SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
Comptia Security + Exam
Start Test
Study First
Subjects
:
certifications
,
comptia-security-+
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Which of the following port numbers is used for SCP by default?
22
Phishing techniques
Implicit deny
Memory - network processes - and system processesserver. If the computer is powered off
2. Data can potentially be stolen from a disk screen-lock protected - smartphone by which of the following?
Mantraps
mitigation - acceptance - transference
Bluesnarfing
Account disablement
3. A security administrator needs to implement a site-to-site VPN tunnel between the main office and a remote branch. Which of the following protocols should be used for the tunnel?
IPSec
Content filtering
Pharming - Logic bomb
War driving
4. Which of the following allows a security administrator to set device traps?
Asset value
SNMP (also use to monitor the parameters of network devices)
Steganography
Phishing techniques
5. Which of the following ports would a security administrator block if the administrator wanted to stop users from accessing outside SMTP services?
Add input validation to forms.
CCTV
25
Baseline reporting
6. An existing application has never been assessed from a security perspective. Which of the following is the BEST assessment technique in order to identify the application's security posture?
The web site's private key.
Determine the potential monetary costs related to a threat
Baseline reporting
Spear phishing
7. Which of the following uses TCP port 22 by default?
SSH - SCP - and SFTP (the MOST secure method to transfer files from a host machine)
NIPS is blocking activities from those specific websites.
The server is missing the default gateway.
NOOP instructions
8. Which of the following is NOT an application layer security protocol?
Off-site backup
The PC has become part of a botnet.
Loop protection
IPSec
9. You have several computers that use the NTLM authentication protocol for client authentication. Network policy requires user passwords with at least 16 characters. What hash algorithm is used for password authentication?
MD5
Load balancer
Evil twin
WPA2-PSK
10. Which of the following should be considered when trying to prevent somebody from capturing network traffic?
PEAP-TLS
EMI shielding
Footprinting
Business impact analysis
11. Which of the following protocols requires the use of a CA based authentication process?
Vulnerability scan
Validate input to remove hypertext
A worm is self-replicating
PEAP-TLS
12. Your organization recently purchased several new laptop computers for employees. You're asked to encrypt the laptop's hard drives without purchasing any additional hardware. What would you use?
content inspection.
WPA2-PSK
Integrity and Authentication
TPM
13. Which of the following reduces the likelihood of a single point of failure when a server fails?
Physical control of the data
Vulnerability scanner
IKE
Clustering
14. Which of the following will provide the HIGHEST level of wireless network security?
Rootkit
WPA2
Pharming - Logic bomb
SNMP (also use to monitor the parameters of network devices)
15. An administrator who wishes to block all database ports at the firewall should include which of the following ports in the block list?
Integrity and Authentication
1433
NIDS
WPA2-PSK
16. Upon investigation an administrator finds a suspicious system-level kernel module which modifies file system operations. This is an example of which of the following?
A system that stops an attack in progress.
Rootkit
IPSec
MAC
17. The detection of a NOOP sled is an indication of which of the following attacks?
Buffer overflow
Location that meets power and connectivity requirementsdatacenter
Decrease the power levels on the WAP
AES and TKIP
18. What principle dictates that a user is given no more privilege necessary than that required to preform his/her job?
Use SSH to connect to the Linux shell
Principle of least privilege
Firewall - VPN
Provider cloud
19. DRPs should contain which of the following?
Off-site backup
Hierarchical list of critical systems
Evil twin
IPSec
20. Which of the following would be implemented to allow access to services while segmenting access to the internal network?
S/MIME PGP
DMZ
Diffie-Hellman
Enact a policy banning users from bringing in personal music devices.
21. Which of the following devices is often used to cache and filter content?
Privacy policy
Deny all
Proxies
MD5
22. A security engineer is troubleshooting a server which cannot be reached from the Internet or the internal network. All other servers on the DMZ are able to communicate with this server. Which of the following is the MOST likely cause?
The server is missing the default gateway.
Information disclosure
White box
Off-site backup
23. Which of the following is an unauthorized wireless router that allows access to a secure network?
Rogue access point
IDEA and TripleDes
Mantraps
Forward to different RDP listening ports.
24. Which of the following is used when performing a quantitative risk analysis?
Protocol analyzer
SSL
Asset value
Bluesnarfing
25. A security administrator working for a health insurance company needs to protect customer data by installing an HVAC system and a mantrap in the data center. Which of the following are being addressed?
Confidentiality - Availability
AES and TKIP
Deny all
IPSec
26. Which of the following are accomplished when a message is digitally signed?
Off-site backup
Integrity and Authentication
Shielding
Power levels
27. Which of the following access control models allows classification and labeling of objects?
smurf attacks
Protocol analyzer
Initial vector
MAC
28. An administrator identifies a security issue on but does not attempt to exploit it. Which of the following describes what the administrator has done?
Only the message data is encrypted
Asset value
ACLs
Vulnerability scan
29. Proper wireless antenna placement and radio power setting reduces the success of which of the following reconnaissance methods?
Baseline reporting
War driving
Trojans
The remote router has ICMP blocked.
30. A security administrator is in charge of a a hot site and a cold site. Due to a recent disaster - the administrator needs to ensure that their cold site is ready to go in case of a disaster. Which of the following does the administrator need to ensur
The PC has become part of a botnet.
Implement a change management strategy
Location that meets power and connectivity requirementsdatacenter
Baseline reporting
31. You are performing risk assessment for an organization. What should you do during impact assessment?
SNMP (also use to monitor the parameters of network devices)
Change Management System
Determine the potential monetary costs related to a threat
The remote router has ICMP blocked.
32. You installed a new e-commerce application on your web server that will allow your company to take orders from their website. You want to ensure that information that customers enter into their web browser is sent securely to the web server. Which of
Diffie-Hellman
SSL
Vulnerability scan
1433
33. When examining HTTP server logs the security administrator notices that the company's online store crashes after a particular search string is executed by a single external user. Which of the following BEST describes this type of attack?
Algorithm
DoS
Humidity
1433
34. A rogue access point with the same SSID as the production wireless network is found. Which of the following BEST describes this attack?
User rights and permissions reviews
Judgment
Evil twin
NIPS is blocking activities from those specific websites.
35. The 802.11i standard specifies support for which encryption algorithms?
AES and TKIP
Segmentation of each wireless user from other wireless users
MS-CHAP
Evil twin
36. Used in conjunction which of the following are PII?
Apply a security control which ties specific ports to end-device MAC addresses and prevents additional devices from being connected to the network.
Birthday - Full name
IPSec
53
37. A security administrator with full administrative rights on the network is forced to temporarily take time off of their duties. Which of the following describes this form of access control?
IPSec
Only the message data is encrypted
Mandatory vacation
Buffer overflow
38. Which of the following is a policy that would force all users to organize their areas as well as help in reducing the risk of possible data theft?
VLAN
ACLs
Fiber optic
Clean desk policy
39. A security administrator wants to determine what data is allowed to be collected from users of the corporate Internet-facing web application. Which of the following should be referenced?
IKE
Smurf attack
Privacy policy
Shoulder surfing
40. An application log shows that the text 'test; rm -rf /etc/passwd' was entered into an HTML form. Which of the following describes the type of attack that was attempted?
Command injection
Clustering
The development team is transferring data to test systems using SFTP and SCP.
Segmentation of each wireless user from other wireless users
41. Which of the following BEST describes the proper method and reason to implement port security?
Symmetric Key
Apply a security control which ties specific ports to end-device MAC addresses and prevents additional devices from being connected to the network.
Implement a change management strategy
EMI shielding
42. Which of the following devices would allow a technician to view IP headers on a data packet?
Security guard - Proximity reader
Protocol analyzer
Spam filters
Confidentiality
43. Which of the following describes the purpose of chain of custody as applied to forensic image retention?
Implement a change management strategy
To provide documentation as to who has handled the evidence
Privilege escalation
Evil twin
44. Which of the following is a management control type?
A system that stops an attack in progress.
Vulnerability scanning
Account disablement
Spear phishing
45. Which of the following is true concerning email message encryption by using S/MIME?
AC filtering - Disabled SSID broadcast
Shielding
Only the message data is encrypted
Judgment
46. A company that purchases insurance to reduce risk is an example of which of the following?
Risk transference
Determine the potential monetary costs related to a threat
Mantrap
Rogue access points
47. A security administrator finished taking a forensic image of a computer's memory. Which of the following should the administrator do to ensure image integrity?
Run the image through SHA256. Answer: D
Hierarchical list of critical systems
Provide an appropriate ambient temperature and Maintain appropriate humidity levels
Buffer overflow
48. Which of the following devices BEST allows a security administrator to identify malicious activity after it has occurred?
The web site's public key.
Rogue access point
Spear phishing
IDS
49. Which of the following is a technique designed to obtain information from a specific person?
The web site's public key.
Before and after the imaging process and then hash the forensic image
Spear phishing
WPA Enterprise
50. Which of the following attacks is manifested as an embedded HTML image object or JavaScript image tag in an email?
IDEA and TripleDes
Proxies
Cross-site scripting
CCTV