WorksheetsNetrust Freshers Battery Exam
Total questions: 40
Worksheet time: 21mins
What best describes a strong Multi-factor Authenticator?
Something You Are, You Know, You Are Right About
Something You Are, You Know, You Have
Something You Are, You Know, You Have Not
Something You Are, You Know, You Only Knew
All of the above
Choose the best statement for Privileged Account.
A privileged account is a user account that has more executive privileges than other executive officers.
A privileged account is a user account that has more privileges than ordinary users.
A privileged account is a user account that has more privileges than executive officers.
A privileged account is a user account that has executive privileges than ordinary users.
True or False: Passwords are vulnerable to brute force regardless of the number of characters.
True
False
Maybe
Which of the following is NOT a threat to identity.
Identity Digital Twin
Identity Theft
Identity Fraud
What eKYC feature employs strong counter-measure against deepfakes?
Liveness Detection
Passive Detection
Passive Liveness
Liveness Feature
True or False: One-Time-Passwords are considered as part of Multi-factor Authentication strategy
TRUE
FALSE
True or False: Identity and Access Management is only for employees.
TRUE
FALSE
Select all that apply: Which are vulnerable to brute force attack?
Passwords
PIN
OTP
Select the best answer: A type of attack that sends a deceptive emails to fool specific category of people within the organization specially the high-ranking individuals.
Business Email Compromise
Phishing
Spear Phishing
Whaling
Based on the image on the right what is it MOST susceptible to when it comes to data security?
Theft
Brute Force
Password Guessing
Select the best answer based on this RISK statement about Information Security: Where the content of the information is changed so that it is no longer accurate or complete.
Integrity
Confidentiality
Availability
Select the best answer based on this statement about information security: When the information needed is made available when needed.
Confidentiality
Integrity
Availability
Select the best answer based on this RISK statement about information securtiy: where one or more person gain unauthorized access to information.
Confidentiality
Integrity
Availability
True or False: An SSL/TLS handshake is a negotiation between two parties on a network – such as a browser and web server – to establish the details of their connection.
TRUE
FALSE
True or False: The difference between a digital signature and a digital certificate is that the certificate binds the digital signature to the object, while the digital signature must ensure that the data or information remains secure from the moment it is sent.
TRUE
FALSE
Fill in the blanks: Hashing is a ______ function that scrambles plain text to produce a unique message digest.
Forward
Two-way
Backward
One-way
True or False: Hashing is can be virtually reversed.
TRUE
FALSE
Which verifies the user application/ request for a digital certificate within a PKI?
Registration authority
Revocation authority
User authority
Primary authority
Bob encrypts and sends a message for Alice using PKI system. What method does Alice use to decrypt the message when she receives it?
Alice's Private Key
Alice's Public Key
Bob's Private Key
Bob's Public Key
Fill in the blanks: ______ algorithms are faster and are suited for bulk encryption.
Symmetric
Assymetric
Which is NOT part of application security practice to eliminate vulnerabilities?
DevSecOps
Mobile and Web VAPT
Use of Static Application and Security Testing
Github Integration
Fill in the blanks: _______ is the practice of integrating security continuously throughout the software and/or application development lifecycle.
DevSecOps
SecOps
DevOps
True or False: The attack surface is the number of all possible points, or attack vectors, where an unauthorized user can access a system and extract data.
True
False
Fill in the blanks: In the context of Application Security, Mobile phones and APIs are considered ______.
Device Vectors
Attack Vectors
Hacking Vectors
True or False: SAST stands for Static Application Security Testing.
TRUE
FALSE
Fill in the blanks: If S in SAST stands for Static, then D in DAST stands for ______.
Disclosed
Distributed
Dynamic
Decrypted
Fill in the blanks: ______ is a security tool or control that helps protect web applications by filtering and monitoring HTTP traffic between a web application and the Internet.
Web Application Firewall
Application Firewall
Application Control
Reverse Proxy
True or False: A Web Application Firewall (WAF) operates through a set of rules often called policies.
TRUE
FALSE
True or False: During a DDoS attack, rate limiting can be quickly implemented by modifying Web Application Firewall (WAF) policies.
TRUE
FALSE
Fill in the blanks: ______ only admits traffic that has been pre-approved.
Allow List
Block List
Deny List
Which is the right answer: An Endpoint Security Control that covers some more advanced capabilities like detecting and investigating security incidents, and ability to remediate endpoints to pre-infection state.
Endpoint Detention and Respond (EDR)
Endpoint Detection and Response (EDR)
Endpoint Detention and Response (EDR)
Endpoint Detection and Respond (EDR)
Fill in the blanks: ______ ______ is the framework that gives us insight how attacker sees the organization.
Mitre Att&ck
CIS Control
NIST
ISO 27001
In the context of Attack Surface Monitoring: Company Social Media Pages also considered part of the __________.
Cloud Assets
Attack Page
Unsupervised Assets
Attack Surface
Fill in the blanks: ______ is the practice of proactively searching for cyber threats that are lurking undetected in a network.
Cyber Hunting
Vulnerability Scanning
Threat hunting
Network Hunting
Which tool is essential in a Security Operations Center (SOC) for it to aggregate data and detect threats in an organization?
EDR
CCTV
Antivirus
SIEM
Which of the following can detect behavior based threats in an endpoint?
Antivirus
EDR
IPS
Application Firewall
True or False: Mean time to detect (MTTD) is one of the main key performance indicators in incident management.
TRUE
FALSE
True or False: In the context of Cyber Incident: Mean Time to Respond (MTTR, sometimes written as Mean Time to Response) is the average time required to return a system to operational condition after receiving notification of a failure or cyberattack.
TRUE
FALSE
Fill in the blanks: A ______ is a facility that houses an information security team responsible for monitoring and analyzing an organization's security posture on an ongoing basis
Security Operations Center
Security Detection Center
Security Response Center
Security Operating Center
Fill in the blanks: ______ is a technology that can identify and stop evasive network threats that couldn't be easily blocked using known attack patterns or signatures.
Network Detection and Response (NDR)
Network Prevention and Response (NPR)
Network Intrustion and Response (NIR)
