Test your basic knowledge |

Comptia Security + Exam

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Several staff members working in a datacenter have reported instances of tailgating. Which of the following could be implemented to prevent this security concern?






2. Which of the following is the BEST way to secure data for the purpose of retention?






3. Which of the following attacks is NOT aimed at fragmentation vulnerabilities of the IP stack?






4. Which of the following can prevent an unauthorized employee from entering a data center?






5. Which of the following is another name for a malicious attacker?






6. A technician needs to limit the wireless signal from reaching outside of a building. Which of the following actions should the technician take?






7. A company needs to be able to prevent entry at all times - to a highly sensitive area inside a public building. In order to ensure the BEST type of physical security - which of the following should be implemented?






8. Which of the following are accomplished when a message is digitally signed?






9. Which of the following is the MOST secure method of utilizing FTP?






10. Risk can be managed in the following ways...






11. Which of the following assists in identifying if a system was properly handled during transport?






12. Which of the following is a detective security control?






13. Which of the following devices is used to optimize and distribute data workloads across multiple computers or networks?






14. A security administrator needs to separate two departments. Which of the following would the administrator implement to perform this?






15. Which of the following devices would allow a technician to view IP headers on a data packet?






16. Users of specific systems are reporting that their data has been corrupted. After a recent patch update to those systems the users are still reporting issues of data being corrupt. Which of the following assessment techniques need to be performed to






17. Which of the following allows a security administrator to set device traps?






18. Which of the following attacks is manifested as an embedded HTML image object or JavaScript image tag in an email?






19. The security administrator implemented privacy password protected screen savers - and hired a secure shredding and disposal service. Which of the following attacks is the security administrator trying to mitigate?






20. A programmer allocates 16 bytes for a string but does not adequately ensure that more than 16 bytes cannot be copied into the variable. This program may be vulnerable to which of the following attacks?






21. When examining HTTP server logs the security administrator notices that the company's online store crashes after a particular search string is executed by a single external user. Which of the following BEST describes this type of attack?






22. Which of the following malware types is an antivirus scanner MOST unlikely to discover?






23. In an 802.11n network which of the following provides the MOST secure method of both encryption and authorization?






24. Which of the following is a best practice when securing a switch from physical access?






25. Based on logs from file servers remote access systems - and IDS - a malicious insider was stealing data using a personal laptop while connected by VPN. The affected company wants access to the laptop to determine loss - but the insider's lawyer insis






26. A user receives an automated call which appears to be from their bank. The automated recording provides details about the bank's privacy policy security policy and requests that the user clearly state their name - birthday and enter the banking detai






27. Your daily bandwidth monitoring report of your Internet connection shows an excessive amount of outgoing traffic on port 25. You have seen peaks in the reports before but this report shows many peaks outside office times. What should you do?






28. Due to sensitive data concerns a security administrator has enacted a policy preventing the use of flash drives. Additionally - which of the following can the administrator implement to reduce the risk of data leakage?






29. Network users whose computers are running Windows7 complain that the extra windows that appear when they browse the Internet are becoming a nuisance. You need to minimize how often these windows appear. What should you do?






30. A security administrator wants to determine what data is allowed to be collected from users of the corporate Internet-facing web application. Which of the following should be referenced?






31. Which of the following is a method to prevent ad-hoc configuration mistakes?






32. Which of the following describes when forensic hashing should occur on a drive?






33. Which of the following should be reviewed periodically to ensure a server maintains the correct security configuration?






34. An existing application has never been assessed from a security perspective. Which of the following is the BEST assessment technique in order to identify the application's security posture?






35. When configuring multiple computers for RDP on the same wireless router it may be necessary to do which of the following?






36. An application log shows that the text 'test; rm -rf /etc/passwd' was entered into an HTML form. Which of the following describes the type of attack that was attempted?






37. Which environmental control is part of TEMPEST compliance?






38. Logs from an IDS show that a computer has been compromised with a botnet and is actively communicating with a command and control which of the following data types will be unavailable for later investigation?






39. Which of the following is MOST commonly a part of routine system audits?






40. What can you prevent when you deploy wireless devices inside a TEMPEST-certified building?






41. Used in conjunction which of the following are PII?






42. Which of the following reduces the likelihood of a single point of failure when a server fails?






43. What asymmetric key is used to encrypt when using HTTPS?

Warning: Invalid argument supplied for foreach() in /var/www/html/basicversity.com/show_quiz.php on line 183


44. A network consists of various remote sites that connect back to two main locations. The security administrator needs to block TELNET access into the network. Which of the following by default - would be the BEST choice to accomplish this goal?






45. What allows for all activities on a network or system to be traced to the user who performed them?






46. Which of the following facilitates computing for heavily utilized systems and networks?






47. Your organization has an existing server and you want to add a hardware device to provide encryption capabilities. What is the easiest way to accomplish this?






48. What principle dictates that a user is given no more privilege necessary than that required to preform his/her job?






49. You are performing risk assessment for an organization. What should you do during impact assessment?






50. How does a NAT server help protect your network?