SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
Comptia Security + Exam
Start Test
Study First
Subjects
:
certifications
,
comptia-security-+
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Which of the following tools provides the ability to determine if an application is transmitting a password in clear-text?
Shielding
Hardware RAID 5 - Software RAID 1
Protocol analyzer
Privilege escalation
2. Which of the following malicious code will do its objectionable deed after a predetermined action takes place or at a specific time?
Logic Bomb
Vulnerability scanning
Principle of least privilege
Install a network-based IDS
3. Logs from an IDS show that a computer has been compromised with a botnet and is actively communicating with a command and control which of the following data types will be unavailable for later investigation?
Memory - network processes - and system processesserver. If the computer is powered off
Baseline reporting
Off-site backup
Confidentiality
4. Which of the following will educate employees about malicious attempts from an attacker to obtain bank account information?
Determine open ports
Birthday - Full name
IKE
Phishing techniques
5. When configuring multiple computers for RDP on the same wireless router it may be necessary to do which of the following?
User rights
Evil twin
Buffer overflow
Forward to different RDP listening ports.
6. Which of the following is used when performing a quantitative risk analysis?
Asset value
FTPS
Off-site backup
MAC address
7. Which of the following is BEST used to prevent ARP poisoning attacks across a network?
Run the image through SHA256. Answer: D
VLAN segregation
The web site's public key.
53
8. Which of the following is MOST relevant to a buffer overflow attack?
25
Account disablement
NOOP instructions
Accountability
9. Which of the following attacks is BEST described as the interruption of network traffic accompanied by the insertion of malicious code?
Integrity and Authentication
Evil twin
1433
Man-in-the-middle
10. Which of the following BEST explains the security benefit of a standardized server image?
Initial vector
Mandated security configurations have been made to the operating system.
Spam filters
Off-site backup
11. Which of the following should a security administrator implement to prevent users from disrupting network connectivity if a user connects both ends of a network cable to different switch ports?
Loop protection
NOOP instructions
Risk assessmentproduct Answer: D
Virtual servers have the same information security requirements as physical servers.
12. Which of the following malware types is an antivirus scanner MOST unlikely to discover?
DMZ
Pharming - Logic bomb
Apply a security control which ties specific ports to end-device MAC addresses and prevents additional devices from being connected to the network.
Logic Bomb
13. Based on logs from file servers remote access systems - and IDS - a malicious insider was stealing data using a personal laptop while connected by VPN. The affected company wants access to the laptop to determine loss - but the insider's lawyer insis
Dumpster diving
Location that meets power and connectivity requirementsdatacenter
Clustering
MAC address
14. Which of the following web application security weaknesses can be mitigated by preventing the use of HTML tags?
SSL
The remote router has ICMP blocked.
HSM
Cross-site scripting
15. You detected an intrusion and are taking the necessary steps to preserve the evidence. You want to make sure the evidence will be admissible in a court of law. What should you do?
Gas
Logic Bomb
Ensure a proper chain of custody
escalation of privileges.
16. Which of the following should be performed on a computer to protect the operating system from malicious software?
Disable unused services - Update HIPS signatures
A worm is self-replicating
Network Access Control
mitigation - acceptance - transference
17. Which of the following BEST describes an intrusion prevention system?
A system that stops an attack in progress.
Black hat
Business impact analysis
TCP SYN flood attack
18. Which of the following are important physical security considerations when choosing a location for a new remote branch office?
Minimize risk of physical data theft. - Minimize the impact of the failure of any one file server.
Off-site backup
The web site's private key.
Visibility - Accessibility - Neighborhood crime rate
19. An application log shows that the text 'test; rm -rf /etc/passwd' was entered into an HTML form. Which of the following describes the type of attack that was attempted?
Command injection
Load balancer
TLS
Disable unused ports
20. An administrator identifies a security issue on but does not attempt to exploit it. Which of the following describes what the administrator has done?
Firewall - VPN
Vulnerability scan
Asset value
Cross-site scripting
21. Which of the following ports would a security administrator block if the administrator wanted to stop users from accessing outside SMTP services?
25
IKE
Multi-factor authentication.
SSH
22. Which of the following wireless security controls can be easily and quickly circumvented using only a network sniffer?
AC filtering - Disabled SSID broadcast
ARP poisoning
MS-CHAP
Rogue access points
23. What principle dictates that a user is given no more privilege necessary than that required to preform his/her job?
MAC
Principle of least privilege
Proxies
MAC address
24. A security administrator with full administrative rights on the network is forced to temporarily take time off of their duties. Which of the following describes this form of access control?
80 - 443
IPSec
25
Mandatory vacation
25. In which of the following locations would a forensic analyst look to find a hooked process?
WPA2-PSK
BIOS
Humidity
Dumpster diving - Shoulder surfing
26. An attacker forces a Windows service that uses the Local System account as its service account to crash. The attacker is able to access administrator-level resources as a result. What kind of attack is this?
Use SSH to connect to the Linux shell
Polymorphic
Privilege escalation
Birthday - Full name
27. Which of the following environmental controls would BEST be used to regulate cooling within a datacenter?
The PC has become part of a botnet.
The web site's public key.
Hot and cold aisles
Availability
28. A user is no longer able to transfer files to the FTP server. The security administrator has verified the ports are open on the network firewall. Which of the following should the security administrator check?
Algorithm
Load balancer
Implicit deny
ACLs
29. A user receives an automated call which appears to be from their bank. The automated recording provides details about the bank's privacy policy security policy and requests that the user clearly state their name - birthday and enter the banking detai
Baseline reporting
Software as a Service (SaaS)
Vishing
Separation of duties
30. You want to improve security for remote administration to several Linux web servers on the Internet. The data as well as the authentication process needs to be encrypted. Which of the following should you do?
By masking the IP address of internal computers from the Internet
Asymmetric and Hashing
Use SSH to connect to the Linux shell
Spam filters
31. Your company wants a new web server that can be accessed both by users on your internal network and by users on the Internet. You advice the company to locate the server behind the corporate firewall so it can enjoy similar protection as the internal
Implicit deny
DMZ
Hierarchical list of critical systems
Command injection
32. You are the network admin for a large LAN with a single - firewall-protected - Internet connection. You want to analyze all network traffic in your local network for suspicious activities and receive a notification when a possible attack is in proces
ACLs
Dumpster diving - Shoulder surfing
Install a network-based IDS
Trojans
33. Which of the following would be the BEST action to perform when conducting a corporate vulnerability assessment?
Organize data based on severity and asset value.
SSH
Blind FTP
To minimize the organizational risk posed by users
34. A visitor plugs their laptop into the network and receives a warning about their antivirus being out of-date along with various patches that are missing. The visitor is unable to access the Internet or any network resources. Which of the following is
The security posture is enabled on the network and remediation must take place before access is given to the visitor on that laptop.
Shoulder surfing
The web site's public key.
Multi-factor authentication.
35. Which of the following protocols requires the use of a CA based authentication process?
Baseline reporting
Implicit deny
PEAP-TLS
Cross-site scripting
36. Which of the following would need to be configured correctly to allow remote access to the network?
By masking the IP address of internal computers from the Internet
Data Encryption Standard (DES)
ACLs
SYN attacks
37. What is the term used to describe the type of attack where a DNS server accepts and uses incorrect information from a host that does not have authority to supply that information?
Baseline reporting
DNS spoofing
Hierarchical list of critical systems
Risk transference
38. On-going annual awareness security training should be coupled with:..
signing of a user agreement.
Data Encryption Standard (DES)
Humidity
Man-in-the-middle
39. Used in conjunction which of the following are PII?
Birthday - Full name
Bluesnarfing
Trojans
Network Access Control
40. A security administrator working for a health insurance company needs to protect customer data by installing an HVAC system and a mantrap in the data center. Which of the following are being addressed?
Protocol analyzer
Mandatory vacations
Confidentiality - Availability
IDS
41. Which of the following manages peer authentication and key exchange for an IPSec connection?
To minimize the organizational risk posed by users
Load balancer
Polymorphic
IKE
42. You discover that company confidential information is being encoded into graphics files and sent to a destination outside of the company. This is an example of what kind of cryptography?
Forward to different RDP listening ports.
TLS
WPA2-PSK
Steganography
43. The 802.11i standard specifies support for which encryption algorithms?
Change Management System
Mandatory vacation
AES and TKIP
CCTV
44. With which of the following is RAID MOST concerned?
Availability
A system that stops an attack in progress.
CAC
The security posture is enabled on the network and remediation must take place before access is given to the visitor on that laptop.
45. What is the advantage of using application virtualization?
Power levels
Lets you minimize the attack surface relating to the application
IPSec
VLAN segregation
46. A security administrator needs to implement a site-to-site VPN tunnel between the main office and a remote branch. Which of the following protocols should be used for the tunnel?
MS-CHAP
IPSec
Off-site backup
Privacy policy
47. Which of the following port numbers is used for SCP by default?
Cognitive passwords
22
Least privilege
Block port 23 on the network firewall.
48. Your daily bandwidth monitoring report of your Internet connection shows an excessive amount of outgoing traffic on port 25. You have seen peaks in the reports before but this report shows many peaks outside office times. What should you do?
Check if relaying is denied for unauthorized domains
The new access point was mis-configured and is interfering with another nearby access point.
White box
Cross-site scripting
49. Which of the following attacks is manifested as an embedded HTML image object or JavaScript image tag in an email?
The development team is transferring data to test systems using SFTP and SCP.
To ensure that staff understands what data they are handling and processing
Cross-site scripting
Install a network-based IDS
50. You are determining environmental control requirements for a data center that will contain several computers? What is the role of an HVAC system in this environment?
Provide an appropriate ambient temperature and Maintain appropriate humidity levels
Install a network-based IDS
ACLs
Mandated security configurations have been made to the operating system.