Which of the following is a major objective of a packet analysis?
a. Ensure physical security
b. Estimate network cost
c. Calculate employee work hours
d. Assess and secure networks
You are a cyber forensic expert wanting to protect devices retrieved from a crime scene
from being remotely wiped of evidence. Which of the following physical security
equipment should you use so that inbound and outbound signals cannot be sent or
received?
a. Faraday bags
b. Protected cable distribution
c. Mantraps
d. Cable locks
A source computer's ability to reach a specified destination computer can be tested
using which of the following?
a. ifconfig
b. ping
c. curl
d. ipconfig
In an interview, you are given the following scenario:
David sent a message to Tina saying, "There is no school today!" For some reason, the
message shoed up on Tina's device as, "Come to the school ASAP!" You (the
candidate) are asked to name the type of attack that would cause this situation.
Which of the following should you identify?
a. Macro attack
b. DNS hijacking
c. MITM
d. DDoS
Which of the following best describes bash?
a. Bash is a network assessment tool
b. Bash is computer hardware
,c. Bash is a command language interpreter
d. Bash is a physical security measure
Which of the following is a third-party network analysis tool?
a. netstat
b. hping
c. curl
d. nmap
In an interview, you are asked to change the permissions of a file on a Linux system so
that the file can only be accessed by its owner. Which of the following tools should you
use?
a. Nessuss
b. grep
c. chmod
d. Cuckoo
Which of the following is an external perimeter defense method?
a. Fire supression
b. Barrier
c. Demilitarized zone (DMZ)
d. Electronic lock
Which of the following statements about domain reputation is correct?
a. Domain reputation will be low if the domain is used for distributing malware or
launching attacks
b. Domain reputation will be high if the enterprise has access to a huge volume of
resources
c. Domain reputation will be high if the domain is used for distributing malware or
launching attacks
d. Domain reputation will be low if the enterprise has access to a huge volume of
resources
Which of the following is a layer 2 attack?
a. DNS poisoning
b. DNS hijacking
c. ARP poisoning
d. DDoS
Your enterprise is hosting a web app that has limited security. As a security
administrator, you are asked to take appropriate measures to restrict threat actos from
,hijacking users' sessions. Which of the following is the most appropriate action for you
to take?
a. You should mention "log off after visit" on the web app
b. You should implement cryptography using OpenSSL
c. You should provide each user a unique static session ID
d. You should encrypt the session ID displayed on the URL
Which of the following best describes VBA?
a. VBA is a hardware network security device
b. VBA is an event-driven programming language
c. VBA is a network assessment tool
d. VBA is a command language interpreter
You are asked to configure your firewall in such a way that the traffic from source
address range 117.112.10.25 through 117.112.15.100 is allowed, while traffic from
117.112.12.25 through 117.112.13.25 is denied, and traffic from 117.112.12.200
through 117.112.13.10 is allowed. How should you configure the firewall?
a. Deny 117.112.12.200 through 117.112.13.10; deny 117.112.12.25 through
117.112.13.25; allow 117.112.10.25 through 117.112.15.100
b. Allow 117.112.12.200 through 117.112.13.10; deny 117.112.12.25 through
117.112.13.25; force-allow 117.112.10.25 through 117.112.15.100
c. Allow 117.112.10.25 through 117.112.15.100; deny 117.112.12.25 through
117.112.13.25; force-allow 117.112.12.200 through 117.112.13.10
d. Allow 117.112.10.25 through 117.112.15.100; deny 117.112.12.25 through
117.112.13.25; allow 117.112.12.200 through 117.112.13.10
Which of the following outlines the process of a proxy server?
a. User - forward proxy - Internet - reverse proxy - server
b. User - internet - reverse proxy - forward proxy - user
c. User - reverse proxy - Internet - forward procy - server
d. User - forward proxy - user - reverse proxy - Internet
Which of the following techniques is the best fit for monitoring traffic on switches with
large volumes of traffic?
a. Signature-based monitoring
b. Port spanning
c. Port mirroring
d. Port TAP
, In an interview, Max was asked to tell one difference between a software firewall and a
virtual firewall. How should Max answer?
a. Software firewalls are locally installed on a device, whereas virtual firewalls run in the
cloud
b. Software firewalls can protect all the endpoints in a network, whereas virtual firewalls
can protect only one device
c. Virtual firewalls are cost-free, whereas software firewalls are paid services
d. Virtual firewalls are used on almost all devices, whereas software firewalls are mostly
used by enterprises
What action does a BPDU guard take when a BPDU is received from an endpoint and
not a switch?
a. The port is disabled, and no traffic will be sent by the port while it can still receive
traffic
b. The port is disabled, and no traffic will be sent or received by the port
c. The port remains active, and no traffic will be received by the port, but it can still send
traffic
d. The port remains active, and the traffic will be forwarded to another port
Which of the following best describes east-west traffic?
a. Movement of data from a router to an enterprise switch
b. Movement of data from an unsecured endpoint to a server outside a data center
c. Movement of data from one server to another within a data center
d. Movement of data from one unsecured endpoint to another
The head of cybersecurity at your enterprise has asked you to set p an IDS that can
create the baseline of all system activities and raise an alarm whenever any abnormal
activities take place, without waiting to check the underlying cause. Which of the
following actions should you take?
a. You should set up an IDS with signature-based monitoring methodology
b. You should set up an IDS with heuristic monitoring methodology
c. You should set up an IDS with behavior-based monitoring methodology
d. You should set up an IDS with anomaly-based monitoring methodology
An employee at your enterprise is caught violating company policies by transferring
confidential data to his private email. As a security admin, you are asked to prevent this
from happening in the future. Which of the following actions should you perform?
a. You should set up a VPN
b. You should set up a DLP
c. You should set up a NAC
d. You should set up an ACL