SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
Comptia Security +: Cyber Ops
Start Test
Study First
Subjects
:
certifications
,
comptia-security-+
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. In the event of a mobile device being lost or stolen - which of the following BEST protects against sensitive information leakage?
Logic bomb
Remote wipe
Non-repudiation
80
2. Jayne - a systems security engineer - is determining which credential-type authentication to use within a planned 802.1x deployment. He is looking for a method that does not require a client certificate - has a server side certificate - and uses TLS
Social engineering
Proxy server
PEAP-MSCHAPv2
ARP poisoning
3. Starbuck - a VPN administrator - was asked to implement an encryption cipher with a MINIMUM effective security of 128-bits. Which of the following should Starbuck select for the tunnel encryption?
Blowfish
Temperature and humidity controls
Rootkit
Cable locks
4. An administrator responsible for building and validating security configurations is a violation of which of the following security principles?
Fail state of the system
Separation of duties
TACACS+
Change management
5. Which of the following should be done before resetting a user's password due to expiration?
6. Jayne - a security administrator - needs to Telnet into a router to change some configurations. Which of the following ports would need to be open to allow Jayne to change the configurations?
Worm outbreak
23
Subnetting
Private key
7. Jayne's CRL is over six months old. Which of the following could Jayne do in order to ensure he has the current information?
Update the CRL; Deploy OCSP
The IDS does not identify a buffer overflow
Rootkit
Fraggle attack
8. Mal - a network administrator - implements the spanning tree protocol on network switches. Which of the following issues does this address?
Anti-spam
VLAN mismatch is occurring.
Loop protection
22
9. Traffic has stopped flowing to and from the company network after the inline IPS hardware failed. Which of the following has occurred?
Trust model
Failsafe
Something you are
Temperature and humidity controls
10. Hashing algorithms are used to address which of the following?
Integrity
Server-side input validation results in a more secure system than client-side input validation.
Disable unused ports
Confidentiality
11. Which of the following security tools can Starbuck - an administrator - implement to mitigate the risks of theft?
Mandatory Access Controls
Device encryption
Accounting should be given read/write access to network share A and read access to network share B. River Tam should be given read access for the specific document on network share A.
Detective
12. Jayne - a server administrator - sets up database forms based on security rating levels. If a user has the lowest security rating then the database automatically determines what access that user has. Which of the following access control methods does
Remote data wipe
Deploy an anti-spam device to protect the network.
Loop protection
Mandatory access control
13. Social networking sites are used daily by the marketing team for promotional purposes. However - confidential company information - including product pictures and potential partnerships - have been inadvertently exposed to the public by dozens of emp
Host based firewall
Temperature and humidity controls
Something you are
Mandate additional security awareness training for all employees.
14. Which of the following security concepts establishes procedures where creation and approval are performed through distinct functions?
Succession planning
Update the CRL; Deploy OCSP
Separation of duties
Proxy server
15. Mal - a security administrator - has observed repeated attempts to break into the network. Which of the following is designed to stop an intrusion on the network?
Dual-homing a server
Risk
NIPS
Separation of duties
16. Which of the following security tools can Starbuck - a security administrator - use to deter theft?
Account lockout
Mean time to restore
Mitigate risk and develop a maintenance plan.
Cable locks
17. An SQL injection vulnerability can be caused by which of the following?
Enforced acceptable usage policy - encryption of confidential emails - and monitoring of communications leaving the organization.
The system shall require users to authenticate to the system with a combination of a password or PIN and a smartcard
PEAP
Improper input validation
18. A packet filtering firewall can protect from which of the following?
Loop protection
Something you are - something you have
TACACS+; SSH
Port scan
19. An application company sent out a software patch for one of their applications on Monday. The company has been receiving reports about intrusion attacks from their customers on Tuesday. Which of the following attacks does this describe?
Zero day
Remote wipe
Use Starbuck's private key to sign the binary
Temperature and humidity controls
20. An application programmer reports to River Tam - the security administrator - that the antivirus software installed on a server is interfering with one of the production HR applications - and requests that antivirus be temporarily turned off. How sho
PEAP
Ask the programmer to replicate the problem in a test environment.
Rogue access point
Sanitization using appropriate software
21. Mal - a security administrator - wants to secure remote telnet services and decides to use the services over SSH. Which of the following ports should Mal allow on the firewall by default?
22
File encryption
Notify security to identify employee's whereabouts.
Host based firewall
22. Which of the following will help Jayne - an administrator; mitigate the risk of static electricity?
Humidity controls
Impersonation
Two fish
The IDS does not identify a buffer overflow
23. Which of the following malware types is BEST described as protecting itself by hooking system processes and hiding its presence?
The DES algorithm is run three consecutive times against the item being encrypted.
Rootkit
Key escrow
River Tam - the attacker - overwhelms a system or application - causing it to crash and bring the server down to cause an outage.
24. Mal - a security administrator - would like to implement laptop encryption to protect data. The Chief Executive Officer (CEO) believes this will be too costly to implement and decides the company will purchase an insurance policy instead. Which of th
Blue jacking
Continuous monitoring
Risk avoidance
Succession planning
25. Which of the following BEST allows Mal - a security administrator - to determine the type - source - and flags of the packet traversing a network for troubleshooting purposes?
Integrity
Proxies
Mandatory access control
Protocol analyzers
26. A company needs to remove sensitive data from hard drives in leased computers before the computers are returned to the supplier. Which of the following is the BEST solution?
Public key
Sanitization using appropriate software
The intermediate CA's public key
Device encryption
27. Mal - a security administrator - has configured and implemented an additional public intermediate CA. Which of the following must Mal submit to the major web browser vendors in order for the certificates - signed by this intermediate - to be trusted?
28. Which of the following elements makes up the standard equation used to define risk?
Separation of duties
Impact; Likelihood
Risk avoidance
Fuzzing
29. River Tam - the security engineer - has discovered that a breach is in progress on a non-production system of moderate importance. Which of the following should River Tam collect FIRST?
Personally owned devices
Blowfish
RAS
Memory dump - ARP cache
30. Which of the following is a policy that would force all users to organize their areas as well as help in reducing the risk of possible data theft?
PEAP-MSCHAPv2
Install application updates
Vishing
Clean desk policy
31. Which of the following would Mal - a security administrator - change to limit how far a wireless signal will travel?
Mitigate risk and develop a maintenance plan.
Two fish
Fraggle attack
Power levels
32. Starbuck - a security administrator - has applied security labels to files and folders to manage and restrict access. Which of the following is Starbuck using?
Antenna placement; Power levels
SSH
Mandatory access control
Separation of duties
33. The fundamental information security principals include confidentiality - availability and which of the following?
The capacity of a system to resist unauthorized changes to stored information
Change management
Personal firewall
Antenna placement; Power-level control
34. River Tam - a network security administrator - has been tasked with setting up a guest wireless network for her corporation. The requirements for this connection state that it must have password authentication - with passwords being changed every wee
The capacity of a system to resist unauthorized changes to stored information
Fail state of the system
Port scan
WPA2-PSK
35. Which of the following is the BEST incident response procedure to take when a previous employee enters a facility?
36. A computer is put into a restricted VLAN until the computer's virus definitions are up-to-date. Which of the following BEST describes this system type?
Zero day
Code review
NAC
To limit the number of endpoints connected through the same switch port
37. Which of the following has a default port of 22?
Separation of duties
RADIUS
Rogue access point
SSH
38. Which of the following attacks is characterized by River Tam attempting to send an email from a Chief Information Officer's (CIO's) non-corporate email account to an IT staff member in order to have a password changed?
Separation of duties
Separation of duties
Antenna placement; Power levels
Impersonation
39. Which of the following is where an unauthorized device is found allowing access to a network?
Mitigation
dcfldd
Rogue access point
Power levels
40. Which of the following are security relevant policies?
Account lockout
Ask the programmer to replicate the problem in a test environment.
Key escrow
Information classification policy; Network access policy; Auditing and monitoring policy
41. Which of the following administrative controls BEST mitigates the risk of ongoing inappropriate employee activities in sensitive areas?
Mitigation
dcfldd
Protocol analyzer
Mandatory vacations
42. Which of the following accurately describes the STRONGEST multifactor authentication?
Business impact assessment
Firewall
Something you are - something you have
Two fish
43. Which of the following encrypts the body of a packet - rather than just the password - while sending information?
Disable unused ports
The IDS does not identify a buffer overflow
Single point of failure
TACACS+
44. Which of the following would River Tam - a security administrator - utilize to identity a weakness within various applications without exploiting that weakness?
Vulnerability scan
Protocol analyzers
Warm site
Separation of duties
45. Starbuck - a security technician - wants to implement secure wireless with authentication. Which of the following allows for wireless to be authenticated via MSCHAPv2?
Antenna placement; Power levels
Clustering
Impersonation
PEAP
46. A company is performing internal security audits after a recent exploitation on one of their proprietary applications. River Tam - the security auditor - is given the workstation with limited documentation regarding the application installed for the
Gray box
Deploy an anti-spam device to protect the network.
Two fish
Mandatory access control
47. A data loss prevention strategy would MOST likely incorporate which of the following to reduce the risk associated with data loss?
RADIUS
Enforced acceptable usage policy - encryption of confidential emails - and monitoring of communications leaving the organization.
21
Blowfish
48. Which of the following techniques floods an application with data in an attempt to find vulnerabilities?
Risk
Fuzzing
Rootkit
Something you are - something you have
49. Which of the following describes the ability for a third party to verify the sender or recipient of a given electronic message during authentication?
Image hashes
Mean time to restore
It is faster to encrypt an individual file.
Non-repudiation
50. River Tam - a security administrator - suspects that a web server may be under attack. The web logs have several entries containing variations of the following entries: 'or 1=1-- or1'=1-- 'or1=1'
Personal firewall
Spam filter
Dictionary; Brute force
SQL injection