Test your basic knowledge |

Comptia Security +: Cyber Ops

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Which of the following is the MOST secure protocol for Mal - an administrator - to use for managing network devices?






2. River Tam - a security analyst - suspects that a rogue web server is running on the network. Which of the following would MOST likely be used to identify the server's IP address?






3. Which of the following security tools can Starbuck - an administrator - implement to mitigate the risks of theft?






4. River Tam - a user - on a public Wi-Fi network logs into a webmail account and is redirected to a search engine. Which of the following attacks may be occurring?






5. Which of the following is a best practice when securing a switch from physical access?






6. River Tam - the security engineer - has discovered that a breach is in progress on a non-production system of moderate importance. Which of the following should River Tam collect FIRST?






7. Which of the following reduces the likelihood of a single point of failure when a server fails?






8. Mal - a security administrator - wants to secure remote telnet services and decides to use the services over SSH. Which of the following ports should Mal allow on the firewall by default?






9. Hashing algorithms are used to address which of the following?






10. Which of the following is the MAIN benefit of server-side versus client-side input validation?






11. Which of the following ports would be blocked if Mal - a security administrator - wants to disable FTP?






12. Which of the following is based on X.500 standards?






13. Which of the following is BEST associated with PKI?






14. Which of the following multifactor authentication methods uses biometrics?






15. Which of the following should be done before resetting a user's password due to expiration?


16. Mal - the security administrator - is implementing a web content fitter. Which of the following is the MOST important design consideration in regards to availability?






17. Which of the following would River Tam - a security administrator - utilize to identity a weakness within various applications without exploiting that weakness?






18. Which of the following is the BEST solution to securely administer remote servers?






19. An example of a false negative






20. River Tam - a security administrator - has generated a key pair for the company web server. Which of the following should she do next to ensure all web traffic to the company web server is encrypted?






21. Which of the following is an improved version of the LANMAN hash?






22. Starbuck - the administrator - is tasked with deploying a strong encryption cipher. Which of the following ciphers would she be the LEAST likely to choose?






23. Which of the following describes the ability for a third party to verify the sender or recipient of a given electronic message during authentication?






24. Which of the following is a feature of Kerberos?






25. Starbuck - a security administrator - has completed the imaging process for 20 computers that were deployed. The image contains the operating system and all required software. Which of the following is this an example of?






26. While traveling Jayne - an employee - decides he would like to download some new movies onto his corporate laptop. While installing software designed to download movies from multiple computers across the Internet. Jayne agrees to share portions of hi






27. Marketing creates a new folder and requests the following access be assigned: Sales Department - Read Marketing Department - Full Control Inside Sales - Read Write This is an example of which of the following?






28. Which of the following should Starbuck - the security administrator - do FIRST when an employee reports the loss of a corporate mobile device?






29. Which of the following is used to verify the identity of the sender of a signed email?






30. An SQL injection vulnerability can be caused by which of the following?






31. Jayne - the security administrator - notices a spike in the number of SQL injection attacks against a web server connected to a backend SQL database. Which of the following practices should be used to prevent an application from passing these attacks






32. While performing basic forensic analysis of a hard drive in River Tam's - the security administrator - possession - which of the following should be verified during the analysis?






33. Which of the following is BEST utilized to actively test security controls on a particular system?






34. The corporate NIPS requires a daily download from its vendor with updated definitions in order to block the latest attacks. Which of the following describes how the NIPS is functioning?






35. Mal - the Chief Executive Officer (CEO) of a company - has increased his travel plans for the next two years to improve business relations. Which of the following would need to be in place in case something happens to Pete?






36. Which of the following is BEST described by a scenario where organizational management chooses to implement an internal Incident Response Structure for the business?






37. Jayne - a security administrator - needs to Telnet into a router to change some configurations. Which of the following ports would need to be open to allow Jayne to change the configurations?






38. River Tam - a security administrator - suspects that a web server may be under attack. The web logs have several entries containing variations of the following entries: 'or 1=1-- or1'=1-- 'or1=1'






39. The Chief Information Security Officer (CISO) tells the network administrator that a security company has been hired to perform a penetration test against their network. The security company asks the CISO which type of testing would be most beneficia






40. Which of the following is a reason why Mal - a security administrator - would implement port security?






41. Which of the following types of data encryption would Starbuck - a security administrator - use if MBR and the file systems needed to be included?






42. Account lockout is a mitigation strategy used by Starbuck - the administrator - to combat which of the following attacks?






43. Which of the following encrypts the body of a packet - rather than just the password - while sending information?






44. Starbuck's - a user - word processing software is exhibiting strange behavior - opening and closing itself at random intervals. There is no other strange behavior on the system. Which of the following would mitigate this problem in the future?






45. Which of the following has a default port of 22?






46. An administrator responsible for building and validating security configurations is a violation of which of the following security principles?






47. Which of the following BEST explains the security benefit of a standardized server image?






48. Starbuck - a security administrator - wants to prevent users in sales from accessing their servers after 6:00 p.m. - and prevent them from accessing accounting's network at all times. Which of the following should Starbuck implement to accomplish the






49. A company notices that there is a flaw in one of their proprietary programs that the company runs in-house. The flaw could cause damage to the HVAC system. Which of the following would the company transfer to an insurance company?






50. Which of the following security concepts establishes procedures where creation and approval are performed through distinct functions?