Test your basic knowledge |

Comptia Security + Exam

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Which of the following devices is used to optimize and distribute data workloads across multiple computers or networks?






2. Based on logs from file servers remote access systems - and IDS - a malicious insider was stealing data using a personal laptop while connected by VPN. The affected company wants access to the laptop to determine loss - but the insider's lawyer insis






3. Which of the following identifies some of the running services on a system?






4. A technician needs to limit the wireless signal from reaching outside of a building. Which of the following actions should the technician take?






5. A security administrator finished taking a forensic image of a computer's memory. Which of the following should the administrator do to ensure image integrity?






6. You need to advise a new wiring system for a company with several locations partly open to the public. A primary requirement is to make tapping into the network as difficult as possible. Which of the following cable types should you advice?






7. In which of the following locations would a forensic analyst look to find a hooked process?






8. Which solution should you use?






9. A security administrator wants to know which systems are more susceptible to an attack compared to other systems on the network. Which of the following assessment tools would be MOST effective?






10. Which of the following access control models allows classification and labeling of objects?






11. Logs from an IDS show that a computer has been compromised with a botnet and is actively communicating with a command and control which of the following data types will be unavailable for later investigation?






12. The 802.11i standard specifies support for which encryption algorithms?






13. Which of the following MUST a programmer implement to prevent cross-site scripting?






14. Which of the following protocols should be blocked at the network perimeter to prevent host enumeration by sweep devices?






15. A visitor plugs their laptop into the network and receives a warning about their antivirus being out of-date along with various patches that are missing. The visitor is unable to access the Internet or any network resources. Which of the following is






16. Which of the following can prevent an unauthorized employee from entering a data center?






17. Which of the following is a best practice when securing a switch from physical access?






18. Which of the following ports would a security administrator block if the administrator wanted to stop users from accessing outside SMTP services?






19. Which of the following uses TCP port 22 by default?






20. A web application has been found to be vulnerable to a SQL injection attack. Which of the following BEST describes the required remediation action?






21. The detection of a NOOP sled is an indication of which of the following attacks?






22. Which of the following will provide the HIGHEST level of wireless network security?






23. In an 802.11n network which of the following provides the MOST secure method of both encryption and authorization?






24. You installed a new e-commerce application on your web server that will allow your company to take orders from their website. You want to ensure that information that customers enter into their web browser is sent securely to the web server. Which of






25. When examining HTTP server logs the security administrator notices that the company's online store crashes after a particular search string is executed by a single external user. Which of the following BEST describes this type of attack?






26. Which of the following includes a photo and can be used for identification?






27. Which of the following encryption algorithms can be used in PGP for data encryption?






28. Which of the following is an example of allowing another user physical access to a secured area without validation of their credentials?






29. Which of the following concepts ensures that the data is only viewable to authorized users?






30. Which of the following logical controls does a flood guard protect against?






31. A security administrator working for a health insurance company needs to protect customer data by installing an HVAC system and a mantrap in the data center. Which of the following are being addressed?






32. Which of the following should be performed on a computer to protect the operating system from malicious software?






33. Which of the following are important physical security considerations when choosing a location for a new remote branch office?






34. Which of the following malicious code will do its objectionable deed after a predetermined action takes place or at a specific time?






35. Isolation mode on an AP provides which of the following functionality types?






36. Which of the following would allow traffic to be redirected through a malicious machine by sending false hardware address updates to a switch?






37. Two systems are being designed. System A has a high availability requirement. System B has a high security requirement with less emphasis on system uptime. Which of the following configurations BEST fits the need for each system?






38. Which of the following web application security weaknesses can be mitigated by preventing the use of HTML tags?






39. Which of the following should be reviewed periodically to ensure a server maintains the correct security configuration?






40. Which of the following is a reason to perform user awareness and training?






41. You want to setup a secure method of sending and receiving email. Which two of the following protocols can be used for this purpose?






42. Upon investigation an administrator finds a suspicious system-level kernel module which modifies file system operations. This is an example of which of the following?






43. Which of the following may cause a user connected to a NAC-enabled network - to not be prompted for credentials?


44. Which environmental control is part of TEMPEST compliance?






45. An existing application has never been assessed from a security perspective. Which of the following is the BEST assessment technique in order to identify the application's security posture?






46. What is the name of the process during which an attacker gathers information about a target company's intranet - remote access - extranet - and Internet connections?






47. Users of specific systems are reporting that their data has been corrupted. After a recent patch update to those systems the users are still reporting issues of data being corrupt. Which of the following assessment techniques need to be performed to






48. Which of the following will educate employees about malicious attempts from an attacker to obtain bank account information?






49. User in your department complain about a slow Internet connection. You monitor the external interface of your company's border router and notice a huge mount of half-open TCP connections. What type of attack is your company currently a victim of?






50. The server log shows 25 SSH login sessions it is a large company and the administrator does not know if this is normal behavior or if the network is under attack. Where should the administrator look to determine if this is normal behavior?