NEW
Font size
WorksheetsCySa+ PT5: 2 of 3
Total questions: 20
Worksheet time: 10mins
Your organization’s primary operating system vendor just released a critical patch for your servers. Your system administrators have recently deployed this patch and verified the installation was successful. The critical patch designed to remediate a vulnerability that can allow a malicious actor to remotely execute code on the server from over the Internet. However, you just ran a vulnerability assessment scan of the network and found that all of the servers are still being reported as having the vulnerability. Why is the scan report still showing a vulnerability even though the patch was installed by the system administrators?
Your vulnerability assessment scan is returning false positives
The critical patch did not remediate the vulnerability
You did not wait enough time after applying the patch before running the vulnerability assessment scan
You scanned the wrong IP range during your vulnerability assessment
TRUE or FALSE: PCI DSS requires the use of an outside consultant to perform internal vulnerability scans.
TRUE
FALSE
Which type of attacker is considered to be sophisticated, highly organized, and typically sponsored by a nation-state?
Script kiddies
Hacktivists
Advanced Persistent Threat
Ethical hacker
TRUE or FALSE: When evaluating the functional impact of a security incident, an analyst should assign a rating of high in cases where the organization is not able to provide some critical services to any users.
TRUE
FALSE
Caleb is designing a playbook for zero-day threats as part of his incident response program. Which of the following items should not be in his plan?
Segmentation
Patching
Using threat intelligence
Whitelisting
What stage of an event is preservation of evidence typically handled?
Preparation
Detection and analysis
Containment, eradication, and recovery
Post-incident activity
During the preparation phase of an organization's incident response process, Aaron gathered a laptop with useful software. The software included a sniffer, forensics tools, thumb drives and external hard drives, networking equipment, and a variety of cables. What type of equipment is this typically called?
A grab bag
A jump kit
A crash cart
A first responder kit
Paula is working on a report that describes the common attack models used by APT actors. Which of the following is a typical characteristic of an APT attack?
They involve sophisticated DDoS attacks
They quietly gather information from compromised systems
They rely on worms to spread
They use encryption to hold data hostage
Degaussing is an example of what type of media sanitization?
Clearing
Purging
Destruction
It isn’t a form of media sanitization
A cyber security technician has been running an intensive vulnerability scan to detect which ports might be open to exploitation. But, during the scan, one of the network services became disabled and this impacted the production server. What information source could be used to evaluate which network service was interrupted?
Syslog
Network mapping
Firewall logs
NIDS
What is NOT part of the security incident validation effort?
Scanning
Sanitization
Patching
Permissions
Richard noticed that the forensic image he attempted to create has failed. What would be the most likely reason for the failure?
Data was modified
The source disk is encrypted
The destination disk has bad sectors
The data cannot be copied in RAW format
TRUE or FALSE: CSIRTs should sometimes include human resource team members.
TRUE
FALSE
NIST describes four major phases in the incident response cycle. Which is not one of the four?
Containment, eradication, and recovery
Notification and communication
Detection and analysis
Preparation
Jenny is trying to detect unexpected output from the application she manages/monitors. What type of tool can be used to detect the output effectively?
A log analysis tool
A behavior based analysis tool
A signature based detection tool
Manual analysis
Several years ago, the Stuxnet attack relied on engineers that took malware with them, crossing the air gap between networks. What type of threat uses this method?
web
removable media
attrition
What is not a major category of security event indicator?
alerts
logs
people
databases
Who should coordinate incident-related communications with the media during an incident response?
Cyber security analysts
Chief Technology Officer
Public Relations Officer
Human Resources Officer
What provides the detailed, tactical information that CSIRT members need when responding to an incident?
Procedures
Guidelines
Policies
Instructions
During what phase of the incident response process does an organization assemble an incident response toolkit?
Preparation
Detection and analysis
Containment, eradication, and recovery
Post-incident activity
