ExamNotes.net  -  IT certification portal

ForumsCertResearchTop sitesNewslettersFree email
HomeRegister
Exams Notes
Practice exams
Exam games
Questions by email
Online training
Training videos
College degrees
Boot camps
Book store
Links directory
Tell a friend
For webmasters

CompTIA Exam Vouchers
Save money on CompTIA exams
Question of the day
Sign up to receive
interactive practice questions
for MCSE, CompTIA
Cisco and other exams
TestKing
Get MCSE, MCSD, CCNA, CCNP,A+, N+ and many more

* ExamSheets *
Guide for Success!
Actual Questions & Answers
MCSE, MCSD, A+ ,CCNA, CCNP
Oracle 8i, Oracle 9i

Online practice tests

Certification sites

Online university

Online college

Online education

Distance learning

Software forum

Server administration forum

Programming resources






This is interesting: Free IT Magazines | Databases help forum



CompTIA > Security+ > test

Show a Printable Version
Email This Page to Someone!
Receive updates to this thread


www.ExamVouchers.com - Get Instant $60 OFF Security+ exam and a free practice test!

Featured site: Online Security+ practice exams from Cert21.com



Pages (2): [1] 2 »

Author test
Boricua
Junior Member




Registered: Mar 2002
Location:
Country: United States
State:
Certifications: CCDA, CCNA, IASO
Working on: CISSP

Total Posts: 10
test

test

Report this post to a moderator

Old Post 07-15-03 06:21 PM
Boricua is offline Click Here to See the Profile for Boricua Click here to Send Boricua a Private Message Add Boricua to your buddy list Find more posts by Boricua Reply w/Quote Edit/Delete Message IP: Logged
Boricua
Junior Member




Registered: Mar 2002
Location:
Country: United States
State:
Certifications: CCDA, CCNA, IASO
Working on: CISSP

Total Posts: 10
Test Questions: Study

I have a couple of questions below which I need help
on.

1. Can somebody tell me what the name of the file
would be if the administrator could only access the
password file from root?

a. shadow
b. passwd
c. password
d. none of the above

2. What are the 3 components of Kerberos?


3. What vulnerability is in TCP/IP that allows a
hijack session to occur?

4. A severed T-1 circuit is an example of what?
a. incident response
b. incident handling
c. disaster recovery
d. business continuity?

5. What is a good practice in deploying a CA?

Just a few questions that have me scratching my head.

Report this post to a moderator

Old Post 07-15-03 06:24 PM
Boricua is offline Click Here to See the Profile for Boricua Click here to Send Boricua a Private Message Add Boricua to your buddy list Find more posts by Boricua Reply w/Quote Edit/Delete Message IP: Logged
RussS
radical dood
M




Registered: Sep 2002
Location: Hamilton
Country: New Zealand (Aotearoa)
State:
Certifications: MCP W2K Pro & Server, A+, Net+, NZQA L3 Computing
Working on: Security+, MCSA, Linux+

Total Posts: 955

First a question ..... where did your questions come from?

__________________
Go hard or go home!

Report this post to a moderator

Old Post 07-15-03 09:19 PM
RussS is offline Click Here to See the Profile for RussS Click here to Send RussS a Private Message Add RussS to your buddy list Find more posts by RussS Send a message to RussS Reply w/Quote Edit/Delete Message IP: Logged
Boricua
Junior Member




Registered: Mar 2002
Location:
Country: United States
State:
Certifications: CCDA, CCNA, IASO
Working on: CISSP

Total Posts: 10

I got them from a friend who has been studying for the CISSP exam as well as the SSCP exam. Do you know any of the answers?

Report this post to a moderator

Old Post 07-15-03 10:27 PM
Boricua is offline Click Here to See the Profile for Boricua Click here to Send Boricua a Private Message Add Boricua to your buddy list Find more posts by Boricua Reply w/Quote Edit/Delete Message IP: Logged
RussS
radical dood
M




Registered: Sep 2002
Location: Hamilton
Country: New Zealand (Aotearoa)
State:
Certifications: MCP W2K Pro & Server, A+, Net+, NZQA L3 Computing
Working on: Security+, MCSA, Linux+

Total Posts: 955

Q1 I haven't seen anything like this in any of the Sec+ materials I have read. However I would hazard a guess and say shadow "Most systems ship with shadow passport support. In this systems users passwords are stored in a seperate file, /etc/shadow. This file cannot be read by most users making it more difficukt for a miscreant with an accoubnt on a computer to break into other users accounts. (Sybex Linux+ / Roderick Smith).

Q2 3 components of Kreberos? I am confused here - does this refeer to the 3 steps of authentication? - Or perhaps the 3 systems involved? (client/KDC/Resource server)

Q3 There are a couple vulnerabilities in TCP/IP. These range from Telnet sessions to web based ecommerce to hijacking session cookies - a wide scope there.

Q4 A severed T1 could be an example of several things depending on various factors.
a. incident response - yes if it involves repairing it.
c. disaster recovery - not6 100%, but could be included if your hot/colf site was also connected to this line.
d. business continuity - yes if your business relies on the T1 line totally.

Q5 Another interesting and possibly confusing one. I would suggest that having a good understanding of the Certificate Policy was right up there.

__________________
Go hard or go home!

Report this post to a moderator

Old Post 07-16-03 02:15 AM
RussS is offline Click Here to See the Profile for RussS Click here to Send RussS a Private Message Add RussS to your buddy list Find more posts by RussS Send a message to RussS Reply w/Quote Edit/Delete Message IP: Logged
Boricua
Junior Member




Registered: Mar 2002
Location:
Country: United States
State:
Certifications: CCDA, CCNA, IASO
Working on: CISSP

Total Posts: 10

Good answers RussS

Can anyone tell me a disadvantage to using a VPN or other encrypted data in a network?

Report this post to a moderator

Old Post 07-19-03 04:22 AM
Boricua is offline Click Here to See the Profile for Boricua Click here to Send Boricua a Private Message Add Boricua to your buddy list Find more posts by Boricua Reply w/Quote Edit/Delete Message IP: Logged
RussS
radical dood
M




Registered: Sep 2002
Location: Hamilton
Country: New Zealand (Aotearoa)
State:
Certifications: MCP W2K Pro & Server, A+, Net+, NZQA L3 Computing
Working on: Security+, MCSA, Linux+

Total Posts: 955

There are a couple that I can think of, but I will wait and see who else responds before I advance my opinion

__________________
Go hard or go home!

Report this post to a moderator

Old Post 07-19-03 07:07 AM
RussS is offline Click Here to See the Profile for RussS Click here to Send RussS a Private Message Add RussS to your buddy list Find more posts by RussS Send a message to RussS Reply w/Quote Edit/Delete Message IP: Logged
Tarzanboy
Senior Member




Registered: Mar 2002
Location:
Country: United States
State:
Certifications: A+, N+, Sec+, MCP, MCSA2k, MCSE2k
Working on: 70-214, 70-292

Total Posts: 1013

1. There is the higher bandwidth consumption required.
2. It requires increased processing time and power.
3. NIDS cannot detect the intent of the packets nullifying any benefits, which would require implementation and use of HIDS, which also increases processing time and power.
4. Interchange of keys can be problematic and usually requires use of a specialized system, such as SSL/TLS.

Cheers,
TB

Report this post to a moderator

Old Post 07-19-03 08:39 AM
Tarzanboy is offline Click Here to See the Profile for Tarzanboy Click here to Send Tarzanboy a Private Message Add Tarzanboy to your buddy list Find more posts by Tarzanboy Reply w/Quote Edit/Delete Message IP: Logged
RussS
radical dood
M




Registered: Sep 2002
Location: Hamilton
Country: New Zealand (Aotearoa)
State:
Certifications: MCP W2K Pro & Server, A+, Net+, NZQA L3 Computing
Working on: Security+, MCSA, Linux+

Total Posts: 955

Excellent responses

I will add common mistakes or problems ....

Forgetting or discounting other forms of security access controls such as NTFS permissions.
Not ensuring that both ends of the VPN have the same permissions etc.
Incorrect firewall settings.

Of course I am consider anything but seriously encrypted VPN or VPN over SSH totally insecure and a waste of time

__________________
Go hard or go home!

Report this post to a moderator

Old Post 07-19-03 09:23 AM
RussS is offline Click Here to See the Profile for RussS Click here to Send RussS a Private Message Add RussS to your buddy list Find more posts by RussS Send a message to RussS Reply w/Quote Edit/Delete Message IP: Logged
Tarzanboy
Senior Member




Registered: Mar 2002
Location:
Country: United States
State:
Certifications: A+, N+, Sec+, MCP, MCSA2k, MCSE2k
Working on: 70-214, 70-292

Total Posts: 1013

What, IPSec traffic between Win2k machines doesn't count?

Cheers,
TB

Report this post to a moderator

Old Post 07-19-03 10:17 AM
Tarzanboy is offline Click Here to See the Profile for Tarzanboy Click here to Send Tarzanboy a Private Message Add Tarzanboy to your buddy list Find more posts by Tarzanboy Reply w/Quote Edit/Delete Message IP: Logged
All times are GMT.
Pages (2): [1] 2 » Post new thread   Post reply

Click here for list of Security+ study guides and order yours now!

CompTIA exam notes

Security+ exam details



Forum Jump:
Rate This Thread:
Forum Rules:
Who Can Read The Forum? Any registered user or guest.
Who Can Post New Topics? Any registered user.
Who Can Post Replies? Any registered user.
Changes: Messages can be edited by their author.
Posts: HTML code is OFF. Smilies are ON. vB code is ON. [IMG] code is OFF.
 

ExamNotes forum archive


Powered by: vBulletin 2.2.8
Copyright ©2000, Jelsoft Enterprises Limited.

  Free Braindumps | mcse braindumps