Question 1
An unauthorized individual enters a building following an employee through the employee entrance after the lunch rush. What type of breach has the individual just performed?
  1. Reverse Social Engineering
  2. Tailgating
  3. Piggybacking
  4. Announced
Correct answer: B
Question 2
Which of the following options represents a conceptual characteristic of an anomaly-based IDS over a signature-based IDS?
  1. Produces less false positives
  2. Can identify unknown attacks
  3. Requires vendor updates for a new threat
  4. Cannot deal with encrypted network traffic
Correct answer: B
Question 3
You are logged in as a local admin on a Windows 7 system and you need to launch the Computer Management Console from command line. 
Which command would you use?
  1. c:\gpedit
  2. c:\compmgmt.msc
  3. c:\ncpa.cp
  4. c:\services.msc
Correct answer: B
Question 4
_________ is a set of extensions to DNS that provide to DNS clients (resolvers) the origin authentication of DNS data to reduce the threat of DNS poisoning, spoofing, and similar types of attacks.
  2. Resource records
  3. Resource transfer
  4. Zone transfer
Correct answer: A
Question 5
PGP, SSL, and IKE are all examples of which type of cryptography?
  1. Hash Algorithm
  2. Digest
  3. Secret Key
  4. Public Key
Correct answer: D
Question 6
Which of the following scanning method splits the TCP header into several packets and makes it difficult for packet filters to detect the purpose of the packet?
  1. ICMP Echo scanning
  2. SYN/FIN scanning using IP fragments
  3. ACK flag probe scanning
  4. IPID scanning
Correct answer: B
Question 7
You have successfully gained access to a Linux server and would like to ensure that the succeeding outgoing traffic from this server will not be caught by Network-Based Intrusion Detection Systems (NIDS). 
What is the best way to evade the NIDS?
  1. Out of band signaling
  2. Protocol Isolation
  3. Encryption
  4. Alternate Data Streams
Correct answer: C
Question 8
What is the purpose of a demilitarized zone on a network?
  1. To scan all traffic coming through the DMZ to the internal network
  2. To only provide direct access to the nodes within the DMZ and protect the network behind it
  3. To provide a place to put the honeypot
  4. To contain the network devices you wish to protect
Correct answer: B
Question 9
The security administrator of ABC needs to permit Internet traffic in the host and UDP traffic in the host He also needs to permit all FTP traffic to the rest of the network and deny all other traffic. After he applied his ACL configuration in the router, nobody can access to the ftp, and the permitted hosts cannot access the Internet. According to the next configuration, what is happening in the network? 
  1. The ACL 104 needs to be first because is UDP
  2. The ACL 110 needs to be changed to port 80
  3. The ACL for FTP must be before the ACL 110
  4. The first ACL is denying all TCP traffic and the other ACLs are being ignored by the router
Correct answer: D
Question 10
When conducting a penetration test, it is crucial to use all means to get all available information about the target network. One of the ways to do that is by sniffing the network. 
Which of the following cannot be performed by the passive network sniffing?
  1. Identifying operating systems, services, protocols and devices
  2. Modifying and replaying captured network traffic
  3. Collecting unencrypted information about usernames and passwords
  4. Capturing a network traffic for further analysis
Correct answer: B

