Try Before You Buy

Download a free sample of any of our exam questions and answers

  • 24/7 customer support, Secure shopping site
  • Free One year updates to match real exam scenarios
  • If you failed your exam after buying our products we will refund the full amount back to you.

CIW 1D0-671 Real Exam Questions Guaranteed Updated Dump from ExamsTorrent [Q16-Q41]

Share

CIW 1D0-671 Real Exam Questions Guaranteed Updated Dump from ExamsTorrent

Verified Pass 1D0-671 Exam in First Attempt Guaranteed

NEW QUESTION # 16
A denial-of-service attack has been perpetrated on your system, resulting in loss of essential data.
Which of the following can help you recover quickly from this attack?

  • A. A backup service
  • B. A firewall
  • C. An intrusion-detection device
  • D. Stateful multi-layer inspection

Answer: A


NEW QUESTION # 17
Which of the following is the simplest, most common firewall design?

  • A. A screened subnet
  • B. A dual-homed bastion host
  • C. A single-homed bastion host
  • D. A screening router

Answer: D


NEW QUESTION # 18
Your organization has made a particularly unpopular policy decision. Your supervisor fears that a series of attacks may occur as a result. You have been assigned to increase automated auditing on a server.
When fulfilling this request, which of the following resources should you audit the most aggressively?

  • A. Authentication databases, including directory servers
  • B. Log files on firewall systems
  • C. Firewall settings for desktop systems
  • D. Intrusion detection systems, especially those placed on sensitive networks

Answer: A


NEW QUESTION # 19
What distinguishes hash encryption from other forms of encryption?

  • A. Hash encryption creates a single key that is used to encrypt and decrypt information.
  • B. Hash encryption is the encryption method of choice when conducting e-commerce transactions.
  • C. Hash encryption is used for information that you want never to be decrypted or read.
  • D. Hash encryption creates a mathematically matched key pair in which one half of the pair encrypts, and the other half decrypts.

Answer: C


NEW QUESTION # 20
You are using a PKI solution that is based on Secure Sockets Layer (SSL).
Which of the following describes the function of the asymmetric-key-encryption algorithm used?

  • A. It encrypts all of the data.
  • B. It encrypts the symmetric key.
  • C. It encrypts the X.509 key.
  • D. It encrypts the hash code used for data integrity.

Answer: B


NEW QUESTION # 21
Which of the following can specify the route by which a packet of information has traveled?

  • A. A physical line trace
  • B. A reverse scan
  • C. A phone line trace
  • D. A packet trace

Answer: D


NEW QUESTION # 22
Your firewall is configured to forbid all internal traffic from going out to the Internet. You want to allow internal clients to access all Web traffic.
At a minimum, what ports must you open in regards to the internal systems?

  • A. TCP Ports 80 and 443
  • B. TCP Port 80 and all ports above 1023
  • C. TCP Ports 80 and 443, and all ports above 1023
  • D. All TCP ports above 80 and below 1023

Answer: C


NEW QUESTION # 23
Jason is attempting to gain unauthorized access to a corporate server by running a program that enters passwords from a long list of possible passwords.
Which type of attack is this?

  • A. Botnet
  • B. Denial of service
  • C. Buffer overflow
  • D. Brute force

Answer: D


NEW QUESTION # 24
Which step in security policy implementation ensures that security policy will change as technology advances?

  • A. Repeat the process and keep current.
  • B. Publish the security policy.
  • C. Log, test and evaluate.
  • D. Secure each resource and service.

Answer: A


NEW QUESTION # 25
After you have determined that a hacker has entered your system, what is the first step you should take?

  • A. Determine the scope of the breach on affected systems.
  • B. Review the pre-written security response policy.
  • C. Document the hacker's activity after penetration has occurred.

Answer: B


NEW QUESTION # 26
Which of the following is the device used to authenticate and encrypt packets in IPsec?

  • A. Internet Key Exchange (IKE)
  • B. Encapsulating Security Payload (ESP)
  • C. Authentication Header (AH)
  • D. Encryption tunnel

Answer: B


NEW QUESTION # 27
What would be the result if you were the recipient of a SYN flood or malformed packet?

  • A. A virus would be unleashed on your system at the time the SYN flood or malformed packet was received.
  • B. You would be misdirected to a fraudulent Web site without your knowledge or consent.
  • C. You would be unable to access a legitimate service, such as establishing a network connection.
  • D. The files on your boot sector would be replaced with infected code.

Answer: C


NEW QUESTION # 28
What is the primary use of hash (one-way) encryption in networking?

  • A. Key exchange, for user authentication
  • B. User authentication, for non-repudiation
  • C. Encrypting files, for data confidentiality
  • D. Signing files, for data integrity

Answer: D


NEW QUESTION # 29
You have been assigned to provide security measures for your office's reception area. Although the company needs to provide security measures, costs must be kept to a minimum.
Which of the following tools is the most appropriate choice?

  • A. Camera
  • B. Firewall
  • C. Intrusion-detection system
  • D. Security guard

Answer: A


NEW QUESTION # 30
Consider the following diagram involving two firewall-protected networks:
Which of the following is necessary for each of the firewalls to allow private IP addresses to be passed on to the Internet?

  • A. Chargeback
  • B. Stateful multi-layer inspection
  • C. DMZ creation
  • D. Masquerading

Answer: D


NEW QUESTION # 31
Which attribute of a security matrix considers the number of employees necessary to successfully implement and maintain your system?

  • A. Access control
  • B. Appropriate cost of ownership
  • C. Ease of use
  • D. Flexibility and scalability

Answer: B


NEW QUESTION # 32
A security breach has occurred involving the company e-commerce server. Customer credit card data has been released to unauthorized third parties.
Which of the following lists the appropriate parties to inform?

  • A. The Internet Service Provider, ICANN and company shareholders
  • B. Affected customers, credit card companies and law enforcement agencies
  • C. External security consultants, company board members and affected customers
  • D. Shareholders, law enforcement agencies and company employees

Answer: B


NEW QUESTION # 33
Which of the following is a primary weakness of asymmetric-key encryption?

  • A. It is difficult to transfer any portion of an asymmetric key securely.
  • B. It can lead to the corruption of encrypted data during network transfer.
  • C. It is reliant on the Secure Sockets Layer (SSL) standard, which has been compromised.
  • D. It is slow because it requires extensive calculations by the computer.

Answer: D


NEW QUESTION # 34
Which of the following is a common problem, yet commonly overlooked, in regards to physical security in server rooms?

  • A. Firewalls that do not have a dedicated backup
  • B. Logic bombs
  • C. Biometric malfunctions
  • D. False ceilings

Answer: D


NEW QUESTION # 35
Danielle was informed by her network administrator that an audit may be conducted during the night to determine the hosts that exist on the network and document any open ports. The next day, Danielle was unable to access any network services.
What may have occurred instead of the anticipated audit?

  • A. A social engineering attack
  • B. A brute-force attack
  • C. A scanning attack
  • D. A zero-day attack

Answer: C


NEW QUESTION # 36
The best way to thwart a dictionary attack is by enforcing a:

  • A. firewall configuration policy.
  • B. strong password policy.
  • C. proxy server policy.
  • D. restricted access policy.

Answer: B


NEW QUESTION # 37
Which of the following applications can help determine whether a denial-ofservice attack is occurring against a network host?

  • A. The iptables command and Windows desktop firewall
  • B. The netstat command and a packet sniffer
  • C. The ps command and a network scanner
  • D. The ping command and User Manager

Answer: B


NEW QUESTION # 38
Which of the following commands would you use to create a simple personal firewall that blocks all incoming ICMP traffic?

  • A. iptables -A INPUT -p icmp -s 10.100.100.0/255.255.255 -d 0/0 -j KILL
  • B. iptables -A INPUT -p icmp -s 0/0 -d 0/0 -j DROP
  • C. iptables - INPUT -p icmp -s 0/0 -d 0/0 -j KILL
  • D. iptables -A INPUT -p icmp -s 10.100.100.0/24 -d 0/0 -j DROP

Answer: B


NEW QUESTION # 39
Which of the following causes problems with firewalls

  • A. Data FTP
  • B. Active FTP
  • C. Control FTP
  • D. Passive FTP

Answer: B


NEW QUESTION # 40
What is the main purpose of reviewing a security incident after it has been resolved?

  • A. To learn what can be changed or improved in your security policy
  • B. To discover and report that a piece of hardware or software has purportedly failed
  • C. To bring charges against the ISP that carries the hacker's account
  • D. To discover who within your company should be reprimanded

Answer: A


NEW QUESTION # 41
......

Download Real CIW 1D0-671 Exam Dumps Test Engine Exam Questions: https://www.examstorrent.com/1D0-671-exam-dumps-torrent.html

Free 1D0-671 Sample Questions and 100% Cover Real Exam Questions: https://drive.google.com/open?id=1sGg3rqWjKIsF_ejSFrNF1kIETmxvNhWx