SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
Comptia Security +: Cyber Ops
Start Test
Study First
Subjects
:
certifications
,
comptia-security-+
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Which of the following allows Mal - a security technician - to prevent email traffic from entering the company servers?
SSH
Spam filter
Impersonation
Ticket granting server
2. Several users' computers are no longer responding normally and sending out spam email to the users' entire contact list. This is an example of which of the following?
Worm outbreak
Separation of duties
Failsafe
Cross-site scripting
3. Which of the following network devices will prevent port scans?
Firewall
Temperature and humidity controls
Personal firewall
Zero day exploit
4. Starbuck has a vendors server in-house for shipping and receiving. She wants to ensure that if the server goes down that the server in-house will be operational again within 24 hours. Which of the following should Starbuck define with the vendor?
The intermediate CA's public key
Mandatory vacations
Mean time to restore
Dictionary; Brute force
5. Which of the following is the MOST important security requirement for mobile devices storing PII?
Remote data wipe
Clustering
Impact; Likelihood
NIPS
6. The accounting department needs access to network share A to maintain a number of financial reporting documents. The department also needs access to network share B in HR to view payroll documentation for cross-referencing items. River Tam - an admin
Group based privileges
Log reviews
Accounting should be given read/write access to network share A and read access to network share B. River Tam should be given read access for the specific document on network share A.
Information classification policy; Network access policy; Auditing and monitoring policy
7. An SQL injection vulnerability can be caused by which of the following?
Code review
Proxy server
Improper input validation
Update the CRL; Deploy OCSP
8. Which of the following is BEST used to break a group of IP addresses into smaller network segments or blocks?
Risk
Key escrow
Subnetting
Rootkit
9. Jayne's CRL is over six months old. Which of the following could Jayne do in order to ensure he has the current information?
Update the CRL; Deploy OCSP
Fraggle attack
Signature based
Mandatory vacations
10. Mal - a security administrator - has configured and implemented an additional public intermediate CA. Which of the following must Mal submit to the major web browser vendors in order for the certificates - signed by this intermediate - to be trusted?
11. Which of the following is where an unauthorized device is found allowing access to a network?
Rogue access point
Cable locks
WPA2-PSK
Separation of duties
12. When Mal - an employee - leaves a company - which of the following should be updated to ensure Pete's security access is reduced or eliminated?
Humidity controls
IPS
Fraggle attack
CRL
13. Which of the following procedures would be used to mitigate the risk of an internal developer embedding malicious code into a production system?
Change management
SQL injection
Assign multiple roles to the existing user ID
Update the CRL; Deploy OCSP
14. Mal - a security administrator - would like to implement laptop encryption to protect data. The Chief Executive Officer (CEO) believes this will be too costly to implement and decides the company will purchase an insurance policy instead. Which of th
The security company is provided with no information about the corporate network or physical locations.
Verify the user's identity
P2P
Risk avoidance
15. Which of the following can Mal - an administrator - use to verify that a downloaded file was not corrupted during the transfer?
MD5 checksum
Mandatory Access Controls
Cold site
Account lockout
16. Jayne - a systems security engineer - is determining which credential-type authentication to use within a planned 802.1x deployment. He is looking for a method that does not require a client certificate - has a server side certificate - and uses TLS
Non-repudiation
IPS
E-discovery
PEAP-MSCHAPv2
17. River Tam - a security guard - reports that the side of the company building has been marked with spray paint. Which of the following could this be an example of?
Power levels
Compare hashes of the original source and system image.
War chalking
Signature based
18. Which of the following malware types is MOST commonly associated with command and control?
Install application updates
Account expiration
Humidity controls
Botnets
19. Which of the following is the BEST incident response procedure to take when a previous employee enters a facility?
20. Which of the following are restricted to 64-bit block sizes?
E-discovery
dcfldd
DES;3 DES
PGP
21. Which of the following attacks is characterized by River Tam attempting to send an email from a Chief Information Officer's (CIO's) non-corporate email account to an IT staff member in order to have a password changed?
Impersonation
Failsafe
Antenna placement; Power-level control
Signature based
22. Which of the following security tools can Starbuck - an administrator - implement to mitigate the risks of theft?
Rogue access point
Software as a Service
Device encryption
Time of day restrictions;Access control lists
23. Which of the following should be implemented to restrict wireless access to the hardware address of a NIC?
TPM
Full disk encryption
MAC filtering
IV attack
24. Mal is reporting an excessive amount of junk mail on the network email server. Which of the following would ONLY reduce the amount of unauthorized mail?
Spam fitters
Humidity controls
Risk avoidance
The DES algorithm is run three consecutive times against the item being encrypted.
25. River Tam - a user - on a public Wi-Fi network logs into a webmail account and is redirected to a search engine. Which of the following attacks may be occurring?
Evil twin
RAID 5 and a storage area network
Sanitization using appropriate software
NTLM
26. Traffic has stopped flowing to and from the company network after the inline IPS hardware failed. Which of the following has occurred?
Memory dump - ARP cache
SSH
AP power levels
Failsafe
27. Mal - the Chief Executive Officer (CEO) of a company - has increased his travel plans for the next two years to improve business relations. Which of the following would need to be in place in case something happens to Pete?
Botnets
Succession planning
Dual-homing a server
P2P
28. River Tam - the software security engineer - is trying to detect issues that could lead to buffer overflows or memory leaks in the company software. Which of the following would help River Tam automate this detection?
80
Fuzzing
21
Clustering
29. When used alone - which of the following controls mitigates the risk of River Tam - an attacker - launching an online brute force password attack?
Account lockout
Fuzzing
Use Starbuck's private key to sign the binary
NTLM
30. Which of the following describes the ability for a third party to verify the sender or recipient of a given electronic message during authentication?
Log reviews
Non-repudiation
Proxies
Port forwarding
31. Which of the following is a policy that would force all users to organize their areas as well as help in reducing the risk of possible data theft?
Full disk encryption
Power levels
Clean desk policy
Mandatory access control
32. Which of the following combinations represents multifactor authentication?
MD5
Passive finger printing
Shoulder surfing
Cipher lock combination and proximity badge
33. Which of the following reduces the likelihood of a single point of failure when a server fails?
80
Clustering
Sanitization using appropriate software
Mandated security configurations have been made to the operating system.
34. Which of the following may cause Starbuck - the security administrator - to seek an ACL work around?
Separation of duties
Shoulder surfing
Encrypt all confidential data.
Zero day exploit
35. Which of the following can River Tam - a security administrator - implement to ensure that encrypted files and devices can be recovered if the passphrase is lost?
Key escrow
Mandatory access control
Signature based
TACACS+; SSH
36. Which of the following mitigates the risk of proprietary information being compromised?
Full disk
File encryption
Code review
Key escrow
37. While River Tam is logging into the server from her workstation - she notices Mal watching her enter the username and password. Which of the following social engineering attacks is Mal executing?
Shoulder surfing
Vishing
Public key
Code review
38. Which of the following functions of a firewall allows Mal - an administrator - to map an external service to an internal host?
RAID 5 and a storage area network
Penetration test
Business impact assessment
Port forwarding
39. Starbuck - a user - has reported an increase in email phishing attempts. Which of the following can be implemented to mitigate the attacks?
It is faster to encrypt an individual file.
Blue jacking
Anti-spam
Trust model
40. Which of the following risks could IT management be mitigating by removing an all-in-one device?
Personally owned devices
Blue jacking
Single point of failure
Accounting should be given read/write access to network share A and read access to network share B. River Tam should be given read access for the specific document on network share A.
41. Which of the following should River Tam - a security technician - perform as the FIRST step when creating a disaster recovery plan for a mission critical accounting system?
Discretionary access control
Business impact assessment
Use Starbuck's private key to sign the binary
Protocol analyzers
42. River Tam - an IT administrator - wants to protect a cluster of servers in a DMZ from zero day attacks. Which of the following would provide the BEST level of protection?
Clustering
Subnetting
PGP
NIPS
43. The Chief Information Security Officer (CISO) tells the network administrator that a security company has been hired to perform a penetration test against their network. The security company asks the CISO which type of testing would be most beneficia
The security company is provided with no information about the corporate network or physical locations.
Cold site
Deploy an anti-spam device to protect the network.
Establish a MAC limit and age
44. To mitigate the adverse effects of network modifications - which of the following should Jayne - the security administrator - implement?
Code review
Change management
Cross-site scripting
The intermediate CA's public key
45. Which of the following inspects traffic entering or leaving a network to look for anomalies against expected baselines?
Mandatory vacations
IPS
Create file hashes for website and critical system files - and compare the current file hashes to the baseline at regular time intervals.
Antenna placement; Power-level control
46. Which of the following is an improved version of the LANMAN hash?
Proxies
Dual-homing a server
Proxy server
NTLM
47. Which of the following ports should be open in order for River Tam and Mal - users - to identify websites by domain name?
RAS
PEAP-MSCHAPv2
Fuzzing
UDP 53
48. Social networking sites are used daily by the marketing team for promotional purposes. However - confidential company information - including product pictures and potential partnerships - have been inadvertently exposed to the public by dozens of emp
21
Mandate additional security awareness training for all employees.
ARP poisoning
Anti-spam
49. Which of the following attacks would be used if River Tam - a user - is receiving unwanted text messages?
Firewall
Blue jacking
Worm outbreak
The capacity of a system to resist unauthorized changes to stored information
50. Which of the following security tools can Starbuck - a security administrator - use to deter theft?
Cable locks
LDAP
Vishing
TPM