CYSA UPDATED EXAMS TEST PAPER QUESTIONS
AND ANSWERS SURE A+
✔✔Authentication that uses the IP address, geographic location, and time of day to help
validate the user is known as what type of authentication? - ✔✔context based
✔✔_________________ allows authentication decisions to be made based on
information about the user, the system they are using, or other data like their
geographic location, behavior, or even time of day. - ✔✔context-based authentication
✔✔_________________ uses a security token to generate a onetime password or
value. - ✔✔token-based authentication
✔✔Which of the following is not a common attack against Kerberos? - ✔✔open redirect-
based attacks
✔✔Common attacks against _________________ include attacks aimed at
administrative accounts, particularly those that attempt to create a ticket granting ticket
and ticket reuse attacks. - ✔✔Kerberos
✔✔Which of the following technologies is not a shared authentication technology? -
✔✔LDAP
✔✔_________________ is sometimes used for single sign-on but is not a shared
authentication technology. - ✔✔LDAP
✔✔OpenID Connect, Oath, and Facebook Connect are all examples of
_________________. - ✔✔shared authentication technologies
, ✔✔Angela is concerned about attackers enumerating her organization's LDAP
directory. What LDAP control should she recommend to help limit the impact of this type
of data gathering? - ✔✔ACLs
✔✔_________________ may help with load issues or denial-of-service attacks. -
✔✔LDAP replication
✔✔TACASs+? - ✔✔route management traffic over a dedicated network
✔✔_________________ should be run on an isolated management network to protect
it from attackers. - ✔✔TACACS+
✔✔Jason has user rights on his Linux workstation, but he wants to read his
department's financial reports, which he knows are stored in a directory that only
administrators can access. He executes a local exploit, which gives him the ability to act
as root. What type of attack is this? - ✔✔privilege escalation
✔✔Chris is responsible for monitoring his organization's file shares and security and
has discovered that employees are consistently retaining access to files after they
change positions. Where in the organization's account life cycle should he focus his
efforts? - ✔✔Step 3 Modify and Maintain Account
✔✔_________________ is the first step in an account life cycle. - ✔✔Create account
and set password
✔✔_________________ is the second step in an account life cycle. - ✔✔Provision to
services and set initial rights and roles
✔✔_________________ is the third step in an account life cycle. - ✔✔Modify and
maintain account
✔✔_________________ is the fourth step in an account life cycle. - ✔✔Disable account
✔✔_________________ is the fifth and final step in an account life cycle. - ✔✔Retire
and deprovision account
✔✔Which of the following methods is not an effective method for preventing brute-force
password guessing attacks via login portals? - ✔✔returning an HTTP error
✔✔CAPTCHAs, login throttling, and locking out accounts after a set number of failed
logins are all useful techniques to stop or delay _________________ password
guessing attacks. - ✔✔brute-force
AND ANSWERS SURE A+
✔✔Authentication that uses the IP address, geographic location, and time of day to help
validate the user is known as what type of authentication? - ✔✔context based
✔✔_________________ allows authentication decisions to be made based on
information about the user, the system they are using, or other data like their
geographic location, behavior, or even time of day. - ✔✔context-based authentication
✔✔_________________ uses a security token to generate a onetime password or
value. - ✔✔token-based authentication
✔✔Which of the following is not a common attack against Kerberos? - ✔✔open redirect-
based attacks
✔✔Common attacks against _________________ include attacks aimed at
administrative accounts, particularly those that attempt to create a ticket granting ticket
and ticket reuse attacks. - ✔✔Kerberos
✔✔Which of the following technologies is not a shared authentication technology? -
✔✔LDAP
✔✔_________________ is sometimes used for single sign-on but is not a shared
authentication technology. - ✔✔LDAP
✔✔OpenID Connect, Oath, and Facebook Connect are all examples of
_________________. - ✔✔shared authentication technologies
, ✔✔Angela is concerned about attackers enumerating her organization's LDAP
directory. What LDAP control should she recommend to help limit the impact of this type
of data gathering? - ✔✔ACLs
✔✔_________________ may help with load issues or denial-of-service attacks. -
✔✔LDAP replication
✔✔TACASs+? - ✔✔route management traffic over a dedicated network
✔✔_________________ should be run on an isolated management network to protect
it from attackers. - ✔✔TACACS+
✔✔Jason has user rights on his Linux workstation, but he wants to read his
department's financial reports, which he knows are stored in a directory that only
administrators can access. He executes a local exploit, which gives him the ability to act
as root. What type of attack is this? - ✔✔privilege escalation
✔✔Chris is responsible for monitoring his organization's file shares and security and
has discovered that employees are consistently retaining access to files after they
change positions. Where in the organization's account life cycle should he focus his
efforts? - ✔✔Step 3 Modify and Maintain Account
✔✔_________________ is the first step in an account life cycle. - ✔✔Create account
and set password
✔✔_________________ is the second step in an account life cycle. - ✔✔Provision to
services and set initial rights and roles
✔✔_________________ is the third step in an account life cycle. - ✔✔Modify and
maintain account
✔✔_________________ is the fourth step in an account life cycle. - ✔✔Disable account
✔✔_________________ is the fifth and final step in an account life cycle. - ✔✔Retire
and deprovision account
✔✔Which of the following methods is not an effective method for preventing brute-force
password guessing attacks via login portals? - ✔✔returning an HTTP error
✔✔CAPTCHAs, login throttling, and locking out accounts after a set number of failed
logins are all useful techniques to stop or delay _________________ password
guessing attacks. - ✔✔brute-force