ASSESSMENT 2026/2027 WITH
QUESTIONS AND 100% CORRECT
ANSWERS | ALREADY GRADED A+ |
GUARANTEED PASS | SECURITY
FUNDAMENTALS PRACTICE EXAM
What statement correctly defines what a rainbow table is in relation to password
attacks?
A rainbow table is a collection of rules designed to match potential password
patterns that may be in use by a particular organization.
A rainbow table contains password masks that are used to guess passwords using a
predetermined sequence.
A rainbow table contains a table of potential hash collisions that can be used to try
and brute force a password.
,A rainbow table is a compressed representation of cleartext passwords that are
related and organized in a sequence. - ANSWER-A rainbow table is a compressed
representation of cleartext passwords that are related and organized in a sequence.
In the management of virtual machines, what are the risks associated with virtual
machine sprawl?
A guest operating system will cease to function without management.
A guest operating system may malfunction and damage the host computer.
A guest operating system may be vulnerable because it has not been maintained.
A guest operating system will consume the resources of the host, even when
offline. - ANSWER-A guest operating system may be vulnerable because it has not
been maintained.
What is the most secure form of IEEE 802.1x authentication?
certificate based
pre-shared key
MAC authentication
token based - ANSWER-certificate based
Once a tester has penetrated a network and gained access, what is the tester's next
step?
,Attempt to pivot or move around inside the network to other resources.
End the test and present the findings to the contracted company.
Close the vulnerability for the target company.
Disconnect from the network and attempt to regain entry using a different method.
- ANSWER-Attempt to pivot or move around inside the network to other
resources.
What DNS vulnerability can be specifically addressed by utilizing Domain Name
System Security Extensions (DNSSEC)?
DNS poisoning
DNS looping
DNS hijacking
DNS spoofing - ANSWER-DNS poisoning
What feature of a mobile device management system could be used to restrict the
use of an application containing confidential data to only a specific geographical
area?
digital locking
location tracking
geofencing
, Wi-Fi fencing - ANSWER-geofencing
How does the use of the perfect forward secrecy key exchange method differ from
other key exchange methods?
Perfect forward secrecy uses temporal keys that are used for a period of time and
then discarded.
Perfect forward secrecy involves the use of public key systems that generate
random public keys that differ for each session.
Perfect forward secrecy utilizes large prime numbers and a related integer agreed
upon by two parties, and the key never changes.
Perfect forward secrecy utilizes elliptic curve cryptography instead of prime
numbers in computation. - ANSWER-Perfect forward secrecy involves the use of
public key systems that generate random public keys that differ for each session.
What does a component's mean time between failures (MTBF) value determine?
It refers to the average amount of times a component will fail before it is no longer
usable.
It determines the exact time at which a component will fall out of warranty
coverage.