wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

V12 exam

Total questions: 125

Worksheet time: 1hrs 3mins

Name
Class
Date
1.

What is a set of extensions to DNS that provide to DNS clients (resolvers) origin authentication, authenticated denial of existence and data integrity, but not availability or confidentiality?

a)

Zone transfer

b)

Resource transfer

c)

Resource records

d)

DNSSEC

2.

Jack sent an email to Jenny with a business proposal. Jenny accepted it and fulfilled all her obligations. Jack suddenly refused his offer when everything was ready and said that he had never sent an email. Which of the following digital signature properties will help Jenny prove that Jack is lying?

a)

Integrity

b)

Non-Repudiation

c)

Authentication

d)

Confidentiality

3.

Which of the following best describes a software firewall?

a)

Software firewall is placed between the anti-virus application and the IDS components of the operating system.

b)

Software firewall is placed between the desktop and the software components of the operating system.

c)

Software firewall is placed between the router and the networking components of the operating system.

d)

Software firewall is placed between the normal application and the networking components of the operating system.

4.

What are the two main conditions for a digital signature?

a)

Unique and have special characters.

b)

It has to be the same number of characters as a physical signature and must be unique.

c)

Unforgeable and authentic.

d)

Legible and neat.

5.

Maria is surfing the internet and try to find information about Super Security LLC. Which

process is Maria doing?

a)

System Hacking

b)

Footprinting

c)

Scanning

d)

Enumeration

6.

Maria conducted a successful attack and gained access to a Linux server. She wants to

avoid that NIDS will not catch the succeeding outgoing traffic from this server in the future.

Which of the following is the best way to avoid detection of NIDS?

a)

Encryption

b)

Out of band signaling

c)

Alternate Data Streams

d)

Protocol Isolation

7.

Ivan, a black hat hacker, sends partial HTTP requests to the target webserver to exhaust

the target server’s maximum concurrent connection pool. He wants to ensure that all

additional connection attempts are rejected. What type of attack does Ivan implement?

a)

Fragmentation

b)

Slowloris

c)

Spoofed Session Flood

d)

HTTP GET/POST

8.

Define Metasploit module used to perform arbitrary, one-off actions such as port scanning,

denial of service, SQL injection and fuzzing?

a)

Payload Module

b)

Exploit Module

c)

NOPS Module

d)

Auxiliary Module

9.

Which regulation defines security and privacy controls for all U.S. federal information

systems except those related to national security?

a)

PCI-DSS

b)

NIST-800-53

c)

EU Safe Harbor

d)

HIPAA

10.

Ivan, a black hat hacker, tries to call numerous random numbers inside the company,

claiming he is from the technical support service. It offers company employee services in

exchange for confidential data or login credentials. What method of social engineering does

Ivan use?

a)

Reverse Social Engineering

b)

Tailgating

c)

Quid Pro Quo

d)

Elicitation

11.

John performs black-box testing. It tries to pass IRC traffic over port 80/TCP from a

compromised web-enabled host during the test. Traffic is blocked, but outbound HTTP traffic

does not meet any obstacles. What type of firewall checks outbound traffic?

a)

Stateful

b)

Packet Filtering

c)

Circuit

d)

Application

12.

Which layer 3 protocol allows for end-to-end encryption of the connection?

a)

SFTP

b)

IPsec

c)

SSL

d)

FTPS

13.

John, a cybersecurity specialist, received a copy of the event logs from all firewalls, Intrusion

Detection Systems (IDS) and proxy servers on a company's network. He tried to match all

the registered events in all the logs, and he found that their sequence didn't match. What

can cause such a problem?

a)

The security breach was a false positive

b)

A proper chain of custody was not observed while collecting the logs

c)

The network devices are not all synchronized

d)

The attacker altered events from the logs

14.

Which of the following command-line flags set a stealth scan for Nmap?

a)

-sT

b)

-sU

c)

-sS

d)

-sM

15.

The attacker posted a message and an image on the forum, in which he embedded a

malicious link. When the victim clicks on this link, the victim's browser sends an

authenticated request to a server. What type of attack did the attacker use?

a)

Cross-site request forgery

b)

Cross-site scripting

c)

SQL injection

d)

Session hijacking

16.

The Web development team is holding an urgent meeting, as they have received information

from testers about a new vulnerability in their Web software. They make an urgent decision

to reduce the likelihood of using the vulnerability. The team beside to modify the software

requirements to disallow users from entering HTML as input into their Web application.

Determine the type of vulnerability that the test team found?

a)

Cross-site scripting vulnerability

b)

Cross-site Request Forgery vulnerability

c)

SQL injection vulnerability

d)

Website defacement vulnerability

17.

You conduct an investigation and finds out that the browser of one of your employees sent

malicious requests that the employee knew nothing about. Identify the web page

vulnerability that the attacker used when the attack to your employee?

a)

File Inclusion Attack

b)

Cross-Site Request Forgery (CSRF)

c)

Command Injection Attacks

d)

Hidden Field Manipulation Attack

18.

Identify the type of jailbreaking which allows user-level access and does not allow iboot-

level access?

a)

Userland Exploit

b)

Bootrom Exploit

c)

iBootrom Exploit

d)

iBoot Exploit

19.

Determine the type of SQL injection:

SELECT * FROM user WHERE name = 'x' AND userid IS NULL; --';

a)

UNION SQL Injection

b)

End of Line Comment

c)

Tautology

d)

Illegal/Logically Incorrect Query

20.

Which of the following SQL injection attack does an attacker usually bypassing user

authentication and extract data by using a conditional OR clause so that the condition of the

WHERE clause will always be true?

a)

UNION SQLi

b)

Error-Based SQLi

c)

End-of-Line Comment

d)

Tautology

21.

Josh, a security analyst, wants to choose a tool for himself to examine links between data.

One of the main requirements is to present data using graphs and link analysis. Which of

the following tools will meet John's requirements?

a)

Metasploit

b)

Maltego

c)

Analyst's Notebook

d)

Palantir

22.

Determine the attack according to the following scenario:

Benjamin performs a cloud attack during the translation of the SOAP message in the TLS

layer. He duplicates the body of the message and sends it to the server as a legitimate user.

As a result of these actions, Benjamin managed to access the server resources to

unauthorized access.

a)

Wrapping

b)

Cloud Hopper

c)

Cloudborne

d)

Side-channel

23.

Determine what of the list below is the type of honeypots that simulates the real production

network of the target organization?

a)

High-interaction Honeypots

b)

Pure Honeypots

c)

Research honeypots

d)

Low-interaction Honeypots

24.

Which type of viruses tries to hide from antivirus programs by actively changing and

corrupting the chosen service call interruptions when they are being run?

a)

Stealth/Tunneling virus

b)

Cavity virus

c)

Polymorphic virus

d)

Tunneling virus

25.

Which of the following is not included in the list of recommendations of PCI Data Security

Standards?

a)

Do not use vendor-supplied defaults for system passwords and other security

parameters

b)

Rotate employees handling credit card transactions on a yearly basis to

different departments

c)

Protect stored cardholder data

d)

Encrypt transmission of cardholder data across open, public networks

26.

Philip, a cybersecurity specialist, needs a tool that can function as a network sniffer, record

network activity, prevent and detect network intrusion. Which of the following tools is suitable

for Philip?

a)

Nmap

b)

Cain & Abel

c)

Snort

d)

Nessus

27.

Suppose your company has implemented identify people based on walking patterns and

made it part of physical control access to the office. The system works according to the

following principle:

The camera captures people walking and identifies employees, and then they must attach

their RFID badges to access the office.

Which of the following best describes this technology?

a)

The solution will have a high level of false positives

b)

Biological motion cannot be used to identify people

c)

Although the approach has two phases, it actually implements just one

authentication factor

d)

The solution implements the two factors authentication: physical object and

physical characteristic

28.

Which of the following protocols is used in a VPN for setting up a secure channel between

two devices?

a)

PPP

b)

PEM

c)

SET

d)

IPSEC

29.

You know that the application you are attacking is vulnerable to an SQL injection, but you

cannot see the result of the injection. You send a SQL query to the database, which makes

the database wait before it can react. You can see from the time the database takes to

respond, whether a query is true or false. What type of SQL injection did you use?

a)

Blind SQLi

b)

Out-of-band SQLi

c)

Error-based SQLi

d)

UNION SQLi

30.

Which of the following application security testing method of white-box testing, in which only

the source code of applications and their components is scanned for determines potential

vulnerabilities in their software and architecture?

a)

IAST

b)

DAST

c)

SAST

d)

MAST

31.

John performs black-box testing. It tries to pass IRC traffic over port 80/TCP from a compromised web-enabled host during the test. Traffic is blocked, but outbound HTTP traffic does not meet any obstacles. What type of firewall checks outbound traffic?

a)

Stateful

b)

Packet Filtering

c)

Circuit

d)

Application

32.

Which of the following is the method of determining the movement of a data packet from an

untrusted external host to a protected internal host through a firewall?

a)

MITM

b)

Firewalking

c)

Session hijacking

d)

Network sniffing

33.

Often, for a successful attack, hackers very skillfully simulate phishing messages. To do

this, they collect the maximum information about the company that they will attack: emails

of real employees (including information about the hierarchy in the company), information

about the appearance of the message (formatting, logos), etc. What is the name of this stage

of the hacker's work?

a)

Exploration stage

b)

Investigation stage

c)

Reconnaissance stage

d)

Enumeration stage

34.

Imagine the following scenario:

1. An attacker created a website with tempting content and benner like: 'Do you want to

make $10 000 in a month?'.

2. Victim clicks to the interesting and attractive content URL.

3. Attacker creates a transparent 'iframe' in front of the banner which victim attempts to click.

Victim thinks that he/she clicks to the 'Do you want to make $10 000 in a month?' banner

but actually he/she clicks to the content or UPL that exists in the transparent 'iframe' which

is set up by the attacker.

What is the name of the attack which is described in the scenario?

a)

Session Fixation

b)

Clickjacking Attack

c)

HTML Injection

d)

HTTP Parameter Pollution

35.

Black hat hacker Ivan wants to implement a man-in-the-middle attack on the corporate

network. For this, he connects his router to the network and redirects traffic to intercept

packets. What can the administrator do to mitigate the attack?

a)

Use the Open Shortest Path First (OSPF)

b)

Add message authentication to the routing protocol

c)

Use only static routes in the corporation's network

d)

Redirection of the traffic is not possible without the explicit admin's

confirmation

36.

Which of the options presented below is not a Bluetooth attack?

a)

Bluesmacking

b)

Bluesnarfing

c)

Bluejacking

d)

Bluedriving

37.

You analyze the logs and see the following output of logs from the machine with the IP

address of 192.168.0.132:

1. Time August 21 11:22:06 Port:20 Source:192.168.0.30 Destination:192.168.0.132 Protocol:TCP

2. Time August 21 11:22:08 Port:21 Source:192.168.0.30 Destination:192.168.0.132 Protocol:TCP

3. Time August 21 11:22:11 Port:22 Source:192.168.0.30 Destination:192.168.0.132 Protocol:TCP

4. Time August 21 11:22:14 Port:23 Source:192.168.0.30 Destination:192.168.0.132 Protocol:TCP

5. Time August 21 11:22:15 Port:25 Source:192.168.0.30 Destination:192.168.0.132 Protocol:TCP

6. Time August 21 11:22:19 Port:80 Source:192.168.0.30 Destination:192.168.0.132 Protocol:TCP

7. Time August 21 11:22:21 Port:443 Source:192.168.0.30 Destination:192.168.0.132 Protocol:TCP

What conclusion can you make based on this output?

a)

Denial of service attack targeting 192.168.0.132

b)

Port scan targeting 192.168.0.30

c)

Teardrop attack targeting 192.168.0.132

d)

Port scan targeting 192.168.0.132

38.

With which of the following SQL injection attacks can an attacker deface a web page, modify

or add data stored in a database and compromised data integrity?

a)

Unauthorized access to an application

b)

Compromised Data Integrity

c)

Loss of data availability

d)

Information Disclosure

39.

The attacker enters its malicious data into intercepted messages in a TCP session since

source routing is disabled. He tries to guess the responses of the client and server. What

hijacking technique is described in this example?

a)

RST

b)

TCP/IP

c)

Blind

d)

Registration

40.

The attacker tries to take advantage of vulnerability where the application does not verify if

the user is authorized to access the internal object via its name or key. Which of the following

queries best describes an attempt to exploit an insecure direct object using the name of the

valid account "User 1"?

a)

"GET/restricted/bank.getaccount(" ̃User1') HTTP/1.1 Host: westbank.com"

b)

"GET/restricted/goldtransfer?to=Account&from=1 or 1=1' HTTP/1.1Host:

westbank.com"

c)

"GET/restricted/\r\n\%00account%00User1%00access HTTP/1.1 Host:

westbank.com"

d)

"GET/restricted/accounts/?name=User1 HTTP/1.1 Host: westbank.com"

41.

What actions should be performed before using a Vulnerability Scanner for scanning a

network?

a)

TCP/IP stack fingerprinting

b)

Checking if the remote host is alive

c)

TCP/UDP Port scanning

d)

Firewall detection

42.

Which of the following is the risk that remains after the amount of risk left over after natural

or inherent risks have been reduced?

a)

Residual risk

b)

Impact risk

c)

Inherent risk

d)

Deferred risk

43.

Which of the following incident handling process phases is responsible for defining rules,

employees training, creating a back-up, and preparing software and hardware resources

before an incident occurs?

a)

Recovery

b)

Containment

c)

Identification

d)

Preparation

44.

Wireshark is one of the most important tools for a cybersecurity specialist. It is used for

network troubleshooting, analysis, software, etc. And you often have to work with a packet

bytes pane. In what format is the data presented in this pane?

a)

ASCII only

b)

Decimal

c)

Binary

d)

Hexadecimal

45.

Alex, a cyber security specialist, should conduct a pentest inside the network, while he

received absolutely no information about the attacked network. What type of testing will Alex

conduct?

a)

Internal, Black-box

b)

External, Black-box

c)

Internal, Grey-box

d)

Internal, White-box

46.

Victor, a white hacker, received an order to perform a penetration test from the company

"Test us".

He starts collecting information and finds the email of an employee of this company in free

access. Victor decides to send a letter to this email, changing the original email address to

the email of the boss of this employee, "boss@testus.com". He asks the employee to

immediately open the "link with the report" and check it. An employee of the company "Test

us" opens this link and infects his computer.

Thanks to these manipulations, Viktor gained access to the corporate network and

successfully conducted a pentest.

What type of attack did Victor use?

a)

Eavesdropping

b)

Piggybacking

c)

Social engineering

d)

Tailgating

47.

Which of the following Nmap's commands allows you to most reduce the probability of

detection by IDS when scanning common ports?

a)

nmap -sT -O -T0

b)

nmap -A --host-timeout 99-T1

c)

nmap -sT -O -T2

d)

nmap -A – Pn

48.

Which of the following is a network software suite designed for 802.11 WEP and WPA-PSK

keys cracking that can recover keys once enough data packets have been captured?

a)

Aircrack-ng

b)

WLAN-crack

c)

Airguard

d)

Wificracker

49.

Which of the following best describes code injection?

a)

Form of attack in which a malicious user gains access to the codebase on the

server and inserts new code.

b)

Form of attack in which a malicious user inserts additional code into the

JavaScript running in the browser.

c)

Form of attack in which a malicious user gets the server to execute arbitrary

code using a buffer overflow.

d)

Form of attack in which a malicious user inserts text into a data field interpreted

as code.

50.

John, a pentester, received an order to conduct an internal audit in the company. One of its

tasks is to search for open ports on servers. Which of the following methods is the best

solution for this task?

a)

Scan servers with Nmap.

b)

Scan servers with MBSA.

c)

Manual scan on each server.

d)

Telnet to every port on each server.

51.

Alex, the penetration tester, performs a server scan. To do this, he uses the method where

the TCP Header is split into many packets so that it becomes difficult to determine what

packages are used for. Determine the scanning technique that Alex uses?

a)

ACK flag scanning

b)

TCP Scanning

c)

IP Fragmentation Scan

d)

Inverse TCP flag scanning

52.

Which of the following is an encryption technique where data is encrypted by a sequence of

photons that have a spinning trait while travelling from one end to another?

a)

Hardware-Based.

b)

Quantum Cryptography.

c)

Homomorphic.

d)

Elliptic Curve Cryptography.

53.

Identify the standard by the description:

A regulation contains a set of guidelines that everyone who processes any electronic data

in medicine should adhere to. It includes information on medical practices, ensuring that all

necessary measures are in place while saving, accessing, and sharing any electronic

medical data to secure patient data.

a)

COBIT

b)

ISO/IEC 27002

c)

HIPAA

d)

FISMA

54.

You makes a series of interactive queries, choosing subsequent plaintexts based on the

information from the previous encryptions. What type of attack are you trying to perform?

a)

Chosen-plaintext attack

b)

Ciphertext-only attack

c)

Known-plaintext attack

d)

Adaptive chosen-plaintext attack

55.

Which of the following options represents a conceptual characteristic of an anomaly-based

IDS over a signature-based IDS?

a)

Can identify unknown attacks.

b)

Produces less false positives.

c)

Cannot deal with encrypted network traffic.

d)

Requires vendor updates for a new threat.

56.

Which of the following is a protocol that used for querying databases that store the registered

users or assignees of an Internet resource, such as a domain name, an IP address block or

an autonomous system?

a)

CAPTCHA

b)

Internet Engineering Task Force

c)

Internet Assigned Numbers Authority

d)

WHOIS

57.

Elon plans to make it difficult for the packet filter to determine the purpose of the packet

when scanning. Which of the following scanning techniques will Elon use?.

a)

ACK scanning.

b)

IPID scanning.

c)

ICMP scanning.

d)

SYN/FIN scanning using IP fragments.

58.

Fill in the blank: PCI Data Security Standards require encrypting transmission of cardholder data across ________.

a)

open, public networks

b)

private, internal networks

c)

encrypted, secure channels

d)

local, isolated systems

59.

Identify Secure Hashing Algorithm, which produces a 160-bit digest from a message on

principles similar to those used in MD4 and MD5?

a)

SHA-2

b)

SHA-1

c)

SHA-0

d)

SHA-3

60.

Ivan, the black hat hacker, split the attack traffic into many packets such that no single packet

triggers the IDS. Which IDS evasion technique does Ivan use?

a)

Unicode Evasion.

b)

Session Splicing.

c)

Low-bandwidth attacks.

d)

Flooding.

61.

Fill in the blank: PCI Data Security Standards recommend restricting access to cardholder data by business ________.

a)

need-to-know

b)

role

c)

location

d)

department

62.

Attacker uses various IDS evasion techniques to bypass intrusion detection mechanisms.

At the same time, IDS is configured to detect possible violations of the security policy,

including unauthorized access and misuse. Which of the following evasion method depend

on the Time-to-Live (TTL) fields of a TCP/IP ?

a)

Denial-of-Service Attack

b)

Unicode Evasion

c)

Obfuscation

d)

Insertion Attack

63.

You managed to compromise a server with an IP address of 10.10.0.5, and you want to get

fast a list of all the machines in this network. Which of the following Nmap command will you

need?

a)

nmap -T4 -F 10.10.0.0/24

b)

nmap -T4 -r 10.10.1.0/24

c)

nmap -T4 -q 10.10.0.0/24

d)

nmap -T4 -p 10.10.0.0/24

64.

Attacker uses various IDS evasion techniques to bypass intrusion detection mechanisms.

At the same time, IDS is configured to detect possible violations of the security policy,

including unauthorized access and misuse. Which of the following evasion method depend

on the Time-to-Live (TTL) fields of a TCP/IP ?

a)

Obfuscation

b)

Denial-of-Service Attack

c)

Insertion Attack

d)

Unicode Evasion

65.

alert tcp any any -> 10.199.10.3 21 (msg: "FTP on the network!";)

Which system usually uses such a configuration setting?

a)

Firewall IPTable

b)

Router IPTable

c)

FTP Server rule

d)

IDS

66.

What is a "Collision attack"?

a)

Сollision attack on a hash tries to find two inputs producing the same hash value.

b)

Collision attacks try to change the hash.

c)

Collision attacks attempt to recover information from a hash.

d)

Collision attacks break the hash into several parts, with the same bytes in each part

to get the private key.

67.

Determine the attack by the description:

Determine the attack by the description: The known-plaintext attack used against DES. This

attack causes that encrypting plaintext with one DES key followed by encrypting it with a

second DES key is no more secure than using a single key.

a)

Traffic analysis attack

b)

Man-in-the-middle attack

c)

Meet-in-the-middle attack

d)

Replay attack

68.

Identify a vulnerability in OpenSSL that allows stealing the information protected under

normal conditions by the SSL/TLS encryption used to secure the Internet?

a)

POODLE

b)

Shellshock

c)

Heartbleed Bug

d)

SSL/TLS Renegotiation Vulnerability

69.

The evil hacker Antonio is trying to attack the IoT device. He will use several fake identities

to create a strong illusion of traffic congestion, affecting communication between

neighbouring nodes and networks. What kind of attack does Antonio perform?

a)

Side-Channel Attack

b)

Forged Malicious Device

c)

Exploit Kits

d)

Sybil Attack

70.

John, a penetration tester, decided to conduct SQL injection testing. He enters a huge

amount of random data and observes changes in output and security loopholes in web

applications. What SQL injection testing technique did John use?

a)

Dynamic Testing.

b)

Static Testing.

c)

Function Testing.

d)

Fuzzing Testing.

71.

Which of the following Nmap options will you use if you want to scan fewer ports than the

default?

a)

-p

b)

-T

c)

-sP

d)

-F

72.

Rajesh, a network administrator found several unknown files in the root directory of his FTP

server. He was very interested in a binary file named "mfs". Rajesh decided to check the

FTP server logs and found that the anonymous user account logged in to the server,

uploaded the files and ran the script using a function provided by the FTP server's software.

Also, he found that "mfs" file is running as a process and it listening to a network port. What

kind of vulnerability must exist to make this attack possible?

a)

Privilege escalation.

b)

Brute force login.

c)

File system permissions.

d)

Directory traversal.

73.

Michael works as a system administrator. He receives a message that several sites are no

longer available. Michael tried to go to the sites by URL, but it didn't work. Then he tried to

ping the sites and enter IP addresses in the browser - it worked. What problem could Michael

identify?

a)

Traffic is Blocked on UDP Port 53

b)

Traffic is Blocked on UDP Port 69

c)

Traffic is Blocked on UDP Port 56

d)

Traffic is Blocked on UDP Port 88

74.

Ivan, an evil hacker, conducts an SQLi attack that is based on True/False questions. What

type of SQLi does Ivan use?

a)

Classic SQLi

b)

Blind SQLi

c)

DMS-specific SQLi

d)

Compound SQLi

75.

Which of the following web application attack inject the special character elements "Carriage

Return" and "Line Feed" into the user’s input to trick the web server, web application, or user

into believing that the current object is terminated and a new object has been initiated?

a)

CRLF Injection.

b)

Server-Side JS Injection.

c)

Log Injection.

d)

HTML Injection.

76.

John, a system administrator, is learning how to work with new technology: Docker. He will

use it to create a network connection between the container interfaces and its parent host

interface. Which of the following network drivers is suitable for John?

a)

Bridge networking.

b)

Macvlan networking.

c)

Host networking.

d)

Overlay networking.

77.

Mark, the network administrator, must allow UDP traffic on the host 10.0.0.3 and Internet

traffic in the host 10.0.0.2. In addition to the main task, he needs to allow all FTP traffic to

the rest of the network and deny all other traffic. Mark applies his ACL configuration on the

router, and everyone has a problem with accessing FTP. In addition, hosts that are allowed

access to the Internet cannot connect to it. In accordance with the following configuration,

determine what happened on the network?

1. access-list 102 deny tcp any any

2. access-list 104 permit udp host 10.0.0.3 any

3. access-list 110 permit tcp host 10.0.0.2 eq www any

4. access-list 108 permit tcp any eq ftp any

a)

The ACL for FTP must be before the ACL 110.

b)

The ACL 104 needs to be first because is UDP.

c)

The ACL 110 needs to be changed to port 80.

d)

The first ACL is denying all TCP traffic, and the router is ignoring the other

ACLs.

78.

Which of the following can be designated as "Wireshark for CLI"?

a)

John the Ripper

b)

ethereal

c)

tcpdump

d)

nessus

79.

What is an automated software testing technique that involves providing invalid, unexpected,

or random data as inputs to a computer program?

a)

Concolic testing

b)

Fuzz testing

c)

Security testing

d)

Monkey testing

80.

Which one of the following Google search operators allows restricting results to those from

a specific website?

a)

[link:]

b)

[inurl:]

c)

[site:]

d)

[cache:]

81.

Based on the following data, you need to calculate the approximate cost of recovery of the

system operation per year:

The cost of a new hard drive is $300;

The chance of a hard drive failure is 1/3;

The recovery specialist earns $10/hour;

Restore the OS and software to the new hard disk - 10 hours;

Restore the database from the last backup to the new hard disk - 4 hours;

Assume the EF = 1 (100%), calculate the SLE, ARO, and ALE.

a)

$146

b)

$440

c)

$960

d)

$295

82.

John needs to choose a firewall that can protect against SQL injection attacks. Which of the

following types of firewalls is suitable for this task?

a)

Packet firewall.

b)

Hardware firewall.

c)

Stateful firewall.

d)

Web application firewall.

83.

Which of the following is the type of violation when an unauthorized individual enters a

building following an employee through the employee entrance?

a)

Tailgating.

b)

Announced.

c)

Pretexting.

d)

Reverse Social Engineering.

84.

Which of the following program attack both the boot sector and executable files?

a)

Polymorphic virus

b)

Multipartite Virus

c)

Macro virus

d)

Stealth virus

85.

The company "Usual company" asked a cybersecurity specialist to check their perimeter

email gateway security. To do this, the specialist creates a specially formatted email

message:

1. From: employee76@usualcompany.com

2. To: employee34@usualcompany.com

3. Subject: Test message

4. Date: 5/8/2021 11:22

He sends this message over the Internet, and a "Usual company " employee receives it.

This means that the gateway of this company doesn't prevent _____.

a)

Email Harvesting

b)

Email Phishing

c)

Email Spoofing

d)

Email Masquerading

86.

Rajesh, the system administrator analyzed the IDS logs and noticed that when accessing

the external router from the administrator's computer to update the router configuration, IDS

registered alerts. What type of an alert is this?

a)

False negative

b)

True positve

c)

True negative

d)

False positive

87.

For the company, an important criterion is the immutability of the financial reports sent by

the financial director to the accountant. They need to be sure that the accountant received

the reports and it hasn't been changed. How can this be achieved?

a)

Use a hash algorithm in the document once CFO approved the financial

statements.

b)

Use a protected excel file.

c)

Reports can send to the accountant using an exclusive USB for that document.

d)

Financial reports can send the financial statements twice, one by email and the

other delivered in USB and the accountant can compare both.

88.

While using your bank's online servicing you notice the following string in the URL bar:

http://www.MyPersonalBank.com/account?id=368940911028389&Damount=10980&Camo

unt=21

You observe that if you modify the Damount & Camount values and submit the request, that

data on the web page reflect the changes. Which type of vulnerability is present on this site?

a)

Web Parameter Tampering

b)

Cookie Tampering

c)

SQL injection

d)

XSS Reflection

89.

Ferdinand installs a virtual communication tower between the two authentic endpoints to

mislead the victim. What attack does Ferdinand perform?

a)

Aspidistra

b)

Wi-Jacking

c)

Sinkhole

d)

aLTEr

90.

Which of the following best describes the "white box testing" methodology?

a)

The internal operation of a system is completely known to the tester.

b)

Only the external operation of a system is accessible to the tester.

c)

Only the internal operation of a system is known to the tester.

d)

The internal operation of a system is only partly accessible to the tester.

91.

Why is a penetration test considered to be better than a vulnerability scan?

a)

The tools used by penetration testers tend to have much more comprehensive

vulnerability databases.

b)

Penetration tests are intended to exploit weaknesses in the architecture of your

IT network, while a vulnerability scan does not typically involve active

exploitation.

c)

A penetration test is often performed by an automated tool, while a vulnerability

scan requires active engagement.

d)

Vulnerability scans only do host discovery and port scanning by default.

92.

Alex, a cybersecurity specialist, received a task from the head to scan open ports. One of

the main conditions was to use the most reliable type of TCP scanning. Which of the

following types of scanning should Alex use?

a)

Half-open Scan.

b)

TCP Connect/Full Open Scan.

c)

Xmas Scan.

d)

NULL Scan.

93.

What best describes two-factor authentication for a credit card (using a card and pin)?

a)

Something you have and something you know.

b)

Something you have and something you are.

c)

Something you are and something you remember.

d)

Something you know and something you are.

94.

What means the flag "-oX" in a Nmap scan?

a)

Output the results in truncated format to the screen.

b)

Run a Xmas scan.

c)

Output the results in XML format to a file.

d)

Run an express scan.

95.

Which of the following characteristics is not true about the Simple Object Access Protocol?

a)

Exchanges data between web services.

b)

Using Extensible Markup Language.

c)

Allows for any programming model.

d)

Only compatible with the application protocol HTTP.

96.

Which of the following wireless standard has bandwidth up to 54 Mbit/s and signals in a

regulated frequency spectrum around 5 GHz?

a)

802.11g

b)

802.11i

c)

802.11n

d)

802.11a

97.

Which of the following cipher is based on factoring the product of two large prime numbers?

a)

SHA-1

b)

RSA

c)

MD5

d)

RC5

98.

Which of the following command will help you launch the Computer Management Console

from" Run " windows as a local administrator Windows 7?

a)

gpedit.msc

b)

ncpa.cpl

c)

compmgmt.msc

d)

services.msc

99.

Which of the following does not apply to IPsec?

a)

Work at the Data Link Layer

b)

Encrypts the payloads

c)

Provides authentication

d)

Use key exchange

100.

According to the Payment Card Industry Data Security Standard, when is it necessary to

conduct external and internal penetration testing?

a)

At least once a year and after any significant upgrade or modification.

b)

At least twice a year or after any significant upgrade or modification.

c)

At least once every three years or after any significant upgrade or modification.

d)

At least once every two years and after any significant upgrade or modification.

101.

What identifies malware by collecting data from protected computers while analyzing it on

the provider’s infrastructure instead of locally?

a)

Heuristics-based detection

b)

Behavioural-based detection

c)

Cloud-based detection

d)

Real-time protection

102.

You are configuring the connection of a new employee's laptop to join an 802.11 network.

The new laptop has the same hardware and software as the laptops of other employees.

You used the wireless packet sniffer and found that it shows that the Wireless Access Point

(WAR) is not responding to the association requests being sent by the laptop. What can

cause this problem?

a)

The laptop is configured for the wrong channel.

b)

The laptop cannot see the SSID of the wireless network.

c)

The WAP does not recognize the la[top's MAC address.

d)

The laptop is not configured to use DHCP.

103.

Which of the following is a logical collection of Internet-connected devices such as

computers, smartphones or Internet of things (IoT) devices whose security has been

breached and control ceded to a third party?

a)

Spambot

b)

Botnet

c)

Spear Phishing

d)

Rootkit

104.

After several unsuccessful attempts to extract cryptography keys using software methods,

Mark is thinking about trying another code-breaking methodology. Which of the following will

best suit Mark based on his unsuccessful attempts?

a)

Frequency Analysis.

b)

Trickery and Deceit.

c)

Brute-Force.

d)

One-Time Pad.

105.

What is meant by a "rubber-hose" attack in cryptography?

a)

Extraction of cryptographic secrets through coercion or torture.

b)

A backdoor is placed into a cryptographic algorithm by its creator.

c)

Forcing the targeted keystream through a hardware-accelerated device such

as an ASIC.

d)

Attempting to decrypt ciphertext by making logical assumptions about the

contents of the original plain text.

106.

The firewall prevents packets from entering the organization through certain ports and

applications. What does this firewall check?

a)

Presentation layer headers and the session layer port numbers.

b)

Application layer port numbers and the transport layer headers.

c)

Application layer headers and transport layer port numbers.

d)

Network layer headers and the session layer port numbers.

107.

Which of the following requires establishing national standards for electronic health care

transactions and national identifiers for providers, health insurance plans, and employers?

a)

SOX

b)

DMCA

c)

HIPAA

d)

PCI-DSS

108.

Identify Bluetooth attck techniques that is used in to send messages to users without the

recipient's consent, for example for guerrilla marketing campaigns?

a)

Bluejacking

b)

Bluesnarfing

c)

Bluesmacking

d)

Bluebugging

109.

Which of the following layers in IoT architecture helps bridge the gap between two endpoints,

such as a device and a client, and carries out message routing, message identification, and

subscribing?

a)

Middleware.

b)

Access Gateway.

c)

Edge Technology.

d)

Internet.

110.

Session splicing is an IDS evasion technique that exploits how some IDSs do not reconstruct

sessions before performing pattern matching on the data. The idea behind session splicing

is to split data between several packets, ensuring that no single packet matches any patterns

within an IDS signature. Which tool can be used to perform session splicing attacks?

a)

Hydra

b)

tcpsplice

c)

Whisker

d)

Burp

111.

Your company has a risk assessment, and according to its results, the risk of a breach in

the main company application is 40%. Your cybersecurity department has made changes to

the application and requested a re-assessment of the risks. The assessment showed that

the risk fell to 12%, with a risk threshold of 20%. Which of the following options would be the

best from a business point of view?

a)

Introduce more controls to bring risk to 0%.

b)

Limit the risk.

c)

Accept the risk.

d)

Avoid the risk.

112.

What actions should you take if you find that the company that hired you is involved with

human trafficking?

a)

Copy the information to removable media and keep it in case you need it.

b)

Stop work and contact the proper legal authorities.

c)

Ignore the information and continue the assessment until the work is done.

d)

Confront the customer and ask her about this.

113.

Viktor, the white hat hacker, conducts a security audit. He gains control over a user account

and tries to access another account's sensitive information and files. How can he do this?

a)

Fingerprinting

b)

Shoulder-Surfing

c)

Privilege Escalation

d)

Port Scanning

114.

The evil hacker Ivan has installed a remote access Trojan on a host. He wants to be sure

that when a victim attempts to go to "www.site.com" that the user is directed to a phishing

site. Which file should Ivan change in this case?

a)

Boot.ini

b)

Sudoers

c)

Hosts

d)

Networks

115.

Ivan, an evil hacker, is preparing to attack the network of a financial company. To do this,

he wants to collect information about the operating systems used on the company's

computers. Which of the following techniques will Ivan use to achieve the desired result?

a)

UDP Scanning.

b)

Banner Grabbing.

c)

SSDP Scanning.

d)

IDLE/IPID Scanning.

116.

Which of the following option is a security feature on switches leverages the DHCP snooping

database to help prevent man-in-the-middle attacks?

a)

Port security

b)

DHCP relay

c)

DAI

d)

Spanning tree

117.

Michael, a technical specialist, discovered that the laptop of one of the employees

connecting to a wireless point couldn't access the Internet, but at the same time, it can

transfer files locally. He checked the IP address and the default gateway. They are both on

192.168.1.0/24. Which of the following caused the problem?

a)

The laptop isn't using a private IP address.

b)

The laptop and the gateway are not on the same network.

c)

The laptop is using an invalid IP address.

d)

The gateway is not routing to a public IP address.

118.

You have been assigned the task of defending the company from network sniffing. Which of

the following is the best option for this task?

a)

Restrict Physical Access to Server Rooms hosting Critical Servers.

b)

Register all machines MAC Address in a Centralized Database.

c)

Using encryption protocols to secure network communications.

d)

Use Static IP Address.

119.

Let's assume that you decided to use PKI to protect the email you will send. At what layer

of the OSI model will this message be encrypted and decrypted?

a)

Application layer.

b)

Session layer.

c)

Transport layer.

d)

Presentation layer.

120.

Which of the following UDP ports is usually used by Network Time Protocol (NTP)?

a)

19

b)

123

c)

161

d)

177

121.

Andrew is conducting a penetration test. He is now embarking on sniffing the target network.

What is not available for Andrew when sniffing the network?

a)

Identifying operating systems, services, protocols and devices.

b)

Capturing network traffic for further analysis.

c)

Collecting unencrypted information about usernames and passwords.

d)

Modifying and replaying captured network traffic.

122.

Which of the following methods is best suited to protect confidential information on your

laptop which can be stolen while travelling?

a)

BIOS password.

b)

Hidden folders.

c)

Full disk encryption.

d)

Password protected files.

123.

How works the mechanism of a Boot Sector Virus?

a)

Moves the MBR to another location on the Random-access memory and copies

itself to the original location of the MBR.

b)

Moves the MBR to another location on the hard disk and copies itself to the

original location of the MBR.

c)

Overwrites the original MBR and only executes the new virus code.

d)

Modifies directory table entries to point to the virus code instead of the actual

MBR.

124.

Which of the following flags will trigger Xmas scan?

a)

-sP

b)

-sA

c)

-sV

d)

-sX

125.

Rajesh, a system administrator, noticed that some clients of his company were victims of

DNS Cache Poisoning. They were redirected to a malicious site when they tried to access

Rajesh's company site. What is the best recommendation to deal with such a threat?

a)

Customer awareness

b)

Use a multi-factor authentication

c)

Use of security agents on customers' computers.

d)

Use Domain Name System Security Extensions (DNSSEC)