Demo Questions

Question 1
Which of the following is a wireless network detector that is commonly found on Linux?

  • A: Kismet
  • B: Abel
  • C: Netstumbler
  • D: Nessus

Question 2
A security consultant decides to use multiple layers of anti-virus defense, such as end user desktop anti-virus and E-mail gateway. 
This approach can be used to mitigate which kind of attack?

  • A: Forensic attack
  • B: ARP spoofing attack
  • C: Social engineering attack
  • D: Scanning attack

Question 3
Which of the following act requires employer's standard national numbers to identify them on standard transactions?

  • A: SOX 
  • B: HIPAA
  • C: DMCA
  • D: PCI-DSS

Question 4
Which of the following is an NMAP script that could help detect HTTP Methods such as GET, POST, HEAD, PUT, DELETE, TRACE?

  • A: http-git
  • B: http-headers
  • C: http enum
  • D: http-methods

Question 5
What is the process of logging, recording, and resolving events that take place in an organization?

  • A: Incident Management Process
  • B: Security Policy
  • C: Internal Procedure
  • D: Metrics

Question 6
You are manually conducting Idle Scanning using Hping2. During your scanning you notice that almost every query increments the IPID regardless of the port being queried. One or two of the queries cause the IPID to increment by more than one value. Why do you think this occurs?

  • A: The zombie you are using is not truly idle.
  • B: A stateful inspection firewall is resetting your queries.
  • C: Hping2 cannot be used for idle scanning.
  • D: These ports are actually open on the target system.

Question 7
Darius is analysing IDS logs. During the investigation, he noticed that there was nothing suspicious found and an alert was triggered on normal web application traffic. 
He can mark this alert as:

  • A: False-Negative
  • B: False-Positive
  • C: True-Positive
  • D: False-Signature

Question 8
The Open Web Application Security Project (OWASP) is the worldwide not-for-profit charitable organization focused on improving the security of software. 
What item is the primary concern on OWASP's Top Ten Project Most Critical Web Application Security Risks?

  • A: Injection
  • B: Cross Site Scripting
  • C: Cross Site Request Forgery
  • D: Path disclosure

Question 9
A recent security audit revealed that there were indeed several occasions that the company's network was breached. After investigating, you discover that your IDS is not configured properly and therefore is unable to trigger alarms when needed. What type of alert is the IDS giving?

  • A: True Positive
  • B: False Negative
  • C: False Positive
  • D: False Positive

Question 10
A Network Administrator was recently promoted to Chief Security Officer at a local university. One of employee's new responsibilities is to manage the implementation of an RFID card access system to a new server room on campus. The server room will house student enrollment information that is securely backed up to an off-site location. 
During a meeting with an outside consultant, the Chief Security Officer explains that he is concerned that the existing security controls have not been designed properly. Currently, the Network Administrator is responsible for approving and issuing RFID card access to the server room, as well as reviewing the electronic access logs on a weekly basis. 
Which of the following is an issue with the situation?

  • A: Segregation of duties
  • B: Undue influence
  • C: Lack of experience
  • D: Inadequate disaster recovery plan


