1D0-671 Sample Questions

1D0-671 Sample Questions & Answers

Network security fundamentals and access-control policy edge out the rest, alongside encryption methods, universal security-implementation guidelines, attack identification and countermeasures, firewall types and terminology, and multi-level firewall design.

Launch the full 1D0-671 simulator →

Showing 10 of 20 free samples.

  1. Question 1IntermediateSelect 3

    Network Security Principles and Implementation · Define Operating System and network device hardening.

    A security team is tasked with hardening a new Linux server. Which of the following actions are considered essential best practices for operating system hardening? (Select THREE)

    Show answer & explanation

    Correct answers: A, C, E

    Essential OS hardening practices aim to reduce the attack surface and enforce the principle of least privilege. Disabling unnecessary services removes potential vulnerabilities. Configuring a host-based firewall provides a critical layer of network defense directly on the server. Implementing mandatory access control (MAC) systems like SELinux provides fine-grained control over process permissions, significantly mitigating the impact of a potential compromise.

  2. Question 2Intermediate

    Encryption and Cryptography · Define a certification authority (CA) and its role related to trust between systems.

    True or False: In a Public Key Infrastructure (PKI) system, a user's private key is mathematically derived from their public key and stored by the Certificate Authority (CA) for recovery purposes.

    Show answer & explanation

    Correct answer: B

    This statement is false. The private key and public key are generated as a pair, but it is computationally infeasible to derive the private key from the public key; this is the fundamental principle of asymmetric cryptography. Furthermore, the private key must be kept secret by the owner and should never be shared with or stored by the Certificate Authority. The CA's role is to vouch for the identity of the public key's owner, not to hold their private key.

  3. Question 3Beginner

    Network Security Fundamentals and Security Policy · Identify the importance of network security, including the CIA triad (Confidentiality, Integrity, and Availability).

    An e-commerce company wants to ensure the integrity of software downloads offered on its customer portal. The goal is to allow customers to verify that the downloaded file has not been altered since it was published by the company. Which cryptographic tool is the most appropriate solution for this requirement?

    Show answer & explanation

    Correct answer: B

    Hashing algorithms like SHA-256 are designed to provide data integrity. The company can compute the hash of the original file and publish it. A customer can then download the file, compute the hash on their own machine, and compare it to the published value. If the hashes match, the customer can be confident the file is unaltered. Encryption provides confidentiality, not integrity, and asymmetric keys are for authentication and key exchange.

  4. Question 4Advanced

    Firewall Technologies · Identify application-level gateways and their features.

    A hospital's network administrator is designing a firewall architecture to protect its Electronic Health Record (EHR) system. Due to compliance requirements, the firewall must be able to inspect and understand the specific application-layer protocols used by the EHR software to block non-compliant commands, even if they are sent over a standard port. Which type of firewall is required to meet this need?

    Show answer & explanation

    Correct answer: D

    An Application-Level Gateway, also known as a proxy firewall, operates at the Application layer (Layer 7) of the OSI model. This allows it to understand application-specific protocols (like HTTP, FTP, or a proprietary EHR protocol). It can perform deep packet inspection to analyze the content of the traffic and make decisions based on specific commands or data, which is exactly what is required to block non-compliant EHR commands. Packet filters and circuit-level gateways operate at lower layers and lack this application awareness.

  5. Question 5Intermediate

    Network Security Principles and Implementation · Identify network security management applications, including network scanners, operating system, add-ons, log analysis tools.

    A security analyst uses the 'nmap' tool to scan a server with the command nmap -sS -p 1-1024 10.1.1.5. What is the primary characteristic of the scan type specified by the -sS flag?

    Show answer & explanation

    Correct answer: C

    The -sS flag in nmap specifies a TCP SYN scan, often called a 'stealth scan' or 'half-open scan'. Instead of completing the full three-way handshake (SYN, SYN/ACK, ACK), it sends a SYN packet and waits for a SYN/ACK. If a SYN/ACK is received, the port is open, and nmap sends a RST (reset) packet to tear down the connection before it is fully established. This method is often less likely to be logged by older or simpler intrusion detection systems, hence the 'stealthy' characteristic.

  6. Question 6Beginner

    Firewall System Design and Incident Response · Distract Cyber-attackers and contain their activity.

    A company is setting up a honeypot as part of its proactive detection strategy. What is the primary goal of deploying a honeypot in a network environment?

    Show answer & explanation

    Correct answer: B

    A honeypot is a decoy computer system set up to attract and trap malicious users or malware. Its primary purpose is to act as a target, diverting attackers from legitimate production systems. By doing this, security teams can safely study the attackers' methods, tools, and intentions without risking actual company assets. Any traffic to the honeypot is inherently suspicious, making it an excellent tool for early threat detection.

  7. Question 7Intermediate

    Security Attacks and Countermeasures · Identify specific types of security attacks.

    Which type of security attack involves an attacker intercepting communications between two parties and relaying messages between them, making them believe they are talking directly to each other over a private connection, when in fact the entire conversation is controlled by the attacker?

    sequenceDiagram participant Alice participant Attacker participant Bob Alice->>Attacker: Hello Bob! (encrypted with Bob's supposed public key) Note over Attacker: Decrypts with own private key, Note over Attacker: re-encrypts with Bob's real public key Attacker->>Bob: Hello Bob! Bob-->>Attacker: Hello Alice! (encrypted with Alice's supposed public key) Note over Attacker: Decrypts with own private key, Note over Attacker: re-encrypts with Alice's real public key Attacker-->>Alice: Hello Alice!

    Show answer & explanation

    Correct answer: C

    This describes a classic Man-in-the-Middle (MitM) attack. The attacker positions themselves between two communicating parties, intercepts all messages, and can read, modify, or inject new messages into the conversation. The diagram clearly shows the attacker intercepting, decrypting, and re-encrypting messages between Alice and Bob, making it a perfect illustration of a MitM attack.

  8. Question 8Advanced

    Security Attacks and Countermeasures · Implementing password storage techniques to include PBKDF2, Bcrypt, salting, and key stretching.

    A company is reviewing its password storage security. A consultant recommends using a key stretching technique like PBKDF2 or bcrypt instead of a simple salted hash. What is the primary security benefit of using key stretching for password storage?

    Show answer & explanation

    Correct answer: C

    Key stretching algorithms (also known as key derivation functions) like PBKDF2 and bcrypt are designed to be deliberately slow. They repeatedly apply a cryptographic hash function thousands of times. This makes it computationally expensive and time-consuming for an attacker to perform brute-force or dictionary attacks against a stolen password hash database, even with specialized hardware like GPUs. A simple salted hash can be computed very quickly, making it more vulnerable to offline cracking.

  9. Question 9Intermediate

    Network Security Principles and Implementation · Identify Trusted Platform Modules and Microsoft BitLocker.

    A startup is deploying its application in a public cloud environment and wants to implement full disk encryption for its virtual machine instances to protect data at rest. Which technology, often integrated with cloud platforms, provides hardware-based root of trust for securely storing cryptographic keys?

    Show answer & explanation

    Correct answer: B

    A Trusted Platform Module (TPM) is a specialized hardware chip that provides secure, hardware-based cryptographic functions. One of its primary roles is to securely generate and store cryptographic keys used for full disk encryption (like with Microsoft BitLocker). It ensures that the encryption keys are protected and are only released when the system boots in a trusted state, providing a hardware root of trust that is more secure than storing keys in software.

  10. Question 10Beginner

    Network Security Fundamentals and Security Policy · Define the significance of a security policy and necessary sub-policies including AUP, NDA, BYOD policies.

    A security auditor is reviewing a company's Acceptable Use Policy (AUP). Which of the following clauses is MOST critical to include in an AUP to mitigate risks from internal users?

    Show answer & explanation

    Correct answer: C

    An Acceptable Use Policy (AUP) defines the rules and constraints that users must agree to for access to a corporate network or the Internet. The most critical security-related clauses prohibit actions that introduce significant risk, such as installing unauthorized software (which could be malware) and sharing passwords (which undermines authentication and accountability). These rules directly address common vectors for security breaches originating from internal users.

Ready for the real thing?

The full 1D0-671 simulator has every exam-style question, timed mode, and instant scoring.