WorksheetsMentoring Sesi 1 - Security+
Total questions: 10
Worksheet time: 6mins
Which security-related phrase relates to the integrity of data?
Accessibility is authorized
Modification is authorized
Knowledge is authorized
Non-repudiation is authorized
An engineer looks to implement security measures by following the five functions in the National Institute of Standards and Technology (NIST) framework. When documenting the "detect" function, what does the engineer focus on?
Evaluate risks and threats
Install, operate, and decommission assets
Ongoing proactive monitoring
Restoration of systems and data
How might the goals of a basic network management not be well-aligned with the goals of security?
Management focuses on confidentiality and availability.
Management focuses on confidentiality over availability.
Management focuses on integrity and confidentiality.
Management focuses on availability over confidentiality.
Any external responsibility for an organization's security lies mainly with which individuals?
The owner
Tech staff
Management
Public relations
What distinguishes DevSecOps from a traditional SOC?
Software code is the responsibility of a programming or development team.
Identification as a single point-of-contact for the notification of security incidents.
A cultural shift within an organization to encourage much more collaboration.
Security is a primary consideration at every stage of software development.
A company has one technician that is solely responsible for applying and testing software and firmware patches. The technician goes on a two-week vacation, and no one is tasked to perform the patching duties during this time. A critical patch is released and not installed due to the absence. According to the National Institute of Standards and Technology (NIST), what has the delay in applying the patch caused?
Control
Risk
Threat
Vulnerability
Any part of the World Wide Web that is accessed through non-standard methods and is intentionally not indexed and hidden from a search engine is called a _____.
Dark net
Cyber threat actor
Deep web
Dark web
Which of the following could represent an insider threat? (Select all the apply.)
Former employee
Contractor
Customer
White box hacker
One aspect of threat modeling is to identify potential threat actors and the risks associated with each one. When assessing the risk that any one type of threat actor poses to an organization, what are the critical factors to profile? (Select all that apply.)
Education
Socioeconomic status
Intent
Motivation
A user with authorized access to systems in a software development firm installs a seemingly harmless, yet unauthorized program on a workstation without the IT department's sanction. Identify the type of threat that is a result of this user's action.
Unintentional insider threat
Malicious insider threat
Intentional attack vector
Shadow IT
