wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

cuestionario1

Total questions: 62

Worksheet time: 31mins

Name
Class
Date
1.

1. An attacker has installed a RAT on a host. The attacker wants to ensure that when a user attempts to go to "www.MyPersonalBank.com", the user is directed to a phishing site. Which file does the attacker need to modify?

a)

Boot.ini

b)

Sudoers

c)

Networks

d)

Hosts

2.

Is a set of extensions to DNS that provide the origin authentication of DNS data to DNS clients (resolvers) so as to reduce the threat of DNS poisoning, poisoning, spoofing, and similar types of attacks

a)

DNSSEC

b)

Resource records

c)

Resource transfer

d)

Zone transfer

3.

Which of the following incident handling process phases is responsible for defining rules, collaborating human workforce, creating a back-up plan, and testing the plans for an organization?

a)

Preparation phase

b)

Containment phase

c)

Identification phase

d)

Recovery phase

4.

The configuration allows a wired or wireless network interface controller to pass all traffic it receives to the Central Processing Unit (CPU), rather than passing only the frames that the controller is intended to receive. Which of the following is being described?

a)

Multi-cast mode

b)

Promiscuous mode

c)

WEM

d)

Port forwarding

5.

A large mobile telephony and data network operator has a data center that houses network elements. These are essentially large computers running on Linux. The perimeter of the data center is secured with firewalls and IPS systems. What is the best security policy concerning this setup?

a)

Network elements must be hardened with user ids and strong passwords. Regular security tests and audits should be performed.

b)

As long as the physical access to the network elements is restricted, there is no need for additional measures.

c)

There is no need for specific security measures on the network elements as long as firewalls and IPS systems exist.

d)

The operator knows that attacks and down time are inevitable and should have a backup site.

6.

PGP, SSL, and IKE are all examples of which type of cryptography?

a)

Digest

b)

Secret Key

c)

Public Key

d)

Hash Algorithm

7.

Peter is surfing the internet looking for information about DX Company. Which hacking process is Peter doing?

a)

Scanning

b)

Footprinting

c)

Enumeration

d)

System Hacking

8.

A hacker is an intelligent individual with excellent computer skills and the ability to explore a computer’s software and hardware without the owner’s permission. Their intention can either be to simply gain knowledge or to illegally make changes. 

Which of the following class of hacker refers to an individual who works both offensively and defensively at various times?

a)

White Hat

b)

Ethical Hacker

c)

Gray Hat

d)

Black Hat

9.

During a recent security assessment, you discover the organization has one Domain Name Server (DNS) in a Demilitarized Zone (DMZ) and a second DNS server on the internal network.

What is this type of DNS configuration commonly called?

a)

DynDNS

b)

DNS Scheme

c)

DNSSEC

d)

Split DNS

10.

What kind of detection techniques is being used in antivirus software that identifies malware by collecting data from multiple protected systems and instead of analyzing files locally it’s made on the provider’s environment?

a)

Behavioral based

b)

Heuristics based

c)

Honeypot based

d)

Cloud based

11.

Which of the following tools is used to analyze the files produced by several packet-capture programs such as tcpdump, WinDump, Wireshark, and EtherPeek?

a)

tcptrace

b)

Nessus

c)

OpenVAS

d)

tcptraceroute

12.

What is the way to decide how a packet will move from an untrusted outside host to a protected inside that is behind a firewall, which permits the hacker to determine which ports are open and if the packets can pass through the packetfiltering of the firewall?

a)

Session hijacking

b)

Firewalking

c)

Man-in-the middle attack

d)

Network sniffing

13.

Which of the following is not a Bluetooth attack?

a)

Bluedriving

b)

Bluesmacking

c)

Bluejacking

d)

Bluesnarfing

14.

What is the role of test automation in security testing?

a)

It is an option but it tends to be very expensive.

b)

It should be used exclusively. Manual testing is outdated because of low speed and possible test setup inconsistencies.

c)

Test automation is not usable in security due to the complexity of the tests.

d)

It can accelerate benchmark tests and repeat them with a consistent test setup. But it cannot replace manual testing completely.

15.

Your company performs penetration tests and security assessments for small and medium-sized business in the local area. During a routine security assessment, you discover information that suggests your client is involved with human trafficking.

What should you do?

a)

Confront the client in a respectful manner and ask her about the data

b)

Copy the data to removable media and keep it in case you need it.

c)

Ignore the data and continue the assessment until completed as agreed.

d)

Immediately stop work and contact the proper legal authorities.

16.

While using your bank’s online servicing you notice the following string in the URL bar: “http: // www. MyPersonalBank. com/ account?id=368940911028389&Damount=10980&Camount=21” 

You observe that if you modify the Damount & Camount values and submit the request, that data on the web page reflects the changes. Which type of vulnerability is present on this site?

a)

Cookie Tampering

b)

SQL Injection

c)

Web Parameter Tampering

d)

XSS Reflection

17.

The establishment of a TCP connection involves a negotiation called three-way handshake. What type of message does the client send to the server in order to begin this negotiation?

a)

ACK

b)

SYN

c)

RST

d)

SYN-ACK

18.

Which type of security feature stops vehicles from crashing through the doors of a building?

a)

Bollards

b)

Receptionist

c)

Mantrap

d)

Turnstile

19.

The company ABC recently contracts a new accountant. The accountant will be working with the financial statements. Those financial statements need to be approved by the CFO and then they will be sent to the accountant but the CFO is worried because he wants to be sure that the information sent to the accountant was not modified once he approved it. 

Which of the following options can be useful to ensure the integrity of the data?

a)

The CFO can use a hash algorithm in the document once he approved the financial statements

b)

The CFO can use an excel file with a password

c)

The financial statements can be sent twice, one by email and the other delivered in USB and the accountant can compare both to be sure is the same document

d)

The document can be sent to the accountant using an exclusive USB for that document

20.

What is the purpose of a demilitarized zone on a network?

a)

To scan all traffic coming through the DMZ to the internal network

b)

To only provide direct access to the nodes within the DMZ and protect the network behind it

c)

To provide a place to put the honeypot

d)

To contain the network devices you wish to protect

21.

Which of the following Linux commands will resolve a domain name into IP address?

a)
b)

>host-t ns hackeddomain.com

c)

>host -t soa hackeddomain.com

d)

>host -t AXFR hackeddomain.com

22.

Shellshock allowed an unauthorized user to gain access to a server. It affected many Internet-facing services, which OS did it not directly affect?

a)

Linux

b)

Unix

c)

OS X

d)

Windows

23.

Which regulation defines security and privacy controls for Federal information systems and organizations?

a)

HIPAA

b)

EU Safe Harbor

c)

PCI-DSS

d)

NIST-800-53

24.

What is a “Collision attack” in cryptography?

a)

What is a “Collision attack” in cryptography?

b)

Collision attacks try to break the hash into three parts to get the plaintext value

c)

Collision attacks try to break the hash into two parts, with the same bytes in each part to get the private key

d)

Collision attacks try to find two inputs producing the same hash

25.

Which of the following tools can be used for passive OS fingerprinting?

a)

nmap

b)

tcpdump

c)

tracert

d)

ping

26.

Which of the following describes the characteristics of a Boot Sector Virus?

a)

Modifies directory table entries so that directory entries point to the virus code instead of the actual program.

b)

Moves the MBR to another location on the RAM and copies itself to the original location of the MBR.

c)

Moves the MBR to another location on the hard disk and copies itself to the original location of the MBR.

d)

Overwrites the original MBR and only executes the new virus code.

27.

Your company was hired by a small healthcare provider to perform a technical assessment on the network. What is the best approach for discovering vulnerabilities on a Windows-based computer?

a)

Use the built-in Windows Update tool

b)

Use a scan tool like Nessus

c)

Check MITRE.org for the latest list of CVE findings

d)

Create a disk image of a clean Windows Installation

28.

Which of the following is a command line packet analyzer similar to GUI-based WireShark?

a)

nessus

b)

tcpdump

c)

ethereal

d)

jack the ripper

29.

DHCP snooping is a great solution to prevent rogue DHCP servers on your network. Which security feature on switchers leverages the DHCP snooping database to help prevent man-in-the-middle attacks?

a)

Spanning tree

b)

Dynamic ARP Inspection (DAI)

c)

Port security

d)

Layer 2 Attack Prevention Protocol (LAPP)

30.

Bob, a network administrator at BigUniversity, realized that some students are connecting their notebooks in the wired network to have Internet access. In the university campus, there are many Ethernet ports available for professors and authorized visitors but not for students.

He identified this when the IDS alerted for malware activities in the network. What should Bob do to avoid this problem?

a)

Disable unused ports in the switches

b)

Separate students in a different VLAN

c)

Use the 802.1x protocol

d)

Ask students to use the wireless network

31.

A company’s policy requires employees to perform file transfers using protocols which encrypt traffic. You suspect some employees are still performing file transfers using unencrypted protocols because the employees do not like changes. 

You have positioned a network sniffer to capture traffic from the laptops used by employees in the data ingest department. Using Wireshark to examine the captured traffic, which command can be used as display filter to find unencrypted file transfers?

a)

tcp.port = = 21

b)

tcp.port = 23

c)

tcp.port = = 21 | | tcp.port = = 22

d)

tcp.port! = 21

32.

You just set up a security system in your network. 

In what kind of system would you find the following string of characters used as a rule within its configuration? alert tcp any any -> 192.168.100.0/24 21 (msg: ““FTP on the network!””;)

a)

A firewall IPTable

b)

FTP Server rule

c)

A router IPTable

d)

An Intrusion Detection System

33.

Which of the following program infects the system boot sector and the executable files at the same time?

a)

Polymorphic virus

b)

Stealth virus

c)

Multipartite virus

d)

Macro virus

34.

To determine if a software program properly handles a wide range of invalid input, a form of automated testing can be used to randomly generate invalid input in an attempt to crash the program. What term is commonly used when referring to this type of testing?

a)

Randomizing

b)

Bounding

c)

Mutating

d)

Fuzzing

35.

An Intrusion Detection System (IDS) has alerted the network administrator to a possibly malicious sequence of packets sent to a Web server in the network’s external DMZ. The packet traffic was captured by the IDS and saved to a PCAP file. What type of network tool can be used to determine if these packets are genuinely malicious or simply a false positive?

a)

Protocol analyzer

b)

Network Sniffer

c)

Intrusion Prevention System (IPS)

d)

Vulnerability scanner

36.

The Heartbleed bug was discovered in 2014 and is widely referred to under MITRE’s Common Vulnerabilities and Exposures (CVE) as CVE-2014-0160. This bug affects the OpenSSL implementation of the Transport Layer Security (TLS) protocols defined in RFC6520. 

What type of key does this bug leave exposed to the Internet making exploitation of any compromised system very easy

a)

Public

b)

Private

c)

Shared

d)

Root

37.

Why should the security analyst disable/remove unnecessary ISAPI filters?

a)

To defend against social engineering attacks

b)

To defend against webserver attacks

c)

To defend against jailbreaking

d)

To defend against wireless attacks

38.

Which of the following is a component of a risk assessment?

a)

Administrative safeguards

b)

Physical Security

c)

DMZ

d)

Logical Interface

39.

CompanyXYZ has asked you to assess the security of their perimeter email gateway. From your office in New York, you craft a specially formatted email message and send it across the Internet to an employee of CompanyXYZ. The employee of CompanyXYZ is aware of your test. Your email message looks like this:

From: jim_miller@companyxyz.com

To: michelle_saunders@companyxyz.com Subject: Test message Date: 4/3/2017 14:37 The employee of CompanyXYZ receives your email message.


This proves that CompanyXYZ’s email gateway doesn’t prevent what?

a)

Email Masquerading

b)

Email Harvesting

c)

Email Phishing

d)

Email Spoofing

40.

Bob, a system administrator at TPNQM SA, concluded one day that a DMZ is not needed if he properly configures the firewall to allow access just to servers/ports, which can have direct internet access, and block the access to workstations. Bob also concluded that DMZ makes sense just when a stateful firewall is available, which is not the case of TPNQM SA. In this context, what can you say?

a)

Bob can be right since DMZ does not make sense when combined with stateless firewalls

b)

Bob is partially right. He does not need to separate networks if he can create rules by destination IPs, one by one

c)

Bob is totally wrong. DMZ is always relevant when the company has internet servers and workstations

d)

Bob is partially right. DMZ does not make sense when a stateless firewall is available

41.

The “Gray-box testing” methodology enforces what kind of restriction?

a)

Only the external operation of a system is accessible to the tester.

b)

The internal operation of a system is only partly accessible to the tester.

c)

The internal operation of a system is completely known to the tester.

d)

The internal operation of a system is completely known to the tester.

42.

When analyzing the IDS logs, the system administrator noticed an alert was logged when the external router was accessed from the administrator’s Computer to update the router configuration. What type of an alert is this?

a)

False negative

b)

True negative

c)

True positive

d)

False positive

43.

A large company intends to use Blackberry for corporate mobile phones and a security analyst is assigned to evaluate the possible threats. 

The analyst will use the Blackjacking attack method to demonstrate how an attacker could circumvent perimeter defenses and gain access to the Prometric Online Testing – Reports https://ibt1.prometric.com/users/custom/report_queue/rq_str... corporate network. 

What tool should the analyst use to perform a Blackjacking attack?

a)

Paros Proxy

b)

BBProxy

c)

Bloover

d)

BBcrack

44.

When you are getting information about a web server, it is very important to know the HTTP Methods (GET, POST, HEAD, PUT, DELETE, TRACE) that are available because there are two critical methods (PUT and DELETE). PUT can upload a file to the server and DELETE can delete a file from the server. You can detect all these methods (GET, POST, HEAD, DELETE, PUT, TRACE) using NMAP script engine. 

What Nmap script will help you with this task?

a)

http-methods

b)

http enum

c)

http-headers

d)

http-git

45.

Todd has been asked by the security officer to purchase a counter-based authentication system. Which of the following best describes this type of system?

a)

A biometric system that bases authentication decisions on behavioral attributes.

b)

A biometric system that bases authentication decisions on behavioral attributes.

c)

An authentication system that creates one-time passwords that are encrypted with secret keys.

d)

An authentication system that uses passphrases that are converted into virtual passwords.

46.

Which of the following is a low-tech way of gaining unauthorized access to systems?

a)

Social Engineering

b)

Eavesdropping

c)

Scanning

d)

Sniffing

47.

Which system consists of a publicly available set of databases that contain domain name registration contact information?

a)

WHOIS

b)

CAPTCHA

c)

IANA

d)

IETF

48.

Why is a penetration test considered to be more thorough than vulnerability scan?

a)

Vulnerability scans only do host discovery and port scanning by default

b)

A penetration test actively exploits vulnerabilities in the targeted infrastructure, while a vulnerability scan does not typically involve active exploitation.

c)

It is not – a penetration test is often performed by an automated tool, while a vulnerability scan requires active engagement.

d)

The tools used by penetration testers tend to have much more comprehensive vulnerability databases.

49.

Bob received this text message on his mobile phone: “Hello, this is Scott Smelby from the Yahoo Bank. Kindly contact me for a vital transaction on: scottsmelby@yahoo.com”.

Which statement below is true? 

a)

This is a scam as everybody can get a @yahoo address, not the Yahoo customer service employees.

b)

This is a scam because Bob does not know Scott.

c)

Bob should write to scottmelby@yahoo.com to verify the identity of Scott.

d)

This is probably a legitimate message as it comes from a respectable organization.

50.

env x=’(){ :;};echo exploit’ bash –c ‘cat/etc/passwd’

What is the Shellshock bash vulnerability attempting to do on a vulnerable Linux host? 

a)

Removes the passwd file

b)

Changes all passwords in passwd

c)

Add new user to the passwd file

d)

Display passwd content to prompt

51.

Which of the following is assured by the use of a hash?

a)

Authentication

b)

Confidentiality

c)

Availability

d)

Integrity

52.

Which results will be returned with the following Google search query? site:target.com – site:Marketing.target.com accounting

a)

Results from matches on the site marketing.target.com that are in the domain target.com but do not include the word accounting.

b)

Results matching all words in the query.

c)

Results for matches on target.com and Marketing.target.com that include the word “accounting”

d)

Results matching “accounting” in domain target.com but not on the site Marketing.target.com

53.

Email is transmitted across the Internet using the Simple Mail Transport Protocol. SMTP does not encrypt email, leaving the information in the message vulnerable to being read by an unauthorized person. SMTP can upgrade a connection between two mail servers to use TLS. Email transmitted by SMTP over TLS is encrypted. What is the name of the command used by SMTP to transmit email over TLS?

a)

OPPORTUNISTICTLS

b)

UPGRADETLS

c)

FORCETLS

d)

STARTTLS

54.

In the field of cryptanalysis, what is meant by a “rubber-hose” attack?

a)

Forcing the targeted keystream through a hardware-accelerated device such as an ASIC.

b)

A backdoor placed into a cryptographic algorithm by its creator.

c)

Extraction of cryptographic secrets through coercion or torture.

d)

Attempting to decrypt ciphertext by making logical assumptions about the contents of the original plaintext.

55.

You are a Network Security Officer. You have two machines. The first machine (192.168.0.99) has snort installed, and the second machine (192.168.0.150) has kiwi syslog installed. You perform a syn scan in your network, and you notice that kiwi syslog is not receiving the alert message from snort. You decide to run wireshark in the snort machine to check if the messages are going to the kiwi syslog machine. What Wireshark filter will show the connections from the snort machine to kiwi syslog machine?

a)

tcp.srcport= = 514 && ip.src= = 92.168.0.99

b)

tcp.srcport= = 514 && ip.src= = 192.168.150

c)

tcp.dstport= = 514 && ip.dst= = 192.168.0.99

d)

tcp.dstport= = 514 && ip.dst= = 192.168.0.150

56.

What two conditions must a digital signature meet? 

a)

Has to be the same number of characters as a physical signature and must be unique.

b)

Has to be unforgeable, and has to be authentic.

c)

Must be unique and have special characters.

d)

Has to be legible and neat.

57.

 A company’s security policy states that all Web browsers must automatically delete their HTTP browser cookies upon terminating. What sort of security breach is this policy attempting to mitigate?

a)

Attempts by attackers to access the user and password information stored in the company’s SQL database.

b)

Attempts by attackers to access Web sites that trust the Web browser user by stealing the user’s authentication credentials.

c)

Attempts by attackers to access password stored on the user’s computer without the user’s knowledge.

d)

Attempts by attackers to determine the user’s Web browser usage patterns, including when sites were visited and for how long.

58.

What is correct about digital signatures?

a)

A digital signature cannot be moved from one signed document to another because it is the hash of the original document encrypted with the private key of the signing party.

b)

Digital signatures may be used in different documents of the same type.

c)

A digital signature cannot be moved from one signed document to another because it is a plain hash of the document content.

d)

Digital signatures are issued once for each user and can be used everywhere until they expire.

59.

An attacker with access to the inside network of a small company launches a successful STP manipulation attack. What will he do next? 

a)

He will create a SPAN entry on the spoofed root bridge and redirect traffic to his computer.

b)

He will activate OSPF on the spoofed root bridge.

c)

He will repeat this action so that it escalates to a DoS attack.

d)

He will repeat the same attack against all L2 switches of the network.

60.

You have gained physical access to a Windows 2008 R2 server which has an accessible disc drive. When you attempt to boot the server and log in, you are unable to guess the password. In your toolkit, you have an Ubuntu 9.10 Linux LiveCD. Which Linux-based tool can change any user’s password or activate disabled Windows accounts? 

a)

John the Ripper

b)

SET C

c)

CHNTPW

d)

Cain & Abel

61.

Scenario1:

1. Victim opens the attacker's web site.

2. Attacker sets up a web site which contains interesting and attractive content like 'Do you want to make $1000 in a day?'.

3.  Victim clicks to the interesting and attractive content URL.

4.   Attacker creates a transparent 'iframe' in front of the URL which victim attempts to click, so victim thinks that he/she clicks to the 'Do you want to make $1000 in a day?' URL but actually he/she clicks to the content or URL that exists in the transparent 'iframe' which is setup by the attacker.

 

What is the name of the attack which is mentioned in the scenario? 

a)

A. Session Fixation

b)

B. HTML Injection

c)

C. Adware

d)

D. Clickjacking attack

62.

To reach a bank web site, the traffic from workstations must pass through a firewall. You have been asked to review the firewall configuration to ensure that workstations in network 10.10.10.0/24 can only reach the bank web site 10.20.20.1 using https.

Which of the following firewall rules meets this requirement? 

a)

A. If (source matches 10.10.10.0/24 and destination matches 10.20.20.1 and port matches 443) then permit

b)

B. If (source matches 10.10.10.0/24 and destination matches 10.20.20.1 and port matches 80 or 443) then permit

c)

C. If (source matches 10.20.20.1 and destination matches 10.10.10.0/24 and port matches 443) then permit

d)

D. If (source matches 10.10.10.0 and destination matches 10.20.20.1 and port matches 443) then permit