25 Random Security+ Questions

Posted by:

|

On:

|

0%

25 Random Questions Security+

1 / 25

What is the purpose of a root certificate in a PKI?

2 / 25

What is the purpose of a Time Stamping Authority (TSA) in a PKI?

3 / 25

A security team wants to implement a solution that will automatically adjust firewall rules based on current threat intelligence feeds. Which of the following BEST describes this type of automation?

4 / 25

Which of the following is the BEST method for tracking portable devices such as laptops and tablets in an organization?

5 / 25

An organization is implementing a new authentication system and wants to use a secure method for storing user passwords. Which of the following techniques would provide the BEST protection against password cracking attempts?

6 / 25

An organization wants to implement a solution that can help them manage and track vulnerabilities throughout their lifecycle. Which of the following would be MOST effective for this purpose?

7 / 25

A security team wants to implement a solution that will automatically detect and respond to potential data exfiltration attempts. Which of the following technologies would be MOST effective for this purpose?

8 / 25

What is the primary purpose of the eradication phase in the incident response process?

9 / 25

A security analyst wants to create a script that will automatically parse log files, extract relevant security events, and send alerts based on predefined criteria. Which of the following scripting languages is BEST suited for this task?

10 / 25

An attacker exploits a vulnerability in a web application where user-supplied input is directly included in LDAP queries without proper sanitization. This allows the attacker to manipulate LDAP statements and potentially gain unauthorized access to the LDAP directory. What type of attack is this?

11 / 25

A company is implementing a new asset tagging system for their data center equipment. Which of the following should be included on the asset tag to BEST support both physical and logical asset management?

12 / 25

A security analyst is implementing a web application firewall (WAF) to protect against common web attacks. Which of the following configurations would be MOST effective in mitigating SQL injection attacks?

13 / 25

A security analyst wants to create a script that will automatically analyze network traffic for potential threats and generate alerts. Which of the following tools would be BEST suited for integration into this script?

14 / 25

A company is outsourcing its security operations center (SOC) to a managed security service provider (MSSP). Which agreement should be implemented to ensure specific incident response times and escalation procedures?

15 / 25

An attacker sends a single ICMP packet to a network broadcast address, causing all systems on the subnet to respond simultaneously to the spoofed source address. This overwhelms the victim’s system with a flood of ICMP responses. What is this type of attack called?

16 / 25

Which vulnerability occurs when an application uses components with known vulnerabilities?

17 / 25

How does version control contribute to effective change management?

18 / 25

A critical server crashes every Friday at exactly 6 PM. An investigation reveals a specific script that runs at that time, which triggers the crash. No other files seem to be affected. What type of malware is most likely causing this behavior?

19 / 25

An organization wants to implement a solution to prevent sensitive data from being leaked through various channels such as email, web uploads, and removable media. Which of the following tools would be MOST effective for this purpose?

20 / 25

During a routine security audit, an IT technician finds that several user accounts have been compromised. The attacker used these accounts to install malware that logs keystrokes and sends the data to an external server. Which type of malware is being used by the attacker?

21 / 25

A security analyst needs to investigate a potential security incident by analyzing network traffic. Which of the following tools would be MOST appropriate for this task?

22 / 25

What is the MOST important consideration when developing security awareness training for non-technical staff?

23 / 25

Which threat actor is MOST likely to use advanced persistent threats (APTs) to target government agencies and critical infrastructure?

24 / 25

A company is developing a disaster recovery plan and needs to determine the sequence in which systems and processes should be recovered. Which of the following would be most helpful in this process?

25 / 25

A company is implementing a new access control system for their research and development department. Which of the following access control models would be MOST appropriate if the goal is to base access decisions on multiple attributes such as user role, project assignment, and time of day?

Your score is

Exit

One response to “25 Random Security+ Questions”