Mary Sunseri
Quiz por , criado more than 1 year ago

Information Technology Quiz sobre Midterm review Chapters 1-5, criado por Mary Sunseri em 03-03-2018.

221
1
0
Mary Sunseri
Criado por Mary Sunseri aproximadamente 6 anos atrás
Fechar

Midterm review Chapters 1-5

Questão 1 de 176

1

Which of the following is the best definition for war-driving?

Selecione uma das seguintes:

  • Driving and seeking rival hackers

  • Driving while hacking and seeking a computer job

  • Driving looking for wireless networks to hack

  • Driving while using a wireless connection to hack

Explicação

Questão 2 de 176

1

In addition to mandating federal agencies to establish security measures, the Computer Security Act of 1987 defined important terms such as:

Selecione uma das seguintes:

  • security information

  • private information

  • unauthorized access

  • sensitive information

Explicação

Questão 3 de 176

1

What are the three approaches to security?

Selecione uma das seguintes:

  • High security, medium security, and low security

  • Perimeter, layered, and hybrid

  • Internal, external, and hybrid

  • Perimeter, complete, and none

Explicação

Questão 4 de 176

1

An attack characterized by an explicit attempt by attackers to prevent legitimate users from accessing a system is called:

Selecione uma das seguintes:

  • war-dialing

  • spoofing

  • denial of service

  • social engineering

Explicação

Questão 5 de 176

1

The first computer incident response team is affiliated with what university?

Selecione uma das seguintes:

  • Harvard University

  • Princeton

  • Carnegie-Mellon University

  • Yale

Explicação

Questão 6 de 176

1

The process of reviewing logs, records, and procedures to determine whether they meet appropriate standards is called:

Selecione uma das seguintes:

  • auditing

  • filtering

  • authenticating

  • sneaking

Explicação

Questão 7 de 176

1

Which of the following best defines the primary difference between a sneaker and an auditor?

Selecione uma das seguintes:

  • There is no difference

  • The sneaker tends to be less skilled

  • The sneaker tends to use more unconventional methods

  • The auditor tends to be less skilled

Explicação

Questão 8 de 176

1

Which of the following types of privacy laws affect computer security?

Selecione uma das seguintes:

  • Any privacy law applicable to your organization

  • Any privacy law

  • Any federal privacy law

  • Any state privacy law

Explicação

Questão 9 de 176

1

An intrusion-detection system is an example of:

Selecione uma das seguintes:

  • Proactive security

  • Perimeter security

  • Good security practices

  • Hybrid security

Explicação

Questão 10 de 176

1

Which of the following is the best definition of “sensitive information”?

Selecione uma das seguintes:

  • Any information that is worth more than $1,000

  • Any information that has monetary value and is protected by any privacy laws

  • Any information that, if accessed by unauthorized personnel, could damage your organization in any way

  • Military or defense related information

Explicação

Questão 11 de 176

1

Which of the following maintains a repository for information on virus outbreaks and detailed information about specific viruses?

Selecione uma das seguintes:

  • F-Secure Corporation

  • CERT

  • SANS Institute

  • Microsoft Security Advisor

Explicação

Questão 12 de 176

1

Which is a technique used to provide false information about data packets?

Selecione uma das seguintes:

  • Phreaking

  • Social engineering

  • Hacking

  • Spoofing

Explicação

Questão 13 de 176

1

What is the term for hacking a phone system?

Selecione uma das seguintes:

  • phreaking

  • Cracking

  • Hacking

  • Telco-hacking

Explicação

Questão 14 de 176

1

Which is NOT one of the three broad classes of security threats?

Selecione uma das seguintes:

  • Preventing or blocking access to a system

  • Gaining unauthorized access into a system

  • Malicious software

  • Disclosing contents of private networks

Explicação

Questão 15 de 176

1

Are there any reasons not to take an extreme view of security, if that view errs on the side of caution?

Selecione uma das seguintes:

  • No, there is no reason not to take such an extreme view.

  • Yes, if you are going to err, assume there are few if any realistic threats.

  • Yes, that can lead to wasting resources on threats that are not likely.

  • Yes, that can require that you increase your security skills in order to implement more rigorous defenses.

Explicação

Questão 16 de 176

1

A text file that is downloaded to a computer by a Web site to provide information about the Web site and online access is called a:

Selecione uma das seguintes:

  • cookie

  • Trojan horse

  • script kiddy

  • key logger

Explicação

Questão 17 de 176

1

Which of the following is the most basic security activity?

Selecione uma das seguintes:

  • Installing a firewall

  • Controlling access to resources

  • Authenticating users

  • Using a virus scanner

Explicação

Questão 18 de 176

1

Which of the following is NOT a connectivity device used to connect machines on a network?

Selecione uma das seguintes:

  • Network interface card

  • Hub

  • Proxy server

  • Switch

Explicação

Questão 19 de 176

1

The process of determining whether the credentials given by a user are authorized to access a particular network resource is called:

Selecione uma das seguintes:

  • auditing

  • accessing

  • authorization

  • authentication

Explicação

Questão 20 de 176

1

Which approach to security is proactive in addressing potential threats before they occur?

Selecione uma das seguintes:

  • Layered security approach

  • Passive security approach

  • Dynamic security approach

  • Hybrid security approach

Explicação

Questão 21 de 176

1

Those who exploit systems for harm such as to erase files, change data, or deface Web sites are typically called:

Selecione uma das seguintes:

  • gray hat hackers

  • black hat hackers

  • white hat hackers

  • red hat hackers

Explicação

Questão 22 de 176

1

Encryption and virtual private networks are techniques used to secure which of the following?

Selecione uma das seguintes:

  • Connection points

  • Data

  • Firewalls

  • Proxy servers

Explicação

Questão 23 de 176

1

Which of the following is the best definition for the term sneaker?

Selecione uma das seguintes:

  • An amateur hacker

  • A person who hacks a system to test its vulnerabilities

  • A person who hacks a system by faking a legitimate password

  • An amateur who hacks a system without being caught

Explicação

Questão 24 de 176

1

Which of the following is not one of the three major classes of threats?

Selecione uma das seguintes:

  • Online auction fraud

  • Denial of Service attacks

  • A computer virus or worm

  • Actually intruding on a system

Explicação

Questão 25 de 176

1

Which is NOT one of the three broad classes of security threats?

Selecione uma das seguintes:

  • Disclosing contents of private networks

  • Malicious software

  • Preventing or blocking access to a system

  • Gaining unauthorized access into a system

Explicação

Questão 26 de 176

1

What is a computer virus?

Selecione uma das seguintes:

  • Any program that can change your Windows registry.

  • Any program that self replicates

  • Any program that causes harm to your system

  • Any program that is downloaded to your system without your permission

Explicação

Questão 27 de 176

1

When assessing threats to a system, what three factors should you consider?

Selecione uma das seguintes:

  • How much traffic the system gets, the security budget, and the skill level of the security team

  • The system’s attractiveness, the information contained on the system, and how much traffic the system gets

  • The skill level of the security team, the system’s attractiveness, and how much traffic the system gets

  • The system’s attractiveness, the information contained on the system, and the security budget

Explicação

Questão 28 de 176

1

Which of the following would most likely be classified as misuses of systems?

Selecione uma das seguintes:

  • Using your business computer to conduct your own (non-company) business

  • Getting an occasional personal email

  • Looking up information on a competitor using the Web

  • Shopping on the web during lunch

Explicação

Questão 29 de 176

1

What is a technique used to determine if someone is trying to falsely deny that they performed a particular action?

Selecione uma das seguintes:

  • Non-repudiation

  • Access Control Authorization

  • Audiiting

  • Sneaking

Explicação

Questão 30 de 176

1

Which approach to security addresses both the system perimeter and individual systems within the network?

Selecione uma das seguintes:

  • Perimeter security approach

  • Layered security approach

  • Hybrid aecurity approach

  • Dynamic security approach

Explicação

Questão 31 de 176

1

Which of the following gives the best definition of spyware?

Selecione uma das seguintes:

  • Any software that monitors which Web sites you visit

  • Any software or hardware that monitors your system

  • Any software that logs keystrokes

  • Any software used to gather intelligence

Explicação

Questão 32 de 176

1

Which of the following is the best definition for non-repudiation?

Selecione uma das seguintes:

  • It is another term for user authentication

  • Processes that verify which user performs what action

  • Security that does not allow the potential intruder to deny his attack

  • Access control

Explicação

Questão 33 de 176

1

Blocking attacks seek to accomplish what?

Selecione uma das seguintes:

  • Prevent legitimate users from accessing a system

  • Breaking into a target system

  • Shut down security measures

  • Install a virus on the target machine

Explicação

Questão 34 de 176

1

Which term is generally used by hackers to refer to attempts at intrusion into a system without permission and usually for malevolent purposes?

Selecione uma das seguintes:

  • Social engineering

  • Blocking

  • Hacking

  • Cracking

Explicação

Questão 35 de 176

1

The most desirable approach to security is one which is:

Selecione uma das seguintes:

  • Layered and dynamic

  • Perimeter and static

  • Layered and static

  • Perimeter and dynamic

Explicação

Questão 36 de 176

1

Which of the following activities do security professionals recommend to limit the chances of becoming a target for a Trojan horse?

Selecione uma das seguintes:

  • Prevent employees from downloading and installing any programs

  • Download and install Windows updates and patches monthly

  • Only open e-mail attachments from friends or co-workers

  • Only download jokes, animated Flash files, or utility programs from popular sites

Explicação

Questão 37 de 176

1

Which method of defense against a SYN flood involves altering the response timeout?

Selecione uma das seguintes:

  • Micro blocks

  • SYN cookies

  • RST cookies

  • Stack tweaking

Explicação

Questão 38 de 176

1

Which created a buffer overflow attack against a Windows flaw called the DCOM RPC vulnerability?

Selecione uma das seguintes:

  • Blaster

  • MyDoom

  • SoBig

  • Slammer

Explicação

Questão 39 de 176

1

What do many analysts believe was the reason for the MyDoom virus/worm?

Selecione uma das seguintes:

  • A DoS attack against Microsoft.com

  • A DoS attack targeting Microsoft Windows IIS servers

  • An e-mail attack targeting Bill Gates

  • A DDoS attack targeting Santa Cruz Operations

Explicação

Questão 40 de 176

1

Which is NOT true about a buffer overflow attack?

Selecione uma das seguintes:

  • Susceptibility to a buffer overflow is entirely contingent on software flaws.

  • A hacker does not need a good working knowledge of some programming language to create a buffer overflow.

  • A buffer overflow can load malicious data into memory and run it on a target machine.

  • A careful programmer will write applications so the buffer will truncate or reject data that exceeds the buffer length.

Explicação

Questão 41 de 176

1

What is the name for a DoS defense that is dependent on sending back a hash code to the client?

Selecione uma das seguintes:

  • Server reflection

  • RST cookie

  • Stack tweaking

  • SYN cookie

Explicação

Questão 42 de 176

1

What is the best way to defend against a buffer overflow?

Selecione uma das seguintes:

  • Stopping all ICMP traffic

  • Using a robust firewall

  • Keeping all software patched and updated

  • Blocking TCP packets at the router

Explicação

Questão 43 de 176

1

The spread of viruses can be minimized by all of the following EXCEPT:

Selecione uma das seguintes:

  • using a code word with friends to determine if attachments are legitimate

  • using a virus scanner

  • immediately following instructions in security alerts e-mailed to you from Microsoft

  • never opening attachments you are unsure of

Explicação

Questão 44 de 176

1

Which of the following is NOT a denial of service attack?

Selecione uma das seguintes:

  • Ping of Death

  • SYN flood

  • Smurf attack

  • Stack tweaking

Explicação

Questão 45 de 176

1

Which of the following is the best definition for IP spoofing?

Selecione uma das seguintes:

  • Sending packets that are misconfigured

  • Sending a packet that appears to come from a trusted IP

  • Setting up a fake Web site that appears to be a different site

  • Rerouting packets to a different IP

Explicação

Questão 46 de 176

1

Which attack relies on broadcast packets to cause a network to actually flood itself with ICMP packets?

Selecione uma das seguintes:

  • Smurf attack

  • SYN flood

  • Tribal flood

  • ICMP flood

Explicação

Questão 47 de 176

1

Which attack occurs by sending packets that are too large for the target machine to handle?

Selecione uma das seguintes:

  • SYN flood

  • ICMP flood

  • Ping of death

  • Stack tweaking

Explicação

Questão 48 de 176

1

One of the most common types of attacks via the Internet is:

Selecione uma das seguintes:

  • Buffer overflow

  • IP spoofing

  • Session hacking

  • Denial of service

Explicação

Questão 49 de 176

1

Which of the following virus attacks initiated a DoS attack?

Selecione uma das seguintes:

  • Walachi

  • MyDoom

  • Bagle

  • Faux

Explicação

Questão 50 de 176

1

Which router configuration is potentially least vulnerable to an attack?

Selecione uma das seguintes:

  • Routers that filter packets with source addresses in the local domain

  • Proxy firewalls where the proxy applications use the source IP address for authentication

  • Routers to external networks that support multiple internal interfaces

  • Routers with two interfaces that support subnetting on the internal network

Explicação

Questão 51 de 176

1

What is a technical weakness of the Stack tweaking defense?

Selecione uma das seguintes:

  • It only decreases time out but does not actually stop DoS attacks

  • It is complicated and requires very skilled technicians to implement

  • It is resource intensive and can degrade server performance.

  • It is ineffective against DoS attacks

Explicação

Questão 52 de 176

1

Which created a domestic “cyber terrorism” attack against a Unix distributor?

Selecione uma das seguintes:

  • MyDoom

  • W32.Storm.Worm

  • Blaster

  • Slammer

Explicação

Questão 53 de 176

1

What is the name for a DoS attack that causes machines on a network to initiate a DoS against one of that network’s servers?

Selecione uma das seguintes:

  • Smurf attack

  • Distributed Denial of Service

  • SYN flood

  • Ping of Death

Explicação

Questão 54 de 176

1

Which of the following would be the best defense if your Web server had limited resources but you needed a strong defense against DoS?

Selecione uma das seguintes:

  • Stack tweaking

  • A firewall

  • SYN cookies

  • RST cookies

Explicação

Questão 55 de 176

1

What was the greatest damage from the Bagle virus?

Selecione uma das seguintes:

  • It deleted system files

  • It corrupted the Windows registry

  • It was difficult to detect

  • It shut down antivirus software

Explicação

Questão 56 de 176

1

How does the SYN cookie work?

Selecione uma das seguintes:

  • Replaces cookies left by virus/worm programs.

  • Causes server to send wrong SYNACK to the client.

  • Prevents memory allocation until third part of SYN ACK handshaking.

  • Enables encryption of outbound packets.

Explicação

Questão 57 de 176

1

From the attacker’s point of view, what is the primary weakness in a DoS attack?

Selecione uma das seguintes:

  • The attack does not cause actual damage

  • The attack must be sustained.

  • The attack is difficult to execute

  • The attack is easily thwarted

Explicação

Questão 58 de 176

1

Shutting down router and firewall ports 5554 and 9996 will block most damage from which of these?

Selecione uma das seguintes:

  • Sobig

  • Trojan horses

  • Bagle

  • Sasser

Explicação

Questão 59 de 176

1

Which attack causes Internet routers to attack the target systems without actually compromising the routers themselves?

Selecione uma das seguintes:

  • ICMP flood

  • SYN flood

  • Tribal Flood Network

  • Distributed Reflection Denial of Service

Explicação

Questão 60 de 176

1

Which attack relies on broadcast packets to cause a network to actually flood itself with ICMP packets?

Selecione uma das seguintes:

  • Tribal flood

  • SYN flood

  • Smurf attack

  • ICMP flood

Explicação

Questão 61 de 176

1

What DoS attack is based on leaving connections half open?

Selecione uma das seguintes:

  • SYN flood

  • Smurf Attack

  • Ping of Death

  • Distributed Denial of Service

Explicação

Questão 62 de 176

1

What is the best method of defending against IP spoofing?

Selecione uma das seguintes:

  • Installing a router/firewall that blocks packets that appear to be originating within the network

  • Blocking all incoming TCP traffic

  • Blocking all incoming ICMP traffic

  • Installing a router/firewall that blocks packets that appear to be originating from outside the network

Explicação

Questão 63 de 176

1

Which of the following best describes session hacking?

Selecione uma das seguintes:

  • Taking over a target machine via a Trojan horse

  • Taking control of the login session

  • Taking control of a target machine remotely

  • Taking control of the communication link between two machines

Explicação

Questão 64 de 176

1

Which of the following is a recommended configuration of your firewall to defend against DoS attacks?

Selecione uma das seguintes:

  • Block TCP packets that originate outside your network

  • Block all incoming packets

  • Block ICMP packets that originate outside your network

  • Block all ICMP packets

Explicação

Questão 65 de 176

1

Which copies itself into the Windows directory and creates a registry key to load itself at startup?

Selecione uma das seguintes:

  • Slammer

  • MyDoom

  • Sasser

  • Bagle

Explicação

Questão 66 de 176

1

Which presented itself as an e-mail from the system administrator informing the user of a virus infection and gave directions to open an e-mail attachment which would then scan for e-mail addresses and shared folders?

Selecione uma das seguintes:

  • Sobig

  • Sasser

  • Minmail

  • Bagle

Explicação

Questão 67 de 176

1

Which of the following best describes a buffer overflow attack?

Selecione uma das seguintes:

  • An attack that attempts to put misconfigured data into a memory buffer

  • An attack that attempts to send oversized TCP packets

  • An attack that attempts to put too much data in a memory buffer

  • An attack that overflows the target with too many TCP packets

Explicação

Questão 68 de 176

1

What is a Trojan horse?

Selecione uma das seguintes:

  • Software that deletes system files then infects other machines

  • Software that self replicates

  • Software that causes harm to your system

  • Software that appears to be benign but really has some malicious purpose

Explicação

Questão 69 de 176

1

Which of the following denial of service attacks results from a client’s failure to respond to the server’s reply to a request for connection?

Selecione uma das seguintes:

  • ICMP flood

  • SYN flood

  • Tribal flood

  • UDP flood

Explicação

Questão 70 de 176

1

What is the danger inherent in IP spoofing attacks?

Selecione uma das seguintes:

  • Many of these attacks open the door for other attacks

  • Many firewalls don’t examine packets that seem to come from within the network.

  • They can be difficult to stop

  • They are very damaging to target systems

Explicação

Questão 71 de 176

1

Which is NOT a typical adverse result of a virus?

Selecione uma das seguintes:

  • Increased network traffic

  • Changing system settings

  • Increased network functionality and responsiveness

  • Deletion of files

Explicação

Questão 72 de 176

1

What type of firewall is Check Point Firewall-1?

Selecione uma das seguintes:

  • Packet filtering/application gateway hybrid

  • SPI/application gateway hybrid

  • Circuit level gateway

  • Application gateway

Explicação

Questão 73 de 176

1

What implementation is Check Point Firewall-1?

Selecione uma das seguintes:

  • Switch based

  • Host based

  • Network based

  • Router based

Explicação

Questão 74 de 176

1

Which is a hardware firewall vendor manufacturing Stateful Packet Inspection units with NAT and DES especially for small offices?

Selecione uma das seguintes:

  • Cisco

  • Wolverine

  • D-Link

  • Check Point

Explicação

Questão 75 de 176

1

Should a home user with ICF block port 80, and why or why not?

Selecione uma das seguintes:

  • She should not because it would prevent her from using Web Pages

  • She should not because that will prevent her from getting updates and patches

  • She should unless she is running a Web server on her machine.

  • She should because port 80 is a common attack point for hackers

Explicação

Questão 76 de 176

1

Why is an SPI firewall more resistant to flooding attacks?

Selecione uma das seguintes:

  • It requires user authentication

  • It examines each packet in the context of previous packets

  • It automatically blocks large traffic from a single IP

  • It examines the destination IP of all packets

Explicação

Questão 77 de 176

1

Snort is which type of IDS?

Selecione uma das seguintes:

  • Client-based

  • Router-based

  • OS-based

  • Host-based

Explicação

Questão 78 de 176

1

Snort is which type of IDS?

Selecione uma das seguintes:

  • Client-based

  • Router-based

  • OS-based

  • Host-based

Explicação

Questão 79 de 176

1

What is one complexity found in enterprise environements that is unlikely in small networks or SOHO environments?

Selecione uma das seguintes:

  • Diverse user groups

  • Web vulnerabilities

  • Multiple operating systems

  • Users running different applications

Explicação

Questão 80 de 176

1

Which type of IDS is the Cisco Sensor?

Selecione uma das seguintes:

  • Anomaly detection

  • Intrusion deterrence

  • Intrusion deflection

  • Anomaly deterrence

Explicação

Questão 81 de 176

1

It should be routine for someone in the IT security staff to

Selecione uma das seguintes:

  • Physically inspect the firewall

  • Review firewall logs

  • Reboot the firewall

  • Test the firewall by attempting a ping flood

Explicação

Questão 82 de 176

1

Using a server running the Linux operating system with its built-in firewall as the network firewall is one example of which firewall configuration?

Selecione uma das seguintes:

  • router-based

  • dual-homed host

  • network host-based

  • screened host

Explicação

Questão 83 de 176

1

What is an advantage of an enterprise environment?

Selecione uma das seguintes:

  • Skilled technical personnel available

  • Multiple operating systems to deal with

  • IDS systems not needed

  • Lower security needs

Explicação

Questão 84 de 176

1

Which is true about SonicWALL firewall solutions?

Selecione uma das seguintes:

  • They work on Linux, Unix, Solaris, and Windows platforms.

  • They are relatively inexpensive.

  • All models contain built-in encryption.

  • They include built-in proxy server capabilities.

Explicação

Questão 85 de 176

1

In which mode of operation does Snort display a continuous stream of packet contents to the console?

Selecione uma das seguintes:

  • Heuristic mode

  • Network intrusion-detection mode

  • Packet logger mode

  • Packet sniffer mode

Explicação

Questão 86 de 176

1

In comparing a packet filter firewall with a stateful packet inspection firewall (SPI), the SPI firewall is:

Selecione uma das seguintes:

  • LESS susceptible to ping and SYN floods but MORE susceptible to IP spoofing

  • LESS susceptible to ping and SYN floods and LESS susceptible to IP spoofing.

  • MORE susceptible to ping and SYN floods and MORE susceptible to IP spoofing

  • MORE susceptible to ping and SYN floods and LESS susceptible to IP spoofing

Explicação

Questão 87 de 176

1

Which of the following are four basic types of firewalls?

Selecione uma das seguintes:

  • Screening, bastion, dual-homed, circuit level

  • Packet filtering, application gateway, circuit level, stateful packet inspection

  • Stateful packet inspection, gateway, bastion, screening

  • Application gateway, bastion, dual-homed, screening

Explicação

Questão 88 de 176

1

In many typical configurations with multiple firewalls, e-mail servers and FTP servers are located in the:

Selecione uma das seguintes:

  • internal corporate network

  • demilitarized zone

  • corporate intranet

  • external network

Explicação

Questão 89 de 176

1

Which of the following is not an advantage of the Fortigate firewall?

Selecione uma das seguintes:

  • Built-in encryption

  • Built-in virus scanning

  • Content filtering

  • Low cost

Explicação

Questão 90 de 176

1

Should a home user block ICMP traffic, and why or why not?

Selecione uma das seguintes:

  • It should be blocked because such traffic is often used to transmit a virus

  • It should be blocked because such traffic is often used to do port scans and flood attacks

  • It should not be blocked because it is necessary for network operations

  • It should not be blocked because it is necessary for using the Web

Explicação

Questão 91 de 176

1

Why might a proxy gateway be susceptible to a flood attack?

Selecione uma das seguintes:

  • It does not require user authentication

  • It allows multiple simultaneous connections

  • It does not properly filter packets

  • Its authentication method takes more time and resources

Explicação

Questão 92 de 176

1

A standalone technology that hides internal addresses from the outside and only allows connections that originate from inside the network is called:

Selecione uma das seguintes:

  • TFTP

  • HTTP

  • DMZ

  • NAT

Explicação

Questão 93 de 176

1

What is another term for preemptive blocking?

Selecione uma das seguintes:

  • Banishment vigilance

  • Intruder blocking

  • Intrusion deflection

  • User deflection

Explicação

Questão 94 de 176

1

Which serves as a single contact point between the Internet and the private network?

Selecione uma das seguintes:

  • Bastion host

  • DMZ

  • Screened host

  • Dual-homed host

Explicação

Questão 95 de 176

1

One type of intrusion-detection and avoidance which involves identifying suspect IP addresses and preventing intrusions is called:

Selecione uma das seguintes:

  • anomaly detection

  • intrusion deterrence

  • preemptive blocking

  • intrusion deflection

Explicação

Questão 96 de 176

1

NAT is a replacement for what technology?

Selecione uma das seguintes:

  • Proxy server

  • Firewall

  • IDS

  • Antivirus software

Explicação

Questão 97 de 176

1

Which is a robust commercial software firewall solution for Linux operating systems?

Selecione uma das seguintes:

  • SonicWALL

  • Wolverine

  • McAfee Personal Firewall

  • Symantec Norton Firewall

Explicação

Questão 98 de 176

1

Which is true about Windows XP Internet Connection Firewall (ICF)?

Selecione uma das seguintes:

  • It has a logging feature enabled by default.

  • It works best in conjunction with a perimeter firewall.

  • It blocks incoming and outgoing packets.

  • It is a screened host firewall.

Explicação

Questão 99 de 176

1

Which of the following is not a profiling strategy used in anomaly detection?

Selecione uma das seguintes:

  • Executable profiling

  • Threshold monitoring

  • Resource profiling

  • System monitoring

Explicação

Questão 100 de 176

1

Which type of intrusion-detection relies on people rather than software or hardware?

Selecione uma das seguintes:

  • Banishment vigilance

  • Intrusion deterrence

  • Infiltration

  • Anomaly detection

Explicação

Questão 101 de 176

1

Which type of firewall is included in Windows XP and many distributions of Linux operating systems?

Selecione uma das seguintes:

  • Stateful packet inspection

  • User authentication

  • Packet filter

  • Application proxy

Explicação

Questão 102 de 176

1

What is one complexity found in enterprise environements that is unlikely in small networks or SOHO environments?

Selecione uma das seguintes:

  • Users running different applications

  • Multiple operating systems

  • Diverse user groups

  • Web vulnerabilities

Explicação

Questão 103 de 176

1

What type of firewall requires individual client applications to be authorized to connect?

Selecione uma das seguintes:

  • Stateful packet inspection

  • Dual-homed

  • Application gateway

  • Screened gateway

Explicação

Questão 104 de 176

1

Which of the following is not one of Snort’s modes?

Selecione uma das seguintes:

  • Network intrusion-detection

  • Sniffer

  • Packet logger

  • Packet filtering

Explicação

Questão 105 de 176

1

What tool does McAfee Personal Firewall offer?

Selecione uma das seguintes:

  • A visual tool to trace attacks

  • NAT

  • Strong encryption

  • Vulnerability scanning

Explicação

Questão 106 de 176

1

An open source software circuit level gateway is available from which of the following?

Selecione uma das seguintes:

  • Watchguard Technologies

  • SonicWALL

  • Teros

  • Amrita Labs

Explicação

Questão 107 de 176

1

Which of the following are four basic types of firewalls?

Selecione uma das seguintes:

  • Application gateway, bastion, dual-homed, screening

  • Packet filtering, application gateway, circuit level, stateful packet inspection

  • Stateful packet inspection, gateway, bastion, screening

  • Screening, bastion, dual-homed, circuit level

Explicação

Questão 108 de 176

1

Which type of firewall creates a private virtual connection with the client?

Selecione uma das seguintes:

  • Circuit level gateway

  • Dual-homed

  • Application gateway

  • Bastion

Explicação

Questão 109 de 176

1

Which type of firewall negotiates between the server and client to permit or deny connection based on the type of software and connection requested?

Selecione uma das seguintes:

  • Circuit level gateway

  • Application gateway

  • Packet filter

  • Stateful packet inspection

Explicação

Questão 110 de 176

1

Which firewall configuration would be appropriate within a network to separate and protect various subnets of a network to provide greater security?

Selecione uma das seguintes:

  • bastion host

  • demilitarized zone

  • router-based

  • dual-homed host

Explicação

Questão 111 de 176

1

Which of the following is not a common feature of most single PC firewalls?

Selecione uma das seguintes:

  • Packet filtering

  • Software-based

  • Ease of use

  • Built-in NAT

Explicação

Questão 112 de 176

1

It should be routine for someone in the IT security staff to

Selecione uma das seguintes:

  • Reboot the firewall

  • Physically inspect the firewall

  • Review firewall logs

  • Test the firewall by attempting a ping flood

Explicação

Questão 113 de 176

1

A firewall designed to secure an individual personal computer is a:

Selecione uma das seguintes:

  • screened host firewall

  • single machine firewall

  • simple hardware firewall

  • combination hardware/software firewall

Explicação

Questão 114 de 176

1

What type of firewall is SonicWALL TI70?

Selecione uma das seguintes:

  • Application gateway

  • Circuit-level gateway

  • Packet screening

  • Stateful Packet Inspection

Explicação

Questão 115 de 176

1

Which of the following is an advantage of the network host-based configuration?

Selecione uma das seguintes:

  • It is resistant to IP spoofing

  • It has user authentication

  • It is inexpensive or free

  • It is more secure

Explicação

Questão 116 de 176

1

Which of the following is a benefit of Cisco firewalls?

Selecione uma das seguintes:

  • Very low cost

  • Built-in virus scanning on all products

  • Built-in IDS on all products

  • Extensive training available on the product

Explicação

Questão 117 de 176

1

Once a circuit level gateway verifies the user’s logon, it creates a virtual circuit between:

Selecione uma das seguintes:

  • the internal client and the external server

  • the external server and the proxy server

  • the external server and the firewall

  • the internal client and the proxy server

Explicação

Questão 118 de 176

1

At what OSI layer do packet filters function?

Selecione uma das seguintes:

  • Physical layer

  • Transport layer

  • Network layer

  • Data link layer

Explicação

Questão 119 de 176

1

Which is NOT a function of an intrusion-detection system?

Selecione uma das seguintes:

  • Inspect all inbound and outbound port activity

  • Notify the system administrator of suspicious activity

  • Infiltrate the illicit system to acquire information

  • Look for patterns in port activity

Explicação

Questão 120 de 176

1

What might one see in an implementation of intrusion deterrence?

Selecione uma das seguintes:

  • Real resources with fake names

  • Fake resources with legitimate-sounding names

  • Blocking of legitimate users by mistake

  • Profiling of users, resources, groups, or applications

Explicação

Questão 121 de 176

1

A system that is set up for attracting and monitoring intruders is called what?

Selecione uma das seguintes:

  • Fly paper

  • Honey pot

  • Hacker cage

  • Trap door

Explicação

Questão 122 de 176

1

A device that hides internal IP addresses is called

Selecione uma das seguintes:

  • Dual-homed host

  • Bastion firewall

  • Proxy server

  • A screened host

Explicação

Questão 123 de 176

1

Medium-sized networks have what problem?

Selecione uma das seguintes:

  • Low budgets

  • Diverse user group

  • Need to connect multiple LANs into a single WAN

  • Lack of skilled technical personnel

Explicação

Questão 124 de 176

1

A firewall that uses a combination of approaches rather than a single approach to protect the network is called:

Selecione uma das seguintes:

  • multi-homed

  • dual-homed

  • open source

  • hybrid

Explicação

Questão 125 de 176

1

How can vulnerability to flooding attacks be reduced with an application gateway?

Selecione uma das seguintes:

  • Packets are continually checked during the connection

  • Vulnerability to flooding attacks with an application gateway cannot be mitigated

  • Authenticating users

  • External systems never see the gateway

Explicação

Questão 126 de 176

1

Identifying abnormal activity on a firewall requires that one establish a:

Selecione uma das seguintes:

  • baseline

  • screened host

  • bastion host

  • proxy server

Explicação

Questão 127 de 176

1

An intrusion-detection system detecting a series of ICMP packets sent to each port from the same IP address might indicate:

Selecione uma das seguintes:

  • scanning of the system for vulnerabilities prior to an attack

  • Trojan horse/virus infection sending information back home

  • a Distributed Denial of Service attack in progress

  • the system has been infiltrated by an outsider

Explicação

Questão 128 de 176

1

Why is an SPI firewall less susceptible to spoofing attacks?

Selecione uma das seguintes:

  • It requires user authentication

  • It requires client application authentication

  • It automatically blocks spoofed packets

  • It examines the source IP of all packets

Explicação

Questão 129 de 176

1

What is ICF?

Selecione uma das seguintes:

  • Windows XP Internet Connection Firewall

  • Windows 2000 Internet Connection Firewall

  • Windows 2000 Internet Control Firewall

  • Windows XP Internet Control Firewall

Explicação

Questão 130 de 176

1

Which is a firewall vendor manufacturing a host-based firewall for Windows 2000 Server, Sun Solaris, and Red Hat Linux environments?

Selecione uma das seguintes:

  • D-Link

  • Wolverine

  • Check Point

  • Cisco

Explicação

Questão 131 de 176

1

Which of the following is not a reason to avoid choosing infiltration as part of an IDS strategy?

Selecione uma das seguintes:

  • It can be time consuming

  • It requires knowledge of the target group

  • It can be expensive

  • The group may retaliate

Explicação

Questão 132 de 176

1

A series of ICMP packets sent to your ports in sequence might indicate what?

Selecione uma das seguintes:

  • A packet sniffer

  • A port scan

  • A DoS attack

  • A ping flood

Explicação

Questão 133 de 176

1

An intrusion-detection method that measures and monitors how programs use system resources is called:

Selecione uma das seguintes:

  • user/group profiling.

  • resource profiling.

  • executable profiling.

  • threshold monitoring.

Explicação

Questão 134 de 176

1

Which strategy is used in the implementation of intrusion deterrence?

Selecione uma das seguintes:

  • Installing honey pots to pose as important system

  • Monitoring connection attempts to identify IP addresses of attackers

  • Using fake names to camouflage important systems

  • Infiltrating online hacker groups

Explicação

Questão 135 de 176

1

Which method of intrusion-detection develops historic usage levels to measure activity against?

Selecione uma das seguintes:

  • Threshold monitoring

  • Application profiling

  • Resource profiling

  • Infiltration profiling

Explicação

Questão 136 de 176

1

What is the greatest danger in a network host-based configuration?

Selecione uma das seguintes:

  • SYN flood attacks

  • IP spoofing

  • Operating System Security flaws

  • Ping flood attacks

Explicação

Questão 137 de 176

1

Which type of firewall is generally the simplest and least expensive?

Selecione uma das seguintes:

  • Circuit level gateway

  • Application gateway

  • Packet filter

  • Stateful packet inspection

Explicação

Questão 138 de 176

1

Implementation of intrusion deflection as a strategy requires the use of:

Selecione uma das seguintes:

  • fake targets

  • blocking software

  • warnings to intruders to leave

  • innocuous names for sensitive targets

Explicação

Questão 139 de 176

1

Which of the following is found in Norton’s personal firewall but not in ICF?

Selecione uma das seguintes:

  • Strong encryption

  • Vulnerability scanning

  • A visual tool to trace attacks

  • NAT

Explicação

Questão 140 de 176

1

Which of the following is a common problem when seeking information on firewalls?

Selecione uma das seguintes:

  • Unbiased information may be hard to find.

  • It is difficult to find information on the Web.

  • Information often emphasizes price rather than features.

  • Documentation is often incomplete

Explicação

Questão 141 de 176

1

Which of the following can be shipped preconfigured?

Selecione uma das seguintes:

  • Router-based firewalls

  • Stateful packet inspection firewalls

  • Dual-homed firewalls

  • Network host-based firewalls

Explicação

Questão 142 de 176

1

Which is a term used to refer to the process of authentication and verification?

Selecione uma das seguintes:

  • Filtering

  • Negotiation

  • Connecting

  • Screening

Explicação

Questão 143 de 176

1

Which type of firewall negotiates between the server and client to permit or deny connection based on the type of software and connection requested?

Selecione uma das seguintes:

  • Circuit level gateway

  • Stateful packet inspection

  • Application gateway

  • Packet filter

Explicação

Questão 144 de 176

1

Which intrusion detection strategy monitors and compares activity against preset acceptable levels?

Selecione uma das seguintes:

  • Threshold monitoring

  • Infiltration monitoring

  • Application monitoring

  • Resource profiling

Explicação

Questão 145 de 176

1

Which of the following is a problem with the approach of a profiling strategy that is used in anomaly detection?

Selecione uma das seguintes:

  • It misses many attacks

  • It is resource intensive

  • It yields many false positives

  • It is difficult to configure

Explicação

Questão 146 de 176

1

What is the purpose of the warning configuration for Specter’s email file?

Selecione uma das seguintes:

  • To scare off at least novice hackers

  • To keep your normal users honest

  • To deter highly skilled hackers

  • To track hackers back to their source IPs

Explicação

Questão 147 de 176

1

Regarding the Firewall-1 firewall, which of the following is NOT true?

Selecione uma das seguintes:

  • It is particularly vulnerable to SYN floods.

  • It is a packet filtering, application gateway hybrid.

  • It uses Stateful Packet Inspection.

  • It automatically blocks and logs oversized packets.

Explicação

Questão 148 de 176

1

IDS is an acronym for:

Selecione uma das seguintes:

  • Intrusion deterrence service

  • Intrusion-detection service

  • Intrusion deterrence system

  • Intrusion-detection system

Explicação

Questão 149 de 176

1

What is the most important security advantage to NAT?

Selecione uma das seguintes:

  • It hides internal network addresses

  • By default it blocks all ICMP packets

  • It blocks incoming ICMP packets

  • By default it only allows outbound connections

Explicação

Questão 150 de 176

1

Which is true about the Wolverine firewall solution?

Selecione uma das seguintes:

  • It includes built-in VPN capabilities.

  • It works on Linux, Unix, Solaris, and Windows platforms.

  • Encryption can be added with a free Web download.

  • It is expensive.

Explicação

Questão 151 de 176

1

What four rules must be set for packet filtering firewalls?

Selecione uma das seguintes:

  • Username, password, protocol type, destination IP

  • Source IP, destination IP, username, password

  • Protocol type, source port, destination port, source IP

  • Protocol version, destination IP, source port, username

Explicação

Questão 152 de 176

1

Setting up parameters for acceptable use, such as the number of login attempts, and watching to see if those levels are exceeded is referred to as what?

Selecione uma das seguintes:

  • Resource profiling

  • Executable profiling

  • System monitoring

  • Threshold monitoring

Explicação

Questão 153 de 176

1

Attempts by an intruder to determine information about a system prior to the start of an intrusion attack is called:

Selecione uma das seguintes:

  • foot printing

  • infiltration

  • deflecting

  • detecting

Explicação

Questão 154 de 176

1

Which is NOT a service included in the Norton single machine firewall?

Selecione uma das seguintes:

  • Data recovery

  • Popup ad blocking

  • Blocking of outgoing traffic

  • Privacy protection

Explicação

Questão 155 de 176

1

Banishment vigilance is another name for:

Selecione uma das seguintes:

  • anomaly detection

  • intrusion deflection

  • intrusion deterrence

  • preemptive blocking

Explicação

Questão 156 de 176

1

Which type of encryption is included with the T170?

Selecione uma das seguintes:

  • PGP and AES

  • WEP and DES

  • WEP and PGP

  • AES and DES

Explicação

Questão 157 de 176

1

Which is a unique feature of the McAfee Personal Firewall that is not found on most personal firewalls?

Selecione uma das seguintes:

  • Blocking incoming traffic on selected ports

  • Online scanning of system for vulnerabilities

  • Performing traceroute to show the source of incoming packets

  • Recording a log of all attempts at incoming packets

Explicação

Questão 158 de 176

1

Why might you run Specter in strange mode?

Selecione uma das seguintes:

  • It will be difficult to determine the system is a honey pot

  • It will deter novice hackers

  • It may fascinate hackers and keep them online long enough to catch them

  • It may confuse hackers and deter them from your systems

Explicação

Questão 159 de 176

1

A firewall configuration using a server as a router and running multiple network interfaces with automatic routing disabled is an example of a:

Selecione uma das seguintes:

  • dual-homed host

  • screened host

  • router-based

  • network host-based

Explicação

Questão 160 de 176

1

Why might a proxy gateway be susceptible to a flood attack?

Selecione uma das seguintes:

  • Its authentication method takes more time and resources

  • It does not properly filter packets

  • It allows multiple simultaneous connections

  • It does not require user authentication

Explicação

Questão 161 de 176

1

Which intrusion-detection method measures activity levels against known short-term and/or long-term work profiles?

Selecione uma das seguintes:

  • Threshold monitoring

  • User/group work profiling

  • Executable profiling

  • Resource profiling

Explicação

Questão 162 de 176

1

Why might a circuit level gateway be inappropriate for some situations?

Selecione uma das seguintes:

  • It blocks web traffic

  • It is simply too expensive

  • It has no user authentication

  • It requires client side configuration

Explicação

Questão 163 de 176

1

Which is NOT true about enterprise networks and firewall solutions?

Selecione uma das seguintes:

  • They are likely to be supported by multiple network administrators.

  • They are usually made up of several interconnected networks.

  • They are usually easier to manage and secure.

  • They are likely to contain several different operating systems.

Explicação

Questão 164 de 176

1

Attempting to make your system appear less appealing is referred to as what?

Selecione uma das seguintes:

  • Intrusion deterrence

  • System deterrence

  • System camouflage

  • Intrusion deflection

Explicação

Questão 165 de 176

1

Which of the following is an important feature of D-Link DFL 300?

Selecione uma das seguintes:

  • Vulnerability scanning

  • Liberal licensing policy

  • WEP encryption

  • Built-in IDS

Explicação

Questão 166 de 176

1

Which firewall solution would be best for a large enterprise running Windows XP Professional and Linux operating systems, using the Internet, and requiring remote access to their Intranet server for field sales people?

Selecione uma das seguintes:

  • Check Point Firewall-1

  • Cisco PIX 515E

  • Fortigate 3600

  • Windows XP Internet Connection Firewall

Explicação

Questão 167 de 176

1

Why is an SPI firewall more resistant to flooding attacks?

Selecione uma das seguintes:

  • It automatically blocks large traffic from a single IP

  • It requires user authentication

  • It examines each packet in the context of previous packets

  • It examines the destination IP of all packets

Explicação

Questão 168 de 176

1

A profiling technique that monitors how applications use resources is called what?

Selecione uma das seguintes:

  • Application monitoring

  • Resource profiling

  • System monitoring

  • Executable profiling

Explicação

Questão 169 de 176

1

Symantec Decoy Server does all of the following EXCEPT:

Selecione uma das seguintes:

  • simulate incoming mail server functions

  • record all traffic related to an intrusion attack

  • simulate outgoing mail server functions

  • track attacking packets to their source

Explicação

Questão 170 de 176

1

Attempting to attract intruders to a system set up to monitor them is called what?

Selecione uma das seguintes:

  • Intrusion routin

  • Intrusion deterrence

  • Intrusion banishment

  • Intrusion deflection

Explicação

Questão 171 de 176

1

Which type of firewall is considered the most secure?

Selecione uma das seguintes:

  • Circuit-level gateway

  • Stateful packet inspection

  • Dual-homed

  • Packet screening

Explicação

Questão 172 de 176

1

Following rules and learning from experience as part of the process to identify and notify an administrator about an intrusion are typical when Snort is operating in which mode?

Selecione uma das seguintes:

  • Network intrusion-detection mode

  • Packet logger mode

  • Sniffer mode

  • Command mode

Explicação

Questão 173 de 176

1

Using a server running the Linux operating system with its built-in firewall as the network firewall is one example of which firewall configuration?

Selecione uma das seguintes:

  • screened host

  • network host-based

  • router-based

  • dual-homed host

Explicação

Questão 174 de 176

1

Which of the following solutions is actually a combination of firewalls?

Selecione uma das seguintes:

  • Dual-homed firewalls

  • Router-based firewalls

  • Screened firewalls

  • Bastion host firewalls

Explicação

Questão 175 de 176

1

Which is NOT one of the basic premises under which a honey pot functions?

Selecione uma das seguintes:

  • Intruders will tend to go for easy targets with valuable data

  • Any traffic to the honey pot is suspicious

  • Security must allow attackers inside

  • Only legitimate users have a reason to connect to it

Explicação

Questão 176 de 176

1

In many typical configurations with multiple firewalls, e-mail servers and FTP servers are located in the:

Selecione uma das seguintes:

  • demilitarized zone

  • internal corporate network

  • corporate Intranet

  • external network

Explicação