Worksheetsgrind sec
Total questions: 166
Worksheet time: 2hrs 44mins
A security administrator has been using EAP-FAST wireless authentication since the migration from WEP to WPA2. The company’s network team now needs to support additional authentication protocols inside of an encrypted tunnel. Which of the following would meet the network team’s requirements?
EAP-TTLS
EAP-TLS
PEAP
EAP-MSCHAPv2
the foundational standard for Information Security Management Systems (ISMS).
ISO 27001
ISO 31000
ISO 27701
ISO 27002
Which of the following standards provides information on privacy and managing PII?
ISO 27701
ISO 31000
ISO 27002
ISO 27001
Information security controls are the focus of the _____ standard.
ISO 27002
ISO 31000
ISO 27701
ISO 27001
sets international standards for risk management practices.
ISO 31000
ISO 27701
ISO 27002
ISO 27001
FTPS
AES
TLS
HTTPS
TLS
AES
SRTP
TLS
AES
Responsible for the organization's data privacy
Data protection officer (DPO)
Data owners
Data processor
Data controller
Data custodian/steward
Associates sensitivity labels to data and complies with laws
Data protection officer (DPO)
Data owners
Data processor
Data controller
Data custodian/steward
Processes data on behalf of the data controller. Often a 3rd party.
Data protection officer (DPO)
Data owners
Data processor
Data controller
Data custodian/steward
Manages the purposes and means by which data is processed
Data protection officer (DPO)
Data owners
Data processor
Data controller
Data custodian/steward
Associates sensitivity labels to data
steward/custodian
controller
owner
Controls implemented using systems (firewalls, antivirus, etc)
Technical
Managerial
Operational
Controls that are implemented by people (security guards, etc)
Technical
Managerial
Operational
Controls that address security design and implementation
Technical
Managerial
Operational
SOAR: conditional steps to follow. a broad process
playbook
runbook
SOAR: linear checklist of steps to perform
playbook
runbook
ASCII formatted file that contains certs and chain certificates.
P7B
DER
P12
Privacy enhanced mail (PEM)
.cer
Common windows format. Usually contains only public key.
P7B
DER
P12
Privacy enhanced mail (PEM)
.cer
Often used to transfer a private and public keypair.
P7B
DER
P12
Privacy enhanced mail (PEM)
.cer
Store many x.509 certs in 1 file. Can be password protected
P7B
DER
P12
Privacy enhanced mail (PEM)
.cer
Base64 encoded DER cert. Good for email.
P7B
DER
P12
Privacy enhanced mail (PEM)
.cer
Certificate format often used for Java applications
P7B
DER
P12
Privacy enhanced mail (PEM)
.cer
Standard for digital certificates
x.509
DER
P7B
Wildcard
Who gets access and what they get access to
(a)
VPN: Connecting sites over a layer 3 network as if they were connected at layer 2. (often implemented with IPSEC)
(a)
Block cipher mode / acts like a stream cipher
CTR (Counter)
ECB (Electronic code book)
CBC (Cipher block chaining)
GCM (Galois/Counter mode)
Each block is XORed with the previous ciphertext block.
CTR (Counter)
ECB (Electronic code book)
CBC (Cipher block chaining)
GCM (Galois/Counter mode)
Backup type that backs up what has changed since the last full backup
Differential
Incremental
Backup type that backs up what has changed since the last backup. Restoring requires every backup in between
Differential
Incremental
Create a central place for all of the diverse cloud providers
Service Integration and Management (SIAM)
Managed service provider
Microservices API
IaaS
What allows for log collection, aggregation, long term storage and more?
(a)
Military use of influence campaigns.
(a)
Targeted phishing attack where the victim believes the sender is someone they know.
Spear phishing
Smishing
Vishing
Spam
Phishing attack targeted at high level members of a company.
Whaling
Spear Phishing
Pharming
Vishing
Spam
The browser can check for certificate revocation
(a)
IMAP using SSL
tcp/993
tcp/995
tcp/587
POP3 using SSL
tcp/993
tcp/995
tcp/587
SMTP with authentication
tcp/993
tcp/995
tcp/587
Form of EAP that utilizes a shared secret (PAC)
EAP-FAST
PEAP
EAP-TLS
EAP-TTLS
MSCHAPv2
Form of EAP where authentication server uses a digital certificate.
EAP-FAST
PEAP
EAP-TLS
EAP-TTLS
MSCHAPv2
Often combined with PEAP
EAP-FAST
PEAP
EAP-TLS
EAP-TTLS
MSCHAPv2
Form of authentication compatible with a GTC (generic token card, hardware token generator)
EAP-FAST
PEAP
EAP-TLS
EAP-TTLS
MSCHAPv2
Form of EAP that requires digital certificates on ALL devices.
EAP-FAST
PEAP
EAP-TLS
EAP-TTLS
MSCHAPv2
Form of EAP that supports other protocols inside a TLS tunnel
EAP-FAST
PEAP
EAP-TLS
EAP-TTLS
MSCHAPv2
Eduroam uses what?
EAP-FAST
PEAP
EAP-TLS
EAP-TTLS
Radius federation
Which of the following can be used to apply security policies to cloud-based implementations?
CASB
MSSP
CSP
VPN
Which part of the PC startup process verifies the digital signature of the OS kernel?
Trusted Boot
Measured Boot
Secure Boot
POST
Which part of the PC startup process verifies the digital signature of the bootloader?
Trusted Boot
Measured Boot
Secure Boot
POST
Which part of the PC startup process verifies that nothing on the computer has been changed by malicious software or other processes?
Trusted Boot
Measured Boot
Secure Boot
POST
Which of the following would be the BEST way to confirm the secure baseline of a deployed application instance?
Perform an integrity measurement
Compare the production application to the sandbox
Perform QA testing on the application instance
Compare the production application to the previous version
Which of the following provides a ticket-based system to provide SSO?
TACACS+
LDAPS
Kerberos
802.1X
the expected lifetime of a nonrepairable product or system
MTTF
MTBF
prediction of how often a repairable system will fail.
MTTF
MTBF
Command used for reading or writing data to the network.
netcat
nmap
netstat
dig
Port scanning and reconnaissance utility
netcat
nmap
netstat
dig
Restoring from a backup after an attack would be what type of security control?
detective
managerial
compensating
physical
Encrypted data is very different from original plaintext.
Confusion
Diffusion
Collision
Obfuscation
Even changing one character in the plaintext will drastically change the encryption output.
Confusion
Diffusion
Collision
Obfuscation
Contains a hash of the IPSec packet to provide integrity of the data.
Authentication Header
Encapsulation Security Payload
Hash-based Message Authentication Code
Electronic Codebook
manages access rights and sets security controls to the data.
Data custodian/steward
Data processor
Privacy officer
Data owner
This form of EAP requires a radius server
EAP-FAST
PEAP
EAP-TLS
EAP-TTLS
MSCHAPv2
Netstat flag which disables domain name resolution
-n
-b
-a
-f
Netstat flag which shows active connections and also shows which TCP and UDP ports are listening for a connection.
-n
-b
-a
-f
Netstat flag which shows what programs are in control of what connections
-n
-b
-a
-f
Netstat flag which shows fully qualified domain names in the foreign address column.
-n
-b
-a
-f
type the command in to view the last 5 lines of syslog
(a)
When an unauthorized person is let in willingly (holding the door for example)
piggyback
tailgating
When an unauthorized individual enters a restricted-access building by following an authorized user.
piggyback
tailgating
fire extinguisher class for common combustibles
CLASS A
CLASS B
CLASS C
CLASS D
fire extinguisher class for liquids
CLASS A
CLASS B
CLASS C
CLASS D
fire extinguisher class for electrical fires
CLASS A
CLASS B
CLASS C
CLASS D
fire extinguisher class for flammable metals
CLASS A
CLASS B
CLASS C
CLASS D
DES block size
(a)
DES key size (a) bits
DES rounds
(a)
Triple DES block size
(a)
Triple DES key size ___ or ___ bits
(a)
Triple DES rounds
(a)
IDEA PGP block size
(a)
IDEA PGP key size (a) bits
IDEA PGP rounds
(a)
Blowfish block size
(a)
Blowfish key size __-____ bits
(a)
Blowfish rounds
(a)
Skipjack block size
(a)
Skipjack key size (a) bits
RC2 block size
(a)
RC2 key size (a) bits
RC4 block size
(a)
RC4 key size ___-____ bits
(a)
RC5 RSA block size __, __. __
(a)
RC5 RSA key size ___-____ bits
(a)
RC5 RSA rounds
(a)
AES block size
(a)
AES key size ___, ____, ____ bit key
(a)
AES rounds __, __, __
(a)
Two fish block size
(a)
Two fish key size _- (a) bits
Two Fish rounds
(a)
RSA is
asymmetric
symmetric
ECC is
asymmetric
symmetric
Diffie-Hellman is
asymmetric
symmetric
El - Gamal is
asymmetric
symmetric
Digital Signature Algorithm (DSA) is
asymmetric
symmetric
Merkle-Hellman Knapsack is
asymmetric
symmetric
AES is
asymmetric
symmetric
DES is
asymmetric
symmetric
3DES is
asymmetric
symmetric
IDEA PGP is
asymmetric
symmetric
Blowfish is
asymmetric
symmetric
Skipjack is
asymmetric
symmetric
RC2 is
asymmetric
symmetric
RC4 is
asymmetric
symmetric
RC5 is
asymmetric
symmetric
Two Fish is
asymmetric
symmetric
Which mode of IPSEC leaves the header untouched?
transport
tunnel
IPSEC mode which encrypts both header and payload
transport
tunnel
WPA2 uses
AES-CCMP
AES-SAE
WPA3 uses
AES-CCMP
AES-SAE
Firewalls and routers are a good example of
rule based access control
role based access control
Mandatory access control
Discretionary access control
chmod - execute
1
2
4
chmod - write
1
2
4
chmod - read
1
2
4
Who is affected by a disaster
stakeholders
Network infrastructure
IT departments
A predetermined set of instructions or procedures that describe how an organization's mission-essential functions will be sustained within 12 hours and for up to 30 days as a result of a disaster event before returning to normal operations.
continuity of operations plan
Business Continuity Plan
Disaster Recovery Plan
contingency plan
defines strategies on how to continue the business in case of a catastrophic event. It details what you will do to keep the business running while systems are down.
continuity of operations plan
Business Continuity Plan
Disaster Recovery Plan
contingency plan
details how to recover from a major event. How to get the systems back to normal. It's about restoring the state before the catastrophic event and how fast you'll get there and how much data you'd lose in terms of RTO, RPO.
continuity of operations plan
Business Continuity Plan
Disaster Recovery Plan
contingency plan
an agreement between two or more parties to enable them to work together that is not legally enforceable but is more formal than an unwritten agreement.
Memorandum of Understanding (MOU)
Service Level Agreement (SLA)
Measurement systems analysis (MSA)
the maximum tolerable time to restore an organization's information system following a disaster, representing the length of time that the organization is willing to attempt to function without its information system
Recovery Time Objective (RTO)
Recovery Point Objective (RPO)
Disaster Recovery Plan
SOC 2
a metric that measures the maximum amount of data loss an organization can tolerate in the event of a disruption such as a cyber attack or data breach. It helps in determining how frequently data should be backed up to minimize potential data loss
Recovery Time Objective (RTO)
Recovery Point Objective (RPO)
Disaster Recovery Plan
SOC 2
focuses on restoring IT systems and infrastructure
continuity of operations plan
Business Continuity Plan
Disaster Recovery Plan
contingency plan
focuses on maintaining critical business functions
continuity of operations plan
Business Continuity Plan
Disaster Recovery Plan
contingency plan
type the incident response acronym
(a)
Two parties can verify non-repudiation.
Message Authentication Code (MAC)
Digitial Signature
Non-repudiation that can be publicly verified
Message Authentication Code (MAC)
Digitial Signature
Includes 20 key actions (the critical security controls)
CIS CSC
NIST RMF
NIST CSF
SOC 2
6 step process that is mandatory for federal agencies and organizations that handle federal data
CIS CSC
NIST RMF
NIST CSF
SOC 2
Which step of the NIST RMF is this: "Categorize - define the enviornment"
(a)
Which step of the NIST RMF is this: "Select - Pick appropriate controls"
(a)
Which step of the NIST RMF is this: "Implement - define proper implementation"
(a)
Which step of the NIST RMF is this: "Assess - determine if controls are working"
(a)
Which step of the NIST RMF is this: "Authorize - make decision to authorize a system"
(a)
Which step of the NIST RMF is this: "Monitor - check for ongoing compliance"
(a)
A voluntary commercial framework. (Identify, Protect, Detect, Respond, and recover)
CIS CSC
NIST RMF
NIST CSF
SOC 2
Type of audit that focuses on firewalls, intrusion detection, and mfa
CIS CSC
NIST RMF
NIST CSF
SOC 2
Tests controls in place at a particular point in time
SOC 2 type I audit
SOC 2 type II audit
Tests controls over a period of at least 6 months
SOC 2 type I audit
SOC 2 type II audit
Cloud specific security controls, and controls are mapped to standards, best practices and regulations
CIS CSC
NIST RMF
CCM (Cloud Controls Matrix)
SOC 2
An enterprise app catalog is provided by what?
(a)
Two people must be preset to perform the business function
dual control
Split knowledge
No one person has all of the details
dual control
Split knowledge
What process verifies device drivers during windows startup
Trusted Boot
Measured Boot
Secure Boot
ELAM
"what if" scenarios based on specific events, that establish the "play book" to follow should that event (and assumed impacts) occur.
continuity of operations plan
Business Continuity Plan
Disaster Recovery Plan
contingency plan
Windows command to view the device's routing table
(a)
explains how an "adversary" exploits a "capability" over an "infrastructure" against a "victim" in simple terms.
Diamond Model of intrusion analysis
NIST Risk Management Framework
ISO/IEC 27701
MITRE Att&CK Framework
6 step process which is mandatory for federal agencies or orgs that handle federal data
Diamond Model of intrusion analysis
NIST Risk Management Framework
ISO/IEC 27701
MITRE Att&CK Framework
Privacy info management systems
Diamond Model of intrusion analysis
NIST Risk Management Framework
ISO/IEC 27701
MITRE Att&CK Framework
Identify potential security techniques to block future attacks, understand methods used to move around
Diamond Model of intrusion analysis
NIST Risk Management Framework
ISO/IEC 27701
MITRE Att&CK Framework
Taking the risk as is
Acceptance
Transference
Mitigation
Risk avoidance
Buying cyber security insurance
Acceptance
Transference
Mitigation
Risk avoidance
Decrease the risk level (example - investing in security systems)
Acceptance
Transference
Mitigation
Risk avoidance
Stop participating in high risk activity
Acceptance
Transference
Mitigation
Risk avoidance
US federal law that requires public companies to implement controls and procedures to ensure the accuracy and security of financial data and systems, and to maintain the confidentiality, integrity, and availability of financial information and systems.
Memorandum of Understanding (MOU)
Service Level Agreement (SLA)
Measurement systems analysis (MSA)
SOX
Assess the measurement process and calculate measurement uncertainty.
Memorandum of Understanding (MOU)
Service Level Agreement (SLA)
Measurement systems analysis (MSA)
SOX
