Practitioner Course Latest Update
2026 EXAM PREP PDF GRADED A+
The most common security weaknesses and exploits are in which standardized list? -
correct answerD. CVE - Common Vulnerabilities and Exposures
Choose the password configuration rules enforced by the Passfilt.dll Windows add-on. -
correct answerC. Password must have a combination of upper case, lower case,
numbers, and special characters; including a 6 character minimum password length
A computer forensics specialist should be attempting to attain which ultimate goal? -
correct answerB. Preserve electronic evidence and protect it from any alteration
What term is used to describe how data is transmitted between nodes on a network or
between networks, with the three common types being Broadcast, Multicast, and
Unicast? - correct answerA. Casting
While conducting Quantitative risk analysis, which formula would be utilized? - correct
answerD. SLE - Single Loss Expectancy
Which protocol listed below resolves a physical MAC address for a given logical IP
address? - correct answerA. ARP
Providing optimal protection, what comprehensive array of layered security solutions
resembles the layers of an onion? - correct answerB. Defense in Depth
Swiping a badge against a magnet reader at an entrance that unlocks the door for entry,
would be which of the following? - correct answerB. Single-factor authentication
Encryption is attained at what layer of the OSI model? - correct answerC. Presentation
Layer - Layer 6
What type of encrypted string is the output of a one way hash function on a string of
random length? - correct answerA. fixed length
What is the main difference between a phreak and a hacker? - correct answerA.
Phreaks specifically target telephone networks
Through what method of deduction is two-factor authentication achieved using your
ATM card? - correct answerC. It combines something you have with something you
know
, Accountability for the timely distribution of information security intelligence data is
assumed by which organization(s)? - correct answerD. All of the organizations listed
Which detail concerning risk analysis would you present to leadership regarding
quantitative analysis ? - correct answerD. D. A and C
Which of the following are categories of a security incident? - correct answerE. All of the
above
A server offering AAA services must provide which services? - correct answerC.
Accounting, Authentication, and Authorization
Working as a network administrator for your organization, which of the following choices
should have the BIND application disabled? - correct answerA. All non DNS servers
Which attribute constitutes the ability to identify and/or audit a user and his/her actions?
- correct answerC. Accountability
What program is designed to intentionally create a clandestine avenue of access or a
security gap within an information system? - correct answerD. Backdoor
Which is NOT a characteristic of the RSA algorithm? - correct answerC. Is based on a
symmetric algorithm
What is the nickname given to the Trusted Computer Security Evaluation Criteria
(TCSEC) book, according to IT professionals? - correct answerA. The orange book
Based on the division of job responsibilities, name the security principle designed for
fraud prevention. - correct answerB. Separation of Duties
Which is an information path within a computer system not used for communications
under normal circumstances? - correct answerB. Covert channel
What type of access control delivers the challenge: Is the person who is attempting to
log on, really who they say they are? - correct answerC. Authentication
How are clipping levels useful to an information security professional? - correct
answerA. Reduce the amount of data to be evaluated
Which of the following is used for moving traffic within individual VLANs? - correct
answerB. VLAN Access Maps
Which of the following is a method of identifying programs that have been approved by
administration for use on end-point devices? - correct answerD. Application Whitelisting