1/239
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Vittoria is working on her computer information systems degree at a local college and has started researching information security positions. Because she has no prior experience, which of the following positions would Vittoria most likely be offered?
a. security administrator
b. security technician
c. security officer
d. security manager
b. security technician
A security technician position is generally an entry-level position for a person who has the necessary technical skills. Technicians provide technical support to configure security hardware, implement security software, and diagnose and troubleshoot problems.
Which of the following is false about the CompTIA Security+ certification?
a. Security+ is one of the most widely acclaimed security certifications.
b. Security+ is internationally recognized as validating a foundation level of security skills and knowledge.
c. The Security+ certification is a vendor-neutral credential.
d. Professionals who hold the Security+ certification earn about the same or slightly less than security professionals who have not achieved this certification
d. Professionals who hold the Security+ certification earn about the same or slightly less than security professionals who have not achieved this certification.
When hiring workers for cybersecurity positions, an overwhelming majority of enterprises use the Computing Technology Industry Association (CompTIA) Security+ certification to verify security competency. Of the hundreds of security certifications currently available, Security+ is one of the most widely acclaimed security certifications. Because it is internationally recognized as validating a foundation level of security skills and knowledge, the Security+ certification has become the security baseline for today's IT security professionals.
Ginevra is explaining to her roommate the relationship between security and convenience. Which statement most accurately indicates this relationship?
a. Security and convenience are directly proportional.
b. Security and convenience have no relationship.
c. Any proportions between security and convenience depends on the type of attack.
d. Security and convenience are inversely proportional.
d. Security and convenience are inversely proportional.
It is important to understand the relationship between security and convenience. The relationship between these two is not directly proportional (as security is increased, convenience is increased) but, instead, it is completely the opposite, known as inversely proportional (as security is increased, convenience is decreased).
Serafina is studying to take the Security+ certification exam. Which of the following of the CIA elements ensures that only authorized parties can view protected information?
a. confidentiality
b. integrity
c. availability
d. credentiality
a. confidentiality
It is important that only approved individuals are able to access sensitive information. For example, the credit card number used to make an online purchase must be kept secure and not made available to other parties. Confidentiality ensures that only authorized parties can view the information. Providing confidentiality can involve several different security tools, ranging from software to encrypt the credit card number stored on the web server to door locks to prevent access to those servers.
Which of the following AAA elements is applied immediately after a user has logged into a computer with their username and password?
a. authentication
b. authorization
c. identification
d. recording
b. authorization
Authorization, granting permission to take an action, is the next step after authentication. Once users have presented their identification and been authenticated, they can log in to a computer system. Computer users are granted access only to the specific services, devices, applications, and files needed to perform their job duties.
Gia has been asked to enhance the security awareness training workshop for new hires. Which category of security control would Gia be using?
a. managerial
b. technical
c. operational
d. physical
c. operational
Operational controls are implemented and executed by people. One example is conducting workshops to help train users to identify and delete suspicious messages.
Which specific type of control is intended to mitigate (lessen) damage caused by an attack?
a. corrective control
b. compensating control
c. preventive control
d. restrictive control
a. corrective control
A control that is intended to mitigate or lessen the damage caused by the incident is called a corrective control.
Which control is designed to ensure that a particular outcome is achieved by providing incentives?
a. deterrent control
b. incentive control
c. detective control
d. directive control
d. directive control
A directive control is designed to ensure that a particular outcome is achieved. One type of directive control is an incentive, which is the "carrot" instead of the "stick." Incentives are often overlooked as a control, but they can be very powerful.
Which of the following controls is NOT implemented before an attack occurs?
a. detective control
b. deterrent control
c. preventive control
d. directive control
a. detective control
A detective control is used to identify an attack and occurs during an attack.
Complete this definition of information security: That which protects the integrity, confidentiality, and availability of information _____.
a. on electronic digital devices and limited analog devices that can connect via the Internet or through a local area network
b. through a long-term process that results in ultimate security
c. using both open-sourced as well as supplier-sourced hardware and software that interacts appropriately with limited resources
d. through products, people, and procedures on the devices that store, manipulate, and transmit the information
d. through products, people, and procedures on the devices that store, manipulate, and transmit the information
Information security may be defined as that which protects the integrity, confidentiality, and availability of information through products, people, and procedures on the devices that store, manipulate, and transmit the information.
Which of the following groups have the lowest level of technical knowledge for carrying out cyberattacks?
a. unskilled attackers
b. hacktivists
c. nation-state actors
d. organized crime
a. unskilled attackers
Individuals who want to perform attacks yet lack the technical knowledge to carry out these attacks are sometimes called unskilled attackers.
Ilaria is explaining to her parents why information security is the preferred term when talking about security in the enterprise. Which of the following would Ilaria NOT say?
a. Cybersecurity usually involves a range of practices, processes, and technologies intended to protect devices, networks, and programs that process and store data in an electronic form.
b. In a business information may be in any format, from electronic files to paper documents.
c. Cybersecurity is a subset of information security.
d. Information security protects "processed data" or information.
c. Cybersecurity is a subset of information security.
Cybersecurity is considered an overall umbrella term under which information security is found.
Which of the following is not considered an attribute of threat actors?
a. level of sophistication/capability
b. educated/uneducated
c. resources/funding
d. internal/external
b. educated/uneducated
The attributes, or characteristic features, of the different groups of threat actors vary widely. Some groups have a high level of power and complexity (called level of sophistication/capability) and have a massive network of resources, while others are "lone wolves" with minimal skills and no resources. In addition, some groups have deep resources/funding while others have none. And whereas some groups of threat actors may originate from within the enterprise, others are strictly outside (internal/external).
What is considered the motivation of an employee who practices shadow IT?
a. deception
b. ignorance
c. ethical
d. malicious
c. ethical
The process of bypassing corporate approval for technology purchases is known as shadow IT. The employee's motivation is often ethical (it has sound moral principles) but nevertheless weakens security.
Which tool is most commonly associated with nation-state actors?
a. Closed-Source Resistant and Recurrent Malware (CSRRM)
b. Advanced Persistent Threat (APT)
c. Unlimited Harvest and Secure Attack (UHSA)
d. Network Spider and Worm Threat (NSAWT)
b. Advanced Persistent Threat (APT)
Nation-state actors are often involved in multiyear intrusion campaigns targeting highly sensitive economic, proprietary, or national security information. This has created a new class of attacks called Advanced Persistent Threats. These attacks use innovative attack tools (advanced) and once a system is infected it silently extracts data over an extended period of time (persistent). APTs are most commonly associated with nation-state actors.
Flavia is reading about insider threats. Which of the following is NOT true about insider threats?
a. Attacks from an insider threat are hard to recognize.
b. Insider threats are usually dismissed as not being a serious risk.
c. Insider threats often occur because the enterprise is watching for outsiders.
d. Government insiders have stolen large volumes of sensitive information.
b. Insider threats are usually dismissed as not being a serious risk.
Attacks from an insider threat are hard to recognize. This is because the threat actor is already trusted to use the computer system and because they come from within the enterprise, whose focus is watching for outsiders. In recent years, government insiders have stolen large volumes of sensitive information and then published it to alert its citizens of clandestine governmental actions. They can be serious risks for an enterprise.
What is the primary motivation of hacktivists?
a. disruption/chaos
b. financial gain
c. data exfiltration
d. war
a. disruption/chaos
Today many hacktivists work through disinformation campaigns by spreading fake news and supporting conspiracy theories, making their motivation disruption/chaos (to produce extreme confusion).
What is another name for "attack surface"?
a. vulnerability exposure
b. threat vector
c. legacy platform
d. attack floor
b. threat vector
An attack surface, also called a threat vector, is a digital platform that threat actors target for their exploits.
Which of the following is NOT a message-based attack surface?
a. voice calls
b. instant messages
c. texts
d. network protocols
d. network protocols
Due to their popularity and widespread usage, coupled with the fact that the other person's true identity can be easily masked, communication tools are popular threat vectors by attackers. The most common communication tools are message-based and include email, texts, instant messages, and voice calls.
Which of the following is NOT true about supply chains?
a. A supply chain is a network that moves a product from its creation to the end-user.
b. Vendors are the first step in a supply chain.
c. Each link in a supply chain can be a potential attack surface.
d. Hardware providers and software providers are types of supply chains.
b. Vendors are the first step in a supply chain.
A supply chain is typically made up of suppliers (the first step in the chain) that provide the raw materials, manufacturers who convert the material into products, vendors who purchase the products to resell them, warehouses that store products, distribution centers that deliver products to the retailers, and retailers who sell the product ultimately to the consumer.
What is the attack surface of social engineering?
a. manipulation
b. human vectors
c. persuasion
d. deception
b. human vectors
Because social engineering occurs through the exploitation of a person, social engineering is sometimes said to be accomplished using human vectors as the attack surface.
Bjorn just received a phone call in which the person claimed to be a senior vice president demanding that his password be reset, or else Bjorn's supervisor would be contacted about his lack of cooperation. Bjorn was convinced that this was a social engineering attack. Which principle of human manipulation did the attacker attempt on Bjorn?
a. authority
b. fright
c. intimidation
d. urgency
c. intimidation
Intimidation is the principle that attempts to frighten and coerce by threat.
Which of the following is NOT a personal technique used by social engineering attackers to gain the trust of the victim?
a. Provide a reason.
b. Project confidence.
c. Demand compliance.
d. Use evasion and diversion.
c. Demand compliance.
Demanding compliance is forceful and does not gain trust.
Albrecht received a call from a senior vice president of finance who had received a phishing email and had deleted it. What type of phishing attack was this?
a. dolphining
b. harpooning
c. phishing spear
d. whaling
d. whaling
One type of spear phishing is whaling. Instead of going after "little fish" or average users, whaling targets the "big fish," namely, wealthy individuals or senior executives within a business who typically would have larger sums of money in a bank account that an attacker could access. By focusing on this smaller but more lucrative group, the attacker can invest more time in the attack and finely tune the message to achieve the highest likelihood of success.
Tobias received an SMS text that falsely said his bank account was overdrawn and to avoid a $45 fee, he should contact the bank immediately with an explanation. What type of social engineering attack is this?
a. texting attack
b. SMS phishing
c. smishing
d. IM vectoring
c. smishing
An avenue for spreading social engineering attacks uses SMS to send fraudulent text messages. This is known as smishing.
Which of the following is NOT true about BEC?
a. It is decreasing in popularity among threat actors.
b. It takes advantage of electronically making payments or transferring funds.
c. It takes advantage of the size and complexity of large enterprises.
d. It is not limited to businesses.
a. It is decreasing in popularity among threat actors.
One particular type of phishing attack that is increasing in popularity is a BEC.
Which social engineering attack is masquerading as a real or fictitious character and then playing out the role of that person on a target?
a. pretending
b. pretexting
c. impersonation
d. acting
c. impersonation
Social engineering impersonation is masquerading as a real or fictitious character and then playing out the role of that person on a victim.
Wolfgang-Cashman is a new intern at the online company WebHighSchoolStore.com. He has been assigned the task of researching all of the similar domain names to theirs in order to counteract attacks. What is Wolfgang-Cashman combating?
a. mistranslations
b. spimming
c. typo squatting
d. redactioning
c. typo squatting
Fake look-alike sites exist because attackers purchase and register the domain names of sites that are spelled similarly to actual sites. This is called typo squatting.
What is false or inaccurate information that comes from a malicious intent?
a. misinformation
b. half-truths
c. disinformation
d. varication
c. disinformation
Disinformation is false or inaccurate misinformation that comes from a malicious intent.
Which of the following is NOT a type of data reconnaissance?
a. purchasing used technology equipment
b. excel dorking
c. dumpster diving
d. shoulder surfing
b. excel dorking
Google dorking uses advanced Google search techniques to look for information that unsuspecting victims have carelessly posted on the web.
Which type of sensor is most appropriate for monitoring a large warehouse for intruders?
a. microwave sensor
b. IR sensor
c. XG sensor
d. passive RGP sensor
a. microwave sensor
Microwave sensors are especially effective in monitoring large areas such as a warehouse to determine if an intruder has entered a restricted area.
Which of the following statements is NOT true about a pressure sensor?
a. A pressure sensor can differentiate between a car and a person.
b. Modern pressure sensors can differentiate between what has entered and where they are headed.
c. A pressor sensor is a type of management control.
d. A pressure sensor can be used to detect if a person has entered a restricted area.
c. A pressor sensor is a type of management control.
Pressure sensors are a type of physical control, not management control.
Arndt is on a team that is increasing the security in an office. They want to allow anyone to pass by a door but have an alarm sound whenever someone gets too close to the door. Which sensor would Arndt recommend using?
a. IR sensor
b. microwave sensor
c. ultrasonic sensor
d. pressure sensor
c. ultrasonic sensor
For physical security applications, an ultrasonic sensor could be used to allow an individual to be present in an area but sound an alarm if the person moves too close to a door.
Which type of buffer is automated and has two interlocking doors, only one of which can be opened at a time?
a. access control vestibule
b. reception area
c. waiting room
d. vestibule office
a. access control vestibule
An automated access control vestibule is used to create a buffer to separate a nonsecure area from a secure area. A device monitors and controls two interlocking doors to a vestibule. When in operation, only one door can be open at any time.
Milan is on a design team that needs to run a hardened carrier PDS underground between two buildings. What requirement would Milan add to the specifications?
a. It must be buried at least 25 feet below surface level.
b. It can only be used for fiber-optic cables.
c. It must be visually inspected on a weekly basis.
d. It must be encased in concrete.
d. It must be encased in concrete.
If the hardened carrier PDS is buried underground, such as running between buildings, the carrier containing the cables must be encased in concrete.
Which data classification has the highest level of data sensitivity?
a. "eyes-only"
b. sensitive
c. private
d. confidential
d. confidential
Confidential has the highest level of data sensitivity.
Jan is working on classifying data. Some data has been identified that if compromised, the function and mission of the enterprise would be severely impacted. Which data classification should Jan give this data?
a. secret
b. top secret
c. critical
d. classified
c. critical
Critical data is identified as data that if it were compromised, the function and mission of the enterprise would be severely impacted.
Which type of data is hospital patient information protected by HIPAA?
a. restricted data
b. regulated data
c. secure data
d. private data
b. regulated data
Regulated data is that which external stipulations are placed on regarding who can see and use the data and in what contexts. Examples of regulated data include PHI, which is data about a person's health status, provision of health care, or payment for health care, and is regulated by HIPAA.
JSON and XML would be classified as which type of data?
a. compiled data
b. lightweight data
c. schematic data
d. non-human-readable data
d. non-human-readable data
Non-human-readable data (also called machine-readable) is data that a device can "interpret" and in its native state is not readily understood by a person. An example of non-human-readable data is JSON and XML.
Which of the following data security methods creates a copy of the original data but uses obfuscation on any sensitive elements?
a. data masking
b. data protecting
c. data tokening
d. data covering
a. data masking
Data masking involves creating a copy of the original data but using obfuscation (making unintelligible) any sensitive elements such as a user's name or Social Security number.
Aaliyah wants to send a message to a friend, but she does not want anyone else to know that she is communicating with them. Which technique would she use?
a. cryptography
b. steganography
c. encryption
d. ciphering
b. steganography
Steganography attempts to hide the very existence of the message or information.
Zeinab has been asked by her supervisor to speak with an angry customer who claims that they never received notification of a change in the terms of service agreement. Zeinab learned that an automated "read receipt" was received, showing that the customer opened the email with the new terms of service outlined. What action will Zeinab now take regarding this customer?
a. repudiation
b. obfuscation
c. integrity
d. nonrepudiation
d. nonrepudiation
Repudiation is defined as denial; nonrepudiation is the inability to deny. Nonrepudiation is the process of proving that a user performed an action.
Which of the following is NOT a form of obfuscation?
a. tokenization
b. ciphering
c. steganography
d. data masking
b. ciphering
Steganography is one form of obfuscation, along with data masking, which involves creating a copy of the original data and making it unintelligible, and tokenization, which obfuscates sensitive data elements, such as an account number, into a random string of characters (token). Ciphering is not a form of obfuscation.
Which of the following is NOT correct about "security through obscurity"?
a. It attempts to hide its existence from outsiders.
b. Proprietary cryptographic algorithms are a common example.
c. It is essentially impossible to achieve.
d. It should only be used as a general information security protection in extreme circumstances.
d. It should only be used as a general information security protection in extreme circumstances.
Obfuscation cannot by itself be used as a general information security protection. This is because it is essentially impossible to keep something completely hidden from everyone all the time. Eventually it will be discovered, and the security compromised.
Layla has encrypted a document so that it can only be viewed by those who have been provided the key. What protection has she given to this document?
a. confidentiality
b. integrity
c. authentication
d. obfuscation
a. confidentiality
Confidentiality ensures that only authorized parties can view the information. Encrypted information that can only be viewed by those who have been provided the key is an example of confidentiality.
Which of the following is NOT correct about a one-time pad (OTP)?
a. It combines plaintext with a random key.
b. The recipient must have a copy of the pad to decrypt the message.
c. It was used during the Cold War.
d. It requires a cipher disk.
d. It requires a cipher disk.
A one-time pad (OTP) can create strong encryption without using a computer or any device. It is entirely hand-calculated.
What is data called that is to be encrypted by inputting it into a cryptographic algorithm?
a. plaintext
b. byte-text
c. cleartext
d. ciphertext
a. plaintext
Unencrypted data that is input for encryption or is the output of decryption is called plaintext.
Which of the following creates the most secure ciphertext?
a. redundant function
b. stream cipher
c. block cipher
d. sponge function
d. sponge function
A sponge function takes as input a string of any length and returns a string of any requested variable length. This function repeatedly applies a process on the input that has been padded with additional characters until all characters are used.
Karyme needs to select a hash algorithm that will produce the longest and most secure digest. Which would she choose?
a. RipeMD160
b. SHA-256
c. XRA3-512
d. Whirlpool
d. Whirlpool
Whirlpool uses a block cipher and takes a message of any length less than 2256 bits and returns a 512-bit message digest.
Which algorithm uses the same key to both encrypt and decrypt data?
a. asymmetric cryptographic algorithm
b. hashing algorithm
c. pairwise keypair algorithm
d. symmetric cryptographic algorithm
d. symmetric cryptographic algorithm
Symmetric cryptographic algorithms use the same key to encrypt and decrypt the data.
Which of the following is NOT to be decrypted but is only used for comparison purposes?
a. Digest
b. Key
c. Stream
d. Algorithm
a. Digest
A hash algorithm creates a unique "digital fingerprint" of a set of data called a digest. It is used primarily for comparison purposes.
Which of these is NOT a characteristic of a secure hash algorithm?
a. Collisions may occur but they should be rare.
b. A message cannot be produced from a predefined hash.
c. The hash should always be the same fixed size.
d. The results of a hash function should not be reversed.
a. Collisions may occur but they should be rare.
Two different sets of data cannot produce the same digest. Changing a single letter in one data set should produce an entirely different digest.
Which of the following is a weakness of RSA?
a. RSA weaknesses are based on ECC.
b. RSA has no known weaknesses.
c. As computers become more powerful, the ability to compute factoring has increased.
d. The digest produced by the RSA algorithm is too short to be secure.
c. As computers become more powerful, the ability to compute factoring has increased.
Because RSA is based on factoring, its weakness is that more powerful computers may be able to calculate factoring and thus break the algorithm.
Which of these is NOT true about ECC?
a. ECC has gained wide popularity.
b. All modern OSs and web browsers use ECC.
c. ECC security is comparable to other asymmetric cryptography but has smaller key sizes.
d. It uses both sloping curves and prime numbers.
d. It uses both sloping curves and prime numbers.
Instead of using large prime numbers as with RSA, ECC uses sloping curves.
If Bob wants to send a secure message to Alice using an asymmetric cryptographic algorithm, which key does he use to encrypt the message?
a. Alice's private key
b. Alice's public key
c. Bob's public key
d. Bob's private key
b. Alice's public key
When an encrypted message is to be sent, the recipient's key and not the sender's key is used to encrypt the message.
Farah needs to encrypt only a few files and does not want the entire disk contents to be encrypted. What type of encryption would she use?
a. file-level encryption
b. byte-level encryption
c. folder-level encryption
d. device-level encryption
a. file-level encryption
Cryptographic software can be used to encrypt or decrypt files one by one, called file-level encryption.
Which type of encryption would protect all data on a hard drive, including the installed OS?
a. FDE
b. SSED
c. TXPM
d. HRHS
a. FDE
To protect the entire hard drive using cryptography is known as full-disk encryption (FDE) and protects all data on a hard drive, including the installed OS.
What is a collision?
a. Two files that produce the same digest.
b. Two ciphertexts that have the same length.
c. Two algorithms that have the same key.
d. Two keys that are the same length.
a. Two files that produce the same digest.
Two files having the same digest is known as a collision. A collision attack is an attempt to find two input strings of a hash function that produce the same hash result.
Nahla has been asked to make a recommendation about the most secure TEE. Which of the following would she choose?
a. SED
b. HSM
c. TPM
d. ARC
c. TPM
Instead of relying on vulnerable software or an external device to be connected to a computer, a trusted execution environment (TEE) is a secure cryptoprocessor that is internal to the computer itself. The Trusted Platform Module (TPM) is an international standard for a cryptoprocessors (a motherboard chip) that provides cryptographic services.
Which type of blockchain can anyone join?
a. Federated blockchain
b. Private blockchain
c. Hybrid blockchain
d. Public blockchain
d. Public blockchain
A public blockchain, also called an open public ledger, is a blockchain network that anyone can join and become part of. A common use of public blockchains is for exchanging cryptocurrencies and crypto mining.
Alarik is explaining to a colleague about digital certificates. Which of the following statements would he use to correctly describe the need for digital certificates?
a. It can speed up processing time when using a web browser.
b. It can hide the public key so that it cannot be abused.
c. It can confirm the true identity of the sender of an encrypted message.
d. It can replace digital signatures with a more robust technology.
b. It can hide the public key so that it cannot be abused.
The public key never needs to be hidden.
What is a technology used to associate a user's identity to a public key and has been digitally signed by a trusted third party?
a. digital signature
b. digital certificate
c. digital codebook
d. digital signing repository (DSR)
b. digital certificate
A digital certificate is a technology used to associate a user's identity to a public key and has been digitally signed by a trusted third party.
Ville has been asked by his supervisor to review the contents of a questionable digital certificate. Which of the following would Ville NOT find in it?
a. owner's private key
b. serial number of the digital certificate
c. name of the issuer
d. owner's name or alias
a. owner's private key
A digital certificate contains the owner's name or alias, the owner's public key, the name of the issuer, the digital signature of the issuer, the serial number of the digital certificate, and the expiration date of the public key that has been digitally signed.
Who is responsible for verifying the credentials of an applicant for a digital certificate?
a. CA
b. registration authority
c. CSR
d. intermediate CSR
b. registration authority
The user electronically signs a digital certificate by affixing their public key and then sends it to a registration authority that is responsible for verifying the credentials of the applicant.
Which of the following is NOT a means by which a person requesting a digital certificate can be authenticated?
a. birth certificate
b. employee badge
c. email
d. telephone number
d. telephone number
A telephone number is not used for authentication.
What is the strongest technology that would assure Alice that Bob is the sender of a message?
a. digital signature
b. encrypted signature
c. digest
d. digital certificate
d. digital certificate
A digital certificate can assure Alice that Bob is the authentic sender of a message.
What is a publicly accessible centralized directory of digital certificates that can be used to view the status of a digital certificate?
a. CA
b. CR
c. CB
d. CX
b. CR
A certificate repository (CR) is a publicly accessible centralized directory of digital certificates that can be used to view the status of a digital certificate. This directory can be managed locally by setting it up as a storage area that is connected to the CA server.
Ansgar is studying how digital certificates can be used. Which of the following is NOT a use of a digital certificate?
a. to encrypt messages for secure email communications
b. to encrypt channels to provide secure communication between clients and servers
c. to verify the authenticity of the CA
d. to verify the identity of clients and servers on the web
c. to verify the authenticity of the CA
A digital certificate is used to identify the owner of a public key but not to verify the authenticity of the CA.
Which of the following performs a real-time lookup of a certificate's status?
a. Pinning
b. OCSP
c. Clipping
d. Remote lookup protocol (RLP)
b. OCSP
The Online Certificate Status Protocol (OCSP) performs a real-time lookup of a certificate's status and is called a "request-response" protocol.
Which of the following is NOT true about a root digital certificate?
a. The next level down is one or more intermediate certificates.
b. It is self-signed.
c. It is created and verified by a CA.
d. It is the endpoint of the chain.
d. It is the endpoint of the chain.
The beginning point of the chain is a specific type of digital certificate known as a root digital certificate.
Tordis has been asked to acquire a digital certificate that will cover all the subdomains of a new site. Which type of certificate would he acquire?
a. omnibus digital certificate
b. subname digital certificate
c. wildcard digital certificate
d. NAXX
c. wildcard digital certificate
A wildcard digital certificate is used to validate a main domain along with all subdomains.
Bengt is setting up a new web server that will have several IP addresses. He only wants to acquire a single digital certificate. Which type of certificate will he acquire?
a. SAN
b. Asterisk digital certificate (ADC)
c. Domain digital certificate
d. EV
a. SAN
The Subject Alternative Name (SAN) allows different values to be associated with a single certificate. It also permits a certificate to cover multiple IP addresses.
hat is the standard format for digital certificates?
a. CN
b. RCN
c. CER x9
d. X-509 Version 3
d. X-509 Version 3
The standard format for digital certificates is X.509 Version 3. Digital certificates following this standard can be read or written by any hardware device or application that follows the X.509 format.
Which of the following is false about PKI?
a. It is the underlying infrastructure that serves as a key management system for controlling public keys, private keys, and digital certificates.
b. It is the set of software, hardware, processes, procedures, and policies that are needed to create, manage, distribute, use, store, and revoke digital certificates across large user populations.
c. It is digital certificate management at scale.
d. It must be used by all enterprises with over 1,000 employees.
d. It must be used by all enterprises with over 1,000 employees.
There is no requirement for the usage of PKI in regard to a specific number of employees.
Which is the first step in a key exchange?
a. The browser generates a random value ("Pre-master secret").
b. The web server sends a message ("ServerHello") to the client.
c. The web browser verifies the server certificate.
d. The web browser sends a message ("ClientHello") to the server.
d. The web browser sends a message ("ClientHello") to the server.
The first step in a key exchange is the web browser sends a message ("ClientHello") to the server.
Dag wants to set up a trust model in which he only will serve as a CA. Which trust model will he choose?
a. bridge trust model
b. distributed trust model
c. hierarchical trust model
d. sole trust model
c. hierarchical trust model
A hierarchical trust model can be used in an organization where one CA is responsible for only the digital certificates for that organization.
Einar has been asked to create a new policy that outlines the process in which keys are managed by a third party and the private key is split with each half encrypted. What policy is Einar creating?
a. key recovery policy
b. key expiration policy
c. extended validation policy
d. key escrow policy
d. key escrow policy
Key escrow refers to a process in which keys are managed by a third party, such as a trusted CA. In key escrow, the private key is split and each half is encrypted. The two halves are registered and sent to the third party, which stores each half in a separate location. A user can then retrieve the two halves, combine them, and use this new copy of the private key for decryption.
Which of the following is the most comprehensive secure communication and transport protocol?
a. SSL
b. TLS
c. IPSec
d. HSS
c. IPSec
IPSec is considered a more robust protocol than TLS. This is because it provides security to IP, which is the basis for all other TCP/IP protocols. In protecting IP, IPSec is essentially protecting everything else in TCP/IP as well.
Gjord has been assigned to design an implementation of IPSec at an old manufacturing plant that has legacy network equipment and many devices. Which implementation will he choose?
a. SRSR
b. AR Stack
c. BITW
d. BITS
d. BITS
BITS adds IPSec to legacy hosts while BITW adds it to legacy network equipment.
Which of the following is NOT a primary characteristic for determining the resiliency of a key to attacks?
a. randomness
b. key derivation
c. cryptoperiod
d. key length
b. key derivation
Key derivation is not a characteristic for determining the resilience of a key.
What word is the currently accepted term that is used today to refer to network-connected hardware devices?
a. host
b. endpoint
c. device
d. client
b. endpoint
The word commonly used when referring to network-connected hardware devices is endpoints. This change reflects the fact that today computing devices are far more than a desktop computer with a keyboard and monitor.
Which of the following is NOT a feature of blocking ransomware?
a. A message on the user's screen appears pretending to be from a reputable third party.
b. It prevents a user from using their computer in a normal fashion.
c. It can be defeated by a double power cycle.
d. It is the earliest form of ransomware.
c. It can be defeated by a double power cycle.
Ransomware prevents a user's device from properly functioning or accessing data until a fee is paid. The ransomware embeds itself into the device in such a way that it cannot be bypassed, and even performing a "power cycle" (turning the device off and on) does not clear the ransomware.
Cillian is explaining to an intern why ransomware is considered to be the most serious malware threat. Which of the follow reasons would Cillian NOT give?
a. Once a device is infected with ransomware, it will never function normally.
b. Launching a ransomware attack is relatively inexpensive and does not require a high degree of skill.
c. Ransomware attacks occur with a very high frequency.
d. Attacks from ransomware have a high impact on organizations.
a. Once a device is infected with ransomware, it will never function normally.
A device infected with ransomware can return to normal after the unlocking key is purchased.
Finn's team leader has just texted him that an employee, who violated company policy by bringing in a file on a USB flash drive, has just reported that their computer is infected with locking ransomware. Why would Finn consider this a serious situation?
a. It sets a precedent by encouraging other employees to violate company policy.
b. It can encrypt all files on any network that is connected to the employee's computer.
c. The organization may be forced to pay up to $500 for the ransom.
d. The employee would have to wait at least an hour before their computer could be restored.
b. It can encrypt all files on any network that is connected to the employee's computer.
In addition to encrypting files on the device's local drive, new variants of locking ransomware encrypt all files on any network or attached device that is connected to that device. This includes secondary drives, USB drives, network-attached storage devices, network servers, and even cloud-based data repositories.
What is the difference between a keylogger and spyware?
a. A keylogger operates much faster than spyware.
b. Spyware is illegal while a keylogger is not.
c. Spyware typically secretly monitors users but unlike a keylogger makes no attempts to gather sensitive user keyboard input.
d. Spyware can be installed using a hardware device while a keylogger cannot.
c. Spyware typically secretly monitors users but unlike a keylogger makes no attempts to gather sensitive user keyboard input.
Spyware is tracking software that is deployed without the consent or control of the user. Spyware typically secretly monitors users but unlike a keylogger makes no attempts to gather sensitive user keyboard input.
Which of the following is NOT a technology used by spyware?
a. tracking software
b. system-modifying software
c. active tracking technologies
d. automatic download of software
c. active tracking technologies
Passive tracking technologies are used to gather information about user activities without installing any software.
Which of the following is NOT true about RATs?
a. A RAT gives the threat agent unauthorized remote access to the victim's computer by using specially configured communication protocols.
b. A RAT and a worm have the same basic function.
c. A RAT allows the attacker to not only monitor what the user is doing but also can change computer settings, browse and copy files, and even use the computer to access other computers connected on the network.
d. A RAT creates an opening into the victim's computer, allowing the threat actor unrestricted access.
b. A RAT and a worm have the same basic function.
A special type of Trojan is a remote access Trojan (RAT). A RAT has the basic functionality of a Trojan.
Which of the following types of computer viruses is malicious computer code that becomes part of a file?
a. file-based virus
b. jump virus
c. fileless virus
d. RAM-Check virus
a. file-based virus
A file-based virus is remarkably similar to a biological virus: it is malicious computer code that becomes part of a file.
Which of the following is NOT a Microsoft Windows common LOLBin?
a. DLR
b. .NET Framework
c. Macro
d. PowerShell
a. DLR
A DLR is fictitious.
Which of the following is sometimes called a "network virus" because it enters a computer to move through the network?
a. fileless virus
b. worm
c. trojan
d. file-based virus
b. worm
A worm is a malicious program that uses a computer network to replicate and is sometimes called a "network virus." A worm is designed to enter a computer through the network and then take advantage of a vulnerability in an application or an OS on the host computer. Once the worm has exploited the vulnerability on one system, it immediately searches for another computer on the network that has the same vulnerability.
Which of these would NOT be considered the result of a logic bomb?
a. Send an email to Rowan's inbox each Monday morning with the agenda of that week's department meeting.
b. If the company's stock price drops below $50, then credit Oscar's retirement account with one additional year of retirement credit.
c. Erase the hard drives of all the servers 90 days after Alfredo's name is removed from the list of current employees.
d. Delete all human resource records regarding Augustine one month after he leaves the company.
a. Send an email to Rowan's inbox each Monday morning with the agenda of that week's department meeting.
Logic bombs have a malicious intent.
Which of the following attacks is based on a website accepting user input without sanitizing it?
a. RSS
b. XSS
c. iSQL
d. SSXRS
b. XSS
In a cross-site scripting (XSS) attack, a website that accepts user input without validating it (called "sanitizing") and uses that input in a response can be exploited.
Which of the following attacks is based on the principle that when a user is currently authenticated on a website and then loads another webpage, the new page inherits the identity and privileges of the first website?
a. SSFR
b. DLLS
c. CSRF
d. DRCR
c. CSRF
A cross-site request forgery (CSRF) takes advantage of an authentication "token" that a website sends to a user's web browser.
Which of the following manipulates the trusting relationship between web servers?
a. SSRF
b. CSRF
c. EXMAL
d. SCSI
a. SSRF
A server-side request forgery (SSRF) takes advantage of a trusting relationship between web servers (as opposed to a CSRF, which manipulates the trust from a user's browser to a server). SSRF attacks exploit how a web server processes external information received from another server.
Which type of memory vulnerability attack manipulates the "return address" of the memory location of a software program?
a. pointer attack
b. stuffing attack
c. integer overwrite
d. buffer overflow attack
d. buffer overflow attack
A buffer overflow attack occurs when a process attempts to store data in RAM beyond the boundaries of a fixed-length storage buffer. This extra data overflows into the adjacent memory locations, or a "buffer overflow." Because the storage buffer typically contains the "return address" memory location of the software program being executed when another function interrupted the process, an attacker can overflow the buffer with a new address pointing to the attacker's malware code.
What race condition can result in a NULL pointer/object dereference?
a. Conflict race condition
b. Value-based race condition
c. Thread race condition
d. Time of check (TOC) to time of use (TOU)
d. Time of check (TOC) to time of use (TOU)
A NULL pointer/object dereference can also be the result of a race condition. A race condition in software occurs when two concurrent threads of execution access a shared resource simultaneously, resulting in unintended consequences. This can be exploited when the software checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check. This is called a time of check (TOC) to time of use (TOU) race condition.
Which of the following would NOT be considered an IoA?
a. resource manipulation
b. out-of-cycle logging
c. account lockout
d. blocked content
a. resource manipulation
Resource consumption occurs when system resources such as memory or processing capabilities are suddenly depleted, which could indicate an attack.
Nollaig is reviewing the steps that an attacker took when they compromised a web server and accessed confidential files. What type of attack was this?
a. directory traversal
b. account overflow
c. race condition
d. TOE
a. directory traversal
Web-based attacks frequently result in directory traversal. The "root" directory is a specific directory on a web server's file system, and users who access the server are usually restricted to the root directory and directories and files beneath the root directory, but they cannot access other directories. A directory traversal attack takes advantage of a vulnerability so that a user can move from the root directory to other restricted directories, viewing confidential files or entering commands to execute on the server.
Which of the following is NOT correct about a secure cookie?
a. It is a means of protection of a web browser.
b. A secure cookie is only sent to the server with an encrypted request.
c. It uses the HTTPS protocol.
d. It prevents an unauthorized person from intercepting a cookie that is being transmitted.
a. It is a means of protection of a web browser.
As a means of protection for cookies, a web browser can send a secure cookie.
Which statement regarding a keylogger is NOT true?
a. Software keyloggers can be designed to send captured information automatically back to the attacker through the Internet.
b. Hardware keyloggers are installed between the keyboard connector and computer keyboard USB port.
c. Software keyloggers are generally easy to detect.
d. Keyloggers can be used to capture passwords, credit card numbers, or personal information.
c. Software keyloggers are generally easy to detect.
Software keyloggers are very difficult if not impossible to detect.