NEW
Font size
WorksheetsSimulasi CIHE
Total questions: 65
Worksheet time: 49mins
Keep a list of __________ computers at a site that is password-protected and only accessible from on-campus IP addresses.
Unblocked
Blocked
__________ is considered to be one of the most famous tools in the Sysinternals suite.
PsTools
Process Explorer
Process Monitor
True or False. Monitor the systems and look for backdoors and other malicious code.
True
False
Some common incident categories are:
Denial of Service
Malicious Code
Unauthorized Access
All of the above
__________: The attacker tricks the user’s system into running code, which appears trustworthy because it seems to belong to the server, which in turn, allows the attacker to obtain a copy of the cookie or perform other operations.
Session Fixation
Session Sidejacking
Attacker
Cross-site scripting
Each ticket has a unique _________ number and an owner
service
identification
tracking
True or False. There is no need to conduct initial analysis on data after it arrives into the collection mechanism
True
False
True or False. Malware requires administrative access and proper permissions can minimize the damage and spread of malware.
True
False
__________ is a real-time monitoring utility that logs sector-level hard disk activity.
Diskview
Disk monitor
Disk utilities
Sigcheck
In Eradication, perform additional analysis, which may include:
Recover deleted files and file fragments
Perform a vulnerability scan
Check for unusual running processes
All of the above
__________ with physical access can try to steal the session key by gaining the file or memory contents of the appropriate part of the user’s computer or server.
Session Fixation
Session Sidejacking
Attacker
Cross-site scripting
__________ is an incident that might have occurred or may be occurring now.
Indication
Precursor
True or False. Compromises that allow remote control of the system, gain root/Administrator privileges, and/or install a backdoor require a complete re-install of the system.
True
False
__________: The attacker uses packet sniffing to read network traffic between two parties to steal the session cookie. Many sites use SSL encryption for login pages to prevent attackers from seeing the password but do not use encryption for the rest of the site.
Session Fixation
Session Sidejacking
Attacker
Cross-site scripting
True or False. Hosts should be configured to provide only the minimum rights to users, processes, or other hosts – Least Privilege.
True
False
__________ is the preparation, detection, management and resolution of incidents or events that may occur in the information system.
Incident Handling
Computer Forensics
Network Forensics
Digital Forensics
What is an anomaly where a process stores data in a buffer outside the memory the programmer set-aside for it?
Heap spray
Stack overflow
Buffer overflow
What are some common security events of interest?
Malicious code events
Denial of service attacks
Espionage
All of the above
True or False. Request tracker has the capability of keeping track of absolutely everything and provides a very efficient search engine.
True
False
__________ is a command line tool that is used to verify the digital signature of files and listing of file hashes.
Diskview
Disk monitor
Disk utilities
Sigcheck
True or False. Hypervisor escape attacks occur because of a hypervisor vulnerability.
True
False
True or False. An incident response plan is a document that defines incidents, severity levels of incident, response plans for each level of incident, incident management team responsibilities and authorizations, communications and reporting plans, and practices and/or guidelines.
True
False
__________ are stored on the client machine.
Session cookies
Persistent cookies
Tracking cookies
__________ may be detected through several means but with different information and trust levels.
Forensics
Incidents
Investigations
What is the first step when preparing for an incident handling event?
Follow-up
Preparation
Eradication
Containment
True or False. An executive summary is a way to report an incident to senior management.
True
False
__________ is used for keeping track of workflow by tracking who is responsible for completing a certain task and when.
Request Tracker
Request Planning
Request Form
True or False. You do not have to report findings and status to necessary parties including command-and-control and system owners.
True
False
Recovery is the _________ stage of the incident process.
First
Second
Third
Fifth
__________: The attacker sets a user’s session ID to one known to him. By sending the user an email with a link that has a particular session ID, the attacker only has to wait until the user logs in.
Session Fixation
Session Sidejacking
Attacker
Cross-site scripting
__________ has different types of tools: data acquisition, image analysis, case reporting, image duplication, and desk sanitization.
Network forensics
Digital forensics
Incident handling
_________ are reports stating that something is wrong.
Damage reports
Incident reports
Investigation reports
__________ are cookies stored with the purpose of tracking activities on all sites.
Session cookies
Persistent cookies
Tracking cookies
True or False. If there is evidence of a rootkit style attack, you should install from the most recent backups.
True
False
__________ is the data you will lose if you power down the system.
Volatile
Non-volatile
If there is an incident, recommend changing __________ for all accounts that interact with the impacted system.
Passwords
Access Controls
Computer Images
True or False. All tools and commands you run during an incident response does not have to be in the toolkit.
True
False
__________ is an incident that may occur in the future.
Indication
Precursor
A team member could be called to be a _________ in court.
Defendant
Prosecutor
Witness
None of these
Multiple images of different operating systems running on top of the hypervisor and each of them appear as if they have their own dedicated hardware.
Hardware
Hypervisor
Guest Operating System
_________ log files can be found under /var/log.
Linux
Unix
Windows
True or False. Request tracker is a ticketing system developed by Best Practice.
True
False
True or False. Restore System is conducting a pre-production security assessment to ensure that the compromised system and its related components are secured.
True
False
True or False. Change your passwords for accounts that interact with impacted systems.
True
False
The final step of the incident handling process is:
Eradication
Recovery
Follow-up
Containment
_________ log files can be viewed using Event Viewer.
Linux
Unix
Windows
In order to fix issues, you should conduct a __________ learned meeting.
Lessons
Processes
True or False. Isolate attack: Where it originated and what it affected.
True
False
True or False. Hypervisor attacks are attacks that target the hypervisor running on the hardware.
True
False
__________ always follows the containment phase of an incident.
Preparation
Follow-up
Eradication
Recovery
True or False. You should create an Executive Summary.
True
False
What is any event that occurs in the organization related to security?
Application
Software
Security
Hardware
True or False. Procedures are not a detailed description of what, when, and how anything is done within the principles of a policy.
True
False
True or False. Once the system has been restored, verify that the operation was successful and the system is back on its normal condition.
True
False
True or False. Archive reports and other relevant documents and communications ("work product”) according to K-State’s retention of records policy and procedures.
True
False
True or False. The goal user awareness is to explain proper rules of behavior for use of an organization’s IT systems and information.
True
False
__________ lay out principles and rules for decision making, should be easy to understand, and can only be understood in one way, and must be followed.
Procedures
Policies
Guidelines
Rules
__________ is a great tool for showing you a cluster-oriented graphical representation of an NTFS-formatted volume, which allows you to determine in which cluster a file is located and whether a file is fragmented or not, or determine what file occupies a particular sector.
Diskview
Disk monitor
Disk utilities
Sigcheck
What are some locations that security event and information management can happen?
OS logs
Firewall/IDS/IPS
Authentication systems
All of the above
True or False. Containment always follows the confirmation of such incident.
True
False
True or False. The first pieces of information to gather during an incident response include system date and time, current running and active process, current network connections, current open ports, applications that listen on the open sockets and current logged in users.
True
False
A piece of software that is used to map guest operating systems to the hardware.
Hardware
Hypervisor
Guest Operating System
__________ executes processes both locally and remotely with redirected output.
Psexec
Process Explorer
Process Monitor
True or False. Guest VM attacks are attacks that target the hypervisor running on the hardware.
True
False
What is one thing that should be created during the follow-up phase?
Report
Plan
Guidelines
Directions
