Network Security Final Exam with all Correct & 100%
Verified Answers |Actual Complete Update |Already
Graded A+
What is NOT a characteristic of Advanced Persistent Threat (APT)? ✔Correct Answer-Is only
used by hactivists against foreign enemies
What term was used to describe attackers who would break into a computer system without the
owner's permission and publicly disclose the vulnerability? ✔Correct Answer-Black Hat
Hackers
What is NOT a reason why it is difficult to defend against today's attackers? ✔Correct Answer-
Greater sophistication of defense tools
Why can brokers command such a high price for what they sell? ✔Correct Answer-The
vulnerability was previously unknown and is unlikely to be patched quickly
What phrase describes the term "security" in a general sense? ✔Correct Answer-The
necessary steps to protect a person or property from harm
___________ ensures that only authorized parties can view the information ✔Correct
Answer-Confidentiality
What is NOT a successive layer in which information security is achieved? ✔Correct Answer-
Purposes
What is a person or element that has the power to carry out a threat? ✔Correct Answer-
Threat Agent
_________ ensures that individuals are who they claim to be ✔Correct Answer-
Authentication
What is the difference between a hactivist and a cyberterrorist? ✔Correct Answer-The aim of
a hactivist is not to incite panic like cyberterrorists
What is NOT a goal of information security? ✔Correct Answer-Limit access control
What act requires enterprises to guard protected health information and implement policies
and procedures to safeguard it? ✔Correct Answer-Health Insurance Portability and
Accountability Act (HIPAA)
,Why do cyberterrorists target power plants, air traffic control centers, and water systems?
✔Correct Answer-They can cause significant disruption by destroying only a few targets
What is the first step in the Cyber Kill Chain? ✔Correct Answer-Reconnaissance
An organization that purchased security products from different vendors is demonstrating what
security principle? ✔Correct Answer-Diversity
What cannot be classified as an "insider"? ✔Correct Answer-Stockholders
What are attackers called who belong to a network of identity thieves and financial fraudsters?
✔Correct Answer-Cybercriminals
What is an objective of state-sponsored attackers? ✔Correct Answer-To spy on citizens
An example of _______ is not revealing the type of computer, operating system, software, and
network connection a computer uses ✔Correct Answer-Obscurity
The _________ is primarily responsible for assessing, managing, and implementing security
✔Correct Answer-Chief Information Security Officer (CISO)
At what point in a vulnerability assessment would an attack tree be utilized? ✔Correct
Answer-Threat Evaluation
In the software development process, when should a design review be conducted? ✔Correct
Answer-As the functional and design specifications are being developed based on the
requirements
A(n) _____ attempts to penetrate a system in order to perform a simulated attack. ✔Correct
Answer-Intrusive Vulnerability Scan
A ________ is a systematic and methodical evaluation of the exposure of assets to attackers,
forces of nature, and any other entity that could cause potential harm. ✔Correct Answer-
Vulnerability Assessment
What CANNOT be classified as an asset? ✔Correct Answer-Accounts Payable
What is NOT a function of a vulnerability scanner? ✔Correct Answer-Alerts users when a new
patch cannot be found
Each of these is a step in risk management EXCEPT _____. ✔Correct Answer-Attack
Assessment
, Which statement regarding vulnerability appraisal is NOT true? ✔Correct Answer-
Vulnerability appraisal is always the easiest and quickest step.
_________ constructs scenarios of the types of threats that assets can face in order to learn
who the attackers are, why they attack, and what types of attacks may occur. ✔Correct
Answer-Threat modeling
What is a current snapshot of the security of an organization? ✔Correct Answer-Vulnerability
appraisal
_______ is a comparison of the present security state of a system to a standard established by
the organization. ✔Correct Answer-Baseline reporting
Which of these is NOT a state of a port that can be returned by a port scanner? ✔Correct
Answer-Busy
A(n) _____ is an agreement between two parties that is not legally enforceable. ✔Correct
Answer-Memorandum of Understanding (MOU)
The protocol File Transfer Protocol (FTP) uses which two ports? ✔Correct Answer-20 and 21
Which statement about the Open Vulnerability and Assessment Language (OVAL) is true?
✔Correct Answer-It attempts to standardize vulnerability assessments.
Which statement regarding a honeypot is NOT true? ✔Correct Answer-It cannot be part of a
honeynet.
If a software application aborts and leaves the program open, which control structure is it
using? ✔Correct Answer-Fail-Open
Which statement about vulnerability scanning is true? ✔Correct Answer-It uses automated
software to scan for vulnerabilities.
If a tester is given the IP addresses, network diagrams, and source code of customer
applications, the tester is using which technique? ✔Correct Answer-White Box
Which statement regarding TCP SYN port scanning is NOT true? ✔Correct Answer-It uses FIN
messages that can pass through firewalls and avoid detection.
An event that appears to be a risk but turns out not to be one is called a _____. ✔Correct
Answer-False Positive
What is NOT a response to risk? ✔Correct Answer-Resistance
Verified Answers |Actual Complete Update |Already
Graded A+
What is NOT a characteristic of Advanced Persistent Threat (APT)? ✔Correct Answer-Is only
used by hactivists against foreign enemies
What term was used to describe attackers who would break into a computer system without the
owner's permission and publicly disclose the vulnerability? ✔Correct Answer-Black Hat
Hackers
What is NOT a reason why it is difficult to defend against today's attackers? ✔Correct Answer-
Greater sophistication of defense tools
Why can brokers command such a high price for what they sell? ✔Correct Answer-The
vulnerability was previously unknown and is unlikely to be patched quickly
What phrase describes the term "security" in a general sense? ✔Correct Answer-The
necessary steps to protect a person or property from harm
___________ ensures that only authorized parties can view the information ✔Correct
Answer-Confidentiality
What is NOT a successive layer in which information security is achieved? ✔Correct Answer-
Purposes
What is a person or element that has the power to carry out a threat? ✔Correct Answer-
Threat Agent
_________ ensures that individuals are who they claim to be ✔Correct Answer-
Authentication
What is the difference between a hactivist and a cyberterrorist? ✔Correct Answer-The aim of
a hactivist is not to incite panic like cyberterrorists
What is NOT a goal of information security? ✔Correct Answer-Limit access control
What act requires enterprises to guard protected health information and implement policies
and procedures to safeguard it? ✔Correct Answer-Health Insurance Portability and
Accountability Act (HIPAA)
,Why do cyberterrorists target power plants, air traffic control centers, and water systems?
✔Correct Answer-They can cause significant disruption by destroying only a few targets
What is the first step in the Cyber Kill Chain? ✔Correct Answer-Reconnaissance
An organization that purchased security products from different vendors is demonstrating what
security principle? ✔Correct Answer-Diversity
What cannot be classified as an "insider"? ✔Correct Answer-Stockholders
What are attackers called who belong to a network of identity thieves and financial fraudsters?
✔Correct Answer-Cybercriminals
What is an objective of state-sponsored attackers? ✔Correct Answer-To spy on citizens
An example of _______ is not revealing the type of computer, operating system, software, and
network connection a computer uses ✔Correct Answer-Obscurity
The _________ is primarily responsible for assessing, managing, and implementing security
✔Correct Answer-Chief Information Security Officer (CISO)
At what point in a vulnerability assessment would an attack tree be utilized? ✔Correct
Answer-Threat Evaluation
In the software development process, when should a design review be conducted? ✔Correct
Answer-As the functional and design specifications are being developed based on the
requirements
A(n) _____ attempts to penetrate a system in order to perform a simulated attack. ✔Correct
Answer-Intrusive Vulnerability Scan
A ________ is a systematic and methodical evaluation of the exposure of assets to attackers,
forces of nature, and any other entity that could cause potential harm. ✔Correct Answer-
Vulnerability Assessment
What CANNOT be classified as an asset? ✔Correct Answer-Accounts Payable
What is NOT a function of a vulnerability scanner? ✔Correct Answer-Alerts users when a new
patch cannot be found
Each of these is a step in risk management EXCEPT _____. ✔Correct Answer-Attack
Assessment
, Which statement regarding vulnerability appraisal is NOT true? ✔Correct Answer-
Vulnerability appraisal is always the easiest and quickest step.
_________ constructs scenarios of the types of threats that assets can face in order to learn
who the attackers are, why they attack, and what types of attacks may occur. ✔Correct
Answer-Threat modeling
What is a current snapshot of the security of an organization? ✔Correct Answer-Vulnerability
appraisal
_______ is a comparison of the present security state of a system to a standard established by
the organization. ✔Correct Answer-Baseline reporting
Which of these is NOT a state of a port that can be returned by a port scanner? ✔Correct
Answer-Busy
A(n) _____ is an agreement between two parties that is not legally enforceable. ✔Correct
Answer-Memorandum of Understanding (MOU)
The protocol File Transfer Protocol (FTP) uses which two ports? ✔Correct Answer-20 and 21
Which statement about the Open Vulnerability and Assessment Language (OVAL) is true?
✔Correct Answer-It attempts to standardize vulnerability assessments.
Which statement regarding a honeypot is NOT true? ✔Correct Answer-It cannot be part of a
honeynet.
If a software application aborts and leaves the program open, which control structure is it
using? ✔Correct Answer-Fail-Open
Which statement about vulnerability scanning is true? ✔Correct Answer-It uses automated
software to scan for vulnerabilities.
If a tester is given the IP addresses, network diagrams, and source code of customer
applications, the tester is using which technique? ✔Correct Answer-White Box
Which statement regarding TCP SYN port scanning is NOT true? ✔Correct Answer-It uses FIN
messages that can pass through firewalls and avoid detection.
An event that appears to be a risk but turns out not to be one is called a _____. ✔Correct
Answer-False Positive
What is NOT a response to risk? ✔Correct Answer-Resistance