SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
Comptia Security +: Cyber Ops
Start Test
Study First
Subjects
:
certifications
,
comptia-security-+
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. A company is installing a wireless network in a building that houses several tenants. Which of the following should be considered to make sure none of the other tenants can detect the company's wireless network?
Antenna placement; Power levels
Cable locks
Business impact assessment
P2P
2. Which of the following network devices will prevent port scans?
Port scan
Fail state of the system
Group based privileges
Firewall
3. Which of the following BEST allows Mal - a security administrator - to determine the type - source - and flags of the packet traversing a network for troubleshooting purposes?
Power levels
Protocol analyzers
23
Use Starbuck's private key to sign the binary
4. Which of the following should be done before resetting a user's password due to expiration?
5. Which of the following should Mal - an administrator - use to verify the integrity of a downloaded file?
RAS
Software as a Service
Two fish
MD5
6. Starbuck - the administrator - is tasked with deploying a strong encryption cipher. Which of the following ciphers would she be the LEAST likely to choose?
Two fish
Proxies
dcfldd
Clustering
7. Which of the following are restricted to 64-bit block sizes?
War chalking
Penetration test
Cold site
DES;3 DES
8. Marketing creates a new folder and requests the following access be assigned: Sales Department - Read Marketing Department - Full Control Inside Sales - Read Write This is an example of which of the following?
Key escrow
Gray box
RBAC
Loop protection
9. Which of the following does Starbuck - a software developer - need to do after compiling the source code of a program to attest the authorship of the binary?
10. Starbuck has a vendors server in-house for shipping and receiving. She wants to ensure that if the server goes down that the server in-house will be operational again within 24 hours. Which of the following should Starbuck define with the vendor?
Port scanner
Mandate additional security awareness training for all employees.
Mean time to restore
Memory dump - ARP cache
11. Which of the following would be the BEST reason for Starbuck - a security administrator - to initially select individual file encryption over whole disk encryption?
WPA2-Enterprise
Mandatory access control
Establish a MAC limit and age
It is faster to encrypt an individual file.
12. Starbuck - a security administrator - has completed the imaging process for 20 computers that were deployed. The image contains the operating system and all required software. Which of the following is this an example of?
dcfldd
Notify security to identify employee's whereabouts.
Deploying and using a trusted OS
Create file hashes for website and critical system files - and compare the current file hashes to the baseline at regular time intervals.
13. Mal - a user - is having trouble dialing into the network from their house. The administrator checks the RADIUS server - the switch connected to the server - and finds that the switch lost configuration after a recent power outage. The administrator
River Tam - the attacker - overwhelms a system or application - causing it to crash and bring the server down to cause an outage.
VLAN mismatch is occurring.
Ticket granting server
GSM phone card and PIN
14. Workers of a small local organization have implemented an off-site location in which the organization can resume operations within 10 business days in the event of a disaster. This type of site is BEST known as which of the following?
Protocol analyzers
Confidentiality
Cold site
Logic bomb
15. Which of the following has a default port of 22?
ARP poisoning
PEAP
SSH
NIPS
16. River Tam - a security administrator - has configured a trusted OS implementation on her servers. Which of the following controls are enacted by the trusted OS implementation?
LDAP
Cold site
Mandatory Access Controls
TACACS+
17. Starbuck - a user - has reported an increase in email phishing attempts. Which of the following can be implemented to mitigate the attacks?
Compare hashes of the original source and system image.
Anti-spam
Business impact assessment
Private key
18. Which of the following is based on X.500 standards?
LDAP
Risk avoidance
Subnetting
Account lockout
19. The log management system at Company A is inadequate to meet the standards required by their corporate governance team. A new automated log management system has been put in place. This is an example of which of the following?
Temperature and humidity controls
Continuous monitoring
Mitigation
Single point of failure
20. Which of the following technologies would allow the removal of a single point of failure?
Group based privileges
Dual-homing a server
Sanitization using appropriate software
Two fish
21. Which of the following techniques floods an application with data in an attempt to find vulnerabilities?
Fuzzing
Private key
Separation of duties
Accounting should be given read/write access to network share A and read access to network share B. River Tam should be given read access for the specific document on network share A.
22. Which of the following is BEST used to break a group of IP addresses into smaller network segments or blocks?
Encrypt all confidential data.
Subnetting
Public key
Firewall
23. A company notices that there is a flaw in one of their proprietary programs that the company runs in-house. The flaw could cause damage to the HVAC system. Which of the following would the company transfer to an insurance company?
Risk
CRL
Improper input validation
Proxy server
24. Which of the following allows a server to request a website on behalf of Starbuck - a user?
Proxies
Install both the private and the public key on the web server.
Warm site
VLAN mismatch is occurring.
25. Jayne - a server administrator - sets up database forms based on security rating levels. If a user has the lowest security rating then the database automatically determines what access that user has. Which of the following access control methods does
GSM phone card and PIN
Port forwarding
Mandatory access control
Server-side input validation results in a more secure system than client-side input validation.
26. Which of the following should be implemented to secure Pete's - a network administrator - day-today maintenance activities?
TACACS+; SSH
Humidity controls
E-discovery
Remote wipe
27. Which of the following commands can Jayne - an administrator - use to create a forensically sound hard drive image?
dcfldd
MD5
Notify security to identify employee's whereabouts.
PEAP
28. Which of the following could River Tam - an administrator - use in a workplace to remove sensitive data at rest from the premises?
Personally owned devices
Anti-spam
Protocol analyzer
Log reviews
29. Which of the following security controls enforces user permissions based on a job role?
PEAP-MSCHAPv2
Group based privileges
ARP poisoning
CA
30. A packet filtering firewall can protect from which of the following?
Port scan
River Tam - the attacker - overwhelms a system or application - causing it to crash and bring the server down to cause an outage.
CRL
Something you are
31. An application programmer reports to River Tam - the security administrator - that the antivirus software installed on a server is interfering with one of the production HR applications - and requests that antivirus be temporarily turned off. How sho
GSM phone card and PIN
Remote data wipe
Ask the programmer to replicate the problem in a test environment.
Signature based
32. Which of the following should River Tam - a security technician - perform as the FIRST step when creating a disaster recovery plan for a mission critical accounting system?
IV attack
Error handling
Business impact assessment
Device encryption
33. When integrating source material from an open source project into a highly secure environment - which of the following precautions should prevent hidden threats?
Separation of duties
Code review
Full disk
Verify the user's identity
34. After setting up a root CA. which of the following can Mal - a security administrator - implement to allow intermediate CAs to handout keys and certificates?
Fraggle attack
Input validation
The IDS does not identify a buffer overflow
Trust model
35. Starbuck - an administrator - is primarily concerned with blocking external attackers from gaining information on remote employees by scanning their laptops. Which of the following security applications is BEST suited for this task?
WPA2-Enterprise
Separation of duties
Personal firewall
Proxy server
36. Which of the following web application security weaknesses can be mitigated by preventing the use of HTML tags?
Worm outbreak
Blue jacking
Cross-site scripting
Warm site
37. Mal is reporting an excessive amount of junk mail on the network email server. Which of the following would ONLY reduce the amount of unauthorized mail?
TPM
Spam fitters
Input validation
Log reviews
38. Which of the following attacks is characterized by River Tam attempting to send an email from a Chief Information Officer's (CIO's) non-corporate email account to an IT staff member in order to have a password changed?
Fraggle attack
Impersonation
Logic bomb
River Tam - the attacker - overwhelms a system or application - causing it to crash and bring the server down to cause an outage.
39. Which of the following is BEST described by a scenario where organizational management chooses to implement an internal Incident Response Structure for the business?
Subnetting
Fuzzing
Mitigation
Server-side input validation results in a more secure system than client-side input validation.
40. Which of the following attacks is manifested as an embedded HTML image object or JavaScript image tag in an email?
Install both the private and the public key on the web server.
Cross-site scripting
Zero day exploit
Mean time to restore
41. Which of the following inspects traffic entering or leaving a network to look for anomalies against expected baselines?
IPS
Personal firewall
ARP poisoning
Software as a Service
42. When reviewing a digital certificate for accuracy - which of the following would Jayne - a security administrator - focus on to determine who affirms the identity of the certificate owner?
CA
Software as a Service
Signature based
VLAN mismatch is occurring.
43. The human resources department of a company has requested full access to all network resources - including those of the financial department. Starbuck - the administrator - denies this - citing...
Update the CRL; Deploy OCSP
Key escrow
The system shall require users to authenticate to the system with a combination of a password or PIN and a smartcard
Separation of duties
44. Which of the following describes the ability for a third party to verify the sender or recipient of a given electronic message during authentication?
File encryption
Non-repudiation
IV attack
Mitigate risk and develop a maintenance plan.
45. Which of the following is the MOST secure protocol for Mal - an administrator - to use for managing network devices?
Worm outbreak
SSH
Mandatory Access Controls
Protocol analyzers
46. Which of the following password policies is the MOST effective against a brute force network attack?
Clean desk policy
Anti-spam
21
Account lockout
47. Mal - a security administrator - has observed repeated attempts to break into the network. Which of the following is designed to stop an intrusion on the network?
River Tam - the attacker - overwhelms a system or application - causing it to crash and bring the server down to cause an outage.
Power levels
NIPS
RBAC
48. Which of the following security tools can Starbuck - an administrator - implement to mitigate the risks of theft?
Single sign-on
Image hashes
The capacity of a system to resist unauthorized changes to stored information
Device encryption
49. Which of the following can Jayne - an administrator - use to ensure the confidentiality of a file when it is being sent over FTP?
Cable locks
File encryption
Something you are
PGP
50. The Chief Information Officer (CIO) wants to protect laptop users from zero day attacks. Which of the following would BEST achieve the CIO's goal?
It is faster to encrypt an individual file.
Ticket granting server
Ask the programmer to replicate the problem in a test environment.
Host based firewall