Search Header Logo

SEC +

Authored by R D

Professional Development

Professional Development

SEC +
AI

AI Actions

Add similar questions

Adjust reading levels

Convert to real-world scenario

Translate activity

More...

    Content View

    Student View

26 questions

Show all answers

1.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

A user is attempting to navigate to a website from inside the company network using a desktop. When the user types in the URL, https://www.site.com, the user is presented with a certificate mismatch warning from the browser. The user does not receive a warning when visiting http://www.anothersite.com. Which of the following describes this attack?

On-path

Domain hijacking

DNS poisoning

Evil twin

Answer explanation

The scenario describes a situation where the user is presented with a certificate mismatch warning when trying to access a website using HTTPS. This could indicate that the DNS resolution for the website has been manipulated, leading to the user being redirected to a different IP address or server controlled by an attacker. This type of attack is known as DNS poisoning, where the attacker maliciously modifies the DNS records to redirect users to fraudulent or malicious websites.

2.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Which of the following tools is effective in preventing a user from accessing unauthorized removable media?

USB data blocker

Faraday cage

Proximity reader

Cable Lock

3.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

A Chief Security Officer is looking for a solution that can provide increased scalability and flexibility for back-end infrastructure, allowing it to be updated and modified without disruption to services. The security architect would like the solution selected to reduce the back-end server resources and has highlighted that session persistence is not important for the applications running on the back-end servers. Which of the following would BEST meet the requirements?

Reverse proxy

Automated patch management

Snapshots

NIC teaming

4.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Which of the following describes a social engineering technique that seeks to exploit a person's sense of urgency?

A phishing email stating a cash settlement has been awarded but will expire soon.

A smishing message stating a package is scheduled for pickup.

A vishing call that requests a donation be made to a local charity.

A SPIM notification claiming to be undercover law enforcement investigating a cybercrime.

Answer explanation

The social engineering technique that seeks to exploit a person's sense of urgency is described in option A. By stating that a cash settlement has been awarded but will expire soon, the attacker creates a sense of urgency and tries to manipulate the recipient into taking immediate action without thoroughly considering the authenticity or legitimacy of the email. This technique aims to pressure the target into making a hasty decision or divulging sensitive information.

5.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

A company is providing security awareness training regarding the importance of not forwarding social media messages from unverified sources. Which of the following risks would this training help to prevent?

Hoaxes

SPIMs

Identify fraud

Credential harvesting

6.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

security analyst is reviewing application logs to determine the source of a breach and locates the following log: https://www.comptia.com/login.php?id='%20or%20'1'1='1


Which
of the following has been observed?

SQLi

XSS

7.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

An audit identified PII being utilized in the development environment of a critical application. The Chief Privacy Officer (CPO) is adamant that this data must be removed; however, the developers are concerned that without real data they cannot perform functionality tests and search for specific data. Which of the following should a security professional implement to BEST satisfy both the CPO's and the development team's requirements?

Data anonymization

Data encryption

Data masking

Data tokenization

Access all questions and much more by creating a free account

Create resources

Host any resource

Get auto-graded reports

Google

Continue with Google

Email

Continue with Email

Classlink

Continue with Classlink

Clever

Continue with Clever

or continue with

Microsoft

Microsoft

Apple

Apple

Others

Others

Already have an account?