Back to overview

Kopie - T.W.S. 601 Teil 2

Discover Kopie - T.W.S. 601 Teil 2: 90 flashcards with questions and answers.

Subject
Sciences / Computer science
Language of creation
English
90 flashcards No ratings yet 0 views
Add to my sets

Sign in to add this set to your collection. You will return here afterwards.

Cards in this set

Card 1

Question

331. An attacker is targeting a company. The attacker notices that the company's employees frequently access a particular website. The attacker decides to infect the website with malware and hopes the employees' devices will also become infected.

Which of the following techniques is the attacker using?

Answer

  • Typosquatting
  • Impersonation
  • Watering-hole attack
  • Pretexting

Card 2

Question

332. While performing a threat-hunting exercise, a security analyst sees some unusual behavior occurring in an application when a user changes the display name. The security analyst decides to perform a static code analysis and receives the following pseudocode:

Which of the following attack types best describes the root cause of the unusual behavior?

Answer

  • Buffer overflow
  • SQL injection
  • Improper error handling
  • Server-side request forgery

Card 3

Question

333. A security team is providing input on the design of a secondary data center that has the following requirements:

- Anatural disaster at the primary site should not affect the secondary site. The secondary site should have the capability for failover during traffic surge situations.

- The secondary site must m eet the same physical security requirements as the primary site. The secondary site must provide pro tection against power surges and outages.

Which of the following should the security team recommend? (Select two).

Answer

  • Deploying load balancers at the primary site
  • Using differential backups at the secondary site
  • Constructing the secondary site in a geographically disperse location
  • Coniguring replication of the web servers at the primary site to offline storage
  • Implementing hot and cold aisles at the secondary site
  • Installing generators

Card 4

Question

334. An account was disabled atter several failed and successful login connections were made from various parts of the Word at various times. A security analysts investigating the issue.

Which of the following account policies has most likely triggered the deactivation action.

Answer

  • Time based logins
  • Geofencing
  • Impossible travel time
  • Password history

Card 5

Question

335. Which of the following should a Chief Information Security Officer consider using to take advantage of industry standard guidelines?

Answer

  • PCI DSS
  • GDPR
  • NIST CSF
  • SSAE SOC 2

Card 6

Question

A security manager is attempting to meet multiple security objectives in the next fiscal year. The
security manager has proposed the purchase of the following four items:

Vendor A:
1- Firewall
1-12 switch
Vendor B:
1- Firewall
1-12 switch

Which of the following security objectives is the security manager attempting to meet? (Select two).

Answer

  • Multipath
  • Simplified patch management
  • Replication
  • Zero-day attack tolerance
  • Scalability
  • Redundancy

Card 7

Question

337. A systems integrator is installing a new access control system for a building. The new system will need to connect to the Company's AD server In order to validate current employees.

Which of the following should the systems integrator configure to be the most secure?

Answer

  • HTTPS
  • SFTP
  • SSH
  • LDAPS

Card 8

Question

338.

Answer

  • Private Key
  • Password Hash
  • Salt-String
  • Cipher Stream

Card 9

Question

339. During a recent cybersecurity audit, the auditors pointed out various types of various types of vulnerabilities in the production area. The hardware in the production area runs applications that are important for production.

Which of the of the following describes what the company should do first to reduce the risk to the production hardware?

Answer

  • Add a banner page to the hardware.
  • Back up the hardware.
  • Apply patches.
  • Install an antivirus solution.

Card 10

Question

340. A security engineer updated an application on company workstations. The application was running before the update, but it is no longer launching successfully.

Which of the following most likely needs to be updated?

Answer

  • Deny list
  • Approved list
  • Blocklist
  • Quarantine list

Card 11

Question

341. A user is trying unsuccessfully to send images via SMS. The user downloaded the images from a corporate email account on a work phone.

Which of the following policies is preventing the user from completing this action?

Answer

  • Content management
  • Application management
  • Full disk encryption
  • Containerization

Card 12

Question

342. A company recently completed the transition from data centers to the cloud. Which of the following solutions will best enable the company to detect security threats in applications that run in isolated environments within the cloud environment?

Answer

  • Virtual networks
  • Security groups
  • Segmentation
  • Container security

Card 13

Question

343. A manager for the development team is concerned about reports showing a common set of vulnerabilities. The set of vulnerabilities is present on almost all of the applications developed by the team.

Which of the following approaches would be most effective for the manager to use to address this issue?

Answer

  • Tune the accuracy of fuzz testing
  • Implement code signing to make code immutable.
  • Invest in secure coding training and application security guidelines.
  • Increase the frequency of dynamic code scans 1o detect issues faster.

Card 14

Question

344. A company is focused on reducing risks from removable media threats. Due to certain primary applications, removable media cannot be entirely prohibited at this time.

Which of the following best describes the company's approach?

Answer

  • Physical security controls
  • Compensating controls
  • Directive control
  • Mitigating controls

Card 15

Question

345. A security administrator would like to ensure all cloud servers will have software preinstalled for facilitating vulnerability scanning and continuous monitoring. Which of the following concepts should the administrator utilize?

Answer

  • Development
  • Provisioning
  • Staging
  • Quality assurance

Card 16

Question

346. An organization wants to secure a LAN/WLAN so users can authenticate and transport data securely. The solution needs to prevent on-path attacks and evil twin attacks.

Which of the following will best meet the organization's need?

Answer

  • MFA
  • 802.1X
  • WPA2
  • TACACS

Card 17

Question

347. An organization recently completed a security control assessment The organization determined some controls did not meet the existing security measures. Additional mitigations are needed to lessen the risk of the non-complaint controls.

Which of the following best describes these mitigations?

Answer

  • Deterrent
  • Compensating
  • Corrective
  • Technical

Card 18

Question

348. A contractor overhears a customer recite their credit card number during a confidential phone call. The credit card Information is later used for a fraudulent transaction. Which of the following social engineering techniques describes this scenario?

Answer

  • Shoulder Surfing
  • Vishing
  • Watering Hole
  • Tailgating

Card 19

Question

349. An analyst is working on an investigation with multiple alarms for multiple hosts. The hosts show signs that they have been compromised by a fast-spreading worm.

Which of the following should be the next step to stop the spread?

Answer

  • Scan the hosts that show signs of infection.
  • Perform an AV scan on the entire network.
  • Disconnect each host from the network.
  • Place all known infected hosts on an isolated network.

Card 20

Question

350. Which of the following best describes a tool used by an organization to identitfy, log, and track any potential risks and corresponding risk information?

Answer

  • Risk control assessment
  • Risk matrix
  • Risk register
  • Quantitative risk assessment

How to use this set

Read the preview and check whether the content and answers suit your learning goal. You can add the public set to your sets to study it. Your account shows the available actions.

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please reload the page.