Preview real exam questions, verified answers and available explanations before choosing a study plan.
Question 1
Drag & drop
DRAG DROP
Match the authentication protocol with its description.
Instructions: To answer, drag the appropriate authentication protocol from the column on the left to its description on the right. Each authentication protocol may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Reveal answer detailsClose answer details
Question 2
Single choice
The manager of a coffee shop hires you to securely set up WiFi in the shop.
To keep computer users from seeing each other, what should you use with an access point?
A
Client bridge mode
B
Client isolation mode
C
MAC address filtering
D
Client mode
Reveal answer detailsClose answer details
Correct answerB
Explanation
Wireless Client Isolation is a unique security feature for wireless networks. When Client Isolation is enabled any and all devices connected to the wireless LAN will be unable to talk to each other.
Question 3
Single choice
Dumpster diving refers to a physical threat that a hacker might use to look for information about a computer network.
Select the correct answer if the underlined text does not make the statement correct. Select "No change is needed" if the underlined text makes the statement correct.
A
Phishing
B
Malware
C
Reverse Social engineering
D
No change is needed
Reveal answer detailsClose answer details
Correct answerD
Question 4
Single choice
A mail system administrator scans for viruses in incoming emails to increase the speed of mail processing.
Select the correct answer if the underlined text does not make the statement correct. Select "No change is needed" if the underlined text makes the statement correct.
A
Decrease the chances of a virus getting to a client machine
B
Verify that the senders of the messages are legitimate
C
Ensure that all links in the messages are trustworthy
D
No change is needed.
Reveal answer detailsClose answer details
Correct answerA
Question 5
Hotspot
HOTSPOT
An employee where you work is unable to access the company message board in Internet Explorer. You review her Internet Options dialog box, as shown in the following image:
Use the drop-down menus to select the answer choice that completes each statement.
Each correct selection is worth one point.
Reveal answer detailsClose answer details
Question 6
Single choice
Which of the following is used to protect all files stored on the drive on which Windows is installed?
A
SocketShield
B
Firewall
C
Bitlocker
D
Hardware keylogger
Reveal answer detailsClose answer details
Correct answerC
Explanation
BitLocker is used to protect all files stored on the drive on which Windows is installed. It encrypts the entire system drive and helps block hackers from accessing the system files they rely on to discover user passwords. BitLocker also prevents hackers from accessing the hard disk by removing it from a computer, and installing it on a different computer. BitLocker does not work for USB Flash Drives. Answer: A is incorrect. SocketShield provides a protection shield to a computer system against malware, viruses, spyware, and various types of keyloggers. SocketShield provides protection at the following two levels: 1. Blocking: In this level, SocketShield uses a list of IP addresses that are known as purveyor of exploits. All http requests for any page in these domains are simply blocked. 2. Shielding: In this level, SocketShield blocks all the current and past IP addresses that are the cause of unauthorized access. Answer: B is incorrect. A firewall is a system that helps in preventing access to a system from unauthorized internet or network users. A firewall can be hardware as well as software. A firewall is implemented on systems that are connected to the internet and are vulnerable to hackers, viruses, worms, and other harmful intrusions. Answer: D is incorrect. Hardware keyloggers are used for keystroke logging, a method of capturing and recording computer users' keystrokes, including sensitive passwords. They can be implemented via BIOS-level firmware, or alternatively, via a device plugged inline between a computer keyboard and a computer. They log all keyboard activities to their internal memory.
Question 7
Multiple choice
John works as a Network Administrator for We-are-secure Inc. The We-are-secure server is based on Windows Server 2003. One day, while analyzing the network security, he receives an error message that Kernel32.exe is encountering a problem. Which of the following steps should John take as a countermeasure to this situation? Each correct answer represents a complete solution. Choose all that apply.
A
He should restore his Windows settings.
B
He should upgrade his antivirus program.
C
He should observe the process viewer (Task Manager) to see whether any new process is running on the computer or not. If any new malicious process is running, he should kill that process.
D
He should download the latest patches for Windows Server 2003 from the Microsoft site, so that he can repair the kernel.
Reveal answer detailsClose answer details
Correct answersB, C
Explanation
Answer: B and C In such a situation, when John receives an error message revealing that Kernel32.exe is encountering a problem, he needs to come to the conclusion that his antivirus program needs to be updated, because Kernel32.exe is not a Microsoft file (It is a Kernel32.DLL file.). Although such viruses normally run on stealth mode, he should examine the process viewer (Task Manager) to see whether any new process is running on the computer or not. If any new process (malicious) is running on the server, he should exterminate that process. Answer: A and D are incorrect. Since kernel.exe is not a real kernel file of Windows, there is no need to repair or download any patch for Windows Server 2003 from the Microsoft site to repair the kernel. Note: Such error messages can be received if the computer is infected with malware, such as Worm_Badtrans.b, Backdoor.G_Door, Glacier Backdoor, Win32.Badtrans.29020, etc.
Question 8
Single choice
Which of the following types of Network Address Translation (NAT) uses a pool of public IP addresses?
A
Static NAT
B
Port Address Translation (PAT)
C
Dynamic NAT
D
Cache NAT
Reveal answer detailsClose answer details
Correct answerC
Explanation
Dynamic Network Address Translation (NAT) uses a pool of public IP addresses. Dynamic NAT is a technique that maps an unregistered IP address to a registered IP address from a group of registered IP addresses. It also establishes a one-to-one mapping between unregistered (private) and registered (public) IP addresses, but the mapping varies depending on the registered address available in the IP address pool at the time of connection. Answer: A is incorrect. Static NAT performs a manual translation of one IP address to a different one. Static NAT is typically used to translate the destination IP address in packets that reach to the translation device (such as a router) for LAN. In static translation type, a manual translation is performed between two addresses and possibly port numbers. Answer: B is incorrect. Port Address Translation (PAT) is also a type of NAT. This type of NAT is used in home networks that are using DSL or cable modems. It is designed to provide Internet access to many internal users through one external address. Answer: D is incorrect. There is no such type of NAT as Cache NAT.
Question 9
Multiple choice
Which of the following practices should be followed to keep passwords secure? Each correct answer represents a complete solution. Choose three.
A
Change the passwords whenever there is suspicion that they may have been compromised.
B
A password should be alpha-numeric.
C
A password should not be more than five words.
D
Never write down a password.
Reveal answer detailsClose answer details
Correct answersA, B, D
Explanation
Answer: D, A, and B The following practices should be followed to keep passwords secure: Never write down a password. Change the passwords whenever there is suspicion that they may have been compromised. A password should be alpha-numeric. Never use the same password for more than one account. Never tell a password to anyone, including people who claim to be from customer service or security. Never communicate a password by telephone, e-mail, or instant messaging. Ensure that an operating system password and application passwords are different. Make passwords completely random but easy for you to remember.
Which is the minimum requirement to create BitLocker-To-Go media on a client computer?
A
Windows XP Professional Service Pack 3
B
Windows Vista Enterprise Edition
C
Windows 7 Enterprise Edition
D
Windows 2000 Professional Service Pack 4
Reveal answer detailsClose answer details
Correct answerA
Question 12
Single choice
Which of the following is a US Federal government algorithm created to generate a secure message digest?
A
DSA
B
RSA
C
Triple DES
D
SHA
Reveal answer detailsClose answer details
Correct answerD
Explanation
SHA is a Federal government algorithm created to generate a secure message digest. The Secure Hash Algorithm (SHA) is a cryptographic hash algorithm. It generates a fixed-length digital representation (message digest) of an input data sequence of any length. The SHA algorithm is very secure, as it is computationally very difficult to find a message that corresponds to a given message digest. In this algorithm, any change to a message will result in a completely different message digest. There are five SHA algorithms: SHA-1, SHA-224, SHA-256, SHA-384, and SHA-512. Answer: A is incorrect. Digital Signature Algorithm (DSA) is a United States Federal Government standard or FIPS for digital signatures. DSA is a public key algorithm; the secret key operates on the message hash generated by SHA-1; to verify a signature, one recomputes the hash of the message, uses the public key to decrypt the signature and then compares the results. The key size is variable from 512 to 1024 bits, which is adequate for the current computing capabilities as long as a user uses more than 768 bits. Answer: B is incorrect. RSA stands for Rivest, Shamir, and Adleman. It is an algorithm for public-key cryptography. It is the first algorithm known to be suitable for signing as well as encryption, and one of the first great advances in public key cryptography. RSA is widely used in electronic commerce protocols, and is believed to be secure given sufficiently long keys and the use of up-to-date implementations. Answer: C is incorrect. Triple DES is the common name for the Triple Data Encryption Algorithm (TDEA). It is so named because it applies the Data Encryption Standard (DES) cipher algorithm three times to each data block. The Data Encryption Standard (DES) is a block cipher (a form of shared secret encryption), which is based on a symmetric-key algorithm that uses a 56-bit key. The algorithm was initially controversial with classified design elements, a relatively short key length, and suspicions about a National Security Agency (NSA) backdoor. Triple DES provides a relatively simple method of increasing the key size of DES to protect against brute force attacks, without requiring a completely new block cipher algorithm.
Question 13
Single choice
In which of the following is the file audit events are written when auditing is enabled?
A
File system ACL
B
Biometric device
C
Network Access Control List
D
Security event log
Reveal answer detailsClose answer details
Correct answerD
Explanation
The various enabled file auditing events are documented and written in the security event log Answer: A is incorrect. A filesystem ACL is deifned as a data structure (usually a table) that contains entries specifying individual user or group rights to specific system objects like programs, processes, or files. These entries are known as access control entries (ACEs) in the Microsoft Windows NT, OpenVMS, Unix-like, and Mac OS X operating systems and each of the accessible object contains an identifier to its ACL. The permissions are used to find the particular access rights, such as whether a user is able to read from, write to, or execute an object. Answer: C is incorrect. Network Access Control List is defined as a set of rules applied to port numbers or network daemon names that are available on a host or other layer 3, and attached with a list of hosts and networks permitted to use the various defined service. The individual servers and routers can have network ACLs. It is used to control both inbound and outbound traffic as firewall does. Answer: B is incorrect. A biometric device is used for uniquely recognizing humans based upon one or more intrinsic, physical, or behavioral traits. Biometrics is used as a form of identity access management and access control. It is also used to identify individuals in groups that are under surveillance. Biometric characteristics can be divided into two main classes: 1. Physiological: These devices are related to the shape of the body. These are not limited to the fingerprint, face recognition, DNA, hand and palm geometry, and iris recognition, which has largely replaced the retina and odor/scent. 2.Behavioral: These are related to the behavior of a person. They are not limited to the typing rhythm, gait, and voice.
Question 14
Single choice
Which technology enables you to filter communications between a program and the Internet?
A
RADIUS server
B
Antivirus software
C
Software firewall
D
BitLocker To Go
Reveal answer detailsClose answer details
Correct answerC
Explanation
There are two types of firewalls the Hardware Firewall and the Software Firewall. A Software Firewall is a software program and a Hardware Firewall is a piece of hardware. Both have the same objective of filtering communications over a system.
Question 15
Single choice
A Virtual Private Network (VPN) is a/an:
A
Intrusion Prevention System that filters unauthorized communications in the enterprise network
B
virtual communication method that stores data transmitted in a private environment
C
tunnel that prevents information that passes through it from being modified or stolen
D
perimeter network that contains secure virtual servers
Reveal answer detailsClose answer details
Correct answerC
Question 16
Hotspot
HOTSPOT
You are at school and logged in to a Windows 7 computer using a standard user account. You need to change some of the properties of a desktop icon for an assignment. Your instructor provides you with an administrator username and password and asks you to do two tasks. When you open the Need Admin Access Properties window, you see the following image:
Use the drop-down menus to select the answer choice that completes each statement. Each correct selection is worth one point.
Reveal answer detailsClose answer details
Question 17
Single choice
Which of the following viruses cannot be detected by signature-based antivirus?
A
Macro virus
B
Boot sector virus
C
MBR virus
D
Polymorphic virus
Reveal answer detailsClose answer details
Correct answerD
Explanation
A polymorphic virus has the ability to change its own signature at the time of infection. This virus is very complicated and hard to detect. When the user runs the infected file in the disk, it loads the virus into the RAM. The new virus starts making its own copies and infects other files of the operating system. The mutation engine of the polymorphic virus generates a new encrypted code, thus changing the signature of the virus. Therefore, polymorphic viruses cannot be detected by signature-based antivirus. Answer: A is incorrect. A macro virus is a virus that consists of a macro code which infects the system. A Macro virus can infect a system rapidly. Since this virus has VB event handlers, it is dynamic in nature and displays random activation. The victim has only to open a file having a macro virus in order to infect the system with the virus. DMV, Nuclear, and Word Concept are some good examples of macro viruses. Answer: C is incorrect. A Master boot record (MBR) virus replaces the boot sector data with its own malicious code. Every time when the computer starts up, the boot sector virus executes. It can then generate activity that is either annoying (system will play sounds at certain times) or destructive (erase the hard drive of the system). Because the code in the Master Boot Record executes before any operating system is started, no operating system can detect or recover from corruption of the Master Boot Record. Answer: B is incorrect. A boot sector virus infects the master boot files of the hard disk or floppy disk. Boot record programs are responsible for booting the operating system and the boot sector virus copies these programs into another part of the hard disk or overwrites these files. Therefore, when the floppy or the hard disk boots, the virus infects the computer.
Question 18
Single choice
Which of the following actions should be taken so that the computer requires confirmation before installing an ActiveX component?
A
Configuring a firewall on the network
B
Configuring the settings on the Web Browser
C
Installing an anti-virus software
D
Configuring DMZ on the network
Reveal answer detailsClose answer details
Correct answerB
Explanation
Configuring the settings on the Web browser will enable a computer to ask for confirmation before installing an ActiveX component. This will enable users to prevent the download of potentially unsafe controls onto the computer. ActiveX controls are software components that can be integrated into Web pages and applications, within a computer or among computers in a network, to reuse the functionality. Reusability of controls reduces development time of applications and improves program interfaces. They enhance the Web pages with formatting features and animation. ActiveX controls can be used in applications written in different programming languages that recognize Microsoft's Component Object Model (COM). These controls always run in a container. ActiveX controls simplify and automate the authoring tasks, display data, and add functionality to Web pages. Answer: A and D are incorrect. Configuring a firewall or DMZ will not help in accomplishing the task.
Question 19
Single choice
Mark works as a Network Administrator for TechMart Inc. The company has a Windows-based network. Mark wants to implement stronger authentication measures for the customers, as well as eliminate IT staff from logging on with high privileges. Mark has various options, but he is required to keep the processes easy for the helpdesk staff.
Which of the following is a service can the staff uses as an alternative of signing in with elevate privileges?
A
Secondary Logon-Run As
B
Security log
C
Hardware firewall
D
Encrypted network configuration
Reveal answer detailsClose answer details
Correct answerA
Explanation
Secondary Logon (Run As) is defined as a starting programs and tools in local administrative context. Windows secondary logon is used to permit administrators to log on with a non-administrative account and be able to perform the several administrative tasks without logging off by using trusted administrative programs in administrative contexts. Answer: B is incorrect. The security log is generated by a firewall or other security device. It is used to define list of events that could affect the security of data or infrastructure, such as access attempts or commands, and the names of the users participating in this illegal process. Answer: C is incorrect. Hardware firewall is defined as the important part of the system and network set-up on a broadband connection. It can be effective with small or no configuration, and is used to protect every machine on a local network. The hardware firewalls will have at least four network ports for connecting to other computers. This type of firewall uses packet filtering for checking the header of a packet in order to check its source and destination. The information obtained in this manner is compared to a set of predefined or user-created rules and then the packet is forwarded or dropped.
Question 20
Single choice
You manage 50 Windows workstations in a computer lab. All workstations belong to the lab Active Directory domain.
You need to implement several audit policies on each workstation in the shortest time possible.
Setting a database to run on a cluster of servers is an example of applying:
A
accessibility
B
availability
C
confidentially
D
integrity
Reveal answer detailsClose answer details
Correct answerA
Question 22
Multiple choice
Which two are included in an enterprise antivirus program? (Choose two.)
A
Attack surface scanning
B
On-demand scanning
C
Packet scanning
D
Scheduled scanning
Reveal answer detailsClose answer details
Correct answersB, D
Question 23
Single choice
Which of the following is a networking protocol that provides centralized Authentication, Authorization, and Accounting management for computers to connect and use a network service?
A
PEAP
B
RADIUS
C
Kerberos
D
MS-CHAP v2
Reveal answer detailsClose answer details
Correct answerB
Explanation
Remote Authentication Dial In User Service (RADIUS) is a networking protocol that provides centralized Authentication, Authorization, and Accounting (AAA) management for computers to connect and use a network service. Because of the broad support and the ubiquitous nature of the RADIUS protocol, it is often used by ISPs and enterprises to manage access to the Internet or internal networks, wireless networks, and integrated e-mail services. These networks may incorporate modems, DSL, access points, VPNs, network ports, Web servers, etc. RADIUS is a client/server protocol that runs in the application layer, using UDP as transport. The Remote Access Server, the Virtual Private Network server, the Network switch with port-based authentication, and the Network Access Server, are all gateways that control access to the network, and all have a RADIUS client component that communicates with the RADIUS server. The RADIUS server is usually a background process running on a UNIX or Windows NT machine. RADIUS serves three functions: To authenticate users or devices before granting them access to a network To authorize those users or devices for certain network services To account for usage of those services Answer: D is incorrect. Microsoft Challenge Handshake Authentication Protocol version 2 (MS-CHAP v2) is the new version of MS-CHAP. MS-CHAP v2 provides the highest level of security and encryption for dial-up connection in the environment consisting of both Windows NT and Windows 2000/XP dial-up clients. It provides mutual authentication, stronger initial data encryption keys, and different encryption keys for sending and receiving data. Answer: A is incorrect. PEAP (Protected Extensible Authentication Protocol) is a method to securely transmit authentication information over wired or wireless networks. It was jointly developed by Cisco Systems, Microsoft, and RSA Security. PEAP is not an encryption protocol; as with other EAP protocols, it only authenticates a client into a network. PEAP uses server-side public key certificates to authenticate the server. It creates an encrypted SSL/TLS (Secure sockets layer/Transport layer security) tunnel between the client and the authentication server. In most configurations, the keys for this encryption are transported using the server's public key. The resultant exchange of authentication information inside the tunnel to authenticate the client is then encrypted and the user credentials are thus safe and secure. Answer: C is incorrect. Kerberos is a computer network authentication protocol that allows individuals communicating over a non-secure network to prove their identity to one another in a secure manner. Kerberos builds on symmetric key cryptography and requires a trusted third party. Kerberos uses as its basis the Needham-Schroeder protocol. It makes use of a trusted third party, termed a key distribution center (KDC), which consists of two logically separate parts: Authentication Server (AS) Ticket Granting Server (TGS) Kerberos works on the basis of tickets, which serve to prove the identity of users. The KDC maintains a database of secret keys; each entity on the network, whether a client or a server, shares a secret key known only to itself and to the KDC. Knowledge of this key serves to prove an entity's identity. For communication between two entities, the KDC generates a session key, which they can use to secure their interactions.
Question 24
Single choice
Mark works as a Systems Administrator for TechMart Inc. The company has a Windows-based network. The company is adding an open, high-speed, wireless access for their customers and secured wireless for employees at all 37 branches. He wants to check the various security concerns for ensuring that business traffic is secured. He is also under pressure to make this new feature a winning strategy for a company.
Which of the following is the most secure protocol that Mark can implement to ensure that the business-related traffic is encrypted?
A
WiFi Protected Access (WPA) 2
B
Extensible Authentication Protocol (EAP)
C
Wired Equivalent Privacy (WEP)
D
Service Set Identifiers
Reveal answer detailsClose answer details
Correct answerA
Explanation
WPA2 (Wi-Fi Protected Access 2) is used to provide network administrators with a high level of assurance that only authorized users are able to access the network. It provides government grade security by implementing the National Institute of Standards and Technology (NIST) FIPS 140-2 compliant AES encryption algorithm. Wireless Security Options are used to decrease the risk of data interception by a third party in Wireless Networking. Data can be protected by using encryption technologies. In Wireless Networking Connection, various methods are used to increase security as follows: Using Wired Equivalent Privacy: The goal is to allow only authorized users to connect to the wireless network. While initially configuring routers and network adapters, users create a WEP key. The level of security depends on the length of the key measured in bits. Another step is to share WEP keys to authorized users. Specifically, it is possible for unauthorized users to determine the mathematical value of a WEP key by monitoring a sufficient amount of networking traffic. WEP is an additional security, but it does not completely address all potential vulnerabilities. Using Wi-Fi Protected Access: The Wi-Fi Protected Access protocol is used to provide higher security over the WEP standard. It is considered as a replacement for the less secured WEP protocol. WPA security is configured on a wireless router or an access point. Using Service Set Identifiers: Service Set Identifiers are used to assist users to find and connect to a wireless network. Whenever a wireless network adapter is available on a computer, Windows Vista automatically identifies the available networks based on their SSID. Answer: B is incorrect. Extensible Authentication Protocol (EAP) is defined as an authentication framework providing for the transport and usage of keying material and parameters that are generated by EAP methods. EAP is not a wire protocol and it defines only message formats.
Question 25
Single choice
You are trying to enable BitLocker on your father's computer.
What is the purpose of the Trusted Platform Module (TPM) when it is used by BitLocker?
A
to store an encrypted file allocation table for the protected drive
B
to provide a co-processor that encrypts/decrypts data
C
to verify the integrity of the early boot components
D
to store the hashed data produced by BitLocker encryption
Reveal answer detailsClose answer details
Correct answerC
Question 26
Single choice
Which of the following tools traces all or specific activities of a user on a computer?
A
Task Manager
B
Event Viewer
C
Network Monitor
D
Keylogger
Reveal answer detailsClose answer details
Correct answerD
Explanation
A keylogger is a software tool that traces all or specific activities of a user on a computer. Once a keylogger is installed on a victim's computer, it can be used for recording all keystrokes on the victim's computer in a predefined log file. An attacker can configure a log file in such a manner that it can be sent automatically to a predefined e-mail address. Some of the main features of a keylogger are as follows: It can record all keystrokes. It can capture all screenshots. It can record all instant messenger conversations. It can be remotely installed. It can be delivered via FTP or e-mail. Answer: A is incorrect. Task Manager is a utility that is used for managing applications, processes, and the general system performance and also for viewing the networking and user statistics. The Task Manager utility is used to run or end programs or applications. Administrators use this tool to quickly identify and terminate a rogue application.
This utility can be run by invoking a Windows Security menu by using the Ctrl+Alt+Delkey combination and then clicking the Task Manager button or by right-clicking the task bar and then clicking the Task Managermenu option. Answer: B is incorrect. Event Viewer is an administrative utility that displays the event log of a computer running Windows NT. Event Viewer displays the following categories of events: Error: These events show significant problems, such as loss of data or loss of functionality. Warning: These events are not necessarily significant but indicate possible problems. Information: These events describe the successful operation of an application, driver, or service. Success Audit: These events show successful audited security access attempts. Failure Audit: These events show failed audited security access attempts. Answer: C is incorrect. Network Monitor (Netmon) is a protocol analyzer. It is used to analyze the network traffic. It is installed by default during the installation of the operating system. It can be installed by using Windows Components Wizard in the Add or Remove Programs tool in Control Panel. Network Monitor is used to perform the following tasks: 1. Capture frames directly from the network. 2. Display and filter captured frames immediately after capture or a later time. 3. Edit captured frames and transmit them on the network. 4. Capture frames from a remote computer.
Question 27
Multiple choice
Which two characteristics should you recommend for a user's domain password? (Choose two.)
Installing uninterruptible power sources to your servers is an example of ensuring:
A
integrity
B
a backup strategy
C
availability
D
accessibility
Reveal answer detailsClose answer details
Correct answerA
Question 29
Multiple choice
You work as a Network Administrator for NetTech Inc. Your computer has the Windows 2000 Server operating system. You want to harden the security of the server. Which of the following changes are required to accomplish this? Each correct answer represents a complete solution. Choose two.
A
Enable the Guest account.
B
Rename the Administrator account.
C
Remove the Administrator account.
D
Disable the Guest account.
Reveal answer detailsClose answer details
Correct answersB, D
Explanation
Answer: B and D For security, you will have to rename the Administrator account and disable the Guest account. Renaming the Administrator account will ensure that hackers do not break into the network or computer by guessing the password of the Administrator account. You can also create a fake Administrator account that has no privileges and audit its use to detect attacks. Disabling the Guest account will prevent users who do not have a domain or local user account from illegally accessing the network or computer. By default, the Guest account is disabled on systems running Windows 2000 Server. If the Guest account is enabled, you will have to disable it.
Question 30
Single choice
Windows Server Update Services (WSUS) is a tool that:
A
Updates data stored in Windows servers
B
Manages the services that run on a server
C
Updates licensing for Windows servers
D
Manages updates for Microsoft software
Reveal answer detailsClose answer details
Correct answerD
Explanation
Windows Server Update Services (WSUS) enables information technology administrators to deploy the latest Microsoft product updates to computers that are running the Windows operating system. By using WSUS, administrators can fully manage the distribution of updates that are released through Microsoft Update to computers in their network. References: http://technet.microsoft.com/en-us/windowsserver/bb332157.aspx
Question 31
Hotspot
HOTSPOT
For each of the following statements, select Yes if the statement is true. Otherwise, select No. Each correct selection is worth one point.
Reveal answer detailsClose answer details
Question 32
Single choice
You are taking over the security of an existing network. You discover a machine that is not being used as such, but has software on it that emulates the activity of a sensitive database server.
What is this?
A
A Polymorphic Virus
B
A Honey Pot
C
A reactive IDS.
D
A Virus
Reveal answer detailsClose answer details
Correct answerB
Explanation
A honey pot is a device specifically designed to emulate a high value target such as a database server or entire sub section of your network. It is designed to attract the hacker's attention.
Question 33
Single choice
Which of the following security methods can be used to detect the DoS attack in order to enhance the security of the network?
A
Protocol analyzer
B
WIPS
C
WLAN controller
D
Spectrum analyzer
Reveal answer detailsClose answer details
Correct answerB
Explanation
WIPS is used to detect the DOS attack in order to enhance the security of the network. Wireless intrusion prevention system (WIPS) is a network device that monitors the radio spectrum for the presence ofunauthorized access points (intrusion detection), and can automaticallytake countermeasures (intrusion prevention). The primary purpose of a WIPS is to prevent unauthorized network access to local area networks and other information assets by wireless devices. Answer: C is incorrect. A wireless LAN controller is a device that is used in combination with Lightweight Access Point Protocol (LWAPP) to manage light weight access points in large quantities by the network administrator or NOC. The wireless LAN controller is a part of the Data Plane within the Cisco Wireless Model. The WLAN controller automatically handles the configuration of anywhere from 6 to 300 wireless access-points, depending on the model. Answer: D is incorrect. A spectrum analyzer, or spectral analyzer, is a device that is used to examine the spectral composition of some electrical, acoustic, or optical waveform. It may also measure the power spectrum. The analog and digital spectrum analyzers are as follows: 1. An analog spectrum analyzer uses either a variable band-pass filter whose mid-frequency is automatically tuned (shifted, swept) through the range of frequencies of which the spectrum is to be measured. 2. A digital spectrum analyzer computes the discrete Fourier transform (DFT), a mathematical process that transforms a waveform into the components of its frequency spectrum. Answer: A is incorrect. A protocol analyzer is a network diagnostic utility for viewing the current contents of a packet traveling on the network. Protocol analyzers are mainly used for performance measurement and troubleshooting. These devices connect to the network to calculate key performance indicators (KPI) to monitor the network and speed up troubleshooting activities.
Question 34
Drag & drop
DRAG DROP
Certain potentially harmful file types should be filtered as attachments of incoming email messages. Match the file extension that should be filtered with its description. Instructions: To answer, drag the appropriate file extension from the column on the left to its description on the right. Each file extension may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. Note: For each correct selection is worth one point.
Reveal answer detailsClose answer details
Question 35
Hotspot
HOTSPOT
You are preparing a local audit policy for your workstation. No auditing is enabled. The settings of your policy are shown in the following image:
Use the drop-down menus to select the answer choice that completes each statement. Each correct selection is worth one point.
Reveal answer detailsClose answer details
Explanation
Dozens of events can be audited in Windows. The events fall into several categories:
Audit account logon events - audit each instance of a user logging on to or logging off from another computer in which this computer is used to validate the account. This event category is applicable to domain controllers only since DC's are used to validate accounts in domains. Audit account management - audit each event of account management on a computer. Examples of account maintenance include password changes, user account and group modifications. Audit directory service access - audit the event of a user accessing an Active Directory object that has its own system access control list (SACL) specified. Audit logon events - audit each instance of a user logging on to or logging off from a computer. Note that this is different than the 'Audit account login events' category. This tracks the logon event to a specific server. The former tracks which domain controller authenticated the user. Audit object access - audit the event of a user accessing an object that has its own system access control list (SACL) specified. Examples of objects are files, folders, registry keys, printers, etc. Audit policy change - audit every incident of a change to user rights assignment policies, audit policies, or trust policies. Audit privilege use - audit each instance of a user exercising a user right. Audit process tracking - audit detailed tracking information for events such as program activation, process exit, handle duplication, and indirect object access. Audit system events - audit when a user restarts or shuts down the computer or when an event occurs that affects either the system security or the security log. References: http://www.petri.co.il/windows_auditing.htm
Question 36
Single choice
Which of the following is a security protocol that is used to protect data from being modified, corrupted, or accessed without authorization?
A
Honeypot
B
IP Security (IPsec)
C
DNSSEC
D
Protocol spoofing
Reveal answer detailsClose answer details
Correct answerB
Explanation
Internet Protocol Security (IPsec) is a protocol suite for securing Internet Protocol (IP) communications by authenticating and encrypting each IP packet of a data stream. IPsec also includes protocols for establishing mutual authentication between agents at the beginning of the session and negotiation of cryptographic keys to be used during the session. IPsec can be used to protect data flows between a pair of hosts, between a pair of security gateways, or between a security gateway and a host. Answer: C is incorrect. Domain Name System Security Extensions (DNSSEC) is a suite of Internet Engineering Task Force (IETF) specifications for securing certain kinds of information provided by the Domain Name System (DNS) as used on Internet Protocol (IP) networks. It is a set of extensions to DNS which provide to DNS clients origin authentication of DNS data, authenticated denial of existence, and data integrity, but not availability or confidentiality. Answer: A is incorrect. A honey pot is a computer that is used to attract potential intruders or attackers. It is for this reason that a honey pot has low security permissions. A honey pot is used to gain information about the intruders and their attack strategies. Answer: D is incorrect. Protocol spoofing is used in data communications for enhancing the performance in situations where an currently working protocol is inadequate. In a computer security context, it refers to several forms of falsification of technically unrelated data.
Question 37
Single choice
You are a network administrator.
All computers run the Microsoft Edge browser.
You need to prevent web cookies from being saved.
What should you enforce?
A
SmartScreen Filter
B
InPrivate Browsing
C
Antivirus protection
D
Cross-Site Scripting Filter
Reveal answer detailsClose answer details
Correct answerB
Question 38
Single choice
You work as a security manager for Company Inc. An individual is connecting to your corporate internal network over the Internet. You have to ensure that he is not an intruder masquerading as an authorized user.
Which of the following technologies will you use to accomplish the task?
A
Two-factor authentication
B
IP address packet filtering
C
Intrusion detection system (IDS)
D
Embedded digital signature
Reveal answer detailsClose answer details
Correct answerA
Explanation
Two-factor authentication offers an extra security mechanism above that offered by passwords alone. It is frequently used by mobile users who want to establish connectivity to a corporate network.
Question 39
Single choice
Which type of password attack attempts to guess passwords by using a list of common passwords?
A
Keylogger
B
brute force
C
man-in-the-middle
D
dictionary
Reveal answer detailsClose answer details
Correct answerD
Question 40
Hotspot
HOTSPOT
For each of the following statements, select Yes if the statement is true. Otherwise, select No. Each correct selection is worth one point.
Reveal answer detailsClose answer details
Question 41
Single choice
You sign up for an online bank account. Every 6 months, the bank requires you to change your password. You have changed your password 5 times in the past. Instead of coming up with a new password, you decide to use one of your past passwords, but the bank's password history prevents you on doing so.
Select the correct answer if the underlined text does not make the statement correct Select "No change is needed" if the underlined text makes the statement correct.
Match the authentication protocol with its description.
Instructions: To answer, drag the appropriate authentication protocol from the column on the left to its description on the right. Each authentication protocol may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Correct Answer:
QUESTION 2
The manager of a coffee shop hires you to securely set up WiFi in the shop.
To keep computer users from seeing each other, what should you use with an access point?
A.
Client bridge mode
B.
Client isolation mode
C.
MAC address filtering
D.
Client mode
Correct Answer: B
Explanation
Explanation/Reference:
Wireless Client Isolation is a unique security feature for wireless networks. When Client Isolation is enabled any and all devices connected to the wireless LAN will be unable to talk to each other.
QUESTION 3
Dumpster diving refers to a physical threat that a hacker might use to look for information about a computer network.
Select the correct answer if the underlined text does not make the statement correct. Select "No change is needed" if the underlined text makes the statement correct.
A.
Phishing
B.
Malware
C.
Reverse Social engineering
D.
No change is needed
Correct Answer: D
QUESTION 4
A mail system administrator scans for viruses in incoming emails to increase the speed of mail processing.
Select the correct answer if the underlined text does not make the statement correct. Select "No change is needed" if the underlined text makes the statement correct.
A.
Decrease the chances of a virus getting to a client machine
B.
Verify that the senders of the messages are legitimate
C.
Ensure that all links in the messages are trustworthy
D.
No change is needed.
Correct Answer: A
QUESTION 5
HOTSPOT
An employee where you work is unable to access the company message board in Internet Explorer. You review her Internet Options dialog box, as shown in the following image:
Use the drop-down menus to select the answer choice that completes each statement.
Each correct selection is worth one point.
Correct Answer:
QUESTION 6
Which of the following is used to protect all files stored on the drive on which Windows is installed?
A.
SocketShield
B.
Firewall
C.
Bitlocker
D.
Hardware keylogger
Correct Answer: C
Explanation
Explanation/Reference:
BitLocker is used to protect all files stored on the drive on which Windows is installed. It encrypts the entire system drive and helps block hackers from accessing the system files they rely on to discover user passwords. BitLocker also prevents hackers from accessing the hard disk by removing it from a computer, and installing it on a different computer. BitLocker does not work for USB Flash Drives. Answer: A is incorrect. SocketShield provides a protection shield to a computer system against malware, viruses, spyware, and various types of keyloggers. SocketShield provides protection at the following two levels: 1. Blocking: In this level, SocketShield uses a list of IP addresses that are known as purveyor of exploits. All http requests for any page in these domains are simply blocked. 2. Shielding: In this level, SocketShield blocks all the current and past IP addresses that are the cause of unauthorized access. Answer: B is incorrect. A firewall is a system that helps in preventing access to a system from unauthorized internet or network users. A firewall can be hardware as well as software. A firewall is implemented on systems that are connected to the internet and are vulnerable to hackers, viruses, worms, and other harmful intrusions. Answer: D is incorrect. Hardware keyloggers are used for keystroke logging, a method of capturing and recording computer users' keystrokes, including sensitive passwords. They can be implemented via BIOS-level firmware, or alternatively, via a device plugged inline between a computer keyboard and a computer. They log all keyboard activities to their internal memory.
QUESTION 7
John works as a Network Administrator for We-are-secure Inc. The We-are-secure server is based on Windows Server 2003. One day, while analyzing the network security, he receives an error message that Kernel32.exe is encountering a problem. Which of the following steps should John take as a countermeasure to this situation? Each correct answer represents a complete solution. Choose all that apply.
A.
He should restore his Windows settings.
B.
He should upgrade his antivirus program.
C.
He should observe the process viewer (Task Manager) to see whether any new process is running on the computer or not. If any new malicious process is running, he should kill that process.
D.
He should download the latest patches for Windows Server 2003 from the Microsoft site, so that he can repair the kernel.
Correct Answer: BC
Explanation
Explanation/Reference:
Answer: B and C In such a situation, when John receives an error message revealing that Kernel32.exe is encountering a problem, he needs to come to the conclusion that his antivirus program needs to be updated, because Kernel32.exe is not a Microsoft file (It is a Kernel32.DLL file.). Although such viruses normally run on stealth mode, he should examine the process viewer (Task Manager) to see whether any new process is running on the computer or not. If any new process (malicious) is running on the server, he should exterminate that process. Answer: A and D are incorrect. Since kernel.exe is not a real kernel file of Windows, there is no need to repair or download any patch for Windows Server 2003 from the Microsoft site to repair the kernel. Note: Such error messages can be received if the computer is infected with malware, such as Worm_Badtrans.b, Backdoor.G_Door, Glacier Backdoor, Win32.Badtrans.29020, etc.
QUESTION 8
Which of the following types of Network Address Translation (NAT) uses a pool of public IP addresses?
A.
Static NAT
B.
Port Address Translation (PAT)
C.
Dynamic NAT
D.
Cache NAT
Correct Answer: C
Explanation
Explanation/Reference:
Dynamic Network Address Translation (NAT) uses a pool of public IP addresses. Dynamic NAT is a technique that maps an unregistered IP address to a registered IP address from a group of registered IP addresses. It also establishes a one-to-one mapping between unregistered (private) and registered (public) IP addresses, but the mapping varies depending on the registered address available in the IP address pool at the time of connection. Answer: A is incorrect. Static NAT performs a manual translation of one IP address to a different one. Static NAT is typically used to translate the destination IP address in packets that reach to the translation device (such as a router) for LAN. In static translation type, a manual translation is performed between two addresses and possibly port numbers. Answer: B is incorrect. Port Address Translation (PAT) is also a type of NAT. This type of NAT is used in home networks that are using DSL or cable modems. It is designed to provide Internet access to many internal users through one external address. Answer: D is incorrect. There is no such type of NAT as Cache NAT.
QUESTION 9
Which of the following practices should be followed to keep passwords secure? Each correct answer represents a complete solution. Choose three.
A.
Change the passwords whenever there is suspicion that they may have been compromised.
B.
A password should be alpha-numeric.
C.
A password should not be more than five words.
D.
Never write down a password.
Correct Answer: ABD
Explanation
Explanation/Reference:
Answer: D, A, and B The following practices should be followed to keep passwords secure: Never write down a password. Change the passwords whenever there is suspicion that they may have been compromised. A password should be alpha-numeric. Never use the same password for more than one account. Never tell a password to anyone, including people who claim to be from customer service or security. Never communicate a password by telephone, e-mail, or instant messaging. Ensure that an operating system password and application passwords are different. Make passwords completely random but easy for you to remember.
Which is the minimum requirement to create BitLocker-To-Go media on a client computer?
A.
Windows XP Professional Service Pack 3
B.
Windows Vista Enterprise Edition
C.
Windows 7 Enterprise Edition
D.
Windows 2000 Professional Service Pack 4
Correct Answer: A
QUESTION 12
Which of the following is a US Federal government algorithm created to generate a secure message digest?
A.
DSA
B.
RSA
C.
Triple DES
D.
SHA
Correct Answer: D
Explanation
Explanation/Reference:
SHA is a Federal government algorithm created to generate a secure message digest. The Secure Hash Algorithm (SHA) is a cryptographic hash algorithm. It generates a fixed-length digital representation (message digest) of an input data sequence of any length. The SHA algorithm is very secure, as it is computationally very difficult to find a message that corresponds to a given message digest. In this algorithm, any change to a message will result in a completely different message digest. There are five SHA algorithms: SHA-1, SHA-224, SHA-256, SHA-384, and SHA-512. Answer: A is incorrect. Digital Signature Algorithm (DSA) is a United States Federal Government standard or FIPS for digital signatures. DSA is a public key algorithm; the secret key operates on the message hash generated by SHA-1; to verify a signature, one recomputes the hash of the message, uses the public key to decrypt the signature and then compares the results. The key size is variable from 512 to 1024 bits, which is adequate for the current computing capabilities as long as a user uses more than 768 bits. Answer: B is incorrect. RSA stands for Rivest, Shamir, and Adleman. It is an algorithm for public-key cryptography. It is the first algorithm known to be suitable for signing as well as encryption, and one of the first great advances in public key cryptography. RSA is widely used in electronic commerce protocols, and is believed to be secure given sufficiently long keys and the use of up-to-date implementations. Answer: C is incorrect. Triple DES is the common name for the Triple Data Encryption Algorithm (TDEA). It is so named because it applies the Data Encryption Standard (DES) cipher algorithm three times to each data block. The Data Encryption Standard (DES) is a block cipher (a form of shared secret encryption), which is based on a symmetric-key algorithm that uses a 56-bit key. The algorithm was initially controversial with classified design elements, a relatively short key length, and suspicions about a National Security Agency (NSA) backdoor. Triple DES provides a relatively simple method of increasing the key size of DES to protect against brute force attacks, without requiring a completely new block cipher algorithm.
QUESTION 13
In which of the following is the file audit events are written when auditing is enabled?
A.
File system ACL
B.
Biometric device
C.
Network Access Control List
D.
Security event log
Correct Answer: D
Explanation
Explanation/Reference:
The various enabled file auditing events are documented and written in the security event log Answer: A is incorrect. A filesystem ACL is deifned as a data structure (usually a table) that contains entries specifying individual user or group rights to specific system objects like programs, processes, or files. These entries are known as access control entries (ACEs) in the Microsoft Windows NT, OpenVMS, Unix-like, and Mac OS X operating systems and each of the accessible object contains an identifier to its ACL. The permissions are used to find the particular access rights, such as whether a user is able to read from, write to, or execute an object. Answer: C is incorrect. Network Access Control List is defined as a set of rules applied to port numbers or network daemon names that are available on a host or other layer 3, and attached with a list of hosts and networks permitted to use the various defined service. The individual servers and routers can have network ACLs. It is used to control both inbound and outbound traffic as firewall does. Answer: B is incorrect. A biometric device is used for uniquely recognizing humans based upon one or more intrinsic, physical, or behavioral traits. Biometrics is used as a form of identity access management and access control. It is also used to identify individuals in groups that are under surveillance. Biometric characteristics can be divided into two main classes: 1. Physiological: These devices are related to the shape of the body. These are not limited to the fingerprint, face recognition, DNA, hand and palm geometry, and iris recognition, which has largely replaced the retina and odor/scent. 2.Behavioral: These are related to the behavior of a person. They are not limited to the typing rhythm, gait, and voice.
QUESTION 14
Which technology enables you to filter communications between a program and the Internet?
A.
RADIUS server
B.
Antivirus software
C.
Software firewall
D.
BitLocker To Go
Correct Answer: C
Explanation
Explanation/Reference:
There are two types of firewalls the Hardware Firewall and the Software Firewall. A Software Firewall is a software program and a Hardware Firewall is a piece of hardware. Both have the same objective of filtering communications over a system.
QUESTION 15
A Virtual Private Network (VPN) is a/an:
A.
Intrusion Prevention System that filters unauthorized communications in the enterprise network
B.
virtual communication method that stores data transmitted in a private environment
C.
tunnel that prevents information that passes through it from being modified or stolen
D.
perimeter network that contains secure virtual servers
Correct Answer: C
QUESTION 16
HOTSPOT
You are at school and logged in to a Windows 7 computer using a standard user account. You need to change some of the properties of a desktop icon for an assignment. Your instructor provides you with an administrator username and password and asks you to do two tasks. When you open the Need Admin Access Properties window, you see the following image:
Use the drop-down menus to select the answer choice that completes each statement. Each correct selection is worth one point.
Correct Answer:
QUESTION 17
Which of the following viruses cannot be detected by signature-based antivirus?
A.
Macro virus
B.
Boot sector virus
C.
MBR virus
D.
Polymorphic virus
Correct Answer: D
Explanation
Explanation/Reference:
A polymorphic virus has the ability to change its own signature at the time of infection. This virus is very complicated and hard to detect. When the user runs the infected file in the disk, it loads the virus into the RAM. The new virus starts making its own copies and infects other files of the operating system. The mutation engine of the polymorphic virus generates a new encrypted code, thus changing the signature of the virus. Therefore, polymorphic viruses cannot be detected by signature-based antivirus. Answer: A is incorrect. A macro virus is a virus that consists of a macro code which infects the system. A Macro virus can infect a system rapidly. Since this virus has VB event handlers, it is dynamic in nature and displays random activation. The victim has only to open a file having a macro virus in order to infect the system with the virus. DMV, Nuclear, and Word Concept are some good examples of macro viruses. Answer: C is incorrect. A Master boot record (MBR) virus replaces the boot sector data with its own malicious code. Every time when the computer starts up, the boot sector virus executes. It can then generate activity that is either annoying (system will play sounds at certain times) or destructive (erase the hard drive of the system). Because the code in the Master Boot Record executes before any operating system is started, no operating system can detect or recover from corruption of the Master Boot Record. Answer: B is incorrect. A boot sector virus infects the master boot files of the hard disk or floppy disk. Boot record programs are responsible for booting the operating system and the boot sector virus copies these programs into another part of the hard disk or overwrites these files. Therefore, when the floppy or the hard disk boots, the virus infects the computer.
QUESTION 18
Which of the following actions should be taken so that the computer requires confirmation before installing an ActiveX component?
A.
Configuring a firewall on the network
B.
Configuring the settings on the Web Browser
C.
Installing an anti-virus software
D.
Configuring DMZ on the network
Correct Answer: B
Explanation
Explanation/Reference:
Configuring the settings on the Web browser will enable a computer to ask for confirmation before installing an ActiveX component. This will enable users to prevent the download of potentially unsafe controls onto the computer. ActiveX controls are software components that can be integrated into Web pages and applications, within a computer or among computers in a network, to reuse the functionality. Reusability of controls reduces development time of applications and improves program interfaces. They enhance the Web pages with formatting features and animation. ActiveX controls can be used in applications written in different programming languages that recognize Microsoft's Component Object Model (COM). These controls always run in a container. ActiveX controls simplify and automate the authoring tasks, display data, and add functionality to Web pages. Answer: A and D are incorrect. Configuring a firewall or DMZ will not help in accomplishing the task.
QUESTION 19
Mark works as a Network Administrator for TechMart Inc. The company has a Windows-based network. Mark wants to implement stronger authentication measures for the customers, as well as eliminate IT staff from logging on with high privileges. Mark has various options, but he is required to keep the processes easy for the helpdesk staff.
Which of the following is a service can the staff uses as an alternative of signing in with elevate privileges?
A.
Secondary Logon-Run As
B.
Security log
C.
Hardware firewall
D.
Encrypted network configuration
Correct Answer: A
Explanation
Explanation/Reference:
Secondary Logon (Run As) is defined as a starting programs and tools in local administrative context. Windows secondary logon is used to permit administrators to log on with a non-administrative account and be able to perform the several administrative tasks without logging off by using trusted administrative programs in administrative contexts. Answer: B is incorrect. The security log is generated by a firewall or other security device. It is used to define list of events that could affect the security of data or infrastructure, such as access attempts or commands, and the names of the users participating in this illegal process. Answer: C is incorrect. Hardware firewall is defined as the important part of the system and network set-up on a broadband connection. It can be effective with small or no configuration, and is used to protect every machine on a local network. The hardware firewalls will have at least four network ports for connecting to other computers. This type of firewall uses packet filtering for checking the header of a packet in order to check its source and destination. The information obtained in this manner is compared to a set of predefined or user-created rules and then the packet is forwarded or dropped.
QUESTION 20
You manage 50 Windows workstations in a computer lab. All workstations belong to the lab Active Directory domain.
You need to implement several audit policies on each workstation in the shortest time possible.
Setting a database to run on a cluster of servers is an example of applying:
A.
accessibility
B.
availability
C.
confidentially
D.
integrity
Correct Answer: A
QUESTION 22
Which two are included in an enterprise antivirus program? (Choose two.)
A.
Attack surface scanning
B.
On-demand scanning
C.
Packet scanning
D.
Scheduled scanning
Correct Answer: BD
QUESTION 23
Which of the following is a networking protocol that provides centralized Authentication, Authorization, and Accounting management for computers to connect and use a network service?
A.
PEAP
B.
RADIUS
C.
Kerberos
D.
MS-CHAP v2
Correct Answer: B
Explanation
Explanation/Reference:
Remote Authentication Dial In User Service (RADIUS) is a networking protocol that provides centralized Authentication, Authorization, and Accounting (AAA) management for computers to connect and use a network service. Because of the broad support and the ubiquitous nature of the RADIUS protocol, it is often used by ISPs and enterprises to manage access to the Internet or internal networks, wireless networks, and integrated e-mail services. These networks may incorporate modems, DSL, access points, VPNs, network ports, Web servers, etc. RADIUS is a client/server protocol that runs in the application layer, using UDP as transport. The Remote Access Server, the Virtual Private Network server, the Network switch with port-based authentication, and the Network Access Server, are all gateways that control access to the network, and all have a RADIUS client component that communicates with the RADIUS server. The RADIUS server is usually a background process running on a UNIX or Windows NT machine. RADIUS serves three functions: To authenticate users or devices before granting them access to a network To authorize those users or devices for certain network services To account for usage of those services Answer: D is incorrect. Microsoft Challenge Handshake Authentication Protocol version 2 (MS-CHAP v2) is the new version of MS-CHAP. MS-CHAP v2 provides the highest level of security and encryption for dial-up connection in the environment consisting of both Windows NT and Windows 2000/XP dial-up clients. It provides mutual authentication, stronger initial data encryption keys, and different encryption keys for sending and receiving data. Answer: A is incorrect. PEAP (Protected Extensible Authentication Protocol) is a method to securely transmit authentication information over wired or wireless networks. It was jointly developed by Cisco Systems, Microsoft, and RSA Security. PEAP is not an encryption protocol; as with other EAP protocols, it only authenticates a client into a network. PEAP uses server-side public key certificates to authenticate the server. It creates an encrypted SSL/TLS (Secure sockets layer/Transport layer security) tunnel between the client and the authentication server. In most configurations, the keys for this encryption are transported using the server's public key. The resultant exchange of authentication information inside the tunnel to authenticate the client is then encrypted and the user credentials are thus safe and secure. Answer: C is incorrect. Kerberos is a computer network authentication protocol that allows individuals communicating over a non-secure network to prove their identity to one another in a secure manner. Kerberos builds on symmetric key cryptography and requires a trusted third party. Kerberos uses as its basis the Needham-Schroeder protocol. It makes use of a trusted third party, termed a key distribution center (KDC), which consists of two logically separate parts: Authentication Server (AS) Ticket Granting Server (TGS) Kerberos works on the basis of tickets, which serve to prove the identity of users. The KDC maintains a database of secret keys; each entity on the network, whether a client or a server, shares a secret key known only to itself and to the KDC. Knowledge of this key serves to prove an entity's identity. For communication between two entities, the KDC generates a session key, which they can use to secure their interactions.
QUESTION 24
Mark works as a Systems Administrator for TechMart Inc. The company has a Windows-based network. The company is adding an open, high-speed, wireless access for their customers and secured wireless for employees at all 37 branches. He wants to check the various security concerns for ensuring that business traffic is secured. He is also under pressure to make this new feature a winning strategy for a company.
Which of the following is the most secure protocol that Mark can implement to ensure that the business-related traffic is encrypted?
A.
WiFi Protected Access (WPA) 2
B.
Extensible Authentication Protocol (EAP)
C.
Wired Equivalent Privacy (WEP)
D.
Service Set Identifiers
Correct Answer: A
Explanation
Explanation/Reference:
WPA2 (Wi-Fi Protected Access 2) is used to provide network administrators with a high level of assurance that only authorized users are able to access the network. It provides government grade security by implementing the National Institute of Standards and Technology (NIST) FIPS 140-2 compliant AES encryption algorithm. Wireless Security Options are used to decrease the risk of data interception by a third party in Wireless Networking. Data can be protected by using encryption technologies. In Wireless Networking Connection, various methods are used to increase security as follows: Using Wired Equivalent Privacy: The goal is to allow only authorized users to connect to the wireless network. While initially configuring routers and network adapters, users create a WEP key. The level of security depends on the length of the key measured in bits. Another step is to share WEP keys to authorized users. Specifically, it is possible for unauthorized users to determine the mathematical value of a WEP key by monitoring a sufficient amount of networking traffic. WEP is an additional security, but it does not completely address all potential vulnerabilities. Using Wi-Fi Protected Access: The Wi-Fi Protected Access protocol is used to provide higher security over the WEP standard. It is considered as a replacement for the less secured WEP protocol. WPA security is configured on a wireless router or an access point. Using Service Set Identifiers: Service Set Identifiers are used to assist users to find and connect to a wireless network. Whenever a wireless network adapter is available on a computer, Windows Vista automatically identifies the available networks based on their SSID. Answer: B is incorrect. Extensible Authentication Protocol (EAP) is defined as an authentication framework providing for the transport and usage of keying material and parameters that are generated by EAP methods. EAP is not a wire protocol and it defines only message formats.
QUESTION 25
You are trying to enable BitLocker on your father's computer.
What is the purpose of the Trusted Platform Module (TPM) when it is used by BitLocker?
A.
to store an encrypted file allocation table for the protected drive
B.
to provide a co-processor that encrypts/decrypts data
C.
to verify the integrity of the early boot components
D.
to store the hashed data produced by BitLocker encryption
Correct Answer: C
QUESTION 26
Which of the following tools traces all or specific activities of a user on a computer?
A.
Task Manager
B.
Event Viewer
C.
Network Monitor
D.
Keylogger
Correct Answer: D
Explanation
Explanation/Reference:
A keylogger is a software tool that traces all or specific activities of a user on a computer. Once a keylogger is installed on a victim's computer, it can be used for recording all keystrokes on the victim's computer in a predefined log file. An attacker can configure a log file in such a manner that it can be sent automatically to a predefined e-mail address. Some of the main features of a keylogger are as follows: It can record all keystrokes. It can capture all screenshots. It can record all instant messenger conversations. It can be remotely installed. It can be delivered via FTP or e-mail. Answer: A is incorrect. Task Manager is a utility that is used for managing applications, processes, and the general system performance and also for viewing the networking and user statistics. The Task Manager utility is used to run or end programs or applications. Administrators use this tool to quickly identify and terminate a rogue application.
This utility can be run by invoking a Windows Security menu by using the Ctrl+Alt+Delkey combination and then clicking the Task Manager button or by right-clicking the task bar and then clicking the Task Managermenu option. Answer: B is incorrect. Event Viewer is an administrative utility that displays the event log of a computer running Windows NT. Event Viewer displays the following categories of events: Error: These events show significant problems, such as loss of data or loss of functionality. Warning: These events are not necessarily significant but indicate possible problems. Information: These events describe the successful operation of an application, driver, or service. Success Audit: These events show successful audited security access attempts. Failure Audit: These events show failed audited security access attempts. Answer: C is incorrect. Network Monitor (Netmon) is a protocol analyzer. It is used to analyze the network traffic. It is installed by default during the installation of the operating system. It can be installed by using Windows Components Wizard in the Add or Remove Programs tool in Control Panel. Network Monitor is used to perform the following tasks: 1. Capture frames directly from the network. 2. Display and filter captured frames immediately after capture or a later time. 3. Edit captured frames and transmit them on the network. 4. Capture frames from a remote computer.
QUESTION 27
Which two characteristics should you recommend for a user's domain password? (Choose two.)
Installing uninterruptible power sources to your servers is an example of ensuring:
A.
integrity
B.
a backup strategy
C.
availability
D.
accessibility
Correct Answer: A
QUESTION 29
You work as a Network Administrator for NetTech Inc. Your computer has the Windows 2000 Server operating system. You want to harden the security of the server. Which of the following changes are required to accomplish this? Each correct answer represents a complete solution. Choose two.
A.
Enable the Guest account.
B.
Rename the Administrator account.
C.
Remove the Administrator account.
D.
Disable the Guest account.
Correct Answer: BD
Explanation
Explanation/Reference:
Answer: B and D For security, you will have to rename the Administrator account and disable the Guest account. Renaming the Administrator account will ensure that hackers do not break into the network or computer by guessing the password of the Administrator account. You can also create a fake Administrator account that has no privileges and audit its use to detect attacks. Disabling the Guest account will prevent users who do not have a domain or local user account from illegally accessing the network or computer. By default, the Guest account is disabled on systems running Windows 2000 Server. If the Guest account is enabled, you will have to disable it.
QUESTION 30
Windows Server Update Services (WSUS) is a tool that:
A.
Updates data stored in Windows servers
B.
Manages the services that run on a server
C.
Updates licensing for Windows servers
D.
Manages updates for Microsoft software
Correct Answer: D
Explanation
Explanation/Reference:
Windows Server Update Services (WSUS) enables information technology administrators to deploy the latest Microsoft product updates to computers that are running the Windows operating system. By using WSUS, administrators can fully manage the distribution of updates that are released through Microsoft Update to computers in their network. References: http://technet.microsoft.com/en-us/windowsserver/bb332157.aspx
QUESTION 31
HOTSPOT
For each of the following statements, select Yes if the statement is true. Otherwise, select No. Each correct selection is worth one point.
Correct Answer:
QUESTION 32
You are taking over the security of an existing network. You discover a machine that is not being used as such, but has software on it that emulates the activity of a sensitive database server.
What is this?
A.
A Polymorphic Virus
B.
A Honey Pot
C.
A reactive IDS.
D.
A Virus
Correct Answer: B
Explanation
Explanation/Reference:
A honey pot is a device specifically designed to emulate a high value target such as a database server or entire sub section of your network. It is designed to attract the hacker's attention.
QUESTION 33
Which of the following security methods can be used to detect the DoS attack in order to enhance the security of the network?
A.
Protocol analyzer
B.
WIPS
C.
WLAN controller
D.
Spectrum analyzer
Correct Answer: B
Explanation
Explanation/Reference:
WIPS is used to detect the DOS attack in order to enhance the security of the network. Wireless intrusion prevention system (WIPS) is a network device that monitors the radio spectrum for the presence ofunauthorized access points (intrusion detection), and can automaticallytake countermeasures (intrusion prevention). The primary purpose of a WIPS is to prevent unauthorized network access to local area networks and other information assets by wireless devices. Answer: C is incorrect. A wireless LAN controller is a device that is used in combination with Lightweight Access Point Protocol (LWAPP) to manage light weight access points in large quantities by the network administrator or NOC. The wireless LAN controller is a part of the Data Plane within the Cisco Wireless Model. The WLAN controller automatically handles the configuration of anywhere from 6 to 300 wireless access-points, depending on the model. Answer: D is incorrect. A spectrum analyzer, or spectral analyzer, is a device that is used to examine the spectral composition of some electrical, acoustic, or optical waveform. It may also measure the power spectrum. The analog and digital spectrum analyzers are as follows: 1. An analog spectrum analyzer uses either a variable band-pass filter whose mid-frequency is automatically tuned (shifted, swept) through the range of frequencies of which the spectrum is to be measured. 2. A digital spectrum analyzer computes the discrete Fourier transform (DFT), a mathematical process that transforms a waveform into the components of its frequency spectrum. Answer: A is incorrect. A protocol analyzer is a network diagnostic utility for viewing the current contents of a packet traveling on the network. Protocol analyzers are mainly used for performance measurement and troubleshooting. These devices connect to the network to calculate key performance indicators (KPI) to monitor the network and speed up troubleshooting activities.
QUESTION 34
DRAG DROP
Certain potentially harmful file types should be filtered as attachments of incoming email messages. Match the file extension that should be filtered with its description. Instructions: To answer, drag the appropriate file extension from the column on the left to its description on the right. Each file extension may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. Note: For each correct selection is worth one point.
Correct Answer:
QUESTION 35
HOTSPOT
You are preparing a local audit policy for your workstation. No auditing is enabled. The settings of your policy are shown in the following image:
Use the drop-down menus to select the answer choice that completes each statement. Each correct selection is worth one point.
Correct Answer:
Explanation
Explanation/Reference:
Dozens of events can be audited in Windows. The events fall into several categories:
Audit account logon events - audit each instance of a user logging on to or logging off from another computer in which this computer is used to validate the account. This event category is applicable to domain controllers only since DC's are used to validate accounts in domains. Audit account management - audit each event of account management on a computer. Examples of account maintenance include password changes, user account and group modifications. Audit directory service access - audit the event of a user accessing an Active Directory object that has its own system access control list (SACL) specified. Audit logon events - audit each instance of a user logging on to or logging off from a computer. Note that this is different than the 'Audit account login events' category. This tracks the logon event to a specific server. The former tracks which domain controller authenticated the user. Audit object access - audit the event of a user accessing an object that has its own system access control list (SACL) specified. Examples of objects are files, folders, registry keys, printers, etc. Audit policy change - audit every incident of a change to user rights assignment policies, audit policies, or trust policies. Audit privilege use - audit each instance of a user exercising a user right. Audit process tracking - audit detailed tracking information for events such as program activation, process exit, handle duplication, and indirect object access. Audit system events - audit when a user restarts or shuts down the computer or when an event occurs that affects either the system security or the security log. References: http://www.petri.co.il/windows_auditing.htm
QUESTION 36
Which of the following is a security protocol that is used to protect data from being modified, corrupted, or accessed without authorization?
A.
Honeypot
B.
IP Security (IPsec)
C.
DNSSEC
D.
Protocol spoofing
Correct Answer: B
Explanation
Explanation/Reference:
Internet Protocol Security (IPsec) is a protocol suite for securing Internet Protocol (IP) communications by authenticating and encrypting each IP packet of a data stream. IPsec also includes protocols for establishing mutual authentication between agents at the beginning of the session and negotiation of cryptographic keys to be used during the session. IPsec can be used to protect data flows between a pair of hosts, between a pair of security gateways, or between a security gateway and a host. Answer: C is incorrect. Domain Name System Security Extensions (DNSSEC) is a suite of Internet Engineering Task Force (IETF) specifications for securing certain kinds of information provided by the Domain Name System (DNS) as used on Internet Protocol (IP) networks. It is a set of extensions to DNS which provide to DNS clients origin authentication of DNS data, authenticated denial of existence, and data integrity, but not availability or confidentiality. Answer: A is incorrect. A honey pot is a computer that is used to attract potential intruders or attackers. It is for this reason that a honey pot has low security permissions. A honey pot is used to gain information about the intruders and their attack strategies. Answer: D is incorrect. Protocol spoofing is used in data communications for enhancing the performance in situations where an currently working protocol is inadequate. In a computer security context, it refers to several forms of falsification of technically unrelated data.
QUESTION 37
You are a network administrator.
All computers run the Microsoft Edge browser.
You need to prevent web cookies from being saved.
What should you enforce?
A.
SmartScreen Filter
B.
InPrivate Browsing
C.
Antivirus protection
D.
Cross-Site Scripting Filter
Correct Answer: B
QUESTION 38
You work as a security manager for Company Inc. An individual is connecting to your corporate internal network over the Internet. You have to ensure that he is not an intruder masquerading as an authorized user.
Which of the following technologies will you use to accomplish the task?
A.
Two-factor authentication
B.
IP address packet filtering
C.
Intrusion detection system (IDS)
D.
Embedded digital signature
Correct Answer: A
Explanation
Explanation/Reference:
Two-factor authentication offers an extra security mechanism above that offered by passwords alone. It is frequently used by mobile users who want to establish connectivity to a corporate network.
QUESTION 39
Which type of password attack attempts to guess passwords by using a list of common passwords?
A.
Keylogger
B.
brute force
C.
man-in-the-middle
D.
dictionary
Correct Answer: D
QUESTION 40
HOTSPOT
For each of the following statements, select Yes if the statement is true. Otherwise, select No. Each correct selection is worth one point.
Correct Answer:
QUESTION 41
You sign up for an online bank account. Every 6 months, the bank requires you to change your password. You have changed your password 5 times in the past. Instead of coming up with a new password, you decide to use one of your past passwords, but the bank's password history prevents you on doing so.
Select the correct answer if the underlined text does not make the statement correct Select "No change is needed" if the underlined text makes the statement correct.