wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

CCST 100-160 Cybersecurity Practice Questions #2

Total questions: 25

Worksheet time: 18mins

Name
Class
Date
1.
Question Image

Match each worm mitigation step from the list below to the correct description. Note: You will receive partial credit for each correct answer:

Containment

Innoculation

Treatment

Quarantine

a)

Clean and patch infected systems

1.

Treatment

b)

Remove or block infected systems from the network

2.

Quarantine

c)

Patch uninfected systems to deprive the worm of more available targets

3.

Innoculation

d)

Compartmentalize and segment the network to limit the spread of the worm to areas already infected

4.

Containment

2.

A restaurant installs a second wireless router that only employees can use. Which statement describes how to securely configure the new router?

a)

Configure the new router to filter IP addresses..

b)

Configure the SSID with broadcast disabled

c)

Configure a higher signal strength to allow coverage in the parking lot.

d)

Configure the SSID with the same SSID used by the customer router

3.

You need to transfer configuration files to a router across an unsecured network. Which protocol should you use to encrypt the files in transit?

a)

Telnet

b)

HTTP

c)

TFTP

d)

SSH

4.
Question Image

You need to diagram an intrusion event by using the Diamond Model. Select each event detail from the list below to the correct location in the diagram:

Customer and product databases

Ransomeware group

Phising Email, Malware

Email Server, Domain Name

a)

Adversary

1.

Ransomeware Group

b)

Capability

2.

Phising Email, Malware

c)

Infrastructure

3.

Email Server, Domain Name

d)

Victum

4.

Customer and product databases

5.

Your company is creating a BYOD policy to allow employees to join their personal smartphones to the company network. Which three requirements are commonly included in a BYOD policy? (Choose 3.)

a)

Deletion of all personal data from the phone

b)

Synchronization of phone lock screen password with network access password F. Installation of secure apps only

c)

Encryption of stored confidential corporate data

d)

Configuration of a strong password

e)

Upgrade of data plan to maximum available

6.

You notice that a new CVE has been shared to an email group that you belong to. What should you do first with the CVE

a)

Look up details of the vulnerability to determine whether it applies to your network. .

b)

Research measures to prevent the CVE from attacking the network

c)

Record the CVE as part of the disaster recovery plan.

d)

Add the CVE to the firewall rules for your organization.

7.

Which encryption type is commonly used to secure WiFi networks?

a)

Data Encryption Standard (DES)

b)

Triple Data Encryption Algorithm (Triple DES)

c)

Advanced Encryption Algorithm (AES)

d)

RSA (Rivest–Shamir–Adleman)

8.
Question Image

You need to manage security risks at your company. In which order should you complete the actions? Move all the actions to the answer area and place them in the correct order

a)

Action Order 1

1.

Identify the Risks

b)

Action Order 2

2.

Prioritize the Risks

c)

Action Order 3

3.

Implement a Response

d)

Action Order 4

4.

Monitor Results

9.

How does sandboxing help with the analysis of malware?

a)

It defines the suspicious or malicious applications that should be blocked. .

b)

It specifies the applications that are authorized for use on the network

c)

It allows suspicious applications to run in a safe and isolated testing environment.

d)

It restricts traffic from passing from one network to another.

10.

Which network security technology passively monitors network traffic and compares the captured packet stream with known malicious signatures?

a)

IDS

b)

IPS

c)

Proxy

Server

d)

Honeypot

11.

Your supervisor tells you that you will participate in a CVSS assessment. What will you be doing?

a)

Performing penetration tests on internal network devices and end systems

b)

Analyzing host logs to identify abnormal activities

c)

Interviewing users to determine their level of cybersecurity awareness

d)

Evaluating end system security and scoring software vulnerabilities

12.

The company web server collects information through a form. The form is accessed by using port 80. The form content is transferred to an encrypted database for storage. You are investigating a complaint that the form content has been compromised. What is the cause of the security breach?

a)

The database was compromised.

b)

The data was transferred to the database using a nonsecure protocol.

c)

The website was accessed using HTTP, which is an unencrypted protocol.

d)

The web browser used to access the site was not updated to the latest version.

13.

You work for a hospital that stores electronic protected health information (ePHI) in an online portal. Authorized employees can use their mobile devices to access patient ePHI. You need to ensure that employees’ mobile devices comply with HIPAA regulations. Which safeguard should you develop and implement?

a)

An ownership policy for employees’ mobile devices

b)

A contingency plan

c)

A policy that requires multi-factor authentication to use the mobile device

d)

A policy to govern how ePHI is removed from mobile devices

14.

You need to design your company’s password policy to adhere to the National Institute of Standards and Technology (NIST) guidelines for user password security. What is the minimum password length that you should require to be consistent with the NIST guidelines?

a)

4 characters

b)

8 characters

c)

16 characters

d)

No minimum length

15.
Question Image

Select each framework from the list below to the correct purpose:

FERPA

FISMA

GDPR

HIPAA

PCI-DSS

a)

Protect the personal information of members of the European Union

1.

GDPR

b)

Protects the healthcare information of individuals

2.

HIPAA

c)

Protects the credit card information of individuals

3.

PCI-DSS

d)

Protects the educational records of individuals

4.

FERPA

e)

Protects information about individuals that is stored by federal agencies.

5.

FISMA

16.

You need a software solution that performs the following tasks:

Compiles network data

Logs information from many sources

Provides orchestration in the form of case management

Automates incident response workflows

What product should you use?

a)

SIEM

b)

SOAR

c)

NextGen IPS

d)

Snort

17.
Question Image

Select each scenario from the list below to the correct type of attacker:

a)

Tries to profit from personal data gained by spamming companies or individuals

1.

Cyber Criminal

b)

Works in conjunction with government to promote its agenda

2.

State-Sponsored Attacker

c)

Works as a company contractor who installs malware on a server

3.

Insider Threat

d)

Interfers in government election to promote a self-defined sense of justice

4.

Hactivist

18.

You are collecting data after a suspected intrusion on the local LAN. You need to capture incoming IP packets to a file for an investigator to analyze. Which two tools should you use? (Choose 2.)

a)

Wireshark

b)

tcpdump

c)

Nmap

d)

netstat

19.

You are reviewing the Application log on a Windows computer. You see an event with an error-level message as shown. What can you determine about the application that generated the event message?

a)

The application is currently running much slower than expected.

b)

The application experienced a significant problem that caused it to fail.

c)

The application recovered from an event without loss of functionality.

d)

The application loaded and ran successfully without issues.

20.

Which security measure can prevent unauthorized devices from automatically connecting to a corporate network through unused switch ports?

a)

Port security

b)

VLAN trunking

c)

NAT

d)

VPN

21.

An administrator wants to ensure that any files downloaded from the internet are automatically scanned for malicious code before execution. Which security control should be implemented?

a)

Host-based firewall

b)

Anti-malware with real-time protection

c)

VPN client

d)

Patch management system

22.

Which step should be performed immediately after identifying a critical vulnerability affecting internet-facing systems?

a)

Which step should be performed immediately after identifying a critical vulnerability affecting internet-facing systems?

b)

Apply the vendor patch or mitigation.

c)

Schedule a quarterly penetration test.

d)

Change the default administrator passwords.

23.

A SOC analyst notices repeated failed login attempts from a foreign IP address followed by a successful login to a privileged account. What is the most appropriate next step?

a)

Reset the affected user’s password and investigate the scope of compromise.

b)

Block all foreign IP addresses from accessing the network.

c)

Run a full vulnerability scan of the corporate network.

d)

Ignore the event unless it happens again.

24.

Which wireless security protocol provides the strongest protection for a home or small business network?

a)

WEP

b)

WPA

c)

WPA2 with AES

d)

WPA3

25.

During an incident response, the security team needs to isolate a compromised server from the rest of the network but still allow forensic analysis. Which action should they take?

a)

Power off the server immediately.

b)

Disconnect the server from the network and connect it to an isolated forensic network.

c)

Delete suspicious files from the server.

d)

Reset all user passwords on the server.