CCBC DCOM 258 Midterm Exam ACTUAL UPDATED QUESTIONS AND
CORRECT ANSWERS
A system administrator needs secure remote access into Secure Shell (SSH)
a Linux server. Evaluate the types of remote
administration to recommend which protocol should be
used in this situation
A technician is configuring Internet Protocol Security Tunnel mode because the whole IP packet is encrypted, and a new IP header is
(IPSec) for communications over a Virtual Private added
Network (VPN). Evaluate the features of available modes
and recommend the best option for implementation
A system administrator is setting up a new Simple Mail Port 25 should be used for message relay
Transfer Protocol (SMTP) configuration. Make
recommendations for how the administrator should Port 465 should be used for message submission over implicit TLS
configure the ports. (Select all that apply.)
A system administrator needs to implement a secure Telnet does not support direct file transfer
remote administration protocol and would like more
information on Telnet. Evaluate and select the features of Telnet uses TCP port 23
Telnet that the administrator should consider to
accomplish this task. (Select all that apply.)
Analyze the methods for authentication to a Secure Shell The client sends a request for authentication and the server generates a challenge
(SSH) and determine which statement best summarizes with the public key
the host-based authentication method.
Transport layer security (TLS) version 1.3 improves upon a TLS version 1.3 removes the ability to downgrade to weaker
vulnerability in TLS1.2. Which statement correctly encryption ciphers and earlier versions of transport layer
describes a remedy for this vulnerability? security.
If an administrator in an exchange server needs to send Secure/Multipurpose Internet Mail Extensions (S/MIME)
digitally signed and encrypted messages, what
messaging implementation will best suit the
administrator's needs?
A system administrator is configuring a new Dynamic Disable unused ports and perform regular physical inspections to look for
Host Configuration Protocol (DHCP) server. Analyze the unauthorized devices.
types of attacks DHCP servers are prone to and
determine which steps the system administrator should Use scanning and intrusion detection to pick up suspicious activity.
take to protect the server. (Select all that apply.)
Enable logging and review the logs for suspicious events.
, An organization routinely communicates directly to a An attacker masquerades as an authoritative name server.
partner company via a domain name. The domain name
now leads to a fraudulent site for all users. Systems
administrators find incorrect host records in DNS. What
do the administrators believe to be the root cause?
When a company attempts to re-register their domain Domain hijacking
name, they find that an attacker has supplied false
credentials to the domain registrar and redirected their
host records to a different IP address. What type of attack
has occurred?
Compare and evaluate the various levels and types of Digital certificates, keys, and hashed passwords are maintained in hardware-based
platform security to conclude which option applies to a storage.
hardware Trusted Platform Module (TPM)
Evaluate approaches to applying patch management Operating System major release updates are known to frequently cause problems
updates to select the accurate statement. with software application compatibility.
Evaluate the features and vulnerabilities found in medical Main portable devices, such as cardiac monitors and insulin pumps, run on
devices and then select the accurate statements. (Select unsupported operating systems.
all that apply.)
Attackers may attempt to gain access in order to kill or injure patients, or hold
medical units ransom.
Contrast vendor support for products and services at the During the end of life (EOL) phase, manufacturers provide limited support,
end of their life cycle. Which of the following statements updates, and spare parts. In the end of service life (EOSL), developers or vendors
describes the difference between support available no longer support the product and no longer push security updates.
during the end of life (EOL) phase and end of service life
(EOSL) phase?
The network manager should ensure all patches are A network manager is installing a new switch on the network. Which option does
applied and it is appropriately configured. the manager use to harden network security after installation?
Compare the features of static and dynamic computing Dynamic computing environments are easier to update than static computing
environments and then select the accurate statements. environments.
(Select all that apply.)
Embedded systems are typically static computing environments, while most
personal computers are dynamic computing environments.
During a training event, an executive at a large company Automatic updates can cause performance and availability issues.
asks the security manager trainer why pushing automatic
updates as a patch management solution is not ideal for
their Enterprise network. How will the security manager
most likely respond?
CORRECT ANSWERS
A system administrator needs secure remote access into Secure Shell (SSH)
a Linux server. Evaluate the types of remote
administration to recommend which protocol should be
used in this situation
A technician is configuring Internet Protocol Security Tunnel mode because the whole IP packet is encrypted, and a new IP header is
(IPSec) for communications over a Virtual Private added
Network (VPN). Evaluate the features of available modes
and recommend the best option for implementation
A system administrator is setting up a new Simple Mail Port 25 should be used for message relay
Transfer Protocol (SMTP) configuration. Make
recommendations for how the administrator should Port 465 should be used for message submission over implicit TLS
configure the ports. (Select all that apply.)
A system administrator needs to implement a secure Telnet does not support direct file transfer
remote administration protocol and would like more
information on Telnet. Evaluate and select the features of Telnet uses TCP port 23
Telnet that the administrator should consider to
accomplish this task. (Select all that apply.)
Analyze the methods for authentication to a Secure Shell The client sends a request for authentication and the server generates a challenge
(SSH) and determine which statement best summarizes with the public key
the host-based authentication method.
Transport layer security (TLS) version 1.3 improves upon a TLS version 1.3 removes the ability to downgrade to weaker
vulnerability in TLS1.2. Which statement correctly encryption ciphers and earlier versions of transport layer
describes a remedy for this vulnerability? security.
If an administrator in an exchange server needs to send Secure/Multipurpose Internet Mail Extensions (S/MIME)
digitally signed and encrypted messages, what
messaging implementation will best suit the
administrator's needs?
A system administrator is configuring a new Dynamic Disable unused ports and perform regular physical inspections to look for
Host Configuration Protocol (DHCP) server. Analyze the unauthorized devices.
types of attacks DHCP servers are prone to and
determine which steps the system administrator should Use scanning and intrusion detection to pick up suspicious activity.
take to protect the server. (Select all that apply.)
Enable logging and review the logs for suspicious events.
, An organization routinely communicates directly to a An attacker masquerades as an authoritative name server.
partner company via a domain name. The domain name
now leads to a fraudulent site for all users. Systems
administrators find incorrect host records in DNS. What
do the administrators believe to be the root cause?
When a company attempts to re-register their domain Domain hijacking
name, they find that an attacker has supplied false
credentials to the domain registrar and redirected their
host records to a different IP address. What type of attack
has occurred?
Compare and evaluate the various levels and types of Digital certificates, keys, and hashed passwords are maintained in hardware-based
platform security to conclude which option applies to a storage.
hardware Trusted Platform Module (TPM)
Evaluate approaches to applying patch management Operating System major release updates are known to frequently cause problems
updates to select the accurate statement. with software application compatibility.
Evaluate the features and vulnerabilities found in medical Main portable devices, such as cardiac monitors and insulin pumps, run on
devices and then select the accurate statements. (Select unsupported operating systems.
all that apply.)
Attackers may attempt to gain access in order to kill or injure patients, or hold
medical units ransom.
Contrast vendor support for products and services at the During the end of life (EOL) phase, manufacturers provide limited support,
end of their life cycle. Which of the following statements updates, and spare parts. In the end of service life (EOSL), developers or vendors
describes the difference between support available no longer support the product and no longer push security updates.
during the end of life (EOL) phase and end of service life
(EOSL) phase?
The network manager should ensure all patches are A network manager is installing a new switch on the network. Which option does
applied and it is appropriately configured. the manager use to harden network security after installation?
Compare the features of static and dynamic computing Dynamic computing environments are easier to update than static computing
environments and then select the accurate statements. environments.
(Select all that apply.)
Embedded systems are typically static computing environments, while most
personal computers are dynamic computing environments.
During a training event, an executive at a large company Automatic updates can cause performance and availability issues.
asks the security manager trainer why pushing automatic
updates as a patch management solution is not ideal for
their Enterprise network. How will the security manager
most likely respond?