wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

CySa+ PT 4: 2/3

Total questions: 20

Worksheet time: 10mins

Name
Class
Date
1.

The presence of _________________ triggers specific vulnerability scanning requirements based upon law or regulation.

a)

​Credit card information

b)

​Protected health information

c)

Personally identifiable information

d)

Trade secret information

2.

Jesus is creating a remediation procedure for vulnerabilities discovered in his organization. He would like to make sure that any vendor patches are tested prior to deploying them in production. What type of environment should be included to best address this issue?

a)

Sandbox

b)

Honeypot

c)

Honeynet

d)

Production

3.

James is working on developing a vulnerability scanner program for a large network of sensors that his organization uses to monitor a transcontinental gas pipeline. What term is typically used to describe this type of network?

a)

​WLAN

b)

VPN

c)

P2P

d)

​SCADA

4.

Timothy’s company is starting a BYOD (bring your own device) policy for all mobile devices. Which of the following allows you to secure the sensitive information on personally owned devices, including administrators, and the ability to remotely wipe corporate information without affecting personal data?

a)

​Remote wipe

b)

Strong passwords

c)

​Biometric authentication

d)

​Containerization

5.

Patrick is the manager of his organization's vulnerability scanning program. He’s experiencing some issues with scans aborting because the previous day scans are still running when the scanner attempts to start the current scans. Which of the following solutions is least likely to resolve the issue?

a)

Add a new scanner

b)

Reduce the scope of scans

c)

Reduce the sensitivity of scans

d)

Reduce the frequency of scans

6.

Cherish is attempting to determine what systems should be subject to vulnerability scanning and what systems are exempt. She’d like to have a base for this decision relating to the criticality of system to business operations. Where would she find this information?

a)

​The CEO

b)

System names

c)

​IP addresses

d)

​Asset inventory

7.

TRUE or FALSE: Organizations may decide not to remediate vulnerabilities because of conflicting business requirements.

a)

TRUE

b)

FALSE

8.

Which of the following vulnerabilities would you consider the greatest threat to information confidentiality?

a)

​HTTP TRACE/TRACK methods enabled

b)

SSL Server with SSLv3 enabled vulnerability

c)

​phpinfo information disclosure vulnerability

d)

​Web application SQL injection vulnerability

9.

Barrett noticed a critical vulnerability in a database at his organization. He received permission to implement an emergency change after the close of the business day. There are currently eight hours before the change window. What else needs to be done to prepare for the change?

a)

Ensure all stakeholders are informed of planned outage

b)

Document the change in the change management system

c)

Identify any potential risks associated with the change

d)

All supplied choices

10.

What SCAP component provides a language for specifying checklists?

a)

​XCCDF

b)

​CPE

c)

CCE

d)

OVAL

11.

Matt is prioritizing vulnerability scans and has interest in basing the frequency of scanning on the information asset value. Which of the following items would be the most appropriate for him to use in this analysis?

a)

​Cost of hardware acquisition

b)

​Cost of hardware replacement

c)

Types of information processed

d)

Depreciated hardware cost

12.

Tanner noticed that a server is running a critical web application vulnerability. He would like to view the logs as the server belongs to his organization. The server is running Apache on CentOS with a default configuration. What is the name of the file where Tanner would expect to find the logs?

a)

​httpd_log

b)

​apache_log

c)

​access_log

d)

​http_log

13.

Nicole is investigating a security incident at a government agency and discovers that attackers obtained PII. What is the information impact of this incident?

a)

​None

b)

​Privacy breach

c)

​Proprietary breach

d)

​Integrity breach

14.

What items represent a document that includes detailed information on when an incident was detected, how impactful the incident was, how it was remediated, the effectiveness of the incident response, and any identified gaps that require improvement?

a)

Forensic analysis report

b)

Chain of custody report

c)

Trends analysis report

d)

Lessons learned report

15.

Choose the set of Linux permissions set up from least permissive to most permissive?

a)

​777, 444, 111

b)

​544, 444, 545

c)

711, 717, 117

d)

111, 734, 747

16.

You have been tasked to conduct a review of the firewall logs. During your review, you notice that an IP address from within your company’s server subnet had been transmitting between 125 to 375 megabytes of data to a foreign IP address during nighttime hours. Looking over the logs, you have determined this has been occurring for approximately 5 days and the affected server has since been taken offline for forensic review. What is MOST likely to increase the impact assessment of the incident?

a)

​PII of company employees and customers was exfiltrated

b)

Raw financial information about the company was accessed

c)

Forensic review of the server required fallback on a less efficient service

d)

​IP addresses and other network-related configurations were exfiltrated

17.

Laura needs a forensic copy of a drive encrypted with BitLocker. Which of the following methods is not one that should be used?

a)

Analyzing the hibernation file

b)

​Analyzing the memory dump file

c)

Retrieving the key from the MBR

d)

​Performing a FireWire attack on mounted drives

18.

After analyzing and correlating activity from the firewall logs, server logs, and the intrusion detection system logs, a cyber security analyst has determined that a sophisticated breach of the company’s network security may have occurred from a group of specialized attackers in a foreign country over the past five months. Up until now, these cyber attacks against the company network had gone unnoticed by the company’s information security team. What would this be an example of?

a)

advanced persistent threat (APT)

b)

​spear phishing

c)

malicious insider threat

d)

​privilege escalation

19.

TRUE or FALSE: Organizations should always involve law enforcement if they suspect a crime was committed.

a)

TRUE

b)

FALSE

20.

Mark wants to validate the application file that he downloaded from the vendor of the application. What information should be requested from the vendor?

a)

File size and file creation date

b)

​MD5 hash

c)

​Private key and cryptographic hash

d)

Public key and cryptographic hash