Final Questions & Practice Exam | Latest
2025/2026 Exam Prep
Deploy one firewall - correct answerYou need to connect your LAN to the Internet. The
configuration needs to include a perimeter network. You need to keep hardware
requirements to a minimum. What should you do?
1) maintain appropriate humidity levels 2) provide an appropriate ambient temperature -
correct answerYou are determining environmental control requirements for a data
center that will contain several computers. What is the role of an HVAC system in this
environment?
Use RAID - correct answerYou need to ensure that a critical server has minimal down
time. You need to ensure data fault tolerance for the server. What should you do?
Deploy a honeypot in the perimeter network - correct answerYou suspect that someone
is trying to gather information about your network. Your network is isolated from from
the Internet by a perimeter network. You need to gather as much information about the
attacker as possible. You want to prevent the attacker from knowing that the attempt
has been detected. What should you do?
1) configure personal software firewalls on all computers 2) install Antivirus software on
all network computers - correct answerWhat is the best way to prepare a network to
prevent a virus infection from spreading?
Enable windows automatic updates - correct answerYou are configuring a computer
running windows server 2008 r for use as a network file server. You want to ensure that
the most recent hot fixes have been applied to the computer. You want to minimize the
effort necessary to maintain the solution. What should you do?
It lets you minimize the attack surface relating to the application. - correct answerWhat
is the advantage of using application virtualization?
Download the updates to a central server on your network and redistribute updates to
network computers. - correct answerAll computers on your network are configured for
automatic updates. You need to be able to control deployment to prevent compatibility
problems. The solution should not compromise operating system security. What should
you do?
1)Rename the local default accounts 2) require strong passwords - correct answerYour
network had servers that are configured as member servers in a Windows Active
,Directory domain. You need to minimize the risk of unauthorized persons logging on
locally to the servers. The solution should have minimal impact on local management
and administration and should not limit administrator acces. What should you do?
MAC - correct answerYou are designing a secure application environment. You need to
ensure that data is kept as secure as possible. You need to select the strictest access
control model. What access control model should you use?
1) place users in OUs based on organizational roles. 2) assign users membership to
security groups based on organizational roles. - correct answerYour network is
configured as a Windows Active Directory Domains. Configure user acces to file folders
that are shared to the network. Directory access is dependent upon a user's role in the
organization. You need to keep the administrative overhead needed to manage access
security to a minimum; be able to quickly modify a user's permissions and be able to
assign a user more than one role. What should you do?
Weak encryption - correct answerPotential risk associated with WEP when used with
WLAN?
1) AES 2)TKIP - correct answer802.11i standard specifies support for which encryption
algorithm?
Implement a key escrow arrangement. - correct answerYou have deployed PKI within
your ogranization. To meet legal requirements, you need to implement a way to provide
decryption keys to a third party on an as-needed basis. What should you do?
1) RA 2) CFL - correct answerWhich component of PKI is necessary for a CA to know
whether to accept or reject certificates from another CA?
1) to ensure that clients are compliant before allowing network access. 2) to provide
automatic remediation for unsecured computers - correct answerWhen would you
implement NAC?
Protocol Analyzer - correct answerYou suspect that an attacker is sending damaged
packets into your network as a way to compromise your firewall. You need to collect as
much information about the attacker as possible. What should you do?
Configure a VLAN - correct answerYour organization has two groups that work with
confidential projects. Membership in these group changes as project requirements
change. For each group, access to and communications with the computers of the other
users in the group must be managed. You need to be able to quickly reconfigure your
network to control security and bandwidth usage between computers; be able to
reconfigure the network quickly without having to physically relocate or reroute cables at
the network patch panel. What should you do?
,Use file servers attached to an NAS system. Lock file servers and NAS in a secure
area. - correct answerWays to protect data on your network. You should- provide easy
backup, minimize risk of physical data theft, minimize the impact of failure of any one
file server. What solution should you use?
Comparing network activity to an established baseline - correct answerHow do anomaly
- based monitoring methodologies identify potential incidents?
Comparing network activity to am established baseline. - correct answerHow do
anomaly - based monitoring methodologies identify potential incidents?
Which of the following defines the difference, if any between a Trojan horse and a
worm?
A. worms self-replicate but Trojan horses do not
B. Trojan horses are malicious attacks, worms are not
C. There is no difference, the two are the same
D. Worms are sent via e-mail, Trojan horses are not - correct answerA. worms self-
replicate but Trojan horses do not
You are the network administrator for your organization. You decide to implement
whitelisting, blacklisting, and the closing of open relays. Which of the following threats
are you attempting to mitigate?
A. spam
B. spyware
C. viruses
D. worms - correct answerA. spam
You are reviewing the logs of a host-based IDS. They show that a computer has been
compromised by a botnet and is communicating with a master server. If you need to
power the computer off, which of the following types of data will be unavailable?
A. memory, system processes, and network processes
B. system disk, e-mail, and log files
C. swap files, system processes, and master boot record
D. memory, archival storage, and temporary files - correct answerA. memory, system
processes, and network processes
What are kernel-level rootkits designed to do to a computer?
A. make a computer susceptible to pop-ups
B. extract confidential information
C. read the BIOS file
D. crack the user's password - correct answerB. extract confidential information
E-mail servers can be maliciously exploited in many ways, for example spoofing e-mail
messages. Which of the following is a common component that attackers would use to
spoof e-mails?
A. logic bomb
, B. session hijacking
C. open relay
D. web proxy - correct answerC. open relay
You are the network security manager for your company. You recently audited a server
and found that a user logged in to the server with a regular account, executed a
program, and performed activities that should be available only to an administrator.
What type of attack does this describe?
A. brute force
B. privilege escalation
C. Trojan horse
D. backdoor - correct answerB. privilege escalation
Malware can use virtualization techniques. Why would this be difficult to detect?
A. the malware might be using a Trojan
B. the malware could be running a more privileged level than the computer's antivirus
software
C. the malware might be running in the command-line
D. a portion of the malware might have already been removed by an IDS - correct
answerB. the malware could be running a more privileged level than the computer's
antivirus software
Which of the following should be performed on a computer to protect the OS from
malicious software?
A. disable unused services
B. update HIPS signatures
C. update NIDS signatures
D. install a perimeter firewall - correct answerA. disable unused services
Which of the following best describes a backdoor?
A. code inserted into software that initiates one of several types of functions when
specific criteria are met
B. computer programs used to bypass normal authentication or other security
mechanisms in place
C. a platonic extra added to an operating system
D. a group of compromised computers - correct answerB. computer programs used to
bypass normal authentication or other security mechanisms in place
Which of the following security threats can be updated remotely from a command
center?
A. worm
B. spam
C. zombie
D. virus - correct answerC. zombie
Which of the following is a common symptom of spyware?