Font size
Worksheetsweek 7 sec+ quiz
Total questions: 27
Worksheet time: 20mins
Which type of analysis involves comparing the cost of implementing a safeguard to the impact of a possible threat?
risk analysis
threat analysis
exposure analysis
vulnerability analysis
You administer a small corporate network. On Friday evening, after close of business, you performed a full backup of the hard disk of one of the company's servers. On Monday evening, you performed a differential backup of the same server's hard disk, and on Tuesday, Wednesday, and Thursday evenings you performed incremental backups of the server's hard disk.
Which files are recorded in the backup that you performed on Thursday?
all of the files on the hard disk
all of the files on the hard disk that were changed or created since the differential backup on Monday
all of the files on the hard disk that were changed or created since the incremental backup on Tuesday
all of the files on the hard disk that were changed or created since the incremental backup on Wednesday
Which concept involves contracting with a third party who will provide a location and equipment to be used in the event of an emergency?
Offsite storage
Alternate processing sites
Disaster recovery plan
Alternate business practices
Management at your company has requested that you implement DLP. What is the purpose of this technology?
It allows organizations to use the Internet to host services and data remotely instead of locally.
It monitors data on computers to ensure the data is not deleted or removed.
It implements hardware-based encryption.
It protects against malware.
Which automation or scripting concept can reduce the risk that new equipment might not have all the same settings, applications, and drivers as your existing equipment without changing vital user settings?
Templates
Configuration validation
Continuous monitoring
Automated courses of action
Management has notified you that the mean time to repair (MTTR) a critical hard drive is too high. You need to address this issue with the least amount of expense. What should you do?
Add another hard drive, and implement disk mirroring.
Add two more hard drives, and implement disk striping with parity.
Add another hard drive, and implement disk striping.
Replace the hard drive with a faster hard drive.
What is typically part of an information policy?
acceptable use
authentication
classification of information
employee termination procedure
Your client is a small retailer that accepts orders via e-mail. The e-mail form submitted by a client's customer includes credit card information, and you demonstrate to the client how risky that is. As a result, the client adds secure credit card processing to their website, and no longer accepts e-mail orders. Which risk management concept does this represent?
Risk acceptance
Risk mitigation
Risk transference
Risk avoidance
The business continuity team is interviewing users to gather information about business units and their functions. Which part of the business continuity plan includes this analysis?
business impact analysis (BIA)
occupant emergency plan (OEP)
disaster recovery plan
contingency plan
You need to display the current protocol statistics and port connections for Windows and UNIX/Linux computers. Which command should you use?
ping
tracert
nbtstat
netstat
As part of a new security initiative, your organization has decided that all employees must undergo security awareness training. What is the aim of this training?
All employees excluding top management should understand the legal implications of loss of information.
All employees in the IT department should be able to handle social engineering attacks.
All employees in the IT department should be able to handle security incidents.
All employees must understand their security responsibilities.
When calculating risks by using the quantitative method, what is the result of multiplying the asset values by the exposure factor (EF)?
SLE
risk elimination
risk elimination
ACV
Which policy defines the sensitivity of a company's data?
a backup policy
a security policy
an information policy
a use policy
Which principle stipulates that multiple modifications to a computer system should NOT be made at the same time?
acceptable use
due diligence
due care
change management
Your company is establishing new employment candidate screening processes. Which of the following should be included? (Choose all that apply.)
Review military records and experience.
Perform a background check.
Check all references.
Verify all education.
Your company has recently started adopting formal security policies to comply with several state regulations. One of the security policies states that certain hardware is vital to the organization. As part of this security policy, you must ensure that you have the required number of components plus one extra to plug into any system in case of failure. Which strategy is this policy demonstrating?
fault tolerance
cold site
clustering
server redundancy
You are the security administrator for your company. You identify a security risk. You decide to continue with the current security plan. However, you develop a contingency plan for if the security risk occurs. Which type of risk response strategy are you demonstrating?
acceptance
avoidance
mitigation
transference
To justify the expenses of the forensic investigation, what is one thing that you should closely document?
Chain of custody
Man-hours
Screenshots
Network traffic and logs
In role-based awareness training, which of the following user groups would need to learn about implementing, managing, and monitoring controls?
System owners
Executive users
Data owners
System administrators
Your client allows the users to choose their own logon names for their account. You have seen opsboss, vpgal, and domainadm used as logons. You care very concerned about these obvious administrative accounts. What security control should you implement?
Standard naming conventions
File system security
Account maintenance
Recertification
What preserves the existence and integrity of relevant electronic records (and paper records) when litigation is imminent?
Data sovereignty
Legal hold
Chain of custody
Incident response plan
The company who just hired you provides a fixed amount to new employees so that the employee can purchase the laptop of their choice. After the purchase, the employee only needs to submit the receipt. What should you implement so that the company is able to better track the laptops?
License compliance
Unauthorized software
Asset management
Baseline deviations
Which factor does NOT minimize the security breach incidents committed by internal employees?
separation of duties
mandatory vacations
nondisclosure agreements signed by employees
rotation of duties
You identify a security risk that you do not have in-house skills to address. You decide to procure contract resources. This contractor will be responsible for handling and managing this security risk. Which type of risk response strategy are you demonstrating?
mitigation
avoidance
transference
acceptance
Your company decides to implement a RAID-5 array on several file servers. Which feature is provided by this deployment?
Scalability
Elasticity
High availability
Distributed allocation
Your organization has recently implemented a new security policy that includes the implementation of the principle of least privilege. You need to ensure that users understand this principle and implement the appropriate procedures to adhere to this principle. What is the best implementation of this principle?
Ensuring that all services use the main administrative account to execute their processes
Completing administrative tasks at a computer that functions only as a server
Issuing the Run as command to execute administrative tasks during a regular user session
Issuing a single account to each user, regardless of his job function
Your client's HR practices include promotion from within, and transferring people between offices on a regular basis. It seems like the most common question you hear when employees talk on the phone is "What office are you working at now and what are you doing?" What practice will ensure that a user's permissions are relevant and current?
Federation
Transitive trusts
Recertification
Standard naming conventions
