WorksheetsDay 4 - Security I - Day 3 Review - 1st Review
Total questions: 22
Worksheet time: 11mins
What was the theme topic of Day 3?
Wireless Networking and Security/Mobile Device Management
Vulnerabilities and Threats
Introduction to Information Security: Network Basics and Terminology
Introduction to Security Terminology / Types of Attacks
What was the SkillSoft Video Training Topic of Day 3?
Social Engineering Techniques & Attack Types
Identifying Different Cyber Attacks
Implementing Secure Protocols & Application Security Solutions
Threat Actors, Intelligence Sources, & Vulnerabilities
What term describes the technique or method used to exploit a vulnerability or deliver a malware payload?
Threat vector
Threat agent
Threat category
Threat actor
Which of these third-party risks would most likely occur due to the use of unsecure coding practices and lack of testing?
System integration
Outsourced container development
Data storage
Supply chain activities
Which source of research would be published by the IEEE?
TTP
OSINT
RFC
Which is an advantage of on-premise database solution as opposed to a cloud service provider?
The public API calls are likely protected with digital signatures
You will often leverage a cloud access security broker
The threat actors are typically internal privileged users
Many accounts will reduce the attack surface
What component will typically store the instances of all organizational configuration items?
SCADA
CASB
CMDB
APT
Which of these statements is true regarding zero-day attacks?
Most malicious code is accounted for today
The CVE is months behind in identifying these vulnerabilities
All malware and exploits were a zero-day at one time or another
The "zero" refers to the threat level on a scale of 0-10
___________ is defined as a collection and distribution of information about exposed computer security exposures.
IoC
STIX
Dark web
Vulnerability databases
___________ is an overlay network that is not indexed by search engines.
IoC
Dark web
STIX
OSINT
__________ is a structured language for cyber threat intelligence.
IoC
Dark web
STIX
OSINT
_________ is a network or host-based cyber observables or artifacts of an incursion.
IoC
OSINT
STIX
Dark web
Which type of threat actor has some level of information about the target but often needs more?
Black hat
Gray hat
White hat
Blue hat
One common type of a vulnerability scan is a port scan.
True
False
________ attempt to exploit a vulnerability when it is found.
Non-intrusive scan
Active scan
Passive scan
Intrusive scan
99% of all firewall breaches will be caused by ________, not vulnerabilities.
hunting
misconfigurations
threats
scans
__________ is an active cyber defense activity.
Configurations
Intelligence Fusion
Maneuver
Threat Hunting
An _______ document represents a structured collection of security configuration rules for some set of target systems.
XCCDF
OVAL
SCAP
CVSS
_______ is an international information security community baseline standard.
XCCDF
OVAL
SCAP
CVSS
Intrusive tests are typically much more accurate.
True
False
There will be some vulnerabilities identified by the scanner that cannot be tied back to a specific known __________.
SCAP
CVE
OVAL
XCCDF
Passive scans compare the system you are scanning to a baseline.
True
False
