SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
Comptia Security +: Cyber Ops
Start Test
Study First
Subjects
:
certifications
,
comptia-security-+
,
it-skills
Instructions:
Answer
50
questions in
15 minutes
.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. The IT Security Department has completed an internal risk assessment and discovered the use of an outdated antivirus definition file. Which of the following is the NEXT step that management should take?
Social engineering
Mitigate risk and develop a maintenance plan.
Install both the private and the public key on the web server.
Impact; Likelihood
2. Which of the following allows active exploitation of security vulnerabilities on a system or network for the purpose of determining true impact?
TACACS+; SSH
MD5
Full disk encryption
Penetration testing
3. Mal - a user - submitted a form on the Internet but received an unexpected response shown below Server Error in "/" Application Runtime error in script on asp.net version 2.0 Which of the following controls should be put in place to prevent Mal from
Install both the private and the public key on the web server.
Mandate additional security awareness training for all employees.
PEAP-MSCHAPv2
Error handling
4. Workers of a small local organization have implemented an off-site location in which the organization can resume operations within 10 business days in the event of a disaster. This type of site is BEST known as which of the following?
Cold site
80
SNMPv3
Single sign-on
5. Which of the following security tools can Starbuck - an administrator - implement to mitigate the risks of theft?
Compare hashes of the original source and system image.
Impersonation
Device encryption
PGP
6. Mal - a network administrator - implements the spanning tree protocol on network switches. Which of the following issues does this address?
RAS
Two fish
Loop protection
Mean time to restore
7. Jayne - the administrator - has been told to confirm what account an email was sent from. Which of the following is this an example of?
Account expiration
E-discovery
21
Risk avoidance
8. Starbuck - a security technician - wants to implement secure wireless with authentication. Which of the following allows for wireless to be authenticated via MSCHAPv2?
Error handling
Trust model
Non-repudiation
PEAP
9. Which of the following is the BEST incident response procedure to take when a previous employee enters a facility?
10. Jayne - a system administrator - wants to establish a nightly available SQL database. Which of the following would be implemented to eliminate a single point of failure in storage and servers?
Deploy an anti-spam device to protect the network.
Full disk
Zero day attack
RAID 5 and a storage area network
11. A data loss prevention strategy would MOST likely incorporate which of the following to reduce the risk associated with data loss?
Enforced acceptable usage policy - encryption of confidential emails - and monitoring of communications leaving the organization.
Port scan
Proxy server
Assign multiple roles to the existing user ID
12. Mal - the Chief Executive Officer (CEO) of a company - has increased his travel plans for the next two years to improve business relations. Which of the following would need to be in place in case something happens to Pete?
Succession planning
Key escrow
Use Starbuck's private key to sign the binary
Detective
13. Mal - a security administrator - would like to implement laptop encryption to protect data. The Chief Executive Officer (CEO) believes this will be too costly to implement and decides the company will purchase an insurance policy instead. Which of th
Use Starbuck's private key to sign the binary
Error handling
The system shall require users to authenticate to the system with a combination of a password or PIN and a smartcard
Risk avoidance
14. River Tam - an attacker - is recording a person typing in their ID number into a keypad to gain access to the building. River Tam then calls the helpdesk and informs them that their PIN no longer works and would like to change it. Which of the follow
Cable locks
PII handling
Impersonation
Account lockout
15. Which of the following protocols provides Mal - an administrator - with the HIGHEST level of security for device traps?
Proxies
Loop protection
Personally owned devices
SNMPv3
16. Which of the following is an improved version of the LANMAN hash?
ARP poisoning
NTLM
Use Starbuck's private key to sign the binary
Application hardening
17. While conducting a network audit - River Tam - a security administrator - discovers that most clients are routing their network traffic through a desktop client instead of the company router. Which of the following is this attack type?
ARP poisoning
PII handling
Humidity controls
Device encryption
18. Which of the following could River Tam - an administrator - use in a workplace to remove sensitive data at rest from the premises?
Change management
Personally owned devices
Mandatory access control
Penetration testing
19. An application programmer reports to River Tam - the security administrator - that the antivirus software installed on a server is interfering with one of the production HR applications - and requests that antivirus be temporarily turned off. How sho
Confidentiality
Integrity
Ask the programmer to replicate the problem in a test environment.
PII handling
20. Which of the following malware types is BEST described as protecting itself by hooking system processes and hiding its presence?
Port scanner
Key escrow
Rootkit
CRL
21. When Mal - an employee - leaves a company - which of the following should be updated to ensure Pete's security access is reduced or eliminated?
Ask the programmer to replicate the problem in a test environment.
CRL
Fraggle attack
Verify the user's identity
22. Which of the following is the MOST secure protocol for Mal - an administrator - to use for managing network devices?
Single point of failure
SSH
Use Starbuck's private key to sign the binary
CRL
23. Which of the following would help Mal - an administrator - prevent access to a rogue access point connected to a switch?
Cable locks
Private key
Establish a MAC limit and age
SSH
24. After setting up a root CA. which of the following can Mal - a security administrator - implement to allow intermediate CAs to handout keys and certificates?
Discretionary access control
Cold site
Cable locks
Trust model
25. The accounting department needs access to network share A to maintain a number of financial reporting documents. The department also needs access to network share B in HR to view payroll documentation for cross-referencing items. River Tam - an admin
Discretionary access control
Accounting should be given read/write access to network share A and read access to network share B. River Tam should be given read access for the specific document on network share A.
RBAC
Cold site
26. Which of the following should Starbuck - the security administrator - do FIRST when an employee reports the loss of a corporate mobile device?
Code review
Power levels
Remotely initiate a device wipe
RAID 5 and a storage area network
27. Starbuck's - a user - word processing software is exhibiting strange behavior - opening and closing itself at random intervals. There is no other strange behavior on the system. Which of the following would mitigate this problem in the future?
RBAC
Fail state of the system
Deploy an anti-spam device to protect the network.
Install application updates
28. Which of the following malware types is MOST likely to execute its payload after Starbuck - an employee - has left the company?
CA
PEAP-MSCHAPv2
Logic bomb
Gray box
29. Which of the following mitigates the risk of proprietary information being compromised?
Passive finger printing
Worm outbreak
File encryption
Cross-site scripting
30. Which of the following is the MAIN benefit of server-side versus client-side input validation?
CRL
dcfldd
Verify the user's identity
Server-side input validation results in a more secure system than client-side input validation.
31. Which of the following BEST describes a software vulnerability that is actively being used by River Tam and Starbuck - attackers - before the vendor releases a protective patch or update?
Zero day attack
Social engineering
Antenna placement; Power-level control
Key escrow
32. A company needs to remove sensitive data from hard drives in leased computers before the computers are returned to the supplier. Which of the following is the BEST solution?
Passive finger printing
Port forwarding
Sanitization using appropriate software
VLAN mismatch is occurring.
33. Mal - a security administrator - wants to secure remote telnet services and decides to use the services over SSH. Which of the following ports should Mal allow on the firewall by default?
Install application updates
22
It is faster to encrypt an individual file.
Fuzzing
34. A company notices that there is a flaw in one of their proprietary programs that the company runs in-house. The flaw could cause damage to the HVAC system. Which of the following would the company transfer to an insurance company?
Vishing
Detective
CA
Risk
35. Mal - the security administrator - is implementing a web content fitter. Which of the following is the MOST important design consideration in regards to availability?
Power levels
UDP 53
Fail state of the system
Mandated security configurations have been made to the operating system.
36. Which of the following network solutions would BEST allow Starbuck - a security technician - to host an extranet application for her company?
Image hashes
Proxies
Software as a Service
Full disk encryption
37. Jayne - a security administrator - is responsible for provisioning role-based user accounts in an enterprise environment. A user has a temporary business need to perform multiple roles within the organization. Which of the following is the BEST solut
Proxy server
The IDS does not identify a buffer overflow
Improper input validation
Assign multiple roles to the existing user ID
38. While traveling - users need access to an internal company web server that contains proprietary information. Mal - the security administrator - should implement a...
Mandated security configurations have been made to the operating system.
Separation of duties
RAS
21
39. A company has sent all of its private keys to a third party. The third party company has created a secure list of these keys. Which of the following has just been implemented?
Blowfish
Humidity controls
Remote wipe
Key escrow
40. Jayne - a security administrator - needs to Telnet into a router to change some configurations. Which of the following ports would need to be open to allow Jayne to change the configurations?
Protocol analyzer
23
Impact; Likelihood
Rogue access point
41. Which of the following is BEST described by a scenario where organizational management chooses to implement an internal Incident Response Structure for the business?
Software as a Service
Clean desk policy
Impersonation
Mitigation
42. Mal - a security administrator - has configured and implemented an additional public intermediate CA. Which of the following must Mal submit to the major web browser vendors in order for the certificates - signed by this intermediate - to be trusted?
43. River Tam - a forensic investigator - believes that the system image she was presented with is not the same as the original source. Which of the following should be done to verify whether or not the image has been tampered with?
Warm site
SSH
Compare hashes of the original source and system image.
Error handling
44. Starbuck - a user - has reported an increase in email phishing attempts. Which of the following can be implemented to mitigate the attacks?
Anti-spam
Zero day exploit
Impersonation
Mitigation
45. River Tam - an attacker - calls the company's from desk and tries to gain insider information by providing specific company information to gain the attendant's trust. The front desk immediately alerts the IT department about this incident. This is an
Impersonation
Validate the identity of an email sender;Encrypt messages;Decrypt messages
Install both the private and the public key on the web server.
Mandatory Access Controls
46. Starbuck - a security administrator - has applied security labels to files and folders to manage and restrict access. Which of the following is Starbuck using?
Something you are - something you have
RAS
Mean time to restore
Mandatory access control
47. River Tam - the security engineer - has discovered that a breach is in progress on a non-production system of moderate importance. Which of the following should River Tam collect FIRST?
Confidentiality
SQL injection
Account expiration
Memory dump - ARP cache
48. Which of the following security tools can Starbuck - a security administrator - use to deter theft?
Server-side input validation results in a more secure system than client-side input validation.
Cable locks
Improper input validation
Zero day attack
49. Which of the following password policies is the MOST effective against a brute force network attack?
22
Account lockout
The system is virtualized
Host based firewall
50. Which of the following implements two factor authentication based on something you know and something you have?
The system shall require users to authenticate to the system with a combination of a password or PIN and a smartcard
MD5
Mitigate risk and develop a maintenance plan.
80