
Sec+ | Important Notes
Authored by Prem Jadhwani
Computers
Professional Development
Used 2+ times

AI Actions
Add similar questions
Adjust reading levels
Convert to real-world scenario
Translate activity
More...
Content View
Student View
12 questions
Show all answers
1.
MATCH QUESTION
3 mins • 5 pts
Match the Security Control to its purpose
SOAR
Software that Aggregates log data and acts as workforce multiplier
Network Access Control (NAC)
Software that detects and STOPS an attack in real-time
Intrusion Prevention System (IPS)
Security technologies that work together to screen devices for health conditions before accessing a network
SIEM
Stops sensitive data exfiltration
Data Loss Prevention (DLP)
Software that automates a response when set up
2.
MATCH QUESTION
3 mins • 5 pts
Match the tool that is used for the provided purpose:
Tabletop Exercise (TTX)
Best way to control company data on a laptop or cellular phone.
Wireshark (PCAP)
Best tool to use to capture data packets going between computers.
Data Tokenization
Best way to test your Incident Response Plan (IRP)
Mobile Device Manager (MDM)
Best way to store credit card data in a database is to replace it with a placeholder.
Firewall Logs
Best way to see internal to external conversations between computers
3.
MATCH QUESTION
3 mins • 5 pts
Match the following:
Business Impact Analysis (BIA)
Best way to transfer risk involved with a security incident.
Compliance Attestation
Step by step guide to responding to a security incident
Playbook
A policy that outlines how long we must store and maintain data
Data Retention
A report provided by a vendor stating that we meet certain regulatory requirements
Cyber Insurance
Report that shows how things are affected when a security incident happens.
4.
MATCH QUESTION
3 mins • 5 pts
Match the regulatory laws to their definition.
ISO 27001
Law that governs how an organization handles credit/debit card data.
ISO 27002
Supporting document that provides security controls to orgs that are required to have ISMS.
ISO 27701
Requires companies handle PII in a manner that keeps it private.
PCI DSS
Privacy law that applies to European Citizens regarding their privacy rights.
General Data Privacy Regulation (GDPR)
Requires an organization to set up an ISMS if they deal with sensitive info.
5.
MATCH QUESTION
3 mins • 5 pts
Match the following terms to their appropriate definitions.
Single Loss Expectancy (SLE)
This is the maximum amount of data that can be lost.
Annual Loss Expectancy (ALE)
The number of times something happens in a given year.
Recovery Point Objective (RPO)
This is the maximum amount of time equipment can be down.
Annual Rate of Occurrence (ARO)
The amount of money we can expect to lose if something occurs.
Recovery Time Objective (RTO)
The amount of money we can expect to lose in a given year due to events occurring.
6.
MATCH QUESTION
3 mins • 5 pts
Match the appropriate solution with the problem.
File Integrity Monitoring (FIM)
Mandy needs to create a way to rollback to a previous point if something goes wrong.
Gap Analysis
Terry wants to enforce security policies on the cloud.
Data Loss Prevention (DLP)
Dameon needs to determine everything that needs to be done to get into compliance.
Backout Plan
Sierra wants to prevent employees from sending sensitive info in email.
Cloud Access Security Broker (CASB)
Jon needs a tool that will help him identify if anything in a file system has changed.
7.
MATCH QUESTION
3 mins • 5 pts
Match the following documents to their purpose
SLA
A formal document that an employee signs to ensure they understand what they are allowed to use an asset for.
BIA
A plan that we put into place to maintain continuity in the event of a disaster or attack.
SOW
A complete analysis on how a situation or event would impact the organization.
BCP
Legal agreement between two parties that outlines service requirements. Often denotes 99.9% uptime.
AUP
A plan that outlines scope of a job, the completion timeline and the cost.
Access all questions and much more by creating a free account
Create resources
Host any resource
Get auto-graded reports

Continue with Google

Continue with Email

Continue with Microsoft
or continue with
%20(1).png)
Apple
Others
Already have an account?