Skip to content

1D0-671 CIW Web Security Associate Practice Questions

Prepare for 1D0-671 with more than an answer.

199 questions in the full set20 sample questionsUpdated Oct 18, 2025
Exam fee
$150 USD
Level
Associate
Valid for
3 years
Domains covered on the exam 6
  1. Network Security Fundamentals and Security Policy18%
  2. Encryption and Cryptography17%
  3. Network Security Principles and Implementation16%
  4. Security Attacks and Countermeasures17%
  5. Firewall Technologies16%
  6. Firewall System Design and Incident Response16%
  1. 1

    A small business is looking for a cost-effective way to obtain a TLS certificate for its public-facing website to enable HTTPS. They have a limited budget and need a solution that is widely trusted by modern web browsers. Which of the following is the most suitable option?

    Show answer details

    Correct answer: C

    Let's Encrypt is a non-profit Certificate Authority that provides free, automated, and open TLS certificates. These certificates are trusted by virtually all modern browsers and are an ideal solution for small businesses and individuals who need to secure their websites with HTTPS without incurring the cost of commercial certificates. EV certificates are expensive, and self-signed certificates will generate trust warnings in user browsers.

  2. 2

    What is the primary difference between an Intrusion Detection System (IDS) and an Intrusion Prevention System (IPS)?

    Show answer details

    Correct answer: C

    The key distinction lies in their response capabilities. An IDS is a passive monitoring system; it analyzes traffic or system logs for suspicious activity and generates an alert for an administrator to review. An IPS is an active, in-line system; it not only detects malicious activity but can also take immediate, automated action to block or prevent the threat, such as dropping malicious packets or terminating a connection.

  3. 3

    A network is segmented into multiple VLANs, including a 'Servers' VLAN and a 'Workstations' VLAN. To enhance security, a firewall is placed between the VLANs. What is the primary function of this firewall in an inter-VLAN routing context?

    Show answer details

    Correct answer: B

    By design, devices on different VLANs cannot communicate directly; they require a Layer 3 device (like a router or a Layer 3 switch) to route traffic between them. Placing a firewall as the inter-VLAN router allows an organization to enforce security policies on all traffic that crosses VLAN boundaries. This enables granular control, such as allowing workstations to access a web server but blocking them from accessing the server's remote administration port.

  4. 4

    Which of the following describes a Rainbow Table attack? (Select TWO)

    Show answer details

    Correct answer: B, C

  5. 5

    A consultant is performing a security assessment and needs to identify potential vulnerabilities without actively exploiting them. The goal is to get a comprehensive report of missing patches, weak configurations, and known software flaws. Which type of security assessment should be performed?

    Show answer details

    Correct answer: B

    A vulnerability assessment (or vulnerability scan) is an automated process of proactively identifying security weaknesses in systems and networks. It uses tools to scan for known vulnerabilities (like CVEs), missing security patches, and insecure configurations. Unlike a penetration test, it does not attempt to actively exploit the vulnerabilities it finds. Its output is a report of potential risks, which aligns perfectly with the consultant's goal.

  6. 6

    A financial services company is implementing a Defense in Depth strategy. The security architect has designed a multi-layered approach to protect sensitive customer data. Which of the following sets of controls best exemplifies the core principle of Defense in Depth?

    Show answer details

    Correct answer: C

    Defense in Depth is a strategy that employs a series of redundant protective measures in case a single security control fails. This option correctly lists multiple, distinct layers of security controls: network (VLANs), host (host-based firewalls), data (encryption), and application (RBAC). The failure of one layer (e.g., the perimeter firewall) would not immediately compromise the entire system because other layers are still in place.

  7. 7

    A security analyst is reviewing network traffic and observes a large volume of small UDP packets originating from a single source IP address, targeting random high-numbered ports on multiple servers. The source IP address does not correspond to any known legitimate client. This pattern is consistent with which of the following activities?

    Show answer details

    Correct answer: B

    A UDP port scan works by sending UDP packets to a range of ports on a target. If a port is open, there is typically no response. If a port is closed, the target system should respond with an ICMP 'Port Unreachable' message. The observed traffic pattern—many UDP packets to various ports—is a classic indicator of a UDP scan, which is a form of reconnaissance used by attackers to map out vulnerable services.

  8. 8

    A developer needs to securely transmit a large 2GB data file to a partner organization. The primary requirements are confidentiality during transit and high performance for the encryption/decryption process. Which cryptographic approach is most suitable for encrypting the file itself?

    Show answer details

    Correct answer: B

    Symmetric encryption algorithms like AES are significantly faster and more computationally efficient than asymmetric algorithms like RSA, especially for large amounts of data. Given the 2GB file size and the performance requirement, AES is the ideal choice for encrypting the file content itself. The symmetric key used for AES would then typically be encrypted using an asymmetric algorithm (like RSA) for secure key exchange with the partner.

  9. 9

    A network administrator is configuring a new packet-filtering firewall to protect a Web server. The company policy states that all inbound traffic should be blocked by default. The Web server needs to accept connections from the Internet on port 443. Which of the following firewall rules should be added to allow this traffic while maintaining the default-deny policy?

    Show answer details

    Correct answer: D

    To allow inbound HTTPS traffic to the Web server, a rule must be created that specifies the conditions for allowed packets. The correct rule allows traffic from any source IP, destined for the specific IP of the Web server, using the TCP protocol on destination port 443. This is a specific 'allow' rule that overrides the general 'deny all' policy for this particular traffic type.

  10. 10

    During a security audit, it was discovered that a critical server has been compromised. The incident response team needs to collect evidence for a forensic investigation. The lead investigator instructs the junior admin to immediately disconnect the server's power cable to preserve the state of the hard drive. Why is this instruction incorrect for digital forensic best practices?

    Show answer details

    Correct answer: C

    The primary mistake in pulling the power cable is the immediate loss of all volatile data stored in Random Access Memory (RAM). This data is critical for a forensic investigation as it contains information about currently running processes (which could be malware), active network connections (showing communication with an attacker), cached data, and potentially even decryption keys for encrypted volumes. The correct first step is to perform a live data acquisition to capture the contents of RAM before powering down the system.

Create an account to continue.