Sec B Questions and Answers Graded A+
Sec B Questions and Answers Graded A+ A company is experiencing an increasing number of systems that are locking up on Windows startup. The security analyst clones a machine, enters into safe mode, and discovers a file in the startup process that runs Wstart bat. @echonoff :asdhbawdhbasdhbawdhb start art start start goto asdhbawdhbasdhbawdhb Given the file contents and the system's issues, which of the following types of malware is present? Logic bomb A company wants to provide centralized authentication for its wireless system. The wireless authentication must integrate with the directory back end. Which of the following is an AAA solution that will provide the required authentication? RADIUS Brainpower Read More Previous Play Next Rewind 10 seconds Move forward 10 seconds Unmute 0:06 / 0:15 Full screen A technician wants to add wireless guest capabilities to an enterprise wireless network that is currently implementing 802.1X EAP-TLS. The guest network must: Support client isolation Issue an unique encryption key to each client Allow guests to register using their personal email addresses Which of the following should the technician implement? (Select TWO) Captive Portal A separate guest SSID A first responder needs to collect digital evidence from a compromised headless virtual host. Which of the following should the first responder collect FIRST? RAM A security administrator is implementing a SIEM and needs to ensure events can be compared against each other based on when the events occurred and were collected. Which of the following does the administrator need to implement to ensure this can be accomplished? NTP An organization's Chief Executive Officer (CEO) directs a newly hired computer technician to install an OS on the CEO's personal laptop. The technician performs the installation, and a software audit later in the month indicates a violation of the EULA occurred as a result. Which of the following would address this violation going forward? AUP After patching computers with the latest application security patches/updates, users are unable to open certain applications. Which of the following will correct the issue? Modifying the security policy for HIDS/HIPS The Chief Executive Officer (CEO) received an email from the Chief Financial Officer (CFO), asking the CEO to send financial details. The CEO thought it was strange that the CFO would ask for the financial details via email. The email address was correct in the "from" section of the email. The CEO clicked the forma nd sent the financial information as requested. Which of the following caused the incident? SPF not enabled A security analyst is performing a manual audit of captured data from a packet analyzer. The analyst looks for Base64 encoded strings and applies the filter asic. Which of the following BEST describes what the analyst is looking for? Unencrypted Credentials A systems administrator is increasing the security settings on a virtual host to ensure users on one VM cannot access information from another VM. Which of the following is the administrator protecting against? VM escape A computer forensics team is performing an integrity check on key system files. The team is comparing the signatures of original baseline files with the latest signatures. The original baseline was taken March 2, 2016, and was established to be clean of malware and uncorrupted. The latest file signatures were generated yesterday. One file is known to be corrupted, but when the team compares the signatures of the original and latest files, the team sees the following: Original: 2d da b1 4a 98 fc f1 98 06 b1 e5 26 df e5 5b 3e cb 83 e1 Latest: 2d da b1 4a 98 fc f1 98 06 b1 e5 26 df e5 5b 3e cb 83 e1 Which of the following is MOST likely the situation? The algorithm used to calculate the hash has a collision weakness and an attacker has exploited it An incidnet response analyst at a large corporation is reviewing proxy log data. The analyst believes a malware infection may have occurred. Upon further review, the analyst determines the computer responsible for the suspicious network traffic is used by the Chief Executive Officer (CEO). Which of the following is the next BEST step for the analyst to take? Disconnect the CEO's workstation from the network An administrator is disposing of media that contains sensitive information. Which of the following will provide the MOST effective method to dispose of media while ensuring the data will be unrecoverable? Shred the hard drive A security analyst is reviewing the password policy for a service account that is used for a critical network service. The password policy for this account is as follows: Enforce password history: Three passwords remembered Maximum password age: 30 days Minimum password age: Zero days Complexity requirements: At least one special character, one uppercase Minimum password length: Seven characters Lockout duration: One day Lockout Threshold: Five failed attempts in 15 minutes Which of the following adjustments would be MOST appropriate for the service account? Disable account lockouts
Document information
- Uploaded on
- January 14, 2024
- Number of pages
- 4
- Written in
- 2023/2024
- Type
- Exam (elaborations)
- Contains
- Questions & answers