Question 1
What command on Windows will display a listing of all open netork connections on a computer and, with
additional parameters, will aslo provide the corresponding process number that is instantiating the
connection?
tracert
ifconfig
netstat
chmod
During a log review, you discover a series of logs that shows the following multiple failed login
attempts
Jan 31 11:39:20 ip-10.0.0.2 sshd[10102]: Invalid user admin from remotehost passwd=bears
Jan 31 11:39:20 ip-10.0.0.2 sshd[10108]: Invalid user admin from remotehost passwd=eat
Jan 31 11:39:20 ip-10.0.0.2 sshd[10114]: Invalid user admin from remotehost passwd=beats
Jan 31 11:39:20 ip-10.0.0.2 sshd[10118]: Invalid user admin from remotehost passwd=battlestar
Jan 31 11:39:20 ip-10.0.0.2 sshd[10120]: Invalid user admin from remotehost passwd=galactica
What type(s) of attack have you discovered?
A A brute force attack
.
B A rainbow table attack
.
C A man-in-the-middle attack
.
D A dictionary attack
.
The Windows Firewall by default logs all in-bound and out-bound traffic requests.
True
False
Under non-discretionary access control, a third-party security administrator determines what users have
access to certain network and system resources.
True
False
,Kerberos is the primary system used for authorization and authentication in Windows Domains. The key
distribution center and the ticket-granding server are often single points of failure making the system
susceptible to outages. What types of attacks does the system protect against?
social engineering
eavesdropping and replay
ping of death
man-in-the-middle and brute force
An Active Directory is a hierarchical directory information system that can be used as a directory service
for internet-based systems or services requiring directory services.
True
False
When establishing firewall rules, the most prudent configuration is to implicitly deny by
blocking all traffic by default then rely on business need and justification to create new rules as
exceptions
True
False
Attackers use zero day exploits more frequently than publicly known n-day exploits and, as a
result, are more successful in their operations.
True
False
Asymmetric encryption is more secure than symmetric encryption
True
False
Enterprises and individual users who applied vendor issued security protection patches would have been
immune to the NotPetya attack that originated from the Ukrainian company M.E.Doc.
True
False
Defense-in-depth is a strategy that:
A Provides a roadmap for securing physical access points to a building as well as controlling the
.
, access to those points.
B Protects assets in an information system environment by employing firewalls and information
. security policies.
C Considers the assets of all things in an environment, and refers to the layering of security
.
tools and methods often varying numerous parameters between layers, in an effort to
restrict or prevent malicious users from penetrating anything more than the outer layers
D Guarantees protection of all layers in an information security architecture and
.
infrastructure by employing multiple methods of protection between layers and across
domains
Secure Shell (SSH) is used as a more secure replacement for legacy remote connection protocol
Telnet and is used through programs such as Putty to remotely administer computers running
various operating systems
True
False
In a virtualized environment, this is responsible for managing resources and requests from the guest
operation systems.
virtual machine
core operating system
kernel
hypervisor
A single sign-on system that uses symmetric key encryption and provide for mutual authentication for
clients and servers.
SESAME
kerberos
identity as a service
federated identify
If the password file can be obtained, the hashes can be cracked to obtain passwords.
True
False
What command on Windows will display a listing of all open netork connections on a computer and, with
additional parameters, will aslo provide the corresponding process number that is instantiating the
connection?
tracert
ifconfig
netstat
chmod
During a log review, you discover a series of logs that shows the following multiple failed login
attempts
Jan 31 11:39:20 ip-10.0.0.2 sshd[10102]: Invalid user admin from remotehost passwd=bears
Jan 31 11:39:20 ip-10.0.0.2 sshd[10108]: Invalid user admin from remotehost passwd=eat
Jan 31 11:39:20 ip-10.0.0.2 sshd[10114]: Invalid user admin from remotehost passwd=beats
Jan 31 11:39:20 ip-10.0.0.2 sshd[10118]: Invalid user admin from remotehost passwd=battlestar
Jan 31 11:39:20 ip-10.0.0.2 sshd[10120]: Invalid user admin from remotehost passwd=galactica
What type(s) of attack have you discovered?
A A brute force attack
.
B A rainbow table attack
.
C A man-in-the-middle attack
.
D A dictionary attack
.
The Windows Firewall by default logs all in-bound and out-bound traffic requests.
True
False
Under non-discretionary access control, a third-party security administrator determines what users have
access to certain network and system resources.
True
False
,Kerberos is the primary system used for authorization and authentication in Windows Domains. The key
distribution center and the ticket-granding server are often single points of failure making the system
susceptible to outages. What types of attacks does the system protect against?
social engineering
eavesdropping and replay
ping of death
man-in-the-middle and brute force
An Active Directory is a hierarchical directory information system that can be used as a directory service
for internet-based systems or services requiring directory services.
True
False
When establishing firewall rules, the most prudent configuration is to implicitly deny by
blocking all traffic by default then rely on business need and justification to create new rules as
exceptions
True
False
Attackers use zero day exploits more frequently than publicly known n-day exploits and, as a
result, are more successful in their operations.
True
False
Asymmetric encryption is more secure than symmetric encryption
True
False
Enterprises and individual users who applied vendor issued security protection patches would have been
immune to the NotPetya attack that originated from the Ukrainian company M.E.Doc.
True
False
Defense-in-depth is a strategy that:
A Provides a roadmap for securing physical access points to a building as well as controlling the
.
, access to those points.
B Protects assets in an information system environment by employing firewalls and information
. security policies.
C Considers the assets of all things in an environment, and refers to the layering of security
.
tools and methods often varying numerous parameters between layers, in an effort to
restrict or prevent malicious users from penetrating anything more than the outer layers
D Guarantees protection of all layers in an information security architecture and
.
infrastructure by employing multiple methods of protection between layers and across
domains
Secure Shell (SSH) is used as a more secure replacement for legacy remote connection protocol
Telnet and is used through programs such as Putty to remotely administer computers running
various operating systems
True
False
In a virtualized environment, this is responsible for managing resources and requests from the guest
operation systems.
virtual machine
core operating system
kernel
hypervisor
A single sign-on system that uses symmetric key encryption and provide for mutual authentication for
clients and servers.
SESAME
kerberos
identity as a service
federated identify
If the password file can be obtained, the hashes can be cracked to obtain passwords.
True
False