Showing posts with label performance based questions. Show all posts
Showing posts with label performance based questions. Show all posts

Saturday, June 22, 2013

Security+ Match Device Controls

Security+ Match Device Controls

The Security+ exam expects you to understand controls and you should be able to match device controls with specific devices. For example, can you match device controls used with mobile devices? Can you match device controls used on servers?

Performance Based Questions

Topics such as security controls for devices are ideally suited for the new performance based questions on the CompTIA Security+ exam. Instead of answering a multiple choice question, you might need to drag and drop different controls to the devices that they protect. If you're unfamiliar with the new performance based questions, you might like to check out these blogs too:

Match Device Controls Practice Question

The following list of controls includes some that are used with mobile devices exclusively. It also includes some controls that are used with servers but not mobile devices. Do you know which ones are which?

Security+ Match Device Controls

Click the image for a larger view.
Some of these are used only on mobile devices, some are only used on servers, and some can be used on both.
Which security controls are for mobile devices? mobiledevicesicon
Which security controls are for servers? serversicon
Pass the Security+ exam the first time you take it:
CompTIA Security+: Get Certified Get Ahead: SY0-301 Study Guide

Match Device Controls for Mobile Devices

Here are the common security controls used for mobile devices:
  • Screen lock. Uses a passcode or password to lock the device. This prevents a thief from using a stolen device.
  • Strong password. Any time a password is used to protect a mobile device (or any device or system), it should be strong. This means they are at least eight characters and include multiple character types, such as upper case, lower case, numbers, and symbols. Two other blogs that cover password topics for the Security+ exam are Understanding Password History, and Three Factors of Authentication and Multifactor Authentication.
  • Data encryption. Encryption protects the confidentiality of data and smartphone security includes device encryption to protect the data against loss of confidentiality. It's possible to selectively encrypt some data on a system, an entire drive, or an entire device.
  • Remote wipe/sanitation. Remote wipe capabilities are useful if the phone is lost. The owner can send a remote wipe signal to the phone to delete all the data on the phone. This also deletes any cached data, such as cached online banking passwords, and provides a complete sanitization of the device, ensuring that all valuable data is removed.
  • Voice encryption. It’s possible to use voice encryption with some phones to help prevent the interception of conversations
  • Global positioning system (GPS) tracking. A GPS pinpoints the location of the phone. Many phones include GPS applications that you can run on another computer. If you lose your phone, GPS can help you find it. Who knows? You may find that it just fell through the cushions in your couch. This is useful to know before you send a remote wipe signal.
  • Cable locks. The number of laptops stolen during lunches at conferences is astronomical. Many people don’t seem to know how common thefts are and often leave their laptops unprotected. Cable locks can secure a mobile computer. They often look about the same as a cable lock used to secure bicycles.
  • Locked cabinet or safe. Small devices can be secured within a locked cabinet or safe. When they aren’t in use, a locked cabinet helps prevent their theft.
If you were to match the controls to the Mobile devices, it might look like this. The idea is that you drag and drop individual controls from the area on the right to the area under Mobile Devices.
Security+ Match Device Controls to Mobile Devices
Click the image for a larger view.

Match Device Controls for Servers

If you were to match the controls to servers, it might look like this:
Security+ Match Device Controls to Servers
Click the image for a larger view.
Some of these items are the same as the mobile devices, and some of the items are unique for servers:
  • Strong password. Any time a password is used to protect a mobile device (or any device or system), it should be strong. This means they are at least eight characters and include multiple character types, such as upper case, lower case, numbers, and symbols. Two other blogs that cover password topics for the Security+ exam are Understanding Password History, and Three Factors of Authentication and Multifactor Authentication.
  • Least privilege. Least privilege is a technical control. It specifies that individuals or processes are granted only those rights and permissions needed to perform their assigned tasks or functions. Rights and permissions are commonly assigned on servers, but rarely on mobile devices such as tablets and smartphones.
  • Data encryption. Encryption protects the confidentiality of data on servers just as it can protect the confidentiality of data on mobile devices.  It's possible to selectively encrypt individual files or entire disk volumes.
  • Mantrap, cipher lock, and proximity lock. This are examples of physical security and they can be used to restrict access to a server room.
  • Firewall. Software-based firewalls are commonly used on servers but are extremely rare on mobile devices.
  • TPM and HSM. Trusted Platform Modules (TPMs) and hardware security modules (HSMs) are hardware encryption devices. You can read more about them in the TPM and HSM Hardware Encryption Devices blog.

Other Security+ Resources

Security+ Match Device Controls Summary

You can expect to see some performance based questions on the Security+ exam and you might even see one requiring you to match device controls to specific devices. While these are different from a typical multiple choice question, you can still answer them correctly as long as you know the content. The information from this blog was derived from the CompTIA Security+: Get Certified Get Ahead: SY0-301 Study Guide, and it covers all of the security controls in the Security+ exam.

Monday, May 6, 2013

Performance Based Question Winner

Performance Based Question Winner

Congratulations to Alan Brown, the Performance Based Question winner on the Get Certified Get Ahead Facebook page. He correctly identified the link page to the blog on Security+ performance based questions. 

I was originally going to give away a copy of the new A+ Rapid Review book but Alan recently completed his Security+ exam. I gave him some options and he chose the SSCP Systems Security Certified Practitioner All-in-One Exam Guide instead. My wife got the book into the mail today.

Performance Based Questions

CompTIA only recently starting adding these to the Security+ exam and I'm occasionally hearing from people that are surprised by the performance based questions. I have done a few things to try to raise the awareness of these including:
This contest on the Get Certified Get Ahead Facebook page was another attempt to raise the awareness of these questions.

Ideally, I could update the CompTIA Security+: Get Certified Get Ahead: SY0-301 Study Guide with information on these but with the new SY0-401 Security+ exam on the horizon it just isn't feasible to update it. Thankfully, the study guide covers all of the content that are testable by these types of questions. It just doesn't talk about anything other than multiple choice questions.

If you know someone that will be taking the Security+exam, make sure that they are a performance based question winner too.  Tell them about the blogs that cover them so that they won't be surprised.

Tuesday, April 30, 2013

Security+ WAP Performance Based Questions

Security+ WAP Performance Based Questions

If you’re planning on taking the Security+ exam you can expect to see some Security+ WAP performance based questions. These questions expect you to know how to configure a wireless access point (WAP). Even if you've done it once or twice, it might not be fresh in your mind so it's good to review the topics. 

Networks commonly use wireless access points (WAPs) and configuring security with them is an important skill to have. CompTIA stresses this on both the Network+ and Security+ exams. You should be able to configure basics such as:
  • Change the SSID
  • Enable/disable SSID broadcast
  • Enable MAC address filtering
  • Configure security such as WPA and WPA2
  • Configure WPA/WPA2 Enterprise
Ideally, you should get your hands on a WAP or a wireless router used in many homes and small offices home offices (SOHOs). They are easily accessible and aren't expensive and the experience configuring it is valuable for on the job and the exam. The following sections show how to configure a Cisco M20 wireless router. All devices aren't exactly the same, but you'll find similar settings if you click around.
Pass the Security+ exam the first time you take it: CompTIA Security+: Get Certified Get Ahead: SY0-301 Study Guide

Accessing the Administration Page

Wireless access points have web pages you can use to configure settings. You can access the administration pages by entering the IP address of the access point into the web browser. The IP address of most access points is either 192.168.1.1 or 192.168.0.1.

After entering the IP address, you're prompted to enter the name and password for the administrator account. These also have defaults such as "admin" for the administrator account and "admin" for the password but it is highly recommended to change the defaults.

Change the SSID

The service set identifier (SSID) is the name of the network.  It is a case sensitive string of up 32 characters. Devices come with a default SSID and it's recommended to change the SSID from the default as a best practice.

The following figure shows the basic setting for SSID. On this WAP, you have to select the Wireless main menu and the Basic Wireless Settings submenu.  You then enter the desired network name for in the Network Name (SSID) text box. In the figure, I used the SSID of MyHomeWAP but any name with 32 characters can be used. Configure SSID for Security+ WAP Performance Based Questions

Enable/Disable SSID Broadcast

You can hide a wireless network from casual users by disabling SSID broadcast and a performance based question might require you to select one of these settings. The following figure shows how this is done on a sample access point. Disable SSID for Security+ WAP Performance Based Questions It's important to realize that even if you disable SSID broadcast, attackers can still discover the SSID with a wireless sniffer. In other words, disabling SSID broadcast doesn't provide any real security. You can read more about in the  Disable SSID Broadcast or Not? blog.

Enable MAC Address Filtering

Another configuration you might need to implement for Security+ WAP performance based questions is media access control (MAC) address filtering. The MAC address is assigned to the network interface card (NIC) when it is manufactured and you can use it to identify specific devices. When used within a MAC address filter, you can restrict access to the wireless network to specific devices based on their MAC address.

As an example, the following figure shows a MAC address filter configured on a wireless access point.  You can see that it is enabled and configured to "Permit PCs listed below to access the wireless network." The wireless client list includes five MAC addresses. Devices with these MAC addresses will be allowed access to the network, but other devices will be blocked.

MAC Filter for Security+ WAP Performance Based Questions

This setting isn't restricted to only PCs. Any wireless device has a MAC address including tablet devices and smartphones.

You can also configure a MAC address filter to block specific devices. For example, if your neighbor is using your access point to access the Internet, you can block his system using his MAC address. You would select the first setting "Prevent PCs listed below from accessing the wireless network" and enter the MAC address of his system.

Configure Security Such as WPA and WPA2

You also need to know how to configure basic security setting such as Wi-Fi Protected Access (WPA) or Wi-Fi Protected Access version 2 (WPA2). You can typically select the appropriate setting from a drop down box and then enter the appropriate passphrase. The settings entered on the access point must be used on all devices that connect to the access point.

 The following figure shows these settings.
  WPA 2 for Security+ WAP Performance Based Questions

Configure WPA/WPA2 Enterprise

Both WPA and WPA2 operate in either Personal or Enterprise modes. Most home and small business networks use Personal mode using a passphrase or password.

Larger enterprises add additional security to WAPs with WPA Enterprise or WPA2 Enterprise.  Enterprise mode provides additional security by adding an authentication server and requiring each user to authenticate through this server. Authentication requires all users to prove their identities and a common way authentication is accomplished is with a username and password. A user claims an identity with a username and proves the identity with a password.

Enterprise mode requires an 802.1x server typically configured as a Remote Authentication Dial-In User Service (RADIUS) server, which is configured separately from the access point. The RADIUS server has access to the user’s authentication credentials and can verify when a user has entered authentication information correctly.

The following figure shows the configuration for an access point using WPA2 Enterprise. After selecting WPA2 Enterprise from the drop down box, the  selections change. You then need to enter the IP address of the RADIUS server and the shared secret configured on the RADIUS server. The default port for RADIUS is 1812 and you only need to change this if the RADIUS server is using a non-default port.RADIUS for Security+ WAP Performance Based Questions  

Other Security+ Resources

Security+ WAP Performance Based Questions Summary

You can expect to see some Security+ WAP performance based questions on the Security+ exam. These questions expect you to know how to configure a wireless access point (WAP) including the SSID, MAC address filtering, and security settings such as WPA2 Personal or WPA2 Enterprise.

Tuesday, January 1, 2013

Security+ and Performance Based Questions


If you’re planning on taking the Security+ exam you can expect to see performance based questions.  They have already been added to A+ and Network+ exams. You can read more about performance based questions here, but in short a performance based question requires you to perform a task rather than simply requiring you to answer a multiple choice question.
I've field several questions about these related to Security+ so here are some answers to some common questions.

When Do They Appear in Security+?

CompTIA has stated that these types of questions will begin to appear in the Security+ exam in the first quarter of 2013. This could be any time between January 1st and March 31st, 2013.
If you've taken the exam and you saw them, I'd love to hear from you so that I can let readers know they have started to appear. You can leave a comment on this page or send me a note through my contact page.

Pass the Security+ exam the first time you take it
CompTIA Security+: Get Certified Get Ahead: SY0-301 Study Guide

How Many Questions Are on The Security+ Exam?

When you have only multiple choice questions, the Security+ exam includes 100 questions.
When performance based questions are added, you'll probably have 90 questions with 87 questions being basic multiple choice questions and three being performance based questions. Here are a couple of pages that give sample multiple choice questions:

What Performance Based Questions Should I Expect?

At this writing, the only people that know the answer to this question are people at CompTIA. However, based on how CompTIA has done this with other exams, we can predict what you might see.

Command Prompt

You might be asked to perform a task from the command prompt. You'll have access to a simulated command prompt and be required to perform a specific task.
In the CompTIA Security+: Get Certified Get Ahead: SY0-301 Study Guide, I gave an example (pages 411 and 412) with a couple of graphics that could easily be used in this exam.
The question could go like this: "Determine if the file shown in the graphic is valid."  The file in the graphic includes a valid MD5 hash.
You are then put into a command prompt with nothing more than a blinking cursor. What do you do?
The first step is to see what is in the current directory. You could do so with the dir command. More than likely, you'll see the file that was displayed in the graphic, along with programs that can be used to create a hash such as md5sum and sha1sum.
Next, you'd calculate the hash on the file using the correct program. This requires you to know that the hash shown in the graphic is an MD5 hash. You'd then run the md5sum program against the file to calculate the hash. If the hash shown in the graphic was a SHA1 hash, you'd need to run sha1sum instead.
That's it. In retrospect, you only need to enter two commands: dir and md5sum filename. However, you need to have some underlying knowledge to do so successfully.

Click on a Diagram

You might be asked to click on a diagram to select something. As an example, you might be tasked with giving a user appropriate permissions to perform job tasks. The diagram then shows a list of groups with specific permissions assigned. You then need to pick which group (or groups) to put the user into.
The key here would be to remember the principle of least privilege and ensure that the user is granted enough rights and permissions to perform the job and no more.

Learn by listening 
Key points from the CompTIA Security+: Get Certified Get Ahead: SY0-301 Study Guide
Over one hour and 20 minutes of audio from the "Remember This" blocks
Over three hours and 20 minutes of questions and answers on audio

What is the Biggest Challenge?

Many of the questions are straight forward and it's easy to identify what is desired. However, the biggest challenge many people report with these types of questions is figuring out what some of the questions are actually asking. For example, the sample in the Command Prompt section earlier only states "Determine if the file shown in the graphic is valid" and shows a graphic. It doesn't tell you to run the dir and the md5sum commands. However, this is the only way you can determine if the file is valid.
With that in mind, you often need to give these types of questions a little more thought and pay attention to the clues given in the question.

How Much Are These Questions Worth?

More than likely these questions are worth more than a typical multiple choice question. While CompTIA doesn't release the actual value of any single question, it's entirely possible that each question is worth a little more than 4 percent of the total.
If the original exam has 100 multiple choice questions and the new exam has 87 multiple choice questions with three performance based questions, these three performance based questions could be worth about 13 percent of the total. If you divide 13 percent by three, it's a little over 4.

Will Books Be Updated to Include Performance Based Questions?

It's unlikely that any books will be updated specifically for the Performance Based Questions. It takes an extensive amount of time and effort to rewrite, edit, layout, proof, and reprint books.
Certification books are typically only updated when the certification changes significantly. For example, the differences in the objectives between SY0-201 and SY0-301 Security+ objectives were significant. Publishers that had SY0-201 books in print published new books on the SY0-301 exam.
Further, most books include the content needed to successfully pass these performance based questions. The objectives aren't changing. The only that is changing is the way that the objectives are being tested. If you understand the content, you will be able to answer the questions.
Along these lines, I've been asked a few times if the CompTIA Security+: Get Certified Get Ahead: SY0-301 Study Guide will be updated. This isn't likely. I expect that CompTIA will be releasing new objectives for the SY0-401 exam sometime this year.  When they do, I'll be updating the SY0-301 Study Guide. You'll probably still be able to take the SY0-301 exam through at least part of 2014.
Realistic practice test questions for the Security+ SY0-301 exam
Available through LearnZapp on your mobile phone

Summary

If you’re planning on taking the Security+ exam any time from today on, you can expect to see performance based questions. These questions are different than multiple choice questions but they are not impossible to answer. If you understand the content, you will likely be able to answer these questions without too much difficulty.