Threats and Vulnerabilities
Security Technologies
Best Practice
Encryption
Utilities
100
Jane, an individual, has recently been calling various financial offices pretending to be another person to gain financial information. Which of the following attacks is being described? A. Phishing B. Tailgating C. Pharming D. Vishing
What is D. Vishing
100
In order to provide flexible working conditions, a company has decided to allow some employees remote access into corporate headquarters. Which of the following security technologies could be used to provide remote access? A. Subnetting B. NAT C. Firewall D. NAC E. VPN
What is Firewall and VPN
100
Which of the following is a best practice before deploying a new desktop operating system image? A. Install network monitoring software B. Perform white box testing C. Remove single points of failure D. Verify operating system security settings D.
What is Verify the operating system security settings
100
Which of the following can be used in code signing? A. AES B. RC4 C. GPG D. CHAP
What is C. GPG
100
Which of the following would be used to identify the security posture without actually exploiting any weaknesses? A. Penetration test B. Code review C. Vulnerability scan D. Brute Force scan
What is C. Vulnerability scan
200
Use of a smart card to authenticate remote servers remains MOST susceptible to which of the following attacks? A. Malicious code on the local system B. Shoulder surfing C. Brute force certificate cracking D. Distributed dictionary attacks
What is A. Malicious code on the local system
200
Which of the following MOST interferes with network-based detection techniques? A. Mime-encoding B. SSL C. FTP D. Anonymous email accounts
What is B. SSL
200
In regards to secure coding practices, why s input validation important? A. It mitigates buffer overflow attacks B. It makes the code more readable C. It provides an application configuration baseline D. It meets gray box testing standards
What is A. It mitigates buffer overflow attacks
200
All of the following are valid cryptographic hash functions EXCEPT: A. RIPEMD B. RC4 C. SHA-512 D. MD4
What is B. RC4
200
Which of the following is tools would Matt, a security administrator, MOST likely use to analyze a malicious payload? A. Vulnerability scanner B. Fuzzer C. Port Scanner D. Protocol analyzer
What is D. Protocol analyzer
300
Which of the following is characterized by an attacker attempting to map out an organization's staff hierarchy in order to send targeted emails? A. Whaling B. Impersonation C. Privilege Escalation D. Spear Phishing
What is A. Whaling
300
Which of the following would most likely have a DMZ interface? A. Firewall B. Switch C. Load Balancer D. Proxy
What is A. Firewall
300
Which of the following specifications would Sara, an adminisrator, implement as a network access control? A. 802.1q B. 802.3 C. 802.11n D. 802.1x
What is D. 802.1x
300
A certificate authority takes which of the following actions in PKI? A. Signs and verifies al infrastructure messages B. Issues and signs all private keys C. Publishes key escrow lists to CRL's D. Issues and signs all root certificates
What is D. Issues and signs all root certificates
300
Matt, an administrator, notices a flood fragmented packet and retransmits from an email server. After disabling the TCP offload setting on the NIC. Matt sees normal traffic with packets flowing in sequence again. Which of the following utilities was he MOST llikely using to view this issue? A. Spam filter B. Protocol analyzer C. Web application firewall D. Load balancer
What is B. Protocol analyzer
400
When checking his webmail, MAtt, a user, changes the URL's string of characters and is able to get into another user's inbox. This is an example of which of the following? A. Header manipulation B. SQL injection C. XML injection D. Session hijacking
What is D. Session hijacking
400
Which of the following defines when Pete, an attacker, attempmts to monitor wireless traffic in order to perform malicious activities? A. XSS B. SQL Injection C. Directory traversal D. Packet sniffing
What is D. Packet Sniffing
400
Which of the following steps should follow the deployment of a patch? A. Antivirus and anti-malware deployment B. Audit and verification C. Fuzzing and exploitation D. Error and exception handling
What is B. Audit and verification
400
Which of the following must be updated immediately when an employee is terminated to prevent unauthorized access? A. Registration B. CA C. CRL D. Recovery Agent
What is C. CRL
400
Which of the following assessments would Pete, the security administrator, use to actively test that an application's security controls are in place? A. Code Review B. Penetration test C. Protocol Analyzer D. Vulnerability scan
What is Penetration test
500
Sara, a user, downloads a keygen to install pirated software. After running the keygen, system performance is extremely slow and numerous antivirus alerts are displayed. Which of the following BEST describes this type of malware? A. Logic Bomb B. Worm C. Trojan D. Adware
What is C. Trojan
500
Which of the following would an antivirus company use to efficiently capture and analyze new and unknown malicious attacks? A. Fuzzer B. IDS C. Proxy D. Honeynet
What is D. Honeynet
500
Why is it important for a penetration ester to have established an agreement with management as to which systems and processes are allowed to be tested? A. Penetration test results are posted publicly, and some systems tested may contain corporate secrets. B. Penetration testers always need to have a comprehensive list of servers, operating systems, IP subnets, and department personnel prior to ensure a complete test. C. Having an agreement allows the penetration tester to look for other systems out of scope and test them for threats against the in-scope systems. D. Some exploits when tested can crash or corrupt a system causing downtime or data loss.
What is D. Some exploits when tested can crash or corrupt a system causing downtime or data loss.
500
Which of the following is a hardware encryption device? A. EFS B. TrueCrypt C. TPM D. SLE
What is TPM
500
Which of the following allows a company to maintain access to encrypted resources when employee turnover is high? A. Recovery Agent B. Certificate Authority C. Trust model D. Key escrow
What is A. Recovery Agent