Info Security Questions

5 September 2022
4.7 (114 reviews)
120 test answers

Unlock all answers in this set

Unlock answers (116)
question
The System/Application Domain holds all the mission-critical systems, applications, and data.
answer
True
question
The director of IT security is generally in charge of ensuring that the Workstation Domain conforms to policy.
answer
True
question
Which mitigation plan is most appropriate to limit the risk of unauthorized access to workstations?
answer
Password protection
question
Which one of the following measures the average amount of time that it takes to repair a system, application, or component?
answer
Mean time to repair (MTTR)
question
Which risk is most effectively mitigated by an upstream Internet service provider (ISP)?
answer
Distributed denial of service (DDoS)
question
Which network device is capable of blocking network connections that are identified as potentially malicious?
answer
Intrusion prevention system (IPS)
question
The most critical aspect of a WAN services contract is how the service provider supplies troubleshooting, network management, and security management services.
answer
True
question
For businesses and organizations under recent compliance laws, data classification standards typically include private, confidential, internal use only, and public domain categories.
answer
True
question
Juans web server was down for an entire day last September. It experienced no other downtime during that month. Which one of the following represents the web server uptime for that month?
answer
96.67%
question
Which element of the security policy framework offers suggestions rather than mandatory actions?
answer
Guideline
question
Networks, routers, and equipment require continuous monitoring and management to keep wide area network (WAN) service available.
answer
True
question
Which security control is most helpful in protecting against eavesdropping on wireless LAN (WLAN) data transmissions that would jeopardize confidentiality?
answer
Applying strong encryption
question
In the Remote Access Domain, if private data or confidential data is compromised remotely, you should set automatic blocking for attempted logon retries.
answer
False
question
Which element of the security policy framework requires approval from upper management and applies to the entire organization?
answer
Policy
question
Which one of the following is NOT a good technique for performing authentication of an end user?
answer
Identification number
question
The asset protection policy defines an organizations data classification standard.
answer
False
question
Which term describes any action that could damage an asset?
answer
Threat
question
Matthew captures traffic on his network and notices connections using ports 20, 22, 23, and 80. Which port normally hosts a protocol that uses secure, encrypted connections?
answer
22
question
Which one of the following is typically used during the identification phase of a remote access connection?
answer
Username
question
The weakest link in the security of an IT infrastructure is the server.
answer
False
question
Jody would like to find a solution that allows real-time document sharing and editing between teams. Which technology would best suit her needs?
answer
Collaboration
question
Gwens company is planning to accept credit cards over the Internet. Which one of the following governs this type of activity and includes provisions that Gwen should implement before accepting credit card transactions?
answer
Payment Card Industry Data Security Standard (PCI DSS)
question
Which one of the following governs the use of Internet of Things (IoT) by healthcare providers, such as physicians and hospitals?
answer
Health Insurance Portability and Accountability Act (HIPAA)
question
Which one of the following is NOT a market driver for the Internet of Things (IoT)?
answer
Global adoption of non-IP networking
question
Which one of the following is NOT an example of store-and- forward messaging?
answer
Telephone call
question
With the use of Mobile IP, which device is responsible for keeping track of mobile nodes (MNs) and forwarding packets to the MNs current network?
answer
Home agent (HA)
question
Which technology can be used to protect the privacy rights of individuals and simultaneously allow organizations to analyze data in aggregate?
answer
Deidentification
question
Which Internet of Things (IoT) challenge involves the difficulty of developing and implementing protocols that allow devices to communicate in a standard fashion?
answer
Interoperability
question
Which organization pursues standards for Internet of Things (IoT) devices and is widely recognized as the authority for creating standards on the Internet?
answer
Internet Engineering Task Force
question
Which one of the following is an example of a business-to- consumer (B2C) application of the Internet of Things (IoT)?
answer
Health monitoring
question
Kairas company recently switched to a new calendaring system provided by a vendor. Kaira and other users connect to the system, hosted at the vendors site, using a web browser. Which service delivery model is Kairas company using?
answer
Software as a Service (SaaS)
question
In Mobile IP, what term describes a device that would like to communicate with a mobile node (MN)?
answer
Correspondent node (CN)
question
From a security perspective, what should organizations expect will occur as they become more dependent upon the Internet of Things (IoT)?
answer
Security risks will increase.
question
Which compliance obligation includes security requirements that apply specifically to federal government agencies in the United States?
answer
Federal Information Security Management Act (FISMA)
question
Which scenario presents a unique challenge for developers of mobile applications?
answer
Selecting multiple items from a list
question
Which one of the following is an advantage that the Internet of Things (IoT) brings to economic development for countries?
answer
Technical and industry development
question
Which of the following is NOT one of the four fundamental principles outlined by the Internet Society that will drive the success of Internet of Things (IoT) innovation?
answer
Secure
question
Which action is the best step to protect Internet of Things (IoT) devices from becoming the entry point for security vulnerabilities into a network while still meeting business requirements?
answer
Applying security updates promptly
question
Which one of the following is NOT an area of critical infrastructure where the Internet of Things (IoT) is likely to spur economic development in less developed countries?
answer
E-commerce
question
Ron is the IT director at a medium-sized company and is constantly bombarded by requests from users who want to select customized mobile devices. He decides to allow users to purchase their own devices. Which type of policy should Ron implement to include the requirements and security controls for this arrangement?
answer
Bring Your Own Device (BYOD)
question
Tony is working with a law enforcement agency to place a wiretap pursuant to a legitimate court order. The wiretap will monitor communications without making any modifications. What type of wiretap is Tony placing?
answer
Passive wiretap
question
Brian notices an attack taking place on his network. When he digs deeper, he realizes that the attacker has a physical presence on the local network and is forging Media Access Control (MAC) addresses. Which type of attack is most likely taking place?
answer
Address Resolution Protocol (ARP) poisoning
question
Florian recently purchased a set of domain names that are similar to those of legitimate websites and used the newly purchased sites to host malware. Which type of attack is Florian using?
answer
Typosquatting
question
Which type of attack involves the creation of some deception in order to trick unsuspecting users?
answer
Fabrication
question
Yuri is a skilled computer security expert who attempts to break into the systems belonging to his clients. He has permission from the clients to perform this testing as part of a paid contract. What type of person is Yuri?
answer
White-hat hacker
question
Marias company recently experienced a major system outage due to the failure of a critical component. During that time period, the company did not register any sales through its online site. Which type of loss did the company experience as a result of lost sales?
answer
Opportunity cost
question
Which control is not designed to combat malware?
answer
Firewalls
question
An attacker attempting to break into a facility pulls the fire alarm to distract the security guard manning an entry point. Which type of social engineering attack is the attacker using?
answer
Urgency
question
Which type of denial of service attack exploits the existence of software flaws to disrupt a service?
answer
Logic attack
question
Which password attack is typically used specifically against password files that contain cryptographic hashes?
answer
Birthday attacks
question
Which one of the following is an example of a disclosure threat?
answer
Espionage
question
Which term describes an action that can damage or compromise an asset?
answer
Threat
question
Users throughout Alisons organization have been receiving unwanted commercial messages over the organizations instant messaging program. What type of attack is taking place?
answer
Spim
question
What type of malicious software masquerades as legitimate software to entice the user to run it?
answer
Trojan horse
question
In which type of attack does the attacker attempt to take over an existing connection between two systems?
answer
Session hijacking
question
Which type of attack against a web application uses a newly discovered vulnerability that is not patchable?
answer
Zero-day attack
question
Bob is using a port scanner to identify open ports on a server in his environment. He is scanning a web server that uses Hypertext Transfer Protocol (HTTP). Which port should Bob expect to be open to support this service?
answer
80
question
Which tool can capture the packets transmitted between systems over a network?
answer
Protocol analyzer
question
Barry discovers that an attacker is running an access point in a building adjacent to his company. The access point is broadcasting the security set identifier (SSID) of an open network owned by the coffee shop in his lobby. Which type of attack is likely taking place?
answer
Evil twin
question
Which group is the most likely target of a social engineering attack?
answer
Receptionists and administrative assistants
question
What is NOT a common motivation for attackers?
answer
Fear
question
What ISO security standard can help guide the creation of an organizations security policy?
answer
27002
question
Gwen is investigating an attack. An intruder managed to take over the identity of a user who was legitimately logged into Gwens companys website by manipulating Hypertext Transfer Protocol (HTTP) headers. Which type of attack likely took place?
answer
Session hijacking
question
Alison discovers that a system under her control has been infected with malware, which is using a key logger to report user keystrokes to a third party. What information security property is this malware attacking?
answer
Confidentiality
question
The CEO of Kellys company recently fell victim to an attack. The attackers sent the CEO an email informing him that his company was being sued and he needed to view a subpoena at a court website. When visiting the website, malicious code was downloaded onto the CEOs computer. What type of attack took place?
answer
Spear phishing
question
Bob is developing a web application that depends upon a database backend. What type of attack could a malicious individual use to send commands through his web application to the database?
answer
SQL injection
question
Which type of virus targets computer hardware and software startup functions?
answer
System infector
question
Larry recently viewed an auction listing on a website. As a result, his computer executed code that popped up a window that asked for his password. What type of attack has Larry likely encountered?
answer
Cross-site scripting (XSS)
question
What type of system is intentionally exposed to attackers in an attempt to lure them out?
answer
Honeypot
question
What tool might be used by an attacker during the reconnaissance phase of an attack to glean information about domain registrations?
answer
Whois
question
What is NOT a typical sign of virus activity on a system?
answer
Unexpected power failures
question
Val would like to limit the websites that her users visit to those on an approved list of pre-cleared sites. What type of approach is Val advocating?
answer
Whitelisting
question
What type of malicious software allows an attacker to remotely control a compromised computer?
answer
Remote Access Tool (RAT)
question
What program, released in 2013, is an example of ransomware?
answer
Crypt0L0cker
question
Yolanda would like to prevent attackers from using her network as a relay point for a smurf attack. What protocol should she block?
answer
Internet Control Message Protocol (ICMP)
question
Adam discovers a virus on his system that is using encryption to modify itself. The virus escapes detection by signature-based antivirus software. What type of virus has he discovered?
answer
Polymorphic virus
question
What file type is least likely to be impacted by a file infector virus?
answer
.docx
question
Brian would like to conduct a port scan against his systems to determine how they look from an attackers viewpoint. What tool can he use for this purpose?
answer
Nmap
question
What is NOT one of the four main purposes of an attack?
answer
Data import
question
Breannes system was infected by malicious code after she installed an innocent-looking solitaire game that she downloaded from the Internet. What type of malware did she likely encounter?
answer
Trojan horse
question
Alice would like to send a message to Bob securely and wishes to encrypt the contents of the message. What key does she use to encrypt this message?
answer
Bobs public key
question
Which information security objective allows trusted entities to endorse information?
answer
Certification
question
Which set of characteristics describes the Caesar cipher accurately?
answer
Symmetric, stream, substitution
question
Which type of cipher works by rearranging the characters in a message?
answer
Transposition
question
What type of function generates the unique value that corresponds to the contents of a message and is used to create a digital signature?
answer
Hash
question
Bob received a message from Alice that contains a digital signature. What cryptographic key does Bob use to verify the digital signature?
answer
Alices public key
question
Which approach to cryptography provides the strongest theoretical protection?
answer
Quantum cryptography
question
Alice would like to send a message to Bob using a digital signature. What cryptographic key does Alice use to create the digital signature?
answer
Alices private key
question
Which of the following allows a certificate authority (CA) to revoke a compromised digital certificate in real time?
answer
Online Certificate Status Protocol (OCSP)
question
What is the only unbreakable cipher when it is used properly?
answer
Vernam
question
What is NOT a symmetric encryption algorithm?
answer
Rivest-Shamir- Adelman (RSA)
question
When Patricia receives a message from Gary, she wants to be able to demonstrate to Sue that the message actually came from Gary. What goal of cryptography is Patricia attempting to achieve?
answer
Nonrepudiation
question
What standard is NOT secure and should never be used on modern wireless networks?
answer
Wired Equivalent Privacy (WEP)
question
Which cryptographic attack offers cryptanalysts the most information about how an encryption algorithm works?
answer
Chosen plaintext
question
Gary is sending a message to Patricia. He wants to ensure that nobody tampers with the message while it is in transit. What goal of cryptography is Gary attempting to achieve?
answer
Integrity
question
Alice and Bob would like to communicate with each other using a session key but they do not already have a shared secret key. Which algorithm can they use to exchange a secret key?
answer
Diffie-Hellman
question
What is NOT a valid encryption key length for use with the Blowfish algorithm?
answer
512 bits
question
What mathematical problem forms the basis of most modern cryptographic algorithms?
answer
Factoring large primes
question
Betty receives a cipher text message from her colleague Tim. What type of function does Betty need to use to read the plaintext message?
answer
Decryption
question
What is NOT an effective key distribution method for plaintext encryption keys?
answer
Unencrypted email
question
Bob has a high-volume virtual private network (VPN). He would like to use a device that would best handle the required processing power. What type of device should he use?
answer
VPN concentrator
question
Hilda is troubleshooting a problem with the encryption of data. At which layer of the OSI Reference Model is she working?
answer
Presentation
question
Gary is configuring a Smartphone and is selecting a wireless connectivity method. Which approach will provide him with the highest speed wireless connectivity?
answer
Wi-Fi
question
What type of network device normally connects directly to endpoints and uses MAC-based filtering to limit traffic flows?
answer
Switch
question
Val would like to isolate several systems belonging to the product development group from other systems on the network, without adding new hardware. What technology can she use?
answer
Virtual LAN (VLAN)
question
Terry is troubleshooting a network that is experiencing high traffic congestion issues. Which device, if present on the network, should be replaced to alleviate these issues?
answer
Hub
question
What is NOT a service commonly offered by unified threat management (UTM) devices?
answer
Wireless network access
question
What type of network connects systems over the largest geographic area?
answer
Wide area network (WAN)
question
What firewall approach is shown in the figure?
answer
Screened subnet
question
Henrys last firewall rule must allow inbound access to a Windows Terminal Server. What port must he allow?
answer
3389
question
What wireless security technology contains significant flaws and should never be used?
answer
Wired Equivalent Privacy (WEP)
question
What type of firewall security feature limits the volume of traffic from individual hosts?
answer
Flood guard
question
Karen would like to use a wireless authentication technology similar to that found in hotels where users are redirected to a webpage when they connect to the network. What technology should she deploy?
answer
Captive portal
question
Barbara is investigating an attack against her network. She notices that the Internet Control Message Protocol (ICMP) echo replies coming into her network far exceed the ICMP echo requests leaving her network. What type of attack is likely taking place?
answer
Smurf
question
What is the maximum value for any octet in an IPv4 IP address?
answer
255
question
Henry is creating a firewall rule that will allow inbound mail to the organization. What TCP port must he allow through the firewall?
answer
25
question
Henry would like to create a different firewall rule that allows encrypted web traffic to reach a web server. What port is used for that communication?
answer
443
question
Norm recently joined a new organization. He noticed that the firewall technology used by his new firm opens separate connections between the devices on both sides of the firewall. What type of technology is being used?
answer
Application proxying
question
What protocol is responsible for assigning IP addresses to hosts on most networks?
answer
Dynamic Host Configuration Protocol (DHCP)
question
David would like to connect a fibre channel storage device to systems over a standard data network. What protocol can he use?
answer
Fibre Channel over Ethernet (FCoE)