SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
Comptia Security +: Cyber Ops
Start Test
Study First
Subjects
:
certifications
,
comptia-security-+
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Which of the following BEST explains the security benefit of a standardized server image?
Mandated security configurations have been made to the operating system.
Impersonation
Update the CRL; Deploy OCSP
22
2. River Tam - a security administrator - is noticing a slow down in the wireless network response. River Tam launches a wireless sniffer and sees a large number of ARP packets being sent to the AP. Which of the following type of attacks is underway?
Install both the private and the public key on the web server.
Assign multiple roles to the existing user ID
IV attack
Rogue access point
3. An application company sent out a software patch for one of their applications on Monday. The company has been receiving reports about intrusion attacks from their customers on Tuesday. Which of the following attacks does this describe?
NIPS
NAC
Mitigate risk and develop a maintenance plan.
Zero day
4. Which of the following multifactor authentication methods uses biometrics?
Loop protection
Use Starbuck's private key to sign the binary
Something you are
Encrypt all confidential data.
5. Which of the following implements two factor authentication based on something you know and something you have?
SNMPv3
Failsafe
The system shall require users to authenticate to the system with a combination of a password or PIN and a smartcard
CA
6. Which of the following security chips does BitLocker utilize?
Cipher lock combination and proximity badge
TPM
Mandatory access control
Impersonation
7. The log management system at Company A is inadequate to meet the standards required by their corporate governance team. A new automated log management system has been put in place. This is an example of which of the following?
dcfldd
Continuous monitoring
Information classification policy; Network access policy; Auditing and monitoring policy
Loop protection
8. Which of the following does Starbuck - a software developer - need to do after compiling the source code of a program to attest the authorship of the binary?
9. To mitigate the adverse effects of network modifications - which of the following should Jayne - the security administrator - implement?
Separation of duties
Change management
Proxies
Cross-site scripting
10. Which of the following network solutions would BEST allow Starbuck - a security technician - to host an extranet application for her company?
Logic bomb
Software as a Service
RAS
Cold site
11. Which of the following would be the BEST reason for Starbuck - a security administrator - to initially select individual file encryption over whole disk encryption?
TACACS+; SSH
Non-repudiation
Antenna placement; Power levels
It is faster to encrypt an individual file.
12. While performing basic forensic analysis of a hard drive in River Tam's - the security administrator - possession - which of the following should be verified during the analysis?
Penetration testing
TACACS+
Install application updates
Image hashes
13. River Tam - a security analyst - discovers which operating systems the client devices on the network are running by only monitoring a mirror port on the router. Which of the following techniques did River Tam use?
Firewall
NAC
Zero day
Passive finger printing
14. Which of the following security tools can Starbuck - an administrator - implement to mitigate the risks of theft?
Evil twin
Risk
Device encryption
Port scanner
15. While River Tam is logging into the server from her workstation - she notices Mal watching her enter the username and password. Which of the following social engineering attacks is Mal executing?
Fail state of the system
Shoulder surfing
Separation of duties
Assign multiple roles to the existing user ID
16. A packet filtering firewall can protect from which of the following?
Port scan
Validate the identity of an email sender;Encrypt messages;Decrypt messages
Firewall
Enforced acceptable usage policy - encryption of confidential emails - and monitoring of communications leaving the organization.
17. Which of the following ports would be blocked if Mal - a security administrator - wants to deny access to websites?
NIPS
Trust model
80
File encryption
18. Starbuck - a user - has reported an increase in email phishing attempts. Which of the following can be implemented to mitigate the attacks?
Clustering
DES;3 DES
Notify security to identify employee's whereabouts.
Anti-spam
19. Which of the following allows Mal - a security technician - to prevent email traffic from entering the company servers?
Business impact assessment
Spam filter
Temperature and humidity controls
Deploy an anti-spam device to protect the network.
20. Starbuck - a security administrator - has applied security labels to files and folders to manage and restrict access. Which of the following is Starbuck using?
Integrity
Remote data wipe
Mandatory access control
Passive finger printing
21. River Tam - a security administrator - suspects that a web server may be under attack. The web logs have several entries containing variations of the following entries: 'or 1=1-- or1'=1-- 'or1=1'
Error handling
Encrypt all confidential data.
Proxies
SQL injection
22. Starbuck - a security administrator - wants to prevent users in sales from accessing their servers after 6:00 p.m. - and prevent them from accessing accounting's network at all times. Which of the following should Starbuck implement to accomplish the
Time of day restrictions;Access control lists
Discretionary access control
Image hashes
Single sign-on
23. River Tam - a forensic investigator - believes that the system image she was presented with is not the same as the original source. Which of the following should be done to verify whether or not the image has been tampered with?
Public key
Compare hashes of the original source and system image.
River Tam - the attacker - overwhelms a system or application - causing it to crash and bring the server down to cause an outage.
Succession planning
24. Which of the following administrative controls BEST mitigates the risk of ongoing inappropriate employee activities in sensitive areas?
Mandatory vacations
Cable locks
Something you are
Error handling
25. Jayne - a system administrator - wants to establish a nightly available SQL database. Which of the following would be implemented to eliminate a single point of failure in storage and servers?
Separation of duties
Mandatory Access Controls
Continuous monitoring
RAID 5 and a storage area network
26. Workers of a small local organization have implemented an off-site location in which the organization can resume operations within 10 business days in the event of a disaster. This type of site is BEST known as which of the following?
Account lockout
Cold site
It is faster to encrypt an individual file.
Deploying and using a trusted OS
27. Which of the following malware types is MOST likely to execute its payload after Starbuck - an employee - has left the company?
Logic bomb
Vulnerability scan
SSH
Impersonation
28. Social networking sites are used daily by the marketing team for promotional purposes. However - confidential company information - including product pictures and potential partnerships - have been inadvertently exposed to the public by dozens of emp
Device encryption
Antenna placement; Power-level control
Mandate additional security awareness training for all employees.
Separation of duties
29. Which of the following is Starbuck - a security administrator - MOST likely implementing when deleting all the unneeded files and modules of a newly install application?
SQL injection
Worm outbreak
Full disk
Application hardening
30. Jayne's CRL is over six months old. Which of the following could Jayne do in order to ensure he has the current information?
Zero day attack
Mean time to restore
Discretionary access control
Update the CRL; Deploy OCSP
31. Starbuck has a vendors server in-house for shipping and receiving. She wants to ensure that if the server goes down that the server in-house will be operational again within 24 hours. Which of the following should Starbuck define with the vendor?
Update the CRL; Deploy OCSP
Mean time to restore
dcfldd
Device encryption
32. Which of the following security concepts establishes procedures where creation and approval are performed through distinct functions?
Separation of duties
Accounting should be given read/write access to network share A and read access to network share B. River Tam should be given read access for the specific document on network share A.
AP power levels
Improper input validation
33. Which of the following ports should be open in order for River Tam and Mal - users - to identify websites by domain name?
Single sign-on
Penetration testing
UDP 53
Non-repudiation
34. In the event of a mobile device being lost or stolen - which of the following BEST protects against sensitive information leakage?
Fail state of the system
Ticket granting server
Remote wipe
War chalking
35. Which of the following malware types is MOST commonly associated with command and control?
Botnets
CRL
Mandatory vacations
Private key
36. Which of the following is BEST described by a scenario where organizational management chooses to implement an internal Incident Response Structure for the business?
WPA2-PSK
Business impact assessment
Mitigation
Code review
37. Which of the following is the purpose of the spanning tree protocol?
Error handling
Impersonation
Loop protection
Separation of duties
38. River Tam - an administrator - suspects a denial of service attack on the network - but does not know where the network traffic is coming from or what type of traffic it is. Which of the following would help River Tam further assess the situation?
Protocol analyzer
It is faster to encrypt an individual file.
Antenna placement; Power-level control
LDAP
39. Which of the following would Mal - a security administrator - change to limit how far a wireless signal will travel?
Logic bomb
Mitigation
Loop protection
Power levels
40. Which of the following technologies would allow the removal of a single point of failure?
TACACS+
E-discovery
Dual-homing a server
SNMPv3
41. Which of the following BEST describes a denial of service attack?
River Tam - the attacker - overwhelms a system or application - causing it to crash and bring the server down to cause an outage.
NAC
Fraggle attack
P2P
42. Mal - the Chief Executive Officer (CEO) of a company - has increased his travel plans for the next two years to improve business relations. Which of the following would need to be in place in case something happens to Pete?
Single sign-on
Rootkit
Succession planning
Input validation
43. Which of the following policies is implemented in order to minimize data loss or theft?
The system shall require users to authenticate to the system with a combination of a password or PIN and a smartcard
NIPS
TACACS+
PII handling
44. Jayne - the administrator - has been told to confirm what account an email was sent from. Which of the following is this an example of?
Time of day restrictions;Access control lists
To limit the number of endpoints connected through the same switch port
E-discovery
Dual-homing a server
45. Which of the following is the MOST important security requirement for mobile devices storing PII?
Install both the private and the public key on the web server.
Input validation
Remote data wipe
Personal firewall
46. Which of the following would River Tam - a security administrator - utilize to identity a weakness within various applications without exploiting that weakness?
Firewall
Vulnerability scan
Assign multiple roles to the existing user ID
Humidity controls
47. Which of the following may cause Starbuck - the security administrator - to seek an ACL work around?
CRL
80
Zero day exploit
Antenna placement; Power levels
48. In a wireless network - which of the following components could cause too much coverage - too little coverage - and interference?
Deploy an anti-spam device to protect the network.
Succession planning
AP power levels
Protocol analyzers
49. Which of the following would MOST likely be implemented in order to prevent employees from accessing certain websites?
Proxy server
ARP poisoning
P2P
Worm outbreak
50. River Tam - a security administrator - has generated a key pair for the company web server. Which of the following should she do next to ensure all web traffic to the company web server is encrypted?
Risk
Install both the private and the public key on the web server.
Encrypt all confidential data.
Spam filter