NEW
Font size
WorksheetsIntro Cyber Exam 5 (Modules 9-11)
Total questions: 68
Worksheet time: 34mins
What is the main goal of storing encryption keys securely?
To ensure easy access for all users
To facilitate key revocation
To prevent unauthorized access
To increase the key's strength
What is an implicit deny in firewall configuration?
A rule that explicitly allows all traffic
A default behavior to block traffic that does not match any rule
A temporary rule that denies access during peak hours
A rule that only denies traffic from specific countries
What is Personally Identifiable Information (PII)?
Any data that can be publicly accessed
Data that can identify, contact, or locate an individual
Information related to a company's financial status
Data that is encrypted and stored securely
What makes smart devices vulnerable to standard attacks?
Their inability to connect to the Internet
The use of proprietary operating systems
Their compute, storage, and network functions
The lack of integrated peripherals
What is a zero-day vulnerability?
A vulnerability patched within a day of its discovery
A vulnerability that exists for zero days
A vulnerability exploited before the developer can patch it
A vulnerability that cannot be patched
A cyber security technician responds to a department experiencing degraded network bandwidth, and customers call the department saying they cannot visit the company website. What is likely causing the issue?
On-path attack
DNS Poisoning
Malware
Distributed DoS (DDoS)
What is the primary purpose of deploying a firewall in a network environment?
To increase the network speed
To filter traffic entering or leaving a network segment
To serve as a primary storage device
To manage user access to the internet
What is a recommended step to secure IoT devices in a corporate environment?
Limiting device functionality
Assigning device configuration to appropriate organizational roles
Using default device configurations
Encouraging employees to manage their own devices
What can mitigate the risks posed by IoT devices in remote working scenarios?
Decreasing the number of devices connected to the home network
Regular audits and employee security awareness training
Using older, more familiar technology
Avoiding the use of Wi-Fi networks
What is a key difference between the perimeter security model and defense in depth?
The perimeter security model uses multiple layers of security, while defense in depth relies on a single layer.
The perimeter security model focuses on internal threats, while defense in depth focuses on external threats.
The perimeter security model relies on trusting internal connections once they're inside the perimeter, while defense in depth does not.
The perimeter security model is a modern approach, while defense in depth is outdated.
What should be done to secure SNMP traffic?
Disable SNMP entirely.
Use the original versions of SNMP.
Configure SNMPv3 or use IPSec for encryption.
Limit SNMP traffic to internal networks.
What is the primary goal of most adversaries when launching network attacks?
To improve network security
To steal information from the network
To provide free services to users
To enhance network performance
What might a firewall be incorrectly doing if an application fails to function correctly?
Allowing all TCP and UDP ports
Blocking TCP or UDP ports that should be open
Increasing bandwidth for all applications
Decrypting all incoming traffic
Which security device is typically used to enforce rules between network zones?
Switch
Router
Firewall
Access Point
How is a user's biometric data used in a biometric lock system?
It is sent to a remote server for storage.
It is recorded and stored on an authentication server.
It is stored on the user's badge.
It is deleted immediately after each use for privacy reasons.
What does MAC filtering on a switch allow an administrator to do?
Limit the bandwidth usage per MAC address.
Define which MAC addresses are permitted to connect to a particular port.
Assign specific IP addresses to MAC addresses.
Monitor the amount of data transmitted by each MAC address.
What is a badge reader used for in building security?
To detect motion at entry points
To authenticate users quickly at access points
To record the time employees leave the building
To provide lighting at entry points
What is MAC spoofing?
Changing the MAC address of a network interface to any arbitrary value
Physically altering the network interface to change its MAC address
Using malware to reveal the MAC address of a device
Intercepting MAC addresses during data transmission
What is a forward proxy primarily used for?
Inbound traffic management
Outbound traffic management
Data encryption only
Data storage
What does "defense in depth" refer to in network security design?
A single, impenetrable layer of security at the network's edge
Placing security controls throughout the network
Focusing solely on physical security measures
Ignoring internal threats and focusing on external attacks
What is the primary goal of implementing security policies within an organization?
To increase the organization's revenue
To ensure compliance with legal requirements
To mitigate risks associated with network systems
To eliminate all risks facing the organization
What is malware?
A type of computer hardware that performs poorly
Software designed to protect computer networks
Software that performs malicious actions
A beneficial software tool that enhances system performance
What is the primary difference between ARP spoofing and ARP poisoning?
ARP spoofing is a passive attack while ARP poisoning is an active attack.
ARP spoofing involves broadcasting fake ARP messages, while ARP poisoning refers to the state of the ARP cache.
ARP poisoning is used to secure network communications, whereas ARP spoofing is a malicious activity.
ARP spoofing and ARP poisoning are terms for the same process, with no difference between them.
What is the purpose of spoofing attacks?
To improve the security of DNS services
To disguise the attacker's identity
To enhance the performance of ARP services
To provide legitimate services to users
Which of the following servers should be placed in a perimeter network?
Database servers containing sensitive information
Web servers providing public access services
File servers used exclusively by internal employees
Internal email servers for employee communication
A network administrator is tasked with securing a company's network infrastructure against ARP cache poisoning attacks. The network consists of several switches and hosts, with IPv4 being the primary protocol used. The administrator decides to implement a security feature on the switches to mitigate these types of attacks.
VLAN tagging
Dynamic ARP Inspection (DAI)
BPDU Guard
DHCP snooping
What is the function of a content filtering firewall or proxy?
To increase bandwidth
To serve as a backup data center
To restrict access
To provide a VPN service
What does enabling Root Guard on ports not used as trunk lines accomplish?
It allows for faster convergence of the spanning tree.
It prevents unauthorized changes to the root bridge selection.
It encrypts BPDU packets for secure transmission.
It increases the number of allowable VLANs on a port.
Due to an increase in foot traffic from outside groups throughout the building, the organization asks their security office to employ equipment that will allow visual monitoring across the organization. What equipment would best be suited to manage this request?
Circuit
Cameras
Motion Detection
Asset Tag
What does DHCP snooping help to prevent?
The operation of rogue DHCP servers
The switch from assigning IP addresses
The encryption of DHCP traffic
The use of static IP addresses on the network
Which factor determines the type of credential a subject can use for authentication?
Authorization model
Accounting system
Authentication factor
Identification process
What is DNS spoofing?
Manipulating cached DNS records
Using false DNS requests or replies
Attacking the physical infrastructure of DNS servers
Infecting DNS servers with malware
Why are longer and more complex passwords more secure against brute force attacks?
They are easier to remember.
They take less time to crack.
They increase the amount of time the attack takes to run.
They are less likely to be stored in password files.
What does the principle of least privilege entail in the context of PAM?
Granting users unlimited rights to perform their job
Granting users only the rights necessary to perform their job
Allowing users to determine their access rights
Providing all users with administrative privileges
Which of the following examples BEST describes shoulder surfing?
Guessing someone's password because it is so common or simple
Finding someone's password in the trash can and using it to access their account
Giving someone you trust your username and account password
Someone nearby watching you enter your password on your computer and recording it
What can the most serious vulnerabilities allow an attacker to do?
Increase system performance
Execute arbitrary code on the system
Improve application security
Encrypt system files for data protection
What is the purpose of a choke point in a screened subnet configuration?
To provide a direct connection to the Internet
To facilitate better access control and easier monitoring
To eliminate the need for internal firewalls
To allow unrestricted access between the perimeter network and the LAN
What is the role of the screening firewall in a screened subnet?
To connect directly to the LAN
To filter communications between hosts in the perimeter and the LAN
To restrict traffic on the external/public interface
To provide unrestricted access to the Internet
What framework does Windows use to provide Single Sign-On (SSO) authentication?
OAuth
LDAP
Kerberos
SAML
What does the Ticket Granting Ticket (TGT) provide in the Kerberos authentication process?
Immediate access to all network resources
A token that grants access to a target application server
Authentication for user logon requests
The ability to request Service Tickets from the TGS
What tool can be used to discover whether false records have been inserted into a DNS server's cache?
Ping
Traceroute
nslookup or dig
Netstat
What are Potentially Unwanted Programs (PUPs)/Potentially Unwanted Applications (PUAs)?
Software that is always malicious and installed without the user's consent
Software installed alongside a package selected by the user
Programs that enhance computer security without the user's knowledge
Applications that cannot be uninstalled by the user
What does "availability" in the CIA Triad refer to?
The data is stored and transferred as intended and that any modification is authorized.
Information and resources are accessible to those authorized when needed.
Information is protected from unauthorized access except to those with the proper permissions.
The system is protected against unauthorized access, attacks, and disclosure.
What is meant by "data at rest"?
Data being transmitted over a network
Data stored on a persistent storage media
Data present in volatile memory
Data being actively processed by a computer
What is the primary purpose of the Spanning Tree Protocol (STP) in a network?
To encrypt traffic between switches
To increase network bandwidth
To prevent switching loops
To facilitate VLAN hopping attacks
What is an on-path attack?
A type of physical attack where the attacker physically intercepts a data transmission.
A type of spoofing attack where a threat actor intercepts communications between two hosts.
A cyber-attack that exclusively targets the path of data storage devices.
An attack where the threat actor creates a new path in a network to reroute data.
What does the term "attack surface" refer to?
The physical area of a network
The total number of users in a system
The range of potential vulnerabilities exploitable by attackers
The graphical interface of security software
How does RBAC differ from using security groups for assigning permissions?
RBAC assigns permissions directly to users, while security groups do not.
RBAC is discretionary, while security groups are nondiscretionary.
RBAC focuses on job roles, while security groups are about user identity.
Security groups encrypt data, while RBAC does not.
What distinguishes an external threat actor from an internal threat actor?
The type of malware they use
Whether they have authorized access to the system
The geographical location of the actor
The sophistication of the attack
What is the role of a Certificate Authority (CA) in PKI?
To distribute private keys to users
To guarantee the validity of digital certificates
To encrypt messages with public keys
To generate symmetric session keys
What does "integrity" in the context of the CIA Triad mean?
The data is stored and transferred as intended and that any modification is authorized.
Information is accessible to those authorized to view or modify it.
Certain information should only be known to certain people.
The system is protected against unauthorized access and attacks.
What is a DHCP starvation attack?
An attack that floods the network with excessive data
An attack that exhausts a DHCP server's address pool
An attack that encrypts all DHCP traffic
An attack that physically damages the DHCP server
Which of the following combinations represents two-factor authentication?
Password and a smart card
Two different passwords
Password and a user's favorite color
Password and the time of login
What can be a source of internal threats?
Hackers from another country
Employees within the organization
Malware found on the Internet
Phishing emails from unknown senders
What is VLAN hopping?
A method to increase the speed of VLAN traffic
An attack designed to send traffic to a VLAN other than the one the host system is in
A technique to reduce network congestion
A security feature of 802.1Q to enhance VLAN compatibility
Which of the following can be a use case for the mirror port in port mirroring?
Connecting another switch
Acting as a monitoring point
Serving as an additional port for network clients
Providing power over Ethernet (PoE) to devices
What is the purpose of the HOSTS file in DNS resolution?
To store the user's browsing history
To act as a backup for DNS servers
To map domain names to IP addresses
To log DNS query errors
What can an organization use geofencing for?
To increase the speed of their internet connection
To monitor the productivity of their employees
To control the use of camera functions on devices
To improve the accuracy of their GPS systems
In the context of IEEE 802.1X, what is the role of a switch configured as a RADIUS client?
To distribute IP addresses
To forward authentication data
To encrypt network traffic
To manage network storage
What is the primary purpose of prevention-type physical controls like electronic locks?
To monitor and record access attempts
To stop an intruder from gaining unauthorized access
To alert security personnel of an unauthorized access attempt
To provide a backup power source for electronic devices
What is one of the key benefits of using a honeypot or honeynet in cybersecurity?
Completely eliminating cyber threats
Providing an early warning of attacks
Increasing the encryption strength
Reducing the need for other security measures
Which of the following network security zones is subject to strict hardening and configuration management policies, and where hosts, user accounts, and traffic are continually monitored to ensure compliance with security policies?
Guest
Public server network
Private client network
Private server administrative networks
Which of the following can be considered a rogue device?
An officially sanctioned DHCP server
A wireless access point installed without IT approval
A firewall configured by the network security team
A company-issued laptop with up-to-date security software
What is a Distributed Reflection DoS (DRDoS) attack?
An attack that improves server reflection capabilities
A type of attack where the victim's IP address is spoofed
A method to reduce network bandwidth consumption
An attack that directly targets the attacker's network
What is the APIPA range used for?
Global internet routing
Private IP addressing when DHCP is unavailable
Static IP addressing
Network address translation (NAT)
What is the difficulty in implementing security controls?
They are always too complex to implement.
They can be expensive.
They are not supported by IT service frameworks.
They only address low-level risks.
What does "protect mode" do when a switch port enters a violation state?
It disables the port and sends alerts.
It drops frames from the invalid source address but keeps the interface open.
It encrypts traffic from the invalid source address.
It reroutes traffic from the invalid source address to a quarantine VLAN.
What is a key pair in public key cryptography?
Two identical keys used for encryption and decryption
A set of two keys, one for signing and one for verification
A set of two keys, one public and one private, used together
Two public keys used interchangeably
