SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
Comptia Security +: Cyber Ops
Start Test
Study First
Subjects
:
certifications
,
comptia-security-+
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Which of the following data loss prevention strategies mitigates the risk of replacing hard drives that cannot be sanitized?
Code review
Host based firewall
Warm site
Full disk encryption
2. Which of the following control types is video monitoring?
Detective
TACACS+
Power levels
TPM
3. Marketing creates a new folder and requests the following access be assigned: Sales Department - Read Marketing Department - Full Control Inside Sales - Read Write This is an example of which of the following?
Deploy an anti-spam device to protect the network.
Humidity controls
Accounting should be given read/write access to network share A and read access to network share B. River Tam should be given read access for the specific document on network share A.
RBAC
4. While River Tam is logging into the server from her workstation - she notices Mal watching her enter the username and password. Which of the following social engineering attacks is Mal executing?
Separation of duties
Shoulder surfing
Cross-site scripting
Mitigate risk and develop a maintenance plan.
5. Jayne - a security administrator - is responsible for provisioning role-based user accounts in an enterprise environment. A user has a temporary business need to perform multiple roles within the organization. Which of the following is the BEST solut
Clean desk policy
PEAP-MSCHAPv2
Impersonation
Assign multiple roles to the existing user ID
6. Which of the following security concepts establishes procedures where creation and approval are performed through distinct functions?
Separation of duties
MD5
Remote data wipe
Anti-spam
7. Which of the following may cause Starbuck - the security administrator - to seek an ACL work around?
dcfldd
Integrity
Proxy server
Zero day exploit
8. Jayne - a security administrator - needs to Telnet into a router to change some configurations. Which of the following ports would need to be open to allow Jayne to change the configurations?
Cross-site scripting
File encryption
E-discovery
23
9. Starbuck - an IT security technician working at a bank - has implemented encryption between two locations. Which of the following security concepts BEST exemplifies the protection provided by this example?
Confidentiality
WPA2-Enterprise
NIPS
MD5 checksum
10. Which of the following ports would be blocked if Mal - a security administrator - wants to disable FTP?
21
Key escrow
Deploying and using a trusted OS
RAS
11. An example of a false negative
Social engineering
SSH
Ticket granting server
The IDS does not identify a buffer overflow
12. Which of the following would MOST likely be implemented in order to prevent employees from accessing certain websites?
Fail state of the system
Proxy server
Botnets
Fuzzing
13. Which of the following is a feature of Kerberos?
Single sign-on
Spam fitters
Mandate additional security awareness training for all employees.
Firewall
14. A packet filtering firewall can protect from which of the following?
dcfldd
PGP
Port scan
Install application updates
15. Which of the following activities should be completed in order to detect anomalies on a network?
Log reviews
RAID 5 and a storage area network
Detective
Install application updates
16. Which of the following authentication protocols forces centralized wireless authentication?
WPA2-Enterprise
CRL
Impersonation
PEAP
17. Mal - the security administrator - is implementing a web content fitter. Which of the following is the MOST important design consideration in regards to availability?
Blue jacking
Fail state of the system
SNMPv3
LDAP
18. While traveling - users need access to an internal company web server that contains proprietary information. Mal - the security administrator - should implement a...
ARP poisoning
RAS
SNMPv3
Impact; Likelihood
19. Which of the following has a default port of 22?
SSH
Separation of duties
Two fish
Loop protection
20. Which of the following is where an unauthorized device is found allowing access to a network?
Dictionary; Brute force
WPA2-Enterprise
Enforced acceptable usage policy - encryption of confidential emails - and monitoring of communications leaving the organization.
Rogue access point
21. A company wants to have a backup site that is a good balance between cost and recovery time objectives. Which of the following is the BEST solution?
Single point of failure
IPS
Warm site
NAC
22. River Tam - an attacker - is recording a person typing in their ID number into a keypad to gain access to the building. River Tam then calls the helpdesk and informs them that their PIN no longer works and would like to change it. Which of the follow
Full disk
Impersonation
IPS
21
23. Which of the following mitigates the risk of proprietary information being compromised?
Change management
Install both the private and the public key on the web server.
Full disk
File encryption
24. River Tam - a user - on a public Wi-Fi network logs into a webmail account and is redirected to a search engine. Which of the following attacks may be occurring?
Cross-site scripting
To limit the number of endpoints connected through the same switch port
Evil twin
Log reviews
25. Which of the following allows a server to request a website on behalf of Starbuck - a user?
Accounting should be given read/write access to network share A and read access to network share B. River Tam should be given read access for the specific document on network share A.
RAID 5 and a storage area network
Proxies
Blowfish
26. Which of the following should Starbuck - the security administrator - do FIRST when an employee reports the loss of a corporate mobile device?
Deploying and using a trusted OS
The IDS does not identify a buffer overflow
Mandatory vacations
Remotely initiate a device wipe
27. Starbuck - the administrator - is tasked with deploying a strong encryption cipher. Which of the following ciphers would she be the LEAST likely to choose?
Two fish
Establish a MAC limit and age
Separation of duties
Mandatory vacations
28. While conducting a network audit - River Tam - a security administrator - discovers that most clients are routing their network traffic through a desktop client instead of the company router. Which of the following is this attack type?
Update the CRL; Deploy OCSP
NAC
Mandatory Access Controls
ARP poisoning
29. Starbuck's - a user - word processing software is exhibiting strange behavior - opening and closing itself at random intervals. There is no other strange behavior on the system. Which of the following would mitigate this problem in the future?
Install application updates
The capacity of a system to resist unauthorized changes to stored information
Antenna placement; Power levels
NIPS
30. Which of the following can River Tam - a security administrator - implement to ensure that encrypted files and devices can be recovered if the passphrase is lost?
The capacity of a system to resist unauthorized changes to stored information
DES;3 DES
Account expiration
Key escrow
31. Which of the following allows active exploitation of security vulnerabilities on a system or network for the purpose of determining true impact?
Fuzzing
Penetration testing
GSM phone card and PIN
Proxy server
32. Which of the following attacks is manifested as an embedded HTML image object or JavaScript image tag in an email?
Risk
Cross-site scripting
IPS
VLAN mismatch is occurring.
33. Which of the following is used by Jayne - a security administrator - to lower the risks associated with electrostatic discharge - corrosion - and thermal breakdown?
Impersonation
Remote data wipe
Temperature and humidity controls
Input validation
34. Jayne - a server administrator - sets up database forms based on security rating levels. If a user has the lowest security rating then the database automatically determines what access that user has. Which of the following access control methods does
Device encryption
Mandatory access control
Impact; Likelihood
Establish a MAC limit and age
35. Jayne - a system administrator - wants to establish a nightly available SQL database. Which of the following would be implemented to eliminate a single point of failure in storage and servers?
Proxies
RAID 5 and a storage area network
Worm outbreak
RBAC
36. A data loss prevention strategy would MOST likely incorporate which of the following to reduce the risk associated with data loss?
PGP
Single sign-on
Disable unused ports
Enforced acceptable usage policy - encryption of confidential emails - and monitoring of communications leaving the organization.
37. Jayne - a systems security engineer - is determining which credential-type authentication to use within a planned 802.1x deployment. He is looking for a method that does not require a client certificate - has a server side certificate - and uses TLS
22
PEAP-MSCHAPv2
TACACS+; SSH
The IDS does not identify a buffer overflow
38. Jayne - a security administrator - has noticed that the website and external systems have been subject to many attack attempts. To verify integrity of the website and critical files - Jayne should
The system shall require users to authenticate to the system with a combination of a password or PIN and a smartcard
Create file hashes for website and critical system files - and compare the current file hashes to the baseline at regular time intervals.
Cold site
Mandate additional security awareness training for all employees.
39. Mal - a user - submitted a form on the Internet but received an unexpected response shown below Server Error in "/" Application Runtime error in script on asp.net version 2.0 Which of the following controls should be put in place to prevent Mal from
Error handling
Protocol analyzer
Install both the private and the public key on the web server.
Full disk encryption
40. The Chief Information Officer (CIO) wants to protect laptop users from zero day attacks. Which of the following would BEST achieve the CIO's goal?
Host based firewall
The capacity of a system to resist unauthorized changes to stored information
Verify the user's identity
Sanitization using appropriate software
41. A computer is put into a restricted VLAN until the computer's virus definitions are up-to-date. Which of the following BEST describes this system type?
Compare hashes of the original source and system image.
Power levels
CA
NAC
42. Which of the following is a best practice when securing a switch from physical access?
Disable unused ports
Full disk encryption
Zero day
Something you are
43. Which of the following is the MOST secure protocol for Mal - an administrator - to use for managing network devices?
SSH
Shoulder surfing
Accounting should be given read/write access to network share A and read access to network share B. River Tam should be given read access for the specific document on network share A.
Fuzzing
44. Which of the following network devices will prevent port scans?
Firewall
Vishing
Validate the identity of an email sender;Encrypt messages;Decrypt messages
Humidity controls
45. River Tam - a security analyst - suspects that a rogue web server is running on the network. Which of the following would MOST likely be used to identify the server's IP address?
Port scanner
To limit the number of endpoints connected through the same switch port
Cross-site scripting
Integrity
46. Mal - a user - is having trouble dialing into the network from their house. The administrator checks the RADIUS server - the switch connected to the server - and finds that the switch lost configuration after a recent power outage. The administrator
Humidity controls
VLAN mismatch is occurring.
RADIUS
SSH
47. Which of the following does Starbuck - a software developer - need to do after compiling the source code of a program to attest the authorship of the binary?
48. An application programmer reports to River Tam - the security administrator - that the antivirus software installed on a server is interfering with one of the production HR applications - and requests that antivirus be temporarily turned off. How sho
Mandate additional security awareness training for all employees.
Ask the programmer to replicate the problem in a test environment.
Compare hashes of the original source and system image.
Fuzzing
49. Starbuck - an administrator - is primarily concerned with blocking external attackers from gaining information on remote employees by scanning their laptops. Which of the following security applications is BEST suited for this task?
Loop protection
Personal firewall
Error handling
Non-repudiation
50. River Tam - the security engineer - has discovered that a breach is in progress on a non-production system of moderate importance. Which of the following should River Tam collect FIRST?
Separation of duties
CA
The system is virtualized
Memory dump - ARP cache