Pass the The SecOps Group Security Practitioner CNSP Questions and answers with CertsForce

Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
Questions # 1:

You are performing a security audit on a company's network infrastructure and have discovered the SNMP community string set to the default value of "public" on several devices. What security risks could this pose, and how might you exploit it?

Options:

A.

The potential risk is that an attacker could use the SNMP protocol to gather sensitive information about the devices. You might use a tool like Snmpwalk to query the devices for information.


B.

The potential risk is that an attacker could use the SNMP protocol to modify the devices' configuration settings. You might use a tool like Snmpset to change the settings.


C.

Both A and B.


D.

None of the above.


Expert Solution
Questions # 2:

Which of the following statements regarding Authorization and Authentication is true?

Options:

A.

Authorization is the process where requests to access a particular resource are granted or denied. Authentication is providing and validating the identity.


B.

Authentication is the process where requests to access a particular resource are granted or denied. Authorization is providing and validating identity.


C.

Authentication includes the execution rules that determine what functionality and data the user can access. Authentication and Authorization are both the same thing.


D.

Authentication controls which processes a person can use and which files they can access, read, or modify. Authentication and authorization typically do not operate together, thus making it impossible to determine who is accessing the information.


Expert Solution
Questions # 3:

Which of the following techniques can be used to bypass network segmentation during infrastructure penetration testing?

Options:

A.

DNS tunneling


B.

VLAN hopping


C.

Covert channels


D.

All of the above


Expert Solution
Questions # 4:

On a Microsoft Windows operating system, what does the following command do?

net localgroup Sales Sales_domain /add

Options:

A.

Display the list of the users of a local group Sales


B.

Add a domain group to the local group Sales


C.

Add a new user to the local group Sales


D.

Add a local group Sales to the domain group


Expert Solution
Questions # 5:

Which is the correct command to change the MAC address for an Ethernet adapter in a Unix-based system?

Options:

A.

ifconfig eth0 hw ether AA:BB:CC:DD:EE:FF


B.

ifconfig eth0 hdw ether AA:BB:CC:DD:EE:FF


C.

ifconfig eth0 hdwr ether AA:BB:CC:DD:EE:FF


D.

ifconfig eth0 hwr ether AA:BB:CC:DD:EE:FF


Expert Solution
Questions # 6:

What kind of files are "Dotfiles" in a Linux-based architecture?

Options:

A.

Library files


B.

Driver files


C.

System files


D.

Hidden files


Expert Solution
Questions # 7:

The application is showing a TLS error message as a result of a website administrator failing to timely renew the TLS certificate. But upon deeper analysis, it appears that the problem is brought on by the expiration of the TLS certificate. Which of the following statements is correct?

Options:

A.

The communication between the browser and the server is now no longer over TLS.


B.

The communication between the browser and the server is still over TLS.


Expert Solution
Questions # 8:

Which of the following services use TCP protocol?

Options:

A.

SNMP


B.

NTP


C.

HTTP


D.

IKE


Expert Solution
Questions # 9:

WannaCry, an attack, spread throughout the world in May 2017 using machines running on outdated Microsoft operating systems. What is WannaCry?

Options:

A.

Ransomware


B.

Malware


Expert Solution
Questions # 10:

Which of the following is true for SNMP?

A)The default community string for read-only access is "public."

B)The default community string for read/write access is "private."

Options:

A.

Only A


B.

Only B


C.

Both A and B


D.

None of the above


Expert Solution
Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions