Table Of Contents  CertiGuide to Security+
 9  Chapter 7:  Practice Exam Answers

Answers to Questions 36-40

36. TACACS+ is an update to TACACS and is backwards compatible. True/False

A. True

B. False

Explanation: Despite the similarity of the Acronym's TACACS+ is NOT compatible with TACACS (Terminal Access Controller Access Control System)



37. The SA (Security Association) for IPSec is managed by




D. SecurID


Explanation: The Internet Security Association and Key Management Protocol (ISAKMP) define a framework for security association management and cryptographic key establishment for the Internet.

AH and ESP are types of IPSec communications, but they do not manage SA's. AES is an encryption algorithm.

& Section 2.1.7: IPSec


38. WEP has security issues because:

A. It was limited by export regulations

B. It uses RC4, a stream cipher. WEP needs an Initialization Vector for RC 4 to overcome the "lossy" nature of radio. The short key length of IV forces reuse.

C. 802.11 was not meant to be secure

D. All choices are correct

E. No choice is correct

Explanation: WEP uses RC4 (a shared-secret stream cipher). An IV is needed to overcome signal loss. The short key length forces the IV key to re-use, a no-no in basic security concepts.

& Section 2.1.8: (Remote Access) Vulnerabilities


39. SPAM carries what sort of costs (choose all that apply):

A. Loss of productivity

B. Loss of bandwidth

C. Revenue drain supporting un-wanted traffic

D. Credit card fraud losses

Explanation: Because it is cheap to purchase email addresses, there is a great deal of spam. The sheer volume of spam costs productivity time deleting it, consumes bandwidth, requiring additional bandwidth to be purchased.

Depending on the content of spam, a user subjected to it could suffer a credit card fraud loss, but that is not the main issue with Spam.

& Section Spam


40. Email hoaxes:

A. Spread fear

B. Cost productivity

C. Improve a firm's image

D. Have no impact

Explanation: This one is obvious. Refer to the web links for sites to confirm hoaxes.

& Section Hoaxes

