MTA Security: 98-367 Flashcards
Which of the following is a process in which data is changed before or while it is entered into a computer system? A. Data diddling B. Authentication C. Domain kiting D. Packet sniffing
Correct Answer: A
Which of the following contains a tree of domain names? A. Domain name space B. Domain name formulation C. Domain Name System D. Authoritative name server
Correct Answer: A
Mark works as a Systems Administrator for TechMart Incl. The company has Windows-based network.
Mark has been assigned a project to track who tries to log into the system and the time of the day at which
the attempts occur. He is also required to create a system to track when confidential files are opened and
who is trying to open it. Now, Mark logs when someone is not able to make a successful attempt to log into
the system as Administrator but he also wants to log when the user is successful to log into the system as
Administrator. Which of the following is the reason of logging by Mark when a user is successfully logged
into the system as well as when he is failed?
A. To determine if and when someone is authenticating successfully with high privilege.
B. To make sure that user is not using the Administrator account.
C. To determine if and when someone is authenticating successfully with high privilege.
D. To make sure that user is not facing any problem.
Correct Answer: C
Mark works as a Systems Administrator for TechMart Inc. The company has a Windows-based network.
The company is adding an open, high-speed, wireless access for their customers and secured wireless for
employees at all 37 branches. He wants to check the various security concerns for ensuring that business
traffic is secured. He is also in under pressure to make this new feature a winning strategy for a company.
Mark wants the employees to be free to troubleshoot their own wireless connections before contacting him.
Which of the following is the basic troubleshooting step that he can ask them to do?
A. To power cycle the wireless access points and then reboot the systems.
B. To configure the network to use only Extensible Authentication Protocol (EAP).
C. To reboot the computers they are using and then use the MAC filtering.
D. To right-click the network icon in the system tray and then select Troubleshoot Problems.
Correct Answer: D
Which of the following protects against unauthorized access to confidential information via encryption and works at the network layer? A. Firewall B. NAT C. IPSec D. MAC address
Correct Answer: C
You want to standardize security throughout your network. You primarily use Microsoft operating systems
for servers and workstations. What is the best way to have standardized security (i.e. same password policies, lockout policies, etc.) throughout the network on clients and servers?
A. Publish the desired policies to all employees directing them to implement according to policy.
B. Configure each computer to adhere to the standard policies.
C. When installing new workstations or servers, image a machine that has proper security settings and install
the new machine with that image.
D. Utilize Windows Security Templates for all computers.
Correct Answer: D
Mark works as a Network Administrator fot Blue Well Inc. The company has a Windows-based network.
Mark is facing a series of problems with email spam and identifying theft via phishing scams. He wants to
implement the various security measures and to provide some education because it is related to the best
practices while using email. Which of the following will Mark ask to employees of his company to do when
they receive an email from a company they know with a request to click the link to “verify their account
information”?
A. Provide the required information
B. Hide the email
C. Use Read-only Domain Controller
D. Delete the email
Correct Answer: D
Which of the following infects the computer and then hides itself from detection by antivirus software? A. EICAR virus B. Boot-sector virus C. Macro virus D. Stealth virus
Correct Answer: D
Which of the following states that a user should never be given more privileges than are required to carry out a task? A. Security through obscurity B. Segregation of duties C. Principle of least privilege D. Role-based security
Correct Answer: C
Which of the following are the major components of the IPsec protocol? Each correct answer represents
a complete solution. Choose all that apply.
A. Encapsulating Security Payload (ESP)
B. Authentication Header (AH)
C. Internet Encryption Key (IEK)
D. Internet Key Exchange (IKE)
Correct Answer: ABD
Which of following is required to be configured to ensure that the Bitlocker storage can be reclaimed?
A. BitLocker to use data recovery agents
B. BitLocker to use the password screen saver
C. BitLocker to use the Secret Retrieval Agent
D. BitLocker to use the Artificial Intelligence recovery option.
Correct Answer: A
The stronger password is a critical element in the security plan. Which of the following are the characteristics
used to make up a strong password?
A. It contains more than seven hundred characters and does not contain the user name, real name, or any
name that can be guessed by the attacker easily.
B. It contains more than seven characters and does not contain the user name, real name, or anyname that
can be guessed by the attacker easily.
C. It contains the user name, real name, or any name that can be remembered easily and does not contain
more than seven characters.
D. It contains more than seven characters and the user name, real name, or any name.
Correct Answer: B
Which of the following can be installed and configured to prevent suspicious emails from entering the
user’s network?
A. Kerberos
B. Single sign-on (SSO)
C. TCP/IP protocol
D. Microsoft Forefront and Threat Management Gateway
Correct Answer: D
Which of the following are types of password policies of Windows 7? Each correct answer represents a
complete solution. Choose all that apply.
A. Store Password Using Reversible Encryption
B. Minimum Password Length
C. User Name Length
D. Password Must Meet Complexity Requirements
Correct Answer: ABD
Which of the following is a technique used to attack an Ethernet wired or wireless network? A. ARP poisoning B. DNS poisoning C. Mail bombing D. Keystroke logging
Correct Answer: A
You work as a Network Administrator for Net Perfect Inc. The company has a Windows Server 2008
network environment. The network is configured as a Windows Active Directory-based single forest
single domain network. You want to configure Network Access Protection (NAP) on your network.
You want that the clients connecting to the network must contain certain configurations. Which of
the following Windows components ensure that only clients having certain health benchmarks
access the network resources? Each correct answer represents a part of the solution. Choose two.
A. Windows Firewall
B. System Health Agents (SHA)
C. Terminal Service
D. System Health Validators (SHV)
E. TS Gateway
Correct Answer: BD
You work as a Network Administrator for Tech Perfect Inc. The company has a Windows 2008 Active
Directory-based network. All client computers on the network run Windows Vista Ultimate. You have
configured a Dynamic DNS (DDNS) on the network. There are a lot of mobile users who often connect to
and disconnect from the network. Users on the network complain of slow network responses. You suspect
that the stale records on the DNS server may be the cause of the issue. You want to remove the stale
records.Which of the following technologies will you use to accomplish the task?
A. RODC
B. Aging
C. Scavenging
D. Forwarding
Correct Answer: C
Which of the following is the process used by attackers for listening to the network traffic? A. Eavesdropping B. Subnetting C. Sanitization D. Hacking
Correct Answer: A
Which of the following is a Windows configuration option that enables administrators to restrict communication among domain members only? A. Demilitarized zone B. Server isolation C. Domain isolation D. Domain kiting
Correct Answer: C
Which of the following are required to enable for preventing the users from downloading and installing
software from the Internet? Each correct answer represents a complete solution. Choose all that apply.
A. Software restriction policies
B. PTR record
C. User Account Control
D. Anti-Virus software
Correct Answer: AC
You check the logs on several clients and find that there is traffic coming in on an odd port (port 1872).
All clients have the Windows XP firewall turned on. What should you do to block this unwanted traffic?
A. Perform a virus scan to find the virus responsible for this traffic.
B. Check the exceptions in the firewall and unselect that port exception.
C. Trace back that traffic and find its origin.
D. Shut down the service that connects to that port.
Correct Answer: B
Which of the following is a set of rules that control the working environment of user accounts and computer accounts? A. Mandatory Access Control B. Access control list C. Group Policy D. Intrusion detection system
Correct Answer: C
By default, what level of security is set for the Local intranet zone? A. High-Medium B. Medium-Low C. High D. Low
Correct Answer: B
Mark works as a Desktop Administrator for TechMart Inc. The company has a Windows-based network.
He has bees assigned a project to upgrade the browsers to Internet Explorer (IE) 8 for working with the
latest Internet technologies Mark wants to ensure that the company uses a number of the security features
built into the browser while maintaining functionality within the company’s intranet. Mark is also educating
his users to be good Internet citizens and use the safe web sur?ng. Mark asked his team to be assured that
they are on a secured website. What they will do?
A. Take a look for a padlock in the lower right corner of the browser and https:// in the address bar.
B. Provide protection against a Distributed Denial of Services attack.
C. Call a team member while behaving to be someone else for gaining access to sensitive information.
D. Go into the Internet Options, select the Security, and add the intranet site to the list of Local Intranet Site.
Correct Answer: A
Mark works as a Security Officer for TechMart Inc. The company has a Windows-based network. He
has bees assigned a project for ensuring the safety of the customer’s money and information, not to
mention the company’s reputation. The company has gone through a security audit to ensure that it is in
compliance with industry regulations and standards. Mark understands the request and has to do his due
diligence for providing any information the regulators require as they are targeting potential security holes.
In this situation, his major concern is the physical security of his company’s system. Which of the following
actions will Mark take to ensure the physical security of the company’s desktop computers?
A. Call a team member while behaving to be someone else for gaining access to sensitive information.
B. Develop a social awareness of security threats within an organization.
C. Use group policies to disable the use of floppy drives or USB drives.
D. Provide protection against a Distributed Denial of Services attack.
Correct Answer: C
Mark works as a Network Administrator for TechMart Inc. The company has a Windows-based network.
Mark wants to implement a method to ensure that the mobile devices are in a good state of security health
when they are trying to access the corporate network. For this purpose, Mark is using NAP. Which of the
following will he do for those computers in the network that are not compatible with NAP?
A. Define exceptions in NAP for computers that are not compatible with NAP.
B. Hide those computers that are not compatible with NAP.
C. Remove those computers that are not compatible with NAP.
D. Do not use the NAP, if any of the computers is showing incompatibility in the entire network.
Correct Answer: A
Which of the following is a collection or list of user accounts or computer accounts? A. Group B. Active Directory C. Domain D. Public folder
Correct Answer: A
Which of the following security features of IE 7+ makes it more difficult for malware to be installed? A. Security zones B. Phishing filter C. Protected mode D. Pop-up blocker
Correct Answer: C
Which of the following viruses cannot be detected by signature-based antivirus? A. Macro virus B. Boot sector virus C. MBR virus D. Polymorphic virus
Correct Answer: D
Which of the following is a secret numeric password shared between a user and a system for authenticating the user to the system? A. Key escrow B. Public key C. Private key D. PIN
Correct Answer: D
Which of the following can be installed for ensuring that the domain is secure in the remote locations? A. Read-Only domain controller (RODC) B. Microsoft Baseline Security Analyzer C. Windows Software Update Services D. DNS dynamic update
Correct Answer: A
You work as a Network Administrator for TechMart Inc. The company has a Windows-based network.
After completing a security audit of the company’s Microsoft Windows Server 2008 R2 file servers, you
have determined that folder and share security requires a revision on the basis of corporate reorganization.
You have noticed that some shares on the file system are not secured. Which of the following will you use to
prevent unauthorized changes to computers on the domain?
A. TCP/IP protocol
B. Kerberos
C. User Account Control (UAC)
D. Lightweight Directory Access Protocol
Correct Answer: C
Which of the following is defined as a digitally signed statement used to authenticate and to secure information on open networks? A. Kerberos B. Public certificate C. Single sign-on (SSO) D. SEAL
Correct Answer: B
Which of the following layers defines the mechanisms that allow data to be passed from one network to another? A. Network layer B. Session layer C. Physical layer D. Data-link layer
Correct Answer: A
You work as a Network Administrator for NetTech Inc. Your computer has the Windows 2000 Server
operating system. You want to harden the security of the server. Which of the following changes are
required to accomplish this? Each correct answer represents a complete solution. Choose two.
A. Enable the Guest account.
B. Rename the Administrator account.
C. Remove the Administrator account.
D. Disable the Guest account.
Correct Answer: BD
Which of the following types of attack is used to configure a computer to behave as another computer
on a trusted network by using the IP address or the physical address?
A. Distributed denial of service (DDOS) attack
B. Honeypot
C. RIP/SAP Spoofing
D. Identity spoofing
Correct Answer: D
Which of the following actions should be taken so that the computer requires confirmation before
installing an ActiveX component?
A. Configuring a firewall on the network
B. Configuring the settings on the Web Browser
C. Installing an anti-virus software
D. Configuring DMZ on the network
Correct Answer: B
What are the main classes of biometric characteristics? Each correct answer represents a complete solution. Choose two. A. Psychological B. Behavioral C. Fundamental D. Physiological
Correct Answer: BD
You work as a network administrator for an insurance company called InZed Inc. The company has
developed a corporate policy that requires all machines to use the IPSec security protocol. If the computer
they are logging in from does not follow this corporate policy, they will be denied access to the network.
Which of the following can you set up to help enforce the corporate policy?
A. Server Access Protection
B. System Center Data Protection Manager (DPM)
C. Microsoft Assessment and Planning (MAP) Toolkit
D. Network Access Protection
Correct Answer: D
Which of the following ports is used by the IMAP4 protocol? A. 443 B. 53 C. 143 D. 110
Correct Answer: C
On which of the following is the level of security set for the restricted sites applied?
A. To the sites that might potentially damage your computer, or your information.
B. To the sites that you have specifically indicated as the ones that you trust.
C. To the Websites and content that are stored on a corporate or business network.
D. To all the Websites by default.
Correct Answer: A
You work as a Network Administrator for NetTech Inc. You want to prevent users from accessing the
graphical user interface (GUI) on the computers in the network. What will you do to accomplish this task?
A. Implement a remote access policy
B. Implement a group policy
C. Apply NTFS permission
D. Implement an account policy
Correct Answer: B
Your Web server crashes at exactly the point where it reaches 1 million total visits. You discover the
cause of the server crash is malicious code. Which description best fits this code?
A. Virus
B. Worm
C. Polymorphic Virus
D. Logic Bomb
Correct Answer: D
Which of the following is the process of keeping track of a user's activity while accessing network resources? A. Authentication B. Auditing C. Spoofing D. Biometrics
Correct Answer: B
Mark works as a Network Administrator for NetTech Inc. The company has a Windows Server 2008
domain-based network. The network has a Windows Server 2008 member server that works as a Routing
and Remote Access Server (RRAS). Mark implements Network Access Protection (NAP) for the network.
Mark wants to configure Point-to-Point Protocol (PPP) authentication on the RRAS server. Which of the
following authentication methods should Mark use to accomplish this task?
A. EAP
B. CHAP
C. SPAP
D. PAP
Correct Answer: A
You are taking over the security of an existing network. You discover a machine that is not being used
as such, but has software on it that emulates the activity of a sensitive database server. What is this?
A. A Polymorphic Virus
B. A Honey Pot
C. A reactive IDS.
D. A Virus
Correct Answer: B
Sam works as a Web Developer for McRobert Inc. He wants to control the way in which a Web browser
receives information and downloads content from Web sites. Which of the following browser settings will
Sam use to accomplish this?
A. Security
B. Certificate
C. Cookies
D. Proxy server
Correct Answer: A
Mark works as a Security Officer for TechMart Inc. The company has a Windows-based network. He
has bees assigned a project for ensuring the safety of the customer’s money and information, not to
mention the company’s reputation. The company has gone through a security audit to ensure that it is in
compliance with industry regulations and standards. Mark understands the request and has to do his due
diligence for providing any information the regulators require as they are targeting potential security holes.
In this situation, his major concern is the physical security of his company’s system. He has a concern that
people are authenticated to the servers in the data center. Which of the following actions will Mark take to
prevent normal users from logging onto the systems?
A. Call a team member while behaving to be someone else for gaining access to sensitive information.
B. Use group policies to disable the use of floppy drives or USB drives.
C. Provide protection against a Distributed Denial of Services attack.
D. Develop a social awareness of security threats within an organization.
Correct Answer: B
Which of the following types of viruses protects itself from antivirus programs and is more difficult to trace? A. Armored virus B. MBR virus C. Boot sector virus D. Macro virus
Correct Answer: A
Which of the following is the edge between the private and locally managed-and-owned side of a
network and the public side that is commonly managed by a service provider?
A. Internet
B. Network perimeter
C. Intranet
D. VLAN
Correct Answer: B
Mark work as a System Administrator for TechMart Inc. The company has a Windows-based network.
Mark wants to allow the remote travel agents to be able to access the corporate network so that they are
free to check email and post appointments that are booked for the particular day. Mark has decided to
permit the travel agents to use their home computers but he is required to be assured that the information is
not compromised by anyone because the security of client information is on the top priority for him. Which
of the following will Mark use to accomplish the task?
A. Implement the principle of least privilege that permits the travel agents for remote access.
B. Implement a Wi-Fi Protected Access that permits the travel agents for remote access.
C. Implement a Wired Equivalent Privacy that permits the travel agents for remote access.
D. Implement a VPN server that permits the travel agents for remote access
Correct Answer: D
Which of the following practices should be followed to keep passwords secure? Each correct answer
represents a complete solution. Choose three.
A. Change the passwords whenever there is suspicion that they may have been compromised.
B. A password should be alpha-numeric.
C. A password should not be more than five words.
D. Never write down a password.
Correct Answer: ABD
Which of the following collects email addresses of users and creates a mailing list? A. Browser B. Cookie C. Spambot D. Perimeter network
Correct Answer: C
In which of the following is the file audit events are written when auditing is enabled? A. File system ACL B. Biometric device C. Network Access Control List D. Security event log
Correct Answer: D
Which of the following security features of IE 7+ helps determine whether a Web site is a legitimate site? A. Protected mode B. Pop-up blocker C. Security zones D. Phishing filter
Correct Answer: D
Ron owns the domain TechPerfect.net. He often receives bounces about messages he didn’t send.
After looking at all such mails, he is sure that someone is spamming e-mails and using his domain name.
What will Ron do to ensure that his domain name is not exploited?
A. Publish the MX record for the domain.
B. Publish the SPF record for the domain.
C. Publish the AAAA record for the domain.
D. Publish the A record for the domain.
Correct Answer: B
Which of the following points has to be considered for using the BitLocker?
A. The deployment of antivirus because BitLocker needs a a removal of buffer overflow.
B. The deployment of SEAL because BitLocker needs an alternative encryption algorithm to software-based
DES, 3DES, and AES. .
C. The deployment of hardware because BitLocker needs a system reserved partition.
D. The deployment of hard disk because BitLocker needs a bot.
Correct Answer: C
Which of the following is a program that runs at a specific date and time to cause unwanted and unauthorized functions? A. Keylogger B. Logic bomb C. Spyware D. Trojan horse
Correct Answer: B
Which of the following is a disadvantage of using biometric identification?
A. It breaks the several firewall security rules.
B. It needs a new network configuration of the entire infrastructure.
C. It can be faked and will not be trusted by several organizations.
D. It is expensive and cannot be afforded by several organizations
Correct Answer: D
You work as a Network Administrator for TechMart Inc. The company has a Windows-based network.
After completing a security audit of the company’s Microsoft Windows Server 2008 R2 file servers, you
have determined that folder and share security requires a revision on the basis of corporate reorganization. You
have noticed that some shares on the file system are not secured. Which of the following is a feature
that you will use to reassign permissions without assigning permissions to every parent and child folder?
A. Inheritance
B. Kerberos
C. TCP/IP protocol
D. User Account Control (UAC)
Correct Answer: A
Which of the following is a US Federal government algorithm created to generate a secure message digest? A. DSA B. RSA C. Triple DES D. SHA
Correct Answer: D
Which of the following can be implemented to ensure that the computers are using latest security updates? A. Hardening B. Windows Software Update Services C. Microsoft Baseline Security Analyzer D. Domain Name System
Correct Answer: B