Home > Certified Internet Web Professional > Quizzes > CIW Web Security Associate 1D0-571 Exam - Practice Test 2
CIW Web Security Associate 1D0-571 Exam - Practice Test 2
Fast practice, instant feedback. Timer auto-submits when time’s up.
Avg score: 17% Most missed: “Which of the following details should be included in documentation of an attack?”
CIW Web Security Associate 1D0-571 Exam - Practice Test 2
Time left 00:00
25 Questions

1. Your organization has made a particularly unpopular policy decision. Your supervisor fears that a series of attacks may occur as a result. You have been assigned to increase automated auditing on a server. When fulfilling this request, which of the following resources should you audit the most aggressively?
2. Which of the following is the primary weakness of symmetric-key encryption?
3. You have just deployed an application that uses hash-based checksums to monitor changes in the configuration scripts of a database server that is accessible via the Internet. Which of the following is a primary concern for this solution?
4. You have implemented a service on a Linux system that allows a user to read and edit resources. What is the function of this service?
5. A disgruntled employee has discovered that the company Web server is not protected against a particular buffer overflow vulnerability. The disgruntled employee has created an application to take advantage of this vulnerability and secretly obtain sensitive data from the Web server's hard disk. This application sends a set of packets to the Web server that causes it to present an unauthenticated terminal with root privileges. What is the name for this particular type of attack?
6. Which of the following details should be included in documentation of an attack?
7. You are creating an information security policy for your company. Which of the following activities will help you focus on creating policies for the most important resources?
8. The most popular types of proxy-oriented firewalls operate at which layer of the OSI/RM?
9. You have been asked to encrypt a large file using a secure encryption algorithm so you can send it via e-mail to your supervisor. Encryption speed is important. The key will not be transmitted across a network. Which form of encryption should you use?
10. At the beginning of an IPsec session, which activity occurs during the Internet Key Exchange (IKE)?
11. Which of the following activities is the most effective at keeping the actions of nae end users from putting the company's physical and logicalWhich of the following activities is the most effective at keeping the actions of na?e end users from putting the company's physical and logical resources at risk?
12. A CGI application on the company's Web server has a bug written into it. This particular bug allows the application to write data into an area of memory that has not been properly allocated to the application. An attacker has created an application that takes advantage of this bug to obtain credit card information. Which of the following security threats is the attacker exploiting, and what can be done to solve the problem?
13. Consider the following image of a packet capture: This packet capture has recorded two types of attacks. Which choice lists both attack types?
14. You are using a PKI solution that is based on Secure Sockets Layer (SSL). Which of the following describes the function of the asymmetric-key-encryption algorithm used?
15. Which of the following is the most likely first step to enable a server to recover from a denial-of-service attack in which all hard disk data is lost?
16. You have implemented a version of the Kerberos protocol for your network. What service does Kerberos primarily offer?
17. You purchased a network scanner six months ago. In spite of regularly conducting scans using this software, you have noticed that attackers have been able to compromise your servers over the last month. Which of the following is the most likely explanation for this problem?
18. Consider the following diagram: Which type of attack is occurring?
19. You have discovered that the ls, su and ps commands no longer function as expected. They do not return information in a manner similar to any other Linux system. Also, the implementation of Tripwire you have installed on this server is returning new hash values. Which of the following has most likely occurred?
20. Jason is attempting to gain unauthorized access to a corporate server by running a program that enters passwords from a long list of possible passwords. Which type of attack is this?
21. You want to create a quick solution that allows you to obtain real-time login information for the administrative account on an LDAP server that you feel may become a target. Which of the following will accomplish this goal?
22. Which of the following is a typical target of a trojan on a Linux system?
23. Which tool is best suited for identifying applications and code on a Web server that can lead to a SQL injection attack?
24. Which of the following errors most commonly occurs when responding to a security breach?
25. Which of the following organizations provides regular updates concerning security breaches and issues?