CIW Security Analyst 1D0-570 Web Demo
This webdemo is just a demo data, only for reference and learning, there is no other purposes
1. The chief operations officer (COO) has questioned the need for
end-user training. Which of the following is the most effective
response?
A.Indicate that you will not be responsible for the next virus outbreak.
B.Remind the CEO about the last virus attack and the expense incurred.
C.Explain that the cost of end-user training is a fraction of the cost
of the last security breach caused by end users.
D.Provide statistics that definitively show how end-user training
reduces the likelihood of security breaches on the corporate network.
Answer: C
2.A Linux system running Apache Server has received millions of SYN
packets that it can no longer respond to, because the client's operator
is maliciously withholding the necessary reply packet. What is the most
common solution for this problem?
A.Implement SSL.
B.Implement SYN cookie support.
C.Upgrade the TCP/IP stack with new software.
D.Upgrade the operating system to support IPsec.
Answer: B
3. What is the first step of a gap analysis?
A.Scan the firewall.
B.Review antivirus settings.
C.Review the security policy.
D.Review intrusion-detection software settings.
Answer: C
4. Which of the following is a main function of a company's information
security policy?
A.It obligates the IT department to basic services.
B.It defines basic responsibilities for all stakeholders.
C.It defines the responsibilities of employees and managers.
D.It defines basic responsibilities for executive management.
Answer: B
5. Consider the following firewall rules:
Incoming traffic:
TCP Port 25
TCP Port 139: Denied
UDP Port 137: Denied
UDP Port 138: Denied
ICMP echo request: Denied
ICMP echo reply: Denied
Outgoing traffic:
TCP Ports 1024 through 65,535 to port 80: Denied
TCP Port 80: Denied
ICMP echo request: Denied
ICMP echo reply: Denied
TCP Port 139: Denied
UDP Port 137: Denied
UDP Port 138: Denied
All company production servers reside behind the corporate firewall.
However, you discover that the Web server performance is very low. After
sniffing the traffic to the Web server, you learn that the Web server
is experiencing a distributed denial-of-service attack in which millions
of ping packets are being directed at the server. Which of the
following is the most plausible explanation for this situation?
A.There is a flaw in the firewall rule set.
B.The firewall is not configured to block ICMP packets generated by the
ping command.
C.The attack is originating from a wireless access point (WAP) connected
to the corporate network.
D.The attack is originating from a Web server that has not been properly
updated, and which has been infected with a Trojan horse.
Answer: C
6. Consider the following sequence:
user1@zeppelin:/public$ su -
root@zeppelin:~# chmod 1777 /public
root@zeppelin:~# exit
Which of the following most accurately describes the result of this
command?
A.Only the root user can create and delete files in the /public
directory.
B.All users can create, delete and read files in the /public directory,
but only root has execute permissions.
C.All users can create and read files in the /public directory, but only
root can delete another user's file.
D.Any user can create files in the / directory, but no user can delete a
file in this directory unless root permissions are obtained.
Answer: C
7. You and your team have created a security policy document that is 120
pages long. Which of the following techniques will help ensure that
upper-level managers read the essential policy elements?
A.Including a sign-off sheet
B.Including an executive summary
C.Using bold type to emphasize essential elements
D.Using italic type to emphasize essential elements
Answer: B
8. Two routers in your company network require a firmware upgrade. Which
of the following upgrade strategies will reduce downtime?
A.Conducting the upgrade while the routers are still running
B.Upgrading the routers using the latest upgrade software
C.Conducting the upgrade after rebooting the router
D.Upgrading the routers after business hours
Answer: D