Official Bank 0/62

CIW v5 Security Essentials (1D0-571) - CIW Actual Exam Questions

Last updated on April 15, 2026

97% Exam Compliance
62 Total Questions
1
Question

Consider the following image of a packet capture: This packet capture has recorded two types of attacks. Which choice lists both attack types?

Question image
Options
A

A dictionary attack and a worm-based attackA.A dictionary attack and a worm-based attack

B

A syn flood attack and a spoofing attackB.A syn flood attack and a spoofing attack

C

A worm attack and a botnet attack C.A worm attack and a botnet attack

D

A SQL injection attack and a virus attackD.A SQL injection attack and a virus attack

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question

At what layer of the OSI/RM does a packet filter operate?

Options
A

Layer 1

B

Layer 3

C

Layer 5

D

Layer 7

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question

Irina has contracted with a company to provide Web design consulting services. The company has asked her to use several large files available via an HTTP server. The IT department has provided Irina with user name and password, as well as the DNS name of the HTTP server. She then used this information to obtain the files she needs to complete her task using Mozilla Firefox. Which of the following is a primary risk factor when authenticating with a standard HTTP server?

Options
A

HTTP uses cleartext transmission during authentication, which can lead to a man-in-the-middle attack.

B

Irina has used the wrong application for this protocol, thus increasing the likelihood of a man-in- the-middle attack.

C

A standard HTTP connection uses public-key encryption that is not sufficiently strong, inviting the possibility of a man-in-the-middle attack.

D

Irina has accessed the Web server using a non-standard Web browser.

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question

Your organization has made a particularly unpopular policy decision. Your supervisor fears that a series of attacks may occur as a result. You have been assigned to increase automated auditing on a server. When fulfilling this request, which of the following resources should you audit the most aggressively?

Options
A

Authentication databases, including directory servers

B

Intrusion detection systems, especially those placed on sensitive networks

C

Log files on firewall systems

D

Firewall settings for desktop systems

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question

Which of the following is most likely to address a problem with an operating system's ability to withstand an attack that attempts to exploit a buffer overflow?

Options
A

Firewall

B

Software update

C

Intrusion detection system

D

Network scanner

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.