WGU C836 pre assessment questions and answers latest updated 2022
WGU C836 pre assessment questions and answers latest updated 2022 Port scanner Which tool can be used to map devices on a network, along with their operating system types and versions? SQL Injection Which web attack is a server-side attack? Availability A company has had several successful denial of service (DoS) attacks on its email server. Which security principle is being attacked? SQL Injection Which web attack is possible due to a lack of input validation? Encryption Which file action implements the principle of confidentiality from the CIA triad? Integrity An organization plans to encrypt data in transit on a network. Which aspect of data is the organization attempting to protect? Integrity Which aspect of the CIA triad is violated by an unauthorized database roll back or undo? Availability A company's website has suffered several denial of service (DoS) attacks and wishes to thwart future attacks. Which security principle is the company addressing? Availability An organization has a requirement that all database servers and file servers be configured to maintain operations in the presence of a failure. Which principle of the CIA triad is this requirement implementing? Operations A company's website policy states that "To gain access to the corporate website, each employee must provide a valid user name and password, and then answer one of six security questions accurately." Which type of security does the policy address? Attribute-based A company wants to update its access control policy. The company wants to prevent hourly employees from logging in to company computers after business hours. Which type of access control policy should be implemented? Relocate the algorithm to encrypted storage. A new software development company has determined that one of its proprietary algorithms is at a high risk for unauthorized disclosure. The company's security up to this point has been fairly lax. Which procedure should the company implement to protect this asset? Restrict account permissions. How can an operating system be hardened in accordance to the principle of least privilege? Limit user account privileges. A user runs an application that has been infected with malware that is less than 24 hours old. The malware then infects the operating system. Which safeguard should be implemented to prevent this type of attack? Weak Passwords A module in a security awareness course shows a user making use of two-factor authentication using a hardware token. Which security failure is being addressed by this training module? A fuzzer Which tool should an application developer use to help identify input validation vulnerabilities? Brute force A systems administrator enables operating system logging to capture unsuccessful log in attempts. Which attack can be uncovered by reviewing such logs? A fuzzer Which type of tool can be used to detect vulnerabilities in source code related to improper handling of user input? Apply the principle of least privilege. An organization wants to minimize the impact of user credential theft by ensuring that only HR staff can access employee personal information. Which security mechanism should it implement? Antivirus An organization wants to prevent malware from infecting its workstations, mobile devices, and web applications. Which security tool should it implement? File encryption A company has files stored on a server that are critical to the organization's viability. The administrator has assigned the appropriate permissions to the files. How should the administrator provide additional confidentiality protection for the files at rest? Firewall Which security solution can an organization deploy to prevent unauthorized external access to its internal network? Confidentiality A file is stored in a marketing folder and is accessible only to members of the marketing group. An attacker uses a phishing scam to gain the credentials of a user who is a member of the marketing group, and then reads the file. Which leg of the CIA triad is being targeted? Availability An attacker performs a buffer overflow attack on an organization's web server. The web server locks up and must be restarted to restore functionality. Which part of the CIA triad is under attack? Integrity Some malware hides itself by replacing some system administrator commands on a server, but the server continues to function normally for its users. Which component of the CIA triad has been compromised? SSL/TLS A bank wants to ensure user interactions with the online
Document information
- Uploaded on
- August 14, 2022
- Number of pages
- 6
- Written in
- 2022/2023
- Type
- Exam (elaborations)
- Contains
- Questions & answers