Home > Certified Internet Web Professional > Quizzes > CIW Web Security Associate 1D0-571 Exam
CIW Web Security Associate 1D0-571 Exam
Fast practice, instant feedback. Timer auto-submits when time’s up.
Avg score: 50% Most missed: “A security breach has occurred in which a third party was able to obtain and mis…”
CIW Web Security Associate 1D0-571 Exam
Time left 00:00
25 Questions

1. Consider the following series of commands from a Linux system: iptables -A input -p icmp -s 0/0 -d 0/0 -j REJECT Which explanation best describes the impact of the resulting firewall ruleset?
2. You want to create a certificate for use in a Secure Sockets Layer (SSL) session. Which of the following is responsible for verifying the identity of an individual and also issuing the certificate?
3. Which of the following organizations provides regular updates concerning security breaches and issues?
4. Requests for Web-based resources have become unacceptably slow. You have been assigned to implement a solution that helps solve this problem. Which of the following would you recommend?
5. At the beginning of an IPsec session, which activity occurs during the Internet Key Exchange (IKE)?
6. Which of the following details should be included in documentation of an attack?
7. Which of the following is the most likely first step to enable a server to recover from a denial-of-service attack in which all hard disk data is lost?
8. What is the primary use of hash (one-way) encryption in networking?
9. What is the first tool needed to create a secure networking environment?
10. A security breach has occurred in which a third party was able to obtain and misuse legitimate authentication information. After investigation, you determined that the specific cause for the breach was that end users have been placing their passwords underneath their keyboards. Which step will best help you resolve this problem?
11. Which of the following errors most commonly occurs when responding to a security breach?
12. Which of the following describes the practice of stateful multi-layer inspection?
13. A new server has been placed on the network. You have been assigned to protect this server using a packet-filtering firewall. To comply with this request, you have enabled the following ruleset: Which choice describes the next step to take now that this ruleset has been enabled?
14. You have implemented a version of the Kerberos protocol for your network. What service does Kerberos primarily offer?
15. Which of the following standards is used for digital certificates?
16. Which choice lists typical firewall functions?
17. Which of the following applications can help determine whether a denial-of-service attack is occurring against a network host?
18. You have been asked to encrypt a large file using a secure encryption algorithm so you can send it via e-mail to your supervisor. Encryption speed is important. The key will not be transmitted across a network. Which form of encryption should you use?
19. Which of the following is a primary auditing activity?
20. A disgruntled employee has discovered that the company Web server is not protected against a particular buffer overflow vulnerability. The disgruntled employee has created an application to take advantage of this vulnerability and secretly obtain sensitive data from the Web server's hard disk. This application sends a set of packets to the Web server that causes it to present an unauthenticated terminal with root privileges. What is the name for this particular type of attack?
21. Which tool is best suited for identifying applications and code on a Web server that can lead to a SQL injection attack?
22. Which of the following is a common problem, yet commonly overlooked, in regards to physical security in server rooms?
23. Consider the following image of a packet capture: This packet capture has recorded two types of attacks. Which choice lists both attack types?
24. Which of the following can help you authoritatively trace a network flooding attack?
25. Irina has contracted with a company to provide Web design consulting services. The company has asked her to use several large files available via an HTTP server. The IT department has provided Irina with user name and password, as well as the DNS name of the HTTP server. She then used this information to obtain the files she needs to complete her task using Mozilla Firefox. Which of the following is a primary risk factor when authenticating with a standard HTTP server?