SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
Comptia Security +: Cyber Ops
Start Test
Study First
Subjects
:
certifications
,
comptia-security-+
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Which of the following network devices will prevent port scans?
MAC filtering
Firewall
Loop protection
Mandate additional security awareness training for all employees.
2. Which of the following is the purpose of the spanning tree protocol?
Spam filter
Loop protection
Cross-site scripting
Temperature and humidity controls
3. Which of the following is BEST described by a scenario where organizational management chooses to implement an internal Incident Response Structure for the business?
Mitigation
SSH
Spam fitters
23
4. Which of the following security tools can Starbuck - an administrator - implement to mitigate the risks of theft?
Device encryption
Subnetting
Improper input validation
Accounting should be given read/write access to network share A and read access to network share B. River Tam should be given read access for the specific document on network share A.
5. Which of the following BEST allows Mal - a security administrator - to determine the type - source - and flags of the packet traversing a network for troubleshooting purposes?
NAC
Protocol analyzers
E-discovery
Mandated security configurations have been made to the operating system.
6. Which of the following authentication protocols forces centralized wireless authentication?
Separation of duties
AP power levels
Penetration test
WPA2-Enterprise
7. While River Tam is logging into the server from her workstation - she notices Mal watching her enter the username and password. Which of the following social engineering attacks is Mal executing?
dcfldd
Fail state of the system
Shoulder surfing
PGP
8. Which of the following malware types is MOST commonly associated with command and control?
It is faster to encrypt an individual file.
NIPS
WPA2-Enterprise
Botnets
9. Which of the following may cause Starbuck - the security administrator - to seek an ACL work around?
The DES algorithm is run three consecutive times against the item being encrypted.
Cross-site scripting
23
Zero day exploit
10. Mal - the Chief Executive Officer (CEO) of a company - has increased his travel plans for the next two years to improve business relations. Which of the following would need to be in place in case something happens to Pete?
Server-side input validation results in a more secure system than client-side input validation.
Spam filter
Cipher lock combination and proximity badge
Succession planning
11. Starbuck - an IT security technician working at a bank - has implemented encryption between two locations. Which of the following security concepts BEST exemplifies the protection provided by this example?
Confidentiality
22
CA
NAC
12. While traveling Jayne - an employee - decides he would like to download some new movies onto his corporate laptop. While installing software designed to download movies from multiple computers across the Internet. Jayne agrees to share portions of hi
Antenna placement; Power-level control
Continuous monitoring
Software as a Service
P2P
13. The human resources department of a company has requested full access to all network resources - including those of the financial department. Starbuck - the administrator - denies this - citing...
DES;3 DES
Establish a MAC limit and age
Separation of duties
CA
14. A company is performing internal security audits after a recent exploitation on one of their proprietary applications. River Tam - the security auditor - is given the workstation with limited documentation regarding the application installed for the
Sanitization using appropriate software
Single point of failure
Gray box
Deploying and using a trusted OS
15. Which of the following is an attack where Mal spreads USB thumb drives throughout a bank's parking lot in order to have malware installed on the banking systems?
80
The IDS does not identify a buffer overflow
Create file hashes for website and critical system files - and compare the current file hashes to the baseline at regular time intervals.
Social engineering
16. Which of the following is similar to a smurf attack - but uses UDP instead to ICMP?
Establish a MAC limit and age
WPA2-PSK
Fraggle attack
GSM phone card and PIN
17. Which of the following security concepts establishes procedures where creation and approval are performed through distinct functions?
Memory dump - ARP cache
Separation of duties
Change management
Rootkit
18. River Tam - a security analyst - suspects that a rogue web server is running on the network. Which of the following would MOST likely be used to identify the server's IP address?
Discretionary access control
The system shall require users to authenticate to the system with a combination of a password or PIN and a smartcard
Encrypt all confidential data.
Port scanner
19. Which of the following does Starbuck - a software developer - need to do after compiling the source code of a program to attest the authorship of the binary?
20. Which of the following is Starbuck - a security administrator - MOST likely implementing when deleting all the unneeded files and modules of a newly install application?
Cable locks
PII handling
TACACS+
Application hardening
21. River Tam - a security guard - reports that the side of the company building has been marked with spray paint. Which of the following could this be an example of?
War chalking
Log reviews
Spam filter
Assign multiple roles to the existing user ID
22. An SQL injection vulnerability can be caused by which of the following?
Improper input validation
Logic bomb
Separation of duties
Spam filter
23. Mal - a security engineer - is trying to inventory all servers in a rack. The engineer launches RDP sessions to five different PCs and notices that the hardware properties are similar. Additionally - the MAC addresses of all five servers appear on th
Ask the programmer to replicate the problem in a test environment.
Clustering
The system is virtualized
Vulnerability scan
24. Which of the following is BEST used to break a group of IP addresses into smaller network segments or blocks?
Penetration testing
Spam filter
Fuzzing
Subnetting
25. An application programmer reports to River Tam - the security administrator - that the antivirus software installed on a server is interfering with one of the production HR applications - and requests that antivirus be temporarily turned off. How sho
Encrypt all confidential data.
Create file hashes for website and critical system files - and compare the current file hashes to the baseline at regular time intervals.
Cross-site scripting
Ask the programmer to replicate the problem in a test environment.
26. Which of the following is a feature of Kerberos?
P2P
RBAC
Protocol analyzers
Single sign-on
27. Which of the following is the MOST important security requirement for mobile devices storing PII?
Remote data wipe
Cross-site scripting
Establish a MAC limit and age
Fail state of the system
28. Which of the following BEST describes a denial of service attack?
River Tam - the attacker - overwhelms a system or application - causing it to crash and bring the server down to cause an outage.
Image hashes
Log reviews
23
29. Which of the following is the MOST secure protocol for Mal - an administrator - to use for managing network devices?
Update the CRL; Deploy OCSP
SSH
Evil twin
Cross-site scripting
30. Mal - a security administrator - has configured and implemented an additional public intermediate CA. Which of the following must Mal submit to the major web browser vendors in order for the certificates - signed by this intermediate - to be trusted?
31. Which of the following administrative controls BEST mitigates the risk of ongoing inappropriate employee activities in sensitive areas?
Notify security to identify employee's whereabouts.
Personally owned devices
Logic bomb
Mandatory vacations
32. Starbuck - a VPN administrator - was asked to implement an encryption cipher with a MINIMUM effective security of 128-bits. Which of the following should Starbuck select for the tunnel encryption?
Mandatory access control
Blowfish
Gray box
Blue jacking
33. Which of the following is where an unauthorized device is found allowing access to a network?
SQL injection
Separation of duties
Validate the identity of an email sender;Encrypt messages;Decrypt messages
Rogue access point
34. Marketing creates a new folder and requests the following access be assigned: Sales Department - Read Marketing Department - Full Control Inside Sales - Read Write This is an example of which of the following?
RAS
Botnets
Change management
RBAC
35. River Tam - a security analyst - discovers which operating systems the client devices on the network are running by only monitoring a mirror port on the router. Which of the following techniques did River Tam use?
Risk avoidance
Passive finger printing
Update the CRL; Deploy OCSP
Install application updates
36. Which of the following open standards should Mal - a security administrator - select for remote authentication of users?
MAC filtering
RADIUS
Device encryption
Mandate additional security awareness training for all employees.
37. An application company sent out a software patch for one of their applications on Monday. The company has been receiving reports about intrusion attacks from their customers on Tuesday. Which of the following attacks does this describe?
22
The capacity of a system to resist unauthorized changes to stored information
Signature based
Zero day
38. Which of the following are security relevant policies?
Information classification policy; Network access policy; Auditing and monitoring policy
It is faster to encrypt an individual file.
Verify the user's identity
Change management
39. Which of the following can Jayne - an administrator - use to ensure the confidentiality of a file when it is being sent over FTP?
Rogue access point
CRL
Mandatory access control
PGP
40. Which of the following BEST explains the security benefit of a standardized server image?
NIPS
Mandated security configurations have been made to the operating system.
P2P
Zero day
41. Which of the following password policies is the MOST effective against a brute force network attack?
RAID 5 and a storage area network
Account lockout
WPA2-PSK
NAC
42. A company notices that there is a flaw in one of their proprietary programs that the company runs in-house. The flaw could cause damage to the HVAC system. Which of the following would the company transfer to an insurance company?
WPA2-Enterprise
Power levels
Ticket granting server
Risk
43. River Tam - a network security administrator - has been tasked with setting up a guest wireless network for her corporation. The requirements for this connection state that it must have password authentication - with passwords being changed every wee
Risk
Discretionary access control
WPA2-PSK
SSH
44. Starbuck - a security administrator - wants to prevent users in sales from accessing their servers after 6:00 p.m. - and prevent them from accessing accounting's network at all times. Which of the following should Starbuck implement to accomplish the
Sanitization using appropriate software
Time of day restrictions;Access control lists
The capacity of a system to resist unauthorized changes to stored information
Encrypt all confidential data.
45. Account lockout is a mitigation strategy used by Starbuck - the administrator - to combat which of the following attacks?
DES;3 DES
Mandate additional security awareness training for all employees.
Improper input validation
Dictionary; Brute force
46. A company has sent all of its private keys to a third party. The third party company has created a secure list of these keys. Which of the following has just been implemented?
Dual-homing a server
Port forwarding
Change management
Key escrow
47. Which of the following malware types is MOST likely to execute its payload after Starbuck - an employee - has left the company?
Succession planning
Gray box
Logic bomb
Fraggle attack
48. Which of the following techniques floods an application with data in an attempt to find vulnerabilities?
WPA2-PSK
Input validation
Mandatory Access Controls
Fuzzing
49. Traffic has stopped flowing to and from the company network after the inline IPS hardware failed. Which of the following has occurred?
PEAP
Failsafe
Private key
NIPS
50. Jayne - a security administrator - needs to Telnet into a router to change some configurations. Which of the following ports would need to be open to allow Jayne to change the configurations?
Protocol analyzers
Notify security to identify employee's whereabouts.
23
Assign multiple roles to the existing user ID