Skip to main content

Computer Security Chapter Exam Questions - 673 Verified Questions

Page 1


Computer Security

Chapter Exam Questions

Course Introduction

Computer Security explores the fundamental principles and practices necessary to protect computer systems, networks, and data from unauthorized access, disruption, or destruction. The course examines topics such as cryptography, authentication, access control, malware, software vulnerabilities, network security protocols, and risk management. Students will analyze real-world security incidents, learn techniques for detecting and mitigating threats, and develop an understanding of legal, ethical, and policy issues surrounding cybersecurity. Through hands-on labs and case studies, participants gain practical skills to identify security gaps and implement effective defense strategies within various computing environments.

Recommended Textbook

Hands On Ethical Hacking and Network Defense 2nd Edition by Michael T. Simpson

Available Study Resources on Quizplus

13 Chapters

673 Verified Questions

673 Flashcards

Source URL: https://quizplus.com/study-set/2085 Page 2

Chapter 1: Ethical Hacking Overview

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/41510

Sample Questions

Q1) The International Council of Electronic Commerce Consultants (EC-Council) has developed a certification designation called ____.

A)CompTIA Security+

B)OSSTMM Professional Security Tester (OPST)

C)Certified Information Systems Security Professional (CISSP)

D)Certified Ethical Hacker (CEH)

Answer: D

Q2) In the ____________________ model, the tester is told what network topology and technology the company is using and is given permission to interview IT personnel and company employees.

Answer: white box

Q3) The ____ certification is designated by the Institute for Security and Open Methodologies (ISECOM), a nonprofit organization that provides security training and certification programs for security professionals.

A)CompTIA Security+

B)OSSTMM Professional Security Tester (OPST)

C)Certified Information Systems Security Professional (CISSP)

D)Certified Ethical Hacker (CEH)

Answer: B

To view all questions and flashcards with answers, click on the resource link above.

Page 3

Chapter 2: Tcpip Concepts Review

Available Study Resources on Quizplus for this Chatper

57 Verified Questions

57 Flashcards

Source URL: https://quizplus.com/quiz/41511

Sample Questions

Q1) What are the critical components of a TCP header? How may hackers abuse them?

Answer: As a security professional,you should know the critical components of a TCP header: TCP flags,the initial sequence number,and source and destination port numbers.Hackers abuse many of these TCP header components;for example,when port scanning,many hackers use the method of sending a packet with a SYN-ACK flag set even though a SYN packet was not sent first.

Q2) In the TCP/IP stack, the ____________________ layer represents the physical network pathway and the network interface card.

Answer: Network

Q3) What is a Class B IP address?

Answer: These address are evenly divided between a two-octet network and a two-octet host address,allowing more than 65,000 host computers per Class B network address.Large organizations and Internet service providers are often assigned Class B Internet addresses.Class B addresses have the format "network.network.node.node".

Q4) A hex number is written with two characters, each representing a byte.

A)True

B)False

Answer: False

To view all questions and flashcards with answers, click on the resource link above.

Page 4

Chapter 3: Network and Computer Attacks

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/41512

Sample Questions

Q1) type of DoS attack

A)shell

B)W32/Sobig.F

C)Luckysploit

D)Ping of Death

E)KeyGhost

F)Melissa

G)Back Orifice

H)Slammer

I)Mytob

Answer: D

Q2) The virus signature file is maintained by ____ software.

A)antivirus

B)keylogger

C)remote control

D)firewall

Answer: A

Q3) ____________________ or rootkits are computer programs that give attackers a means of regaining access to the attacked computer later.

Answer: Backdoors

To view all questions and flashcards with answers, click on the resource link above. Page 5

Chapter 4: Footprinting and Social Engineering

Available Study Resources on Quizplus for this Chatper

51 Verified Questions

51 Flashcards

Source URL: https://quizplus.com/quiz/41513

Sample Questions

Q1) To help prevent ____ attacks, you must educate your users not to type logon names and passwords when someone is standing directly behind them-or even standing nearby.

A)shoulder-surfing

B)footprinting

C)piggybacking

D)social engineering

Q2) Server received invalid response from upstream server

A)HTTP 400 Bad Request

B)HTTP 403 Forbidden

C)HTTP 404 Not Found

D)HTTP 405 Method Not Allowed

E)HTTP 408 Request Timeout

F)HTTP 500 Internal Server Error

G)HTTP 502 Bad Gateway

H)HTTP 503 Service Unavailable

I)HTTP 504 Gateway Timeout

Q3) Why is ATM shoulder surfing much easier than computer shoulder surfing?

Q4) What is the purpose of a Web bug? How do they relate to or differ from spyware?

Q5) What type of information is usually gathered by social engineering?

To view all questions and flashcards with answers, click on the resource link above. Page 6

Chapter 5: Port Scanning

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/41514

Sample Questions

Q1) In a Linux script, the line ____ is important because it identifies the file as a script.

A)#!/bin/sh

B)#!/bin/script

C)#!/bin/shscript

D)#!/bin/sc

Q2) ____ is a reasonably priced commercial port scanner with a GUI interface.

A)AW Security Port Scanner

B)Common Vulnerabilities and Exposures

C)Ethereal

D)Tcpdump

Q3) Nmap has a GUI version called ____________________ that makes it easier to work with some of the more complex options.

Q4) When a TCP three-way handshake ends, both parties send a(n) ____ packet to end the connection.

A)SYN

B)ACK

C)FIN

D)RST

Q5) What is a UDP scan?

To view all questions and flashcards with answers, click on the resource link above. Page 7

Chapter 6: Enumeration

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/41515

Sample Questions

Q1) LDAP (port ____) is the protocol used to access Novell's eDirectory, Microsoft Active Directory, and Apple Open Directory.

A)52

B)89

C)128

D)389

Q2) uses SUSE Linux as its OS

A)Windows 98

B)Windows 95

C)Windows Server 2003

D)Fedora Linux

E)Solaris

F)Windows XP Professional

G)Novell Open Enterprise Server

H)Windows 2000 Server/Professional

I)Windows NT 3.51 Server/Workstation

Q3) The enumeration process for Windows Me is the same as for Windows 98.

A)True

B)False

Q4) What is Hyena and what can it be used for?

To view all questions and flashcards with answers, click on the resource link above. Page 8

Chapter 7: Programming for Security Professionals

Available Study Resources on Quizplus for this Chatper

53 Verified Questions

53 Flashcards

Source URL: https://quizplus.com/quiz/41516

Sample Questions

Q1) What is a dangerous thing about programming in the C language?

Q2) In Perl, variables begin with the ____ character.

A)%

B)!

C)*

D)$

Q3) GNU C and C++ compilers

A)pseudocode

B)conversion specifier

C)class

D)bug

E)variable

F)do loop

G)compiler

H)while loop

I)gcc

Q4) Why is documenting computer programs essential?

Q5) List and describe the variable types used in C.

Q6) How does C's for loop work?

Q7) What is an algorithm? You may use an analogy to explain the concept.

To view all questions and flashcards with answers, click on the resource link above. Page 9

Chapter 8: Desktop and Server Os Vulnerabilities

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/41517

Sample Questions

Q1) For a Windows computer to be able to access a *nix resource, ____ must be enabled on both systems.

A)NetBIOS

B)SMB

C)CIFS

D)NetBEUI

Q2) SMB stands for _________________________.

Q3) What should a password policy include?

Q4) Microsoft's Systems Management Server (SMS) can manage security patches for all computers on a network.

A)True

B)False

Q5) The MBSA can check for missing security updates.

A)True

B)False

Q6) What functions do most Trojan programs perform?

Q7) To perform MBSA-style scans you can run the tool from the command line by using ____________________.exe.

Q8) What can a security tester using enumeration tools do?

Q9) Why should you review logs regularly? How should you accomplish this task? Page 10

To view all questions and flashcards with answers, click on the resource link above. Page 11

Chapter 9: Embedded Operating Systems: The Hidden Threat

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/41518

Sample Questions

Q1) The ____ worm spread by exploiting outdated or poorly configured router OSs that contained easy-to-guess passwords.

A)SQL Slammer

B)psyb0t

C)Melissa

D)Nimda

Q2) an operating system that runs in an embedded system

A)Windows Embedded Standard

B)Green Hill Software

C)RTLinux

D)VxWorks

E)RTEMS

F)embedded operating system

G)Quebec

H)QNX

I)SCADA

Q3) Many hackers today want more than just notoriety. What are they looking for and how do they accomplish it?

Q4) List at least four best practices for protecting embedded OSs.

Q5) What types of embedded systems are found in a typical corporate building?

To view all questions and flashcards with answers, click on the resource link above. Page 12

Chapter 10: Hacking Web Servers

Available Study Resources on Quizplus for this Chatper

52 Verified Questions

52 Flashcards

Source URL: https://quizplus.com/quiz/41519

Sample Questions

Q1) The column tag in CFML is ____.

A)<CFCOL>

B)<?COL>

C)<%COL>

D)<CFCOLUMN>

Q2) CGI programs can be written in many different programming and scripting languages, such as C/C++, Perl, UNIX shells, Visual Basic, and FORTRAN.

A)True

B)False

Q3) What is ActiveX Data Objects (ADO)?

Q4) ____ was originally used primarily on UNIX systems, but is used more widely now on many platforms, such as Macintosh and Windows.

A)HTML

B)JScript

C)VBScript

D)PHP

Q5) What can an attacker do after gaining control of a Web server?

Q6) In Windows, IIS stands for ______________________________.

Q7) What is VBScript?

To view all questions and flashcards with answers, click on the resource link above. Page 13

Chapter 11: Hacking Wireless Networks

Available Study Resources on Quizplus for this Chatper

52 Verified Questions

52 Flashcards

Source URL: https://quizplus.com/quiz/41520

Sample Questions

Q1) What is the IEEE 802.15 standard?

Q2) What is WEP? Is it a good way to secure wireless networks?

Q3) ____ is a product for conducting wardriving attacks written by Mike Kershaw. This product is free and runs on Linux, BSD, Mac OS X, and even Linux PDAs.

A)NetStumbler

B)Kismet

C)Wardriver

D)AirSnort

Q4) addresses wireless MANs for mobile users who are sitting in trains, subways, or cars

A)802.16

B)spread spectrum

C)802.11b

D)narrowband

E)802.20

F)infrared (IR)

G)802.1X

H)Bluetooth

I)HiperLAN2

Q5) What is the function of a WG of the IEEE?

To view all questions and flashcards with answers, click on the resource link above. Page 14

Chapter 12: Cryptography

Available Study Resources on Quizplus for this Chatper

58 Verified Questions

58 Flashcards

Source URL: https://quizplus.com/quiz/41521

Sample Questions

Q1) output of a hashing algorithm

A)asymmetric encryption

B)collision free

C)symmetric encryption

D)certificate

E)hashing

F)collision

G)stream cipher

H)message digest

I)block cipher

Q2) What is a certificate?

Q3) In a ____ attack, the attacker has the ciphertext of several messages that were encrypted with the same encryption algorithm but has no access to the plaintext, so he or she must try to figure out the key used to encrypt the data.

A)chosen-ciphertext

B)chosen-plaintext

C)known plaintext

D)ciphertext-only

Q4) What is a substitution cipher?

Q5) What is the difference between a public key and a private key?

Page 15

To view all questions and flashcards with answers, click on the resource link above.

Chapter 13: Network Protection Systems

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/41522

Sample Questions

Q1) ____ is a PHP-based honeypot that can be installed on any Apache Web Server system with PHP.

A)Decoy Server

B)NetBait

C)SANS Internet Storm Center

D)Honeyd

Q2) ____ monitor network devices so that security administrators can identify attacks in progress and stop them.

A)Firewalls

B)DMZs

C)Honeypots

D)IDSs

Q3) To see the router's routing table, a Cisco administrator would type this command:

A)show running-config

B)show startup-config

C)show interfaces

D)show ip route

Q4) List the components of a Cisco router.

Q5) What are the interfaces in a Cisco router?

To view all questions and flashcards with answers, click on the resource link above. Page 16

Turn static files into dynamic content formats.

Create a flipbook
Computer Security Chapter Exam Questions - 673 Verified Questions by Quizplus - Issuu