Worksheetsweek 6 workshop quiz for sec+
Total questions: 25
Worksheet time: 13mins
Which of these options simulates a disaster and allows you to check the thoroughness of your disaster recovery plan?
Business continuity plans
After-action reports
Critical business functions
Tabletop exercises
You identify a security risk that you do not have in-house skills to address. You decide to procure contract resources. This contractor will be responsible for handling and managing this security risk. Which type of risk response strategy are you demonstrating?
mitigation
transference
acceptance
avoidance
Your company develops an incident response plan. When the Web server undergoes a DoS attack, the incident response team follows the incident response plan and returns the Web server to normal operation. What should be the final outcome of this incident?
incident type/category
documented incident
escalation guidelines
roles and responsibilities
When calculating risks by using the quantitative method, what is the result of multiplying the asset values by the exposure factor (EF)?
SLE
risk elimination
ACV
ALE
As your organization's security administrator, you are reviewing the audit results to assess if your organization's security baselines are maintained. In which phase of the security management life cycle are you engaged?
Monitor and Evaluate
Implement
Operate and Maintain
Plan and Organize
Which policy defines the sensitivity of a company's data?
a security policy
a backup policy
a use policy
an information policy
Your company contracts with a third-party janitorial service to clean the offices every night. Which one of these policies presents the greatest risk to the organization if it is NOT implemented?
Personal email
Job rotation
Clean desk policy
NDA
Which concept involves contracting with a third party who will provide a location and equipment to be used in the event of an emergency?
Alternate processing sites
Alternate business practices
Offsite storage
Disaster recovery plan
What is defined in an acceptable use policy?
which users require access to certain company data
how users are allowed to employ company hardware
the sensitivity of company data
which method administrators should use to back up network data
Which technique attempts to predict the likelihood a threat will occur and assigns monetary values in the event a loss occurs?
Qualitative risk analysis
Delphi technique
Quantitative risk analysis
Vulnerability assessment
You are the security administrator for your company. You identify a security risk. You decide to continue with the current security plan. However, you develop a contingency plan for if the security risk occurs. Which type of risk response strategy are you demonstrating?
mitigation
transference
avoidance
acceptance
Your client is a small retailer that accepts orders via e-mail. The e-mail form submitted by a client's customer includes credit card information, and you demonstrate to the client how risky that is. As a result, the client adds secure credit card processing to their website, and no longer accepts e-mail orders. Which risk management concept does this represent?
Risk transference
Risk avoidance
Risk acceptance
Risk mitigation
What is meant by MTBF?
the average amount of time from one failure to the next
the estimated amount of time that it will take to replace a piece of equipment
the estimated amount of time that a piece of equipment will be used before it should be replaced
the estimated amount of time that it will take to repair a piece of equipment when failure occurs
Which events should be considered as part of the business continuity plan? (Choose all that apply.)
non-emergency server relocation
natural disaster
hardware failure
employee resignation
Which process allows you to deploy, configure, and manage data centers through scripts?
Baselining
Immutable systems
Waterfall
IaC
Which principle stipulates that multiple modifications to a computer system should NOT be made at the same time?
due care
acceptable use
change management
due diligence
Your client's HR practices include promotion from within, and transferring people between offices on a regular basis. It seems like the most common question you hear when employees talk on the phone is "What office are you working at now and what are you doing?" What practice will ensure that a user's permissions are relevant and current?
Transitive trusts
Standard naming conventions
Federation
Recertification
The business continuity team is interviewing users to gather information about business units and their functions. Which part of the business continuity plan includes this analysis?
business impact analysis (BIA)
disaster recovery plan
contingency plan
occupant emergency plan (OEP)
Which type of analysis involves comparing the cost of implementing a safeguard to the impact of a possible threat?
exposure analysis
risk analysis
threat analysis
vulnerability analysis
Your company is establishing new employment candidate screening processes. Which of the following should be included? (Choose all that apply.)
Check all references.
Perform a background check.
Verify all education.
Review military records and experience.
In role-based awareness training, which of the following user groups would need to learn about implementing, managing, and monitoring controls?
Data owners
System administrators
System owners
Executive users
The company who just hired you provides a fixed amount to new employees so that the employee can purchase the laptop of their choice. After the purchase, the employee only needs to submit the receipt. What should you implement so that the company is able to better track the laptops?
Baseline deviations
Unauthorized software
Asset management
License compliance
You are about to begin a forensic investigation. Which of the following is NOT part of the investigation?
Capture a system image.
Perform network traffic and log analysis.
Follow the incident response plan.
Capture video.
What concept is being illustrated when user accounts are created by one employee and user permissions are configured by another employee?
rotation of duties
two-man control
collusion
separation of duties
As your organization's security officer, you are currently completing audits to ensure that your security settings meet the established baselines. In which phase of the security management life cycle are you engaged?
Implement
Monitor and Evaluate
Plan and Organize
Operate and Maintain
