











CompTIA
Exam Vouchers
Save money on CompTIA exams
| Question of the day
Sign up to receive
interactive practice questions
for MCSE, CompTIA
Cisco and other exams
| TestKing
Get MCSE, MCSD, CCNA, CCNP,A+, N+ and many more | * ExamSheets *
Guide for Success!
Actual Questions & Answers
MCSE, MCSD, A+ ,CCNA, CCNP
Oracle 8i, Oracle 9i Online practice tests
Certification sites Online university Online college Online education Distance learning Software forum Server administration forum Programming resources
|
|  |
Pages (2): [1] 2 »
Boricua
Junior Member
Registered: Mar 2002 Location: Country: United States State: Certifications: CCDA, CCNA, IASO Working on: CISSP
Total Posts: 10
|
|
|
07-15-03 06:21 PM
|
|
Boricua
Junior Member
Registered: Mar 2002 Location: Country: United States State: Certifications: CCDA, CCNA, IASO Working on: CISSP
Total Posts: 10
|
|
Test Questions: Study
I have a couple of questions below which I need help
on.
1. Can somebody tell me what the name of the file
would be if the administrator could only access the
password file from root?
a. shadow
b. passwd
c. password
d. none of the above
2. What are the 3 components of Kerberos?
3. What vulnerability is in TCP/IP that allows a
hijack session to occur?
4. A severed T-1 circuit is an example of what?
a. incident response
b. incident handling
c. disaster recovery
d. business continuity?
5. What is a good practice in deploying a CA?
Just a few questions that have me scratching my head.
Report this post to a moderator
|
|
07-15-03 06:24 PM
|
|
RussS
radical dood M

Registered: Sep 2002 Location: Hamilton Country: New Zealand (Aotearoa) State: Certifications: MCP W2K Pro & Server, A+, Net+, NZQA L3 Computing Working on: Security+, MCSA, Linux+
Total Posts: 955
|
|
|
07-15-03 09:19 PM
|
|
Boricua
Junior Member
Registered: Mar 2002 Location: Country: United States State: Certifications: CCDA, CCNA, IASO Working on: CISSP
Total Posts: 10
|
|
I got them from a friend who has been studying for the CISSP exam as well as the SSCP exam. Do you know any of the answers?
Report this post to a moderator
|
|
07-15-03 10:27 PM
|
|
RussS
radical dood M

Registered: Sep 2002 Location: Hamilton Country: New Zealand (Aotearoa) State: Certifications: MCP W2K Pro & Server, A+, Net+, NZQA L3 Computing Working on: Security+, MCSA, Linux+
Total Posts: 955
|
|
Q1 I haven't seen anything like this in any of the Sec+ materials I have read. However I would hazard a guess and say shadow "Most systems ship with shadow passport support. In this systems users passwords are stored in a seperate file, /etc/shadow. This file cannot be read by most users making it more difficukt for a miscreant with an accoubnt on a computer to break into other users accounts. (Sybex Linux+ / Roderick Smith).
Q2 3 components of Kreberos? I am confused here - does this refeer to the 3 steps of authentication? - Or perhaps the 3 systems involved? (client/KDC/Resource server)
Q3 There are a couple vulnerabilities in TCP/IP. These range from Telnet sessions to web based ecommerce to hijacking session cookies - a wide scope there.
Q4 A severed T1 could be an example of several things depending on various factors.
a. incident response - yes if it involves repairing it.
c. disaster recovery - not6 100%, but could be included if your hot/colf site was also connected to this line.
d. business continuity - yes if your business relies on the T1 line totally.
Q5 Another interesting and possibly confusing one. I would suggest that having a good understanding of the Certificate Policy was right up there.
__________________
Go hard or go home!
Report this post to a moderator
|
|
07-16-03 02:15 AM
|
|
Boricua
Junior Member
Registered: Mar 2002 Location: Country: United States State: Certifications: CCDA, CCNA, IASO Working on: CISSP
Total Posts: 10
|
|
|
07-19-03 04:22 AM
|
|
RussS
radical dood M

Registered: Sep 2002 Location: Hamilton Country: New Zealand (Aotearoa) State: Certifications: MCP W2K Pro & Server, A+, Net+, NZQA L3 Computing Working on: Security+, MCSA, Linux+
Total Posts: 955
|
|
There are a couple that I can think of, but I will wait and see who else responds before I advance my opinion 
__________________
Go hard or go home!
Report this post to a moderator
|
|
07-19-03 07:07 AM
|
|
Tarzanboy
Senior Member
Registered: Mar 2002 Location: Country: United States State: Certifications: A+, N+, Sec+, MCP, MCSA2k, MCSE2k Working on: 70-214, 70-292
Total Posts: 1013
|
|
1. There is the higher bandwidth consumption required.
2. It requires increased processing time and power.
3. NIDS cannot detect the intent of the packets nullifying any benefits, which would require implementation and use of HIDS, which also increases processing time and power.
4. Interchange of keys can be problematic and usually requires use of a specialized system, such as SSL/TLS.
Cheers,
TB
Report this post to a moderator
|
|
07-19-03 08:39 AM
|
|
RussS
radical dood M

Registered: Sep 2002 Location: Hamilton Country: New Zealand (Aotearoa) State: Certifications: MCP W2K Pro & Server, A+, Net+, NZQA L3 Computing Working on: Security+, MCSA, Linux+
Total Posts: 955
|
|
Excellent responses
I will add common mistakes or problems ....
Forgetting or discounting other forms of security access controls such as NTFS permissions.
Not ensuring that both ends of the VPN have the same permissions etc.
Incorrect firewall settings.
Of course I am consider anything but seriously encrypted VPN or VPN over SSH totally insecure and a waste of time 
__________________
Go hard or go home!
Report this post to a moderator
|
|
07-19-03 09:23 AM
|
|
Tarzanboy
Senior Member
Registered: Mar 2002 Location: Country: United States State: Certifications: A+, N+, Sec+, MCP, MCSA2k, MCSE2k Working on: 70-214, 70-292
Total Posts: 1013
|
|
|
07-19-03 10:17 AM
|
|
|
Click here for list of Security+
study guides and order yours now!
CompTIA exam notes
Security+ exam details
Forum Rules: Who Can Read The Forum? Any registered user or guest.
Who Can Post New Topics? Any registered user.
Who Can Post Replies? Any registered user.
Changes: Messages can be edited by their author.
Posts: HTML code is OFF. Smilies are ON. vB code is ON. [IMG] code is OFF. |
|
ExamNotes forum archive
|