210-250 Practice Questions
198 real 210-250 exam questions with expert-verified answers and explanations. Page 1 of 4.
- Question #1
Which definition of a process in Windows is true?
- Question #2
Which definition of permissions in Linux is true?
- Question #3
Which hashing algorithm is the least secure?
- Question #4
Which protocol is expected to have NTP a user agent, host, and referrer headers in a packet capture?
- Question #5
Which definition of a daemon on Linux is true?
- Question #6
Which definition of vulnerability is true?
- Question #7
Which option is an advantage to using network-based anti-virus versus host-based anti- virus?
- Question #8
Which evasion method involves performing actions slower than normal to prevent detection?
- Question #9
Which event occurs when a signature-based IDS encounters network traffic that triggers an alert?
- Question #10
Which data can be obtained using NetFlow?
- Question #11
Which term describes the act of a user, without authority or permission, obtaining rights on a system, beyond what were assigned?
- Question #12
Refer to the exhibit. A TFTP server has recently been installed in the Atlanta office. The network administrator is located in the NY office and has attempted to make a connection...
- Question #13
Which term represents a potential danger that could take advantage of a weakness in a system?
- Question #14
Which security principle states that more than one person is required to perform a critical task?
- Question #15
You must create a vulnerability management framework. Which main purpose of this framework is true?
- Question #16
In computer security, which information is the term PHI used to describe?
- Question #17
Which security monitoring data type requires the most storage space?
- Question #18
Which type of exploit normally requires the culprit to have prior access to the target system?
- Question #19
Which identifier is used to describe the application or process that submitted a log message?
- Question #20
Which concern is important when monitoring NTP servers for abnormal levels of traffic?
- Question #21
Which protocol is primarily supported by the third layer of the Open Systems Interconnection reference model?
- Question #22
A firewall requires deep packet inspection to evaluate which layer?
- Question #23
Which two protocols are used for email (Choose two )
- Question #24
Which two options are recognized forms of phishing? (Choose two )
- Question #25
While viewing packet capture data, you notice that one IP is sending and receiving traffic for multiple devices by modifying the IP header, Which option is making this behavior pos...
- Question #26
Which definition of an antivirus program is true?
- Question #27
Which type of attack occurs when an attacker is successful in eavesdropping on a conversation between two IPS phones?
- Question #28
An intrusion detection system begins receiving an abnormally high volume of scanning from numerous sources. Which evasion technique does this attempt indicate?
- Question #29
Which type of attack occurs when an attacker utilizes a botnet to reflect requests off an NTP server to overwhelm their target?
- Question #30
In NetFlow records, which flags indicate that an HTTP connection was stopped by a security appliance, like a firewall, before it could be built fully?
- Question #31
Which definition of a fork in Linux is true?
- Question #32
Which two actions are valid uses of public key infrastructure? (Choose two )
- Question #33
Which two terms are types of cross site scripting attacks? (Choose two )
- Question #34
Which network device is used to separate broadcast domains?
- Question #35
Based on which statement does the discretionary access control security model grant or restrict access ?
- Question #36
Which cryptographic key is contained in an X.509 certificate?
- Question #37
Which two activities are examples of social engineering? (Choose two)
- Question #38
Which hash algorithm is the weakest?
- Question #39
A user reports difficulties accessing certain external web pages, When examining traffic to and from the external domain in full packet captures, you notice many SYNs that have the...
- Question #40
Which tool is commonly used by threat actors on a webpage to take advantage of the softwarevulnerabilitiesof a system to spread malware?
- Question #41
Refer to the exhibit. During an analysis this list of email attachments is found. Which files contain the same content?
- Question #42
Which term represents the practice of giving employees only those permissions necessary to perform their specific role within an organization?
- Question #43
Which term represents the chronological record of how evidence was collected- analyzed, preserved, and transferred?
- Question #44
Which two tasks can be performed by analyzing the logs of a traditional stateful firewall? (Choose two.)
- Question #45
Which security monitoring data type is associated with application server logs?
- Question #46
Where is a host-based intrusion detection system located?
- Question #47
One of the objectives of information security is to protect the CIA of information and systems. What does CIA mean in this context?
- Question #48
According to RFC 1035 which transport protocol is recommended for use with DNS queries?
- Question #49
Which definition describes the main purpose of a Security Information and Event Management solution ?
- Question #50
Which option is a purpose of port scanning?