SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
Comptia Security +: Cyber Ops
Start Test
Study First
Subjects
:
certifications
,
comptia-security-+
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Which of the following should be implemented to secure Pete's - a network administrator - day-today maintenance activities?
E-discovery
Succession planning
Fail state of the system
TACACS+; SSH
2. Which of the following web application security weaknesses can be mitigated by preventing the use of HTML tags?
Mandatory access control
Host based firewall
Logic bomb
Cross-site scripting
3. Which of the following accurately describes the STRONGEST multifactor authentication?
Assign multiple roles to the existing user ID
Something you are - something you have
Fuzzing
Mitigate risk and develop a maintenance plan.
4. Starbuck - a security administrator - wants to prevent users in sales from accessing their servers after 6:00 p.m. - and prevent them from accessing accounting's network at all times. Which of the following should Starbuck implement to accomplish the
Spam fitters
Time of day restrictions;Access control lists
War chalking
Improper input validation
5. Which of the following security concepts establishes procedures where creation and approval are performed through distinct functions?
Penetration test
Separation of duties
SQL injection
RBAC
6. Which of the following procedures would be used to mitigate the risk of an internal developer embedding malicious code into a production system?
Host based firewall
Change management
Rogue access point
Personal firewall
7. Which of the following inspects traffic entering or leaving a network to look for anomalies against expected baselines?
Ticket granting server
Sanitization using appropriate software
IPS
Log reviews
8. Jayne - the administrator - has been told to confirm what account an email was sent from. Which of the following is this an example of?
The capacity of a system to resist unauthorized changes to stored information
E-discovery
Information classification policy; Network access policy; Auditing and monitoring policy
Ask the programmer to replicate the problem in a test environment.
9. Jayne's CRL is over six months old. Which of the following could Jayne do in order to ensure he has the current information?
Memory dump - ARP cache
Update the CRL; Deploy OCSP
Social engineering
Mandatory Access Controls
10. Jayne - a systems security engineer - is determining which credential-type authentication to use within a planned 802.1x deployment. He is looking for a method that does not require a client certificate - has a server side certificate - and uses TLS
Proxies
PEAP-MSCHAPv2
Social engineering
Deploy an anti-spam device to protect the network.
11. Mal - a security administrator - wants to secure remote telnet services and decides to use the services over SSH. Which of the following ports should Mal allow on the firewall by default?
Server-side input validation results in a more secure system than client-side input validation.
Proxies
22
Zero day attack
12. Which of the following is BEST utilized to actively test security controls on a particular system?
Spam filter
Penetration test
Mandated security configurations have been made to the operating system.
SSH
13. River Tam - a user - on a public Wi-Fi network logs into a webmail account and is redirected to a search engine. Which of the following attacks may be occurring?
Input validation
Private key
dcfldd
Evil twin
14. Which of the following would help Mal - an administrator - prevent access to a rogue access point connected to a switch?
Establish a MAC limit and age
Log reviews
Confidentiality
Integrity
15. Which of the following protocols provides Mal - an administrator - with the HIGHEST level of security for device traps?
SNMPv3
MD5 checksum
Something you are - something you have
ARP poisoning
16. When integrating source material from an open source project into a highly secure environment - which of the following precautions should prevent hidden threats?
SNMPv3
Fuzzing
MD5
Code review
17. Which of the following authentication protocols forces centralized wireless authentication?
Port scan
WPA2-Enterprise
MAC filtering
Account lockout
18. Mal - a user - submitted a form on the Internet but received an unexpected response shown below Server Error in "/" Application Runtime error in script on asp.net version 2.0 Which of the following controls should be put in place to prevent Mal from
Error handling
Cross-site scripting
Separation of duties
Proxy server
19. Which of the following techniques floods an application with data in an attempt to find vulnerabilities?
Error handling
Impact; Likelihood
Fuzzing
NTLM
20. Which of the following is similar to a smurf attack - but uses UDP instead to ICMP?
MAC filtering
Fraggle attack
Vishing
Cable locks
21. Which of the following elements makes up the standard equation used to define risk?
Impact; Likelihood
Mitigate risk and develop a maintenance plan.
Account expiration
Worm outbreak
22. Which of the following password policies is the MOST effective against a brute force network attack?
Social engineering
Impact; Likelihood
TACACS+; SSH
Account lockout
23. Which of the following reduces the likelihood of a single point of failure when a server fails?
Clustering
Group based privileges
Application hardening
Humidity controls
24. Workers of a small local organization have implemented an off-site location in which the organization can resume operations within 10 business days in the event of a disaster. This type of site is BEST known as which of the following?
Cold site
Evil twin
SSH
Trust model
25. A computer is put into a restricted VLAN until the computer's virus definitions are up-to-date. Which of the following BEST describes this system type?
Protocol analyzer
The intermediate CA's public key
Account lockout
NAC
26. Which of the following encrypts the body of a packet - rather than just the password - while sending information?
Separation of duties
TACACS+
Verify the user's identity
Change management
27. Employees are reporting that they are receiving unusual calls from the help desk for the purpose of verifying their user credentials. Which of the following attack types is occurring?
Vishing
File encryption
MD5
Group based privileges
28. Mal - a user - is having trouble dialing into the network from their house. The administrator checks the RADIUS server - the switch connected to the server - and finds that the switch lost configuration after a recent power outage. The administrator
RAS
PEAP
VLAN mismatch is occurring.
RAID 5 and a storage area network
29. Jayne - a security administrator - wants to allow content owners to determine who has access to tiles. Which of the following access control types does this describe?
Antenna placement; Power-level control
Blue jacking
Separation of duties
Discretionary access control
30. The corporate NIPS requires a daily download from its vendor with updated definitions in order to block the latest attacks. Which of the following describes how the NIPS is functioning?
Logic bomb
Signature based
Port scan
Mandatory Access Controls
31. Which of the following activities should be completed in order to detect anomalies on a network?
Account lockout
Time of day restrictions;Access control lists
Log reviews
Install both the private and the public key on the web server.
32. The log management system at Company A is inadequate to meet the standards required by their corporate governance team. A new automated log management system has been put in place. This is an example of which of the following?
Power levels
Encrypt all confidential data.
Business impact assessment
Continuous monitoring
33. Which of the following is a policy that would force all users to organize their areas as well as help in reducing the risk of possible data theft?
Clean desk policy
Public key
Business impact assessment
Something you are - something you have
34. While traveling - users need access to an internal company web server that contains proprietary information. Mal - the security administrator - should implement a...
Account lockout
Zero day attack
Proxy server
RAS
35. Jayne - a security administrator - has noticed that the website and external systems have been subject to many attack attempts. To verify integrity of the website and critical files - Jayne should
Create file hashes for website and critical system files - and compare the current file hashes to the baseline at regular time intervals.
Cipher lock combination and proximity badge
Error handling
Clustering
36. River Tam - an attacker - calls the company's from desk and tries to gain insider information by providing specific company information to gain the attendant's trust. The front desk immediately alerts the IT department about this incident. This is an
P2P
The intermediate CA's public key
Install application updates
Impersonation
37. An application company sent out a software patch for one of their applications on Monday. The company has been receiving reports about intrusion attacks from their customers on Tuesday. Which of the following attacks does this describe?
Zero day
Subnetting
Disable unused ports
Dual-homing a server
38. Hashing algorithms are used to address which of the following?
Enforced acceptable usage policy - encryption of confidential emails - and monitoring of communications leaving the organization.
TACACS+; SSH
Integrity
Mandatory access control
39. Which of the following is an example of authentication using something Starbuck - a user - has and something she knows?
PGP
SNMPv3
22
GSM phone card and PIN
40. Which of the following BEST explains the security benefit of a standardized server image?
Software as a Service
Mandatory access control
Zero day attack
Mandated security configurations have been made to the operating system.
41. Which of the following security tools can Starbuck - a security administrator - use to deter theft?
Use Starbuck's private key to sign the binary
PGP
Validate the identity of an email sender;Encrypt messages;Decrypt messages
Cable locks
42. Marketing creates a new folder and requests the following access be assigned: Sales Department - Read Marketing Department - Full Control Inside Sales - Read Write This is an example of which of the following?
RBAC
Subnetting
Mandatory access control
Zero day exploit
43. When moving from an internally controlled environment to a fully outsourced infrastructure environment - such as cloud computing - it is MOST important to...
Encrypt all confidential data.
CRL
Power levels
Device encryption
44. An application programmer reports to River Tam - the security administrator - that the antivirus software installed on a server is interfering with one of the production HR applications - and requests that antivirus be temporarily turned off. How sho
Ask the programmer to replicate the problem in a test environment.
Humidity controls
Input validation
Rootkit
45. Which of the following could River Tam - an administrator - use in a workplace to remove sensitive data at rest from the premises?
Personally owned devices
Compare hashes of the original source and system image.
Single sign-on
Passive finger printing
46. Which of the following has a default port of 22?
SSH
RBAC
The system is virtualized
Public key
47. Which of the following allows Mal - a security technician - to prevent email traffic from entering the company servers?
Spam filter
E-discovery
Power levels
TACACS+; SSH
48. When reviewing a digital certificate for accuracy - which of the following would Jayne - a security administrator - focus on to determine who affirms the identity of the certificate owner?
Cable locks
CA
Mandatory Access Controls
Deploying and using a trusted OS
49. Which of the following is Starbuck - a security administrator - MOST likely implementing when deleting all the unneeded files and modules of a newly install application?
Application hardening
RAID 5 and a storage area network
Rogue access point
Key escrow
50. The Chief Information Officer (CIO) wants to protect laptop users from zero day attacks. Which of the following would BEST achieve the CIO's goal?
ARP poisoning
SQL injection
Host based firewall
Antenna placement; Power levels