wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Simulasi CIHE

Total questions: 65

Worksheet time: 49mins

Name
Class
Date
1.

Keep a list of __________ computers at a site that is password-protected and only accessible from on-campus IP addresses.

a)

Unblocked

b)

Blocked

2.

__________ is considered to be one of the most famous tools in the Sysinternals suite.

a)

PsTools

b)

Process Explorer

c)

Process Monitor

3.

True or False. Monitor the systems and look for backdoors and other malicious code.

a)

True

b)

False

4.

Some common incident categories are:

a)

Denial of Service

b)

Malicious Code

c)

Unauthorized Access

d)

All of the above

5.

__________: The attacker tricks the user’s system into running code, which appears trustworthy because it seems to belong to the server, which in turn, allows the attacker to obtain a copy of the cookie or perform other operations.

a)

Session Fixation

b)

Session Sidejacking

c)

Attacker

d)

Cross-site scripting

6.

Each ticket has a unique _________ number and an owner

a)

service

b)

identification

c)

tracking

7.

True or False. There is no need to conduct initial analysis on data after it arrives into the collection mechanism

a)

True

b)

False

8.

True or False. Malware requires administrative access and proper permissions can minimize the damage and spread of malware.

a)

True

b)

False

9.

__________ is a real-time monitoring utility that logs sector-level hard disk activity.

a)

Diskview

b)

Disk monitor

c)

Disk utilities

d)

Sigcheck

10.

In Eradication, perform additional analysis, which may include:

a)

Recover deleted files and file fragments

b)

Perform a vulnerability scan

c)

Check for unusual running processes

d)

All of the above

11.

__________ with physical access can try to steal the session key by gaining the file or memory contents of the appropriate part of the user’s computer or server.

a)

Session Fixation

b)

Session Sidejacking

c)

Attacker

d)

Cross-site scripting

12.

__________ is an incident that might have occurred or may be occurring now.

a)

Indication

b)

Precursor

13.

True or False. Compromises that allow remote control of the system, gain root/Administrator privileges, and/or install a backdoor require a complete re-install of the system.

a)

True

b)

False

14.

__________: The attacker uses packet sniffing to read network traffic between two parties to steal the session cookie. Many sites use SSL encryption for login pages to prevent attackers from seeing the password but do not use encryption for the rest of the site.

a)

Session Fixation

b)

Session Sidejacking

c)

Attacker

d)

Cross-site scripting

15.

True or False. Hosts should be configured to provide only the minimum rights to users, processes, or other hosts – Least Privilege.

a)

True

b)

False

16.

__________ is the preparation, detection, management and resolution of incidents or events that may occur in the information system.

a)

Incident Handling

b)

Computer Forensics

c)

Network Forensics

d)

Digital Forensics

17.

What is an anomaly where a process stores data in a buffer outside the memory the programmer set-aside for it?

a)

Heap spray

b)

Stack overflow

c)

Buffer overflow

18.

What are some common security events of interest?

a)

Malicious code events

b)

Denial of service attacks

c)

Espionage

d)

All of the above

19.

True or False. Request tracker has the capability of keeping track of absolutely everything and provides a very efficient search engine.

a)

True

b)

False

20.

__________ is a command line tool that is used to verify the digital signature of files and listing of file hashes.

a)

Diskview

b)

Disk monitor

c)

Disk utilities

d)

Sigcheck

21.

True or False. Hypervisor escape attacks occur because of a hypervisor vulnerability.

a)

True

b)

False

22.

True or False. An incident response plan is a document that defines incidents, severity levels of incident, response plans for each level of incident, incident management team responsibilities and authorizations, communications and reporting plans, and practices and/or guidelines.

a)

True

b)

False

23.

__________ are stored on the client machine.

a)

Session cookies

b)

Persistent cookies

c)

Tracking cookies

24.

__________ may be detected through several means but with different information and trust levels.

a)

Forensics

b)

Incidents

c)

Investigations

25.

What is the first step when preparing for an incident handling event?

a)

Follow-up

b)

Preparation

c)

Eradication

d)

Containment

26.

True or False. An executive summary is a way to report an incident to senior management.

a)

True

b)

False

27.

__________ is used for keeping track of workflow by tracking who is responsible for completing a certain task and when.

a)

Request Tracker

b)

Request Planning

c)

Request Form

28.

True or False. You do not have to report findings and status to necessary parties including command-and-control and system owners.

a)

True

b)

False

29.

Recovery is the _________ stage of the incident process.

a)

First

b)

Second

c)

Third

d)

Fifth

30.

__________: The attacker sets a user’s session ID to one known to him. By sending the user an email with a link that has a particular session ID, the attacker only has to wait until the user logs in.

a)

Session Fixation

b)

Session Sidejacking

c)

Attacker

d)

Cross-site scripting

31.

__________ has different types of tools: data acquisition, image analysis, case reporting, image duplication, and desk sanitization.

a)

Network forensics

b)

Digital forensics

c)

Incident handling

32.

_________ are reports stating that something is wrong.

a)

Damage reports

b)

Incident reports

c)

Investigation reports

33.

__________ are cookies stored with the purpose of tracking activities on all sites.

a)

Session cookies

b)

Persistent cookies

c)

Tracking cookies

34.

True or False. If there is evidence of a rootkit style attack, you should install from the most recent backups.

a)

True

b)

False

35.

__________ is the data you will lose if you power down the system.

a)

Volatile

b)

Non-volatile

36.

If there is an incident, recommend changing __________ for all accounts that interact with the impacted system.

a)

Passwords

b)

Access Controls

c)

Computer Images

37.

True or False. All tools and commands you run during an incident response does not have to be in the toolkit.

a)

True

b)

False

38.

__________ is an incident that may occur in the future.

a)

Indication

b)

Precursor

39.

A team member could be called to be a _________ in court.

a)

Defendant

b)

Prosecutor

c)

Witness

d)

None of these

40.

Multiple images of different operating systems running on top of the hypervisor and each of them appear as if they have their own dedicated hardware.

a)

Hardware

b)

Hypervisor

c)

Guest Operating System

41.

_________ log files can be found under /var/log.

a)

Linux

b)

Unix

c)

Windows

42.

True or False. Request tracker is a ticketing system developed by Best Practice.

a)

True

b)

False

43.

True or False. Restore System is conducting a pre-production security assessment to ensure that the compromised system and its related components are secured.

a)

True

b)

False

44.

True or False. Change your passwords for accounts that interact with impacted systems.

a)

True

b)

False

45.

The final step of the incident handling process is:

a)

Eradication

b)

Recovery

c)

Follow-up

d)

Containment

46.

_________ log files can be viewed using Event Viewer.

a)

Linux

b)

Unix

c)

Windows

47.

In order to fix issues, you should conduct a __________ learned meeting.

a)

Lessons

b)

Processes

48.

True or False. Isolate attack: Where it originated and what it affected.

a)

True

b)

False

49.

True or False. Hypervisor attacks are attacks that target the hypervisor running on the hardware.

a)

True

b)

False

50.

__________ always follows the containment phase of an incident.

a)

Preparation

b)

Follow-up

c)

Eradication

d)

Recovery

51.

True or False. You should create an Executive Summary.

a)

True

b)

False

52.

What is any event that occurs in the organization related to security?

a)

Application

b)

Software

c)

Security

d)

Hardware

53.

True or False. Procedures are not a detailed description of what, when, and how anything is done within the principles of a policy.

a)

True

b)

False

54.

True or False. Once the system has been restored, verify that the operation was successful and the system is back on its normal condition.

a)

True

b)

False

55.

True or False. Archive reports and other relevant documents and communications ("work product”) according to K-State’s retention of records policy and procedures.

a)

True

b)

False

56.

True or False. The goal user awareness is to explain proper rules of behavior for use of an organization’s IT systems and information.

a)

True

b)

False

57.

__________ lay out principles and rules for decision making, should be easy to understand, and can only be understood in one way, and must be followed.

a)

Procedures

b)

Policies

c)

Guidelines

d)

Rules

58.

__________ is a great tool for showing you a cluster-oriented graphical representation of an NTFS-formatted volume, which allows you to determine in which cluster a file is located and whether a file is fragmented or not, or determine what file occupies a particular sector.

a)

Diskview

b)

Disk monitor

c)

Disk utilities

d)

Sigcheck

59.

What are some locations that security event and information management can happen?

a)

OS logs

b)

Firewall/IDS/IPS

c)

Authentication systems

d)

All of the above

60.

True or False. Containment always follows the confirmation of such incident.

a)

True

b)

False

61.

True or False. The first pieces of information to gather during an incident response include system date and time, current running and active process, current network connections, current open ports, applications that listen on the open sockets and current logged in users.

a)

True

b)

False

62.

A piece of software that is used to map guest operating systems to the hardware.

a)

Hardware

b)

Hypervisor

c)

Guest Operating System

63.

__________ executes processes both locally and remotely with redirected output.

a)

Psexec

b)

Process Explorer

c)

Process Monitor

64.

True or False. Guest VM attacks are attacks that target the hypervisor running on the hardware.

a)

True

b)

False

65.

What is one thing that should be created during the follow-up phase?

a)

Report

b)

Plan

c)

Guidelines

d)

Directions