Practice

General Security Concepts

Name what a control does (prevent, detect, correct, deter) and who carries it out. For keys: sign with your private key, encrypt with the reader's public key.

A lesson for this domain

Question 1Objective 1.1

A data center posts a security guard at the entrance who checks every visitor's badge. Which control category does the guard belong to?

Question 2Objective 1.1

A sign on a fence reads: "Restricted area. Trespassers will be prosecuted." What control type is the sign?

Question 3Objective 1.1

An intrusion detection system alerts the security team when it sees a known exploit signature, but it does not block the traffic. Which control type is it?

Question 4Objective 1.1

A legacy controller cannot be patched because the vendor no longer exists. The team places it on an isolated VLAN with strict access rules. What is the VLAN acting as?

Question 5Objective 1.1

After a VPN session ends, the server records the user name, the session length and the data transferred. Which part of AAA is this?

Question 6Objective 1.1

A manager approves a payment by signing it with her private key. Later she claims she never approved it. Which property lets the company show that she did?

Question 7Objective 1.1

In a Zero Trust design, which component evaluates each access request against policy and decides whether to allow it?

Question 8Objective 1.1

A help desk analyst needs to reset user passwords but nothing else in the directory. What should the analyst be given?

Question 9Objective 1.2

A change request to upgrade the email server must describe how to return to the previous version if the upgrade fails. What is this part of the request called?

Question 10Objective 1.2

Which group reviews proposed changes, weighs their risk and approves or rejects them before they are scheduled?

Question 11Objective 1.2

An online store schedules a database patch for 02:00 to 04:00 on Sunday, when traffic is lowest. What has the team chosen?

Question 12Objective 1.2

A team plans to restart a database service to apply a patch. Which step most directly prevents an unexpected outage of the applications that use that database?

Question 13Objective 1.2

An administrator edits a firewall configuration file. Which practice lets the team see exactly what changed and restore an earlier version?

Question 14Objective 1.3

Alice wants to sign a document so that anyone can verify it came from her. Which key does she use to create the signature?

Question 15Objective 1.3

Alice wants to send Bob a file that only Bob can read, using asymmetric encryption. Which key encrypts the file?

Question 16Objective 1.3

Two users choose the same password, but their stored password hashes are different. What explains this?

Question 17Objective 1.3

A browser checks whether a website's certificate has been revoked by sending a query about that one certificate and getting a signed good or revoked answer. Which mechanism is it using?

Question 18Objective 1.3

A company needs one certificate that covers www.example.com, shop.example.com and mail.example.com. Which certificate fits best?

Question 19Objective 1.3

Company laptops are often left in taxis. Which control best protects the data on a lost laptop's drive?

Question 20Objective 1.3

A vendor lists a download's SHA-256 value on its own HTTPS website. The SHA-256 of the file you downloaded matches it. What does the match show?

Question 21Objective 1.3

TLS uses asymmetric cryptography during the handshake and then switches to symmetric encryption for the session. Why switch?