SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
Comptia Security + Exam
Start Test
Study First
Subjects
:
certifications
,
comptia-security-+
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. What principle requires that for a particular set of transactions - no one individual is solely responsible or allowed to execute the complete set?
Symmetric
Separation of duties
Algorithm
Integrity
2. An administrator is updating firmware on routers throughout the company. Where should the administrator document this work?
Change Management System
Integrity
Rogue access points
Clean desk policy
3. You need to advise a new wiring system for a company with several locations partly open to the public. A primary requirement is to make tapping into the network as difficult as possible. Which of the following cable types should you advice?
IKE
Fiber optic
DNS spoofing
Mandatory vacation
4. A visitor plugs their laptop into the network and receives a warning about their antivirus being out of-date along with various patches that are missing. The visitor is unable to access the Internet or any network resources. Which of the following is
Vulnerability scanning
Pharming - Logic bomb
To ensure that staff understands what data they are handling and processing
The security posture is enabled on the network and remediation must take place before access is given to the visitor on that laptop.
5. Which of the following manages peer authentication and key exchange for an IPSec connection?
Shielding
Vishing
ARP poisoning
IKE
6. A security administrator is tasked with ensuring that all servers are highly available and that hard drive failure will not affect an individual server. Which of the following configurations will allow for high availability?
Hardware RAID 5 - Software RAID 1
The server is missing the default gateway.
Load balancer
Physical control of the data
7. A user receives an automated call which appears to be from their bank. The automated recording provides details about the bank's privacy policy security policy and requests that the user clearly state their name - birthday and enter the banking detai
Risk transference
A system that stops an attack in progress.
Vishing
Physical control of the data
8. What principle dictates that a user is given no more privilege necessary than that required to preform his/her job?
ICMP
Steganography
To ensure that staff understands what data they are handling and processing
Principle of least privilege
9. Instead of giving a security administrator full the administrator is given rights only to review logs and update security related network devices. Additional rights are handed out to network administrators for the areas that fall within their job des
Separation of duties
Spear phishing
Least privilege
DMZ
10. What asymmetric key is used to encrypt when using HTTPS?
11. Which of the following will educate employees about malicious attempts from an attacker to obtain bank account information?
AC filtering - Disabled SSID broadcast
Vulnerability scanning
Location that meets power and connectivity requirementsdatacenter
Phishing techniques
12. Which of the following is a best practice when securing a switch from physical access?
Lets you minimize the attack surface relating to the application
It is used to provide data encryption for WAP connections.
Disable unused ports
Validate input to remove hypertext
13. Which of the following is the BEST way to secure data for the purpose of retention?
Off-site backup
SYN attacks
IPSec
Lets you minimize the attack surface relating to the application
14. A helpdesk engineer just received a phone call from an administrator at a remote branch office. The administrator claimed to have forgotten the password for the root account of the UNIX servers. Although the helpdesk engineer didn't know of any admin
Confidentiality
Social Engineering attack
Cross-site scripting
Mandated security configurations have been made to the operating system.
15. Your company wants a new web server that can be accessed both by users on your internal network and by users on the Internet. You advice the company to locate the server behind the corporate firewall so it can enjoy similar protection as the internal
Principle of least privilege
Multi-factor authentication.
Use SSH to connect to the Linux shell
DMZ
16. Which of the following can prevent an unauthorized employee from entering a data center?
The remote router has ICMP blocked.
Hardware RAID 5 - Software RAID 1
Use SSH to connect to the Linux shell
Security guard - Proximity reader
17. A company needs to be able to prevent entry at all times - to a highly sensitive area inside a public building. In order to ensure the BEST type of physical security - which of the following should be implemented?
Mantrap
Vulnerability scan
Network Access Control
VPN concentrator
18. Which of the following protocols should be blocked at the network perimeter to prevent host enumeration by sweep devices?
The remote router has ICMP blocked.
ICMP
Run the image through SHA256. Answer: D
Man-in-the-middle
19. What asymmetric key is used to decrypt when using HTTPS?
20. When examining HTTP server logs the security administrator notices that the company's online store crashes after a particular search string is executed by a single external user. Which of the following BEST describes this type of attack?
DoS
Proxies
Change Management System
SSH - SCP - and SFTP (the MOST secure method to transfer files from a host machine)
21. A security administrator working for a health insurance company needs to protect customer data by installing an HVAC system and a mantrap in the data center. Which of the following are being addressed?
Social Engineering attack
Confidentiality - Availability
ACLs
Configure the IE popup blockers
22. A security administrator finished taking a forensic image of a computer's memory. Which of the following should the administrator do to ensure image integrity?
Provide an appropriate ambient temperature and Maintain appropriate humidity levels
Run the image through SHA256. Answer: D
Symmetric Key
CAC
23. Which of the following facilitates computing for heavily utilized systems and networks?
Integrity
Provider cloud
Rootkit
Memory - network processes - and system processesserver. If the computer is powered off
24. Actively monitoring data streams in search of malicious code or behavior is an example of..
Mantrap
content inspection.
White box
Mantraps
25. Which of the following would allow traffic to be redirected through a malicious machine by sending false hardware address updates to a switch?
quantitative risk assessment
Install a network-based IDS
IKE
ARP poisoning
26. While browsing the Internet an administrator notices their browser behaves erratically - appears to download something - and then crashes. Upon restarting the PC - the administrator notices performance is extremely slow and there are hundreds of outb
SNMP (also use to monitor the parameters of network devices)
Fault tolerance
WPA2-PSK
The PC has become part of a botnet.
27. Which of the following is BEST used to prevent ARP poisoning attacks across a network?
DMZ
Vulnerability scan
Apply a security control which ties specific ports to end-device MAC addresses and prevents additional devices from being connected to the network.
VLAN segregation
28. In which of the following locations would a forensic analyst look to find a hooked process?
BIOS
ID badges
HSM
NIDS
29. Which of the following is used for exchanging secret keys over an insecure public network?
Virtual servers have the same information security requirements as physical servers.
Add input validation to forms.
Diffie-Hellman
Algorithm
30. You are designing a Web-based application. You design the application so that it runs under a security context that allows only those privileges required for the application to run to minimize risk in the event of an attack. This is an example of whi
MD5
Organize data based on severity and asset value.
Principle of least privilege
Segmentation of each wireless user from other wireless users
31. The security administrator implemented privacy password protected screen savers - and hired a secure shredding and disposal service. Which of the following attacks is the security administrator trying to mitigate?
MAC address
Social Engineering attack
Asset value
Dumpster diving - Shoulder surfing
32. A targeted email attack sent to the company's Chief Executive Officer (CEO) is known as which of the following?
DoS
Social Engineering attack
Whaling
Physical control of the data
33. Data can potentially be stolen from a disk screen-lock protected - smartphone by which of the following?
Humidity
Implicit deny
Smurf attack
Bluesnarfing
34. You are performing risk assessment for an organization. What should you do during impact assessment?
IDS
Implicit deny
Determine the potential monetary costs related to a threat
Security guard - Proximity reader
35. Which of the following wireless security controls can be easily and quickly circumvented using only a network sniffer?
AC filtering - Disabled SSID broadcast
User rights
Spam filters
Use SSH to connect to the Linux shell
36. A set of instructions normally implemented on a computer system as a procedure to manipulate data is called a(n)?
Algorithm
Rogue access point
White box
Spam filters
37. Two systems are being designed. System A has a high availability requirement. System B has a high security requirement with less emphasis on system uptime. Which of the following configurations BEST fits the need for each system?
Install a network-based IDS
Ensure a proper chain of custody
Lets you minimize the attack surface relating to the application
System A fails open. System B fails closed.
38. A security administrator needs to implement a site-to-site VPN tunnel between the main office and a remote branch. Which of the following protocols should be used for the tunnel?
IPSec
FTPS
Provide an appropriate ambient temperature and Maintain appropriate humidity levels
AES and TKIP
39. What is the name of the process during which an attacker gathers information about a target company's intranet - remote access - extranet - and Internet connections?
VPN concentrator
DAC
Footprinting
NIPS is blocking activities from those specific websites.
40. Which of the following is the MOST likely cause of a single computer communicating with an unknown IRC server and scanning other systems on the network?
escalation of privileges.
Botnet
The development team is transferring data to test systems using SFTP and SCP.
Mantraps
41. A programmer allocates 16 bytes for a string but does not adequately ensure that more than 16 bytes cannot be copied into the variable. This program may be vulnerable to which of the following attacks?
It is used to provide data encryption for WAP connections.
Fiber optic
HSM
Buffer overflow
42. Which of the following is the MAIN reason to require data labeling?
To ensure that staff understands what data they are handling and processing
Steganography
To provide documentation as to who has handled the evidence
Integrity and Authentication
43. Which of the following should be enabled to ensure only certain wireless clients can access the network?
MAC filtering
Security guard - Proximity reader
Trojans
VLAN segregation
44. Which of the following is the BEST choice for encryption on a wireless network?
Integrity and Authentication
WPA2-PSK
Fiber optic
Vulnerability scan
45. Which of the following is MOST likely to be the last rule contained on any firewall?
Buffer overflow
Firewall rulesflow of network traffic at the edge of the network
Implicit deny
Use SSH to connect to the Linux shell
46. In order to ensure high availability of all critical backups of the main data center are done in the middle of the night and then the backup tapes are taken to an offsite location. Which of the following would ensure the minimal amount of downtime in
Trojans
Polymorphic
Having the offsite location of tapes also be the hot siteservers
Baseline reporting
47. Which of the following BEST explains the security benefit of a standardized server image?
Pharming - Logic bomb
Spear phishing
Mandated security configurations have been made to the operating system.
Baseline reporting
48. Logs from an IDS show that a computer has been compromised with a botnet and is actively communicating with a command and control which of the following data types will be unavailable for later investigation?
Clustering
DMZ
Memory - network processes - and system processesserver. If the computer is powered off
Minimize risk of physical data theft. - Minimize the impact of the failure of any one file server.
49. Which of the following attacks is manifested as an embedded HTML image object or JavaScript image tag in an email?
ARP poisoning
Only the message data is encrypted
Cross-site scripting
Smurf attack
50. With which of the following is RAID MOST concerned?
IDS
Privacy policy
Firewall rulesflow of network traffic at the edge of the network
Availability