CIW Web Security Associate Free Sample Questions

Create a free account to browse all 20 sample questions. The full practice test includes 199 questions. Use the simulator for timed and flashcard mode.

Try Simulator

1D0-671 Sample Questions

  1. Question 1

    Q1

    A financial services company is implementing a Defense in Depth strategy. The security architect has designed a multi-layered approach to protect sensitive customer data. Which of the following sets of controls best exemplifies the core principle of Defense in Depth?

    Show answer & explanation

    Correct answer: C

    Defense in Depth is a strategy that employs a series of redundant protective measures in case a single security control fails. This option correctly lists multiple, distinct layers of security controls: network (VLANs), host (host-based firewalls), data (encryption), and application (RBAC). The failure of one layer (e.g., the perimeter firewall) would not immediately compromise the entire system because other layers are still in place.

  2. Question 2

    Q2

    A security analyst is reviewing network traffic and observes a large volume of small UDP packets originating from a single source IP address, targeting random high-numbered ports on multiple servers. The source IP address does not correspond to any known legitimate client. This pattern is consistent with which of the following activities?

    Show answer & explanation

    Correct answer: B

    A UDP port scan works by sending UDP packets to a range of ports on a target. If a port is open, there is typically no response. If a port is closed, the target system should respond with an ICMP 'Port Unreachable' message. The observed traffic pattern—many UDP packets to various ports—is a classic indicator of a UDP scan, which is a form of reconnaissance used by attackers to map out vulnerable services.

  3. Question 3

    Q3

    A developer needs to securely transmit a large 2GB data file to a partner organization. The primary requirements are confidentiality during transit and high performance for the encryption/decryption process. Which cryptographic approach is most suitable for encrypting the file itself?

    Show answer & explanation

    Correct answer: B

    Symmetric encryption algorithms like AES are significantly faster and more computationally efficient than asymmetric algorithms like RSA, especially for large amounts of data. Given the 2GB file size and the performance requirement, AES is the ideal choice for encrypting the file content itself. The symmetric key used for AES would then typically be encrypted using an asymmetric algorithm (like RSA) for secure key exchange with the partner.

  4. Question 4

    Q4

    A network administrator is configuring a new packet-filtering firewall to protect a Web server. The company policy states that all inbound traffic should be blocked by default. The Web server needs to accept connections from the Internet on port 443. Which of the following firewall rules should be added to allow this traffic while maintaining the default-deny policy?

    Show answer & explanation

    Correct answer: D

    To allow inbound HTTPS traffic to the Web server, a rule must be created that specifies the conditions for allowed packets. The correct rule allows traffic from any source IP, destined for the specific IP of the Web server, using the TCP protocol on destination port 443. This is a specific 'allow' rule that overrides the general 'deny all' policy for this particular traffic type.

  5. Question 5

    Q5

    During a security audit, it was discovered that a critical server has been compromised. The incident response team needs to collect evidence for a forensic investigation. The lead investigator instructs the junior admin to immediately disconnect the server's power cable to preserve the state of the hard drive. Why is this instruction incorrect for digital forensic best practices?

    Show answer & explanation

    Correct answer: C

    The primary mistake in pulling the power cable is the immediate loss of all volatile data stored in Random Access Memory (RAM). This data is critical for a forensic investigation as it contains information about currently running processes (which could be malware), active network connections (showing communication with an attacker), cached data, and potentially even decryption keys for encrypted volumes. The correct first step is to perform a live data acquisition to capture the contents of RAM before powering down the system.

  6. Question 6

    Q6Multiple answers

    A security team is tasked with hardening a new Linux server. Which of the following actions are considered essential best practices for operating system hardening? (Select THREE)

    Show answer & explanation

    Correct answers: A, C, E

    Essential OS hardening practices aim to reduce the attack surface and enforce the principle of least privilege. Disabling unnecessary services removes potential vulnerabilities. Configuring a host-based firewall provides a critical layer of network defense directly on the server. Implementing mandatory access control (MAC) systems like SELinux provides fine-grained control over process permissions, significantly mitigating the impact of a potential compromise.

  7. Question 7

    Q7

    True or False: In a Public Key Infrastructure (PKI) system, a user's private key is mathematically derived from their public key and stored by the Certificate Authority (CA) for recovery purposes.

    Show answer & explanation

    Correct answer: B

    This statement is false. The private key and public key are generated as a pair, but it is computationally infeasible to derive the private key from the public key; this is the fundamental principle of asymmetric cryptography. Furthermore, the private key must be kept secret by the owner and should never be shared with or stored by the Certificate Authority. The CA's role is to vouch for the identity of the public key's owner, not to hold their private key.

  8. Question 8

    Q8

    An e-commerce company wants to ensure the integrity of software downloads offered on its customer portal. The goal is to allow customers to verify that the downloaded file has not been altered since it was published by the company. Which cryptographic tool is the most appropriate solution for this requirement?

    Show answer & explanation

    Correct answer: B

    Hashing algorithms like SHA-256 are designed to provide data integrity. The company can compute the hash of the original file and publish it. A customer can then download the file, compute the hash on their own machine, and compare it to the published value. If the hashes match, the customer can be confident the file is unaltered. Encryption provides confidentiality, not integrity, and asymmetric keys are for authentication and key exchange.

  9. Question 9

    Q9

    A hospital's network administrator is designing a firewall architecture to protect its Electronic Health Record (EHR) system. Due to compliance requirements, the firewall must be able to inspect and understand the specific application-layer protocols used by the EHR software to block non-compliant commands, even if they are sent over a standard port. Which type of firewall is required to meet this need?

    Show answer & explanation

    Correct answer: D

    An Application-Level Gateway, also known as a proxy firewall, operates at the Application layer (Layer 7) of the OSI model. This allows it to understand application-specific protocols (like HTTP, FTP, or a proprietary EHR protocol). It can perform deep packet inspection to analyze the content of the traffic and make decisions based on specific commands or data, which is exactly what is required to block non-compliant EHR commands. Packet filters and circuit-level gateways operate at lower layers and lack this application awareness.

  10. Question 10

    Q10

    A security analyst uses the 'nmap' tool to scan a server with the command nmap -sS -p 1-1024 10.1.1.5. What is the primary characteristic of the scan type specified by the -sS flag?

    Show answer & explanation

    Correct answer: C

    The -sS flag in nmap specifies a TCP SYN scan, often called a 'stealth scan' or 'half-open scan'. Instead of completing the full three-way handshake (SYN, SYN/ACK, ACK), it sends a SYN packet and waits for a SYN/ACK. If a SYN/ACK is received, the port is open, and nmap sends a RST (reset) packet to tear down the connection before it is fully established. This method is often less likely to be logged by older or simpler intrusion detection systems, hence the 'stealthy' characteristic.

Register free to unlock 10 more sample questions

Create a free account to continue with the rest of the 1D0-671 sample set.

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 199 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon