Browse all practice questions for the SBOLC Security Fundamentals Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

SBOLC Security Fundamentals Practice Test course image
All questions

These questions are part of the practice quiz. Start practicing

  • What does the production environment refer to?
  • Which of the following is a major advantage of asymmetric cryptography?
  • Which of the following is true regarding the role of a Switch in networking?
  • What does the term 'Key Stretching' refer to in cryptography?
  • What are roving security controls primarily composed of?
  • Which network technique separates broadcast domains?
  • What is the primary aim of Organized Crime in the context of cybersecurity?
  • What does a horizontal privilege escalation attack involve?
  • What is an example of a Host-to-Site VPN topology?
  • What does a honeynet consist of?
  • What is a root certificate?
  • What is a defining feature of Ransomware?
  • Which VPN topology example connects two branches of a corporate network?
  • Job rotation is primarily used for which of the following purposes?
  • What type of hacker operates in a legal gray area?
  • What characterizes the structure of a DNS database?
  • What does VLAN Trunking Protocol (VTP) allow switches to do?
  • What is Port Address Translation (PAT) used for?
  • What is one of the key elements of an onboarding procedure?
  • What does a Functional Recovery Plan (FRP) provide for a business?
  • Which advantage does quantitative risk assessment provide?
  • What is the maximum tolerable downtime (MTD) in business continuity planning?
  • What does TPM stand for in the context of security?
  • What is an Extended Validation Certificate primarily known for?
  • What is a common characteristic of script kiddies in the cybersecurity landscape?
  • What type of authentication mechanism allows multiple different types of methods for access?
  • Which of the following best describes the process of key recovery?
  • What does EOL refer to in a business context?
  • What is a primary function of a Network-based Intrusion Prevention System (NIPS)?
  • Who is responsible for collecting and verifying identities on behalf of the Certificate Authority?
  • In the given scenario, what is the Single Loss Expectancy (SLE) if a building worth $1,000,000 is damaged by fire?
  • Which method involves a planned action for accepting risks?
  • What characterizes a test environment?
  • What is the purpose of RAID technology?
  • Which phase comes after "Processing" in the Information Lifecycle Model?
  • What does SNMP stand for?
  • What is the main purpose of the Online Certificate Status Protocol (OCSP)?
  • What is a key characteristic of signature-based detection systems?
  • What is a significant weakness of Pre-Shared Key (PSK) authentication?
  • Which term describes a network designed to lure attackers?
  • What is the primary focus of Business Continuity Planning (BCP)?
  • What do Network-based Intrusion Detection Systems (NIDS) monitor?
  • What is the role of the private key in asymmetric cryptography?
  • What is a sandbox environment primarily designed to do?
  • Which of the following is a key component of the NIST Risk Management Framework?
  • What best describes state actors in cybersecurity?
  • How does port security function in a network?
  • Which type of certificate is created and mapped to a specific user account?
  • Which of the following best characterizes the purpose of a computer virus?
  • How does simultaneous Authentication of Equals (SAE) enhance wireless security?
  • How can race conditions be exploited in an attack?
  • Which of the following best describes the impact of a broadcast storm on a switch's processing?
  • What is the characteristic of a cold site?
  • What is the significance of OCSP Stapling?
  • What is the role of a protocol analyzer in network security?
  • What is a key characteristic of Symmetric algorithms?
  • What does BYOD stand for in a corporate environment?
  • What distinguishes a Next Generation Firewall (NGFW) from traditional firewalls?
  • What type of information can be found in an X.509 Digital Certificate?
  • What does a successful Business Impact Analysis consider?
  • Which classification of information deals specifically with proprietary matters?
  • What does BSSID refer to in a wireless network?
  • What is the primary purpose of an ESSID?
  • Which components are included in the Security Monitoring Architecture?
  • What is a common function of a Remote Access Trojan (RAT)?
  • What is the primary function of the IEEE 802.1D Spanning Tree Protocol (STP)?
  • What is the main goal of file integrity checks?
  • In which environment are product concepts turned into written code?
  • What is the function of APIPA?
  • Which policy ensures that sensitive items are not accessible when not in use?
  • What is the purpose of mandatory vacations in a workplace?
  • Which term refers to the potential to cause harm to an asset?
  • What is the purpose of using conduits to protect sensitive cables?
  • What type of cryptography does a Hybrid Cryptosystem utilize?
  • Which of the following is a component of data backup solutions?
  • What is an active countermeasure against race conditions?
  • What does Layer 2 Tunneling Protocol (L2TP) combine?
  • What is the primary purpose of a De-militarized Zone (DMZ) in a network?
  • Which of the following is a feature of antivirus software?
  • What is the main advantage of a Virtual Desktop Infrastructure (VDI)?
  • What does behavior-based detection rely on to identify security breaches?
  • Who are Script Kiddies in the context of cybersecurity?
  • What does Separation of Duties aim to achieve in an organization?
  • Which VPN method allows only specific traffic destined for the corporate network to pass through the tunnel?
  • What is a key feature of a honeynet?
  • What does the term 'Data in Transit' refer to?
  • Which access control model uses preconfigured rules to grant access?
  • What is the nature of an Intranet?
  • Which of the following best describes Geofencing?
  • What occurs when a Rootkit successfully embeds itself in an operating system?
  • Which term describes removing the activity that creates risk?
  • What does VDI stand for?
  • What is the output of a hashing algorithm?
  • Which authentication method uses a combination of something you know and something you have?
  • What does AUP stand for?
  • What does MAC stand for in the context of message authentication?
  • What purpose does Spyware serve in a system?
  • What is the function of File Transfer Protocol Secure (FTPS)?
  • Which category does Managerial Controls fall under?
  • What does the Clean Desk Policy require employees to do?
  • Which of the following is a disadvantage of qualitative risk assessment?
  • Which technique is associated with Obfuscation?
  • What protocol is used for secure remote access and terminal communications?
  • What does Annualized Loss Expectancy (ALE) measure?
  • What type of risk involves old systems posing potential security issues?
  • What does “Integrity” in the CIA Triad focus on?
  • What does FQDN stand for?
  • Which of the following is NOT a goal of implementing honeypots?
  • What does BPA stand for in a business context?
  • Which of the following risks involves compliance or licensing issues related to software?
  • What is the primary function of a Host-Based Firewall?
  • What ports are used by Secure Shell (SSH)?
  • What is the primary function of Internet Protocol Security (IPsec)?
  • Which type of malware encrypts key files and folders and demands payment to unlock them?
  • Which type of messages encapsulates PPP frames in L2TP?
  • What does MTBF measure?
  • What is an Access Control Entry (ACE)?
  • What type of messages does the control part of L2TP handle?
  • In the context of encryption ciphers, what is a Steam Cipher?
  • Which NAC type involves redirecting users to comply with authentication requirements?
  • What is the primary purpose of a honeyfile?
  • What is the primary focus of a Risk Management process?
  • Which entity is responsible for creating, signing, and revoking asymmetric keys?
  • What is a key feature of the Corporate Owned, Personally Enabled (COPE) model?
  • Which of the following is a countermeasure for vertical privilege escalation?
  • What is a single purpose certificate commonly used for?
  • What is the primary function of RADIUS?
  • What is a key characteristic of a Logic Bomb?
  • What is the function of a Subject Alternative Name (SAN) extension in multi-domain certificates?
  • Why are honeynets considered effective in security strategies?
  • What is NOT one of the four security goals of Cryptography?
  • What role does a Root CA play in a PKI system?
  • Shoulder surfing is primarily concerned with observing what type of information?
  • What is a key characteristic of an Appliance Firewall?
  • Which type of authentication requires both ends to authenticate each other?
  • What approach uses numerical values to assess risk?
  • What is meant by 'Attribute-Based Access Control' (ABAC)?
  • What is a primary characteristic of switching loops in a network?
  • What does Business Impact Analysis (BIA) help determine?
  • What type of risk is characterized by factors originating outside an organization?
  • In the OSI model, what layer does a Router operate in?
  • What often motivates unethical actors to engage in domain hijacking?
  • What type of threat does a Web Application Firewall (WAF) specifically protect against?
  • Which of the following is an example of Type 2 authentication?
  • What is a Disaster Recovery Plan (DRP)?
  • Which of the following is NOT a type of Protected Information?
  • Which principle of social engineering uses a sense of urgency to manipulate behavior?
  • Which technique is used for permanently destroying media so that it cannot be reconstructed?
  • What function do Backdoors serve in malware?
  • What is one common characteristic of RFID systems?
  • What type of cryptography uses a single key for both encryption and decryption?
  • What is the primary purpose of Database Tokenization?
  • What does tailgating or piggybacking refer to in security terms?
  • What resource allocation distinguishes advanced persistent threats?
  • What is the role of the Extended Service Set ID (ESSID)?
  • What does a False Positive indicate?
  • What does SPIM refer to in cybersecurity terminology?
  • What is a key function of NAT in a networking environment?
  • What is the role of a Reverse Proxy?
  • Which component of a digital certificate indicates the period during which it is valid?
  • What defines a Self-Encrypting Drive (SED)?
  • Which of the following is a countermeasure against malware?
  • What key feature differentiates X.509 certificates?
  • What is bluebugging?
  • Which type of attacker is focused on gaining competitive advantage?
  • What characteristic is essential for a honeypot?
  • What is the primary function of Anomaly-Based Detection?
  • Which port is associated with the Kerberos V5 authentication protocol?
  • What is the function of a Key Escrow service?
  • What are "single points of failure" in the context of BCP?
  • Which type of malware can propagate on its own without a host application?
  • Which of the following is a method used in physical security controls to prevent unauthorized access?
  • What does RSA stand for in cryptographic protocols?
  • What is the purpose of the Information Lifecycle Model?
  • What is a key feature of entry point security controls?
  • Which of the following is NOT a step in establishing a trusted operating system?
  • What does system hardening involve regarding default settings?
  • What best describes how a NIDS operates?
  • Who is the primary target in a phishing attack?
  • Which RAID level uses data striping with a dedicated parity drive?
  • What type of protocol is Secure File Transfer Protocol (SFTP)?
  • What is spam commonly defined as?
  • What does NIST stand for?
  • What is the function of temperature sensors within environmental security controls?
  • Which classification best describes customer data in Business Information Classifications?
  • What is the main purpose of identifying control gaps in risk management?
  • Which evaluation correctly identifies a situation where an attacker was recognized by an IDS?
  • What type of target does whaling primarily focus on?
  • What does the Object Identifiers (OID) in an X.509 Digital Certificate signify?
  • Which ports are associated with the Simple Network Management Protocol (SNMP)?
  • What does MTTR indicate?
  • Which step is part of enforcing least privilege management?
  • What is described as a flaw or hole in the security posture?
  • What does the term “Data at Rest” refer to?
  • Which statement is true about the digital certificate's CA's Distinguished Name (DN)?
  • Which of the following is NOT a common attribute of threat actors?
  • Which system is referred to as a Host-based Intrusion Detection System (HIDS)?
  • What protocol is referred to by the acronym DHE?
  • Which term describes a digital signature's ability to confirm a sender's authenticity?
  • What does a Virtual Private Network (VPN) primarily do?
  • What happens to a digital certificate once it is added to a CRL?
  • What is the purpose of a Honeypot in security?
  • What does APT stand for in the context of cybersecurity?
  • What does Database Normalization aim to achieve?
  • What motivates Hacktivists in their attacks?
  • Type squatting involves the registration of what type of domain?
  • What does DDoS stand for?
  • Which Bluetooth attack involves sending unsolicited messages?
  • Which type of system is likely to employ file integrity checking?
  • Which of the following is included in the hiring and termination policy elements?
  • What is the primary purpose of Public Key Infrastructure (PKI)?
  • What is Network Address Translation (NAT) primarily used for?
  • What is the primary function of Mobile Device Management (MDM)?
  • Which of the following is a characteristic of shared or generic accounts?
  • What is a typical characteristic of a host-based Web Application Firewall (WAF)?
  • What is an Extranet primarily used for?
  • What is the primary purpose of air gapping in network security?
  • How can NIPS adjust its security posture?
  • What does FQDN stand for in the context of DNS?
  • What is the primary purpose of Data Loss Prevention (DLP) systems?
  • What does RPO stand for in the context of recovery objectives?
  • What does the term 'Insider Threats' refer to?
  • What is Shadow IT?
  • In a privilege escalation attack, what does an attacker achieve?
  • Which of the following is a type of Drive Encryption Solution?
  • What is domain hijacking associated with?
  • Which of the following is NOT a type of common site implementation?
  • What does a Trusted Platform Module (TPM) primarily store?
  • What outcome can a well-configured honeynet provide for an organization?
  • In the COPE model, how does the company manage devices?
  • What is the primary function of a Block Cipher?
  • What does ISAKMP stand for?
  • What is the main function of HMAC?
  • What defines a machine certificate?
  • What does the "High" classification denote in Generic Information Classifications?
  • What does PRNG stand for in cryptography?
  • What are database stored procedures?
  • Honeypots primarily serve what type of purpose in cybersecurity?
  • In what context is a recovery agent used?
  • What equals the asset value multiplied by the exposure factor percentage?
  • What is the purpose of an Initialization Vector (IV)?
  • Which of the following is NOT considered a technique for media destruction?
  • What type of technology does RFID utilize?
  • What is a critical function of an Intermediate CA?
  • What is a key feature of Automatic Private Internet Protocol Addressing (APIPA)?
  • What does NAC stand for in a network security context?
  • What effect can multiple Layer 2 paths have on a network?
  • What is the focus of system hardening?
  • Which of the following is a method or technique used to manipulate a flaw?
  • What security measure helps mitigate risks associated with humidity?
  • Which of the following is classified as a Detective Control?
  • What is the purpose of DHCP Snooping?
  • What is a characteristic of Compensating Controls?
  • Which type of agreement is less formal and focuses on mutual goals between two or more organizations?
  • What is the primary focus of RTO?
  • What is indicated by the term SPIT?
  • What is a primary goal of a virus in computer systems?
  • Which RAID level offers redundancy with block-level striping and distributed parity?
  • Which of the following describes Discretionary Access Control (DAC)?
  • Which account type has permissions to make system changes?
  • What does a Host-based Intrusion Prevention System (HIPS) primarily do?
  • What is the primary purpose of patch management?
  • Which type of information is categorized under Personally Identifiable Information (PII)?
  • Which protocol is designed to be used with Wired Equivalent Privacy (WEP)?
  • What is the first phase outlined in the Information Lifecycle Model?
  • What does CYOD allow employees to do?
  • What is the main purpose of NFC technology?
  • Which VPN tunneling method requires that the client uses a VPN tunnel whenever connecting to an untrusted network?
  • What is a Hardware Security Module (HSM)?
  • What risk management strategy involves offloading risk to an external party?
  • How can honeyfiles benefit system security?
  • What type of data does a honeyfile typically contain?
  • Vishing is often used in conjunction with which technique to enhance its effectiveness?
  • What refers to the risk remaining after risk mitigation measures have been implemented?
  • Which of the following is a classification of military information?
  • What occurs during an integer overflow?
  • How can memory leaks affect software performance?
  • What type of network segmentation does Logical Separation often involve?
  • What method does pharming use to mislead users?
  • Which of the following is NOT a component of a digital signature?
  • What is the primary role of shimming in system processes?
  • What does the acronym ECGHE stand for in the context of security protocols?
  • Which of the following is a characteristic of VPNs using TLS?
  • Which function is identified in Business Continuity Planning as crucial for operations?
  • How does a honeynet enhance traditional security measures?
  • System hardening should include all of the following EXCEPT:
  • What type of data is referred to as “Data in Use”?
  • A Trojan Horse is primarily known for which of the following characteristics?
  • What is a key feature of an in-band management interface?
  • What does RAT stand for in the context of cybersecurity?
  • Which protocol uses ports TCP 20 and TCP 21?
  • Which of the following is true about Asymmetric Cryptography?
  • Which type of malware is designed to hide itself from security software and utilities?
  • What does the acronym MOA stand for in the context of agreements?
  • Which access control model is considered the most restrictive?
  • In the context of physical separation, what separates collision domains?
  • Which of the following describes the staging environment?
  • What is a memory leak in software development?
  • Which type of certificate is specifically used for S/MIME or PGP email cryptosystems?
  • What distinguishes MS-CHAP from standard CHAP?
  • Which type of hacker is known as a White Hat?
  • What is the primary role of a Proxy Server?
  • What is a key characteristic of Shadow IT?
  • What is refactoring primarily concerned with in code development?
  • What type of information is considered Protected Health Information (PHI)?
  • Which of the following is an example of vertical privilege escalation?
  • What does "In-Band Exchange" refer to?
  • Which statement accurately describes the "Full Tunnel" VPN method?
  • What issue does a broadcast storm typically cause in a network?
  • What is a limitation of quantitative risk assessment?
  • What does the CIA Triad Model primarily address?
  • What does GAN stand for in cybersecurity?
  • Which method of data sanitization involves the use of an electromagnetic field?
  • Which of the following is a physical perimeter security control?
  • What type of controls includes security cameras and motion-sensitive alarms?
  • What is one characteristic of Malicious Scripts?
  • Which method of authentication is the most vulnerable to being compromised?
  • In cyber security, who typically uses honeypots?
  • Which statement is true about certificate mapping?
  • What does a Certificate Signing Request (CSR) entail?
  • What does SAE stand for in the context of wireless security?
  • In network architecture, what does the North-South Traffic Zone indicate?
  • What is the main purpose of Secure Sockets Layer (SSL)?
  • What are the ports for FTPS?
  • What best describes Zero Trusted Architecture?
  • What does Deep Packet Inspection (DPI) involve?
  • What type of firewall is also known as a Personal Firewall?
  • What does HSM stand for regarding security technologies?
  • What is a VLAN?
  • Which type of lock is typically considered a biometric lock?
  • System hardening is mainly focused on?
  • What does DHCP stand for?
  • What is a method of updating known bugs or flaws in security applications?
  • What layer of the OSI model does a Switch operate in?
  • What distinguishes spear phishing from regular phishing?
  • Which authentication protocol is known for its three-way handshake process?
  • What is the primary role of a Certificate Authority (CA)?
  • Which of these is a motivation for threat actors?
  • Which sensor type detects environmental changes such as temperature?
  • Which firewall type requires significant amounts of memory to track TCP connections?
  • What does the Spanning Tree Protocol primarily prevent?
  • Which type of encryption commonly uses a single key to encrypt and decrypt messages securely?
  • In Tunnel Mode of IPsec, what is encapsulated?
  • What is the primary function of a Keystroke Logger?
  • Which of the following is NOT a type of account listed in the content?
  • What is an example of a Corrective Control?
  • What advantage does an out-of-band management interface provide?
  • Which principle of social engineering involves exploiting someone's perception of authority?
  • Which component of a digital signature creates the hash?
  • Which best describes a hardware-based WAF?
  • Which of the following options represents a warm site?
  • What does TACACS+ stand for?
  • What is the main function of a honeypot?
  • What does PFS stand for in the context of cryptography?
  • Which of the following steps is NOT part of mitigating operational risk?
  • What does the term "wiping" refer to in data sanitization?
  • What is a Digital Signature?
  • Which traffic zone refers to network traffic that occurs within a data center's security area?
  • What does the term "prepending" refer to in cybersecurity?
  • What is the principle of least privilege management?
  • What type of attack involves pretending to be someone else to gain unauthorized access?
  • Which of the following best describes a hashing function?
  • What differentiates Worms from other types of malware?
  • What does Key Pinning involve?
  • What vulnerability is common in PSK that leads to security risks?
  • What does SSID stand for in networking?
  • In the AAA security model, what does 'Authentication' refer to?
  • Which of the following best describes spam in the context of Internet communication?
  • Which environment serves as a final testing ground before production?
  • What is the key characteristic of Out-of-Band Exchange?
  • What is the primary function of the Kerberos V5 protocol?
  • What does the Extensible Authentication Protocol (EAP) extend?
  • What role does a Preventative Control serve in security?
  • Which firewall analyzes traffic at layers 3 and 4 of the OSI model?
  • Which mode of IPsec is designed for end-to-end encryption of data?
  • What does the Certificate Revocation List (CRL) contain?
  • What does malware aim to achieve in a system?
  • In a network context, which statement about IP addressing is true for DHCP?
  • What purpose does the serial number in a digital certificate serve?
  • What describes the "Secret" classification in military information?
  • What benefit does implementing a VLAN offer to a network?
  • What is a buffer overflow?
  • Which of the following is NOT a responsibility of a Certificate Authority?
  • What type of portal places a prospective system in a restricted area until compliance is met?
  • What distinguishes dynamic tokens from static tokens?
  • What does the term 'multi-homed' refer to in hardware-based WAF?
  • What type of controls are designed to discourage attacks?
  • What does COBO stand for in a corporate context?
  • What type of account is characterized by temporary usage?
  • Which policy is designed to mitigate risks associated with disclosing sensitive company information?
  • What is the primary focus of the NIST Risk Management Framework (RMF)?
  • What is the primary method used in vishing?
  • Which of the following is NOT considered a Cryptographic Principle?
  • In which scenario is symmetric cryptography typically preferred?
  • What advantage does using honeyfiles provide in a network security context?
  • What is the primary function of a user certificate?
  • What type of malicious code requires the host's interpreter to process its instructions?
  • What does DNS stand for in networking?
  • What is a key feature of Agent-Based NAC?
  • What is Steganography primarily used for?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy