You work as a security manager in Mariotiss Inc. Your enterprise has been facing network and software security threats since a few months. You want to renew your current security policies and management to enhance the safety of your information systems. Which of the following is the best practice to initiate the renewal process from the lowest level with the least managerial effort?
-
A
Start the Incident handling process.
-
B
Change the entire security policy.
-
C
-
D
Switch to a new network infrastructure.
Reveal answer details
Close answer details
Which of the following is the phase of Incident handling process in which the distinction between an event and an incident is made?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 3
Multiple choice
Which of the following two cryptography methods are used by NTFS Encrypting File System (EFS) to encrypt the data stored on a disk on a file-by-file basis?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
John works as a professional Ethical Hacker. He has been assigned a project to test the security of www.we-are-secure.com. On the We-are-secure login page, he enters ='or''=' as a username and successfully logs in to the user page of the Web site. The We-are-secure login page is vulnerable to a __________.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Which of the following statements about digital signature is true?
-
A
Digital signature is required for an e-mail message to get through a firewall.
-
B
Digital signature verifies the identity of the person who applies it to a document.
-
C
Digital signature decrypts the contents of documents.
-
D
Digital signature compresses the message to which it is applied.
Reveal answer details
Close answer details
Which of the following methods of encryption uses a single key to encrypt and decrypt data?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Rick is the project manager of a construction project. He is in a process to procure some construction equipments. There are four vendors available for supplying the equipments. Rick does not want one of them to participate in the bidding as he has some personal grudges against the owner of the vendor. This is the violation of which of the following categories of the Project Management Institute Code of Ethics and Professional Conduct?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
You work as a project manager for TYU project. You are planning for risk mitigation. You need to identify the risks that will need a more in-depth analysis. Which of the following activities will help you in this?
-
A
-
B
-
C
Estimate activity duration
-
D
Reveal answer details
Close answer details
Which of the following statements about Public Key Infrastructure (PKI) is true?
-
A
It uses symmetric key pairs.
-
B
It uses public key encryption.
-
C
It is a digital representation of information that identifies users.
-
D
It provides security using data encryption and digital signature.
Reveal answer details
Close answer details
Question 10
Single choice
Which of the following terms is used for a router that filters traffic before it is passed to the firewall?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 11
Multiple choice
Adam works as a Professional Penetration Tester for Umbrella Inc. A project has been assigned to him to carry out a Black Box penetration testing as a regular evaluation of the system security and integrity of the company's network. Which of the following statements are true about the Black Box penetration testing? Each correct answer represents a complete solution. Choose all that apply.
-
A
Black box testing provides the testers with complete knowledge of the infrastructure to be tested.
-
B
Black box testing simulates an attack from someone who is unfamiliar with the system.
-
C
Black box testing simulates an attack from someone who is familiar with the system.
-
D
Black box testing assumes no prior knowledge of the infrastructure to be tested.
Reveal answer details
Close answer details
Question 12
Single choice
Computer networks and the Internet are the prime mode of Information transfer today. Which of the following is a technique used for modifying messages, providing Information and Cyber security, and reducing the risk of hacking attacks during communications and message passing over the Internet?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 13
Multiple choice
Which of the following are the differences between routed protocols and routing protocols? Each correct answer represents a complete solution. Choose two.
-
A
A routing protocol is configured on an interface and decides the method of packet delivery.
-
B
A routing protocol decides the path for a packet through the network.
-
C
A routed protocol is configured on an interface and decides how a packet will be delivered.
-
D
A routed protocol works on the transport layer of the OSI model.
Reveal answer details
Close answer details
Question 14
Single choice
Which of the following books is used to examine integrity and availability?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 15
Multiple choice
Victor works as a network administrator for DataSecu Inc. He uses a dual firewall Demilitarized Zone (DMZ) to insulate the rest of the network from the portions, which is available to the Internet. Which of the following security threats may occur if DMZ protocol attacks are performed? Each correct answer represents a complete solution. Choose all that apply.
-
A
Attacker can exploit any protocol used to go into the internal network or intranet of the com pany.
-
B
Attacker managing to break the first firewall defense can access the internal network without breaking the second firewall if it is different.
-
C
Attacker can gain access to the Web server in a DMZ and exploit the database.
-
D
Attacker can perform Zero Day attack by delivering a malicious payload that is not a part of the intrusion detection/prevention systems guarding the network.
Reveal answer details
Close answer details
Question 16
Single choice
You have created a Web site, which will be used for e-commerce. You want to ensure that the transactions are highly secured. For this purpose, you have to create a system to verify the identity of a potential customer. Which of the following security techniques will you use?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 17
Single choice
You work as an Incident handler in Mariotrixt.Inc. You have followed the Incident handling process to handle the events and incidents. You identify Denial of Service attack (DOS) from a network linked to your internal enterprise network. Which of the following phases of the Incident handling process should you follow next to handle this incident?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 18
Single choice
Mark is implementing security on his e-commerce site. He wants to ensure that a customer sending a message is really the one he claims to be. Which of the following techniques will he use to ensure this?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 19
Single choice
The IT Director of the company is very concerned about the security of the network. Which audit policy should he implement to detect possible intrusions into the network? (Click the Exhibit button on the toolbar to see the case study.)
-
A
The success and failure auditing for policy change.
-
B
The success and failure auditing for process tracking.
-
C
The success and failure auditing for logon events.
-
D
The success and failure auditing for privilege use.
Reveal answer details
Close answer details
Question 20
Multiple choice
Adam, a novice Web user is getting large amount of unsolicited commercial emails on his email address. He suspects that the emails he is receiving are the Spam. Which of the following steps will he take to stop the Spam? Each correct answer represents a complete solution. Choose all that apply.
-
A
Forward a copy of the spam to the ISP to make the ISP conscious of the spam.
-
B
Send an email to the domain administrator responsible for the initiating IP address.
-
C
Report the incident to the FTC (The U.S. Federal Trade Commission) by sending a copy of the spam message.
-
D
Close existing email account and open new email account.
Reveal answer details
Close answer details
Question 21
Single choice
You send and receive messages on Internet. A man-in-the-middle attack can be performed to capture and read your message. Which of the following Information assurance pillars ensures the security of your message or data against this type of attack?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 22
Multiple choice
You work as a Network Administrator for Tech Perfect Inc. The company has recruited a large number of fresh employees. You have been asked to give them a presentation on data protection and confidentiality to ensure a secure wireless communication between the employees. What types of information require confidentiality? Each correct answer represents a complete solution. Choose all that apply.
-
A
Information that is public
-
B
Information that reveals technical data
-
C
Information that may reveal systems relationships
-
D
Information that may reveal organizational relationships
Reveal answer details
Close answer details
Question 23
Single choice
Which of the following devices or hardware parts employs SMART model system as a monitoring system?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 24
Single choice
John works as a Network Administrator for Bordeaux Inc. He is planning to design a strategy, so that the employees can connect to a scheduling application. Which of the following strategies is best suited for the company? (Click the Exhibit button on the toolbar to see the case study.)
-
A
Deploy a VPN server on the VLAN network, and an IIS server on the corporate LAN at the headquarters.
-
B
Deploy a VPN server on the VLAN network, and an IIS server on DMZ.
-
C
Deploy a VPN server on the corporate LAN at the headquarters, and an IIS server on DMZ.
-
D
Deploy a VPN server on DMZ, and an IIS server on the corporate LAN at the headquarters.
Reveal answer details
Close answer details
Question 25
Multiple choice
The IT administrator wants to implement a stronger security policy. What are the four most important security priorities for uCertify Software Systems Pvt. Ltd. ? (Click the Exhibit button on the toolbar to see the case study.)
-
A
Providing secure communications between Washington and the headquarters office.
-
B
Implementing Certificate services on Texas office.
-
C
Preventing denial-of-service attacks.
-
D
Ensuring secure authentication.
-
E
Preventing unauthorized network access.
-
F
Providing two-factor authentication.
-
G
Protecting employee data on portable computers.
-
H
Providing secure communications between the overseas office and the headquarters.
Reveal answer details
Close answer details
Correct answersD, E, G, H
Question 26
Single choice
You have successfully installed an IRM server into your environment. This IRM server will be utilized to protect the company's videos, which are available to all employees but contain sensitive data. You log on to the WSS 3.0 server with administrator permissions and navigate to the Operations section. What option should you now choose so that you can input the RMS server name for the WSS 3.0 server to use?
-
A
Self-service site management
-
B
-
C
Information Rights Management
-
D
Reveal answer details
Close answer details
Question 27
Single choice
You are an Incident manager in Orangesect.Inc. You have been tasked to set up a new extension of your enterprise. The networking, to be done in the new extension, requires different types of cables and an appropriate policy that will be decided by you. Which of the following stages in the Incident handling process involves your decision making?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 28
Single choice
Which of the following is an examination of the controls within an Information technology (IT) infrastructure?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 29
Multiple choice
Which of the following objects in an Active Directory serve as security principles? Each correct answer represents a part of the solution. Choose all that apply.
-
A
-
B
Organizational units (OUs)
-
C
-
D
Reveal answer details
Close answer details
Question 30
Single choice
You work as a security manager for Qualxiss Inc. Your Company involves OODA loop for resolving and deciding over company issues. You have detected a security breach issue in your company. Which of the following procedures regarding the breach is involved in the observe phase of the OODA loop?
-
A
Follow the company security guidelines.
-
B
Decide an activity based on a hypothesis.
-
C
Implement an action practically as policies.
-
D
Consider previous experiences of security breaches.
Reveal answer details
Close answer details
Question 31
Single choice
Which of the following options cannot be accessed from Windows Update?
-
A
-
B
-
C
-
D
View AntiVirus Software Update
Reveal answer details
Close answer details
Question 32
Single choice
You are the security manager of Microliss Inc. Your enterprise uses a wireless network infrastructure with access points ranging 150-350 feet. The employees using the network complain that their passwords and important official information have been traced. You discover the following clues: The information has proved beneficial to another company. The other company is located about 340 feet away from your office. The other company is also using wireless network. The bandwidth of your network has degraded to a great extent. Which of the following methods of attack has been used?
-
A
A piggybacking attack has been performed.
-
B
The information is traced using Bluebugging.
-
C
A DOS attack has been performed.
-
D
A worm has exported the information.
Reveal answer details
Close answer details
Question 33
Single choice
Joseph works as a Software Developer for WebTech Inc. He wants to protect the algorithms and the techniques of programming that he uses in developing an application. Which of the following laws are used to protect a part of software?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 34
Single choice
Part of your change management plan details what should happen in the change control system for your project. Theresa, a junior project manager, asks what the configuration management activities are for scope changes. You tell her that all of the following are valid configuration management activities except for which one?
-
A
Configuration Status Accounting
-
B
Configuration Item Costing
-
C
Configuration Identification
-
D
Configuration Verification and Auditing
Reveal answer details
Close answer details
Question 35
Single choice
You work as an Application Developer for uCertify Inc. The company uses Visual Studio .NET Framework 3.5 as its application development platform. You are working on a WCF service. You have decided to implement transport level security. Which of the following security protocols will you use?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 36
Single choice
Tom and Gary are in a debate over which software should be purchased as part of their project. Gary tells Tom that because he's the senior software developer and has been with the company for 12 years, he'll be making the decision on the software. What type of conflict resolution has happened in this instance?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 37
Multiple choice
Availability Management allows organizations to sustain the IT service availability to support the business at a justifiable cost. Which of the following elements of Availability Management is used to perform at an agreed level over a period of time? Each correct answer represents a part of the solution. Choose all that apply.
-
A
-
B
-
C
-
D
-
E
-
F
-
G
Reveal answer details
Close answer details
Correct answersA, B, D, E, F, G
Question 38
Single choice
The workstations on your network utilize Windows XP (service pack 2 or later). Many users take their laptops on the road. You are very concerned about the security and want to have a robust firewall solution for mobile users. You have decided that all your firewalls to use the Stateful Packet Inspection (SPI) method. What must you do to provide SPI to your mobile users?
-
A
You must purchase a third party firewall solution for your mobile users.
-
B
Do nothing. Windows XP service pack 2 has a firewall turned on by default.
-
C
Download the SPI template from Microsoft.
-
D
Configure the Windows XP firewall to use SPI.
Reveal answer details
Close answer details
Question 39
Single choice
Which of the following types of attacks cannot be prevented by technical measures only?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 40
Multiple choice
Which of the following statements about Secure Shell (SSH) are true? Each correct answer represents a complete solution. Choose three.
-
A
It was designed as a replacement for TELNET and other insecure shells.
-
B
It is a network protocol used primarily on Linux and Unix based systems.
-
C
It allows data to be exchanged using a secure channel between two networked devices.
-
D
It is the core routing protocol of the Internet.
Reveal answer details
Close answer details
Question 41
Multiple choice
Which two security components should you implement on the sales personnel portable computers to increase security? (Click the Exhibit button on the toolbar to see the case study.) Each correct answer represents a complete solution. Choose two.
-
A
-
B
-
C
-
D
Remote Authentication Dial-In User Service (RADIUS)
-
E
Encrypting File System (EFS)
Reveal answer details
Close answer details
Question 42
Single choice
You have been tasked with finding an encryption methodology for your company's network. The solution must use public key encryption which is keyed to the users email address. Which of the following should you select?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 43
Single choice
Your network utilizes a coax cable for connections between various network segments. Your predecessor made sure none of the coax cables were in an exposed area that could easily be accessed. This caused the use of significant extra cabling. Why do you think this was done?
-
A
This was an error you should correct. It wastes the cable and may make maintenance more difficult.
-
B
He was concerned about wireless interception of data.
-
C
He was concerned about electromagnetic emanation being used to gather data.
-
D
He was concerned about vampire taps.
Reveal answer details
Close answer details
Question 44
Multiple choice
You are configuring the Terminal service. What Protocols are required with Terminal services? (Click the Exhibit button on the toolbar to see the case study.) Each correct answer represents a part of the solution. Choose two.
-
A
-
B
-
C
-
D
-
E
Reveal answer details
Close answer details
Question 45
Single choice
Which of the following cryptographic system services ensures that information will not be disclosed to any unauthorized person on a local network?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 46
Single choice
You work as a Network administrator for Infonet Inc. The company has 135 Windows XP Professional computers and twenty Windows 2003 Server computers. You want to specify the number of invalid logon attempts allowed before a user account is locked out. What will you do to accomplish the task?
-
A
Reset Account Lockout Counter After policy
-
B
Set Account Lockout Threshold policy
-
C
Enforce Password Must Meet Complexity Requirements policy
-
D
Set Account Lockout Duration policy
Reveal answer details
Close answer details
Question 47
Single choice
Your corporate network uses a Proxy Server for Internet access. The Manufacturing group has access permission for WWW protocol in the Web Proxy service, and access permission for POP3 protocol, in the WinSock Proxy service. The Supervisors group has access permission for WWW and FTP Read protocols in the Web Proxy service, and access permission for the SMTP protocol in the WinSock Proxy service. The Quality Control group has access permission only for WWW protocol in the Web Proxy service. The Interns group has no permissions granted in any of the Proxy Server services. Kate is a member of all four groups. In the Proxy Server services, which protocols does Kate have permission to use?
-
A
-
B
-
C
WWW, FTP Read, POP3, and SMTP
-
D
Reveal answer details
Close answer details
Question 48
Multiple choice
Which of the following provide data confidentiality services by encrypting the data sent between wireless systems? Each correct answer represents a complete solution. Choose two.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 49
Single choice
Which of the following is the best approach to conflict resolution?
-
A
Hard work and understanding
-
B
Mutual respect and cooperation
-
C
-
D
Reveal answer details
Close answer details
Question 50
Single choice
Tom works as the project manager for BlueWell Inc. He is working with his project to ensure timely and appropriate generation, retrieval, distribution, collection, storage, and ultimate disposition of project information. What is the process in which Tom is working?
-
A
Stakeholder expectation management
-
B
-
C
Work performance measurement
-
D
Project communication management
Reveal answer details
Close answer details
|