SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
Comptia Security +: Cyber Ops
Start Test
Study First
Subjects
:
certifications
,
comptia-security-+
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. An application company sent out a software patch for one of their applications on Monday. The company has been receiving reports about intrusion attacks from their customers on Tuesday. Which of the following attacks does this describe?
Antenna placement; Power-level control
Zero day
MD5
SQL injection
2. Mal - the Chief Executive Officer (CEO) of a company - has increased his travel plans for the next two years to improve business relations. Which of the following would need to be in place in case something happens to Pete?
Passive finger printing
Succession planning
Something you are - something you have
NIPS
3. Which of the following describes the ability for a third party to verify the sender or recipient of a given electronic message during authentication?
Impersonation
Non-repudiation
Impact; Likelihood
SSH
4. Employees are reporting that they are receiving unusual calls from the help desk for the purpose of verifying their user credentials. Which of the following attack types is occurring?
Update the CRL; Deploy OCSP
Improper input validation
Vishing
The capacity of a system to resist unauthorized changes to stored information
5. River Tam - a security administrator - has generated a key pair for the company web server. Which of the following should she do next to ensure all web traffic to the company web server is encrypted?
Spam filter
Protocol analyzers
Install both the private and the public key on the web server.
Vishing
6. A company needs to remove sensitive data from hard drives in leased computers before the computers are returned to the supplier. Which of the following is the BEST solution?
Discretionary access control
Sanitization using appropriate software
Ticket granting server
WPA2-PSK
7. An SQL injection vulnerability can be caused by which of the following?
The intermediate CA's public key
Trust model
Improper input validation
MAC filtering
8. Which of the following BEST allows Mal - a security administrator - to determine the type - source - and flags of the packet traversing a network for troubleshooting purposes?
Enforced acceptable usage policy - encryption of confidential emails - and monitoring of communications leaving the organization.
Mean time to restore
Protocol analyzers
GSM phone card and PIN
9. Jayne - a security administrator - wants to allow content owners to determine who has access to tiles. Which of the following access control types does this describe?
E-discovery
Improper input validation
Separation of duties
Discretionary access control
10. Which of the following password policies is the MOST effective against a brute force network attack?
Log reviews
Account lockout
Failsafe
Compare hashes of the original source and system image.
11. When used alone - which of the following controls mitigates the risk of River Tam - an attacker - launching an online brute force password attack?
The system is virtualized
Account lockout
Sanitization using appropriate software
Mandatory access control
12. Starbuck - a security administrator - wants to prevent users in sales from accessing their servers after 6:00 p.m. - and prevent them from accessing accounting's network at all times. Which of the following should Starbuck implement to accomplish the
Rogue access point
Fuzzing
Port scanner
Time of day restrictions;Access control lists
13. Which of the following is where an unauthorized device is found allowing access to a network?
NAC
Single point of failure
Account expiration
Rogue access point
14. Which of the following allows Mal - a security technician - to prevent email traffic from entering the company servers?
To limit the number of endpoints connected through the same switch port
Spam filter
Mandated security configurations have been made to the operating system.
Encrypt all confidential data.
15. Starbuck - an IT security technician working at a bank - has implemented encryption between two locations. Which of the following security concepts BEST exemplifies the protection provided by this example?
Improper input validation
23
Confidentiality
The capacity of a system to resist unauthorized changes to stored information
16. Starbuck's - a user - word processing software is exhibiting strange behavior - opening and closing itself at random intervals. There is no other strange behavior on the system. Which of the following would mitigate this problem in the future?
Something you are - something you have
TACACS+
AP power levels
Install application updates
17. Hashing algorithms are used to address which of the following?
Loop protection
Single point of failure
Subnetting
Integrity
18. Which of the following reduces the likelihood of a single point of failure when a server fails?
Clustering
Full disk
Single sign-on
CRL
19. A company notices that there is a flaw in one of their proprietary programs that the company runs in-house. The flaw could cause damage to the HVAC system. Which of the following would the company transfer to an insurance company?
Risk
Impersonation
Antenna placement; Power levels
NTLM
20. Which of the following risks could IT management be mitigating by removing an all-in-one device?
SQL injection
MD5
Single point of failure
SSH
21. Which of the following multifactor authentication methods uses biometrics?
SSH
Something you are
Port scanner
Impersonation
22. When integrating source material from an open source project into a highly secure environment - which of the following precautions should prevent hidden threats?
Protocol analyzer
Code review
Remote data wipe
Separation of duties
23. The log management system at Company A is inadequate to meet the standards required by their corporate governance team. A new automated log management system has been put in place. This is an example of which of the following?
Temperature and humidity controls
Verify the user's identity
E-discovery
Continuous monitoring
24. Which of the following is a reason why Mal - a security administrator - would implement port security?
Change management
To limit the number of endpoints connected through the same switch port
Verify the user's identity
Key escrow
25. The accounting department needs access to network share A to maintain a number of financial reporting documents. The department also needs access to network share B in HR to view payroll documentation for cross-referencing items. River Tam - an admin
Temperature and humidity controls
Code review
SSH
Accounting should be given read/write access to network share A and read access to network share B. River Tam should be given read access for the specific document on network share A.
26. Which of the following techniques floods an application with data in an attempt to find vulnerabilities?
Dictionary; Brute force
Risk avoidance
PGP
Fuzzing
27. The human resources department of a company has requested full access to all network resources - including those of the financial department. Starbuck - the administrator - denies this - citing...
Something you are - something you have
Separation of duties
Mandatory Access Controls
Antenna placement; Power levels
28. Which of the following does Starbuck - a software developer - need to do after compiling the source code of a program to attest the authorship of the binary?
29. Which of the following would Mal - a security administrator - change to limit how far a wireless signal will travel?
Ask the programmer to replicate the problem in a test environment.
Confidentiality
Power levels
Validate the identity of an email sender;Encrypt messages;Decrypt messages
30. Which of the following accurately describes the STRONGEST multifactor authentication?
Something you are - something you have
Personally owned devices
Create file hashes for website and critical system files - and compare the current file hashes to the baseline at regular time intervals.
Install application updates
31. River Tam - a security administrator - has configured a trusted OS implementation on her servers. Which of the following controls are enacted by the trusted OS implementation?
Remote wipe
Mandatory Access Controls
Cipher lock combination and proximity badge
Improper input validation
32. Mal - a security administrator - would like to implement laptop encryption to protect data. The Chief Executive Officer (CEO) believes this will be too costly to implement and decides the company will purchase an insurance policy instead. Which of th
Cold site
The system shall require users to authenticate to the system with a combination of a password or PIN and a smartcard
VLAN mismatch is occurring.
Risk avoidance
33. Which of the following BEST describes a denial of service attack?
River Tam - the attacker - overwhelms a system or application - causing it to crash and bring the server down to cause an outage.
Loop protection
Trust model
Zero day attack
34. Account lockout is a mitigation strategy used by Starbuck - the administrator - to combat which of the following attacks?
Install both the private and the public key on the web server.
Dictionary; Brute force
PGP
RAID 5 and a storage area network
35. Which of the following should River Tam - a security technician - perform as the FIRST step when creating a disaster recovery plan for a mission critical accounting system?
Business impact assessment
Group based privileges
Account expiration
80
36. Mal - a security engineer - is trying to inventory all servers in a rack. The engineer launches RDP sessions to five different PCs and notices that the hardware properties are similar. Additionally - the MAC addresses of all five servers appear on th
Zero day
Enforced acceptable usage policy - encryption of confidential emails - and monitoring of communications leaving the organization.
Single sign-on
The system is virtualized
37. Mal - a security administrator - wants to secure remote telnet services and decides to use the services over SSH. Which of the following ports should Mal allow on the firewall by default?
22
Application hardening
Encrypt all confidential data.
SSH
38. Which of the following network solutions would BEST allow Starbuck - a security technician - to host an extranet application for her company?
Continuous monitoring
Software as a Service
Trust model
Encrypt all confidential data.
39. A valid server-role in a Kerberos authentication system
Firewall
Software as a Service
Business impact assessment
Ticket granting server
40. Which of the following should Starbuck - the security administrator - do FIRST when an employee reports the loss of a corporate mobile device?
Integrity
Proxies
Remotely initiate a device wipe
Account lockout
41. Which of the following is the BEST incident response procedure to take when a previous employee enters a facility?
42. The Chief Information Officer (CIO) wants to protect laptop users from zero day attacks. Which of the following would BEST achieve the CIO's goal?
Single point of failure
Host based firewall
Zero day exploit
Impersonation
43. Which of the following elements makes up the standard equation used to define risk?
Mandatory vacations
Impact; Likelihood
Impersonation
Ticket granting server
44. Which of the following security chips does BitLocker utilize?
Discretionary access control
Mandatory Access Controls
TPM
Succession planning
45. While performing basic forensic analysis of a hard drive in River Tam's - the security administrator - possession - which of the following should be verified during the analysis?
The IDS does not identify a buffer overflow
Fraggle attack
Encrypt all confidential data.
Image hashes
46. Which of the following encrypts the body of a packet - rather than just the password - while sending information?
Group based privileges
Clustering
TACACS+
Disable unused ports
47. River Tam - an administrator - suspects a denial of service attack on the network - but does not know where the network traffic is coming from or what type of traffic it is. Which of the following would help River Tam further assess the situation?
Protocol analyzer
P2P
Loop protection
War chalking
48. An administrator responsible for building and validating security configurations is a violation of which of the following security principles?
Remote wipe
Two fish
Separation of duties
Ticket granting server
49. Which of the following attacks would be used if River Tam - a user - is receiving unwanted text messages?
Subnetting
Blue jacking
Social engineering
Port scanner
50. Which of the following would be the BEST reason for Starbuck - a security administrator - to initially select individual file encryption over whole disk encryption?
Clustering
It is faster to encrypt an individual file.
Subnetting
E-discovery