Browse all practice questions for the GIAC Information Security Fundamentals (GISF) Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

GIAC Information Security Fundamentals (GISF) Practice Test course image
More practice questions

These questions are part of the practice quiz. Start practicing

  • What does the term 'ciphertext' imply about the integrity of communication?
  • Which protocol is primarily responsible for sending emails?
  • What is a differential backup?
  • What is a primary characteristic of discretionary access controls (DAC)?
  • What is the hexadecimal equivalent of the binary value 1010?
  • What does decryption accomplish?
  • What is the purpose of a Cloud Controls Matrix (CCM)?
  • What is meant by sideloading in mobile applications?
  • What is the primary function of a firewall?
  • What is the concept of island hopping in the context of cybersecurity?
  • Which of the following statements best captures the essence of risk ignorance?
  • What is a machine-in-the-middle attack?
  • What is a brute force attack?
  • What role does the chief information security officer (CISO) typically play in an organization?
  • Which one of the following best describes asymmetric cryptography?
  • What does Shadow IT refer to?
  • What is the aim of preventive measures in security?
  • How are offensive countermeasures related to active defense?
  • Which Wi-Fi standard offers the highest throughput currently available?
  • Which of the following actions would most likely enable an attacker to gain higher privileges?
  • How is a byte calculated when working with multiple bytes?
  • What does a digital certificate primarily certify?
  • How many bits are there in a byte?
  • What is often a sign of a broken hashing algorithm?
  • What does the second hexadecimal digit represent when calculating hexadecimal values?
  • What type of firewall filters traffic based on the state of existing connections?
  • What is an essential characteristic of effective gap analysis?
  • What is a worm in the context of information security?
  • What is the purpose of the covering tracks phase in an attack?
  • What type of protocol is Transmission Control Protocol (TCP)?
  • What is the process of modifying an Apple mobile device to remove software restrictions known as?
  • What is the primary characteristic of the dark web?
  • What is a potential target for attackers when using application allowlisting?
  • What does WEP stand for in the context of Wi-Fi security?
  • Who in an organization has primary responsibility and knowledge of data management?
  • What does a one-way hash function provide in terms of data integrity?
  • What is normally considered when identifying countermeasures?
  • What is the combined value of all place values in a full byte?
  • Which of the following approaches may be taken when some risks cannot be completely avoided or mitigated?
  • What type of information does the File Transfer Protocol (FTP) transmit?
  • What key advantage does using both differential and full backups provide?
  • What does a true positive indicate in the context of an IDS?
  • When discussing data representation, what does 'octet' refer to?
  • In the context of cryptography, what is an important consideration aside from confidentiality?
  • Which of the following is an example of spoofing?
  • In a substitution cipher, what method is used to replace units of a message?
  • What does a physical countermeasure primarily involve?
  • What is the main feature of the ICMP in the context of IP?
  • What is the primary purpose of content filtering in a network?
  • What does the acronym PDR stand for in the context of security management?
  • Which of the following best describes token authentication?
  • What does a weak key attack exploit?
  • Frequency analysis is primarily used against which type of cryptographic method?
  • What is a backup?
  • Which standard is commonly referred to as Wi-Fi 5?
  • Which tool is commonly used to identify vulnerabilities in systems?
  • What is "work factor" in the context of cryptography?
  • What is the role of a default gateway in a network?
  • In risk management, what does risk acceptance imply?
  • What does the concept of risk avoidance entail?
  • What is the term "WarXing" used to describe?
  • What does DMZ stand for in a network context?
  • Which aspect is critical to the function of hardware that is part of the security control hierarchy?
  • What is a key in the context of cryptography?
  • What is a key component of asset valuation?
  • What does vulnerability analysis primarily assess?
  • What does OS hardening typically involve?
  • What is a common characteristic of exploit software?
  • What defines a Local Area Network (LAN)?
  • What is plaintext in the context of cryptography?
  • What is the essence of cloud computing?
  • What is the function of a server in a network environment?
  • What is the primary purpose of antivirus software?
  • What is the ideal frequency to perform full backups?
  • What is the significance of classifying alerts as true positive, false positive, true negative, and false negative?
  • During which process is a user granted specific access rights to resources?
  • What type of attack uses social engineering to manipulate a DNS registrar?
  • What port number is used by the Post Office Protocol version 3 (POP3) for retrieving email?
  • What is a drive-by download?
  • What is the purpose of the Address Resolution Protocol (ARP)?
  • What is the purpose of ransomware?
  • What is the role of a personal firewall?
  • How does a buffer overflow attack typically operate?
  • What is meant by implicit denial in access control?
  • Which of the following best describes the concept of confidentiality in security?
  • What is the ultimate goal of creating backups in information security?
  • In the binary system, which of the following represents the highest digit?
  • Which of the following describes a feature of a worm?
  • Which phase of an attack involves installing tools to ensure undetected access?
  • Which of the following is a characteristic of JavaScript?
  • What is the primary function of a network protocol?
  • What type of backup would allow quicker restoration of everyday files while maintaining full system recovery options?
  • Maintaining access is which number phase in the attack lifecycle?
  • Which cryptographic process would involve reorganizing the input data into a format suitable for security?
  • What does the process of verification in authentication involve?
  • Which type of device typically uses dynamic IP addresses?
  • What is direct social engineering?
  • What is the term for an infection vector that uses attractive USB drives left in public areas?
  • Which user account type can access shared resources but with limited permissions?
  • What does the term 'network' refer to in a computing context?
  • Which device commonly uses DHCP to obtain an IP address?
  • Which of the following accurately describes a characteristic of AES-128?
  • What is the main objective of confirmed backup recovery?
  • In role-based access control (RBAC), what determines a user’s access permissions?
  • Why might an organization want to reduce the power level on a Wi-Fi transmitter?
  • What does HTML5 primarily incorporate to enhance interactivity?
  • What does non-repudiation refer to in the context of information security?
  • What type of encryption does Bluetooth's secure simple pairing use?
  • What does the concept of accountability help prevent in information security?
  • Which of the following is the correct abbreviation for a byte?
  • What is the purpose of Elliptic Curve Cryptography (ECC)?
  • What is the first step in the risk management process?
  • What is the primary goal of the gaining access phase in an attack?
  • To compute the value of nibbles, what is added after calculating the high-order nibble?
  • What function does gateway antivirus serve in a network?
  • What are access controls used for?
  • What is a distributed denial-of-service (DDoS) attack?
  • Which elements are critical for a good information system?
  • What characterizes a Wide Area Network (WAN)?
  • What does accountability in a security context refer to?
  • What is a true negative in relation to an IDS/IPS?
  • What method of phishing attack uses text messages (SMS) to deceive victims?
  • What type of user interface allows interaction through text and visual images like icons?
  • What file system does Windows use for managing access control?
  • Why is it important to implement both signature and heuristics detection in antivirus software?
  • What is the role of an operating system (OS) on a computer?
  • What is one of the primary concerns regarding the use of attractive USB drives left in public areas?
  • DES stands for what in the context of cryptography?
  • Which type of attack would suggest that a hash function is compromised?
  • What should a properly functioning IDS alert you about?
  • Which class of Bluetooth is most commonly used?
  • Which operation is fundamental to modern encryption schemes and compares two binary bits?
  • What is the main characteristic of a cryptographic key?
  • What is the value of a terabyte in megabytes?
  • In what way do persistent cookies differ from non-persistent cookies?
  • Which type of security solution monitors the environment and takes automatic action against unauthorized access attempts?
  • What is the standard port number for Simple Mail Transfer Protocol (SMTP) used to send email?
  • Why is the order of rules important in a packet filter firewall?
  • Which feature best describes asymmetric encryption?
  • Which term describes a condition that allows a threat to potentially exploit a system?
  • What kind of addresses does NAT translate?
  • What is the purpose of private browsing in modern browsers?
  • What is the purpose of Network Address Translation (NAT)?
  • What is the historical significance of Triple DES?
  • Which attack method uses known plaintext to determine the key of ciphertext?
  • What is the primary role of firewall rules?
  • What does compartmentalization in network security refer to?
  • What authentication system does Enterprise Level Authentication (ELA) rely on?
  • What is the purpose of the 'chmod' command in Linux?
  • Which phishing attack method is characterized by the use of SMS text messages?
  • What is the primary purpose of implementing detection and reaction capabilities in risk management?
  • Which of the following components is part of a digital certificate?
  • Which of the following protocols would likely be used for email transmission?
  • Which of the following represents a bit?
  • What is a characteristic of Infrastructure as a Service (IaaS)?
  • Which type of phishing is conducted through telephone calls or VoIP systems?
  • How does a differential backup compare to an incremental backup?
  • In a business email compromise (BEC) attack, the threat actor impersonates which entity to gain financial advantage?
  • Which Wi-Fi security protocols are currently considered secure?
  • What does the term "impact" refer to in the context of risk assessment?
  • How does an external insider gain access to a system?
  • Why is authentication essential in information security?
  • What does the 'C' in the CIA Triad stand for?
  • Which attack can involve sending unsolicited ARP requests or replies?
  • What type of backup includes all data?
  • What security measures are utilized in Bluetooth's secure simple pairing?
  • Which of the following is NOT a property of signcryption?
  • What does a key derivation function (KDF) produce?
  • What is the purpose of cognitive password authentication?
  • What does the term "proprietary algorithm" commonly imply in cryptography?
  • Which aspect of the CIA Triad ensures that information is only accessible to those authorized?
  • What is the result when adding the high-order and low-order nibbles together?
  • What is the function of a non-persistent cookie?
  • What do firewall rules typically determine?
  • What does an algorithm represent in cryptography?
  • What does SSID stand for in the context of wireless networking?
  • What is a primary risk associated with the dark web?
  • What is the underlying technology that ensures the security of cryptocurrencies?
  • What does a 500 Series server return code indicate?
  • Which protocol is known for achieving higher transmission speeds at the cost of reliability?
  • What does the term "detect" refer to in a security context?
  • In a binary system, how is the value of a byte determined?
  • What is an Intrusion Detection System (IDS) primarily used for?
  • What is a digital envelope in the context of hybrid cryptography?
  • Which of the following best describes the goal of a botnet?
  • What does the operating system manage on behalf of the user?
  • What does ECDH combine with to facilitate encryption?
  • What does Software as a Service (SaaS) provide to its users?
  • In the context of information security, what is the significance of the reconnaissance phase?
  • What is privilege escalation?
  • What does TKIP stand for?
  • What does 'Availability' imply in information security?
  • What does a denial-of-service (DoS) attack aim to achieve?
  • What is the main purpose of minimum password aging?
  • What is the network port number commonly used for FTP?
  • What is a key characteristic of ciphertext-only attacks?
  • What is the primary meaning of privilege in information security?
  • What does the Ping command do in network troubleshooting?
  • What is the key factor that a senior manager decides regarding organizational risk?
  • What does wardriving involve?
  • What is the second phase of an attack where vulnerable assets are identified?
  • What technique involves injecting randomized data into software for testing purposes?
  • What is the main function of non-repudiation in communications?
  • Which type of hacking method is exemplified by spear phishing?
  • What does the Consensus Assessment Initiative Questionnaire (CAIQ) allow cloud customers to do?
  • What occurs when a hashing algorithm generates the same hash for different inputs?
  • Which of the following roles primarily utilizes the data within an organization?
  • What is the purpose of patching an operating system?
  • What is steganography primarily used for?
  • What essential tactic is at the core of social engineering attacks?
  • What is a key benefit of using multifactor authentication?
  • What is a unique characteristic of MAC addresses?
  • Which of the following accurately describes cache poisoning?
  • What does maximum password aging require?
  • What does a 200 Series server return code indicate?
  • Which step follows the asset valuation in the risk management process?
  • What does cryptanalysis involve?
  • What encryption method is used by WPA2?
  • Which of the following is a detailed explanation of how to implement a security policy?
  • What is identified during the threat identification step?
  • What is an IP address?
  • What command is used in Linux to change file or directory permissions?
  • What is typically the action denied to a non-privileged user account?
  • What does spoofing mean in the context of cybersecurity?
  • In hybrid cryptography, what role does the asymmetric key play?
  • What distinguishes indirect social engineering from direct social engineering?
  • Which type of cryptography requires the same key for both encryption and decryption?
  • What type of account usually has administrative privileges on a device or network?
  • What type of devices would typically be connected in a Local Area Network (LAN)?
  • What does active defense refer to?
  • Which term best describes actions taken to lessen the impact of a vulnerability?
  • What port number is associated with HTTPS?
  • What does the term 'cross-platform' refer to in programming?
  • Which protocol is primarily responsible for routing packets across interconnected networks?
  • What type of phishing attack specifically targets wealthy or powerful individuals?
  • What term describes the assurance that data is correct and maintained by authorized personnel?
  • What is involved in the response phase of incident management?
  • What is the key length of the AES-128 encryption standard?
  • What role does a client play in a network?
  • What is cryptocurrency?
  • What does SHA stand for in cryptography?
  • What type of protocol is IP categorized as?
  • Which of the following is classified as a technical countermeasure?
  • What does a packet filter firewall analyze to determine access permissions?
  • What does risk transference refer to in a security context?
  • What is a virus in the context of computer security?
  • What does WPA2 use for encryption?
  • Which of the following describes fuzzing most accurately?
  • What approach do professional pen-testers take?
  • What type of cryptographic technique transposes the order of letters or words to obscure meaning?
  • What is the significance of using a random "salt" in a key derivation function?
  • What type of account provides high-level permissions for configurations and data access?
  • Which permission allows a user to modify file content?
  • What distinguishes a stream cipher from a block cipher?
  • Which of the following statements is true regarding stateful inspection firewalls?
  • What is a one-time passphrase used for?
  • What does a routing table contain?
  • Which type of firewall is the most common in use today?
  • Which response from a server indicates an open port?
  • What is the primary function of a port scanner?
  • What is the goal of implementing safeguards in security measures?
  • What action is typically taken by browsers when private browsing is enabled?
  • What is the main function of a data custodian?
  • What does a Request for Comment (RFC) document provide regarding a protocol?
  • What is a primary risk management tool for cloud consumers?
  • What characterizes a Trojan horse in cybersecurity?
  • What does the term "symmetric" refer to in symmetric cryptography?
  • What does penetration testing involve?
  • What are the place values used in a nibble?
  • What does it mean for a web page to be "defaced" in a drive-by download attack?
  • Which of the following defines a countermeasure?
  • Which attack type involves DNS server manipulation to provide false information?
  • What is the primary function of a rootkit?
  • What is SSH (Secure Shell) primarily used for?
  • What is the main goal of segmentation within a network?
  • Which wireless setup method is considered rare?
  • What can be a consequence of using a rogue access point?
  • What protocol uses port 443 for secure communications?
  • In symmetric encryption, what type of key is used?
  • Which service model allows customers to manage their own production applications while the provider manages hardware and core system applications?
  • In what way does indirect social engineering differ from other forms?
  • What does a 'bit' represent in computing?
  • Which type of cryptographic key is generally easier to manage?
  • Which three items are required for configuring IPv4?
  • According to Moore's Law, how often does processing speed double?
  • What is a network port?
  • A megabyte is equivalent to how many kilobytes?
  • Which term describes the transformation of plaintext to ciphertext?
  • What is the definition of a 'nibble' in data representation?
  • Which account type typically has restricted access to only its own files?
  • Which categories are used for antivirus detection?
  • What is a preimage attack?
  • What is the root directory in a computer's directory hierarchy?
  • What is a web cookie?
  • What is typically the role of a default gateway in a network?
  • Which of the following is an example of a wide area network?
  • What is a false positive in the context of an IDS?
  • What kind of data would be lost if only differential backups are used without regular full backups?
  • What is the term for unauthorized entry by following someone through a secure door?
  • What is the characteristic of a stateful inspection firewall regarding deep and shallow inspection?
  • What phase of an attack involves identifying assets that could be targeted for exploitation?
  • What main purpose do access controls serve in information security?
  • Which operating system is not case-sensitive and uses \ as a path separator?
  • What is the method for calculating the value of bytes?
  • Which statement best describes the cumulative effect of a differential backup?
  • What is the main benefit of Wi-Fi Protected Setup (WPS)?
  • What function does IPSec serve in a security protocol?
  • Which term describes the legal standard assessing how protective an organization is toward its assets?
  • A type of substitution cipher that employs multiple alphabets to enhance security is known as what?
  • What protocol does Diffie-Hellman use for key exchange?
  • What is Triple DES primarily known for?
  • Which component is essential for interpreting and executing program instructions on a computer?
  • How are incremental backups characterized?
  • In asymmetric encryption, what type of key is typically used?
  • Which tool is commonly used as a network utility for scanning?
  • What percentage of the Internet is considered the deep web?
  • Which of the following is indicated by a 400 Series server return code?
  • What is the primary function of encryption?
  • What does cryptography primarily focus on?
  • Which operating system is case-sensitive and uses / as a path separator?
  • What does a vulnerability scanner typically do?
  • What is the definition of a user in the context of a computer system?
  • What function does the robots.txt file serve on a web server?
  • Which feature of WPA2 helps ensure that each packet is unique?
  • What principle ensures that users have the minimum necessary access to perform their tasks?
  • What type of inspection allows a firewall to check only headers, making it faster but potentially less thorough?
  • Is Bluetooth susceptible to warXing attacks?
  • Which type of cipher is characterized by encrypting letters with another letter in a one-to-one relationship?
  • What defines a data spill in information security?
  • What does the security control hierarchy illustrate?
  • Who is considered the subject in an access control context?
  • What is the function of the Domain Name System (DNS)?
  • What is an all-in-one security appliance also known as?
  • What does the notation 0x signify in numeric representation?
  • What is juice jacking?
  • What is the primary purpose of an access control list (ACL)?
  • What is the purpose of likelihood and impact estimates in the risk management process?
  • What does hybrid cryptography combine?
  • What does SYN stand for in networking?
  • What does OS hardening aim to achieve?
  • Does the Internet Protocol (IP) guarantee delivery of packets?
  • What does Dynamic Host Configuration Protocol (DHCP) primarily do?
  • What is the main advantage of using hybrid cryptography?
  • What does the hexadecimal symbol 'A' represent in decimal?
  • What type of programming environment uses Java Virtual Machines?
  • How much does the keyspace increase with the addition of a bit?
  • What is the primary characteristic of the AES (Advanced Encryption Standard)?
  • What is the primary purpose of a directory in an operating system?
  • What is the total number of bits in a kilobyte?
  • What is the function of a cryptographic algorithm in relation to keys?
  • Which of the following is a key feature of heuristics detection methods in antivirus software?
  • What does the term "malware" refer to overall?
  • What type of key exchange methods can HTTPS utilize?
  • How does a vulnerability scanner enhance port scanning?
  • Which of the following best describes a symmetric key?
  • What are the three types of token authentication?
  • Which type of phone can bypass perimeter controls such as firewalls or content filters?
  • What defines an accidental insider?
  • Which service model allows a user to fully manage their applications on a cloud infrastructure?
  • How many bytes are there in a megabyte?
  • What is the role of awareness training in administrative countermeasures?
  • What is Command and Control (C2) in cybersecurity?
  • What is the encryption used by WPA3?
  • What is the equivalent of a gigabyte in megabytes?
  • In a Linux system, what is the account referred to as User #0?
  • Which term describes a network of compromised devices that can be controlled by an attacker?
  • What is the term for following someone through a secure door without authorization?
  • What type of network security device is a web application firewall designed to protect against?
  • What is the goal of domain hijacking?
  • What does a MAC address do?
  • What is the range of possible byte values in computing?
  • Which encryption protocol replaced WEP?
  • Which of the following describes authentication?
  • What is commonly referred to as an "evil twin" access point?
  • What type of storage does RAM provide in a computer system?
  • What characterizes a disgruntled insider threat?
  • What is the value of a kilobyte in bytes?
  • What is NOT a purpose of the gaining access phase?
  • What does keyspace refer to?
  • Which aspect of cloud computing distinguishes it from traditional computing?
  • What is the main purpose of using a one-way hash in communications?
  • How does a web cookie contribute to HTTP traffic?
  • What does lateral movement refer to in cybersecurity?
  • What is the purpose of a Pre-shared Key (PSK) in wireless networking?
  • What does biometrics authentication rely on?
  • What is a characteristic of social engineering attacks?
  • What does "likelihood" refer to in the context of risk assessment?
  • In the context of access controls, what does ACE stand for?
  • How many bytes are contained within an IP address?
  • In Windows, what is the purpose of NTFS?
  • What is an example of an administrative countermeasure?
  • What does accountability in an information system offer?
  • What kind of content does the surface web consist of?
  • What is a common term for a wireless access point?
  • What does an Access Control Entry (ACE) contain in a Windows environment?
  • What is the primary concern of a threat to information security?
  • Which backup type is most recommended for situations where reliability is essential and time for recovery is critical?
  • What is cryptojacking?
  • Which of the following describes a BlueSniper rifle?
  • In a scenario with multiple permission sets in place, which type of permission takes effect?
  • What does the presence of a malicious add-on usually indicate?
  • What role does a data custodian play in implementing security measures?
  • How does a Graphical User Interface (GUI) function?
  • What is the primary function of the Internet Control Message Protocol (ICMP)?
  • What action is commonly taken during maintaining access?
  • Which of the following is an example of something you have in terms of authentication?
  • In which scenario would a full system image backup be most beneficial?
  • What is the primary purpose of a digital signature?
  • What is active content primarily used for on a computer?
  • In cybersecurity, which action describes pivoting?
  • What is defined as anything that can potentially cause harm to assets or people?
  • What distinguishes a persistent cookie?
  • Which bit is referred to as 'low-order' or 'least-significant'?
  • What is a domain attack?
  • When a port scanner sends a SYN to a server, what are two possible responses that can be received?
  • What is the primary objective of gap analysis?
  • What is the value range for a nibble in computing?
  • How many digits does the base 10 number system consist of?
  • What is the digit range in the binary number system?
  • What is a malicious add-on?
  • What do offensive countermeasures aim to accomplish?
  • What is the primary purpose of WEP?
  • Which access control model allows the owner of an object to delegate permissions to other users?
  • What could be a main characteristic of an external insider?
  • Which protocol is used to communicate error messages related to IP?
  • Which algorithm is used for encryption, digital signatures, and secure key exchange?
  • Which of the following is NOT a method of handling risk?
  • What is the function of a key encryption key (KEK)?
  • What is the definition of a user account in a computing context?
  • What is a full system image backup?
  • Why is it important to regularly schedule backups?
  • What feature does signature detection in antivirus software rely on?
  • What are the place values of bits in a byte?
  • What defines multifactor authentication?
  • What is the initial input for a key derivation function (KDF)?
  • Which of the following is NOT a characteristic of the zero trust security model?
  • What does a packet represent in a network?
  • What is the main purpose of a hashing function?
  • What does a 300 Series server return code signify?
  • How does heuristics detection identify potential threats?
  • What is primarily involved in asset identification?
  • Which step in the risk management process determines how important the assets are?
  • Which statement best describes elliptic curve cryptography (ECC)?
  • What does deep inspection in a firewall involve?
  • Can Bluetooth signals be intercepted beyond their typical operational range?
  • What is a birthday attack?
  • What is a session key?
  • What is the purpose of authentication in information security?
  • ASCII is a system used for encoding what type of values?
  • What is an important function of a user ID in an operating system?
  • What process does blockchain use to maintain security?
  • What typically defines the length of ciphertext in a running key encryption method?
  • What does risk avoidance involve?
  • What is the main purpose of a rootkit in an attack scenario?
  • What does a Group ID represent in a computing environment?
  • Why is MD5 considered antiquated?
  • What is a Command Line Interface (CLI)?
  • In networking, what is the consequence of a packet arriving out of order at its destination?
  • Which measure is most directly related to reducing vulnerability?
  • In information security, what does the term 'access control' generally relate to?
  • In Linux, what term is used for what Windows calls a folder?
  • What occurs during an exclusive lookup?
  • Can MAC addresses be encrypted to enhance security?
  • Which term describes the number used by a computer to recognize a user account?
  • Which of the following is the purpose of an encryption key?
  • What is a kernel in the context of an operating system?
  • What is a primary function of a web application firewall (WAF)?
  • In what manner does spyware typically operate?
  • What is an example of a potential risk when using public charging stations?
  • What does 'high-order' or 'most-significant' refer to in binary numbers?
  • What does role-based access control (RBAC) primarily focus on?
  • Which attack targets a specific group of individuals who visit the same website?
  • Why is it important to respond effectively to security incidents?
  • What is the function of the CPU in a computer system?
  • Which process step is concerned with finding gaps in current security measures?
  • Which of the following is true about Linux file systems?
  • What is the primary goal of secure coding?
  • What is a VPN primarily used for?
  • What does Desktop as a Service (DaaS) enable users to do?
  • What technique involves gaining compromising information by observing someone from a close distance?
  • When might cognitive password systems be used?
  • Which cryptographic method is faster?
  • What does the prudent person rule require of an organization?
  • When should you ideally perform a differential backup?
  • What is a logic bomb?
  • What is the main feature of User Datagram Protocol (UDP) compared to TCP?
  • How should vulnerabilities be addressed to improve security?
  • Which type of backup only copies data items that have changed since the last backup?
  • What capability does an intrusion prevention system (IPS) provide?
  • Which of the following describes a device that requests services from a server?
  • In terms of network management, what is a primary benefit of segmentation?
  • What principle aims to prevent users from accessing more information than necessary?
  • Which of the following methods is NOT typically a part of wireless device setup?
  • Which protocol is considered interim before more secure protocols were adopted?
  • What does ciphertext refer to?
  • What is the definition of a group in the context of user accounts?
  • How many gigabytes are in a terabyte?
  • What does a biometric system compare during authentication?
  • What does permission refer to in an IT security context?
  • Which of the following statements is true regarding a false positive?
  • When securing a wireless network, why is it advisable to assume effectively infinite distance?
  • What port number does HTTP typically use?
  • What is pretexting in the context of social engineering?
  • What does the prefix "0d" represent in numbering systems?
  • What defines an enclave in network security?
  • What is one characteristic of a well-configured personal firewall?
  • What type of attack involves an attacker associating their MAC address with someone else's IP address to intercept traffic?
  • What does the term "pivot to admin" relate to?
  • Which hash algorithm is commonly used in government applications but is being phased out?
  • What is the primary function of a sniffer?
  • What constitutes a rogue access point?
  • Which activity involves informing individuals of the rules they must follow in an organization?
  • What does application allowlisting do?
  • Why is security training essential for employees?
  • What is signcryption?
  • What does using symmetric key encryption primarily ensure?
  • Which of the following best defines a block cipher?
  • What is the meaning of RST in networking?
  • Which type of firewall is known for blocking network access from external networks while potentially causing latency issues?
  • During an attack, what does lateral movement accomplish?
  • What is the final phase in the attack lifecycle where attackers hide their tracks?
  • What is a risk associated with using password lockout on internet-facing accounts?
  • What does reducing risks associated with high Wi-Fi signal range imply for a network?
  • Which of the following is NOT one of the five phases of an attack?
  • Which programming language is commonly used to create interactive effects within web browsers?
  • What is a potential drawback of using only differential backups?
  • Which of the following best describes the function of a DMZ in network architecture?
  • What does the prefix "0b" indicate in number systems?
  • What are two common methods for setting up Wi-Fi devices?
  • What is a benefit of using an all-in-one security appliance?
  • What is the primary purpose of patch management in an organization?
  • In networking terms, what does ACK represent?
  • What does a TCP/IP protocol primarily facilitate?
  • What is the maximum throughput for Wi-Fi 6/6E (802.11ax)?
  • What is meant by authorization in information security?
  • In which phase of the risk management process is the financial impact of a threat assessed?
  • What does the key exchange process involve?
  • Which of the following accurately describes a hard drive?
  • Which role has the legal responsibility to protect an organization's assets?
  • What is the goal of risk mitigation in the context of asset protection?
  • What are the three predefined Linux file permissions?
  • What does Port Address Translation (PAT) allow multiple devices to do?
  • What is exploit software primarily used for?
  • What defines spear phishing?
  • What type of phishing uses a deep fake voice impersonation?
  • What is the zero trust security model based on?
  • What does virtualization create on a single computing device?
  • What is a malware development kit/factory?
  • What is the goal of threat hunting?
  • What is the purpose of security policies in an organization?
  • What does spyware do?
  • What is the role of a security procedure?
  • What is the main function of a sinkhole in network security?
  • Which of the following are typical file permissions in a computing system?
  • What does escrow in the context of information security refer to?
  • What does the acronym "DaaS" stand for in cloud computing?
  • What is the primary purpose of RAM in a computer system?
  • Which attack strategy is most effective when the attacker has both plaintext and ciphertext for analysis?
  • What does ECDH stand for in cryptography?
  • What can potentially be a drawback of proxy firewalls?
  • Which of the following is an example of something-we-know authentication?
  • What is the purpose of a security protocol?
  • In network security, what does false negative entail?
  • What is a Pseudo-random number generator (PRNG) used for in computers?
  • What is the primary role of Public Key Infrastructure (PKI)?
  • What role does accountability play in securing information systems?
  • What happens if the full backup is lost and only the differential backups are available?
  • Which of the following phases precedes Gaining access in an attack?
  • What defines the hexadecimal number system?
  • Who is responsible for using the data and ensuring its proper management?
  • What is a running key in the context of encryption?
  • Which of the following services is considered a delivery model for the cloud focused primarily on software deployment?
  • What is the primary vulnerability of monoalphabetic ciphers?
  • What is the primary function of Bluetooth technology?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy