WorksheetsCyberops quiz
Total questions: 10
Worksheet time: 11mins
What is a difference between SIEM and SOAR?
SOAR predicts and prevents security alerts, while SIEM checks attack patterns and applies the mitigation.
SIEM predicts and prevents security alerts, while SOAR checks attack patterns and applies the mitigation.
SOAR's primary function is to collect and detect anomalies, while SIEM is more focused on security operations automation and response.
SIEM's primary function is to collect and detect anomalies, while SOAR is more focused on security operations automation and response.
What is a difference between data obtained from Tap and SPAN ports?
SPAN improves the detection of media errors, while Tap provides direct access to traffic with lowered data visibility.
SPAN passively splits traffic between a network device and the network without altering it, while Tap alters response times.
Tap mirrors existing traffic from specified ports, while SPAN presents more structured data for deeper analysis.
Tap sends traffic from physical layers to the monitoring device, while SPAN provides a copy of network traffic from switch to destination.
An engineer received an alert affecting the degraded performance of a critical server. Analysis showed a heavy CPU and memory load. What is the next step the engineer should take to investigatethis resource usage?
Run ps -m to capture the existing state of daemons and map required processes to find the gap
Run ps -d to decrease the priority state of high load processes to avoid resource exhaustion
Run ps -u to find out who executed additional processes that caused a high load on a server
Run ps -ef to understand which processes are taking a high amount of resources
What is an incident response plan?
an organizational approach to events that could lead to asset loss or disruption of operations
an organizational approach to system backup and data archiving aligned to regulations
an organizational approach to disaster recovery and timely restoration of operational services
an organizational approach to security management to ensure a service lifecycle and continuous improvements
What are two symmetric encryption algorithms? (Choose two.)
3DES
HMAC
MD5
AES
SHA
Which antimalware software approach can recognize various characteristics of known malware files to detect a threat?
heuristics-based
behaviour-based
signature-based
routing-based
Which protocol is attacked when a cybercriminal provides an invalid gateway in order to create a man-in-the-middle attack?
DHCP
DNS
ICMP
HTTP/HTTPS
For which discovery mode will an AP generate the most traffic on a WLAN?
active mode
mixed mode
passive mode
open mode
When real-time reporting of security events from multiple sources is being received, which function in SIEM provides capturing and processing of data in a common format?
log collection
normalization
compliance
aggregation
An administrator is concerned with restricting which network applications and uses are acceptable to the organization. What security policy component does the administrator use to address these concerns?
network maintenance policy
remote access policy
acceptable use policy
incident handling procedures policy
