v5 Security Essentials Free Sample Questions

12 free sample questions62 in the full practice test

Try simulator

1D0-571 Sample Questions

  1. Question 1

    Which of the following is a primary auditing activity?

    Answer and explanation

    Correct answer: C

    Checking log files is the primary auditing activity as it involves systematically reviewing system, application, and security logs to identify unauthorized access attempts, policy violations, and security incidents. Auditing focuses on monitoring and analyzing what has already occurred rather than preventing future events. Encrypting data files is a data protection control, changing login accounts is an access management task, and configuring firewalls is a preventive security control - none of these constitute the core auditing function of reviewing and analyzing logged events for security assessment and compliance purposes.

  2. Question 2

    Your organization has made a particularly unpopular policy decision. Your supervisor fears that a series of attacks may occur as a result. You have been assigned to increase automated auditing on a server. When fulfilling this request, which of the following resources should you audit the most aggressively?

    Answer and explanation

    Correct answer: A

    Authentication databases and directory servers should be the primary focus for increased automated auditing when expecting potential insider attacks, as these systems track all user login attempts, failed authentications, privilege escalations, and account modifications. When employees are disgruntled due to unpopular policies, monitoring authentication events helps detect unauthorized access attempts, credential abuse, and suspicious login patterns. While IDS systems, firewall logs, and desktop firewall settings provide valuable security data, authentication databases offer the most direct visibility into user behavior and potential insider threats during periods of organizational tension.

  3. Question 3

    You have discovered that the Is, su and ps commands no longer function as expected. They do not return information in a manner similar to any other Linux system. Also, the implementation of Tripwire you have installed on this server is returning new hash values. Which of the following has most likely occurred?

    Answer and explanation

    Correct answer: D

    A rootkit has been installed on the system, as evidenced by the modification of fundamental system commands (ls, su, ps) and the Tripwire file integrity monitoring system detecting new hash values. Rootkits specifically target and replace core system binaries and commands to hide malicious activity while maintaining persistent access. The altered behavior of these essential commands indicates kernel-level compromise typical of rootkit infections. Trojans typically focus on specific malicious payloads, SQL injection attacks target database applications, and spyware primarily monitors user activity - none of these would systematically alter core system commands or trigger widespread file integrity violations detected by Tripwire.

  4. Question 4

    A disgruntled employee has discovered that the company Web server is not protected against a particular buffer overflow vulnerability. The disgruntled employee has created an application to take advantage of this vulnerability and secretly obtain sensitive data from the Web server's hard disk. This application sends a set of packets to the Web server that causes it to present an unauthenticated terminal with root privileges. What is the name for this particular type of attack?

    Answer and explanation

    Correct answer: D

    This represents a zero-day attack because the employee discovered and exploited a previously unknown buffer overflow vulnerability that the security team and vendors were unaware of, creating a custom application to exploit this unpatched weakness. Zero-day attacks leverage vulnerabilities that have not been publicly disclosed or patched, giving defenders zero days to prepare. Man-in-the-middle attacks intercept communications between parties, trojans are malicious programs disguised as legitimate software, and denial of service attacks aim to make resources unavailable - none of these accurately describe exploiting an undisclosed buffer overflow vulnerability with custom exploit code.

  5. Question 5

    Which of the following details should be included in documentation of an attack?

    Answer and explanation

    Correct answer: C

    Attack documentation must include the time and date of the attack and names of employees contacted during response to establish a clear timeline and chain of custody for incident response procedures. This factual information is essential for forensic analysis, legal proceedings, and post-incident reviews. Security policy overviews belong in separate policy documents, cost estimates require extensive financial analysis that may not be immediately available, and while network resources and recommendations are valuable, they are typically documented in separate technical and lessons-learned reports rather than the primary incident documentation which focuses on factual chronology and response coordination.

  6. Question 6

    At the beginning of an IPsec session, which activity occurs during the Internet Key Exchange (IKE)?

    Answer and explanation

    Correct answer: B

    During the Internet Key Exchange (IKE) phase of IPsec session establishment, negotiating the authentication method is a fundamental activity that determines how the communicating parties will verify each other's identities before establishing the secure tunnel. IKE Phase 1 specifically handles authentication method selection (pre-shared keys, digital certificates, or other methods) along with encryption and hashing algorithms. Determining security associations comes after authentication is established, network identification numbers are not part of IKE negotiation, and IP version selection occurs at the network layer before IPsec processing begins.

Register free to unlock 6 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 62 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon