Browse all practice questions for the GIAC Information Security Fundamentals (GISF) Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

GIAC Information Security Fundamentals (GISF) Practice Test course image
More practice questions

These questions are part of the practice quiz. Start practicing

  • What is a distributed denial-of-service (DDoS) attack?
  • What happens if the full backup is lost and only the differential backups are available?
  • In a binary system, how is the value of a byte determined?
  • What function does gateway antivirus serve in a network?
  • Which one of the following best describes asymmetric cryptography?
  • Which programming language is commonly used to create interactive effects within web browsers?
  • Which wireless setup method is considered rare?
  • What is the historical significance of Triple DES?
  • What does the acronym "DaaS" stand for in cloud computing?
  • What is the primary purpose of RAM in a computer system?
  • What type of attack involves an attacker associating their MAC address with someone else's IP address to intercept traffic?
  • What is the ultimate goal of creating backups in information security?
  • What does it mean for a web page to be "defaced" in a drive-by download attack?
  • Which permission allows a user to modify file content?
  • What technique involves gaining compromising information by observing someone from a close distance?
  • What is a domain attack?
  • Who in an organization has primary responsibility and knowledge of data management?
  • What is an essential characteristic of effective gap analysis?
  • What is signcryption?
  • Which of the following best describes the concept of confidentiality in security?
  • What is a common term for a wireless access point?
  • What does a 'bit' represent in computing?
  • A megabyte is equivalent to how many kilobytes?
  • What does Dynamic Host Configuration Protocol (DHCP) primarily do?
  • Which phishing attack method is characterized by the use of SMS text messages?
  • How does a vulnerability scanner enhance port scanning?
  • Which of the following best describes a symmetric key?
  • What is the primary function of encryption?
  • Why is authentication essential in information security?
  • In information security, what does the term 'access control' generally relate to?
  • What is the purpose of patching an operating system?
  • What is primarily involved in asset identification?
  • Which type of backup only copies data items that have changed since the last backup?
  • What type of phishing attack specifically targets wealthy or powerful individuals?
  • What is the purpose of authentication in information security?
  • What is the primary function of Bluetooth technology?
  • What is a unique characteristic of MAC addresses?
  • What does reducing risks associated with high Wi-Fi signal range imply for a network?
  • What are the three types of token authentication?
  • What is the purpose of Elliptic Curve Cryptography (ECC)?
  • What is the primary purpose of WEP?
  • How does a buffer overflow attack typically operate?
  • What file system does Windows use for managing access control?
  • Which term describes a condition that allows a threat to potentially exploit a system?
  • What is the network port number commonly used for FTP?
  • What is a risk associated with using password lockout on internet-facing accounts?
  • Which of the following statements best captures the essence of risk ignorance?
  • Which type of phishing is conducted through telephone calls or VoIP systems?
  • Which attack targets a specific group of individuals who visit the same website?
  • What does the notation 0x signify in numeric representation?
  • What do firewall rules typically determine?
  • What is the purpose of Network Address Translation (NAT)?
  • What is the role of a security procedure?
  • What does a digital certificate primarily certify?
  • What is a common characteristic of exploit software?
  • What does hybrid cryptography combine?
  • What does cryptanalysis involve?
  • What is a Pseudo-random number generator (PRNG) used for in computers?
  • What does 'Availability' imply in information security?
  • How does heuristics detection identify potential threats?
  • What is meant by authorization in information security?
  • Which of the following describes a BlueSniper rifle?
  • When a port scanner sends a SYN to a server, what are two possible responses that can be received?
  • Which component is essential for interpreting and executing program instructions on a computer?
  • What type of information does the File Transfer Protocol (FTP) transmit?
  • When discussing data representation, what does 'octet' refer to?
  • What is the goal of threat hunting?
  • What is the primary purpose of content filtering in a network?
  • Why is it important to respond effectively to security incidents?
  • Which type of phone can bypass perimeter controls such as firewalls or content filters?
  • In the binary system, which of the following represents the highest digit?
  • What role does a data custodian play in implementing security measures?
  • What is the primary vulnerability of monoalphabetic ciphers?
  • What key advantage does using both differential and full backups provide?
  • Who is responsible for using the data and ensuring its proper management?
  • Which of the following components is part of a digital certificate?
  • In the context of cryptography, what is an important consideration aside from confidentiality?
  • What does accountability in an information system offer?
  • How many gigabytes are in a terabyte?
  • What is the essence of cloud computing?
  • Which term best describes actions taken to lessen the impact of a vulnerability?
  • What is plaintext in the context of cryptography?
  • What is a characteristic of social engineering attacks?
  • What does decryption accomplish?
  • What does biometrics authentication rely on?
  • Which of the following is a key feature of heuristics detection methods in antivirus software?
  • What does a routing table contain?
  • Which of the following best describes the goal of a botnet?
  • What is the primary role of firewall rules?
  • What does an Access Control Entry (ACE) contain in a Windows environment?
  • Which of the following is a detailed explanation of how to implement a security policy?
  • Which cryptographic process would involve reorganizing the input data into a format suitable for security?
  • What does WEP stand for in the context of Wi-Fi security?
  • Which protocol is primarily responsible for sending emails?
  • What is the purpose of cognitive password authentication?
  • Which term describes the transformation of plaintext to ciphertext?
  • Which step follows the asset valuation in the risk management process?
  • What is a potential drawback of using only differential backups?
  • What does SSID stand for in the context of wireless networking?
  • What is an example of a potential risk when using public charging stations?
  • What does TKIP stand for?
  • Which three items are required for configuring IPv4?
  • What is Command and Control (C2) in cybersecurity?
  • Can Bluetooth signals be intercepted beyond their typical operational range?
  • DES stands for what in the context of cryptography?
  • What does the prefix "0b" indicate in number systems?
  • What is the definition of a group in the context of user accounts?
  • How are offensive countermeasures related to active defense?
  • What is the purpose of a Pre-shared Key (PSK) in wireless networking?
  • What is Triple DES primarily known for?
  • What is a running key in the context of encryption?
  • Which type of firewall is the most common in use today?
  • What does a physical countermeasure primarily involve?
  • Which attack method uses known plaintext to determine the key of ciphertext?
  • What is the term for an infection vector that uses attractive USB drives left in public areas?
  • Which type of security solution monitors the environment and takes automatic action against unauthorized access attempts?
  • In risk management, what does risk acceptance imply?
  • What is the term for following someone through a secure door without authorization?
  • What does lateral movement refer to in cybersecurity?
  • What does application allowlisting do?
  • What is a machine-in-the-middle attack?
  • Why is it important to implement both signature and heuristics detection in antivirus software?
  • Which type of hacking method is exemplified by spear phishing?
  • Which of the following describes a feature of a worm?
  • What is involved in the response phase of incident management?
  • In Linux, what term is used for what Windows calls a folder?
  • What type of inspection allows a firewall to check only headers, making it faster but potentially less thorough?
  • What is the primary function of a sniffer?
  • What is the purpose of the 'chmod' command in Linux?
  • What is the role of a default gateway in a network?
  • What is the purpose of ransomware?
  • What is the goal of domain hijacking?
  • Which term describes a network of compromised devices that can be controlled by an attacker?
  • Which term describes the number used by a computer to recognize a user account?
  • What constitutes a rogue access point?
  • What are the place values used in a nibble?
  • Which of the following best defines a block cipher?
  • What does the concept of accountability help prevent in information security?
  • What is the final phase in the attack lifecycle where attackers hide their tracks?
  • Which of the following is classified as a technical countermeasure?
  • What can be a consequence of using a rogue access point?
  • What is a web cookie?
  • What is the main function of a data custodian?
  • What security measures are utilized in Bluetooth's secure simple pairing?
  • What is the ideal frequency to perform full backups?
  • What does the Ping command do in network troubleshooting?
  • What role does a client play in a network?
  • What is the term for unauthorized entry by following someone through a secure door?
  • What is the key length of the AES-128 encryption standard?
  • What is steganography primarily used for?
  • In symmetric encryption, what type of key is used?
  • Which of the following protocols would likely be used for email transmission?
  • In the context of access controls, what does ACE stand for?
  • Which aspect of the CIA Triad ensures that information is only accessible to those authorized?
  • Which protocol is known for achieving higher transmission speeds at the cost of reliability?
  • Which protocol is used to communicate error messages related to IP?
  • What action is commonly taken during maintaining access?
  • Which of the following approaches may be taken when some risks cannot be completely avoided or mitigated?
  • What is a potential target for attackers when using application allowlisting?
  • How many bits are there in a byte?
  • Which elements are critical for a good information system?
  • What does spyware do?
  • Which phase of an attack involves installing tools to ensure undetected access?
  • What does the term "symmetric" refer to in symmetric cryptography?
  • What does OS hardening aim to achieve?
  • What is the primary purpose of a directory in an operating system?
  • What does ECDH stand for in cryptography?
  • What is the main feature of User Datagram Protocol (UDP) compared to TCP?
  • What defines a Local Area Network (LAN)?
  • What occurs when a hashing algorithm generates the same hash for different inputs?
  • What is the primary function of a rootkit?
  • What is the role of a personal firewall?
  • What does a 500 Series server return code indicate?
  • What type of attack uses social engineering to manipulate a DNS registrar?
  • What defines multifactor authentication?
  • What does ciphertext refer to?
  • Is Bluetooth susceptible to warXing attacks?
  • What essential tactic is at the core of social engineering attacks?
  • What role does the chief information security officer (CISO) typically play in an organization?
  • What action is typically taken by browsers when private browsing is enabled?
  • Which of the following statements is true regarding stateful inspection firewalls?
  • What characterizes a disgruntled insider threat?
  • What is privilege escalation?
  • Which of the following accurately describes a characteristic of AES-128?
  • What is a VPN primarily used for?
  • In the context of information security, what is the significance of the reconnaissance phase?
  • In a substitution cipher, what method is used to replace units of a message?
  • What feature does signature detection in antivirus software rely on?
  • Which tool is commonly used to identify vulnerabilities in systems?
  • What is the purpose of the Address Resolution Protocol (ARP)?
  • What does the term "detect" refer to in a security context?
  • What does DMZ stand for in a network context?
  • What is the primary goal of the gaining access phase in an attack?
  • Which role has the legal responsibility to protect an organization's assets?
  • What term describes the assurance that data is correct and maintained by authorized personnel?
  • Which response from a server indicates an open port?
  • What type of encryption does Bluetooth's secure simple pairing use?
  • Which Wi-Fi standard offers the highest throughput currently available?
  • Which of the following is an example of something you have in terms of authentication?
  • Which type of cryptography requires the same key for both encryption and decryption?
  • What is the main function of a sinkhole in network security?
  • What characterizes a Wide Area Network (WAN)?
  • In a Linux system, what is the account referred to as User #0?
  • What does a one-way hash function provide in terms of data integrity?
  • A type of substitution cipher that employs multiple alphabets to enhance security is known as what?
  • How does a web cookie contribute to HTTP traffic?
  • Which aspect of cloud computing distinguishes it from traditional computing?
  • What is cryptocurrency?
  • What is the value of a terabyte in megabytes?
  • What is the definition of a user account in a computing context?
  • What encryption method is used by WPA2?
  • What does wardriving involve?
  • What is the purpose of a security protocol?
  • In cybersecurity, which action describes pivoting?
  • What defines spear phishing?
  • Which type of cryptographic key is generally easier to manage?
  • What is the total number of bits in a kilobyte?
  • Which of the following is an example of spoofing?
  • In terms of network management, what is a primary benefit of segmentation?
  • What function does IPSec serve in a security protocol?
  • Who is considered the subject in an access control context?
  • Why is the order of rules important in a packet filter firewall?
  • During an attack, what does lateral movement accomplish?
  • What type of protocol is Transmission Control Protocol (TCP)?
  • What technique involves injecting randomized data into software for testing purposes?
  • What is an all-in-one security appliance also known as?
  • Which class of Bluetooth is most commonly used?
  • What role does accountability play in securing information systems?
  • What does the term 'ciphertext' imply about the integrity of communication?
  • What is the primary role of Public Key Infrastructure (PKI)?
  • What is a virus in the context of computer security?
  • What is the primary objective of gap analysis?
  • What type of phishing uses a deep fake voice impersonation?
  • Which attack type involves DNS server manipulation to provide false information?
  • What is the zero trust security model based on?
  • What type of storage does RAM provide in a computer system?
  • What is the root directory in a computer's directory hierarchy?
  • What is the main purpose of a hashing function?
  • What defines the hexadecimal number system?
  • What is the term "WarXing" used to describe?
  • Which of the following is true about Linux file systems?
  • What command is used in Linux to change file or directory permissions?
  • Which type of firewall is known for blocking network access from external networks while potentially causing latency issues?
  • Which Wi-Fi security protocols are currently considered secure?
  • What could be a main characteristic of an external insider?
  • What is the value of a kilobyte in bytes?
  • What is a backup?
  • What is a malware development kit/factory?
  • Which type of attack would suggest that a hash function is compromised?
  • What does penetration testing involve?
  • What is the primary characteristic of the AES (Advanced Encryption Standard)?
  • What protocol uses port 443 for secure communications?
  • Which aspect is critical to the function of hardware that is part of the security control hierarchy?
  • Which term describes the legal standard assessing how protective an organization is toward its assets?
  • Which device commonly uses DHCP to obtain an IP address?
  • What is a session key?
  • What does the term "impact" refer to in the context of risk assessment?
  • What is the main advantage of using hybrid cryptography?
  • Why is it important to regularly schedule backups?
  • Which of the following describes authentication?
  • What does risk avoidance involve?
  • Which of the following roles primarily utilizes the data within an organization?
  • What is the primary purpose of implementing detection and reaction capabilities in risk management?
  • What principle aims to prevent users from accessing more information than necessary?
  • What is the primary meaning of privilege in information security?
  • What is the main purpose of using a one-way hash in communications?
  • What is a differential backup?
  • What is the encryption used by WPA3?
  • What principle ensures that users have the minimum necessary access to perform their tasks?
  • Which tool is commonly used as a network utility for scanning?
  • What does a TCP/IP protocol primarily facilitate?
  • What does Shadow IT refer to?
  • Which service model allows a user to fully manage their applications on a cloud infrastructure?
  • What is a birthday attack?
  • What is the purpose of security policies in an organization?
  • In which scenario would a full system image backup be most beneficial?
  • What is the aim of preventive measures in security?
  • How many digits does the base 10 number system consist of?
  • What is an important function of a user ID in an operating system?
  • What does the hexadecimal symbol 'A' represent in decimal?
  • What is meant by implicit denial in access control?
  • Which feature of WPA2 helps ensure that each packet is unique?
  • What does active defense refer to?
  • What is the purpose of the covering tracks phase in an attack?
  • Which cryptographic method is faster?
  • What does risk transference refer to in a security context?
  • What is a brute force attack?
  • What does the Consensus Assessment Initiative Questionnaire (CAIQ) allow cloud customers to do?
  • What does the term "pivot to admin" relate to?
  • What is exploit software primarily used for?
  • What is "work factor" in the context of cryptography?
  • What is the maximum throughput for Wi-Fi 6/6E (802.11ax)?
  • What distinguishes indirect social engineering from direct social engineering?
  • What does maximum password aging require?
  • What defines a data spill in information security?
  • What are the place values of bits in a byte?
  • What does accountability in a security context refer to?
  • What does the presence of a malicious add-on usually indicate?
  • What is the function of a key encryption key (KEK)?
  • Which of the following services is considered a delivery model for the cloud focused primarily on software deployment?
  • Which statement best describes elliptic curve cryptography (ECC)?
  • What is a primary risk management tool for cloud consumers?
  • In what way does indirect social engineering differ from other forms?
  • What is a primary function of a web application firewall (WAF)?
  • What is the standard port number for Simple Mail Transfer Protocol (SMTP) used to send email?
  • What does a weak key attack exploit?
  • What is the definition of a user in the context of a computer system?
  • What distinguishes a persistent cookie?
  • What is a key in the context of cryptography?
  • Which operation is fundamental to modern encryption schemes and compares two binary bits?
  • What does SYN stand for in networking?
  • What does permission refer to in an IT security context?
  • What does the term 'network' refer to in a computing context?
  • What are access controls used for?
  • Does the Internet Protocol (IP) guarantee delivery of packets?
  • What does a Group ID represent in a computing environment?
  • What does the key exchange process involve?
  • What is the result when adding the high-order and low-order nibbles together?
  • What does Desktop as a Service (DaaS) enable users to do?
  • How should vulnerabilities be addressed to improve security?
  • What defines an accidental insider?
  • What distinguishes a stream cipher from a block cipher?
  • What does the process of verification in authentication involve?
  • What is the primary function of a port scanner?
  • What port number does HTTP typically use?
  • What is the primary function of the Internet Control Message Protocol (ICMP)?
  • Which user account type can access shared resources but with limited permissions?
  • Which service model allows customers to manage their own production applications while the provider manages hardware and core system applications?
  • What is the goal of implementing safeguards in security measures?
  • What is the second phase of an attack where vulnerable assets are identified?
  • What is one of the primary concerns regarding the use of attractive USB drives left in public areas?
  • What is a Command Line Interface (CLI)?
  • What type of account provides high-level permissions for configurations and data access?
  • What is juice jacking?
  • What is the key factor that a senior manager decides regarding organizational risk?
  • Which of the following phases precedes Gaining access in an attack?
  • What does non-repudiation refer to in the context of information security?
  • What is the concept of island hopping in the context of cybersecurity?
  • What is the definition of a 'nibble' in data representation?
  • Maintaining access is which number phase in the attack lifecycle?
  • What typically defines the length of ciphertext in a running key encryption method?
  • What is the primary function of a firewall?
  • What is a primary risk associated with the dark web?
  • Which categories are used for antivirus detection?
  • Which type of device typically uses dynamic IP addresses?
  • What percentage of the Internet is considered the deep web?
  • What does spoofing mean in the context of cybersecurity?
  • Which protocol is primarily responsible for routing packets across interconnected networks?
  • Which of the following is NOT a property of signcryption?
  • What is the primary purpose of antivirus software?
  • What is the significance of classifying alerts as true positive, false positive, true negative, and false negative?
  • What is the combined value of all place values in a full byte?
  • What is the goal of risk mitigation in the context of asset protection?
  • What does "likelihood" refer to in the context of risk assessment?
  • What does the term "proprietary algorithm" commonly imply in cryptography?
  • What is the significance of using a random "salt" in a key derivation function?
  • What does a biometric system compare during authentication?
  • What is a key component of asset valuation?
  • Frequency analysis is primarily used against which type of cryptographic method?
  • What is typically the action denied to a non-privileged user account?
  • Which of the following actions would most likely enable an attacker to gain higher privileges?
  • What kind of data would be lost if only differential backups are used without regular full backups?
  • What does Port Address Translation (PAT) allow multiple devices to do?
  • What is cryptojacking?
  • What does WPA2 use for encryption?
  • In network security, what does false negative entail?
  • How many bytes are contained within an IP address?
  • Which of the following is an example of a wide area network?
  • Which of the following is the correct abbreviation for a byte?
  • What is the function of the Domain Name System (DNS)?
  • What are two common methods for setting up Wi-Fi devices?
  • What does an algorithm represent in cryptography?
  • Which backup type is most recommended for situations where reliability is essential and time for recovery is critical?
  • To compute the value of nibbles, what is added after calculating the high-order nibble?
  • What is the main benefit of Wi-Fi Protected Setup (WPS)?
  • What is the purpose of likelihood and impact estimates in the risk management process?
  • Which account type typically has restricted access to only its own files?
  • How many bytes are there in a megabyte?
  • What type of user interface allows interaction through text and visual images like icons?
  • Which of the following best describes the function of a DMZ in network architecture?
  • What method of phishing attack uses text messages (SMS) to deceive victims?
  • Which of the following is a characteristic of JavaScript?
  • What is often a sign of a broken hashing algorithm?
  • What is the primary concern of a threat to information security?
  • What does a Request for Comment (RFC) document provide regarding a protocol?
  • Which of the following defines a countermeasure?
  • What does role-based access control (RBAC) primarily focus on?
  • What is the role of awareness training in administrative countermeasures?
  • Which type of cipher is characterized by encrypting letters with another letter in a one-to-one relationship?
  • Which of the following methods is NOT typically a part of wireless device setup?
  • What type of programming environment uses Java Virtual Machines?
  • How is a byte calculated when working with multiple bytes?
  • What does Software as a Service (SaaS) provide to its users?
  • What is a kernel in the context of an operating system?
  • What type of protocol is IP categorized as?
  • In a scenario with multiple permission sets in place, which type of permission takes effect?
  • What does a MAC address do?
  • What is a characteristic of Infrastructure as a Service (IaaS)?
  • Which of the following is NOT one of the five phases of an attack?
  • What is a network port?
  • What is normally considered when identifying countermeasures?
  • What is the initial input for a key derivation function (KDF)?
  • What is the purpose of private browsing in modern browsers?
  • What does HTML5 primarily incorporate to enhance interactivity?
  • What does a 200 Series server return code indicate?
  • What is the primary characteristic of the dark web?
  • Which of the following describes fuzzing most accurately?
  • What is identified during the threat identification step?
  • Which of the following is an example of something-we-know authentication?
  • Which of the following is indicated by a 400 Series server return code?
  • Which feature best describes asymmetric encryption?
  • What authentication system does Enterprise Level Authentication (ELA) rely on?
  • What does a packet represent in a network?
  • What is a false positive in the context of an IDS?
  • What is the main purpose of a rootkit in an attack scenario?
  • What does the concept of risk avoidance entail?
  • Which step in the risk management process determines how important the assets are?
  • What is the method for calculating the value of bytes?
  • What port number is used by the Post Office Protocol version 3 (POP3) for retrieving email?
  • What type of cryptographic technique transposes the order of letters or words to obscure meaning?
  • What is the primary purpose of a digital signature?
  • What kind of addresses does NAT translate?
  • Why is security training essential for employees?
  • Which hash algorithm is commonly used in government applications but is being phased out?
  • What phase of an attack involves identifying assets that could be targeted for exploitation?
  • What characterizes a Trojan horse in cybersecurity?
  • What is the main purpose of minimum password aging?
  • How does a Graphical User Interface (GUI) function?
  • During which process is a user granted specific access rights to resources?
  • How much does the keyspace increase with the addition of a bit?
  • In networking, what is the consequence of a packet arriving out of order at its destination?
  • What does deep inspection in a firewall involve?
  • How are incremental backups characterized?
  • What does the term "malware" refer to overall?
  • What does the security control hierarchy illustrate?
  • What is a full system image backup?
  • What type of devices would typically be connected in a Local Area Network (LAN)?
  • What is the primary function of a network protocol?
  • What is the underlying technology that ensures the security of cryptocurrencies?
  • What is an Intrusion Detection System (IDS) primarily used for?
  • What is the role of an operating system (OS) on a computer?
  • What is NOT a purpose of the gaining access phase?
  • Which activity involves informing individuals of the rules they must follow in an organization?
  • What is the process of modifying an Apple mobile device to remove software restrictions known as?
  • What is a key benefit of using multifactor authentication?
  • What port number is associated with HTTPS?
  • What is a one-time passphrase used for?
  • What does virtualization create on a single computing device?
  • Which operating system is not case-sensitive and uses \ as a path separator?
  • What is a true negative in relation to an IDS/IPS?
  • Which of the following describes a device that requests services from a server?
  • What is a benefit of using an all-in-one security appliance?
  • Which of the following are typical file permissions in a computing system?
  • Which bit is referred to as 'low-order' or 'least-significant'?
  • Which algorithm is used for encryption, digital signatures, and secure key exchange?
  • What is the function of a non-persistent cookie?
  • What is the value range for a nibble in computing?
  • What is a preimage attack?
  • What is pretexting in the context of social engineering?
  • What is an IP address?
  • According to Moore's Law, how often does processing speed double?
  • Which of the following is NOT a method of handling risk?
  • What is direct social engineering?
  • What does a true positive indicate in the context of an IDS?
  • What is the primary purpose of an access control list (ACL)?
  • Which of the following represents a bit?
  • What is the purpose of a Cloud Controls Matrix (CCM)?
  • What can potentially be a drawback of proxy firewalls?
  • Which measure is most directly related to reducing vulnerability?
  • In what manner does spyware typically operate?
  • What is SSH (Secure Shell) primarily used for?
  • What is the characteristic of a stateful inspection firewall regarding deep and shallow inspection?
  • What is meant by sideloading in mobile applications?
  • What kind of content does the surface web consist of?
  • What is a drive-by download?
  • What is the meaning of RST in networking?
  • What is the first step in the risk management process?
  • What does SHA stand for in cryptography?
  • In Windows, what is the purpose of NTFS?
  • What is defined as anything that can potentially cause harm to assets or people?
  • What does using symmetric key encryption primarily ensure?
  • Which of the following accurately describes cache poisoning?
  • What type of backup would allow quicker restoration of everyday files while maintaining full system recovery options?
  • What is a malicious add-on?
  • What does a vulnerability scanner typically do?
  • What is a digital envelope in the context of hybrid cryptography?
  • What does the 'C' in the CIA Triad stand for?
  • Which protocol is considered interim before more secure protocols were adopted?
  • What is an example of an administrative countermeasure?
  • What does ECDH combine with to facilitate encryption?
  • What process does blockchain use to maintain security?
  • ASCII is a system used for encoding what type of values?
  • What does a packet filter firewall analyze to determine access permissions?
  • What is the hexadecimal equivalent of the binary value 1010?
  • What is a logic bomb?
  • What main purpose do access controls serve in information security?
  • Which attack can involve sending unsolicited ARP requests or replies?
  • What is the function of a cryptographic algorithm in relation to keys?
  • What is the main goal of segmentation within a network?
  • When securing a wireless network, why is it advisable to assume effectively infinite distance?
  • Which of the following is the purpose of an encryption key?
  • What type of backup includes all data?
  • What is the main feature of the ICMP in the context of IP?
  • What occurs during an exclusive lookup?
  • Which of the following is NOT a characteristic of the zero trust security model?
  • What is the primary purpose of patch management in an organization?
  • What is one characteristic of a well-configured personal firewall?
  • What protocol does Diffie-Hellman use for key exchange?
  • What is active content primarily used for on a computer?
  • What does the prudent person rule require of an organization?
  • What does a denial-of-service (DoS) attack aim to achieve?
  • In what way do persistent cookies differ from non-persistent cookies?
  • What does a 300 Series server return code signify?
  • Which of the following accurately describes a hard drive?
  • What type of account usually has administrative privileges on a device or network?
  • What is commonly referred to as an "evil twin" access point?
  • When might cognitive password systems be used?
  • What does escrow in the context of information security refer to?
  • What are the three predefined Linux file permissions?
  • Which attack strategy is most effective when the attacker has both plaintext and ciphertext for analysis?
  • When should you ideally perform a differential backup?
  • What does cryptography primarily focus on?
  • What does compartmentalization in network security refer to?
  • What does 'high-order' or 'most-significant' refer to in binary numbers?
  • What is a primary characteristic of discretionary access controls (DAC)?
  • Which statement best describes the cumulative effect of a differential backup?
  • What does the second hexadecimal digit represent when calculating hexadecimal values?
  • What does keyspace refer to?
  • What defines an enclave in network security?
  • What type of network security device is a web application firewall designed to protect against?
  • What is a worm in the context of information security?
  • Which process step is concerned with finding gaps in current security measures?
  • Why is MD5 considered antiquated?
  • What does a key derivation function (KDF) produce?
  • What do offensive countermeasures aim to accomplish?
  • What does the operating system manage on behalf of the user?
  • In networking terms, what does ACK represent?
  • What does the acronym PDR stand for in the context of security management?
  • What is the main function of non-repudiation in communications?
  • What type of key exchange methods can HTTPS utilize?
  • Which operating system is case-sensitive and uses / as a path separator?
  • What is the main characteristic of a cryptographic key?
  • What does OS hardening typically involve?
  • What is the main objective of confirmed backup recovery?
  • What type of firewall filters traffic based on the state of existing connections?
  • What should a properly functioning IDS alert you about?
  • Which standard is commonly referred to as Wi-Fi 5?
  • In which phase of the risk management process is the financial impact of a threat assessed?
  • What approach do professional pen-testers take?
  • What is the equivalent of a gigabyte in megabytes?
  • What is the function of the CPU in a computer system?
  • What function does the robots.txt file serve on a web server?
  • What is the range of possible byte values in computing?
  • What does vulnerability analysis primarily assess?
  • What does the term 'cross-platform' refer to in programming?
  • What is the digit range in the binary number system?
  • What is a key characteristic of ciphertext-only attacks?
  • Which of the following best describes token authentication?
  • In asymmetric encryption, what type of key is typically used?
  • How does a differential backup compare to an incremental backup?
  • Which encryption protocol replaced WEP?
  • In hybrid cryptography, what role does the asymmetric key play?
  • What capability does an intrusion prevention system (IPS) provide?
  • Can MAC addresses be encrypted to enhance security?
  • In role-based access control (RBAC), what determines a user’s access permissions?
  • In a business email compromise (BEC) attack, the threat actor impersonates which entity to gain financial advantage?
  • How does an external insider gain access to a system?
  • What does the prefix "0d" represent in numbering systems?
  • Which access control model allows the owner of an object to delegate permissions to other users?
  • What is typically the role of a default gateway in a network?
  • Which of the following statements is true regarding a false positive?
  • Why might an organization want to reduce the power level on a Wi-Fi transmitter?
  • What is the function of a server in a network environment?
  • What is the primary goal of secure coding?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy