Questions
Something you know and something you have are authentication:
- Passwords
- Factors
- Credentials
- Identities
Drawbacks of Web application firewall technology include:
- Detection of some attacks
- Configuration and performance
- Flexible policy enforcement
- Specialized security knowledge
Authentication and session management are security concerns of which programming language?
- C
- Java
- .NET
- Managed Code
In the OSI reference model, on which layer can a telephone number be described?
- Layer1, as a telephone number represents a series of electrical impulses
- Layer 3, because a telephone number describes communication between different networks
- This depends on the nature of the telephony system (for instance, Voice-over-IP versus public switched telephony network (PSTN))
- None, as the telephone system is a circuit-based network and the OSI system only describes packet-switched networks
In which of the following situations is the network itself not a target of attack?
- A denial-of-service attack on servers on a network
- Hacking into a router
- A virus outbreak saturating network capacity
- A man-in-the-middle attack
What is the optimal placement for network-based intrusion detection systems (NIDSs)?
- On the network perimeter, to alert the network administrator of all attack attempts
- On network segments with business-critical systems
- At the network operations center (NOC)
- At an external service provider
Which of the following is an advantage of fiber-optic over copper cables from a security perspective?
- Fiber optics provides higher bandwidth.
- Fiber optics are more difficult to wiretap.
- Fiber optics are immune to wiretap.
- None — the two are equivalent; network security is independent from the physical layer.
Which of the following configurations of a WLAN's SSID offers adequate security protection?
- Using an obscure SSID to confuse and distract an attacker
- Not using any SSID at all to prevent an attacker from connecting to the network
- Not broadcasting an SSID to make it harder to detect the WLAN
- None of the above
Which of the following is the principal security risk of broadband Internet access proliferation for home users?
- Users using peer-to-peer file-sharing networks for breaches of intellectual property
- PCs connected permanently to the Internet are prone to receive more spam mails, thereby increasing the risk for the user to become infected with viruses and Trojans.
- PCs will become infected with dialers on DSL lines (run over telephony lines), thereby exposing the user to almost limitless financial risk
- Home computers that are not securely configured or maintained and are permanently connected to the Internet become easy prey for attackers
Which of the following is the principal weakness of DNS (Domain Name System)?
- Lack of authentication of servers, and thereby authenticity of records
- Its latency, which enables insertion of records between the time when a record has expired and when it is refreshed
- The fact that it is a simple, distributed, hierarchical database instead of a singular, relational one, thereby giving rise to the possibility of inconsistencies going undetected for a certain amount of time
- The fact that addresses in e-mail can be spoofed without checking their validity in DNS, caused by the fact that DNS addresses are not digitally signed
It is important to create detailed security configuration instructions for end users because:
- All configuration information should be documented
- The end users are not normally a part of the process.
- Configuration decisions have security implications.
- Documentation should be placed under secure version control
Orally obtaining a password from an employee is the result of:
- Social engineering
- Weak authentication controls
- Ticket-granting server authorization
- Voice recognition software
Which function would be most compatible with the security function?
- Data entry
- Database administration
- Change management
- Network management
A potential vulnerability of the Kerberos authentication server is:
- Single point of failure
- Asymmetric key compromise
- Use of dynamic passwords
- Limited lifetimes for authentication credentials
Setting clear security roles has the following benefits except:
- Establishes personal accountability
- Enables continuous improvement
- Reduces cross-training requirements
- Reduces departmental turf battles
Which of the following requires that a user or process be granted access to only those resources necessary to perform assigned functions.
- Discretionary access control
- Separation of duties
- Least privilege
- Rotation of duties
In mandatory access control, the system controls access and the owner determines:
- Validation
- Need to know
- Consensus
- Verification
Which is a fundamental disadvantage of biometrics?
- Revoking credentials
- Encryption
- Communications
- Placement
A disadvantage of single sign-on is:
- Consistent time-out enforcement across platforms
- A compromised password exposes all authorized resources
- Use of multiple passwords to remember
- Password change control
Availability makes information accessible by protecting from each of the following except:
- Denial of services
- Fires, floods, and hurricanes
- Unreadable backup tapes
- Unauthorized transactions