

Information Security Exam Solutions
Course Introduction
Information Security is a comprehensive course designed to introduce students to the foundational concepts, principles, and practices essential for safeguarding information systems. Covering key areas such as risk assessment, threat identification, cryptography, network security, and regulatory compliance, this course emphasizes the importance of protecting digital assets from unauthorized access, cyberattacks, and data breaches. Students will gain practical experience with security tools and techniques, learn to develop security policies, and understand the ethical and legal considerations in information security management. By the end of the course, students will be equipped to identify vulnerabilities, implement effective security measures, and contribute to the creation of resilient information infrastructures.
Recommended Textbook
Hands On Ethical Hacking and Network Defense 2nd Edition
Available Study Resources on Quizplus
13 Chapters
673 Verified Questions
673 Flashcards
Source URL: https://quizplus.com/study-set/2085

Page 2
by Michael T. Simpson

Chapter 1: Ethical Hacking Overview
Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/41510
Sample Questions
Q1) copies code from knowledgeable programmers instead of creating the code himself/herself
Answer: F
Q2) the tester might get information about which OSs are used, but not get any network diagrams
Answer: H
Q3) In the context of penetration testing, what is the gray box model?
Answer: The gray box model is a hybrid of the white and black box models.In this model,the company gives a tester only partial information.For example,the tester might get information about which OSs are used,but not get any network diagrams.
Q4) Penetration testers and security testers usually have a laptop computer configured with ____ and hacking tools.
A)multiple OSs
B)tiger boxes
C)packet sniffers
D)script kiddies
Answer: A
Q5) composed of people with varied skills who perform penetration tests
Answer: B
To view all questions and flashcards with answers, click on the resource link above. Page 3
Chapter 2: Tcpip Concepts Review
Available Study Resources on Quizplus for this Chatper
57 Verified Questions
57 Flashcards
Source URL: https://quizplus.com/quiz/41511
Sample Questions
Q1) No matter what medium connects computers on a network-copper wires, fiber-optic cables, or a wireless setup-the same protocol must be running on all computers if communication is going to function correctly.
A)True
B)False
Answer: True
Q2) ____ was the standard for moving or copying large files and is still used today, although to a lesser extent because of the popularity of HTTP.
A)FTP
B)TFTP
C)SNMP
D)SMTP
Answer: A
Q3) UDP is an unreliable data delivery protocol. Why is it widely used on the Internet?
Answer: UDP is a widely used protocol on the Internet because of its speed.UDP doesn't need to verify whether the receiver is listening or ready to accept the packets.The sender doesn't care-it just sends,even if the receiver isn't ready to accept the packet.
To view all questions and flashcards with answers, click on the resource link above.

4
Chapter 3: Network and Computer Attacks
Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/41512
Sample Questions
Q1) How does a buffer overflow attack work?
Answer: In a buffer overflow attack,a programmer finds a vulnerability in poorly written code that doesn't check for a defined amount of space use.For example,if a program defines a buffer size of 100 MB (the total amount of memory the program is supposed to use),and the program writes data over the 100 MB mark without triggering an error or preventing this occurrence,you have a buffer overflow.Basically,the attacker writes code that overflows the buffer;this is possible because the buffer capacity hasn't been defined correctly in the program.The trick is to not fill the overflow buffer with meaningless data,but to fill it with executable program code.That way,the OS runs the code,and the attacker's program does something harmful.Usually,the code elevates the attacker's permissions to that of an administrator's level or gives the attacker the same privileges as the program's owner or creator.
Q2) ____ is a remote control program.
A)Slammer
B)BlackIce
C)Symantec pcAnywhere
D)Zone Alarm
Answer: C
To view all questions and flashcards with answers, click on the resource link above.

Page 5

Chapter 4: Footprinting and Social Engineering
Available Study Resources on Quizplus for this Chatper
51 Verified Questions
51 Flashcards
Source URL: https://quizplus.com/quiz/41513
Sample Questions
Q1) ____ is a tool that is used to gather IP and domain information.
A)Whois
B)Netcat
C)Metis
D)Dig
Q2) A(n) ____________________ is a person skilled at reading what users enter on their keyboards, especially logon names and passwords.
Q3) ____ is the most basic HTTP method.
A)GET
B)PUT
C)CONNECT
D)HEAD
Q4) Namedroppers is a tool that can be used to capture Web server information and possible vulnerabilities in a Web site's pages that could allow exploits such as SQL injection and buffer overflows.
A)True
B)False
Q5) What is "competitive intelligence"?
Q6) What is the purpose of a Web bug? How do they relate to or differ from spyware?
Page 6
To view all questions and flashcards with answers, click on the resource link above.

Chapter 5: Port Scanning
Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/41514
Sample Questions
Q1) does not allow entry or access to a service
A)Nmap
B)pcAnywhere
C)XMAS scan
D)connect scan
E)closed port
F)ACK scan
G)filtered port
H)open port
I)NULL scan
Q2) If subnetting is used in an organization, you can include the broadcast address by mistake when performing ping sweeps. How might this happen?
Q3) ____ was developed to assist security testers in conducting tests on large networks and to consolidate many of the tools needed for large-scale endeavors.
A)Unicornscan
B)NetScanTools
C)Nessus
D)Nmap
Q4) What makes the OpenVAS tool unique?
To view all questions and flashcards with answers, click on the resource link above. Page 7

Chapter 6: Enumeration
Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/41515
Sample Questions
Q1) ____ is an enhancement to NDS (NetWare Directory Services).
A)Active Directory
B)Bindery
C)X.500
D)eDirectory
Q2) more stable than its predecessor, with an improved file system (FAT32)
A)Windows 98
B)Windows 95
C)Windows Server 2003
D)Fedora Linux
E)Solaris
F)Windows XP Professional
G)Novell Open Enterprise Server
H)Windows 2000 Server/Professional
I)Windows NT 3.51 Server/Workstation
Q3) Windows 95 uses the ____ file system.
A)FAT16
B)FAT32
C)NTFS
D)ext3
To view all questions and flashcards with answers, click on the resource link above. Page 8

Chapter 7: Programming for Security Professionals
Available Study Resources on Quizplus for this Chatper
53 Verified Questions
53 Flashcards
Source URL: https://quizplus.com/quiz/41516
Sample Questions
Q1) How is branching performed in Perl?
Q2) English-like language you can use to help create the structure of your program
A)pseudocode
B)conversion specifier
C)class
D)bug
E)variable
F)do loop
G)compiler
H)while loop
I)gcc
Q3) You must always add "//" at the end of comment text in C.
A)True
B)False
Q4) UNIX was first written in assembly language, soon rewritten in ____.
A)Smalltalk
B)Perl
C)Python
D)C
Q5) Mention three C compilers and on which operating systems they are available.
Page 9
To view all questions and flashcards with answers, click on the resource link above.

Chapter 8: Desktop and Server Os Vulnerabilities
Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/41517
Sample Questions
Q1) to harden Microsoft systems, you should rename this account
A)antivirus software
B)port 389
C)Guest
D)port 53
E)port 443
F)port 80
G)unused services
H)Administrator
I)blank
Q2) In Windows Server 2003 and 2008, how does a domain controller locate resources in a domain?
Q3) You can use _____________________________________________ information when testing Linux computers for known vulnerabilities.
Q4) What is the Common Internet File System (CIFS) protocol?
Q5) To perform MBSA-style scans you can run the tool from the command line by using ____________________.exe.
Q6) What should a password policy include?
Q7) What can a security tester using enumeration tools do?
To view all questions and flashcards with answers, click on the resource link above. Page 10

Chapter 9: Embedded Operating Systems: The Hidden Threat
Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/41518
Sample Questions
Q1) Embedded systems include their own operating system, called a(n) "_________________________".
Q2) What types of systems use VxWorks?
Q3) Which of the following could be considered the biggest security threat for an organization?
A)spyware
B)employees
C)kernels
D)routers
Q4) QNX, from QNX Software Systems, is a commercial
Q5) Many viruses, worms, Trojans, and other attack vectors take advantage of ____code.
A)shortened
B)shared
C)modified
D)cache
Q7) List at least four best practices for protecting embedded OSs. Page 11
Q6) Many hackers today want more than just notoriety. What are they looking for and how do they accomplish it?
To view all questions and flashcards with answers, click on the resource link above. Page 12

Chapter 10: Hacking Web Servers
Available Study Resources on Quizplus for this Chatper
52 Verified Questions
52 Flashcards
Source URL: https://quizplus.com/quiz/41519
Sample Questions
Q1) The ____ Search page is an excellent starting point when investigating VBScript vulnerabilities.
A)CVE Web site
B)CERT
C)Microsoft Security Bulletin
D)Macromedia security
Q2) What can an attacker do after gaining control of a Web server?
Q3) CFML stands for ______________________________.
Q4) All CFML tags begin with "____".
A)(?)
B)CF
C)CFML
D)%
Q5) In Windows, IIS stands for ______________________________.
Q6) Web applications written in CFML can also contain other client-side technologies, such as HTML and JavaScript.
A)True
B)False
Q7) Why should security professionals have at least a little knowledge about the Apache Web Server?
To view all questions and flashcards with answers, click on the resource link above. Page 13
Chapter 11: Hacking Wireless Networks
Available Study Resources on Quizplus for this Chatper
52 Verified Questions
52 Flashcards
Source URL: https://quizplus.com/quiz/41520
Sample Questions
Q1) The 802.11 standard applies to the Physical layer of the OSI model, which deals with wireless connectivity issues of fixed, portable, and moving stations in a local area, and the Media Access Control (MAC) sublayer of the ____.
A)Network Link layer
B)Data Link layer
C)transport layer
D)session layer
Q2) The ____ standard can achieve a throughput of 54 Mbps.
A)802.11b
B)802.11e
C)802.11g
D)802.11i
Q3) What is WEP? Is it a good way to secure wireless networks?
Q4) What is the role of a WNIC?
Q5) Wireless routers are designed so that they do not interfere with wireless telephones. A)True
B)False
Q6) WEP stands for _________________________.
Q7) What is wardriving?

14
To view all questions and flashcards with answers, click on the resource link above.

Chapter 12: Cryptography
Available Study Resources on Quizplus for this Chatper
58 Verified Questions
58 Flashcards
Source URL: https://quizplus.com/quiz/41521
Sample Questions
Q1) ____ refers to verifying the sender or receiver (or both) is who he or she claims to be.
A)Authentication
B)Nonrepudiation
C)Availability
D)Authorization
Q2) occurs if two different messages produce the same hash value
A)asymmetric encryption
B)collision free
C)symmetric encryption
D)certificate
E)hashing
F)collision
G)stream cipher
H)message digest
I)block cipher
Q3) What is the difference between a public key and a private key?
Q4) What is a one-way function? Provide an example or an analogy to help explain the concept.
Q5) How does public key infrastructure work?
To view all questions and flashcards with answers, click on the resource link above. Page 15

Chapter 13: Network Protection Systems
Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/41522
Sample Questions
Q1) ____, written in C for *nix platforms, is an open-source virtual honeypot created and maintained by Niels Provos.
A)Decoy Server
B)NetBait
C)Tiny Honeypot
D)Honeyd
Q2) also called privileged mode
A)stateful packet filter
B)firewall
C)NAT
D)DMZ
E)stateless packet filter
F)user mode
G)enable mode
H)ASA
I)privileged mode
Q3) A standard IP access list is restricted to source IP addresses.
A)True
B)False
Q4) What are the interfaces in a Cisco router?
To view all questions and flashcards with answers, click on the resource link above. Page 16