SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
GIAC
Start Test
Study First
Subjects
:
certifications
,
giac
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Isolates systems when they initially connect to the network - allows systems to be scanned and checked prior to being put on a trusted segment
HIDS monitor
NAC
TFTP
The three goals of security
2. It interacts with data and prepares it to be transmitted across the network. It ensures reliable connectivity from end-to-end
Remote maintenance
Plaintext
What range is a class C network?
The transport layer
3. A low end firewall that can quickly be deployed using existing hardware. They examine packets themselves with no content.
Stateful firewall
Some honeypot advantages
Rootkit
Stateless packet filter
4. fast - with little fidelity - examines header information and limited payload data
Risk
No State Inspection ACK flag set
Shallow packet inspection
Some NIDS topology limitations
5. Prepends to the beginning of the file and gains control when the first instruction of the infected COM file is executed - appending to the end - virus writes its payload to the end and inserts jump instruction as the first instruction - which execute
COM/Script program infector
Best way to protect wireless networks
Shallow packet inspection
Kismet
6. Publish separate mail - web - and DNS servers to the internet - provide appropriate access from internal network to internet - protect internal from external attack - provide defense in depth - protect all aspects of the system
Some network design objectives
To close a TCP session
The physical layer stack
The Information Centric defense in depth
7. A system resource that has no legitimate purpose or reason for someone to connect to it - its purpose is to draw in attackers to understand how they break into a system
Brute force
The transport layer
Risk
Honeypot
8. deployment challenges including topology and access limitations - analyzing encrypted traffic - quantity vs. quality of signatures - performance limitations with extensive analysis techniques - very costly for proper management
IDS data normalization
NIDS challenges
Address resolution protocol
Wardriving
9. ATM supports two types of virtual circuits: permanent virtual circuits and switches virtual circuit - PVC is set up in advance - usually manually - SVC is established automatically through a signaling protocol and can be created on the fly - establis
Stateful firewall
Race conditions
Types of ATM virtual circuits
What range is a class A network?
10. Wide Area Network - Larger than MAN or LAN - uses public network - phone lines - and leased lines to tie LAN and MAN over a dispersed area
Stateful firewall
WAN
ATM work
Race conditions
11. Metropolitan area network - spans across city or town - larger than a LAN - uses fiber for backbone
MAN
Honeypot
Logic bomb
Permutation
12. 1.0.0.0 through 127.255.255.255 - subnet mask starts at 255.0.0.0
Hubs
LAN
What range is a class A network?
The TCP/IP model
13. Good for multimedia - can use small single packets - multicasting is required - speed is the highest priority
NAC
The transport layer
Social engineering
Some reasons to use UDP over TCP
14. free windows based wireless scanner for 802.1b - detects access point settings - supports GSP integration - identifies networks as encrypted or unencrypted
Group
Network stumbler
the application layer
What threats should be protected against - based on threat levels
15. Means multiple iterations won't matter. If you encrypt with a key - then re-encrypt - it's the same as using one key.
Types of ATM virtual circuits
Firewall
Rootkit
Group
16. Attaches itself to existing program files and activated when the exe is launched
The protected enclave to defense in depth
Some firewall benefits
What primary threats should be protected against
Program infector
17. Weakness in a system - inherent in a complex system - majority are due to poor coding - gateway by which threats are manifested
Bridge
Vulnerabilities
Anomaly analysis work
Nmap scanning techniques
18. An agreement on how different computer will work - protocols define the format and order of messages and what to do upon receipt of the messages - basically the rules of the network
NIDS advantages
Social engineering
The OSI Protocol Stack
A network protocol
19. risk = threat x vulnerability - impossible to eliminate - security is an exercise in loss reduction
Kismet
Overview of TCP
Risk
Brute force
20. Attacks systems through known vulnerabilities - automatically scans for more systems to attack - lowers system defenses - installs rootkit or root shell - opens up back doors - self contained malware that can copy itself
The three goals of security
Worms
IDS data normalization
War Dialing
21. low interaction production honeypot - network daemon that can simulate other hosts - each host can appear as a different OS
Honeyd
Some common UDP ports
Macro virus
What range is a class A network?
22. FIN 130 - ACK 131 - FIN 570 - ACK 571
What primary threats should be protected against
When talking about protocols and referencing layers - what stack is used
To close a TCP session
Trojan horse
23. Personal area network - phone tethering - bluetooth - etc
Honeypot
Trap door
PAN
Some firewall challenges
24. Trying to ID modems in a telephone exchange that may be susceptible to compromise
What ways should the crypto key be protected?
HIDS monitor
War Dialing
Trap door
25. size is whatever the length of the UDP portion of the packet. Could be as large as 65 -535
Plaintext
Datagram length of a UDP packet
Wardriving
Overview of TCP
26. Physical layer - Data link layer - Network Layer - Transport Layer - Session Layer - Presentation Layer - Application Layer
Ciphertext
The OSI model
DDoS attack
The Uniform Protection to defense in depth
27. Connects the physical part of the network (cables) with the abstract (packets and datastreams)
When talking about protocols and referencing layers - what stack is used
The transport layer
Deep packet inspection
The data link layer
28. Uses flow control to handle network congestion - can send larger amounts of data per packet - has guaranteed delivery of transmitted data - better protection against spoofing - reduces need for error checking at higher OSI layers
Types of viruses
LAN
Some reasons to use TCP over UDP
Router
29. Poor programming without error checking can allow commands to be run in an input field. This can point to a command further in the buffer that will execute the attacker's payload.
The five threat vectors
Asynchronous Transfer Mode
Program infector
Buffer overflow
30. -Malicious code might execute destructive overwrite to hard disks -Malicious mas mailing code might expose sensitive information to the internet - web server compromise might expose organization to ridicule - Web server compromise might expose custom
Types of ATM virtual circuits
Some external threat concerns
HIDS monitor
Some network design objectives
31. Allows admins to remotely access a system for troubleshooting. - E.g VNC - GoToMyPc - PC Anywhere
The OSI model
Remote maintenance
Ciphertext
Some reasons to use UDP over TCP
32. Small program triggered by an event that provides an action. E.g. scheduled file removal if countdown isn't reset - ie: employee was fired
Program infector
Trap door
A network protocol
Logic bomb
33. Malware - insider threat - natural disaster - terrorism - pandemic
Stateless packet filter
What primary threats should be protected against
The goals of cryptography
Some common UDP ports
34. Confidentiality - symmetric encryption
The goals of cryptography
Risk
Boot record infector
Some types of malicious code
35. Relies on executable code insertion and user interaction to spread
Social engineering
IDS data normalization
Parasitic malware
The CIA triad
36. 192.0.0.0 through 223.255.255.255 - subnet mask of 255.255.255.0
Datagram length of a UDP packet
The network layer
Some types of malicious code
What range is a class C network?
37. Uses a 1 to 1 substitution of arbitrary numbers - given a one character mapping - you cannot determine the key
Arbitrary substitution
Nmap scanning techniques
Deep packet inspection
Alteration of code
38. 20 - FTP data - 21 - FTP - 23 - Telnet - 25 - SNMP - 53 - DNS - 79 - Finger - 80 - HTTP - 110 - POP - 443 - HTTPS
The difference in stacks
Some common TCP ports
LAN
Some network design objectives
39. When someone has compromised the integrity of data or a program. Allows attackers to create backdoors.
The five threat vectors
DDoS attack
SYN flood
Alteration of code
40. Worms and Wireless - modems - tunnel anything through HTTP - social engineering
The four basic approaches to defense in depth
The presentation layer
Some ways to bypass firewall protections
Some common UDP ports
41. Uniform protection - protected enclaves - information centric - threat vector analysis
The four basic approaches to defense in depth
the application layer
Some common TCP ports
Group
42. A cracking tool inserted into the OS that allows the attacker to do as they please.
Rootkit
File Integrity checking work
Stateful firewall
Asynchronous Transfer Mode
43. Netmasks or subnets provide a method for identifying what portion of an address is the network - and what portion is the host
What ways should the crypto key be protected?
A netmask
IDS data normalization
Rotation?
44. Full open - half open (stealth scan) - UDP - Ping
Some Pen Test techniques
Nmap scanning techniques
Vulnerabilities
Some common UDP ports
45. The Practice of sending an ACK inside another packet going to the same destination
Ack Piggybacking
Vulnerabilities
Buffer overflow
When talking about protocols and referencing layers - what stack is used
46. 1. physical 2. data 3. network 4. transport 5. session 6. presentation 7. application
Wardriving
The OSI Protocol Stack
A netmask
Checksum in UDP
47. Allows segmentation of a switch into different networks - regardless of where a system is plugged in - creates separate networks through software not hardware
48. Very simplistic. All systems are attached to the same cable segment. Rarely used because they're unreliable - low fault tolerance - poor traffic isolation - with limited scalability
File integrity checking work
Asynchronous Transfer Mode
Bus Topology
Some common UDP ports
49. Spread as an office attachment with executable code programmed using macro facility - targets are data files - visual basic editor and other macro languages - payload executes when the code is launched
LAN
Router
Buffer overflow
Macro virus
50. An attempt to gain access by bombarding it with guesses until the password is found.
Integrity of Data
Snort
Brute force
TFTP