CMIT 320 FINAL EXAM 2024/2025 ACTUAL EXAM TESTBANK
CMIT 320 Final Exam
COMPLETE QUESTIONS WITH VERIFIED ANSWERS
Study online at https://quizlet.com/_gyp5n2
1. what connection type is very similar to bluetooth but ANT (Adaptive Network
used by more specialized devices, such as sensors and Technology)
fitness trackers
2. What would you recommend to a team member who Output from the latest
is interested in additional sources of information to configuration review, vul-
assist with refining their own understanding of the nerability scanning, and
current attack surface of the organization? penetration tests
3. A user complains that after entering a URL into a typosquatting
browser, what appeared to be the correct page is dis-
played in the browser. However, after clicking a few
links on the page, it became obvious that the site the
user arrived at was not the correct site, but instead a
malicious copy of the site the user intended to visit.
Which of the following attacks did the user most likely
fall prey to?
4. An enterprise cloud administrator needs to create a Place the instances in sep-
trust boundary between two compute instances in the arate subnets and use a
same default security group and on the same IPv4 network firewall between
subnet within an AWS virtual private cloud (VPC). What the subnets.
would be an effective solution to the administrator's
needs?
5. You've taken up a contract helping to upgrade the DCS
existing industrial control network for an oil refinery.
What network type should you expect to work with?
6. Which of the following is a risk to cloud services that Your data may be threat-
is not a risk to on-premises services? ened by attacks launched
on the data of others.
, CMIT 320 Final Exam
Study online at https://quizlet.com/_gyp5n2
7. Which of the following factors has no effect on chain Documentation of the
of custody, with regard to digital evidence that is pre- presiding judge and op-
sented to the court? posing counsel
8. On a subnet with limited physical security, you're wor- 802.1AE/MACsec
ried about ARP poisoning and DHCP spoofing attacks.
What switch feature could help prevent both?
9. Your company is developing a custom web app for OAuth
the sales team. It should be able to access a list of
Salesforce contacts, but for security reasons, the app
shouldn't be able to access the actual Salesforce ac-
count. What standard would allow this?
10. Uses an authenticator to block communications be- 802.1X
tween unauthorized users or workstations and the
local network
Requires the use of EAP and an authentication server
11. Centrally secures access to server resources deployed Kerberos
within or across a non-secure network
12. Restricts access to a LAN via a WAN link Point to Point Proto-
col (PPP) with Challenge
Handshake Authentication
Protocol (CHAP)
13. a framework for enterprise risk management 31000
14. focuses on personal data and privacy 27701
15. defines the various security controls in greater detail 27002
16. details the steps to implement a compliant ISMS 27001
, CMIT 320 Final Exam
Study online at https://quizlet.com/_gyp5n2
17. what area of compliance requirements is part of all of log retention
the following regulations
HIPAA
PCI DSS
SOX
GLBA
FISMA
18. describes attacks as the pivoting interactions among The Diamond Model of In-
adversaries, victims, capabilities, and infrastructure trusion Analysis
19. a knowledge base of adversary techniques presented mitre att&ck
as a matrix for enterprise
20. a linear seven step attack model that defenders use to cyber kill chain
interrupt the steps and stop the attack
21. After a security incident, you rush to take a screenshot Order of Volatility
of a telltale running process before you leisurely take
a backup of suspicious files on the hard drive. What
forensic principle are you exercising?
22. Which of the following are forms of cybersecurity re- A diesel generator
silience that help to ensure fault tolerance or recover- NIC teaming
ability of services in the case of an outage? Geographically dispersed
data centers
23. Which organization offers freely accessible top-ten OWASP
lists and cheat sheets in the field of secure develop-
ment of web applications?
24. What is the difference between a bluejacking and a Bluesnarfing involves data
bluesnarfing attack? compromise.
, CMIT 320 Final Exam
Study online at https://quizlet.com/_gyp5n2
25. In the area of threat hunting, what is meant by intelli- Gathering intelligence
gence fusion? from multiple sources to
feed advanced analytics
26. Upon browsing the website shop.javatucana.com, The web server's certifi-
which your company uses regularly in the normal cate is on the CRL.
course of business, you are greeted by a privacy er- There are no wildcards in
ror that states, "Your connection is not private." After the web server's certifi-
confirming that your own computer's date and time cate.
are correct, you positively verify the following details:
The valid-date range of the web server's certificate is
current.
The certificate's chain of trust is valid, which includes
the fact that your computer trusts the root CA's certifi-
cate
The certificate's Subject Alternative Name field con-
tains javatucana.com.
You accurately entered shop.javatucana.com in the
web browser.
Given your inability to explain the privacy error based
on your investigation of these factors, what could be
the cause for the error?
27. What technology uses the TPM to store hashes of measured boot
signed boot files for comparison the next time the
system boots and for export in a quote for remote
attestation?
28. After having trouble navigating to a webpage on the install the certificate of the
Internet, resulting in a privacy error, you inspect the intermediate CA
site's certificate and notice the chain of certificates
contains three nodes, one being the leaf certificate of
CMIT 320 Final Exam
COMPLETE QUESTIONS WITH VERIFIED ANSWERS
Study online at https://quizlet.com/_gyp5n2
1. what connection type is very similar to bluetooth but ANT (Adaptive Network
used by more specialized devices, such as sensors and Technology)
fitness trackers
2. What would you recommend to a team member who Output from the latest
is interested in additional sources of information to configuration review, vul-
assist with refining their own understanding of the nerability scanning, and
current attack surface of the organization? penetration tests
3. A user complains that after entering a URL into a typosquatting
browser, what appeared to be the correct page is dis-
played in the browser. However, after clicking a few
links on the page, it became obvious that the site the
user arrived at was not the correct site, but instead a
malicious copy of the site the user intended to visit.
Which of the following attacks did the user most likely
fall prey to?
4. An enterprise cloud administrator needs to create a Place the instances in sep-
trust boundary between two compute instances in the arate subnets and use a
same default security group and on the same IPv4 network firewall between
subnet within an AWS virtual private cloud (VPC). What the subnets.
would be an effective solution to the administrator's
needs?
5. You've taken up a contract helping to upgrade the DCS
existing industrial control network for an oil refinery.
What network type should you expect to work with?
6. Which of the following is a risk to cloud services that Your data may be threat-
is not a risk to on-premises services? ened by attacks launched
on the data of others.
, CMIT 320 Final Exam
Study online at https://quizlet.com/_gyp5n2
7. Which of the following factors has no effect on chain Documentation of the
of custody, with regard to digital evidence that is pre- presiding judge and op-
sented to the court? posing counsel
8. On a subnet with limited physical security, you're wor- 802.1AE/MACsec
ried about ARP poisoning and DHCP spoofing attacks.
What switch feature could help prevent both?
9. Your company is developing a custom web app for OAuth
the sales team. It should be able to access a list of
Salesforce contacts, but for security reasons, the app
shouldn't be able to access the actual Salesforce ac-
count. What standard would allow this?
10. Uses an authenticator to block communications be- 802.1X
tween unauthorized users or workstations and the
local network
Requires the use of EAP and an authentication server
11. Centrally secures access to server resources deployed Kerberos
within or across a non-secure network
12. Restricts access to a LAN via a WAN link Point to Point Proto-
col (PPP) with Challenge
Handshake Authentication
Protocol (CHAP)
13. a framework for enterprise risk management 31000
14. focuses on personal data and privacy 27701
15. defines the various security controls in greater detail 27002
16. details the steps to implement a compliant ISMS 27001
, CMIT 320 Final Exam
Study online at https://quizlet.com/_gyp5n2
17. what area of compliance requirements is part of all of log retention
the following regulations
HIPAA
PCI DSS
SOX
GLBA
FISMA
18. describes attacks as the pivoting interactions among The Diamond Model of In-
adversaries, victims, capabilities, and infrastructure trusion Analysis
19. a knowledge base of adversary techniques presented mitre att&ck
as a matrix for enterprise
20. a linear seven step attack model that defenders use to cyber kill chain
interrupt the steps and stop the attack
21. After a security incident, you rush to take a screenshot Order of Volatility
of a telltale running process before you leisurely take
a backup of suspicious files on the hard drive. What
forensic principle are you exercising?
22. Which of the following are forms of cybersecurity re- A diesel generator
silience that help to ensure fault tolerance or recover- NIC teaming
ability of services in the case of an outage? Geographically dispersed
data centers
23. Which organization offers freely accessible top-ten OWASP
lists and cheat sheets in the field of secure develop-
ment of web applications?
24. What is the difference between a bluejacking and a Bluesnarfing involves data
bluesnarfing attack? compromise.
, CMIT 320 Final Exam
Study online at https://quizlet.com/_gyp5n2
25. In the area of threat hunting, what is meant by intelli- Gathering intelligence
gence fusion? from multiple sources to
feed advanced analytics
26. Upon browsing the website shop.javatucana.com, The web server's certifi-
which your company uses regularly in the normal cate is on the CRL.
course of business, you are greeted by a privacy er- There are no wildcards in
ror that states, "Your connection is not private." After the web server's certifi-
confirming that your own computer's date and time cate.
are correct, you positively verify the following details:
The valid-date range of the web server's certificate is
current.
The certificate's chain of trust is valid, which includes
the fact that your computer trusts the root CA's certifi-
cate
The certificate's Subject Alternative Name field con-
tains javatucana.com.
You accurately entered shop.javatucana.com in the
web browser.
Given your inability to explain the privacy error based
on your investigation of these factors, what could be
the cause for the error?
27. What technology uses the TPM to store hashes of measured boot
signed boot files for comparison the next time the
system boots and for export in a quote for remote
attestation?
28. After having trouble navigating to a webpage on the install the certificate of the
Internet, resulting in a privacy error, you inspect the intermediate CA
site's certificate and notice the chain of certificates
contains three nodes, one being the leaf certificate of