Sec + Flashcards

1
Q
An achievement in providing worldwide Internet security was the signing of certificates associated
with which of the following protocols?
A. TCP/IP
B. SSL
C. SCP
D. SSH
A

B

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

A Chief Information Security Officer (CISO) wants to implement two-factor authentication within
the company. Which of the following would fulfill the CISO’s requirements?
A. Username and password
B. Retina scan and fingerprint scan
C. USB token and PIN
D. Proximity badge and token

A

C

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q
Which of the following can a security administrator implement on mobile devices that will help prevent unwanted people from viewing the data if the device is left unattended?
A. Screen lock
B. Voice encryption
C. GPS tracking
D. Device encryption
A

A

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Which of the following would a security administrator implement in order to identify a problem
between two systems that are not communicating properly?
A. Protocol analyzer
B. Baseline report
C. Risk assessment
D. Vulnerability scan

A

A

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q
Which of the following can result in significant administrative overhead from incorrect reporting?
A. Job rotation
B. Acceptable usage policies
C. False positives
D. Mandatory vacations
A

C

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

A security administrator wants to perform routine tests on the network during working hours when
certain applications are being accessed by the most people. Which of the following would allow
the security administrator to test the lack of security controls for those applications with the least
impact to the system?
A. Penetration test
B. Vulnerability scan
C. Load testing
D. Port scanner

A

B

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q
Which of the following risk concepts requires an organization to determine the number of failures per year?
A. SLE
B. ALE
C. MTBF
D. Quantitative analysis
A

B

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

A system security analyst using an enterprise monitoring tool notices an unknown internal host
exfiltrating files to several foreign IP addresses. Which of the following would be an appropriate
mitigation technique?
A. Disabling unnecessary accounts
B. Rogue machine detection
C. Encrypting sensitive files
D. Implementing antivirus

A

B

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Three of the primary security control types that can be implemented are.
A. Supervisory, subordinate, and peer.
B. Personal, procedural, and legal.
C. Operational, technical, and management.
D. Mandatory, discretionary, and permanent.

A

C

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q
The helpdesk reports increased calls from clients reporting spikes in malware infections on their
systems. Which of the following phases of incident response is MOST appropriate as a FIRST response?
A. Recovery
B. Follow-up
C. Validation
D. Identification
E. Eradication
F. Containment
A

D

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q
Which of the following protocols operates at the HIGHEST level of the OSI model?
A. ICMP
B. IPSec
C. SCP
D. TCP
A

C

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Joe, the system administrator, has been asked to calculate the Annual Loss Expectancy (ALE) for
a $5,000 server, which often crashes. In the past year, the server has crashed 10 times, requiring
a system reboot to recover with only 10% loss of data or function. Which of the following is the
ALE of this server?
A. $500
B. $5,000
C. $25,000
D. $50,000

A

B

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q
Which of the following should an administrator implement to research current attack
methodologies?
A. Design reviews
B. Honeypot
C. Vulnerability scanner
D. Code reviews
A

B

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q
Which of the following can be implemented in hardware or software to protect a web server from
cross-site scripting attacks?
A. Intrusion Detection System
B. Flood Guard Protection
C. Web Application Firewall
D. URL Content Filter
A

C

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q
Which of the following means of wireless authentication is easily vulnerable to spoofing?
A. MAC Filtering
B. WPA - LEAP
C. WPA - PEAP
D. Enabled SSID
A

A

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

The BEST methods for a web developer to prevent the website application code from being
vulnerable to cross-site request forgery (XSRF) are to: (Select TWO).
A. permit redirection to Internet-facing web URLs.
B. ensure all HTML tags are enclosed in angle brackets, e.g., ””.
C. validate and filter input on the server side and client side.
D. use a web proxy to pass website requests between the user and the application.
E. restrict and sanitize use of special characters in input and URLs.

A

CE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Jane, a security administrator, needs to implement a secure wireless authentication method that
uses a remote RADIUS server for authentication.
Which of the following is an authentication method Jane should use?
A. WPA2-PSK
B. WEP-PSK
C. CCMP
D. LEAP

A

D

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Computer evidence at a crime scene is documented with a tag stating who had possession of the
evidence at a given time.
Which of the following does this illustrate?
A. System image capture
B. Record time offset
C. Order of volatility
D. Chain of custody

A

D

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

A network administrator is configuring access control for the sales department which has high
employee turnover. Which of the following is BEST suited when assigning user rights to individuals
in the sales department?
A. Time of day restrictions
B. Group based privileges
C. User assigned privileges
D. Domain admin restrictions

A

B

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q
Which of the following is being tested when a company’s payroll server is powered off for eight
hours?
A. Succession plan
B. Business impact document
C. Continuity of operations plan
D. Risk assessment plan
A

C

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

A security analyst, Ann, is reviewing an IRC channel and notices that a malicious exploit has been
created for a frequently used application. She notifies the software vendor and asks them for
remediation steps, but is alarmed to find that no patches are available to mitigate this vulnerability.
Which of the following BEST describes this exploit?
A. Malicious insider threat
B. Zero-day
C. Client-side attack
D. Malicious add-on

A

B

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

A security administrator has concerns about new types of media which allow for the mass
distribution of personal comments to a select group of people. To mitigate the risks involved with
this media, employees should receive training on which of the following?
A. Peer to Peer
B. Mobile devices
C. Social networking
D. Personally owned devices

A

C

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

A network administrator is responsible for securing applications against external attacks. Every
month, the underlying operating system is updated. There is no process in place for other software
updates.
Which of the following processes could MOST effectively mitigate these risks?
A. Application hardening
B. Application change management
C. Application patch management
D. Application firewall review

A

C

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

A software developer is responsible for writing the code on an accounting application. Another
software developer is responsible for developing code on a system in human resources. Once a
year they have to switch roles for several weeks.
Which of the following practices is being implemented?
A. Mandatory vacations
B. Job rotation
C. Least privilege
D. Separation of duties

A

B

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q
A network engineer is designing a secure tunneled VPN. Which of the following protocols would
be the MOST secure?
A. IPsec
B. SFTP
C. BGP
D. PPTP
A

A

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q
Which of the following implementation steps would be appropriate for a public wireless hot-spot?
A. Reduce power level
B. Disable SSID broadcast
C. Open system authentication
D. MAC filter
A

C

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

Which of the following is a step in deploying a WPA2-Enterprise wireless network?
A. Install a token on the authentication server
B. Install a DHCP server on the authentication server
C. Install an encryption key on the authentication server
D. Install a digital certificate on the authentication server

A

D

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q
Which of the following controls would allow a company to reduce the exposure of sensitive systems from unmanaged devices on internal networks?
A. 802.1x
B. Data encryption
C. Password strength
D. BGP
A

A

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

Which of the following preventative controls would be appropriate for responding to a directive to
reduce the attack surface of a specific host?
A. Installing anti-malware
B. Implementing an IDS
C. Taking a baseline configuration
D. Disabling unnecessary services

A

D

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

A security manager must remain aware of the security posture of each system. Which of the
following supports this requirement?
A. Training staff on security policies
B. Establishing baseline reporting
C. Installing anti-malware software
D. Disabling unnecessary accounts/services

A

B

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

Deploying a wildcard certificate is one strategy to:
A. Secure the certificate’s private key.
B. Increase the certificate’s encryption key length.
C. Extend the renewal date of the certificate.
D. Reduce the certificate management burden.

A

D

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

The security administrator needs to manage traffic on a layer 3 device to support FTP from a new
remote site. Which of the following would need to be implemented?
A. Implicit deny
B. VLAN management
C. Port security
D. Access control lists

A

D

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
33
Q
Which of the following ports is used for SSH, by default?
A. 23
B. 32
C. 12
D. 22
A

D

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
34
Q

A network administrator has been tasked with securing the WLAN. Which of the following
cryptographic products would be used to provide the MOST secure environment for the WLAN?
A. WPA2 CCMP
B. WPA
C. WPA with MAC filtering
D. WPA2 TKIP

A

A

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
35
Q
A server with the IP address of 10.10.2.4 has been having intermittent connection issues. The logs
show repeated connection attempts from the following IPs:
10.10.3.16
10.10.3.23
212.178.24.26
217.24.94.83
These attempts are overloading the server to the point that it cannot respond to traffic. Which of
the following attacks is occurring?
A. XSS
B. DDoS
C. DoS
D. Xmas
A

B

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
36
Q
Which of the following ciphers would be BEST used to encrypt streaming video?
A. RSA
B. RC4
C. SHA1
D. 3DES
A

B

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
37
Q

A user attempting to log on to a workstation for the first time is prompted for the following
information before being granted access: username, password, and a four-digit security pin that
was mailed to him during account registration. This is an example of which of the following?
A. Dual-factor authentication
B. Multifactor authentication
C. Single factor authentication
D. Biometric authentication

A

C

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
38
Q

After analyzing and correlating activity from multiple sensors, the security administrator has
determined that a group of very well organized individuals from an enemy country is responsible
for various attempts to breach the company network, through the use of very sophisticated and
targeted attacks. Which of the following is this an example of?
A. Privilege escalation
B. Advanced persistent threat
C. Malicious insider threat
D. Spear phishing

A

B

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
39
Q

Which of the following is true about input validation in a client-server architecture, when data integrity is critical to the organization?
A. It should be enforced on the client side only.
B. It must be protected by SSL encryption.
C. It must rely on the user’s knowledge of the application.
D. It should be performed on the server side.

A

D

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
40
Q

A merchant acquirer has the need to store credit card numbers in a transactional database in a
high performance environment. Which of the following BEST protects the credit card data?
A. Database field encryption
B. File-level encryption
C. Data loss prevention system
D. Full disk encryption

A

A

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
41
Q

A bank has a fleet of aging payment terminals used by merchants for transactional processing.
The terminals currently support single DES but require an upgrade in order to be compliant with
security standards. Which of the following is likely to be the simplest upgrade to the aging
terminals which will improve in-transit protection of transactional data?
A. AES
B. 3DES
C. RC4
D. WPA2

A

B

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
42
Q
Which of the following is BEST at blocking attacks and providing security at layer 7 of the OSI
model?
A. WAF
B. NIDS
C. Routers
D. Switches
A

A

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
43
Q
Which of the following is BEST used to capture and analyze network traffic between hosts on the
same network segment?
A. Protocol analyzer
B. Router
C. Firewall
D. HIPS
A

A

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
44
Q

After a number of highly publicized and embarrassing customer data leaks as a result of social
engineering attacks by phone, the Chief Information Officer (CIO) has decided user training will
reduce the risk of another data leak. Which of the following would be MOST effective in reducing
data leaks in this situation?
A. Information Security Awareness
B. Social Media and BYOD
C. Data Handling and Disposal
D. Acceptable Use of IT Systems

A

A

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
45
Q
Which of the following functions provides an output which cannot be reversed and converts data
into a string of characters?
A. Hashing
B. Stream ciphers
C. Steganography
D. Block ciphers
A

A

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
46
Q
Which of the following encrypts data a single bit at a time?
A. Stream cipher
B. Steganography
C. 3DES
D. Hashing
A

A

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
47
Q
Which of the following is used to verify data integrity?
A. SHA
B. 3DES
C. AES
D. RSA
A

A

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
48
Q
By default, which of the following uses TCP port 22? (Select THREE).
A. FTPS
B. STELNET
C. TLS
D. SCP
E. SSL
F. HTTPS
G. SSH
H. SFTP
A

D C H

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
49
Q

Access mechanisms to data on encrypted USB hard drives must be implemented correctly otherwise:
A. user accounts may be inadvertently locked out.
B. data on the USB drive could be corrupted.
C. data on the hard drive will be vulnerable to log analysis.
D. the security controls on the USB drive can be bypassed.

A

D

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
50
Q

Maintenance workers find an active network switch hidden above a dropped-ceiling tile in the
CEO’s office with various connected cables from the office. Which of the following describes the
type of attack that was occurring?
A. Spear phishing
B. Packet sniffing
C. Impersonation
D. MAC flooding

A

B

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
51
Q

A security administrator is segregating all web-facing server traffic from the internal network and
restricting it to a single interface on a firewall. Which of the following BEST describes this new
network?
A. VLAN
B. Subnet
C. VPN
D. DMZ

A

D

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
52
Q

Which of the following was based on a previous X.500 specification and allows either unencrypted
authentication or encrypted authentication through the use of TLS?
A. Kerberos
B. TACACS+
C. RADIUS
D. LDAP

A

D

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
53
Q

The Quality Assurance team is testing a new third party developed application. The Quality team
does not have any experience with the application. Which of the following is the team performing?
A. Grey box testing
B. Black box testing
C. Penetration testing
D. White box testing

A

B

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
54
Q
Which of the following has a storage root key?
A. HSM
B. EFS
C. TPM
D. TKIP
A

C

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
55
Q

A datacenter requires that staff be able to identify whether or not items have been removed from
the facility. Which of the following controls will allow the organization to provide automated
notification of item removal?
A. CCTV
B. Environmental monitoring
C. RFID
D. EMI shielding

A

C

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
56
Q

A malicious person gained access to a datacenter by ripping the proximity badge reader off the
wall near the datacenter entrance. This caused the electronic locks on the datacenter door to
release because the:
A. badge reader was improperly installed.
B. system was designed to fail open for life-safety.
C. system was installed in a fail closed configuration.
D. system used magnetic locks and the locks became demagnetized.

A

B

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
57
Q

The concept of rendering data passing between two points over an IP based network impervious
to all but the most sophisticated advanced persistent threats is BEST categorized as which of the
following?
A. Stream ciphers
B. Transport encryption
C. Key escrow
D. Block ciphers

A

B

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
58
Q

On Monday, all company employees report being unable to connect to the corporate wireless
network, which uses 802.1x with PEAP. A technician verifies that no configuration changes were
made to the wireless network and its supporting infrastructure, and that there are no outages.
Which of the following is the MOST likely cause for this issue?
A. Too many incorrect authentication attempts have caused users to be temporarily disabled.
B. The DNS server is overwhelmed with connections and is unable to respond to queries.
C. The company IDS detected a wireless attack and disabled the wireless network.
D. The Remote Authentication Dial-In User Service server certificate has expired.

A

D

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
59
Q

Which of the following would BEST deter an attacker trying to brute force 4-digit PIN numbers to
access an account at a bank teller machine?
A. Account expiration settings
B. Complexity of PIN
C. Account lockout settings
D. PIN history requirements

A

C

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
60
Q

An administrator discovers that many users have used their same passwords for years even
though the network requires that the passwords be changed every six weeks. Which of the
following, when used together, would BEST prevent users from reusing their existing password?
(Select TWO).
A. Length of password
B. Password history
C. Minimum password age
D. Password expiration
E. Password complexity
F. Non-dictionary words

A

B C

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
61
Q

A recent audit has discovered that at the time of password expiration clients are able to recycle the
previous credentials for authentication. Which of the following controls should be used together to
prevent this from occurring? (Select TWO).
A. Password age
B. Password hashing
C. Password complexity
D. Password history
E. Password length

A

A D

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
62
Q

A system administrator is configuring UNIX accounts to authenticate against an external server.
The configuration file asks for the following information DC=ServerName and DC=COM. Which of
the following authentication services is being used?
A. RADIUS
B. SAML
C. TACACS+
D. LDAP

A

D

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
63
Q
In Kerberos, the Ticket Granting Ticket (TGT) is used for which of the following?
A. Identification
B. Authorization
C. Authentication
D. Multifactor authentication
A

C

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
64
Q
Which of the following network design elements allows for many internal devices to share one
public IP address?
A. DNAT
B. PAT
C. DNS
D. DMZ
A

B

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
65
Q

Which of the following components of an all-in-one security appliance would MOST likely be
configured in order to restrict access to peer-to-peer file sharing websites?
A. Spam filter
B. URL filter
C. Content inspection
D. Malware inspection

A

B

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
66
Q

When considering a vendor-specific vulnerability in critical industrial control systems which of the
following techniques supports availability?
A. Deploying identical application firewalls at the border
B. Incorporating diversity into redundant design
C. Enforcing application white lists on the support workstations
D. Ensuring the systems’ anti-virus definitions are up-to-date

A

B

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
67
Q

During the information gathering stage of a deploying role-based access control model, which of
the following information is MOST likely required?
A. Conditional rules under which certain systems may be accessed
B. Matrix of job titles with required access privileges
C. Clearance levels of all company personnel
D. Normal hours of business operation

A

B

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
68
Q

The Chief Technical Officer (CTO) has been informed of a potential fraud committed by a
database administrator performing several other job functions within the company. Which of the
following is the BEST method to prevent such activities in the future?
A. Job rotation
B. Separation of duties
C. Mandatory Vacations
D. Least Privilege

A

B

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
69
Q

Ann would like to forward some Personal Identifiable Information to her HR department by email,
but she is worried about the confidentiality of the information. Which of the following will
accomplish this task securely?
A. Digital Signatures
B. Hashing
C. Secret Key
D. Encryption

A

D

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
70
Q

A company is trying to limit the risk associated with the use of unapproved USB devices to copy
documents. Which of the following would be the BEST technology control to use in this scenario?
A. Content filtering
B. IDS
C. Audit logs
D. DLP

A

D

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
71
Q

A company is trying to implement physical deterrent controls to improve the overall security
posture of their data center. Which of the following BEST meets their goal?
A. Visitor logs
B. Firewall
C. Hardware locks
D. Environmental monitoring

A

C

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
72
Q

A company’s employees were victims of a spear phishing campaign impersonating the CEO. The
company would now like to implement a solution to improve the overall security posture by
assuring their employees that email originated from the CEO. Which of the following controls could
they implement to BEST meet this goal?
A. Spam filter
B. Digital signatures
C. Antivirus software
D. Digital certificates

A

B

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
73
Q

A security technician is attempting to improve the overall security posture of an internal mail
server. Which of the following actions would BEST accomplish this goal?
A. Monitoring event logs daily
B. Disabling unnecessary services
C. Deploying a content filter on the network
D. Deploy an IDS on the network

A

B

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
74
Q
A bank has recently deployed mobile tablets to all loan officers for use at customer sites. Which of
the following would BEST prevent the disclosure of customer data in the event that a tablet is lost
or stolen?
A. Application control
B. Remote wiping
C. GPS
D. Screen-locks
Answer: B
A

C

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
75
Q
Which of the following is the primary security concern when deploying a mobile device on a network?
A. Strong authentication
B. Interoperability
C. Data security
D. Cloud storage technique
A

C

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
76
Q

Which of the following technical controls is BEST used to define which applications a user can
install and run on a company issued mobile device?
A. Authentication
B. Blacklisting
C. Whitelisting
D. Acceptable use policy

A

D

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
77
Q

After a company has standardized to a single operating system, not all servers are immune to a
well-known OS vulnerability. Which of the following solutions would mitigate this issue?
A. Host based firewall
B. Initial baseline configurations
C. Discretionary access control
D. Patch management system

A

B

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
78
Q
A security administrator discovers an image file that has several plain text documents hidden in the file. Which of the following security goals is met by camouflaging data inside of other files?
A. Integrity
B. Confidentiality
C. Steganography
D. Availability
A

B

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
79
Q

A company determines a need for additional protection from rogue devices plugging into physical
ports around the building. Which of the following provides the highest degree of protection from
unauthorized wired network access?
A. Intrusion Prevention Systems
B. MAC filtering
C. Flood guards
D. 802.1x

A

D

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
80
Q

A company is preparing to decommission an offline, non-networked root certificate server. Before
sending the server’s drives to be destroyed by a contracted company, the Chief Security Officer
(CSO) wants to be certain that the data will not be accessed. Which of the following, if
implemented, would BEST reassure the CSO? (Select TWO).
A. Disk hashing procedures
B. Full disk encryption
C. Data retention policies
D. Disk wiping procedures
E. Removable media encryption

A

B D

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
81
Q

During the analysis of a PCAP file, a security analyst noticed several communications with a
remote server on port 53. Which of the following protocol types is observed in this traffic?
A. FTP
B. DNS
C. Email
D. NetBIOS

A

B

82
Q

A compromised workstation utilized in a Distributed Denial of Service (DDOS) attack has been
removed from the network and an image of the hard drive has been created. However, the system
administrator stated that the system was left unattended for several hours before the image was
created. In the event of a court case, which of the following is likely to be an issue with this
incident?
A. Eye Witness
B. Data Analysis of the hard drive
C. Chain of custody
D. Expert Witness

A

C

83
Q

During which of the following phases of the Incident Response process should a security
administrator define and implement general defense against malware?
A. Lessons Learned
B. Preparation
C. Eradication
D. Identification

A

B

84
Q

Due to hardware limitation, a technician must implement a wireless encryption algorithm that uses
the RC4 protocol. Which of the following is a wireless encryption solution that the technician
should implement while ensuring the STRONGEST level of security?
A. WPA2-AES
B. 802.11ac
C. WPA-TKIP
D. WEP

A

C

85
Q
Joe, a user, wants to send an encrypted email to Ann. Which of the following will Ann need to use
to verify that the email came from Joe and decrypt it? (Select TWO).
A. The CA’s public key
B. Ann’s public key
C. Joe’s private key
D. Ann’s private key
E. The CA’s private key
F. Joe’s public key
A

D F

86
Q
Joe, a user, wants to send an encrypted email to Ann. Which of the following will Ann need to use
to verify the validity’s of Joe’s certificate? (Select TWO).
A. The CA’s public key
B. Joe’s private key
C. Ann’s public key
D. The CA’s private key
E. Joe’s public key
F. Ann’s private key
A

A E

87
Q

A technician wants to implement a dual factor authentication system that will enable the
organization to authorize access to sensitive systems on a need-to-know basis. Which of the
following should be implemented during the authorization stage?
A. Biometrics
B. Mandatory access control
C. Single sign-on
D. Role-based access control

A

A

88
Q

A security researcher wants to reverse engineer an executable file to determine if it is malicious.
The file was found on an underused server and appears to contain a zero-day exploit. Which of
the following can the researcher do to determine if the file is malicious in nature?
A. TCP/IP socket design review
B. Executable code review
C. OS Baseline comparison
D. Software architecture review

A

C

89
Q

A recent spike in virus detections has been attributed to end-users visiting www.compnay.com.
The business has an established relationship with an organization using the URL of
www.company.com but not with the site that has been causing the infections. Which of the
following would BEST describe this type of attack?
A. Typo squatting
B. Session hijacking
C. Cross-site scripting
D. Spear phishing

A

A

90
Q

A company has proprietary mission critical devices connected to their network which are
configured remotely by both employees and approved customers. The administrator wants to
monitor device security without changing their baseline configuration. Which of the following
should be implemented to secure the devices without risking availability?
A. Host-based firewall
B. IDS
C. IPS
D. Honeypot

A

B

91
Q

An administrator has a network subnet dedicated to a group of users. Due to concerns regarding
data and network security, the administrator desires to provide network access for this group only.
Which of the following would BEST address this desire?
A. Install a proxy server between the users’ computers and the switch to filter inbound network
traffic.
B. Block commonly used ports and forward them to higher and unused port numbers.
C. Configure the switch to allow only traffic from computers based upon their physical address.
D. Install host-based intrusion detection software to monitor incoming DHCP Discover requests.

A

C

92
Q

Which of the following is a security concern regarding users bringing personally-owned devices
that they connect to the corporate network?
A. Cross-platform compatibility issues between personal devices and server-based applications
B. Lack of controls in place to ensure that the devices have the latest system patches and
signature files
C. Non-corporate devices are more difficult to locate when a user is terminated
D. Non-purchased or leased equipment may cause failure during the audits of company-owned
assets

A

B

93
Q

Due to issues with building keys being duplicated and distributed, a security administrator wishes
to change to a different security control regarding a restricted area. The goal is to provide access
based upon facial recognition. Which of the following will address this requirement?
A. Set up mantraps to avoid tailgating of approved users.
B. Place a guard at the entrance to approve access.
C. Install a fingerprint scanner at the entrance.
D. Implement proximity readers to scan users’ badges.

A

B

94
Q

A security administrator has concerns regarding employees saving data on company provided
mobile devices. Which of the following would BEST address the administrator’s concerns?
A. Install a mobile application that tracks read and write functions on the device.
B. Create a company policy prohibiting the use of mobile devices for personal use.
C. Enable GPS functionality to track the location of the mobile devices.
D. Configure the devices so that removable media use is disabled.

A

D

95
Q
Identifying residual risk is MOST important to which of the following concepts?
A. Risk deterrence
B. Risk acceptance
C. Risk mitigation
D. Risk avoidance
A

B

96
Q

The information security technician wants to ensure security controls are deployed and functioning
as intended to be able to maintain an appropriate security posture. Which of the following security
techniques is MOST appropriate to do this?
A. Log audits
B. System hardening
C. Use IPS/IDS
D. Continuous security monitoring

A

D

97
Q

A small company can only afford to buy an all-in-one wireless router/switch. The company has 3
wireless BYOD users and 2 web servers without wireless access. Which of the following should
the company configure to protect the servers from the user devices? (Select TWO).
A. Deny incoming connections to the outside router interface.
B. Change the default HTTP port
C. Implement EAP-TLS to establish mutual authentication
D. Disable the physical switch ports
E. Create a server VLAN
F. Create an ACL to access the server

A

E F

98
Q

Users can authenticate to a company’s web applications using their credentials from a popular
social media site. Which of the following poses the greatest risk with this integration?
A. Malicious users can exploit local corporate credentials with their social media credentials
B. Changes to passwords on the social media site can be delayed from replicating to the company
C. Data loss from the corporate servers can create legal liabilities with the social media site
D. Password breaches to the social media site affect the company application as well

A

D

99
Q
A security team has established a security awareness program. Which of the following would
BEST prove the success of the program?
A. Policies
B. Procedures
C. Metrics
D. Standards
A

C

100
Q
A company needs to receive data that contains personally identifiable information. The company
requires both the transmission and data at rest to be encrypted. Which of the following achieves
this goal? (Select TWO).
A. SSH
B. TFTP
C. NTLM
D. TKIP
E. SMTP
F. PGP/GPG
A

A F

101
Q

An organization does not have adequate resources to administer its large infrastructure. A security
administrator wishes to combine the security controls of some of the network devices in the
organization. Which of the following methods would BEST accomplish this goal?
A. Unified Threat Management
B. Virtual Private Network
C. Single sign on
D. Role-based management

A

A

102
Q
Which of the following would allow the organization to divide a Class C IP address range into
several ranges?
A. DMZ
B. Virtual LANs
C. NAT
D. Subnetting
A

D

103
Q

The security administrator is currently unaware of an incident that occurred a week ago. Which of
the following will ensure the administrator is notified in a timely manner in the future?
A. User permissions reviews
B. Incident response team
C. Change management
D. Routine auditing

A

D

104
Q

An access point has been configured for AES encryption but a client is unable to connect to it.
Which of the following should be configured on the client to fix this issue?
A. WEP
B. CCMP
C. TKIP
D. RC4

A

B

105
Q

The system administrator is tasked with changing the administrator password across all 2000
computers in the organization. Which of the following should the system administrator implement
to accomplish this task?
A. A security group
B. A group policy
C. Key escrow
D. Certificate revocation

A

B

106
Q

A network administrator wants to block both DNS requests and zone transfers coming from
outside IP addresses. The company uses a firewall which implements an implicit allow and is
currently configured with the following ACL applied to its external interfacE.
PERMIT TCP ANY ANY 80
PERMIT TCP ANY ANY 443
Which of the following rules would accomplish this task? (Select TWO).
A. Change the firewall default settings so that it implements an implicit deny
B. Apply the current ACL to all interfaces of the firewall
C. Remove the current ACL
D. Add the following ACL at the top of the current ACL
DENY TCP ANY ANY 53
E. Add the following ACL at the bottom of the current ACL
DENY ICMP ANY ANY 53
F. Add the following ACL at the bottom of the current ACL
DENY IP ANY ANY 53

A

A F

107
Q

Which of the following attacks would cause all mobile devices to lose their association with
corporate access points while the attack is underway?
A. Wireless jamming
B. Evil twin
C. Rogue AP
D. Packet sniffing

A

A

108
Q

An administrator wants to ensure that the reclaimed space of a hard drive has been sanitized
while the computer is in use. Which of the following can be implemented?
A. Cluster tip wiping
B. Individual file encryption
C. Full disk encryption
D. Storage retention

A

A

109
Q

A company is looking to improve their security posture by addressing risks uncovered by a recent
penetration test. Which of the following risks is MOST likely to affect the business on a day-to-day
basis?
A. Insufficient encryption methods
B. Large scale natural disasters
C. Corporate espionage
D. Lack of antivirus software

A

D

110
Q

Ann, an employee, is cleaning out her desk and disposes of paperwork containing confidential
customer information in a recycle bin without shredding it first. This is MOST likely to increase the
risk of loss from which of the following attacks?
A. Shoulder surfing
B. Dumpster diving
C. Tailgating
D. Spoofing

A

B

111
Q

A recently installed application update caused a vital application to crash during the middle of the
workday. The application remained down until a previous version could be reinstalled on the
server, and this resulted in a significant loss of data and revenue.
Which of the following could BEST prevent this issue from occurring again?
A. Application configuration baselines
B. Application hardening
C. Application access controls
D. Application patch management

A

D

112
Q

A security administrator wishes to increase the security of the wireless network. Which of the
following BEST addresses this concern?
A. Change the encryption from TKIP-based to CCMP-based.
B. Set all nearby access points to operate on the same channel.
C. Configure the access point to use WEP instead of WPA2.
D. Enable all access points to broadcast their SSIDs.

A

A

113
Q

The system administrator has deployed updated security controls for the network to limit risk of
attack. The security manager is concerned that controls continue to function as intended to
maintain appropriate security posture.
Which of the following risk mitigation strategies is MOST important to the security manager?
A. User permissions
B. Policy enforcement
C. Routine audits
D. Change management

A

C

114
Q

A company is about to release a very large patch to its customers. An administrator is required to
test patch installations several times prior to distributing them to customer PCs.
Which of the following should the administrator use to test the patching process quickly and often?
A. Create an incremental backup of an unpatched PC
B. Create an image of a patched PC and replicate it to servers
C. Create a full disk image to restore after each installation
D. Create a virtualized sandbox and utilize snapshots

A

D

115
Q

An auditing team has found that passwords do not meet best business practices. Which of the
following will MOST increase the security of the passwords? (Select TWO).
A. Password Complexity
B. Password Expiration
C. Password Age
D. Password Length
E. Password History

A

A D

116
Q

A vulnerability scan is reporting that patches are missing on a server. After a review, it is
determined that the application requiring the patch does not exist on the operating system.
Which of the following describes this cause?
A. Application hardening
B. False positive
C. Baseline code review
D. False negative

A

B

117
Q

Company A submitted a bid on a contract to do work for Company B via email. Company B was
insistent that the bid did not come from Company A. Which of the following would have assured
that the bid was submitted by Company A?
A. Steganography
B. Hashing
C. Encryption
D. Digital Signatures

A

D

118
Q

Ann, a sales manager, successfully connected her company-issued smartphone to the wireless
network in her office without supplying a username/password combination. Upon disconnecting
from the wireless network, she attempted to connect her personal tablet computer to the same
wireless network and could not connect.
Which of the following is MOST likely the reason?
A. The company wireless is using a MAC filter.
B. The company wireless has SSID broadcast disabled.
C. The company wireless is using WEP.
D. The company wireless is using WPA2.

A

A

119
Q

A network technician is on the phone with the system administration team. Power to the server
room was lost and servers need to be restarted. The DNS services must be the first to be
restarted. Several machines are powered off. Assuming each server only provides one service,
which of the following should be powered on FIRST to establish DNS services?
A. Bind server
B. Apache server
C. Exchange server
D. RADIUS server

A

A

120
Q

A security administrator is reviewing the company’s continuity plan. The plan specifies an RTO of
six hours and RPO of two days. Which of the following is the plan describing?
A. Systems should be restored within six hours and no later than two days after the incident.
B. Systems should be restored within two days and should remain operational for at least six hours.
C. Systems should be restored within six hours with a minimum of two days worth of data.
D. Systems should be restored within two days with a minimum of six hours worth of data.

A

C

121
Q

The incident response team has received the following email messagE.
From: monitor@ext-company.com
To: security@company.com
Subject: Copyright infringement
A copyright infringement alert was triggered by IP address 13.10.66.5 at 09: 50: 01 GMT.
After reviewing the following web logs for IP 13.10.66.5, the team is unable to correlate and
identify the incident.
09: 45: 33 13.10.66.5 http: //remote.site.com/login.asp?user=john
09: 50: 22 13.10.66.5 http: //remote.site.com/logout.asp?user=anne
10: 50: 01 13.10.66.5 http: //remote.site.com/access.asp?file=movie.mov
11: 02: 45 13.10.65.5 http: //remote.site.com/download.asp?movie.mov=ok
Which of the following is the MOST likely reason why the incident response team is unable to
identify and correlate the incident?
A. The logs are corrupt and no longer forensically sound.
B. Traffic logs for the incident are unavailable.
C. Chain of custody was not properly maintained.
D. Incident time offsets were not accounted for.

A

D

122
Q

A server dedicated to the storage and processing of sensitive information was compromised with a
rootkit and sensitive data was exfiltrated. Which of the following incident response procedures is
best suited to restore the server?
A. Wipe the storage, reinstall the OS from original media and restore the data from the last known
good backup.
B. Keep the data partition, restore the OS from the most current backup and run a full system
antivirus scan.
C. Format the storage and reinstall both the OS and the data from the most current backup.
D. Erase the storage, reinstall the OS from most current backup and only restore the data that was
not compromised.

A

A

123
Q
Which of the following describes a type of malware which is difficult to reverse engineer in a virtual lab?
A. Armored virus
B. Polymorphic malware
C. Logic bomb
D. Rootkit
A

A

124
Q

Using a heuristic system to detect an anomaly in a computer’s baseline, a system administrator
was able to detect an attack even though the company signature based IDS and antivirus did not
detect it. Further analysis revealed that the attacker had downloaded an executable file onto the
company PC from the USB port, and executed it to trigger a privilege escalation flaw.
Which of the following attacks has MOST likely occurred?
A. Cookie stealing
B. Zero-day
C. Directory traversal
D. XML injection

A

B

125
Q

After copying a sensitive document from his desktop to a flash drive, Joe, a user, realizes that the
document is no longer encrypted. Which of the following can a security technician implement to
ensure that documents stored on Joe’s desktop remain encrypted when moved to external media
or other network based storage?
A. Whole disk encryption
B. Removable disk encryption
C. Database record level encryption
D. File level encryption

A

D

126
Q

A security administrator must implement a system to allow clients to securely negotiate encryption
keys with the company’s server over a public unencrypted communication channel.
Which of the following implements the required secure key negotiation? (Select TWO).
A. PBKDF2
B. Symmetric encryption
C. Steganography
D. ECDHE
E. Diffie-Hellman

A

D E

127
Q

Acme Corp has selectively outsourced proprietary business processes to ABC Services. Due to
some technical issues, ABC services wants to send some of Acme Corp’s debug data to a third
party vendor for problem resolution. Which of the following MUST be considered prior to sending
data to a third party?
A. The data should be encrypted prior to transport
B. This would not constitute unauthorized data sharing
C. This may violate data ownership and non-disclosure agreements
D. Acme Corp should send the data to ABC Services’ vendor instead

A

C

128
Q

An organization has introduced token-based authentication to system administrators due to risk of
password compromise. The tokens have a set of numbers that automatically change every 30
seconds. Which of the following type of authentication mechanism is this?
A. TOTP
B. Smart card
C. CHAP
D. HOTP

A

A

129
Q

A security technician at a small business is worried about the Layer 2 switches in the network
suffering from a DoS style attack caused by staff incorrectly cabling network connections between
switches.
Which of the following will BEST mitigate the risk if implemented on the switches?
A. Spanning tree
B. Flood guards
C. Access control lists
D. Syn flood

A

A

130
Q

An administrator wants to establish a WiFi network using a high gain directional antenna with a
narrow radiation pattern to connect two buildings separated by a very long distance. Which of the
following antennas would be BEST for this situation?
A. Dipole
B. Yagi
C. Sector
D. Omni

A

B

131
Q

An attacker used an undocumented and unknown application exploit to gain access to a file
server. Which of the following BEST describes this type of attack?
A. Integer overflow
B. Cross-site scripting
C. Zero-day
D. Session hijacking
E. XML injection

A

C

132
Q

Which of the following is an XML based open standard used in the exchange of authentication and
authorization information between different parties?
A. LDAP
B. SAML
C. TACACS+
D. Kerberos

A

B

133
Q

Which of the following ports and protocol types must be opened on a host with a host-based
firewall to allow incoming SFTP connections?
A. 21/UDP
B. 21/TCP
C. 22/UDP
D. 22/TCP

A

D

134
Q

A user, Ann, is reporting to the company IT support group that her workstation screen is blank
other than a window with a message requesting payment or else her hard drive will be formatted.
Which of the following types of malware is on Ann’s workstation?
A. Trojan
B. Spyware
C. Adware
D. Ransomware

A

D

135
Q

Which of the following controls can be implemented together to prevent data loss in the event of
theft of a mobile device storing sensitive information? (Select TWO).
A. Full device encryption
B. Screen locks
C. GPS
D. Asset tracking
E. Inventory control

A

A B

136
Q

A way to assure data at-rest is secure even in the event of loss or theft is to use:
A. Full device encryption.
B. Special permissions on the file system.
C. Trusted Platform Module integration.
D. Access Control Lists.

A

A

137
Q

A security audit identifies a number of large email messages being sent by a specific user from
their company email account to another address external to the company. These messages were
sent prior to a company data breach, which prompted the security audit. The user was one of a
few people who had access to the leaked data. Review of the suspect’s emails show they consist
mostly of pictures of the user at various locations during a recent vacation. No suspicious activities
from other users who have access to the data were discovered.
Which of the following is occurring?
A. The user is encrypting the data in the outgoing messages.
B. The user is using steganography.
C. The user is spamming to obfuscate the activity.
D. The user is using hashing to embed data in the emails.

A

B

138
Q
A security analyst is reviewing firewall logs while investigating a compromised web server. The
following ports appear in the log:
22, 25, 445, 1433, 3128, 3389, 6667
Which of the following protocols was used to access the server remotely?
A. LDAP
B. HTTP
C. RDP
D. HTTPS
A

C

139
Q

An organization does not want the wireless network name to be easily discovered. Which of the
following software features should be configured on the access points?
A. SSID broadcast
B. MAC filter
C. WPA2
D. Antenna placement

A

A

140
Q

A computer is suspected of being compromised by malware. The security analyst examines the
computer and finds that a service called Telnet is running and connecting to an external website
over port 443. This Telnet service was found by comparing the system’s services to the list of
standard services on the company’s system image. This review process depends on:
A. MAC filtering.
B. System hardening.
C. Rogue machine detection.
D. Baselining.

A

D

141
Q

A software developer wants to prevent stored passwords from being easily decrypted. When the
password is stored by the application, additional text is added to each password before the
password is hashed. This technique is known as:
A. Symmetric cryptography.
B. Private key cryptography.
C. Salting.
D. Rainbow tables.

A

C

142
Q

In which of the following steps of incident response does a team analyze the incident and
determine steps to prevent a future occurrence?
A. Mitigation
B. Identification
C. Preparation
D. Lessons learned

A

D

143
Q

A security technician has been asked to recommend an authentication mechanism that will allow
users to authenticate using a password that will only be valid for a predefined time interval. Which
of the following should the security technician recommend?
A. CHAP
B. TOTP
C. HOTP
D. PAP

A

B

144
Q

A security administrator must implement a wireless encryption system to secure mobile devices’
communication. Some users have mobile devices which only support 56-bit encryption. Which of
the following wireless encryption methods should be implemented?
A. RC4
B. AES
C. MD5
D. TKIP

A

A

145
Q

After a security incident involving a physical asset, which of the following should be done at the
beginning?
A. Record every person who was in possession of assets, continuing post-incident.
B. Create working images of data in the following order: hard drive then RAM.
C. Back up storage devices so work can be performed on the devices immediately.
D. Write a report detailing the incident and mitigation suggestions.

A

A

146
Q

Which of the following is the GREATEST security risk of two or more companies working together
under a Memorandum of Understanding?
A. Budgetary considerations may not have been written into the MOU, leaving an entity to absorb
more cost than intended at signing.
B. MOUs have strict policies in place for services performed between the entities and the penalties
for compromising a partner are high.
C. MOUs are generally loose agreements and therefore may not have strict guidelines in place to
protect sensitive data between the two entities.
D. MOUs between two companies working together cannot be held to the same legal standards as
SLAs.

A

C

147
Q

Joe, a user, reports to the system administrator that he is receiving an error stating his certificate
has been revoked. Which of the following is the name of the database repository for these
certificates?
A. CSR
B. OSCP
C. CA
D. CRL

A

D

148
Q

A software company has completed a security assessment. The assessment states that the
company should implement fencing and lighting around the property. Additionally, the assessment
states that production releases of their software should be digitally signed. Given the
recommendations, the company was deficient in which of the following core security areas?
(Select TWO).

A. Fault tolerance
B. Encryption
C. Availability
D. Integrity
E. Safety
F. Confidentiality
A

D E

149
Q

A user was reissued a smart card after the previous smart card had expired. The user is able to
log into the domain but is now unable to send digitally signed or encrypted email. Which of the
following would the user need to perform?
A. Remove all previous smart card certificates from the local certificate store.
B. Publish the new certificates to the global address list.
C. Make the certificates available to the operating system.
D. Recover the previous smart card certificates.

A

B

150
Q

Users are encouraged to click on a link in an email to obtain exclusive access to the newest
version of a popular Smartphone. This is an example of.
A. Scarcity
B. Familiarity
C. Intimidation
D. Trust

A

A

151
Q

Which of the following types of attacks involves interception of authentication traffic in an attempt
to gain unauthorized access to a wireless network?
A. Near field communication
B. IV attack
C. Evil twin
D. Replay attack

A

B

152
Q

Which of the following is a BEST practice when dealing with user accounts that will only need to
be active for a limited time period?
A. When creating the account, set the account to not remember password history.
B. When creating the account, set an expiration date on the account.
C. When creating the account, set a password expiration date on the account.
D. When creating the account, set the account to have time of day restrictions.

A

B

153
Q
Which of the following types of authentication packages user credentials in a ticket?
A. Kerberos
B. LDAP
C. TACACS+
D. RADIUS
A

A

154
Q
Which of the following is required to allow multiple servers to exist on one physical server?
A. Software as a Service (SaaS)
B. Platform as a Service (PaaS)
C. Virtualization
D. Infrastructure as a Service (IaaS)
A

C

155
Q

Several employees submit the same phishing email to the administrator. The administrator finds
that the links in the email are not being blocked by the company’s security device. Which of the
following might the administrator do in the short term to prevent the emails from being received?
A. Configure an ACL
B. Implement a URL filter
C. Add the domain to a block list
D. Enable TLS on the mail server

A

C

156
Q

A company has several conference rooms with wired network jacks that are used by both
employees and guests. Employees need access to internal resources and guests only need
access to the Internet. Which of the following combinations is BEST to meet the requirements?
A. NAT and DMZ
B. VPN and IPSec
C. Switches and a firewall
D. 802.1x and VLANs

A

D

157
Q

LDAP and Kerberos are commonly used for which of the following?
A. To perform queries on a directory service
B. To store usernames and passwords for Federated Identity
C. To sign SSL wildcard certificates for subdomains
D. To utilize single sign-on capabilities

A

D

158
Q
An administrator needs to renew a certificate for a web server. Which of the following should be
submitted to a CA?
A. CSR
B. Recovery agent
C. Private key
D. CRL
A

A

159
Q

An administrator needs to submit a new CSR to a CA. Which of the following is a valid FIRST
step?
A. Generate a new private key based on AES.
B. Generate a new public key based on RSA.
C. Generate a new public key based on AES.
D. Generate a new private key based on RSA.

A

D

160
Q

The security team would like to gather intelligence about the types of attacks being launched
against the organization. Which of the following would provide them with the MOST information?
A. Implement a honeynet
B. Perform a penetration test
C. Examine firewall logs
D. Deploy an IDS

A

A

161
Q

After recovering from a data breach in which customer data was lost, the legal team meets with
the Chief Security Officer (CSO) to discuss ways to better protect the privacy of customer data.
Which of the following controls support this goal?
A. Contingency planning
B. Encryption and stronger access control
C. Hashing and non-repudiation
D. Redundancy and fault tolerance

A

B

162
Q

A security engineer, Joe, has been asked to create a secure connection between his mail server
and the mail server of a business partner. Which of the following protocol would be MOST appropriate?
A. HTTPS
B. SSH
C. FTP
D. TLS

A

D

163
Q

A new network administrator is setting up a new file server for the company. Which of the following
would be the BEST way to manage folder security?
A. Assign users manually and perform regular user access reviews
B. Allow read only access to all folders and require users to request permission
C. Assign data owners to each folder and allow them to add individual users to each folder
D. Create security groups for each folder and assign appropriate users to each group

A

D

164
Q

A recent vulnerability scan found that Telnet is enabled on all network devices. Which of the
following protocols should be used instead of Telnet?
A. SCP
B. SSH
C. SFTP
D. SSL

A

B

165
Q

A network engineer is setting up a network for a company. There is a BYOD policy for the
employees so that they can connect their laptops and mobile devices.
Which of the following technologies should be employed to separate the administrative network
from the network in which all of the employees’ devices are connected?
A. VPN
B. VLAN
C. WPA2
D. MAC filtering

A

B

166
Q

A network administrator is asked to send a large file containing PII to a business associate.
Which of the following protocols is the BEST choice to use?
A. SSH
B. SFTP
C. SMTP
D. FTP

A

B

167
Q

When performing the daily review of the system vulnerability scans of the network Joe, the
administrator, noticed several security related vulnerabilities with an assigned vulnerability
identification number. Joe researches the assigned vulnerability identification number from the
vendor website. Joe proceeds with applying the recommended solution for identified vulnerability.
Which of the following is the type of vulnerability described?
A. Network based
B. IDS
C. Signature based
D. Host based

A

C

168
Q

A malicious individual is attempting to write too much data to an application’s memory. Which of
the following describes this type of attack?
A. Zero-day
B. SQL injection
C. Buffer overflow
D. XSRF

A

C

169
Q

Ann, a security administrator, wishes to replace their RADIUS authentication with a more secure
protocol, which can utilize EAP. Which of the following would BEST fit her objective?
A. CHAP
B. SAML
C. Kerberos
D. Diameter

A

D

170
Q

Ann, a security administrator, has concerns regarding her company’s wireless network. The
network is open and available for visiting prospective clients in the conference room, but she
notices that many more devices are connecting to the network than should be.
Which of the following would BEST alleviate Ann’s concerns with minimum disturbance of current
functionality for clients?
A. Enable MAC filtering on the wireless access point.
B. Configure WPA2 encryption on the wireless access point.
C. Lower the antenna’s broadcasting power.
D. Disable SSID broadcasting.

A

C

171
Q

A distributed denial of service attack can BEST be described as:
A. Invalid characters being entered into a field in a database application.
B. Users attempting to input random or invalid data into fields within a web browser application.
C. Multiple computers attacking a single target in an organized attempt to deplete its resources.
D. Multiple attackers attempting to gain elevated privileges on a target system.

A

C

172
Q

Joe analyzed the following log and determined the security team should implement which of the
following as a mitigation method against further attempts?
Host 192.168.1.123
[00: 00: 01]Successful Login: 015 192.168.1.123 : local
[00: 00: 03]Unsuccessful Login: 022 214.34.56.006 : RDP 192.168.1.124
[00: 00: 04]UnSuccessful Login: 010 214.34.56.006 : RDP 192.168.1.124
[00: 00: 07]UnSuccessful Login: 007 214.34.56.006 : RDP 192.168.1.124
[00: 00: 08]UnSuccessful Login: 003 214.34.56.006 : RDP 192.168.1.124
A. Reporting
B. IDS
C. Monitor system logs
D. Hardening

A

D

173
Q
A computer supply company is located in a building with three wireless networks. The system
security team implemented a quarterly security scan and saw the following.
SSID State Channel Level
Computer AreUs1 connected 1 70dbm
Computer AreUs2 connected 5 80dbm
Computer AreUs3 connected 3 75dbm
Computer AreUs4 connected 6 95dbm
Which of the following is this an example of?
A. Rogue access point
B. Near field communication
C. Jamming
D. Packet sniffing
A

AA

174
Q

A systems administrator has implemented PKI on a classified government network. In the event
that a disconnect occurs from the primary CA, which of the following should be accessible locally
from every site to ensure users with bad certificates cannot gain access to the network?
A. A CRL
B. Make the RA available
C. A verification authority
D. A redundant CA

A

D

175
Q

While configuring a new access layer switch, the administrator, Joe, was advised that he needed
to make sure that only devices authorized to access the network would be permitted to login and
utilize resources. Which of the following should the administrator implement to ensure this
happens?
A. Log Analysis
B. VLAN Management
C. Network separation
D. 802.1x

A

D

176
Q
A vulnerability assessment indicates that a router can be accessed from default port 80 and
default port 22. Which of the following should be executed on the router to prevent access via
these ports? (Select TWO).
A. FTP service should be disabled
B. HTTPS service should be disabled
C. SSH service should be disabled
D. HTTP service should disabled
E. Telnet service should be disabled
A

C D

177
Q

Results from a vulnerability analysis indicate that all enabled virtual terminals on a router can be
accessed using the same password. The company’s network device security policy mandates that
at least one virtual terminal have a different password than the other virtual terminals. Which of the
following sets of commands would meet this requirement?
A. line vty 0 6 P@s5W0Rd password line vty 7 Qwer++!Y password
B. line console 0 password password line vty 0 4 password P@s5W0Rd
C. line vty 0 3 password Qwer++!Y line vty 4 password P@s5W0Rd
D. line vty 0 3 password Qwer++!Y line console 0 password P@s5W0Rd

A

C

178
Q

Joe, an employee, was escorted from the company premises due to suspicion of revealing trade
secrets to a competitor. Joe had already been working for two hours before leaving the premises.
A security technician was asked to prepare a report of files that had changed since last night’s
integrity scan. Which of the following could the technician use to prepare the report? (Select TWO).
A. PGP
B. MD5
C. ECC
D. AES
E. Blowfish
F. HMAC

A

B F

179
Q
Ann has read and write access to an employee database, while Joe has only read access. Ann is
leaving for a conference.
Which of the following types of authorization could be utilized to trigger write access for Joe when
Ann is absent?
A. Mandatory access control
B. Role-based access control
C. Discretionary access control
D. Rule-based access control
A

D

180
Q

Human Resources suspects an employee is accessing the employee salary database. The
administrator is asked to find out who it is. In order to complete this task, which of the following is a
security control that should be in place?
A. Shared accounts should be prohibited.
B. Account lockout should be enabled
C. Privileges should be assigned to groups rather than individuals
D. Time of day restrictions should be in use

A

A

181
Q

An administrator finds that non-production servers are being frequently compromised, production
servers are rebooting at unplanned times and kernel versions are several releases behind the
version with all current security fixes. Which of the following should the administrator implement?
A. Snapshots
B. Sandboxing
C. Patch management
D. Intrusion detection system

A

C

182
Q

An auditor’s report discovered several accounts with no activity for over 60 days. The accounts
were later identified as contractors’ accounts who would be returning in three months and would
need to resume the activities. Which of the following would mitigate and secure the auditors
finding?
A. Disable unnecessary contractor accounts and inform the auditor of the update.
B. Reset contractor accounts and inform the auditor of the update.
C. Inform the auditor that the accounts belong to the contractors.
D. Delete contractor accounts and inform the auditor of the update.

A

A

183
Q

Ann, the security administrator, wishes to implement multifactor security. Which of the following
should be implemented in order to compliment password usage and smart cards?
A. Hard tokens
B. Fingerprint readers
C. Swipe badge readers
D. Passphrases

A

B

184
Q

Customers’ credit card information was stolen from a popular video streaming company. A security
consultant determined that the information was stolen, while in transit, from the gaming consoles
of a particular vendor. Which of the following methods should the company consider to secure this
data in the future?
A. Application firewalls
B. Manual updates
C. Firmware version control
D. Encrypted TCP wrappers

A

A

185
Q

A new intern was assigned to the system engineering department, which consists of the system
architect and system software developer’s teams. These two teams have separate privileges. The
intern requires privileges to view the system architectural drawings and comment on some
software development projects. Which of the following methods should the system administrator
implement?
A. Group based privileges
B. Generic account prohibition
C. User access review
D. Credential management

A

A

186
Q

One of the system administrators at a company is assigned to maintain a secure computer lab.
The administrator has rights to configure machines, install software, and perform user account
maintenance. However, the administrator cannot add new computers to the domain, because that
requires authorization from the Information Assurance Officer. This is an example of which of the
following?
A. Mandatory access
B. Rule-based access control
C. Least privilege
D. Job rotation

A

C

187
Q

A small business needs to incorporate fault tolerance into their infrastructure to increase data
availability. Which of the following options would be the BEST solution at a minimal cost?
A. Clustering
B. Mirrored server
C. RAID
D. Tape backup

A

C

188
Q

A new application needs to be deployed on a virtual server. The virtual server hosts a SQL server
that is used by several employees.
Which of the following is the BEST approach for implementation of the new application on the
virtual server?
A. Take a snapshot of the virtual server after installing the new application and store the snapshot
in a secure location.
B. Generate a baseline report detailing all installed applications on the virtualized server after
installing the new application.
C. Take a snapshot of the virtual server before installing the new application and store the
snapshot in a secure location.
D. Create an exact copy of the virtual server and store the copy on an external hard drive after
installing the new application.

A

C

189
Q
Ann wants to send a file to Joe using PKI. Which of the following should Ann use in order to sign
the file?
A. Joe’s public key
B. Joe’s private key
C. Ann’s public key
D. Ann’s private key
A

D

190
Q

Which of the following protocols is used to validate whether trust is in place and accurate by
returning responses of either “good”, “unknown”, or “revoked”?
A. CRL
B. PKI
C. OCSP
D. RA

A

C

191
Q

During a recent investigation, an auditor discovered that an engineer’s compromised workstation
was being used to connect to SCADA systems while the engineer was not logged in. The engineer
is responsible for administering the SCADA systems and cannot be blocked from connecting to
them. The SCADA systems cannot be modified without vendor approval which requires months of
testing.
Which of the following is MOST likely to protect the SCADA systems from misuse?
A. Update anti-virus definitions on SCADA systems
B. Audit accounts on the SCADA systems
C. Install a firewall on the SCADA network
D. Deploy NIPS at the edge of the SCADA network

A

D

192
Q

A security administrator must implement a network authentication solution which will ensure
encryption of user credentials when users enter their username and password to authenticate to
the network.
Which of the following should the administrator implement?
A. WPA2 over EAP-TTLS
B. WPA-PSK
C. WPA2 with WPS
D. WEP over EAP-PEAP

A

D

193
Q

Several employees have been printing files that include personally identifiable information of
customers. Auditors have raised concerns about the destruction of these hard copies after they
are created, and management has decided the best way to address this concern is by preventing
these files from being printed.
Which of the following would be the BEST control to implement?
A. File encryption
B. Printer hardening
C. Clean desk policies
D. Data loss prevention

A

D

194
Q

The company’s sales team plans to work late to provide the Chief Executive Officer (CEO) with a
special report of sales before the quarter ends. After working for several hours, the team finds they
cannot save or print the reports.
Which of the following controls is preventing them from completing their work?
A. Discretionary access control
B. Role-based access control
C. Time of Day access control
D. Mandatory access control

A

C

195
Q
A security engineer is asked by the company’s development team to recommend the most secure
method for password storage.
Which of the following provide the BEST protection against brute forcing stored passwords?
(Select TWO).
A. PBKDF2
B. MD5
C. SHA2
D. Bcrypt
E. AES
F. CHAP
A

A D

196
Q

After entering the following information into a SOHO wireless router, a mobile device’s user
reports being unable to connect to the network:
PERMIT 0A: D1: FA. B1: 03: 37
DENY 01: 33: 7F: AB: 10: AB
Which of the following is preventing the device from connecting?
A. WPA2-PSK requires a supplicant on the mobile device.
B. Hardware address filtering is blocking the device.
C. TCP/IP Port filtering has been implemented on the SOHO router.
D. IP address filtering has disabled the device from connecting.

A

B

197
Q

The call center supervisor has reported that many employees have been playing preinstalled
games on company computers and this is reducing productivity.
Which of the following would be MOST effective for preventing this behavior?
A. Acceptable use policies
B. Host-based firewalls
C. Content inspection
D. Application whitelisting

A

D

198
Q
When creating a public / private key pair, for which of the following ciphers would a user need to
specify the key strength?
A. SHA
B. AES
C. DES
D. RSA
A

D

199
Q

A company has decided to move large data sets to a cloud provider in order to limit the costs of
new infrastructure. Some of the data is sensitive and the Chief Information Officer wants to make
sure both parties have a clear understanding of the controls needed to protect the data.
Which of the following types of interoperability agreement is this?
A. ISA
B. MOU
C. SLA
D. BPA

A

A

200
Q
Which of the following solutions provides the most flexibility when testing new security controls
prior to implementation?
A. Trusted OS
B. Host software baselining
C. OS hardening
D. Virtualization
A

D