NEW
Font size
WorksheetsQuiz CSA (Final)
Total questions: 20
Worksheet time: 17mins
What code HTTPS Status for server cannot handle the request?
4xx
1xx
2xx
5xx
What does HTTPS Status code 403 represents?
Forbidden Error
Unauthorized Error
Not Found Error
Internal Server Error
John as a SOC analyst is worried about the amount of Tor traffic hitting the network. He wants to prepare a dashboard in the SIEM to get a graph to identify the locations from where the TOR traffic is coming. Which of the following data source will he use to prepare the dashboard?
Apache/ Web Server logs with IP addresses and Host Name
DHCP/Logs capable of maintaining IP addresses or hostnames with IPtoName resolution
IIS/ Web Server logs with IP addresses and user agent IPtouseragent resolution.
DNS/ Web Server logs with IP addresses
David is a SOC analyst in Karen Tech. One day an attack is initiated by the intruders but David was not able to find any suspicious events. This type of incident is categorized into?
False positive Incidents
False Negative Incidents
True Positive Incidents
True Negative Incidents
An organization is implementing and deploying the SIEM with following capabilities. What kind of SIEM deployment architecture the organization is planning to implement?
Cloud, MSSP Managed
Self-hosted, MSSP Managed
Self-hosted, Self-Managed
Self-hosted, Jointly Managed
Identify the attack in which the attacker exploits a target system through publicly known but still unpatched vulnerabilities.
DNS Poisoning Attack
Slow DoS Attack
DHCP Starvation
Zero-Day Attack
Which of the following can help you eliminate the burden of investigating false positives?
Not trusting the security devices
Ingesting the context data
Treating every alert as high level
Treating every alert as high leve
Which of the following is a Threat Intelligence Platform?
Which of the following is a report writing tool that will help incident handlers to generate efficient reports on detected incidents during incident response process?
threat_note
MagicTree
IntelMQ
Malstrom
Which of the following technique involves scanning the headers of IP packets leaving a network to make sure that the unauthorized or malicious traffic never leaves the internal network?
Ingress Filtering
Egress Filtering
Throttling
Rate Limiting
Which one of the following is the correct flow for Setting Up a Computer Forensics Lab?
Planning and budgeting → Forensics lab licensing → Physical location and structural design considerations → Work area considerations → Physical security recommendations → Human resource considerations
Planning and budgeting → Physical location and structural design considerations→ Forensics lab licensing → Human resource considerations → Work area considerations → Physical security recommendations
Planning and budgeting → Physical location and structural design considerations → Forensics lab licensing → Work area considerations → Human resource considerations → Physical security recommendations
Planning and budgeting → Physical location and structural design considerations → Work area considerations → Human resource considerations → Physical security recommendations → Forensics lab licensing
According to the Risk Matrix table, what will be the risk level when the probability of an attack is very high, and the impact of that attack is major?
Low
Extreme
High
Medium
John doe is a member of an IRT, which was started recently in a company named Mesh Tech. He wanted to find the purpose and scope of the planned incident response capabilities. What is he looking for?
Incident Response Resources
Incident Response Mission
Incident Response Vision
Incident Response Intelligence
According to the forensics investigation process, what is the next step carried
out right after collecting the evidence?
Set a Forensic lab
Call Organizational Disciplinary Team
Create a Chain of Custody Document
Send it to the nearby police station
John doe a SOC analyst, while monitoring logs, noticed large TXT , NULL payloads. What does this indicate?
Concurrent VPN Connections Attempt
DNS Exfiltration Attempt
DHCP Starvation Attempt
Covering Tracks Attempt
Which of the following steps of incident handling and response process focus on limiting the scope and extent of an incident?
Containment
Data Collection
Identification
Eradication
Which of the following tool can be used to filter web requests associated with the SQL Injection attack?
nmap
Hydra
UrlScan
Zap Proxy
Which encoding replaces unusual ASCII characters with “%” followed by the character’s two-digit ASCII code expressed in hexadecimal?
URL Encoding
Unicode Encoding
Base64 Encoding
UTF Encoding
Which of the following security technology is used to attract and trap people who attempt unauthorized or illicit utilization of the host system?
Honeypot
De-Militarized Zone (DMZ)
Firewall
Intrusion Detection System
Which of the following attack can be eradicated by using a safe API to avoid the use of the interpreter entirely?
Command Injection Attacks
LDAP Injection Attacks
File Injection Attacks
SQL Injection Attacks
