Test your basic knowledge |

Comptia Security +: Cyber Ops

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Which of the following should be implemented to secure Pete's - a network administrator - day-today maintenance activities?






2. Which of the following web application security weaknesses can be mitigated by preventing the use of HTML tags?






3. Which of the following accurately describes the STRONGEST multifactor authentication?






4. Starbuck - a security administrator - wants to prevent users in sales from accessing their servers after 6:00 p.m. - and prevent them from accessing accounting's network at all times. Which of the following should Starbuck implement to accomplish the






5. Which of the following security concepts establishes procedures where creation and approval are performed through distinct functions?






6. Which of the following procedures would be used to mitigate the risk of an internal developer embedding malicious code into a production system?






7. Which of the following inspects traffic entering or leaving a network to look for anomalies against expected baselines?






8. Jayne - the administrator - has been told to confirm what account an email was sent from. Which of the following is this an example of?






9. Jayne's CRL is over six months old. Which of the following could Jayne do in order to ensure he has the current information?






10. Jayne - a systems security engineer - is determining which credential-type authentication to use within a planned 802.1x deployment. He is looking for a method that does not require a client certificate - has a server side certificate - and uses TLS






11. Mal - a security administrator - wants to secure remote telnet services and decides to use the services over SSH. Which of the following ports should Mal allow on the firewall by default?






12. Which of the following is BEST utilized to actively test security controls on a particular system?






13. River Tam - a user - on a public Wi-Fi network logs into a webmail account and is redirected to a search engine. Which of the following attacks may be occurring?






14. Which of the following would help Mal - an administrator - prevent access to a rogue access point connected to a switch?






15. Which of the following protocols provides Mal - an administrator - with the HIGHEST level of security for device traps?






16. When integrating source material from an open source project into a highly secure environment - which of the following precautions should prevent hidden threats?






17. Which of the following authentication protocols forces centralized wireless authentication?






18. Mal - a user - submitted a form on the Internet but received an unexpected response shown below Server Error in "/" Application Runtime error in script on asp.net version 2.0 Which of the following controls should be put in place to prevent Mal from






19. Which of the following techniques floods an application with data in an attempt to find vulnerabilities?






20. Which of the following is similar to a smurf attack - but uses UDP instead to ICMP?






21. Which of the following elements makes up the standard equation used to define risk?






22. Which of the following password policies is the MOST effective against a brute force network attack?






23. Which of the following reduces the likelihood of a single point of failure when a server fails?






24. Workers of a small local organization have implemented an off-site location in which the organization can resume operations within 10 business days in the event of a disaster. This type of site is BEST known as which of the following?






25. A computer is put into a restricted VLAN until the computer's virus definitions are up-to-date. Which of the following BEST describes this system type?






26. Which of the following encrypts the body of a packet - rather than just the password - while sending information?






27. Employees are reporting that they are receiving unusual calls from the help desk for the purpose of verifying their user credentials. Which of the following attack types is occurring?






28. Mal - a user - is having trouble dialing into the network from their house. The administrator checks the RADIUS server - the switch connected to the server - and finds that the switch lost configuration after a recent power outage. The administrator






29. Jayne - a security administrator - wants to allow content owners to determine who has access to tiles. Which of the following access control types does this describe?






30. The corporate NIPS requires a daily download from its vendor with updated definitions in order to block the latest attacks. Which of the following describes how the NIPS is functioning?






31. Which of the following activities should be completed in order to detect anomalies on a network?






32. The log management system at Company A is inadequate to meet the standards required by their corporate governance team. A new automated log management system has been put in place. This is an example of which of the following?






33. Which of the following is a policy that would force all users to organize their areas as well as help in reducing the risk of possible data theft?






34. While traveling - users need access to an internal company web server that contains proprietary information. Mal - the security administrator - should implement a...






35. Jayne - a security administrator - has noticed that the website and external systems have been subject to many attack attempts. To verify integrity of the website and critical files - Jayne should






36. River Tam - an attacker - calls the company's from desk and tries to gain insider information by providing specific company information to gain the attendant's trust. The front desk immediately alerts the IT department about this incident. This is an






37. An application company sent out a software patch for one of their applications on Monday. The company has been receiving reports about intrusion attacks from their customers on Tuesday. Which of the following attacks does this describe?






38. Hashing algorithms are used to address which of the following?






39. Which of the following is an example of authentication using something Starbuck - a user - has and something she knows?






40. Which of the following BEST explains the security benefit of a standardized server image?






41. Which of the following security tools can Starbuck - a security administrator - use to deter theft?






42. Marketing creates a new folder and requests the following access be assigned: Sales Department - Read Marketing Department - Full Control Inside Sales - Read Write This is an example of which of the following?






43. When moving from an internally controlled environment to a fully outsourced infrastructure environment - such as cloud computing - it is MOST important to...






44. An application programmer reports to River Tam - the security administrator - that the antivirus software installed on a server is interfering with one of the production HR applications - and requests that antivirus be temporarily turned off. How sho






45. Which of the following could River Tam - an administrator - use in a workplace to remove sensitive data at rest from the premises?






46. Which of the following has a default port of 22?






47. Which of the following allows Mal - a security technician - to prevent email traffic from entering the company servers?






48. When reviewing a digital certificate for accuracy - which of the following would Jayne - a security administrator - focus on to determine who affirms the identity of the certificate owner?






49. Which of the following is Starbuck - a security administrator - MOST likely implementing when deleting all the unneeded files and modules of a newly install application?






50. The Chief Information Officer (CIO) wants to protect laptop users from zero day attacks. Which of the following would BEST achieve the CIO's goal?