Back to overview

CompTIA Securtiy+ Set11 A_3_3_IDS_and_SIEM

CompTIA Securtiy+ Set11 A_3_3_IDS_and_SIEM

Subject
Sciences / Computer science
Language of creation
English
39 flashcards No ratings yet 0 views
Add to my sets

Sign in to add this set to your collection. You will return here afterwards.

Cards in this set

Card 1

Question

0022
A security analyst is reviewing the following output from an IPS:

Given this output, which of the following can be concluded? (Select two.)

 

Answer

  • The source IP of the attack is coming from 250.19.18.22.
  • The source IP of the attack is coming from 250.19.18.71.
  • The attacker sent a malformed IGAP packet, triggering the alert.
  • The attacker sent a malformed TCP packet, triggering the alert.
  • The TTL value is outside of the expected range, triggering the alert.

Card 2

Question

0053
A security administrator has found a hash in the environment known to belong to malware. The administrator
then finds this file to be in in the pre-update area of the OS, which indicates it was pushed from the central patch
system.

File: winx86_adobe_flash_upgrade.exe
Hash: 99ac28bede43ab869b853ba62c4ea243

The administrator pulls a report from the patch management system with the following output:

Given the above outputs, which of the following MOST likely happened?

Answer

  • The file was corrupted after it left the patch system.
  • The file was infected when the patch manager downloaded it.
  • The file was not approved in the application whitelist system.
  • The file was embedded with a logic bomb to evade detection.

Card 3

Question

0152
After a routine audit, a company discovers that engineering documents have been leaving the network on a
particular port. The company must allow outbound traffic on this port, as it has a legitimate business use. Blocking
the port would cause an outage. Which of the following technology controls should the company implement?

Answer

  • NAC
  • DLP
  • Web proxy
  • ACL

Card 4

Question

0174
The security administrator receives an email on a non-company account from a coworker stating that some
reports are not exporting correctly. Attached to the email was an example report file with several customer’s
names and credit card numbers with the PIN.

Which of the following is the BEST technical controls that will help mitigate this risk of disclosing sensitive data?

Answer

  • Configure the mail server to require TLS connections for every email to ensure all transport data is encrypted
  • Create a user training program to identify the correct use of email and perform regular audits to ensure compliance
  • Implement a DLP solution on the email gateway to scan email and remove sensitive data or files
  • Classify all data according to its sensitivity and inform the users of data that is prohibited to share

Card 5

Question

0192
While reviewing the monthly internet usage it is noted that there is a large spike in traffic classified as "unknown"
and does not appear to be within the bounds of the organizations Acceptable Use Policy.

Which of the following tool or technology would work BEST for obtaining more information on this traffic?

Answer

  • IDS logs
  • Firewall logs
  • Protocol analyzer
  • Increased spam filtering

Card 6

Question

0242
A computer on a company network was infected with a zero-day exploit after an employee accidently opened an
email that contained malicious content. The employee recognized the email as malicious and was attempting to
delete it, but accidently opened it.

Which of the following should be done to prevent this scenario from occurring again in the future?

Answer

  • Install host-based firewalls on all computers that have an email client installed
  • Set the email program default to open messages in plain text
  • Install end-point protection on all computers that access web email
  • Create new email spam filters to delete all messages from that sender

Card 7

Question

0271
A security administrator needs to implement a system that detects possible intrusions based upon a vendor
provided list.

Which of the following BEST describes this type of IDS?

Answer

  • Signature based
  • Behavior-based
  • Anomaly-based
  • Heuristic

Card 8

Question

0297
Joe, a website administrator, believes he owns the intellectual property for a company invention and has been
replacing image files on the company's public facing website in the DMZ. Joe is using steganography to hide stolen
data.

Which of the following controls can be implemented to mitigate this type of inside threat?

Answer

  • Digital signatures
  • File integrity monitoring
  • Access controls
  • Change management
  • Stateful inspection firewall

Card 9

Question

0326
A security administrator suspects that data on a server has been exfiltrated as a result of unauthorized remote
access.

Which of the following would assist the administrator in confirming the suspicions? (Select TWO)

Answer

  • Network access control
  • DLP alerts
  • File integrity monitoring
  • Log analysis
  • Host firewall rules

Card 10

Question

0344
An administrator thinks the UNIX systems may be compromised, but a review of system log files provides no useful
information. After discussing the situation with the security team, the administrator suspects that the attacker
may be altering the log files and removing evidence of intrusion activity.

Which of the following actions will help detect attacker attempts to further alter log files?

Answer

  • Change the permissions on the user‘s home directory
  • Enable verbose system logging
  • Implement remote syslog
  • Set the bash_history log file to "read only"

Card 11

Question

0405
The Chief Information Security Officer (CISO) is asking for ways to protect against zero-day exploits. The CISO is
concerned that an unrecognized threat could compromise corporate data and result in regulatory fines as well as
poor corporate publicity. The network is mostly flat, with split staff/guest wireless functionality. Which of the
following equipment MUST be deployed to guard against unknown threats?

Answer

  • Implementation of an off-site datacenter hosting all company data, as well as deployment of VDI for all client computing needs
  • Cloud-based antivirus solution, running as local admin, with push technology for definition updates
  • Host-based heuristic IPS, segregated on a management VLAN, with direct control of the perimeter firewall ACLs
  • Behavior-based IPS with a communication link to a cloud-based vulnerability and threat feed

Card 12

Question

0406
An organization has several production-critical SCADA1 supervisory systems that cannot follow the normal 30-day
patching policy. Which of the following BEST maximizes the protection of these systems from malicious software?

Answer

  • Configure a firewall with deep packet inspection that restricts traffic to the systems.
  • Configure a separate zone for the systems and restrict access to known ports.
  • Configure the systems to ensure only necessary applications are able to run.
  • Configure the host firewall to ensure only the necessary applications have listening ports

Card 13

Question

0419
A security administrator learns that PII, which was gathered by the organization, has been found in an open forum.
As a result, several C-IeveI executives found their identities were compromised, and they were victims of a recent
whaling attack. Which of the following would prevent these problems in the future? (Select TWO).

Answer

  • Implement a reverse proxy.
  • Implement an email DLP.
  • Implement a spam filter.
  • Implement a HIDS.

Card 14

Question

0434
A technician receives a device with the following anomalies:
- Frequent pop-up ads
- Slow response time switching between active programs
- Unresponsive peripherals
The technician reviews the following log file entries:

File Name Source MD5 Target MD5
Status
antivirus.exe F794F21CD33E4F57890DDEA5CF267ED2 F794F21CD33E4F57890DDEA5CF267ED2 Automatic iexplore.exe 7FAAF21CD33E4F57890DDEA5CF29CCEA AA87F21CD33E4F57890DDEAEE2197333 Automatic service.exe 77FF390CD33E4F57890DDEA5CF28881F 77FF390CD33E4F57890DDEA5CF28881F Manual USB.exe E289F21CD33E4F57890DDEA5CF28EDC0 E289F21CD33E4F57890DDEA5CF28EDC0 Stopped

Based on the above output, which of the following should be reviewed?

 

Answer

  • The file integrity check
  • The web application firewall
  • The data execution prevention
  • The removable media control

Card 15

Question

0487
A security administrator installed a new network scanner that identifies new host systems on the network. Which
of the following did the security administrator install?

Answer

  • Vulnerability scanner
  • Network-based IDS
  • Rogue system detection
  • Configuration compliance scanner

Card 16

Question

0502
A security administrator is trying to eradicate a worm, which is spreading throughout the organization, using an
old remote vulnerability in the SMB protocol. The worm uses Nmap to identify target hosts within the company.
The administrator wants to implement a solution that will eradicate the current worm and any future attacks that
may be using zero-day vulnerabilities. Which of the following would BEST meet the requirements when
implemented?

Answer

  • Host-based firewall
  • Network-based intrusion prevention system
  • Enterprise patch management system
  • Application blacklisting
  • File integrity checking

Card 17

Question

0544
A security analyst receives a notification from the IDS after working hours, indicating a spike in network traffic.
Which of the following BEST describes this type of IDS?

Answer

  • Stateful
  • Anomaly-based
  • Host-based
  • Signature-based

Card 18

Question

0547
A company recently experienced data exfiltration via the corporate network. In response to the breach, a security
analyst recommends deploying an out-of-band IDS solution. The analyst says the solution can be implemented
without purchasing any additional network hardware. Which of the following solutions will be used to deploy the
IDS?

Answer

  • Network tap
  • Network proxy
  • Port mirroring
  • Honeypot

Card 19

Question

0548
An organization wants to implement a solution that allows for automated logical controls for network defense. An
engineer plans to select an appropriate network security component, which automates response actions based on
security threats to the network. Which of the following would be MOST appropriate based on the engineer’s
requirements?

Answer

  • NIPS
  • HIDS
  • Elastic load balancer
  • Web proxy
  • NAC

Card 20

Question

0554
A small-to-medium sized company wants to block the use of USB devices on its network. Which of the following is
the MOST cost-effective way for the security analyst to prevent this?

Answer

  • Implement a DLP system
  • Apply a GPO
  • Conduct user awareness training
  • Enforce the AUP

How to use this set

Read the preview and check whether the content and answers suit your learning goal. You can add the public set to your sets to study it. Your account shows the available actions.

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please reload the page.