wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Day 4 - Security I - Day 3 Review - 1st Review

Total questions: 22

Worksheet time: 11mins

Name
Class
Date
1.

What was the theme topic of Day 3?

a)

Wireless Networking and Security/Mobile Device Management

b)

Vulnerabilities and Threats

c)

Introduction to Information Security: Network Basics and Terminology

d)

Introduction to Security Terminology / Types of Attacks

2.

What was the SkillSoft Video Training Topic of Day 3?

a)

Social Engineering Techniques & Attack Types

b)

Identifying Different Cyber Attacks

c)

Implementing Secure Protocols & Application Security Solutions

d)

Threat Actors, Intelligence Sources, & Vulnerabilities

3.

What term describes the technique or method used to exploit a vulnerability or deliver a malware payload?

a)

Threat vector

b)

Threat agent

c)

Threat category

d)

Threat actor

4.

Which of these third-party risks would most likely occur due to the use of unsecure coding practices and lack of testing?

a)

System integration

b)

Outsourced container development

c)

Data storage

d)

Supply chain activities

5.

Which source of research would be published by the IEEE?

a)

TTP

b)

OSINT

c)

RFC

d)

Twitter

6.

Which is an advantage of on-premise database solution as opposed to a cloud service provider?

a)

The public API calls are likely protected with digital signatures

b)

You will often leverage a cloud access security broker

c)

The threat actors are typically internal privileged users

d)

Many accounts will reduce the attack surface

7.

What component will typically store the instances of all organizational configuration items?

a)

SCADA

b)

CASB

c)

CMDB

d)

APT

8.

Which of these statements is true regarding zero-day attacks?

a)

Most malicious code is accounted for today

b)

The CVE is months behind in identifying these vulnerabilities

c)

All malware and exploits were a zero-day at one time or another

d)

The "zero" refers to the threat level on a scale of 0-10

9.

___________ is defined as a collection and distribution of information about exposed computer security exposures.

a)

IoC

b)

STIX

c)

Dark web

d)

Vulnerability databases

10.

___________ is an overlay network that is not indexed by search engines.

a)

IoC

b)

Dark web

c)

STIX

d)

OSINT

11.

__________ is a structured language for cyber threat intelligence.

a)

IoC

b)

Dark web

c)

STIX

d)

OSINT

12.

_________ is a network or host-based cyber observables or artifacts of an incursion.

a)

IoC

b)

OSINT

c)

STIX

d)

Dark web

13.

Which type of threat actor has some level of information about the target but often needs more?

a)

Black hat

b)

Gray hat

c)

White hat

d)

Blue hat

14.

One common type of a vulnerability scan is a port scan.

a)

True

b)

False

15.

________ attempt to exploit a vulnerability when it is found.

a)

Non-intrusive scan

b)

Active scan

c)

Passive scan

d)

Intrusive scan

16.

99% of all firewall breaches will be caused by ________, not vulnerabilities.

a)

hunting

b)

misconfigurations

c)

threats

d)

scans

17.

__________ is an active cyber defense activity.

a)

Configurations

b)

Intelligence Fusion

c)

Maneuver

d)

Threat Hunting

18.

An _______ document represents a structured collection of security configuration rules for some set of target systems.

a)

XCCDF

b)

OVAL

c)

SCAP

d)

CVSS

19.

_______ is an international information security community baseline standard.

a)

XCCDF

b)

OVAL

c)

SCAP

d)

CVSS

20.

Intrusive tests are typically much more accurate.

a)

True

b)

False

21.

There will be some vulnerabilities identified by the scanner that cannot be tied back to a specific known __________.

a)

SCAP

b)

CVE

c)

OVAL

d)

XCCDF

22.

Passive scans compare the system you are scanning to a baseline.

a)

True

b)

False