wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

ECIH Preparation

Total questions: 12

Worksheet time: 12mins

Name
Class
Date
1.

Which of the following terms may be defined as “a measure of possible inability to achieve a goal,

objective, or target within a defined security, cost plan and technical limitations that adversely

affects the organization’s operation and revenues?

a)

Incident Respons

b)

Threat

c)

Vulnerability

d)

Risk

2.

A distributed Denial of Service (DDoS) attack is a more common type of DoS Attack, where a single

system is targeted by a large number of infected machines over the Internet. In a DDoS attack,

attackers first infect multiple systems which are known as:

a)

Trojan

b)

Zombies

c)

Spyware

d)

Worms

3.

The goal of incident response is to handle the incident in a way that minimizes damage and reduces

recovery time and cost. Which of the following does NOT constitute a goal of incident response?

a)

Dealing properly with legal issues that may arise during incidents

b)

Helping personal to recover quickly and efficiently from security incidents, minimizing loss or theft

and disruption of services

c)

Using information gathered during incident handling to prepare for handling future incidents in a

better way and to provide stronger protection for systems and data

d)

Dealing with human resources department and various employee conflict behaviors

4.

An organization faced an information security incident where a disgruntled employee passed

sensitive access control information to a competitor. The organization’s incident response manager,

upon investigation, found that the incident must be handled within a few hours on the same day to

maintain business continuity and market competitiveness. How would you categorize such

information security incident?

a)

Middle level incident

b)

Low level incident

c)

High level incident

d)

Ultra-High level incident

5.

Business continuity is defined as the ability of an organization to continue to function even after a

disastrous event, accomplished through the deployment of redundant hardware and software, the

use of fault tolerant systems, as well as a solid backup and recovery strategy. Identify the plan which

is mandatory part of a business continuity plan?

a)

Sales and Marketing plan

b)

Forensics Procedure Plan

c)

Business Recovery Plan

d)

New business strategy plan

6.

Which of the following is an appropriate flow of the incident recovery steps?

a)

System Operation-System Restoration-System Validation-System Monitoring

b)

System Restoration-System Monitoring-System Validation-System Operations

c)

System Restoration-System Validation-System Operations-System Monitoring

d)

System Validation-System Operation-System Restoration-System Monitoring

7.

A computer Risk Policy is a set of ideas to be implemented to overcome the risk associated with

computer security incidents. Identify the procedure that is NOT part of the computer risk policy?

a)

Procedure for the ongoing training of employees authorized to access the system

b)

Procedure to identify security funds to hedge risk

c)

Procedure to monitor the efficiency of security controls

d)

Provisions for continuing support if there is an interruption in the system or if the system crashes

8.

Identify the network security incident where intended authorized users are prevented from using

system, network, or applications by flooding the network with high volume of traffic that consumes

all existing network resources.

a)

URL Manipulation

b)

XSS Attack

c)

Denial of Service Attack

d)

SQL Injection

9.

Incident handling and response steps help you to detect, identify, respond and manage an incident.

Which of the following steps focus on limiting the scope and extent of an incident?

a)

Eradication

b)

Identification

c)

Data collection

d)

Containment

10.

Policies are designed to protect the organizational resources on the network by establishingthe set rules and procedures. Which of the following policies authorizes a group of users to perform aset of actions on a set of resources

a)

Documentation policy

b)

Access control policy

c)

Logging policy

d)

Audit trail policy

11.

The data on the affected system must be backed up so that it can be retrieved if it is damagedduring incident response. The system backup can also be used for further investigations of theincident. Identify the stage of the incident response and handling process in which complete backupof the infected system is carried out

a)

Eradication

b)

Incident recording

c)

Incident investigation

d)

Containment

12.

The role that applies appropriate technology and tries to eradicate and recover from theincident is known as

a)

Incident coordinator

b)

Incident Handler

c)

Incident Analyst

d)

Incident Manager