SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
Comptia Security +: Vocab
Start Test
Study First
Subjects
:
certifications
,
comptia-security-+
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Good for distance - longer than 100M
Coax
Embezzlement
Owner
War dialing
2. Virtual LANs. Separating broadcast domains on a single network. A way of partitioning communications channels.
Brewer-Nash model
VLANs
Trade Secret
Switches / Bridges
3. In cryptography - encryption is the process of obscuring information to make it unreadable without special knowledge.
Warm Site
Patriot Act
Encryption
Replay
4. In computing - the Challenge-Handshake Authentication Protocol authenticates a user to an Internet access provider. CHAP provides protection against playback attack by the peer through the use of an incrementally changing identifier and of a variable
CHAP
Hacker
Social engineering
Brute Force
5. The output of a hash function is a digest.
Open network
Digest
Common criteria
Finger scanning
6. Business Impact Analysis. A BIA is a functional analysis in which a team collects data through interviews and documentary sources. It documents business functions - activities - and transactions.
Software
Fire extinguisher
BIA
Artificial Neural Networks (ANN)
7. Accepting all packets
Fire extinguisher
Callback Security/Call Forwarding
Firewall types
Promiscuous mode
8. This deals with differences between plaintext password storage and transmission - versus encrypted password storage and transmission.
Security Perimeter
Risk Analysis
CRC (Cyclic Redundancy Check)
Cyphertext only
9. In computer terminology - a honeypot is a trap set to detect - deflect or in some manner counteract attempts at unauthorized use of information systems. Generally it consists of a computer - data or a network site that appears to be part of a network
Honey pot
Debug
Enticement
Detective - Preventive - Corrective
10. Software designed to infiltrate or damage a computer system - without the owner's consent.
BIOS
Malware
Trap Door
CORBA
11. 'If you cant see it - its secure'. Bad policy to live by.
Packet Sniffing
Security through obscurity
Copyright
CORBA
12. Jumping into dumpsters to retrieve information about someone/something/a company
Masquerade
IRC
Expert System
Dumpster diving
13. The most popular computer language used to create - modify - retrieve and manipulate data from relational database management systems. The language has evolved beyond its original purpose to support object-relational database management systems. It i
Acceptable use
Clipper Chip
Decentralized
SQL (Structured Query Language)
14. ('rotate by 13 places' - sometimes hyphenated ROT-13) Is a simple Caesar cipher used for obscuring text by replacing each letter with the letter thirteen places down the alphabet
ROT-13
Decentralized
Phreaker
Keystroke logging
15. In cryptography - a substitution cipher is a method of encryption by which units of plaintext are substituted with ciphertext according to a regular system; the 'units' may be single letters (the most common) - pairs of letters - triplets of letters
Dogs
Motion detector
Schema
Substitution
16. Same as a block cipher except that it is applied to a data stream one bit at a time
RADIUS (Remote authentication dial-in user service)
Well-known ports
DHCP
Stream cipher
17. Among the most common types of viruses and the least damaging - these are hidden within applications that must be executed in order to execute the virus.
Macro
Job rotation
Risk Acceptance
War driving
18. The user
/etc/passwd
User
Code of ethics
Worm
19. Grabs an image of the finger which is then stored in a database and then works in a one-to-many database
Finger printing
Owner
Tailgating / Piggybacking
ActiveX Object Linking and Embedding
20. Internet Architecture Board. This board is responsible for protecting the Internet.
IAB
TCB
Asymmetric
Username/password
21. Continuation of Operations Plan
Passive attacks
Change management
COOP
Cold Site
22. An attempt to trick the system into believing that something false is real
Software development lifecycle
SESAME
Hoax
Buffer overflow
23. Network devices that operate at layer 2. Every port on a switch is a separate collision domain
Quality Assurance
Cold Site
Technical - Administrative - Physical
Switches / Bridges
24. The EU spec. If databases exist - users are allowed to check data into them - allowed to change them if wrong - etc.
Privacy Act of 1974
IAB
Multithreading
TCP Wrappers
25. Disclosure - Alteration - Destruction. These things break the CIA triad
CIA
PKI
Bugtraq
DAD
26. Methodical process of finding and reducing the number of bugs - or defects - in a computer program or a piece of electronic hardware thus making it behave as expected
TACACS (Terminal access controller access control system)
Common criteria
Debug
Transposition
27. If an employee is suspected of wrongdoing - sending them away from work for a while so that their actions can be audited.
Mandatory vacation
Identification
Motion detector
Username/password
28. An audit trail is a chronological sequence of audit records - each of which contains evidence directly pertaining to and resulting from the execution of a business process or system function. Audit records typically result from activities such as tra
Stream cipher
CORBA
Audit Trail
Degausser
29. Network Address Translation
SSO (Single sign-on)
NAT
Hot Site
Risk Acceptance
30. Also civil law
Cookies
Exit interview
Tort
Kerberos
31. A simple authentication protocol used to authenticate a user to a remote access server or Internet service provider (ISP). Almost all NOS remote servers support PAP. PAP transmits unencrypted ASCII passwords over the network and is therefore consider
Security kernel
PAP (Password Authentication Protocol)
Bugtraq
ARP (Address Resolution Protocol)
32. The process of certifying a system that has been built to ensure that it meets the security standards that you have said you will use.
Certification
Scanning
Authentication
CGI (The Common Gateway Interface)
33. Involving the measurement of quantity or amount.
Quantitative
Accountability
Penetration testing
Granularity
34. Ethernet - Cat5 - Twisted to allow for longer runs.
Termination procedures
Twisted pair
Bastion hosts
TCP Wrappers
35. When a DNS server goes out to resolve a name - and gets the wrong response back - it caches the wrong address for the default DNS time period - thus poisoning the cache for that period of time
Authentication
Scanning
Repeaters
DNS cache poisoning
36. Deals with the same things as due diligence except that they deal with accepting responsibility instead of liability.
Due Care
SSO (Single sign-on)
DNS cache poisoning
CEO
37. Trusted Computing Base. Comprised of the hardware - software - and firmware of the system.
DDOS
TCB
Fiber optic
Authorization creep
38. In cryptanalysis and computer security - this attack is a technique for defeating a cipher or authentication mechanism by trying to determine its decryption key or passphrase by searching a large number of possibilities. In contrast with a brute forc
CRC (Cyclic Redundancy Check)
Sniffing
Dictionary Attack
SSH
39. An instance of a scripting language
Content dependant
Hash
ROM (Read-only memory)
Script
40. Also known as Rijndael - is a block cipher adopted as an encryption standard by the US government. It is expected to be used worldwide and analyzed extensively - as was the case with its predecessor - the Data Encryption Standard (DES). AES was adopt
CGI (The Common Gateway Interface)
AES (Advanced Encryption Standard)
Firmware
DMZ
41. Someone whose hacking is primarily targeted at the phone systems
Cryptanalysis
Private Addressing
Phreaker
SSO (Single sign-on)
42. A legal term used to describe an out-of-court statement offered to establish the truth of the facts asserted in that statement. Hearsay is generally not admissible in common law courts because it is of dubious value - but there are many exceptions to
Hearsay Evidence
Due Care
Smart cards
AES (Advanced Encryption Standard)
43. The process of developing a planned approach to change in an organization. Typically the objective is to maximize the collective benefits for all people involved in the change and minimize the risk of failure of implementing the change.
Change management
Honey pot
Due Care
Aggregation
44. Non-repudiation is the concept of ensuring that a contract - especially one agreed to via the Internet - cannot later be denied by one of the parties involved.
Keystroke logging
Call tree
Due Diligence
Non-repudiation
45. Random Number Base
SSH
Carnivore
Nonce
Copyright
46. Scanning the airwaves for radio transmissions
Software librarian
SQL (Structured Query Language)
Polymorphism
Scanning
47. Attack which does not result in an unauthorized state change - such as an attack that only monitors and/or records data.
Passive attacks
Dogs
BIA
l0pht
48. An attacker spoofs the source IP in a packet header - to make a ping request appear to have originated from the future victim's network - then the responding network responds in full force to these requests and brings down the victim's network.
Smurf
OSI Model
Format 7 times
Dictionary Attack
49. The practice of following someone with a security code or keycard through a security door - generally in workplaces.
Tailgating / Piggybacking
Copyright
Keystroke logging
Hubs
50. In a distributed attack - the attacking computer hosts are often zombie computers with broadband connections to the Internet that have been compromised by viruses or Trojan horse programs that allow the perpetrator to remotely control the machine and
Birthday attack
Fraud
DDOS
Detective - Preventive - Corrective