Page | 1
itn 260 Questions with Detailed Verified
Answers
Question: The X.509 standard applies to which of the following?
A) Public key infrastructure
B) SSL providers
C) Certificate Revocation Lists
D) Digital certificates
Ans: D) Digital certificates
Question: What are two ways that a certificate can stop being used?
A) Expiration and revocation
B) Expiration and certificate signing request
C) PKI replacement and revocation
D) Certificate signing reset and revocation
Ans: A) Expiration and revocation
Question: What are two protocols that can provide AuthN & AuthZ for a user
to a network?
A) SSO & XTACACS
B) TACACS+ & RADIUS
C) RADIUS & SAML
D) SAML & TACACS+
, Page | 2
Ans: B) TACACS+ & RADIUS
Question: A pen tester working on a web application makes sure that no
regular user accounts can access administrator data or functionality. Which
form of access control is this an example of?
A) MAC
B) DAC
C) RBAC
D) OAuth
Ans: D) OAuth
Question: Within the PKI system keys are carried in a digital structure known
as what?
A) Certificate
B) Symmetric key
C) Hash
D) Asymmetric key
Ans: A) Certificate
Question: Which of the following is NOT part of a certificate authority (CA)?
A) People who manage certificates
B) Hardware & software
C) Policies & procedures
D) Global symmetric keys
, Page | 3
Ans: D) Global symmetric keys
Question: You are working with a development group on a new web
application that will be hosted in the cloud. They need single sign-on
capability to exchange authentication and authorization data between
multiple security domains and they prefer working with XML. What would you
suggest they use?
A) OpenID
B) SAML
C) SecureID
D) RADIUS
Ans: B) SAML
Question: Which of the following protocols uses a key distribution center and
can securely pass a symmetric key over an insecure network?
A) PAP
B) LDAP
C) CHAP
D) Kerberos
Ans: D) Kerberos
Question: What is a common method to accomplish Discretionary Access
Control (DAC) on Linux-based systems?
A) File system permissions such as NTFS
B) Strict adherence to classification of objects by sensitivity & subjects by
formal authorization to access objects of that sensitivity
, Page | 4
C) Permission bits
D) UEFI & Full disk encryption
Ans: C) Permission bits
Question: A certificate issued for *.example.com would be valid for both
one.example.com as well as two.example.com. This is an example of what
kind of certificate?
A) Wildcard
B) Extended validation
C) Domain validation
D) Cross-certification
Ans: A) Wildcard
Question: How are attachments included in a normal emails with no
additional protocols or tools being used?
A) Base64 encoded
B) PGP encrypted
C) Base64 encrypted
D) AES-256 encoded
Ans: A) Base64 encoded
Question: Which of the following statements is TRUE?
A) Corporate tax records should be maintained for no more than two to five
years
B) Maintaining data according to a data retention policy can help limit risk
itn 260 Questions with Detailed Verified
Answers
Question: The X.509 standard applies to which of the following?
A) Public key infrastructure
B) SSL providers
C) Certificate Revocation Lists
D) Digital certificates
Ans: D) Digital certificates
Question: What are two ways that a certificate can stop being used?
A) Expiration and revocation
B) Expiration and certificate signing request
C) PKI replacement and revocation
D) Certificate signing reset and revocation
Ans: A) Expiration and revocation
Question: What are two protocols that can provide AuthN & AuthZ for a user
to a network?
A) SSO & XTACACS
B) TACACS+ & RADIUS
C) RADIUS & SAML
D) SAML & TACACS+
, Page | 2
Ans: B) TACACS+ & RADIUS
Question: A pen tester working on a web application makes sure that no
regular user accounts can access administrator data or functionality. Which
form of access control is this an example of?
A) MAC
B) DAC
C) RBAC
D) OAuth
Ans: D) OAuth
Question: Within the PKI system keys are carried in a digital structure known
as what?
A) Certificate
B) Symmetric key
C) Hash
D) Asymmetric key
Ans: A) Certificate
Question: Which of the following is NOT part of a certificate authority (CA)?
A) People who manage certificates
B) Hardware & software
C) Policies & procedures
D) Global symmetric keys
, Page | 3
Ans: D) Global symmetric keys
Question: You are working with a development group on a new web
application that will be hosted in the cloud. They need single sign-on
capability to exchange authentication and authorization data between
multiple security domains and they prefer working with XML. What would you
suggest they use?
A) OpenID
B) SAML
C) SecureID
D) RADIUS
Ans: B) SAML
Question: Which of the following protocols uses a key distribution center and
can securely pass a symmetric key over an insecure network?
A) PAP
B) LDAP
C) CHAP
D) Kerberos
Ans: D) Kerberos
Question: What is a common method to accomplish Discretionary Access
Control (DAC) on Linux-based systems?
A) File system permissions such as NTFS
B) Strict adherence to classification of objects by sensitivity & subjects by
formal authorization to access objects of that sensitivity
, Page | 4
C) Permission bits
D) UEFI & Full disk encryption
Ans: C) Permission bits
Question: A certificate issued for *.example.com would be valid for both
one.example.com as well as two.example.com. This is an example of what
kind of certificate?
A) Wildcard
B) Extended validation
C) Domain validation
D) Cross-certification
Ans: A) Wildcard
Question: How are attachments included in a normal emails with no
additional protocols or tools being used?
A) Base64 encoded
B) PGP encrypted
C) Base64 encrypted
D) AES-256 encoded
Ans: A) Base64 encoded
Question: Which of the following statements is TRUE?
A) Corporate tax records should be maintained for no more than two to five
years
B) Maintaining data according to a data retention policy can help limit risk