SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
Comptia Security +: Cyber Ops
Start Test
Study First
Subjects
:
certifications
,
comptia-security-+
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Which of the following is the MOST secure protocol for Mal - an administrator - to use for managing network devices?
Dictionary; Brute force
The DES algorithm is run three consecutive times against the item being encrypted.
SSH
Impersonation
2. River Tam - a security analyst - suspects that a rogue web server is running on the network. Which of the following would MOST likely be used to identify the server's IP address?
Port scanner
Ticket granting server
TACACS+
Assign multiple roles to the existing user ID
3. Which of the following security tools can Starbuck - an administrator - implement to mitigate the risks of theft?
LDAP
Port forwarding
Group based privileges
Device encryption
4. River Tam - a user - on a public Wi-Fi network logs into a webmail account and is redirected to a search engine. Which of the following attacks may be occurring?
Account expiration
MD5 checksum
P2P
Evil twin
5. Which of the following is a best practice when securing a switch from physical access?
Cold site
dcfldd
Disable unused ports
Subnetting
6. River Tam - the security engineer - has discovered that a breach is in progress on a non-production system of moderate importance. Which of the following should River Tam collect FIRST?
Memory dump - ARP cache
Temperature and humidity controls
River Tam - the attacker - overwhelms a system or application - causing it to crash and bring the server down to cause an outage.
80
7. Which of the following reduces the likelihood of a single point of failure when a server fails?
Accounting should be given read/write access to network share A and read access to network share B. River Tam should be given read access for the specific document on network share A.
The DES algorithm is run three consecutive times against the item being encrypted.
Clustering
Deploying and using a trusted OS
8. Mal - a security administrator - wants to secure remote telnet services and decides to use the services over SSH. Which of the following ports should Mal allow on the firewall by default?
Mean time to restore
Fuzzing
22
Validate the identity of an email sender;Encrypt messages;Decrypt messages
9. Hashing algorithms are used to address which of the following?
Signature based
Use Starbuck's private key to sign the binary
Integrity
22
10. Which of the following is the MAIN benefit of server-side versus client-side input validation?
Gray box
Ask the programmer to replicate the problem in a test environment.
Mandated security configurations have been made to the operating system.
Server-side input validation results in a more secure system than client-side input validation.
11. Which of the following ports would be blocked if Mal - a security administrator - wants to disable FTP?
21
RADIUS
Fraggle attack
Verify the user's identity
12. Which of the following is based on X.500 standards?
Spam fitters
ARP poisoning
LDAP
Use Starbuck's private key to sign the binary
13. Which of the following is BEST associated with PKI?
File encryption
Private key
Rootkit
IV attack
14. Which of the following multifactor authentication methods uses biometrics?
Proxies
The intermediate CA's public key
Something you are
River Tam - the attacker - overwhelms a system or application - causing it to crash and bring the server down to cause an outage.
15. Which of the following should be done before resetting a user's password due to expiration?
16. Mal - the security administrator - is implementing a web content fitter. Which of the following is the MOST important design consideration in regards to availability?
Two fish
The security company is provided with no information about the corporate network or physical locations.
Fail state of the system
WPA2-Enterprise
17. Which of the following would River Tam - a security administrator - utilize to identity a weakness within various applications without exploiting that weakness?
Group based privileges
Vulnerability scan
Single point of failure
Penetration testing
18. Which of the following is the BEST solution to securely administer remote servers?
SSH
MD5 checksum
Port scanner
Rogue access point
19. An example of a false negative
MD5
Zero day
Signature based
The IDS does not identify a buffer overflow
20. River Tam - a security administrator - has generated a key pair for the company web server. Which of the following should she do next to ensure all web traffic to the company web server is encrypted?
Install both the private and the public key on the web server.
MD5
21
It is faster to encrypt an individual file.
21. Which of the following is an improved version of the LANMAN hash?
Signature based
Failsafe
NTLM
P2P
22. Starbuck - the administrator - is tasked with deploying a strong encryption cipher. Which of the following ciphers would she be the LEAST likely to choose?
Proxy server
Two fish
Failsafe
Ticket granting server
23. Which of the following describes the ability for a third party to verify the sender or recipient of a given electronic message during authentication?
Information classification policy; Network access policy; Auditing and monitoring policy
80
RAS
Non-repudiation
24. Which of the following is a feature of Kerberos?
Impersonation
Single sign-on
Use Starbuck's private key to sign the binary
Risk avoidance
25. Starbuck - a security administrator - has completed the imaging process for 20 computers that were deployed. The image contains the operating system and all required software. Which of the following is this an example of?
Encrypt all confidential data.
LDAP
Deploying and using a trusted OS
Error handling
26. While traveling Jayne - an employee - decides he would like to download some new movies onto his corporate laptop. While installing software designed to download movies from multiple computers across the Internet. Jayne agrees to share portions of hi
P2P
Mandatory vacations
Enforced acceptable usage policy - encryption of confidential emails - and monitoring of communications leaving the organization.
The security company is provided with no information about the corporate network or physical locations.
27. Marketing creates a new folder and requests the following access be assigned: Sales Department - Read Marketing Department - Full Control Inside Sales - Read Write This is an example of which of the following?
The DES algorithm is run three consecutive times against the item being encrypted.
TACACS+
RBAC
Remotely initiate a device wipe
28. Which of the following should Starbuck - the security administrator - do FIRST when an employee reports the loss of a corporate mobile device?
Proxy server
Remotely initiate a device wipe
Botnets
The DES algorithm is run three consecutive times against the item being encrypted.
29. Which of the following is used to verify the identity of the sender of a signed email?
The DES algorithm is run three consecutive times against the item being encrypted.
To limit the number of endpoints connected through the same switch port
WPA2-Enterprise
Public key
30. An SQL injection vulnerability can be caused by which of the following?
Mandatory access control
Time of day restrictions;Access control lists
Subnetting
Improper input validation
31. Jayne - the security administrator - notices a spike in the number of SQL injection attacks against a web server connected to a backend SQL database. Which of the following practices should be used to prevent an application from passing these attacks
River Tam - the attacker - overwhelms a system or application - causing it to crash and bring the server down to cause an outage.
Input validation
Firewall
Detective
32. While performing basic forensic analysis of a hard drive in River Tam's - the security administrator - possession - which of the following should be verified during the analysis?
Enforced acceptable usage policy - encryption of confidential emails - and monitoring of communications leaving the organization.
Vulnerability scan
Image hashes
Install application updates
33. Which of the following is BEST utilized to actively test security controls on a particular system?
Worm outbreak
The DES algorithm is run three consecutive times against the item being encrypted.
Loop protection
Penetration test
34. The corporate NIPS requires a daily download from its vendor with updated definitions in order to block the latest attacks. Which of the following describes how the NIPS is functioning?
TPM
Remote wipe
AP power levels
Signature based
35. Mal - the Chief Executive Officer (CEO) of a company - has increased his travel plans for the next two years to improve business relations. Which of the following would need to be in place in case something happens to Pete?
Separation of duties
Succession planning
Image hashes
Temperature and humidity controls
36. Which of the following is BEST described by a scenario where organizational management chooses to implement an internal Incident Response Structure for the business?
Temperature and humidity controls
NAC
WPA2-PSK
Mitigation
37. Jayne - a security administrator - needs to Telnet into a router to change some configurations. Which of the following ports would need to be open to allow Jayne to change the configurations?
22
Time of day restrictions;Access control lists
Cross-site scripting
23
38. River Tam - a security administrator - suspects that a web server may be under attack. The web logs have several entries containing variations of the following entries: 'or 1=1-- or1'=1-- 'or1=1'
SQL injection
Use Starbuck's private key to sign the binary
NTLM
RAID 5 and a storage area network
39. The Chief Information Security Officer (CISO) tells the network administrator that a security company has been hired to perform a penetration test against their network. The security company asks the CISO which type of testing would be most beneficia
Blue jacking
The security company is provided with no information about the corporate network or physical locations.
Passive finger printing
IPS
40. Which of the following is a reason why Mal - a security administrator - would implement port security?
To limit the number of endpoints connected through the same switch port
PGP
Change management
Zero day exploit
41. Which of the following types of data encryption would Starbuck - a security administrator - use if MBR and the file systems needed to be included?
Vishing
Key escrow
Full disk
Passive finger printing
42. Account lockout is a mitigation strategy used by Starbuck - the administrator - to combat which of the following attacks?
Loop protection
Dictionary; Brute force
Time of day restrictions;Access control lists
Succession planning
43. Which of the following encrypts the body of a packet - rather than just the password - while sending information?
The security company is provided with no information about the corporate network or physical locations.
Vulnerability scan
TACACS+
CA
44. Starbuck's - a user - word processing software is exhibiting strange behavior - opening and closing itself at random intervals. There is no other strange behavior on the system. Which of the following would mitigate this problem in the future?
Group based privileges
Install application updates
Remote wipe
Accounting should be given read/write access to network share A and read access to network share B. River Tam should be given read access for the specific document on network share A.
45. Which of the following has a default port of 22?
Improper input validation
GSM phone card and PIN
Firewall
SSH
46. An administrator responsible for building and validating security configurations is a violation of which of the following security principles?
Notify security to identify employee's whereabouts.
Separation of duties
Install application updates
IPS
47. Which of the following BEST explains the security benefit of a standardized server image?
PII handling
Validate the identity of an email sender;Encrypt messages;Decrypt messages
Firewall
Mandated security configurations have been made to the operating system.
48. Starbuck - a security administrator - wants to prevent users in sales from accessing their servers after 6:00 p.m. - and prevent them from accessing accounting's network at all times. Which of the following should Starbuck implement to accomplish the
Time of day restrictions;Access control lists
Create file hashes for website and critical system files - and compare the current file hashes to the baseline at regular time intervals.
Zero day attack
VLAN mismatch is occurring.
49. A company notices that there is a flaw in one of their proprietary programs that the company runs in-house. The flaw could cause damage to the HVAC system. Which of the following would the company transfer to an insurance company?
Remotely initiate a device wipe
SNMPv3
Risk
Rootkit
50. Which of the following security concepts establishes procedures where creation and approval are performed through distinct functions?
Account lockout
Separation of duties
NIPS
Clean desk policy