CMIT 320 FINAL EXAM QUESTIONS AND VERIFIED
CORRECT ANSWERS
100% PASS
Which of the following situations would most likely motivate a
hacktivist? - ANSWER A large food-processing enterprise is dumping
byproducts into a nearby stream.
What SNMP component is a database of predefined manageable items
for a particular device? - ANSWER MIB (management information
base)
what is eDiscovery - ANSWER process for sharing electronic forensic
data
Which of the following is the reason why attacks over the telephone,
claiming that well-known groups of individuals have taken advantage of
the assistance being offered, are as effective as they are? - ANSWER
consensus
Your employer stores a copy of all private keys used on devices in the
enterprise because the regulatory agency that audits and certifies your
company's business practices demands centralized access to them in
case the court's order decryption of any official communications at the
agency's request. What is this an example of? - ANSWER key escrow
storage of private keys by a third-party, whether for the user's benefit
in case a data encryption key is lost, or for the benefit of an
organization such as an employer or government agency
what type of control is a security assessment procedure - ANSWER
operational
,Your organization has decided to outsource several IT services to a
cloud provider. They're hosted outside your enterprise network, but
you want to centrally manage all authentication, encryption, activity
logging, and other security policies for connections between local
computers and the cloud and would like to keep this management and
control internal to your organization. What security solution would
address these issues? - ANSWER security broker
Which of the following is an algorithm employed in asymmetric
cryptography that uses newer complex mathematical approaches to
create relatively short but very secure and high-performance keys? -
ANSWER ECC (elliptic curve cryptography)
Which of the following statements about vulnerability scans is
accurate? - ANSWER Vulnerability scans should consist of credentialed
scans as well as non-credentialed scans.
In a building floor plan, you notice lines that follow a few of the
hallways, terminating in various locations, including the data center and
conference rooms. The legend at the bottom of the diagram for these
lines is labeled "Protected Distribution System (PDS)." What is a PDS
used for? - ANSWER unencrypted data
Which of the following is an example of an attribute that strengthens
the authentication process but does not act as a primary authentication
factor? - ANSWER A point-of-contact signing someone else into a
secure facility
You're receiving many unauthorized network scans using methods
carefully designed to bypass existing firewall rules. What device or
feature would be the best way to recognize and block those scans? -
ANSWER IPS (intrusion prevention system)
, A network technician has been asked to troubleshoot recently observed
performance issues as well as the root cause of new alerts regarding
network traffic anomalies. Which monitoring tool should the technician
choose first to troubleshoot both problems? - ANSWER bandwidth
monitor
Your WAP is currently secured with WPA-Personal encryption and
authentication, using a shared key. Wi-Fi Protected Setup (WPS) is
currently disabled. Which of the following is true? - ANSWER Enabling
802.1X could increase security, but enabling WPS would reduce it.
Your organization has a degausser in the basement. What media can it
securely destroy? - ANSWER hard drives
backup tapes
(removes magnetism of the object)
Which statements about service accounts are most accurate? -
ANSWER A web server will have a service account that owns and
accesses resources as if it were a user but independent of which user
installed or ran the service.
It is an account associated with an application or service that needs to
interact with the system.
Which of the following is a packet crafting utility useful to attackers and
penetration testers? - ANSWER hping
a binary file format found mainly in Java environments - ANSWER DER
a very popular Base-64 ASCII-encoded file format - ANSWER PEM
the predecessor to PKCS #12 & compatible when used in naming P12 -
ANSWER PFX
CORRECT ANSWERS
100% PASS
Which of the following situations would most likely motivate a
hacktivist? - ANSWER A large food-processing enterprise is dumping
byproducts into a nearby stream.
What SNMP component is a database of predefined manageable items
for a particular device? - ANSWER MIB (management information
base)
what is eDiscovery - ANSWER process for sharing electronic forensic
data
Which of the following is the reason why attacks over the telephone,
claiming that well-known groups of individuals have taken advantage of
the assistance being offered, are as effective as they are? - ANSWER
consensus
Your employer stores a copy of all private keys used on devices in the
enterprise because the regulatory agency that audits and certifies your
company's business practices demands centralized access to them in
case the court's order decryption of any official communications at the
agency's request. What is this an example of? - ANSWER key escrow
storage of private keys by a third-party, whether for the user's benefit
in case a data encryption key is lost, or for the benefit of an
organization such as an employer or government agency
what type of control is a security assessment procedure - ANSWER
operational
,Your organization has decided to outsource several IT services to a
cloud provider. They're hosted outside your enterprise network, but
you want to centrally manage all authentication, encryption, activity
logging, and other security policies for connections between local
computers and the cloud and would like to keep this management and
control internal to your organization. What security solution would
address these issues? - ANSWER security broker
Which of the following is an algorithm employed in asymmetric
cryptography that uses newer complex mathematical approaches to
create relatively short but very secure and high-performance keys? -
ANSWER ECC (elliptic curve cryptography)
Which of the following statements about vulnerability scans is
accurate? - ANSWER Vulnerability scans should consist of credentialed
scans as well as non-credentialed scans.
In a building floor plan, you notice lines that follow a few of the
hallways, terminating in various locations, including the data center and
conference rooms. The legend at the bottom of the diagram for these
lines is labeled "Protected Distribution System (PDS)." What is a PDS
used for? - ANSWER unencrypted data
Which of the following is an example of an attribute that strengthens
the authentication process but does not act as a primary authentication
factor? - ANSWER A point-of-contact signing someone else into a
secure facility
You're receiving many unauthorized network scans using methods
carefully designed to bypass existing firewall rules. What device or
feature would be the best way to recognize and block those scans? -
ANSWER IPS (intrusion prevention system)
, A network technician has been asked to troubleshoot recently observed
performance issues as well as the root cause of new alerts regarding
network traffic anomalies. Which monitoring tool should the technician
choose first to troubleshoot both problems? - ANSWER bandwidth
monitor
Your WAP is currently secured with WPA-Personal encryption and
authentication, using a shared key. Wi-Fi Protected Setup (WPS) is
currently disabled. Which of the following is true? - ANSWER Enabling
802.1X could increase security, but enabling WPS would reduce it.
Your organization has a degausser in the basement. What media can it
securely destroy? - ANSWER hard drives
backup tapes
(removes magnetism of the object)
Which statements about service accounts are most accurate? -
ANSWER A web server will have a service account that owns and
accesses resources as if it were a user but independent of which user
installed or ran the service.
It is an account associated with an application or service that needs to
interact with the system.
Which of the following is a packet crafting utility useful to attackers and
penetration testers? - ANSWER hping
a binary file format found mainly in Java environments - ANSWER DER
a very popular Base-64 ASCII-encoded file format - ANSWER PEM
the predecessor to PKCS #12 & compatible when used in naming P12 -
ANSWER PFX