Font size
WorksheetsCanvas 9.0
Total questions: 30
Worksheet time: 16mins
Alula is exploring the implementation of a ZTA framework at his organization. Which of the following best represents considerations he is most likely to keep in the forefront? Select two.
Ensure systems are in place such that no external entity is trusted, not even remote workers.
Ensure subjects and systems are only able to access resources within their zone.
Ensure the PEP is configured to properly provide input into the PDP.
Focus on authentication and authorization.
Do not implicitly trust internal entities.
An associate is hired by a close friend to learn information technology (IT) administration skills on the job. The associate finds a 24-port hub in a cabinet and is considering using it in a small network setting for a lab environment that will be accessed using Telnet. If the associate uses the hub, which mitigation principle would be violated?
Segmentation
Isolation
Device placement
Selection of effective controls
Budgetary constraints are preventing a small company from upgrading their faulty wireless access points until the following month. An employee needs to synchronize the password on their company-issued laptop, so they disconnect the Ethernet cable from the desktop computer and plug it into the laptop. However, no connectivity is established with the laptop. What is the most likely reason?
The switch port has port security enabled.
The IP address on the laptop is incorrect.
The switch port needs to be enabled.
The DHCP server is currently offline.
Port mirroring needs to be enabled.
A company decided to remove their FIM installation for reasons that could be justified and opted to deploy an alternative solution. Which of the following represents the most likely reason why they removed their FIM installation?
They wanted a system capable of monitoring both authorized and unauthorized changes to files.
The logs generated were too generic without providing detailed and specific information.
It was not effective at identifying critical changes to files.
The system was generating more information than could be effectively analyzed.
A company has adopted the policy of placing servers in different VLANs. What security benefit can they derive from this practice? Select two.
It is easier to implement a DMZ when VLANs are used.
Allows for sensitive data to only be transported to members of the VLAN.
IEEE 802.1Q provides features that some security appliances can take advantage of.
Can be used to enforce firewall or IDS inspection during communications between servers.
VLANs help facilitate the implementation of security zones to help prevent unauthorized access.
A company has multiple branches. They use a VPN to encrypt all traffic to and from the central office. As they continue to grow, they've noticed a reduction in performance at the central office. Which of the following represents a possible short-term solution? Select two.
Upgrade the VPN concentration.
Use site-to-site VPN connections.
Use a full funnel implementation.
Do not encrypt web-surfing traffic.
Use a split-funnel implementation.
A company implements a web filtering solution. However, they notice that some websites contain suspicious pages that are not being blocked. As a result, they adopt a solution that blocks all the pages for a given website. What solution did the company most likely implement?
Web application firewall
Web security server
DNS filtering
URL scanning
Website filtering
A company is growing and now has 200 procurement agents who buy a wide variety of products on behalf of many large corporations. They often access a series of approved vendor websites, but access speeds seem to be deteriorating with every new agent they hire. Which of the following can they implement to help improve performance and security?
Secure load-balancing technology for the local network
A web application firewall
A reverse proxy server
A forward proxy server
A company launched a digital product that is selling so well that their web server is unable to keep up with the requests. They are evaluating the possibility of adding a second web server along with a load balancer. What type of load balancer should they add, and what security benefit can it provide?
Layer 4 load balancer; it can filter traffic to prevent access to malicious websites based on the URL.
Layer 7 load balancer; it can detect and prevent protocol attacks directed at the server.
Layer 7 load balancer; it can detect and stop attacks directed at an application.
Layer 4 load balancer; it can hide HTTP error pages or remove server headers from HTTP responses.
A cyberthreat agency concludes traffic is being sent to an attacker's server based on the characteristics of the traffic. They notify the authorities who then orchestrate a plan to redirect the traffic away from the attacker's server for further analysis. Which of the following most likely represents the strategy the authorities implemented to redirect traffic?
Lure
Sinkhole
Honeynet
Deflection
Disruption
An employee fully recovers from an accident and returns to their previous position after 12 months. However, when the employee tries to connect to the network using their wireless laptop, access is not granted. Which of the following most likely describes why access was not granted?
The company implemented an NAC system, so the laptop needs an NAC agent.
Port security prevented the laptop from successfully connecting.
The laptop needs an operating system upgrade.
The laptop is connecting to the wrong LAN.
12. Gino needs to procure a networking appliance that will filter traffic to permit or deny certain packets. At the very least, he should buy a firewall that is capable of filtering traffic based on which of the following parameters?
Protocol
IP address
MAC address
Port number
Specific user-defined bit patterns
Heba configures a firewall rule to prevent traffic from Network A. However, some network services from Network A should be permitted but because of their source IP address they will be blocked by default. What type of firewall rule action should Heba apply?
Allow
Force Apply
Force Permit
Force Allow
Force Bypass
A junior technician configures a firewall. The network administrator then runs tests and analyzes the traffic to verify the firewall was configured as expected. The network administrator notices that the only traffic allowed to enter the internal network is return traffic that was requested from an internal source. Which of the following best describes this type of packet filtering?
Active packet filtering
Dynamic packet filtering
One-way packet filtering
Two-way packet filtering
Stateful packet filtering
Karim is promoted and told he is being given permission to access a secure server. However, as soon he attempts to log in, the host-based IPS on the server issues an alert and prevents him from logging in. Why did the IPS deny access?
The IPS was connected incorrectly; it should have been connected to a port on the switch.
When analyzing the traffic, the IPS compared it against the signatures and found a match.
Because Karim logging into the secure server is not an activity regularly seen on the network.
The signature file on the IDS needs to be updated to indicate Karim can now access the server.
Lakia needs to implement a web filtering solution that will also filter traffic from remote users. Which of the following options is Lakia most likely to implement?
Centralized proxy scanning
Agent-based scanning
Browser scanning
Cloud scanning
Mosa owns a small business. One of his employees spends at least 4 hours a day searching for wholesale products to sell in the store and through the website. In the short term, Mosa wants to implement a quick, inexpensive, and easy-to-install solution to help filter and block potentially suspicious websites. What would you recommend?
Centralized proxy scanning
Browser scanning
Web application firewall
Web security server
Agent-based scanning
A network administrator is implementing a DMZ with input from a consultant. The consultant recommends using two firewalls instead of one. Why would this recommendation be made? Select three.
The second firewall eliminates the requirement to use a jump server.
It helps reduce the restrictions imposed by a potential single point of failure.
It is more difficult for an attacker to breach two separate firewalls than just one.
Load balancing to equally distribute incoming and outgoing traffic between the firewalls.
It facilitates the creation of a screened subnet to limit the exposure from external networks.
A network administrator specifies a statement that reads "Deny management traffic from untrusted networks to Network B." What type of firewall is the network administrator most likely configuring?
A. A rule-based firewall
B. A WAF
C. A Layer 7 firewall
D. A policy-based firewall
E. A content-filtering firewall
A router connects networks A, B, and C. A threat actor is successful in breaching the security protocols and breaks into network A. From network A, the threat actor spoofs the source IP address as if it is originating from network C and sends traffic to network B. How can this condition be mitigated?
Enable port security on the router.
Use an ARP detection appliance.
Apply an inbound ACL on the router.
Enable layer 4 firewall capabilities on the router.
A security company deliberately creates an Internet-facing network containing some servers with a few vulnerabilities. Why would the company do this?
To determine if the attacker activities are of the low-interaction or high-interaction variety.
To test whether threat actors can use it as a vector to access the internal secure network.
To track and record the number of successful versus failed login attempts.
To study the methods used by attackers.
To make the internal network invisible.
The security team of a large company is debating the type of security devices they should deploy. They have a limited budget and cannot buy all the devices stipulated by the requirements of the individual attendees. If they agree on one device capable of performing several security functions, what type of device are they most likely to deploy?
WAF
UTM
IPS
Proxy Server
Protocol filtering firewall
Two switches, S1 and S2, are connected to each other. To realize segmentation and greater security, each switch has three VLANs configured (students, faculty, and IT). When a faculty endpoint connected to S1 communicates with a faculty endpoint connected to S2, how does S2 know the message belongs to the faculty VLAN?
S1 tags the message, indicating it belongs to the faculty VLAN when sending it to S2.
A logical VPN implemented between the two switches tags the message when sending it.
S1 uses the vendor-neutral IEEE 802.11 protocol to tag the message when sending it.
A router needs to be used between the switches to ensure successful delivery of VLAN messages.
Which of the following are true statements regarding the differences or similarities between EDR and XDR? Select two.
XDR tools aggregate data from endpoints, network appliances, and cloud repositories.
EDR tools aggregate data from endpoints, network devices, servers, and email systems.
EDR uses a cloud-based analysis engine whereas XDR uses a local server as the analysis engine.
EDR is more robust and provides greater protection than XDR.
XDR gives a higher level of visibility and context to incidences.
Which of the following mitigation principles used to secure information is a true statement? Select two.
Comparing the current state of information security with recommended controls is gap analysis.
Applying security measures to reduce unnecessary vulnerabilities is configuration enforcement.
Keeping multiple instances of an attack surface separate is considered segmentation.
Dividing a network into multiple subnets is achieved through address analysis.
Physically locating important devices in secure locations is isolation.
Which of the following represents security criteria a NAC system is most likely to enforce? Select two.
IPv4 and IPv6 addresses
Operating system version
Anti-malware software
Operating system patches
Active Directory agent
Which of the following statements are true regarding software firewalls versus hardware firewalls? Select two.
A hardware firewall provides less of a target for attackers.
A hardware firewall is more expensive than a software firewall.
A software firewall is implemented virtually within a hardware firewall.
A software firewall requires more effort to configure because it has more features.
A software firewall runs on a computer whereas a hardware firewall runs on a router.
Which one of the two-part answers best completes the statement? Security appliances and software are ________ while a secure infrastructure design is ________.
reactive; proactive
soft targets; more difficult to breach
physical implementations; best implemented virtually
flexible and dynamic; rigid and static
You are asked to design a network for a medium-sized company with three tiers of security requirements for the IT staff. Which of the following statements are you most likely to agree with?
Keep all servers (web, database, file, backup, departmental, etc.) in a secure dedicated network.
Where applicable, use automated provisioning to simplify the configuration of networks.
Do not use logical segmentation, especially if users are scattered.
Physically isolate all three networks.
You are responsible for ensuring the company's servers are secure. Which of the following policies should you implement?
Apply patches.
Monitor the server.
Remove unnecessary software.
Physically secure the server.
All of these.
