100-160 Sample Questions

100-160 Sample Questions & Answers

Endpoint operating-system security carries the largest share, from assessment tools to policy compliance, alongside TCP/IP vulnerabilities, core access-management principles, vulnerability and risk management, and escalating security incidents.

Launch the full 100-160 simulator →

Showing 6 of 12 free samples.

  1. Question 1Advanced

    Essential Security Principles · Explain common threats and vulnerabilities

    A physical security consultant is hired to test the defenses of a logistics company's main headquarters. The consultant arrives at the facility during the morning rush hour. Carrying two large boxes of donuts, the consultant approaches the secure entrance just as an employee swipes their RFID badge. The employee politely holds the door open, allowing the consultant to enter without badging in.

    Once inside, the consultant walks to an empty cubicle and leaves a USB flash drive labeled 'Q3 Executive Bonuses' on the desk. An hour later, an employee finds the drive, plugs it into their workstation, and unknowingly executes a hidden payload that establishes a reverse shell to the consultant's server.

    Which combination of attack vectors did the consultant successfully utilize in this scenario?

    flowchart TD A[Attacker arrives at HQ] --> B[Waits for employee to swipe badge] B --> C[Employee holds door open] C --> D[Attacker enters without badge] D --> E[Leaves labeled USB on desk] E --> F[Victim plugs in USB] F --> G[Payload executes]
    Show answer & explanation

    Correct answer: B

    Tailgating (or piggybacking) occurs when an unauthorized person follows an authorized person into a restricted area, often by exploiting common courtesy, such as holding a door. Baiting is a social engineering attack where an attacker leaves a physical device (like a USB drive) in a location where a victim is likely to find it, relying on curiosity to prompt the victim to plug it in.

  2. Question 2Beginner

    Essential Security Principles · Explain access management principles

    A systems administrator is explaining the AAA framework to a new help desk employee. The administrator notes that when a user attempts to access a network device, the system first verifies the user's identity, then determines what commands the user is allowed to execute, and finally logs the commands the user actually runs. Which component of AAA is responsible for determining what commands the user is allowed to execute?

    Show answer & explanation

    Correct answer: D

    In the AAA framework, Authorization is the process of determining what rights or privileges a user has after they have been successfully identified. Authentication verifies the identity (who the user is), Authorization determines permissions (what they can do), and Accounting tracks their actions (what they did).

  3. Question 3Beginner

    Essential Security Principles · Explain encryption methods and applications

    True or False: Hashing is a reversible cryptographic process that allows the original plaintext data to be recovered by applying the correct decryption key.

    Show answer & explanation

    Correct answer: B

    Hashing is a one-way mathematical function designed to ensure data integrity. Unlike encryption, which is a two-way (reversible) process, a hash cannot be reversed or decrypted to reveal the original plaintext. It is primarily used to verify that data has not been altered.

  4. Question 4Intermediate

    Essential Security Principles · Explain encryption methods and applications

    A corporate executive needs to send a highly sensitive financial report to the Chief Financial Officer (CFO) via email. The organization uses a Public Key Infrastructure (PKI) for secure communications. To ensure that only the CFO can read the contents of the email, which cryptographic key must the executive use to encrypt the message?

    Show answer & explanation

    Correct answer: A

    In asymmetric encryption (used in PKI), a public key is used to encrypt data, and the corresponding private key is used to decrypt it. To ensure only the CFO can read the email, the sender (executive) must encrypt the message using the recipient's (CFO's) public key. The CFO will then use their own private key to decrypt it.

  5. Question 5Advanced

    Essential Security Principles · Explain encryption methods and applications

    A database administrator is configuring a new human resources application. The application retrieves employee records from an encrypted hard drive, decrypts the records, and holds them in system RAM while generating payroll reports. In this specific scenario, what state is the data in while it resides unencrypted in the system RAM?

    Show answer & explanation

    Correct answer: C

    Data in use refers to active data that is currently being accessed, processed, or read by an application or system, typically residing in volatile memory (RAM) or CPU caches. Data at rest refers to inactive data stored physically (like on a hard drive), and data in transit refers to data moving across a network.

  6. Question 6Intermediate

    Essential Security Principles · Explain encryption methods and applications

    A security auditor is reviewing the cryptography standards used by a legacy application. The auditor mandates that the application must be updated because it relies on an obsolete, weak algorithm that is highly susceptible to brute-force attacks due to its short 56-bit key length. Which algorithm is the auditor demanding be replaced?

    Show answer & explanation

    Correct answer: C

    The Data Encryption Standard (DES) is a legacy symmetric encryption algorithm that uses a 56-bit key. It is considered weak and obsolete because modern computing power can easily crack it via brute-force attacks. Advanced Encryption Standard (AES) is the current strong standard, while RSA is a strong asymmetric algorithm, and SHA-256 is a strong hashing algorithm.

Ready for the real thing?

The full 100-160 simulator has every exam-style question, timed mode, and instant scoring.