SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
Comptia Security +: Cyber Ops
Start Test
Study First
Subjects
:
certifications
,
comptia-security-+
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Which of the following are restricted to 64-bit block sizes?
Personal firewall
DES;3 DES
Succession planning
Mandate additional security awareness training for all employees.
2. Which of the following attacks is manifested as an embedded HTML image object or JavaScript image tag in an email?
Mitigate risk and develop a maintenance plan.
Fail state of the system
Impersonation
Cross-site scripting
3. The IT Security Department has completed an internal risk assessment and discovered the use of an outdated antivirus definition file. Which of the following is the NEXT step that management should take?
Install application updates
Private key
Separation of duties
Mitigate risk and develop a maintenance plan.
4. Starbuck - a security administrator - has completed the imaging process for 20 computers that were deployed. The image contains the operating system and all required software. Which of the following is this an example of?
80
WPA2-PSK
VLAN mismatch is occurring.
Deploying and using a trusted OS
5. The corporate NIPS requires a daily download from its vendor with updated definitions in order to block the latest attacks. Which of the following describes how the NIPS is functioning?
Signature based
Cipher lock combination and proximity badge
Mandatory access control
Mandate additional security awareness training for all employees.
6. Which of the following would be the BEST reason for Starbuck - a security administrator - to initially select individual file encryption over whole disk encryption?
Fraggle attack
80
It is faster to encrypt an individual file.
Encrypt all confidential data.
7. To mitigate the adverse effects of network modifications - which of the following should Jayne - the security administrator - implement?
TACACS+
Change management
Remote data wipe
TACACS+; SSH
8. Which of the following does Starbuck - a software developer - need to do after compiling the source code of a program to attest the authorship of the binary?
9. Which of the following is BEST utilized to actively test security controls on a particular system?
Penetration test
PII handling
Mitigation
Detective
10. River Tam - a forensic investigator - believes that the system image she was presented with is not the same as the original source. Which of the following should be done to verify whether or not the image has been tampered with?
Compare hashes of the original source and system image.
Fraggle attack
NIPS
PEAP-MSCHAPv2
11. River Tam - a security administrator - suspects that a web server may be under attack. The web logs have several entries containing variations of the following entries: 'or 1=1-- or1'=1-- 'or1=1'
Spam filter
Ticket granting server
SQL injection
LDAP
12. A company is installing a wireless network in a building that houses several tenants. Which of the following should be considered to make sure none of the other tenants can detect the company's wireless network?
PEAP
Vishing
Antenna placement; Power levels
TACACS+; SSH
13. Jayne - a security administrator - wants to allow content owners to determine who has access to tiles. Which of the following access control types does this describe?
Discretionary access control
Zero day
MD5 checksum
Cipher lock combination and proximity badge
14. Which of the following encrypts the body of a packet - rather than just the password - while sending information?
TACACS+
The system is virtualized
The intermediate CA's public key
RAS
15. An application company sent out a software patch for one of their applications on Monday. The company has been receiving reports about intrusion attacks from their customers on Tuesday. Which of the following attacks does this describe?
Zero day
Social engineering
Time of day restrictions;Access control lists
AP power levels
16. River Tam - an attacker - calls the company's from desk and tries to gain insider information by providing specific company information to gain the attendant's trust. The front desk immediately alerts the IT department about this incident. This is an
Notify security to identify employee's whereabouts.
Impersonation
Port scan
Clustering
17. The fundamental information security principals include confidentiality - availability and which of the following?
Clean desk policy
The capacity of a system to resist unauthorized changes to stored information
Business impact assessment
TACACS+; SSH
18. Which of the following is an example of authentication using something Starbuck - a user - has and something she knows?
Mandatory access control
Code review
Cable locks
GSM phone card and PIN
19. After setting up a root CA. which of the following can Mal - a security administrator - implement to allow intermediate CAs to handout keys and certificates?
The IDS does not identify a buffer overflow
Trust model
SSH
dcfldd
20. Mal - a security administrator - would like to implement laptop encryption to protect data. The Chief Executive Officer (CEO) believes this will be too costly to implement and decides the company will purchase an insurance policy instead. Which of th
Risk avoidance
Something you are - something you have
River Tam - the attacker - overwhelms a system or application - causing it to crash and bring the server down to cause an outage.
Passive finger printing
21. An example of a false negative
SSH
The IDS does not identify a buffer overflow
Humidity controls
Cross-site scripting
22. Which of the following should River Tam - a security technician - perform as the FIRST step when creating a disaster recovery plan for a mission critical accounting system?
NAC
Anti-spam
Host based firewall
Business impact assessment
23. The accounting department needs access to network share A to maintain a number of financial reporting documents. The department also needs access to network share B in HR to view payroll documentation for cross-referencing items. River Tam - an admin
E-discovery
Accounting should be given read/write access to network share A and read access to network share B. River Tam should be given read access for the specific document on network share A.
Port scanner
Cold site
24. Starbuck - an IT security technician working at a bank - has implemented encryption between two locations. Which of the following security concepts BEST exemplifies the protection provided by this example?
Confidentiality
Antenna placement; Power-level control
Single sign-on
Deploying and using a trusted OS
25. River Tam - an attacker - is recording a person typing in their ID number into a keypad to gain access to the building. River Tam then calls the helpdesk and informs them that their PIN no longer works and would like to change it. Which of the follow
P2P
Failsafe
RADIUS
Impersonation
26. Jayne - the administrator - has been told to confirm what account an email was sent from. Which of the following is this an example of?
E-discovery
Create file hashes for website and critical system files - and compare the current file hashes to the baseline at regular time intervals.
MAC filtering
Mandatory access control
27. Which of the following password policies is the MOST effective against a brute force network attack?
PII handling
Port forwarding
Time of day restrictions;Access control lists
Account lockout
28. Which of the following controls mitigates the risk of Jayne - an attacker - gaining access to a company network by using a former employee's credential?
Clean desk policy
DES;3 DES
Account expiration
Update the CRL; Deploy OCSP
29. Which of the following would MOST likely be implemented in order to prevent employees from accessing certain websites?
Blowfish
Proxy server
Risk
File encryption
30. Social networking sites are used daily by the marketing team for promotional purposes. However - confidential company information - including product pictures and potential partnerships - have been inadvertently exposed to the public by dozens of emp
The security company is provided with no information about the corporate network or physical locations.
Trust model
The DES algorithm is run three consecutive times against the item being encrypted.
Mandate additional security awareness training for all employees.
31. The Chief Information Officer (CIO) wants to protect laptop users from zero day attacks. Which of the following would BEST achieve the CIO's goal?
Private key
Host based firewall
PGP
Information classification policy; Network access policy; Auditing and monitoring policy
32. A company notices that there is a flaw in one of their proprietary programs that the company runs in-house. The flaw could cause damage to the HVAC system. Which of the following would the company transfer to an insurance company?
Risk
Full disk
Separation of duties
80
33. Mal - a security administrator - has observed repeated attempts to break into the network. Which of the following is designed to stop an intrusion on the network?
NIPS
Spam filter
Rogue access point
Account lockout
34. Starbuck - a security administrator - has applied security labels to files and folders to manage and restrict access. Which of the following is Starbuck using?
Full disk encryption
Proxies
Loop protection
Mandatory access control
35. Which of the following mitigates the risk of proprietary information being compromised?
Zero day
File encryption
Blue jacking
Two fish
36. River Tam - a security administrator - has configured a trusted OS implementation on her servers. Which of the following controls are enacted by the trusted OS implementation?
SSH
PEAP
Spam fitters
Mandatory Access Controls
37. Which of the following commands can Jayne - an administrator - use to create a forensically sound hard drive image?
22
dcfldd
RAID 5 and a storage area network
CRL
38. Which of the following is BEST used to break a group of IP addresses into smaller network segments or blocks?
Subnetting
SSH
MAC filtering
AP power levels
39. Which of the following reduces the likelihood of a single point of failure when a server fails?
MD5 checksum
AP power levels
Clustering
Social engineering
40. Jayne - a systems security engineer - is determining which credential-type authentication to use within a planned 802.1x deployment. He is looking for a method that does not require a client certificate - has a server side certificate - and uses TLS
PEAP-MSCHAPv2
Single sign-on
Remotely initiate a device wipe
Compare hashes of the original source and system image.
41. Which of the following security tools can Starbuck - a security administrator - use to deter theft?
ARP poisoning
Clustering
Cable locks
Remote wipe
42. Which of the following has a default port of 22?
TPM
Dictionary; Brute force
Zero day attack
SSH
43. Which of the following should be implemented to restrict wireless access to the hardware address of a NIC?
Humidity controls
MAC filtering
Verify the user's identity
LDAP
44. Which of the following is used to verify the identity of the sender of a signed email?
To limit the number of endpoints connected through the same switch port
Zero day
Account expiration
Public key
45. When reviewing a digital certificate for accuracy - which of the following would Jayne - a security administrator - focus on to determine who affirms the identity of the certificate owner?
CA
Separation of duties
Social engineering
SNMPv3
46. When Mal - an employee - leaves a company - which of the following should be updated to ensure Pete's security access is reduced or eliminated?
Warm site
CA
Protocol analyzers
CRL
47. A company needs to remove sensitive data from hard drives in leased computers before the computers are returned to the supplier. Which of the following is the BEST solution?
Impersonation
Host based firewall
Code review
Sanitization using appropriate software
48. Which of the following are security relevant policies?
Evil twin
Install both the private and the public key on the web server.
Logic bomb
Information classification policy; Network access policy; Auditing and monitoring policy
49. Mal is reporting an excessive amount of junk mail on the network email server. Which of the following would ONLY reduce the amount of unauthorized mail?
WPA2-PSK
Impersonation
Spam fitters
Gray box
50. Starbuck has a vendors server in-house for shipping and receiving. She wants to ensure that if the server goes down that the server in-house will be operational again within 24 hours. Which of the following should Starbuck define with the vendor?
Dual-homing a server
Mean time to restore
Penetration test
Clean desk policy