wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

CySa+ PT 4: 3/3

Total questions: 18

Worksheet time: 9mins

Name
Class
Date
1.

Stacy is in charge of Windows workstations in her domain and wants to protect them from buffer overflow attacks. What should be recommended to the domain administrators at her company?

a)

Install an anti-malware tool

b)

Install an antivirus tool

c)

Enable DEP in Windows

d)

Set VirtualAllocProtection to 1 in the registry

2.

What sanitization technique uses only logical techniques to remove data?

a)

Purge

b)

Degauss

c)

Destroy

d)

Clear

3.

Sarah is attempting to determine whether the user of a company-owned laptop accessed a malicious wireless access point. Where can he find a list of the wireless networks the system already knows about?

a)

The registry

b)

The user profile directory

c)

The wireless adapter cache

d)

Wireless network lists are not stored after use.

4.

Steven is performing a forensic analysis of an iPhone backup and has discovered that only some of the information is there, not all of it. What is the best scenario that would result in the backup being used only having partial information?

a)

The backup was interrupted

b)

The backup is encrypted

c)

The backup is a differential backup

d)

The backup is stored in iCloud.

5.

What regulation protects the privacy of student educational records?

a)

HIPPA

b)

FERPA

c)

SOX

d)

GLBA

6.

Of the systems mentioned below, which of the following is not considered a component that belongs to the category of identity management infrastructure?

a)

HR system

b)

LDAP

c)

Provisioning engine

d)

Auditing system

7.

Matt has been offered and accepted a position as a cybersecurity analyst for a bank which is privately owned. Which of the following regulations will have the greatest impact on his cybersecurity program?

a)

HIPAA

b)

GLBA

c)

FERPA

d)

SOX

8.

Isaac is deploying a SIEM (security information and event management) system at his company. He doesn’t currently have the funding to purchase a commercial product, so which item, from the list below, would be a SIEM with an open source licensing model?

a)

AlienVault

b)

QRadar

c)

ArcSight

d)

OSSIM

9.

Which policy contains (or should contain) requirements for removing user access when the user is terminated?

a)

Data ownership policy

b)

Data classification policy

c)

Data retention policy

d)

Account management policy

10.

A cyber security professional visited an e-commerce website by typing in its URL and found that the administrative web frontend for its backend e-commerce application is accessible over the Internet and is only being protected by the default password. What three things should the analyst recommend to the website owner in order to MOST securely remediate this discovered vulnerability?

a)

​Rename the URL to a more obscure name, whitelist all corporate IP blocks, and require two-factor authentication

b)

Change the username and default password, whitelist specific source IP addresses, and require two-factor authentication for access

c)

​Change the default password, whitelist all specific IP blocks, and require two-factor authentication

d)

​Red Team all corporate IP blocks, require an alphanumeric passphrase for the default password, and require two-factor authentication

11.

You have been asked to recommend a few technologies that are PKI X.509 compliant for use in some secure functions in the organization. What technology would NOT meet the compatibility requirement?

a)

AES

b)

PKCS

c)

SSL/TLS

d)

3DES

12.

In which tier of the NIST cybersecurity framework does an organization understand its dependencies and partners?

a)

Partial

b)

Risk informed

c)

Repeatable

d)

Adaptive

13.

Ashley is looking for a physical security control for her organization that will help protect against attacks where an individual could drive a vehicle through the glass doors in the front of the building. Which of the following would be the most effective way to protect against such attack?

a)

​Mantraps

b)

​Security guards

c)

​Bollards

d)

​Intrusion alarm

14.

There are four tiers of implementations for the NIST Cybersecurity Framework. What are they, ordered from least mature to most mature?

a)

Partial, Risk Informed, Repeatable, Adaptive

b)

Partial, Repeatable, Risk Informed, Adaptive

c)

Partial, Risk Informed, Managed, Adaptive

d)

Partial, Managed, Risk Informed, Adaptive

15.

Liberty Beverages allows its visiting business partners from SodaCorp to use an available Ethernet port in the Liberty Beverage conference rooms when they are in the building. This access is provided to allow employees of SodaCorp to have the ability to establish a VPN connection back to the SodaCorp network. You have been tasked to ensure that SodaCorp employees can gain direct Internet access from the Ethernet port in the conference room only. But, if a Liberty Beverage employee uses the same Ethernet port, they should be able to access Liberty’s internal network as well. What should you use to ensure this capability?

a)

ACL

b)

SIEM

c)

MAC

d)

NAC

16.

Tony’s manager requires him to receive and inventory the items that his co-worker Barbara orders. This is an example of what kind of personnel control?

a)

Separation of duties

b)

Background checks

c)

Dual control

d)

Mandatory vacation

17.

OWASP (Open Web Application Security Project) maintains an application called Orizon. This application reviews Java classes and points out potential security flaws. What type of tool is Orizon?

a)

Fuzzer

b)

Static code analyzer

c)

Web application assessor

d)

Fault injector

18.

Tony works for a company as a cybersecurity analyst. His company runs a website that allows public postings. Recently, users have started complaining about the website having pop-up messages asking for passwords. Simultaneously, there has been more compromised user accounts. What type of attack is most likely the cause of these happenings?

a)

SQL injection

b)

Cross-site scripting

c)

Cross-site request forgery

d)

Rootkit