Test your basic knowledge |

Comptia Security + Exam

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Which of the following tools provides the ability to determine if an application is transmitting a password in clear-text?






2. Which of the following malicious code will do its objectionable deed after a predetermined action takes place or at a specific time?






3. Logs from an IDS show that a computer has been compromised with a botnet and is actively communicating with a command and control which of the following data types will be unavailable for later investigation?






4. Which of the following will educate employees about malicious attempts from an attacker to obtain bank account information?






5. When configuring multiple computers for RDP on the same wireless router it may be necessary to do which of the following?






6. Which of the following is used when performing a quantitative risk analysis?






7. Which of the following is BEST used to prevent ARP poisoning attacks across a network?






8. Which of the following is MOST relevant to a buffer overflow attack?






9. Which of the following attacks is BEST described as the interruption of network traffic accompanied by the insertion of malicious code?






10. Which of the following BEST explains the security benefit of a standardized server image?






11. Which of the following should a security administrator implement to prevent users from disrupting network connectivity if a user connects both ends of a network cable to different switch ports?






12. Which of the following malware types is an antivirus scanner MOST unlikely to discover?






13. Based on logs from file servers remote access systems - and IDS - a malicious insider was stealing data using a personal laptop while connected by VPN. The affected company wants access to the laptop to determine loss - but the insider's lawyer insis






14. Which of the following web application security weaknesses can be mitigated by preventing the use of HTML tags?






15. You detected an intrusion and are taking the necessary steps to preserve the evidence. You want to make sure the evidence will be admissible in a court of law. What should you do?






16. Which of the following should be performed on a computer to protect the operating system from malicious software?






17. Which of the following BEST describes an intrusion prevention system?






18. Which of the following are important physical security considerations when choosing a location for a new remote branch office?






19. An application log shows that the text 'test; rm -rf /etc/passwd' was entered into an HTML form. Which of the following describes the type of attack that was attempted?






20. An administrator identifies a security issue on but does not attempt to exploit it. Which of the following describes what the administrator has done?






21. Which of the following ports would a security administrator block if the administrator wanted to stop users from accessing outside SMTP services?






22. Which of the following wireless security controls can be easily and quickly circumvented using only a network sniffer?






23. What principle dictates that a user is given no more privilege necessary than that required to preform his/her job?






24. A security administrator with full administrative rights on the network is forced to temporarily take time off of their duties. Which of the following describes this form of access control?






25. In which of the following locations would a forensic analyst look to find a hooked process?






26. An attacker forces a Windows service that uses the Local System account as its service account to crash. The attacker is able to access administrator-level resources as a result. What kind of attack is this?






27. Which of the following environmental controls would BEST be used to regulate cooling within a datacenter?






28. A user is no longer able to transfer files to the FTP server. The security administrator has verified the ports are open on the network firewall. Which of the following should the security administrator check?






29. A user receives an automated call which appears to be from their bank. The automated recording provides details about the bank's privacy policy security policy and requests that the user clearly state their name - birthday and enter the banking detai






30. You want to improve security for remote administration to several Linux web servers on the Internet. The data as well as the authentication process needs to be encrypted. Which of the following should you do?






31. Your company wants a new web server that can be accessed both by users on your internal network and by users on the Internet. You advice the company to locate the server behind the corporate firewall so it can enjoy similar protection as the internal






32. You are the network admin for a large LAN with a single - firewall-protected - Internet connection. You want to analyze all network traffic in your local network for suspicious activities and receive a notification when a possible attack is in proces






33. Which of the following would be the BEST action to perform when conducting a corporate vulnerability assessment?






34. A visitor plugs their laptop into the network and receives a warning about their antivirus being out of-date along with various patches that are missing. The visitor is unable to access the Internet or any network resources. Which of the following is






35. Which of the following protocols requires the use of a CA based authentication process?






36. Which of the following would need to be configured correctly to allow remote access to the network?






37. What is the term used to describe the type of attack where a DNS server accepts and uses incorrect information from a host that does not have authority to supply that information?






38. On-going annual awareness security training should be coupled with:..






39. Used in conjunction which of the following are PII?






40. A security administrator working for a health insurance company needs to protect customer data by installing an HVAC system and a mantrap in the data center. Which of the following are being addressed?






41. Which of the following manages peer authentication and key exchange for an IPSec connection?






42. You discover that company confidential information is being encoded into graphics files and sent to a destination outside of the company. This is an example of what kind of cryptography?






43. The 802.11i standard specifies support for which encryption algorithms?






44. With which of the following is RAID MOST concerned?






45. What is the advantage of using application virtualization?






46. A security administrator needs to implement a site-to-site VPN tunnel between the main office and a remote branch. Which of the following protocols should be used for the tunnel?






47. Which of the following port numbers is used for SCP by default?






48. Your daily bandwidth monitoring report of your Internet connection shows an excessive amount of outgoing traffic on port 25. You have seen peaks in the reports before but this report shows many peaks outside office times. What should you do?






49. Which of the following attacks is manifested as an embedded HTML image object or JavaScript image tag in an email?






50. You are determining environmental control requirements for a data center that will contain several computers? What is the role of an HVAC system in this environment?