Comptia Security+ Practice Exam (1)
100 Questions I 5927 Attempts I Created By mastermind1100 1499 days ago Comptia Security+ Practice Exam- 1
Full length Comptia Security+ Practice Exam. Take this exam like the real exam to see if you are completely prepared for the real exam. Time yourself to 90 minutes to get a feel of the pressures of the real exam. The practice test is designed to reflect the final exam.
Full length Comptia Security+ Practice Exam. Take this exam like the real exam to see if you are completely prepared for the real exam. Time yourself to 90 minutes to get a feel of the pressures of the real exam. The practice test is designed to reflect the final exam.
Question Excerpt From Comptia Security+ Practice Exam (1)
| Q.1) | Which of the Following is an item most likely to be addressed in an Acceptable Use Policy |
| A. |
| B. |
| C. |
| D. |
| E. |
| Q.2) | Covert channel is a communication channel that can be used for: |
| A. |
| B. |
| C. |
| D. |
| Q.3) | Enforcing minimum privileges for general system users can be easily achieved through the use of: |
| A. |
| B. |
| C. |
| D. |
| Q.4) | Which of the following services should be logged for security purpose? |
| A. |
| B. |
| C. |
| D. |
| E. |
| Q.5) | All logs are kept on archive for a period of time. What determines this period of time? |
| A. |
| B. |
| C. |
| D. |
| E. |
| Q.6) | With RBAC, roles are: |
| A. |
| B. |
| C. |
| D. |
| E. |
| Q.7) | With _______________, access decisions are based on the roles that individual users have as part of an organization. |
| A. |
| B. |
| C. |
| D. |
| E. |
| Q.8) | Which of the following is a feature of the Rule based access control? |
| A. |
| B. |
| C. |
| D. |
| Q.9) | A firewall can be classified as a: |
| A. |
| B. |
| C. |
| D. |
| E. |
| Q.10) | In the Lattice Based Access Control model, controls are applied to: |
| A. |
| B. |
| C. |
| D. |
| E. |
| Q.11) | With Discretionary access controls, who determines who has access and what privilege they have? |
| A. |
| B. |
| C. |
| D. |
| E. |
| Q.12) | Under MAC, which of the following is true? |
| A. |
| B. |
| C. |
| D. |
| E. |
| Q.13) | Under MAC, a clearance is a |
| A. |
| B. |
| C. |
| D. |
| Q.14) | Access controls that are not based on the policy are characterized as: |
| A. |
| B. |
| C. |
| D. |
| E. |
| Q.15) | DAC are characterized by many organizations as: |
| A. |
| B. |
| C. |
| D. |
| E. |
| Q.16) | A password represents: |
| A. |
| B. |
| C. |
| D. |
| E. |
| Q.17) | A smartcard represents: |
| A. |
| B. |
| C. |
| D. |
| E. |
| Q.18) | Which of the following is NOT a good password deployment guideline? |
| A. |
| B. |
| C. |
| D. |
| E. |
| Q.19) | Which of the following is an effective measure against a certain type of brute force password attack? |
| A. |
| B. |
| C. |
| D. |
| E. |
| Q.20) | What type of attacks occurs when a rogue application has been planted on an unsuspecting user's workstation? |
| A. |
| B. |
| C. |
| D. |
| E. |
| Q.21) | Which of the following attacks could be the most successful when the security technology is properly implemented and configured? |
| A. |
| B. |
| C. |
| D. |
| E. |
| Q.22) | What is a protocol used for carrying authentication, authorization, and configuration information between a Network Access Server and a shared Authentication Server? |
| A. |
| B. |
| C. |
| D. |
| E. |
| Q.23) | In a RADIUS architecture, which of the following acts as a client? |
| A. |
| B. |
| C. |
| D. |
| E. |
| Q.24) | The majority of commercial intrusion detection systems are: |
| A. |
| B. |
| C. |
| D. |
| Q.25) | Which of the following is a drawback of Network-based IDSs? |
| A. |
| B. |
| C. |
| D. |
| E. |
| Q.26) | Which of the following will you consider as clear-text protocols? |
| A. |
| B. |
| C. |
| D. |
| E. |
| Q.27) | Microsoft supports the _______________ and ______standards for use in extranet. |
| A. |
| B. |
| C. |
| D. |
| E. |
| Q.28) | Which of the following protocols did Microsoft develop for use in VPNs? |
| A. |
| B. |
| C. |
| D. |
| E. |
| Q.29) | To allow your Windows clients to connect to your Windows NT Server using the public network as a medium, what technology might you find useful? |
| A. |
| B. |
| C. |
| D. |
| E. |
| Q.30) | What technology involves the use of electronic wallet? |
| A. |
| B. |
| C. |
| D. |
| E. |
| Q.31) | With Java, what can be embedded in a web browser, allowing programs to be executed as they are downloaded from the World Wide Web? |
| A. |
| B. |
| C. |
| D. |
| E. |
| Q.32) | ActiveX controls can be digitally signed using a technology called: |
| A. |
| B. |
| C. |
| D. |
| E. |
| Q.33) | A centralized database of remote users for a multi-site network typically uses |
| A. |
| B. |
| C. |
| D. |
| Q.34) | Which of the following is more of an irritation than a security threat? |
| A. |
| B. |
| C. |
| D. |
| Q.35) | Creating a basic standard for application settings, security settings, and active services on every company laptop would be considered |
| A. |
| B. |
| C. |
| D. |
| Q.36) | All of the following are correct about LDAP EXCEPT: |
| A. |
| B. |
| C. |
| D. |
| Q.37) | Least privilege is defined as giving access to information: |
| A. |
| B. |
| C. |
| D. |
| E. |
| Q.38) |
An administrator wishes to enable network auditing policies. Which of
the following should the security administrator log? |
| A. |
| B. |
| C. |
| D. |
| Q.39) | From a security perspective a performance baseline is MOST useful for: |
| A. |
| B. |
| C. |
| D. |
| E. |
| Q.40) | A company creates its own application that accesses the company databases and requires a unique login, based on the user’s domain account. The developer has an undocumented login for testing that does not need to be authenticated against the domain. Which of the following is a security issue regarding this scenario? |
| A. |
| B. |
| C. |
| D. |
| Q.41) | In order to perform a TCP hijacking attack, an attacker would be required to: |
| A. |
| B. |
| C. |
| D. |
| Q.42) | A passive response is the most common type of response to a number of intrusions. Which of the following is not a passive response strategy ? |
| A. |
| B. |
| C. |
| D. |
| E. |
| Q.43) | When using network monitoring systems to monitor workstations, which of the following elements should be reviewed because their information could indicate a possible attack ? |
| A. |
| B. |
| C. |
| D. |
| Q.44) | Which if the following technologies would you use if you need to implement a system that simulates a network of vulnerable devices, so that this network can be targeted by attackers ? |
| A. |
| B. |
| C. |
| D. |
| Q.45) | Which of the following intrusion detection technologies work by monitoring the file structure of a system to determine whether any system files were deleted or modified by an attacker ? |
| A. |
| B. |
| C. |
| D. |
| Q.46) | Which of the following is NOT a valid access control mechanism? |
| A. |
| B. |
| C. |
| D. |
| Q.47) | Which of the following best describes an access control mechanism in which access control decisions are based on the responsibilities that an individual user or process has in an organization? |
| A. |
| B. |
| C. |
| D. |
| E. |
| Q.48) | Which of the following best describes an access control mechanism that allows the data owner to create and administer access control? |
| A. |
| B. |
| C. |
| D. |
| Q.49) | Which of the following is an inherent flaw of DAC (Discretionary Access Control)? |
| A. |
| B. |
| C. |
| D. |
| Q.50) | Which of the following access control methods provides the most granular access to protected objects? |
| A. |
| B. |
| C. |
| D. |
| Q.51) | You work as the security administrator at Certkiller .com. You set permissions on a file object in a network operating system which uses DAC (Discretionary Access Control). The ACL (Access Control List) of the file is as follows: Owner: Read, Write, Execute User A: Read, Write, - User B: -, -, - (None) Sales: Read,-, - Marketing: -, Write, - Other Read, Write, - User "A" is the owner of the file. User "B" is a member of the Sales group. What effective permissions does User "B" have on the file? |
| A. |
| B. |
| C. |
| D. |
| E. |
| Q.52) | You work as the security administrator at Certkiller .com. Certkiller has a RBAC (Role Based Access Control) compliant system for which you are planning the security implementation. There are three types of resources including files, printers, and mailboxes and four distinct departments with distinct functions including Sales, Marketing, Management, and Production in the system. Each department needs access to different resources. Each user has a workstation. Which roles should you create to support the RBAC (Role Based Access Control) model? |
| A. |
| B. |
| C. |
| D. |
| Q.53) | With regard to DAC (Discretionary Access Control), which of the following statements are true? |
| A. |
| B. |
| C. |
| D. |
| E. |
| Q.54) | Which of the following are used to make access decisions in a MAC (Mandatory Access Control) environment? |
| A. |
| B. |
| C. |
| D. |
| Q.55) | Which of the following access control methods allows access control decisions to be based on security labels associated with each data item and each user? |
| A. |
| B. |
| C. |
| D. |
| Q.56) | Which of the following access control methods relies on user security clearance and data classification? |
| A. |
| B. |
| C. |
| D. |
| Q.57) | Which of the following is a characteristic of MAC (Mandatory Access Control)? |
| A. |
| B. |
| C. |
| D. |
| Q.58) | Which of the following terms represents a MAC (Mandatory Access Control) model? |
| A. |
| B. |
| C. |
| D. |
| Q.59) | Identify the access control model that makes use of security labels connected to the objects? |
| A. |
| B. |
| C. |
| D. |
| Q.60) | Which of the following is an example of a task-based control model? |
| A. |
| B. |
| C. |
| D. |
| Q.61) | Identify from the list below the access control models that makes use of subject and object labels? |
| A. |
| B. |
| C. |
| D. |
| Q.62) | What is the access control model that explicitly assigns access rights to users? |
| A. |
| B. |
| C. |
| D. |
| Q.63) | Identify the access decisions based on a Mandatory Access Control (MAC) environment? |
| A. |
| B. |
| C. |
| D. |
| Q.64) | What access control model is a Windows file server an example of? |
| A. |
| B. |
| C. |
| D. |
| Q.65) | Which servers should be located on a private network? |
| A. |
| B. |
| C. |
| D. |
| Q.66) | What model assigns sensitivity labels to users and their data? |
| A. |
| B. |
| C. |
| D. |
| E. |
| Q.67) | The Certkiller .com network contains of various departments that makes use of an access control model. The finance department only requires access to the personal data of staff and the marketing department only needs access to the production data. Which access control model is MOST suitable? |
| A. |
| B. |
| C. |
| D. |
| Q.68) | Which access controls are based on security labels assigned to every data item and every user? |
| A. |
| B. |
| C. |
| D. |
| Q.69) | Determine the access control model where users are assigned access rights based on their function within the organization? |
| A. |
| B. |
| C. |
| D. |
| Q.70) | Which of the following password generators is based on challenge-response mechanisms? |
| A. |
| B. |
| C. |
| D. |
| Q.71) | Which of the following password management systems is designed to provide availability for a large number of users? |
| A. |
| B. |
| C. |
| D. |
| Q.72) | Which of the following provides the best protection against an intercepted password? |
| A. |
| B. |
| C. |
| D. |
| Q.73) | Which of the following best describes a challenge-response session? |
| A. |
| B. |
| C. |
| D. |
| Q.74) | Which of the following must be deployed for Kerberos to function correctly? |
| A. |
| B. |
| C. |
| D. |
| Q.75) | Why are clocks used in a Kerberos authentication system? |
| A. |
| B. |
| C. |
| D. |
| Q.76) | Which of the following factors must be considered when implementing Kerberos authentication? |
| A. |
| B. |
| C. |
| D. |
| Q.77) | You work as the security administrator at Certkiller .com. You want to ensure that only encrypted passwords are used during authentication. Which authentication protocol should you use? |
| A. |
| B. |
| C. |
| D. |
| Q.78) | Which of the following are the main components of a Kerberos server? |
| A. |
| B. |
| C. |
| D. |
| Q.79) | When does CHAP (Challenge Handshake Authentication Protocol) perform the handshake process? |
| A. |
| B. |
| C. |
| D. |
| Q.80) | For which of the following can biometrics be used? |
| A. |
| B. |
| C. |
| D. |
| Q.81) | Which of the following is the most costly method of an authentication? |
| A. |
| B. |
| C. |
| D. |
| Q.82) | Which of the following provides the strongest form of authentication? |
| A. |
| B. |
| C. |
| D. |
| Q.83) | Identify the different types of certificate-based authentication? (Choose TWO) |
| A. |
| B. |
| C. |
| D. |
| Q.84) | Which services is provided by message authentication codes? |
| A. |
| B. |
| C. |
| D. |
| Q.85) | When an attacker captures part of a communication and later sends the communication segment to the server whilst pretending to be the user it is known as a: |
| A. |
| B. |
| C. |
| D. |
| Q.86) | Why would reusing a ticket as a replay attack in Kerberos not be successful? |
| A. |
| B. |
| C. |
| D. |
| Q.87) | Identify the authentication system where a unique username and password is used to access multiple systems within a company? |
| A. |
| B. |
| C. |
| D. |
| Q.88) | Identify the method that should be used to ensure that the user is able to authenticate to the server and the server to the user? |
| A. |
| B. |
| C. |
| D. |
| Q.89) | Identify the process where users can access numerous resources without needing multiple credentials? |
| A. |
| B. |
| C. |
| D. |
| Q.90) | Determine the two-factor authentication for an information system? |
| A. |
| B. |
| C. |
| D. |
| Q.91) | What is based upon an authentication server that allocates tickets to users? |
| A. |
| B. |
| C. |
| D. |
| Q.92) | Which authentication will provide a username, a password and undergo a thumb print scan to access a workstation? |
| A. |
| B. |
| C. |
| D. |
| Q.93) | Determine the authentication mechanisms that use key fob based identification systems? (Choose TWO) |
| A. |
| B. |
| C. |
| D. |
| E. |
| Q.94) | You deploy a biometric authentication system in the Certkiller .com environment. Identify the tool that is reliable with the lowest cross over problem rate? |
| A. |
| B. |
| C. |
| D. |
| Q.95) | Certkiller .com deploy Kerberos authentication on the network. What does Kerberos need to function properly? (Choose TWO) |
| A. |
| B. |
| C. |
| D. |
| E. |
| Q.96) | What authentication model uses a smart card and a User ID/Password for accessing network resources? |
| A. |
| B. |
| C. |
| D. |
| Q.97) | Which of the following represents the best method for securing a web browser? |
| A. |
| B. |
| C. |
| D. |
| Q.98) | How many ports in TCP/IP (Transmission Control Protocol/Internet Protocol) are vulnerable to being scanned, exploited, or attached? |
| A. |
| B. |
| C. |
| D. |
| Q.99) | Which of the following ports does a DNS (Domain Name Service) server require? |
| A. |
| B. |
| C. |
| D. |
| Q.100) | Why are non-essential services appealing to attackers? (Choose TWO) |
| A. |
| B. |
| C. |
| D. |
| E. |
Take this quiz by clicking Start button on top.
Quiz Comments (5)
I'm Interested in knowing why the quiz was rated low. The
question poised are actual question you would be asked in
the security + Test. If you find any question questionable
or incorrect Feel free to leave a comment and I'll fix or
provide that actual references that prove the answer correctposted by:mastermind1100 1470 days ago
I believe there were a few errors... I stopped at the
question about maintaining password security against brute
force attacks... i think it was around 8 or so. The
"correct" answer was listed something like "using non
dictionary..." dictionary or not (has no effect on a brute
force attack, only in conjunction with a dictionary attack
would this be true the best answer here is none of the
above), none of the answers provided an applicable answer to
this question IMO, to make the question valid there should
be a "Use a combination of letters numbers and special
characters(unless you are using windows then you might as
well have no password)" There was at least one other that I
remember either not being an applicable sec+ question or
containing misinformation about the question or answer.posted by:jerror 1458 days ago
Q.9) Certkiller .com deploy Kerberos authentication on the
network. What does Kerberos need to function properly?
(Choose TWO)
A.Kerberos requires a Key Distribution Center. (your
answer)
B.Kerberos requires POP-3. (missed)
C.Kerberos requires extranets.
D.Kerberos requires accurate network time.
E.Kerberos requires SSL/TLS. (your answer)
Correct answer are: A, E as Kerberos requires central data
management by KDC (Key distribution Center) not POP3 for
email client, go to Q.14 that one is corrected one, its
answer is C.
Also
Q.99) Which if the following technologies would you use if
you need to implement a system that simulates a network of
vulnerable devices, so that this network can be targeted by
attackers ?
A.A circuit-level firewall
B.A honey pot(your answer)
C.A IDS
D.A system integrity verifier
That question answer I believe is: Honeynet (it traps
attackers on false network) but Honeypot allows an
administrator a chance to observe an attack on the network.
Q.14)Answer A repeated from the questionQ.14) Which of the
following factors must be considered when implementing
Kerberos authentication?)
Q.21)Which of the following is more of an irritation than a
security threat? Answer B and D repeatedposted by:Guest 1248 days ago
Please login to post comments.
After login, we will forward you back to this quiz.
Related Topics
More Quizzes by mastermind1100
- Comptia Security+ Practice Exam (2)
- Comptia Security+ Practice Exam (3)
- CEH and Countermeasures v7 Version 4.2
- Checkpoint CCSA R70.1

