1D0-571 v5 Security Essentials Practice Questions
Prepare for 1D0-571 with more than an answer.
- 1
Requests for Web-based resources have become unacceptably slow. You have been assigned to implement a solution that helps solve this problem. Which of the following would you recommend?
Show answer details
Correct answer: B
Implementing caching on the network proxy server directly addresses slow Web-based resource requests by storing frequently accessed content locally, reducing bandwidth consumption and response times for subsequent requests to the same resources. Proxy caching eliminates repeated downloads of identical content and minimizes latency from external servers. Stateful multi-layer inspection adds processing overhead that would further slow requests, authentication mechanisms introduce additional delays for user verification, and screening routers focus on security filtering rather than performance optimization, making caching the most effective solution for improving Web resource access speed.
- 2
You have been asked to encrypt a large file using a secure encryption algorithm so you can send it via e-mail to your supen/isor. Encryption speed is important. The key will not be transmitted across a network. Which form of encryption should you use?
Show answer details
Correct answer: D
Symmetric encryption is optimal for large file encryption when speed is important and the key does not need network transmission, as it uses the same key for both encryption and decryption with significantly faster processing than asymmetric algorithms. Symmetric algorithms like AES can encrypt large volumes of data hundreds of times faster than asymmetric encryption. Asymmetric encryption is computationally intensive and impractical for large files, PGP typically combines both symmetric and asymmetric methods adding complexity, and hash functions provide data integrity verification rather than encryption, making symmetric encryption the best choice for fast, large file encryption scenarios.
- 3
A distributed denial-of-service (DDOS) attack has occurred where both ICMP and TCP packets have crashed the company's Web server. Which of the following techniques will best help reduce the severity of this attack?
Show answer details
Correct answer: A
Filtering traffic at the firewall provides the most effective immediate response to a DDoS attack by blocking malicious ICMP and TCP packets before they reach the Web server, reducing the attack load and preventing server resource exhaustion. Firewall filtering can implement rate limiting, block specific source IPs, and drop suspicious traffic patterns. Changing ISPs does not address the attack itself and may cause service disruption, switching Web server software does not mitigate DDoS traffic volume, and database separation provides architectural benefits but does not reduce the incoming attack traffic overwhelming the Web server.
- 4
Which of the following is a primary auditing activity?
Show answer details
Correct answer: C
Checking log files is the primary auditing activity as it involves systematically reviewing system, application, and security logs to identify unauthorized access attempts, policy violations, and security incidents. Auditing focuses on monitoring and analyzing what has already occurred rather than preventing future events. Encrypting data files is a data protection control, changing login accounts is an access management task, and configuring firewalls is a preventive security control - none of these constitute the core auditing function of reviewing and analyzing logged events for security assessment and compliance purposes.
- 5
Your organization has made a particularly unpopular policy decision. Your supervisor fears that a series of attacks may occur as a result. You have been assigned to increase automated auditing on a server. When fulfilling this request, which of the following resources should you audit the most aggressively?
Show answer details
Correct answer: A
Authentication databases and directory servers should be the primary focus for increased automated auditing when expecting potential insider attacks, as these systems track all user login attempts, failed authentications, privilege escalations, and account modifications. When employees are disgruntled due to unpopular policies, monitoring authentication events helps detect unauthorized access attempts, credential abuse, and suspicious login patterns. While IDS systems, firewall logs, and desktop firewall settings provide valuable security data, authentication databases offer the most direct visibility into user behavior and potential insider threats during periods of organizational tension.
- 6
You have discovered that the Is, su and ps commands no longer function as expected. They do not return information in a manner similar to any other Linux system. Also, the implementation of Tripwire you have installed on this server is returning new hash values. Which of the following has most likely occurred?
Show answer details
Correct answer: D
A rootkit has been installed on the system, as evidenced by the modification of fundamental system commands (ls, su, ps) and the Tripwire file integrity monitoring system detecting new hash values. Rootkits specifically target and replace core system binaries and commands to hide malicious activity while maintaining persistent access. The altered behavior of these essential commands indicates kernel-level compromise typical of rootkit infections. Trojans typically focus on specific malicious payloads, SQL injection attacks target database applications, and spyware primarily monitors user activity - none of these would systematically alter core system commands or trigger widespread file integrity violations detected by Tripwire.
