Question 1
Multiple choice
You have decided to implement video surveillance in your company in order to enhance network security. Which of the following locations must have a camera in order to provide the minimum level of security for the network resources? Each correct answer represents a complete solution. Choose two.
-
A
-
B
-
C
-
D
-
E
Reveal answer details
Close answer details
John works as a Network Administrator for NetPerfect Inc. The company has a Windows-based network. John has been assigned a project to build a network for the sales department of the company. It is important for the LAN to continue working even if there is a break in the cabling. Which of the following topologies should John use to accomplish the task?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
You are the Security Consultant and have been contacted by a client regarding their encryption and hashing algorithms. Their in-house network administrator tells you that their current hashing algorithm is an older one with known weaknesses and is not collision resistant.Which algorithm are they most likely using for hashing?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Which of the following is the duration of time and a service level within which a business process must be restored after a disaster in order to avoid unacceptable consequences associated with a break in business continuity?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
You work as a CSO (Chief Security Officer) for Tech Perfect Inc. You want to perform the following tasks: Develop a risk-driven enterprise information security architecture. Deliver security infrastructure solutions that support critical business initiatives. Which of the following methods will you use to accomplish these tasks?
-
A
Service-oriented architecture
-
B
Sherwood Applied Business Security Architecture
-
C
Service-oriented modeling framework
-
D
Service-oriented modeling and architecture
Reveal answer details
Close answer details
Question 6
Multiple choice
Which of the following are types of access control attacks? Each correct answer represents a complete solution. Choose all that apply.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 7
Multiple choice
Mark works as a Network Administrator for NetTech Inc. He wants to connect the company's headquarter and its regional offices using a WAN technology. For this, he uses packet-switched connection. Which of the following WAN technologies will Mark use to connect the offices? Each correct answer represents a complete solution. Choose two.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
In software development, which of the following analysis is used to document the services and functions that have been accidentally left out, deliberately eliminated or still need to be developed?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Maria works as a Network Security Officer for Gentech Inc. She wants to encrypt her network traffic. The specific requirement for the encryption algorithm is that it must be a symmetric key block cipher. Which of the following techniques will she use to fulfill this requirement?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 10
Single choice
John works as a security manager for SoftTech Inc. He is working with his team on the disaster recovery management plan. One of his team members has a doubt related to the most cost effective DRP testing plan. According to you, which of the following disaster recovery testing plans is the most cost-effective and efficient way to identify areas of overlap in the plan before conducting more demanding training exercises?
-
A
-
B
-
C
Structured walk-through test
-
D
Reveal answer details
Close answer details
Question 11
Single choice
Which of the following categories of access controls is deployed in the organization to prevent all direct contacts with systems?
-
A
-
B
-
C
-
D
Administrative access control
Reveal answer details
Close answer details
Question 12
Single choice
In which of the following cryptographic attacking techniques does an attacker obtain encrypted messages that have been encrypted using the same encryption algorithm?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 13
Single choice
Which of the following cryptographic algorithm uses public key and private key to encrypt or decrypt data ?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 14
Single choice
Which of the following schemes is used by the Kerberos authentication?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 15
Single choice
Which of the following methods will allow data to be sent on the Internet in a secure format?
-
A
Serial Line Interface Protocol
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 16
Single choice
Which of the following types of ciphers operates on a group of bits rather than an individual character or bit of a message?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 17
Single choice
You work as a Chief Security Officer for Tech Perfect Inc. The company has a TCP/IP based network. You want to use a firewall that can track the state of active connections of the network and then determine which network packets are allowed to enter through the firewall. Which of the following firewalls has this feature?
-
A
Stateful packet inspection firewall
-
B
-
C
Dynamic packet-filtering firewall
-
D
Application gateway firewall
Reveal answer details
Close answer details
Question 18
Multiple choice
Which of the following techniques can be used by an administrator while working with the symmetric encryption cryptography? Each correct answer represents a complete solution. Choose all that apply.
-
A
-
B
-
C
-
D
Message Authentication Code
Reveal answer details
Close answer details
Question 19
Single choice
Adam works as a Security Analyst for Umbrella Inc. CEO of the company ordered him to implement two-factor authentication for the employees to access their networks. He has told him that he would like to use some type of hardware device in tandem with a security or identifying pin number. Adam decides to implement smart cards but they are not cost effective. Which of the following types of hardware devices will Adam use to implement two-factor authentication?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 20
Single choice
Which of the following is a correct sequence of different layers of Open System Interconnection (OSI) model?
-
A
Physical layer, data link layer, network layer, transport layer, presentation layer, session layer, and application layer
-
B
Physical layer, network layer, transport layer, data link layer, session layer, presentation layer, and application layer
-
C
application layer, presentation layer, network layer, transport layer, session layer, data link layer, and physical layer
-
D
Physical layer, data link layer, network layer, transport layer, session layer, presentation layer, and application layer
Reveal answer details
Close answer details
Question 21
Single choice
You are responsible for security at a hospital. Since many computers are accessed by multiple employees 24 hours a day, 7 days a week, controlling physical access to computers is very difficult. This is compounded by a high number of non employees moving through the building. You are concerned about unauthorized access to patient records. What would best solve this problem?
-
A
-
B
Time of day restrictions.
-
C
-
D
Video surveillance of all computers.
Reveal answer details
Close answer details
Question 22
Single choice
You work as a Security Manager for Tech Perfect Inc. A number of people are involved with you in the DRP efforts. You have maintained several different types of plan documents, intended for different audiences. Which of the following documents will be useful for you as well as public relations personnel who require a non-technical perspective on the entire organization's disaster recovery efforts?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 23
Single choice
You work as a Security Manager for Tech Perfect Inc. The management tells you to implement a hashing method in the organization that can resist forgery and is not open to the man-in-the-middle attack. Which of the following methods will you use to accomplish the task?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 24
Single choice
Which of the following security devices is presented to indicate some feat of service, a special accomplishment, a symbol of authority granted by taking an oath, a sign of legitimate employment or student status, or as a simple means of identification?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 25
Single choice
Peter works as a Network Administrator for Net World Inc. The company wants to allow remote users to connect and access its private network through a dial-up connection via the Internet. All the data will be sent across a public network. For security reasons, the management wants the data sent through the Internet to be encrypted. The company plans to use a Layer 2 Tunneling Protocol (L2TP) connection. Which communication protocol will Peter use to accomplish the task?
-
A
-
B
Microsoft Point-to-Point Encryption (MPPE)
-
C
Pretty Good Privacy (PGP)
-
D
Data Encryption Standard (DES)
Reveal answer details
Close answer details
Question 26
Multiple choice
Which of the following are examples of physical controls used to prevent unauthorized access to sensitive materials?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 27
Multiple choice
Which of the following statements are true about Public-key cryptography? Each correct answer represents a complete solution. Choose two.
-
A
Data encrypted with the secret key can only be decrypted by another secret key.
-
B
The secret key can encrypt a message, and anyone with the public key can decrypt it.
-
C
The distinguishing technique used in public key-private key cryptography is the use of symmetric key algorithms.
-
D
Data encrypted by the public key can only be decrypted by the secret key.
Reveal answer details
Close answer details
Question 28
Single choice
You are the Network Administrator for a small business. You need a widely used, but highly secure hashing algorithm. Which of the following should you choose?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 29
Multiple choice
Which of the following encryption algorithms are based on block ciphers?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 30
Single choice
Single Loss Expectancy (SLE) represents an organization's loss from a single threat. Which of the following formulas best describes the Single Loss Expectancy (SLE)?
-
A
SLE = Asset Value (AV) * Exposure Factor (EF)
-
B
SLE = Asset Value (AV) * Annualized Rate of Occurrence (ARO)
-
C
SLE = Annualized Loss Expectancy (ALE) * Annualized Rate of Occurrence (ARO)
-
D
SLE = Annualized Loss Expectancy (ALE) * Exposure Factor (EF)
Reveal answer details
Close answer details
Question 31
Multiple choice
Which of the following are the centralized administration technologies? Each correct answer represents a complete solution. Choose all that apply.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 32
Single choice
In which of the following cryptographic attacking techniques does the attacker pick up the information to be encrypted and take a copy of it with the encrypted data?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 33
Single choice
The service-oriented modeling framework (SOMF) introduces five major life cycle modeling activities that drive a service evolution during design-time and run-time. Which of the following activities integrates SOA software assets and establishes SOA logical environment dependencies?
-
A
Service-oriented business integration modeling
-
B
Service-oriented logical design modeling
-
C
Service-oriented discovery and analysis modeling
-
D
Service-oriented logical architecture modeling
Reveal answer details
Close answer details
Question 34
Single choice
Which of the following plans is a comprehensive statement of consistent actions to be taken before, during, and after a disruptive event that causes a significant loss of information systems resources?
-
A
-
B
-
C
-
D
Continuity of Operations plan
Reveal answer details
Close answer details
Question 35
Multiple choice
The service-oriented modeling framework (SOMF) provides a common modeling notation to address alignment between business and IT organizations. Which of the following principles does the SOMF concentrate on? Each correct answer represents a part of the solution. Choose all that apply.
-
A
Disaster recovery planning
-
B
-
C
-
D
Architectural components abstraction
-
E
Reveal answer details
Close answer details
Correct answersB, C, D, E
Question 36
Multiple choice
Which of the following keys are included in a certificate revocation list (CRL) of a public key infrastructure (PKI)? Each correct answer represents a complete solution. Choose two.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
|