BANK | ACCURATE CURRENTLY TESTING
VERSIONS ALL EXAM QUESTIONS AND
ANSWERS | EXPERT VERIFIED FOR
GUARANTEED PASS | CERTMASTER COMPTIA
NETWORK+ FINAL ASSESSMENT LATEST
UPDATE
TABLE OF CONTENT PAGE
Comptia Security+ Certmaster - Domain 1.0---------------------------------------------------2-9
Comptia Certmaster CE Security+ Domain 1.0 General Security Concepts Assessment ----
------------------------------------------------------------------------------------------------------------10-12
Certmaster CE Security+ Domain 1.0 General Security Concepts-------------------------13-16
Comptia Certmaster CE Security+ Domain 1.0 General Security Concepts Assessment -----
------------------------------------------------------------------------------------------------------------17-23
Security+ Certmaster CE 701 Renewal - Domain 1.0----------------------------------------- 24-28
Security+ SYO-701 Certmaster CE Domain 1.0 -----------------------------------------------29-31
Comptia Certmaster CE Security+ Domain 2.0 Threats, Vulnerabilities, And Mitigations
Assessment --------------------------------------------------------------------------------------------32-42
Comptia Certmaster CE Security+ Section 2 -------------------------------------------------43-52
Comptia Security+ Certmaster - Domain 3.0 Assessment -----------------------------------53-63
Sec + Certmaster SY0-701 Domain 3 Assessment ---------------------------------------------64-75
Comptia Certmaster Security+ SY0-701 Domain 3.0 Security Architecture Assessment -----
--------------------------------------------------------------------------------------------------------- 76-86
Comptia Certmaster CE For Security+ - Domain 4.0 Security Operations Assessment -------
------------------------------------------------------------------------------------------------------------87-129
Comptia Certmaster CE Security+ Domain 4.0 Security Operations Assessment---------------
-----------------------------------------------------------------------------------------------------------130-136
Comptia Certmaster Security+ SY0-701 Domain 4.0 Security Operations Assessment -------
-----------------------------------------------------------------------------------------------------------137-151
Comptia Certmaster CE Security+ Domain 5.0 ----------------------------------------------152-156
CERTMASTER CE SECURITY+ DOMAIN 5.0 --------------------------------------------157-166
Certmaster Comptia Network+ Final Assessment--------------------------------------------167-235
1|Page
,Comptia Security+ Certmaster - Domain 1.0
A security engineer examined some suspicious error logs on a Windows server that
showed attempts to run shellcode to a web application. The shellcode showed
multiple lines beginning with Invoke-Command. What type of script is the
suspicious code trying to run? - CORRECT ANSWER ✔✔- PowerShell script
A web application's code prevents the output of any type of information when an
error occurs during a request. The development team cited security reasons as to
why they developed the application in this way. What sort of security issues did the
team have concerns about in this case? - CORRECT ANSWER ✔✔- Revealing
database server configuration
A security operations center (SOC) analyst investigates the propagation of a
memory-resident virus across the network and notices a rapid consumption of
network bandwidth, causing a Denial of Service (DoS). What type of virus is this?
- CORRECT ANSWER ✔✔- A worm
After recently being targeted by multiple brute-force and dictionary attacks, a
software engineer employs salting and key stretching to enhance security for stored
password hashes. How can salting and key stretching bolster the security of the
company's password hashes? - CORRECT ANSWER ✔✔- It adds an additional
value to the stored hash with the purpose of frustrating attempts to crack hashes.
If a user's computer becomes infected with malware and used as part of a botnet,
which of the following actions can be initiated by the attacker? (Select all that
apply.) - CORRECT ANSWER ✔✔- -Launch a Distributed Denial of Service
(DDoS) attack
-Launch a mass-mail spam attack
-Establish a connection with a Command and Control server
2|Page
,By compromising a Windows XP application that ran on a Windows 10 machine,
an attacker installed persistent malware on a victim computer with local
administrator privileges. What should the attacker add to the registry, along with
its files added to the system folder, to execute this malware? - CORRECT
ANSWER ✔✔- A shim
A hacker is trying to gain remote access to a company computer by trying brute
force password attacks using a few common passwords in conjunction with
multiple usernames. What specific type of password attack is the hacker most
likely performing? - CORRECT ANSWER ✔✔- Password spraying attack
An attacker used an exploit to steal information from a mobile device, which
allowed the attacker to circumvent the authentication process. Which of the
following attacks was used to exploit the mobile device? - CORRECT ANSWER
✔✔- Bluesnarfing
An attacker is preparing to perform what type of attack when the target
vulnerabilities include headers and payloads of specific application protocols? -
CORRECT ANSWER ✔✔- Application attack
A malicious user sniffed credentials exchanged between two computers by
intercepting communications between them. What type of attack did the attacker
execute? - CORRECT ANSWER ✔✔- A Man-in-the-Middle attack
An attacker passes data that deliberately overfills an area of memory that the
application reserves to store the expected data. Which vulnerability exploit resulted
from the attacker's actions? - CORRECT ANSWER ✔✔- A buffer overflow
Wi-Fi Protected Access (WPA) fixes critical vulnerabilities in the earlier wired
equivalent privacy (WEP) standard. Understanding that WPA uses a combination
3|Page
, of an RC4 stream cipher and Temporal Key Integrity Protocol (TKIP), this makes
a wireless access point NOT vulnerable to which of the following attacks when
related to encrypted wireless packets? - CORRECT ANSWER ✔✔- IV attacks
A Linux systems admin reported a suspicious .py file that ran on a daily schedule
after business hours. The file includes shellcode that would automate Application
Programming Interface (API) calls to a web application to get information. What
type of script is executing this shellcode? - CORRECT ANSWER ✔✔- Python
script
A malicious actor is preparing a script to run with an Excel spreadsheet as soon as
the target opens the file. The script includes a few macros designed to secretly
gather and send information to a remote server. How is the malicious actor
accomplishing this task? - CORRECT ANSWER ✔✔- By using VBA code
An attacker wants to exploit a weakness in a password protocol to calculate the
hash of a password. What methods allow the attacker to match a hash to obtain
authentication? (Select the best two responses.) - CORRECT ANSWER ✔✔- -
Dictionary attack
- Rainbow table
If a user's device becomes infected with ransomware, which of the following
would have been the best way to mitigate this compromise? - CORRECT
ANSWER ✔✔- Have up-to-date backups.
An attacker installs Trojan malware that can execute remote backdoor commands,
such as the ability to upload files and install software to a victim PC. What type of
Trojan malware is this? - CORRECT ANSWER ✔✔- A Remote Access Trojan
(RAT)
4|Page