SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
Comptia Security +
Start Test
Study First
Subjects
:
certifications
,
comptia-security-+
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. UPS Types
Here the administrator creates resource access policies and the users cannot modify them. These policies in turn will dictate which user(s) have access to which resource(s).
143
1. Offline/Standby - Power is taken from the AC source (wall) until a power failure occurs then it is switched to the battery. 2. Online (Double Conversion/Delta Conversion) - Power is taken from the battery at all times. 3. Line Interactive - Power
Bastion Host
2. What is the SLE (Single Loss Expectancy)?
In Windows NT 4 SP4.
The asset value multiplied by the exposure factor asset value x exposure factor = SLE
80
1. PPTP - Point to Point Tunneling Protocol 2. L2TP - Layer 2 Tunneling Protocol 3. IPSEC - Internet Protocol Security used to provide encryption for L2TP
3. POP3 port number
1. Local computer GPO 2. Local administrator and non-administrator GPOs 3. Local user-specific GPO 4. Site GPO 5. Domain GPO 6. Organizational Unit GPO(s)
1. PPTP - Point to Point Tunneling Protocol 2. L2TP - Layer 2 Tunneling Protocol 3. IPSEC - Internet Protocol Security used to provide encryption for L2TP
1. S/MIME - Secure Multipurpose Internet Mail Extension 2. PGP - Pretty Good Privacy
110
4. What is a Trojan?
1. SPI - Stateful Packet Inspection firewall 2. Stateless firewall
A program that appears to be harmless but delivers malicious code to a computer NetBUS and BackOrrifice are two of the most popular trojans - they are typically embedded in benign looking programs - when the programs are executed a backdoor to the sy
The name of the file that tracks expired certificates is the CRL (Certificate Revocation List).
25
5. What is UBE?
143
1. Represent the configuration of the system(s) to be tested. 2. Analyze the system(s) 3. Report the results
Unsolicited Bulk Email or SPAM
Use a solution that supports nonrepudiation
6. Telnet port number
1. Dynamic NAT - A private IP address is mapped to a public IP address drawing from a pool of registered public IP addresses (one-to-many). 2. Static NAT - A private IP address is mapped to a public IP address the public IP address that is being mapp
1701
23
Are the same thing.
7. NNTP port number
1. Dynamic NAT - A private IP address is mapped to a public IP address drawing from a pool of registered public IP addresses (one-to-many). 2. Static NAT - A private IP address is mapped to a public IP address the public IP address that is being mapp
A rootkit is a form of malicious software that grants full system control to the user. The term comes from the UNIX/Linux environment - where the highest level of system administrator is called the root user.
22
119
8. What is a Zombie?
Through the use of digital signatures
No - all hosts on a VLAN do not have to be connected to the same switch - a VLAN can span multiple switches.
A system that has been compromised by malware and can be remote controlled by another computer during an attack - usually a DDoS attack. Zombies are also known as bots or network robots.
Anything that impacts or edits the way in which a server/application responds/answers a user's request.
9. IDS/IPS Alerts
1. True Positive - Correctly identifies an attack 2. True Negative - Correctly identifies legitimate traffic 3. False Positive - Incorrectly identifies legitimate traffic as an attack 4. False Negative - Incorrectly identifies an attack as legitimate
1. Represent the configuration of the system(s) to be tested. 2. Analyze the system(s) 3. Report the results
443
1. Dictionary 2. Brute Force 3. Rainbow Tables 4. Masked Attack
10. What is the standard that covers PKI?
1. DES - Data Encryption Standard 2. 3DES - Triple Data Encryption Standard 3. AES - Advanced Encryption Standard 4. AES256 - Advanced Encryption Standard 256-bit 5. RC5 - Rivest Cipher 5 6. RC6 - Rivest Cipher 6 7. Blowfish 8. IDEA - International D
The asset value multiplied by the exposure factor asset value x exposure factor = SLE
X.509 is the standard that covers PKI
The name of the file that tracks expired certificates is the CRL (Certificate Revocation List).
11. IPSEC Encryption Modes
110
C:Windowssystem32driversetcservices
1. Transport Mode - Packet data is encrypted but not the header information. 2. Tunnel Mode - Enitre packet (data & header information) is encrypted.
143
12. PPTP port number
23
Earlier versions of PGP relied on public key cryptography but not X.509 - it used a web of trust instead. Current versions of PGP include both models through a key management server - X.509 using a hierarchical approach based on a Certificate Authori
X.500 is the standard that covers LDAP
1723
13. How do you ensure an email comes from the person it advertises as being the sender?
1. Access Control - MAC Filtering 2. Encryption - WEP - WPA - WPA2 3. Authentication - RADIUS 4. Isolation - VLANs
Use a solution that supports nonrepudiation
A differential backup backs up all files that have changed since the last full backup - and is quicker to restore than multiple incremental backups.
Here the administrator creates resource access policies and the users cannot modify them. These policies in turn will dictate which user(s) have access to which resource(s).
14. TACACS port number
1723
49
143
67 - 68
15. Password Crackers
1. MD4 - Message Digest 4 (128-bit digest) 2. MD5 - Message Digest 5 (128-bit digest - used in NTLMv2) 3. SHA - Secure Hashing Algorithm (160/256/512-bit digest)
It can be identified by the use of a single quote character which is used to signal to the web server that what follows is a SQL query.
1. John the Ripper 2. Cain & Abel 3. THC Hydra
The name of the file that tracks expired certificates is the CRL (Certificate Revocation List).
16. DHCP port number
(2^number of host bits)-2 = number of hosts
A program that appears to be harmless but delivers malicious code to a computer NetBUS and BackOrrifice are two of the most popular trojans - they are typically embedded in benign looking programs - when the programs are executed a backdoor to the sy
67 - 68
A system that has been compromised by malware and can be remote controlled by another computer during an attack - usually a DDoS attack. Zombies are also known as bots or network robots.
17. What is a hotfix?
No - all hosts on a VLAN do not have to be connected to the same switch - a VLAN can span multiple switches.
C:Windowssystem32driversetcservices
A combination of files geared - towards fixing one or more security issues with a given piece of software. Note that hotfixes are usually created shortly after a security hole is identified.
Unsolicited Bulk Email or SPAM
18. When was NTLMv2 first introduced?
1. Represent the configuration of the system(s) to be tested. 2. Analyze the system(s) 3. Report the results
110
In Windows NT 4 SP4.
443
19. How does an offline UPS provide power?
20. Access Control Models
1. Confidentiality 2. Integrity 3. Availability
A differential backup backs up all files that have changed since the last full backup - and is quicker to restore than multiple incremental backups.
1. MAC - Mandatory Access Control 2. DAC - Discretionary Access Control 3. RBAC - Role-Based Access Control 4. NAC - Network Access Control 5. Physical
1. Something you know2. Something you have 3. Something you are
21. The Goals of Security
1. Signatures must be updated 2. Zero day exploits
1. Confidentiality 2. Integrity 3. Availability
1. Dynamic NAT - A private IP address is mapped to a public IP address drawing from a pool of registered public IP addresses (one-to-many). 2. Static NAT - A private IP address is mapped to a public IP address the public IP address that is being mapp
3389
22. Types of Firewalls
119
1. Signatures must be updated 2. Zero day exploits
1. SPI - Stateful Packet Inspection firewall 2. Stateless firewall
If one application is deployed to 100 workstations it needs to be patched 100 times but if the same application is deployed to 1 shared virtual host it only needs to be patched once.
23. Can a VLAN be used to SEGREGATE access to a DHCP server?
Yes because all hosts connected to a VLAN are in the same broadcast domain - and DHCP works based on broadcast packets.
67 - 68
1. Transport Mode - Packet data is encrypted but not the header information. 2. Tunnel Mode - Enitre packet (data & header information) is encrypted.
49
24. Goals of Email Security
1. John the Ripper 2. Cain & Abel 3. THC Hydra
BitLocker
1. Confidentiality 2. Integrity 3. Authentication 4. Nonrepudiation
23
25. Types of L2TP Tunnels
BitLocker
Through the use of digital signatures
1. Transport Mode - Packet data is encrypted but not the header information. 2. Tunnel Mode - Enitre packet (data & header information) is encrypted.
1. Voluntary Tunnel 2. Compulsory Tunnel - Incoming Call 3. Compulsory Tunnel - Remote Dial 4. Multi-Hop Connection Tunnel
26. Asymmetric Key Ciphers
1. Confidentiality 2. Integrity 3. Availability
1. Diffe-Hellman - Used in key exchange 2. Elliptic Curve - Used in OpenSSL and Bouncy Castle for Java & C# - .Net framework. 3. ElGamal - Used in PGP and GNU Privacy Guard 4. RSA - One of the best known public key ciphers - it was developed at MIT.
1. Confidentiality 2. Integrity 3. Authentication 4. Nonrepudiation
1. Access Control - MAC Filtering 2. Encryption - WEP - WPA - WPA2 3. Authentication - RADIUS 4. Isolation - VLANs
27. Symmetric Key Ciphers
If one application is deployed to 100 workstations it needs to be patched 100 times but if the same application is deployed to 1 shared virtual host it only needs to be patched once.
1. DES - Data Encryption Standard 2. 3DES - Triple Data Encryption Standard 3. AES - Advanced Encryption Standard 4. AES256 - Advanced Encryption Standard 256-bit 5. RC5 - Rivest Cipher 5 6. RC6 - Rivest Cipher 6 7. Blowfish 8. IDEA - International D
Yes a VLAN can provide scalability because it is configured via software not hardware.
1. PPTP - Point to Point Tunneling Protocol 2. L2TP - Layer 2 Tunneling Protocol 3. IPSEC - Internet Protocol Security used to provide encryption for L2TP
28. Can PGP be used to provide nonrepudiation?
PGP can be used to both encrypt and digitally sign emails - because it can be used to digitally sign emails it provides nonrepudiation.
1. Authentication 2. Authorization 3. Accounting
1. SPI - Stateful Packet Inspection firewall 2. Stateless firewall
143
29. Ways to Secure a WiFi Access Point
1. Confidentiality 2. Integrity 3. Authentication 4. Nonrepudiation
Use a solution that supports nonrepudiation
1. Access Control - MAC Filtering 2. Encryption - WEP - WPA - WPA2 3. Authentication - RADIUS 4. Isolation - VLANs
An online or double conversion UPS will charge it's battery and provide power to any connected devices at the same time.
30. The 3 As
1. Represent the configuration of the system(s) to be tested. 2. Analyze the system(s) 3. Report the results
1. Authentication 2. Authorization 3. Accounting
No - all hosts on a VLAN do not have to be connected to the same switch - a VLAN can span multiple switches.
The integrity of a message.
31. What is the standard that covers LDAP?
1. Dictionary 2. Brute Force 3. Rainbow Tables 4. Masked Attack
X.500 is the standard that covers LDAP
1. Technology Weakness 2. Configuration Weakness 3. Policy Weakness 4. Human Error or Malice
22
32. HTTPS port number
1. Dictionary 2. Brute Force 3. Rainbow Tables 4. Masked Attack
1. LM - Local Area Network Manager (Used in XP and before - DES is the hash) 2. NTLMv1/v2 - New Technology LANMAN (Used in Vista - 7 - and Server 2008) 3. Kerberos - Used in Active Directory
110
443
33. Windows Password Authentication Protocols
53
110
3389
1. LM - Local Area Network Manager (Used in XP and before - DES is the hash) 2. NTLMv1/v2 - New Technology LANMAN (Used in Vista - 7 - and Server 2008) 3. Kerberos - Used in Active Directory
34. Human Behaviors that Social Engineering Will Exploit
1. Represent the configuration of the system(s) to be tested. 2. Analyze the system(s) 3. Report the results
A rootkit is a form of malicious software that grants full system control to the user. The term comes from the UNIX/Linux environment - where the highest level of system administrator is called the root user.
The asset value multiplied by the exposure factor asset value x exposure factor = SLE
1. Trust 2. Fear 3. Lack of konwledge
35. What is THC Hydra?
1. Represent the configuration of the system(s) to be tested. 2. Analyze the system(s) 3. Report the results
A fast network authentication password cracker that can go after many different services.
1723
An offline UPS remains idle until AC power is lost then it uses its' internal battery to provide power to attached equipment.
36. How does a differential backup work?
A differential backup backs up all files that have changed since the last full backup - and is quicker to restore than multiple incremental backups.
Here the administrator creates resource access policies and the users cannot modify them. These policies in turn will dictate which user(s) have access to which resource(s).
1. LM - Local Area Network Manager (Used in XP and before - DES is the hash) 2. NTLMv1/v2 - New Technology LANMAN (Used in Vista - 7 - and Server 2008) 3. Kerberos - Used in Active Directory
Use a solution that supports nonrepudiation
37. How can you introduce nonrepudiation and authentication to Mutual SSL client authentication?
1. MD4 - Message Digest 4 (128-bit digest) 2. MD5 - Message Digest 5 (128-bit digest - used in NTLMv2) 3. SHA - Secure Hashing Algorithm (160/256/512-bit digest)
1. Local computer GPO 2. Local administrator and non-administrator GPOs 3. Local user-specific GPO 4. Site GPO 5. Domain GPO 6. Organizational Unit GPO(s)
3389
Through the use of digital signatures
38. What is output validation?
39. The 3 Ss
23
1. Something you know2. Something you have 3. Something you are
X.500 is the standard that covers LDAP
1. Signatures must be updated 2. Zero day exploits
40. In PKI what is the name of the file that tracks expired certificates?
The name of the file that tracks expired certificates is the CRL (Certificate Revocation List).
1. Phishing 2. Hoaxes 3. Dumpster Diving 4. Shoulder Surfing
1. Authentication 2. Authorization 3. Accounting
1. Access Control - MAC Filtering 2. Encryption - WEP - WPA - WPA2 3. Authentication - RADIUS 4. Isolation - VLANs
41. The Primary Causes of Compromised Security
1. Technology Weakness 2. Configuration Weakness 3. Policy Weakness 4. Human Error or Malice
1. John the Ripper 2. Cain & Abel 3. THC Hydra
1. Represent the configuration of the system(s) to be tested. 2. Analyze the system(s) 3. Report the results
A rootkit is a form of malicious software that grants full system control to the user. The term comes from the UNIX/Linux environment - where the highest level of system administrator is called the root user.
42. Steps in the OVAL Assessment Process
1. True Positive - Correctly identifies an attack 2. True Negative - Correctly identifies legitimate traffic 3. False Positive - Incorrectly identifies legitimate traffic as an attack 4. False Negative - Incorrectly identifies an attack as legitimate
1. Transport Mode - Packet data is encrypted but not the header information. 2. Tunnel Mode - Enitre packet (data & header information) is encrypted.
1. Confidentiality 2. Integrity 3. Authentication 4. Nonrepudiation
1. Represent the configuration of the system(s) to be tested. 2. Analyze the system(s) 3. Report the results
43. What do digital signatures prove?
1. Dictionary 2. Brute Force 3. Rainbow Tables 4. Masked Attack
In Windows NT 4 SP4.
A program that appears to be harmless but delivers malicious code to a computer NetBUS and BackOrrifice are two of the most popular trojans - they are typically embedded in benign looking programs - when the programs are executed a backdoor to the sy
The integrity of a message.
44. What is PWDUMP?
1. Diffe-Hellman - Used in key exchange 2. Elliptic Curve - Used in OpenSSL and Bouncy Castle for Java & C# - .Net framework. 3. ElGamal - Used in PGP and GNU Privacy Guard 4. RSA - One of the best known public key ciphers - it was developed at MIT.
Yes a VLAN can provide scalability because it is configured via software not hardware.
3389
A tool used to extract NTLM and LANMAN hashes from a Windows based targeted host.
45. How does an online/double conversion UPS provide power?
46. Versions of NAT
Here the administrator creates resource access policies and the users cannot modify them. These policies in turn will dictate which user(s) have access to which resource(s).
67 - 68
1. Dynamic NAT - A private IP address is mapped to a public IP address drawing from a pool of registered public IP addresses (one-to-many). 2. Static NAT - A private IP address is mapped to a public IP address the public IP address that is being mapp
1701
47. Do all hosts on a VLAN have to be connected to the same switch?
No - all hosts on a VLAN do not have to be connected to the same switch - a VLAN can span multiple switches.
1. S/MIME - Secure Multipurpose Internet Mail Extension 2. PGP - Pretty Good Privacy
The name of the file that tracks expired certificates is the CRL (Certificate Revocation List).
Through the use of digital signatures
48. In a Windows Doamin - How is a GPO Applied?
PGP can be used to both encrypt and digitally sign emails - because it can be used to digitally sign emails it provides nonrepudiation.
A system that has been compromised by malware and can be remote controlled by another computer during an attack - usually a DDoS attack. Zombies are also known as bots or network robots.
1. Technology Weakness 2. Configuration Weakness 3. Policy Weakness 4. Human Error or Malice
1. Local computer GPO 2. Local administrator and non-administrator GPOs 3. Local user-specific GPO 4. Site GPO 5. Domain GPO 6. Organizational Unit GPO(s)
49. In Windows what is the path to the file that contains a list of well-known ports?
1. True Positive - Correctly identifies an attack 2. True Negative - Correctly identifies legitimate traffic 3. False Positive - Incorrectly identifies legitimate traffic as an attack 4. False Negative - Incorrectly identifies an attack as legitimate
C:Windowssystem32driversetcservices
1. DES - 64-bit block - 56-bit key - 16 rounds 2. 3DES - DES is used 3 times with 3 different keys 3. AES - 128-bit block - 128/192-bit key - 10/12/14 rounds 4. AES256 - AES used with a 256-bit key 5. RC5 - 32/64/128-bit block - 0-2040 key - 0-255 ro
A fast network authentication password cracker that can go after many different services.
50. DNS port number
1. DES - Data Encryption Standard 2. 3DES - Triple Data Encryption Standard 3. AES - Advanced Encryption Standard 4. AES256 - Advanced Encryption Standard 256-bit 5. RC5 - Rivest Cipher 5 6. RC6 - Rivest Cipher 6 7. Blowfish 8. IDEA - International D
Here the administrator creates resource access policies and the users cannot modify them. These policies in turn will dictate which user(s) have access to which resource(s).
A fast network authentication password cracker that can go after many different services.
53