wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

CySa+ PT5: 2 of 3

Total questions: 20

Worksheet time: 10mins

Name
Class
Date
1.

Your organization’s primary operating system vendor just released a critical patch for your servers. Your system administrators have recently deployed this patch and verified the installation was successful. The critical patch designed to remediate a vulnerability that can allow a malicious actor to remotely execute code on the server from over the Internet. However, you just ran a vulnerability assessment scan of the network and found that all of the servers are still being reported as having the vulnerability. Why is the scan report still showing a vulnerability even though the patch was installed by the system administrators?

a)

Your vulnerability assessment scan is returning false positives

b)

The critical patch did not remediate the vulnerability

c)

You did not wait enough time after applying the patch before running the vulnerability assessment scan

d)

You scanned the wrong IP range during your vulnerability assessment

2.

TRUE or FALSE: PCI DSS requires the use of an outside consultant to perform internal vulnerability scans.

a)

TRUE

b)

FALSE

3.

Which type of attacker is considered to be sophisticated, highly organized, and typically sponsored by a nation-state?

a)

​Script kiddies

b)

​Hacktivists

c)

​Advanced Persistent Threat

d)

​Ethical hacker

4.

TRUE or FALSE: When evaluating the functional impact of a security incident, an analyst should assign a rating of high in cases where the organization is not able to provide some critical services to any users.

a)

TRUE

b)

FALSE

5.

Caleb is designing a playbook for zero-day threats as part of his incident response program. Which of the following items should not be in his plan?

a)

​Segmentation

b)

Patching

c)

Using threat intelligence

d)

Whitelisting

6.

What stage of an event is preservation of evidence typically handled?

a)

Preparation

b)

Detection and analysis

c)

Containment, eradication, and recovery

d)

​Post-incident activity

7.

During the preparation phase of an organization's incident response process, Aaron gathered a laptop with useful software. The software included a sniffer, forensics tools, thumb drives and external hard drives, networking equipment, and a variety of cables. What type of equipment is this typically called?

a)

​A grab bag

b)

​A jump kit

c)

​A crash cart

d)

​A first responder kit

8.

Paula is working on a report that describes the common attack models used by APT actors. Which of the following is a typical characteristic of an APT attack?

a)

They involve sophisticated DDoS attacks

b)

They quietly gather information from compromised systems

c)

​They rely on worms to spread

d)

​They use encryption to hold data hostage

9.

Degaussing is an example of what type of media sanitization?

a)

Clearing

b)

​Purging

c)

Destruction

d)

​It isn’t a form of media sanitization

10.

A cyber security technician has been running an intensive vulnerability scan to detect which ports might be open to exploitation. But, during the scan, one of the network services became disabled and this impacted the production server. What information source could be used to evaluate which network service was interrupted?

a)

​Syslog

b)

​Network mapping

c)

​Firewall logs

d)

​NIDS

11.

What is NOT part of the security incident validation effort?

a)

​Scanning

b)

Sanitization

c)

​Patching

d)

​Permissions

12.

Richard noticed that the forensic image he attempted to create has failed. What would be the most likely reason for the failure?

a)

Data was modified

b)

​The source disk is encrypted

c)

​The destination disk has bad sectors

d)

The data cannot be copied in RAW format

13.

TRUE or FALSE: CSIRTs should sometimes include human resource team members.

a)

TRUE

b)

FALSE

14.

NIST describes four major phases in the incident response cycle. Which is not one of the four?

a)

​Containment, eradication, and recovery

b)

​Notification and communication

c)

​Detection and analysis

d)

Preparation

15.

Jenny is trying to detect unexpected output from the application she manages/monitors. What type of tool can be used to detect the output effectively?

a)

​A log analysis tool

b)

​A behavior based analysis tool

c)

​A signature based detection tool

d)

​Manual analysis

16.

Several years ago, the Stuxnet attack relied on engineers that took malware with them, crossing the air gap between networks. What type of threat uses this method?

a)

email

b)

web

c)

removable media

d)

attrition

17.

What is not a major category of security event indicator?

a)

alerts

b)

logs

c)

people

d)

databases

18.

Who should coordinate incident-related communications with the media during an incident response?

a)

​Cyber security analysts

b)

Chief Technology Officer

c)

​Public Relations Officer

d)

​Human Resources Officer

19.

What provides the detailed, tactical information that CSIRT members need when responding to an incident?

a)

Procedures

b)

Guidelines

c)

​Policies

d)

​Instructions

20.

During what phase of the incident response process does an organization assemble an incident response toolkit?

a)

​Preparation

b)

​Detection and analysis

c)

Containment, eradication, and recovery

d)

​Post-incident activity