SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
Comptia Security +: Cyber Ops
Start Test
Study First
Subjects
:
certifications
,
comptia-security-+
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. An application company sent out a software patch for one of their applications on Monday. The company has been receiving reports about intrusion attacks from their customers on Tuesday. Which of the following attacks does this describe?
Software as a Service
Ask the programmer to replicate the problem in a test environment.
TACACS+
Zero day
2. Which of the following will help Jayne - an administrator; mitigate the risk of static electricity?
Clustering
Application hardening
Gray box
Humidity controls
3. Starbuck - an IT security technician working at a bank - has implemented encryption between two locations. Which of the following security concepts BEST exemplifies the protection provided by this example?
Proxies
Confidentiality
Enforced acceptable usage policy - encryption of confidential emails - and monitoring of communications leaving the organization.
Zero day
4. Mal - a security administrator - has observed repeated attempts to break into the network. Which of the following is designed to stop an intrusion on the network?
Impersonation
NIPS
Code review
CA
5. Which of the following is a feature of Kerberos?
NIPS
Single sign-on
Enforced acceptable usage policy - encryption of confidential emails - and monitoring of communications leaving the organization.
Evil twin
6. A company needs to remove sensitive data from hard drives in leased computers before the computers are returned to the supplier. Which of the following is the BEST solution?
To limit the number of endpoints connected through the same switch port
Account lockout
Sanitization using appropriate software
Evil twin
7. Which of the following would MOST likely be implemented in order to prevent employees from accessing certain websites?
Separation of duties
Proxy server
WPA2-PSK
Image hashes
8. Which of the following techniques floods an application with data in an attempt to find vulnerabilities?
CA
Risk avoidance
Clustering
Fuzzing
9. River Tam - a security administrator - suspects that a web server may be under attack. The web logs have several entries containing variations of the following entries: 'or 1=1-- or1'=1-- 'or1=1'
VLAN mismatch is occurring.
23
SQL injection
Mandatory vacations
10. Which of the following should Mal - an administrator - use to verify the integrity of a downloaded file?
MD5
Cipher lock combination and proximity badge
NAC
Mandate additional security awareness training for all employees.
11. Social networking sites are used daily by the marketing team for promotional purposes. However - confidential company information - including product pictures and potential partnerships - have been inadvertently exposed to the public by dozens of emp
23
Antenna placement; Power levels
Mandate additional security awareness training for all employees.
Mitigation
12. Workers of a small local organization have implemented an off-site location in which the organization can resume operations within 10 business days in the event of a disaster. This type of site is BEST known as which of the following?
Cold site
Private key
80
Mandated security configurations have been made to the operating system.
13. Which of the following policies is implemented in order to minimize data loss or theft?
RAID 5 and a storage area network
SSH
PII handling
dcfldd
14. Which of the following is the BEST solution to securely administer remote servers?
SSH
To limit the number of endpoints connected through the same switch port
Mitigation
22
15. Mal - a user - is having trouble dialing into the network from their house. The administrator checks the RADIUS server - the switch connected to the server - and finds that the switch lost configuration after a recent power outage. The administrator
Worm outbreak
VLAN mismatch is occurring.
Single point of failure
Power levels
16. A company has sent all of its private keys to a third party. The third party company has created a secure list of these keys. Which of the following has just been implemented?
Key escrow
Private key
RAS
Separation of duties
17. Starbuck - a security administrator - has applied security labels to files and folders to manage and restrict access. Which of the following is Starbuck using?
Disable unused ports
Firewall
Mandatory access control
P2P
18. Which of the following allows Mal - a security technician - to prevent email traffic from entering the company servers?
NIPS
Spam filter
Penetration testing
Logic bomb
19. Which of the following data loss prevention strategies mitigates the risk of replacing hard drives that cannot be sanitized?
WPA2-PSK
SSH
Full disk encryption
Rogue access point
20. Traffic has stopped flowing to and from the company network after the inline IPS hardware failed. Which of the following has occurred?
Social engineering
NAC
Failsafe
E-discovery
21. Which of the following attacks is characterized by River Tam attempting to send an email from a Chief Information Officer's (CIO's) non-corporate email account to an IT staff member in order to have a password changed?
Software as a Service
Impersonation
NTLM
Remote data wipe
22. Which of the following should River Tam - a security technician - perform as the FIRST step when creating a disaster recovery plan for a mission critical accounting system?
Impersonation
Ticket granting server
Business impact assessment
PII handling
23. When integrating source material from an open source project into a highly secure environment - which of the following precautions should prevent hidden threats?
Code review
NIPS
Non-repudiation
The security company is provided with no information about the corporate network or physical locations.
24. Which of the following is an example of authentication using something Starbuck - a user - has and something she knows?
GSM phone card and PIN
Install application updates
Notify security to identify employee's whereabouts.
Change management
25. Mal - a network administrator - implements the spanning tree protocol on network switches. Which of the following issues does this address?
Loop protection
Fuzzing
Error handling
Cable locks
26. River Tam - the software security engineer - is trying to detect issues that could lead to buffer overflows or memory leaks in the company software. Which of the following would help River Tam automate this detection?
Port scanner
Time of day restrictions;Access control lists
IV attack
Fuzzing
27. Which of the following is Starbuck - a security administrator - MOST likely implementing when deleting all the unneeded files and modules of a newly install application?
The system is virtualized
Key escrow
SSH
Application hardening
28. A data loss prevention strategy would MOST likely incorporate which of the following to reduce the risk associated with data loss?
Enforced acceptable usage policy - encryption of confidential emails - and monitoring of communications leaving the organization.
IV attack
Separation of duties
Fail state of the system
29. Which of the following would River Tam - a security administrator - utilize to identity a weakness within various applications without exploiting that weakness?
Cross-site scripting
Remote data wipe
Application hardening
Vulnerability scan
30. Which of the following authentication protocols forces centralized wireless authentication?
UDP 53
Warm site
WPA2-Enterprise
Penetration testing
31. Which of the following attacks is manifested as an embedded HTML image object or JavaScript image tag in an email?
Spam fitters
Rogue access point
Key escrow
Cross-site scripting
32. Mal - a user - submitted a form on the Internet but received an unexpected response shown below Server Error in "/" Application Runtime error in script on asp.net version 2.0 Which of the following controls should be put in place to prevent Mal from
Account lockout
Error handling
Temperature and humidity controls
Cipher lock combination and proximity badge
33. Starbuck - a VPN administrator - was asked to implement an encryption cipher with a MINIMUM effective security of 128-bits. Which of the following should Starbuck select for the tunnel encryption?
Fail state of the system
Blowfish
TACACS+
Use Starbuck's private key to sign the binary
34. The Chief Information Security Officer (CISO) tells the network administrator that a security company has been hired to perform a penetration test against their network. The security company asks the CISO which type of testing would be most beneficia
Blue jacking
Blowfish
The security company is provided with no information about the corporate network or physical locations.
Compare hashes of the original source and system image.
35. When reviewing a digital certificate for accuracy - which of the following would Jayne - a security administrator - focus on to determine who affirms the identity of the certificate owner?
Risk avoidance
Compare hashes of the original source and system image.
CA
Change management
36. Which of the following password policies is the MOST effective against a brute force network attack?
Deploying and using a trusted OS
Proxy server
Account lockout
Succession planning
37. Which of the following is the purpose of the spanning tree protocol?
Establish a MAC limit and age
Loop protection
Time of day restrictions;Access control lists
Risk avoidance
38. Which of the following functions of a firewall allows Mal - an administrator - to map an external service to an internal host?
Use Starbuck's private key to sign the binary
Update the CRL; Deploy OCSP
Separation of duties
Port forwarding
39. When Mal - an employee - leaves a company - which of the following should be updated to ensure Pete's security access is reduced or eliminated?
Proxy server
Warm site
Cross-site scripting
CRL
40. Which of the following open standards should Mal - a security administrator - select for remote authentication of users?
Information classification policy; Network access policy; Auditing and monitoring policy
RADIUS
Firewall
IPS
41. A company is performing internal security audits after a recent exploitation on one of their proprietary applications. River Tam - the security auditor - is given the workstation with limited documentation regarding the application installed for the
Gray box
21
80
Notify security to identify employee's whereabouts.
42. While conducting a network audit - River Tam - a security administrator - discovers that most clients are routing their network traffic through a desktop client instead of the company router. Which of the following is this attack type?
Ask the programmer to replicate the problem in a test environment.
ARP poisoning
Remote wipe
E-discovery
43. The corporate NIPS requires a daily download from its vendor with updated definitions in order to block the latest attacks. Which of the following describes how the NIPS is functioning?
Signature based
Remotely initiate a device wipe
23
IPS
44. River Tam - an administrator - suspects a denial of service attack on the network - but does not know where the network traffic is coming from or what type of traffic it is. Which of the following would help River Tam further assess the situation?
Private key
Protocol analyzer
Image hashes
Update the CRL; Deploy OCSP
45. Which of the following is based on X.500 standards?
Host based firewall
Deploying and using a trusted OS
LDAP
Blowfish
46. Jayne - a security administrator - needs to Telnet into a router to change some configurations. Which of the following ports would need to be open to allow Jayne to change the configurations?
Mandatory vacations
Port forwarding
Clustering
23
47. Which of the following is an attack where Mal spreads USB thumb drives throughout a bank's parking lot in order to have malware installed on the banking systems?
Install both the private and the public key on the web server.
Two fish
Remote wipe
Social engineering
48. In a wireless network - which of the following components could cause too much coverage - too little coverage - and interference?
PEAP
AP power levels
Two fish
Device encryption
49. Jayne - the security administrator - notices a spike in the number of SQL injection attacks against a web server connected to a backend SQL database. Which of the following practices should be used to prevent an application from passing these attacks
Code review
Single sign-on
Input validation
MAC filtering
50. Mal - the security administrator - is implementing a web content fitter. Which of the following is the MOST important design consideration in regards to availability?
Loop protection
Non-repudiation
Fail state of the system
Change management