Test your basic knowledge |

Comptia Security + Exam

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Which of the following port numbers is used for SCP by default?






2. Data can potentially be stolen from a disk screen-lock protected - smartphone by which of the following?






3. A security administrator needs to implement a site-to-site VPN tunnel between the main office and a remote branch. Which of the following protocols should be used for the tunnel?






4. Which of the following allows a security administrator to set device traps?






5. Which of the following ports would a security administrator block if the administrator wanted to stop users from accessing outside SMTP services?






6. An existing application has never been assessed from a security perspective. Which of the following is the BEST assessment technique in order to identify the application's security posture?






7. Which of the following uses TCP port 22 by default?






8. Which of the following is NOT an application layer security protocol?






9. You have several computers that use the NTLM authentication protocol for client authentication. Network policy requires user passwords with at least 16 characters. What hash algorithm is used for password authentication?






10. Which of the following should be considered when trying to prevent somebody from capturing network traffic?






11. Which of the following protocols requires the use of a CA based authentication process?






12. Your organization recently purchased several new laptop computers for employees. You're asked to encrypt the laptop's hard drives without purchasing any additional hardware. What would you use?






13. Which of the following reduces the likelihood of a single point of failure when a server fails?






14. Which of the following will provide the HIGHEST level of wireless network security?






15. An administrator who wishes to block all database ports at the firewall should include which of the following ports in the block list?






16. Upon investigation an administrator finds a suspicious system-level kernel module which modifies file system operations. This is an example of which of the following?






17. The detection of a NOOP sled is an indication of which of the following attacks?






18. What principle dictates that a user is given no more privilege necessary than that required to preform his/her job?






19. DRPs should contain which of the following?






20. Which of the following would be implemented to allow access to services while segmenting access to the internal network?






21. Which of the following devices is often used to cache and filter content?






22. A security engineer is troubleshooting a server which cannot be reached from the Internet or the internal network. All other servers on the DMZ are able to communicate with this server. Which of the following is the MOST likely cause?






23. Which of the following is an unauthorized wireless router that allows access to a secure network?






24. Which of the following is used when performing a quantitative risk analysis?






25. A security administrator working for a health insurance company needs to protect customer data by installing an HVAC system and a mantrap in the data center. Which of the following are being addressed?






26. Which of the following are accomplished when a message is digitally signed?






27. Which of the following access control models allows classification and labeling of objects?






28. An administrator identifies a security issue on but does not attempt to exploit it. Which of the following describes what the administrator has done?






29. Proper wireless antenna placement and radio power setting reduces the success of which of the following reconnaissance methods?






30. A security administrator is in charge of a a hot site and a cold site. Due to a recent disaster - the administrator needs to ensure that their cold site is ready to go in case of a disaster. Which of the following does the administrator need to ensur






31. You are performing risk assessment for an organization. What should you do during impact assessment?






32. You installed a new e-commerce application on your web server that will allow your company to take orders from their website. You want to ensure that information that customers enter into their web browser is sent securely to the web server. Which of






33. When examining HTTP server logs the security administrator notices that the company's online store crashes after a particular search string is executed by a single external user. Which of the following BEST describes this type of attack?






34. A rogue access point with the same SSID as the production wireless network is found. Which of the following BEST describes this attack?






35. The 802.11i standard specifies support for which encryption algorithms?






36. Used in conjunction which of the following are PII?






37. A security administrator with full administrative rights on the network is forced to temporarily take time off of their duties. Which of the following describes this form of access control?






38. Which of the following is a policy that would force all users to organize their areas as well as help in reducing the risk of possible data theft?






39. A security administrator wants to determine what data is allowed to be collected from users of the corporate Internet-facing web application. Which of the following should be referenced?






40. An application log shows that the text 'test; rm -rf /etc/passwd' was entered into an HTML form. Which of the following describes the type of attack that was attempted?






41. Which of the following BEST describes the proper method and reason to implement port security?






42. Which of the following devices would allow a technician to view IP headers on a data packet?






43. Which of the following describes the purpose of chain of custody as applied to forensic image retention?






44. Which of the following is a management control type?






45. Which of the following is true concerning email message encryption by using S/MIME?






46. A company that purchases insurance to reduce risk is an example of which of the following?






47. A security administrator finished taking a forensic image of a computer's memory. Which of the following should the administrator do to ensure image integrity?






48. Which of the following devices BEST allows a security administrator to identify malicious activity after it has occurred?






49. Which of the following is a technique designed to obtain information from a specific person?






50. Which of the following attacks is manifested as an embedded HTML image object or JavaScript image tag in an email?