COMPXM EXAM SCRIPT WITH VERIFIED
QUESTIONS AND ANSWERS
●● 3DES
Answer: Triple Digital Encryption Standard. A symmetric algorithm
used to encrypt data and provide confidentiality. It was originally
designed as a replacement for DES. It uses multiple keys and multiple
passes and is not as efficient as AES, but is still used in some
applications, such as when hardware doesn't support AES.
●● AAA
Answer: Authentication, Authorization, and Accounting. AAA protocols
are used in remote access systems. For example, TACACS + is an AAA
protocol that uses multiple challenges and responses during a session.
Authentication verifies a user's identification. Authorization determines
if a user should have access. Accounting tracks a user's access with logs.
●● ACE
Answer: Access Control Entry. Identifies a user or group that is granted
permission to a resource. ACEs are contained within a DACL in NTFS.
●● ACL
Answer: Access control list. A list of rules used to grant access to a
resource. In NTFS, a list of ACEs makes up the ACL for a resource. In a
,firewall, an ACL identifies traffic that is allowed or blocked based on IP
addresses, networks, ports, and some protocols (using the protocol ID).
●● AES
Answer: Advanced Encryption Standard. A symmetric algorithm used to
encrypt data and provide confidentiality. AES is quick, highly secure,
and used in a wide assortment of cryptography schemes. It includes key
sizes of 128 bits, 192 bits, or 256 bits.
●● AES256
Answer: Advanced Encryption Standard 256 bit. AES sometimes
includes the number of bits used in the encryption keys and AES256
uses 256-bit encryption keys.
●● AH
Answer: Authentication Header. IPsec includes both AH and ESP. AH
provides authentication and integrity, and ESP provides confidentiality,
integrity, and authentication. AH is identified with protocol ID number
51.
●● ALE
Answer: Annualized loss expectancy. Used to measure risk with
annualized rate of occurrence (ARO) and single loss expectancy (SLE).
The ALE identifies the total amount of loss expected for a given risk.
The calculation is SLE × ARO = ALE.
,●● AP
Answer: Access point, short for wireless access point (WAP). APs
provide access to a wired network to wireless clients. Many APs support
isolation mode to segment wireless uses from other wireless users.
●● ARO
Answer: Annualized rate of occurrence. Used to measure risk with
annualized loss expectancy (ALE) and single loss expectancy (SLE).
The ARO identifies how many times a loss is expected to occur in a
year. The calculation is SLE × ARO = ALE.
●● ARP
Answer: Address Resolution Protocol. Resolves IP addresses to MAC
addresses. ARP poisoning attacks can redirect traffic through an
attacker's system by sending false MAC address updates. VLAN
segregation helps prevent the scope of ARP poisoning attacks within a
network.
●● AUP
Answer: Acceptable use policy. An AUP defines proper system usage. It
will often describe the purpose of computer systems and networks, how
users can access them, and the responsibilities of users when accessing
the systems.
, ●● BCP
Answer: Business continuity plan. A plan that helps an organization
predict and plan for potential outages of critical services or functions. It
includes disaster recovery elements that provide the steps used to return
critical functions to operation after an outage. A BIA is a part of a BCP
and the BIA drives decisions to create redundancies such as failover
clusters or alternate sites.
●● BIA
Answer: Business impact analysis. The BIA identifies critical business
or mission requirements and includes elements such as Recovery Time
Objectives (RTOs) and Recovery Point Objectives (RPOs), but it doesn't
identify solutions.
●● BIOS
Answer: Basic Input/ Output System. A computer's firmware used to
manipulate different settings such as the date and time, boot drive, and
access password.
●● BOTS
Answer: Network Robots. An automated program or system used to
perform one or more tasks. A malicious botnet is group of computers
called zombies and controlled through a command-and-control server.
Attackers use malware to join computers to botnets. Zombies regularly
check in with the command-and-control server and can launch DDoS
attacks against other victims. Botnet activity often includes hundreds of
QUESTIONS AND ANSWERS
●● 3DES
Answer: Triple Digital Encryption Standard. A symmetric algorithm
used to encrypt data and provide confidentiality. It was originally
designed as a replacement for DES. It uses multiple keys and multiple
passes and is not as efficient as AES, but is still used in some
applications, such as when hardware doesn't support AES.
●● AAA
Answer: Authentication, Authorization, and Accounting. AAA protocols
are used in remote access systems. For example, TACACS + is an AAA
protocol that uses multiple challenges and responses during a session.
Authentication verifies a user's identification. Authorization determines
if a user should have access. Accounting tracks a user's access with logs.
●● ACE
Answer: Access Control Entry. Identifies a user or group that is granted
permission to a resource. ACEs are contained within a DACL in NTFS.
●● ACL
Answer: Access control list. A list of rules used to grant access to a
resource. In NTFS, a list of ACEs makes up the ACL for a resource. In a
,firewall, an ACL identifies traffic that is allowed or blocked based on IP
addresses, networks, ports, and some protocols (using the protocol ID).
●● AES
Answer: Advanced Encryption Standard. A symmetric algorithm used to
encrypt data and provide confidentiality. AES is quick, highly secure,
and used in a wide assortment of cryptography schemes. It includes key
sizes of 128 bits, 192 bits, or 256 bits.
●● AES256
Answer: Advanced Encryption Standard 256 bit. AES sometimes
includes the number of bits used in the encryption keys and AES256
uses 256-bit encryption keys.
●● AH
Answer: Authentication Header. IPsec includes both AH and ESP. AH
provides authentication and integrity, and ESP provides confidentiality,
integrity, and authentication. AH is identified with protocol ID number
51.
●● ALE
Answer: Annualized loss expectancy. Used to measure risk with
annualized rate of occurrence (ARO) and single loss expectancy (SLE).
The ALE identifies the total amount of loss expected for a given risk.
The calculation is SLE × ARO = ALE.
,●● AP
Answer: Access point, short for wireless access point (WAP). APs
provide access to a wired network to wireless clients. Many APs support
isolation mode to segment wireless uses from other wireless users.
●● ARO
Answer: Annualized rate of occurrence. Used to measure risk with
annualized loss expectancy (ALE) and single loss expectancy (SLE).
The ARO identifies how many times a loss is expected to occur in a
year. The calculation is SLE × ARO = ALE.
●● ARP
Answer: Address Resolution Protocol. Resolves IP addresses to MAC
addresses. ARP poisoning attacks can redirect traffic through an
attacker's system by sending false MAC address updates. VLAN
segregation helps prevent the scope of ARP poisoning attacks within a
network.
●● AUP
Answer: Acceptable use policy. An AUP defines proper system usage. It
will often describe the purpose of computer systems and networks, how
users can access them, and the responsibilities of users when accessing
the systems.
, ●● BCP
Answer: Business continuity plan. A plan that helps an organization
predict and plan for potential outages of critical services or functions. It
includes disaster recovery elements that provide the steps used to return
critical functions to operation after an outage. A BIA is a part of a BCP
and the BIA drives decisions to create redundancies such as failover
clusters or alternate sites.
●● BIA
Answer: Business impact analysis. The BIA identifies critical business
or mission requirements and includes elements such as Recovery Time
Objectives (RTOs) and Recovery Point Objectives (RPOs), but it doesn't
identify solutions.
●● BIOS
Answer: Basic Input/ Output System. A computer's firmware used to
manipulate different settings such as the date and time, boot drive, and
access password.
●● BOTS
Answer: Network Robots. An automated program or system used to
perform one or more tasks. A malicious botnet is group of computers
called zombies and controlled through a command-and-control server.
Attackers use malware to join computers to botnets. Zombies regularly
check in with the command-and-control server and can launch DDoS
attacks against other victims. Botnet activity often includes hundreds of