Preview real exam questions, verified answers and available explanations before choosing a study plan.
Question 1
Single choice
An organization has hired a penetration tester to test the security of its ten web servers. The penetration tester is able to gain root/administrative access in several servers by explogting vulnerabilities associated with the implementation of SMTP, POP, DNS, FTP, Telnet, and IMAP.
Which of the following recommendations should the penetration tester provide to the organization to better protect their web servers in the future?
A
Use a honeypot
B
Disable unnecessary services
C
Implement transport layer security
D
Increase application event logging
Reveal answer detailsClose answer details
Correct answerB
Question 2
Single choice
A dumpster diver recovers several hard drives from a company and is able to obtain confidential data from one of the hard drives. The company then discovers its information is posted online.
Which of the following methods would have MOST likely prevented the data from being exposed?
A
Removing the hard drive from its enclosure
B
Using software to repeatedly rewrite over the disk space
C
Using Blowfish encryption on the hard drives
D
Using magnetic fields to erase the data
Reveal answer detailsClose answer details
Correct answerD
Question 3
Single choice
The Chief Technology Officer (CTO) of a company, Ann, is putting together a hardware budget for the next 10 years. She is asking for the average lifespan of each hardware device so that she is able to calculate when she will have to replace each device.
Which of the following categories BEST describes what she is looking for?
A
ALE
B
MTTR
C
MTBF
D
MTTF
Reveal answer detailsClose answer details
Correct answerD
Question 4
Single choice
A security analyst is reviewing the following packet capture of an attack directed at a company's server located in the DMZ:
Which of the following ACLs provides the BEST protection against the above attack and any further attacks from the same IP, while minimizing service interruption?
A
DENY TCO From ANY to 172.31.64.4
B
Deny UDP from 192.168.1.0/24 to 172.31.67.0/24
C
Deny IP from 192.168.1.10/32 to 0.0.0.0/0
D
Deny TCP from 192.168.1.10 to 172.31.67.4
Reveal answer detailsClose answer details
Correct answerC
Question 5
Single choice
Which of the following should identify critical systems and components?
A
MOU
B
BPA
C
ITCP
D
BCP
Reveal answer detailsClose answer details
Correct answerD
Question 6
Single choice
An application developer is designing an application involving secure transports from one service to another that will pass over port 80 for a request.
Which of the following secure protocols is the developer MOST likely to use?
A
FTPS
B
SFTP
C
SSL
D
LDAPS
Reveal answer detailsClose answer details
Correct answerC
Question 7
Single choice
A security administrator must implement a system to ensure that invalid certificates are not used by a custom developed application. The system must be able to check the validity of certificates even when internet access is unavailable.
Which of the following MUST be implemented to support this requirement?
A
CSR
B
OCSP
C
CRL
D
SSH
Reveal answer detailsClose answer details
Correct answerC
Question 8
Single choice
Which of the following threat actors is MOST likely to steal a company's proprietary information to gain a market edge and reduce time to market?
A
Competitor
B
Hacktivist
C
Insider
D
Organized crime.
Reveal answer detailsClose answer details
Correct answerA
Question 9
Single choice
Which of the following would a security specialist be able to determine upon examination of a server's certificate?
A
CA public key
B
Server private key
C
CSR
D
OID
Reveal answer detailsClose answer details
Correct answerD
Question 10
Single choice
A system administrator wants to provide for and enforce wireless access accountability during events where external speakers are invited to make presentations to a mixed audience of employees and non-employees.
Which of the following should the administrator implement?
A
Shared accounts
B
Preshared passwords
C
Least privilege
D
Sponsored guest
Reveal answer detailsClose answer details
Correct answerD
Question 11
Single choice
A Chief Information Officer (CIO) drafts an agreement between the organization and its employees. The agreement outlines ramifications for releasing information without consent and/for approvals.
Which of the following BEST describes this type of agreement?
A
ISA
B
NDA
C
MOU
D
SLA
Reveal answer detailsClose answer details
Correct answerB
Question 12
Multiple choice
A security analyst is performing a quantitative risk analysis. The risk analysis should show the potential monetary loss each time a threat or event occurs. Given this requirement, which of the following concepts would assist the analyst in determining this value? (Select two.)
A
ALE
B
AV
C
ARO
D
EF
E
ROI
Reveal answer detailsClose answer details
Correct answersB, D
Question 13
Single choice
Joe notices there are several user accounts on the local network generating spam with embedded malicious code.
Which of the following technical control should Joe put in place to BEST reduce these incidents?
A
Account lockout
B
Group Based Privileges
C
Least privilege
D
Password complexity
Reveal answer detailsClose answer details
Correct answerA
Question 14
Single choice
Ann a security analyst is monitoring the IDS console and noticed multiple connections from an internal host to a suspicious call back domain.
Which of the following tools would aid her to decipher the network traffic?
A
Vulnerability Scanner
B
NMAP
C
NETSTAT
D
Packet Analyzer
Reveal answer detailsClose answer details
Correct answerC
Question 15
Single choice
When connected to a secure WAP, which of the following encryption technologies is MOST likely to be configured when connecting to WPA2-PSK?
A
DES
B
AES
C
MD5
D
WEP
Reveal answer detailsClose answer details
Correct answerB
Question 16
Single choice
A datacenter manager has been asked to prioritize critical system recovery priorities.
Which of the following is the MOST critical for immediate recovery?
A
Communications software
B
Operating system software
C
Weekly summary reports to management
D
Financial and production software
Reveal answer detailsClose answer details
Correct answerB
Question 17
Single choice
A technician needs to implement a system which will properly authenticate users by their username and password only when the users are logging in from a computer in the office building. Any attempt to authenticate from a location other than the office building should be rejected.
Which of the following MUST the technician implement?
A
Dual factor authentication
B
Transitive authentication
C
Single factor authentication
D
Biometric authentication
Reveal answer detailsClose answer details
Correct answerB
Question 18
Single choice
A security administrator has found a hash in the environment known to belong to malware. The administrator then finds this file to be in in the preupdate area of the OS, which indicates it was pushed from the central patch system.
The administrator pulls a report from the patch management system with the following output:
Given the above outputs, which of the following MOST likely happened?
A
The file was corrupted after it left the patch system.
B
The file was infected when the patch manager downloaded it.
C
The file was not approved in the application whitelist system.
D
The file was embedded with a logic bomb to evade detection.
Reveal answer detailsClose answer details
Correct answerB
Question 19
Single choice
Which of the following types of attacks precedes the installation of a rootkit on a server?
A
Pharming
B
DDoS
C
Privilege escalation
D
DoS
Reveal answer detailsClose answer details
Correct answerC
Question 20
Hotspot
HOTSPOT
For each of the given items, select the appropriate authentication category from the drop down choices. Select the appropriate authentication type for the following items:
Reveal answer detailsClose answer details
Explanation
Biometrics refers to a collection of physical attributes of the human body that can be used as identification or an authentication factor. Fingerprints and retinas are physical attributes of the human body. Two types of tokens exist, Time-based one-time password (TOTP) tokens and HMACbased one-time password (HOTP). TOTP tokens generate passwords at fixed time intervals, whereas HOTP tokens generate passwords not based on fixed time intervals but instead based on a non-repeating one-way function, such as a hash or HMAC operation. Smart cards can have Multi-factor and proximity authentication embedded into it. PAP allows for two entities to share a password in advance and use the password as the basis of authentication. The same goes for PIN numbers. References: Stewart, James Michael, CompTIA Security+ Review Guide, Sybex, Indianapolis, 2014, pp. 282, 285 (http://en.wikipedia.org/wiki/Password_authentication_protocol#Working_cycle) http://en.wikipedia.org/wiki/Smart_card#Security
Question 21
Single choice
An organization is working with a cloud services provider to transition critical business applications to a hybrid cloud environment. The organization retains sensitive customer data and wants to ensure the provider has sufficient administrative and logical controls in place to protect its data. In which of the following documents would this concern MOST likely be addressed?
A
Service level agreement
B
Interconnection security agreement
C
Non-disclosure agreement
D
Business process analysis
Reveal answer detailsClose answer details
Correct answerA
Question 22
Single choice
Which of the following BEST describes an important security advantage yielded by implementing vendor diversity?
A
Sustainability
B
Homogeneity
C
Resiliency
D
Configurability
Reveal answer detailsClose answer details
Correct answerC
Question 23
Hotspot
HOTSPOT
The security administrator has installed a new firewall which implements an implicit DENY policy by default. Click on the firewall and configure it to allow ONLY the following communication. 1. The Accounting workstation can ONLY access the web server on the public network over the default HTTPS port. The accounting workstation should not access other networks. 2. The HR workstation should be restricted to communicate with the Financial server ONLY, over the default SCP port 3. The Admin workstation should ONLY be able to access the servers on the secure network over the default TFTP port. Instructions: The firewall will process the rules in a top-down manner in order as a first match The port number must be typed in and only one port number can be entered per rule Type ANY for all ports. The original firewall configuration can be reset at any time by pressing the reset button. Once you have met the simulation requirements, click save and then Done to submit.
Reveal answer detailsClose answer details
Explanation
Implicit deny is the default security stance that says if you aren't specifically granted access or privileges for a resource, you're denied access by default.
Rule #1 allows the Accounting workstation to ONLY access the web server on the public network over the default HTTPS port, which is TCP port 443. Rule #2 allows the HR workstation to ONLY communicate with the Financial server over the default SCP port, which is TCP Port 22 Rule #3 & Rule #4 allow the Admin workstation to ONLY access the Financial and Purchasing servers located on the secure network over the default TFTP port, which is Port 69. References: Stewart, James Michael, CompTIA Security+ Review Guide, Sybex, Indianapolis, 2014, pp.26, 44 (http://en.wikipedia.org/wiki/List_of_TCP_and_UDP_port_numbers)
Question 24
Single choice
A security analyst accesses corporate web pages and inputs random data in the forms. The response received includes the type of database used and SQL commands that the database accepts.
Which of the following should the security analyst use to prevent this vulnerability?
A
Application fuzzing
B
Error handling
C
Input validation
D
Pointer dereference
Reveal answer detailsClose answer details
Correct answerC
Question 25
Single choice
An administrator is testing the collision resistance of different hashing algorithms.
Which of the following is the strongest collision resistance test?
A
Find two identical messages with different hashes
B
Find two identical messages with the same hash
C
Find a common has between two specific messages
D
Find a common hash between a specific message and a random message
Reveal answer detailsClose answer details
Correct answerA
Question 26
Single choice
A company is planning to encrypt the files in several sensitive directories of a file server with a symmetric key.
Which of the following could be used?
A
RSA
B
TwoFish
C
Diffie-Helman
D
NTLMv2
E
RIPEMD
Reveal answer detailsClose answer details
Correct answerB
Question 27
Single choice
A company exchanges information with a business partner. An annual audit of the business partner is conducted against the SLA in order to verify:
A
Performance and service delivery metrics
B
Backups are being performed and tested
C
Data ownership is being maintained and audited
D
Risk awareness is being adhered to and enforced
Reveal answer detailsClose answer details
Correct answerA
Question 28
Single choice
A supervisor in your organization was demoted on Friday afternoon. The supervisor had the ability to modify the contents of a confidential database, as well as other managerial permissions. On Monday morning, the database administrator reported that log files indicated that several records were missing from the database.
Which of the following risk mitigation strategies should have been implemented when the supervisor was demoted?
A
Incident management
B
Routine auditing
C
IT governance
D
Monthly user rights reviews
Reveal answer detailsClose answer details
Correct answerD
Question 29
Single choice
A company is using a mobile device deployment model in which employees use their personal devices for work at their own discretion. Some of the problems the company is encountering include the following:
There is no standardization. Employees ask for reimbursement for their devices. Employees do not replace their devices often enough to keep them running efficiently. The company does not have enough control over the devices.
Which of the following is a deployment model that would help the company overcome these problems?
A
BYOD
B
VDI
C
COPE
D
CYOD
Reveal answer detailsClose answer details
Correct answerD
Question 30
Hotspot
HOTSPOT
Select the appropriate attack from each drop down list to label the corresponding illustrated attack Instructions: Attacks may only be used once, and will disappear from drop down list if selected. When you have completed the simulation, please select the Done button to submit.
Reveal answer detailsClose answer details
Explanation
1: Spear phishing is an e-mail spoofing fraud attempt that targets a specific organization,seeking unauthorized access to confidential data. As with the e-mail messages used in regular phishing expeditions, spear phishing messages appear to come from a trusted source. Phishing messages usually appear to come from a large and well-known company or Web site with a broad membership base, such as eBay or PayPal. In the case of spear phishing, however, the apparent source of the e-mail is likely to be an individual within the recipient's own company and generally someone in a position of authority. 2: The Hoax in this question is designed to make people believe that the fake AV (antivirus) software is genuine. 3: Vishing is the act of using the telephone in an attempt to scam the user into surrendering private information that will be used for identity theft. The scammer usually pretends to be a legitimate business, and fools the victim into thinking he or she will profit. 4: Phishing is the act of sending an email to a user falsely claiming to be an established legitimate enterprise in an attempt to scam the user into surrendering private information that will be used for identity theft. Phishing email will direct the user to visit a website where they are asked to update personal information, such as a password, credit card, social security, or bank account numbers, that the legitimate organization already has. The website, however, is bogus and set up only to steal the information the user enters on the page. 5: Similar in nature to e-mail phishing, pharming seeks to obtain personal or private (usually financial related) information through domain spoofing. Rather than being spammed with malicious and mischievous e-mail requests for you to visit spoof Web sites which appear legitimate, pharming 'poisons' a DNS server by infusing false information into the DNS server, resulting in a user's request being redirected elsewhere. Your browser, however will show you are at the correct Web site, which makes pharming a bit more serious and more difficult to detect. Phishing attempts to scam people one at a time with an e-mail while pharming allows the scammers to target large groups of people at one time through domain spoofing. References: http://searchsecurity.techtarget.com/definition/spear-phishing http://www.webopedia.com/TERM/V/vishing.html http://www.webopedia.com/TERM/P/phishing.html http://www.webopedia.com/TERM/P/pharming.html
Question 31
Single choice
A security engineer is configuring a system that requires the X.509 certificate information to be pasted into a form field in Base64 encoded format to import it into the system.
Which of the following certificate formats should the engineer use to obtain the information in the required format?
A
PFX
B
PEM
C
DER
D
CER
Reveal answer detailsClose answer details
Correct answerB
Question 32
Single choice
Which of the following cryptographic attacks would salting of passwords render ineffective?
A
Brute force
B
Dictionary
C
Rainbow tables
D
Birthday
Reveal answer detailsClose answer details
Correct answerC
Question 33
Single choice
A senior incident response manager receives a call about some external IPs communicating with internal computers during off hours.
Which of the following types of malware is MOST likely causing this issue?
A
Botnet
B
Ransomware
C
Polymorphic malware
D
Armored virus
Reveal answer detailsClose answer details
Correct answerA
Question 34
Single choice
A web application is configured to target browsers and allow access to bank accounts to siphon money to a foreign account. This is an example of which of the following attacks?
A
SQL injection
B
Header manipulation
C
Cross-site scripting
D
Flash cookie explogtation
Reveal answer detailsClose answer details
Correct answerC
Question 35
Single choice
To reduce disk consumption, an organization's legal department has recently approved a new policy setting the data retention period for sent email at six months.
Which of the following is the BEST way to ensure this goal is met?
A
Create a daily encrypted backup of the relevant emails.
B
Configure the email server to delete the relevant emails.
C
Migrate the relevant emails into an "Archived" folder.
D
Implement automatic disk compression on email servers.
Reveal answer detailsClose answer details
Correct answerA
Question 36
Single choice
A malicious attacker has intercepted HTTP traffic and inserted an ASCII line that sets the referrer URL.
Which of the following is the attacker most likely utilizing?
A
Header manipulation
B
Cookie hijacking
C
Cross-site scripting
D
Xml injection
Reveal answer detailsClose answer details
Correct answerA
Question 37
Single choice
A security program manager wants to actively test the security posture of a system. The system is not yet in production and has no uptime requirement or active user base.
Which of the following methods will produce a report which shows vulnerabilities that were actually explogted?
A
Peer review
B
Component testing
C
Penetration testing
D
Vulnerability testing
Reveal answer detailsClose answer details
Correct answerC
Explanation
A penetration test, or pen test, is an attempt to evaluate the security of an IT infrastructure by safely trying to explogt vulnerabilities.
Question 38
Single choice
After a user reports stow computer performance, a systems administrator detects a suspicious file, which was installed as part of a freeware software package.
The systems administrator reviews the output below:
Based on the above information, which of the following types of malware was installed on the user's computer?
A
RAT
B
Keylogger
C
Spyware
D
Worm
E
Bot
Reveal answer detailsClose answer details
Correct answerA
Question 39
Single choice
Which of the following is the summary of loss for a given year?
A
MTBF
B
ALE
C
SLA
D
ARO
Reveal answer detailsClose answer details
Correct answerB
Question 40
Multiple choice
A company has three divisions, each with its own networks and services. The company decides to make its secure web portal accessible to all employees utilizing their existing usernames and passwords. The security administrator has elected to use SAML to support authentication. In this scenario, which of the following will occur when users try to authenticate to the portal? (Select two.)
A
The portal will function as a service provider and request an authentication assertion.
B
The portal will function as an identity provider and issue an authentication assertion.
C
The portal will request an authentication ticket from each network that is transitively trusted.
D
The back-end networks will function as an identity provider and issue an authentication assertion.
E
The back-end networks will request authentication tickets from the portal, which will act as the third- party service provider authentication store.
F
The back-end networks will verify the assertion token issued by the portal functioning as the identity provider.
Reveal answer detailsClose answer details
Correct answersA, B
Question 41
Single choice
A security team wants to establish an Incident Response plan. The team has never experienced an incident.
Which of the following would BEST help them establish plans and procedures?
A
Table top exercises
B
Lessons learned
C
Escalation procedures
D
Recovery procedures
Reveal answer detailsClose answer details
Correct answerA
Question 42
Single choice
A security guard has informed the Chief Information Security Officer that a person with a tablet has been walking around the building. The guard also noticed strange white markings in different areas of the parking lot. The person is attempting which of the following types of attacks?
A
Jamming
B
War chalking
C
Packet sniffing
D
Near field communication
Reveal answer detailsClose answer details
Correct answerB
Question 43
Single choice
Which of the following attacks specifically impacts data availability?
A
DDoS
B
Trojan
C
MITM
D
Rootkit
Reveal answer detailsClose answer details
Correct answerA
Explanation
References:
Question 44
Single choice
Joe is exchanging encrypted email with another party. Joe encrypts the initial email with a key. When Joe receives a response, he is unable to decrypt the response with the same key he used initially.
Which of the following would explain the situation?
A
An ephemeral key was used for one of the messages
B
A stream cipher was used for the initial email; a block cipher was used for the reply
C
Out-of-band key exchange has taken place
D
Asymmetric encryption is being used
Reveal answer detailsClose answer details
Correct answerD
Explanation
Asymmetric algorithms use two keys to encrypt and decrypt dat A. These asymmetric keys are referred to as the public key and the private key. The sender uses the public key to encrypt a message, and the receiver uses the private key to decrypt the message; what one key does, the other one undoes.
Question 45
Single choice
A company is developing a new secure technology and requires computers being used for development to be isolated.
Which of the following should be implemented to provide the MOST secure environment?
A
A perimeter firewall and IDS
B
An air gapped computer network
C
A honeypot residing in a DMZ
D
An ad hoc network with NAT
E
A bastion host
Reveal answer detailsClose answer details
Correct answerB
Question 46
Single choice
A network operations manager has added a second row of server racks in the datacenter. These racks face the opposite direction of the first row of racks.
Which of the following is the reason the manager installed the racks this way?
A
To lower energy consumption by sharing power outlets
B
To create environmental hot and cold isles
C
To eliminate the potential for electromagnetic interference
D
To maximize fire suppression capabilities
Reveal answer detailsClose answer details
Correct answerB
Question 47
Single choice
A network administrator wants to ensure that users do not connect any unauthorized devices to the company network. Each desk needs to connect a VoIP phone and computer.
Which of the following is the BEST way to accomplish this?
A
Enforce authentication for network devices
B
Configure the phones on one VLAN, and computers on another
C
Enable and configure port channels
D
Make users sign an Acceptable use Agreement
Reveal answer detailsClose answer details
Correct answerA
Question 48
Single choice
The security administrator receives an email on a non-company account from a coworker stating that some reports are not exporting correctly. Attached to the email was an example report file with several customers' names and credit card numbers with the PIN.
Which of the following is the BEST technical controls that will help mitigate this risk of disclosing sensitive data?
A
Configure the mail server to require TLS connections for every email to ensure all transport data is encrypted
B
Create a user training program to identify the correct use of email and perform regular audits to ensure compliance
C
Implement a DLP solution on the email gateway to scan email and remove sensitive data or files
D
Classify all data according to its sensitivity and inform the users of data that is prohibited to share
Reveal answer detailsClose answer details
Correct answerC
Question 49
Single choice
A technician is configuring a wireless guest network. After applying the most recent changes the technician finds the new devices can no longer find the wireless network by name but existing devices are still able to use the wireless network.
Which of the following security measures did the technician MOST likely implement to cause this Scenario?
A
Deactivation of SSID broadcast
B
Reduction of WAP signal output power
C
Activation of 802.1X with RADIUS
D
Implementation of MAC filtering
E
Beacon interval was decreased
Reveal answer detailsClose answer details
Correct answerA
Question 50
Single choice
A group of non-profit agencies wants to implement a cloud service to share resources with each other and minimize costs.
Which of the following cloud deployment models BEST describes this type of effort?
A
Public
B
Hybrid
C
Community
D
Private
Reveal answer detailsClose answer details
Correct answerC
Question 51
Single choice
During a routine audit, it is discovered that someone has been using a stale administrator account to log into a seldom used server. The person has been using the server to view inappropriate websites that are prohibited to end users.
Which of the following could best prevent this from occurring again?
A
Credential management
B
Group policy management
C
Acceptable use policy
D
Account expiration policy
Reveal answer detailsClose answer details
Correct answerB
Question 52
Single choice
Which of the following attack types BEST describes a client-side attack that is used to manipulate an HTML iframe with JavaScript code via a web browser?
A
Buffer overflow
B
MITM
C
XSS
D
SQLi
Reveal answer detailsClose answer details
Correct answerC
Question 53
Single choice
A company wants to ensure that the validity of publicly trusted certificates used by its web server can be determined even during an extended internet outage.
An organization has hired a penetration tester to test the security of its ten web servers. The penetration tester is able to gain root/administrative access in several servers by explogting vulnerabilities associated with the implementation of SMTP, POP, DNS, FTP, Telnet, and IMAP.
Which of the following recommendations should the penetration tester provide to the organization to better protect their web servers in the future?
A.
Use a honeypot
B.
Disable unnecessary services
C.
Implement transport layer security
D.
Increase application event logging
Correct Answer: B
QUESTION 2
A dumpster diver recovers several hard drives from a company and is able to obtain confidential data from one of the hard drives. The company then discovers its information is posted online.
Which of the following methods would have MOST likely prevented the data from being exposed?
A.
Removing the hard drive from its enclosure
B.
Using software to repeatedly rewrite over the disk space
C.
Using Blowfish encryption on the hard drives
D.
Using magnetic fields to erase the data
Correct Answer: D
QUESTION 3
The Chief Technology Officer (CTO) of a company, Ann, is putting together a hardware budget for the next 10 years. She is asking for the average lifespan of each hardware device so that she is able to calculate when she will have to replace each device.
Which of the following categories BEST describes what she is looking for?
A.
ALE
B.
MTTR
C.
MTBF
D.
MTTF
Correct Answer: D
QUESTION 4
A security analyst is reviewing the following packet capture of an attack directed at a company's server located in the DMZ:
Which of the following ACLs provides the BEST protection against the above attack and any further attacks from the same IP, while minimizing service interruption?
A.
DENY TCO From ANY to 172.31.64.4
B.
Deny UDP from 192.168.1.0/24 to 172.31.67.0/24
C.
Deny IP from 192.168.1.10/32 to 0.0.0.0/0
D.
Deny TCP from 192.168.1.10 to 172.31.67.4
Correct Answer: C
QUESTION 5
Which of the following should identify critical systems and components?
A.
MOU
B.
BPA
C.
ITCP
D.
BCP
Correct Answer: D
QUESTION 6
An application developer is designing an application involving secure transports from one service to another that will pass over port 80 for a request.
Which of the following secure protocols is the developer MOST likely to use?
A.
FTPS
B.
SFTP
C.
SSL
D.
LDAPS
Correct Answer: C
QUESTION 7
A security administrator must implement a system to ensure that invalid certificates are not used by a custom developed application. The system must be able to check the validity of certificates even when internet access is unavailable.
Which of the following MUST be implemented to support this requirement?
A.
CSR
B.
OCSP
C.
CRL
D.
SSH
Correct Answer: C
QUESTION 8
Which of the following threat actors is MOST likely to steal a company's proprietary information to gain a market edge and reduce time to market?
A.
Competitor
B.
Hacktivist
C.
Insider
D.
Organized crime.
Correct Answer: A
QUESTION 9
Which of the following would a security specialist be able to determine upon examination of a server's certificate?
A.
CA public key
B.
Server private key
C.
CSR
D.
OID
Correct Answer: D
QUESTION 10
A system administrator wants to provide for and enforce wireless access accountability during events where external speakers are invited to make presentations to a mixed audience of employees and non-employees.
Which of the following should the administrator implement?
A.
Shared accounts
B.
Preshared passwords
C.
Least privilege
D.
Sponsored guest
Correct Answer: D
QUESTION 11
A Chief Information Officer (CIO) drafts an agreement between the organization and its employees. The agreement outlines ramifications for releasing information without consent and/for approvals.
Which of the following BEST describes this type of agreement?
A.
ISA
B.
NDA
C.
MOU
D.
SLA
Correct Answer: B
QUESTION 12
A security analyst is performing a quantitative risk analysis. The risk analysis should show the potential monetary loss each time a threat or event occurs. Given this requirement, which of the following concepts would assist the analyst in determining this value? (Select two.)
A.
ALE
B.
AV
C.
ARO
D.
EF
E.
ROI
Correct Answer: BD
QUESTION 13
Joe notices there are several user accounts on the local network generating spam with embedded malicious code.
Which of the following technical control should Joe put in place to BEST reduce these incidents?
A.
Account lockout
B.
Group Based Privileges
C.
Least privilege
D.
Password complexity
Correct Answer: A
QUESTION 14
Ann a security analyst is monitoring the IDS console and noticed multiple connections from an internal host to a suspicious call back domain.
Which of the following tools would aid her to decipher the network traffic?
A.
Vulnerability Scanner
B.
NMAP
C.
NETSTAT
D.
Packet Analyzer
Correct Answer: C
QUESTION 15
When connected to a secure WAP, which of the following encryption technologies is MOST likely to be configured when connecting to WPA2-PSK?
A.
DES
B.
AES
C.
MD5
D.
WEP
Correct Answer: B
QUESTION 16
A datacenter manager has been asked to prioritize critical system recovery priorities.
Which of the following is the MOST critical for immediate recovery?
A.
Communications software
B.
Operating system software
C.
Weekly summary reports to management
D.
Financial and production software
Correct Answer: B
QUESTION 17
A technician needs to implement a system which will properly authenticate users by their username and password only when the users are logging in from a computer in the office building. Any attempt to authenticate from a location other than the office building should be rejected.
Which of the following MUST the technician implement?
A.
Dual factor authentication
B.
Transitive authentication
C.
Single factor authentication
D.
Biometric authentication
Correct Answer: B
QUESTION 18
A security administrator has found a hash in the environment known to belong to malware. The administrator then finds this file to be in in the preupdate area of the OS, which indicates it was pushed from the central patch system.
The administrator pulls a report from the patch management system with the following output:
Given the above outputs, which of the following MOST likely happened?
A.
The file was corrupted after it left the patch system.
B.
The file was infected when the patch manager downloaded it.
C.
The file was not approved in the application whitelist system.
D.
The file was embedded with a logic bomb to evade detection.
Correct Answer: B
QUESTION 19
Which of the following types of attacks precedes the installation of a rootkit on a server?
A.
Pharming
B.
DDoS
C.
Privilege escalation
D.
DoS
Correct Answer: C
QUESTION 20
HOTSPOT
For each of the given items, select the appropriate authentication category from the drop down choices. Select the appropriate authentication type for the following items:
Correct Answer:
Explanation
Explanation/Reference:
Biometrics refers to a collection of physical attributes of the human body that can be used as identification or an authentication factor. Fingerprints and retinas are physical attributes of the human body. Two types of tokens exist, Time-based one-time password (TOTP) tokens and HMACbased one-time password (HOTP). TOTP tokens generate passwords at fixed time intervals, whereas HOTP tokens generate passwords not based on fixed time intervals but instead based on a non-repeating one-way function, such as a hash or HMAC operation. Smart cards can have Multi-factor and proximity authentication embedded into it. PAP allows for two entities to share a password in advance and use the password as the basis of authentication. The same goes for PIN numbers. References: Stewart, James Michael, CompTIA Security+ Review Guide, Sybex, Indianapolis, 2014, pp. 282, 285 (http://en.wikipedia.org/wiki/Password_authentication_protocol#Working_cycle) http://en.wikipedia.org/wiki/Smart_card#Security
QUESTION 21
An organization is working with a cloud services provider to transition critical business applications to a hybrid cloud environment. The organization retains sensitive customer data and wants to ensure the provider has sufficient administrative and logical controls in place to protect its data. In which of the following documents would this concern MOST likely be addressed?
A.
Service level agreement
B.
Interconnection security agreement
C.
Non-disclosure agreement
D.
Business process analysis
Correct Answer: A
QUESTION 22
Which of the following BEST describes an important security advantage yielded by implementing vendor diversity?
A.
Sustainability
B.
Homogeneity
C.
Resiliency
D.
Configurability
Correct Answer: C
QUESTION 23
HOTSPOT
The security administrator has installed a new firewall which implements an implicit DENY policy by default. Click on the firewall and configure it to allow ONLY the following communication. 1. The Accounting workstation can ONLY access the web server on the public network over the default HTTPS port. The accounting workstation should not access other networks. 2. The HR workstation should be restricted to communicate with the Financial server ONLY, over the default SCP port 3. The Admin workstation should ONLY be able to access the servers on the secure network over the default TFTP port. Instructions: The firewall will process the rules in a top-down manner in order as a first match The port number must be typed in and only one port number can be entered per rule Type ANY for all ports. The original firewall configuration can be reset at any time by pressing the reset button. Once you have met the simulation requirements, click save and then Done to submit.
Correct Answer:
Explanation
Explanation/Reference:
Implicit deny is the default security stance that says if you aren't specifically granted access or privileges for a resource, you're denied access by default.
Rule #1 allows the Accounting workstation to ONLY access the web server on the public network over the default HTTPS port, which is TCP port 443. Rule #2 allows the HR workstation to ONLY communicate with the Financial server over the default SCP port, which is TCP Port 22 Rule #3 & Rule #4 allow the Admin workstation to ONLY access the Financial and Purchasing servers located on the secure network over the default TFTP port, which is Port 69. References: Stewart, James Michael, CompTIA Security+ Review Guide, Sybex, Indianapolis, 2014, pp.26, 44 (http://en.wikipedia.org/wiki/List_of_TCP_and_UDP_port_numbers)
QUESTION 24
A security analyst accesses corporate web pages and inputs random data in the forms. The response received includes the type of database used and SQL commands that the database accepts.
Which of the following should the security analyst use to prevent this vulnerability?
A.
Application fuzzing
B.
Error handling
C.
Input validation
D.
Pointer dereference
Correct Answer: C
QUESTION 25
An administrator is testing the collision resistance of different hashing algorithms.
Which of the following is the strongest collision resistance test?
A.
Find two identical messages with different hashes
B.
Find two identical messages with the same hash
C.
Find a common has between two specific messages
D.
Find a common hash between a specific message and a random message
Correct Answer: A
QUESTION 26
A company is planning to encrypt the files in several sensitive directories of a file server with a symmetric key.
Which of the following could be used?
A.
RSA
B.
TwoFish
C.
Diffie-Helman
D.
NTLMv2
E.
RIPEMD
Correct Answer: B
QUESTION 27
A company exchanges information with a business partner. An annual audit of the business partner is conducted against the SLA in order to verify:
A.
Performance and service delivery metrics
B.
Backups are being performed and tested
C.
Data ownership is being maintained and audited
D.
Risk awareness is being adhered to and enforced
Correct Answer: A
QUESTION 28
A supervisor in your organization was demoted on Friday afternoon. The supervisor had the ability to modify the contents of a confidential database, as well as other managerial permissions. On Monday morning, the database administrator reported that log files indicated that several records were missing from the database.
Which of the following risk mitigation strategies should have been implemented when the supervisor was demoted?
A.
Incident management
B.
Routine auditing
C.
IT governance
D.
Monthly user rights reviews
Correct Answer: D
QUESTION 29
A company is using a mobile device deployment model in which employees use their personal devices for work at their own discretion. Some of the problems the company is encountering include the following:
There is no standardization. Employees ask for reimbursement for their devices. Employees do not replace their devices often enough to keep them running efficiently. The company does not have enough control over the devices.
Which of the following is a deployment model that would help the company overcome these problems?
A.
BYOD
B.
VDI
C.
COPE
D.
CYOD
Correct Answer: D
QUESTION 30
HOTSPOT
Select the appropriate attack from each drop down list to label the corresponding illustrated attack Instructions: Attacks may only be used once, and will disappear from drop down list if selected. When you have completed the simulation, please select the Done button to submit.
Correct Answer:
Explanation
Explanation/Reference:
1: Spear phishing is an e-mail spoofing fraud attempt that targets a specific organization,seeking unauthorized access to confidential data. As with the e-mail messages used in regular phishing expeditions, spear phishing messages appear to come from a trusted source. Phishing messages usually appear to come from a large and well-known company or Web site with a broad membership base, such as eBay or PayPal. In the case of spear phishing, however, the apparent source of the e-mail is likely to be an individual within the recipient's own company and generally someone in a position of authority. 2: The Hoax in this question is designed to make people believe that the fake AV (antivirus) software is genuine. 3: Vishing is the act of using the telephone in an attempt to scam the user into surrendering private information that will be used for identity theft. The scammer usually pretends to be a legitimate business, and fools the victim into thinking he or she will profit. 4: Phishing is the act of sending an email to a user falsely claiming to be an established legitimate enterprise in an attempt to scam the user into surrendering private information that will be used for identity theft. Phishing email will direct the user to visit a website where they are asked to update personal information, such as a password, credit card, social security, or bank account numbers, that the legitimate organization already has. The website, however, is bogus and set up only to steal the information the user enters on the page. 5: Similar in nature to e-mail phishing, pharming seeks to obtain personal or private (usually financial related) information through domain spoofing. Rather than being spammed with malicious and mischievous e-mail requests for you to visit spoof Web sites which appear legitimate, pharming 'poisons' a DNS server by infusing false information into the DNS server, resulting in a user's request being redirected elsewhere. Your browser, however will show you are at the correct Web site, which makes pharming a bit more serious and more difficult to detect. Phishing attempts to scam people one at a time with an e-mail while pharming allows the scammers to target large groups of people at one time through domain spoofing. References: http://searchsecurity.techtarget.com/definition/spear-phishing http://www.webopedia.com/TERM/V/vishing.html http://www.webopedia.com/TERM/P/phishing.html http://www.webopedia.com/TERM/P/pharming.html
QUESTION 31
A security engineer is configuring a system that requires the X.509 certificate information to be pasted into a form field in Base64 encoded format to import it into the system.
Which of the following certificate formats should the engineer use to obtain the information in the required format?
A.
PFX
B.
PEM
C.
DER
D.
CER
Correct Answer: B
QUESTION 32
Which of the following cryptographic attacks would salting of passwords render ineffective?
A.
Brute force
B.
Dictionary
C.
Rainbow tables
D.
Birthday
Correct Answer: C
QUESTION 33
A senior incident response manager receives a call about some external IPs communicating with internal computers during off hours.
Which of the following types of malware is MOST likely causing this issue?
A.
Botnet
B.
Ransomware
C.
Polymorphic malware
D.
Armored virus
Correct Answer: A
QUESTION 34
A web application is configured to target browsers and allow access to bank accounts to siphon money to a foreign account. This is an example of which of the following attacks?
A.
SQL injection
B.
Header manipulation
C.
Cross-site scripting
D.
Flash cookie explogtation
Correct Answer: C
QUESTION 35
To reduce disk consumption, an organization's legal department has recently approved a new policy setting the data retention period for sent email at six months.
Which of the following is the BEST way to ensure this goal is met?
A.
Create a daily encrypted backup of the relevant emails.
B.
Configure the email server to delete the relevant emails.
C.
Migrate the relevant emails into an "Archived" folder.
D.
Implement automatic disk compression on email servers.
Correct Answer: A
QUESTION 36
A malicious attacker has intercepted HTTP traffic and inserted an ASCII line that sets the referrer URL.
Which of the following is the attacker most likely utilizing?
A.
Header manipulation
B.
Cookie hijacking
C.
Cross-site scripting
D.
Xml injection
Correct Answer: A
QUESTION 37
A security program manager wants to actively test the security posture of a system. The system is not yet in production and has no uptime requirement or active user base.
Which of the following methods will produce a report which shows vulnerabilities that were actually explogted?
A.
Peer review
B.
Component testing
C.
Penetration testing
D.
Vulnerability testing
Correct Answer: C
Explanation
Explanation/Reference:
A penetration test, or pen test, is an attempt to evaluate the security of an IT infrastructure by safely trying to explogt vulnerabilities.
QUESTION 38
After a user reports stow computer performance, a systems administrator detects a suspicious file, which was installed as part of a freeware software package.
The systems administrator reviews the output below:
Based on the above information, which of the following types of malware was installed on the user's computer?
A.
RAT
B.
Keylogger
C.
Spyware
D.
Worm
E.
Bot
Correct Answer: A
QUESTION 39
Which of the following is the summary of loss for a given year?
A.
MTBF
B.
ALE
C.
SLA
D.
ARO
Correct Answer: B
QUESTION 40
A company has three divisions, each with its own networks and services. The company decides to make its secure web portal accessible to all employees utilizing their existing usernames and passwords. The security administrator has elected to use SAML to support authentication. In this scenario, which of the following will occur when users try to authenticate to the portal? (Select two.)
A.
The portal will function as a service provider and request an authentication assertion.
B.
The portal will function as an identity provider and issue an authentication assertion.
C.
The portal will request an authentication ticket from each network that is transitively trusted.
D.
The back-end networks will function as an identity provider and issue an authentication assertion.
E.
The back-end networks will request authentication tickets from the portal, which will act as the third- party service provider authentication store.
F.
The back-end networks will verify the assertion token issued by the portal functioning as the identity provider.
Correct Answer: AB
QUESTION 41
A security team wants to establish an Incident Response plan. The team has never experienced an incident.
Which of the following would BEST help them establish plans and procedures?
A.
Table top exercises
B.
Lessons learned
C.
Escalation procedures
D.
Recovery procedures
Correct Answer: A
QUESTION 42
A security guard has informed the Chief Information Security Officer that a person with a tablet has been walking around the building. The guard also noticed strange white markings in different areas of the parking lot. The person is attempting which of the following types of attacks?
A.
Jamming
B.
War chalking
C.
Packet sniffing
D.
Near field communication
Correct Answer: B
QUESTION 43
Which of the following attacks specifically impacts data availability?
A.
DDoS
B.
Trojan
C.
MITM
D.
Rootkit
Correct Answer: A
Explanation
Explanation/Reference:
References:
QUESTION 44
Joe is exchanging encrypted email with another party. Joe encrypts the initial email with a key. When Joe receives a response, he is unable to decrypt the response with the same key he used initially.
Which of the following would explain the situation?
A.
An ephemeral key was used for one of the messages
B.
A stream cipher was used for the initial email; a block cipher was used for the reply
C.
Out-of-band key exchange has taken place
D.
Asymmetric encryption is being used
Correct Answer: D
Explanation
Explanation/Reference:
Asymmetric algorithms use two keys to encrypt and decrypt dat A. These asymmetric keys are referred to as the public key and the private key. The sender uses the public key to encrypt a message, and the receiver uses the private key to decrypt the message; what one key does, the other one undoes.
QUESTION 45
A company is developing a new secure technology and requires computers being used for development to be isolated.
Which of the following should be implemented to provide the MOST secure environment?
A.
A perimeter firewall and IDS
B.
An air gapped computer network
C.
A honeypot residing in a DMZ
D.
An ad hoc network with NAT
E.
A bastion host
Correct Answer: B
QUESTION 46
A network operations manager has added a second row of server racks in the datacenter. These racks face the opposite direction of the first row of racks.
Which of the following is the reason the manager installed the racks this way?
A.
To lower energy consumption by sharing power outlets
B.
To create environmental hot and cold isles
C.
To eliminate the potential for electromagnetic interference
D.
To maximize fire suppression capabilities
Correct Answer: B
QUESTION 47
A network administrator wants to ensure that users do not connect any unauthorized devices to the company network. Each desk needs to connect a VoIP phone and computer.
Which of the following is the BEST way to accomplish this?
A.
Enforce authentication for network devices
B.
Configure the phones on one VLAN, and computers on another
C.
Enable and configure port channels
D.
Make users sign an Acceptable use Agreement
Correct Answer: A
QUESTION 48
The security administrator receives an email on a non-company account from a coworker stating that some reports are not exporting correctly. Attached to the email was an example report file with several customers' names and credit card numbers with the PIN.
Which of the following is the BEST technical controls that will help mitigate this risk of disclosing sensitive data?
A.
Configure the mail server to require TLS connections for every email to ensure all transport data is encrypted
B.
Create a user training program to identify the correct use of email and perform regular audits to ensure compliance
C.
Implement a DLP solution on the email gateway to scan email and remove sensitive data or files
D.
Classify all data according to its sensitivity and inform the users of data that is prohibited to share
Correct Answer: C
QUESTION 49
A technician is configuring a wireless guest network. After applying the most recent changes the technician finds the new devices can no longer find the wireless network by name but existing devices are still able to use the wireless network.
Which of the following security measures did the technician MOST likely implement to cause this Scenario?
A.
Deactivation of SSID broadcast
B.
Reduction of WAP signal output power
C.
Activation of 802.1X with RADIUS
D.
Implementation of MAC filtering
E.
Beacon interval was decreased
Correct Answer: A
QUESTION 50
A group of non-profit agencies wants to implement a cloud service to share resources with each other and minimize costs.
Which of the following cloud deployment models BEST describes this type of effort?
A.
Public
B.
Hybrid
C.
Community
D.
Private
Correct Answer: C
QUESTION 51
During a routine audit, it is discovered that someone has been using a stale administrator account to log into a seldom used server. The person has been using the server to view inappropriate websites that are prohibited to end users.
Which of the following could best prevent this from occurring again?
A.
Credential management
B.
Group policy management
C.
Acceptable use policy
D.
Account expiration policy
Correct Answer: B
QUESTION 52
Which of the following attack types BEST describes a client-side attack that is used to manipulate an HTML iframe with JavaScript code via a web browser?
A.
Buffer overflow
B.
MITM
C.
XSS
D.
SQLi
Correct Answer: C
QUESTION 53
A company wants to ensure that the validity of publicly trusted certificates used by its web server can be determined even during an extended internet outage.