Font size
WorksheetsBasic Cybersecurity Concepts 1
Total questions: 25
Worksheet time: 15mins
Which of the following steps is required to mitigate data breach risks?
Use strong credentials and disable multi-factor authentication.
Use strong credentials and enable multi-factor authentication.
Reuse passwords, because it is easier that way.
What is the most common password in 2019 according to NCSC?
(a)
CYDEO customers' personal information was breached, what should be done?
Notify customers and let them know about the breach.
Ignore customers and deal with them later.
Not tell anyone about the breach and delay until things are calmed down.
Which of the following should you monitor or include in the SIEM? (select multiple)
Laptops
Antivirus
Servers
Routers
Firewall
Can SIEM work by itself, or does it need input from other devices?
It works directly with a firewall.
It depends on the company's infrastructure.
It needs input from other devices.
It can work by itself.
What would NOT be one of SOAR solutions for your company in case of a ransomware attack?
Automate the steps to be taken once the incident was detected.
Help to collaborate between SOC analysts.
Automatically fix the issue.
Provide a clear path on the escalation process.
Which is the correct order of the incident response process steps?
Preparation, Identification, Containment, Eradication, Recovery, Lessons Learned
Lessons Learned, Recovery, Eradication, Containment, Identification, Preparation
Identification, Preparation, Containment, Eradication, Lessons Learned, Recovery
Identification, Preparation, Containment, Eradication, Recovery, Lessons Learned
SOAR can help your company automatically decrypt files to avoid a ransomware attack.
True
False
What type of security solution would allow you to tell whether a file was really malicious or a false-positive?
Threat intelligence
Playbook
SOAR
SIEM
What does OSINT stand for?
Open Source Intelligence
Orchestrated Source Intelligence New Technology
Open Source Interconnection
Orchestrated Source Intelligence Network Technology
SIEM can easily help your company automatically decrypt files to avoid a ransomware attack.
True
False
What does OWASP stand for?
Open Worldwide Application Security Project
Orchestrated Web Application Security Protocols
Open Web Appliance Security Platform
Orchestrated Worldwide Application Security Project
What does BCP stand for?
Business Continuity Plan
Business Correction Plan
Business Continuity Project
Bees Can Pollute
What does DRP stand for?
Disaster Recovery Plan
Data Response Plan
Disc Recovery Plan
Directory Response Program
What's the main difference between the BCP and DRP?
BCP is focused on resuming the business operations, and DRP is focused on resuming the IT infrastructure that supports the business.
Sometimes they are the same, sometimes they are not.
DRP is focused on resuming the business operations, and BCP is focused on resuming the IT infrastructure that supports the business.
It depends on the company's security policy.
What is the term that best describes setting a lower priority to addressing a known vulnerability?
Grey area
Business continuity
Acceptable risk
Incident ignorance
Which of the followings are the primary objectives of a SOC?
(Choose all that apply.)
prevent
detect
publish findings on
respond to
ignore insignificant
Which of the following is NOT a tool that is commonly managed by SOC analysts?
Security Incident and Event Management solution
Active Directory Domain
Security Orchestration, Automation and Response solution
Threat Intelligence Platform
Firewall Policy
Which of the following tasks are typically performed on a daily basis by a SOC Analyst?
Reviewing alerts and logs
Reverse engineering malware
Defending against DDoS attacks launched by nation state threat actors
Containing lateral movement
What are some of the job roles commonly found in a SOC? (Choose all that apply.)
DevOps engineer
SOC analyst
Threat hunter
Reverse malware engineer
SOC manager
What are two methods used to protect confidentiality?
Privileged access management
Encryption
Hashing
Intrusion detection systems
What is a common attack to disrupt availability?
random attack
data breach
man in the middle
DDoS attack
Which factor of the triad is affected when security controls are too restrictive?
Availability
Integrity
Confidentiality
What is the process of taking a snapshot of a system to help protect its integrity?
baselining
silverlining
crossroad
overlining
How do you feel this week?
