NEW
Font size
WorksheetsCySa+ PT 4: 2/3
Total questions: 20
Worksheet time: 10mins
The presence of _________________ triggers specific vulnerability scanning requirements based upon law or regulation.
Credit card information
Protected health information
Personally identifiable information
Trade secret information
Jesus is creating a remediation procedure for vulnerabilities discovered in his organization. He would like to make sure that any vendor patches are tested prior to deploying them in production. What type of environment should be included to best address this issue?
Sandbox
Honeypot
Honeynet
Production
James is working on developing a vulnerability scanner program for a large network of sensors that his organization uses to monitor a transcontinental gas pipeline. What term is typically used to describe this type of network?
WLAN
VPN
P2P
SCADA
Timothy’s company is starting a BYOD (bring your own device) policy for all mobile devices. Which of the following allows you to secure the sensitive information on personally owned devices, including administrators, and the ability to remotely wipe corporate information without affecting personal data?
Remote wipe
Strong passwords
Biometric authentication
Containerization
Patrick is the manager of his organization's vulnerability scanning program. He’s experiencing some issues with scans aborting because the previous day scans are still running when the scanner attempts to start the current scans. Which of the following solutions is least likely to resolve the issue?
Add a new scanner
Reduce the scope of scans
Reduce the sensitivity of scans
Reduce the frequency of scans
Cherish is attempting to determine what systems should be subject to vulnerability scanning and what systems are exempt. She’d like to have a base for this decision relating to the criticality of system to business operations. Where would she find this information?
The CEO
System names
IP addresses
Asset inventory
TRUE or FALSE: Organizations may decide not to remediate vulnerabilities because of conflicting business requirements.
TRUE
FALSE
Which of the following vulnerabilities would you consider the greatest threat to information confidentiality?
HTTP TRACE/TRACK methods enabled
SSL Server with SSLv3 enabled vulnerability
phpinfo information disclosure vulnerability
Web application SQL injection vulnerability
Barrett noticed a critical vulnerability in a database at his organization. He received permission to implement an emergency change after the close of the business day. There are currently eight hours before the change window. What else needs to be done to prepare for the change?
Ensure all stakeholders are informed of planned outage
Document the change in the change management system
Identify any potential risks associated with the change
All supplied choices
What SCAP component provides a language for specifying checklists?
XCCDF
CPE
CCE
OVAL
Matt is prioritizing vulnerability scans and has interest in basing the frequency of scanning on the information asset value. Which of the following items would be the most appropriate for him to use in this analysis?
Cost of hardware acquisition
Cost of hardware replacement
Types of information processed
Depreciated hardware cost
Tanner noticed that a server is running a critical web application vulnerability. He would like to view the logs as the server belongs to his organization. The server is running Apache on CentOS with a default configuration. What is the name of the file where Tanner would expect to find the logs?
httpd_log
apache_log
access_log
http_log
Nicole is investigating a security incident at a government agency and discovers that attackers obtained PII. What is the information impact of this incident?
None
Privacy breach
Proprietary breach
Integrity breach
What items represent a document that includes detailed information on when an incident was detected, how impactful the incident was, how it was remediated, the effectiveness of the incident response, and any identified gaps that require improvement?
Forensic analysis report
Chain of custody report
Trends analysis report
Lessons learned report
Choose the set of Linux permissions set up from least permissive to most permissive?
777, 444, 111
544, 444, 545
711, 717, 117
111, 734, 747
You have been tasked to conduct a review of the firewall logs. During your review, you notice that an IP address from within your company’s server subnet had been transmitting between 125 to 375 megabytes of data to a foreign IP address during nighttime hours. Looking over the logs, you have determined this has been occurring for approximately 5 days and the affected server has since been taken offline for forensic review. What is MOST likely to increase the impact assessment of the incident?
PII of company employees and customers was exfiltrated
Raw financial information about the company was accessed
Forensic review of the server required fallback on a less efficient service
IP addresses and other network-related configurations were exfiltrated
Laura needs a forensic copy of a drive encrypted with BitLocker. Which of the following methods is not one that should be used?
Analyzing the hibernation file
Analyzing the memory dump file
Retrieving the key from the MBR
Performing a FireWire attack on mounted drives
After analyzing and correlating activity from the firewall logs, server logs, and the intrusion detection system logs, a cyber security analyst has determined that a sophisticated breach of the company’s network security may have occurred from a group of specialized attackers in a foreign country over the past five months. Up until now, these cyber attacks against the company network had gone unnoticed by the company’s information security team. What would this be an example of?
advanced persistent threat (APT)
spear phishing
malicious insider threat
privilege escalation
TRUE or FALSE: Organizations should always involve law enforcement if they suspect a crime was committed.
TRUE
FALSE
Mark wants to validate the application file that he downloaded from the vendor of the application. What information should be requested from the vendor?
File size and file creation date
MD5 hash
Private key and cryptographic hash
Public key and cryptographic hash
