Test your basic knowledge |

Comptia Security + Exam

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. What principle requires that for a particular set of transactions - no one individual is solely responsible or allowed to execute the complete set?






2. An administrator is updating firmware on routers throughout the company. Where should the administrator document this work?






3. You need to advise a new wiring system for a company with several locations partly open to the public. A primary requirement is to make tapping into the network as difficult as possible. Which of the following cable types should you advice?






4. A visitor plugs their laptop into the network and receives a warning about their antivirus being out of-date along with various patches that are missing. The visitor is unable to access the Internet or any network resources. Which of the following is






5. Which of the following manages peer authentication and key exchange for an IPSec connection?






6. A security administrator is tasked with ensuring that all servers are highly available and that hard drive failure will not affect an individual server. Which of the following configurations will allow for high availability?






7. A user receives an automated call which appears to be from their bank. The automated recording provides details about the bank's privacy policy security policy and requests that the user clearly state their name - birthday and enter the banking detai






8. What principle dictates that a user is given no more privilege necessary than that required to preform his/her job?






9. Instead of giving a security administrator full the administrator is given rights only to review logs and update security related network devices. Additional rights are handed out to network administrators for the areas that fall within their job des






10. What asymmetric key is used to encrypt when using HTTPS?


11. Which of the following will educate employees about malicious attempts from an attacker to obtain bank account information?






12. Which of the following is a best practice when securing a switch from physical access?






13. Which of the following is the BEST way to secure data for the purpose of retention?






14. A helpdesk engineer just received a phone call from an administrator at a remote branch office. The administrator claimed to have forgotten the password for the root account of the UNIX servers. Although the helpdesk engineer didn't know of any admin






15. Your company wants a new web server that can be accessed both by users on your internal network and by users on the Internet. You advice the company to locate the server behind the corporate firewall so it can enjoy similar protection as the internal






16. Which of the following can prevent an unauthorized employee from entering a data center?






17. A company needs to be able to prevent entry at all times - to a highly sensitive area inside a public building. In order to ensure the BEST type of physical security - which of the following should be implemented?






18. Which of the following protocols should be blocked at the network perimeter to prevent host enumeration by sweep devices?






19. What asymmetric key is used to decrypt when using HTTPS?


20. When examining HTTP server logs the security administrator notices that the company's online store crashes after a particular search string is executed by a single external user. Which of the following BEST describes this type of attack?






21. A security administrator working for a health insurance company needs to protect customer data by installing an HVAC system and a mantrap in the data center. Which of the following are being addressed?






22. A security administrator finished taking a forensic image of a computer's memory. Which of the following should the administrator do to ensure image integrity?






23. Which of the following facilitates computing for heavily utilized systems and networks?






24. Actively monitoring data streams in search of malicious code or behavior is an example of..






25. Which of the following would allow traffic to be redirected through a malicious machine by sending false hardware address updates to a switch?






26. While browsing the Internet an administrator notices their browser behaves erratically - appears to download something - and then crashes. Upon restarting the PC - the administrator notices performance is extremely slow and there are hundreds of outb






27. Which of the following is BEST used to prevent ARP poisoning attacks across a network?






28. In which of the following locations would a forensic analyst look to find a hooked process?






29. Which of the following is used for exchanging secret keys over an insecure public network?






30. You are designing a Web-based application. You design the application so that it runs under a security context that allows only those privileges required for the application to run to minimize risk in the event of an attack. This is an example of whi






31. The security administrator implemented privacy password protected screen savers - and hired a secure shredding and disposal service. Which of the following attacks is the security administrator trying to mitigate?






32. A targeted email attack sent to the company's Chief Executive Officer (CEO) is known as which of the following?






33. Data can potentially be stolen from a disk screen-lock protected - smartphone by which of the following?






34. You are performing risk assessment for an organization. What should you do during impact assessment?






35. Which of the following wireless security controls can be easily and quickly circumvented using only a network sniffer?






36. A set of instructions normally implemented on a computer system as a procedure to manipulate data is called a(n)?






37. Two systems are being designed. System A has a high availability requirement. System B has a high security requirement with less emphasis on system uptime. Which of the following configurations BEST fits the need for each system?






38. A security administrator needs to implement a site-to-site VPN tunnel between the main office and a remote branch. Which of the following protocols should be used for the tunnel?






39. What is the name of the process during which an attacker gathers information about a target company's intranet - remote access - extranet - and Internet connections?






40. Which of the following is the MOST likely cause of a single computer communicating with an unknown IRC server and scanning other systems on the network?






41. A programmer allocates 16 bytes for a string but does not adequately ensure that more than 16 bytes cannot be copied into the variable. This program may be vulnerable to which of the following attacks?






42. Which of the following is the MAIN reason to require data labeling?






43. Which of the following should be enabled to ensure only certain wireless clients can access the network?






44. Which of the following is the BEST choice for encryption on a wireless network?






45. Which of the following is MOST likely to be the last rule contained on any firewall?






46. In order to ensure high availability of all critical backups of the main data center are done in the middle of the night and then the backup tapes are taken to an offsite location. Which of the following would ensure the minimal amount of downtime in






47. Which of the following BEST explains the security benefit of a standardized server image?






48. Logs from an IDS show that a computer has been compromised with a botnet and is actively communicating with a command and control which of the following data types will be unavailable for later investigation?






49. Which of the following attacks is manifested as an embedded HTML image object or JavaScript image tag in an email?






50. With which of the following is RAID MOST concerned?