servers so that existing servers are not overwhelmed.
c)
The traffic will require more bandwidth to send to multiple servers.
d)
All links to redundant servers will require encrypted tunneling protocols.
e)
The LBM probe messages may appear as suspicious traffic.
Reset
