SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
Comptia Security + Exam
Start Test
Study First
Subjects
:
certifications
,
comptia-security-+
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Which of the following devices is used to optimize and distribute data workloads across multiple computers or networks?
Algorithm
Load balancer
IPv6
Mandated security configurations have been made to the operating system.
2. Based on logs from file servers remote access systems - and IDS - a malicious insider was stealing data using a personal laptop while connected by VPN. The affected company wants access to the laptop to determine loss - but the insider's lawyer insis
MAC address
Account disablement
System A fails open. System B fails closed.
Off-site backup
3. Which of the following identifies some of the running services on a system?
escalation of privileges.
Add input validation to forms.
Apply a security control which ties specific ports to end-device MAC addresses and prevents additional devices from being connected to the network.
Determine open ports
4. A technician needs to limit the wireless signal from reaching outside of a building. Which of the following actions should the technician take?
Forward to different RDP listening ports.
Botnet
Disable unused services - Update HIPS signatures
Decrease the power levels on the WAP
5. A security administrator finished taking a forensic image of a computer's memory. Which of the following should the administrator do to ensure image integrity?
Deny all
Smurf attack
Logic Bomb
Run the image through SHA256. Answer: D
6. You need to advise a new wiring system for a company with several locations partly open to the public. A primary requirement is to make tapping into the network as difficult as possible. Which of the following cable types should you advice?
Buffer overflow
Fiber optic
Cross-site scripting
Cross-site scripting
7. In which of the following locations would a forensic analyst look to find a hooked process?
System A fails open. System B fails closed.
Having the offsite location of tapes also be the hot siteservers
Symmetric
BIOS
8. Which solution should you use?
se file servers attached to an NAS system.
The development team is transferring data to test systems using SFTP and SCP.
Blind FTP
Logic Bomb
9. A security administrator wants to know which systems are more susceptible to an attack compared to other systems on the network. Which of the following assessment tools would be MOST effective?
Rogue access points
Vulnerability scanner
Principle of least privilege
Security guard - Proximity reader
10. Which of the following access control models allows classification and labeling of objects?
MAC
Content filtering
Tailgating
ACLs
11. Logs from an IDS show that a computer has been compromised with a botnet and is actively communicating with a command and control which of the following data types will be unavailable for later investigation?
Algorithm
Provide an appropriate ambient temperature and Maintain appropriate humidity levels
Memory - network processes - and system processesserver. If the computer is powered off
Hardware RAID 5 - Software RAID 1
12. The 802.11i standard specifies support for which encryption algorithms?
SNMP (also use to monitor the parameters of network devices)
Vulnerability scanner
AES and TKIP
Power levels
13. Which of the following MUST a programmer implement to prevent cross-site scripting?
Clustering
Validate input to remove hypertext
signing of a user agreement.
Platform as a Service
14. Which of the following protocols should be blocked at the network perimeter to prevent host enumeration by sweep devices?
SSL
Cognitive passwords
ICMP
VLAN
15. A visitor plugs their laptop into the network and receives a warning about their antivirus being out of-date along with various patches that are missing. The visitor is unable to access the Internet or any network resources. Which of the following is
Footprinting
Security guard - Proximity reader
WPA Enterprise
The security posture is enabled on the network and remediation must take place before access is given to the visitor on that laptop.
16. Which of the following can prevent an unauthorized employee from entering a data center?
Tailgating
Risk transference
Security guard - Proximity reader
Separation of duties
17. Which of the following is a best practice when securing a switch from physical access?
Disable unused ports
22
Information disclosure
Network Access Control
18. Which of the following ports would a security administrator block if the administrator wanted to stop users from accessing outside SMTP services?
White box
Algorithm
Footprinting
25
19. Which of the following uses TCP port 22 by default?
22
SSH - SCP - and SFTP (the MOST secure method to transfer files from a host machine)
The web site's private key.
Disable unused ports
20. A web application has been found to be vulnerable to a SQL injection attack. Which of the following BEST describes the required remediation action?
Steganography
Add input validation to forms.
Trojans
IPSec
21. The detection of a NOOP sled is an indication of which of the following attacks?
Botnet
Multi-factor authentication.
ICMP
Buffer overflow
22. Which of the following will provide the HIGHEST level of wireless network security?
SSH
Accountability
quantitative risk assessment
WPA2
23. In an 802.11n network which of the following provides the MOST secure method of both encryption and authorization?
Add input validation to forms.
mitigation - acceptance - transference
signing of a user agreement.
WPA Enterprise
24. You installed a new e-commerce application on your web server that will allow your company to take orders from their website. You want to ensure that information that customers enter into their web browser is sent securely to the web server. Which of
DAC
Mandatory vacation
SSL
SYN attacks
25. When examining HTTP server logs the security administrator notices that the company's online store crashes after a particular search string is executed by a single external user. Which of the following BEST describes this type of attack?
IPSec
Load balancer
User rights and permissions reviews
DoS
26. Which of the following includes a photo and can be used for identification?
Configure the IE popup blockers
CAC
Availability
Dumpster diving
27. Which of the following encryption algorithms can be used in PGP for data encryption?
Fraud
IDEA and TripleDes
Separation of duties
Shoulder surfing
28. Which of the following is an example of allowing another user physical access to a secured area without validation of their credentials?
Multi-factor authentication.
Validate input to remove hypertext
Tailgating
Provider cloud
29. Which of the following concepts ensures that the data is only viewable to authorized users?
Confidentiality
Protocol analyzer
Location that meets power and connectivity requirementsdatacenter
Command injection
30. Which of the following logical controls does a flood guard protect against?
Shoulder surfing
SYN attacks
Symmetric
Black hat
31. A security administrator working for a health insurance company needs to protect customer data by installing an HVAC system and a mantrap in the data center. Which of the following are being addressed?
DMZ
Confidentiality - Availability
Steganography
CCTV
32. Which of the following should be performed on a computer to protect the operating system from malicious software?
Disable unused services - Update HIPS signatures
Lets you minimize the attack surface relating to the application
A system that stops an attack in progress.
Mantrap
33. Which of the following are important physical security considerations when choosing a location for a new remote branch office?
System A fails open. System B fails closed.
Having the offsite location of tapes also be the hot siteservers
WPA Enterprise
Visibility - Accessibility - Neighborhood crime rate
34. Which of the following malicious code will do its objectionable deed after a predetermined action takes place or at a specific time?
User rights
TLS
User rights and permissions reviews
Logic Bomb
35. Isolation mode on an AP provides which of the following functionality types?
Segmentation of each wireless user from other wireless users
Bluesnarfing
Power levels
Use SSH to connect to the Linux shell
36. Which of the following would allow traffic to be redirected through a malicious machine by sending false hardware address updates to a switch?
escalation of privileges.
Block port 23 on the network firewall.
Protocol analyzer
ARP poisoning
37. Two systems are being designed. System A has a high availability requirement. System B has a high security requirement with less emphasis on system uptime. Which of the following configurations BEST fits the need for each system?
Firewall rulesflow of network traffic at the edge of the network
White box
Software as a Service
System A fails open. System B fails closed.
38. Which of the following web application security weaknesses can be mitigated by preventing the use of HTML tags?
The web site's private key.
The new access point was mis-configured and is interfering with another nearby access point.
Cross-site scripting
Fraud
39. Which of the following should be reviewed periodically to ensure a server maintains the correct security configuration?
Configure the IE popup blockers
Virtual servers have the same information security requirements as physical servers.
User rights
Shoulder surfing
40. Which of the following is a reason to perform user awareness and training?
Baseline reporting
Minimize risk of physical data theft. - Minimize the impact of the failure of any one file server.
To minimize the organizational risk posed by users
Evil twin
41. You want to setup a secure method of sending and receiving email. Which two of the following protocols can be used for this purpose?
Bluesnarfing
MAC filtering
S/MIME PGP
User rights and permissions reviews
42. Upon investigation an administrator finds a suspicious system-level kernel module which modifies file system operations. This is an example of which of the following?
53
Rootkit
Before and after the imaging process and then hash the forensic image
MAC address
43. Which of the following may cause a user connected to a NAC-enabled network - to not be prompted for credentials?
44. Which environmental control is part of TEMPEST compliance?
Buffer overflow
Privilege escalation
Shielding
Logic Bomb
45. An existing application has never been assessed from a security perspective. Which of the following is the BEST assessment technique in order to identify the application's security posture?
Baseline reporting
Proxies
Memory - network processes - and system processesserver. If the computer is powered off
The development team is transferring data to test systems using SFTP and SCP.
46. What is the name of the process during which an attacker gathers information about a target company's intranet - remote access - extranet - and Internet connections?
Mandated security configurations have been made to the operating system.
MAC filtering
Smurf attack
Footprinting
47. Users of specific systems are reporting that their data has been corrupted. After a recent patch update to those systems the users are still reporting issues of data being corrupt. Which of the following assessment techniques need to be performed to
Tailgating
Logic Bomb
Vulnerability scan
DES
48. Which of the following will educate employees about malicious attempts from an attacker to obtain bank account information?
Phishing techniques
Clustering
MAC
Vulnerability scanning
49. User in your department complain about a slow Internet connection. You monitor the external interface of your company's border router and notice a huge mount of half-open TCP connections. What type of attack is your company currently a victim of?
HSM
Principle of least privilege
Buffer overflow
TCP SYN flood attack
50. The server log shows 25 SSH login sessions it is a large company and the administrator does not know if this is normal behavior or if the network is under attack. Where should the administrator look to determine if this is normal behavior?
Configure the IE popup blockers
Baseline reporting
Provide an appropriate ambient temperature and Maintain appropriate humidity levels
Loop protection