All questions

GIAC Information Security Fundamentals (GISF) Practice Test

Browse all practice questions for the GIAC Information Security Fundamentals (GISF) Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

GIAC Information Security Fundamentals (GISF) Practice Test 2026 – The Complete All-in-One Guide for Exam Success! course image
All questions

These questions are part of the practice quiz. Start practicing

  • What is the main function of a data custodian?
  • What does the acronym PDR stand for in the context of security management?
  • What does Software as a Service (SaaS) provide to its users?
  • What is the main purpose of using a one-way hash in communications?
  • Which type of cryptography requires the same key for both encryption and decryption?
  • Which phase of an attack involves installing tools to ensure undetected access?
  • What does using symmetric key encryption primarily ensure?
  • Which class of Bluetooth is most commonly used?
  • What characterizes a Wide Area Network (WAN)?
  • What principle ensures that users have the minimum necessary access to perform their tasks?
  • What is steganography primarily used for?
  • In a binary system, how is the value of a byte determined?
  • What type of storage does RAM provide in a computer system?
  • What is a Pseudo-random number generator (PRNG) used for in computers?
  • How does an external insider gain access to a system?
  • What does a true positive indicate in the context of an IDS?
  • What characterizes a disgruntled insider threat?
  • Which of the following best defines an application protocol?
  • What does deep inspection in a firewall involve?
  • What are two common methods for setting up Wi-Fi devices?
  • What is a brute force attack?
  • What is the purpose of ransomware?
  • What is the equivalent of a gigabyte in megabytes?
  • What percentage of the Internet is considered the deep web?
  • What does a Request for Comment (RFC) document provide regarding a protocol?
  • What do firewall rules typically determine?
  • What is a characteristic of Infrastructure as a Service (IaaS)?
  • What is meant by sideloading in mobile applications?
  • What is the primary purpose of antivirus software?
  • What does vulnerability analysis primarily assess?
  • Which protocol is used to communicate error messages related to IP?
  • Which protocol is primarily responsible for sending emails?
  • What term describes the assurance that data is correct and maintained by authorized personnel?
  • What is the final phase in the attack lifecycle where attackers hide their tracks?
  • What is the term for an infection vector that uses attractive USB drives left in public areas?
  • What is an essential characteristic of effective gap analysis?
  • What is a kernel in the context of an operating system?
  • Which of the following protocols would likely be used for email transmission?
  • What kind of data would be lost if only differential backups are used without regular full backups?
  • Which term describes the transformation of plaintext to ciphertext?
  • Why is authentication essential in information security?
  • Which of the following best describes the goal of a botnet?
  • In a Linux system, what is the account referred to as User #0?
  • What does the security control hierarchy illustrate?
  • Which access control model allows the owner of an object to delegate permissions to other users?
  • What is the definition of a 'nibble' in data representation?
  • In what way does indirect social engineering differ from other forms?
  • What is a common term for a wireless access point?
  • What can be a consequence of using a rogue access point?
  • Which of the following is indicated by a 400 Series server return code?
  • What function does the robots.txt file serve on a web server?
  • What does non-repudiation refer to in the context of information security?
  • What type of devices would typically be connected in a Local Area Network (LAN)?
  • What does risk avoidance involve?
  • In the context of cryptography, what is an important consideration aside from confidentiality?
  • What is involved in the response phase of incident management?
  • What does compartmentalization in network security refer to?
  • Which term describes the legal standard assessing how protective an organization is toward its assets?
  • Why is it important to respond effectively to security incidents?
  • What is a network port?
  • What type of information does the File Transfer Protocol (FTP) transmit?
  • What does cryptanalysis involve?
  • What is a domain attack?
  • What type of protocol is Transmission Control Protocol (TCP)?
  • Which statement best describes elliptic curve cryptography (ECC)?
  • What is the term for following someone through a secure door without authorization?
  • What is the purpose of authentication in information security?
  • Which of the following roles primarily utilizes the data within an organization?
  • Which operating system is not case-sensitive and uses \ as a path separator?
  • When securing a wireless network, why is it advisable to assume effectively infinite distance?
  • What is the primary function of a port scanner?
  • What defines an enclave in network security?
  • What is the purpose of cognitive password authentication?
  • What is the function of a non-persistent cookie?
  • What is the primary purpose of WEP?
  • In the context of information security, what is the significance of the reconnaissance phase?
  • Which Wi-Fi standard offers the highest throughput currently available?
  • What is Command and Control (C2) in cybersecurity?
  • What is a primary characteristic of discretionary access controls (DAC)?
  • What kind of addresses does NAT translate?
  • What capability does an intrusion prevention system (IPS) provide?
  • What defines spear phishing?
  • Which component is essential for interpreting and executing program instructions on a computer?
  • What is the primary function of Bluetooth technology?
  • What is the result when adding the high-order and low-order nibbles together?
  • What file system does Windows use for managing access control?
  • What does 'high-order' or 'most-significant' refer to in binary numbers?
  • Which tool is commonly used as a network utility for scanning?
  • What is a distributed denial-of-service (DDoS) attack?
  • What is a digital envelope in the context of hybrid cryptography?
  • What is the primary role of firewall rules?
  • Which of the following is true about Linux file systems?
  • What is the standard port number for Simple Mail Transfer Protocol (SMTP) used to send email?
  • What does SHA stand for in cryptography?
  • Which of the following statements is true regarding a false positive?
  • What are the three predefined Linux file permissions?
  • What does permission refer to in an IT security context?
  • What does risk transference refer to in a security context?
  • What role does a client play in a network?
  • Which attack type involves DNS server manipulation to provide false information?
  • What technique involves injecting randomized data into software for testing purposes?
  • Which attack strategy is most effective when the attacker has both plaintext and ciphertext for analysis?
  • Which bit is referred to as 'low-order' or 'least-significant'?
  • What are access controls used for?
  • What is the definition of a group in the context of user accounts?
  • What port number does HTTP typically use?
  • Maintaining access is which number phase in the attack lifecycle?
  • Which step follows the asset valuation in the risk management process?
  • What port number is used by the Post Office Protocol version 3 (POP3) for retrieving email?
  • Which three items are required for configuring IPv4?
  • Which of the following best describes token authentication?
  • What is a key in the context of cryptography?
  • What is cryptojacking?
  • What does biometrics authentication rely on?
  • What distinguishes a persistent cookie?
  • What is normally considered when identifying countermeasures?
  • What is active content primarily used for on a computer?
  • What is the role of awareness training in administrative countermeasures?
  • What is the historical significance of Triple DES?
  • What defines multifactor authentication?
  • What is a characteristic of social engineering attacks?
  • What is the primary purpose of RAM in a computer system?
  • How are incremental backups characterized?
  • Which type of phishing is conducted through telephone calls or VoIP systems?
  • Why is security training essential for employees?
  • What does virtualization create on a single computing device?
  • What does 'Availability' imply in information security?
  • How many bytes are contained within an IP address?
  • What is the function of the CPU in a computer system?
  • In terms of network management, what is a primary benefit of segmentation?
  • What happens if the full backup is lost and only the differential backups are available?
  • Which of the following represents a bit?
  • What is the definition of a user account in a computing context?
  • What is the role of an operating system (OS) on a computer?
  • What does keyspace refer to?
  • What does TKIP stand for?
  • Which process step is concerned with finding gaps in current security measures?
  • Which tool is commonly used to identify vulnerabilities in systems?
  • In cybersecurity, which action describes pivoting?
  • What does the concept of risk avoidance entail?
  • What does the term "malware" refer to overall?
  • What typically defines the length of ciphertext in a running key encryption method?
  • What is a drive-by download?
  • What is the significance of classifying alerts as true positive, false positive, true negative, and false negative?
  • ASCII is a system used for encoding what type of values?
  • What role does a data custodian play in implementing security measures?
  • What function does IPSec serve in a security protocol?
  • What is the value range for a nibble in computing?
  • According to Moore's Law, how often does processing speed double?
  • Which of the following is an example of spoofing?
  • Which of the following best describes a symmetric key?
  • What does the term "proprietary algorithm" commonly imply in cryptography?
  • What is the goal of risk mitigation in the context of asset protection?
  • What is the primary function of a rootkit?
  • What does the term 'ciphertext' imply about the integrity of communication?
  • What is the key factor that a senior manager decides regarding organizational risk?
  • What is the primary characteristic of the dark web?
  • What is direct social engineering?
  • Which of the following statements is true regarding stateful inspection firewalls?
  • What does a routing table contain?
  • Which of the following is the purpose of an encryption key?
  • What does the term "symmetric" refer to in symmetric cryptography?
  • What is one of the primary concerns regarding the use of attractive USB drives left in public areas?
  • What is the role of a security procedure?
  • What does penetration testing involve?
  • Which attack targets a specific group of individuals who visit the same website?
  • What is the first step in the risk management process?
  • Which operation is fundamental to modern encryption schemes and compares two binary bits?
  • Which operating system is case-sensitive and uses / as a path separator?
  • Which of the following is the correct abbreviation for a byte?
  • Which type of device typically uses dynamic IP addresses?
  • What does WEP stand for in the context of Wi-Fi security?
  • Which cryptographic process would involve reorganizing the input data into a format suitable for security?
  • Which of the following statements best captures the essence of risk ignorance?
  • What is the primary function of a firewall?
  • Which measure is most directly related to reducing vulnerability?
  • Does the Internet Protocol (IP) guarantee delivery of packets?
  • What is the purpose of Network Address Translation (NAT)?
  • How does a Graphical User Interface (GUI) function?
  • What is typically the role of a default gateway in a network?
  • What is the primary purpose of implementing detection and reaction capabilities in risk management?
  • What does the operating system manage on behalf of the user?
  • Which protocol is primarily responsible for routing packets across interconnected networks?
  • What is the main advantage of a differential backup over a full backup?
  • What is the concept of island hopping in the context of cybersecurity?
  • Which response from a server indicates an open port?
  • What is an IP address?
  • How should vulnerabilities be addressed to improve security?
  • What defines a Local Area Network (LAN)?
  • What does maximum password aging require?
  • What is the main purpose of minimum password aging?
  • Which permission allows a user to modify file content?
  • How many gigabytes are in a terabyte?
  • What is the primary characteristic of the AES (Advanced Encryption Standard)?
  • How much does the keyspace increase with the addition of a bit?
  • What type of protocol is IP categorized as?
  • Which of the following best describes the concept of confidentiality in security?
  • What is the purpose of a Pre-shared Key (PSK) in wireless networking?
  • How does a vulnerability scanner enhance port scanning?
  • What distinguishes a stream cipher from a block cipher?
  • What does an Access Control Entry (ACE) contain in a Windows environment?
  • What is the main function of non-repudiation in communications?
  • Which phishing attack method is characterized by the use of SMS text messages?
  • In hybrid cryptography, what role does the asymmetric key play?
  • Which term describes the number used by a computer to recognize a user account?
  • What does it mean for a web page to be "defaced" in a drive-by download attack?
  • What is a logic bomb?
  • What is the purpose of a security protocol?
  • Which service model allows a user to fully manage their applications on a cloud infrastructure?
  • In which scenario would a full system image backup be most beneficial?
  • What occurs during an exclusive lookup?
  • What does a key derivation function (KDF) produce?
  • What is the purpose of a Cloud Controls Matrix (CCM)?
  • Which elements are critical for a good information system?
  • Why is it important to regularly schedule backups?
  • What is the primary goal of the gaining access phase in an attack?
  • What does the term "impact" refer to in the context of risk assessment?
  • What does a 500 Series server return code indicate?
  • What is the primary goal of secure coding?
  • Which of the following accurately describes cache poisoning?
  • How many digits does the base 10 number system consist of?
  • What does Port Address Translation (PAT) allow multiple devices to do?
  • Which of the following describes a device that requests services from a server?
  • What defines a data spill in information security?
  • Which type of security solution monitors the environment and takes automatic action against unauthorized access attempts?
  • What does the notation 0x signify in numeric representation?
  • What is the network port number commonly used for FTP?
  • What is privilege escalation?
  • Which type of firewall is the most common in use today?
  • What is a common characteristic of exploit software?
  • What function does gateway antivirus serve in a network?
  • How does a differential backup compare to an incremental backup?
  • What is commonly referred to as an "evil twin" access point?
  • What is the second phase of an attack where vulnerable assets are identified?
  • What is the essence of cloud computing?
  • What distinguishes indirect social engineering from direct social engineering?
  • Which of the following is NOT a method of handling risk?
  • Which of the following is an example of something you have in terms of authentication?
  • What type of programming environment uses Java Virtual Machines?
  • What does the term 'network' refer to in a computing context?
  • Which protocol is considered interim before more secure protocols were adopted?
  • What is the purpose of private browsing in modern browsers?
  • When discussing data representation, what does 'octet' refer to?
  • A megabyte is equivalent to how many kilobytes?
  • What principle aims to prevent users from accessing more information than necessary?
  • To compute the value of nibbles, what is added after calculating the high-order nibble?
  • What does decryption accomplish?
  • What security measures are utilized in Bluetooth's secure simple pairing?
  • In networking terms, what does ACK represent?
  • What is a key benefit of using multifactor authentication?
  • What is the purpose of the 'chmod' command in Linux?
  • What does the second hexadecimal digit represent when calculating hexadecimal values?
  • What type of network security device is a web application firewall designed to protect against?
  • What is the main feature of User Datagram Protocol (UDP) compared to TCP?
  • Which of the following is NOT a characteristic of the zero trust security model?
  • What is a risk associated with using password lockout on internet-facing accounts?
  • What is the method for calculating the value of bytes?
  • What is a web cookie?
  • In which phase of the risk management process is the financial impact of a threat assessed?
  • What does the hexadecimal symbol 'A' represent in decimal?
  • What does ECDH stand for in cryptography?
  • In networking, what is the consequence of a packet arriving out of order at its destination?
  • What is the purpose of the Address Resolution Protocol (ARP)?
  • What is the maximum throughput for Wi-Fi 6/6E (802.11ax)?
  • What does the 'C' in the CIA Triad stand for?
  • What is the main function of a sinkhole in network security?
  • What is an important function of a user ID in an operating system?
  • What is the primary role of Public Key Infrastructure (PKI)?
  • What is an example of a potential risk when using public charging stations?
  • What is the value of a kilobyte in bytes?
  • What does a digital certificate primarily certify?
  • What is "work factor" in the context of cryptography?
  • Which of the following best defines a block cipher?
  • Why is the order of rules important in a packet filter firewall?
  • A type of substitution cipher that employs multiple alphabets to enhance security is known as what?
  • What type of backup includes all data?
  • What should a properly functioning IDS alert you about?
  • In a substitution cipher, what method is used to replace units of a message?
  • What is the primary concern of a threat to information security?
  • In asymmetric encryption, what type of key is typically used?
  • What is a one-time passphrase used for?
  • What does Dynamic Host Configuration Protocol (DHCP) primarily do?
  • What is the definition of a user in the context of a computer system?
  • Which type of cipher is characterized by encrypting letters with another letter in a one-to-one relationship?
  • Which account type typically has restricted access to only its own files?
  • What does role-based access control (RBAC) primarily focus on?
  • What does spoofing mean in the context of cybersecurity?
  • What is a worm in the context of information security?
  • What does wardriving involve?
  • What is the main advantage of using hybrid cryptography?
  • What is a true negative in relation to an IDS/IPS?
  • How are offensive countermeasures related to active defense?
  • What does accountability in a security context refer to?
  • What is an Intrusion Detection System (IDS) primarily used for?
  • Which of the following is NOT a property of signcryption?
  • What is exploit software primarily used for?
  • What does Shadow IT refer to?
  • What is an example of an administrative countermeasure?
  • Which type of cryptographic key is generally easier to manage?
  • Which of the following is a key feature of heuristics detection methods in antivirus software?
  • What is a malicious add-on?
  • What is a Command Line Interface (CLI)?
  • What type of cryptographic technique transposes the order of letters or words to obscure meaning?
  • Which of the following services is considered a delivery model for the cloud focused primarily on software deployment?
  • What does active defense refer to?
  • What is the goal of domain hijacking?
  • What is a potential target for attackers when using application allowlisting?
  • Who in an organization has primary responsibility and knowledge of data management?
  • What is the value of a terabyte in megabytes?
  • What is the aim of preventive measures in security?
  • What is the primary purpose of patch management in an organization?
  • Which service model allows customers to manage their own production applications while the provider manages hardware and core system applications?
  • What is often a sign of a broken hashing algorithm?
  • What is the main characteristic of a cryptographic key?
  • What is the primary function of a sniffer?
  • What is cryptocurrency?
  • What does OS hardening typically involve?
  • When should you ideally perform a differential backup?
  • How many bits are there in a byte?
  • Frequency analysis is primarily used against which type of cryptographic method?
  • What is the function of a server in a network environment?
  • What main purpose do access controls serve in information security?
  • What is the primary meaning of privilege in information security?
  • What does SYN stand for in networking?
  • In a business email compromise (BEC) attack, the threat actor impersonates which entity to gain financial advantage?
  • During which process is a user granted specific access rights to resources?
  • What is the function of a key encryption key (KEK)?
  • Which hash algorithm is commonly used in government applications but is being phased out?
  • What does a physical countermeasure primarily involve?
  • What are the place values of bits in a byte?
  • What is a primary function of a web application firewall (WAF)?
  • Which of the following is an example of something-we-know authentication?
  • In the context of access controls, what does ACE stand for?
  • Which of the following actions would most likely enable an attacker to gain higher privileges?
  • Which algorithm is used for encryption, digital signatures, and secure key exchange?
  • What does DMZ stand for in a network context?
  • Which of the following describes a BlueSniper rifle?
  • Which statement best describes the cumulative effect of a differential backup?
  • Which role has the legal responsibility to protect an organization's assets?
  • Which of the following is classified as a technical countermeasure?
  • What is the primary function of the Internet Control Message Protocol (ICMP)?
  • Which device commonly uses DHCP to obtain an IP address?
  • Which aspect of the CIA Triad ensures that information is only accessible to those authorized?
  • What does a vulnerability scanner typically do?
  • Which attack method uses known plaintext to determine the key of ciphertext?
  • What is the purpose of likelihood and impact estimates in the risk management process?
  • What is SSH (Secure Shell) primarily used for?
  • What does the acronym "DaaS" stand for in cloud computing?
  • What is a benefit of using an all-in-one security appliance?
  • What is the range of possible byte values in computing?
  • Which feature best describes asymmetric encryption?
  • What do offensive countermeasures aim to accomplish?
  • Which attack can involve sending unsolicited ARP requests or replies?
  • What approach do professional pen-testers take?
  • Which of the following defines a countermeasure?
  • What type of firewall filters traffic based on the state of existing connections?
  • Which of the following is a characteristic of JavaScript?
  • What does the term "detect" refer to in a security context?
  • Which aspect is critical to the function of hardware that is part of the security control hierarchy?
  • When a port scanner sends a SYN to a server, what are two possible responses that can be received?
  • What does the prudent person rule require of an organization?
  • What is a differential backup?
  • What feature does signature detection in antivirus software rely on?
  • What does WPA2 use for encryption?
  • What does the prefix "0b" indicate in number systems?
  • Which of the following is NOT one of the five phases of an attack?
  • How does a buffer overflow attack typically operate?
  • What key advantage does using both differential and full backups provide?
  • What is the root directory in a computer's directory hierarchy?
  • What does the presence of a malicious add-on usually indicate?
  • What is a VPN primarily used for?
  • What is the digit range in the binary number system?
  • What is the meaning of RST in networking?
  • Why might an organization want to reduce the power level on a Wi-Fi transmitter?
  • What is the characteristic of a stateful inspection firewall regarding deep and shallow inspection?
  • Which term describes a network of compromised devices that can be controlled by an attacker?
  • What type of inspection allows a firewall to check only headers, making it faster but potentially less thorough?
  • What does the process of verification in authentication involve?
  • What type of account provides high-level permissions for configurations and data access?
  • Which of the following accurately describes a characteristic of AES-128?
  • During an attack, what does lateral movement accomplish?
  • Which of the following is an example of a wide area network?
  • What is the key length of the AES-128 encryption standard?
  • What is the primary vulnerability of monoalphabetic ciphers?
  • What is the primary function of encryption?
  • What phase of an attack involves identifying assets that could be targeted for exploitation?
  • In Linux, what term is used for what Windows calls a folder?
  • When might cognitive password systems be used?
  • What command is used in Linux to change file or directory permissions?
  • What is the primary purpose of a directory in an operating system?
  • Which aspect of cloud computing distinguishes it from traditional computing?
  • What does escrow in the context of information security refer to?
  • What is a potential drawback of using only differential backups?
  • How many bytes are there in a megabyte?
  • Which of the following approaches may be taken when some risks cannot be completely avoided or mitigated?
  • What is the underlying technology that ensures the security of cryptocurrencies?
  • Which of the following describes a feature of a worm?
  • What does accountability in an information system offer?
  • What does hybrid cryptography combine?
  • Which of the following best describes the function of a DMZ in network architecture?
  • What is Triple DES primarily known for?
  • What is the main benefit of Wi-Fi Protected Setup (WPS)?
  • What characterizes a Trojan horse in cybersecurity?
  • Which of the following phases precedes Gaining access in an attack?
  • How does a web cookie contribute to HTTP traffic?
  • What is the main purpose of a rootkit in an attack scenario?
  • What does a 'bit' represent in computing?
  • In a scenario with multiple permission sets in place, which type of permission takes effect?
  • In Windows, what is the purpose of NTFS?
  • What does application allowlisting do?
  • What is the goal of implementing safeguards in security measures?
  • What is signcryption?
  • What is the term "WarXing" used to describe?
  • What is juice jacking?
  • What does a 200 Series server return code indicate?
  • What is the purpose of the covering tracks phase in an attack?
  • What does the Consensus Assessment Initiative Questionnaire (CAIQ) allow cloud customers to do?
  • How is a byte calculated when working with multiple bytes?
  • What type of account usually has administrative privileges on a device or network?
  • What does a TCP/IP protocol primarily facilitate?
  • What type of encryption does Bluetooth's secure simple pairing use?
  • Which activity involves informing individuals of the rules they must follow in an organization?
  • What is the encryption used by WPA3?
  • What could be a main characteristic of an external insider?
  • What does a one-way hash function provide in terms of data integrity?
  • What is the zero trust security model based on?
  • What is the goal of threat hunting?
  • What essential tactic is at the core of social engineering attacks?
  • What is the role of a default gateway in a network?
  • What does an algorithm represent in cryptography?
  • What is a machine-in-the-middle attack?
  • What occurs when a hashing algorithm generates the same hash for different inputs?
  • Can MAC addresses be encrypted to enhance security?
  • What is a primary risk associated with the dark web?
  • Why is it important to implement both signature and heuristics detection in antivirus software?
  • What action is typically taken by browsers when private browsing is enabled?
  • Which protocol is known for achieving higher transmission speeds at the cost of reliability?
  • In risk management, what does risk acceptance imply?
  • Why is MD5 considered antiquated?
  • What does spyware do?
  • What does Desktop as a Service (DaaS) enable users to do?
  • What action is commonly taken during maintaining access?
  • What does a biometric system compare during authentication?
  • Which term describes a condition that allows a threat to potentially exploit a system?
  • Which of the following are typical file permissions in a computing system?
  • What constitutes a rogue access point?
  • What process does blockchain use to maintain security?
  • What is the main goal of segmentation within a network?
  • What is a primary risk management tool for cloud consumers?
  • What is primarily involved in asset identification?
  • Which one of the following best describes asymmetric cryptography?
  • What encryption method is used by WPA2?
  • Which type of phone can bypass perimeter controls such as firewalls or content filters?
  • What defines an accidental insider?
  • What is meant by implicit denial in access control?
  • What is an all-in-one security appliance also known as?
  • Which categories are used for antivirus detection?
  • DES stands for what in the context of cryptography?
  • What is plaintext in the context of cryptography?
  • What technique involves gaining compromising information by observing someone from a close distance?
  • What is the combined value of all place values in a full byte?
  • What does OS hardening aim to achieve?
  • How does heuristics detection identify potential threats?
  • What is the primary purpose of an access control list (ACL)?
  • What does SSID stand for in the context of wireless networking?
  • Which type of backup only copies data items that have changed since the last backup?
  • What are the three types of token authentication?
  • Which term best describes actions taken to lessen the impact of a vulnerability?
  • What does a weak key attack exploit?
  • What is the process of modifying an Apple mobile device to remove software restrictions known as?
  • What is the primary purpose of content filtering in a network?
  • What does ECDH combine with to facilitate encryption?
  • In what way do persistent cookies differ from non-persistent cookies?
  • What does cryptography primarily focus on?
  • What type of attack involves an attacker associating their MAC address with someone else's IP address to intercept traffic?
  • Which of the following components is part of a digital certificate?
  • What is NOT a purpose of the gaining access phase?
  • What does a 300 Series server return code signify?
  • What does the concept of accountability help prevent in information security?
  • Which of the following is a detailed explanation of how to implement a security policy?
  • Which of the following describes fuzzing most accurately?
  • What method of phishing attack uses text messages (SMS) to deceive victims?
  • What is the purpose of patching an operating system?
  • What does "likelihood" refer to in the context of risk assessment?
  • Which standard is commonly referred to as Wi-Fi 5?
  • What does a packet filter firewall analyze to determine access permissions?
  • What is typically the action denied to a non-privileged user account?
  • What kind of content does the surface web consist of?
  • What type of phishing uses a deep fake voice impersonation?
  • What is the primary objective of gap analysis?
  • What type of backup would allow quicker restoration of everyday files while maintaining full system recovery options?
  • What is a backup?
  • Which type of hacking method is exemplified by spear phishing?
  • Is Bluetooth susceptible to warXing attacks?
  • What port number is associated with HTTPS?
  • What is a full system image backup?
  • Which of the following accurately describes a hard drive?
  • Which type of firewall is known for blocking network access from external networks while potentially causing latency issues?
  • What is a session key?
  • Who is considered the subject in an access control context?
  • In information security, what does the term 'access control' generally relate to?
  • Which backup type is most recommended for situations where reliability is essential and time for recovery is critical?
  • What is the main feature of the ICMP in the context of IP?
  • What authentication system does Enterprise Level Authentication (ELA) rely on?
  • What is pretexting in the context of social engineering?
  • Which user account type can access shared resources but with limited permissions?
  • What does a packet represent in a network?
  • What is a key characteristic of ciphertext-only attacks?
  • What does a MAC address do?
  • What is a malware development kit/factory?
  • What is the term for unauthorized entry by following someone through a secure door?
  • Which encryption protocol replaced WEP?
  • What is a running key in the context of encryption?
  • What does a denial-of-service (DoS) attack aim to achieve?
  • What does the prefix "0d" represent in numbering systems?
  • What does the key exchange process involve?
  • What is a unique characteristic of MAC addresses?
  • What type of key exchange methods can HTTPS utilize?
  • What does the term "pivot to admin" relate to?
  • Who is responsible for using the data and ensuring its proper management?
  • What is the hexadecimal equivalent of the binary value 1010?
  • What is the significance of using a random "salt" in a key derivation function?
  • What role does accountability play in securing information systems?
  • Which programming language is commonly used to create interactive effects within web browsers?
  • Which of the following describes authentication?
  • Can Bluetooth signals be intercepted beyond their typical operational range?
  • What are the place values used in a nibble?
  • In role-based access control (RBAC), what determines a user’s access permissions?
  • What is the primary purpose of a digital signature?
  • In what manner does spyware typically operate?
  • Which feature of WPA2 helps ensure that each packet is unique?
  • Which wireless setup method is considered rare?
  • What is the ideal frequency to perform full backups?
  • What does a Group ID represent in a computing environment?
  • What can potentially be a drawback of proxy firewalls?
  • In the binary system, which of the following represents the highest digit?
  • What is a virus in the context of computer security?
  • Which step in the risk management process determines how important the assets are?
  • What is the main purpose of a hashing function?
  • What type of user interface allows interaction through text and visual images like icons?
  • What is the role of a personal firewall?
  • What does lateral movement refer to in cybersecurity?
  • In network security, what does false negative entail?
  • Which cryptographic method is faster?
  • What is a birthday attack?
  • What is a preimage attack?
  • What is the purpose of Elliptic Curve Cryptography (ECC)?
  • What is the main objective of confirmed backup recovery?
  • What defines the hexadecimal number system?
  • What is one characteristic of a well-configured personal firewall?
  • Which Wi-Fi security protocols are currently considered secure?
  • What does HTML5 primarily incorporate to enhance interactivity?
  • What does the Ping command do in network troubleshooting?
  • What protocol uses port 443 for secure communications?
  • What is the primary function of a network protocol?
  • What is the function of a cryptographic algorithm in relation to keys?
  • What is the function of the Domain Name System (DNS)?
  • What role does the chief information security officer (CISO) typically play in an organization?
  • Which of the following methods is NOT typically a part of wireless device setup?
  • What type of attack uses social engineering to manipulate a DNS registrar?
  • What is meant by authorization in information security?
  • What does the term 'cross-platform' refer to in programming?
  • What type of phishing attack specifically targets wealthy or powerful individuals?
  • What is a false positive in the context of an IDS?
  • In symmetric encryption, what type of key is used?
  • What is the total number of bits in a kilobyte?
  • What protocol does Diffie-Hellman use for key exchange?
  • What does ciphertext refer to?
  • What is the ultimate goal of creating backups in information security?
  • What is identified during the threat identification step?
  • What is defined as anything that can potentially cause harm to assets or people?
  • What is the initial input for a key derivation function (KDF)?
  • What is the purpose of security policies in an organization?
  • What does reducing risks associated with high Wi-Fi signal range imply for a network?
  • What is a key component of asset valuation?
  • Which type of attack would suggest that a hash function is compromised?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy