- StudyBlue
- Alabama
- Russell Co High School
- Security +
- Keels
- SECURITY + EXAM PRACTICE
SECURITY + EXAM PRACTICE
Security + with Keels at Russell Co High School
About this deck
Created: 2010-12-12
Size: 80 flashcards
Views: 531
About StudyBlue
Dennis
Sign up (free) to study this.
. By default, the 802.11 standard defines which of the following authentication models?
- Password Authentication
- Biometrics
- Open Authentication
- Shared-key Authentication
You want to implement network security that will inspect both outbound and inbound traffic and deny or permit traffic based on different rules. Which of the following will perform this function?a
- Firewall
- IDS
- Protocol Analyzer
- TACACS+
Which of the following services uses port 110?
- SSH
- POP3
- LDAP
- L2TP
Which of the following provides for the highest level of security during login?
a. Two-Factor Authentication
b. One-Factor Authentication
c. Single Sign-On
d. Strong Authentication
Which of the following cable types would an attacker successfully implement a vampire tap?
- Fiber Optic
- Shielded Twisted Pair
- Unshielded Twisted Pair
- Coaxial
A chip on the motherboard of the computer that provides cryptographic services, such as a true random number generator and full support for asymmetric encryption, is known as?
- Trusted Platform Module
- Subscriber Identity Module
- Common Access Card
- File Encryption Key
Which of the following protocols is used to protect email messages by using digital certificates?
- SMTP
- POP3
- S/MIME
- ISAKMP
Which of the following services uses port 19?
- FTP
- Echo
- Telnet
- Chargen
Which of the following forms of physical access control involve a combination lock that allows access after the buttons are pushed in the proper sequence?
- Deadbolt Lock
- Preset Lock
- Tailgate Sensor
- Cipher Lock
Which of the following algorithms is an asymmetric algorithm?
- RC4
- DES
- RSA
- MD5
Which RAID Level uses a striped disk array so that data is broken down into blocks and each block is written to a separate disk drive?
- RAID 0
- RAID 1
- RAID 3
- RAID 5
An attacker injecting client-side scripts into a dynamic Web page in order to capture sensitive information from the intended victim is exploiting which computer security vulnerability?
- SMTP Open Relay
- XSS
- SQL Injection
- Java
Which of the following types of backups only backs up files that have the archive bit turned on, but removes the archive bit when backed up?
a. Full Backup
b. Differential Backup
c. Grandfather Backup
d. Incremental Backup
The presentation of credentials typically performed when logging on to a system is known as?
a. Authentication
b. Identification
c. Authorization
d. Access
Which of the following is not a component of the AAA (“Triple A”) Model?
a. Availability
b. Accounting
c. Authenticity
d. Authorization
You are working in the data center when you hear a noise on one of the computers followed by flames. Which is the best type of fire extinguisher to put out the fire?
a. Class A
b. Class B
c. Class C
d. Class D
Which of the following replaces multiple private IP addresses with a single public IP address?
a. MAC
b. NIC
c. NAT
d. PAT
Which symmetric algorithm is utilized by WEP?
a. Elliptic Curve
b. RC4
c. Diffie-Hellman
d. El Gamal
Which of the following refers to any combination of hardware and software that enables access to remote users to a local internal network?
a. SSO
b. EAP
c. RAS
d. PAP
Once evidence is collected at a crime scene, what is the first action that should be taken?
a. Limit loss and damage to the asset
b. Initiate a chain of custody
c. Begin forensic analysis
d. Initiate the incident response plan
What are two defensive measures employed to prevent buffer overflows?
a. ASLR and ActiveX
b. Java and DEP
c. DEP and ASLR
d. ActiveX and Java
Which of the following network authentication protocols uses symmetric key cryptography, stores a shared key for each network resource and uses a Key Distribution Center (KDC)?
a. Telnet
b. Kerberos
c. Netware
d. TACACS+
Executable code that tracks your online activity and reports it back to marketers without actually attacking your computer is categorized as?
- Adware
- Trojan
- Virus
- Rootkit
An unauthenticated connection to a Microsoft Windows 2000 or Windows NT computer that does not require a username or password is known as?
- Freeware
- Open Authentication
- Null Session
- Remote Desktop
End users are complaining about a lot of email from online vendors and pharmacies. Which of the following is this an example of?
- Spam
- Trojan
- Phishing
- Adware
Which of the following ensures that a user cannot deny having sent a message?
- Availability
- Integrity
- Authenticity
- Nonrepudiation
NONREPUDIATION
As an administrator, before configuring any IDS technologies that would scan for anomalies, you would first have to obtain:
- Permit
- Definitions
- Security Baseline
- Anomaly Signatures
Reviewing a subject’s privileges over an object is known as:
- Privilege Creep
- Privilege Auditing
- Performance Monitor
- System Monitor
Which of the following is most likely to allow an attacker to make a switch function as a hub?
- MAC Flooding
- ARP Poisioning
- DNS Poisioning
- Fake Device Redirect
A program that attaches itself to a document or program and then executes when that document is opened or program is launched is known as which type of malware?
- Virus
- Trojan Horse
- Worm
- Spam
What is a form of access control that allows by default unless a condition is specifically denied?
- Implicit Deny
- Explicit Deny
- Access Control Entry
- Separation of Duties
Which of the following RAID Levels mirrors its actions from the primary drive to another drive, creating an exact duplicate to achieve fault tolerance?
- RAID 0
- RAID 1
- RAID 3
- RAID 5
Which of the following wireless standards operates at the 2.4 GHz radio frequency spectrum and can support devices transmitting at 54 Mbps?
- 802.11a
- 802.11b
- 802.11g
- 802.11n
Which of the following services uses port 88?
- TACACS+
- RADIUS
- Kerberos
- IMAP v4
Ensuring that information is correct and no unauthorized person or malicious software has altered the data is known as:
- Authenticity
- Nonrepudiation
- Confidentiality
- Integrity
What is it called when two different messages are hashed and, in result, produce the same digest?
- PKI
- Detection
- Collusion
- Collision
Which type of attack involves the man-in-the-middle capturing login credentials between a computer and a server, then at a later time, using the captured credentials?
- Spoofing
- Denial of Service
- Smurf
- Replay
What is the term used to describe a system attack that provides input data that exceeds the limits recognized by a program?
- Cookie
- Denial of Service
- Buffer Overflow
- Input Validation
What would an attacker use to break into a computer, gain privileges to perform unauthorized functions, and remove traces of the attacker’s existence?
- Rootkit
- Backdoor
- Privilege Escalation
- Penetration Test
Which type of monitoring methodology is used to examine network traffic, activity, transactions, or behavior by comparing against a predefined set of definitions?
- Anomaly-Based
- Signature-Based
- Behavior-Based
- Heuristic-Based
Which of the following hides the IP address of a network device by replacing a single private IP address with a single public IP address?
- PAT
- PAP
- NAT
- NAC
What is the term given to an alarm that is raised when there is no abnormal behavior called?
- False Positive
- False Negative
- False Acceptance
- False Rejection
Which of the following services are affected by shutting down ports 110 and 143?
- FTP and HTTP
- DNS and DHCP
- SMTP and SNMP
- POP and IMAP
Which of the following types of algorithms takes a variable-length message and produces a fixed-length hash?
- Stream Cipher
- Block Cipher
- Message Digest
- Diffie-Hellman
Which of the following define the actions employees, contractors, vendors, or visitors may perform while accessing systems and networking equipment?
- SLA
- ILM
- PII
- AUP
The technique known as “sandboxing” is used to defend against attacks from which of the following?
- ActiveX Controls
- Java Applet
- JavaScript
- Third-Party Cookie
Using cryptography to prove that the sender was legitimate and not an imposter is an example of which protection?
- Authenticity
- Accounting
- Availability
- Authorization
What can an attacker use to send massive amounts of spam and perform distributed denial of service attacks?
- Zombie
- Botnet
- Load Balancing
- Phishing
Which of the following would be the best tool in helping an administrator quickly find a rouge device on the network?
- Protocol Analyzer
- Network Mapper
- DNS Log Aggregator
- Vulnerability Scanner
Which asymmetric algorithm is used to encrypt a shared key in order to establish a symmetric session?
- RSA
- Whirlpool
- Message Digest
- Diffie-Hellman
An email message designed to trick the user into surrendering sensitive and/or private information is known as:
- Phishing
- Pharming
- Hoax
- Honeymail
Which access control model is the most restrictive, uses labels, and subscribes to the idea of need to know?
- Discretionary Access Control
- Mandatory Access Control
- Role-Based Access Control
- Rule-Based Access Control
An attack from one computer designed to consume network resources so that the network or its devices cannot respond to legitimate requests is best described as:
- Denial-of-Service
- Buffer Overflow
- DNS Zone Transfer
- Brute Force Attack
Granting users only the minimum number of privileges necessary to perform their job is known as:
- Need-to-know
- Least privilege
- Job rotation
- Separation of duties
Which of the following attacks begins with the attacker creating hashes of common words and comparing those hashed words against those in a stolen password file?
- Birthday Attack
- Rainbow Table
- Dictionary Attack
- Brute Force
Unsolicited messages sent via Bluetooth to Bluetooth-enabled devices is known as:
- Blue Jacking
- Blue Sniping
- Blue Snarfing
- Blue Bombing
Which of the following is used to address customer-specific, security-related issues?
- Hotfix
- Critical Update
- Patch
- Feature Pack
What software scans a computer for infections as well as monitor computer activity and scan all new documents that might contain malware?
- Popup Blocker
- Antispyware
- Antispam
- Antivirus
Which of the following modes of IPSec encrypts only the data portion of each packet and leaves the header unencrypted?
- Authentication Mode
- Transport Mode
- Tunnel Mode
- Encapsulating Mode
What is known as malware installed on a computer that collects information about users, such as Internet surfing habits or browser history, without their knowledge?
- Third-Party Cookie
- Recon Virus
- ARP Poisoning
- Spyware
The fraudulent act of taking advantage of the 5-day grace period to delete Internet domain names is known as:
a. Kiting
b. Spoofing
c. Poisoning
d. Zone Transfer
If a user is able to log in to their MSN Hotmail email account and is able to access multiple services without having to authenticate, which access control model is being used?
- Extended
- Single Sign-On
- Multifactor
- Multivendor
An account that is secretly set up without the administrator’s knowledge or permission, that cannot be detected, and that allows for remote access to the device is known as?
- Default Account
- Cache
- Backdoor
- Certificate Repository
What is the concept of having more than one person required to complete a task to avoid a single user from having complete control known as?
- Separation of Duties
- Job Rotation
- Least Privilege
- Need to Know
Which of the following is not a use for a protocol analyzer?
- Network Traffic Characterization
- Network Troubleshooting
- Security Analysis
- Packet Shaping
Which term best describes a low-level system program that uses a notification engine designed to monitor and track down hidden activity on a desktop system, server, PDA, or cell phone?
a. Activity Monitor
b. Protocol Analyzer
c. System Monitor
d. Performance Monitor
About this deck
Created: 2010-12-12
Size: 80 flashcards
Views: 531
About StudyBlue
Dennis