Home > Quiz: What's your infosec IQ?
Security Quiz:
EMAIL THIS

Quiz: What's your infosec IQ?

13 Oct 2005 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

We get a lot of positive feedback about our quizzes on SearchSecurity. But it seems that we've been a little too easy on some of you. So, we've collected our toughest questions to see how well you stand up to a challenge. Put your knowledge to the test and let us know how you do.

1.) An IDS follows a two-step process consisting of a passive component and an active component. Which of the following is part of the active component?
a. Inspection of password files to detect inadvisable passwords
b. Mechanisms put in place to reenact known methods of attack and record system responses
c. Inspection of system to detect policy violations
d. Inspection of configuration files to detect inadvisable settings
Answer

More security quizzes
Web Security School Entrance Exam

Playing with fire(walls)

E-mail security

Vulnerability management

Is spyware getting the best of you?

Locking down IIS

Intrusion detection and prevention systems

2.) Which of the following is the best definition of risk analysis when discussing IT security?
a. Risk analysis looks at the probability that a hacker may break in to your system.
b. Risk analysis looks at the probability that your security measures won't stop a hacker breaking in to your system.
c. Risk analysis determines what resources you need to protect and quantifies the costs of not protecting them.
d. Risk analysis looks at the probability that a vulnerability exists in your system.
e. Risk analysis looks at the consequences of being connected to the Internet.
Answer

3.) What type of attacks do some firewalls try to limit by enforcing rules on how long a GET or POST request can be?
a. Smurf
b. Denial of service
c. Buffer overflow
d. LAND
Answer

4.) What happens if you digitally sign and inject a footer on an e-mail message in the wrong order?
a. Nothing.
b. The message won't be sent.
c. The footer will invalidate the signature.
d. The footer will be illegible.
Answer

5.) Which is the correct set of network components that need to be available for the Internet-facing network card of a dual-homed IIS Web server running on Windows 2000?
a. Client for Microsoft Networks, File and Printer Sharing for Microsoft Networks, Internet Protocol (TCP/IP)
b. Client for Microsoft Networks, Internet Protocol (TCP/IP)
c. Internet Protocol (TCP/IP)
d. File and Printer Sharing for Microsoft Networks, Internet Protocol (TCP/IP)
e. None of the above
Answer

6.) What firewall topology utilizes a triple-homed firewall?
a. Series circuit
b. Bastion host
c. Screened subnet
d. Dual firewalls
Answer

7.) What is the difference between a network vulnerability assessment and a penetration test?
a. A penetration test identifies running services, and vulnerability assessments provide a more in-depth understanding of vulnerabilities.
b. A penetration test enumerates resources, and a vulnerability assessment enumerates vulnerabilities.
c. A penetration test exploits vulnerabilities, and a vulnerability assessment finds vulnerabilities.
d. They are one in the same.
Answer

8.) What differentiates a pop-up download from a drive-by download?
a. A pop-up download is a program that automatically downloads to the user's computer.
b. A pop-up download asks the user's permission before downloading a program to their computer.
c. A pop-up download is frequently installed with another application.
d. A pop-up download is carried out invisibly to the user.
Answer

9.) Which of the following vulnerabilities allows an attacker to take control of IIS?
a. ISAPI Extension buffer overflows
b. Microsoft Server Message Block vulnerability
c. Windows License Logging Service overflow
d. All of the above
Answer

10.) What is the purpose of a shadow honeypot?
a. To flag attacks against known vulnerabilities.
b. To help reduce false positives in a signature-based IDS.
c. To randomly check suspicious traffic identified by an anomaly detection system.
d. To enhance the accuracy of a traditional honeypot.
Answer
How'd you score?
9-10 correct: Security scholar
6-8 correct: Security savvy
3-5 correct: Security novice
0-2 correct: Security simpleton


BROWSE BY TAG
Application and Platform Security,   Application Attacks (Buffer Overflows, Cross-Site Scripting),   Enterprise Vulnerability Management,   Security Testing and Ethical Hacking,   Email Protection,   Email Security Guidelines, Encryption and Appliances,   Web Security Tools and Best Practices,   Web Server Threats and Countermeasures,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Application Attacks (Buffer Overflows, Cross-Site Scripting)
Quiz: How to build secure applications
Black box and white box testing: Which is best?
Adobe warns of critical update for Reader, Acrobat 9.1.3
9 Ways to Improve Application Security After an Incident
Developers Need Help with Security Errors
Buffer overflow tutorial: How to find vulnerabilities, prevent attacks
SQL injection protection: A guide on how to prevent and stop attacks
Experts rebuke programmers who use SQL injection as feature
SANS: Application threats, website flaws pose biggest security threats
Mozilla helps Adobe push out faster patches
Application Attacks (Buffer Overflows, Cross-Site Scripting) Research

Security Testing and Ethical Hacking
H.D. Moore speaks about Metasploit Project deal, Release 3.3
Could Metasploit popularity erode?
Metasploit Project acquired by vulnerability management firm Rapid7
Should management processes change based on a patch release schedule?
Does an EULA make it truly illegal to decompile software?
Screencast: BackTrack 4 offers an arsenal of penetration testing tools
Security testing firm uncovers XML vulnerabilities
Screencast: Samurai offers pen-testing nirvana
The requirements needed to make an external penetration test legal
McAfee to acquire Solidcore Systems for whitelisting

Email Security Guidelines, Encryption and Appliances
How to confirm the receipt of an email with security protocols
Best Email Security Products
Can an IP spoofing tool be used to spam SPF servers?
WatchGuard acquires email and Web security vendor BorderWare
McAfee to acquire email SaaS vendor MX Logic
What does 'invoked by uid 78' mean?
How to configure firewall ports for webmail system implementation
Fierce competition prompted new Cisco email security options
Cisco brings email security appliances closer to SaaS
Cisco offers more email security choices, but lacks vision

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
buffer overflow  (SearchSecurity.com)
cache poisoning  (SearchSecurity.com)
cyberterrorism  (SearchSecurity.com)
dictionary attack  (SearchSecurity.com)
directory harvest attack  (SearchSecurity.com)
distributed denial-of-service attack  (SearchSecurity.com)
JavaScript hijacking  (SearchSecurity.com)
ping of death  (SearchSecurity.com)
stack smashing  (SearchSecurity.com)
SYN flooding  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary




Search Additional Security Research and Solutions
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts