wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

DECEMBER CMA CISCO CYBERSECURITY ESSENTIALS EXAM

Total questions: 60

Worksheet time: 30mins

Name
Class
Date
1.

Which type of malware is designed to replicate itself and spread to other computers without requiring a host program or human interaction?

a)

Virus

b)

Worm

c)

Trojan horse

d)

Spyware

2.

What is the primary difference between a vulnerability and an exploit?

a)

A vulnerability is a weakness in a system, while an exploit is code or technique that takes advantage of that weakness

b)

A vulnerability is software-based, while an exploit is hardware-based

c)

A vulnerability affects networks, while an exploit affects individual computers

d)

A vulnerability is intentional, while an exploit is accidental

3.

An organization discovers that an attacker has been monitoring their network traffic to capture sensitive information such as login credentials and financial data. What type of attack is being described?

a)

Sniffing attack

b)

DoS attack

c)

Phishing attack

d)

Buffer overflow attack

4.

Which type of social engineering attack involves an attacker observing someone entering confidential information such as a password or PIN code?

a)

Tailgating

b)

Shoulder surfing

c)

Pretexting

d)

Baiting

5.

Which security principle ensures that only authorized individuals can access specific resources or information?

a)

Accountability

b)

Confidentiality

c)

Integrity

d)

Availability

6.

An organization implements multiple layers of security controls including firewalls, intrusion detection systems, antivirus software, and access controls. What security strategy is being employed?

a)

Perimeter security

b)

Defense in depth

c)

Least privilege

d)

Security through obscurity

7.

Which type of threat actor is typically motivated by personal beliefs, ideologies, or causes and uses cyberattacks to promote their agenda?

a)

Script kiddies

b)

Hacktivists

c)

Insider threats

d)

Cybercriminals

8.

A company evaluates a security risk and determines that the cost of implementing controls exceeds the potential loss from the threat. Management decides to acknowledge the risk and take no action. Which risk management strategy is this?

a)

Risk avoidance

b)

Risk transfer

c)

Risk reduction

d)

Risk acceptance

9.

What information does the protocol field in an IPv4 header identify?

a)

The destination port number

b)

The upper-layer protocol such as TCP or UDP

c)

The type of service requested

d)

The total length of the packet

10.

Which protocol is commonly exploited in amplification and reflection DDoS attacks because it operates without requiring a connection establishment?

a)

TCP

b)

ICMP

c)

UDP

d)

ARP

11.

What is the purpose of the sequence number field in a TCP segment header?

a)

To identify the source port

b)

To ensure data is reassembled in the correct order

c)

To specify the window size

d)

To indicate the type of TCP connection

12.

An attacker sends a gratuitous ARP message on the local network associating their MAC address with the IP address of the default gateway. What type of attack is the threat actor launching?

a)

DNS poisoning

b)

ARP spoofing

c)

DHCP starvation

d)

MAC flooding

13.

What is the purpose of implementing DHCP snooping on a network switch?

a)

To encrypt all DHCP traffic

b)

To prevent rogue DHCP servers from providing IP configuration to clients

c)

To increase the speed of DHCP assignments

d)

To allow multiple DHCP servers on the same subnet

14.

Which type of malware is designed to hide its existence and provide privileged access to a computer while masking its presence from security tools?

a)

Worm

b)

Virus

c)

Rootkit

d)

Adware

15.

What is the primary goal of a SQL injection attack?

a)

To overwhelm a database server with requests

b)

To manipulate database queries to gain unauthorized access to data

c)

To encrypt database files and demand ransom

d)

To replicate the attack across multiple database servers

16.

An attacker floods a switch's MAC address table with thousands of fake MAC addresses, causing the switch to behave like a hub and broadcast traffic to all ports. What type of attack is this?

a)

MAC address spoofing

b)

CAM table overflow

c)

VLAN hopping

d)

STP manipulation

17.

An attacker sets up a fake wireless access point with the same SSID as a legitimate corporate network to intercept user credentials and data. What type of attack is this?

a)

Evil twin attack

b)

Jamming attack

c)

Wardriving

d)

Bluejacking

18.

What is the purpose of disabling SSID broadcasting on a wireless access point?

a)

To encrypt all wireless traffic

b)

To make the network slightly less visible to casual users

c)

To prevent all unauthorized access

d)

To increase wireless signal strength

19.

Which wireless security protocol introduced the use of TKIP (Temporal Key Integrity Protocol) to improve security over WEP?

a)

WPA

b)

WPA2

c)

WPA3

d)

WEP2

20.

What is the primary function of a site survey when deploying a wireless network?

a)

To identify the number of users who will connect

b)

To determine optimal access point placement and identify sources of interference

c)

To configure encryption settings on all devices

d)

To establish MAC address filtering rules

21.

What is the main difference between the implementation of IDS and IPS devices?

a)

An IDS needs to be deployed with a firewall device, whereas an IPS can replace a firewall.

b)

An IDS can negatively impact the packet flow, whereas IPS cannot.

c)

An IDS uses signature-based technology to detect malicious packets, whereas an IPS uses profile-based technology.

d)

An IDS would allow malicious traffic to pass before it is addressed, whereas an IPS stops it immediately.

22.

What protocol provides authentication, integrity, and confidentiality services and is a type of VPN?

a)

IPsec

b)

ESP

c)

MD5

d)

AES

23.

Which firewall feature is used to ensure that packets coming into a network are legitimate responses to requests initiated from internal hosts?

a)

Stateful packet inspection

b)

Packet filtering

c)

URL filtering

d)

Application filtering

24.

What networking monitoring technology enables a switch to copy and forward traffic sent and received on multiple interfaces out another interface towards a network analysis device?

a)

Network tap

b)

Port Mirroring

c)

SNMP

d)

NetFlow

25.

When a user makes changes to the settings of a Windows system, where are these changes stored?

a)

Control Panel

b)

Boot.ini

c)

Win.ini

d)

Registry

26.

What technology was created to replace the BIOS program on modern personal computer motherboards?

a)

RAM

b)

UEFI

c)

MBR

d)

CMOS

27.

Which command is used to manually query a DNS server to resolve a specific host name?

a)

nslookup

b)

ping

c)

ipconfig

d)

tracert

28.

How much RAM is addressable by a 32-bit version of Windows?

a)

8 GB

b)

4 GB

c)

32 GB

d)

16 GB

29.

A system administrator issues the command ps on a server that is running the Linux operating system. What is the purpose of this command?

a)

To change file permissions

b)

To display the contents of the current directory

c)

To process a new task

d)

To list the processes currently running in the system

30.

What type of tool is used by a Linux administrator to attack a computer or network to find vulnerabilities?

a)

Intrusion detection system

b)

Firewall

c)

Malware analysis

d)

PenTesting

31.

What is a benefit of Linux being an open source operating system?

a)

Linux distributions must include free support without cost.

b)

Linux distributions are simpler operating systems since they are not designed to be connected to a network.

c)

Linux distributions are maintained by a single organization.

d)

Linux distribution source code can be modified and then recompiled.

32.

Which method can be used to harden a device?

a)

Force periodic password changes.

b)

Allow users to re-use old passwords.

c)

Allow default services to remain enabled.

d)

Allow USB auto-detection.

33.

Which technology might increase the security challenge to the implementation of IoT in an enterprise environment?

a)

Cloud computing

b)

Network bandwidth

c)

CPU processing speed

d)

Data storage

34.

What is a host-based intrusion detection system (HIDS)?

a)

It identifies potential attacks and sends alerts but does not stop the traffic.

b)

It combines the functionalities of antimalware applications with firewall protection.

c)

It detects and stops potential direct attacks but does not scan for malware.

d)

It is an agentless system that scans files on a host for potential malware.

35.

Which statement describes the term attack surface?

a)

It is the total sum of vulnerabilities in a system that is accessible to an attacker.

b)

It is the network interface where attacks originate.

c)

It is the total number of attacks towards an organization within a day.

d)

It is the group of hosts that experiences the same attack.

36.

What type of lock is recommended to secure an office door?

a)

Cable lock

b)

Keyed entry lock

c)

Cipher lock

d)

Security cage

37.

What type of cybersecurity laws protect you from an organization that might want to share your sensitive data?

a)

Privacy laws

b)

Intellectual property laws

c)

Cybercrime laws

d)

E-discovery laws

38.

An organization allows employees to work from home two days a week. Which technology should be implemented to ensure data confidentiality as data is transmitted?

a)

SHS

b)

VPN

c)

VLAN

d)

RAID

39.

Which of the following are foundational principles of the cybersecurity domain? (choose three)

a)

Integrity

b)

Availability

c)

Confidentiality

d)

Encryption

e)

Policy

40.

Which two methods help to ensure data integrity? (choose two)

a)

Data consistency checks

b)

Hashing

c)

Repudiation

d)

Authorization

e)

Privacy

41.

Which device is usually the first line of defense in a layered defense-in-depth approach?

a)

Access layer switch

b)

Edge router

c)

Internal router

d)

Firewall

42.

What is the benefit of a defense-in-depth approach?

a)

Only a single layer of security at the network core is required.

b)

All network vulnerabilities are mitigated.

c)

The need for firewalls is eliminated.

d)

The effectiveness of other security measures is not impacted when a security mechanism fails.

43.

What component of a security policy explicitly defines the type of traffic allowed on a network and what users are allowed and not allowed to do?

a)

Identification and authentication policies

b)

Password policies

c)

Acceptable use policies

d)

Remote access policies

44.

An administrator discovers that a user is accessing a newly established website that may be detrimental to company security. What action should the administrator take first in terms of the security policy?

a)

Revise the AUP immediately and get all users to sign the updated AUP.

b)

Create a firewall rule blocking the respective website.

c)

Immediately suspend the network privileges of the user.

d)

Ask the user to stop immediately and inform the user that this constitutes grounds for dismissal.

45.

Which service will resolve a specific web address into an IP address of the destination web server?

a)

DHCP

b)

NTP

c)

ICMP

d)

DNS

46.

Mutual authentication can prevent which type of attack?

a)

Man-in-the-middle

b)

Wireless sniffing

c)

Wireless IP spoofing

d)

Wireless poisoning

47.

Which utility uses the Internet Control Messaging Protocol?

a)

RIP

b)

DNS

c)

Ping

d)

NTP

48.

What is the purpose of a DMZ?

a)

It analyzes traffic for intrusion attempts and sends reports to management stations.

b)

It creates an encrypted and authenticated tunnel for remote hosts to access the internal network.

c)

It provides secure connectivity for clients that connect to the internal network through the wireless LAN.

d)

It allows external hosts to access specific company servers while maintaining the security restrictions for the internal network.

49.

Which component is a pillar of the zero trust security approach that focuses on the secure access of devices, such as servers, printers, and other endpoints, including devices attached to IoT?

a)

Workforce

b)

Workflows

c)

Workloads

d)

Workplace

50.

What Windows utility should be used to configure password rules and account lockout policies on a system that is not part of a domain?

a)

Event Viewer security log

b)

Local Security Policy tool

c)

Active Directory Security tool

d)

Computer Management

51.

What is the purpose of the network security accounting function?

a)

To require users to prove who they are

b)

To determine which resource a user can access

c)

To keep track of the actions of a user

d)

To provide challenge and response questions

52.

Which AAA component can be established using token cards?

a)

Accounting

b)

Authorization

c)

Auditing

d)

Authentication

53.

In applying an ACL to a router interface, which traffic is designated as outbound?

a)

Traffic that is leaving the router and going towards the destination host

b)

Traffic for which the router can find no routing table entry

c)

Traffic that is going from the destination IP address into the router

d)

Traffic that is coming from the source IP address into the router

54.

What wild card mask will match network 172.16.0.0 through 172.19.0.0?

a)

0.0.3.225

b)

0.252.255.255

c)

0.0.255.255

d)

0.3.255.255

55.

What is the quickest way to remove a single ACE from a named ACL?

a)

Create a new ACL with a different number and apply the new ACL to the router interface

b)

Use the no keyword and the sequence number of the ACE to be removed

c)

Use the no access-list command to remove the entire ACL, then recreate it without the ACE.

d)

Copy the ACL into a text editor, remove the ACE, then copy the ACL back into the router.

56.

Which scenario would cause an ACL misconfiguration and deny all traffic?

a)

Apply a named ACL to a VTY line.

b)

Apply an ACL that has all deny ACE statements.

c)

Apply a standard ACL in the inbound direction.

d)

Apply a standard ACL using the ip access-group out command.

57.

What is one benefit of using a next-generation firewall rather than a stateful firewall?

a)

Support of logging

b)

Reactive protection against internet threats

c)

Support of TCP-based packet filtering

d)

Integrated use of an intrusion prevention system (IPS)

58.

What are two characteristics of an application gateway firewall (Choose two.)

a)

Uses a simple policy table look-up to filter traffic based on Layer 3 and Layer 4 information.

b)

Analyzes traffic at Layers 3, 4, 5, and 7 of the OSI model.

c)

Provides an integrated intrusion prevention and detection feature.

d)

Uses connection information maintained in a state table and analyzes traffic at OSI Layers 3, 4, and 5.

e)

Performs most filtering and firewall control in software.

59.

Which type of traffic is usually blocked when implementing a demilitarized zone?

a)

Traffic that is returning from the DMZ network and traveling to the private network

b)

Traffic originating from the private network and traveling to the DMZ network

c)

Traffic originating from the DMZ network and traveling to the private network

d)

Traffic that is returning from the public network and traveling to the DMZ network

60.

When implementing a ZPF, which statement describes a zone?

a)

A zone is a group of hardened computers known as bastion hosts.

b)

A zone is a group of administrative devices that protect against rogue access point installations.

c)

A zone is a group of one or more devices that provide backup and disaster recovery mechanisms.

d)

A zone is a group of one or more interfaces that have similar functions or features.