Browse all practice questions for the Network Security (NETSEC) 1 Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

Network Security (NETSEC) 1 Practice Test course image
More practice questions

These questions are part of the practice quiz. Start practicing

  • Is it possible for a countermeasure to be both detective and corrective?
  • What is the principle of least privilege?
  • Attackers cannot use IP address spoofing in port scanning attack packets.
  • Which statement about hacking definitions is TRUE?
  • Most traditional external attackers were heavily motivated by ________.
  • Which statement best describes the threat environment?
  • Attackers rarely use IP address spoofing to conceal their identities.
  • What is ARP spoofing and how can it be mitigated?
  • What is the key distinction between a secure VPN and remote desktop protocols?
  • The material suggests cyberwar involvement occurs ________ a physical attack.
  • What is defense-in-depth and how does it improve security?
  • Bribing an employee is a tactic used in what kind of espionage?
  • Which statement best describes SSL/TLS VPNs?
  • Botnets usually have multiple owners over time.
  • Which statement best describes a VPN tunnel?
  • Which of the following can be a type of spyware?
  • What is the purpose of logging in security?
  • In fraud, the perpetrator tries to obtain money or other goods by threatening to take actions that would be against the victim's interest.
  • Which statement about symmetric key rotation and key escrow is true?
  • What is DNSSEC and what does it protect?
  • Stealing credit card numbers is also known as ________.
  • Generally speaking, script kiddies have high levels of technical skills.
  • Which option is NOT one of the three common core goals of security?
  • Preventative countermeasures identify when a threat is attacking and especially when it is succeeding.
  • Internal threats can arise from employees who misuse legitimate access.
  • What is MFA and why is it effective?
  • Which statement about encryption versus hashing is true?
  • During TLS certificate verification, what steps does the client perform?
  • Which of the following are ways that trade secret espionage can occur?
  • Misappropriation of assets is best described as:
  • Which attack is most precise when a fake bank website is used to harvest credentials?
  • Compared to non-computer crime, computer crime is very small.
  • How do risk assessment and patch management relate?
  • What term refers to the intentional destruction of hardware, software, or data?
  • ICMP Echo messages are primarily associated with which activity?
  • An e-mail that seems to come from a frequent customer and leads to a fake site is an example of which attack?
  • Mobile code usually is delivered through ________.
  • If you discover you can access someone else's files by hitting a certain key and you look around briefly, this is hacking.
  • What is the purpose of PKI revocation and how do OCSP and CRL help?
  • Which statement reflects a typical characteristic of system controls in security?
  • Which statement best describes preventative countermeasures?
  • ______ consists of activities that violate a company's IT use policies or ethics policies.
  • What is a security baseline?
  • Prosecuting attackers in other countries is relatively straightforward under existing computer crime laws.
  • To prosecute people or companies who steal its trade secrets, a company must take ________ precautions to protect those trade secrets.
  • A small program that, after installed, downloads a larger attack program is called a ________.
  • The dominant type of attacker today is the ________.
  • The material indicates cyberwar actions are primarily performed by ________.
  • An e-mail that appears to be from your bank and directs you to a fake website is an example of which attack?
  • What is the primary function of an intrusion detection system (IDS)?
  • What is Kerberos?
  • The primary purpose for attackers to send port scanning probes to hosts is to identify which ports are open.
  • Which practice helps defend against padding oracle attacks?
  • Which protocols commonly use HMAC for message authentication?
  • The statement 'cyberwar is conducted by national governments' is supported by which option?
  • If an attacker deletes critical files from a corporate database, this is an attack against which security goal?
  • Countries would engage in cyberwar ________.
  • Which statement best captures the difference between a firewall and an IDS?
  • Cyberwar is described as attacks carried out by ________.
  • Which option best describes the relationship between incident management and problem management?
  • What is the purpose of the TLS handshake?
  • Some malware can jump directly between computers without human intervention.
  • Which of the following is a method attackers use to conceal their identity during reconnaissance?
  • Which is an example of an asymmetric encryption algorithm?
  • Which three concepts are the common core goals of information security?
  • Which statement best describes why employees pose an increased risk to organizations?
  • Which protocol is secure for remote device management and what practices improve its security?
  • The terms "intellectual property" and "trade secret" are synonymous.
  • An internal threat could include misuse of internal credentials to access systems.
  • Which sequence best describes the typical steps in a security risk assessment?
  • What is asymmetric encryption and give an example?
  • About how long was the Sony PlayStation Network offline as a result of the cyber attacks?
  • What best describes data loss prevention (DLP)?
  • Which statement best defines a VPN and its common types?
  • Social engineering is rarely used in hacking.
  • Which statement about preventative countermeasures is correct?
  • ______ attacks take advantage of flawed human judgment by convincing the victim to take actions that are counter to security policies.
  • Which component is commonly used by spyware to capture keystrokes?
  • When a company visits a website to collect public information about a competitor, this activity is a form of trade secret espionage.
  • The definition of spam is 'unsolicited commercial e-mail.'
  • ______ is a generic term for "evil software."
  • A(n) attack requires a victim host to prepare for many connections, using up resources until the computer can no longer serve legitimate users. (Choose the most specific.)
  • What does a Certificate Revocation List (CRL) provide?
  • The statement "Intellectual property and trade secret are synonyms" is:
  • What is zero trust architecture?
  • Which statement accurately describes a firewall and its common types?
  • What is the term for watching someone type their password to learn the password?
  • In pretexting, an attacker calls claiming to be a certain person in order to ask for private information about that person.
  • Carding is more serious than identity theft.
  • What is the primary method by which a botnet is controlled?
  • Carding is the name given to the theft of which type of data?
  • Which of the following is true about the relationship between detective and preventative countermeasures?
  • To obtain IP addresses through reconnaissance, an attacker can use ________.
  • Tailgating is another term for piggybacking.
  • Which term describes attackers who rely on readily available tools rather than developing their own code?
  • Phishing is best described as a deceptive technique used to obtain credentials. Which defenses are effective?
  • When a threat succeeds in causing harm to a business, this is called a ________.
  • What is NAT and how does it contribute to security?
  • What is a padding oracle vulnerability and how is it mitigated?
  • According to the material, which statement is true about countermeasure controls?
  • Money mules transfer stolen money for criminals and take a small percentage for themselves.
  • Many e-commerce companies will not ship to certain countries because of a high rate of consumer fraud. To get around this, attackers use ________.
  • What is a typical observable effect of a DoS attack?
  • The actors in cyberwar are described as ________.
  • Which attacker profile is described as the most common today?
  • What is a sandbox in security?
  • Which statement describes the difference between incident management and problem management in ITSM?
  • One of the two characterizations of expert hackers is ________.
  • What is the term for following someone through a secure door without authorization?
  • Terrorists' use of information technology can be employed to ________.
  • Which secure coding practices help prevent buffer overflows?
  • Which statement best defines a security policy and what it should include?
  • Which statement best describes the contents of a digital certificate?
  • Which item is NOT typically contained in a digital certificate?
  • RAT stands for which term?
  • Which type of program can hide itself from normal inspection and detection?
  • Misappropriation of assets is an example of what kind of theft?
  • Is the statement 'Most cookies are dangerous' true or false?
  • Which of the following is NOT a listed countermeasure type in the material?
  • Which practice contributes to defending against ransomware?
  • Which mechanism is used to move funds across borders as described in the material?
  • Social engineering attacks exploit which aspect of security?
  • Which statement best describes the difference between encryption and hashing?
  • In risk management, what does likelihood refer to?
  • Which type of malware is designed to hide its presence by masquerading as a legitimate process?
  • IT can be used by terrorists to finance their terrorism.
  • Mobile code is usually contained in webpages.
  • Which type of countermeasure is described as designed to prevent threats before they cause harm?
  • In fraud, the attacker deceives the victim into doing something against the victim's financial self-interest.
  • The term for sending packets with forged source IP addresses is:
  • In hacking, the perpetrator tries to obtain money or other goods by threatening to take actions that would be against the victim's interest.
  • Which form of online fraud involves paying for clicks that do not generate potential new customers?
  • Sophisticated attacks are often difficult to identify amid the noise of many ________ attacks.
  • A Trojan horse is a program that hides itself by deleting a system file and taking on the system file's name.
  • What is the role of monitoring in risk mitigation?
  • What does a cipher suite comprise?
  • Confidentiality means that attackers cannot change or destroy information.
  • What is the OWASP Top 10?
  • Which statement accurately describes ARP's role on a local network?
  • Employees often have extensive knowledge of systems and can pose a greater risk than external attackers due to:
  • Which practice is an example of sabotage?
  • What term describes software that pretends to be legitimate to deceive users into installing it?
  • Which statement best describes cyberwar according to the material?
  • Why did hackers attack Sony Corp?
  • In TLS certificate verification, why is hostname matching important?
  • Which malware types can spread through e-mail attachments?
  • What is patch management and why is it important?
  • Which of the following describes a characteristic related to expert hackers, specifically the trait of persistence?
  • The fastest propagation occurs with some types of malware.
  • What is the primary difference between an intrusion detection system (IDS) and an intrusion prevention system (IPS)?
  • A botmaster can remotely ________.
  • What is a certificate authority (CA) in PKI?
  • Employees are dangerous because they __________.
  • Which of the following is a type of countermeasure?
  • Which statement is true about penalties for hacking and the amount stolen?
  • Which statements about viruses and worms are both true?
  • Traditional hackers are motivated by ________.
  • Which of the following best describes social engineering?
  • What is a digital signature?
  • Who threatens to cause at least temporary harm to a victim company's IT infrastructure unless payment is made?
  • ICMP Echo messages are often used in ________.
  • What is per-message authentication and which protocol uses HMAC?
  • When a threat succeeds in causing harm to a business, this is a(n) ________.
  • Which entities may engage in commercial espionage against a firm?
  • Which statement correctly describes symmetric key rotation and key escrow?
  • When multiple attack machines are used in a chain, victims can often trace the activity to which hop?
  • Which statement describes IPSec-based VPNs and SSL/TLS VPNs?
  • Explain the difference between DNS poisoning and DNS spoofing.
  • The attack method used in the Sony data breaches was which of the following?
  • Which option best describes a next-generation firewall?
  • Which of the following are types of countermeasures?
  • If you accidentally find someone's password and use it to access a system, this is considered:
  • Which combination contributes to preventing buffer overflows?
  • Most traditional external attackers were primarily motivated by the thrill of breaking in.
  • Misappropriation of assets is an example of employee financial theft.
  • Which of the following reflects the key phases of an incident response plan?
  • Most traditional external hackers do not cause extensive damage or commit theft for money.
  • In pretexting, the attacker uses impersonation to obtain private information.
  • Terrorists can use information technology to ________.
  • Public Key Infrastructure (PKI) is used in security to:
  • Which statement is a cloud security best practice for NETSEC?
  • What do detective countermeasures primarily do?
  • Which hacker group was likely involved in the Sony data breaches?
  • ______ is form of online fraud when bogus clicks are performed to charge the advertiser without creating potential new customers.
  • What is residual risk?
  • Which action can lead to sexual harassment lawsuits in many organizations?
  • If most countermeasure controls are preventative, which statement follows?
  • Penalties for hacking are ________.
  • The four options for who conducts cyberwar include national governments, terrorists, both, or neither. Which is correct?
  • What does a digital certificate bind?
  • Which of the following are examples of social engineering?
  • True or false: When considering penalties for hacking, motivation is irrelevant.
  • What were the approximate dollar losses for the Sony data breaches?
  • What is network segmentation and why is it important?
  • What term describes the illegal practice of obtaining a firm's trade secrets through unauthorized access or illicit means?
  • In a virus, the code that does damage is called the payload.
  • Which term describes a targeted phishing attack aimed at a specific individual?
  • Identity theft is defined as stealing credit card numbers.
  • Which option best describes the timing of cyberwar activity around a physical conflict?
  • Which countermeasure type focuses on restoring normal operations after an incident?
  • According to the material, port scanning's primary purpose is to determine which ports are open.
  • In response to a chain of attack, victims can often trace the attack back to the final attack computer.
  • What is forward secrecy and how does it protect past sessions?
  • Which term best describes a small program that, once installed, retrieves a larger malicious payload from a remote server?
  • Which hash property ensures it is infeasible to invert the hash to obtain the original input?
  • Which statement is false regarding countermeasures?
  • Another name for safeguard is ________.
  • It is true or false that rootkits replace legitimate programs and are a deeper threat than Trojan horses?
  • Detective countermeasures are best described as:
  • Cybercriminals avoid black market forums.
  • What is a DMZ and its purpose?
  • Is trade secret protection automatic under the law?
  • What are the essential properties of a good hash function?
  • Cyberwar consists of computer-based attacks conducted by ________.
  • Which statement is true about definitions of hacking?
  • Nonmobile malware can be on webpages that users download.
  • In Kerberos, which entity issues tickets used for mutual authentication?
  • What is symmetric encryption and give an example?
  • A DoS attack attempts to make a server or network unavailable to serve legitimate users by flooding it with attack packets.
  • What is a man-in-the-middle (MITM) attack and how can it be prevented?
  • Running a seemingly innocent program that logs you into a government server is hacking.
  • What does the CIA triad stand for in network security?
  • Traditional external hackers typically cause extensive damage or theft for money.
  • Which statement about a digital certificate is incorrect?
  • Which term describes following an authorized person into a restricted area?
  • Under current U.S. federal laws, if a company allows personal information to be stolen, it may be subject to government fines.
  • Which statement correctly defines hacking?
  • IT usage by terrorists includes which of the following?
  • In ________, the perpetrator tries to obtain money or other goods by threatening to take actions that would be against the victim's interest.
  • Trade secret theft can occur through interception, hacking, and other traditional cybercrimes.
  • Which statement best describes extortion?
  • A program that gives the attacker remote access control of your computer is specifically called a ________.
  • Terrorists using information technology is described as capable of which of the following?
  • Which statement about malware is true?
  • ______ may engage in commercial espionage against a firm.
  • Which type of malware are programs that attach themselves to legitimate programs?
  • Which statement about detective countermeasures is correct?
  • Which statement best describes ransomware and a basic defense?
  • Sending packets with false IP source addresses is called ________.
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy