NDE CERTIFICATION QUESTIONS (CYBERQ) PART 2
UPDATED ACTUAL QUESTIONS AND CORRECT
ANSWERS
Question:
1. James, a network defender, was appointed to secure the organization's private network from
unauthorized entries. To achieve this, James configured an intermediary computer system that receives
requests on public interface from external network and provides controlled access to resources in the
private network. This mediatory system serves as scapegoat when attacks are initiated on the intranet.
Which of the following security controls James has configured to secure the internal network?
Answer:
Bastion Host
Question:
2. Finch, a network administrator in the process of securing the internal network, segregated the LAN
creating an independent subnetwork. The newly created subnetwork has been placed between the
organization's internal network and the outside public network to enable high-level protection for the LAN.
Identify the independent network created by Finch in the above scenario to protect the LAN.
Answer:
Demilitarized Zone
Question:
3. Which of the following types of bastion host is a firewall device with only one network interface and all
the traffic is routed through the bastion host?
Answer:
Single-homed bastion host
Question:
4. Which of the following types of bastion host operates with multiple network connections but the
network connections do not interact with each other?
Answer:
Non-routing dual-homed host
Question:
5. Which of the following types of bastion host is useful in testing new applications whose security flaws
are not yet known and for running services that are not secure?
Answer:
Victim Machines
Question:
6. Which of the following layers of the OSI model cannot be protected by any firewall technology?
Answer:
Physical layer
,Question:
7. Which of the following information allows the firewall to check whether the packet has a SYN, ACK, or
other bits set for connecting with the destination host?
Answer:
TCP code bits
Question:
8. Which of the following header attributes allows the firewall to check whether the packet is coming from
an unreliable site?
Answer:
Interface
Question:
9. Bob, a network defender, at an organization was observing the network behavior by deploying a firewall
on the organization's network. He examined whether the firewall rules are set according to the actions
performed by the firewall or whether it has any bugs. In which of the following steps of firewall
implementation was Bob in the above scenario?
Answer:
Testing
Question:
10. Given below are the different steps involved in firewall implementation and deployment.
1.) Planning
2.) Testing
3.) Managing and maintaining
4.) Configuring
5.) Deploying What is the correct sequence of steps involved in firewall implementation and deployment?
Answer:
1 -> 4 -> 2 -> 5 -> 3
Question:
11. Which of the following types of IDS detection method involves first creating models of possible
intrusions and then comparing these models with incoming events to make a detection decision?
Answer:
Signature recognition
Question:
12. James, a security team member, was assessing the security across organizational assets. He identified
sudden fluctuations in the bandwidth consumption and repeated login attempts being made from remote
hosts. Which of the following types of intrusion attempt James has identified in the above scenario?
Answer:
Networks intrusion
, Question:
13. John, a network specialist at an organization, was monitoring the IDS screen. He identified a
suspicious activity performed by an attacker and subsequently performed pre-configured or automated
counter-action such as restarting the network traffic, and blocked the hacker's further activity on the
organizations network. In which of the following intrusion detection step does an IDS take pre-configured
counter-action against the hacker?
Answer:
IDS responds
Question:
14. David, a network specialist at an organization, was monitoring incidents on an IDS solution. The IDS
solution detected suspicious activity performed by a threat actor over the organization's network and had
sent an email alert to David operating at the control room. David immediately took the pre-configured
counter-action and blocked the attacker from further attempts on the organization's network. Identify the
tool that helped David detect intrusion attempts in the above scenario.
Answer:
Suricata
Question:
15. Which of the following types of honeypot simulates only a limited number of services and applications
of a target system or network and if the attacker does something that the emulation does not expect, the
honeypot will simply generate an error?
Answer:
Low-interaction honeypot
Question:
16. Which of the following types of honeypot emulates the real production network of a target organization
and causes attackers to devote their time and resources toward attacking the critical production system of
the company?
Answer:
Pure honeypot
Question:
17. Sofy, a cyber security analyst, plans to develop a more secure network infrastructure by implementing
a honeypot. She deploys a honeypot that simulates a real OS as well as applications and services of their
network. Further, the deployed honeypot can also log and analyze more complex attacks and helps in
capturing more useful data. Identify the type of honeypot implemented by Sofy in the above scenario.
Answer:
Medium-interaction honeypot
Question:
18. Identify the type of honeypots that are specifically designed to trap web crawlers.
Answer:
Spider Honeypots
UPDATED ACTUAL QUESTIONS AND CORRECT
ANSWERS
Question:
1. James, a network defender, was appointed to secure the organization's private network from
unauthorized entries. To achieve this, James configured an intermediary computer system that receives
requests on public interface from external network and provides controlled access to resources in the
private network. This mediatory system serves as scapegoat when attacks are initiated on the intranet.
Which of the following security controls James has configured to secure the internal network?
Answer:
Bastion Host
Question:
2. Finch, a network administrator in the process of securing the internal network, segregated the LAN
creating an independent subnetwork. The newly created subnetwork has been placed between the
organization's internal network and the outside public network to enable high-level protection for the LAN.
Identify the independent network created by Finch in the above scenario to protect the LAN.
Answer:
Demilitarized Zone
Question:
3. Which of the following types of bastion host is a firewall device with only one network interface and all
the traffic is routed through the bastion host?
Answer:
Single-homed bastion host
Question:
4. Which of the following types of bastion host operates with multiple network connections but the
network connections do not interact with each other?
Answer:
Non-routing dual-homed host
Question:
5. Which of the following types of bastion host is useful in testing new applications whose security flaws
are not yet known and for running services that are not secure?
Answer:
Victim Machines
Question:
6. Which of the following layers of the OSI model cannot be protected by any firewall technology?
Answer:
Physical layer
,Question:
7. Which of the following information allows the firewall to check whether the packet has a SYN, ACK, or
other bits set for connecting with the destination host?
Answer:
TCP code bits
Question:
8. Which of the following header attributes allows the firewall to check whether the packet is coming from
an unreliable site?
Answer:
Interface
Question:
9. Bob, a network defender, at an organization was observing the network behavior by deploying a firewall
on the organization's network. He examined whether the firewall rules are set according to the actions
performed by the firewall or whether it has any bugs. In which of the following steps of firewall
implementation was Bob in the above scenario?
Answer:
Testing
Question:
10. Given below are the different steps involved in firewall implementation and deployment.
1.) Planning
2.) Testing
3.) Managing and maintaining
4.) Configuring
5.) Deploying What is the correct sequence of steps involved in firewall implementation and deployment?
Answer:
1 -> 4 -> 2 -> 5 -> 3
Question:
11. Which of the following types of IDS detection method involves first creating models of possible
intrusions and then comparing these models with incoming events to make a detection decision?
Answer:
Signature recognition
Question:
12. James, a security team member, was assessing the security across organizational assets. He identified
sudden fluctuations in the bandwidth consumption and repeated login attempts being made from remote
hosts. Which of the following types of intrusion attempt James has identified in the above scenario?
Answer:
Networks intrusion
, Question:
13. John, a network specialist at an organization, was monitoring the IDS screen. He identified a
suspicious activity performed by an attacker and subsequently performed pre-configured or automated
counter-action such as restarting the network traffic, and blocked the hacker's further activity on the
organizations network. In which of the following intrusion detection step does an IDS take pre-configured
counter-action against the hacker?
Answer:
IDS responds
Question:
14. David, a network specialist at an organization, was monitoring incidents on an IDS solution. The IDS
solution detected suspicious activity performed by a threat actor over the organization's network and had
sent an email alert to David operating at the control room. David immediately took the pre-configured
counter-action and blocked the attacker from further attempts on the organization's network. Identify the
tool that helped David detect intrusion attempts in the above scenario.
Answer:
Suricata
Question:
15. Which of the following types of honeypot simulates only a limited number of services and applications
of a target system or network and if the attacker does something that the emulation does not expect, the
honeypot will simply generate an error?
Answer:
Low-interaction honeypot
Question:
16. Which of the following types of honeypot emulates the real production network of a target organization
and causes attackers to devote their time and resources toward attacking the critical production system of
the company?
Answer:
Pure honeypot
Question:
17. Sofy, a cyber security analyst, plans to develop a more secure network infrastructure by implementing
a honeypot. She deploys a honeypot that simulates a real OS as well as applications and services of their
network. Further, the deployed honeypot can also log and analyze more complex attacks and helps in
capturing more useful data. Identify the type of honeypot implemented by Sofy in the above scenario.
Answer:
Medium-interaction honeypot
Question:
18. Identify the type of honeypots that are specifically designed to trap web crawlers.
Answer:
Spider Honeypots