Skip to main content

Information Security Exam Solutions - 673 Verified Questions

Page 1


Information Security Exam Solutions

Course Introduction

Information Security is a comprehensive course designed to introduce students to the foundational concepts, principles, and practices essential for safeguarding information systems. Covering key areas such as risk assessment, threat identification, cryptography, network security, and regulatory compliance, this course emphasizes the importance of protecting digital assets from unauthorized access, cyberattacks, and data breaches. Students will gain practical experience with security tools and techniques, learn to develop security policies, and understand the ethical and legal considerations in information security management. By the end of the course, students will be equipped to identify vulnerabilities, implement effective security measures, and contribute to the creation of resilient information infrastructures.

Recommended Textbook

Hands On Ethical Hacking and Network Defense 2nd Edition

Available Study Resources on Quizplus

13 Chapters

673 Verified Questions

673 Flashcards

Source URL: https://quizplus.com/study-set/2085

Page 2

by Michael T. Simpson

Chapter 1: Ethical Hacking Overview

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/41510

Sample Questions

Q1) copies code from knowledgeable programmers instead of creating the code himself/herself

Answer: F

Q2) the tester might get information about which OSs are used, but not get any network diagrams

Answer: H

Q3) In the context of penetration testing, what is the gray box model?

Answer: The gray box model is a hybrid of the white and black box models.In this model,the company gives a tester only partial information.For example,the tester might get information about which OSs are used,but not get any network diagrams.

Q4) Penetration testers and security testers usually have a laptop computer configured with ____ and hacking tools.

A)multiple OSs

B)tiger boxes

C)packet sniffers

D)script kiddies

Answer: A

Q5) composed of people with varied skills who perform penetration tests

Answer: B

To view all questions and flashcards with answers, click on the resource link above. Page 3

Chapter 2: Tcpip Concepts Review

Available Study Resources on Quizplus for this Chatper

57 Verified Questions

57 Flashcards

Source URL: https://quizplus.com/quiz/41511

Sample Questions

Q1) No matter what medium connects computers on a network-copper wires, fiber-optic cables, or a wireless setup-the same protocol must be running on all computers if communication is going to function correctly.

A)True

B)False

Answer: True

Q2) ____ was the standard for moving or copying large files and is still used today, although to a lesser extent because of the popularity of HTTP.

A)FTP

B)TFTP

C)SNMP

D)SMTP

Answer: A

Q3) UDP is an unreliable data delivery protocol. Why is it widely used on the Internet?

Answer: UDP is a widely used protocol on the Internet because of its speed.UDP doesn't need to verify whether the receiver is listening or ready to accept the packets.The sender doesn't care-it just sends,even if the receiver isn't ready to accept the packet.

To view all questions and flashcards with answers, click on the resource link above.

4

Chapter 3: Network and Computer Attacks

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/41512

Sample Questions

Q1) How does a buffer overflow attack work?

Answer: In a buffer overflow attack,a programmer finds a vulnerability in poorly written code that doesn't check for a defined amount of space use.For example,if a program defines a buffer size of 100 MB (the total amount of memory the program is supposed to use),and the program writes data over the 100 MB mark without triggering an error or preventing this occurrence,you have a buffer overflow.Basically,the attacker writes code that overflows the buffer;this is possible because the buffer capacity hasn't been defined correctly in the program.The trick is to not fill the overflow buffer with meaningless data,but to fill it with executable program code.That way,the OS runs the code,and the attacker's program does something harmful.Usually,the code elevates the attacker's permissions to that of an administrator's level or gives the attacker the same privileges as the program's owner or creator.

Q2) ____ is a remote control program.

A)Slammer

B)BlackIce

C)Symantec pcAnywhere

D)Zone Alarm

Answer: C

To view all questions and flashcards with answers, click on the resource link above.

Page 5

Chapter 4: Footprinting and Social Engineering

Available Study Resources on Quizplus for this Chatper

51 Verified Questions

51 Flashcards

Source URL: https://quizplus.com/quiz/41513

Sample Questions

Q1) ____ is a tool that is used to gather IP and domain information.

A)Whois

B)Netcat

C)Metis

D)Dig

Q2) A(n) ____________________ is a person skilled at reading what users enter on their keyboards, especially logon names and passwords.

Q3) ____ is the most basic HTTP method.

A)GET

B)PUT

C)CONNECT

D)HEAD

Q4) Namedroppers is a tool that can be used to capture Web server information and possible vulnerabilities in a Web site's pages that could allow exploits such as SQL injection and buffer overflows.

A)True

B)False

Q5) What is "competitive intelligence"?

Q6) What is the purpose of a Web bug? How do they relate to or differ from spyware?

Page 6

To view all questions and flashcards with answers, click on the resource link above.

Chapter 5: Port Scanning

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/41514

Sample Questions

Q1) does not allow entry or access to a service

A)Nmap

B)pcAnywhere

C)XMAS scan

D)connect scan

E)closed port

F)ACK scan

G)filtered port

H)open port

I)NULL scan

Q2) If subnetting is used in an organization, you can include the broadcast address by mistake when performing ping sweeps. How might this happen?

Q3) ____ was developed to assist security testers in conducting tests on large networks and to consolidate many of the tools needed for large-scale endeavors.

A)Unicornscan

B)NetScanTools

C)Nessus

D)Nmap

Q4) What makes the OpenVAS tool unique?

To view all questions and flashcards with answers, click on the resource link above. Page 7

Chapter 6: Enumeration

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/41515

Sample Questions

Q1) ____ is an enhancement to NDS (NetWare Directory Services).

A)Active Directory

B)Bindery

C)X.500

D)eDirectory

Q2) more stable than its predecessor, with an improved file system (FAT32)

A)Windows 98

B)Windows 95

C)Windows Server 2003

D)Fedora Linux

E)Solaris

F)Windows XP Professional

G)Novell Open Enterprise Server

H)Windows 2000 Server/Professional

I)Windows NT 3.51 Server/Workstation

Q3) Windows 95 uses the ____ file system.

A)FAT16

B)FAT32

C)NTFS

D)ext3

To view all questions and flashcards with answers, click on the resource link above. Page 8

Chapter 7: Programming for Security Professionals

Available Study Resources on Quizplus for this Chatper

53 Verified Questions

53 Flashcards

Source URL: https://quizplus.com/quiz/41516

Sample Questions

Q1) How is branching performed in Perl?

Q2) English-like language you can use to help create the structure of your program

A)pseudocode

B)conversion specifier

C)class

D)bug

E)variable

F)do loop

G)compiler

H)while loop

I)gcc

Q3) You must always add "//" at the end of comment text in C.

A)True

B)False

Q4) UNIX was first written in assembly language, soon rewritten in ____.

A)Smalltalk

B)Perl

C)Python

D)C

Q5) Mention three C compilers and on which operating systems they are available.

Page 9

To view all questions and flashcards with answers, click on the resource link above.

Chapter 8: Desktop and Server Os Vulnerabilities

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/41517

Sample Questions

Q1) to harden Microsoft systems, you should rename this account

A)antivirus software

B)port 389

C)Guest

D)port 53

E)port 443

F)port 80

G)unused services

H)Administrator

I)blank

Q2) In Windows Server 2003 and 2008, how does a domain controller locate resources in a domain?

Q3) You can use _____________________________________________ information when testing Linux computers for known vulnerabilities.

Q4) What is the Common Internet File System (CIFS) protocol?

Q5) To perform MBSA-style scans you can run the tool from the command line by using ____________________.exe.

Q6) What should a password policy include?

Q7) What can a security tester using enumeration tools do?

To view all questions and flashcards with answers, click on the resource link above. Page 10

Chapter 9: Embedded Operating Systems: The Hidden Threat

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/41518

Sample Questions

Q1) Embedded systems include their own operating system, called a(n) "_________________________".

Q2) What types of systems use VxWorks?

Q3) Which of the following could be considered the biggest security threat for an organization?

A)spyware

B)employees

C)kernels

D)routers

Q4) QNX, from QNX Software Systems, is a commercial

Q5) Many viruses, worms, Trojans, and other attack vectors take advantage of ____code.

A)shortened

B)shared

C)modified

D)cache

Q7) List at least four best practices for protecting embedded OSs. Page 11

Q6) Many hackers today want more than just notoriety. What are they looking for and how do they accomplish it?

To view all questions and flashcards with answers, click on the resource link above. Page 12

Chapter 10: Hacking Web Servers

Available Study Resources on Quizplus for this Chatper

52 Verified Questions

52 Flashcards

Source URL: https://quizplus.com/quiz/41519

Sample Questions

Q1) The ____ Search page is an excellent starting point when investigating VBScript vulnerabilities.

A)CVE Web site

B)CERT

C)Microsoft Security Bulletin

D)Macromedia security

Q2) What can an attacker do after gaining control of a Web server?

Q3) CFML stands for ______________________________.

Q4) All CFML tags begin with "____".

A)(?)

B)CF

C)CFML

D)%

Q5) In Windows, IIS stands for ______________________________.

Q6) Web applications written in CFML can also contain other client-side technologies, such as HTML and JavaScript.

A)True

B)False

Q7) Why should security professionals have at least a little knowledge about the Apache Web Server?

To view all questions and flashcards with answers, click on the resource link above. Page 13

Chapter 11: Hacking Wireless Networks

Available Study Resources on Quizplus for this Chatper

52 Verified Questions

52 Flashcards

Source URL: https://quizplus.com/quiz/41520

Sample Questions

Q1) The 802.11 standard applies to the Physical layer of the OSI model, which deals with wireless connectivity issues of fixed, portable, and moving stations in a local area, and the Media Access Control (MAC) sublayer of the ____.

A)Network Link layer

B)Data Link layer

C)transport layer

D)session layer

Q2) The ____ standard can achieve a throughput of 54 Mbps.

A)802.11b

B)802.11e

C)802.11g

D)802.11i

Q3) What is WEP? Is it a good way to secure wireless networks?

Q4) What is the role of a WNIC?

Q5) Wireless routers are designed so that they do not interfere with wireless telephones. A)True

B)False

Q6) WEP stands for _________________________.

Q7) What is wardriving?

14

To view all questions and flashcards with answers, click on the resource link above.

Chapter 12: Cryptography

Available Study Resources on Quizplus for this Chatper

58 Verified Questions

58 Flashcards

Source URL: https://quizplus.com/quiz/41521

Sample Questions

Q1) ____ refers to verifying the sender or receiver (or both) is who he or she claims to be.

A)Authentication

B)Nonrepudiation

C)Availability

D)Authorization

Q2) occurs if two different messages produce the same hash value

A)asymmetric encryption

B)collision free

C)symmetric encryption

D)certificate

E)hashing

F)collision

G)stream cipher

H)message digest

I)block cipher

Q3) What is the difference between a public key and a private key?

Q4) What is a one-way function? Provide an example or an analogy to help explain the concept.

Q5) How does public key infrastructure work?

To view all questions and flashcards with answers, click on the resource link above. Page 15

Chapter 13: Network Protection Systems

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/41522

Sample Questions

Q1) ____, written in C for *nix platforms, is an open-source virtual honeypot created and maintained by Niels Provos.

A)Decoy Server

B)NetBait

C)Tiny Honeypot

D)Honeyd

Q2) also called privileged mode

A)stateful packet filter

B)firewall

C)NAT

D)DMZ

E)stateless packet filter

F)user mode

G)enable mode

H)ASA

I)privileged mode

Q3) A standard IP access list is restricted to source IP addresses.

A)True

B)False

Q4) What are the interfaces in a Cisco router?

To view all questions and flashcards with answers, click on the resource link above. Page 16

Turn static files into dynamic content formats.

Create a flipbook
Information Security Exam Solutions - 673 Verified Questions by Quizplus - Issuu