wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Quiz CSA (Final)

Total questions: 20

Worksheet time: 17mins

Name
Class
Date
1.

What code HTTPS Status for server cannot handle the request?

a)

4xx

b)

1xx

c)

2xx

d)

5xx

2.

What does HTTPS Status code 403 represents?

a)

Forbidden Error

b)

Unauthorized Error

c)

Not Found Error

d)

Internal Server Error

3.

John as a SOC analyst is worried about the amount of Tor traffic hitting the network. He wants to prepare a dashboard in the SIEM to get a graph to identify the locations from where the TOR traffic is coming. Which of the following data source will he use to prepare the dashboard?

a)

Apache/ Web Server logs with IP addresses and Host Name

b)

DHCP/Logs capable of maintaining IP addresses or hostnames with IPtoName resolution

c)

IIS/ Web Server logs with IP addresses and user agent IPtouseragent resolution.

d)

DNS/ Web Server logs with IP addresses

4.

David is a SOC analyst in Karen Tech. One day an attack is initiated by the intruders but David was not able to find any suspicious events. This type of incident is categorized into?

a)

False positive Incidents

b)

False Negative Incidents

c)

True Positive Incidents

d)

True Negative Incidents

5.

An organization is implementing and deploying the SIEM with following capabilities. What kind of SIEM deployment architecture the organization is planning to implement?

a)

Cloud, MSSP Managed

b)

Self-hosted, MSSP Managed

c)

Self-hosted, Self-Managed

d)

Self-hosted, Jointly Managed

6.

Identify the attack in which the attacker exploits a target system through publicly known but still unpatched vulnerabilities.

a)

DNS Poisoning Attack

b)

Slow DoS Attack

c)

DHCP Starvation

d)

Zero-Day Attack

7.

Which of the following can help you eliminate the burden of investigating false positives?

a)

Not trusting the security devices

b)

Ingesting the context data

c)

Treating every alert as high level

d)

Treating every alert as high leve

8.

Which of the following is a Threat Intelligence Platform?

a)

TC Complete

b)

Keepnote

c)

SolarWinds MS

9.

Which of the following is a report writing tool that will help incident handlers to generate efficient reports on detected incidents during incident response process?

a)

threat_note

b)

MagicTree

c)

IntelMQ

d)

Malstrom

10.

Which of the following technique involves scanning the headers of IP packets leaving a network to make sure that the unauthorized or malicious traffic never leaves the internal network?

a)

Ingress Filtering

b)

Egress Filtering

c)

Throttling

d)

Rate Limiting

11.

Which one of the following is the correct flow for Setting Up a Computer Forensics Lab?

a)

Planning and budgeting → Forensics lab licensing → Physical location and structural design considerations → Work area considerations → Physical security recommendations → Human resource considerations

b)

Planning and budgeting → Physical location and structural design considerations→ Forensics lab licensing → Human resource considerations → Work area considerations → Physical security recommendations

c)

Planning and budgeting → Physical location and structural design considerations → Forensics lab licensing → Work area considerations → Human resource considerations → Physical security recommendations

d)

Planning and budgeting → Physical location and structural design considerations → Work area considerations → Human resource considerations → Physical security recommendations → Forensics lab licensing

12.

According to the Risk Matrix table, what will be the risk level when the probability of an attack is very high, and the impact of that attack is major?

a)

Low

b)

Extreme

c)

High

d)

Medium

13.

John doe is a member of an IRT, which was started recently in a company named Mesh Tech. He wanted to find the purpose and scope of the planned incident response capabilities. What is he looking for?

a)

Incident Response Resources

b)

Incident Response Mission

c)

Incident Response Vision

d)

Incident Response Intelligence

14.

According to the forensics investigation process, what is the next step carried

out right after collecting the evidence?

a)

Set a Forensic lab

b)

Call Organizational Disciplinary Team

c)

Create a Chain of Custody Document

d)

Send it to the nearby police station

15.

John doe a SOC analyst, while monitoring logs, noticed large TXT , NULL payloads. What does this indicate?

a)

Concurrent VPN Connections Attempt

b)

DNS Exfiltration Attempt

c)

DHCP Starvation Attempt

d)

Covering Tracks Attempt

16.

Which of the following steps of incident handling and response process focus on limiting the scope and extent of an incident?

a)

Containment

b)

Data Collection

c)

Identification

d)

Eradication

17.

Which of the following tool can be used to filter web requests associated with the SQL Injection attack?

a)

nmap

b)

Hydra

c)

UrlScan

d)

Zap Proxy

18.

Which encoding replaces unusual ASCII characters with “%” followed by the character’s two-digit ASCII code expressed in hexadecimal?

a)

URL Encoding

b)

Unicode Encoding

c)

Base64 Encoding

d)

UTF Encoding

19.

Which of the following security technology is used to attract and trap people who attempt unauthorized or illicit utilization of the host system?

a)

Honeypot

b)

De-Militarized Zone (DMZ)

c)

Firewall

d)

Intrusion Detection System

20.

Which of the following attack can be eradicated by using a safe API to avoid the use of the interpreter entirely?

a)

Command Injection Attacks

b)

LDAP Injection Attacks

c)

File Injection Attacks

d)

SQL Injection Attacks