Test your basic knowledge |

Comptia Security +: Cyber Ops

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Which of the following policies is implemented in order to minimize data loss or theft?






2. Which of the following should Starbuck - the security administrator - do FIRST when an employee reports the loss of a corporate mobile device?






3. A company is performing internal security audits after a recent exploitation on one of their proprietary applications. River Tam - the security auditor - is given the workstation with limited documentation regarding the application installed for the






4. Which of the following is the MOST secure protocol for Mal - an administrator - to use for managing network devices?






5. Mal - a user - is having trouble dialing into the network from their house. The administrator checks the RADIUS server - the switch connected to the server - and finds that the switch lost configuration after a recent power outage. The administrator






6. Which of the following techniques floods an application with data in an attempt to find vulnerabilities?






7. Which of the following is the MAIN benefit of server-side versus client-side input validation?






8. Which of the following commands can Jayne - an administrator - use to create a forensically sound hard drive image?






9. Jayne - the security administrator - notices a spike in the number of SQL injection attacks against a web server connected to a backend SQL database. Which of the following practices should be used to prevent an application from passing these attacks






10. Which of the following can River Tam - a security administrator - implement to ensure that encrypted files and devices can be recovered if the passphrase is lost?






11. River Tam - a security administrator - is noticing a slow down in the wireless network response. River Tam launches a wireless sniffer and sees a large number of ARP packets being sent to the AP. Which of the following type of attacks is underway?






12. Which of the following security tools can Starbuck - a security administrator - use to deter theft?






13. River Tam - an administrator - suspects a denial of service attack on the network - but does not know where the network traffic is coming from or what type of traffic it is. Which of the following would help River Tam further assess the situation?






14. Which of the following is an improved version of the LANMAN hash?






15. The fundamental information security principals include confidentiality - availability and which of the following?






16. When moving from an internally controlled environment to a fully outsourced infrastructure environment - such as cloud computing - it is MOST important to...






17. River Tam and Starbuck - users - are reporting an increase in the amount of unwanted email that they are receiving each day. Which of the following would be the BEST way to respond to this issue without creating a lot of administrative overhead?






18. A company needs to remove sensitive data from hard drives in leased computers before the computers are returned to the supplier. Which of the following is the BEST solution?






19. Starbuck - an administrator - is primarily concerned with blocking external attackers from gaining information on remote employees by scanning their laptops. Which of the following security applications is BEST suited for this task?






20. When used alone - which of the following controls mitigates the risk of River Tam - an attacker - launching an online brute force password attack?






21. In the event of a mobile device being lost or stolen - which of the following BEST protects against sensitive information leakage?






22. Which of the following activities should be completed in order to detect anomalies on a network?






23. A company has sent all of its private keys to a third party. The third party company has created a secure list of these keys. Which of the following has just been implemented?






24. Starbuck - an IT security technician working at a bank - has implemented encryption between two locations. Which of the following security concepts BEST exemplifies the protection provided by this example?






25. Account lockout is a mitigation strategy used by Starbuck - the administrator - to combat which of the following attacks?






26. Which of the following security chips does BitLocker utilize?






27. Which of the following should River Tam - a security technician - perform as the FIRST step when creating a disaster recovery plan for a mission critical accounting system?






28. Which of the following mitigates the risk of proprietary information being compromised?






29. Which of the following attacks is characterized by River Tam attempting to send an email from a Chief Information Officer's (CIO's) non-corporate email account to an IT staff member in order to have a password changed?






30. Jayne - a systems security engineer - is determining which credential-type authentication to use within a planned 802.1x deployment. He is looking for a method that does not require a client certificate - has a server side certificate - and uses TLS






31. Which of the following controls mitigates the risk of Jayne - an attacker - gaining access to a company network by using a former employee's credential?






32. While performing basic forensic analysis of a hard drive in River Tam's - the security administrator - possession - which of the following should be verified during the analysis?






33. Which of the following network devices will prevent port scans?






34. Which of the following reduces the likelihood of a single point of failure when a server fails?






35. Which of the following is based on X.500 standards?






36. Which of the following malware types is MOST likely to execute its payload after Starbuck - an employee - has left the company?






37. Which of the following network solutions would BEST allow Starbuck - a security technician - to host an extranet application for her company?






38. Jayne's CRL is over six months old. Which of the following could Jayne do in order to ensure he has the current information?






39. Which of the following types of data encryption would Starbuck - a security administrator - use if MBR and the file systems needed to be included?






40. River Tam - a security analyst - suspects that a rogue web server is running on the network. Which of the following would MOST likely be used to identify the server's IP address?






41. River Tam - the security engineer - has discovered that a breach is in progress on a non-production system of moderate importance. Which of the following should River Tam collect FIRST?






42. Mal - a security administrator - has observed repeated attempts to break into the network. Which of the following is designed to stop an intrusion on the network?






43. Starbuck - a security technician - wants to implement secure wireless with authentication. Which of the following allows for wireless to be authenticated via MSCHAPv2?






44. River Tam - a security administrator - has generated a key pair for the company web server. Which of the following should she do next to ensure all web traffic to the company web server is encrypted?






45. Which of the following BEST allows Mal - a security administrator - to determine the type - source - and flags of the packet traversing a network for troubleshooting purposes?






46. Which of the following malware types is MOST commonly associated with command and control?






47. Starbuck - a VPN administrator - was asked to implement an encryption cipher with a MINIMUM effective security of 128-bits. Which of the following should Starbuck select for the tunnel encryption?






48. Which of the following would be the BEST reason for Starbuck - a security administrator - to initially select individual file encryption over whole disk encryption?






49. Hashing algorithms are used to address which of the following?






50. Which of the following malware types is BEST described as protecting itself by hooking system processes and hiding its presence?