Skip to main content

1D0-571 Real Exam Questions

CIW v5 Security Essentials

62 questions available · Page 1 of 7

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

Which of the following is a common problem, yet commonly overlooked, in regards to physical security in server rooms?

  1. A

    Firewalls that do not have a dedicated backup

  2. B

    False ceilings

  3. C

    Logic bombs

  4. D

    Biometric malfunctions

Show answer and explanation

Correct answer: B

Question 2 Single choice

Which choice lists typical firewall functions?

  1. A

    Creating a VLAN and configuring the intrusion-detection system

  2. B

    Issuing alerts and limiting host access

  3. C

    Logging traffic and creating a choke point

  4. D

    Implementing the security policy and scanning the internal network

Show answer and explanation

Correct answer: C

Question 3 Single choice

A CGI application on the company's Web server has a bug written into it. This particular bug allows the application to write data into an area of memory that has not been properly allocated to the application. An attacker has created an application that takes advantage of this bug to obtain credit card information.

Which of the following security threats is the attacker exploiting, and what can be done to solve the problem?

  1. A

    - Buffer overflow - Work with the Web developer to solve the problem

  2. B

    - SQL injection - Work with a database administrator to solve the problem

  3. C

    - Denial of service - Contact the organization that wrote the code for the Web server

  4. D

    - Man-in-the-middle attack - Contact the company auditor

Show answer and explanation

Correct answer: A

Question 4 Single choice

You are using a PKI solution that is based on Secure Sockets Layer (SSL).

Which of the following describes the function of the asymmetric-key-encryption algorithm used?

  1. A

    It encrypts the symmetric key.

  2. B

    It encrypts all of the data.

  3. C

    It encrypts the hash code used for data integrity.

  4. D

    It encrypts the X.509 key.

Show answer and explanation

Correct answer: A

Question 5 Single choice

Which of the following is considered to be the most secure default firewall policy, yet usually causes the most work from an administrative perspective?

  1. A

    Configuring the firewall to respond automatically to threats

  2. B

    Blocking all access by default, then allowing only necessary connections

  3. C

    Configuring the firewall to coordinate with the intrusion-detection system

  4. D

    Allowing all access by default, then blocking only suspect network connections

Show answer and explanation

Correct answer: B

Question 6 Single choice

Which of the following is a primary auditing activity?

  1. A

    Encrypting data files

  2. B

    Changing login accounts

  3. C

    Checking log files

  4. D

    Configuring the firewall

Show answer and explanation

Correct answer: C

Question 7 Single choice

Consider the following image:

From the information in this image, what type of attack is occurring?

  1. A

    A man-in-the-middle attack

  2. B

    A brute-force attack

  3. C

    A connection-hijacking attack

  4. D

    A spoofingattackD.A spoofing attack

Show answer and explanation

Correct answer: B

Question 8 Single choice

Which of the following is most likely to pose a security threat to a Web server?

  1. A

    CGI scripts

  2. B

    Database connections

  3. C

    Flash or Silverlight animation files

  4. D

    LDAP servers

Show answer and explanation

Correct answer: A

Question 9 Single choice

A new server has been placed on the network. You have been assigned to protect this server using a packet-filtering firewall. To comply with this request, you have enabled the following ruleset:

Which choice describes the next step to take now that this ruleset has been enabled?

  1. A

    From the internal network, use your Web browser to determine whether all internal users can access the Web server.

  2. B

    From the internal network, use your e-mail client to determine whether all internal users can access the e-mail server.

  3. C

    From the external network, use your Web browser to determine whether all external users can access the Web server.

  4. D

    From the external network, use your e-mail client to determine whether all external users can access the e-mail server.

Show answer and explanation

Correct answer: D

Question 10 Single choice

Which of the following applications can help determine whether a denial-of-service attack is occurring against a network host?

  1. A

    Thenetstat command and a packet sniffer

  2. B

    Theps command and a network scanner

  3. C

    The ping command and User Manager

  4. D

    Theiptables command and Windows desktop firewall

Show answer and explanation

Correct answer: A