wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Cybersecurity Certification

Total questions: 61

Worksheet time: 31mins

Name
Class
Date
1.

A system on your network is experiencing slower than usual response times. In order to gather information about the status of the system, you issue the netstat =l command to display all of the TCP ports that are in the listing state. What does the Listening state indicate about these ports?

a)

The state of the connection on the ports is unknown.

b)

The remote end disconnected and the ports are closing.

c)

The ports are open on the system and are waiting for connections.

d)

The ports are actively connected to another system or process.

2.

Match each NIST incident response lifecycle phase to its correct description:
1. Mitigate the impact of the incident
2. Report the cause and cost of the incident and the steps to prevent future incidents
3. Evaluates incident indicators to determine whether they are legitimate attacks and alerts the organization of the incidents
4. Establishes an incident response capability to ensure that organizational assets are sufficiently secure

a)

Preparation,
Post-incident Activity, Detection and Analysis, Containment,
Eradication, and Recovery

b)

Detection and Analysis, Preparation, Containment, Eradication, and Recovery, Post-incident Activity

c)

Containment, Eradication, and Recovery, Post-incident Activity, Detection and Analysis, Preparation

d)

Preparation, Detection and Analysis, Containment, Eradication, and Recovery, Post-incident Activity

3.

What is the purpose of a hypervisor?

a)

It creates and runs virtual machines.

b)

It monitors and logs network traffic for malicious packets.

c)

It provides and monitors firewall services for cloud computing.

d)

It provides and services a gateway between users and the internet.

4.

What enables the network security team to keep track of the operating system version, security updates, and patches on end user’s devices?

a)

Business continuity planning

b)

Asset management

c)

Incident management

d)

Security policies and procedures

5.

What should you create to prevent spoofing of the internal network?

a)

A DNS record

b)

A NAT rule

c)

A record in the host file

d)

An ACL

6.

Which two private IPv4 addresses would be blocked on the internet to prevent security and performance issues? (Choose 2)

a)

203.0.113.168

b)

192.168.18.189

c)

224.0.2.172

d)

172.18.100.78

7.

While conducting a risk evaluation at your company, you identify risks that are related to the web server located in the office. The risks include hardware and software failure as well as web service interruption caused by cyber attacks. You recommend purchasing insurance and hiring another organization to maintain the web server to help mitigate the risks. What type of risk management strategy is being applied?

a)

Risk reduction

b)

Risk avoidance

c)

Risk acceptance

d)

Risk transfer

8.

Which CIA Triad term corresponds to the principle that "Data should be accessed and read by authorized users only"?

a)

Integrity

b)

Confidentiality

c)

Availability

d)

Authentication

9.

Which CIA Triad term corresponds to the principle that "Data should never be altered or compromised"?

a)

Confidentiality

b)

Availability

c)

Integrity

d)

Encryption

10.

Which CIA Triad term corresponds to the principle that "Legitimate requests should have access to data at all times"?

a)

Availability

b)

Confidentiality

c)

Integrity

d)

Authorization

11.

The employees in the accounting department of a company receive an email about the latest federal regulations. The email contains a hyperlink to register for a webinar hosted by a government agency. As a security officer, you notice that the hyperlink points to an unknown party. Which type of cybersecurity threat should you investigate?

a)

Spear phishing

b)

Smishing

c)

Ransomware

d)

Vishing

12.

Your home network seems to have slowed down considerably. You look at the home router GUI and notice that an unknown host is attached to the network. What should you do to prevent this specific host from attaching to the network again?

a)

Implement MAC address filtering.

b)

Create an IP access control list.

c)

Change the network SSID.

d)

Block the host IP address.

13.

Which classification of security alert is the greatest threat to an organization because it represents undetected exploits?

a)

False negative

b)

False positive

c)

True negative

d)

True positive

14.

You are working with the senior administration team to identify potential risks. Which phase of risk management are you in?

a)

Choosing risk strategies

b)

Measuring residual risk

c)

Mitigating risks

d)

Determining a risk profile

15.

A corporation hires a group of experienced cyber criminals to create a prolonged and in-depth presence on the network of a competitor. This presence will allow the corporation to steal or sabotage. Which type of attack does this scenario describe?

a)

Ransomware

b)

Man-in-the-middle

c)

APT

d)

DDoS

16.

You need to allow employees to access your company’s secure network from their homes. Which type of security should you implement?

a)

SNMP

b)

VPN

c)

BYOD

d)

IDS

17.

Which data type is protected through hard disk encryption?

a)

Data in process

b)

Data at rest

c)

Data in transit

d)

Data in use

18.

You need to transfer configuration files to a router across an unsecured network. Which protocol should you use to encrypt the files in transit?

a)

TFTP

b)

HTTP

c)

SSH

d)

Telnet

19.

You are monitoring the syslog server and observe that the DNS server is sending messages with a Warning severity. What do these messages indicate about the operation of the DNS server?

a)

The DNS server is unusable due to a severe malfunction and is shutting down

b)

The server has a hardware error that does not require immediate attention

c)

A condition exists that will cause errors in the future if the issue is not fixed

d)

An error condition is occurring that must be addressed immediately

20.

You are a security technician. You just completed a full scan of a Windows 10 PC. Where should you go to view the scan result?

a)

Windows Task Manager

b)

Windows System Logs

c)

Windows Application Logs

d)

Windows Security

21.

Your organization's SIEM system alerts you that users are connecting to an unusual URL. You need to determine whether the URL is malicious and what type of threat it represents. What should you do?

a)

Submit the URL to a threat intelligence portal for analysis

b)

Ask users why they visited the website

c)

Visit the URL to determine whether the website is legitimate

d)

Block the URL by placing it on the network block list

22.

Several employees complain that the company intranet site is no longer accepting their login information. You attempt to connect by using the URL and notice some misspellings on the site. When you connect by using the IP address, the site functions normally. What should you do?

a)

Verify the accuracy of the entry for the site in the local DNS server

b)

Take the company web portal offline immediately

c)

Update the web server software to the latest version

d)

Restore a backup copy of the authentication database

23.

Which two actions should you take immediately to address unexplained computer crashes and unwanted pop-up messages without impacting data? (Choose 2)

a)

Reinstall Windows on the affected workstations

b)

Deploy a policy to install and automatically update antivirus and anti-malware software

c)

Scan affected workstations and remove malware

d)

Configure the network firewall to block malware from entering the internal network

24.

A cybersecurity analyst is investigating an unknown executable file discovered on a Linux desktop computer. The analyst enters the following command in the terminal ls -l. What is the purpose of the command.

a)

To display the content of a text file

b)

To open a text editor

c)

To display the file permission and ownership of the executable file

d)

To navigate to the folder that is passed as an argument to the command

25.

You need to filter the websites that are available to employees on the company network. Which type of device should you deploy?

a)

IPS

b)

Proxy server

c)

IDS

d)

Honeypot

26.

A security analyst discovers that a hacker was able to gain root access to an enterprise Linux server. The hacker accessed the server as a guest, used a program to bypass the root password, and then killed essential processes as the root user. Which type of endpoint attack is this?

a)

Buffer overflow

b)

DDoS

c)

Privilege escalation

d)

Brute force

27.

Which wireless encryption technology required AES to secure home wireless network?

a)

WEP

b)

WPA

c)

WPA2

d)

TKIP

28.

Which three authentication factors are valid for use in a multifactor authentication scenario? (Choose 3)

a)

Something you earn

b)

Something you know

c)

Something you are

d)

Something you see

e)

Something you have

29.

True or False: A security analyst may use a disgruntled employee network credential to monitor behavior.

a)

True

b)

False

30.

True or False: A security analyst may access employee data on a company server if authorized.

a)

True

b)

False

31.

True or False: A security analyst may share sensitive data with unauthorized users.

a)

True

b)

False

32.

What are two natural disasters that would cause a company to implement a disaster recovery plan? (Choose 2)

a)

Hazardous material spills

b)

Floods

c)

Nuclear contamination

d)

Volcanic eruptions

33.

After an administrator installs an operating system update on a laptop, the laptop user can no longer print to their wireless printer. What should solve the issue?

a)

Check for patches for wireless printers

b)

Reinstall the same service pack

c)

Install a new device driver for the wireless printer

d)

Update the firmware on the laptop

34.

Which activity is an example of active reconnaissance performed during a penetration test?

a)

Using a browser to view the HTTP source code of company webpages

b)

Gathering employee information from available web directories and social media

c)

Performing an Nmap port scan on the LAN to determine types of connected devices and open ports

d)

Searching the WHOIS database for the owner and technical contact information for a domain

35.

You are reviewing company remote access procedures and notice that telnet is being used to connect to the corporate database server to check on inventory levels. Which two actions should you take immediately? (Choose 2)

a)

Force users to implement secure telnet passwords.

b)

Disable telnet access on the server.

c)

Implement SSH access on the server.

d)

Reconfigure the server to only accept HTTPS connection.

36.

Which activity by an adversary is an example of an exploit that is attempting to gain credentials?

a)

Installing a backdoor in order to enable two-way communication with the device.

b)

Sending an email with a link to a fictitious web portal login page.

c)

Obtaining a directory listing of files located on the web database server.

d)

Executing a remote port scan of all of the enterprise-registered IP addresses.

37.

Which two basic metrics should be taken into consideration when assigning a severity to a vulnerability during an assessment? (Choose 2)

a)

The likelihood that an adversary can and will exploit the vulnerability

b)

The impacts that an exploit of the vulnerability will have on the organization

c)

The time involved in choosing replacement software to replace older systems

d)

The age of the hardware running the software that contains the vulnerability

38.

What are two disadvantages of public vulnerability databases? (Choose 2)

a)

Threat actors can access the databases to learn how to vary their threats to avoid detection

b)

Publicly available databases are incompatible with most security platforms

c)

It can take a long time for reported vulnerabilities to be investigated and approved for addition to the databases

d)

It is costly for intelligence analysts to document and submit newly discovered vulnerabilities

39.

Which framework protects the personal information of members of the European Union?

a)

HIPAA

b)

GDPR

c)

FERPA

d)

PCI-DSS

40.

Which framework is responsible for protecting the healthcare information of individuals?

a)

FERPA

b)

PCI-DSS

c)

HIPAA

d)

FISMA

41.

Which framework protects the credit card information of individuals?

a)

PCI-DSS

b)

GDPR

c)

HIPAA

d)

FERPA

42.

Which framework protects the educational records of individuals?

a)

FISMA

b)

FERPA

c)

GDPR

d)

HIPAA

43.

Which framework protects information about individuals that is stored by federal agencies?

a)

FERPA

b)

PCI-DSS

c)

FISMA

d)

GDPR

44.

Which command displays both the configured DNS server information and the IP address resolution for a URL?

a)

Ping

b)

Nslookup

c)

Traceroute

d)

Nmap

45.

Customers of an online shopping store are complaining that they cannot visit the website. As an IT technician, you restart the website. After 30 minutes, the website crashes again. You suspect that the website has been experiencing which type of cybersecurity threat?

a)

Spear phishing

b)

Ransomware

c)

Denial of service

d)

Social engineering

46.

You are a security analyst. You are reviewing output from the SIEM. You notice an alert concerning malicious files detected by the IDS. After reviewing the user, device, and posture information, you determine that it is a valid alert. What should you do next?

a)

Escalate the situation immediately

b)

Log the alert and watch for a second occurrence

c)

Prepare notes to present at the weekly cybersecurity team meeting

d)

Update the documentation to include the new alert information

47.

In order to do online banking, you enter a strong password and then enter the 5-digit code sent to you on your smartphone. Which type of authentication does this situation describe?

a)

VPN

b)

Multifactor

c)

AAA

d)

RADIUS

48.

What does hashing provide for the communication?

a)

Data integrity

b)

Data encryption

c)

Data non-repudiation

d)

Origin authentication

49.

You work for a community health care organization that uses an electronic health record (EHR) system. You have implemented the physical and technical safeguards required by HIPAA. You need to prove that the EHR system is compliant with those safeguards. Which two approaches should you use to verify the system is compliant? (Choose 2).

a)

Automatic log-off implementation

b)

Penetration testing

c)

Security awareness training

d)

IT auditing

50.

Move each cybersecurity tools from the list in the left to the correct location on the Vulnerability Process diagram on the right.

a)

Discover: Nmap, Nessus Scanner

Prioritize: CVSS

Remediate: Window Auto Update, Patch Management Software

b)

Discover: CVSS, Nmap

Prioritize: Patch Management Software

Remediate: Window Auto Update, Nessus Scanner

c)

Discover: Window Auto Update, CVSS

Prioritize: Patch Management Software

Remediate: Nmap, Nessus Scanner

51.

Clean and patch infection system

a)

Treatment

b)

Containment

c)

Inoculation

d)

Quarantine

52.

Remove or block infected system from the network

a)

Treatment

b)

Containment

c)

Inoculation

d)

Quarantine

53.

Patch uninfected systems to deprive the worm of more available targets

a)

Treatment

b)

Containment

c)

Inoculation

d)

Quarantine

54.

Compartmentalize and segment the network to limit the spread of the worm to areas already infected

a)

Treatment

b)

Containment

c)

Inoculation

d)

Quarantine

55.

People, property, or data

a)

Asset

b)

Threat

c)

Risk

d)

Vulnerability

56.

An action that causes a negative impact

a)

Asset

b)

Threat

c)

Risk

d)

Vulnerability

57.

The potential for loss, damage, or destruction

a)

Asset

b)

Threat

c)

Risk

d)

Vulnerability

58.

A weakness that potentially exposes organizations to cyber attacks

a)

Asset

b)

Threat

c)

Risk

d)

Vulnerability

59.

Discover unwanted event

a)

Detective measures

b)

Preventive measures

c)

Corrective measures

60.

Avert the occurrence of an event

a)

Detective measures

b)

Preventive measures

c)

Corrective measures

61.

Restore a system after an event

a)

Detective measures

b)

Preventive measures

c)

Corrective measures