wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

M4-Q4

Total questions: 10

Worksheet time: 10mins

Name
Class
Date
1.

Which of the following is not a part of SIEM tools?

a)

Sensor

b)

Agent

c)

Collector

d)

Log

2.

Which one is not the part of SIEM application?

a)

Normalization

b)

Risk assessment

c)

Vulnerability Scanning

d)

Real-time monitoring

3.

How does a SIEM tool handle the issue of Completeness of log?

a)

Encryption

b)

Timestamping

c)

Digital Signing

d)

Hashing

4.

The computer security incident response team (CSIRT) of an organization publishes detailed descriptions of recent threats. An IS auditor's GREATEST concern should be that the users may:

a)

Forward the security alert

b)

Implement individual solutions

c)

Fail to understand the threat

d)

Use this information to launch attacks

5.

The main goal of the Security Operation Centre (SOC) is

a)

Detect, analyze and report

b)

Collect, analyze and report

c)

Detect, analyze and respond

d)

Collect, analyze and respond

6.

What is the primary purpose of an incident management program?

a)

Conduct lessons learned sessions

b)

Alert key individuals

c)

Identify and assess incidents

d)

Assign responsibility

7.

SOC shall be ineffective without the support of:

a)

Risk

b)

Budget

c)

Quality

d)

Top management

8.

Phases of an incident management program

a)

Plan, prepare and respond

b)

Prepare, Respond, and follow up

c)

Plan, prepare and follow up

d)

Prepare, plan and respond

9.

Within an Incident Response Management program, the Containment phase aims to

a)

Block the event

b)

Remove the event

c)

Reduce the impact

d)

Rise the event

10.

The basic operation of the SIEM tools, on the logs collected from the devices, is

a)

Correlating the log

b)

Live Correlating the log

c)

Collecting the log

d)

Analyzing the log