Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Cyberops quiz

Total questions: 10

Worksheet time: 11mins

Name
Class
Date
1.

What is a difference between SIEM and SOAR? 

a)

SOAR predicts and prevents security alerts, while SIEM checks attack patterns and applies the mitigation.

b)

SIEM predicts and prevents security alerts, while SOAR checks attack patterns and applies the mitigation.

c)

SOAR's primary function is to collect and detect anomalies, while SIEM is more focused on security operations automation and response.

d)

SIEM's primary function is to collect and detect anomalies, while SOAR is more focused on security operations automation and response.

2.

What is a difference between data obtained from Tap and SPAN ports?

a)

SPAN improves the detection of media errors, while Tap provides direct access to traffic with lowered data visibility.

b)

SPAN passively splits traffic between a network device and the network without altering it, while Tap alters response times.

c)

Tap mirrors existing traffic from specified ports, while SPAN presents more structured data for deeper analysis.

d)

Tap sends traffic from physical layers to the monitoring device, while SPAN provides a copy of network traffic from switch to destination.

3.

An engineer received an alert affecting the degraded performance of a critical server. Analysis showed a heavy CPU and memory load. What is the next step the engineer should take to investigatethis resource usage?

a)

Run ps -m to capture the existing state of daemons and map required processes to find the gap

b)

Run ps -d to decrease the priority state of high load processes to avoid resource exhaustion

c)

Run ps -u to find out who executed additional processes that caused a high load on a server

d)

Run ps -ef to understand which processes are taking a high amount of resources

4.

What is an incident response plan?

a)

an organizational approach to events that could lead to asset loss or disruption of operations

b)

an organizational approach to system backup and data archiving aligned to regulations

c)

an organizational approach to disaster recovery and timely restoration of operational services

d)

an organizational approach to security management to ensure a service lifecycle and continuous improvements

5.

What are two symmetric encryption algorithms? (Choose two.)

a)

3DES

b)

HMAC

c)

MD5

d)

AES

e)

SHA

6.

Which antimalware software approach can recognize various characteristics of known malware files to detect a threat?

a)

heuristics-based

b)

behaviour-based

c)

signature-based

d)

routing-based

7.

Which protocol is attacked when a cybercriminal provides an invalid gateway in order to create a man-in-the-middle attack?

a)

DHCP

b)

DNS

c)

ICMP

d)

HTTP/HTTPS

8.

For which discovery mode will an AP generate the most traffic on a WLAN?

a)

active mode

b)

mixed mode

c)

passive mode

d)

open mode

9.

When real-time reporting of security events from multiple sources is being received, which function in SIEM provides capturing and processing of data in a common format?

a)

log collection

b)

normalization

c)

compliance

d)

aggregation

10.

An administrator is concerned with restricting which network applications and uses are acceptable to the organization. What security policy component does the administrator use to address these concerns?

a)

network maintenance policy

b)

remote access policy

c)

acceptable use policy

d)

incident handling procedures policy