CIW 1D0-671 Exam Overview:
| Certification Vendor: | CIW |
|---|---|
| Exam Name: | CIW Web Security Associate Exam |
| Exam Number: | 1D0-671 |
| Exam Format: | Multiple-choice |
| Passing Score: | 69.09% |
| Related Certifications: | CIW Web Security Professional CIW Web Security Specialist |
| Certificate Validity Period: | 3 years |
| Real Exam Qty: | 55 |
| Exam Price: | $175 USD |
| Available Languages: | English |
| Exam Duration: | 90 minutes |
| Recommended Training: | uCertify CIW 1D0-671 Training CIW Official Web Security Associate Courseware |
| Exam Registration: | CIW Official Site PSI Testing Center |
| Sample Questions: | CIW 1D0-671 Sample Questions |
| Exam Way: | Online proctored or in-person at authorized test centers |
| Pre Condition: | No formal prerequisites; recommended basic knowledge of web technologies and networking |
| Official Syllabus URL: | https://ciwcertified.com/courses/ciw-web-security-associate/ |
CIW 1D0-671 Exam Syllabus Topics:
| Section | Weight | Objectives |
|---|---|---|
| VPN and Wireless Security | 20% | - Wireless network vulnerabilities - Virtual Private Networks (VPN) protocols - Wireless encryption standards |
| Firewalls and Intrusion Detection | 20% | - Firewall types and deployment - Access control mechanisms - Intrusion Detection Systems (IDS) and IPS |
| Incident Response and Security Audits | 20% | - Recovery and continuity planning - Security auditing and compliance - Incident detection and response procedures |
| Cryptography and Encryption | 20% | - Encryption algorithms and standards - Digital signatures and certificates - Public key infrastructure (PKI) |
| Network Security Fundamentals | 20% | - Security risk assessment and management - Threats, vulnerabilities, and attacks - Security principles and policies |
CIW Web Security Associate Sample Questions:
Question 1
David has enabled auditing on the C, D and E drives of his Web server. This server runs Windows Server 2003 and uses all SCSI components. After David has finished his change, the help desk receives calls from customers complaining that transactions are being completed at an unusually slow rate.
What has David failed to consider?
A. The performance effects that auditing can have on a system
B. Network latency and system uptime requirements that appear to be system performance problems
C. The restriction that auditing cannot be established on a RAID array in Windows Server 2003
D. The limitation that auditing can be performed on only two disks of a RAID array
Question 2
Which protocol uses cleartext communication by default?
A. HTTP
B. IPSEC
C. POP3
D. SSL
Question 3
What is TEMPEST?
A. A standard developed by the U.S. government to help control electromagnetic transmissions that interfere with network connectivity
B. A physical security technique that applies humidity controls and proper ventilation to networking equipment
C. A physical access control technique in which knowledgeable, skilled guards are placed at all locations containing false ceilings and exposed jacks
D. A biometric technique that places an individual's biometric information onto smart cards
Question 4
Which choice lists typical firewall functions?
A. Logging traffic and creating a choke point
B. Implementing the security policy and scanning the internal network
C. Creating a VLAN and configuring the intrusion-detection system
D. Issuing alerts and limiting host access
Question 5
All servers assume that a valid IP address belongs to the computer that sent it. Because TCP/IP contains no built-in authentication, a hacker can assume the identity of another device.
If your security depends entirely upon the TCP/IP identity, which type of attack can allow a hacker to gain access to your system?
A. A social engineering attack
B. A spoofing attack
C. A denial-of-service attack
D. A brute-force attack
Solutions:
| Question 1 Answer: A | Question 2 Answer: A | Question 3 Answer: A | Question 4 Answer: A | Question 5 Answer: B |

We're so confident of our products that we provide no hassle product exchange.


By Phil


