Home > Certified Internet Web Professional > Quizzes > CIW Web Security Associate (1D0-571) Certification
CIW Web Security Associate (1D0-571) Certification
Fast practice, instant feedback. Timer auto-submits when time’s up.
Avg score: 60% Most missed: “What is the primary strength of symmetric-key encryption?”
CIW Web Security Associate (1D0-571) Certification
Time left 00:00
25 Questions

1. Irina has contracted with a company to provide Web design consulting services. The company has asked her to use several large files available via an HTTP server. The IT department has provided Irina with user name and password, as well as the DNS name of the HTTP server. She then used this information to obtain the files she needs to complete her task using Mozilla Firefox. Which of the following is a primary risk factor when authenticating with a standard HTTP server?
2. You have discovered that the ls, su and ps commands no longer function as expected. They do not return information in a manner similar to any other Linux system. Also, the implementation of Tripwire you have installed on this server is returning new hash values. Which of the following has most likely occurred?
3. You are creating an information security policy for your company. Which of the following activities will help you focus on creating policies for the most important resources?
4. Which of the following details should be included in documentation of an attack?
5. A new video conferencing device has been installed on the network. You have been assigned to troubleshoot a connectivity problem between remote workers and the central company. Specifically, remote workers are having problems making any connection at all. Which technique will most likely help you solve this problem while retaining the existing level of security at the firewall?
6. Your organization has made a particularly unpopular policy decision. Your supervisor fears that a series of attacks may occur as a result. You have been assigned to increase automated auditing on a server. When fulfilling this request, which of the following resources should you audit the most aggressively?
7. Which of the following is the most likely first step to enable a server to recover from a denial-of-service attack in which all hard disk data is lost?
8. Which tool is best suited for identifying applications and code on a Web server that can lead to a SQL injection attack?
9. Jason is attempting to gain unauthorized access to a corporate server by running a program that enters passwords from a long list of possible passwords. Which type of attack is this?
10. What is the primary drawback of using symmetric-key encryption?
11. You have been assigned to provide security measures for your office's reception area. Although the company needs to provide security measures, costs must be kept to a minimum. Which of the following tools is the most appropriate choice?
12. Consider the following image of a packet capture: This packet capture has recorded two types of attacks. Which choice lists both attack types?
13. Which of the following is most likely to pose a security threat to a Web server?
14. Which of the following is the primary weakness of symmetric-key encryption?
15. Which of the following is considered to be the most secure default firewall policy, yet usually causes the most work from an administrative perspective?
16. You want to create a certificate for use in a Secure Sockets Layer (SSL) session. Which of the following is responsible for verifying the identity of an individual and also issuing the certificate?
17. You have been assigned to configure a DMZ that uses multiple firewall components. Specifically, you must configure a router that will authoritatively monitor and, if necessary, block traffic. This device will be the last one that inspects traffic before it passes to the internal network. Which term best describes this device?
18. A new server has been placed on the network. You have been assigned to protect this server using a packet- filtering firewall. To comply with this request, you have enabled the following ruleset: Which choice describes the next step to take now that this ruleset has been enabled?
19. Consider the following series of commands from a Linux system: iptables -A input -p icmp -s 0/0 -d 0/0 -j REJECT Which explanation best describes the impact of the resulting firewall ruleset?
20. At the beginning of an IPsec session, which activity occurs during the Internet Key Exchange (IKE)?
21. Which of the following is a primary auditing activity?
22. A CGI application on the company's Web server has a bug written into it. This particular bug allows the application to write data into an area of memory that has not been properly allocated to the application. An attacker has created an application that takes advantage of this bug to obtain credit card information. Which of the following security threats is the attacker exploiting, and what can be done to solve the problem?
23. You have implemented a version of the Kerberos protocol for your network. What service does Kerberos primarily offer?
24. Which of the following applications can help determine whether a denial-of-service attack is occurring against a network host?
25. What is the first tool needed to create a secure networking environment?