Skip to main content

98-367 Real Exam Questions

Security Fundamentals

277 questions available · Page 1 of 28

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

To prevent users from copying data to removable media, you should:

  1. A

    Lock the computer cases

  2. B

    Apply a group policy

  3. C

    Disable copy and paste

  4. D

    Store media in a locked room

Show answer and explanation

Correct answer: B

Explanation

References:
http://blogs.technet.com/b/askds/archive/2008/08/25/removable-storage-group-policy-and-windows-server-2008-and-windows-vista.aspx

Question 2 Single choice

What is the standard or basic collection of NTFS permissions?

  1. A

    Read and execute, read, write, full control, modify, list folder contents

  2. B

    Change permissions, read permissions, write permissions

  3. C

    Read attributes, list folder/read data, traverse folder/execute file

  4. D

    Create files/write data, create folders/append data, take ownership

Show answer and explanation

Correct answer: A

Explanation

References:
http://technet.microsoft.com/en-us/library/bb727008.aspx

Question 3 Multiple choice

What are three examples of two-factor authentication? (Choose three.)

  1. A

    A fingerprint and a pattern

  2. B

    A password and a smart card

  3. C

    A username and a password

  4. D

    A password and a pin number

  5. E

    A pin number and a debit card

Show answer and explanation

Correct answers: A, B, E

Explanation

At minimum two-factor authentication requires two out of three regulatory-approved authentication variables such as: Something you know (like the PIN on your bank card or email password).

Something you have (the physical bank card or a authenticator token).
Something you are (biometrics like your finger print or iris pattern).

Question 4 Single choice

Mark works as a Systems Administrator for TechMart Inc. The company has a Windows-based network.
The company is adding an open, high-speed, wireless access for their customers and secured wireless for employees at all 37 branches. He wants to check the various security concerns for ensuring that business traffic is secured. He is also in under pressure to make this new feature a winning strategy for a company.
Mark wants the employees to be free to troubleshoot their own wireless connections before contacting him.

Which of the following is the basic troubleshooting step that he can ask them to do?

  1. A

    To power cycle the wireless access points and then reboot the systems.

  2. B

    To configure the network to use only Extensible Authentication Protocol (EAP).

  3. C

    To reboot the computers they are using and then use the MAC filtering.

  4. D

    To right-click the network icon in the system tray and then select Troubleshoot Problems.

Show answer and explanation

Correct answer: D

Explanation

The basic troubleshooting step that Mark can ask his employees is to right-click the network icon in the system tray and then select Troubleshoot Problems. Answer: B is incorrect. Extensible Authentication Protocol (EAP) is defined as an authentication framework providing for the transport and usage of keying material and parameters that are generated by EAP methods. EAP is not a wire protocol and it defines only message formats.

Question 5 Single choice

Mark works as a Network Administrator for TechMart Inc. The company has a Windows-based network.
Mark wants to implement a method to ensure that the mobile devices are in a good state of security health when they are trying to access the corporate network.

Which of the following is a control or strategy that Mark will implement to assure the security health?

  1. A

    TCP/IP protocol

  2. B

    Kerberos

  3. C

    Single Sign On

  4. D

    Network Access Protection

Show answer and explanation

Correct answer: D

Explanation

Network Access Protection (NAP) is a set of operating system components included with the Windows Server 2008 and Windows Vista/7 operating systems. It ensures that the client computers on a private network meet administrator-defined requirements for system health. NAP policies define the required configuration and update status for a client computer's operating system and critical software. For example, an administrator can set policies that computers might be required to have antivirus software with the latest virus definition installed and current operating system updates. Using NAP, a network administrator can enforce compliance with health requirements for the client computers connection to the network. NAP helps network administrators to reduce the risk caused by improperly configured client computers that might be exposed to viruses and other malicious software. Answer: C is incorrect. Single sign-on (SSO) is defined as a mechanism in which a single action of user authentication and authorization is used to allow a user to access all computers and systems where he got a access permission, without entering passwords for multiple times.
Answer: B is incorrect. Kerberos is defined as a secure method used for authenticating a request for a service in a computer network. Answer: A is incorrect. TCP/IP protocol is used to define the rule computers are required to follow for communicating with each other over the internet.

Question 6 Single choice

Phishing is an attempt to:

  1. A

    Obtain information by posing as a trustworthy entity.

  2. B

    Limit access to e-mail systems by authorized users.

  3. C

    Steal data through the use of network intrusion.

  4. D

    Corrupt e-mail databases through the use of viruses.

Show answer and explanation

Correct answer: A

Explanation

Phishing is the act of attempting to acquire sensitive information such as usernames, passwords, and credit card details (and sometimes, indirectly, money) by masquerading as a trustworthy entity in an electronic communication.

Question 7 Single choice

Many Internet sites that you visit require a user name and password.

How should you secure these passwords?

  1. A

    Save them to a text file

  2. B

    Enable session caching

  3. C

    Configure the browser to save passwords

  4. D

    Save them to an encrypted file

  5. E

    Reuse the same password

Show answer and explanation

Correct answer: D

Question 8 Single choice

Role separation improves server security by:

  1. A

    Enforcing principle of least privilege.

  2. B

    Installing applications on separate hard disks.

  3. C

    Physically separating high security servers from other servers.

  4. D

    Placing servers on separate VLANs.

Show answer and explanation

Correct answer: A

Question 9 Single choice

This question requires that you evaluate the underlined text to determine if it is correct.
The first line of defense against attacks from the Internet is a software firewall.

Select the correct answer if the underlined text does not make the statement correct. Select "No change is needed'' if the underlined text makes the statement correct.

  1. A

    hardware firewall

  2. B

    virus software

  3. C

    radius server

  4. D

    No change is needed

Show answer and explanation

Correct answer: A

Question 10 Single choice

Which of the following ports is used by the Remote Desktop Protocol?

  1. A

    80

  2. B

    23

  3. C

    3389

  4. D

    110

Show answer and explanation

Correct answer: C

Explanation

Port 3389 is used by the Remote Desktop Protocol. Answer: B is incorrect. Port 23 is used by the TELNET protocol. Answer: A is incorrect. Port 80 is used by the HTTP protocol. Answer: D is incorrect. Port 110 is used by the POP3 protocol.