CIW 1D0-671 Exam Overview:
| Certification Vendor: | CIW |
| Exam Name: | CIW Web Security Associate Exam |
| Exam Number: | 1D0-671 |
| Related Certifications: | CIW Web Security Specialist CIW Web Security Professional |
| Exam Format: | Multiple-choice |
| Passing Score: | 69.09% |
| Available Languages: | English |
| Certificate Validity Period: | 3 years |
| Exam Duration: | 90 minutes |
| Exam Price: | $175 USD |
| Real Exam Qty: | 55 |
| Recommended Training: | CIW Official Web Security Associate Courseware uCertify CIW 1D0-671 Training |
| Exam Registration: | CIW Official Site PSI Testing Center |
| Sample Questions: | CIW 1D0-671 Sample Questions |
| Exam Way: | Online proctored or in-person at authorized test centers |
| Pre Condition: | No formal prerequisites; recommended basic knowledge of web technologies and networking |
| Official Syllabus URL: | https://ciwcertified.com/courses/ciw-web-security-associate/ |
CIW 1D0-671 Exam Syllabus Topics:
| Section | Weight | Objectives |
|---|---|---|
| Topic 1: Network Security Fundamentals | 20% | - Security risk assessment and management - Security principles and policies - Threats, vulnerabilities, and attacks |
| Topic 2: Incident Response and Security Audits | 20% | - Incident detection and response procedures - Security auditing and compliance - Recovery and continuity planning |
| Topic 3: VPN and Wireless Security | 20% | - Virtual Private Networks (VPN) protocols - Wireless network vulnerabilities - Wireless encryption standards |
| Topic 4: Firewalls and Intrusion Detection | 20% | - Intrusion Detection Systems (IDS) and IPS - Firewall types and deployment - Access control mechanisms |
| Topic 5: Cryptography and Encryption | 20% | - Digital signatures and certificates - Public key infrastructure (PKI) - Encryption algorithms and standards |
CIW Web Security Associate Sample Questions:
1. You purchased a network scanner six months ago. In spite of regularly conducting scans using this software, you have noticed that attackers have been able to compromise your servers over the last month.
Which of the following is the most likely explanation for this problem?
A) The network scanner needs an update.
B) The network scanner is no substitute for scans conducted by an individual.
C) The network scanner needs to be replaced.
D) The network scanner has a trojan.
2. Which choice lists typical firewall functions?
A) Creating a VLAN and configuring the intrusion-detection system
B) Implementing the security policy and scanning the internal network
C) Logging traffic and creating a choke point
D) Issuing alerts and limiting host access
3. A security breach has occurred in which a third party was able to obtain and misuse legitimate authentication information. After investigation, you determined that the specific cause for the breach was that end users have been placing their passwords underneath their keyboards.
Which step will best help you resolve this problem?
A) Inform end users that their passwords will be changing on a regular basis and require more complex passwords.
B) Change all passwords on the company servers immediately and inform end users that their passwords will be changing on a regular basis.
C) Set passwords to expire at specific intervals and establish mandatory continual training sessions.
D) Discipline specific end users as object lessons to the rest of the staff and reset passwords on all systems immediately.
4. A distributed denial-of-service (DDOS) attack has occurred where both ICMP and TCP packets have crashed the company's Web server.
Which of the following techniques will best help reduce the severity of this attack?
A) Changing your ISP
B) Installing Apache Server rather than Microsoft IIS
C) Placing the database and the Web server on separate systems
D) Filtering traffic at the firewall
5. How do activity logs help to implement and maintain a security plan?
A) Activity logs provide advice on firewall installation, because they enable network baseline creation.
B) Activity logs allow you to determine if and how an unauthorized activity occurred.
C) Activity logs remind users to log on with strong passwords, because the logs can be analyzed to see if users are complying with policy.
D) Activity logs dissuade would-be hackers from breaching your security.
Solutions:
| Question # 1 Answer: A | Question # 2 Answer: C | Question # 3 Answer: C | Question # 4 Answer: D | Question # 5 Answer: B |
We're so confident of our products that we provide no hassle product exchange.


By Oliver

