wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

1-30 Quiz

Total questions: 30

Worksheet time: 3600secs

Name
Class
Date
1.

NO.1 The process of passively gathering information prior to launching a cyberattack is called:

a)

(A). tailgating

b)

(B). reconnaissance

c)

(C). pharming

d)

(D). prepending

2.

NO.2 A Chief Security Office's (CSO's) key priorities are to improve preparation, response, and

recovery practices to minimize system downtime and enhance organizational resilience to

ransomware attacks. Which of the following would BEST meet the CSO's objectives?

a)

(A). Use email-filtering software and centralized account management, patch high-risk systems, and

restrict administration privileges on fileshares.

b)

(B). Purchase cyber insurance from a reputable provider to reduce expenses during an incident.

c)

(C). Invest in end-user awareness training to change the long-term culture and behavior of staff and

executives, reducing the organization's susceptibility to phishing attacks.

d)

(D). Implement application whitelisting and centralized event-log management, and perform regular

testing and validation of full backups.

3.

NO.3 A new plug-and-play storage device was installed on a PC in the corporate environment. Which

of the following safeguards will BEST help to protect the PC from malicious files on the storage

device?

a)

(A). Change the default settings on the PC.

b)

(B). Define the PC firewall rules to limit access.

c)

(C). Encrypt the disk on the storage device.

d)

(D). Plug the storage device in to the UPS

4.

NO.4 An organization is concerned about hackers potentially entering a facility and plugging in a

remotely accessible Kali Linux box. Which of the following should be the first lines of defense against

such an attack? (Select Two)

a)

(A). MAC filtering

b)

(B). Zero Trust segmentation

c)

(C). Network access control

d)

(D) Access control vestibules

e)

(E) Guards

5.

NO.5 The following is an administrative control that would be MOST effective to reduce the

occurrence of malware execution?

a)

(A). Security awareness training

b)

(B). Frequency of NIDS updates

c)

(C). Change control procedures

d)

(D). EDR reporting cycle

6.

NO.6 A security analyst is investigation an incident that was first reported as an issue connecting to

network shares and the internet, While reviewing logs and tool output, the analyst sees the

following:

Which of the following attacks has occurred?

a)

(A). IP conflict

b)

(B). Pass-the-hash

c)

(C). MAC flooding

d)

(D). Directory traversal

e)

(E). ARP poisoning

7.

NO.7 Which of the following technical controls is BEST suited for the detection and prevention of

buffer overflows on hosts?

a)

(A). DLP

b)

(B). HIDS

c)

(C). EDR

d)

(D). NIPS

8.

NO.8 A nuclear plant was the victim of a recent attack, and all the networks were air gapped. A

subsequent investigation revealed a worm as the source of the issue. Which of the following BEST

explains what happened?

a)

(A). A malicious USB was introduced by an unsuspecting employee.

b)

(B). The ICS firmware was outdated

c)

(C). A local machine has a RAT installed.

d)

(D). The HVAC was connected to the maintenance vendor.

9.

NO.9 Which of the following ISO standards is certified for privacy?

a)

(A). ISO 9001

b)

(B). ISO 27002

c)

(C). ISO 27701

d)

(D). ISO 31000

10.

NO.10 An incident, which is affecting dozens of systems, involves malware that reaches out to an

Internet service for rules and updates. The IP addresses for the Internet host appear to be different in

each case. The organization would like to determine a common IoC to support response and recovery

actions. Which of the following sources of information would BEST support this solution?

a)

(A). Web log files

b)

(B). Browser cache

c)

(C). DNS query logs

d)

(D). Antivirus

11.

NO.11 Which of the following incident response steps involves actions to protect critical systems

while maintaining business operations?

a)

(A). Investigation

b)

(B). Containment

c)

(C). Recovery

d)

(D). Lessons learned

12.

NO.12 A Chief Executive Officer (CEO) is dissatisfied with the level of service from the company's

new service provider. The service provider is preventing the CEO from sending email from a work

account to a personal account. Which of the following types of service providers is being used?

a)

(A). Telecommunications service provider

b)

(B). Cloud service provider

c)

(C). Master managed service provider

d)

(D) Managed security service provider

13.

NO.13 A researcher has been analyzing large data sets for the last ten months. The researcher works

with colleagues from other institutions and typically connects via SSH to retrieve additional data.

Historically, this setup has worked without issue, but the researcher recently started getting the

following message:

Which of the following network attacks is the researcher MOST likely experiencing?

a)

(A). MAC cloning

b)

(B). Evil twin

c)

(C). Man-in-the-middle

d)

(D). ARP poisoning

14.

NO.14 A smart retail business has a local store and a newly established and growing online

storefront. A recent storm caused a power outage to the business and the local ISP, resulting in

several hours of lost sales and delayed order processing. The business owner now needs to ensure

two things:

* Protection from power outages

* Always-available connectivity In case of an outage

The owner has decided to implement battery backups for the computer equipment Which of the

following would BEST fulfill the owner's second need?

a)

(A). Lease a point-to-point circuit to provide dedicated access.

b)

(B). Connect the business router to its own dedicated UPS.

c)

(C). Purchase services from a cloud provider for high availability

d)

D Replace the business's wired network with a wireless network.

15.

NO.15 A company Is concerned about is security after a red-team exercise. The report shows the

team was able to reach the critical servers due to the SMB being exposed to the Internet and running

NTLMV1,

Which of the following BEST explains the findings?

a)

(A). Default settings on the servers

b)

(B). Unsecured administrator accounts

c)

(C). Open ports and services

d)

(D). Weak Data encryption

16.

NO.16 A company is setting up a web server on the Internet that will utilize both encrypted and

unencrypted web-browsing protocols. A security engineer runs a port scan against the server from

the Internet and sees the following output:

Which of the following steps would be best for the security engineer to take NEXT?

a)

(A). Allow DNS access from the internet.

b)

(B). Block SMTP access from the Internet

c)

(C). Block HTTPS access from the Internet

d)

(D). Block SSH access from the Internet.

17.

NO.17 An attacked is attempting to exploit users by creating a fake website with the URL

www.validwebsite.com.

The attacker's intent is to imitate the look and feel of a legitimate website to obtain personal

information from unsuspecting users. Which of the following social-engineering attacks does this

describe?

a)

(A). Information elicitation

b)

(B) Typo squatting

c)

(C). Impersonation

d)

(D). Watering-hole attack

18.

NO.18 A company is implementing MFA for all applications that store sensitive data. The IT manager

wants MFA to be non-disruptive and user friendly. Which of the following technologies should the IT

manager use when implementing MFA?

a)

(A). One-time passwords

b)

(B). Email tokens

c)

(C). Push notifications

d)

(D). Hardware authentication

19.

NO.19 A financial organization has adopted a new secure, encrypted document-sharing application

to help with its customer loan process. Some important PII needs to be shared across this new

platform, but it is getting blocked by the DLP systems. Which of the following actions will BEST allow

the PII to be shared with the secure application without compromising the organization's security

posture?

a)

(A). Configure the DLP policies to allow all PII

b)

(B). Configure the firewall to allow all ports that are used by this application

c)

(C). Configure the antivirus software to allow the application

d)

(D). Configure the DLP policies to whitelist this application with the specific PII

e)

(E). Configure the application to encrypt the PII

20.

NO.20 An organization's Chief Security Officer (CSO) wants to validate the business's involvement in

the incident response plan to ensure its validity and thoroughness. Which of the following will the

CSO MOST likely use?

a)

(A). An external security assessment

b)

(B). A bug bounty program

c)

(C). A tabletop exercise

d)

(D). A red-team engagement

21.

NO.21 A small business just recovered from a ransomware attack against its file servers by

purchasing the decryption keys from the attackers. The issue was triggered by a phishing email and

the IT administrator wants to ensure it does not happen again. Which of the following should the IT

administrator do FIRST after recovery?

a)

(A). Scan the NAS for residual or dormant malware and take new daily backups that are tested on a

frequent basis

b)

(B). Restrict administrative privileges and patch ail systems and applications.

c)

(C). Rebuild all workstations and install new antivirus software

d)

(D). Implement application whitelisting and perform user application hardening

22.

NO.22 Name: Wikipedia.org

Address: 208.80.154.224

Which of the following attacks MOST likely occurred on the user's internal network?

a)

(A). DNS poisoning

b)

(B). URL redirection

c)

(C). ARP poisoning

d)

(D). /etc/hosts poisoning

23.

NO.23 A SOC is implementing an in sider-threat-detection program. The primary concern is that

users may be accessing confidential data without authorization. Which of the following should be

deployed to detect a potential insider threat?

a)

(A). A honeyfile

b)

(B). A DMZ

c)

(C). DLP

d)

(D). File integrity monitoring

24.

NO.24 A SECURITY ANALYST NEEDS TO FIND REAL-TIME DATA ON THE LATEST MALWARE AND loCs

WHICH OF THE FOLLOWING BEST DESCRIBE THE SOLUTION THE ANALYST SHOULD PERSUE?

a)

(A). ADVISORIES AND BULLETINS

b)

(B). THREAT FEEDS

c)

(C). SECURITY NEWS ARTICLES

d)

(D). PEER-REVIEWED CONTENT

25.

NO.26 An attacker is attempting, to harvest user credentials on a client's website. A security analyst

notices multiple attempts of random usernames and passwords. When the analyst types in a random

username and password.

the logon screen displays the following message:

Which of the following should the analyst recommend be enabled?

a)

(A). Input validation

b)

(B). Obfuscation

c)

(C). Error handling

d)

(D). Username lockout

26.

NO.27 Security analysts are conducting an investigation of an attack that occurred inside the

organization's network.

An attacker was able to connect network traffic between workstation throughout the network. The

analysts review the following logs:

The layer 2 address table has hundred of entries similar to the ones above. Which of the following

attacks has MOST likely occurred?

a)

(A). SQL injection

b)

(B). DNS spoofing

c)

(C). MAC flooding

d)

(D). ARP poisoning

27.

NO.28 An organization hired a consultant to assist with an active attack, and the consultant was able

to identify the compromised accounts and computers. Which of the following is the consultant MOST

likely to recommend to prepare for eradication?

a)

(A). Quarantining the compromised accounts and computers, only providing them with network

access

b)

(B). Segmenting the compromised accounts and computers into a honeynet so as to not alert the

attackers.

c)

(C) Isolating the compromised accounts and computers, cutting off all network and internet access.

d)

(D). Logging off and deleting the compromised accounts and computers to eliminate attacker access.

28.

NO.29 Which of the following provides the BEST protection for sensitive information and data stored

in cloud-based services but still allows for full functionality and searchability of data within the cloudbased

services?

a)

(A). Data encryption

b)

(B). Data masking

c)

(C). Anonymization

d)

(D). Tokenization

29.

NO.30 A major political party experienced a server breach. The hacker then publicly posted stolen

internal communications concerning campaign strategies to give the opposition party an advantage.

Which of the following BEST describes these threat actors?

a)

(A). Semi-authorized hackers

b)

(B). State actors

c)

(C). Script kiddies

d)

(D). Advanced persistent threats

30.

NO.25 Leveraging the information supplied below, complete the CSR (Cetificate Signing Request) for the server to set up TLS

(HTTPS)

Hostname            : ws01

Domain                : comptia.org

IPv4                      : 10.1.9.50

IPV4                     : 10.2.10.50

Root                     : home.aspx*

DNS CNAME       : homesite.

a)
b)
c)
d)