SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
Comptia Security +: Vocab
Start Test
Study First
Subjects
:
certifications
,
comptia-security-+
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. An imaginary boundary between the components that make up the TCB and the components that are not covered by the TCB
Illegal/Unethical
Skipjack
Fences
Security Perimeter
2. A spoofing attack - a kind of attack in data communication - in which a third party tries to mislead the communication participants using forged information.
Common criteria
Masquerade
Hacker
Format 7 times
3. In a separation of duties model - this is where code is checked in and out
Firmware
Software development lifecycle
Software librarian
Risk Management
4. Communications that don't take the natural course of email (when you don't want eavesdropping to happen)
Noise & perturbation
MOM
Out of band
Private Addressing
5. An audit trail is a chronological sequence of audit records - each of which contains evidence directly pertaining to and resulting from the execution of a business process or system function. Audit records typically result from activities such as tra
Audit Trail
Aggregation
DMZ
Finger scanning
6. Business Impact Analysis. A BIA is a functional analysis in which a team collects data through interviews and documentary sources. It documents business functions - activities - and transactions.
Tailgating / Piggybacking
Multiprocessing
BIA
Boot-sector Virus
7. Rotating employee's job duties so that things can be checked that they are doing to make sure nothing fraudulent is occurring.
Mandatory vacation
Job rotation
Passive attacks
Firmware
8. Residual physical representation of data that has been in some way erased. After storage media is erased there may be some physical characteristics that allow data to be reconstructed.
Data remanence
BIA
Bastion hosts
Cold Site
9. Computer Incident Response Team
FAR/FRR/CER
Dictionary Attack
Eavesdropping
CIRT
10. Also known as Rijndael - is a block cipher adopted as an encryption standard by the US government. It is expected to be used worldwide and analyzed extensively - as was the case with its predecessor - the Data Encryption Standard (DES). AES was adopt
Cryptanalysis
Authorization creep
WAP (Wireless Application Protocol)
AES (Advanced Encryption Standard)
11. A form of redundancy check (a very simple measure for protecting the integrity of data by detecting errors in data that is sent through space or time.
Dumpster diving
Virtual Memory/Pagefile.sys
Hot Site
Checksum
12. A name given to a system implemented by the FBI that is analogous to wiretapping except in this case - e-mail and other communications are being tapped instead of telephone conversations. Carnivore was essentially a customizable packet sniffer that c
SSO (Single sign-on)
BIOS
Carnivore
Expert systems
13. A specialized form of software authentication that enables a user to authenticate once and gain access to the resources of multiple software systems.
Security Perimeter
Software
ROT-13
SSO (Single sign-on)
14. A formula - practice - process - design - instrument - pattern - or compilation of information used by a business to obtain an advantage over competitors within the same industry or profession.
ARO (Annualized Rate of Occurrence)
Trade Secret
Incentive programs
Brewer-Nash model
15. Issued by the United States National Computer Security Center (NCSC - an arm of the NSA) as 'Trusted Computer System Evaluation Criteria' - a DOD standard 5200.23-STD in December 1985 superseding CSC-STD-001-83 - the TCSEC (frequently referred to as
TCSEC
DCOM
Coax
Eavesdropping
16. This factor represents a measure of the magnitude of loss or impact on the value of an asset.
DNS cache poisoning
Bastion hosts
Fences
EF (Exposure Factor)
17. In computer networking - this is the method for finding a host's hardware address when only its IP address is known. Due to the overwhelming prevalence of IPv4 and ethernet - ARP is primarily used to translate ethernet MAC addresses from IP addresses
CHAP
Base-64
ARP (Address Resolution Protocol)
Classes of IP networks
18. When security is managed at many different points in an organization
Inference
Virtual Memory/Pagefile.sys
Acceptable use
Decentralized
19. Network devices that operate at layer 3. This device separates broadcast domains.
Routers
VPN (Virtual Private Network)
Scanning
Inference
20. A mechanism by which connections to TCP services on a system are allowed or disallowed
Probing
Routers
TCP Wrappers
/etc/passwd
21. The process of training end users / employees in the ways and processes of security. This helps to mitigate risk to the company (if the employees know what to do) and also helps the employees to know what is expected of them security-wise - so that t
Bastion hosts
Buffer overflow
Security Awareness Training
Hubs
22. They all deal with objects or identifiers that are used during authentication. They provide information that will allow the authentication to happen. There are many types.
Tokens
Active attacks
Cyphertext only
Trojan horses
23. A hash function (or hash algorithm) is a way of creating a small digital 'fingerprint' from any kind of data. The function chops and mixes the data to create the fingerprint - often called a hash value. The hash value is commonly represented as a sho
Social engineering
Fire extinguisher
Hash
Hacker
24. A site that is ready and available within minutes or hours to continue processing. This is a site that is fully configured and ready to go.
Non-repudiation
Script
Entrapment
Hot Site
25. A distinctive sign of some kind which is used by a business to uniquely identify itself and its products and services to consumers - and to distinguish the business and its products and / or services from those of other businesses.
Trademark
Authorization
VPN (Virtual Private Network)
Senior Management
26. A hidden communications channel on a system that allows for the bypassing of the system security policy
Covert channels
Noise & perturbation
Sniffing
Authentication
27. Threat to physical security.
Hoax
Expert System
Trojan horses
Sabotage
28. An attacker spoofs the source IP in a packet header - to make a ping request appear to have originated from the future victim's network - then the responding network responds in full force to these requests and brings down the victim's network.
CD-Rom
Diffie-Hellman
Smurf
UUEncode
29. Network device that operates at layer 1. Concentrator.
Digital signing
Hubs
Brute Force
Cold Site
30. Countermeasure to put fake stuff into a database so if someone is reading it they will get the wrong info.
Patriot Act
PKI
Packet Sniffing
Noise & perturbation
31. Must be in place for you to use a biometric system
Hoax
Biometric profile
NAT
Spoofing
32. The amount of users that the system can process in a given amount of time. A typical acceptable amount is 10/minute
Certification
Throughput of a Biometric System
COOP
Phreaker
33. (OLE) is a distributed object system and protocol developed by Microsoft. OLE allows an editor to 'farm out' part of a document to another editor and then reimport it. Its primary use is for managing compound documents - but it is also used for trans
Rijndael
ActiveX Object Linking and Embedding
Twisted pair
Job rotation
34. This is the file on a UNIX system where usernames to password MD5 hash outputs are stored. The system uses this file to determine if the password entered for a given username is correct.
Senior Management
/etc/passwd
Script
Security Perimeter
35. In risk assessment - the average monetary value of losses per year. SLE x ARO = ALE
Passive attacks
Promiscuous mode
ALE (Annualized Loss Expectancy)
Illegal/Unethical
36. Also civil law
Tort
DNS cache poisoning
Keystroke logging
COOP
37. When a DNS server goes out to resolve a name - and gets the wrong response back - it caches the wrong address for the default DNS time period - thus poisoning the cache for that period of time
Authorization
DNS cache poisoning
Packet Sniffing
CEO
38. Personal - Network - and Application
Cookies
Firewall types
Phreaker
User
39. Internet Relay Chat.
Transposition
IRC
Fiber optic
Digest
40. The real cost of acquiring/maintaining/developing a system
Trade Secret
Trap Door
BIA
Asset Value
41. Animals with teeth. Not as discriminate as guards
Keystroke logging
Detective - Preventive - Corrective
Dogs
Hacker
42. In cryptography - it is a block cipher
Telnet
Risk Analysis
Certification
Skipjack
43. Software designed to infiltrate or damage a computer system - without the owner's consent.
Halon
War driving
Malware
TACACS (Terminal access controller access control system)
44. When you know something from a source - and can infer other related information based off of what you know - when you may not necessarily have access to that data normally.
TCSEC
/etc/passwd
CGI (The Common Gateway Interface)
Inference
45. If an employee is suspected of wrongdoing - sending them away from work for a while so that their actions can be audited.
Mandatory vacation
Decentralized
Risk Mitigation
Finger printing
46. Emanations from one wire coupling with another wire
TCSEC
Multipartite
Crosstalk
Brute Force
47. When you have a certain amount of access and you change jobs and you keep that access from the previous position. Also known as enlargement of permission and privilege escalation.
DCOM
Hot Site
Brewer-Nash model
Authorization creep
48. In cryptography - it is one of the simplest and most widely-known encryption techniques. It is a type of substitution cipher in which each letter in the plaintext is replaced by a letter some fixed number of positions further down the alphabet.
NAT
Schema
DDOS
Caesar Cipher
49. An attack that is similar to smurf but instead of using ICMP (ping) it uses UDP as its weapon of choice. It broadcasts a spoofed UDP packet to the amplifying network.
Trademark
Fraggle
Promiscuous mode
Dogs
50. Entails planning and system actions to ensure that a project is following good quality management practices
Owner
Centralized
Hardware
Quality Assurance