1D0-571 Sample Questions

1D0-571 Sample Questions & Answers

Free v5 Security Essentials practice questions with worked answers and explanations. See how the ExamJungle simulator prepares you — then jump into the full test.

Launch the full 1D0-571 simulator →

Showing 6 of 12 free samples.

  1. Question 1

    A disgruntled employee has discovered that the company Web server is not protected against a particular buffer overflow vulnerability. The disgruntled employee has created an application to take advantage of this vulnerability and secretly obtain sensitive data from the Web server's hard disk. This application sends a set of packets to the Web server that causes it to present an unauthenticated terminal with root privileges. What is the name for this particular type of attack?

    Show answer & explanation

    Correct answer: D

    This represents a zero-day attack because the employee discovered and exploited a previously unknown buffer overflow vulnerability that the security team and vendors were unaware of, creating a custom application to exploit this unpatched weakness. Zero-day attacks leverage vulnerabilities that have not been publicly disclosed or patched, giving defenders zero days to prepare. Man-in-the-middle attacks intercept communications between parties, trojans are malicious programs disguised as legitimate software, and denial of service attacks aim to make resources unavailable - none of these accurately describe exploiting an undisclosed buffer overflow vulnerability with custom exploit code.

  2. Question 2

    Which of the following details should be included in documentation of an attack?

    Show answer & explanation

    Correct answer: C

    Attack documentation must include the time and date of the attack and names of employees contacted during response to establish a clear timeline and chain of custody for incident response procedures. This factual information is essential for forensic analysis, legal proceedings, and post-incident reviews. Security policy overviews belong in separate policy documents, cost estimates require extensive financial analysis that may not be immediately available, and while network resources and recommendations are valuable, they are typically documented in separate technical and lessons-learned reports rather than the primary incident documentation which focuses on factual chronology and response coordination.

  3. Question 3

    At the beginning of an IPsec session, which activity occurs during the Internet Key Exchange (IKE)?

    Show answer & explanation

    Correct answer: B

    During the Internet Key Exchange (IKE) phase of IPsec session establishment, negotiating the authentication method is a fundamental activity that determines how the communicating parties will verify each other's identities before establishing the secure tunnel. IKE Phase 1 specifically handles authentication method selection (pre-shared keys, digital certificates, or other methods) along with encryption and hashing algorithms. Determining security associations comes after authentication is established, network identification numbers are not part of IKE negotiation, and IP version selection occurs at the network layer before IPsec processing begins.

  4. Question 4

    Which of the following is most likely to pose a security threat to a Web server?

    Show answer & explanation

    Correct answer: A

    CGI scripts pose the most significant security threat to Web servers because they execute code on the server with elevated privileges and often lack proper input validation, making them vulnerable to injection attacks, buffer overflows, and arbitrary code execution. CGI scripts run in the server's security context and can access system resources, making any vulnerability in CGI code a direct pathway to server compromise. Database connections are typically secured through connection pooling and authentication, Flash/Silverlight files are client-side technologies with limited server access, and LDAP servers are external authentication services that don't directly threaten the Web server itself.

  5. Question 5

    You have been assigned to configure a DMZ that uses multiple firewall components. Specifically, you must configure a router that will authoritatively monitor and, if necessary, block traffic. This device will be the last one that inspects traffic before it passes to the internal network. Which term best describes this device?

    Show answer & explanation

    Correct answer: D

    A choke router serves as the authoritative final inspection point before traffic reaches the internal network in a multi-layered DMZ architecture, providing the last line of defense with the most restrictive access control policies. The choke router enforces the most stringent security rules and acts as the ultimate gateway controller. Screening routers provide initial filtering but are not typically the final authoritative control point, bastion hosts are hardened servers that provide specific services rather than traffic inspection, and proxy servers handle application-layer communication but do not provide the authoritative network-level traffic control required for this DMZ design.

  6. Question 6

    You have implemented a version of the Kerberos protocol for your network. What service does Kerberos primarily offer?

    Show answer & explanation

    Correct answer: A

    Kerberos primarily provides authentication services through its ticket-based system that securely verifies user and service identities using a trusted third-party Key Distribution Center (KDC). The protocol eliminates the need to transmit passwords over the network by using encrypted tickets and session keys for mutual authentication between clients and servers. While Kerberos uses encryption internally for ticket protection, encryption is not its primary service; non-repudiation requires digital signatures which Kerberos does not provide; and data integrity is handled by other protocols, making authentication the core function of the Kerberos security framework.

Ready for the real thing?

The full 1D0-571 simulator has every exam-style question, timed mode, and instant scoring.