Chapter One
Category Two
Category Three
Category Four
Category Five
100

You need to transmit PII via email and you want to maintain its confidentiality. The best method is what? 

What is Encryption? 

100

Your organization recently updated an online application that employees use to log on when working from home. Employees enter their username and password into the application from their smartphone and the application logs their location using GPS. What authentication is being used?

What is One-Factor?

100

You manage a Linux computer used for security within your network. You plan to use it to inspect and handle network-based traffic using IPtables. What network device can this replace?

What is a Firewall?

100

You need to provide connectivity between two buildings without running any cables. You decide to use two 802.11ac APs to provide wireless connectivity between the buildings. What is the best option to support this need?

Use directional antennas on both access points? 

100

The Springfield Nuclear Power Plant has created an online application teaching nuclear physics. Only students and teachers in the Springfield Elementary school can access this application via the cloud. What type of cloud service model is this?

What is Software As A Service (SaaS)?

200

Grandpa hid several plaintext documents within an image file. He then sent the image file to Gregory. What BEST describes the purpose of his actions?

What is Steganography?

200

Your organization is planning to implement remote access capabilities. Management wants strong authentication and wants to ensure that passwords expire after a predefined time interval. What is the best way to implement this? 

What is Time-Based-One-Time Password (TOTP)?


200

An organization has recently had several attacks against servers within a DMZ. Security administrators discovered that many of these attacks are using TCP, but they did not start with a three-way handshake. What would be the best firewall state for this? 

What is a stateful firewall?

200

You want to implement the STRONGEST level of security on a wireless network. How would you implement this goal? 

A. Implementing WPA with TKIP

B. Disabling SSID broadcast

C. Enabling MAC filtering

D. Implementing WPA2 with CCMP

What is implementing WPA2 with CCMP? 

200

Lisa does not have access to the project.doc file, but she needs access to this file for her job. Homer is the system administrator and he has identified the following permissions for the file:

rwx rw- ---

What should Homer use to grant Lisa read access to the file?

What is the Chmod Command? 

300

Management has mandated the use of digital signatures by all personnel within your organization. What Use Case does this support? 

What is non-repudiation?

300

A network includes a ticket-granting ticket server used for authentication. Which authentication service does this network use?

What is Kerberos?

300

Your organization wants to increase security for VoIP and video teleconferencing applications used within the network. Which protocols will BEST support this goal?

What is Secure Real Time Protocol?

300

Attackers have recently launched several attacks against servers in your organization’s DMZ. You are tasked with identifying a solution that will have the best chance at preventing these attacks in the future. Which Intrusion system would be best and what type? 

What is an in-band IPS? 

300

Management within your organization wants to prevent users from copying documents to USB flash drives. Which of the following can be used to meet this goal?

A. DLP

B. HSM

C. COPE

D. SED

What is Data Loss Prevention? 

400

Your organization has implemented a VDI for most users. When a user logs off, the desktop reverts to its original state without saving any changes made by the user. What best describes this behavior? 

What is Non-persistence

400

Members of a project team chose to meet at a local library to complete some work on a key project. All of them are authorized to work from home using a VPN connection and have connected from home successfully. However, they found that they were unable to connect to the network using the VPN from the library and they could not access any of the project data. What is the MOST likely reason why they can’t access this data?

What is a Location-Based Policy?

400

Management within your organization wants to ensure that switches are not susceptible to switching loop problems. What Protocol is the best to meet to this need? 

What is Rapid Spanning Tree Protocol (RSTP)? 
400

Your wireless network name is myoffice. You disabled the SSID broadcast several days ago. Today, you notice that a wireless network named "myoffice" is available to wireless users. You verified that SSID broadcast is still disabled. What is most likely the cause for this behavior?

What is an Evil Twin? 

400

Bizzfad is planning to implement a CYOD deployment model. You’re asked to provide input for the new policy. Which of the following concepts are appropriate for this policy?

A. SCADA access

B. Storage segmentation

C. Database security

D. Embedded RTOS

What is Storage Segmentation? 

500

Administrators frequently create VMs for testing. They sometimes leave these running without using them again after they complete their tests. What does this describe? 

What is VM Sprawl?

500

Your organization is implementing an SDN. Management wants to use an access control model that controls access based on attributes. What is the the BEST solution?

What is Attribute Based Access Control (ABAC)

500

Management at your organization wants to prevent employees from accessing social media sites using company-owned computers. What would be the best proxy to implement? 

What is a Non-transparent Proxy?

500

Your organization is planning to implement a VPN. They want to ensure that after a VPN client connects to the VPN server, all traffic from the VPN client is encrypted. Which of the following would BEST meet this goal?

A. Split tunnel

B. Full tunnel

C. IPsec using Tunnel mode

D. IPsec using Transport mode

What is a Full Tunnel? 

500

Looking at logs for an online web application, you see that someone has entered the following phrase into several queries:

‘ or ‘1’=’1’ --

What type of attack could this be perceived as? 

What is an SQL injection? 

M
e
n
u