SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
Comptia Security +
Start Test
Study First
Subjects
:
certifications
,
comptia-security-+
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. POP3 port number
110
A fast network authentication password cracker that can go after many different services.
1. Diffe-Hellman 2. Elliptic Curve (EC) 3. ElGamal 4. RSA - Rivest - Shamir - Aldeman 5. DSA - Digital Signature Algorithm
1. Signatures must be updated 2. Zero day exploits
2. What is a Zombie?
1. Dynamic NAT - A private IP address is mapped to a public IP address drawing from a pool of registered public IP addresses (one-to-many). 2. Static NAT - A private IP address is mapped to a public IP address the public IP address that is being mapp
A system that has been compromised by malware and can be remote controlled by another computer during an attack - usually a DDoS attack. Zombies are also known as bots or network robots.
1. Trust 2. Fear 3. Lack of konwledge
1. Represent the configuration of the system(s) to be tested. 2. Analyze the system(s) 3. Report the results
3. What do digital signatures prove?
The integrity of a message.
110
Yes because all hosts connected to a VLAN are in the same broadcast domain - and DHCP works based on broadcast packets.
49
4. What is THC Hydra?
Are the same thing.
A program that appears to be harmless but delivers malicious code to a computer NetBUS and BackOrrifice are two of the most popular trojans - they are typically embedded in benign looking programs - when the programs are executed a backdoor to the sy
A fast network authentication password cracker that can go after many different services.
49
5. Checksums
It can be identified by the use of a single quote character which is used to signal to the web server that what follows is a SQL query.
1. Elevation Prompt 2. Privilege Elevation
53
1. MD4 - Message Digest 4 (128-bit digest) 2. MD5 - Message Digest 5 (128-bit digest - used in NTLMv2) 3. SHA - Secure Hashing Algorithm (160/256/512-bit digest)
6. IMAP port number
1. Voluntary Tunnel 2. Compulsory Tunnel - Incoming Call 3. Compulsory Tunnel - Remote Dial 4. Multi-Hop Connection Tunnel
143
1. Trust 2. Fear 3. Lack of konwledge
1. Diffe-Hellman 2. Elliptic Curve (EC) 3. ElGamal 4. RSA - Rivest - Shamir - Aldeman 5. DSA - Digital Signature Algorithm
7. What is PWDUMP?
Bastion Host
A system that has been compromised by malware and can be remote controlled by another computer during an attack - usually a DDoS attack. Zombies are also known as bots or network robots.
A combination of files geared - towards fixing one or more security issues with a given piece of software. Note that hotfixes are usually created shortly after a security hole is identified.
A tool used to extract NTLM and LANMAN hashes from a Windows based targeted host.
8. Human Behaviors that Social Engineering Will Exploit
Unsolicited Bulk Email or SPAM
A differential backup backs up all files that have changed since the last full backup - and is quicker to restore than multiple incremental backups.
1. Trust 2. Fear 3. Lack of konwledge
53
9. Secure Email Protocols
A program that appears to be harmless but delivers malicious code to a computer NetBUS and BackOrrifice are two of the most popular trojans - they are typically embedded in benign looking programs - when the programs are executed a backdoor to the sy
1. S/MIME - Secure Multipurpose Internet Mail Extension 2. PGP - Pretty Good Privacy
(2^number of host bits)-2 = number of hosts
1. Transport Mode - Packet data is encrypted but not the header information. 2. Tunnel Mode - Enitre packet (data & header information) is encrypted.
10. UPS Types
Here the administrator creates resource access policies and the users cannot modify them. These policies in turn will dictate which user(s) have access to which resource(s).
1. DES - 64-bit block - 56-bit key - 16 rounds 2. 3DES - DES is used 3 times with 3 different keys 3. AES - 128-bit block - 128/192-bit key - 10/12/14 rounds 4. AES256 - AES used with a 256-bit key 5. RC5 - 32/64/128-bit block - 0-2040 key - 0-255 ro
1. Diffe-Hellman - Used in key exchange 2. Elliptic Curve - Used in OpenSSL and Bouncy Castle for Java & C# - .Net framework. 3. ElGamal - Used in PGP and GNU Privacy Guard 4. RSA - One of the best known public key ciphers - it was developed at MIT.
1. Offline/Standby - Power is taken from the AC source (wall) until a power failure occurs then it is switched to the battery. 2. Online (Double Conversion/Delta Conversion) - Power is taken from the battery at all times. 3. Line Interactive - Power
11. L2TP port number
1. Access Control - MAC Filtering 2. Encryption - WEP - WPA - WPA2 3. Authentication - RADIUS 4. Isolation - VLANs
1701
1. True Positive - Correctly identifies an attack 2. True Negative - Correctly identifies legitimate traffic 3. False Positive - Incorrectly identifies legitimate traffic as an attack 4. False Negative - Incorrectly identifies an attack as legitimate
1. Dictionary 2. Brute Force 3. Rainbow Tables 4. Masked Attack
12. Storage Types
The integrity of a message.
BitLocker
25
1. Online - The most available type of storage. Disk containing data is attached to the network or a system that is attached to the network. Examples include normal backup disk - RAID - and SAN. No direct physical human interaction is required to get
13. Symmetric Key Ciphers
1. Confidentiality 2. Integrity 3. Authentication 4. Nonrepudiation
1. Dynamic NAT - A private IP address is mapped to a public IP address drawing from a pool of registered public IP addresses (one-to-many). 2. Static NAT - A private IP address is mapped to a public IP address the public IP address that is being mapp
1. John the Ripper 2. Cain & Abel 3. THC Hydra
1. DES - Data Encryption Standard 2. 3DES - Triple Data Encryption Standard 3. AES - Advanced Encryption Standard 4. AES256 - Advanced Encryption Standard 256-bit 5. RC5 - Rivest Cipher 5 6. RC6 - Rivest Cipher 6 7. Blowfish 8. IDEA - International D
14. User Account Control (UAC) is an Example of
Anything that impacts or edits the way in which a server/application responds/answers a user's request.
1. Elevation Prompt 2. Privilege Elevation
PGP can be used to both encrypt and digitally sign emails - because it can be used to digitally sign emails it provides nonrepudiation.
23
15. Password Attacks
1. Dictionary 2. Brute Force 3. Rainbow Tables 4. Masked Attack
1. True Positive - Correctly identifies an attack 2. True Negative - Correctly identifies legitimate traffic 3. False Positive - Incorrectly identifies legitimate traffic as an attack 4. False Negative - Incorrectly identifies an attack as legitimate
1. Online - The most available type of storage. Disk containing data is attached to the network or a system that is attached to the network. Examples include normal backup disk - RAID - and SAN. No direct physical human interaction is required to get
1. Phishing 2. Hoaxes 3. Dumpster Diving 4. Shoulder Surfing
16. PPTP port number
1. Diffe-Hellman 2. Elliptic Curve (EC) 3. ElGamal 4. RSA - Rivest - Shamir - Aldeman 5. DSA - Digital Signature Algorithm
An incremental backup backs up only those files that have changed since the backup of any type - and is quicker to complete the backup.
1723
1. Signatures must be updated 2. Zero day exploits
17. Windows Password Authentication Protocols
In Windows NT 4 SP4.
1. LM - Local Area Network Manager (Used in XP and before - DES is the hash) 2. NTLMv1/v2 - New Technology LANMAN (Used in Vista - 7 - and Server 2008) 3. Kerberos - Used in Active Directory
1. Access Control - MAC Filtering 2. Encryption - WEP - WPA - WPA2 3. Authentication - RADIUS 4. Isolation - VLANs
Yes because all hosts connected to a VLAN are in the same broadcast domain - and DHCP works based on broadcast packets.
18. Ways to Secure a WiFi Access Point
A tool used to extract NTLM and LANMAN hashes from a Windows based targeted host.
1. Access Control - MAC Filtering 2. Encryption - WEP - WPA - WPA2 3. Authentication - RADIUS 4. Isolation - VLANs
Yes because all hosts connected to a VLAN are in the same broadcast domain - and DHCP works based on broadcast packets.
1723
19. LDAP port number
1. Technology Weakness 2. Configuration Weakness 3. Policy Weakness 4. Human Error or Malice
110
A system that has been compromised by malware and can be remote controlled by another computer during an attack - usually a DDoS attack. Zombies are also known as bots or network robots.
389
20. Types of Firewalls
1. SPI - Stateful Packet Inspection firewall 2. Stateless firewall
The integrity of a message.
443
A rootkit is a form of malicious software that grants full system control to the user. The term comes from the UNIX/Linux environment - where the highest level of system administrator is called the root user.
21. What is the standard that covers LDAP?
X.500 is the standard that covers LDAP
Yes a VLAN can provide scalability because it is configured via software not hardware.
Yes because all hosts connected to a VLAN are in the same broadcast domain - and DHCP works based on broadcast packets.
22
22. HTTP port number
It can be identified by the use of a single quote character which is used to signal to the web server that what follows is a SQL query.
80
The name of the file that tracks expired certificates is the CRL (Certificate Revocation List).
No - all hosts on a VLAN do not have to be connected to the same switch - a VLAN can span multiple switches.
23. When was NTLMv2 first introduced?
119
In Windows NT 4 SP4.
X.500 is the standard that covers LDAP
BitLocker
24. IDS/IPS Alerts
119
110
1. True Positive - Correctly identifies an attack 2. True Negative - Correctly identifies legitimate traffic 3. False Positive - Incorrectly identifies legitimate traffic as an attack 4. False Negative - Incorrectly identifies an attack as legitimate
1. Elevation Prompt 2. Privilege Elevation
25. Symmetric Key Ciphers
1. DES - 64-bit block - 56-bit key - 16 rounds 2. 3DES - DES is used 3 times with 3 different keys 3. AES - 128-bit block - 128/192-bit key - 10/12/14 rounds 4. AES256 - AES used with a 256-bit key 5. RC5 - 32/64/128-bit block - 0-2040 key - 0-255 ro
119
1. Diffe-Hellman 2. Elliptic Curve (EC) 3. ElGamal 4. RSA - Rivest - Shamir - Aldeman 5. DSA - Digital Signature Algorithm
The asset value multiplied by the exposure factor asset value x exposure factor = SLE
26. SSH port number
A fast network authentication password cracker that can go after many different services.
22
Are the same thing.
1. S/MIME - Secure Multipurpose Internet Mail Extension 2. PGP - Pretty Good Privacy
27. The 3 As
C:Windowssystem32driversetcservices
Unsolicited Bulk Email or SPAM
1. Authentication 2. Authorization 3. Accounting
A rootkit is a form of malicious software that grants full system control to the user. The term comes from the UNIX/Linux environment - where the highest level of system administrator is called the root user.
28. What is UBE?
1. Offline/Standby - Power is taken from the AC source (wall) until a power failure occurs then it is switched to the battery. 2. Online (Double Conversion/Delta Conversion) - Power is taken from the battery at all times. 3. Line Interactive - Power
In Windows NT 4 SP4.
1. Trust 2. Fear 3. Lack of konwledge
Unsolicited Bulk Email or SPAM
29. Protocols Used for VPN
1. Dynamic NAT - A private IP address is mapped to a public IP address drawing from a pool of registered public IP addresses (one-to-many). 2. Static NAT - A private IP address is mapped to a public IP address the public IP address that is being mapp
1. PPTP - Point to Point Tunneling Protocol 2. L2TP - Layer 2 Tunneling Protocol 3. IPSEC - Internet Protocol Security used to provide encryption for L2TP
1. Dictionary 2. Brute Force 3. Rainbow Tables 4. Masked Attack
1. Diffe-Hellman 2. Elliptic Curve (EC) 3. ElGamal 4. RSA - Rivest - Shamir - Aldeman 5. DSA - Digital Signature Algorithm
30. How does an online/double conversion UPS provide power?
31. What is a Trojan?
25
A program that appears to be harmless but delivers malicious code to a computer NetBUS and BackOrrifice are two of the most popular trojans - they are typically embedded in benign looking programs - when the programs are executed a backdoor to the sy
Here the administrator creates resource access policies and the users cannot modify them. These policies in turn will dictate which user(s) have access to which resource(s).
1. Diffe-Hellman 2. Elliptic Curve (EC) 3. ElGamal 4. RSA - Rivest - Shamir - Aldeman 5. DSA - Digital Signature Algorithm
32. How could a shared virtual machine reduce the workload for IT staff?
An incremental backup backs up only those files that have changed since the backup of any type - and is quicker to complete the backup.
1723
If one application is deployed to 100 workstations it needs to be patched 100 times but if the same application is deployed to 1 shared virtual host it only needs to be patched once.
1. PPTP - Point to Point Tunneling Protocol 2. L2TP - Layer 2 Tunneling Protocol 3. IPSEC - Internet Protocol Security used to provide encryption for L2TP
33. How can you introduce nonrepudiation and authentication to Mutual SSL client authentication?
Through the use of digital signatures
53
A program that appears to be harmless but delivers malicious code to a computer NetBUS and BackOrrifice are two of the most popular trojans - they are typically embedded in benign looking programs - when the programs are executed a backdoor to the sy
23
34. Goals of Email Security
1. Access Control - MAC Filtering 2. Encryption - WEP - WPA - WPA2 3. Authentication - RADIUS 4. Isolation - VLANs
1. MD4 - Message Digest 4 (128-bit digest) 2. MD5 - Message Digest 5 (128-bit digest - used in NTLMv2) 3. SHA - Secure Hashing Algorithm (160/256/512-bit digest)
X.500 is the standard that covers LDAP
1. Confidentiality 2. Integrity 3. Authentication 4. Nonrepudiation
35. Types of L2TP Tunnels
1. PPTP - Point to Point Tunneling Protocol 2. L2TP - Layer 2 Tunneling Protocol 3. IPSEC - Internet Protocol Security used to provide encryption for L2TP
1. Voluntary Tunnel 2. Compulsory Tunnel - Incoming Call 3. Compulsory Tunnel - Remote Dial 4. Multi-Hop Connection Tunnel
67 - 68
80
36. How can you identify a SQL Injection attack?
1723
A fast network authentication password cracker that can go after many different services.
A program that appears to be harmless but delivers malicious code to a computer NetBUS and BackOrrifice are two of the most popular trojans - they are typically embedded in benign looking programs - when the programs are executed a backdoor to the sy
It can be identified by the use of a single quote character which is used to signal to the web server that what follows is a SQL query.
37. DHCP port number
1. Local computer GPO 2. Local administrator and non-administrator GPOs 3. Local user-specific GPO 4. Site GPO 5. Domain GPO 6. Organizational Unit GPO(s)
67 - 68
23
A tool used to extract NTLM and LANMAN hashes from a Windows based targeted host.
38. The 3 Ss
23
443
A fast network authentication password cracker that can go after many different services.
1. Something you know2. Something you have 3. Something you are
39. Access Control Models
In Windows NT 4 SP4.
1. MAC - Mandatory Access Control 2. DAC - Discretionary Access Control 3. RBAC - Role-Based Access Control 4. NAC - Network Access Control 5. Physical
BitLocker
1. SPI - Stateful Packet Inspection firewall 2. Stateless firewall
40. Weaknesses of Antivirus Software
1. Signatures must be updated 2. Zero day exploits
23
143
1. Trust 2. Fear 3. Lack of konwledge
41. Do all hosts on a VLAN have to be connected to the same switch?
1. Authentication 2. Authorization 3. Accounting
An online or double conversion UPS will charge it's battery and provide power to any connected devices at the same time.
A rootkit is a form of malicious software that grants full system control to the user. The term comes from the UNIX/Linux environment - where the highest level of system administrator is called the root user.
No - all hosts on a VLAN do not have to be connected to the same switch - a VLAN can span multiple switches.
42. Password Crackers
1. John the Ripper 2. Cain & Abel 3. THC Hydra
1. LM - Local Area Network Manager (Used in XP and before - DES is the hash) 2. NTLMv1/v2 - New Technology LANMAN (Used in Vista - 7 - and Server 2008) 3. Kerberos - Used in Active Directory
The name of the file that tracks expired certificates is the CRL (Certificate Revocation List).
389
43. Does PGP rely on X.509 (Digital Certificates - PKI)?
Earlier versions of PGP relied on public key cryptography but not X.509 - it used a web of trust instead. Current versions of PGP include both models through a key management server - X.509 using a hierarchical approach based on a Certificate Authori
The integrity of a message.
If one application is deployed to 100 workstations it needs to be patched 100 times but if the same application is deployed to 1 shared virtual host it only needs to be patched once.
Yes a VLAN can provide scalability because it is configured via software not hardware.
44. Versions of NAT
1. Online - The most available type of storage. Disk containing data is attached to the network or a system that is attached to the network. Examples include normal backup disk - RAID - and SAN. No direct physical human interaction is required to get
1. Dynamic NAT - A private IP address is mapped to a public IP address drawing from a pool of registered public IP addresses (one-to-many). 2. Static NAT - A private IP address is mapped to a public IP address the public IP address that is being mapp
The name of the file that tracks expired certificates is the CRL (Certificate Revocation List).
Yes because all hosts connected to a VLAN are in the same broadcast domain - and DHCP works based on broadcast packets.
45. A web server that is located outside the DMZ is known as a...
Bastion Host
1723
1. Something you know2. Something you have 3. Something you are
If one application is deployed to 100 workstations it needs to be patched 100 times but if the same application is deployed to 1 shared virtual host it only needs to be patched once.
46. DNS port number
A tool used to extract NTLM and LANMAN hashes from a Windows based targeted host.
53
A fast network authentication password cracker that can go after many different services.
1. Confidentiality 2. Integrity 3. Availability
47. NNTP port number
119
X.509 is the standard that covers PKI
1. DES - Data Encryption Standard 2. 3DES - Triple Data Encryption Standard 3. AES - Advanced Encryption Standard 4. AES256 - Advanced Encryption Standard 256-bit 5. RC5 - Rivest Cipher 5 6. RC6 - Rivest Cipher 6 7. Blowfish 8. IDEA - International D
The asset value multiplied by the exposure factor asset value x exposure factor = SLE
48. What formula is used to find the number of hosts?
53
Yes a VLAN can provide scalability because it is configured via software not hardware.
(2^number of host bits)-2 = number of hosts
1. PPTP - Point to Point Tunneling Protocol 2. L2TP - Layer 2 Tunneling Protocol 3. IPSEC - Internet Protocol Security used to provide encryption for L2TP
49. What is the name of Vista's hard drive encryption technology?
Unsolicited Bulk Email or SPAM
1723
80
BitLocker
50. Remote Desktop port number
A differential backup backs up all files that have changed since the last full backup - and is quicker to restore than multiple incremental backups.
3389
A rootkit is a form of malicious software that grants full system control to the user. The term comes from the UNIX/Linux environment - where the highest level of system administrator is called the root user.
1. Diffe-Hellman 2. Elliptic Curve (EC) 3. ElGamal 4. RSA - Rivest - Shamir - Aldeman 5. DSA - Digital Signature Algorithm