Font size
WorksheetsSec+ Day 1-4 review
Total questions: 44
Worksheet time: 44mins
This type of threat actor(s) are highly skilled and have significant resources and funding. Their motivations may be espionage, disruption/chaos and even war preparation. These threat actors are usually sponsoring by government entities. What threat actor am I not describing? Select all that apply
Nation-state
Script Kiddie
Hacktivist
Organized crime
A large corporation decided to start a large factory to build hardware for computers. They announced it on their website. A week later, the company's website is defaced with messages condemning the whole project and demanding the project be stopped. No sensitive data was stolen, but the attack gain wide attention on social media.
Which type of threat actor is most likely responsible for this attack?
Organize crime
Script Kiddie
Activist
Hacktivist
Insider threat
Alvin was tired of having just one computer at work to do all his work. So he brought in a switch, connected the switch to the wall jack. He then connected his work desktop to the switch and a personal laptop to the switch. He is using his laptop to listen to music and YouTube while completing work on his work desktop.
What type of threat is this an example of?
Insider Threat
Shadow It
Unskilled Attacker
Script Kiddie
An attacker impersonates a company executive and sends an urgent email to the finance department requesting a wire transfer to a "new vendor". The message appears legitimate and uses the executive's real email signature. This type of social engineering attack is known as (a) . (Acronym)
You are monitoring the network for suspicious activity. You receive an alert that several employees have been sent an email containing pictures of cats. When you download one of the images in an isolated environment, you discover that hidden malware is embedded within the image file. What technique did the attacker use?
Phishing
Veganography
Watering Hole
Steganography
From the picture provided, what is the biggest issue that you need to fix in order to harden this WAP?
Uncheck hide SSID
Uncheck 2.4GHz/5GHz
Disable Smart connect
Change the Security to a better protocol
You are installing a new WAP in your home. You enable WPA 3, changed the SSID, enabled a guest network to segment guests. After confirming all these best security practices, you can't help but feel like you forgot 1 more important thing? What did you forget to change?
Enable VLANs
Disable Bluetooth
Change default credentials
Hide SSID
Telnet Secure installed a software update from a trusted vendor. Soon after, several systems begin showing unusual outbound network connections to an unknown IP. Upon investigation, you discover that the vendor's software update had been modified by an attacker before distribution. What type of attack does this scenario describe?
Supply Chain Attack
Insider threat
Watering Hole
Drive-by download
True or False: Best hardening practices include enforcing MFA, monitoring for misconfigurations, implementing PoLP, and applying latest security patches.
True
False
A network administrator is preparing to deploy a new Wi-Fi network in an office building. Before placing the access points, the admin walks through the building measuring signal strength, identifying interference, and checking for areas that may have weak coverage.
Which of the following is the BEST description of this activity?
Site Survey
Heat Map
The company is issuing smartphones to all management level employees that they can also use for personal tasks. The organization retains full control over the device, to include the ability to remotely wipe the device if lost or compromised. This mobile device management strategy is called (a) (acronym)
Alvin was called in on his only day off this year because Geff in accounting picked up a USB from the parking lot and plugged it into his computer. Before Alvin gets to the office, he has someone disconnect the PC from the network and asked for the USB to be secured until he gets there. What is one technique Alvin can do to check what is inside the USB safely.
Type 2 Hypervisor
Type 1 Virtualization
Sandboxing
Fire Geff
Ash wants to send a secure message to Misty. To do this, Ash encrypts the message using A, and Misty decrypts the message using B. Select the correct answer for each letter.
A: Ash’s public key; B: Ash’s private key
A: Misty’s public key; B: Misty’s private key
A: Ash’s private key; B: Misty’s public key
A: Misty’s private key; B: Ash’s public key
A(n) (a) is a dedicated hardware device that securely generates, stores and manages cryptographic keys. often used for server-based encryption or PKI operations. (acronym)
Telnet Secure is increasing security. They are implementing a software that will take all stored credit card numbers and replace them with randomly generated strings that have no meaningful value outside of the company systems. What technique is being used?
Hashing
Tokenization
Data masking
Encryption
Which of the following are hashing algorithms?
AES 256
AES 512
MD5
SHA-256
A technique used to protect against pre-computed hash attacks and ensures uniqueness. This technique is done by adding unique data to passwords before hashing to prevent rainbow attacks.
(a)
A technique that applies multiple iterations of a hashing function to a password to make it harder for attackers to crack is called _____?
Salting
Data masking
Key Stretching
3DES
A distributed ledger that records transactions in blocks that are cryptographically linked describes which of the following?
Cipherchain
Blockchain
PKI
Syslog
A company uses digital certificates for authentication. When the internet goes down, users can no longer verify certificates because the system can’t reach the OCSP server.
What could allow certificate validation to continue during the outage?
Disable certificate checks
Use a locally cached CRL
Increase the certificate's validity
Switch to a wildcard certificate
On an ACL, there is a rule that is always there but never shown. What is that rule called?
Explicit Accept
Explicit Deny
Implicit Accept
Implicit Deny
Your company wants to prevent attackers from sending emails that appear to come from its domain. Which DNS record helps mail servers verify the authorized sending mail servers?
MX
DKIM
DMARC
SPF
The company wants to use _______ to detect and block malicious attachments and phishing links before messages reach user inboxes. This is a technical control. What is the company using?
DMARC
DKIM
SPF
Email Security Gateway
An employee attempts to email a spreadsheet containing customer SSN to a personal address. The company's (a) system blocks the email because it detects sensitive data in the attachment. (acronym)
The company is implement a security solution. This solution will have devices authenticate when joining the network, enforce policies, verify if devices meet security requirements, automatically quarantine devices that fail security requirement checks and provide continuous monitoring. (Acronym)
(a)
Alvin is reviewing user accounts and finds that the company has 457 active employees but over 600 active user accounts. Which process was not properly followed?
Provisioning
Deactivate the account
De-provisioning
All of the above
You use your university campus credentials to log into a third-party educational platform instead of creating new accounts. What does this concept describe?
SSO
Federation
IAM
None of the above
A system reports its hardware and software configuration to a trusted authority to verify that it has not been tampered with. What is this process called?
Authentication
Attestation
Authorization
Encryption
Alex creates a confidential file on his computer and grants Alvin permission to read it. Alvin cannot change the access settings; only Alex decides who can access his file.
DAC
MAC
Role-base access control
Rule-based access control
(a) allows teams to manage servers, networks and other resources programmatically using code or scripts. (acronymn)
A company has a single on-premises data center that hosts all their email servers, file storage, and internal applications. Employees from all offices must connect to this data center to access any company resources. Recently, the company experienced a power outage at the data center, which caused all employees to lose access to email, shared files, and business applications for several hours.
Which architecture does this company use, and what is a major risk of this setup?
Decentralized; risk of inconsistent data across offices
Centralized; risk of single point of failure
Decentralized; risk of complex management
Centralized; risk of redundant processing
True or False: Embedded systems often operate in real-time, meaning they must respond immediately to input or environmental changes.
True
False
What is the purpose of platform diversity in an enterprise network?
Reduce software licensing cost
Simplify system administration
Reduce the risk that a single exploit can compromise all systems
ensure all systems use the same operating system
Alvin, Michael and Alex were invited to meeting where the company are discussing the steps to respond to a ransomware attack. They are not activating any systems and someone brought pizza with pineapples. Which type of exercise is being held?
Parallel test
Tabletop exercise
Simulation testing
Failover testing
The data center firewall experience a critical hardware failure and stops all traffic until it is repaired. What type of fail-safe behavior is this?
Fail-Open
Fail-Close
Fail-Parallel
Fail-Simulation
An organization wants to analyze user traffic patterns to detect anomalies without affecting network performance. They install a device that captures packets and forwards them to a monitoring system. Which type of monitoring is this?
Active monitoring
Passive monitoring
Remote monitoring
SIEM monitoring
A company wants to securely connect two branch offices over the internet using a VPN. Which tunneling protocol is BEST suited for encrypting all IP traffic between the offices?
TLS
SSh
IPsec
SSL
(a) is a security framework that combines network and security services in a cloud-delivered model, providing secure access to applications regardless of user location. (Acronym)
An organization implements VLANs to separate the accounting, HR, and sales departments. Additionally, the company hosts its public web server in a DMZ protected by two firewalls. Which of the following best describes this design principle?
PoLP
Network Segmentation
De-Provisioning
Aggregation
An organization is retiring old laptops that were used by former employees. The IT team ensures that all drives are wiped, credentials removed, and assets updated in the inventory before sending the devices to a certified recycling center. Which process is this an example of?
Provisioning
Patching
Decomissioning
Segmentation
An administrator wants to secure a web application server. She disables unused services, applies the latest patches, enforces strong passwords, and installs a host-based firewall. Which of the following BEST describes this process?
Vulnerability scanning
Hardening
Encryption
Network Segmentation
What web-based vulnerability is executed by injecting malicious scripts into web pages? Often used to hijack sessions.
SQLi
XSS
Memory injection
SQLi and XSS
Alvin misses flappy bird and all the good times he had with the game. The app store removed flappy bird from its listing. Alvin decides to download flappy bird from a third party. What is Alvin doing?
Rooting
Jailbreaking
downloading
side loadin
You are working on a security team, you were assigned to gather intelligence to enhance threat detection capabilities. Information you are suppose to gathered are found on publicly available blogs, forums and social media posts. What type of intelligence is this? (Acronym)
(a)
