
Ace CIW 1D0-671 Certification with Actual Questions Jun 11, 2025 Updated
2025 The Most Effective 1D0-671 with 126 Questions Answers
NEW QUESTION # 36
In relation to security, which of the following is the primary benefit of classifying systems?
- A. Ability to recover quickly from a natural or man-made disaster
- B. Ability to identify common attacks
- C. Identification of highest-priority systems to protect
- D. Collection of information for properly configuring the firewall
Answer: C
NEW QUESTION # 37
Which of the following is a primary auditing activity?
- A. Checking log files
- B. Encrypting data files
- C. Configuring the firewall
- D. Changing login accounts
Answer: A
NEW QUESTION # 38
An effective way to prevent a user from becoming the victim of a malicious bot is to use a technique in which the user must view a distorted text image, and then type it before he or she is allowed to proceed with a transaction.
This technique is known as a:
- A. CAPTCHA.
- B. zombie.
- C. botnet.
- D. SQL injection.
Answer: A
NEW QUESTION # 39
Which of the following is a typical target of a trojan on a Linux system?
- A. Shared libraries
- B. System32 DLL files
- C. Kernel modules
- D. Boot sector files
Answer: C
NEW QUESTION # 40
What is the primary use of hash (one-way) encryption in networking?
- A. Key exchange, for user authentication
- B. Signing files, for data integrity
- C. User authentication, for non-repudiation
- D. Encrypting files, for data confidentiality
Answer: B
NEW QUESTION # 41
Which of the following standards is used for digital certificates?
- A. X.509
- B. DES
- C. Diffie-Hellman
- D. RC5
Answer: A
NEW QUESTION # 42
Which of the following can effectively thwart VLAN hopping?
- A. Removing the default VLAN setting (VLAN1) from any trunk port
- B. Enabling multiple firewalls on your broadcast domain
- C. Enabling your network's autotrunking capability
- D. Ensuring that each trunk port retains its default VLAN setting (VLAN1)
Answer: A
NEW QUESTION # 43
Which type of encryption poses challenges to key transport?
- A. Symmetric-key encryption
- B. Asymmetric-key encryption
- C. Hash encryption
- D. Diffie-Hellman
Answer: A
NEW QUESTION # 44
You have just deployed an application that uses hash-based checksums to monitor changes in the configuration scripts of a database server that is accessible via the Internet.
Which of the following is a primary concern for this solution?
- A. The amount of memory remaining now that the checksum-based application is running
- B. The possibility of a buffer overflow attack leading to a security breach
- C. The security of the checksum database on a read-only media format
- D. The extra hard disk space required to store the database of checksums
Answer: C
NEW QUESTION # 45
Which of the following can help reduce the likelihood of a successful dictionary attack?
- A. A strong password policy
- B. A security policy
- C. The use of Microsoft Active Directory
- D. An IPSEC-based VPN
Answer: A
NEW QUESTION # 46
You have determined that the company Web server has several vulnerabilities, including a buffer overflow that has resulted in an attack. The Web server uses PHP and has direct connections to an Oracle database server. It also uses many CGI scripts.
Which of the following is the most effective way to respond to this attack?
- A. Installing an intrusion detection service to monitor logins
- B. Using the POST method instead of the GET method for a Web form
- C. Using the GET method instead of the POST method for a Web form
- D. Installing software updates for the Web server daemon
Answer: D
NEW QUESTION # 47
What is the term for a self-replicating program or algorithm that consumes system resources?
- A. Trojan
- B. Illicit server
- C. Worm
- D. Root kit
Answer: C
NEW QUESTION # 48
Which of the following is a common problem with proxy servers?
- A. Proxy servers may return old cached information.
- B. Proxy servers cannot filter out specific application-layer traffic.
- C. Because proxy servers do not mask network resources, hackers may be able to access all exposed systems.
- D. Proxy servers do not log incoming and outgoing access, so you will not be able to see details of successful and failed connections.
Answer: A
NEW QUESTION # 49
You have implemented a service on a Linux system that allows a user to read and edit resources.
What is the function of this service?
- A. Intrusion detection
- B. Access control
- C. Data integrity
- D. Authentication
Answer: B
NEW QUESTION # 50
Which of the following is the most likely first step to enable a server to recover from a denial-of- service attack in which all hard disk data is lost?
- A. Rebuild your RAID 0 array
- B. Contact a disk recovery service
- C. Enable virtualization
- D. Contact the backup service
Answer: D
NEW QUESTION # 51
Which of the following security measures presents the most risk?
- A. A jail
- B. A firewall application
- C. A login script
- D. A tripwire
Answer: A
NEW QUESTION # 52
You want to create a quick solution that allows you to obtain real-time login information for the administrative account on an LDAP server that you feel may become a target.
Which of the following will accomplish this goal?
- A. Install an application that creates checksums of the contents on the hard disk.
- B. Create a dummy administrator account on the system so that a potential hacker is distracted from the real login account.
- C. Create a login script for the administrative account that records logins to a separate server.
- D. Reinstall the LDAP service on the server so that it is updated and more secure.
Answer: C
NEW QUESTION # 53
You have determined that an attack is currently underway on your database server. An attacker is currently logged in, modifying data. You want to preserve logs, caching and other data on this affected server.
Which of the following actions will best allow you to stop the attack and still preserve data?
- A. Shut down the server
- B. Force an instant password reset
- C. Back up the system logs
- D. Pull the server network cable
Answer: D
NEW QUESTION # 54
What is the first tool needed to create a secure networking environment?
- A. User authentication
- B. Security policy
- C. Auditing
- D. Confidentiality
Answer: B
NEW QUESTION # 55
Which task should you perform first when considering where to place equipment?
- A. Conduct research to determine the appropriate products for your organization.
- B. Secure funding.
- C. Conduct a needs assessment audit.
- D. Consult with management to determine specific needs.
Answer: C
NEW QUESTION # 56
You are using a PKI solution that is based on Secure Sockets Layer (SSL).
Which of the following describes the function of the asymmetric-key-encryption algorithm used?
- A. It encrypts the symmetric key.
- B. It encrypts the X.509 key.
- C. It encrypts the hash code used for data integrity.
- D. It encrypts all of the data.
Answer: A
NEW QUESTION # 57
You have discovered that the ls, su and ps commands no longer function as expected. They do not return information in a manner similar to any other Linux system. Also, the implementation of Tripwire you have installed on this server is returning new hash values.
Which of the following has most likely occurred?
- A. A trojan has attacked the system.
- B. A spyware application has been installed.
- C. A SQL injection attack has occurred.
- D. A root kit has been installed on the system.
Answer: D
NEW QUESTION # 58
Which of the following is a security principle that allows you to protect your network resources?
- A. Provide training for end users and IT workers.
- B. Realize that some high-end systems should stand alone.
- C. Deploy security enforcement only in the largest departments.
- D. Avoid being suspicious of legitimate activity.
Answer: A
NEW QUESTION # 59
What would be the result if you were the recipient of a SYN flood or malformed packet?
- A. A virus would be unleashed on your system at the time the SYN flood or malformed packet was received.
- B. You would be unable to access a legitimate service, such as establishing a network connection.
- C. You would be misdirected to a fraudulent Web site without your knowledge or consent.
- D. The files on your boot sector would be replaced with infected code.
Answer: B
NEW QUESTION # 60
Which of the following tools allows you to implement packet filtering for a network?
- A. Bridge
- B. Browser
- C. Router
- D. Hub
Answer: C
NEW QUESTION # 61
......
Try Free and Start Using Realistic Verified 1D0-671 Dumps Instantly.: https://www.actual4exams.com/1D0-671-valid-dump.html
1D0-671 Actual Questions - Instant Download 126 Questions: https://drive.google.com/open?id=1poVOQz5EGhOdQeiqGk4QvHFqfF2a95rC